BNJ_CORE_Insight_Acquisition__15_May_2017__JCW_signed_Final.pdf

PDF 403 KB Posted

Attached to
CORE Insight Federal contract opportunity
Solicitation number
ED-FSA-17-Q-0014
Issued by
Department of Education Office of Federal Student Aid

View the file

Other files for this federal contract opportunity

Other files attached to CORE Insight, newest first.
File Type Posted
CORE_Insight_Solicitation_Vendor_Questions_and_Answers.docx DOCX document
CORE_Insight_Pricing_Sheet.xlsx XLSX spreadsheet
RFQ_CORE_Insight__15_May_2017_JCW.docx DOCX document

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

Brand Name Justification Department of Education - Federal Student Aid

CORE Insight Software License and Maintenance Support Services

1. Identification of the agency and the contracting activity.

The United States Department of Education (DoED), Federal Student Aid (FSA) Acquisitions, proposes to solicit and award a Contract for Core Insight software license and maintenance support. This software license and Maintenance (renewal) product is a brand name justification (BNJ) prepared in accordance with the criteria stated in FAR Part 13.501(a)(1)(ii) & FAR Part 6.303-2.

2. Nature and/or description of the action being approved.

Acquisition/renewal of CORE Insight software license and maintenance support. The purpose of the (renewal) of the existing Core Insight Software license and Maintenance support Acquisition is required to fulfill the mandated regulatory requirements and address continuous monitoring to provide real time investigation and tracking of vulnerabilities and alerting to threats and attacks against the FSA Enterprise. The Remote Auditors are used by the FSA SOC to perform the following:

Validation of vulnerability data from multiple sources

Pinpoint exposures and know how an attacker can reach our critical assets

Trace attack paths across multiple vectors

Demonstrate how attackers can chain vulnerabilities across vectors to move through our environment

Measure the impact of remediation efforts

Compare and track results over time

3. A description of the supplies or services required to meet the agency’s needs

(including the estimated value).

FSA requires the following software license and Maintenance products/service for a period of performance of 6/27/2017 to 6/26/2018:

Part # Part Description Quantity GVT-C103M01Y CORE Impact Pro Unlimited 1

IP Count, 3 Machine 1YR Subscription License

GVT-CIE-Maint CORE Insight Maintenance - Annual 1 -10000 Maintenance – 10,000 Targets

GVT-Maint – CORE Maintenance for Remote 2 Auditor –P Auditors

Estimated value for base year service is $104,234.00

Option Year One 6/27/2018 – 6/26/2019 $104,234.00 Option Year Two 6/27/2019 – 6/26/2020 $104,234.00 Option Year Three 6/27/2020 – 6/26/2021 $104,234.00

Total Estimated Value Base and Option Years $416,936.00

The Contracting Officer intends to award a firm fixed-price contract.

4. An identification of the statutory authority and supporting rationale.

41 USC 1901 – Simplified Acquisition Procedures

5. A demonstration that the proposed contractor’s unique qualifications or the nature of the acquisition requires use of the authority cited.

Core Impact is a solution for assessing and testing security vulnerabilities throughout an organization. Core Impact replicates attacks that pivot across systems, devices, and applications, while revealing how chains of exploitable vulnerabilities open paths to an organization’s mission-critical systems and data.

Core Impact gives visibility into the effectiveness of endpoint defenses and reveals where pressing risks exist across a network. This enables organizations to detect, prevent, and respond to real-world, multi-staged threats.

Features:

Replicates attacks across all systems, reveals the exploited vulnerability, and allows to remediate the risk immediately.

Pen-testing capabilities that allow to test all workstations for various vulnerabilities, in addition to gauging the effectiveness of anti-virus, HIPS, and other perimeter defenses.

Evaluates security posture using the same techniques employed by today’s cyber-criminals. Users can re-test exploited systems months after a pen-test, and agents can be upgraded through this feature.

