E-DLP questions and answers.xlsx
XLSX spreadsheet 25 KB Posted
- Attached to
- Enterprise Data Loss Prevention (E-DLP) Federal contract opportunity
- Solicitation number
- FA877320R0003
About this file
This document contains a statement of objectives and combined synopsis/solicitation for an Enterprise Data Loss Prevention proof of concept. The Air Force is seeking a vendor to conduct a five-month proof of concept at Langley Air Force Base involving at least 100 users. The proof of concept will demonstrate the ability to centrally manage security policies across NIPR and SIPR networks using a cross domain solution, integrate with the Air Force's Microsoft Office 365 environment, and provide guidance on establishing an organizational data loss prevention program. Questions are due by May 26th and quotes are due by June 16th. The proof of concept will start in August 2020 and end in December 2020/January 2021. The solicitation is not set aside for small businesses.
View the file
Other files for this federal contract opportunity
Show all 28
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
Sheet1
Requirement: Enterprise Data Loss Prevention (E-DLP)
| SOO Paragraph, Synopsis/Solicitation, or Attachment Reference | Contractor Question | Government Response |
| Synopsis/Solicitation and SOO | Can the government please clarify where exactly (which networks/classifications) it expects the solution's DLP sensors to be deployed for the purposes of the POC? While Scenario 1 mentions cross domain integration, its unclear whether a full DLP deployment is required for NIPR, SIPR, and/or JWICS for the purposes of this POC. | For the purposes of this POC, the target networks are NIPR and SIPR. We would expect the central security policy management capability to reside on SIPR with the ability to deploy security policies on NIPR and SIPR. Additionally, we would expect alerting on NIPR to be presented on a SIPR management console such that an operator can analyze and process alerts from both NIPR and SIPR on a single console. |
| Synopsis/Solicitation and SOO | Because a CDS solution takes considerable time to get approved and deployed on the network - time that would eat into the short, 5 month POC - will the government be requiring the contractor to fully deploy and implement a CDS as part of this POC? Or, will the contractor be able to simply demonstrate integration with the USAF's existing CDS solution in order to focus the POC on the power of DLP? | The desired approach for this POC is to demonstrate integration with existing AF CDS solutions. |
| SOO | With UEBA solutions critical to preventing Insider Threats, will the government be requiring the contractor to deploy a fully integrated UEBA solution during this POC? | The purpose of the POC is to demonstrate market leading capabilities so that the AF can better understand technical, policy, training, and other implications of market leading E-DLP offerings. The contractor should be able to demonstrate the value of thier UEBA solution to the AF in such a way as to enable the AF to make informed decisions on possible future acquisitions. |
| SOO | With EDR being referenced, is the government interested in seeing a fully deployed endoint protection solution with fully integrated EDR during this POC? | The primary focus of this POC is Enterprise Data Loss Prevention. If a vendor uses an EDR as part of their technical solution to support E-DLP then it will need to be implemented to such a level that the AF can evaluate it's efficacy to prevent data loss at the endpoint. Additional EDR features are not the focus of this POC. |
| SOO | Understanding that the AFIN has great size and complexity, can the government provide a more specific number of end users it requires to be supported in order for the contractor to meet requirement 3.j. "Ability to scale solution to the AFIN?" | Estimates in terms of the number of endpoints and users on the AFIN vary, but generally the contractor would use 750K users and 1M endpoints as planning factors for future consideration. |
| SOO | While no less than 100 users is specifically called out in the SOO for the purposes of this POC, how does the government plan to ensure that the contractor is providing a solution that has the "ability to scale solution to the AFIN?" Should the contractor(s) be required to provide a signed/certified listing of all of their customer's with over 250K users? | The vendor's answers to the technical scenarios and CSOW will be used to evaluate whether the contractor has the ability to scale the solution to the AFIN |
