E-DLP Proof of Concept Objectives v6-3.pdf

PDF 544 KB Posted

Attached to
Enterprise Data Loss Prevention (E-DLP) Federal contract opportunity
Solicitation number
FA877320R0003
Issued by
Department of the Air Force Space Command

About this file

This document contains a Statement of Objectives (SOO) for an Enterprise Data Loss Prevention (E-DLP) Proof of Concept (POC) opportunity with the Department of the Air Force Space Command. The Air Force seeks a vendor to conduct an E-DLP POC at a single Air Force base involving at least 100 users, multiple data owners, and representation of all main data egress points, including applying DLP capabilities to on-premises and cloud data at rest, in transit, and in use. The POC must also demonstrate the ability to aggregate and correlate alerts across multiple networks/classifications using a cross domain solution. The SOO outlines eight objectives for the POC, including identifying sensitive information, establishing relevant policies, assessing capability requirements, employment training, and deployment to endpoints, networks, storage, and cloud applications and storage. Offerors must submit any questions by 26 May 2020 and quotes are due by 16 June 2020 in response to Solicitation FA877320R0003.

View the file

Other files for this federal contract opportunity

Other files attached to Enterprise Data Loss Prevention (E-DLP), newest first.
File Type Posted
DD Form 254 Solicitation_JBSA 27 August 2020.pdf PDF
DD Form 1423 - A001 E-DLP POC POAM 18 Aug 20.pdf PDF
Rev 4 E-DLP Pricing Matrix.xlsx XLSX spreadsheet
E-DLP Proof of Concept Objectives -Final 18 August 2020.pdf PDF
DD Form 1423 - A002 E-DLP POC Burndown Rate 18 Aug 20.pdf PDF
DD Form 1423 - A005 E-DLP POC Training Plan 18 Aug 20.pdf PDF
DD Form 254 Solicitation_JBSA.pdf PDF
Attach 7 Additional Representations.pdf PDF
DD Form 1423 - A004 E-DLP POC Security Plan 18 Aug 20.pdf PDF
DD Form 1423 - A003 E-DLP POC Weekly Status Report 18 Aug 20.pdf PDF
Rev 4 Enterprise Data Loss Prevention Combined Synopsis Solicitation 18 August 2020.pdf PDF
Rev 3 Enterprise Data Loss Prevention Combined Synopsis Solicitation.pdf PDF
DD Form 1423 - A002 E-DLP POC Burndown Rate.pdf PDF
DD Form 254 Solicitation.pdf PDF
DD Form 1423 - A003 E-DLP POC Weekly Status Report.pdf PDF
E-DLP questions and answers.xlsx XLSX spreadsheet
Langley NIPR - Annotated CHES.pdf PDF
DD Form 1423 - A001 E-DLP POC POAM.pdf PDF
E-DLP Proof of Concept Objectives v7-3.pdf PDF
DD Form 1423 - A005 E-DLP POC Training Plan.pdf PDF
Rev 2 E-DLP Pricing Matrix.xlsx XLSX spreadsheet
DD Form 1423 - A004 E-DLP POC Security Plan.pdf PDF
Rev 2 Enterprise Data Loss Prevention Combined Synopsis Solicitation.pdf PDF
Rev 1 Enterprise Data Loss Prevention Combined Synopsis Solicitation.pdf PDF
E-DLP Clauses and Provisions .pdf PDF
E-DLP Pricing Matrix.xlsx XLSX spreadsheet
Enterprise Data Loss Prevention Combined Synopsis Solicitation.pdf PDF
E-DLP question and answer template.xlsx XLSX spreadsheet
Show all 28

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

Statement of Objectives (SOO)

Enterprise Data Loss Prevention Proof of Concept

Problem: The United States Air Force does not have an Enterprise Data Loss Prevention

Program. We do not have the requisite policies, organization, training, or equipment to empower data owners and users to effectively secure all Air Force sensitive data. Instead, we implement point solutions employed by IT professionals rather than data owners based on specific use cases such as protecting operational security information, personally identifiable information, and network indicators like diagrams and user credentials. These point solutions are not integrated and are operated by various organizations.

For the purpose of this POC, we adopt the following description of E-DLP:

Enterprise DLP solutions offer a centralized policy management and reporting service that defines, disseminates and monitors DLP policies across one or more deployment scenarios such as endpoint, network, discovery and cloud. Enterprise DLP solutions incorporate advanced content inspection techniques to identify even the most complex of content and apply remediation. Enterprise DLP solutions provide a broad and very flexible deployment solution set that is applicable to many diverse use cases including regulatory compliance, internal policy compliance and intellectual property protection.

Proof of Concept: Because the Air Force is unfamiliar with the practical application of current market E-DLP technologies and the supporting policies, organization and training to create an effective E-DLP program, we are seeking a vendor to conduct a Proof of Concept at a single Air

Force Base. The full scope of the POC will be determined once the vendor is selected, but we prefer that it include at least 100 users, multiple data owners, and be representative of all the main egress points for data from that Air Force Base (e.g., endpoint, email, network, cloud, storage) and apply DLP capabilities to data at rest on-premises or in cloud applications and cloud storage, in transit, and in use. The POC will also demonstrate the ability to aggregate and correlate alerting across multiple networks/classifications (e.g., NIPR, SIPR, JWICS) using a Cross

Domain Solution.

