BNJ_CORE_Insight_Acquisition__15_May_2017__JCW_signed_Final.pdf
PDF 403 KB Posted
- Attached to
- CORE Insight Federal contract opportunity
- Solicitation number
- ED-FSA-17-Q-0014
View the file
Other files for this federal contract opportunity
| File | Type | Posted |
|---|---|---|
| CORE_Insight_Solicitation_Vendor_Questions_and_Answers.docx | DOCX document | |
| CORE_Insight_Pricing_Sheet.xlsx | XLSX spreadsheet | |
| RFQ_CORE_Insight__15_May_2017_JCW.docx | DOCX document |
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
Brand Name Justification Department of Education - Federal Student Aid
CORE Insight Software License and Maintenance Support Services
1. Identification of the agency and the contracting activity.
The United States Department of Education (DoED), Federal Student Aid (FSA) Acquisitions, proposes to solicit and award a Contract for Core Insight software license and maintenance support. This software license and Maintenance (renewal) product is a brand name justification (BNJ) prepared in accordance with the criteria stated in FAR Part 13.501(a)(1)(ii) & FAR Part 6.303-2.
2. Nature and/or description of the action being approved.
Acquisition/renewal of CORE Insight software license and maintenance support. The purpose of the (renewal) of the existing Core Insight Software license and Maintenance support Acquisition is required to fulfill the mandated regulatory requirements and address continuous monitoring to provide real time investigation and tracking of vulnerabilities and alerting to threats and attacks against the FSA Enterprise. The Remote Auditors are used by the FSA SOC to perform the following:
Validation of vulnerability data from multiple sources
Pinpoint exposures and know how an attacker can reach our critical assets
Trace attack paths across multiple vectors
Demonstrate how attackers can chain vulnerabilities across vectors to move through our environment
Measure the impact of remediation efforts
Compare and track results over time
3. A description of the supplies or services required to meet the agency’s needs
(including the estimated value).
FSA requires the following software license and Maintenance products/service for a period of performance of 6/27/2017 to 6/26/2018:
Part # Part Description Quantity GVT-C103M01Y CORE Impact Pro Unlimited 1
IP Count, 3 Machine 1YR Subscription License
GVT-CIE-Maint CORE Insight Maintenance - Annual 1 -10000 Maintenance – 10,000 Targets
GVT-Maint – CORE Maintenance for Remote 2 Auditor –P Auditors
Estimated value for base year service is $104,234.00
Option Year One 6/27/2018 – 6/26/2019 $104,234.00 Option Year Two 6/27/2019 – 6/26/2020 $104,234.00 Option Year Three 6/27/2020 – 6/26/2021 $104,234.00
Total Estimated Value Base and Option Years $416,936.00
The Contracting Officer intends to award a firm fixed-price contract.
4. An identification of the statutory authority and supporting rationale.
41 USC 1901 – Simplified Acquisition Procedures
5. A demonstration that the proposed contractor’s unique qualifications or the nature of the acquisition requires use of the authority cited.
Core Impact is a solution for assessing and testing security vulnerabilities throughout an organization. Core Impact replicates attacks that pivot across systems, devices, and applications, while revealing how chains of exploitable vulnerabilities open paths to an organization’s mission-critical systems and data.
Core Impact gives visibility into the effectiveness of endpoint defenses and reveals where pressing risks exist across a network. This enables organizations to detect, prevent, and respond to real-world, multi-staged threats.
Features:
Replicates attacks across all systems, reveals the exploited vulnerability, and allows to remediate the risk immediately.
Pen-testing capabilities that allow to test all workstations for various vulnerabilities, in addition to gauging the effectiveness of anti-virus, HIPS, and other perimeter defenses.
Evaluates security posture using the same techniques employed by today’s cyber-criminals. Users can re-test exploited systems months after a pen-test, and agents can be upgraded through this feature.
