E-DLP Proof of Concept Objectives -Final 18 August 2020.pdf
PDF 567 KB Posted
- Attached to
- Enterprise Data Loss Prevention (E-DLP) Federal contract opportunity
- Solicitation number
- FA877320R0003
About this file
This document includes a Statement of Objectives (SOO) and related solicitation for an Enterprise Data Loss Prevention (E-DLP) Proof of Concept. The Air Force seeks a vendor to conduct an E-DLP POC at a single base involving at least 100 users, multiple data owners, and representation of all main data egress points, including demonstrating DLP capabilities for data at rest, in motion, and in use. The POC will also demonstrate the ability to aggregate and correlate alerting across networks using a cross domain solution. The period of performance is from August 2020 through December 2020. Quotes are due by June 16, 2020. The SOO provides extensive requirements for the POC, including establishing E-DLP policies, demonstrating E-DLP capabilities across various use cases and technologies, providing training, and refining policies. The solicitation references Attachment 1 SOO and provides solicitation number, due dates for questions and quotes, and contact information for the contracting officer.
View the file
Other files for this federal contract opportunity
Show all 28
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
Statement of Objectives (SOO)
Enterprise Data Loss Prevention Proof of Concept
Problem: The United States Air Force does not have an Enterprise Data Loss Prevention
Program. We do not have the requisite policies, organization, training, or equipment to empower data owners and users to effectively secure all Air Force sensitive data. Instead, we implement point solutions employed by IT professionals rather than data owners based on specific use cases such as protecting operational security information, personally identifiable information, and network indicators like diagrams and user credentials. These point solutions are not integrated and are operated by various organizations.
For the purpose of this POC, we adopt the following description of E-DLP:
Enterprise DLP solutions offer a centralized policy management and reporting service that defines, disseminates and monitors DLP policies across one or more deployment scenarios such as endpoint, network, discovery and cloud. Enterprise DLP solutions incorporate advanced content inspection techniques to identify even the most complex of content and apply remediation. Enterprise DLP solutions provide a broad and very flexible deployment solution set that is applicable to many diverse use cases including regulatory compliance, internal policy compliance and intellectual property protection.
Proof of Concept: Because the Air Force is unfamiliar with the practical application of current market E-DLP technologies and the supporting policies, organization and training to create an effective E-DLP program, we are seeking a vendor to conduct a Proof of Concept at JBSA-
Lackland with an expected implementation date of August 2020 thru December 2020. The users and data owners will be on JBSA-Lackland, TX. The operators and analysts monitoring the
E-DLP system and creating security policies will reside at Lackland AFB. Attached are high-level diagrams of the on premise and cloud-based network services at JBSA-Lackland, TX. Additional technical details will be provided after contract award during the site survey phase.
The AF anticipates a delay between when the contract is awarded and the start of the period of performance due to Information Assurance issues that cannot be addressed until the technical solution is known. The AF will be seeking an Interim Authority to Test (IATT) which will require providing information such as Hardware list, Software list, Security Technical Implementation
Guide (STIG) Applicability List, Ports, Protocols, and Services Matrix, System and Cybersecurity
Test Plans and Schedule, and Cybersecurity Test Results (e.g., vulnerability scans, STIG check results). The Authorizing Official for this POC is ACC/A6. The A&A team will work with the 688
CW who will in turn manage all coordination for the ACC/A6.
Another area that may cause delay between contract award and the start of the period of performance is any cryptographic requirements associated with the vendor’s technical solution.
The vendor will be expected to follow all cryptographic standards directed by the AF Public Key
Infrastructure Program Office.
The full scope of the POC will be determined once the vendor is selected, but we prefer that it include at least 100 users, multiple data owners, and be representative of all the main egress points for data from that Air Force Base (e.g., endpoint, email, network, cloud, storage) and apply DLP capabilities to data at rest on-premises or in cloud applications and cloud storage, in transit, and in use. The number and type of monitoring points will be limited to the minimum required to assess the vendor solution against our five broad egress use cases as well as on specific OSs listed below in the SOO. The Air Force will consider a larger target population if it is required to effectively assess the proposed technical solution. The average outbound traffic at
JBSA-Lackland, TX is 274.94M/s with a maximum of 744.59M/s. The AF is not specifying a required cloud provider for this POC. The only stipulation is that if a cloud provider is required to implement the vendor's proposed technical solution that 1) the vendor should price the cloud services in the POC and 2) the CSP must meet all applicable FEDRAMP requirements. For the purpose of this POC, the vendor only needs to demonstrate E-DLP cloud egress for NIPR-based cloud services.
