ERAS_Bridge_Justification_Redacted.pdf
PDF 1 MB Posted
- Attached to
- Urgent Sole Source - Trusted Integrator Federal contract opportunity
- Solicitation number
- 15F06723P0002554
About this file
This justification document seeks approval for a sole source contract award to CIS Secure Computing Inc. to provide trusted integrator support services for the Federal Bureau of Investigation's Enterprise Remote Access Solution. The FBI requires these services to maintain critical functionality of its ERAS system, which provides remote access to over 3,420 classified mobile devices, until a new contract can be competitively awarded. CIS Secure is the only company qualified as it is an authorized reseller of Integrity Global Security's proprietary Integrity OS, which is necessary to support the existing ERAS infrastructure. The justification cites unusual and compelling urgency under FAR 6.302-2 to award this stop-gap, 12-month contract on a non-competitive basis due to risks to ongoing FBI operations should remote access be disrupted.
View the file
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
FEDERAL BUREAU OF INVESTIGATION
FINANCE AND FACILITIES DIVISION | PROCUREMENT SECTION
JUSTIFICATION AND APPROVAL (J&A) FOR OTHER THAN
FULL AND OPEN COMPETITION (41 U.S.C. §3304(A)(2))
Requisition Number: DJF-23-2000-PR-0001384
Date: September 28, 2023.
Estimated Contract Dollar Value:
1. Identification of the agency and contracting activity.
The U.S. Department of Justice (DOJ), Federal Bureau of Investigation (FBI), Information Technology Acquisitions Unit (ITAU), has prepared this justification for other than full and open competition for an Enterprise Remote Access Service (ERAS) contract with a Commercial Solutions for Classified (CSfC) Trusted Integrator partnered with Integrity Global Security (IGS) on behalf of the Mobility Program Office (MPO), Information Technology Infrastructure Division
(ITID).
2. The nature and/or description of the action being approved, i.e., sole source, limited competition, establishment of a new source, etc.
The Government contemplates the award of a firm fixed price contract in support of the ERAS ecosystem as a sole source to CIS Secure Computing Inc. (CIS Secure). The period of performance will be for a one (1) year base period. CIS Secure is a CSfC Trusted Integrator that is an authorized reseller of the Integrity Operating System (OS) IGS and capable of performance.
3. A description of the supplies or services required to meet the agency’s needs.
FBI’s Information Technology Infrastructure Division’s (ITID’s) Mobility Program Office (MPO) selected NSA's CSfC Mobility Access Capability Package (MACP) 2.5.1 as the preferred solution for ERAS 3.0 since it utilizes approved cryptographic algorithms and National Information Assurance Partnership (NIAP) evaluated components, which delivers a truly secure mobile communication solution. ERAS 3.0 provides a secure form of mobile communication to the FBI’s enclave (FBINet) for users outside of FBI workspaces, remote offices. ERAS 3.0 also expands on end-user capabilities (i.e. including Wireless/LTE capability, over-the–air provisioning, and expansion of End-user device form factors for laptops/tablets) which will allow FBI users to become more efficient with doing their jobs. The ERAS 3.0 Solution’s EUD, the Archon ZV laptop, has separate secure containers for each authentication step in the creation of CSfC dual encrypted tunnels.
The ERAS 3.0 solution traverses information from an end-user device (Laptop) across three environment boundaries (black, gray, and red) using two nested, independent encrypted tunnels (inner/outer) to protect the confidentiality and integrity of data as it travels across multiple classification levels, before being sent across the untrusted network, classified data is encrypted twice: first by an Outer VPN component, and then by an Inner VPN component.
At the other end of the data flow, the received packet is correspondingly decrypted twice:
first by an Outer VPN component, and then by an Inner Encryption component
The ERAS 3.0 solution is managed using Red Management Services for Inner Encryption components and Gray Management Services for Outer Encryption components.
The Black Management Services include an outer Black firewall and administrator workstation that will use enterprise black authentication services.
