MAS - Missing Link Communications LLC - GS35F0448R
PDF 469 KB
- Attached to
- Federal Supply Schedule GS35F0448R Federal contract IDV
- Contract number
- GS35F0448R
- Issued by
- GSA Federal Acquisition Service
About this file
This document provides details for a federal supply schedule contract held by Missing Link Communications, LLC. The contract was awarded on March 24, 2005 by GSA Federal Acquisition Service and has a period of performance through March 23, 2025. It establishes labor rates for several IT-related special item numbers, including highly adaptive cybersecurity services, IT professional services, and management consulting. Relevant labor categories are defined for areas such as cybersecurity engineering, network administration, project management, and training. The contract holder is authorized to provide services including risk assessments, security architecture design, vulnerability testing, and incident response across the federal IT marketplace through this multiple award schedule vehicle.
Missing Link Communications, LLC (DBA Missing Link Security) Pricelist and/or Vendor Terms and Conditions for GS35F0448R, a Federal Supply Schedule awarded to Missing Link Communications, LLC (DBA Missing Link Security), under Information Technology Schedule 70 (IT-70)
View the file
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
General Services Administration Federal Acquisition Service
Authorized Federal Supply Schedule FSS Price List
Schedule: Multiple Award Schedule (MAS)
Contract Number: GS-35F-0448R
Contract Period: March 24, 2015 – March 23, 2025
Pricelist Version: PA-0067 dated Jan 26, 2024
UEI: NYL2NY3UJZD5
NAICS: 541519
Business Size: Service Disabled, Veteran-Owned Small Business (SDVOSB), Woman-Owned Small Business (WOSB)
SIN Description
OLM/RC Order-Level Materials (OLMs)
541611/RC
Management and Financial Consulting, Acquisition and Grants Management Support, and Business Program and Project Management Services
54151HACS/RC
Highly Adaptive Cybersecurity Services (HACS)
ALL SUBCATEGORIES
54151S/RC Information Technology (IT) Professional Services
D301 IT Facility Operation and Maintenance
D302 IT Systems Development Services
D306 IT Systems Analysis Services
D307 Automated Information Systems Design and Integration Services
D308 Programming Services
D310 IT Backup and Security Services
D311 IT Data Conversion Services
D316 IT Network Management Services
D399 Other IT Services, Not elsewhere classified
1. All non-professional labor categories must be incidental to and used solely to support hardware, software and/or professional services, and cannot be purchased separately.
2. Offeror’s and Agencies are advised that the Group MAS – Information Technology Schedule is not to be used as a means to procure services which properly fall under the Brooks Act. These services include, but are not limited to, architectural, engineering, mapping, cartographic production, remote sensing, geographic information systems, and related services. FAR 36.6 distinguishes between mapping services of an A/E nature and mapping services which are not connected nor incidental to the traditionally accepted A/E Services
3. This solicitation is not intended to solicit for the reselling of IT Professional Services, except for the provision of implementation, maintenance, integration, or training services in direct support of a product. Under such circumstances, the services must be performance by the publisher or manufacturer or one of their authorized agents.
Missing Link Communications, LLC dba
Missing Link Security 7630 Little River TPKE, Ste 205
Annandale, VA 22003
Laura Prakash, CEO
PHONE:
602-821-1839
FAX:
610-564-8221
EMAIL:
laura.prakash@mls-va.com
Online access to contract ordering information, terms and conditions, pricing, and the option to create an electronic delivery order are available through GSA Advantage!®. The website for GSA Advantage!® is:
https://www.GSAAdvantage.gov.
For more information on ordering go to the following website:
https://www.gsa.gov/schedules.
mailto:laura.prakash@mls-va.com https://www.gsaadvantage.gov/ https://www.gsa.gov/schedules
Contents 1a. Table of Awarded Special Item Numbers (SINs):
1b. Identification of the lowest priced model number and lowest unit price for each SIN:
1c. Description of All Labor Categories:
2. Maximum order:
3. Minimum order:
4. Geographic coverage (delivery area):
5. Point(s) of production (city, county, and State or foreign country)
6. Discount from list prices or statement of net price
7. Quantity Discounts:
8. Prompt payment terms:
9. Foreign Items (list items by country of origin):
10a. Time of Delivery: (Contractor insert number of days.)
10b. Expedited Delivery:
10c. Overnight and 2-day delivery:
10d. Urgent Requirements:
11. F.O.B. point(s):
12a. Ordering address(es):
12b. Ordering procedures:
13. Payment address(es)
14. Warranty provision:
15. Export packing charges, if applicable:
16. Terms and conditions of rental, maintenance, and repair (if applicable)
17. Terms and conditions of installation (if applicable):
18a. Terms and conditions of repair parts indicating date of parts price lists and any discounts from list prices (if applicable)
18b. Terms and conditions for any other services (if applicable)
19. List of service and distribution points (if applicable)
20. List of participating dealers (if applicable)
21. Preventive maintenance (if applicable)
22a. Special attributes such as environmental attributes (e.g., recycled content, energy efficiency, and/or reduced pollutants)
22b. Section 508 compliance for EIT:
23. Unique Entity Identifier (UEI) Number:
24. Notification regarding registration in System for Award Management (SAM) database
Exhibit A: Labor Category Rates
TERMS AND CONDITIONS APPLICABLE TO HIGHLY ADAPTIVE CYBERSECURITY SERVICES (HACS) (SPECIAL
ITEM NUMBERS 54151HACS)
CYBERSECURITY LABOR CATEGORY DESCRIPTIONS – 54151HACS
TERMS AND CONDITIONS APPLICABLE TO INFORMATION TECHNOLOGY (IT) PROFESSIONAL SERVICES
(SPECIAL ITEM NUMBER 54151S)
IT LABOR CATEGORY DESCRIPTIONS – 54151S
PROFESSIONAL SERVICES - BUSINESS ADMINISTRATIVE SERVICES - 541611
Customer Information
1a. Table of Awarded Special Item Numbers (SINs):
OLM, OLM/RC – Order Level Materials (OLMs) 541611/RC - Management and Financial Consulting, Acquisition and Grants Management Support, and Business Program and Project Management Services 54151HACS, 54151HACS/RC – Highly Adaptive Cybersecurity Services (HACS)
High Value Asset Assessments Risk and Vulnerability Assessments Cyber Hunt Incident Response Penetration Testing
54151S, 54151S/RC – Information Technology (IT) Professional Services
1b. Identification of the lowest priced model number and lowest unit price for each SIN:
See Exhibit A.