The POC will also demonstrate the ability to aggregate and correlate alerting across multiple networks/classifications (e.g., NIPR, SIPR, JWICS) using a Cross Domain Solution as well as publish policies from a central policy management console to targeted networks (i.e., bi-directional CDS flow). For this POC, the approach should demonstrate integration with an existing AF CDS solution for NIPR and SIPR on the production networks (i.e., no simulations).
Integration into a JWICS CDS is not expected during this POC. Technical details of current AF
CDS capabilities will be provided to the vendor after contract award as part of the site survey phase of the POC. The vendor must be able to provide cleared personnel up to SECRET. The government will not sponsor clearances.
This will not be limited to a technology demonstration. It will also include developing the requisite policies to support holistic employment of E-DLP. Additionally, we will seek ways to best organize and train our IT Airmen and data owners and users to effectively employ E-DLP capabilities. The AF desires a solution that enables the user, administrator, and data owner to take action depending how the security policy is designed. One of the central tenets of this
POC is to better define these roles and responsibilities within the organization and establish the appropriate organizational policies, training, and E-DLP security policies necessary to implement an AF E-DLP Program. The AF seeks guidance on industry best practice and other consulting as part of this POC to ensure an AF E-DLP Program will be successful. The AF is currently working on defining its information types and desired policies in preparation for this POC, but will definitely seek guidance and consulting from the vendor.
Where possible, we seek to leverage existing investments and organizations to build an AF E-
DLP program. If the vendor uses specific DLP capabilities such as endpoint, network, etc., as part of their technical solution to support E-DLP, it will need to be implemented to such a level that the AF can evaluate its efficacy to prevent data loss at that level. The focus of the POC is E-
DLP, not specific DLP capabilities, but the POC would recommend options to retire, replace, and/or consolidate existing AF DLP-related capabilities. Examples of current capabilities include native DLP capabilities in O365 and Fidelis network sensors. Onsite engineering assistance to meet these requirements will be dependent on the complexity and scale of the technical solution and the effectiveness of the training provided to system administrators and maintainers.
Our preferred operating model for the POC is contractor owned, government operated. The AF will not be acquiring additional hardware or software to support this POC. The vendor will be required to provide all necessary hardware and software to meet the requirements of this POC.
Bidders and solution providers cannot be foreign owned entities. The vendor may integrate with existing AF hardware and software to implement their technical solution.
Proposals should be sufficiently detailed to aid in not only assessing the technical merit of the proposed solution for each requirement specified, but also the Information Assurance implications of the technical solution (e.g., information and artifacts that will aid in the development of the required Risk Management Framework package to attain an Interim
Authority To Test (IATT)). Key artifacts include answering the Air Force (AF) Information
Technology (IT) System Categorization and Selection Checklist, System Authorization Boundary
(Topology) Artifact, Hardware list, Software list, Security Technical Implementation Guide
(STIG) Applicability List, Ports, Protocols, and Services Matrix (required), System and
Cybersecurity Test Plans and Schedule, Cybersecurity Test Results (e.g., vulnerability scans, STIG check results). If portions of the proposed technical solution are already adopted by other USG departments and agencies, providing the Information Assurance artifacts for those installations will greatly improve the speed at which the Air Force can gain an IATT for this POC. The vendor, in coordination with the Air Force, will need to finalize all required security and test plans.
Contract Data Requirements:
Contractor format is acceptable. All deliveries should be in format compatible with either
Microsoft Word, Microsoft PowerPoint, or Adobe PDF format.
1. Provide a burn down chart of funds and/or man hours within their weekly or monthly reports.
2. Provide a weekly status report detailing the status of tasks as outlined in the POA&M.
The report should summarize the work completed, key findings, and any recommendations for follow-on activity outside that which is already defined in the approved POA&M. Additionally, the report may include recommendations for the retirement, replacement, and/or consolidation of existing AF technologies as well as other remediation of gaps or vulnerabilities to improve the data security posture of the
POC target population. Finally, reports may include a listing of sources, partners, possible alternative courses of action to that which is defined in the approved POA&M, and any implications for training, policy, personnel, or logistics.
