DRAFT Attachment 1 NCCS SOW.pdf
PDF 711 KB Posted
- Attached to
- DHS Network Operations Security Center (NOSC) Network, Cloud, and Cyber Services (NCCS) 2. 0 Federal contract opportunity
- Solicitation number
- 70RTAC26R00000007
About this file
This is a Statement of Work (SOW) for the DHS Network Operations Security Center (NOSC) Network, Cloud, and Cyber Services (NCCS) 2.0 contract, dated September 16, 2026 (Version 1.3).
The contract procures comprehensive cybersecurity, network operations, management, and professional support services for DHS Headquarters and select DHS Components. The contractor must provide 24x7x365 monitoring and analysis of network infrastructure, cloud platforms, systems, applications, and cybersecurity events across the DHS enterprise, including the OneNet WAN and select LAN networks spanning multiple classification levels from unclassified through Top Secret/SCI/SAP. Core services include Tier 1 and Tier 2 operational staffing for network operations, cloud platform support, and cybersecurity monitoring; incident management and response; log management and analysis; vulnerability assessments; threat hunting; penetration testing; cyber forensics and malware analysis; email security; threat intelligence; intrusion defense; evidence management; and security control assessments. The contractor must establish a Program Management Office to continuously improve NOSC capabilities using ITIL v4, CMMI for Services, NIST Cybersecurity Framework, and DHS Systems Engineering Lifecycle standards. Additional responsibilities include maintaining a knowledge management repository, developing policies and SOPs, managing service catalogs, communications strategy, project management support, continuous service improvement programs, performance metrics, capability testing and training, data call fulfillment, CSP Program support, vulnerability management, and Zero Trust implementation assistance. Field engineering support must be provided regionally throughout the Continental United States. The period of performance consists of one 12-month Base Period and four optional 12-month ordering periods. Work locations include DHS facilities in the Washington DC metropolitan area, Stennis Mississippi, Chandler Arizona, and other CONUS sites designated in task orders. The contract is structured as an IDIQ vehicle with task orders to be issued for specific DHS components and operational requirements. All contractor personnel must maintain appropriate security clearances (up to TS/SCI/SAP), comply with DHS security policies and procedures, and undergo background investigations. Key personnel include a Program Manager (requiring 10 years cybersecurity management experience with PMP and CISSP certifications) and Deputy Program Manager (5 years experience with CISSP certification).
View the file
Other files for this federal contract opportunity
| File | Type | Posted |
|---|---|---|
| DRAFT Attachment 4 NCCS Reading Room Instructions.docx | DOCX document | |
| Draft Attachment 3 NCCS Labor Category Descriptions.xlsx | XLSX spreadsheet | |
| Draft NCCS RFP Questions from Vendors.xlsx | XLSX spreadsheet | |
| DRAFT Attachment 2_NCCS Pricing Template 07152026 Draft (002) (003).xlsx | XLSX spreadsheet | |
| DRAFT NCCS RFP_9-16-2026.docx | DOCX document |
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
i
DHS Network Operations Security Center (NOSC) Network, Cloud, and Cyber Services (NCCS) 2.0 Statement of Work (SOW)
September 16, 2026
Version 1.3 i
Record of Changes
No. Date Reference A=Add
M=Modify D=Delete
Description of Change
1.0 1/16/2026 A Draft
1.1 2/10/2026 A, M Modify HSEN to OneNet
1.2 2/20/2026 M Added paragraph to Purpose Modify Place of Performance
1.3 8/19/2026 A Updated sections to include additions for component use.
Introduction The Department of Homeland Security (DHS) Office of the Chief Information Officer (OCIO) provides network, cloud/platform and system, and cybersecurity management services for the DHS Enterprise through the DHS Headquarters Network Operations and Service Center (NOSC) working in conjunction with the DHS Components. The NOSC serves as the central Information Technology (IT) service management monitoring and communications hub for network infrastructure, cloud platforms and systems, and cybersecurity (“cyber”) incidents and event management and coordination across the broader DHS information enterprise, including coordination with all DHS Components. The NOSC detects and identifies network service outages and cybersecurity threats and incidents and coordinates additional services and functions.
DHS intends to continue to evolve its NOSC operational model and its constituent sub-capability elements— doctrine, policy, and procedure; organization and planning; test, training, and exercise; material (including technology and systems); leadership; personnel; facilities; and regulations and standards—in order to ensure, assure, and improve the confidentiality, integrity, availability, privacy, access to, accountability, authentication, authorization, and non-repudiation of the DHS information enterprise.
Within those parameters of cyber and information security, the identification and detection of threats and risks to respond to, and the recovery of network infrastructure, cloud platform, and system and applications that comprise the DHS Headquarters (HQ) information enterprise from malicious actors or compromise is the central and necessary purpose of the DHS HQ NOSC and DHS component Network Operations Center/Security Operations Centers (NOC/SOCs). The evolution and continuous improvement of these capabilities and the capability elements must be performed in concert with an ever-increasing and rapidly evolving set file of requirements, including emerging requirements such as Zero Trust and expanded log file management and reporting requirements for cyber events.
Background The DHS information enterprise core infrastructure includes data centers, colocation facilities, and commercial, private cloud, and Gov-cloud resources interconnected by the Homeland Security OneNet wide area network (WAN). The OneNet WAN environment is supported by the DHS OneNet Hybrid Computing Environment (HCE), which includes on- premises infrastructure, network, compute, storage, and application support from DHS Data Center 1 (DC1) as well as multiple DHS Cloud Access Points (DCAPs) that leverage public cloud infrastructure for provisioning public cloud (i.e., Amazon Web Services (AWS); Microsoft Azure) support.
