Cybersecurity Testing DRAFT SIR _ 693KA8-20-R-00017.pdf
PDF 856 KB Posted
- Attached to
- ATO Cybersecurity Testing (DRAFT SIR) Federal contract opportunity
- Solicitation number
- 693KA8-20-R-00017
About this file
This is a draft solicitation for cybersecurity testing services. The Federal Aviation Administration is seeking independent risk assessment, penetration testing, and other cybersecurity capabilities to meet continuous monitoring requirements. Services include program management, security assessments, vulnerability analysis, penetration testing, aircraft testing, and specialized assessments. Responses are due by July 31, 2020. The solicitation is a small business set-aside to be performed at various FAA facilities nationwide. The period of performance is one base year with four option years. Pricing is time-and-materials based on labor categories and other direct costs.
View the file
Other files for this federal contract opportunity
| File | Type | Posted |
|---|---|---|
| Attachment _ FISMA Systems.xlsx | XLSX spreadsheet | |
| Attachment L002 - Section B - Price Worksheet.xlsx | XLSX spreadsheet | |
| Attachment L003 - Past Performance Questionnaire.docx | DOCX document | |
| J Attach J002 - Labor Category Descriptions and Qualifications.docx | DOCX document | |
| Attachment L001 - Q and A Template (1).xlsx | XLSX spreadsheet | |
| Attachment _ NIST.FIPS.199.pdf |
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
SIR 693KA8-20-R-00017 (Cybersecurity and Penetration Testing)
1 | P a g e
Section A – Standard Form 33
Section B – Supplies or Services and Price/Costs
B.1 Brief Description of Services
B.2 Contract Type – Time and Materials
B.3 Ceiling Value
B.4 Overview of Pricing Schedules
Section C – Statement of Work
C.1 Introduction
C.2 References
C.3 Requirements
C.4 Deliverables
Section D - Packaging, Marking, and Shipping
D.1 Requirements
Section E – Inspection and Acceptance
E.1 AMS Clauses
E.2 General
Section F – Deliveries or Performance
F.1 AMS Clauses
F.2 Period of Performance
F.3 Place of Performance
F.4 Deliverables
Section G – Contract Administration Data
G.1 AMS Clauses
G.2 Points of Contact
G.3 Contracting Officer’s Authority
G.4 Correspondence
2 | P a g e
G.5 Electronic Communications
G.6 Invoicing and Payments
G.7 Travel
Section H – Special Contract Requirements
H.1 AMS Clauses Incorporated in Full Text
H.2 Interpretation of Contract
H.3 Personal Services and Inherently Governmental Functions Prohibited
H.4 Personnel Requirements and Work Hours
H.5 Notification of Debarment and Suspension
H.6 Dissemination of Contract Information
H.7 Definition of Days
H.8 Post-Award Conference
Section I - Contract Clauses
I.1 Clauses Incorporated by Reference
I.2 Clauses Incorporated in Full Text
Section J – List of Attachments
Section K – Representations and Certifications
K.1 Provisions Incorporated by Reference
K.2 Provisions in Full Text
Section L – Instructions and Notices to Offerors
L.1 AMS Provisions Incorporated by Reference
L.2 AMS Provisions in Full Text
L.3 Date, Time, and Method of Submission
L.4 Expenses Related to Offeror Submissions
L.5 Notification of Award and Debriefing of Unsuccessful Offerors
L.6 Number of Awards
3 | P a g e
L.7 Contractor Responsibility
L.8 Communications with Offerors
L.9 Non-Governmental Evaluators and Advisors
L.10 General Proposal Instructions
L.11 Volume I – Technical Capability
L.12 Volume II – Price
L.13 Volume III – Past Performance
L.14 List of Solicitation – Specific Attachments
Section M – Evaluation Factors for Award
M.1 AMS Provisions Incorporated by Reference
M.2 General Information
M.3 Evaluation Methodology
M.4 Technical Capability (Volume I)
M.5 Price Evaluation (Volume II)
M.6 Past Performance (Volume III)
4 | P a g e
SECTION A – STANDARD FORM 33
Reserved
5 | P a g e
SECTION B – SUPPLIES OR SERVICES AND PRICE/COSTS
B.1 BRIEF DESCRIPTION OF SERVICES
This contract includes a variety of cybersecurity related services including penetration testing. Specific tasks are set forth in Section C.
B.2 CONTRACT TYPE – TIME AND MATERIALS
This contract is Time-and-Materials (T&M) type contract
B.3 CEILING VALUE
The ceiling value of this contract is TBDB.4 Overview of Pricing Schedules
B.4.1 CONTRACT LINE ITEM NUMBERS (CLINS) SUMMARY
CLINs for the five-year (60 month) period of performance are as follows.
Description Base Period (Year 1) Option 1 (Year 2) Option 2 (Year 3) Option 3 (Year 4) Option 4 (Year 5)
Labor 1001A 2001A 3001A 4001A 5001A Travel and ODCs 1001B 2001B 3001B 4001B 5001B
B.4.1.1 CLIN 1001A – 5001A [LABOR]
Attachment J001, Labor Schedule contains fully burdened hourly rates. Attachment J002, Labor Category Description and Qualifications.
B.4.1.2 CLIN 1001B – 5001B [TRAVEL AND OTHER DIRECT COSTS (ODCS)]
The ODC and Travel schedule below contain the estimated Not-to-Exceed (NTE) amounts inclusive of any applicable rates for all five years of performance.
