MAS - Breakpoint Labs, L.L.C. - GS35F248GA
PDF 996 KB
- Attached to
- Federal Supply Schedule GS35F248GA Federal contract IDV
- Contract number
- GS35F248GA
- Issued by
- GSA Federal Acquisition Service
About this file
This document outlines a federal supply schedule contract for highly adaptive cybersecurity services. The contract was awarded on February 17, 2022 to BreakPoint Labs, LLC by the GSA Federal Acquisition Service, and provides services through February 16, 2027. Key services offered under the contract include penetration testing, incident response, cyber hunt activities, risk and vulnerability assessments, and high value asset assessments. The contract identifies various labor categories such as cybersecurity subject matter experts, technical experts, analysts, and engineers to support these services. Pricing is provided for each labor category on both daily and hourly rates. The contract establishes terms and requirements for ordering activities to utilize these cybersecurity offerings through the remainder of the award period.
Breakpoint Labs, LLC Pricelist and/or Vendor Terms and Conditions for GS35F248GA, a Federal Supply Schedule awarded to Breakpoint Labs, LLC, under Information Technology Schedule 70 (IT-70)
View the file
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
Mississippi State University RFP 16-89 Comprehensive Cybersecurity Assessment Services
Build. Protect. Learn.
Authorized Federal Supply Service (FSS) Information Technology Category IT Services / Highly Adaptive Cybersecurity Services (HACS) - Pricelist
General Services Administration (GSA) Federal Acquisition Service (FAS) Multiple Award Schedule (MAS)
Special Item Number: 54151HACS
Contract Number: GS-35F-248GA Schedule: MAS Refresh 9 MAS Mod: PS-A839 Supplement No. 1 – dated December 23, 2021 Contract Period: February 17, 2022
– February 16, 2027
8116 Arlington Boulevard, #255, Falls Church, VA 22042 1-844-HACKME2 (422-5632) ♦ www.breakpoint-labs.com ♦ contracts@breakpoint-labs.com
Business Size: Small http://www.breakpoint-labs.com/ mailto:contracts@breakpoint-labs.com
Information Technology (IT) Multiple Award Schedule Highly Adaptive Cybersecurity Services (HACS)
Contract Number: GS-35F-248GA ii
Table of Contents
CUSTOMER INFORMATION
SCHEDULE TITLE
CONTACT INFORMATION
1A. SPECIAL ITEM NUMBERS (SINS):
SPECIAL ITEM NUMBERS DESCRIPTION
1.B LOWEST PRICED MODEL NUMBER AND PRICE FOR EACH SIN:
NOT APPLICABLE
1.C SERVICES OFFERED:
SEE PRICE LIST
2. MINIMUM ORDER
3. MAXIMUM ORDER
4. GEOGRAPHIC SCOPE OF CONTRACT (DELIVERY AREA)
GOVERNMENT PURCHASE CARDS
LIABILITY FOR INJURY OF DAMAGE
STATISTICAL DATA FOR GOVERNMENT ORDERING OFFICE COMPLETION OF SF-279
5. POINT(S) OF PRODUCTION:
NOT APPLICABLE
6. DISCOUNT FROM LIST PRICES OR STATEMENT OF NET PRICE:
7. QUANTITY DISCOUNTS:
NOT APPLICABLE
8. PROMPT PAYMENT TERMS:
NOT APPLICABLE
9. FOREIGN ITEMS:
NOT APPLICABLE
10A. TIME OF DELIVERY:
10B. EXPEDITED DELIVERY:
10C. OVERNIGHT AND 2 DAY DELIVERY:
10D. URGENT REQUIREMENTS:
11. F.O.B POINT(S):
12A. ORDERING ADDRESS(ES):
12B. ORDERING PROCEDURES:
FEDERAL INFORMATION TECHNOLOGY / TELECOMMUNICATIONS STANDARDS REQUIREMENTS . 7
FEDERAL INFORMATION PROCESSING STANDARDS PUBLICATIONS (FIPS PUBS)
FEDERAL TELECOMMUNICATION STANDARDS (FED-STDS)
CONTRACTOR TASKS / SPECIAL REQUIREMENTS (C-FSS-370) (NOV 2003)
CONTRACT ADMINISTRATION FOR ORDERING ACTIVITIES
GSA ADVANTAGE!™
PURCHASE OF OPEN MARKET ITEMS
BLANKET PURCHASE AGREEMENTS (BPAS)
CONTRACTOR TEAM ARRANGEMENTS
INSTALLATION, DEINSTALLATION, REINSTALLATION
PRIME CONTRACTOR ORDERING FROM FEDERAL SUPPLY SCHEDULES
INSURANCE – WORK ON A GOVERNMENT INSTALLATION (JAN 1997)(FAR 52.228-5)
SOFTWARE INTEROPERABILITY
Contract Number: GS-35F-248GA iii
ADVANCE PAYMENTS
13. PAYMENT ADDRESS(ES):
14. WARRANTY PROVISION:
15. EXPORT PACKING CHARGES:
16. TERMS AND CONDITIONS OF RENTAL, MAINTENANCE, AND REPAIR:
17. TERMS AND CONDITIONS OF INSTALLATION:
18A. TERMS AND CONDITIONS OF REPAIR PARTS:
18B. TERMS AND CONDITIONS FOR ANY OTHER SERVICES:
19. LIST OF SERVICE AND DISTRIBUTION POINTS:
20. LIST OF PARTICIPATING DEALERS:
21. PREVENTIVE MAINTENANCE:
22A. SPECIAL ATTRIBUTES:
22B. SECTION 508 COMPLIANCE:
23. DATA UNIVERSAL NUMBER SYSTEM (DUNS) NUMBER:
24. NOTIFICATION REGARDING REGISTRATION IN SYSTEM FOR AWARD MANAGEMENT (SAM)
DATABASE:
COMMERCIAL AND GOVERNMENT ENTITY (CAGE) CODE
SPECIAL NOTICE TO AGENCIES: SMALL BUSINESS PARTICIPATION
OVERSEAS ACTIVITIES
CENTRAL CONTRACTOR REGISTRATION (CCR) DATABASE
TRADE AGREEMENTS ACT OF 1979, AS AMENDED
TERMS AND CONDITIONS APPLICABLE TO
HIGHLY ADAPTIVE CYBERSECURITY SERVICES (HACS)
(SPECIAL ITEM NUMBER: 54151HACS
SCOPE
ORDER