| SOO | How does the government plan to confirm the technical capabilities of the solution? Should each contractor be required to provide answers to the SOO with the detailed specifics for how they meet each of the government's requirements? | Although the RFIs submitted previously provided insight into how each of the vendor solutions met each of the requirements specified, the AF would expect the Proposal to be sufficiently detailed to aid in not only assessing the technical merit of the proposed solution for each requirement specified, but also the Information Assurance implications of the technical solution (e.g., information and artifacts that will aid in the development of the required Risk Management Framwork package to attain an Interim Authority To Test (IATT)). Key artifacts include answering the Air Force (AF) Information Technology (IT) System Categorization and Selection Checklist, System Authorization Boundary (Topology) Artifact, Hardware list, Software list, Security Technical Implementation Guide (STIG) Applicability List, Ports, Protocols, and Services Matrix (required), System and Cybersecurity Test Plans and Schedule, Cybersecurity Test Results (e.g., vulnerability scans, STIG check results). |
| Synopsis/Solicitation II(1)b.5 Scenario 2 | What is the existing system/network architecture to be used in conjunction with the pilot? | Attached are a notional base area network architecture and cloud hosted services connectivity that fairly represent the system/network architecture for this POC. |
| SOO, Paragraph 3h and 3l | Integration of products is a common industry practice to provide solutions/functionality. Can the AF please explain what is acceptable versus unacceptable integration into another product for functionality to meet the Capabilities of the SOO? | Given the breadth of the requirements specified in the RFP, it is difficult to answer this directly. The asnwer woiuld depend on what integrations are required. The AF is interested in any opportunitiy to retire, replace, conslidate, and/or integrate with existing capability investments. However, the AF adheres to following industry standard best practices and will carefully weigh the necessary integrations proposed by each vendor's technical solutions provided in their Proposals in terms of function and security. For example, we do desire that the vendor will integrate with existing AF Cross Domain Solutions. We also expect integration with cloud hosted services such as O365. Note that the AF expects that the system/network environment will be returned to the state preivous to the start of the Proof Of Concept and therefore any integrations with existing AF capabilities will need to be rolled back without affecting daily network and security services of the host base. |
| SOO, Paragraph 3l | Can the proposed solution provide OEM integration of products for functionality? | Yes, but the vendor must either provide the necessary OEM products or integrate with OEM products the AF already owns. The AF will not acquire additional capabilties or services above and beyond current investments in order to enable the E-DLP POC vendor's technical solution |
| SOO, Paragraph 3l | Can the proposed solution provide integration of vendor acquired companies/products for functionality? | Yes |
| SOO, Paragraph 3l | Can the proposed solution integrate into a commercial database, like Oracle or SQL Server, for functionality? | Yes, but the vendor must either provide the necessary OEM products or integrate with OEM products the AF already owns. The AF will not acquire additional capabilties or services above and beyond current investments in order to enable the E-DLP POC vendor's technical solution |
| SOO Paragraph 1c and 4c | What are the number of monitoring points available/required? What are the bandwidth requirements for monitored traffic? | As this is a Proof of Concept, the number and type of montioring points will be limited to the minimum required to assess the vendor solution against our five broad egress use cases (endpoint, network, cloud, email, storage) as well as on specific OSs listed in the SOO. |
The average outbound traffic at Langley AFB is 7.65M/s; peak of 13M/s.