Period Travel and ODC CLIN Travel and ODC Value Base Period (Year 1) 1001B $105,916.50 Option 1 (Year 2) 2001B $119,023.14 Option 2 (Year 3) 3001B $134,226.84 Option 3 (Year 4) 4001B $151,863.14 Option 4 (Year 5) 5001B $172,321.24
Total $683,350.86
ODCs include:
1. Materials purchased specifically for performance of work under this contracts that are not part of the Contractor’s burden rates (e.g., software licenses specific to work performed under this contract) and
2. Incidental services directly related to and necessary for the performance of work under this contract (e.g.
computer hosting services).
B.4.2 PRICING TERMS
B.4.2.1 LABOR
1. The fully burdened hourly rates in the labor schedule in B.4.1.1 include wages, fringe benefits, overhead, general and administrative cost, and profit.
6 | P a g e
2. The rates in the labor schedule in B.4.1.1 are ceiling rates and will apply to all direct labor hours regardless of whether the Contractor or one of its subcontractors performs the labor.
B.4.2.2 ODCS AND TRAVEL
1. When ODCs and Travel are required to fulfill individual contract requirements, the FAA will reimburse them at cost.
2. FAA will only reimburse the Contractor for ODCs and Travel proposed and approved in accordance with Section G.7, below.
3. The Contractor may apply either a G&A rate (in the event it has an approved accounting system) or an Administrative Fee of not to exceed four (4) percent (in the event it does not have an approved accounting system) to ODCs.
7 | P a g e
SECTION C – STATEMENT OF WORK
C.1 INTRODUCTION
C.1.1 BACKGROUND
The FAA, like all federal agencies, relies on a wide variety of telecommunications networks, networked systems, devices, and platforms to carry out its mission. The National Air Space (NAS), in particular, consists of most of these integrated networks, systems, and applications. The increasing complexity of these networks and systems may lead to potential defect or weakness in system security procedure, design, implementation, or internal control. This creates opportunity that foreign nations and non-state actors can acquire the ability to exploit these vulnerabilities and thereby penetrate and disrupt the FAA’s critical information infrastructure. Cybersecurity is the art of protecting networks, devices, and data from unauthorized access or criminal use and the practice of ensuring confidentiality, integrity, and availability of information.
The E-Government Act (Public Law 107-347), passed by the 107th Congress and signed into law by the President in December 2002, recognized the importance of information security to the economic and national security interests of the United States. Title III of the E-Government Act, entitled the Federal Information Security Management Act of 2014 (FISMA 2014), requires each federal agency to develop, document, and implement an agency-wide program to provide information security for the information and systems that support the operations and assets of the agency, including those provided or managed by another agency, contractor, or other sources.
The FAA runs a multi-faceted cybersecurity program to protect the NAS in accordance with FISMA. The ATO Cybersecurity Group (ACG), a line of business under the NAS Security and Enterprise Operations (NASEO) within the Air Traffic Organization (ATO), is the lead organization for governing, implementing, and managing cybersecurity controls for the NAS. Cybersecurity Testing is one of the multi-faceted cybersecurity programs managed by the ACG.
C.1.2 OBJECTIVES
FAA requires subject matter expertise and operational support to carry out its cybersecurity operations. In particular, the FAA requires contractor support to perform security assessments and to support penetration testing efforts. The objectives of this contract are to:
• Obtain technical support for FAA’s ongoing annual security assessment process; and
• Obtain subject matter expertise to support and enhance the FAA’s penetration testing capabilities.
C.1.3 SCOPE
The Contractor must furnish to the Government all necessary labor, services, and materials (except as specified by the Government) required to accomplish the efforts as specifically set forth in this Statement of Work (SOW). The Contractor must perform all tasks under the technical direction of the Contracting Officer’s Representative (COR).
The scope of work includes the following core services:
• Program Management Support
• Cybersecurity Testing o Independent Risk Assessment Testing o Penetration Testing
8 | P a g e
Sections C.3 and C.4 describes specific tasks and activities
C.1.4 INHERENTLY GOVERNMENTAL FUNCTIONS
The Contractor must not perform any inherently governmental functions, as identified in the Office of Federal Procurement Policy Letter 11-01. These are functions that are so intimately related to the public interest as to require performance by Federal Government employees. These functions include activities that require either the exercise of discretion in applying Federal Government authority or the making of value judgments in making decisions for the Government. Support under this contract is limited to non-decision-making activities that do not bind the Government, such as analyses, studies, and assistance. Contract employee recommendations must be forwarded to a Government employee for review and consideration.
C.2 REFERENCES
The Contractor must ensure all work is in full compliance with regulations expressed in the following procedures, orders, and programs unless otherwise directed by the Contracting Officer’s Representative (COR). In the event of a conflict between this SOW and any of the applicable documents cited within, the requirements of this SOW take precedence.
In providing the Cybersecurity Testing required under this contract, the Contractor must comply with the applicable FAA orders, directives, and policies listed below. The Contractor is responsible for reviewing all applicable documents and understanding their impact on the delivery of the required services. Applicable documents are subject to revision, and it is the Contractor’s responsibility to ensure that the most current version of each document is used and that new applicable documents are adopted.