PERFORMANCE OF SERVICES
INSPECTION OF SERVICES
RESPONSIBILITIES OF THE CONTRACTOR
INDEPENDENT CONTRACTOR
INVOICES
RESUMES
APPROVAL OF SUBCONTRACTS
DESCRIPTION OF HIGHLY ADAPTIVE CYBERSECURITY SERVICES AND PRICING
SPECIAL ITEM NUMBER 54151HACS – PENETRATION TESTING – SUBJECT TO COOPERATIVE
PURCHASING
SPECIAL ITEM NUMBER 54151HACS – INCIDENT RESPONSE – SUBJECT TO COOPERATIVE
PURCHASING
SPECIAL ITEM NUMBER 54151HACS – CYBER HUNT – SUBJECT TO COOPERATIVE PURCHASING .. 18 SPECIAL ITEM NUMBER 54151HACS – RISK AND VULNERABILITY ASSESSMENTS (RVA) – SUBJECT
TO COOPERATIVE PURCHASING
SPECIAL ITEM NUMBER 54151HACS – HIGH VALUE ASSET ASSESSMENTS (HVA) – SUBJECT TO
COOPERATIVE PURCHASING
LABOR CATEGORY DESCRIPTIONS
EQUIVALENCIES
Contract Number: GS-35F-248GA iv
PRICING
BREAKPOINT LABS, LLC. COMMITMENT TO PROMOTE
SMALL BUSINESS PARTICIPATION PROCUREMENT PROGRAMS
BEST VALUE BLANKET PURCHASE AGREEMENT
FEDERAL SUPPLY MULTIPLE AWARD SCHEDULE
(CUSTOMER NAME)
BLANKET PURCHASE AGREEMENT
Contract Number: GS-35F-248GA 5
Customer Information
Schedule Title General Services Administration (GSA) Information Technology (IT) Multiple Award Schedule Highly Adaptive Cybersecurity Services (HACS)
Contact Information BreakPoint Labs, LLC.
8116 Arlington Boulevard, #255 Falls Church, VA 22042 Phone: 1-844-422-5632 Fax: 410-505-9229 Website: https://breakpoint-labs.com Email: contracts@breakpoint-labs.com
1a. SPECIAL ITEM NUMBERS (SINs):
Special Item Numbers Description Special Item Number: 54151HACS Highly Adaptive Cybersecurity Services (HACS)
1.b LOWEST PRICED MODEL NUMBER AND PRICE FOR EACH SIN:
Not Applicable
1.c SERVICES OFFERED:
See Price List
2. Minimum Order The maximum dollar of orders to be issued is $500,000.
3. Maximum Order The minimum dollar of orders to be issued is $100.00.
4. Geographic Scope of Contract (Delivery Area) The Geographic Scope of Contract is domestic and overseas delivery
Domestic delivery is delivery within the 48 contiguous states, Alaska, Hawaii, Puerto Rico, Washington, DC, and U.S. Territories. Domestic delivery also includes a port or consolidation point, within the aforementioned areas, for orders received from overseas activities.
Overseas delivery is delivery to points outside of the 48 contiguous states, Washington, DC, Alaska, Hawaii, Puerto Rico, and U.S. Territories
Government Purchase Cards Government purchase cards are accepted for orders equal to or less than the micro-purchase threshold for oral or written orders under this contract.
https://breakpoint-labs.com/
Contract Number: GS-35F-248GA 6
Liability for Injury of Damage The Contractor shall not be liable for any injury to ordering activity personnel or damage to ordering activity property arising from the use of equipment maintained by the Contractor, unless such injury or damage is due to the fault or negligence of the Contractor.
Statistical Data for Government Ordering Office Completion of SF-279 Block 9: G. Order/Modification Under Federal Schedule Contract Block 16: Data Universal Numbering System (DUNS) Number: 079914189 Block 30: Type of Contractor: B. Other Small Business Block 31: Woman-Owned Small Business: No Block 37: Contractor's Taxpayer Identification Number (TIN): 47-4581296 Block 40: Veteran Owned Small Business (VOSB): No
5. Point(s) of Production:
Not Applicable
6. Discount from list prices or statement of net price:
SIN 54151HACS
Prices shown are NET prices; basic discounts have been deducted.
Dollar Volume: 1% for any order greater than $500,000 Government Education Institutions: Not applicable Other: Not applicable
7. Quantity Discounts:
Not applicable
8. Prompt Payment Terms:
Not applicable
9. Foreign Items:
Not Applicable
10a. Time of Delivery:
SIN 54151HACS
As negotiated between ordering activity and BreakPoint Labs, LLC.
10b. Expedited Delivery:
Contact Contractor
10c. Overnight and 2 Day Delivery:
Contact Contractor
10d. Urgent Requirements:
When the Federal Supply Schedule contract delivery period does not meet the bona fide urgent delivery requirements of an ordering activity, ordering activities are encouraged, if time permits, to
Contract Number: GS-35F-248GA 7 contact the Contractor for the purpose of obtaining accelerated delivery. The Contractor shall reply to the inquiry within 3 workdays after receipt. (Telephonic replies shall be confirmed by the Contractor in writing.) If the Contractor offers an accelerated delivery time acceptable to the ordering activity, any order(s) placed pursuant to the agreed upon accelerated delivery time frame shall be delivered within this shorter delivery time and in accordance with all other terms and conditions of the contract.
