DHS CISA SSN Insights Program Support.pdf
PDF 161 KB Posted
- Attached to
- CISA Insights Program Support Federal contract opportunity
- Solicitation number
- PCCS-23-40003
View the file
Other files for this federal contract opportunity
| File | Type | Posted |
|---|---|---|
| DHS CISA Insights Program Updated Draft SOW - 4-21-2023.pdf | ||
| DHS CISA Insights Program Support Draft SOW.pdf |
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
SOURCES SOURCE NOTICE
Department of Homeland Security (DHS)
Cybersecurity and Infrastructure Security Agency (CISA) Insights Program Support
BACKGROUND
CISA’s mission is to lead the national effort to protect and enhance the resilience of the nation’s physical and cyber infrastructure. CISA’s vision is a secure and resilient critical infrastructure for the American people. CISA plays two key roles: the operational lead for Federal Cybersecurity, or the Federal “dot gov” and as the national coordinator for Critical Infrastructure Security and Resilience. CISA’s organizational structure includes the Cybersecurity Division (CSD), Emergency Communications Division (ECD), Infrastructure Security Division (ISD), Integrated Operations Division (IOD), Stakeholder Engagement Division (SED), and the National Risk Management Center (NRMC).
Within CSD, the VM Sub-Division’s mission is to reduce risk to the Nation by enabling stakeholders to understand and manage vulnerabilities. This mission is achieved through five main lines of effort: 1) reduce stakeholder vulnerabilities, 2) increase National resilience, 3) enable data-driven decisions, 4) influence operational behaviors, and 5) the responsible disclosure of vulnerabilities. VM’s organizational structure is comprised of the Insights Branch, Assessments Branch, Fusion Branch, Methodology Branch, and Disclosure Branch.
The Insights Branch mission is to reduce vulnerability risk and attack surface exposure through continuous data analysis to enable crucial infrastructure resiliency and stakeholder visibility into cyber threats. Insights is comprised of five sections: Cross Functional Planning and Coordination, Data Statistics and Visualization, Mitigation Insights, Risk Insights, and Performance Insights. The sections work together to implement VM’s mission by developing and disseminating analytic content to stakeholders that enable data-driven decisions and influence operational behaviors to reduce the attack surface and enhance cyber resiliency.
SUBMISSION DETAILS
North America Industry Classification Systems (NAICS) 541611 Administrative Management and General Management Consulting Service; Small Business Size Standard $24.5M
Product Service Code (PSC) R405 Support – Professional: Operations Research/Quantitative Analysis
Note: In accordance with DHS Directive 060-01, Development and Use of Strategic Sourcing Contract Vehicles, dated 24 August 2012, strategic sourcing vehicles are mandatory for use, with limited exceptions. Therefore, a strategically sourced contract vehicle will take priority over awarding a standalone CISA contract.
Submit electronic responses to: hannah.moussa@cisa.dhs.gov, nathalie.snyder@cisa.dhs.gov, and justice.harvey@cisa.dhs.gov by or before 12:00 p.m. Eastern Standard Time (EST), March 15, 2023. The subject line of the email should read, “Insight Program Support.”
Industry input is also requested on the draft attached SOW. Questions and/or feedback related to the draft SOW must be submitted as a separate document.
Responses must have a cover page containing the following information:
a) Contractor Name and Facility Address (list all relevant or significant office locations)
b) Point of Contact Information including contact name, telephone number and email
c) SAM Unique Entity Identification (UEI) number
d) Socio-Economic Status
e) Current Facility Clearance Level
f) Website URL
Interested parties should submit a capability statement in either Microsoft Word or Adobe pdf, limited to five (5) pages; 8.5 x 11-inch pages, no less than font size 10.
Provide responses to the following questions:
1. List any existing Government contract vehicle (Governmentwide Acquisition Contract (GWAC), Multiple Award Schedule (MAS) program, Blanket Purchase Agreement (BPA), etc.) your company currently holds to provide the services described in the Draft Statement of Work (SOW).
2. Does your company have experience providing program management and analytic risk advice product development expertise across a cross-functional team that supports operational and strategic cybersecurity work streams? Please describe your company’s capabilities and experience in this area.
3. Does your company have experience analyzing all-source data to generate analytic outputs for vulnerability and risk intelligence reports with expertise and technical capability across data integration, analytic planning and innovation, operational support, product support, and analytical development? What methodology(ies) has your company used to develop intelligence products? What tools and technologies does your company have experience using to conduct these activities? Please describe your company’s capabilities and experience in this area.
4. Does your company have experience drawing insights from proactive vulnerability hunting (identification of vulnerabilities) among defined stakeholder attack surfaces (ecosystems) that may significantly impact a US critical infrastructure sector or national critical function if targeted and compromised? Does your company have experience producing vulnerability and risk intelligence that apprises stakeholders of active and strategic national cybersecurity vulnerability concerns and spur action to reduce risk? What tools and technologies does your company have experience using to conduct these activities? Please describe your company’s capabilities and experience in this area.
mailto:hannah.moussa@cisa.dhs.gov mailto:nathalie.snyder@cisa.dhs.gov mailto:justice.harvey@cisa.dhs.gov
5. Does your company have experience providing tailored risk reduction mitigation strategies for stakeholders, along with experience identifying, acquiring, and verifying data requirements to achieve increased attack surface visibility? Please describe your company’s capabilities and experience in this area.
6. Does your company have experience providing a performance measurement and effectiveness capability across many Lines of Effort (LOE), including but not limited to products and services, legislative actions, organizational planning, implementation of strategic and operational objectives, and mission surge events? Please describe your company’s capabilities and experience in this area.
7. Does your company have experience defining and maintaining project quality throughout a process to include but not limited to: creating project standards, procedures, processes, reporting templates, strategic plans, knowledge management and using metrics to measure progress? Please describe your company’s capabilities and experience in this area.
8. What are any best practices, efficiencies and/or lessons learned based on your experience that you feel are important and applicable to the requirement?
File details come from the government source that posted it. Updated .