E-DLP Proof of Concept Objectives v6-3.pdf
PDF 544 KB Posted
- Attached to
- Enterprise Data Loss Prevention (E-DLP) Federal contract opportunity
- Solicitation number
- FA877320R0003
About this file
This document outlines objectives for an Enterprise Data Loss Prevention (E-DLP) proof of concept project for the United States Air Force. The Air Force seeks to conduct a proof of concept with a vendor to deploy an E-DLP solution at a single Air Force base including at least 100 users across multiple data types and egress points such as endpoints, email, network, cloud storage and applications. The objectives include requirements to identify and classify sensitive Air Force information using various detection techniques including machine learning, establish E-DLP program policies and organizational structure, define E-DLP capability and deployment requirements, provide user training, and demonstrate the solution's ability to protect data at rest, in motion and in use across different computing environments and classifications. Successful vendors must also be able to integrate with the Air Force's existing security tools and scale to the entire Air Force network. The proof of concept aims to evaluate current E-DLP technologies and recommend options for consolidating or replacing existing Air Force DLP capabilities as part of a comprehensive E-DLP program.
View the file
Other files for this federal contract opportunity
| File | Type | Posted |
|---|---|---|
| RFI Response Form.docx | DOCX document | |
| E-DLP REQUEST FOR INFORMATION .pdf |
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
Statement of Objectives (SOO)
Enterprise Data Loss Prevention Proof of Concept
Problem: The United States Air Force does not have an Enterprise Data Loss Prevention
Program. We do not have the requisite policies, organization, training, or equipment to empower data owners and users to effectively secure all Air Force sensitive data. Instead, we implement point solutions employed by IT professionals rather than data owners based on specific use cases such as protecting operational security information, personally identifiable information, and network indicators like diagrams and user credentials. These point solutions are not integrated and are operated by various organizations.
For the purpose of this POC, we adopt the following description of E-DLP:
Enterprise DLP solutions offer a centralized policy management and reporting service that defines, disseminates and monitors DLP policies across one or more deployment scenarios such as endpoint, network, discovery and cloud. Enterprise DLP solutions incorporate advanced content inspection techniques to identify even the most complex of content and apply remediation. Enterprise DLP solutions provide a broad and very flexible deployment solution set that is applicable to many diverse use cases including regulatory compliance, internal policy compliance and intellectual property protection.
Proof of Concept: Because the Air Force is unfamiliar with the practical application of current market E-DLP technologies and the supporting policies, organization and training to create an effective E-DLP program, we are seeking a vendor to conduct a Proof of Concept at a single Air
Force Base. The full scope of the POC will be determined once the vendor is selected, but we prefer that it include at least 100 users, multiple data owners, and be representative of all the main egress points for data from that Air Force Base (e.g., endpoint, email, network, cloud, storage) and apply DLP capabilities to data at rest on-premises or in cloud applications and cloud storage, in transit, and in use. The POC will also demonstrate the ability to aggregate and correlate alerting across multiple networks/classifications (e.g., NIPR, SIPR, JWICS) using a Cross
Domain Solution.
This will not be limited to a technology demonstration. It will also include developing the requisite policies to support holistic employment of E-DLP. Additionally, we will seek ways to best organize and train our IT Airmen and data owners and users to effectively employ E-DLP capabilities. Taken together, these are the functions that would comprise a comprehensive, effective AF E-DLP Program.
Where possible, we seek to leverage existing investments and organizations to build an AF E-
DLP program. Our preferred operating model is government owned, government operated.
The proof of concept would recommend options to retire, replace, and/or consolidate existing
AF DLP-related capabilities.