11. F.O.B point(s):
SIN 54151HACS
Destination.
12a. Ordering Address(es):
BreakPoint Labs, LLC.
8116 Arlington Boulevard, #255 Falls Church, VA 22042 Phone: 1-844-422-5632 Fax: 410-505-9229 Website: https://breakpoint-labs.com Email: contracts@breakpoint-labs.com
12b. Ordering Procedures:
Ordering activities shall use the ordering procedures of Federal Acquisition Regulation (FAR)
8.405 when placing an order or establishing a BPA for supplies or services. These procedures apply to all schedules.
a. FAR 8.405-1 Ordering procedures for supplies, and services not requiring a statement of work.
b. FAR 8.405-2 Ordering procedures for services requiring a statement of work.
Federal Information Technology / Telecommunications Standards Requirements Ordering activities acquiring products from this Schedule must comply with the provisions of the Federal Standards Program, as appropriate (reference: NIST Federal Standards Index). Inquiries to determine whether or not specific products listed herein comply with Federal Information Processing Standards (FIPS) or Federal Telecommunication Standards (FED-STDS), which are cited by ordering activities, shall be responded to promptly by the Contractor.
Federal Information Processing Standards Publications (FIPS PUBS) Information Technology products under this Schedule that do not conform to Federal Information Processing Standards (FIPS) should not be acquired unless a waiver has been granted in accordance with the applicable "FIPS Publication." Federal Information Processing Standards Publications (FIPS PUBS) are issued by the U.S. Department of Commerce, National Institute of Standards and Technology (NIST), pursuant to National Security Act. Information concerning their availability and applicability should be obtained from the National Technical Information Service (NTIS), 5285 Port Royal Road, Springfield, Virginia 22161. FIPS PUBS include voluntary standards when these are adopted for Federal use. Individual orders for FIPS PUBS should be referred to the NTIS Sales
Contract Number: GS-35F-248GA 8
Office, and orders for subscription service should be referred to the NTIS Subscription Officer, both at the above address, or telephone number (703) 487-4650.
Federal Telecommunication Standards (FED-STDS) Telecommunication products under this Schedule that do not conform to Federal Telecommunication Standards (FED-STDS) should not be acquired unless a waiver has been granted in accordance with the applicable "FED-STD." Federal Telecommunication Standards are issued by the U.S. Department of Commerce, NIST, pursuant to National Security Act. Ordering information and information concerning the availability of FED-STDS should be obtained from the GSA, Federal Acquisition Service, Specification Section, 470 East L’Enfant Plaza, Suite 8100, SW, Washington, DC 20407, telephone number (202)619-8925. Please include a self-addressed mailing label when requesting information by mail. Information concerning their applicability can be obtained by writing or calling the U.S. Department of Commerce, NIST, Gaithersburg, MD 20899, telephone number (301) 975-2833.
Contractor Tasks / Special Requirements (C-FSS-370) (NOV 2003)
a. Security Clearances: The Contractor may be required to obtain/possess varying levels of security clearances in the performance of orders issued under this contract. All costs associated with obtaining/possessing such security clearances should be factored into the price offered under the Multiple Award Schedule.
b. Travel: The Contractor may be required to travel in performance of orders issued under this contract. Allowable travel and per diem charges are governed by Pub .L. 99-234 and FAR Part 31, and are reimbursable by the ordering agency or can be priced as a fixed price item on orders placed under the Multiple Award Schedule. Travel in performance of a task order will only be reimbursable to the extent authorized by the ordering agency. The Industrial Funding Fee does NOT apply to travel and per diem charges
c. Certifications, Licenses and Accreditations: As a commercial practice, the Contractor may be required to obtain/possess any variety of certifications, licenses and accreditations for specific FSC/service code classifications offered. All costs associated with obtaining/ possessing such certifications, licenses and accreditations should be factored into the price offered under the Multiple Award Schedule program.
d. Insurance: As a commercial practice, the Contractor may be required to obtain/possess insurance coverage for specific FSC/service code classifications offered. All costs associated with obtaining/possessing such insurance should be factored into the price offered under the Multiple Award Schedule program.
e. Personnel: The Contractor may be required to provide key personnel, resumes or skill category descriptions in the performance of orders issued under this contract. Ordering activities may require agency approval of additions or replacements to key personnel.
f. Organizational Conflicts of Interest: Where there may be an organizational conflict of interest as determined by the ordering agency, the Contractor’s participation in such order may be restricted in accordance with FAR Part 9.5.
g. Documentation/Standards: The Contractor may be requested to provide products or services in accordance with rules, regulations, OMB orders, standards and documentation as specified by the agency’s order.
h. Data/Deliverable Requirements: Any required data/deliverables at the ordering level will be as specified or negotiated in the agency’s order.
Contract Number: GS-35F-248GA 9
i. Government-Furnished Property: As specified by the agency’s order, the Government may provide property, equipment, materials or resources as necessary.
j. Availability of Funds: Many Government agencies’ operating funds are appropriated for a specific fiscal year. Funds may not be presently available for any orders placed under the contract or any option year. The Government’s obligation on orders placed under this contract is contingent upon the availability of appropriated funds from which payment for ordering purposes can be made. No legal liability on the part of the Government for any payment may arise until funds are available to the ordering Contracting Officer.
k. Overtime: For professional services, the labor rates in the Schedule should not vary by virtue of the Contractor having worked overtime. For services applicable to the Service Contract Act (as identified in the Schedule), the labor rates in the Schedule will vary as governed by labor laws (usually assessed a time and a half of the labor rate).
Contract Administration for Ordering Activities Any ordering activity, with respect to any one or more delivery orders placed by it under this contract, may exercise the same rights of termination as might the GSA Contracting Officer under provisions of FAR 52.212 -4, paragraphs (1) Termination for the ordering activity’s convenience, and (m) Termination for Cause (See 52.212-4).
