MAS - Gritter - Francona, Inc. - GS35F482GA

PDF 675 KB

Attached to
Federal Supply Schedule GS35F482GA Federal contract IDV
Contract number
GS35F482GA
Issued by
GSA Federal Acquisition Service

About this file

This document provides a federal supply schedule price list for information technology products and services awarded to Gritter Francona, Inc. The schedule contract was awarded on June 7, 2017 under GS35F482GA and has a potential value of $7,704,104. It includes special item numbers for highly adaptive cybersecurity services, information technology training, and information technology professional services.

The price list details labor categories and rates that escalate annually up to 5 years, as well as fixed prices for cybersecurity training courses. It also provides descriptions of six professional services labor categories with required education, experience, and certifications. The categories range from entry level to senior level and cover technical skills such as vulnerability assessments, penetration testing, and compliance functions including policy development and risk assessments.

Delta Risk LLC Pricelist and/or Vendor Terms and Conditions for GS35F482GA, a Federal Supply Schedule awarded to Delta Risk LLC, under Information Technology Schedule 70 (IT-70)

View the file

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

7361 Calhoun Place, Suite 450 Rockville, MD 20855

AUTHORIZED FEDERAL SUPPLY SERVICE

INFORMATION TECHNOLOGY SCHEDULE PRICELIST

GENERAL PURPOSE COMMERCIAL INFORMATION TECHNOLOGY

EQUIPMENT, SOFTWARE AND SERVICES

Special Item No.

• 54151HACS --- HIGHLY ADAPTIVE CYBERSECURITY SERVICES (HACS)

• 611420 --- Information Technology Training

• 54151S --- INFORMATION TECHNOLOGY PROFESSIONAL SERVICES

FSC/PSC Class D310 IT AND TELECOM- CYBER SECURITY AND DATA BACKUP

Gritter Francona, Inc.

7361 Calhoun Place, Suite 450

Rockville, MD 20855

(616) 218-8349 www.gritterfrancona.com

Contract Number: GS-35F-482GA

Period Covered by Contract: 07 June 2017 – 06 June 2022

General Services Administration

Federal Supply Service

Pricelist current through Modification #A839, dated 03/23/2022

Products and ordering information in this Authorized Information Technology Schedule Pricelist are also available on the GSA Advantage! System (http://www.gsaadvantage.gov).

CUSTOMER INFORMATION

1a. Table of awarded special item numbers with appropriate cross-reference to item descriptions and awarded prices.

SIN Labor Category GSA Price inclusive of IFF

54151HACS, 54151S Level 1 $80.94

54151HACS, 54151S Level 2 $110.00

54151HACS, 54151S Level 3

$116.75

54151HACS, 54151S Level 4

$146.43

54151HACS, 54151S Level 5 $190.65

54151HACS, 54151S Level 6 $305.05

SIN Training Course GSA Price inclusive of IFF

611420 Cyber Security Investigations

$7,472.01

611420 Vulnerability Assessment (VA) (New full day course development & delivery)

$26,619.04

611420 Executive Cyber Security Awareness $2,687.85

611420 Program Security Fundamentals

$28,538.93

1b. Identification of the lowest priced model number and lowest unit price for that model for each special item number awarded in the contract. This price is the Government price based on a unit of one, exclusive of any quantity/dollar volume, prompt payment, or any other concession affecting price. Those contracts that have unit prices based on the geographic location of the customer, should show the range of the lowest price, and cite the areas to which the prices apply. N/A

1c. If the Contractor is proposing hourly rates, a description of all corresponding commercial job titles, experience, functional responsibility and education for those types of employees or subcontractors who will perform services shall be provided. If hourly rates are not applicable, indicate “Not applicable” for this item.

See terms and conditions for labor category descriptions.

2. Maximum order.

• Special Item Number 54151HACS - $500,000

• Special Item Number 611420 - $25,000

• Special Item Number 54151S - $500,000

3. Minimum order. $100.00

4. Geographic coverage (delivery area). CONUS

5. Point(s) of production (city, county, and State or foreign country). N/A

6. Discount from list prices or statement of net price. 1-3% from list price

7. Quantity discounts. None

8. Prompt payment terms. Note: Prompt payment terms must be followed by the statement "Information for

Ordering Offices: Prompt payment terms cannot be negotiated out of the contractual agreement in exchange for other concessions." 0% in Net 30 Days.