1c. Description of All Labor Categories:
See Exhibit B.
2. Maximum order:
OLM, OLM/RC – $250,000
541611/RC – $1,000,000
54151HACS, 54151HAC/RC – $500,000
54151S, 54151S/RC – $500,000
3. Minimum order:
$100.00
4. Geographic coverage (delivery area):
Domestic Delivery Only (the 48 contiguous states, D.C., Hawaii, Alaska, and US Territories). Domestic Delivery also includes a port of consolidation point, within the aforementioned areas, for orders received from overseas activities.
5. Point(s) of production (city, county, and State or foreign country).
Missing Link Communications, LLC
6. Discount from list prices or statement of net price.
Prices are listed as GSA Net. Discount deducted and IFF included.
7. Quantity Discounts:
None
8. Prompt payment terms:
Net 30. "Information for Ordering Offices: Prompt payment terms cannot be negotiated out of the contractual agreement in exchange for other concessions."
9. Foreign Items (list items by country of origin):
Not Applicable
10a. Time of Delivery: (Contractor insert number of days.)
Missing Link will adhere to the delivery schedule stipulated in each delivery order and/or delivery order amendment.
10b. Expedited Delivery:
See Urgent Requirements (10d) below.
10c. Overnight and 2-day delivery:
See Urgent Requirements (10d) below.
10d. Urgent Requirements:
When the Federal Supply Schedule contract delivery period does not meet the bona fide urgent requirements of an ordering activity, ordering activities are encouraged, if time permits, to contact the Contractor for the purpose of obtaining accelerated delivery. The contractor shall reply to the inquiry within 3 workdays after receipt. (Telephonic replies shall be confirmed by the Contractor in writing). If the Contractor offers an accelerated delivery time acceptable to the ordering activity, and order(s) placed pursuant to the agreed upon accelerated delivery time frame shall be delivered within this shorter delivery time and in accordance with all other terms and conditions of the contract.
11. F.O.B. point(s):
Destination, Point of Exportation
12a. Ordering address(es):
Missing Link Communications, LLC
12b. Ordering procedures:
For supplies and services, the ordering procedures, information on Blanket Purchase Agreements (BPA’s) are found in Federal Acquisition Regulation
(FAR) 8.405-3.
13. Payment address(es).
Missing Link Communications, LLC
Customer Information
14. Warranty provision:
Not Applicable
15. Export packing charges, if applicable:
Not Applicable
16. Terms and conditions of rental, maintenance, and repair (if applicable).
Not Applicable
17. Terms and conditions of installation (if applicable):
Not Applicable
18a. Terms and conditions of repair parts indicating date of parts price lists and any discounts from list prices (if applicable).
Not Applicable
18b. Terms and conditions for any other services (if applicable).
Not Applicable
19. List of service and distribution points (if applicable).
Missing Link Communications, LLC
20. List of participating dealers (if applicable).
Not Applicable
21. Preventive maintenance (if applicable).
Not Applicable
22a. Special attributes such as environmental attributes (e.g., recycled content, energy efficiency, and/or reduced pollutants).
Not Applicable
22b. Section 508 compliance for EIT:
The EIT standards can be found at:
www.Section508.gov/.
23. Unique Entity Identifier (UEI) Number:
NYL2NY3UJZD5
24. Notification regarding registration in System for Award Management (SAM) database.
Contractor has an Active Registration in the SAM database.