GSA Advantage!™ GSA Advantage!™ is an on-line, interactive electronic information and ordering system that provides on-line access to vendors' schedule prices with ordering information, which may be found at https://www.gsaadvantage.gov.
Purchase of Open Market Items NOTE: Open Market Items are also known as incidental items, noncontract items, non-Schedule items, and items not on a Federal Supply Schedule contract. Ordering Activities procuring open market items must follow FAR 8.402(f).
For administrative convenience, an ordering activity contracting officer may add items not on the Federal Supply Multiple Award Schedule (MAS) -- referred to as open market items -- to a Federal Supply Schedule blanket purchase agreement (BPA) or an individual task or delivery order, only if-
(1) All applicable acquisition regulations pertaining to the purchase of the items not on the Federal Supply Schedule have been followed (e.g., publicizing (Part 5), competition requirements (Part 6), acquisition of commercial items (Part 12), contracting methods (Parts 13, 14, and 15), and small business programs (Part 19));
(2) The ordering activity contracting officer has determined the price for the items not on the Federal Supply Schedule is fair and reasonable;
(3) The items are clearly labeled on the order as items not on the Federal Supply Schedule;
and
(4) All clauses applicable to items not on the Federal Supply Schedule are included in the order.
https://www.gsaadvantage.gov/
Contract Number: GS-35F-248GA 10
Blanket Purchase Agreements (BPAs) The use of BPAs under any schedule contract to fill repetitive needs for supplies or services is allowable. BPAs may be established with one or more schedule contractors. The number of BPAs to be established is within the discretion of the ordering activity establishing the BPA and should be based on a strategy that is expected to maximize the effectiveness of the BPA(s). Ordering activities shall follow FAR 8.405-3 when creating and implementing BPA(s).
Contractor Team Arrangements Contractors participating in contractor team arrangements must abide by all terms and conditions of their respective contracts. This includes compliance with Clauses 552.238-74, Industrial Funding Fee and Sales Reporting, i.e., each contractor (team member) must report sales and remit the IFF for all products and services provided under its individual contract.
Installation, Deinstallation, Reinstallation The Davis-Bacon Act (40 U.S.C. 276a-276a-7) provides that contracts in excess of $2,000 to which the United States or the District of Columbia is a party for construction, alteration, or repair (including painting and decorating) of public buildings or public works with the United States, shall contain a clause that no laborer or mechanic employed directly upon the site of the work shall receive less than the prevailing wage rates as determined by the Secretary of Labor. The requirements of the Davis-Bacon Act do not apply if the construction work is incidental to the furnishing of supplies, equipment, or services. For example, the requirements do not apply to simple installation or alteration of a public building or public work that is incidental to furnishing supplies or equipment under a supply contract. However, if the construction, alteration or repair is segregable and exceeds $2,000, then the requirements of the Davis-Bacon Act applies.
The ordering activity issuing the task order against this contract will be responsible for proper administration and enforcement of the Federal labor standards covered by the Davis-Bacon Act.
The proper Davis-Bacon wage determination will be issued by the ordering activity at the time a request for quotations is made for applicable construction classified installation, deinstallation, and reinstallation services under SIN 132 -8 or 132-9.
Prime Contractor Ordering From Federal Supply Schedules Prime Contractors (on cost reimbursement contracts) placing orders under Federal Supply Schedules, on behalf of an ordering activity, shall follow the terms of the applicable schedule and authorization and include with each order –
a. A copy of the authorization from the ordering activity with whom the contractor has the prime contract (unless a copy was previously furnished to the Federal Supply Schedule contractor); and
b. The following statement:
This order is placed under written authorization from dated . In the event of any inconsistency between the terms and conditions of this order and those of your Federal Supply Schedule contract, the latter will govern.
Contract Number: GS-35F-248GA 11
Insurance – Work on a Government Installation (JAN 1997)(FAR 52.228-5)
a. The Contractor shall, at its own expense, provide and maintain during the entire performance of this contract, at least the kinds and minimum amounts of insurance required in the Schedule or elsewhere in the contract.
b. Before commencing work under this contract, the Contractor shall notify the Contracting Officer in writing that the required insurance has been obtained. The policies evidencing required insurance shall contain an endorsement to the effect that any cancellation or any material change adversely affecting the Government's interest shall not be effective—
(1) For such period as the laws of the State in which this contract is to be performed prescribe; or
(2) Until 30 days after the insurer or the Contractor gives written notice to the Contracting
Officer, whichever period is longer.
c. The Contractor shall insert the substance of this clause, including this paragraph (c), in subcontracts under this contract that require work on a Government installation and shall require subcontractors to provide and maintain the insurance required in the Schedule or elsewhere in the contract. The Contractor shall maintain a copy of all subcontractors' proofs of required insurance, and shall make copies available to the Contracting Officer upon request.
Software Interoperability Offerors are encouraged to identify within their software items any component interfaces that support open standard interoperability. An item’s interface may be identified as interoperable on the basis of participation in a Government agency-sponsored program or in an independent organization program. Interfaces may be identified by reference to an interface registered in the component registry located at http://www.core.gov.
Advance Payments A payment under this contract to provide a service or deliver an article for the United States Government may not be more than the value of the service already provided or the article already delivered. Advance or pre-payment is not authorized or allowed under this contract. (31 U.S.C.
3324).
13. Payment Address(es):
BreakPoint Labs, LLC.