DHS is comprised of Headquarters and various Components, Offices, and Directorates. Each Component has unique and separate mission requirements and operates in a specific mission space; all are supported by a common unclassified, general purpose local area network (LAN) for data transport, the A-LAN, that comprises the largest portion of the larger OneNet. Some operational Components and/or mission-specific Offices (e.g., Office of the Inspector General, the St. Elizabeth’s Campus, etc.) also operate component or location-specific networks or enclaves that are supported by the broader OneNet and A-LAN networks. The data traversing this network is typically considered Sensitive but Unclassified (SBU) or Controlled Unclassified Information ( CUI).
Additional networks supporting HQ and comprising OneNet include: “B-LAN” (also known as Homeland Secure Data Network (HSDN)) at the secret classification level; and “C-LAN” which supports top secret classified data processing via the Joint Worldwide Intelligence Communications System (JWICS); and “D- LAN”, which supports information processing for Special Access Programs (SAP). SAP requirements are included in this Statement of Work (SOW) because the Network Operations and Security Center (NOSC) provides support for an SAP program.
Purpose and Objectives The purpose of this Contract is to procure the full range of cybersecurity, network operations, management, and other professional support services described herein for the DHS HQ OCIO and select DHS Components. These services will enable DHS to provide network, cloud platform, system, application, and cybersecurity monitoring and analysis, incident management and coordination, and alert and notification functions in support of the broader DHS information enterprise and to provide other related cybersecurity services.
The primary objective of this Contract is to evolve the DHS HQ NOSC to build a best-in-class service entity that meets DHS Cybersecurity Provider (CSP) Program, industrial, and other doctrinal Center of Excellence service maturity standards. The secondary objective is to redefine the DHS HQ NOSC as the central hub of IT Service Management—for network infrastructure (WAN and select LAN); platform (including cloud), system, and application; and cybersecurity—monitoring and analysis, event and incident management, and incident response and recovery for the DHS OneNet at all information processing and classification levels – open source, SBU and CUI, Classified (Secret and Top Secret), Sensitive Compartmented Information, and Special Access Program information.
This contract is primarily intended to provide operational staffing for Tier 1 and Tier 2 network, cloud, and cybersecurity services in support of the DHS NOSC. Higher‑tier (Tier 3) engineering, architecture, and subject matter expert functions will generally remain Government‑led, except where this Statement of Work (SOW) explicitly identifies specific Tier 3 support requirements in defined task areas or individual Task Orders.
Network infrastructure monitoring and analysis and event and incident management and response services are comprised of, but not limited to, pro-active and reactive monitoring of all network infrastructure comprising the OneNet WAN and all DHS HQ / Management Directorate LANs, including the up/down status of all circuits as well as edge infrastructure devices and boundary points for both HQ and DHS components.
Cloud, platform, system, application monitoring and analysis and event and incident management and response services are similarly comprised of, but not limited to, pro-active and reactive monitoring of all tenant cloud, platform, FISMA system, and other applications.
Cybersecurity services include but are not limited to the following general class of cybersecurity capabilities and functions: monitoring and analysis (M&A) support, log management support, incident handling and incident response support, asset visibility and monitoring, email security, cyber threat intelligence (CTI) support, intrusion defense, threat hunting; cyber forensics and malware analysis (CFMA), evidence management and insider threat support, cybersecurity maturity analytic testing (blue, purple, and red teaming), and penetration testing. Additional cybersecurity services such as DHS CSP component Network Operations Center (NOC) / Security Operations Center (SOC) audits, the Information Security Vulnerability Management Program, Security Control Assessment Support, and reporting on Federal Information Security Modernization Act (FISMA) metrics are also included.
All of this work—network infrastructure; cloud, platform, system, and application; and cybersecurity monitoring and analysis and event and incident management and response— includes coordination with other internal and external entities and vendors to coordinate service degradation/outage triage and root cause analysis; service restoration coordination, including some Tier 3 engineering and operations and maintenance activities for select edge devices; and end-to-end communication and coordination leveraging various technologies and communications methods.
This scope of work also includes the establishment of a Program Management Office (PMO) to baseline, evaluate, and continuously improve all capability elements (doctrine and policy, organization and planning, test, training, and exercise, systems, leadership, personnel, facilities, and regulations and standards) of the DHS NOSC over time in accordance with industry standards and best practices, to include the Information Technology Infrastructure Library (ITIL) v4; the Capability Maturity Model Institute (CMMI) for Services; the Software Engineering Institute’s CERT Resilience Management Model; the National Institute of Standards and Technology (NIST) Cybersecurity Framework (CSF); other NIST guidance (including NIST SP 800-53 Rev. 5), International Standards Organization / International Electrotechnical Commission (ISO/IEC) standards; and U.S. law and policy.
Note: U.S. policy includes Executive Orders, and other relevant U.S. government Federal Civilian Executive Branch (FCEB) regulations and standards, including Office of Management and Budget (OMB), Government Accountability Office (GAO), DHS, and DHS Cybersecurity and Infrastructure Security Agency (CISA) directives and standards (including, e.g., OMB M- 26-14; CISA BOD 22-01; and FCEB, OMB, and DHS Zero Trust guidance).