| SOO, Paragraph "Proof of Concept" & 4a, Synopsis/Solicitation II(1)b. | Are the 100 users/Data Owners to be located on JBLE Langley AFB only? | The users and data owners will be on Langley AFB. The operators and analysts monitoring the E-DLP system and creating security policies will reside at Lackland AFB. |
| Synopsis/Solicitation II(1)b.5 Scenario 1 | Will hardware or cloud infrastructure be provided, or do bidders need to account for the acquisition of such resources for the purposes of the pilot? | The AF will not be acquiring additional hardware or software to support this Proof of Concept. The vendor will be required to provide all necessary hardware and software to meet the requirements of this POC. The vendor may integrate with existing AF hardware and software to implement their technical solution. The technical solution must demonstrate DLP capabilities related to endpoint, network, storage, email, and cloud services. The AF has adequate operational infrastructure in place to enable a technical solution that covers the five broad egress use cases. |
| N/A | Would the government define the timeframe of expectations for implementation? | Aug 2020 thru Dec 2020 |
| N/A | For any cloud resource usage, will the cloud spend be billing through an existing, government-owned Master Billing Account? | No |
| N/A | What are the certification and accreditation requirements of the proposed solution? DoDIN Approved Products List? Common Criteria? Etc. | Although employing technical soluitons that may already have Authorizations to Operate (ATO) from other USG departments or agencies or that may already be listed on the DoDIN APL, the POC team is preparing to gain an Interim Authority To Test (IATT). To gain the IATT, the POC team will need to address issues such as answering the Air Force (AF) Information Technology (IT) System Categorization and Selection Checklist, System Authorization Boundary (Topology) Artifact, Hardware list, Software list, Security Technical Implementation Guide (STIG) Applicability List, Ports, Protocols, and Services Matrix (required), System and Cybersecurity Test Plans and Schedule, Cybersecurity Test Results (e.g., vulnerability scans, STIG check results). |
| N/A | Can bidders/solution providers be a foreign owned entity? | No |
| Synopsis/Solicitation and SOO | Because a CDS solution takes considerable time to get approved and deployed on the network - time that would eat into the short, 5 month POC - will the government be requiring the contractor to fully deploy and implement a CDS as part of this POC? Or, will the contractor be able to simply demonstrate integration with the USAF's existing CDS solution in order to focus the POC on the power of DLP? | The desired approach for this POC is to demonstrate integration with existing AF CDS solutions. |
| Synopsis/Solicitation and SOO | If demonstrating the CDS integration across NIPR/SIPR is required, but for the purposes of this POC only, the contractor is allowed to use the existing CDS solution as GFE (simply to prove the integration), then can the USAF provide the name, make, and model of the current CDS solution it has deployed? | Due to the sesnsitivity of this information, it will only be provided at the time of award to a cleared vendor. |
| SOO | Consdering that, at least as far as we know, no manufacturer today has an endpoint agent for MS-DOS, Windows 98, and Windows 2000, will the USAF accept endpoints running those operating systems to be protected by other components of a holistic EDLP solution? (i.e. network sensors, web sensors, etc.) | Yes |
| SOO | - What use cases associated with a Linux agent (e.g. data at rest scans, data in motion, etc.) is the USAF requiring? |
- Is the Linux requirement intended for servers or for endpoints?
| - What specific versions of Linux is the USAF requiring and/or using today (e.g. RHEL, Ubuntu, CentOS, etc.)? | The AF desires to exercise at rest, in transit, and in process use cases on Linux workstations and servers. Current examples include RHEL6, Ubuntu10, and various Linux Kernels. | ||
| Synopsis/Solicitation | Typically, customers have 1 policy set for their unclassified networks (NIPR), and a different (or multiple) policy sets for their classified networks (SIPR in this case) as traditionally customers want to protect different data sets across the varios network classification levels. i.e. something that needs protection on SIPR, may not necessarily need to be protected on NIPR (or vice versa). Additionally, on SIPR (or other classifed networks) DLP/Insider Threat policy would most likely become classified itself, meaning that you definitely wouldn't want to apply the same policy set on an unclassified network. Therefore, with regard to Scenario 2, is the government A) asking the contractor to show a seperate unclassified/NIPR policy set deployed at Langley from Lackland, as well as a seperate policy set deployed at Langley from Lackland on SIPR? Or, B) asking the contractor to deploy a single policy set simultaneously across NIPR and SIPR? We assume option A would be the case considering the potential for an incident, but would like the government to confirm. | The AF needs the ability to apply unclassified, common policy to all networks and classifications. The AF also needs the ability to apply potentially classified, targeted policies. | |
