Draft SOW_Cybersecurity Spt.pdf
PDF 618 KB Posted
- Attached to
- Request for Information: Cybersecurity and Program Support Federal contract opportunity
- Solicitation number
- NCUA25RFI0028
- Issued by
- National Credit Union Administration
About this file
This draft Statement of Work (SOW) is for the National Credit Union Administration (NCUA) Office of the Chief Information Officer's Cybersecurity and Program Support contract. The solicitation seeks a contractor to provide comprehensive cybersecurity services across 11 task areas, including program support, audit management, cybersecurity architecture and engineering, security operations, incident management, forensics, threat intelligence, project management, and optional surge support.
Key contract details include a base period of one calendar year with four optional one-year periods, a transition period of one month, and performance primarily at 1775 Duke Street in Alexandria, VA. The contractor will be responsible for enhancing threat visibility, strengthening incident response, improving risk management, and enabling proactive defense. Specific requirements include developing strategic plans, maintaining cybersecurity frameworks, conducting vulnerability assessments, performing penetration testing, analyzing cyber threats, and supporting continuous monitoring and authorization processes. The contract is designated as high-risk, requiring all contractor employees to be U.S. citizens, and personnel performing cyberthreat intelligence work will need Top Secret security clearance with Sensitive Compartmented Information (SCI) level access.
View the file
Other files for this federal contract opportunity
| File | Type | Posted |
|---|---|---|
| NCUA Cybersecurity Spt RFI_091725.pdf |
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
National Credit Union Administration
Office of the Chief Information Officer
Cybersecurity and Program Support
DRAFT Statement of Work September 2025
NCUA25RFI0028 NCUA Cybersecurity and Program Support Statement of Work
Page | 2
TABLE OF CONTENTS
1. BACKGROUND
2. SCOPE
3. SPECIFIC REQUIREMENTS
3.1 TASK AREAS
3.1.1. TASK AREA 1: CYBERSECURITY PROGRAM SUPPORT
3.1.1.1. Program Management
3.1.1.2. Cybersecurity Program Support
3.1.1.3. Cybersecurity Policy and Documentation Support
3.1.1.4. Enterprise Risk Assessment
3.1.1.5. Information System Assessment & Authorization Support
3.1.1.6. Cybersecurity Subject Matter Expertise Technical Advisory Services
3.1.1.7. Cybersecurity Awareness and Training
3.1.2. TASK AREA 2: AUDIT MANAGEMENT
3.1.3. TASK AREA 3: CYBERSECURITY ARCHITECTURE AND
ENGINEERING
3.1.4. TASK AREA 4: SECURITY OPERATIONS CENTER
3.1.4.1. Asset and Vulnerability Management
3.1.5. TASK AREA 5: INCIDENT MANAGEMENT
3.1.5.1. Penetration Testing
3.1.6. TASK AREA 6: FORENSICS, MALWARE ANALYSIS AND
ADVANCED HUNTING AND E-DISCOVERY
3.1.7. TASK AREA 7: CYBER THREAT INTELLIGENCE AND
INFORMATION SHARING
3.1.8. TASK AREA 8: PROJECT MANAGEMENT
3.1.9. OPTIONAL TASK AREA 9: SURGE SUPPORT
3.1.10. OPTIONAL TASK AREa 10: INFORMATION SYSTEM SECURITY
OFFICER SUPPORT
3.1.11. OPTIONAL TASK AREA 11: CYBER SUPPLY CHAIN RISK
MANAGEMENT
4. CONTRACT MANAGEMENT
4.1 KICKOFF MEETING
4.2 PROJECT STATUS MEETINGS
4.3 AD HOC STATUS MEETINGS
4.4 STAFFING PLAN
Page | 3
4.5 KEY PERSONNEL
4.6 QUALITY ASSURANCE AND SURVEILLANCE PLAN
4.7 NON-DISCLOSURE
4.8 GOVERNMENT-FURNISHED EQUIPMENT AND INFORMATION
4.9 SERVICE LEVEL AGREEMENTS
5. TRANSITION IN AND TRANSITION OUT PLAN
5.1 TRANSITION IN PLAN
5.2 TRANSITION OUT PLAN
6. DELIVERABLES
6.1 DELIVERY SCHEDULE
7. PLACE OF PERFORMANCE
8. PERIOD OF PERFORMANCE
9. OTHER DIRECT COSTS
10. SECURITY
Page | 4
1. BACKGROUND The National Credit Union Administration (NCUA) is an independent federal agency that regulates, charters, and supervises federal credit unions throughout the United States and its territories. NCUA ensures savings in federal and most state-chartered credit unions through the National Credit Union Share Insurance Fund (NCUSIF), a federal fund backed by the full faith and credit of the United States Government, which insures the deposits for more than 143 million credit union members.
The NCUA headquarters is in Alexandria, Virginia, and has three Regional Offices located in Alexandria, Virginia; Austin, Texas; and Tempe, Arizona. Field employees are stationed in more than 200 duty stations located throughout the continental United States, Alaska, Hawaii, and Puerto Rico.
The NCUA utilizes many assets, including facilities, communications equipment, computer systems, employees, contractors, public trust, and information. A loss to any one of these assets could affect the goals or the quality of support necessary to carry out the NCUA mission. Additionally, the NCUA collects, uses, and stores information that falls into the categories of privacy data, proprietary data, procurement data, inter-agency data, and privileged system information. Access to these types of information is controlled by the Privacy Act of 1974 (as amended), the Computer Security Act of 1987 (as amended), and the Federal Information Security Management Act (FISMA) of 2002, as well as many important rules, regulations, policies, and guidelines promulgated by the Office of Management and Budget (OMB), and the National Institute of Standards and Technology (NIST). As a result, the NCUA has a legal and practical responsibility to maintain the Confidentiality, Integrity, and Availability of this information.
