EDR_Requirements_Final RFI Ver 1.xlsx
XLSX spreadsheet 23 KB Posted
- Attached to
- End Point and Detection (EDR) Software RFI Federal contract opportunity
- Solicitation number
- ITSO220086
- Issued by
- Administrative Office of the U.S. Courts
View the file
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
Instructions Instructions to Offerors
1. In Column B, cell B1 please enter the name of the software solution.
| 2. Please enter how the software is sold in Column B, cell B2 (i.e. Open Market, NASA SEWP, GSA MAS, license structure), Please enter all that apply. |
| 3. In Column E use the drop down boxes to indicate yes if the software solution meets the requirement specified in Column D or no if the software does not meet the requirement. In Column F provide a detailed description of how the software solution meets the requirement in Column D. |
Requirements List
| Solution Name: | ||||||
| How is the solution sold: | ||||||
| Requirement Number | Requirement Area | Requirement Title | Requirement(s) - The software licenses provided shall be able to meet all of the following requirements: | Supported | ||
| (YES/NO) | Describe in detail how the proposed product meets the requirements. | |||||
| 1 | Management | Software as a Service (SAS) | 1. The solution must be FedRAMP level moderate approved. FedRAMP provides a standardized approach to security assessment, authorization, and continuous monitoring for cloud products and services used by the US government. | 1. Add answer here. | ||
| 2 | Management | Storage | 1. The solution must provide at least 14 days of recorded host activity for searching by threat hunt teams. |
2. The recorded activity must be able to identify the processes that resulted in the activity that was searched for (e.g. the process that initiated the DNS request) even if recorded activity did not result in a detection. The recorded activity is for "look-back" analysis.
1. Add answer here.
2. Add answer here.
3 Management Access Control 1. The solution must provide role based hiearchical access control so that data associated with one domain is not visible or accessible to another domain.
2. An administrator that has global authorization to all collected data (independent of the domain of origin) is required.
1. Add answer here.
2. Add answer here.
| 4 | Management | Rollback | 1. The solution must have the ability to "roll back" (i.e. reverse) policy changes or faulty detections without requiring an interruption in service to end users. | 1. Add answer here. | |
| 5 | Agent | Platform Support | 1. 7500 Agents that support Windows, Linux (RHEL 6 and later) and MAC OS X laptops, desktops, and servers are required. | 1. Add answer here. | |
| 6 | Agent | Platform Limitations | 1. The feature limitations of Linux agents (if any) must be clearly defined. | 1. Add answer here. | |
| 7 | Agent | VDI Support | 1. The solution must support agents for Virtual Desktop Infrastructure (VDI) environments. | 1. Add answer here. | |
| 8 | Agent | Tracing | 1. The solution must provide historical and real-time visibility into all code execution. | 1. Add answer here. | |
| 9 | Solution | Data Accessibility | 1. The solution must provide historical data even when the endpoint is no longer powered on. | 1. Add answer here. | |
| 10 | Solution | Scheduled Automated Indicator Sweeps | 1. The solution must provide scheduled automated indicator sweeps based on integrated threat intelligence feeds even if the endpoints are not connected. | 1. Add answer here. | |
| 11 | Solution | Customer Supplied Yara Rules | 1. The solution must support custom, “scheduled” indicator sweeps using customer supplied YARA rules and/or sweeps by filename, process name or hash even f the endpoints are not connected. | 1. Add answer here. | |
| 12 | Solution | AV | 1. The solution must not interfere with or require the disablement of Trend Micro Apex One anti malware solutions. | 1. Add answer here. | |
| 13 | Solution | Quarantine | 1. The solution must have the ability to quarantine selected or unhealthy endpoints by blocking network communications to everything except an administrator configurable group of hosts. | 1. Add answer here. | |
| 14 | Solution | IOC / IOA storage | 1. The solution must store indicator of compromise (IOC)/indicator of attack (IOA) data in a central location for retrospective analysis | 1. Add answer here. | |
| 15 | Solution | Detections based on Process Behaviour | 1. The solution must have a facility to detect malicious activity based on the behavior of a process. | 1. Add answer here. | |
| 16 | Solution | Known and Unknown Malware | 1. The solution must protect against known and unknown malware without relying on daily agent/definition updates. | 1. Add answer here. | |
| 17 | Reporting | Process Tree View | 1. The solution must include a view that displays a full process tree to identify process spawning for root cause analysis. | 1. Add answer here. | |
| Column1 | |||||
| Yes | |||||
| No |
File details come from the government source that posted it. Updated .