8116 Arlington Boulevard, #255 Falls Church, VA 22042 Phone: 1-844-422-5632 Fax: 410-505-9229 Website: https://breakpoint-labs.com Email: finance@breakpoint-labs.com
14. Warranty Provision:
a. For the purpose of this contract, commitments, warranties and representations include, in addition to those agreed to for the entire schedule contract:
(1) Time of delivery/installation quotations for individual orders;
(2) Technical representations and/or warranties of products concerning performance, total system performance and/or configuration, physical, design and/or functional http://www.core.gov/ mailto:finance@breakpoint-labs.com
Contract Number: GS-35F-248GA 12 characteristics and capabilities of a product/equipment/ service/software package submitted in response to requirements which result in orders under this schedule contract.
(3) Any representations and/or warranties concerning the products made in any literature, description, drawings and/or specifications furnished by the Contractor.
b. The above is not intended to encompass items not currently covered by the GSA Schedule contract.
15. Export Packing Charges:
Not Applicable
16. Terms and Conditions of Rental, Maintenance, and Repair:
Not Applicable
17. Terms and Conditions of Installation:
Not Applicable
18a. Terms and Conditions of Repair Parts:
Not Applicable
18b. Terms and Conditions for Any Other Services:
19. List of Service and Distribution Points:
Not Applicable
20. List of Participating Dealers:
Not Applicable
21. Preventive Maintenance:
Not Applicable
22a. Special Attributes:
Not Applicable
22b. Section 508 Compliance:
If applicable, Section 508 compliance information on the supplies and services in this contract are available in Electronic and Information Technology (EIT) at the following: https://breakpoint-labs.com
The EIT standard can be found at: www.Section508.gov.
23. Data Universal Number System (DUNS) number:
079914189 http://www.section508.gov/
Contract Number: GS-35F-248GA 13
24. Notification Regarding Registration in System for Award Management (SAM) database:
Contractor has registered in the Systems for Award Management.
Commercial and Government Entity (CAGE) Code
7FZP3
Special Notice to Agencies: Small Business Participation SBA strongly supports the participation of small business concerns in the Federal Acquisition Service. To enhance Small Business Participation SBA policy allows agencies to include in their procurement base and goals, the dollar value of orders expected to be placed against the Federal Supply Schedules, and to report accomplishments against these goals.
For orders exceeding the micropurchase threshold, FAR 8.404 requires agencies to consider the catalogs/pricelists of at least three schedule contractors or consider reasonably available information by using the GSA Advantage!™ on- line shopping service (www.gsaadvantage.gov).
The catalogs/pricelists, GSA Advantage!™ and the Federal Acquisition Service Home Page (www.gsa.gov/fas) contain information on a broad array of products and services offered by small business concerns.
This information should be used as a tool to assist ordering activities in meeting or exceeding established small business goals. It should also be used as a tool to assist in including small, small disadvantaged, and women-owned small businesses among those considered when selecting pricelists for a best value determination.
For orders exceeding the micropurchase threshold, customers are to give preference to small business concerns when two or more items at the same delivered price will satisfy their requirement.
Overseas Activities The terms and conditions of this contract shall apply to all orders for installation, maintenance and repair of equipment in areas listed in the pricelist outside the 48 contiguous states and the District of Columbia, except as indicated below:
None.
Upon request of the Contractor, the ordering activity may provide the Contractor with logistics support, as available, in accordance with all applicable ordering activity regulations. Such ordering activity support will be provided on a reimbursable basis, and will only be provided to the Contractor's technical personnel whose services are exclusively required for the fulfillment of the terms and conditions of this contract.
Central Contractor Registration (CCR) Database BreakPoint Labs, LLC. has registered with the CCR Database.
Trade Agreements Act of 1979, as Amended All items are U.S. made end products, designated country end products, Caribbean Basin country end products, Canadian end products, or Mexican end products as defined in the Trade Agreements Act of 1979, as amended.
http://www.gsaadvantage.gov/ http://www.gsa.gov/fas
Contract Number: GS-35F-248GA 14
TERMS AND CONDITIONS APPLICABLE TO
HIGHLY ADAPTIVE CYBERSECURITY SERVICES (HACS)
(SPECIAL ITEM NUMBER: 54151HACS
Vendor suitability for offering services through the Highly Adaptive Cybersecurity Services (HACS) SINs must be in accordance with the following laws and standards when applicable to the specific task orders, including but not limited to:
• Federal Acquisition Regulation (FAR) Part 52.204-21
• OMB Memorandum M-17-12 - Preparing for and Responding to a Breach of Personally
• Identifiable Information (PII)
• OMB Memorandum M- 19-03 - Strengthening the Cybersecurity of Federal Agencies by enhancing the High Value Asset Program
• 2017 Report to the President on Federal IT Modernization
• The Cybersecurity National Action Plan (CNAP)
• NIST SP 800-14 - Generally Accepted Principles and Practices for Securing Information
• Technology Systems
• NIST SP 800-27A - Engineering Principles for Information Technology Security
(A Baseline for Achieving Security)
• NIST SP 800-30 - Guide for Conducting Risk Assessments
• NIST SP 800-35 - Guide to Information Technology Security Services
• NIST SP 800-37 - Risk Management Framework for Information Systems and
Organizations: A Systems Life Cycle Approach for Security and Privacy
• NIST SP 800-39 - Managing Information Security Risk: Organization, Mission, and Information System View
• NIST SP 800-44 - Guidelines on Securing Public Web Servers
• NIST SP 800-48 - Guide to Securing Legacy IEEE 802.11 Wireless Networks
• NIST SP 800-53 – Security and Privacy Controls for Federal Information
Systems and Organizations
• NIST SP 800-61 - Computer Security Incident Handling Guide
• NIST SP 800-64 - Security Considerations in the System Development Life
Cycle
• NIST SP 800-82 - Guide to Industrial Control Systems (ICS) Security
• NIST SP 800-86 - Guide to Integrating Forensic Techniques into Incident
Response
• NIST SP 800-115 - Technical Guide to Information Security Testing and
Assessment
• NIST SP 800-128 - Guide for Security-Focused Configuration Management of
Information Systems
• NIST SP 800-137 - Information Security Continuous Monitoring (ISCM) for
Federal nformation Systems and Organizations
• NIST SP 800-153 - Guidelines for Securing Wireless Local Area Networks
(WLANs)
• NIST SP 800-160 - Systems Security Engineering: Considerations for a
Multidisciplinary Approach in the Engineering of Trustworthy Secure Systems
Contract Number: GS-35F-248GA 15
• NIST SP 800-171 - Protecting Controlled Unclassified Information in non-federal Information Systems and Organizations.