http://www.section508.gov/
Exhibit A: Labor Category Rates
SIN Labor Category March 2022 -
March 2023 -
March 2024 -
54151S Associate Information Security (IS) /Information Management
(IM) Specialist $92.34 $96.04 $99.88
54151S Compliance Officer $218.16 $226.89 $235.96 54151S Expert Consultant I $238.28 $247.81 $257.72
54151S Information Systems Security Officer (ISSO) $208.96 $217.32 $226.01
54151S Information Security (IS)
/Information Management (IM) Specialist
$111.71 $116.18 $120.82
54151S Junior Level Security Consultant $184.61 $192.00 $199.68 54151S Lead Engineer $286.90 $298.37 $310.31 54151S Management Analyst - Sr. $99.40 $103.38 $107.52 54151S Management Analyst - Mid. $62.42 $64.92 $67.52 54151S Mid-Level Certification Agent $189.64 $197.23 $205.12 54151S Mid-Level Security Consultant $201.39 $209.45 $217.83
54151S Project Manager (PM) / Technical Lead $286.90 $298.37 $310.31
54151S Project Manager (PM) /Senior Compliance Officer $226.55 $235.61 $245.04
54151S Principal Information Security (IS) /Information Management
(IM) Specialist $163.81 $170.36 $177.18
54151S Principal Technical Trainer $115.18 $119.78 $124.58
54151S Principal-Information Security Engineer (ISSE) $176.76 $183.83 $191.19
54151S Scientist $165.30 $171.91 $178.79 54151S Security Analyst - Mid $100.23 $104.24 $108.41 54151S Security Architect $218.16 $226.89 $235.96 54151S Senior Security Consultant $231.92 $241.19 $250.84 54151S Senior Certification Agent $209.77 $218.16 $226.89
54151S Senior Information Security (IS) /Information Management (IM)
Specialist $144.94 $150.73 $156.76
54151S Senior Information Security
(IS)/System Development (SD) Specialist
$144.94 $150.73 $156.76
54151S Senior Scientist $178.71 $185.86 $193.29 54151S Senior Security Analyst $120.84 $125.67 $130.70 54151S Senior Security Engineer $184.61 $192.00 $199.68 54151S Senior Technical Trainer $95.81 $99.65 $103.63
54151S Senior Information Security Engineer (ISSE) $110.71 $115.14 $119.75
54151S SME-Information Security Engineer (ISSE) $226.98 $236.06 $245.50
54151S Special Program Advisor $221.53 $230.39 $239.61 54151S Subject Matter Expert $158.84 $165.19 $171.80 54151S Technical Trainer $79.44 $82.62 $85.92 54151S Technical Writer $96.97 $100.85 $104.88 54151S Senior Network Engineer $120.94 $125.78 $130.81
March 2022 -
March 2023 -
March 2024 -
54151S Network and Computer Systems Administrator I $99.93 $103.92 $108.08
54151S Network and Computer Systems Administrator II $100.78 $104.82 $109.01
54151S Network and Computer Systems Administrator III $102.56 $106.67 $110.93
54151S Network and Computer Systems Administrator IIII $110.09 $114.49 $119.07
54151S Program Manager $126.40 $131.45 $136.71
54151S Computer Network Support Specialist $50.40 $52.41 $54.51
54151S Sr. Information Assurance Engineer (IAE) $100.78 $104.82 $109.01
54151S System Architect $122.18 $127.07 $132.15 54151S Junior Technician (Off-Site) $78.24 $81.37 $84.63 54151S Mid Technician (Off-Site) $153.34 $159.48 $165.86 54151S Project Manager (Off-Site) $225.12 $234.12 $243.49 54151S Senior Technician (Off-Site) $195.60 $203.42 $211.56
54151S Management Analyst - Sr. (Off- Site) $96.93 $100.80 $104.84
54151S Management Analyst - Mid. (Off- Site) $60.87 $63.30 $65.83
54151S Senior Network Engineer (Off- Site) $121.56 $126.43 $131.48
541611 Management Analyst I $55.84 $58.08 $60.40
541611 Management Analyst II $57.93 $60.25 $62.66
541611 Senior Analyst II $94.02 $97.77 $101.68
541611 Sr. Administrative Specialist $66.75 $69.42 $72.20
541611 Senior Analyst I $86.63 $90.10 $93.70
541611 Financial Analyst $103.46 $107.60 $111.90
541611 Program Management Support $95.28 $99.09 $103.05
54151HACS
Cybersecurity Information
Systems Security / Information Assurance Engineer
$95.14 $98.94 $102.90
54151HACS Executive Assistant I $53.92 $56.08 $58.32
54151HACS Executive Assistant II $61.31 $63.76 $66.31
54151HACS Cybersecurity COMSEC Engineer
II $108.91 $113.27 $117.80
54151HACS Cybersecurity COMSEC Engineer I $87.35 $90.84 $94.47
54151HACS Cybersecurity Engineer I $79.80 $82.99 $86.31
54151HACS Cybersecurity Analyst I $70.01 $72.81 $75.72
54151HACS IT Systems Analyst II $81.64 $84.90 $88.30
March 2022 -
March 2023 -
March 2024 -
54151HACS IT Systems Analyst III $108.53 $112.87 $117.39
54151HACS PKI Engineer Level III $119.58 $124.36 $129.33 54151HACS Cybersecurity Policy Analyst $98.31 $102.24 $106.33 54151HACS Cybersecurity Analyst II $91.70 $95.37 $99.18
54151HACS Cybersecurity Analyst, Mid $92.90 $96.61 $100.48
54151HACS Cybersecurity Analyst, Sr. $106.96 $111.23 $115.68
54151HACS Cybersecurity Engineer II $90.56 $94.18 $97.95
54151HACS Cybersecurity Senior Network Engineer $121.56 $126.43 $131.48
54151HACS Cybersecurity Information Systems Security Officer (ISSO) $137.57 $143.08 $148.80
54151HACS
Cybersecurity Network and
Computer Systems Administrator I
$100.44 $104.46 $108.64
54151HACS
Cybersecurity Network and
Computer Systems Administrator II
$101.31 $105.36 $109.57
54151HACS
Cybersecurity Network and
Computer Systems Administrator III
$103.10 $107.22 $111.51
54151HACS
Cybersecurity Network and
Computer Systems Administrator IIII
$110.66 $115.08 $119.69
54151HACS Cybersecurity Program Manager $127.05 $132.14 $137.42
54151HACS Cybersecurity Computer Network Support Specialist $50.66 $52.68 $54.79
54151HACS Cybersecurity Sr. Information Assurance Engineer (IAE) $101.31 $105.36 $109.57
54151HACS Cybersecurity System Architect $122.81 $127.73 $132.84
54151HACS Cybersecurity Technical Writer $50.66 $52.68 $54.79
Highly Adaptive Cybersecurity Services (HACS) Awarded Subcategories:
High Value Asset Assessments
Risk and Vulnerability Assessments
Cyber Hunt
Incident Response
Penetration Testing
TERMS AND CONDITIONS APPLICABLE TO HIGHLY ADAPTIVE CYBERSECURITY SERVICES
(HACS) (SPECIAL ITEM NUMBERS 54151HACS)
Vendor suitability for offering services through the Highly Adaptive Cybersecurity Services (HACS) SIN must be in accordance with the following laws and standards when applicable to the specific task orders, including but not limited to:
● Federal Acquisition Regulation (FAR) Part 52.204-21
● OMB Memorandum M-17-12 - Preparing for and Responding to a Breach of Personally Identifiable Information (PII)
● OMB Memorandum M- 19-03 - Strengthening the Cybersecurity of Federal Agencies by enhancing the High Value Asset Program
● 2017 Report to the President on Federal IT Modernization