In summary, the service provider shall be responsible for identifying, protecting against, detecting, responding to, and recovering from any malicious or disruptive Information Technology events and incidents, and ensuring that DHS OCIO is able to rapidly respond to circumstances that threaten DHS’s information enterprise and contributing to the increasing resilience of DHS OneNet and its evolving network infrastructure for an expanding user and subscriber base.
Tasks Task 1: Contract Management Contract Management facilitates all services and operations management functions for the contract. It involves the development, implementation, and administration of the Contractor’s support services. The contractor shall provide program management oversight, reporting and other general contract management services needed to achieve the cost, schedule, performance, quality, and communication goals under the contract.
1.1 Program Management Services
Program Management Services include the following tasks:
1) Plan, organize, structure, and execute management of integrated IT services, projects, and deliverables under this contract
2) Meet with and assist OCIO (and/or DHS Component) management staff to determine and apply industry best practices (including ITIL v4, CMMI for Services, and NIST CSF) to existing business operations and potential future operational improvements
3) Provide cost and budget management, billing/invoicing services, Rough Order of Magnitude (ROM) responses for buildouts, projects, deployments, and special activities (i.e., conference support)
4) Ensure continued service delivery in accordance with the service level requirements, regardless of changing or fluctuating workload or personnel availability
5) Improve processes by facilitating performance planning and alignment
6) Drive business and operational process standardization
7) Document business and service operations processes, including reporting
8) Provide all contractor staffing support including the Entry on Duty (EOD) process ensuring sufficient cleared staff (unclassified through top secret access) are available to meet operational demands
9) Provide management oversight of all activities performed by Contractor personnel, including the effective use of subcontractors to satisfy the objectives and service level requirements identified at the order level
10) Develop, implement, and continuously improve all business functions required for contract implementation, including: a Service and Performance Management Program, Records Management Program, and a Communications Management Program.
11) Manage and maintain contract service catalog
1.2 Transition Planning and Management
The Contractor shall ensure that the transition of operational support services from predecessor contractors to successor contractors shall occur without disruption of DHS operations and service delivery and with full cooperation between incoming and outgoing contractors.
The Contractor shall plan and manage the process of assuming operational responsibility from outgoing incumbent contractor(s) and for the eventual hand-off of operational responsibility to a successor contractor or the Government. The Contractor shall generate a Transition-In Plan for assuming responsibility and a Transition-Out plan for handing over operations to a successor contractor at contract end.
1.3 Business Continuity and Disaster Planning
The Contractor shall develop a Business Continuity Plan that includes critical information needed to continue operations during an unplanned event. The plan shall state essential functions and systems and processes that must be sustained; and details on how to maintain them.
The Contractor shall develop a Disaster Recovery Plan to include a process for resuming normal business operations and reconstructing or salvaging vital and other important records and equipment. This plan will be a guide for all managers and employees during and after a disaster.
Task 2: Capability Delivery and Improvement The Contractor shall support the design, development, staffing, management, implementation, and continuous improvement of a PMO or similar structure (e.g., Center of Excellence) to define, measure, manage, and continuously improve and optimize IT service management and cybersecurity capabilities and services in accordance with ITIL v4, CMMI for Services, NIST CSF, DHS Systems Engineering Lifecycle (SELC), and other best practices relevant to the capabilities and services being delivered. This service management function shall be in support of developing all capability elements (doctrine, planning, and governance, organization, training, systems, tools, and technologies, leadership, personnel, facilities, regulations, and standards) that comprise DHS information enterprise network, cloud/platform/system/application, and cybersecurity services.
Specifically regarding ITIL and the NIST CSF, the contractor shall be responsible for aligning all services and business processes under this contract to the 34 business practices identified in ITIL v4 and managing all of these practices and sub-processes for the NOSC as well as aligning these to the functions, categories, and sub-categories defined by the NIST CSF.
In conjunction with NIST SP 800-53 Rev. 5, DHS 4300A/B, and the ITIL v4 service catalogue and service financial management practices, the contractor shall be responsible for proposing, documenting, baselining, and managing a NOSC service catalogue and common control catalogue that provides tiered service support models to potential subscribers with tailored security control levels for the FISMA system owner use at differing service levels and costs.
2.1 Knowledge Management
The Contractor shall maintain a Knowledge Management repository and ensure that the repository contents are complete and current, and that new content is added to the repository as it is created.
The Contractor shall ensure that the Knowledge Management repository exists and resides on DHS-approved systems and infrastructure accessible by all DHS Components. The repository shall provide organized storage and access to the most current as well as historical cybersecurity and network operations policies, procedures, processes, and other documentation.
Content of the Knowledge Management repository shall include all contract deliverables, operational reports, analyses, technical diagrams, as-designed and as-build diagrams, architecture specifications, policies, procedures, and other current operational information artifacts.
2.2 Doctrine, Policy, Planning, and Standard Operating Procedures Development Support The Contractor shall provide policy support, including recommendations and guidance as needed, for the continuing evolution of DHS Policy Directive 4300A, Information Technology System Security Program, Sensitive Systems, DHS Policy Directive 4300B, and any other network resilience and cybersecurity policy program requirements across OCIO (and within select DHS components).
The Contractor shall assist with policy creation, policy implementation planning, and the development of any and all policy, planning, and procedural documents to include briefings, trainings, and Standard Operating Procedures (SOPs) needed to finalize and promulgate policy and doctrine across the enterprise.