Scope
a. The labor categories, prices, terms and conditions stated under Special Item Number
54151HACS High Adaptive Cybersecurity Services apply exclusively to High Adaptive Cybersecurity Services within the scope of this Information Technology Multiple Award Schedule.
b. Services under this SIN are limited to Highly Adaptive Cybersecurity Services only.
Software and hardware products are under different Special Item Numbers on the IT Multiple Award Schedule (e.g. 33411, 811212, 518210C), and may be quoted along with services to provide a total solution.
c. These SINs provide ordering activities with access to Highly Adaptive Cybersecurity services only.
d. Highly Adaptive Cybersecurity Services provided under these SINs shall comply with all Cybersecurity certifications and industry standards as applicable pertaining to the type of services as specified by ordering agency.
e. The Contractor shall provide services at the Contractor’s facility and/or at the ordering activity location, as agreed to by the Contractor and the ordering activity.
Order
a. Agencies may use written orders, Electronic Data Interchange (EDI) orders, Blanket
Purchase Agreements, individual purchase orders, or task orders for ordering services under this contract. Blanket Purchase Agreements shall not extend beyond the end of the contract period; all services and delivery shall be made and the contract terms and conditions shall continue in effect until the completion of the order. Orders for tasks which extend beyond the fiscal year for which funds are available shall include FAR 52.232-19 (Deviation – May 2003) Availability of Funds for the Next Fiscal Year. The purchase order shall specify the availability of funds and the period for which funds are available.
b. All task orders are subject to the terms and conditions of the contract. In the event of conflict between a task order and the contract, the contract will take precedence.
Performance of Services
a. The Contractor shall commence performance of services on the date agreed to by the
Contractor and the ordering activity. All Contracts will be fully funded.
b. The Contractor agrees to render services during normal working hours, unless otherwise agreed to by the Contractor and the ordering activity.
c. The ordering activity should include the criteria for satisfactory completion for each task in the Statement of Work or Delivery Order. Services shall be completed in a good and workmanlike manner.
d. Any Contractor travel required in the performance of Highly Adaptive Cybersecurity Services must comply with the Federal Travel Regulation or Joint Travel Regulations, as applicable, in effect on the date(s) the travel is performed. Established Federal Government per diem rates will apply to all Contractor travel. Contractors cannot use GSA city pair contracts. All travel will be agreed upon with the client prior to the Contractor’s travel.
Contract Number: GS-35F-248GA 16
Inspection of Services Inspection of services is in accordance with 552.212-4 - CONTRACT TERMS AND
CONDITIONS – COMMERCIAL ITEMS (MAY 2015) (ALTERNATE II – JUL 2009) (FAR
DEVIATION – JUL 2015) (TAILORED) for Firm-Fixed Price and Time-and-Materials and Labor- Hour Contracts orders placed under this contract.
Responsibilities of the Contractor Subject to the ordering activity’s security regulations, the ordering activity shall permit Contractor access to all facilities necessary to perform the requisite Highly Adaptive Cybersecurity Services.
Independent Contractor
a. Definitions.
“Contractor” means the person, firm, unincorporated association, joint venture, partnership, or corporation that is a party to this contract.
“Contractor and its affiliates” and “Contractor or its affiliates” refers to the Contractor, its chief executives, directors, officers, subsidiaries, affiliates, subcontractors at any tier, and consultants and any joint venture involving the Contractor, any entity into or with which the Contractor subsequently merges or affiliates, or any other successor or assignee of the Contractor.
An “Organizational conflict of interest” exists when the nature of the work to be performed under a proposed ordering activity contract, without some restriction on ordering activities by the Contractor and its affiliates, may either (i) result in an unfair competitive advantage to the Contractor or its affiliates or (ii) impair the Contractor’s or its affiliates’ objectivity in performing contract work.
b. To avoid an organizational or financial conflict of interest and to avoid prejudicing the best interests of the ordering activity, ordering activities may place restrictions on the Contractors, its affiliates, chief executives, directors, subsidiaries and subcontractors at any tier when placing orders against schedule contracts. Such restrictions shall be consistent with FAR 9.505 and shall be designed to avoid, neutralize, or mitigate organizational conflicts of interest that might otherwise exist in situations related to individual orders placed against the schedule contract. Examples of situations, which may require restrictions, are provided at FAR 9.508.
Invoices The Contractor, upon completion of the work ordered, shall submit invoices for Highly Adaptive Cybersecurity Services. Progress payments may be authorized by the ordering activity on individual orders if appropriate. Progress payments shall be based upon completion of defined milestones or interim products. Invoices shall be submitted monthly for recurring services performed during the preceding month.
Resumes Resumes shall be provided to the GSA Contracting Officer or the user ordering activity upon request.
Contract Number: GS-35F-248GA 17
Approval of Subcontracts The ordering activity may require that the Contractor receive, from the ordering activity's Contracting Officer, written consent before placing any subcontract for furnishing any of the work called for in a task order.
Description of Highly Adaptive Cybersecurity Services and Pricing
a. The Contractor shall provide a description of each type of Highly Adaptive Cybersecurity
Service offered under Special Item Number 54151HACS for Highly Adaptive Cybersecurity Services and it should be presented in the same manner as the Contractor sells to its commercial and other ordering activity customers. If the Contractor is proposing hourly rates, a description of all corresponding commercial job titles (labor categories) for those individuals who will perform the service should be provided.
b. Pricing for all Highly Adaptive Cybersecurity Services shall be in accordance with the Contractor’s customary commercial practices; e.g., hourly rates, minimum general experience and minimum education.
