SSS_Inquiry_QA_5MAR2025.pdf

PDF 147 KB Posted

Attached to
Enterprise Security Services (ESS) Federal contract opportunity
Solicitation number
FA810225R1000
Issued by
Department of the Air Force Materiel Command Lifecycle Management Center Tinker Air Force Base

About this file

This is a Questions & Answers document for a Sources Sought Synopsis (SSS) related to Enterprise Security Services (ESS) for the High Frequency Global Communications System (HFGCS), with questions and responses dated between February-March 2025.

The Q&A clarifies that this is a new stand-alone requirement with no incumbent contractor. Key details include: responses are due March 3, 2025 at 1300 CST; contractor personnel must obtain minimum Secret clearance; management of security tools will be remote; the scope covers 13 global stations, Network Control Stations (NCS), and peripherals; current tools include Endpoint Security, SIEM, and Vulnerability Scanner. The work involves intrusion detection, vulnerability scanning, STIG services, and cyber incident response planning. Personnel must be IAT II certified per 8140.01. The government indicates limited flexibility for implementing next-generation cybersecurity solutions beyond current SIEM (Splunk) and ACAS platforms. No specific acquisition timeline or award date is provided as this is only a market research effort to gain insight for a potential requirement.

View the file

Other files for this federal contract opportunity

Other files attached to Enterprise Security Services (ESS), newest first.
File Type Posted
SSS_Inquiry_Questions_and_Answers_28Feb2025.pdf PDF
ContractorCapabilitySurvey_28Feb2025.pdf PDF
SSS_Inquiry_Questions_and_Answers_14Feb2025.pdf PDF
SSS_Inquiry_Questions_and_Answers.pdf PDF
SSS_3Feb2025.pdf PDF
DRAFT_PWS_EnterpriseSecurityServices_30JAN2025.pdf PDF

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

Date Vendor Questions Government Response Revised Government Response

2/4/2025 Request the Government to provide the Incumbent Vendor’s Name & the contract number (which is currently underperformance)?

The original Government response inadvertently and mistakenly referenced a parent contract/order number and indicated a Prime Contractor currently exists.

To be abundantly clear this potential ESS requirement would be considered a new stand-alone requirement and therefore does not have an incumbent or existing contract number. No further information can be provided.

2/4/2025 What is the total award value (size) of the current contract, which is presently ongoing by the Incumbent vendor?

The original Government response inadvertently and mistakenly referenced a parent contract/order number and indicated a Prime Contractor currently exists.

To be abundantly clear this potential ESS requirement would be considered a new stand-alone requirement and therefore does not have an incumbent or existing contract number. No further information can be provided.

2/4/2025

Provide information as to what the Government is specifically looking for in the SS response or how to format the information. Is there a page limit, or any specific format as to questions or capabilities that you are looking to have addressed? For the similar services is there any format you would like to have these in? Customer, value, period of performance, Gov POC information, and how man, etc.? Up to 3 or something like that?

The Government inadvertently left off the SSS document dated 3 Feb 2025, that includes a Contractor Capability Survey.

There is not a specific format or page limit required when submitting your response to this document. Any other information that was questioned should be answered within the attached document. If further questions are needed please reach out to Jocelyn Johnson at jocelyn.johnson.2@us.af.mil, Juan Carlos Escobar at juan.escobar@us.af.mil and 2nd Lt. Sara Wine at sara.wine@us.af.mil

2/4/2025 Please confirm that the due date is Mar 3rd at 1:00PM CST. Correct. The due date is 3 March 2025 at 1:00 (1300) CST.

2/14/2025 Is the Government expecting Contractors to have a Facility Clearance?

The monitoring would be done either remotely or with physical personnel onsite. Contractor personnel would be expected to obtain at a minimum a Secret clearance level with potential for future clearance upgrades if necessary No, the management of the security tools will be remote.

2/14/2025

If an FCL is required for this opportunity, what level of FCL will be necessary, and will it be needed at the time of submission or at the time of award? Additionally, if an FCL is required, is the government planning to sponsor the FCL for the awarded contractor?

The Contractor Field Security Officer would be responsible for contractor personnel. The management of the security tools will be remote.

2/14/2025 Can the government please share the acquisition timeline for this requirement with us?

At this time the Government does not have an expected requirement and therefore does not have a projected timeline. The purpose of this sources sought is to gain insight for a potential requirement.

2/14/2025 What is the anticipated award date? N/A. See response stated above.

2/14/2025 Could you provide more details on the specific challenges your team has faced with Intrusion Detection and Vulnerability Scanning in the past?

The original Government response inadvertently and mistakenly indicated that there is a current Prime Contractor. To be abundantly clear this potential requirement would be considered a new stand-alone requirement and therefore does not have an incumbent or existing contract number. One of the main challenges is having to fulfill this potential ESS services requirement independently through a new stand-alone contract vehicle rather than acquiring similar services through an existing contract vehicle. The purpose of this sources sought is to gain insight for a potential requirement.

2/14/2025 What tools and systems are currently in place, and are there any gaps or opportunities for enhancement?