The Contractor shall create, update, and maintain standard operating procedures such that those procedures maintain consistency with Policy Directive 4300A.
2.3 Service Catalog, Relationship and Service Management Practices The Contractor shall develop, manage, and implement the NOSC’s IT Service Catalog listing the services provided by the NOSC and/or Component NOC/SOC.
The Contractor shall manage relationships with NOSC subscribers and customer organizations, including coordinating with the NOSC, subscriber program offices, and the budget offices for all subscribers in accordance with NOSC’s IT Service Catalog and the DHS Cybersecurity Program requirements.
The Contractor shall support and interface with all annual budget, finance, and acquisition processes (including Planning, Programming, Budgeting, and Execution and Capital Program Investment Committee processes).
2.4 Communications Support
The Contractor shall develop and tailor a Communications Plan to achieve the operational objectives and to improve operational outcomes.
The Contractor shall design, develop, and continuously improve a NOSC Communications Strategy, to include strategic, operational, and tactical communications and outreach.
The Contractor shall ensure that communications with DHS Stakeholders including OCIO Management, Component Management, Component NOCs and SOCs, programs, Subscribers, and other entities inside and outside of DHS are maintained to keep all interested parties apprised of the current operational status and the status of progress in restoring disrupted service and recovering from cybersecurity attacks.
2.5 Project Management Support
The Contractor shall manage and execute projects using agile approaches, methodologies, and best practices to implement and enhance key capabilities and services quickly and efficiently.
2.6 Continuous Service Improvement Program (CSIP)
The Contractor shall identify and implement Service performance improvements in the context of a Continuous Service Improvement Program (CSIP).
The Contractor shall implement a program of periodic performance measurement to track maturity development and increases in operational efficiency.
The Contractor shall propose a set of measures for measuring the overall maturity of operations and develop a baseline assessment of the maturity of DHS NOSC or component NOC/SOC operations based on approved measures. The Contractor shall design a performance measurement process based on the approved set of performance measures and assess the maturity of performance based on those measures on a semi-annual basis.
The Contractor shall recommend operational improvements to maximize the efficiency and productivity of personnel working at each level in the Tier 1 through Tier 3 structure. The
Contractor shall identify and recommend innovations in the application of automation that will reduce the amount of low-threat network traffic requiring personal attention and reduce unnecessary escalations to higher Tiers.
The Contractor shall identify and recommend improvements in techniques and procedures and/or use of agentic AI, that improve the ability of personnel at each Tier level to resolve issues freeing personnel at higher levels to focus more on high-value analysis enabling the DHS NOSC to detect and deflect threats rather than having to engage in incident response.
The Contractor shall develop and continuously improve NOSC doctrine (including policies, processes, and procedures) and documentation, including (but not limited to) a NOSC IT Service Management Process Register, NOSC Process Map, NOSC Service Catalog (including financial support models), Common Controls Catalog, and NOSC CSIP Implementation Plan.
The Contractor shall define and manage all NOSC business processes consistent with ITIL v4, CMMI for Services, NIST CSF, DHS CSP, and other DHS regulations and standards.
The Contractor shall ensure that NOSC structure and organization (as laid out in the NOSC Concept of Operations (CONOPS) and NOSC Operations Plan) evolves annually to lead to improved IT service management business process outcomes.
The Contractor shall design and execute the program in accordance with Homeland Security Exercise Evaluation Program (HSEEP) principles and standards.
2.7 Performance and Investment Metrics
The Contractor shall propose, design, and implement a performance and investment metrics measurement process. The Contractor shall propose metrics for measuring performance and monitor those metrics across performance periods to identify areas where improvement is required. The Contractor shall implement analytical processes that project the results of proposed changes.
The Contractor shall design and implement a performance metrics pilot project and deliver a Performance Metrics Pilot Plan to demonstrate the feasibility and value of proposed metrics, measurement processes, and analyses. The Contractor shall also develop Program Deployment Plan to implement the overall performance metrics plan.
2.8 Capability Test, Training, and Exercise
The Contractor shall implement a Capability Test, Training, and Exercise (TT&E) Program (including continuous improvement program) that is chartered, designed, staffed, and managed to evaluate and continuously improve the DHS NOSC, Chief Information Security Officer Directorate (CISOD), and partner organization capabilities and coordination. The Contractor shall establish and monitor a training program to develop and maintain skill levels among all staff in cybersecurity, network management, and software tools used in service delivery.
Software tools training shall include training in the use and administration of vulnerability assessment tools, penetration testing tools, and incident tracking tools.
This test, training, and exercise program shall be in support of both OCIO operational personnel (NOSC Federal and contract employees) as well as executives, end-users, implementers, and other roles required to implement full lifecycle IT service management.
2.9 Data Call and Data Acquisition Support
The Contractor shall acknowledge and fulfill data requests (data calls) regardless of origin.
Sources may include DHS Headquarters Offices and Directorates; DHS Management; DHS Components; and other non-DHS customers to include Freedom of Information Act (FOIA), Office of Inspector General (OIG), Office of General Counsel (OGC), Congress, and Federal, State, and Local law enforcement agencies.
The Contractor shall utilize standard (e.g., Microsoft Office) and other IT applications for data manipulation. The Contractor shall recommend use cases for agentic AI to automate recurring data calls.