The following is an example of the manner in which the description of a commercial job title should be presented (see SCP FSS 004)
EXAMPLE
Commercial Job Title: Computer Network Defense Analysis
Description: Uses defensive measures and information collected from a variety of sources to identify, analyze, and report events that occur or might occur within the network in order to protect information, information systems, and networks from threats.
Professionals involved in this specialty perform the following tasks:
• Provide timely detection, identification, and alerting of possible attacks/intrusions, anomalous activities, and misuse activities and distinguish these incidents and events from benign activities
• Provide daily summary reports of network events and activity relevant to Computer Network Defense practices
• Monitor external data sources (e.g., Computer Network Defense vendor sites, Computer Emergency Response Teams, SANS, Security Focus) to maintain currency of Computer Network Defense threat condition and determine which security issues may have an impact on the enterprise.
Knowledge, Skills and Abilities: Knowledge of applicable laws (e.g., Electronic Communications Privacy Act, Foreign Intelligence Surveillance Act, Protect America Act, search and seizure laws, civil liberties and privacy laws, etc.), statutes (e.g., in Titles 10, 18, 32, 50 in U.S. Code), Presidential Directives, executive branch guidelines, and/or administrative/criminal legal guidelines and procedures relevant to work performed
Minimum Experience: 5 Years
Minimum Education Requirements: a bachelor's of science degree with a concentration in computer science, cybersecurity services, management information systems (MIS), engineering or information science is essential.
Contract Number: GS-35F-248GA 18
Highly Desirable: Offensive Security Certified Professional (OSCP) or commercial Cybersecurity advanced certification(s).
Special Item Number 54151HACS – Penetration Testing – Subject to Cooperative Purchasing Penetration testing is security testing in which assessors mimic real-world attacks to identify methods for circumventing the security features of an application, system, or network. Related Job Titles include but are not limited to: Blue Team Technician, Penetration Tester, Red Team Technician, and Ethical Hacker.
Tasks include but are not limited to:
• Conducting and/or supporting authorized penetration testing on enterprise network assets.
• Analyzing site/enterprise Computer Network Defense policies and configurations and evaluate compliance with regulations and enterprise directives.
• Assisting with the selection of cost-effective security controls to mitigate risk (e.g., protection of information, systems, and processes).
Special Item Number 54151HACS – Incident Response – Subject to Cooperative Purchasing Incident response services help organizations impacted by a Cybersecurity compromise determine the extent of the incident, remove the adversary from their systems, and restore their networks to a more secure state.
Related Job Titles include: but are not limited to: Incident Response Analyst, Computer Crime Investigator, and Intrusion Analyst.
Tasks include but are not limited to:
• Collect intrusion artifacts (e.g., source code, malware, and trojans) and use discovered data to enable mitigation of potential Computer Network Defense incidents within the enterprise.
• Perform command and control functions in response to incidents.
• Correlate incident data to identify specific vulnerabilities and make recommendations that enable expeditious remediation.
Special Item Number 54151HACS – Cyber Hunt – Subject to Cooperative Purchasing Cyber hunt activities are responses to crisis or urgent situations within the pertinent domain to mitigate immediate and potential threats. Cyber Hunt activities start with the premise that threat actors known to target some organizations in a specific industry, or specific systems, are likely to also target other organizations in the same industry or with the same systems. Use information and threat intelligence specifically focused on the proximate incident to identify undiscovered attacks.
Investigates and analyzes all relevant response activities.
Related Job Titles include but are not limited to: Computer Crime Investigator, Incident
Handler, Incident Responder, Incident Response Analyst, Incident Response Coordinator and Intrusion Analyst.
Tasks include but are not limited to:
• Collecting intrusion artifacts (e.g., source code, malware, and trojans) and use discovered data to enable mitigation of potential Computer Network Defense incidents within the enterprise.
Contract Number: GS-35F-248GA 19
• Coordinating with and provide expert technical support to enterprise-wide Computer Network Defense technicians to resolve Computer Network Defense incidents.
• Correlating incident data to identify specific vulnerabilities and make recommendations that enable expeditious remediation.
Special Item Number 54151HACS – Risk and Vulnerability Assessments (RVA) – Subject to Cooperative Purchasing Risk and vulnerability assessments conduct assessments of threats and vulnerabilities, determines deviations from acceptable configurations, enterprise or local policy, assesses the level of risk, and develops and/or recommends appropriate mitigation countermeasures in operational and non-operational situations. At a minimum offerors who would like to be considered for this SIN must offer the following services: Network Mapping, Vulnerability Scanning, Phishing Assessment, Wireless Assessment, Web Application Assessment, Operating System Security Assessment (OSSA), and Database Assessment.
Related Job Titles include but are not limited to: Risk/Vulnerability Analyst, Vulnerability Manager, Ethical Hacker, Computer Network Defense (CND) Auditor, Compliance Manager, and Information Security Engineer.
At a minimum, offerors who would like to be considered for this SIN must offer the following services:
• Network Mapping - consists of identifying assets on an agreed upon IP address space or network range(s).
• Vulnerability Scanning - comprehensively identifies IT vulnerabilities associated with agency systems that are potentially exploitable by attackers.
• Phishing Assessment - includes activities to evaluate the level of awareness of the agency workforce with regard to digital form of social engineering that uses authentic looking, but bogus, emails request information from users or direct them to a fake Website that requests information. Phishing assessments can include scanning, testing, or both and can be conducted as a one- time event or as part of a larger campaign to be conducted over several months.
• Wireless Assessment - includes wireless access point (WAP) detection, penetration testing or both and is performed while onsite at a customer s facility.