9a. Notification that Government purchase cards are accepted at or below the micro-purchase threshold.

• Purchase cards are accepted at or below the micro-purchase threshold.

9b. Notification whether Government purchase cards are accepted or not accepted above the micro-purchase threshold.

• Purchase cards are accepted above the micro-purchase threshold.

10. Foreign items (list items by country of origin). None

11a. Time of delivery. (Contractor insert number of days.) At task order level.

11b. Expedited Delivery. The Contractor will insert the sentence “Items available for expedited delivery are noted in this price list.” under this heading. The Contractor may use a symbol of its choosing to highlight items in its price lists that have expedited delivery.

• Customer may contact the Contractor for expedited delivery

11c. Overnight and 2-day delivery. The Contractor will indicate whether overnight and 2-day delivery are available. Also, the Contractor will indicate that the schedule customer may contact the Contractor for rates for overnight and 2-day delivery.

• Customer may contact the Contractor for rates for overnight and 2-day delivery

11d. Urgent Requirements. The Contractor will note in its price list the “Urgent Requirements” clause of its contract and advise agencies that they can also contact the Contractor’s representative to affect a faster delivery.

• Customer may contact the Contractor to affect a faster delivery

12. F.O.B. point. N/A

13a. Ordering address.

7361 Calhoun Place, Suite 450

13b. Ordering procedures: For supplies and services, the ordering procedures, information on Blanket

Purchase Agreements (BPA’s) are found in Federal Acquisition Regulation (FAR) 8.405-3.

14. Payment address.

7364 Calhoun Place, Suite 450

616-218-8349

15. Warranty provision. Standard

16. Export packing charges, if applicable. N/A

17. Terms and conditions of Government purchase card acceptance (any thresholds above the micro-purchase level). N/A

18. Terms and conditions of rental, maintenance, and repair (if applicable). N/A

19. Terms and conditions of installation (if applicable). N/A

20. Terms and conditions of repair parts indicating date of parts price lists and any discounts from list prices (if applicable). N/A

20a. Terms and conditions for any other services (if applicable). N/A

21. List of service and distribution points (if applicable). N/A

22. List of participating dealers (if applicable). N/A

23. Preventive maintenance (if applicable). N/A

24a. Special attributes such as environmental attributes. N/A

24b. If applicable, indicate that Section 508 compliance information is available on Electronic and Information

Technology (EIT) supplies and services and show where full details can be found (e.g. contractor’s website or other location.) The EIT standards can be found at: www.Section508.gov/.

Section 508 compliance information on the supplies and services in this contract are available at the following website address (URL): to come when needed

The EIT standard can be found at: www.Section508.gov/.

25. Data Universal Number System (DUNS) number. 027678710

26. Notification regarding registration in Central Contractor Registration (CCR) database.

• Registered with Cage Code 53EZ8 http://www.section508.gov/ http://www.section508.gov/

1. SCOPE

a. The Contractor shall provide training courses normally available to commercial customers, which will permit ordering activity users to make full, efficient use of general-purpose commercial

IT products. Training is restricted to training courses for those products within the scope of this solicitation.

b. The Contractor shall provide training at the Contractor's facility and/or at the ordering activity's location, as agreed to by the Contractor and the ordering activity.

2. ORDER

Written orders, EDI orders (GSA Advantage! and FACNET), credit card orders, and orders placed under blanket purchase agreements (BPAs) shall be the basis for the purchase of training courses in accordance with the terms of this contract. Orders shall include the student's name, course title, course date and time, and contracted dollar amount of the course.

3. TIME OF DELIVERY

The Contractor shall conduct training on the date (time, day, month, and year) agreed to by the

Contractor and the ordering activity.

4. CANCELLATION AND RESCHEDULING

a. The ordering activity will notify the Contractor at least seventy-two (72) hours before the scheduled training date, if a student will be unable to attend. The Contractor will then permit the ordering activity to either cancel the order or reschedule the training at no additional charge. In the event the training class is rescheduled, the ordering activity will modify its original training order to specify the time and date of the rescheduled training class.

b. In the event the ordering activity fails to cancel or reschedule a training course within the time frame specified in paragraph a, above, the ordering activity will be liable for the contracted dollar amount of the training course. The Contractor agrees to permit the ordering activity to reschedule a student who fails to attend a training class within ninety (90) days from the original course date, at no additional charge.

c. The ordering activity reserves the right to substitute one student for another up to the first day of class.

d. In the event the Contractor is unable to conduct training on the date agreed to by the

Contractor and the ordering activity, the Contractor must notify the ordering activity at least seventy-two (72) hours before the scheduled training date.