The Gray Management Services include:
Administration workstation Separate site-to-site IPsec VPN for Gray administrator access from FBI HQ Gray firewall Security Information and Event Monitoring (SIEM) Intrusion Detection System (IDS) Additional components located between the Outer VPN Gateway and Inner
Encryption components Gray Management Services which include an Outer VPN Locally run Gray Device Certification Authority (CA) Certificate Revocation List (CRL) CRL Distribution Point (CDP) Gray OCSP Commvault Backup services
The Red Management Services include Administration workstation Inner Firewall Inner VPN Security Information and Event Monitoring (SIEM) Intrusion Detection System (IDS) EUD Issuing CA authorities (Gray & Red) Red Device Certification Authority (CA) CRL Distribution Point (CDP)
Red OCSP OTA Archon Manager Commvault Backup services ERAS 3.0 will also utilize many enterprise services:
Trusted Internet Connection (TIC) DMZ Firewall TIC DMZ Switches TIC DMZ Load Balancers ITID Enterprise Authentication and Authorization services Red Cisco ACI spine and leaf network Riverbed monitoring Enterprise Security Operations Center (ESOC) security monitoring
The hardware/software supporting ERAS 3.0 consists of the following:
Name / Application Version Manufacturer Function Archon ZV v3.0.9 & 3.0.10 Integrity Global Security EUD OS Aruba VIA Client 3.1.0.1811011 Aruba VPN Client ArubaOS 8.6.0.8-FIPS Aruba VPN OS Cisco AnyConnect v4.7.04056 Cisco VPN Client Cisco ASA 9.12(4)10 Cisco VPN Management Cisco StealthWatch Virtual Appliance v7.1.3 Cisco Virtual Appliance
Cisco Management / Network Monitoring
Cisco Netflow Virtual Appliance v7.1.3 Cisco Virtual Appliance Cisco Netflow Collector
Cisco Netflow Virtual Appliance v7.1.3 Cisco Virtual Appliance
Cisco Netflow Collector Management
CommVault v11 SP 17 CommVault Backup and restore of critical files Dell iDRAC 4.22.0.0 Dell Remote Access Console Dell Force10 OS FTOS-S3100-9.14.2.6 Dell Dell Switch S3124
Dell OS10 Enterprise Edition v10.5.1.3.190 Dell Dell Switch S4112
Forcepoint NGFW v6.5.7 Forcepoint Firewall OS Forcepoint SMC v6.7.2 Forcepoint Firewall Management Microsoft Windows 10 x64 Windows 10 Microsoft Laptop OS Microsoft Windows Server 2016 Server 2016 Microsoft Server OS Nessus Professional 8.15 Tenable Vulnerability Scanning Pacstar IQ-Core v3.9.55.130 PacStar SEIM, Certificate provisioning
Red Hat Enterprise Linux 7.8 7.8 RedHat Archon Provisioning and OTA Certificate Rekey
SCAP compliance checker 5.4.1 DOD Security Baseline Check Sonic Wall SonicOS 6.5.4.4-44n Sonicwall IDS OS
VMware VMware ESXi6.7.0, 17700523 VMware Hypervisor
VMware - Photon OS VMware v6.7.0.4800 VMware vCetner Server
Vmware Virtual Machine Virtual Hardware Level 14 VMware Virtual Machine
MasterClock NTP Server v5.9.3 MasterClock NTP Server
MPO requires a Trusted Integrator to support the FBI in the implementation of the CSfC Capability Package (CP) at an estimated total cost of . Trusted Integrators specialize in bringing together CSfC components in accordance with the CSfC CP to ensure secure and proper solution functionality.
Trusted Integrators must be prepared to demonstrate, upon request from NSA, that they have the staff and processes in place to architect, design, integrate, test, document, field and support systems that meet the requirements of the CSfC program.