The Contractor shall provide the Government with regular status updates for their requests and inform customers and CIO and OGC management of any outages or disruptions in service that could negatively affect resolution time of data acquisition requests.
2.10 Cybersecurity Services Provider Program
The Contractor shall ensure that the NOSC operations continuously increase maturity as assessed by the maturity levels described for individual metrics in the CSP Evaluator Scoring Metrics.
The Contractor shall ensure that the NOSC maintains continuous Cybersecurity Services CSP Program Center of Excellence (COE) accreditation for providing both NOC and SOC services.
The Contractor shall ensure that the NOSC complies with changes to the CSP Evaluator Scoring Metrics as those changes are promulgated by CISOD and is prepared for the next re-accreditation assessment under the changed CSP metrics.
The Contractor shall develop, maintain, and enhance SOPs such that those SOPs satisfy requirements for NOSC re-accreditation as a COE under the CSP Program Evaluator Scoring Metrics in force at the time of re-accreditation.
The Contractor shall conduct preparatory assessments of the NOSC and each Subscriber to NOSC services in preparation for NOSC re-accreditation to ensure that the NOSC and its Subscribers qualify for re-accreditation.
Task 3: Network, Cloud, and Cybersecurity Monitoring and Analysis, Event and Incident Management and Response, and Associated Support Services The Contractor shall be responsible for planning, organizing, developing, managing, implementing, and continuously improving all network, cloud/platform and system/application, and core cybersecurity M&A and event and incident management (including alert and notification and event remediation) services in accordance with ITIL v4, CMMI for Services, the NIST CSF, the DHS SELC, DHS CSP, and FCEB and DHS requirements.
3.1 M&A and Incident Response
The Contractor shall monitor the DHS information enterprise—including all of OneNet and constituent WAN entities and select HQ and component LAN and circuit infrastructures—for network, cloud, platform, system and application, and cybersecurity events 24x7x365 to pro-actively identify threats, risks, outages, and service degradations.
The Contractor shall ensure that the DHS NOSC demonstrates seamless continuity across network infrastructure, cloud platform, system and application, and cybersecurity monitoring and analysis and incident coordination and response workloads across multiple NOSC locations and geographically distributed teams.
The Contractor shall monitor the NOSC scope including Trusted Internet Connections (TICs) to the Internet, OneNet circuits, Points of Presence or Policy Enforcement Points where HQ and Component networks connect to the OneNet, and Subscriber systems and networks.
The Contractor shall provide immediate, real-time monitoring of DHS systems and networks belonging to DHS, cloud service providers, and contractors 24x7x365.
The Contractor shall initiate response to events that negatively affect service delivery. The Contractor shall respond immediately to all network and any potential cyber incidents.
The Contractor shall support a typical ITIL-based Service Desk structure (organized from Tier 0 to Tier 4), including all Tier 0, Tier 1, and Tier 2 functions, and select Tier 3 functions. With some variations, a typical IT service desk is organized in such manner where: Tier 0 is user self-help (including, in this instance, interactive portals for user reporting of events and incidents);
Tier 1 is basic event/incident triage, classification, and ticketing, and immediate IT service restoration if possible; Tier 2 is in-depth technical support for most technical issue types; Tier 3 is subject matter expert service and product support, including trouble-shooting for advanced network service degradation issues; and Tier 4 is external vendor support.
The Contractor shall support a typical ITIL-based Service Desk structure (organized from Tier 0 to Tier 4) and shall:
• Provide full operational coverage for Tier 0, Tier 1, and Tier 2 functions, including user self-help, initial triage and classification, ticketing, and in-depth technical support for most incident types; and
• Provide only those Tier 3 functions that are expressly identified in this SOW or in individual Task Orders.
All other Tier 3 and Tier 4 activities, including strategic architecture, major design changes, and enterprise-level engineering, will remain the responsibility of DHS or other designated providers.
The Contractor shall ensure that incidents are escalated from Tier 1 to Tier 2, and from Tier 2 to designated Tier 3 resources, in accordance with established NOSC procedures and service level requirements.
The Contractor shall escalate events and incidents that cannot be resolved at Tier 1 to Tier 2 for the more advanced technical expertise required for resolution is available.
The Contractor shall ensure that unresolved networking and cybersecurity incidents are escalated from Tier 1 to Tier 2 according to established protocols.
The Contractor shall escalate to Tier 2 network management, cloud, and cybersecurity issues that cannot be resolved by Tier 1 analysts within the time limit stipulated by NOSC management for Tier 1 action. The Contractor shall provide Tier 2 response for escalated incidents and continue and expand response activities initiated by Tier 1.
The Contractor shall provide Tier 2 levels of effort and technical expertise beyond those available at Tier 1 as required for incident response, resolution, and recovery.
The Contractor shall track and report all network component failures and escalations from Tier 1 to Tier 2 continuously to resolution and restoration of service. Contractor response shall be measured and compared to established service level agreements.
The contractor shall provide only those Tier 3 functions that are expressly identified in this SOW or in individual Task Orders.
3.2 Network Operations Services
The Contractor shall monitor and manage DHS Networks 24x7x365 including monitoring network availability and troubleshooting and resolving network outage incidents.
The Contractor shall monitor network traffic, utilization, and trends to characterize network traffic volume, bottlenecks, and points of failure.
The Contractor shall analyze findings to ensure that sufficient bandwidth capacity is planned and implemented to ensure network infrastructure to accommodate current and forecasted customer traffic.