TERMS AND CONDITIONS APPLICABLE TO PURCHASE OF

TRAINING COURSES FOR GENERAL PURPOSE COMMERCIAL

INFORMATION TECHNOLOGY EQUIPMENT AND SOFTWARE

(SPECIAL ITEM NUMBER - 611420)

5. FOLLOW-UP SUPPORT

The Contractor agrees to provide each student with unlimited telephone support or online support for a period of one (1) year from the completion of the training course. During this period, the student may contact the Contractor's instructors for refresher assistance and answers to related course curriculum questions.

6. PRICE FOR TRAINING

The price that the ordering activity will be charged will be the ordering activity training price in effect at the time of order placement, or the ordering activity price in effect at the time the training course is conducted, whichever is less.

Course title

Course Length

PRICE per

Course

(including IFF)

Cyber Security Investigations Full Day $7,472.01

Vulnerability Assessment (VA) (New full day course development & delivery) Full Day $26,619.04

Executive Cyber Security Awareness 1/2 Day $2,687.85

Program Security Fundamentals 4 Days $28,538.93

7. INVOICES AND PAYMENT

Invoices for training shall be submitted by the Contractor after ordering activity completion of the training course. Charges for training must be paid in arrears (31 U.S.C. 3324). PROMPT PAYMENT

DISCOUNT, IF APPLICABLE, SHALL BE SHOWN ON THE INVOICE.

8. FORMAT AND CONTENT OF TRAINING

a. The Contractor shall provide written materials (i.e., manuals, handbooks, texts, etc.)

normally provided with course offerings, printed and copied two-sided on paper containing 30% postconsumer materials (fiber). Such documentation will become the property of the student upon completion of the training class.

b. **If applicable** For hands-on training courses, there must be a one-to-one assignment of IT equipment to students.

c. The Contractor shall provide each student with a Certificate of Training at the completion of each training course.

d. The Contractor shall provide the following information for each training course offered:

(1) The course title and a brief description of the course content, to include the course format (e.g., lecture, discussion, hands-on training);

(2) The length of the course;

(3) Mandatory and desirable prerequisites for student enrollment;

(4) The minimum and maximum number of students per class;

(5) The locations where the course is offered;

(6) Class schedules; and

(7) Price (per student, per class (if applicable)).

Course title Brief Description

Cyber

Security

Investigations

This one-day course introduces students to the processes involved in investigating a cybersecurity incident, specifically focused on the information collection and analysis perspective. Students learn about digital forensics techniques and how the information can be used to help pain the picture of a cyber incident. This course provides the basic knowledge and skills to help students understand how an investigation is conducted and the processes included.

Length: 1 Day

Type: Technical Training, no mandatory prerequisite for enrollment.

Location: Remote or in-person

Vulnerability

Assessment

(VA) (New full day course development

& delivery)

This one-day course is designed to familiarize students with concepts and processes involved in performing a vulnerability assessment. Students will learn the preparatory considerations, how to conduct basic vulnerability scans, and reporting goals following an assessment. This course provides the overall picture a student needs to understand the managerial and operational concepts of a vulnerability assessment.

Length: 1 Day

Executive

Cyber

Security

Awareness

This course provides senior government officials training in cyber policy and operations that was not built into their developmental training due to its relative newness. The goal is to provide senior leaders with enough background on cyberspace to understand its strategic implications and uses, current government policies that govern actions in the cyber domain, and current threats that the United States face in the cyber environment. Students will be familiarized with the individual risks that USG senior leaders face in utilizing information technology and cyber systems. It is understood that today’s senior cyber leadership may have limited cyber experience and background – this course serves to expand their cyber knowledge base and individual skills. This half-day course is presented live on customer site.

Length: 1/2 Day

Program

Security

Fundamentals

This four-day course provides students with a broad understanding of security policy, principles, rules, and procedures. Students will learn about the multiple facets of security related to Special Access Programs (SAP), focusing on Department of Defense (DoD), Intelligence Community (IC), and other service-related regulations and guidance.