This will not be limited to a technology demonstration. It will also include developing the requisite policies to support holistic employment of E-DLP. Additionally, we will seek ways to best organize and train our IT Airmen and data owners and users to effectively employ E-DLP capabilities. Taken together, these are the functions that would comprise a comprehensive, effective AF E-DLP Program.

Where possible, we seek to leverage existing investments and organizations to build an AF E-

DLP program. Our preferred operating model is government owned, government operated.

The proof of concept would recommend options to retire, replace, and/or consolidate existing

AF DLP-related capabilities.

Objectives:

1. Identify AF sensitive information

a. Ability to automatically detect, assess, and classify sensitive content using content-aware detection techniques such as: partial and exact data matching, structured data fingerprinting, statistical analysis, extended regular expression matching, and conceptual and lexicon analysis, image recognition, optical character recognition, forms recognition and others.

b. Support the detection of sensitive data content in structured, unstructured, and semi-structured data, using registered or described data definitions

c. Encrypted traffic management providing Secure Socket Layer (SSL) and Transport

Layer Security (TLS) visibility (break/inspect).

d. Use of machine learning to detect content

e. Information fingerprinting, metadata matching, machine learning

f. Enable Data Owners/Users to tag/classify their information

g. Maintain tagging persistency as files safe renamed, copied and pasted, converted to another file type, archived, and encrypted

2. Establish relevant E-DLP Program Policies and recommend changes to those policies

a. SAF (CN, CO, CDM)

b. MAJCOM

c. 16AF/AFCYBER

d. Base-level

3. E-DLP Capability Requirements

a. Provides a single centralized management console for all sensors

b. Includes event management workflow and reporting

c. Supports advanced policy definition and ability to deploy use for all endpoints, in storage, in motion, or a selected combination

d. Enables Organization’s Data Owner to make risk decision on data loss for data in use, data at rest, and data in motion

e. Allows for full remediation policy options: report/warn, allow, exception, redact, tokenize, move, protect/encrypt, forbid/block, quarantine

f. Hybrid on-premises and cloud-based E-DLP solution

g. Adds contextualization by incorporating externally sourced data to create a more complete view of the risks surrounding individual events

h. High integration with other technical threat detection capabilities like Endpoint

Detection and Response (EDR) and User-Entity Behavior Analytics (UEBA) for improved unified data threat prevention

i. Ability to integrate into security information and event management (SIEM)

j. Ability to scale solution to the AFIN

k. Can be used on Windows, Linux, or Mac OS X

l. Must not require integration into another product for functionality

4. E-DLP Employment

a. Provide IT and Data Owner/User Training for 100 users

b. Demonstrate E-DLP capability to identify content, assess data, and protect data across multiple organizations and across distinctly different data sets

c. Demonstrate E-DLP capability via data owner’s desired policy remediation options in 5e on-premises and cloud data at rest (file shares, database, endpoints), in motion over the network (email, share point posting, web posting, network traffic, cloud) and in use (email, IM, cloud apps, removable devices?).

d. Demonstrate an ability to scale solution

e. Continue to refine policies in Objective 2.

f. Recommend options to retire, replace, and/or consolidate existing AF DLP-related capabilities.

5. EDLP Employment Endpoint

a. Detect, assess, and classify data in use and storage using content-aware detection techniques such as: partial and exact data matching, structured data fingerprinting, statistical analysis, extended regular expression matching, and conceptual and lexicon analysis, image recognition, optical character recognition, forms recognition, and others.

b. Demonstrate the ability to aggregate and correlate alerting across multiple networks/classifications (e.g., NIPR, SIPR, JWICS) using a Cross Domain Solution.

c. Must be able to detect the following file types: CAD, .pdf, .xls, .doc, .txt, .jpg, ….

d. Ability to perform internal content analysis.

e. Ability to be employed on the following operating systems.

i. Linux,

ii. Macintosh OS,

iii. MS-DOS,

iv. Windows 98,

v. Windows 2000,

vi. Windows 10

f. Mobile devices such as IOS, Blackberry, Android, Microsoft-based laptops, tablets, phones

g. Printers

h. Virtual machines

i. Email

j. Browser

k. Removable devices

l. User roles within DLP policies

m. Ability for user to take action that is user driven and customizable when sensitive data is found

6. EDLP Employment Network

a. Detect, assess and classify data in motion

b. Email, webmail

c. Web, http/https

d. IM

7. EDLP Employment Storage

a. Detect, assess and classify data at rest

b. File servers

c. Databases

d. Share point

e. NAS

8. EDPL Employment Cloud

a. Data in use and at rest

b. Cloud apps

c. Storage

d. Future WS

e. Microsoft’s cloud based email

File details come from the government source that posted it. Updated .