3. Provide an Information Assurance Security Plan detailing the following information for the proposed technical solution:
a. Topology/Authorization Boundary Diagram
b. Hardware list
c. Software list
d. Security Technical Implementation Guide (STIG) Applicability List
e. Ports, Protocols, and Services Matrix
f. System and Cybersecurity Test Plans and Schedule
g. Cybersecurity Test Results (e.g., vulnerability scans, STIG check results)
4. Provide a training plan for users, data owners, system administrators/maintainers, and operators. Training plan should be in the form of train-the-trainer where the initial training will be conducted by the vendor and all subsequent training will be administered by the Air Force employing vendor provided materials.
For users, the training should be focused on how to use and/or create tags to manually tag data; how to override security policy in the event of a false positive; and other areas deemed appropriate based on the technology selected.
For data owners, the same training as above with the additional ability to write and either forward for approval or publish security policy associated with their data, dependent on the capabilities of the technology selected.
For administrators/maintainers, the training should be focused on the Tier 1 level support tasks required to keep the technology at a known, good baseline of operation.
For operators, the training should focus on writing and publishing security policy, responding to system alerts, and auditing system capability to ensure it is operating as designed.
Objectives: (NOTE: There is no weighting in terms of priority for these objectives. 3rd party solutions are allowable to meet these requirements, but must be provided by the vendor as part of this solicitation. The AF will not purchase any technologies for the purposes of this POC.)
1. Identify AF sensitive information
a. Ability to automatically detect, assess, and classify sensitive content using content-aware detection techniques such as: partial and exact data matching, structured data fingerprinting, statistical analysis, extended regular expression matching, and conceptual and lexicon analysis, image recognition, optical character recognition, forms recognition and others.
b. Support the detection of sensitive data content in structured, unstructured, and semi-structured data, using registered or described data definitions
c. Encrypted traffic management providing Secure Socket Layer (SSL) and Transport
Layer Security (TLS) visibility (break/inspect).
d. Use of machine learning to detect content
e. Information fingerprinting, metadata matching, machine learning
f. Enable Data Owners/Users to tag/classify their information
g. Maintain tagging persistency as files safe renamed, copied and pasted, converted to another file type, archived, and encrypted
2. Establish relevant E-DLP Program Policies and recommend changes to those policies
a. SAF (CN, CO, CDM)
b. MAJCOM
c. 16AF/AFCYBER
d. Base-level
3. E-DLP Capability Requirements
a. Provides a single centralized management console for all sensors. The central security policy management capability would reside on SIPR with the ability to deploy security policies on NIPR and SIPR (i.e., a single policy controller on the highest network to control policies on lower networks). The AF needs the ability to apply unclassified, common policy to all networks and classifications. The AF also needs the ability to apply potentially classified, targeted policies on SIPR. Alerts from NIPR would be presented on the SIPR console such that an operator can analyze and process alerts from both NIPR and SIPR on a single console.
b. Includes event management workflow and reporting
c. Supports advanced policy definition and ability to deploy use for all endpoints, in storage, in motion, or a selected combination
d. Enables Organization’s Data Owner to make risk decision on data loss for data in use, data at rest, and data in motion
e. Allows for full remediation policy options: report/warn, allow, exception, redact, tokenize, move, protect/encrypt, forbid/block, quarantine. No Air Force policies specific to E-DLP exist for redaction and tokenization. For the purposes of this POC, the Air Force will follow industry standards and best practices for these functions.
f. Hybrid on-premises and cloud-based E-DLP solution
g. Adds contextualization by incorporating externally sourced data to create a more complete view of the risks surrounding individual events
h. High integration with other technical threat detection capabilities like Endpoint
Detection and Response (EDR) and User-Entity Behavior Analytics (UEBA) for improved unified data threat prevention. "High integration" implies that all the components of the E-DLP technical solution are integrated in such a way as to provide near real-time to real-time alerting of automated system actions and recommendations to the operator/analyst. The contractor should be able to demonstrate the value of their UEBA solution to the AF in such a way as to enable the AF to better understand technical, policy, training, and other implications of market leading E-DLP offerings to make informed decisions on possible future acquisitions.
i. Ability to integrate into security information and event management (SIEM)
j. Ability to scale solution to the AFIN. The AFIN is approximately 750K users and
1M endpoints. To assess this ability, the contractors statement of work (CSOW) and response to the technical scenarios in the solicitation will be used.
k. Can be used on Windows, Linux, or Mac OS X
l. Must not require integration into another product for functionality. The proposed technical solution will either 1) provide all necessary technologies to implement the set of requirements or 2) rely on integration with existing AF technologies and investments. The AF will not purchase any technologies to enable the technical solution of the vendor. The AF is interested in any opportunity to retire, replace, consolidate, and/or integrate with existing capability investments. However, the AF adheres to following industry standard best practices and will carefully weigh the necessary integrations proposed by each vendor's technical solutions provided in their Proposals in terms of function and security. For example, we do desire that the vendor will integrate with existing AF Cross Domain Solutions. We also expect integration with cloud hosted services such as crypto. The AF employs DLP capabilities resident in
Microsoft O365 through the Security Compliance Center to enforce email DLP.