● The Cybersecurity National Action Plan (CNAP)
● NIST SP 800-14 - Generally Accepted Principles and Practices for Securing Information Technology Systems
● NIST SP 800-27A - Engineering Principles for Information Technology Security (A Baseline for Achieving Security)
● NIST SP 800-30 - Guide for Conducting Risk Assessments
● NIST SP 800-35 - Guide to Information Technology Security Services
● NIST SP 800-37 - Risk Management Framework for Information Systems and Organizations: A Systems Life Cycle Approach for Security and Privacy
● NIST SP 800-39 - Managing Information Security Risk: Organization, Mission, and Information System View
● NIST SP 800-44 - Guidelines on Securing Public Web Servers
● NIST SP 800-48 - Guide to Securing Legacy IEEE 802.11 Wireless Networks
● NIST SP 800-53 – Security and Privacy Controls for Federal Information Systems and Organizations
● NIST SP 800-61 - Computer Security Incident Handling Guide
● NIST SP 800-64 - Security Considerations in the System Development Life Cycle
● NIST SP 800-82 - Guide to Industrial Control Systems (ICS) Security
● NIST SP 800-86 - Guide to Integrating Forensic Techniques into Incident Response
● NIST SP 800-115 - Technical Guide to Information Security Testing and Assessment
● NIST SP 800-128 - Guide for Security-Focused Configuration Management of Information Systems
● NIST SP 800-137 - Information Security Continuous Monitoring (ISCM) for Federal Information Systems and Organizations
● NIST SP 800-153 - Guidelines for Securing Wireless Local Area Networks (WLANs)
● NIST SP 800-160 - Systems Security Engineering: Considerations for a Multidisciplinary Approach in the Engineering of Trustworthy Secure Systems
● NIST SP 800-171 - Protecting Controlled Unclassified Information in non-federal Information Systems and Organizations
1. SCOPE
a. The labor categories, prices, terms and conditions stated under Special Item Number 54151HACS Highly Adaptive Cybersecurity Services (HACS) apply exclusively to Highly Adaptive Cybersecurity Services within the scope of this Information Technology Schedule.
b. Services under this SIN are limited to Highly Adaptive Cybersecurity Services only. Software and hardware products are under different Special Item Numbers on MAS and may be quoted along with services to provide a total solution.
c. This SIN provides ordering activities with access to Highly Adaptive Cybersecurity services only.
d. Highly Adaptive Cybersecurity Services provided under this SIN shall comply with all Cybersecurity certifications and industry standards as applicable pertaining to the type of services as specified by ordering agency.
e. SCOPE:
54151HACS Highly Adaptive Cybersecurity Services (HACS) - SUBJECT TO COOPERATIVE PURCHASING - includes proactive and reactive cybersecurity services that improve the customer’s enterprise-level security posture.
The scope of this category encompasses a wide range of fields that include, but are not limited to, Risk Management Framework (RMF) services, information assurance (IA), virus detection, network management, situational awareness and incident response, secure web hosting, and backup and security services.
The seven-step RMF includes preparation, information security categorization; control selection, implementation, and assessment; system and common control authorizations; and continuous monitoring.. RMF activities may also include Information Security Continuous Monitoring Assessment (ISCMA) which evaluate organization-wide ISCM implementations, and also Federal Incident Response Evaluations (FIREs), which assess an organization’s incident management functions.
The scope of this category also includes Security Operations Center (SOC) services. The SOC scope includes services such as: 24x7x365 monitoring and analysis, traffic analysis, incident response and coordination, penetration testing, anti-virus management, intrusion detection and prevention, and information sharing.
HACS vendors are able to identify and protect a customer’s information resources, detect and respond to cybersecurity events or incidents, and recover capabilities or services impaired by any incidents that emerge.
Sub-Categories - (not all vendors have been placed within the following subcategories.
To view a complete list of vendors, click on the SIN)
● High Value Asset (HVA) Assessments include Risk and Vulnerability Assessment (RVA) which assesses threats and vulnerabilities, determines deviations from acceptable configurations, enterprise or local policy, assesses the level of risk, and develops and/or recommends appropriate mitigation countermeasures in operational and non-operational situations. The services offered in the RVA sub-category include Network Mapping, Vulnerability Scanning, Phishing Assessment, Wireless Assessment, Web Application Assessment, Operating System Security Assessment (OSSA), Database Assessment, and Penetration Testing. Security Architecture Review (SAR) evaluates a subset of the agency’s HVA security posture to determine whether the agency has properly architected its cybersecurity solutions and ensures that agency leadership fully understands the risks inherent in the implemented cybersecurity solution. The SAR process utilizes in-person interviews, documentation reviews, and leading practice evaluations of the HVA environment and supporting systems. SAR provides a holistic analysis of how an HVA’s individual security components integrate and operate, including how data is protected during operations. Systems Security Engineering (SSE) identifies security vulnerabilities and minimizes or contains risks associated with these vulnerabilities spanning the Systems Development Life Cycle. SSE focuses on, but is not limited to the following security areas: perimeter security, network security, endpoint security, application security, physical security, and data security.
● Risk and Vulnerability Assessment (RVA) assesses threats and vulnerabilities, determines deviations from acceptable configurations, enterprise or local policy, assesses the level of risk, and develops and/or recommends appropriate mitigation countermeasures in operational and non-operational situations. The services offered in the RVA sub-category include Network Mapping, Vulnerability Scanning, Phishing Assessment, Wireless Assessment, Web Application Assessment, Operating System Security Assessment (OSSA), Database Assessment, and Penetration Testing.