Document Title Link Executive Order (EO) 13636, Improving Critical Infrastructure Cybersecurity https://obamawhitehouse.archives.gov/the-press-office/2013/02/12/executive-order-improving-critical-infrastructure-cybersecurity
Presidential Policy Directive (PPD) – 21, Critical Infrastructure Security and Resilience https://obamawhitehouse.archives.gov/the-press-office/2013/02/12/presidential-policy-directive-critical-infrastructure-security-and-resil
Federal Information Security Management Act (FISMA) of https://csrc.nist.gov/topics/laws-and-regulations/laws/fisma
Office of Management and Budget (OMB) Memorandum M-14-03, Enhancing the Security of Federal Information and Information Systems https://obamawhitehouse.archives.gov/sites/default/files/o mb/memoranda/2014/m-14-03.pdf
ATO Order JO_1370.114, Implementation of FAA Telecommunications (FTI) Services and Information Security Requirements in the NAS https://www.faa.gov/regulations_policies/orders_notices/in dex.cfm/go/document.information/documentID/1019628
FAA Information Security and Privacy Program & Policy https://www.faa.gov/regulations_policies/orders_notices/in dex.cfm/go/document.information/documentID/1030708
NIST Special Publication 800-37 Rev. 2 - Risk Management Framework for Information Systems and Organizations: A System Life Cycle Approach for Security and Privacy https://csrc.nist.gov/publications/detail/sp/800-37/rev- 2/draft
NIST Special Publication 800-53 Rev. 4 - Security and Privacy Controls for Federal Information Systems and Organizations https://csrc.nist.gov/publications/detail/sp/800-53/rev- 5/draft https://obamawhitehouse.archives.gov/the-press-office/2013/02/12/executive-order-improving-critical-infrastructure-cybersecurity https://obamawhitehouse.archives.gov/the-press-office/2013/02/12/executive-order-improving-critical-infrastructure-cybersecurity https://obamawhitehouse.archives.gov/the-press-office/2013/02/12/executive-order-improving-critical-infrastructure-cybersecurity https://obamawhitehouse.archives.gov/the-press-office/2013/02/12/presidential-policy-directive-critical-infrastructure-security-and-resil https://obamawhitehouse.archives.gov/the-press-office/2013/02/12/presidential-policy-directive-critical-infrastructure-security-and-resil https://obamawhitehouse.archives.gov/the-press-office/2013/02/12/presidential-policy-directive-critical-infrastructure-security-and-resil https://csrc.nist.gov/topics/laws-and-regulations/laws/fisma https://www.faa.gov/regulations_policies/orders_notices/index.cfm/go/document.information/documentID/1019628 https://www.faa.gov/regulations_policies/orders_notices/index.cfm/go/document.information/documentID/1019628 https://www.faa.gov/regulations_policies/orders_notices/index.cfm/go/document.information/documentID/1030708 https://www.faa.gov/regulations_policies/orders_notices/index.cfm/go/document.information/documentID/1030708 https://csrc.nist.gov/publications/detail/sp/800-37/rev-2/draft https://csrc.nist.gov/publications/detail/sp/800-37/rev-2/draft https://csrc.nist.gov/publications/detail/sp/800-53/rev-5/draft https://csrc.nist.gov/publications/detail/sp/800-53/rev-5/draft
9 | P a g e
NIST Special Publication (SP) 800-82, Guide to Industrial Control Systems (ICS) Security:
https://csrc.nist.gov/publications/detail/sp/800- 82/archive/2011-06-09
NIST Special Publication 800-137 - Information Security Continuous Monitoring (ISCM) for Federal Information Systems and Organizations:
https://csrc.nist.gov/publications/detail/sp/800-137/final
FIPS-199 - Standards for Security Categorization of Federal Information and Information Systems https://csrc.nist.gov/publications/detail/fips/199/final
FAA Order 1370.121 - FAA Information Security and Privacy Program & Policy https://www.faa.gov/regulations_policies/orders_notices/in dex.cfm/go/document.information/documentID/1030708
FY18_ATO_SSP_MODERATE-to- HIGH_FIPS_Change_Workbook_v1.1_17-0914
Provided by the FAA, as required
Fiscal Year 2018 (FY18) Security Authorization Handbook https://faaco.faa.gov/index.cfm/attachment/download/7771 ATO Information Security Continuous Monitoring (ISCM) Plan for NAS and Mission Support (MS) Systems https://employees.faa.gov/org/linebusiness/ato/operations/ technical_operations/neo/issp/authorization/media/ATO%20 NAS%20ISCM%20FY18%20Plan%20Rev%2017_18-0403.docx
National Institute Standards and Technology (NIST) Special Publication (SP) 800-115 https://csrc.nist.gov/publications/detail/sp/800-115/final
C.3 REQUIREMENTS
C.3.1 TASK 1 – PROGRAM MANAGEMENT SUPPORT
The Contractor must provide and manage all personnel and resources necessary to execute the performance of this contract. The Contractor must manage all Contractor resources, personnel, subcontractors, and activities involved in the delivery of required support as defined in this SOW. The Contractor must designate a Program Manager (PM) who is responsible for the overall performance of the contract.
The Contractor is responsible for performing all start-up activities required to support the Government’s transition from the incumbent contracts including but not limited to staffing actions and personnel certifications required to perform work efforts as ordered and implementation of Government-furnished tools, equipment, and processes to support the scheduling of testing delivery, contract administration, and other functions as applicable.
The PM must be the Contractor’s official representative for the technical and administrative performance of all services required under this contract and serve as the Contractor’s focal point for interactions with the Government’s Program Office. The PM must keep FAA counterparts informed of any issues that could adversely affect performance of the required work efforts and make recommendations for resolution. The PM must ensure that all required Contractor resources are available and sufficient, both in terms of the quantity of resources and their qualifications, to successfully perform all the tasks required in the SOW. The PM must establish and maintain clear and effective lines of authority, coordination, communication, and accountability for contract-wide work efforts.
The Contractor must prepare and submit a comprehensive Program Management Plan (PMP) (CDRL 001) describing its approach to managing Cybersecurity Testing support in accordance with the contract.
C.3.1.1 STAFFING AND RECRUITMENT
The Contractor must recruit and staff qualified personnel to perform the efforts required under this contract in accordance with the Government-approved PMP (CDRL 001).