Length: 4 Days

e. For those courses conducted at the ordering activity’s location, instructor travel charges (if applicable), including mileage and daily living expenses (e.g., per diem charges) are governed by

Pub. L. 99-234 and FAR Part 31.205-46, and are reimbursable by the ordering activity on orders placed under the Multiple Award Schedule, as applicable, in effect on the date(s) the travel is performed. Contractors cannot use GSA city pair contracts. The Industrial Funding Fee does NOT apply to travel and per diem charges.

f. For Online Training Courses, a copy of all training material must be available for electronic download by the students.

9. “NO CHARGE” TRAINING

The Contractor shall describe any training provided with equipment and/or software provided under this contract, free of charge, in the space provided below.

None

Course title Brief Description

****NOTE: All non-professional labor categories must be incidental to, and used solely to support professional services, and cannot be purchased separately.

1. SCOPE

a. The prices, terms and conditions stated under Special Item Number 54151S Information

Technology Professional Services apply exclusively to IT Professional Services within the scope of this Information Technology Schedule.

b. The Contractor shall provide services at the Contractor’s facility and/or at the ordering activity location, as agreed to by the Contractor and the ordering activity.

2. PERFORMANCE INCENTIVES I-FSS-60 Performance Incentives (April 2000)

a. Performance incentives may be agreed upon between the Contractor and the ordering activity on individual fixed price orders or Blanket Purchase Agreements under this contract.

b. The ordering activity must establish a maximum performance incentive price for these services and/or total solutions on individual orders or Blanket Purchase Agreements.

c. Incentives should be designed to relate results achieved by the contractor to specified targets. To the maximum extent practicable, ordering activities shall consider establishing incentives where performance is critical to the ordering activity’s mission and incentives are likely to motivate the contractor. Incentives shall be based on objectively measurable tasks.

3. ORDER

a. Agencies may use written orders, EDI orders, blanket purchase agreements, individual purchase orders, or task orders for ordering services under this contract. Blanket Purchase

Agreements shall not extend beyond the end of the contract period; all services and delivery shall be made, and the contract terms and conditions shall continue in effect until the completion of the order. Orders for tasks which extend beyond the fiscal year for which funds are available shall include FAR 52.232-19 (Deviation – May 2003) Availability of Funds for the Next Fiscal Year. The purchase order shall specify the availability of funds and the period for which funds are available.

b. All task orders are subject to the terms and conditions of the contract. In the event of conflict between a task order and the contract, the contract will take precedence.

4. PERFORMANCE OF SERVICES

a. The Contractor shall commence performance of services on the date agreed to by the

Contractor and the ordering activity.

b. The Contractor agrees to render services only during normal working hours, unless otherwise agreed to by the Contractor and the ordering activity.

TERMS AND CONDITIONS APPLICABLE TO INFORMATION TECHNOLOGY (IT)

PROFESSIONAL SERVICES (SPECIAL ITEM NUMBER - 54151S)

c. The ordering activity should include the criteria for satisfactory completion for each task in the Statement of Work or Delivery Order. Services shall be completed in a good and workmanlike manner.

d. Any Contractor travel required in the performance of IT Services must comply with the

Federal Travel Regulation or Joint Travel Regulations, as applicable, in effect on the date(s) the travel is performed. Established Federal Government per diem rates will apply to all Contractor travel. Contractors cannot use GSA city pair contracts.

5. STOP-WORK ORDER (FAR 52.242-15) (AUG 1989)

(a) The Contracting Officer may, at any time, by written order to the Contractor, require the

Contractor to stop all, or any part, of the work called for by this contract for a period of 90 days after the order is delivered to the Contractor, and for any further period to which the parties may agree. The order shall be specifically identified as a stop-work order issued under this clause. Upon receipt of the order, the Contractor shall immediately comply with its terms and take all reasonable steps to minimize the incurrence of costs allocable to the work covered by the order during the period of work stoppage. Within a period of 90 days after a stop-work is delivered to the

Contractor, or within any extension of that period to which the parties shall have agreed, the

Contracting Officer shall either-

(1) Cancel the stop-work order; or

(2) Terminate the work covered by the order as provided in the Default, or the

Termination for Convenience of the Government, clause of this contract.