The NCUA, like many organizations, faces significant challenges in managing agency risk across its networks and information systems. Information assets have become increasingly difficult to protect due to advances in the threat landscape, such as easy-to-use cyber-attack frameworks, advanced threat actor persistence and technological attack evolution, data obfuscation, and social engineering such as phishing attacks. These factors have resulted in a critical necessity for utilizing an innovative and forward-thinking implementation of information security at the agency. Through innovative advances in the implementation of security, inclusion of security requirements throughout the system and software development life cycle, and the continuous monitoring and ongoing authorization program, the agency’s objective is to effectively manage information security risk through an optimal security posture, and thus protects and ensures the Confidentiality, Integrity, and Availability of NCUA’s information.
To safeguard the Confidentiality, Integrity, and Availability Triad of its information and information systems effectively, NCUA has established the Information Security Program under the Office of the Chief Information Officer (OCIO) Cybersecurity Division. The OCIO Cybersecurity Program carries out the day-to-day responsibilities on behalf of the Chief Information Officer (CIO) and the Senior Agency Information Security and Risk Officer (SAISRO) who bear the primary responsibility to ensure compliance with FISMA, OMB, NIST, and all applicable laws, directives, policies, and directed actions on a continual basis.
Page | 5
2. SCOPE The NCUA seeks to acquire contract services to, identify, protect, detect, respond, recover, operate, maintain and continuously improve its Cybersecurity Program.
The contractor shall support the NCUA mission by ensuring compliance with FISMA, OMB, NIST and other federal and industry policies, procedures and guidelines adopted by NCUA.
This Statement of Work (SOW) describes a broad set of contractor responsibilities to support cybersecurity program objectives. The principal purpose of these responsibilities is for the contractor to provide comprehensive cybersecurity tools and expert support to the CIO and the SAISRO to:
• Enhance Threat Visibility: Continuous monitoring of systems, networks, and applications to identify potential vulnerabilities and malicious activity.
• Strengthen Incident Response: Develop and implement a structured and efficient process to detect, triage, and remediate security incidents, minimizing damage and downtime.
• Enhance Risk Management: Align risk management with organizational risk tolerance and compliance standards, ensuring adherence to regulatory frameworks such as FISMA, NIST Cybersecurity Framework (CSF), laws, and regulations.
• Enable Proactive Defense: Leverage threat intelligence and analytics to predict, prevent, and mitigate potential attacks before they materialize.
3. SPECIFIC REQUIREMENTS
3.1 TASK AREAS
The Contractor shall perform tasks in the following areas. The contract type, Firm-Fixed Price (FFP) or Time-and-Materials (T&M), has been identified for each task area:
1. Cybersecurity Program Support (FFP)
2. Audit Management (FFP)
3. Cybersecurity Architecture and Engineering (FFP)
4. Security Operations Center (FFP)
5. Incident Management (T&M)
6. Forensics Support, Malware Analysis, and Advanced Hunting (FFP)
7. Cyber Threat Intelligence and Information Sharing (T&M)
8. Project Management Support (T&M)
OPTIONAL TASK AREAS
9. Surge Support (T&M)
10. Information System Security Officer Support (FFP)
11. Cyber Supply Chain Risk Management (FFP)
3.1.1. TASK AREA 1: CYBERSECURITY PROGRAM SUPPORT
3.1.1.1. Program Management
Page | 6
The Contractor shall develop, execute, and maintain a Program Management Plan that ensures the effective overall management of the program support in accordance with the Project Management Body of Knowledge and the Federal Acquisition Institute. This includes the management and oversight of all activities performed by contractor personnel, including subcontractors, to satisfy the requirements and deliverables identified in this SOW. The Contractor shall identify a Program Manager (PM) by name, who will be Key Personnel and shall provide management, direction, administration, quality assurance, and leadership of the execution of this contract. The Contractor shall effectively and efficiently manage cost, schedule, and performance using integrated program management processes across all aspects of performance and in a manner that yields cost savings and/or performance efficiencies.
The PM shall ensure the deliverables and work performed are effectively managed via program plans, oversight, and reporting. The PM shall have the necessary authority to utilize resources to ensure the work under this contract is accomplished consistently with technical, cost, and schedule requirements as well as prudent programmatic and technical risk mitigation.
The Contractor shall provide a Continual Service Improvement (CSI) Plan that identifies strategic and tactical improvements to the NCUA Cybersecurity Program, defines metrics and measures associated with said improvements, gathers and processes the associated data for analysis, presents and utilizes the information to ensure resilient operations.
3.1.1.2. Cybersecurity Program Support
The Contractor shall provide program support to NCUA employees and contractors on the application of cybersecurity specific to business and technical situations and settings. The Contractor shall provide cybersecurity program support services, including, but not limited to the following:
a. Develop, evolve, execute, and maintain a three (3) year Cybersecurity Strategic Plan that ensures the programs ability to meet its long-term effectiveness and maturity objectives to include any emerging threats to the agency.
b. Develop and maintain a Cybersecurity Framework Profile.
c. Develop and implement cybersecurity strategic and tactical goals and objectives.
d. Determine the impact of new technology or policy (e.g., Continuous Diagnostics and
Mitigation (CDM) technologies, zero-trust architecture, anomaly-based tools, virtual environments, etc.) on the NCUA cybersecurity program.
e. Facilitate technical meetings, including material preparation, documentation, presentation and collection of notes, outcomes and follow on tasks as necessary, only when such support is explicitly requested for specific assignments.
f. Provide expert analysis and document preparation for various analytical efforts focused on processes and procedures.
g. Review various draft documents and provide timely feedback to NCUA employees and contractors.
h. Identify, develop, and support implementation of a Performance Management program that includes key performance indicators (KPIs), key risk indicators (KRIs), tracking metrics, and trend analysis.