● Cyber Hunt activities respond to crises or urgent situations within the pertinent domain to mitigate immediate and potential threats. Cyber Hunts start with the premise that threat actors known to target some organizations in a specific industry or with specific systems are likely to also target other organizations in the same industry or with the same systems.
● Incident Response services help organizations impacted by a cybersecurity compromise determine the extent of the incident, remove the adversary from their systems, and restore their networks to a more secure state.
● Penetration Testing is security testing in which assessors mimic real-world attacks to identify methods for circumventing the security features of an application, system, or network. f. The Contractor shall provide services at the Contractor’s facility and/or at the ordering activity location, as agreed to by the Contractor and the ordering activity.
2. ORDER
a. Agencies may use written orders, Electronic Data Interchange (EDI) orders, Blanket Purchase Agreements, individual purchase orders, or task orders for ordering services under this contract. Blanket Purchase Agreements shall not extend beyond the end of the contract period;
all services and delivery shall be made and the contract terms and conditions shall continue in effect until the completion of the order. Orders for tasks which extend beyond the fiscal year for which funds are available shall include FAR 52.232-19 (Deviation – May 2003) Availability of Funds for the Next Fiscal Year. The purchase order shall specify the availability of funds and the period for which funds are available.
b. All task orders are subject to the terms and conditions of the contract. In the event of conflict between a task order and the contract, the contract will take precedence.
3. PERFORMANCE OF SERVICES
a. The Contractor shall commence performance of services on the date agreed to by the Contractor and the ordering activity. All Contracts will be fully funded.
b. The Contractor agrees to render services during normal working hours, unless otherwise agreed to by the Contractor and the ordering activity.
c. The ordering activity should include the criteria for satisfactory completion for each task in the Statement of Work or Delivery Order. Services shall be completed in a good and workmanlike manner.
d. Any Contractor travel required in the performance of Highly Adaptive Cybersecurity Services must comply with the Federal Travel Regulation or Joint Travel Regulations, as applicable, in effect on the date(s) the travel is performed. Established Federal Government per diem rates will apply to all Contractor travel. Contractors cannot use GSA city pair contracts. All travel will be agreed upon with the client prior to the Contractor’s travel.
4. INSPECTION OF SERVICES
Inspection of services is in accordance with 552.212-4 - CONTRACT TERMS AND CONDITIONS– COMMERCIAL ITEMS (Jan 2017) & (ALTERNATE I-Jan 2017) for Time-and-Materials and Labor-Hour orders placed under this contract.
5. RESPONSIBILITIES OF THE CONTRACTOR
The Contractor shall comply with all laws, ordinances, and regulations (Federal, State, City, or otherwise) covering work of this character. If the end product of a task order is software, then FAR 52.227-14 (May 2014) Rights in Data – General, may apply.
The Contractor shall comply with contract clause (52.204-21) to the Federal Acquisition Regulation (FAR) for the basic safeguarding of contractor information systems that process, store, or transmit Federal data received by the contract in performance of the contract. This includes contract documents and all information generated in the performance of the contract.
6. RESPONSIBILITIES OF THE ORDERING ACTIVITY
Subject to the ordering activity security regulations, the ordering activity shall permit Contractor access to all facilities necessary to perform the requisite Highly Adaptive Cybersecurity Services.
7. INDEPENDENT CONTRACTOR
All Highly Adaptive Cybersecurity Services performed by the Contractor under the terms of this contract shall be as an independent Contractor, and not as an agent or employee of the ordering activity.
8. ORGANIZATIONAL CONFLICTS OF INTEREST
a. Definitions.
“Contractor” means the person, firm, unincorporated association, joint venture, partnership, or corporation that is a party to this contract.
“Contractor and its affiliates” and “Contractor or its affiliates” refers to the Contractor, its chief executives, directors, officers, subsidiaries, affiliates, subcontractors at any tier, and consultants and any joint venture involving the Contractor, any entity into or with which the Contractor subsequently merges or affiliates, or any other successor or assignee of the Contractor.
An “Organizational conflict of interest” exists when the nature of the work to be performed under a proposed ordering activity contract, without some restriction on ordering activities by the Contractor and its affiliates, may either (i) result in an unfair competitive advantage to the Contractor or its affiliates or (ii) impair the Contractor’s or its affiliates’ objectivity in performing contract work.
b. To avoid an organizational or financial conflict of interest and to avoid prejudicing the best interests of the ordering activity, ordering activities may place restrictions on the Contractors, its affiliates, chief executives, directors, subsidiaries and subcontractors at any tier when placing orders against schedule contracts. Such restrictions shall be consistent with FAR 9.505 and shall be designed to avoid, neutralize, or mitigate organizational conflicts of interest that might otherwise exist in situations related to individual orders placed against the schedule contract. Examples of situations, which may require restrictions, are provided at FAR 9.508.
9. INVOICES
The Contractor, upon completion of the work ordered, shall submit invoices for Highly Adaptive Cybersecurity Services. Progress payments may be authorized by the ordering activity on individual orders if appropriate. Progress payments shall be based upon completion of defined milestones or interim products. Invoices shall be submitted monthly for recurring services performed during the preceding month.
10. RESUMES
Resumes shall be provided to the GSA Contracting Officer or the user ordering activity upon request.
11. APPROVAL OF SUBCONTRACTS
The ordering activity may require that the Contractor receive, from the ordering activity
Contracting Officer, written consent before placing any subcontract for furnishing any of the work called for in a task order.