The Contractor shall coordinate, manage, and report on all access, asset and configuration, availability, capacity, change, demand, information security, IT service continuity, release and deployment, request fulfilment, service level, and service validation and testing processes.
3.3 Cloud, Platform, and System Operations Services
The Contractor shall manage, optimize, and troubleshoot issues for DHS’s cloud compute, storage, and application hosting platforms, and for all other platforms, systems, and applications that comprise the OneNet, including troubleshooting of connectivity, latency, degraded performance, or unavailability issues.
The Contractor shall monitor and analyze cloud computing statistics and systems using Cloud Service Provider statistical feeds (e.g., Amazon Web Services; Microsoft Azure) and monitoring tool alert captures (e.g., Dynatrace) to determine possible points of failure and work with both IT Operations Cloud Computing Tier 2 Team, OCIO Solution Development Directorate (SDD) Cloud Tier 3 Teams, and stakeholders, and recommend modifications to cloud-based environments and configurations to avoid or remediate unscheduled outages.
3.4 Core Cybersecurity Services
3.4.1 Log Management and Analysis
The Contractor shall provide log file analysis to identify attack vectors used, targets of attacks, incident root causes, impacts to subscriber networks, and trends.
The Contractor shall process incoming log files by the NOSC Security Information and Event Management (SIEM) application upon receipt. The Contractor shall receive and store incoming log files for time periods established for log file analysis.
The Contractor shall ensure that all required logs that feed into the NOSC SIEM (and other file repositories) are active 24x7x365 and devise and implement solutions to ensure immediate escalation to Tier 3 Security Engineering upon any log feed outage.
The Contractor shall archive stored log files when reaching prescribed age thresholds. The Contractor shall retrieve archived log files for analysis within a prescribed retrieval timeframe.
3.4.1 Email Security
The Contractor shall identify the scope of infections resulting from email containing malicious content, notify affected users, and coordinate recovery across DHS.
The Contractor shall redirect incoming email messages exhibiting characteristics of malicious content, spam, or other undesirable incoming traffic to designated mailboxes and quarantine.
The Contractor shall evaluate suspicious email messages and analyze malicious payloads.
The Contractor shall block email addresses responsible for messages exhibiting characteristics of malicious content, spam, phishing, or other undesirable incoming traffic.
3.4.2 Cybersecurity Threat Intelligence
The Contractor shall collect information on emerging cyber threats at different classification levels from Internet security firms, Government organizations, private industry, and foreign Governments, and assess, evaluate, and use to develop cyber defense measures.
The Contractor shall identify strategic risks through working with Security Control Assessors (Information System Security Managers (ISSMs), Information System Security Officers (ISSOs), system owners, and other applicable teams to collect data contributing to the full picture of strategic cyber risks facing DHS.
The Contractor shall identify Tactical cybersecurity risks in concert with SOCs, other CTI teams, vulnerability assessment teams (VATs), and other applicable teams to create a full picture of risks facing DHS.
The Contractor shall determine the intentions of adversary groups to conduct computer network exploitation (CNE) and computer network attacks (CNA) against U.S. private sector and Government networks and information systems.
The Contractor shall identify common gaps in information system security using methods such as the MITRE Adversarial Tactics, Techniques, and Common Knowledge® (ATT&CK®) framework to focus recommendations to the Government for funding in support of remediating security gaps for multiple systems.
The Contractor shall distribute cyber threat information across DHS to provide situational awareness to DHS SOCs, NOCs, and enterprise level decision makers.
3.4.3 Vulnerability Assessments
The Contractor shall conduct Vulnerability Assessment scans for Headquarters and Subscriber systems and networks to identify potential computer security vulnerabilities, risks, and threats.
The Contractor shall conduct, operate, and maintain assessments and the resulting Vulnerability Assessment data and reports.
The Contractor shall support the NOSC enclave, OneNet, and Redundant TICs through the conduct of scheduled and ad-hoc vulnerability assessment scanning. Scanning shall include:
• Host-based and vulnerability assessments
• Network vulnerability assessments
• Database vulnerability assessments
• Web-based vulnerability assessments
• Cloud-based vulnerability assessments The Contractor shall employ ad-hoc or emergency vulnerability scanning to support targeted incident investigation, escalation, and emergency response to security events in accordance with documented procedures.
The Contractor shall coordinate with Component security staff to explain findings, provide recommendations on mitigations, and advocate for mitigation of vulnerabilities.
3.4.5 Attack Sensing and Warning
The Contractor shall detect and identify advanced, persistent, and coordinated cybersecurity threats across multiple networks. The Contractor shall detect threats characterized by distributed, long term, coordinated, low visibility network-based attacks and develop and implement courses of action to remediate or mitigate those threats.
The Contractor shall correlate threat intelligence with hardware and software assets potentially impacted by those threats. The Contractor shall assess the potential resulting impacts to operations and shall communicate threats, countermeasures, and courses of action across DHS to Components and subscribers for implementation.
3.4.6 Content Development
The Contractor shall analyze data feeds and event logs, and correlate the results with known threats, vulnerabilities, and incidents to create new security content and updates to Enterprise NOSC dashboards.
The Contractor shall develop, disseminate, and implement new security content such as Intrusion Detection Systems (IDS), Intrusion Prevention Systems (IPS), Data Loss Prevention (DLP) correlation rules and cyber threat indicators.