C.3.1.2 TESTING SCHEDULE COORDINATION, DELIVERY AND RESOURCE MANAGEMENT
https://csrc.nist.gov/publications/detail/sp/800-137/final https://www.faa.gov/regulations_policies/orders_notices/index.cfm/go/document.information/documentID/1030708 https://www.faa.gov/regulations_policies/orders_notices/index.cfm/go/document.information/documentID/1030708 https://faaco.faa.gov/index.cfm/attachment/download/7771 https://csrc.nist.gov/publications/detail/sp/800-115/final
10 | P a g e
The Government will provide a yearly risk assessment and vulnerability assessment schedule to the Contractor. The Contractor must support the development of testing schedules in conjunction with the FAA designee for specific locations, as requested. The Contractor must provide on-site support services as outlined in the schedule in accordance with Section F.7. The Contractor must assign and provide the required resources to ensure on-time start and completion of testing in accordance with the schedule.
As detailed in the Program Management Review (CDRL 002), the Contractor must provide a schedule that aligns with the PMP per Task 3.1.2 to include the following:
• Depicts the system, test dates, and staffing for all scheduled testing in the Fiscal Year;
• Identifies task level resource requirements; and
• End results/deliverables.
C.3.1.3 MEETING ATTENDANCE
As requested by the CO or COR, the Contractor must participate in technical or programmatic meetings at Government-designated facilities and/or the Contractor’s facilities. The Government will indicate whether participation must be in-person or whether it may be via teleconference depending on the nature of the meeting.
The personnel representing the Contractor must have the requisite knowledge and skills to discuss the topics identified on the meeting agenda. Support of meetings includes the Post Award Conference. As requested by the Government, the Contractor must prepare and submit agendas, minutes, and presentation materials for all meetings and reviews.
C.3.1.4 QUALITY CONTROL /QUALITY ASSURANCE
The Contractor must include a Quality Control / Quality Assurance (QC/QA) function that is responsible for assessing and maintaining the quality of services and products provided under this contract. The Contractor must prepare and submit a Quality Control Plan (CDRL 003) that describes the QC/QA systems and processes that will be used to measure and ensure the quality of services and products.
QC/QA must be completed in accordance with applicable FAA orders and policies referenced in section C.3. The Contractor must implement and maintain QC/QA systems and processes that comply with the Government-approved Quality Control Plan. The Contractor must review and update the approved QCP upon any changes to the contract (e.g., additional duties, staffing changes, new quality assurance measures) or when directed by the COR.
C.3.1.5 STATUS REPORTING
The Contractor must provide Monthly Status Reports (MSRs) (CDRL 004) based on the deliverables identified in this SOW. The Contractor must provide an MSR that documents the activities of the previous month and identifies planned activities for the following month.
C.3.1.6 PROGRAM MANAGEMENT REVIEW
The Contractor must meet quarterly with the Program Management Organization (PMO) and COR for a Program Management Review (PMR) (CDRL 001) at a location mutually agreed upon by the FAA and the Contractor.
11 | P a g e
The Contractor must present and administratively support the quarterly PMRs. The Contractor must provide all PMR materials at least five (5) business days prior to the scheduled meeting. The Contractor must prepare and deliver PMR minutes including action items, issues, resolutions, or specific FAA instructions no later than five (5) business days after the meeting.
C.3.1.7 CONTRACT TRANSITION
C.3.1.7.1 PHASE-IN TRANSITION PLAN, REPORT AND PERIOD
The Phase-In period commences upon contract award. The duration of this Phase-In period will not exceed (30) business days.
As detailed in the Phase-In Transition Plan (CDRL 005), the Contractor must develop a Transition Phase-In Plan to describe the necessary activities and procedures required to accomplish a smooth transition from the incumbent Contractor to this contract. The Transition Plan must address updating contract documentation, badging of personnel, access to IT resources (e.g., Knowledge Sharing Network), property receipts, and the estimated resource requirements from the incumbent Contractor.
The Contractor must coordinate with the Government on-site representative at each site identified. The Contractor must be responsible for all subcontractor and vendor personnel who visit or work at Government facilities. The Contractor must ensure that all personnel who visit or work at Government facilities meet Government security requirements. The Contractor must ensure that precautions for the safety of the personnel and property are in place before starting work and are followed throughout the period of performance of the work. The Contractor must conduct an inspection of the site with the Government on-site representative.
The Contractor must develop a Phase-In Inventory Report (CDRL 006) that identifies all equipment and documentation required for Contractor use during the period of performance.
C.3.1.7.2 PHASE-OUT TRANSITION PLAN, REPORT AND PERIOD
The last ninety (90) business days of this contract will constitute the Phase-Out Period. As detailed in the Phase-Out Transition Plan (CDRL 007), the Contractor must develop and submit a Transition Phase-Out Plan for Government approval that addresses the processes and procedures necessary to ensure continuity of operations and a smooth transition to the successor contractor. During this period, the Contractor must conduct a final inventory of equipment and materials, finalizing program records, and ensure continuity of operations.
The Contractor must develop a Phase-Out Inventory Plan (CDRL 008) that identifies all equipment and documentation required for Contractor use during the period of performance.
C.3.2 TASK 2 – INDEPENDENT RISK ASSESSMENT SUPPORT
As directed, and in accordance with the Test Schedule (CDRL 009) the Contractor must perform security system assessments on all ATO systems identified in the ATO Information Security Continuous Monitoring (ISCM) Plan. The Contractor must use the methods (illustrated in Figure 1, below) set forth in NIST 800-53A Rev 4 or latest version to conduct the assessments. The objective of the independent risk assessment task is to ensure that current (and future) NAS systems receive and retain authority to operate.