(b) If a stop-work order issued under this clause is canceled or the period of the order or any extension thereof expires, the Contractor shall resume work. The Contracting Officer shall make an equitable adjustment in the delivery schedule or contract price, or both, and the contract shall be modified, in writing, accordingly, if-

(1) The stop-work order results in an increase in the time required for, or in the

Contractor's cost properly allocable to, the performance of any part of this contract; and

(2) The Contractor asserts its right to the adjustment within 30 days after the end of the period of work stoppage; provided, that, if the Contracting Officer decides the facts justify the action, the Contracting Officer may receive and act upon the claim submitted at any time before final payment under this contract.

(c) If a stop-work order is not canceled and the work covered by the order is terminated for the convenience of the Government, the Contracting Officer shall allow reasonable costs resulting from the stop-work order in arriving at the termination settlement.

(d) If a stop-work order is not canceled and the work covered by the order is terminated for default, the Contracting Officer shall allow, by equitable adjustment or otherwise, reasonable costs resulting from the stop-work order.

6. INSPECTION OF SERVICES

In accordance with FAR 52.212-4 CONTRACT TERMS AND CONDITIONS--COMMERCIAL ITEMS

(MAR 2009) (DEVIATION I - FEB 2007) for Firm-Fixed Price orders and FAR 52.212-4 CONTRACT

TERMS AND CONDITIONS COMMERCIAL ITEMS (MAR 2009) (ALTERNATE I OCT 2008)

(DEVIATION I – FEB 2007) applies to Time-and-Materials and Labor-Hour Contracts orders placed under this contract.

7. RESPONSIBILITIES OF THE CONTRACTOR

The Contractor shall comply with all laws, ordinances, and regulations (Federal, State, City, or otherwise) covering work of this character. If the end product of a task order is software, then FAR

52.227-14 (Dec 2007) Rights in Data – General, may apply.

8. RESPONSIBILITIES OF THE ORDERING ACTIVITY

Subject to security regulations, the ordering activity shall permit Contractor access to all facilities necessary to perform the requisite IT Professional Services.

9. INDEPENDENT CONTRACTOR

All IT Professional Services performed by the Contractor under the terms of this contract shall be as an independent Contractor, and not as an agent or employee of the ordering activity.

10. ORGANIZATIONAL CONFLICTS OF INTEREST

a. Definitions.

“Contractor” means the person, firm, unincorporated association, joint venture, partnership, or corporation that is a party to this contract.

“Contractor and its affiliates” and “Contractor or its affiliates” refers to the Contractor, its chief executives, directors, officers, subsidiaries, affiliates, subcontractors at any tier, and consultants and any joint venture involving the Contractor, any entity into or with which the Contractor subsequently merges or affiliates, or any other successor or assignee of the Contractor.

An “Organizational conflict of interest” exists when the nature of the work to be performed under a proposed ordering activity contract, without some restriction on ordering activities by the

Contractor and its affiliates, may either (i) result in an unfair competitive advantage to the

Contractor or its affiliates or (ii) impair the Contractor’s or its affiliates’ objectivity in performing contract work.

b. To avoid an organizational or financial conflict of interest and to avoid prejudicing the best interests of the ordering activity, ordering activities may place restrictions on the Contractors, its affiliates, chief executives, directors, subsidiaries and subcontractors at any tier when placing orders against schedule contracts. Such restrictions shall be consistent with FAR 9.505 and shall be designed to avoid, neutralize, or mitigate organizational conflicts of interest that might otherwise exist in situations related to individual orders placed against the schedule contract. Examples of situations, which may require restrictions, are provided at FAR 9.508.

11. INVOICES

The Contractor, upon completion of the work ordered, shall submit invoices for IT Professional services. Progress payments may be authorized by the ordering activity on individual orders if appropriate. Progress payments shall be based upon completion of defined milestones or interim products. Invoices shall be submitted monthly for recurring services performed during the preceding month.