3.4.7 Threat Hunting
The Contractor shall manage all aspects of the cyber-Threat Hunt lifecycle, including creation and improvement of enterprise-specific Threat Models and threat hypotheses, plan and scope Threat Hunt campaigns, missions, and activities against a variety of threat types and identify enterprise defense gaps and propose potential mitigation activities.
The Contractor shall perform cyber-Threat Hunt missions by identifying and investigating patterns and anomalies in data, suspicious network activities, including access from Outside the Continental United States (OCONUS) or utilization of non-standard credentials, anomalous or suspicious telemetry, and other Cyber Threat Intelligence.
The Contractor shall proactively search networks to detect and isolate advanced cybersecurity threats that evade in-place security solutions.
The Contractor shall regularly perform advanced analysis and adversary hunting activities to proactively uncover evidence of adversary presence on DHS networks.
The Contractor shall follow incident response procedures for detected insider threat activity.
3.4.7 Cyber Forensics and Malware Analysis Support
The Contractor shall analyze digital media devices and media to identify, reverse engineer, and de-obfuscate malware and other content causing cybersecurity incidents.
The Contractor shall operate cyber forensics and malware analysis laboratory facilities that are accessible and available where malware can be identified, analyzed, and reverse engineered. All such facilities shall be isolated from DHS networks to ensure that malware threats under investigation pose no potential threat to the DHS Enterprise.
3.4.8 Penetration Testing
The Contractor shall conduct High Value Asset (HVA) assessments and penetration tests and conduct or assist with penetration tests as requested by Components, System Owners, Information System Security Managers, or Information System Security Officers in support of Security Controls Assessments, continuous monitoring, and FISMA requirements.
The Contractor shall provide penetration testing summary reports, in accordance with the signed Rules of Engagement (ROE) document, to the appropriate System Owner/ISSM/ISSO, Government lead, DHS Program Manager and document the findings.
The Contractor shall prepare and submit security testing Rules or Engagement (ROE) for High Value Assets (HVA), Internal & External Threat Assessments, prior to conducting penetration testing and ensure that the ROE provides the operational security controls to protect both the system and network.
3.4.8 SOC Maturity Analytic Testing Program – Blue, Purple, and Red Teaming and Adversary Emulation The Contractor shall develop an analytic testing program to assess the NOSC’s cybersecurity capabilities via the use of blue, purple, and red teams. This program shall include the design, development, and execution of table-top exercises and authorized tests (i.e., Red Teaming) that emulate a potential adversary’s attack or exploitation capabilities against the DHS enterprise’s security posture. The Contractor shall also conduct or participate in exercises defending against real or simulated attacks (i.e., Blue Teaming) launched by mock attackers (i.e., Red Teams). The Contractor shall also engage in Purple Team table-top and actual tests conducted jointly by mock network attackers (Red Teams) and network defenders (Blue Teams). The Contractor shall support teaming exercises with ad-hoc Vulnerability Assessments.
3.4.9 Evidence Management
The Contractor shall preserve information and data encountered in the course of incident response and recovery efforts or in the course of malware analysis for law enforcement purposes.
The Contractor shall follow proper chain of custody, storage, handling, and transmission procedures for various evidence categories including but not limited to SBU, For Official Use Only (FOUO), Law Enforcement Sensitive (LES), Confidential, Secret, Top Secret and Top Secret/Sensitive Compartmented Information (TS/SCI).
3.4.10 Cloud Security
The Contractor shall conduct real-time (when possible, based on tools) monitoring and triaging of security alerts from SIEM, System, Network Appliance (Firewalls, IDS, etc.), Cloud Service (AWS, Azure, IBM, etc.), email (Microsoft Office 365,), and Endpoint (including Endpoint Detection and Response Solutions (EDR)) systems.
The Contractor shall monitor voice (phone) and electronic (email) and other sources designated by the Government for notification of network and cloud incidents, outages, and service degradations involving network services, Cloud Service Provider environments, Mission
Essential Systems (MES) hosted in data centers and cloud environments, or DHS Component entities.
3.5 Program Web and Tool Support and System Administration
The Contractor shall implement, configure, maintain, and operate Government furnished network, cybersecurity, and systems management software applications, dashboard applications, and hardware appliances. The Contractor shall provide recommendations regarding new tools and services that can be integrated into NOSC and/or Component NOC/SOC operations and regarding decommissioning of obsolete tools and services. The Contractor shall conduct 24x7x365 cybersecurity, network, system, enclave, and cloud management monitoring and analysis operations. Monitoring shall include Enterprise and NOSC dashboards. The Contractor shall apply various antivirus, intrusion detection, and vulnerability assessment tools, techniques, and procedures. The Contractor shall configure Forensic and Log Management tools in support of identifying rogue and malicious software and suspicious and unapproved activities.
The Contractor shall assist as required in the administration of tools used in the course of fulfilling Contractor responsibilities. The Contractor shall assist in the administration of incident tracking tools and in training Contractor and Government personnel in the use of the supporting tool suites.
The Contractor shall develop, integrate, manage, and maintain monitoring tools and dashboards (e.g., system and application monitoring software, AWS Dashboards, Azure Dashboards). The Contractor shall maintain a cyber incident dashboard, update as incident status changes, and provide continuous management updates. The Contractor shall support the content development and updates to Enterprise NOSC dashboards. The Contractor shall support the content development and updates to Enterprise NOSC dashboards.