Page | 7
i. Generate regular and ad hoc dashboards, reports, and metrics.
j. Use, maintain, and mature an NCUA provided enterprise Governance, Risk, and
Compliance (eGRC) solution.
k. Draft responses to ad hoc Federal inquiries for NCUA review and to support NCUA
Federal reporting requirements.
l. Update project charters, and project management plans yearly or as required.
m. Create, Maintain, and Update integrated master project schedule of all task areas, WBS, risk register, lessons learned.
n. Draft responses to Federal inquiries or reporting documents (e.g., FISMA, HVA, etc.) on an annual, quarterly, or ad hoc basis, as necessary.
o. Report on FISMA inventory and provide Plan of Action & Milestones (POA&M) and
Risk Acceptance reports monthly.
3.1.1.3. Cybersecurity Policy and Documentation Support
The Contractor shall proactively review, update, and maintain information security policy, guidance documents, directives, templates, and materials to ensure all documentation reflects and incorporates the most recent version of all NCUA information security documentation. The Contractor and the Government shall agree on a timeframe for preparing, reviewing, and approving documents as well as updates to documents. The timeframe shall be determined by the size, complexity, and breadth of the assignment. The Contractor shall ensure any documents or updates to documents have gone through a quality controls check for accuracy and appearance, including correction of spelling, grammar, and formatting errors, before submission to the Government for review and approval.
The Contractor shall provide support for cybersecurity policy and documentation support to include, but not limited to the following:
a. Inventory existing cybersecurity policies, instructions, standards and procedures and recommend disposition (i.e., continued use as-is, needs revision, or deactivate).
b. Recommend, review, and update existing, and/or develop new cybersecurity policies, instructions, standards, and procedures.
c. Ensure documentation is current and relevant for NCUA processes and programs.
d. Ensure alignment with the current Agency policies, instructions, standard and procedures such as personnel security, physical security, systems development lifecycle, and enterprise architecture.
e. Incorporate new NCUA policies, procedures, and controls into the agency’s eGRC solution.
f. Draft, review, and/or comment on CIO and SAISRO directives and other policies, procedures, and correspondence.
g. Provide documentation and comprehensive system security planning and lifecycle management.
h. Produce documentation, which includes security documentation, expedited lifecycle documentation, user manuals, training material, standard operating procedures, network diagrams, system-level security requirements, security specifications, and metrics.
i. Develop and maintain a list of high-value assets that correspond to NCUA’s Business Impact Analysis.
Page | 8
3.1.1.4. Enterprise Risk Assessment
The Contractor shall provide support to include, but not limited to, the following areas:
a. Conduct an annual Enterprise Cybersecurity Risk Assessment resulting in the identification and registration of all identified cybersecurity risk to the agency.
b. Identify and document risks and track the risks by creating POA&Ms.
3.1.1.5. Information System Assessment & Authorization Support The Contractor shall provide support to include, but not limited to, the following areas:
a. Evolve, execute, and maintain Assessment and Authorization (A&A) activities for all
NCUA systems and services in accordance with OMB, NIST, and the Department of Homeland Security (DHS), Cybersecurity & Infrastructure Security Agency (CISA).
b. Validate information system categorization, the selection of common and core security controls, the validation of the implementation of the security controls, the validation of the assessment of the security controls, the authorization of the information system, and the monitoring of the security controls both manual and automated.
c. Evolve, execute, and maintain the NCUA POA&M process to adhere to NIST and Agency Standard Operating Procedures.
d. Review and analyze all system artifacts for accuracy, completeness, in support of Authorization to Operate (ATO) requests.
e. Review and assess ATO / Authority to Use (ATU) packages, making recommendations to authorize/deny systems and services prior to submission to the SAISRO and AO.
f. Maintain, update, and prepare A&A and POA&M Standard Operating Procedures.
g. Develop and support the ongoing authorization (OA) process that includes continuous monitoring.
h. Deliver ATO / ATU packages to System Owners, SAISRO, Authorizing Official, and
Authorizing Officials Designated Representatives.
3.1.1.6. Cybersecurity Subject Matter Expertise Technical Advisory Services The Contractor shall provide cybersecurity subject matter expertise technical advisory services which includes, but are not limited to, the following types of ad hoc activities, which could occur several times a month:
a. Expertise related to the NCUA Cybersecurity A&A program that is comprised of systems and services of varying size and complexity.
b. Specific guidance and technical expertise in the form of standards, policies, procedures, and oversight for the NCUA A&A program.
c. Provide advice based on a review and analysis of third-party websites and applications as necessary.
d. Advise, document, review, and feedback on the application of security requirements
(e.g., technical review boards, review of system security plans, risk assessments, plan of action and milestone reports).
e. Prepare situational awareness brief regarding cybersecurity policy, and contractors and developer trends for NCUA senior management.
f. Determine the impact of new or changing applicable federal policy changes.
g. Determine the impact of new or revised legislation and regulations.
Page | 9
h. Conduct research and present analyses to evaluate and/or determine emerging industry technology trends, government agency best practices, and security issues.