The AF is seeking technical solutions that either integrate with O365 email DLP or replaces those services through other means. The AF does not want to employ email DLP policies separately in SCC and then all other DLP policies through other means. The goal is to "Write Once, Publish Everywhere." The AF already has a production O365 environment so no additional investment is required for this
POC.
m. Note that the AF expects that the system/network environment will be returned to the state previous to the start of the POC and therefore any integrations with existing AF capabilities will need to be rolled back without affecting daily network and security services of the host base. The proposed solution may provide OEM integration of products for functionality, but the vendor must provide the OEM products or integrate into OEM products the AF already owns.
4. E-DLP Employment
a. Provide Operator, Administrator, Maintainer, Data Owner and User Training to support at least 100 users and endpoints (e.g., workstations and servers).
b. Demonstrate E-DLP capability to identify content, assess data, and protect data across multiple organizations and across distinctly different data sets
c. Demonstrate E-DLP capability via data owner’s desired policy remediation options in 5e on-premises and cloud data at rest (file shares, database, endpoints), in motion over the network (email, share point posting, web posting, network traffic, cloud) and in use (email, IM, cloud apps, removable devices?).
d. Demonstrate an ability to scale solution. To assess this ability, the contractors statement of work (CSOW) and response to the technical scenarios in the solicitation will be used.
e. Continue to refine policies in Objective 2.
f. Recommend options to retire, replace, and/or consolidate existing AF DLP-related capabilities.
5. EDLP Employment Endpoint
a. Detect, assess, and classify data in use and storage using content-aware detection techniques such as: partial and exact data matching, structured data fingerprinting, statistical analysis, extended regular expression matching, and conceptual and lexicon analysis, image recognition, optical character recognition, forms recognition, and others.
b. Demonstrate the ability to aggregate and correlate alerting across multiple networks/classifications (e.g., NIPR, SIPR, JWICS) using a Cross Domain Solution.
c. Must be able to detect the following file types: CAD, .pdf, .xls, .doc, .txt, .jpg, ….
d. Ability to perform internal content analysis. Internal content analysis includes, but is not limited to, keyword matches, dictionary matches, the evaluation of regular expressions, internal functions, and other methods to detect content that matches DLP policies.
e. Ability to be employed on the following operating systems. The AF will not release the number of endpoints running available operating systems prior to contract award. This will be provided during the vendor site survey. If the vendor's technical solution does not have an agent that can be deployed on endpoints employing legacy operating systems, then the AF will consider alternatives to endpoint agents that can meet the intent of the stated endpoint requirements. Legacy operating systems are denoted with asterisks and may be protected by other components of a holistic E-DLP solution (i.e. network sensors, web sensors, etc.).
i. Linux (Work station and server; examples include Red Had Enterprise and
Ubuntu and various Linux Kernels)
ii. Macintosh OS,
iii. MS-DOS***,
iv. Windows 98***,
v. Windows 2000***,
vi. Windows 10
f. Mobile devices such as IOS, Blackberry, Android, Microsoft-based laptops, tablets, phones
g. Printers
h. Virtual machines
i. Email
j. Browser
k. Removable devices
l. User roles within DLP policies
m. Ability for user to take action that is user driven and customizable when sensitive data is found
n. Must follow the international and United States regulations. For example: DoD, USAF, and the EU General Data Protection (GDPR) regulations.
6. EDLP Employment Network
a. Detect, assess and classify data in motion
b. Email, webmail
c. Web, http/https
d. IM
7. EDLP Employment Storage
a. Detect, assess and classify data at rest
b. File servers
c. Databases
d. Share point
e. NAS
8. EDPL Employment Cloud
a. Data in use and at rest
b. Cloud apps
c. Storage
d. Future WS
e. Microsoft’s cloud based email
File details come from the government source that posted it. Updated .