Checkmarx SOW.docx
DOCX document 28 KB Posted
- Attached to
- Checkmarx Licenses Federal contract opportunity
- Solicitation number
- OIT-393-2023-0761-RAW
About this file
This statement of work outlines the Checkmarx software licenses and services required by the Centers for Medicare and Medicaid Services. The agency needs 100 Checkmarx user licenses to allow all 100 developers to scan Apex code for security vulnerabilities as they work. It also requires 50 project licenses to scan all Salesforce applications, as well as a server license to support the necessary scanning. Additional concurrent scanning engines are needed to handle the scanning load. An auditor license will help optimize the false positive and negative rates. An integration license is required to streamline scanning and remediation within their existing development processes. The related federal contract opportunity is solicitation number OIT-393-2023-0761-RAW from the Department of Health and Human Services to provide these Checkmarx licenses and services.
View the file
Other files for this federal contract opportunity
| File | Type | Posted |
|---|---|---|
| RFQ.docx | DOCX document |
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
Statement of Work Checkmarx August 2, 2023
Checkmarx Static Code Analysis (CxSAST) will allow CMS to scan Apex code as developers are creating it to identify and ultimately remediate security risks introduced by insecure code. Compared with other source analysis tools, Checkmarx is widely accepted by the Salesforce development team because it seamlessly fits into the existing software development life cycle and helps in quick implementation to meet CMS ever-evolving business needs. CMS has 100 developers writing Salesforce applications. In order to ensure that CMS has full coverage in identifying vulnerabilities produced by the Salesforce developers we will require 100 licenses of Checkmarx users. (Cx-VolUser-1YR- AllSupLangIncApex). Checkmarx provides a 2:1 ratio of users to projects at no additional cost. Projects are identified as a code base that is scanned at one time. CMS will require the 50 projects in order to scan all of the CMS Salesforce applications. (Cx-Project-1Yr-AllSupLangIncApex). Checkmarx requires each environment to be licensed for one server (Cx-Server-1YR- AllSupLangIncApex). In order to meet the scanning demands of CMS, multiple scanning engines will need to be run simultaneously. Checkmarx offers the ability to do this through the acquisition of additional scanning engines (Cx-Concurrent Scans). The creation of custom queries are required in order ensure a low false/true positive rate that is unique to the CMS environment. Checkmarx provides this capability through an Auditor license (Cx-Auditor-1YR- AllSupLangIncApex). In order to streamline the scanning/remediation process, CMS requires the ability to integrate the Checkmarx solution with their existing development stack. Checkmarx provides this capability through an integration license (Cx-Integration-1YR- AllLangIncApex) image1.emf
File details come from the government source that posted it. Updated .