3.1.1.7. Cybersecurity Awareness and Training
The Contractor shall provide subject matter expert support for the delivery and maintenance of a comprehensive cybersecurity awareness and training program. The program shall include, but is not limited to, providing support in the following areas:
a. Assess and provide recommendations of the existing training program and materials.
b. Develop, deliver, and maintain outreach and communication plan for cybersecurity (e.g., brown bags, webinars).
c. Engage with the Information Security Systems Officer (ISSO) and Business/System
Owner community to communicate changes to the Cybersecurity Program and Governance.
d. Enhance, document, administer, and deliver a comprehensive program to measure and improve the cybersecurity awareness and vigilance of NCUA system users, including those with significant security and IT administrative responsibilities.
e. Coordinate with NCUA’s training vendor to update security awareness training, as required.
f. Provide support in the development, implementation, and tracking of general user and role-based cybersecurity training.
g. Maintain and update reporting and tracking processes for cybersecurity awareness and role-based training.
h. Provide support to the coordination of training seminars, training meetings, conferences, etc.
i. Provide support to the development, implementation, and training of National Cybersecurity Awareness Month.
3.1.2. TASK AREA 2: AUDIT MANAGEMENT
The Contractor shall provide subject matter expertise and support to maintain and enhance an Audit Management program. OCIO facilitates audits for various reasons to include requests from the Government Accountability Office, Office of Inspector General, FISMA Compliance, High Value Asset, Chief Financial Officer, Internal Control audits, etc.
The Contractor shall provide support to include, but not limited to, the following areas:
a. Maintain, update, and prepare Audit Management Standard Operating Procedures.
b. Maintain an audit request and response database that is accessible by multiple stakeholders.
c. Independently research, gather information, and submit audit artifacts, as needed.
d. Coordinate with stakeholders to acquire audit artifacts and responses, as needed.
e. Support the Audit Liaison in research and drafting of audit responses.
f. Conduct recurring audit meetings with NCUA management and audit stakeholders.
g. Maintain a list of findings and follow the findings through remediation and closure.
h. Manage each audit engagement in collaboration with all stakeholders.
i. Assist with managing and maintaining visibility of POA&Ms to achieve acceptable levels of risk.
j. Establish and maintain metrics to show progress and performance of audit.
Page | 10
k. Report on audit and risk as required.
l. Meet due dates and deadlines for audit work and responsibilities.
3.1.3. TASK AREA 3: CYBERSECURITY ARCHITECTURE AND
ENGINEERING
The Contractor shall provide support to include, but not limited to, the following areas:
a. Provide security engineering subject matter expertise in coordination with the OCIO enterprise architecture, technical review board, applications, and IT operations.
b. Engineer, implement, integrate, optimize, and administer innovative security solutions that reduce Agency risk by providing increased visibility and responsible readiness across the enterprise.
c. Ensure security system architecture and engineering is built into the solution/design as part of the System Development Life Cycle (SDLC) and is documented.
d. Provide subject matter expertise, counsel, and support on the use of current and future security tools used to secure NCUA’s infrastructure, applications, and systems.
e. Identify misconfigurations in security tools and capabilities for systems operated by and on behalf of NCUA.
f. Develop and maintain an enterprise information security engineering plan and an information security architecture.
g. Develop information security architecture drawings for NCUA’s network and systems.
h. Coordinate with stakeholders in OCIO to design, configure, implement, and operate information technology tools in support of Continuous Diagnostics and Mitigation.
i. Receive, aggregate, and display information from CDM tools at the agency and federal level.
j. Coordinate with security operations and incident management to build layers of alert coordination, enrichment, integration, and automation between platforms and cybersecurity technology for efficiency and effectiveness.
k. Develop a plan to implement and maintain each phase of CDM:
• Manage hardware assets (HWAM), software assets (SWAM), security management configuration settings (CSM), and software vulnerabilities (VUL)
• Manage account/access/managed privileges (PRIV), trust determination for people granted access (TRUST), credentials and authentication (CRED), and security related training (BEHAVE)
• Manage network and perimeter components, host and device components, data at rest and in transit, and user behavior and activities. This includes management of events (MNGEVT); operate, monitor, and improve (OMI); design and build-in security (DBS); boundary protection (BOUND); supply chain risk management (SCRM); and ongoing authorization
• Manage the protection of data through the capabilities: data discovery/classification (DISC); data protection (PROT); data loss prevention (DLP); data breach/spillage mitigation (MIT); and information rights management (IRM)
3.1.4. TASK AREA 4: SECURITY OPERATIONS CENTER
Page | 11
The NCUA Security Operations Center (SOC) is responsible for maintaining comprehensive situational awareness, visibility, and response readiness across NCUA. The Contractor shall provide support to include, but is not limited to, the following areas:
a. Maintain, update, and prepare SOC Concept of Operations and Standard Operating
Procedures.
b. Monitor, defend, and protect perimeter interface for malicious network traffic.
c. Monitor, defend, and protect hosts within the NCUA boundary for malicious activity or activity that could indicate lateral movement within the environment.
d. Perform advanced network analysis of egress and ingress traffic.
e. Conduct initial triage, containment, categorization, and escalation for suspicious events and incidents.
f. Perform triage and short-turn analysis of potential security incidents generated by near real-time security alert feeds.
g. Perform curation, tune and optimize detections, analytics, signatures, correlation rules, and response rules deployed on SOC detection and analytics systems, such as EDR, SIEM, and SOAR.
h. Use knowledge of adversary Tactics, Techniques and Procedures (TTPs) and agency systems to create detections and analytics to detect and understand various activity in SOC sensors and analytic systems, from scratch, as needed.
i. Receive, document, and process reports of potential security incidents from agency and third parties. These reports may come through written (e.g., email, OneStop) or verbal means.
j. Perform in-depth, detailed analysis of suspected incidents, identifying details such as the origin, extent, and implications of the incident, and characterizing the confidence of these conclusions.
k. Support incident or compromise response activities as necessary.
l. Provide security impact assessments and risk analysis of vulnerabilities, incidents, and change requests.
m. Provide situational awareness and reporting on cybersecurity status, incidents, and trends in adversary behavior.
n. Operate and maintain cybersecurity technology (e.g., endpoint detection and response, security information and event management platform, etc.).
o. Develop and publish security operations dashboards and visualizations.