Endpoint systems tested with commercial-grade client-side exploits in a controlled manner using a simple interface. Through network testing, this solution gathers network information and performs attacks to test the systems’ ability to identify and remediate.
Core Impact can import and validate the exploitability of results from many other network and web vulnerability scanners.
Core Vulnerability Insight
Core Vulnerability Insight unifies, regulates, and prioritizes vulnerability management initiatives enterprise-wide. It consolidates multiple vulnerability scans across vendors, while matching known exploits and simulating attacks, enables to focus on the most vulnerable points of a network.
With greater scalability and advanced attack path analytics, Core Insight helps to accurately identify the vulnerabilities that pose the greatest threat to critical business assets, regardless of the size and complexity of your IT landscape. Once critical vulnerabilities are prioritized, you can move quickly to remediate the threat in your systems.
Features:
Single occurrence asset stores for fast data import, analytics, and queries with pre-defined connectors to popular vulnerability assessment solutions.
Demonstrate how attackers can chain vulnerabilities across vectors to move through your environment and consider all possible exploits, including “in-the-wild,” private, theoretical, wormified, virus, and malware.
Reveal specific assets and exposed resources while validating systems and devices that may lead to critical business assets.
Customize with templates and share granular filtering, grouping, and configuration of large amounts of data that measure the effectiveness of remediation efforts, compare, and track results over time.
Advantages of CORE vs Competitors
Replicate attacker attempts to access and manipulate data for use in possible training and learning lessons.
Use client-side exploits to test endpoint system security, assess defenses, and pivot to network test.
Validates compliance with government and industry regulations.
Identifies critical exposures posed by mobile devices on your network.
Includes remote auditors.
6. A description of efforts made to ensure that offers are solicited from as many potential sources as is practicable, including whether a notice was or will be publicized as required by Subpart 5.2 and, if not, which exception under 5.202 applies.
https://acquisition.gov/far/current/html/Subpart%205_2.html#wp1107980 https://acquisition.gov/far/current/html/Subpart%205_2.html#wp1107990
Market research has identified a sufficient number of resellers (listed below) to ensure adequate competition. The solicitation will be publicized on FedBizOpps to allow maximum amount of resellers the opportunity to submit quotes. See below:
Vendors
IT Federal Sales Dan Hooper dhooper@itfedsales.com 603-560-3330 Fax: 888-840-8253
RedHawk IT James Hawkins James.Hawkins@RedHawkIT.com 703-490-9192
Carahsoft Technologies David Niedfeldt David.Niedfeldt@Carahsoft.com 703.889.9868
7. A determination by the contracting officer that the anticipated cost to the Government will be fair and reasonable.
CORE Insight services are available on the open market. With adequate competition amongst resellers and comparison to historical pricing paid, the Contracting Officer will determine the price is fair and reasonable.
8. A description of the market research conducted among schedule holders and the results or a statement of the reason market research was not conducted.
Market research was limited to authorized resellers of CORE Insight services, identified under GSA Schedule.
9. Any other facts supporting the justification.
None.
10. A listing of the sources, if any, that expressed, in writing, an interest in the acquisition.
mailto:dhooper@itfedsales.com mailto:James.Hawkins@RedHawkIT.com mailto:David.Niedfeldt@Carahsoft.com
11. A statement of the actions, if any, the agency may take to remove or overcome any barriers that led to the restricted consideration before any subsequent acquisition for the supplies or services is made.
12. Certification.
This justification is accurate and complete to the best of my knowledge and belief. The requiring FSA program office has provided written supporting data, which is contained in the contract file, that verifies the technical requirements and support the government ongoing need to use the aforementioned brand name commercial items.
John Williams Date Contracts Specialists US Department of Education Federal Student Aid
John.Williams Typewritten Text 18 May 2017
John.Williams Typewritten Text
| 2017-05-18T09:56:07-0400 | |
| John Williams |
File details come from the government source that posted it. Updated .