12. PAYMENTS

For firm-fixed price orders the ordering activity shall pay the Contractor, upon submission of proper invoices or vouchers, the prices stipulated in this contract for service rendered and accepted. Progress payments shall be made only when authorized by the order. For time-and-materials orders, the Payments under Time-and-Materials and Labor-Hour Contracts at

FAR 52.212-4 (MAR 2009) (ALTERNATE I – OCT 2008) (DEVIATION I – FEB 2007) applies to time-and-materials orders placed under this contract. For labor-hour orders, the Payment under

Time-and-Materials and Labor-Hour Contracts at FAR 52.212-4 (MAR 2009) (ALTERNATE I – OCT

2008) (DEVIATION I – FEB 2007) applies to labor-hour orders placed under this contract. 52.216-

31(Feb 2007) Time-and-Materials/Labor-Hour Proposal Requirements—Commercial Item

Acquisition. As prescribed in 16.601(e)(3), insert the following provision:

(a) The Government contemplates award of a Time-and-Materials or Labor-Hour type of contract resulting from this solicitation.

(b) The offeror must specify fixed hourly rates in its offer that include wages, overhead, general and administrative expenses, and profit. The offeror must specify whether the fixed hourly rate for each labor category applies to labor performed by—

(1) The offeror;

(2) Subcontractors; and/or

(3) Divisions, subsidiaries, or affiliates of the offeror under a common control.

13. RESUMES

Resumes shall be provided to the GSA Contracting Officer or the user ordering activity upon request.

14. INCIDENTAL SUPPORT COSTS

Incidental support costs are available outside the scope of this contract. The costs will be negotiated separately with the ordering activity in accordance with the guidelines set forth in the

FAR.

15. APPROVAL OF SUBCONTRACTS

The ordering activity may require that the Contractor receive, from the ordering activity's

Contracting Officer, written consent before placing any subcontract for furnishing any of the work called for in a task order.

16. DESCRIPTION OF IT PROFESSIONAL SERVICES AND PRICING

Gritter Francona will provide personnel and services covering a range of Information Assurance issues, to include cybersecurity, policy, governance, technical implementation, penetration testing, vulnerability assessments, exercises (operational and table top), Risk Management Framework, assessments, and others as identified. Our experienced team can provide a full range of these services to include assistance in scoping, implementing, assessing, and auditing. We can work with any technical solution implemented and place a focus on looking at processes and applicable security controls to your unique situation.

For labor category descriptions go to page 21 below for review.

Escalated GSA Proposed Prices w/2% escalation rate including IFF

Labor Category year 1 year 2 year 3 year 4 year 5

Level 1 $77.80 $79.36 $80.94 $82.56 $84.21

Level 2 $105.73 $107.84 $110.00 $112.20 $114.45

Level 3 $112.22 $114.46 $116.75 $119.09 $121.47

Level 4 $140.74 $143.55 $146.43 $149.35 $152.34

Level 5 $183.25 $186.92 $190.65 $194.47 $198.36

Level 6 $293.20 $299.06 $305.05 $311.15 $317.37

Vendor suitability for offering services through the Highly Adaptive Cybersecurity Services (HACS)

SIN must be in accordance with the following laws and standards when applicable to the specific task orders, including but not limited to:

● Federal Acquisition Regulation (FAR) Part 52.204-21

● OMB Memorandum M-06-19 - Reporting Incidents Involving Personally Identifiable

Information and Incorporating the Cost for Security in Agency Information Technology Investments

● OMB Memorandum M -07-16 - Safeguarding Against and Responding to the Breach of

Personally Identifiable Information

● OMB Memorandum M-16-03 - Fiscal Year 2015-2016 Guidance on Federal Information

Security and Privacy Management Requirements

● OMB Memorandum M-16-04 – Cybersecurity Implementation Plan (CSIP) for Federal

Civilian Government

● The Cybersecurity National Action Plan (CNAP)

● OMB Memorandum M-17-09 Management of Federal High Value Assets

● NIST SP 800-14 - Generally Accepted Principles and Practices for Securing Information

Technology Systems

● NIST SP 800-27A - Engineering Principles for Information Technology Security (A Baseline for Achieving Security)

● NIST SP 800-30 - Guide for Conducting Risk Assessments

● NIST SP 800-35 - Guide to Information Technology Security Services

● NIST SP 800-37 - Guide for Applying the Risk Management Framework to Federal

Information Systems: A Security Life Cycle Approach

● NIST SP 800-39 - Managing Information Security Risk: Organization, Mission, and