12 | P a g e
Figure 1 – NIST 800-53A Methods
• Examine: The Examine method is the process of reviewing, inspecting, observing, studying, or analyzing one or more assessment objects (i.e., specifications, mechanisms, or activities). The purpose of the Examine method is to facilitate assessor understanding, achieve clarification or obtain evidence.
• Interview: The Interview method is the process of holding discussions with individuals or groups of individuals within an organization. The purpose of the Interview method is to facilitate assessor understanding, achieve clarification, or obtain evidence.
• Test: The Test method is the process of exercising one or more assessment objects (i.e., activities or mechanisms) under specified conditions to compare actual with expected behavior.
In all three assessment methods, the results are used in making specific determinations called for in the determination statements and thereby achieving the objectives for the assessment procedure. Therefore, all three assessment methods (Examine, Interview, and Test) must be used to complete a Security Assessment Report (SAR)(CDRL 010). The Test method for NAS systems may be conducted in a Lab environment due to potential adverse impacts to air traffic safety and efficiency that may be attributed to security scan testing tools. With prior agreement and coordination with AIT/AIS, Mission support systems can be tested in their operational environment upon prior agreement and coordination with the FAA’s Information & Technology (AIT) and Aviation Information System (AIS) Departments.
For each assessment, the Contractor must perform the tasks including but not limited to:
• Support Independent Risk Assessment planning and coordination at multiple facilities and locations nationwide. This includes developing a System Security Assessment test plan (CDRL 011) and participating in pre-assessment and post-assessment activities.
• Perform Independent Risk Assessments to support new system authorizations, existing system reauthorizations, and NAS assets, when directed by the COR.
• Develop and maintain vulnerability scanning strategies to include Tactics, Techniques, and Procedures
(TTP).
• Develop Independent Risk Assessment documentation and formulate into a Security Assessment Report (SAR) (CDRL 010).
Examine
Review, inspect, observe, study, or analyze one or more assessment objects
Interview
Hold discussions with individuals or groups of individuals within an organization.
Test Exercise one or more assessment objects (i.e., activities or mechanisms) under specified conditions to compare actual with expected behavior
13 | P a g e
• Provide Risk Translation and develop draft Plan of Action and Milestones (POAMS) (CDRL 012).
• The Contractor must perform Regression Independent Risk Assessment to validate patches, fixes, and configuration changes made to the system, network, or web application under test mitigate the identified discrepancy, vulnerability, or noncompliance with Center for Internet Security (CIS) CIS Benchmark guideline from the original Vulnerability Scan. All Regression Testing must be documented by amending or appending the original Independent Risk Assessment Report.
C.3.3 TASK 3 – VULNERABILITY ASSESSMENT AND ANALYSIS OF ALTERNATIVES
The Contractor must conduct comprehensive vulnerability assessments. The Contractor must conduct vulnerability assessments on the following aspects of FAA systems and infrastructure:
• Network systems, services and devices;
• Applications (including patches);
• Cloud Based Service;
• Operating Systems (including patches);
• Web-Facing applications, devices and elements;
• Databases; and
• Other assets as determined by FAA Order, Policy, Guidance, or FAA direction.
The Contractor must identify and utilize industry leading technologies, or proven technologies, to develop and implement capabilities for vulnerability assessments of the FAA critical infrastructure. When directed by the COR, for critical mission processes, the Contractor must also conduct a systematic assessment of Mission Essential Functions (MEFs) susceptibility to process failures and the vulnerability of automatic cyber processes and inter-process communication to accidents and attacks.
The Contractor must also assess, analyze, and report on the results of the vulnerability assessment in accordance with FAA policy, guidance, established process, procedures, or direction of the COR. For each assessment, the Contractor must:
• Plan for the assessment;
• Perform the assessment;
• Document the System Security Assessment Report (SAR) assessment (CDRL 010) and recommend mitigation strategies. This includes:
o Identifying vulnerabilities;;
o Describing the risk to FAA o Recommending the implementation of existing technologies and methods (i.e., platforms, applications, frameworks, and capabilities) to incorporate threat avoidance and cyber defense;
o Recommending the development of new technologies and methods (i.e., platforms, applications, frameworks, and capabilities) to incorporate threat avoidance and cyber defense;
14 | P a g e
• Performing an Analysis of Alternatives on the recommended mitigations strategies documenting the costs, benefits and risk of each recommended.
C.3.3.1 VULNERABILITY MITIGATION AND ANALYSIS OF ALTERNATIVES
The Contractor must collaborate with the FAA to identify technologies, areas for development of new technologies, and analyze risks associated with each in order to mitigate vulnerabilities found in each assessment.
C.3.3.2 VULNERABILITY TESTING SUPPORT
The Contractor must perform software testing to confirm whether a change has had an adverse effect on a recent program or code change. The Contractor must ensure that the old code still works once the latest code change has been completed. Regression testing must include the prioritization of the test cases to minimize the business impact, critical and frequently used functionalities to limit the requirement for a retest of all existing test. The Contractor’s Regression Testing must include but is not limited to the following:
• Test Cases which have frequent defects.
• Functionalities which are more visible to the users.
• Test Cases which verify core features of the product.
• Test Cases of functionalities which has undergone more and recent changes.
• All integration Test Cases.
• All Complex Test Cases.
• Boundary value Test Cases.
• A sample of successful Test Cases.
• A sample of failure Test Case.
C.3.4 TASK 4 – PENETRATION TESTING SUPPORT
The Contractor must perform Penetration Testing of the ATO NAS security posture in order to provide detailed analysis of identification of application, system, and network vulnerabilities; gaps in IT security governance;
assessment of patching methodologies; current network security capabilities; and potential existing security incidents. Penetration testing will be within the scope of ATO, NAS accessible hosts residing in the security boundary of the Agency network environments. This includes underlying Network Management and Out of Band segments that provide network communications and services to publicly accessible hosts.