| Synopsis/Solicitation | This question is directly associated with the question directly above in excel line 9. As one of it's "must have" requirements, the government lists the ability to "Write Once, Publish Everywherer" across all DLP/Insider Threat sensors. Can the government clarify if the "write once, publish everywhere" requirement is for single networks only (i.e. individual policy sets for NIPR, individual policy sets for SIPR, etc.), or does the government mean for the "Write Once, Publish Everywhere" to be across networks (across NIPR/SIPR/JWICS, etc.) Due to the reasons listed above we assume that the USAF means for this requirement to be across single networks only, but would like to confirm. | The AF needs the ability to "write once, publish everywhere" across all networks and all classifications. In instances where a security policy itself may be classified, the AF needs the ability to publish that policy on targeted networks and enclaves. | |
| Synopsis/Solicitation | On page 4 of the Synopsis/Solicitation, the USAF lists 'MUST HAVES/NON-NEGOTIABLE" requirements. However, even though this is an EDLP RFP, the USAF lists "integrating with Cross Domain Solutions" as the #1 requirement. Can the government clarify whether or not the 5 requirements listed will be evaluated evenly, or if certain requirements will carry more weight than others? | There is no weighting among requirements at this time. | |
| SOO | Does the government require the prime hold a facilities clearance and/or have cleared personnel? As the DoD is just recently looking for DLP solutions, most of the services and programmatic expertise comes from companies who may not hold the proper clearances for cleared work. If a facilities clearance and/or having cleared personnel is a requirement for this POC, is the government willing/able to sponsor clearances in order to ensure an experienced DLP consulting and programmatic contractor is able to respond to this solicitation? | The POC vendor will need to provide cleared personnel up to SECRET. The government will not sponsor clearances. | |
| SOO | As the DoD is just recently considering DLP solutions, will the government be providing an IATO (or similar) approval immediately upon award in order for solutions that may not currently have every government certification to be deployed onto the network in support of this POC? Considering the short (5 month) timeline, ensuring that an IATO will be provided will be critical in order to stay on the required timeline. | The AF anticipates a delay between when the contract is awarded and the start of the period of performance due to Information Assurance issues that cannot be addressed until the technical solution is known. The AF will be seeking an Interim Authority to Test (IATT) which will require providing information such as Hardware list, Software list, Security Technical Implementation Guide (STIG) Applicability List, Ports, Protocols, and Services Matrix, System and Cybersecurity Test Plans and Schedule, and Cybersecurity Test Results (e.g., vulnerability scans, STIG check results). | |
| Synopsis/Solitication (Technical Scenario 1) | Is the AF expecting a single Policy Controller on highest network to control lower network policies through Cross Domain? Or will the AF expect to have a Policy Controller on each classification level that can communicate to remote locations within the same classification level? | The AF is expecting a single Policy Controller on the highest network to control lower network policies through the Cross Domain Solution. | |
| SOO | How many users/endpoints per classification networks? | For the purposes of this POC, the AF seeks a minimum of 100 users and 100 endpoints to fully evaluate the propsed technical solution. | |
| SOO | Will the POC use simulated networks or production networks to prove the cross domain functionality? | The POC will use production networks to prove the cross domain functionality | |
| SOO | Will the POC require an ATO? | The POC wil require an Interim Authority to Test (IATT). | |
| Synopsis/Solitication | Is it the Air Force’s intent to award this solicitation in FY2020 if funding becomes available before 1 Oct 2020? | Yes. | |