Endpoint systems tested with commercial-grade client-side exploits in a controlled manner using a simple interface. Through network testing, this solution gathers network information and performs attacks to test the systems’ ability to identify and remediate.

Core Impact can import and validate the exploitability of results from many other network and web vulnerability scanners.

Core Vulnerability Insight

Core Vulnerability Insight unifies, regulates, and prioritizes vulnerability management initiatives enterprise-wide. It consolidates multiple vulnerability scans across vendors, while matching known exploits and simulating attacks, enables to focus on the most vulnerable points of a network.

With greater scalability and advanced attack path analytics, Core Insight helps to accurately identify the vulnerabilities that pose the greatest threat to critical business assets, regardless of the size and complexity of your IT landscape. Once critical vulnerabilities are prioritized, you can move quickly to remediate the threat in your systems.

Features:

Single occurrence asset stores for fast data import, analytics, and queries with pre-defined connectors to popular vulnerability assessment solutions.

Demonstrate how attackers can chain vulnerabilities across vectors to move through your environment and consider all possible exploits, including “in-the-wild,” private, theoretical, wormified, virus, and malware.

Reveal specific assets and exposed resources while validating systems and devices that may lead to critical business assets.

Customize with templates and share granular filtering, grouping, and configuration of large amounts of data that measure the effectiveness of remediation efforts, compare, and track results over time.

Advantages of CORE vs Competitors

Replicate attacker attempts to access and manipulate data for use in possible training and learning lessons.

Use client-side exploits to test endpoint system security, assess defenses, and pivot to network test.

Validates compliance with government and industry regulations.

Identifies critical exposures posed by mobile devices on your network.

Includes remote auditors.

6. A description of efforts made to ensure that offers are solicited from as many potential sources as is practicable, including whether a notice was or will be publicized as required by Subpart 5.2 and, if not, which exception under 5.202 applies.

https://acquisition.gov/far/current/html/Subpart%205_2.html#wp1107980 https://acquisition.gov/far/current/html/Subpart%205_2.html#wp1107990

Market research has identified a sufficient number of resellers (listed below) to ensure adequate competition. The solicitation will be publicized on FedBizOpps to allow maximum amount of resellers the opportunity to submit quotes. See below:

Vendors

IT Federal Sales Dan Hooper dhooper@itfedsales.com 603-560-3330 Fax: 888-840-8253

RedHawk IT James Hawkins James.Hawkins@RedHawkIT.com 703-490-9192

Carahsoft Technologies David Niedfeldt David.Niedfeldt@Carahsoft.com 703.889.9868

7. A determination by the contracting officer that the anticipated cost to the Government will be fair and reasonable.

CORE Insight services are available on the open market. With adequate competition amongst resellers and comparison to historical pricing paid, the Contracting Officer will determine the price is fair and reasonable.

8. A description of the market research conducted among schedule holders and the results or a statement of the reason market research was not conducted.

Market research was limited to authorized resellers of CORE Insight services, identified under GSA Schedule.

9. Any other facts supporting the justification.

None.

10. A listing of the sources, if any, that expressed, in writing, an interest in the acquisition.

mailto:dhooper@itfedsales.com mailto:James.Hawkins@RedHawkIT.com mailto:David.Niedfeldt@Carahsoft.com

11. A statement of the actions, if any, the agency may take to remove or overcome any barriers that led to the restricted consideration before any subsequent acquisition for the supplies or services is made.

12. Certification.

This justification is accurate and complete to the best of my knowledge and belief. The requiring FSA program office has provided written supporting data, which is contained in the contract file, that verifies the technical requirements and support the government ongoing need to use the aforementioned brand name commercial items.

John Williams Date Contracts Specialists US Department of Education Federal Student Aid

John.Williams Typewritten Text 18 May 2017

John.Williams Typewritten Text

2017-05-18T09:56:07-0400
John Williams

File details come from the government source that posted it. Updated .