The Contractor must also provide Network, System, and Application penetration testing support following the guidelines delineated in National Institute Standards and Technology (NIST) Special Publication (SP) 800-115, “Technical Guide to Information Security Testing and Assessment,” and must be in accordance with Federal Information Processing Standards (FIPS) and National Institute Standards and Technology (NIST) System Authorization requirements and guidance. The assessment and reporting will be based on the NIST 800-53 low, 15 | P a g e moderate, and high security controls, Federal Information Processing Standard, (FIPS-199), FAA Order 1370.121, and other applicable government standard and policies.
As directed, and in accordance with the schedule agreed to (CDRL 010), the Contractor must perform penetration testing of FAA systems. The FAA will specify the environments (labs, modeling and simulation, exercise, real world) in which the Contractor will conduct each penetration test. The objectives of the penetration testing task are to:
• Discover new or existing software, firmware, hardware, and system vulnerabilities;
• Determine the impact of those vulnerabilities;
• Identify strategies to mitigate the potential impact of specific vulnerabilities; and
• Lower risk exposure across the NAS.
For each Penetration Test, the Contractor must:
• Develop Rules of Engagement (ROE) with the system owner and ACG to ensure that all parties understand and agree with the scope of the penetration test effort as documented in the Penetration Test Plan (CDRL 0013);
• Plan for the test;
• Perform the test; and
• Document the results of the test in the Penetration Test Report (CDRL 0014). This includes, but is not limited to:
o Describing any deviations from the rules of engagement or test plan;
o Describing the attack vector(s) test and threat model(s) followed during testing;
o Identifying any vulnerabilities exposed and describing how they can be exploited to gain access to NAS systems;
o Documenting overall results for inclusion in the Penetration Test Report (PTR);
o Developing briefings to support POAM development and remediation activities;
o Confirming that previously identified vulnerability findings have been remediated and are no longer a risk (if applicable); and o If requested, the Contractor must also provide FAA leadership with recommended remediation actions to lower overall risk exposure.
The Contractor must use standard penetration testing tools approved by the FAA. The Contractor must not circumvent access controls and privilege escalation. During penetration testing, the Contractor must not delete any live data or perform any Denial of Service attacks. Additionally, the Contractor must make every attempt to not disrupt operations (if applicable).
In the event that the Contractor gains access to a system during penetration testing:
16 | P a g e
• The tester must assess the potential impact and risk to the system, associated systems, and/or network infrastructure. If the assessment reveals a risk or impact to operations, the finding(s) should be immediately reported to the FAA, documented and the Contractor must seek and receive FAA approval to continue testing. Additionally, if the tester’s exploit, including but not limited to payloads, escalation tools, and configuration changes, made system modifications in order to gain access, then the tester must assess if these modifications could negatively affect the system baseline configuration or performance.
• The Contractor must assess the potential for damage to the system, associated systems and/or network infrastructure. If the assessment reveals a risk of damage or impact to operation, the finding should be documented, and the Contractor must seek and receive FAA approval to continue testing. The Contractor must document any system modifications made during the exploit that effect the target system(s) baseline configuration(s). If changes were made, the Contractor must document the changes as artifacts for vulnerability assessment and for normalizing the system back to configuration baseline post penetration testing.
• The Contractor must assess the ability of the attacker to leverage the system for access to additional systems and networks. This includes:
o An inventory of all applications, data storage devices and systems, and identification and authentication measures, made available to the FAA upon request.
o An inventory of all agency hardware and its operating systems and network management systems made available to the FAA upon request.
o Network Exploitation in a multi-vendor environment to include but not limited to: wireless technologies, network routers (Layer 3), network switches (Layer 2), firewalls, IDS/IPS’s, and Cloud services.
The Contractor must support Regression Penetration Testing to validate patches, fixes, and configuration changes made to the system, network, or web application under test mitigate the identified discrepancy or vulnerability identified in the original Penetration Test. All Regression Testing must be documented by amending or appending the original Penetration Test Report (CDRL 0014).
C.3.4.1 CYBER TESTING EXERCISES (RED AND BLUE TEAMING)
The Contractor must be required to support Red Teaming and/or Blue Teaming exercises. The list in the figure below is short representative of Red Teaming and Blue Teaming exercises and does not include every simulated environment, technique, or method that the Contractor and FAA may agree to use during performance. All Red Teaming and Blue Teaming Exercise must be conducted in a simulated environment or in an environment as directed by the FAA.
17 | P a g e
Red Teaming Blue Teaming
• Contractor acts as a Red Teamer (ethical (White Hat) attacker) and attempts to break or circumvent network and/or system defenses.
• Objective is to simulate attacks against a NAS network and/or systems that the Blue Team support to test the effectiveness of the cybersecurity defenses and Blue Team’s ability to detect and mitigate an attacker’s advances.
• Shall be conducted in a simulated environment.
• Contractor acts as a Blue Teamer (defensive cybersecurity personnel charged with maintaining network and/or system cybersecurity defenses).
• Works to harden defenses against simulated attacks.
• Objective is to detect and defend against simulated attacks by the Red Team identifying improvements to the cybersecurity posture and defenses of the network and/or system being simulated.
C.3.5 TASK 5 – AIRCRAFT CYBER TESTING SUPPORT
The Contractor must provide test support and capabilities for Aircraft Cyber vulnerability and penetration testing.
The Contractor must conduct Aircraft Cyber test activities, analyze, and report on Aircraft Testing results. The Contractor must assess all critical aircraft systems to identify weaknesses in systems that are vulnerable to attack to include identifying vulnerabilities in aircraft flight systems.