*Endpoint Security *Security Information and Event Management (SIEM) Tool *Vulnerability Scanner No other information can be provided at this time.

2/14/2025 How critical is the alignment with the 2025/2026 strategic goals, especially in terms of the readiness of systems and infrastructures?

HFGCS as a System is modernizing and requires capability to achieve compliance with DoD platform (NIPRNet/AFNET) to enable strategic global missions.

2/14/2025 Can you clarify what the desired effect is of the Vulnerability Indexing Report (CDRL A003)? The indexing word has me a bit confused.

The report has historically been an Excel spreadsheet with raw vulnerability scan data compiled and formatted to provide clear information easy-to-read for our contracted system administrators to digest and work from when mitigating vulnerabilities. Our existing service provider produces and sends this every week.

2/14/2025 Is this contract item IRP exercise Report (CDRL A008) meant to be doing tabletop exercises and can this be clarified?

This would include tabletop exercises. Tabletop exercises involve key stakeholders in walking through actions to be taken by each involved party when a cyber incident occurs. The contractor would facilitate the exercise through coordination with the Government Information System Security Manager (ISSM) and provide a report with feedback/recommendations how tasks/areas can be improved.

2/14/2025 Cybersecurity Workforce certification (CDRL A010), is this mean to be a report that clarifies the contract workforce and how many certified people they have working the contract?

No. Any personnel through the contract vehicle must be IAT II certified IAW 8140.01. There should be no personnel non-certified working in this capability within the HFGCS.

2/14/2025 Can you define better what these phases would be for Transition Plan – Phase- In/Phase-Out Strategy (CDRL A014)?

Contractor should provide documents, training material, etc. requested by the Program Management Office (PMO) for if/when the PMO replaces one contractor with another. This enables knowledge management to be sustained during any potential switch-over. No specific “phases” within the submitted plan are necessary, unless otherwise developed by the contractor.

2/14/2025 And there is no CDRL for continuous monitoring plan development? And if there were this component what systems and areas at Tinker would this effect?

Nothing on Tinker would be impacted. The HFGCS does not reside on Tinker AFB. The monitoring would be done at the Network Control Stations (NCS)s (either remotely or with physical personnel onsite). The PWS does not make any mention of a “continuous monitoring plan development” requirement.

2/14/2025 Will this only impact the High Frequency Global Communications System (HFGCS)? Yes

2/14/2025 I could not find in the document what the scope for Enterprise Security Services (ESS) would be? Is this to be used in all areas of the base?

*No; just the HFGCS. The HFGCS does not reside on Tinker AFB.

*The primary scope of the HFGCS PMO system includes 13 global stations, NCS(s), and peripherals (Any Control/Any Station (ACAS), and End Point Applications (EDAs)

2/14/2025 Do you know or have a time frame that this will need to be done for the initial requested information?

N/A

2/14/2025 What is the priority in terms of meeting security compliance and maintaining operational readiness?

Security compliance is necessary in maintaining operational readiness.

2/14/2025 Is this a new opportunity or an extension of an ongoing effort? See response stated above.

2/14/2025 What challenges or pain points have been identified in previous efforts that we should consider?

Training and providing personnel.

2/14/2025 How does this align with your 2025/2026 goals? See response stated above.

2/14/2025 Will there be any future opportunities for subcontracting, and what would be the process for a potential partnership?

Please note this is not a solicitation but a sources sought. At this time the information is not available, but if the requirement develops further details will be provided.

2/19/2025 Will the Air Force require the prime contractor to have an active Facility Clearance (FCL) at the time of award, or will sponsorship be available for qualifying firms? No, the management of the security tools will be remote.

2/19/2025 Will USAF consider subcontractors with federal civilian cybersecurity past performance (e.g., DHS, DOJ) as relevant experience, or must past performance be strictly DoD-related?

In the event we move forward with a solicitation, all past performance on recent and relevant contracts will be considered.

2/19/2025

What flexibility does USAF have in adopting next-generation cybersecurity solutions, such as AI-driven threat detection, Zero Trust security frameworks, or cloud-based security automation, beyond the currently stated SIEM (Splunk) and ACAS platforms?

Limited flexibility for HFGCS

2/28/2025 Can you verify that questions B1 and D1 in the attached SSS are valid?

Question B1 from the Contractor Capability Survey has been removed. See the attached revised document.

Question D1 the ESS team has determined that this question is valid and will remain on the Contractor Capability Survey.

2/28/2025 This could affect everyone's RFI responses. There is an inference to manufacturing in question B.1. Based on our review of the draft PWS, we do not identify a requirement for manufacturing. However, if the Government anticipates hardware procurement or integration needs, we welcome clarification.

To clarify - This is not a RFI. The posting is for a Sources Sought Synopsis. In reference to your B1 question see the resonse above.

2/28/2025 This could affect the number of responses with qualified capabilities. The draft PWS does not specify the number or locations of the Net Control Stations (NCSs).

Understanding the number and location of these sites would affect our RFI response.

Could the Government provide details about the NCS sites?

Please see clarification to the Contractor Capability Survey Question B1 above.

Sheet1

File details come from the government source that posted it. Updated .