| Synopsis/Solitication | To evaluate the technical portions of the POC, does the vendor need to develop a test plan or does the Air Force already have a test plan? | The vendor, in coordination with the AF, will develop a test plan to support the requred IATT. | |
| SOO(Section 3e) | Can additional information and guidance be provided on required standards for redaction and tokenization? | AF is seeking industry best practices for redaction and tokenization. No existing formal standards exist. | |
| SOO (Section 3e) | Is the requirement to provide product integration with 3rd party solutions for data redaction and tokenization or to provide native capabilities built into the DLP solution? | 3rd party solutions for redaction and tokenization are allowable, but must be provided by the vendor as part of this soliciation. The AF will no purchase any technologies for the purposes of this POC. | |
| SOO | Will the AF consider increasing the number of endpoints from 100 users to 1000 users? This would better provide a picture of activity and result in more accurate risk score per user based on the amount of data providing user baseline for analytic modeling. | The minimum required by the AF is 100 endpoints and users. If the vendor requires more endpoints and/or users to fully present their techincal capabilities then the AF then that is acceptable. | |
| SOO | Will the AF be providing the infrastructure to virtualize the POC or can the vendor provide loaner hw equipment to be returned minus hard drives? | The AF is not acquring any technologies to support this POC. The vendor is required to provide all necessary infrastructure to support their proposed technical solution. | |
| Synopsis/Solicitation | Is it possible to get any extension beyond the June 16th due date? | No. | |
| Where is the POC running and what is it running on? Would it be acceptable to deploy a POC in a virtual, cloud-based POC environment to be integrated with and shared with the government? | Where the POC runs and on what it is running will be dependent on the technical solution provided by the vendor. If the vendor solution is or has components that are virtual, cloud-based then that is acceptable. However, the vendor is required to provide that infrastructure for the POC. The AF will not be acquiring additional capabilities to enable a vendor technical solution. | ||
| In regard to E-DLP Capability Requirements, will the government clarify its definition of "high integration" with threat detection capabilities such as EDR and UEBA? | "High integration" implies that all the components of the E-DLP techincal solution are integrated in such a way as to provide near real-time to real-time alerting of automated system actions and recommendations to the operator/analyst. | ||
| Will the government please confirm whether onsite engineering presence will be required throughout the full five (5) month POC? | The level of onsite engineering assistance will depend on the complexity of the proposed technical solution and the length of time required to implement the full technical solution. | ||
| Reference SOO 3L: | The SOO states that the capability must not require integration into another product for functionality. Will the government please clarify this requirement? The lion's share of solutions incorporate multiple connected components (products) and are built to afford the highest level of usability and protection. If the integration of an additional capability improves the security efficacy of the USAF and can be useful to the underlying use case, are respondents able to propose them as part of its POC solution. | The intent of that requirement was to ensure that the proposed technical solution either 1) provide all necessary technologies to implement the set of requirements or 2) relies on integration with existing AF technologies and investments. The AF will not purchase any technologies to enable the technical solution of the vendor. | |
| Reference SOO 4D: | The requirement states that the solution should demonstrate the ability to scale. Can the USAF please clarify how it expects vendors to demonstrate scalability during the POC? | The vendors answers to the technical scenarios and CSOW should demonstrate scalibility such as implementing a similar technical solution in a large, complex, global network. Further, the vendor could also demonstrate scalability by designing a POC in which we can scale from 100 endpoints and users up to potentially the entire target base population. | |
| Reference SOO 4F: | The requirement states the USAF expects for the awardee(s) to recommend options to retire, replace, and/or consolidate USAF DLP-related capabilities. Will the government please clarify which DLP-related solutions are currently under ownership and/or currently deployed? | The AF employs point solutions for specific DLP use cases. Examples include the Security Compliance Center in Microsoft Office 365 and employment of Fidelis sensors on premises. | |