Objectives:
1. Identify AF sensitive information
a. Ability to automatically detect, assess, and classify sensitive content using content-aware detection techniques such as: partial and exact data matching, structured data fingerprinting, statistical analysis, extended regular expression matching, and conceptual and lexicon analysis, image recognition, optical character recognition, forms recognition and others.
b. Support the detection of sensitive data content in structured, unstructured, and semi-structured data, using registered or described data definitions
c. Encrypted traffic management providing Secure Socket Layer (SSL) and Transport
Layer Security (TLS) visibility (break/inspect).
d. Use of machine learning to detect content
e. Information fingerprinting, metadata matching, machine learning
f. Enable Data Owners/Users to tag/classify their information
g. Maintain tagging persistency as files safe renamed, copied and pasted, converted to another file type, archived, and encrypted
2. Establish relevant E-DLP Program Policies and recommend changes to those policies
a. SAF (CN, CO, CDM)
b. MAJCOM
c. 16AF/AFCYBER
d. Base-level
3. E-DLP Capability Requirements
a. Provides a single centralized management console for all sensors
b. Includes event management workflow and reporting
c. Supports advanced policy definition and ability to deploy use for all endpoints, in storage, in motion, or a selected combination
d. Enables Organization’s Data Owner to make risk decision on data loss for data in use, data at rest, and data in motion
e. Allows for full remediation policy options: report/warn, allow, exception, redact, tokenize, move, protect/encrypt, forbid/block, quarantine
f. Hybrid on-premises and cloud-based E-DLP solution
g. Adds contextualization by incorporating externally sourced data to create a more complete view of the risks surrounding individual events
h. High integration with other technical threat detection capabilities like Endpoint
Detection and Response (EDR) and User-Entity Behavior Analytics (UEBA) for improved unified data threat prevention
i. Ability to integrate into security information and event management (SIEM)
j. Ability to scale solution to the AFIN
k. Can be used on Windows, Linux, or Mac OS X
l. Must not require integration into another product for functionality
4. E-DLP Employment
a. Provide IT and Data Owner/User Training for 100 users
b. Demonstrate E-DLP capability to identify content, assess data, and protect data across multiple organizations and across distinctly different data sets
c. Demonstrate E-DLP capability via data owner’s desired policy remediation options in 5e on-premises and cloud data at rest (file shares, database, endpoints), in motion over the network (email, share point posting, web posting, network traffic, cloud) and in use (email, IM, cloud apps, removable devices?).
d. Demonstrate an ability to scale solution
e. Continue to refine policies in Objective 2.
f. Recommend options to retire, replace, and/or consolidate existing AF DLP-related capabilities.
5. EDLP Employment Endpoint
a. Detect, assess, and classify data in use and storage using content-aware detection techniques such as: partial and exact data matching, structured data fingerprinting, statistical analysis, extended regular expression matching, and conceptual and lexicon analysis, image recognition, optical character recognition, forms recognition, and others.
b. Demonstrate the ability to aggregate and correlate alerting across multiple networks/classifications (e.g., NIPR, SIPR, JWICS) using a Cross Domain Solution.
c. Must be able to detect the following file types: CAD, .pdf, .xls, .doc, .txt, .jpg, ….
d. Ability to perform internal content analysis.
e. Ability to be employed on the following operating systems.
i. Linux,
ii. Macintosh OS,
iii. MS-DOS,
iv. Windows 98,
v. Windows 2000,
vi. Windows 10
f. Mobile devices such as IOS, Blackberry, Android, Microsoft-based laptops, tablets, phones
g. Printers
h. Virtual machines
i. Email
j. Browser
k. Removable devices
l. User roles within DLP policies
m. Ability for user to take action that is user driven and customizable when sensitive data is found
6. EDLP Employment Network
a. Detect, assess and classify data in motion
b. Email, webmail
c. Web, http/https
d. IM
7. EDLP Employment Storage
a. Detect, assess and classify data at rest
b. File servers
c. Databases
d. Share point
e. NAS
8. EDPL Employment Cloud
a. Data in use and at rest
b. Cloud apps
c. Storage
d. Future WS
e. Microsoft’s cloud based email
File details come from the government source that posted it. Updated .