12. DESCRIPTION OF HIGHLY ADAPTIVE CYBERSECURITY SERVICES AND PRICING
a. The Contractor shall provide a description of each type of Highly Adaptive Cybersecurity Service offered under Special Item Number 54151HACS for Highly Adaptive Cybersecurity Services and it should be presented in the same manner as the Contractor sells to its commercial and other ordering activity customers. If the Contractor is proposing hourly rates, a description of all corresponding commercial job titles (labor categories) for those individuals who will perform the service should be provided.
b. Pricing for all Highly Adaptive Cybersecurity Services shall be in accordance with the Contractor’s customary commercial practices; e.g., hourly rates, minimum general experience and minimum education.
The following is an example of the manner in which the description of a commercial job title should be presented (see SCP FSS 004)
EXAMPLE
Commercial Job Title: Computer Network Defense Analysis
Description: Uses defensive measures and information collected from a variety of sources to identify, analyze, and report events that occur or might occur within the network in order to protect information, information systems, and networks from threats.
Professionals involved in this specialty perform the following tasks:
▪ Provide timely detection, identification, and alerting of possible attacks/intrusions, anomalous activities, and misuse activities and distinguish these incidents and events from benign activities
▪ Provide daily summary reports of network events and activity relevant to Computer Network Defense practices
▪ Monitor external data sources (e.g., Computer Network Defense vendor sites, Computer Emergency Response Teams, SANS, Security Focus) to maintain currency of Computer Network Defense threat condition and determine which security issues may have an impact on the enterprise.
Knowledge, Skills and Abilities: Knowledge of applicable laws (e.g., Electronic Communications Privacy Act, Foreign Intelligence Surveillance Act, Protect America Act, search and seizure laws, civil liberties and privacy laws, etc.), statutes (e.g., in Titles 10, 18, 32, 50 in U.S. Code), Presidential Directives, executive branch guidelines, and/or administrative/criminal legal guidelines and procedures relevant to work performed
Minimum Experience: 5 Years
Minimum Education Requirements: a bachelor's of science degree with a concentration in computer science, cybersecurity services, management information systems (MIS), engineering or information science is essential.
Highly Desirable: Offensive Security Certified Professional (OSCP) or commercial
Cybersecurity advanced certification(s).
CYBERSECURITY LABOR CATEGORY DESCRIPTIONS – 54151HACS
Cybersecur ity Information Systems Security / Information Assurance Engineer
Education: Bachelor's Degree or Equivalent
Experience: 6 years of experience with Cyber Security technologies including the design, building and implementing Cyber Security solutions
Duties/Responsibilities: Plan and conduct engineering projects concerned with research, design and development of new or modification and improvement of existing equipment(s) and systems applicable to PM mission. Apply the theories, principles, standards and information systems security methods and a working knowledge of the related engineering disciplines to evaluate system requirements, determine hardware and software design detail and performance characteristics necessary to meet operational requirements. Recommend new designs and techniques leading to cost effective system enhancement. Analyze specific system requirements and design modifications or deviations in hardware or software subsystems to ensure fulfillment of user related needs and will adequately resist established and projected threat environments.
Executive Ass i stant I
Education: Associates Degree
Experience: One to two (1-2) years of experience in performing administrative support
Duties/Responsibilities: The Executive Assistant I receives, screens, and directs incoming phone calls, visitors, and mail, maintains time and attendance reports; and responds to general inquiries, prepares travel documents, makes travel arrangements and maintains travel records.
Executive Ass i stant I I
Education: Associates Degree
Experience: Two to four (2-4) years of experience in performing administrative support
Duties/Responsibilities: The Executive Assistant II receives, screens, and directs incoming phone calls, visitors, and mail, maintains time and attendance reports; and responds to general inquiries, prepares travel documents, makes travel arrangements and maintains travel records.
Cybersecur ity COMSEC Engineer I
Education: Bachelor’s Degree in Computer Science or Information Technology.
Experience: 4 years of experience with Cyber Security technologies including the design, building and implementing Cyber Security solutions
Duties/Responsibilities: Performs communications security (COMSEC) services, potentially COMSEC responsible officer (CRO) or alternate responsible officer (ACRO), manages multiple COMSEC accounts, as well as have the ability to perform audits and train personnel in COMSEC procedures and the use of related equipment. Applies and has a strong understanding of COMSEC accountability as well as knowledge of the procedures required for the issue and receipt of COMSEC equipment and materials to include inventory, handling, storage, packing, shipment and administration of all cryptographic materials.
Cybersecur ity COMSEC Engineer I I
Education: Bachelor’s Degree in Computer Science or Information Technology.
Experience: 6 years of experience with Cyber Security technologies including the design, building and implementing Cyber Security solutions
Duties/Responsibilities: Performs communications security (COMSEC) services, potentially COMSEC responsible officer (CRO) or alternate responsible officer (ACRO), manages multiple COMSEC accounts, as well as have the ability to perform audits and train personnel in COMSEC procedures and the use of related equipment. Applies and has a strong understanding of COMSEC accountability as well as knowledge of the procedures required for the issue and receipt of COMSEC equipment and materials to include inventory, handling, storage, packing, shipment and administration of all cryptographic materials.
Cybersecur ity Engineer I
Education: Bachelor’s degree in a related degree in a related field
Experience: 3 years of experience with Cyber Security technologies including the design, building and implementing Cyber Security solutions
Duties/Responsibilities: Working under immediate supervision of the Cybersecurity Engineer II, responsible for maintaining and modifying moderately complex Cyber Security technologies. Provided project planning, guidance and technical expertise in the following areas: Cyber Security engineering program, policy, process, and planning;
risk management, auditing, and assessments; Assessment and Authorization (A&A) using the NIST Risk Management Framework (RMF) guidelines; and quality planning and control.