For each assessment, the Contractor must perform the following tasks:
• Support Test planning and coordination. This includes developing a System Security Assessment Test Plan (CDRL 011) and participating in pre-assessment and post-assessment activities.
• Provide technical expertise to interpret and implement the latest security standards, policies, and procedures required by Commercial Entities, Federal Agencies, and the Department of Defense (DoD) for cyber security.
• Provide technical expertise to plan and conduct Offensive Cyber Operations and Defensive Cyber Operations against critical aviation systems.
• Develop a Rules of Engagement (ROE) for the conduct of the penetration testing unless one was developed by the DoD.
• The Contractor must abide by the ROE developed by the DoD.
• Coordinate and conduct cyber tests and analysis to determine the security posture of aircraft systems.
• Develop, review or evaluate cyber operations and information assurance documentation as it relates to aircraft aviation ecosystems.
• Develop Independent Risk Assessment documentation and formulate into a System Security
Assessment Report (SAR) (CDRL 010).
The Contractor must provide SME analysis and operations support in all major areas of IA to include Computer Network Defense (CND), Software Security, Database Management, Design/Test, Hardware/Firmware, Physical Security, and aircraft Network Infrastructure.
18 | P a g e
• The Contractor must provide electronics/avionics/survivability equipment technical expertise at the component, assembly, subsystem, and system levels, and integrate into the next higher assembly for both hardware and software.
• The Contractor must develop, analyze, review, and validate recommended avionics’ form, fit, and function specifications; interface control documents; and aircraft integration documents.
• The Contractor must develop and/or evaluate and provide recommendations for electronics/ avionics/survivability related to active cyber threats and attacks.
• The Contractor must provide analyses, studies, data review, and recommendations concerning cyber threats against:
o Antennas, multi-mode millimeter wave radar, pilot night vision systems, command and control interface, electromagnetic interference, cockpit controls/displays, electromagnetic emissions (EME), communications security, processing systems, integrated systems/architectures, fault detection/diagnostics systems, and aircraft flight controls.
• The Contractor must analyze programs of other services to determine if interchangeability and/or interoperability of aircraft systems can be obtained.
C.3.6 TASK 6 – OPERATIONAL SITE ASSESSMENT
The Contractor must provide test support and capabilities for Operational Site Assessment Testing. The Contractor must provide the following for each assessment:
• Support Test planning and coordination. This includes developing a System Security Assessment Test Plan (CDRL 011) and participating in pre-assessment and post-assessment activities.
• Coordinate with FAA security points of contact (POC) to ensure test procedures have been validated through testing in the William J. Hughes Technical Center (WJHTC) lab environment.
• Collaborate and coordinate with all stakeholders.
• Perform interviews at the designated test sites.
• Collect configuration files and other artifacts as required.
• Develop Independent Risk Assessment documentation and formulate into a Security Assessment
Report (SAR) (CDRL 011).
• Ensure security controls are in place and give the ability to verify baselined system-level security controls have been met in the field.
C.3.7 TASK 7 – SPECIALIZED ASSESSMENTS
The Contractor must provide testing support for systems requiring specialized assessments. This may include the following scenarios:
• The Contractor must support Test planning and coordination. This includes developing a System Security Assessment Test Plan (CDRL 011) and participating in pre-assessment and post-assessment activities.
19 | P a g e
• The Contractor must perform specialized testing and assessments of industry equipment, such as switches, firewalls, load balancers, or other equipment, as directed by the COR, against current FAA and ATO performance and cybersecurity requirements. The Contractor must provide a detailed written report of the performed specialized testing and assessments.
• The Contractor must perform specialized testing, evaluation, and assessments, which encompasses a broad range of cybersecurity testing technology, of NAS edge device(s) or other devices, as requested by the COR, against current FAA and ATO performance and cybersecurity requirements. The Contractor must provide a detailed written report of the performed specialized testing, evaluation, and assessments.
• The Contractor must perform specialized testing, evaluation, and assessments of cybersecurity and industry equipment against current FAA and ATO performance and cybersecurity requirements for the purpose of potentially being added to the ACG approved equipment list. The types of cybersecurity and industry equipment may consist of Keyboard Video & Mouse (KVM), Test Access Points (TAP), Data Diode’s, Palo Alto’s, and others types of equipment as directed by the COR. The Contractor must provide a detailed written report of the performed specialized testing, evaluation, and assessments of the different types of cybersecurity and industry equipment assigned by the COR for evaluation.
• As directed by the COR, the Contractor must perform specialized testing, evaluation, and assessments, which encompasses a broad range of cybersecurity testing technology, of NAS edge devices being requested by NAS system owners. In order to conduct assessments of potential NAS edge devices, the Contractor must gather requirements from the NAS system owners and engineers as well as other resources as applicable. The Contractor must provide a detailed written report of the performed specialized testing, evaluation, and assessments.
• As directed by the COR, the Contractor must provide a sandboxing and/or simulations test environment to isolate and test untested or untrusted code, applications, or software without impact to the operational environment. This simulations test environment must also be used for Red Teaming and Blue Teaming Exercises.
• The Contractor must develop Independent Risk Assessment documentation and formulate into a
Security Assessment Report (SAR) (CDRL 010).
As directed by the COR, the Contractor must perform pre and post scans of requesting NAS systems. The Contractor must coordinate all scans with system owners for scheduling and technical purposes. All scans must utilize various cybersecurity tools such as, but not limited to, Nessus, WebInspect, nMAP, Tcpdump, AppDetective Pro, Metasploit, Burp Suite. A written report must be provided for each system scanned. The report must provide the results of each system scanned, scanning method used, and submitted to ACG and the system owner(s).