• Web Application Assessment - includes scanning, testing or both of outward facing web applications for defects in Web service implementation may lead to exploitable vulnerabilities. Provide report on how to implement Web services securely and that traditional network security tools and techniques are used to limit access to the Web Service to only those networks and systems that should have legitimate access.
• Operating System Security Assessment (OSSA) - assesses the configuration of select host operating systems (OS) against standardized configuration baselines.
• Database Assessment - assesses the configuration of selected databases against configuration baselines in order to identify potential misconfigurations and/or database vulnerabilities.
Special Item Number 54151HACS – High Value Asset Assessments (HVA) – Subject to Cooperative Purchasing
Contract Number: GS-35F-248GA 20
High Value Asset Assessments – include Risk and Vulnerability Assessment (RVA) which assesses threats and vulnerabilities, determines deviations from acceptable configurations, enterprise or local policy, assesses the level of risk, and develops and/or recommends appropriate mitigation countermeasures in operational and non-operational situations. Security Architecture Review (SAR) evaluates a subset of the agency’s HVA security posture to determine whether the agency has properly architected its cybersecurity solutions and ensures that agency leadership fully understands the risks inherent in the implemented cybersecurity solution. The SAR process utilizes in-person interviews, documentation reviews, and leading practice evaluations of the HVA environment and supporting systems. SAR provides a holistic analysis of how an HVA’s individual security components integrate and operate, including how data is protected during operations. Systems Security Engineering (SSE) identifies security vulnerabilities and minimizes or contains risks associated with these vulnerabilities spanning the Systems Development Life Cycle. SSE focuses on, but is not limited to the following security areas: perimeter security, network security, endpoint security, application security, physical security, and data security.
Related Job Titles include but are not limited to: Risk/Vulnerability Analyst, Vulnerability Manager, Ethical Hacker, Computer Network Defense (CND) Auditor, Compliance Manager, and Information Security Engineer.
At a minimum, the following services are offered:
• Network Mapping - consists of identifying assets on an agreed upon IP address space or network range(s).
• Vulnerability Scanning - comprehensively identifies IT vulnerabilities associated with agency systems that are potentially exploitable by attackers.
• Phishing Assessment - includes activities to evaluate the level of awareness of the agency workforce with regard to digital form of social engineering that uses authentic looking, but bogus, emails request information from users or direct them to a fake Website that requests information. Phishing assessments can include scanning, testing, or both and can be conducted as a one- time event or as part of a larger campaign to be conducted over several months.
• Wireless Assessment - includes wireless access point (WAP) detection, penetration testing or both and is performed while onsite at a customer s facility.
• Web Application Assessment - includes scanning, testing or both of outward facing web applications for defects in Web service implementation may lead to exploitable vulnerabilities. Provide report on how to implement Web services securely and that traditional network security tools and techniques are used to limit access to the Web Service to only those networks and systems that should have legitimate access.
• Operating System Security Assessment (OSSA) - assesses the configuration of select host operating systems (OS) against standardized configuration baselines.
• Identification of security vulnerabilities and minimization or containment of risks associated with these vulnerabilities spanning the Systems Development Life Cycle
• Database Assessment - assesses the configuration of selected databases against configuration baselines in order to identify potential misconfigurations and/or database vulnerabilities.
Contract Number: GS-35F-248GA 21
Labor Category Descriptions
Labor Category Cybersecurity Subject Matter Expert Functional Responsibilities
- Generally recognized as a leader in the industry in their area of expertise; sought out by others in the area of expertise for advice and guidance
- Provides expert support, analysis, strategy. Policy, research, and advice into exceptionally complex problems, and processes relating to cybersecurity or other functional area
- Serves as technical expert on executive-level project teams providing technical direction, interpretation and alternatives.
Expertise is in Cybersecurity or other functional area.
- Performs highly specialized and technical tasks associated with the most current and cutting-edge technologies including research and development
- May serve as a technical consultant to a project or a number projects dealing with area of cybersecurity or other related technical fields
- Coordinates with Customers/Government personnel to ensure the problems have been properly defined and the solutions satisfy customer needs
Minimum Qualifications and Experience
Qualifications and experience will be determined on a case-by-case basis. Generally, the labor category requires the following minimum qualifications and experience for each corresponding level.
Level Education Experience (Years) Level III PhD or Equivalent 15+ Level II Masters or Equivalent 8-12 Level I Bachelors or Equivalent 2-5
Labor Category Cybersecurity Technical Expert
Responsibilities
- Performs or reviews technical security assessments of computing environments to identify points of vulnerability, non-compliance with established IA standards and regulations and recommend mitigation strategies
- Validates and verifies system security requirements definitions and analyses and establishes system security designs
- Designs, develops, implements and/or integrates IA and security systems and system components including those for networking, computing, and enclave environments to include those with multiple enclaves and with differing data protection/classification requirements
- Builds cybersecurity into systems deployed to operational environments
- Assists architects and systems developers in the identification and implementation of appropriate information security functionality to ensure uniform application security policy and enterprise solutions
- Supports the design and implementation of security architectures
Contract Number: GS-35F-248GA 22
- May provide or support cybersecurity assessments, defensive and offensive cyber operations (DCO), cybersecurity training and research and development (R&D)
- Contributes to the security planning, assessment, risk analysis, risk management, RMF, certification and awareness activities for system and networking operations
- Performs system installation, configuration maintenance, account maintenance, signature maintenance, patch management, and troubleshooting of operational IA and DCO systems
- Applies system security engineering expertise in one or more of the following to: system security design process; engineering life cycle;
information domain; cross domain solutions; identification;
authentication; and authorization; system integration; risk management; intrusion detection; contingency planning; incident handling; configuration control; change management; auditing;
certification and accreditation process;…
This is the start of the file's text. The full file is on GovTribe.
File details come from the government source that posted it. Updated .