Cybersecur ity Analyst I
Education: Bachelor’s Degree in Computer Science or Information Technology.
Experience: 4 years of experience in Information Assurance or Cybersecurity.
Duties/Responsibilities: Under direct supervision, supports analysis of systems, programs, and/or planning activities. Duties may involve research and contributing authorship in support of policies, procedures, and other technical documentation and supporting analysis of IA/Cyber related programs and initiatives. Duties may also include the research and analysis in support of the design and development of relationships and solutions to resolve problems within the specialty area.
IT Systems Analyst I I
Education: Bachelor’s Degree in Computer Science or Information Technology.
Experience: 4 years of IT experience in areas such as software requirements definition, design, coding, testing, or deployment. Experience must demonstrate working knowledge of modern software design paradigms, software development tools and software development best practices, analytical skills, and oral, written communications ability.
Duties/Responsibilities: IT Systems Analyst II will interact with system stakeholders and subject matter experts and use knowledge of cost/schedule constraints and technical feasibility to determine and formalize comprehensive top-level system requirements. The IT Systems Analyst II will determine and document at the functional components that will be required to implement the system and the necessary interactions between components. He or she will document the hardware, software, protocols, and integration requirements for the system components and establishes implementation partitions. The IT Systems Analyst II will provide input into the creation of implementation plans and schedules and will provide input on selection of technological purchases with regards to processing, data storage, data access, and applications development.
IT Systems Analyst I I I
Education: Bachelor’s Degree in Computer Science or Information Technology.
Experience: 5 years of experience with Cyber Security technologies including the design, building and implementing Cyber Security solutions
Duties/Responsibilities: The IT systems Analyst III will interact with system stakeholders and subject matter experts, and use knowledge of cost/schedule constraints and technical feasibility to determine and formalize comprehensive top-level system requirements. The IT Systems Analyst III will determine and document the functional components that will be required to implement the system and the necessary interactions between components. He or she will document the hardware, software, protocols, and integration requirements for the system components and establishes implementation partitions.
PKI Engineer Level I I I
Education: Bachelor’s Degree in Computer Science or Information Technology.
Experience: 5 years of experience with Cyber Security technologies including the design, building and implementing Cyber Security solutions
Duties/Responsibilities: Will assist in providing policy, process and technical support to the design, mature and sustain Microsoft Certificate Services and Entrust Identity Guard credential management systems, based Public Key Infrastructure (PKI).
Cybersecur ity Pol icy Analyst
Education: Bachelor’s Degree in Computer Science or Information Technology.
Experience: 5 years of relevant cybersecurity policy experience
Duties/Responsibilities: Reviews, consolidates and develops cybersecurity policy in accordance with RFP requirements. Fully versed in the general tenets supporting the overall DOD implementation of its cybersecurity policies, procedures and process and able to provide technical support and assistance to federal agencies and assess IT policies, standards, guidelines or procedures to ensure a balance of security and operational requirements. Required to brief senior management on cybersecurity policy changes, updates and progress
Cybersecur ity Analyst I I
Education: Bachelor’s Degree in Computer Science or Information Technology.
Experience: 4 years of experience with Cyber Security technologies including the design, building and implementing Cyber Security solutions
Duties/Responsibilities: Supports analysis of systems, programs, and/or planning activities. Duties may involve research and contributing authorship in support of policies, procedures, and other technical documentation and supporting analysis of IA/Cyber related programs and initiatives. Duties may also include the research and analysis in support of the design and development of relationships and solutions to resolve problems within the specialty area.
Cybersecur ity Analyst , Mid
Education: Bachelor’s Degree in Computer Science or Information Technology.
Experience: 4 years of experience with Cyber Security technologies including the design, building and implementing Cyber Security solutions
Duties/Responsibilities: Supports analysis of systems, programs, and/or planning activities. Duties may involve research and contributing authorship in support of policies, procedures, and other technical documentation and supporting analysis of IA/Cyber related programs and initiatives. Duties may also include the research and analysis in support of the design and development of relationships and solutions to resolve problems within the specialty area.
Cybersecur ity Analyst , Sr.
Education: Bachelor’s Degree in Computer Science or Information Technology.
Experience: 6 years of experience with Cyber Security technologies including the design, building and implementing Cyber Security solutions
Duties/Responsibilities: Supports analysis of systems, programs, and/or planning activities. Duties may involve research and contributing authorship in support of policies, procedures, and other technical documentation and supporting analysis of IA/Cyber related programs and initiatives. Duties may also include the research and analysis in support of the design and development of relationships and solutions to resolve problems within the specialty area.
Cybersecur ity Engineer I I
Education: Bachelor’s Degree in Computer Science or Information Technology.
Experience: 4 years of experience with Cyber Security technologies including the design, building and implementing Cyber Security solutions
Duties/Responsibilities: Working under immediate supervision of the Cybersecurity Engineer II, responsible for maintaining and modifying moderately complex Cyber Security technologies. Provided project planning, guidance and technical expertise in the following areas: Cyber Security engineering program, policy, process, and planning;
risk management, auditing, and assessments; Assessment and Authorization (A&A) using the NIST Risk Management Framework (RMF) guidelines; and quality planning and control.
Cybersecur ity Senior Network Engineer
Education: Bachelor’s Degree in Computer Science or Information Technology.
Experience: 4 years of experience with Cyber Security technologies including the design, building and implementing Cyber Security solutions
Duties/Responsibilities: Requires hands on Cybersecurity experience with racking and stacking equipment, configuring Cisco devices such as firewalls, routers and switches and the ability to create, update and maintain network documentation. Must be able to implement new technology and architecture designs by managing three different networks.
Review existing network designs and core network switch configurations to ensure they meet the latest security guidelines and that the network is running at optimum levels and secure.