C.3.8 TASK 8 – INTERNATIONAL ASSESSMENTS
The Contractor must provide testing support for international assessments to include the following but not inclusive of:
20 | P a g e
• The Contractor must support Test planning and coordination. This includes developing a System Security Assessment Test Plan (CDRL 011) and participating in pre-assessment and post-assessment activities.
• Perform risk assessments of FAA IT assets residing in foreign countries and provide FAA leadership with reliable information on protecting the NAS from compromise from foreign sources. Contractor will be required to provide their findings and recommendations in a written report.
• Assess the physical location of services provide to ensure unauthorized access to telecommunications rooms, server rooms and personnel access is within FAA policy and guidelines.
• Where possible, provide Vulnerability scanning and penetration testing, interviews, and artifact gathering to identify vulnerabilities that may impact the NAS.
• Interact with telecommunications providers to determine security posture of the telecommunications provided, i.e., Ports and Protocols utilized and provide findings and recommendations on the security posture of those services.
• Assess the services through the FAA Telecommunications Infrastructure National Test Bed (FNTB) at the Tech Center prior to implementation.
• Provide an assessment of the different demarcation points for FAA data entering and exiting the NAS from a foreign entity.
• Provide an assessment of hardware and applications used by International partners and how these applications and hardware impact the security posture of the NAS.
• The Contractor must develop Independent Risk Assessment documentation and formulate into a Security Assessment Report (SAR) (CDRL 010).
C.4 DELIVERABLES
A full list of deliverables is in Section F.4.2
21 | P a g e
SECTION D - PACKAGING, MARKING, AND SHIPPING
D.1 REQUIREMENTS
The Contractor must package, mark, and ship all deliverables in accordance with Government specifications.
D.1.1 PHYSICAL DELIVERABLES
At a minimum, the Contractor must attach a cover letter to all deliverables that includes the contract number and Contractor name.
D.1.2 ELECTRONIC DELIVERABLES
Information on how to mark and submit electronic deliverables is in Section G.5, below.
22 | P a g e
SECTION E – INSPECTION AND ACCEPTANCE
E.1 AMS CLAUSES
E.1.1 CLAUSES INCORPORATED BY REFERENCE
AMS 3.1-1 - CLAUSES AND PROVISIONS INCORPORATED BY REFERENCE (JULY 2019)
This screening information request (SIR) or contract, as applicable, incorporates by reference the provisions or clauses listed below with the same force and effect as if they were given in full text. Upon request, the Contracting Officer will make the full text available, or offerors and contractors may obtain the full text via Internet at:
https://fast.faa.gov/contractclauses.cfm
The following contract clause or clauses pertinent to this section are hereby incorporated by reference:
Clause Number Date Title 3.10.4-5 Apr-96 Inspection - Time-and-Material and Labor-Hour
E.2 GENERAL
1. Inspection and acceptance will be performed at FAA site.
2. The Contracting Officer’s Representative (COR) is the Government official authorized to inspect and accept or reject deliverables.
3. The Contractor may presume that a deliverable has been accepted unless the COR rejects it in writing within 15 days of its submission.
https://fast.faa.gov/contractclauses.cfm
23 | P a g e
SECTION F – DELIVERIES OR PERFORMANCE
F.1 AMS CLAUSES
F.1.1 CLAUSES INCORPORATED BY REFERENCE
AMS 3.1-1 - CLAUSES AND PROVISIONS INCORPORATED BY REFERENCE (JULY 2019)
This screening information request (SIR) or contract, as applicable, incorporates by reference the provisions or clauses listed below with the same force and effect as if they were given in full text. Upon request, the Contracting Officer will make the full text available, or offerors and contractors may obtain the full text via Internet at:
https://fast.faa.gov/contractclauses.cfm
The following contract clause or clauses pertinent to this section are hereby incorporated by reference:
Clause Number Date Title 3.10.1-9 Oct-96 Stop-Work Order 3.10.1-24 Mar-09 Notice of Delay 3.11-34 Apr-99 F.O.B. Destination
F.1.2 CLAUSES INCORPORATED IN FULL TEXT
3.8.2-22 Substitution or Addition of Personnel (October 2006)
1. The Contractor must assign only those individuals whose resumes, personnel data, and/or personnel qualification statements have been submitted and determined by the Contracting Officer to meet the minimum requirements of the contract. The Contractor must not substitute or add personnel except in accordance with this clause.
2. Substitution of Personnel.
(a) For the first 60 days of contract performance, the Contractor must not substitute personnel for the individuals whose resumes or other personal qualification were submitted with its offer and that were determined by the Contracting Officer to be acceptable at the time of contract award, unless such substitutions are because of an individual's sudden illness, death, or termination of employment. In any of these events, the Contractor must promptly notify the Contracting Officer and propose substitute personnel as required by paragraph (4) below.
(b) If an individual becomes, for whatever reason, unavailable for work under the contract for a continuous period exceeding thirty (30) working days, or is expected to devote substantially less effort to the planned work, the Contractor must propose a substitute personnel as required by paragraph (4) below.
3. Addition of Personnel. If an FAA requirement will increase the specified level of effort for a designated labor category, but not the overall level of effort of the contract, then the Contractor must notify the Contracting Officer to add personnel to the designated labor category. The Contractor must request added personnel as required by paragraph (4) below.
4. Request and Review. The Contractor must submit the request for substitute or added personnel in writing to the Contracting Officer at least 15 days (if a security clearance must be obtained, at least 45 days) before the proposed date of substitution or addition.
This is the start of the file's text. The full file is on GovTribe.
File details come from the government source that posted it. Updated .