3.1.4.1. Asset and Vulnerability Management
a. Maintain, update, and prepare Asset and Vulnerability Management Standard Operating
Procedures.
b. Ensure security tools are installed and operational in accordance with service level agreements (SLAs) (i.e., IT/OT).
c. Collect and curate knowledge of assets, networks, and services, mapping their interdependencies, and calculating criticality and risk.
d. Conduct vulnerability scanning of assets for vulnerability status, including patch level and installed software, and security-relevant configuration, for purposes of calculating security risk and compliance status.
e. Accept, triage, and analyze vulnerability reports from vulnerability researchers.
Page | 12
f. Coordinate vulnerability disclosure remediation activities with stakeholders and validate remediation.
g. Coordinate with stakeholders to prioritize and implement vulnerability remediation.
h. Coordinate with CISA and NCUA stakeholders to maintain accuracy and updates to the
CISA CDM dashboards.
i. Develop and publish asset and vulnerability management dashboards and reports.
3.1.5. TASK AREA 5: INCIDENT MANAGEMENT
The NCUA Cybersecurity Incident Response Team (CSIRT) provides a variety of critical functions related to situational awareness, incident and vulnerability management, coordination, collaboration, and security oversight for NCUA’s infrastructure, applications, and systems. The Contractor shall provide support to the CSIRT to include, but is not limited to, the following areas:
a. Review and update the Enterprise Incident Response Plan annually.
b. Conduct annual incident response testing.
c. Maintain, update, and prepare Enterprise Incident Response Standard Operating
Procedures.
d. Lead, direct, and/or coordinate response in partnership with constituents, incident response stakeholders and third parties.
e. Perform activities supporting incident/adversary containment, damage management, adversary eviction, and system recovery to reduce current impact and move to a state that will prevent future incidents.
f. Provide stakeholders with timely relevant information, in accordance with the Incident Response Plan, to enable effective response activities.
g. Perform information gathering, information distribution, and notification in support of an ongoing incident.
h. Develop and publish incident, after-action, and executive reports.
3.1.5.1. Penetration Testing
The Contractor shall coordinate and conduct all Agency penetration testing on systems operated by and on behalf of NCUA. NCUA applications and infrastructure shall be accessible only through NCUA-specified authentication methods, and available only to vetted personnel.
The Contractor shall provide support to include, but is not limited to, the following areas:
a. Develop, maintain, and update Penetration Testing Concept of Operations and Standard
Operating Procedures.
b. Coordinate with the NCUA before each assessment to determine the appropriate assessment model and identify the underlying technology.
c. Draft NCUA Rules of Engagement and Test Specific, Penetration Documents for engagements.
d. Perform red teaming, pen testing, adversary emulation, purple teaming, breach and attack simulation, or other testing detections with the goal of improving SOC operations and the agency’s overall defensive posture.
e. Provide assessment activities: onboarding, active assessment of the target, findings, triage, detailed reporting, and patch validation.
Page | 13
f. Draft and publish a report for each penetration test including results, findings, and proposed remediation efforts (if applicable).
g. Maintain overall tracking of Penetration Testing activities.
h. Integrate penetration testing activities with other testing efforts, including but not limited to, vulnerability assessments, threat modeling, event detection evaluation, continuous monitoring tool verification, incident response, and incident reporting compliance.
3.1.6. TASK AREA 6: FORENSICS, MALWARE ANALYSIS AND
ADVANCED HUNTING AND E-DISCOVERY
The Contractor shall provide support to include, but is not limited to, the following areas:
a. Provide network and media digital forensics, advanced threat hunting, and malware analysis capabilities.
b. Utilize industry standard techniques, tools, and procedures to perform network and media digital forensics, incident response, malware analysis, advanced threat hunting across NCUA infrastructure.
c. Execute proactive defense of all systems operated by and on behalf of NCUA through Indicators of Compromise (IOC) sweeps / host interrogation and persistent threat hunting.
d. Provide status updates for Incident Response, Digital Forensics, and Malware Analysis according to the battle rhythm established by the Enterprise Incident Response Plan.
e. Prepare Enterprise Forensics, Malware Analysis and Advanced Hunting Plan.
f. Provide Monthly Technical Status Report.
g. Maintain, update, and prepare Standard Operating Procedures for Malware Analysis, Forensic Analysis, and Advanced Threat Hunting.
h. Create incident response and forensics reports documenting findings, detailed analysis, recommendations, and lessons learned.
i. Develop and build security content, scripts, tools, or methods to enhance forensic processes.
j. Coordinate and support NCUA Insider Threat investigations.
3.1.7. TASK AREA 7: CYBER THREAT INTELLIGENCE AND
INFORMATION SHARING
Cyberthreat intelligence and information sharing ensures an optimal Agency security posture by identifying ongoing, immediate, and emerging threats to the organization, including threat actors, attack vectors, and breach scenarios.