| Reference SOO 5D: | Will the USAF please clarify its expectations for performing internal content analysis? | Internal content analysis includes, but is not limited to, keyword matches, dictionary matches, the evaluation of regular expressions, internal functions, and other methods to detect content that matches DLP policies. | |
| Reference SOO 5E: | In this section, the USAF defines the operating systems that require the ability for the solution to be "employed on". Can the USAF please clarify its definition of "employed"? In addition, how many endpoints (including servers) are running MS-DOS, Windows 98, and Windows 2000? These are highly legacy operating systems which Microsoft is no longer supporting. | The AF will not release the number of endpoints running available operating systems. Employment means that the given operating system is installed and in use on a given endpoint. If the vendor's technical solution, for example, does not have an agent that can be deployed on endpoints employing legacy operating systems, then the AF will consider alternatives to endpoint agents that can meet the intent of the stated endpoint requirements. | |
| Reference SOO 5M: | Will the government clarify whether responsibility falls to the user or administrator for taking action that is user driven and customizable when sensitive data is found? | The AF desires a solution that enables the user, administrator, and data owner to take action depending how the security policy is designed. One of the central tenets of this POC is to be better define these roles and responsibilities within the organization and establish the appropriate organizational policies, training, and E-DLP security policies necessary to implement an AF E-DLP Program. | |
| CDS is governed by NSA not AF, based on our understanding. What specifically are you looking for in CDS? Is the AF simply looking for no spillage of data? | The AF seeks the means to centralize security policy management and E-DLP administration across all networks, all classifications. We expect that means, for example, that alerts from NIPR would need to traverse a CDS such that the alerts can be displayed on a SIPR-based administration/operator console. | ||
| I have a question about the existing solution through O365 the Air Force currently owns for DLP. Are you looking for support or enablement for a POC, or are you looking to procure the same solution again? | The AF is seeking an E-DLP technical solution that takes into account existing investments and operating environments and makes recommendations to retire, replace, or consolidate where appropriate. | ||
| EDLP Combined Synopsis/Tech scenarios | The proposed technical solution must integrate with the AF Cloud Hosted Enterprise Services (CHES) environment. QUESTION: How is this integration being paid for? Is the Air Force paying the AF CHES CSP to host this integrated solution, or is the vendor who is building the EDLP and CDS paying the AF CHES CSP hosting costs? | The AF employs DLP capabilities resident in Microsoft O365 through the Security Compliance Center to enforce email DLP. The AF is seeking technical solutions that either integrate with O365 email DLP or replaces those services through other means. The AF does not want to employ email DLP policies separately in SCC and then all other DLP policies through other means. The goal is to "Write Once, Publish Everywhere." The AF already has a production O365 environment so no additional investment is required for this POC. | |
| EDLP Combined Synopsis/Tech scenarios | In our pricing, should we identify the Cloud Hosting Costs for the CDS or is the Government paying for that via the AF CHES environment? | This is confusing since the AF Cloud Hosted Enterprise Services is different from a Cross Domain Solution. The AF is not paying for any technologies required to implement the vendor's techncial solution. The vendor must provide all needed technologies and/or integrate with existing AF production technologies. | |
| EDLP Combined Synopsis/Tech scenarios | In our pricing, should we identify the Cloud Hosting Costs for the EDLP solution or is the Government paying for that via the AF CHES environment? | If there are cloud hosted components of the vendor's technical solution, the vendor will need to incorporate those costs into their pricing. | |
| EDLP Combined Synopsis/Tech scenarios | Since the POC is lasting 5 months, does the Government expect the RMF package to be completed prior the POC starting? | Yes. The AF will require an approved Interim Authority to Test (IATT) prior to the start of the period of performance. Most of the artifacts to support the IATT approval are dependent on the specific technical solution the AF is seeking in the POC and therefore cannot be complete until after awarding the contract. | |