The Contractor shall ensure that tool licenses and maintenance agreements are tracked and projections for license expirations are continuously maintained for a minimum of twelve (12) months into the future.
The Contractor shall assist the Government in generating communications to applicable stakeholders regarding cyber risk management, developing, and managing a holistic risk management dashboard to provide senior management a near real-time visual representation of cyber risks.
The Contractor shall support troubleshooting network problems by providing technical support associated with new or revised hardware or software installations. The Contractor shall support coordination of new OneNet connections including direct links with other agencies.
3.6 Service Delivery Implementation
The Contractor shall establish a full lifecycle process to triage, manage, monitor, analyze, track, and close all OneNet service requests, including coordination with GSA Enterprise Infrastructure Solutions (EIS) or other contract vehicles such as Data Center and Cloud Optimization (DCCO) Support Services, for coordination with various entities and Local Exchange Carriers for circuit installation across the United States and territories.
Task 4: OneNet Network Infrastructure Operations and Maintenance Support Services The Contractor shall provide operations and maintenance (O&M) support primarily at the Tier 1 and Tier 2 levels for OneNet edge or Component network infrastructure. This includes day-to-day monitoring, basic and intermediate troubleshooting, implementation of approved configuration changes, and support for incident response activities as directed by DHS.
The Contractor’s Tier 3 support for OneNet edge infrastructure shall be limited to configuration, troubleshooting, and engineering activities explicitly directed by DHS and defined in this SOW or in individual Task Orders. Higher Tier 3 and other strategic engineering responsibilities, including major design changes and enterprise-wide architecture decisions, will remain under Government control or other contracts, as designated by DHS.
This infrastructure consists of: Layer 2 switches, Layer 3 switches, routers, hubs/concentrators, gateways, bridges, and repeaters; modems, wireless LAN controllers and wireless access points;
load balancers; forward and reverse proxy servers and devices; network, application, database, and web application firewalls; intrusion detection and prevention devices; network sandbox devices (including honeynets); encryption and decryption devices (including TACLANE®); and all other networking elements and cybersecurity devices at points where Component sub-networks and Local Area Networks connect to the OneNet and where the OneNet connects to TICs or Policy Enforcement Points or Points of Presence.
The Contractor shall configure edge infrastructure devices and update those configurations under the Enterprise Configuration Control process. The Contractor shall monitor edge devices to assess device health and correct operation and shall assist in responding to cybersecurity and network outage incidents. Edge infrastructure will be located at DC1in Stennis Mississippi, at all DCAPs, and at various locations within the National Capital Region (NCR).
Network Infrastructure Operations and Maintenance support shall include participating DHS Component network infrastructures, operational environments, locations, processes, and supporting toolsets, where incorporated by Component Task Orders, in addition to DHS OneNet enterprise infrastructure.
4.1 IT Service Management
Configuration, Change, and Release Management The Contractor shall develop, manage, and implement a cradle-to-grave configuration, change, and release management program for all OneNet or Component network and edge infrastructure in conjunction with all DHS network policies, including the OneNet Enterprise Configuration Control process or similar Component change management process. The Contractor shall implement all proposed network infrastructure modifications under the approval of the DHS change control governance process, including by supporting approval of all changes via the DHS OneNet Change Control Board or the Component Change Control Board.
Configuration, Change, and Release Management shall support participating DHS Component-specific configuration baselines, change management procedures, approval authorities, governance requirements, and release procedures where incorporated by Component Task Orders, in addition to DHS OneNet enterprise governance.
Task 5: Field Engineering Technical Services The Contractor shall station Field Engineering support personnel regionally throughout the Continental United States (CONUS) to provide IT support requiring hands-on intervention at DHS facilities and sites lacking local IT support. The Contractor shall post Field Engineering support personnel at select CONUS locations from which they may be dispatched to facilities requiring support. Field Engineering support personnel shall be qualified to determine the nature of a service outage at a location and shall initiate response activity to restore service. Field Engineering support personnel shall be capable of determining whether an outage is the result of a commercial circuit failure or if it is due to some internal failure at a facility. For failures determined to have occurred within a facility, Field Engineering support personnel shall be capable of identifying the failed network or system components and be capable of either restoring the failed components to an operational status or of replacing those components as circumstances require. Failing components may include routers, switches, firewalls, servers, and desktop computing devices.
Task 6: Other Cybersecurity Services
6.1 Cybersecurity Services Provider (CSP) Program
All DHS FISMA systems are required to obtain NOC or SOC services from a DHS accredited NOC or SOC. DHS Component NOCs and SOCs must pass a formal assessment and receive a designation of either Accredited or Center of Excellence (COE). COEs are authorized to provide NOC and SOC services to other DHS Components. Accredited organizations are authorized to provide services only to their own Components and associated systems. Components that fail to achieve Accredited or COE designations are unaccredited and must subscribe to the services of a COE NOC or SOC from within DHS. Each accredited NOC and SOC will undergo a periodic reaccreditation and will be inspected at least every three (3) years or when Providers or Subscribers revise their service agreements. Component Subscribers will be assessed on their Provider’s anniversary date to ensure services received meet the required maturity level.
The Contractor shall conduct Cybersecurity Accreditation Audits of all DHS organizations providing NOC or SOC services and their associated Subscribers.
The Contractor shall administer the Cybersecurity Services…
This is the start of the file's text. The full file is on GovTribe.
File details come from the government source that posted it. Updated .