In order to become a Trusted Integrator, the sponsoring organization must comply with NSA’s criteria for a CSfC Integrator.1
4. The statutory authority permitting other than full and open competition.
The statutory authority permitting other than full and open competition is 41 U.S.C. 3304(a)(2) as implemented by the Federal Acquisition Regulation (FAR) Subpart 6.302-2 entitled, “Unusual and Compelling Urgency.”
5. Demonstrate the unique qualifications of the proposed contractor or the nature of the action requiring the use of the authority.
The FBI’s ITID, MPO is responsible for providing remote access to FBI classified enterprise information technology (IT) resources via secure mobile client devices. The FBI’s classified mobile program is known as the Enterprise Remote Access Solution (ERAS) which has been operational since 2014 and is defined as a National Security System (NSS) per the Committee
1 https://www.nsa.gov/Resources/Commercial-Solutions-for-Classified-Program/Trusted-Integrator-List/ on National Security Systems (CNSS). The CNSS sets national-level information assurance (IA) policies, directives, instructions, operational procedures, guidance and advisories for the security of NSS. As such, the FBI must manage security risks against NSS standards to combat the increasing number of internal and external threats that can never be completely eliminated but, through shared measures and safeguards can be implemented in order to protect NSS. To ensure compliance with CNSS Policy No. 7, as well as CNSS Directive No. 510, the ERAS must be compliant with the National Security Agency’s (NSA) Commercial Solution for Classified (CSfC).
, the FBI is unable to obtain critical updates to the ERAS operating system through the sub, Integrity Global Security.2 These issues, through no fault of the FBI, have halted all break-fix efforts which have severely impacted the FBI’s ERAS end-users by not allowing operational enhancements to the OS as required by the current contract.
Without the Integrity OS, the FBI’s current solution will not work. As a proposed solution, the incumbent prime contractor recommended a path forward to upgrade all existing ERAS devices to their proprietary software. This was not the path the FBI wanted to take for several reasons to include:
1) The software offered by the incumbent is not on the NIAP approved list of software, which is required for the Authority to Operate issued by the Authorizing Official.
2) The software offered by the incumbent had not been tested with the FBI and would require an Authority to Test before testing.
3) The FBI would have to resubmit its ERAS 3.0 CSfC package to the NSA due to a change with the Operating System. Approvals for CSfC package submissions can take 6 months or more.
4) The MPO would need to re-submit a new ATO package for ERAS based on the new NSA submittal.
5) Once NSA and ATO approval is complete, all 3,420 ERAS devices will need to be returned to FBIHQ to re-image and re-distribute back out to the enterprise.
The above outlined steps are all unplanned work not prioritized by the ITID. If the FBI were to pursue this option, it would take over a year to complete. In the interim, the FBI would be
2 Integrity OS is a proprietary operating system engineered and developed by IGS alone.
without its critical ERAS capability. The FBI cannot lose ERAS services. Thus, it needs to issue a short-term contract with a Trusted Integrator that is a reseller of IGS’s Integrity OS to be able to sustain the existing ERAS infrastructure until a new contract is awarded for the next ERAS solution.
CIS Secure is a CSfC listed Trusted Integrator that has a partnership with Integrity Global Security (IGS). To maintain functionality of ERAS it is essential that the FBI award to a Trusted Integrator that is an authorized reseller of IGS’s Integrity OS. Without a Trusted Integrator that is an authorized reseller of Integrity OS, the FBI will not be able to use the Integrity OS nor provide critical security patches and enhancements to the 3,420 ERAS laptops deployed across the enterprise, supporting mission critical operations provide critical security patches and enhancements to the 3,420 ERAS laptops deployed across the enterprise, supporting mission critical operations.
INTEGRITY Global Security (IGS) is the sole distributor, and licensor of all intellectual property known as the INTEGRITY Enterprise OS. It is the critical supporting platform for the FBI’s secured ERAS EUD. The INTEGRITY Enterprise OS is not currently integrated into any other CSfC solution or licensed to any original equipment manufacturer.