| EDLP Combined Synopsis/Tech scenarios | Does the Government expect the RMF Package to be completed and signed during the 5 month POC? | The AF is seeking an Interim Authority to Test for the puposes of this POC. During the POC, the AF will continue to build the remainder of the RMF package to prepare for an eventual Authority to Operate (ATO) if the technical solution meets the AF's E-DLP requirements. | |
| EDLP Combined Synopsis/Tech scenarios | Who is the Authorizing Official that our A&A team will work with for the RMF package to be completed? | The Authorizing Official for this POC is ACC/A6. The A&A team will work with the 688 CW who will in turn manage all coordination for the ACC/A6. | |
| EDLP Combined Synopsis/Tech scenarios | Does the AF CHES provide a SIPRNet cloud? | For the purpose of this POC, the vendor only needs to demonstrate E-DLP cloud egress on NIPR. | |
| EDLP Combined Synopsis/Tech scenarios | What is the Cloud Access Point that the AF CHES uses? | That information will be provided once the contract is awarded due to its sensitive nature. | |
| EDLP Combined Synopsis/Tech scenarios | Is the CDS requirement a bidirectional feed meaning NIPR to SIPR to NIPR? | Yes. The AF requires the ability to write and publish security policies from SIPR to NIPR. Likewise, alerting of DLP events on NIPR must be presented on a SIPR-based operator console. | |
| EDLP Combined Synopsis/Tech scenarios | Where does the Government want the ELDP data to reside for NIPR / SIPR / JWCIS? In other words, because a CDS is being used to push data from NIRP to SIPR does the Government want the ELDP data to reside on the NIPR and SIPR, or only on the SIPR? | It's unclear what the vendor means by "EDLP data." If this means security policies and alerts, it will depend in part of the vendor's technical solution. At this time, the AF requires the ability to "write once, publish everywhere" on all networks and all classifications. There may be cases where certain policies may be classified and need to reside on the appropriate network. | |
| EDLP Combined Synopsis/Tech scenarios | Is the CDS requirement a one way feed meaning NIPR to SIPR? | No. It is a two-way feed to enable security policies written on SIPR to be published to NIPR. | |
| EDLP Combined Synopsis/Tech scenarios | Is the JWCS EDLP feed going from the JWCS to SIPR? | JWICS is not in scope for this POC. Target networks are NIPR and SIPR. | |
| SOO 1 | Based upon our experience with deploying an E-DLP solution, the platform requires a learning phase of up to 6 months. Does the government expect the learning phase to be part of the POC? | Yes. The AF expects training for users, data owners, administrators, operators/analysts, maintainers and other work roles to be included in this POC. | |
| SOO 5e | We know that Microsoft no longer provides software support, updates, or security patches for MS-DOS, Windows 98, nd Windows 2000. Based on the threat vectors that can take advantage of this critical vulnerability, are these 3 operating systems running on AF.mil (NIPRNET)? Are these 3 operating systems running on AF.smil.mil (SIPRNET)? | Due to the sesnsitivity of this information, it will only be provided at the time of award to a cleared vendor. | |
| SOO 3f and 8 | What cloud provider is required for the Hybrid on-premises and cloud-based E-DLP solution? | The AF is not specifying a required cloud provider for this POC. The only stiupation is that if a cloud provider is required to implement the vendor's proposed technical solution that 1) the vendor should price the cloud services in the POC and 2) the CSP must meet all applicable FEDRAMP requirements. | |
| EDLP Combined Synopsis | What cloud service provider is hosting the AF Cloud Hosted Enterprise Services (CHES) environment? | Microsoft | |
| SOO- The POC will also demonstrate the ability to aggregate and correlate alerting across multiple networks/classifications (e.g., NIPR, SIPR, JWICS) using a Cross Domain Solution. | Can you provide more information or explain the concept of a cross domain alerts? How would you desire for it to work? | As an example, in the event that a DLP policy is triggered on NIPR, that alert should be presented at an operator/analyst console resident on SIPR. | |
| SOO - Describe the architecture for how an operator at Lackland AFB can publish a policy and apply it to all data egress points at Langley AFB. | What’s the process for commands to submit information types and policies? Related - will the vendor be expected to create a means for developing and governing an approval flow for these? | The AF intends to execute this POC to enable a future AF E-DLP Program. In other words, this is not just a technology POC, but an organizational POC as well. The AF seeks guidance on industry best practice and other consulting as part of this POC to ensure an AF E-DLP Program will be successful. The AF is currently working on defining its information types and desired policies in preparation for this POC, but will definitely seek guidance and consulting from the vendor. | |