The Contractor shall coordinate with the OCIO, Office of Continuity and Security Management (OCSM), and the Office of Examination and Insurance (E&I) Critical Infrastructure Division, as appropriate, to inform stakeholders, improve situational awareness, highlight risk relevant to the agency or financial sector, facilitate rapid response, and assist with qualifying organizational risk.
The Contractor shall provide support to include, but not limited to, the following areas:
a. Maintain, update, and prepare cyberthreat intelligence and information sharing Standard
Operating Procedure.
Page | 14
b. Monitor threat intelligence sources (security alerts, warnings, and other indicators).
c. Collect cyber threat intelligence products, including Cyber Threat Intelligence (CTI) feeds and reports.
d. Process and integrate CTI into SOC systems and parsing and filtering information for further consumption by the SOC and its constituency.
e. Provide cyberthreat intelligence to include, but not limited to, cyber campaigns against
US information technology potentially affecting NCUA systems, attacks against the Federal/Private Financial Sector, tactics, techniques, and procedures being reported across Federal/Private Financial Sector.
f. Utilize analytic techniques to track, trend, and correlate adversary behavior over time, and support risk decision making.
g. Create and produce CTI reports describing specific adversaries, their TTPs, and campaigns. This may include using a cyber threat intelligence platform or other tools to enhance analysis.
h. Perform proactive discovery of security vulnerabilities not previously known to the SOC (e.g., “0 days”), through reviewing internal incidents, cyber threat intelligence collection, and software reverse engineering.
i. Provide weekly cyberthreat intel briefs.
j. Develop and distribute a weekly Threat Intelligence Newsletter.
k. Advise and communicate cyberthreat intelligence information and other relevant security data and alerts to NCUA and OCIO leadership.
l. Qualify organizational risk based on cyberthreat intelligence.
3.1.8. TASK AREA 8: PROJECT MANAGEMENT
The Contractor shall provide support to include, but is not limited to, the following areas:
a. Coordinate a matrixed team of government and contractor resources to develop and document project requirements and achieve the goals of OCIO projects related to infrastructure, platform, and cybersecurity.
b. Organize, direct, coordinate, plan, and execute project activities.
c. Provide support to government project managers, as needed, to effectively manage scope, cost, and schedule of projects.
d. Develop, manage, and maintain tools to monitor and provide status reporting such as the
Project Plan, Project Status Reports, Project Briefings, Project Schedule, Technical, and Financial Reports.
e. Develop and maintain interactive business analytics and data visualization reports.
f. Support project acquisition, contract, and budget management tasks and activities.
g. Support development, collection, categorization, and maintenance of all work products created by the project team.
h. Develop, execute, and maintain a Project Management Plan, project schedule, risk matrix, and WBS that ensure the effective overall management of the project in accordance with the Project Management Body of Knowledge.
3.1.9. OPTIONAL TASK AREA 9: SURGE SUPPORT
The Contractor shall provide surge support as needed for the NCUA’s cybersecurity program. This task will establish a separate Contract Line-Item number (CLIN) with a Not To Exceed (NTE) value of 5% of the annual price of the contract and will only be funded if
Page | 15 a need is identified. If surge support is identified, the government in coordination with the contractor will identify the level of effort (LOE) for the surge and develop a proposal. The funding for this task will be provided via bilateral modification. No work can begin until a bilateral modification is issued or the Contracting Officer provides the contractor with an email/communication of Authorization to Proceed.
3.1.10. OPTIONAL TASK AREA 10: INFORMATION SYSTEM
SECURITY OFFICER SUPPORT
The Contractor shall lead the effort to achieve an ATO or ATU by preparing and maintaining the deliverables required by the A&A process, manage the A&A process, brief stakeholders of process status, and provide overall management of the A&A effort.
Subsequently, the Contractor shall be responsible for monitoring the security posture and recommending changes to meet NCUA IT security requirements.
The Contractor shall provide support to include, but is not limited to, the following areas:
a. Coordinate with security / privacy control assessors to establish A&A submission timelines.
b. Prepare, deliver, and maintain all required deliverables to achieve an ATO or ATU for
NCUA systems and services, to include:
• FIPS 199
• E-Authentication
• Incident Response Plan
• Configuration Management Plan
• Risk Assessment
• System Security and Privacy Plan
• Privacy Impact Assessment
• Information Security Continuous Monitoring Plan
• System/Service Account Reviews
• Artifacts for A&A/Reauthorization Efforts
c. Recommend security categorization of the information system based on NIST standards.
d. Select, coordinate implementation, document implementation, provide evidence of implementation, and monitor security controls in accordance with NIST standards.
e. Develop recommendations to improve or change system security based on analysis of the information system security artifacts and security posture, and ensure defects are identified.
f. Analyze security scan, vulnerability, and penetration data about the information system, whether security controls have been implemented, and produce documentation that support achievement of a successful A&A/reauthorization decision.
g. Maintain all documents and artifacts associated with the initial authorization and continuous monitoring of NCUA systems.
h. Develop, document, and recommend a system-level strategy supported by artifacts to support continuous monitoring of the effectiveness of the employed security controls within or inherited by the system, and monitoring of any proposed or actual changes to the system and its operational environment.
i. Engage with members of the NCUA security team to determine and document the potential impact of changes to the system and environment.
Page | 16
j. Assess security control changes and update the security plan and the POA&M, as required.
k. Manage POA&Ms and coordinate with stakeholders to implement corrective actions for security control weaknesses.
l. Conduct continuous monitoring in accordance with the information system continuous monitoring plan and the NCUA Information Security and Privacy Continuous Monitoring Strategy.
m. Adhere to the ISSO responsibilities as contained in the NCUA Information Security and Privacy Continuous Monitoring Strategy.
n. Maintain a risk register associated with security findings of each information system monitored.