• Configure and maintain Cisco devices such as router, switches, Nexus switches and Palo Alto firewalls
• Recommend updates and changes to the existing WAN network design, LAN design, and wireless network design
• Recommend updates and changes for the existing core network switch configurations
• Generate network designs for new Client locations or renovated spaces
• Experience with configuring and maintaining TACLANES
• Generate Bill of Materials (BOM) for new network projects in new or renovated Client locations
• Conduct market research for Client network projects.
• Engineer wired network solutions for future Client projects.
• Develop and maintain accurate network documentation and network diagrams
• Perform network assessments and security audits.
• Review existing WAN and LAN designs which are in one of the following formats: Visio, CAD, PDF, Excel, Word and Power Point.
• Support Cisco VOIP technologies
• Understanding and knowledge of ATO process
• Manage switches, routers, firewalls, application delivery controllers/load-balancers, wireless, VPN and security devices
• Develop implementation plans and carry out change effectively and successfully
• Monitor the network to ensure acceptable performance and availability, and identify and resolve network problems
Cybersecur ity Information Systems Security Officer ( ISSO)
Education: Bachelor’s Degree in Computer Science or Information Technology.
Experience: 6 years of experience with Cyber Security technologies including the design, building and implementing Cyber Security solutions
Duties/Responsibilities: Information Systems Security Officer (ISSO) is responsible for determining enterprise-wide information security standards. ISSO develops and implements information security standards and procedures.
The ISSO ensures that all information systems are functional and secure. The ISSO will be familiar with a variety of the field's concepts, practices, and procedures. The ISSO relies on extensive experience and judgment to plan and accomplish goals.
Cybersecur ity Network and Computer Systems Administrator I
Education: Bachelor’s Degree in Computer Science or Information Technology.
Experience: 2 years of experience with Cyber Security technologies including the design, building and implementing Cyber Security solutions
Duties/Responsibilities: The Network and Computer Systems Administrator will have overall responsibility to perform system installation, set-up, administration, maintenance, troubleshooting and end-user support to OTCD-supplied Title III and Pen Register systems. This includes:
• Provides technical and management input on major tasks or technology assignments.
• Perform system capacity analysis and planning.
• Serves as a key contact for local and remote locations and customers to obtain clarification of problems.
• Provide resolution of system failures and degradation.
Cybersecur ity Network and Computer Systems Administrator I I
Education: Bachelor’s Degree in Computer Science or Information Technology.
Experience: 3 years of experience with Cyber Security technologies including the design, building and
Duties/Responsibilities: The Network and Computer Systems Administrator will have overall responsibility to perform system installation, set-up, administration, maintenance, troubleshooting and end-user support to OTCD-supplied Title III and Pen Register systems. This includes:
• Provides technical and management input on major tasks or technology assignments.
• Perform system capacity analysis and planning.
• Serves as a key contact for local and remote locations and customers to obtain clarification of problems.
• Provide resolution of system failures and degradation.
Cybersecur ity Network and Computer Systems Administrator I I I
Education: Bachelor’s Degree in Computer Science or Information Technology.
Experience: 4 years of experience with Cyber Security technologies including the design, building and implementing Cyber Security solutions
Duties/Responsibilities: The Network and Computer Systems Administrator will have overall responsibility to perform system installation, set-up, administration, maintenance, troubleshooting and end-user support to OTCD-supplied Title III and Pen Register systems. This includes:
• Provides technical and management input on major tasks or technology assignments.
• Perform system capacity analysis and planning.
• Serves as a key contact for local and remote locations and customers to obtain clarification of problems.
• Provide resolution of system failures and degradation.
Cybersecur ity Network and Computer Systems Administrator I I I I
Education: Bachelor’s Degree in Computer Science or Information Technology.
Experience: 5 years of experience with Cyber Security technologies including the design, building and implementing Cyber Security solutions
Duties/Responsibilities: The Network and Computer Systems Administrator will have overall responsibility to perform system installation, set-up, administration, maintenance, troubleshooting and end-user support to OTCD-supplied Title III and Pen Register systems. This includes:
• Provides technical and management input on major tasks or technology assignments.
• Perform system capacity analysis and planning.
• Serves as a key contact for local and remote locations and customers to obtain clarification of problems.
• Provide resolution of system failures and degradation.
Cybersecur ity Program Manager
Education: Bachelor’s Degree in Computer Science or Information Technology.
Experience: 4 years of experience with Cyber Security technologies including the design, building and implementing Cyber Security solutions
Duties/Responsibilities: The Program Manager (PM) provides oversight and technical review of project tasks and provides functional analysis in order to achieve optimal design configurations. PM has the ability to interpret various regulations, policies and other constraints and assess their impact on project costs. The PM is an expert in an IT discipline/technology or specific functional area related to IT (i.e. compliance and assurance). The PM possesses a thorough knowledge of design requirements and operational procedures for IT systems, applications and relational databases. The PM assists other leads in identifying all required system/software/design changes to be incorporated into project documents as well as configuration management databases.
Cybersecur ity Computer Network Support Specia l ist
Education: Associate Degree in Computer Science or Information Technology.
Experience: 2 years of experience with Cyber Security technologies including the design, building and
Duties/Responsibilities: The Computer Network Support Specialist (CNSS) is responsible for design, planning, and direction on all Computer network task orders. The CNSS provides additional QA/QC review of Computer Networking projects. Analyzes, troubleshoots, and evaluates computer network problems. They play an important role in the routine maintenance of an organization's networks, such as performing file backups on the network.
Cybersecur ity Sr. Information Assurance Engineer ( IAE)
Education: Bachelor’s Degree in Computer Science or Information Technology.
Experience: 4 years of experience with Cyber Security technologies including…
This is the start of the file's text. The full file is on GovTribe.
File details come from the government source that posted it. Updated .