| Synopsis- Specific descriptions of how the Offeror will integrate their solution with the AF CHES O365 environment is required. The Offeror shall also demonstrate the ability of the solution to alert and provide reports to 68 NWS operators of E-DLP violations and/or automated or recommended actions taken at Langley AFB. | Can you provide information or explain how and why the CHES O365 DLP POC will integrate with the capabilities described in this RFP? | The AF currently invests in subscription DLP services wihin the CHES O365 environment. The AF requires the ability to "write once, publish everywhere," so the vendor's technical solution must account for the current AF CHES O365 environment where we currently employ DLP security policies. This may mean that the vendor presents a central security policy console that abstracts the Microsoft Security Compliance Center through, for example, API calls, or may even recommend retiring/replacing those Microsoft-based DLP services and enables a different solution for DLP in the O365 environment. | |
| SOO - Encrypted traffic management providing Secure Socket Layer (SSL) and Transport Layer Security (TLS) visibility (break/inspect) | Based on this information is the USAF planning on continued use of S/MIME? | Due to the sesnsitivity of this information, it will only be provided at the time of award to a cleared vendor. | |
| With regards to the notice, will Phase I include acquiring HW/SW? | Phase I will certainly allow for a site survey and acquisition of HW/SW, but to the greatest extent possible, the AF expects the vendor to either have the required HW/SW in hand or be able to demonstrate a very short timeline for acquisition given the tight timeline of this POC. As a reminder, the AF is not seeking HW/SW acquistion as part of this POC. The POC is intended for a vendor to demonstrate their technical solution through the employment of vendor owned HW/SW in the AF's production environment and then retrograde at the conclusion of the POC. | ||
| Will you require both KMIP and non-KMIP integration? | Yes. | ||
| Will a requirement for American-made/manufactured be a requirement or benefit for this effort | Yes. | ||
| Based on the success of this effort, will the USAF anticipate using Lackland AFB as a pilot program to replicate the success of this EDLP with other locations? | Yes. | ||
| The documentation mentions a myriad of technologies that will require integration. Could you provide detail of those technologies? | This question is too broad to answer as written. The AF expects that the vendor will perform all integration as reqiured to demonstrate how their technical solution meets the requirements as stated in the Statement of Objectives. | ||
| Will this require FIPS 140-2, Level 2 or higher required as part of this effort? | Yes. | ||
| What is the anticipated time frame for the deployment of the POC? Could you estimate on the time frame for this effort through to deployment | The target start for the Proof of Concept is Aug 2020 with the expected end date in Dec 2020/Jan 2021. | ||
| When looking at the increasing amount of data that will be encrypted, how are the keys for the data, as well as the policies restricting/granting the use of these keys/data, being managed? | The AF PKI Program Office is available to answer these questions specifically. | ||
| As part of Phase 1, we anticipate including acquisition of a key management solution that includes the ability to provide centralized full life cycle policy management. If no, could you please explan how data will be protected in a standardized manner? | The AF PKI Program Office is available to answer these questions specifically. | ||
| We would like to ask if the Air Force is only seeking responses that can cover all three scenarios (Cross Domain Solution Integration, Central Security Policy Management and Integration with AF CHES, and Technical and Procedural Approach to an Organizational E-DLP Program), or is it acceptable for bidders to respond to just one or two of the scenarios? Thank you. | All three scenarios must be answered. | ||
| The North American Industry Classification System (NAICS) code for this project is 541519 with a size standard of $27.5M. Is the intent to set this requirement aside as a Small Business Set Aside? | This requirement will not be a Small Business Set Aside. |
File details come from the government source that posted it. Updated .