The INTEGRITY Enterprise OS and the Secured with INTEGRITY Client are only available for sale directly from IGS or from authorized resellers (Trusted Integrator such as CIS Secure).
If the FBI was to award a contract to a different Trusted Integrator (TI) that offered a different CSfC mobile classified offering other than Integrity OS, that would require a complete rebuild of the ERAS infrastructure, from the equipment supporting ERAS in the data centers (servers, networking, RSA, PKI, cross domain, etc.). The FBI would have to submit a new ERAS 3.0 CSfC package to the NSA for review and approval. This is a significant undertaking by NSA and typically has a minimum 6-month turn-around. The FBI requires an Authority to Operate before a system can be deployed to the enterprise and a new ERAS solution will need to go through that approval process based on the approval from the NSA. With the end of the current contract due to unforeseen contractual issues, if the FBI was to award to a TI with a new CSfC solution, the current ERAS environment will have to be shut down until the new solutions is engineered and approved for enterprise use. This will severely impacted FBI mission-critical operations that rely on ERAS services on a daily basis.
6. A description of efforts made to ensure that offers are solicited from as many potential sources as is practicable, including whether a notice was or will be publicized as required by Subpart 5.2 and, if not, which exception under 5.202 applies.
The Government is citing the exception found in FAR 5.202(a)(2) which utilized for unusual and compelling urgency stating that the Government would be seriously injured if the agency complies with the time periods specified in 5.203.
INTEGRITY OS is a proprietary solution developed by Integrity Global Security. In order to adequately satisfy the FBI’s needs for this requirement, any potential vendor must be an authorized reseller of IGS’ INTEGRITY OS. The use of any other operating system is unacceptable because it would require 3,420 EUDs being recalled, reconfigured, and redeployed to field. The OS must comply with NSA’s CSfC Program standards and must be on NIAP Product Compliance List before being considered for deployment.
This short-term contract to CIS is a stop-gap measure to prevent the loss of critical services. Due to a truncated time frame the FBI is pursuing a sole source action as the required time to evaluate multiple proposals would push an award past the period of performance causing a lapse in connectivity with ERAS which would place ongoing operations utilizing the ERAS in jeopardy.
Once the contract is awarded to CIS, the Government anticipates issuing a solicitation on GSA MAS under SIN 54151S or NASA SEWP for a full and open competition after exclusion of sources for further development and enhancement of the ERAS.
7. The anticipated dollar value of the proposed acquisition, including options if applicable, and a determination by the Contracting Officer that the anticipated cost to the Government will be fair and reasonable.
Trusted Integrator support services to included security patches and enhancements for INTEGRITY OS for a period of performance for twelve (12) months has been estimated at .
There will be no option periods. The Contracting Officer will use price analysis to determine fair and reasonable prices.
8. A description of the market research conducted and the results.
Limited market research was completed for this requirement as it an unusually compelling and urgent requirement. A more thorough market research effort is current underway for the requirement following this contract. This current requirement is being taken to maintain the operability of the ERAS citing FAR 6.302-2, “Unusual urgency and compelling.” Market research for a Trusted Integrator for Integrity OS identified CIS Secure as a capable provider.
9. Any other facts supporting the use of other than full and open competition.
10. A listing of any sources that expressed a written interest in the acquisition.
Not applicable as the FBI is not posting a Notice of Intent pursuant to FAR 5.202(a)(2).
11. A statement of any actions the agency may take to remove or overcome any barriers to competition, if subsequent acquisitions are anticipated.
MPO will continue to communicate and coordinate with Industry and survey the open market to ensure vendors that can provide Trusted Integrator services for INTEGRITY OS are aware of the requirement. It is the intention of the government to conduct thorough market research before solicitating for a new award for ERAS after this stop-gap award to prevent the loss of critical services is completed.
File details come from the government source that posted it. Updated .