EDR_Requirements_Final RFI Ver 1.xlsx

XLSX spreadsheet 23 KB Posted

Attached to
End Point and Detection (EDR) Software RFI Federal contract opportunity
Solicitation number
ITSO220086
Issued by
Administrative Office of the U.S. Courts

View the file

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

Instructions Instructions to Offerors

1. In Column B, cell B1 please enter the name of the software solution.

2. Please enter how the software is sold in Column B, cell B2 (i.e. Open Market, NASA SEWP, GSA MAS, license structure), Please enter all that apply.
3. In Column E use the drop down boxes to indicate yes if the software solution meets the requirement specified in Column D or no if the software does not meet the requirement. In Column F provide a detailed description of how the software solution meets the requirement in Column D.

Requirements List

Solution Name:
How is the solution sold:
Requirement NumberRequirement AreaRequirement TitleRequirement(s) - The software licenses provided shall be able to meet all of the following requirements:Supported
(YES/NO)Describe in detail how the proposed product meets the requirements.
1ManagementSoftware as a Service (SAS)1. The solution must be FedRAMP level moderate approved. FedRAMP provides a standardized approach to security assessment, authorization, and continuous monitoring for cloud products and services used by the US government.1. Add answer here.
2ManagementStorage1. The solution must provide at least 14 days of recorded host activity for searching by threat hunt teams.

2. The recorded activity must be able to identify the processes that resulted in the activity that was searched for (e.g. the process that initiated the DNS request) even if recorded activity did not result in a detection. The recorded activity is for "look-back" analysis.

1. Add answer here.

2. Add answer here.

3 Management Access Control 1. The solution must provide role based hiearchical access control so that data associated with one domain is not visible or accessible to another domain.

2. An administrator that has global authorization to all collected data (independent of the domain of origin) is required.

1. Add answer here.

2. Add answer here.

4ManagementRollback1. The solution must have the ability to "roll back" (i.e. reverse) policy changes or faulty detections without requiring an interruption in service to end users.1. Add answer here.
5AgentPlatform Support1. 7500 Agents that support Windows, Linux (RHEL 6 and later) and MAC OS X laptops, desktops, and servers are required.1. Add answer here.
6AgentPlatform Limitations1. The feature limitations of Linux agents (if any) must be clearly defined.1. Add answer here.
7AgentVDI Support1. The solution must support agents for Virtual Desktop Infrastructure (VDI) environments.1. Add answer here.
8AgentTracing1. The solution must provide historical and real-time visibility into all code execution.1. Add answer here.
9SolutionData Accessibility1. The solution must provide historical data even when the endpoint is no longer powered on.1. Add answer here.
10SolutionScheduled Automated Indicator Sweeps1. The solution must provide scheduled automated indicator sweeps based on integrated threat intelligence feeds even if the endpoints are not connected.1. Add answer here.
11SolutionCustomer Supplied Yara Rules1. The solution must support custom, “scheduled” indicator sweeps using customer supplied YARA rules and/or sweeps by filename, process name or hash even f the endpoints are not connected.1. Add answer here.
12SolutionAV1. The solution must not interfere with or require the disablement of Trend Micro Apex One anti malware solutions.1. Add answer here.
13SolutionQuarantine1. The solution must have the ability to quarantine selected or unhealthy endpoints by blocking network communications to everything except an administrator configurable group of hosts.1. Add answer here.
14SolutionIOC / IOA storage1. The solution must store indicator of compromise (IOC)/indicator of attack (IOA) data in a central location for retrospective analysis1. Add answer here.
15SolutionDetections based on Process Behaviour1. The solution must have a facility to detect malicious activity based on the behavior of a process.1. Add answer here.
16SolutionKnown and Unknown Malware1. The solution must protect against known and unknown malware without relying on daily agent/definition updates.1. Add answer here.
17ReportingProcess Tree View1. The solution must include a view that displays a full process tree to identify process spawning for root cause analysis.1. Add answer here.
Column1
Yes
No

File details come from the government source that posted it. Updated .