3.1.11. OPTIONAL TASK AREA 11: CYBER SUPPLY CHAIN RISK
MANAGEMENT
The Contractor shall lead the effort to identify, assess, and mitigate risks associated with the supply chain of information and communications technology products and services. The goal is to ensure the security, integrity, and resilience of the supply chain by addressing vulnerabilities and threats that could compromise the confidentiality, integrity, or availability of critical systems and data. This includes evaluating suppliers, managing third-party risks, and implementing best practices to protect against cyber threats throughout the entire supply chain lifecycle.
The Contractor shall provide support to include, but is not limited to, the following areas:
a. Maintain, update, and prepare C-SCRM standard operating procedures.
b. Configure, use, maintain, and mature an NCUA provided C-SCRM solution.
c. Coordinate with stakeholders to integrate and maintain C-SCRM information into the
NCUA provided GRC Platform.
d. Perform complex data mining with structured and unstructured data and delivering research and analytics.
e. Conduct detailed supply chain analyses of a product, program, and sector supply chain risks.
f. Perform risk assessments of entities, including fraud (for example, engaging in counterfeiting, deception, intentional misrepresentation), foreign investment, reputational, cybersecurity and financial.
g. Continuously monitor in real-time (as source data is updated) C-SCRM.
h. Develop and publish C-SCRM dashboards and visualizations.
i. Manage and maintain the NCUA approved products list.
4. CONTRACT MANAGEMENT
4.1 KICKOFF MEETING
Upon award, the contractor shall schedule and coordinate a Kickoff Meeting at the location approved by Government. The meeting will provide an introduction between the contractor personnel and Government personnel who will be involved with the contract. The meeting will provide the opportunity to discuss technical, management, and security issues, and
Page | 17 reporting procedures. At a minimum, the attendees shall include Key Personnel, relevant Government personnel, and the Contracting Officer’s Representative (COR).
The Contractor shall schedule the Kickoff Meeting within 5 days of contract award at which time, the following shall be provided by the Contractor:
• Project work schedule
• Technical, Management, and Security Issues
• Non-Disclosure Agreements for Contractor shall be provided and require signature
• Reporting Procedures
The Contractor shall provide minutes of this meeting.
4.2 PROJECT STATUS MEETINGS
Monthly Project Status Meetings shall be conducted among the Contractor, and the COR.
Other NCUA stakeholders may be invited to attend at the COR’s discretion. Meetings shall be held monthly, at a minimum, and may be more frequent at the COR’s discretion. At these meetings, the Contractor shall provide the most recent Monthly Progress Review Report for the tasks listed below.
The Contractor shall provide a Progress Review Report to include the following:
• An overview of the items completed since the last reporting period
• An overview of the project status with a focus on outstanding issues and risks
• An overview of the work to be performed through the next reporting period
• An overview of the financial status
• A discussion of issues and risk
• A discussion of items delayed/not on schedule
4.3 AD HOC STATUS MEETINGS
The PM, and where needed other appropriate contractor personnel, shall participate in routing and periodic status meetings with key government personnel, at times on short notice. The purpose of such meetings is to ensure NCUA stakeholders are informed of program status and progress on activities. The meetings provide an opportunity to set priorities, identify opportunities or concerns, and coordinate resolution of identified problems.
4.4 STAFFING PLAN
The Contractor shall develop, deliver, and maintain a staffing plan. The staffing plan shall be considered a living document and can be changed or updated upon agreement between the COR and the Contractor Program Manager. At a minimum, the staffing plan shall include:
• Explanation of the process undertaken to ensure proposed employees staffed in each labor category meet the specific qualifications and have the requisite skills for the position.
• Determination of how much time will be needed to fill vacant positions.
Page | 18
• Knowledge, Skills, and Experience: The Contractor shall describe how they will provide personnel with knowledge, skills, and experience to meet the requirements of the SOW.
• Training Strategy: The Contractor shall describe how they plan to keep staff trained and up to date on current technologies.
• Retention Strategy: The Contractor shall identify the retention strategy to minimize Contractor staff turnover.
• Staffing Strategy: The Contractor shall describe their recruiting and staffing processes for filling vacant positions as personnel leave the contract, including their reach back strategy and process for communicating with the NCUA on any personnel changes.
4.5 KEY PERSONNEL
The following personnel are determined to be key personnel for this contract.
Key Personnel Description Program Manager (Section 3.1.1.)
Master of Science in Management or related business field.
Mandatory certifications include the Project Management Professional (PMP), Information Technology Infrastructure Library (ITIL), Certified in Risk and Information Systems Control (CRISC); Certified Information System Security Professional (CISSP) is preferred. Minimum 10 years of experience managing information security teams including cloud, network, and client application information security. Experience leading IT strategy, transformation, technical architecture, and security solution engagements. Experience with federal agencies of similar size, scope, and complexity.
Cyber Information Assurance / Security Specialist Lead (Section 3.1.2.)
Master of Science in Information Management Systems or related field. Minimum 7 years of experience in IT and security, minimum of 3 years’ experience supporting an Information Security program at a Federal Agency. Experience with the Federal Information Security Modernization Act (FISMA), Federal Risk and Authorization Management Program (FedRAMP), Federal Information Processing Standards (FIPS), and National Institute of Standards and Technology (NIST) Special Publications. Experience utilizing the Risk Management Framework, the Cyber Security Framework, executing Security Assessment and Authorization activities, and the ability to translate requirements from system engineers and developers into data-driven and risk-based recommendations. Experience working with and managing relationships with System Owners, Information System Security Officers, Authorizing Officials, and Chief Information System Security Officers. Experience managing IT Governance, Risk, and Compliance Programs and using RSA Archer eGRC tool.
Mandatory certifications include the Certified Information System Security Professional (CISSP) and Certified Information Systems
Page | 19
All proposed substitutions of key personnel shall be in accordance with NCUA Clause 9.3002-2 Contractor Key Personnel (See RFP Attachment 2).
4.6 QUALITY ASSURANCE AND SURVEILLANCE PLAN
Key Personnel Description Auditor (CISA); Project Management Professional (PMP) is preferred.
Security Operations Lead (3.1.4.)
Bachelor of Science in Information Technology, Computer Science or related field. Minimum of 10 years’ experience providing security operations and penetration testing support. Minimum 5 years’ managing and directing security operations. Responsible for the ability to implement the various phases of Continuous Diagnostics and Mitigation, establishing baselines for security tools to ensure proper configuration and deployment, architecting, deploying, and maintaining security products and services, and recommending and implementing solutions for protecting data throughout its lifecycle. Mandatory certifications include the Certified Information System Security Professional Information Systems Security Management Professional (CISSP-ISSMP), Certified Information System Security Professional Information Systems Security Architecture Professional (CISSP-ISSAP);
Certified Network Security Engineer (CNSE) is preferred.
Incident Management Lead (3.1.5.)
Master of Science in Information Technology, Information Security, or related field. Minimum of 10 years’ experience providing incident response, security operations, and penetration testing support. Minimum 5 years’ managing and directing incident response teams with a demonstrated understanding of threat sharing, indicators of compromise, malware analysis, and forensic analysis. Responsible for formulating short and long-term strategies to advance cyber security controls, design, architect, engineer security solutions and assist with deployment strategies, and communicate and manage relationships with senior managers for threat and intelligence sharing. Mandatory certifications include the EC-council Certified Ethical Hacker, EC-Council Licensed Penetration Testers, EC-Council Certified Security Analyst.
Digital Forensics Analyst (3.1.6.)
Must have at least 5 years of experience conducting, or supporting the conduct of, digital forensic analysis (Windows, Linux and Mac), digital media acquisition (disk duplication), mobile device acquisition/analysis, malware analysis. Experience with M365, Azure and AWS. Ability to investigate Virtual Machines, Cloud Trail, IAM logs. Utilize state-of-the-art technologies such as EDR, SEIM, and full packet capture to perform hunt and investigative activity to examine endpoint and network-based activity. Accepted certifications; SANS GIAC: GCIH, GCFA, GCFE, GREM, GISF, GXPN, GCTI, GOSI, EnCase (EnCE, CFSR, ENCEP)
Page | 20
The Contractor shall submit a draft Quality Assurance and Surveillance Plan (QASP) with the proposal that at a minimum, describes the process, details, and schedule for providing ongoing quality assurance to ensure that the requirements of the contract are satisfied. The plan shall include methods for identifying, resolving and preventing deficiencies in the quality and timeliness of services performed under this contract to ensure the level of performance meets the contract requirements.
The QASP shall consist of the following information:
• A description of the review/audit process, its documentation, methods of internal review, identification of staff position(s) performing the reviews, and the frequency of the reviews.
• A description of the approach and procedures for communicating with the NCUA;
handling corrective actions; and identifying and implementing potential improvements to the program services.
• A process for project tracking in terms of the deliverables identified in the proposal.
• A description of the performance requirements for each phase of the project and/or labor category.
• A description of the performance objective for each Performance Standard.
• A description of the quantifiable Acceptable Level of Performance for each
Performance Standard.
• A description of the method of surveillance including who will perform the surveillance, the frequency, and the process for accomplishing the surveillance.
4.7 NON-DISCLOSURE
The Contractor shall be required to execute a non-disclosure agreement that will be applicable to all employees working on this contract. The NDA shall be provided at contract award.
4.8 GOVERNMENT-FURNISHED EQUIPMENT AND
INFORMATION
The NCUA shall provide the personnel, furniture, workstation hardware, software, and all necessary building utilities for the Contractor team assigned on government site. NCUA shall provide workstations, mobile devices as applicable, network accounts, appropriate system accesses.
4.9 SERVICE LEVEL AGREEMENTS
Service Level Agreements (SLAs) are a contractual tool that establish the level of performance expected of the Contractor on a given task as agreed to between the Contractor and NCUA. Although the Contractor is required to be fully compliant with all requirements of this SOW, the SLAs help define acceptable levels of compliance. They are intended to measure how well the key aspects of the SOW are carried out.
The contractor shall provide a baseline Service Level Agreement (SLA) agreed on by the Government that ensures delivery of resilient information security services. A draft SLA is attached to this SOW (Attachment 1) This baseline shall be matured over the life of the
Page | 21 contract based on the target maturity level attributes associated with repeatable and resilient services. Of note, the SLA baseline shall have plans and trend data maintained and reported to ensure continuous improvement toward maturity targets. The Contractor shall, at a minimum report monthly on SLAs and in coordination with NCUA, evaluate the effectiveness of the SLAs to modify, develop, and implement more effective SLAs.
5. TRANSITION IN AND TRANSITION OUT PLAN
5.1 TRANSITION IN PLAN
The following relates to and from an existing (incumbent) contractor subsequent to the award of this contract should a transition be necessary. Activities related to transition shall be conducted over a period of approximately one month.
This is the start of the file's text. The full file is on GovTribe.
File details come from the government source that posted it. Updated .