Information System View

● NIST SP 800-44 - Guidelines on Securing Public Web Servers

● NIST SP 800-48 - Guide to Securing Legacy IEEE 802.11 Wireless Networks

TERMS AND CONDITIONS APPLICABLE TO HIGHLY ADAPTIVE CYBERSECURITY SERVICES

(HACS) (SPECIAL ITEM NUMBER - 54151HACS)

● NIST SP 800-53 – Security and Privacy Controls for Federal Information Systems and

Organizations

● NIST SP 800-61 - Computer Security Incident Handling Guide

● NIST SP 800-64 - Security Considerations in the System Development Life Cycle

● NIST SP 800-82 - Guide to Industrial Control Systems (ICS) Security

● NIST SP 800-86 - Guide to Integrating Forensic Techniques into Incident Response

● NIST SP 800-115 - Technical Guide to Information Security Testing and Assessment

● NIST SP 800-128 - Guide for Security-Focused Configuration Management of Information

Systems

● NIST SP 800-137 - Information Security Continuous Monitoring (ISCM) for Federal

Information Systems and Organizations

● NIST SP 800-153 - Guidelines for Securing Wireless Local Area Networks (WLANs)

● NIST SP 800-171 - Protecting Controlled Unclassified Information in non-federal

Information Systems and Organizations

****NOTE: All non-professional labor categories must be incidental to, and used solely to support

Highly Adaptive Cybersecurity Services, and cannot be purchased separately.

****NOTE: All labor categories under the Special Item Number 54151S Information Technology

Professional Services may remain under SIN 54151S unless the labor categories are specific to the

Highly Adaptive Cybersecurity Services SIN 54151HACS.

1. SCOPE

a. The labor categories, prices, terms and conditions stated under Special Item Number

54151HACS High Adaptive Cybersecurity Services apply exclusively to High Adaptive Cybersecurity

Services within the scope of this Information Technology Schedule.

b. Services under these SINs are limited to Highly Adaptive Cybersecurity Services only.

Software and hardware products are under different Special Item Numbers on IT Schedule 70 (e.g.

511210, 33411), and may be quoted along with services to provide a total solution.

c. These SINs provide ordering activities with access to Highly Adaptive Cybersecurity services only.

d. Highly Adaptive Cybersecurity Services provided under these SINs shall comply with all

Cybersecurity certifications and industry standards as applicable pertaining to the type of services as specified by ordering agency.

e. The Contractor shall provide services at the Contractor’s facility and/or at the ordering activity location, as agreed to by the Contractor and the ordering activity.

2. ORDER

a. Agencies may use written orders, Electronic Data Interchange (EDI) orders, Blanket

Purchase Agreements, individual purchase orders, or task orders for ordering services under this contract. Blanket Purchase Agreements shall not extend beyond the end of the contract period; all services and delivery shall be made, and the contract terms and conditions shall continue in effect until the completion of the order. Orders for tasks which extend beyond the fiscal year for which funds are available shall include FAR 52.232-19 (Deviation – May 2003) Availability of Funds for the Next Fiscal Year. The purchase order shall specify the availability of funds and the period for which funds are available.

b. All task orders are subject to the terms and conditions of the contract. In the event of conflict between a task order and the contract, the contract will take precedence.

3. PERFORMANCE OF SERVICES

a. The Contractor shall commence performance of services on the date agreed to by the

Contractor and the ordering activity. All Contracts will be fully funded.

b. The Contractor agrees to render services during normal working hours, unless otherwise agreed to by the Contractor and the ordering activity.

a. The ordering activity should include the criteria for satisfactory completion for each task in the Statement of Work or Delivery Order. Services shall be completed in a good and workmanlike manner.

b. Any Contractor travel required in the performance of Highly Adaptive Cybersecurity

Services must

c. comply with the Federal Travel Regulation or Joint Travel Regulations, as applicable, in effect on the date(s) the travel is performed. Established Federal Government per diem rates will apply to all Contractor travel. Contractors cannot use GSA city pair contracts. All travel will be agreed upon with the client prior to the Contractor’s travel.

4. INSPECTION OF SERVICES

Inspection of services is in accordance with 552.212-4 - CONTRACT TERMS AND CONDITIONS –

COMMERCIAL ITEMS (MAY 2015) (ALTERNATE II – JUL 2009) (FAR DEVIATION – JUL 2015)

(TAILORED) for Firm-Fixed Price and Time-and-Materials and Labor-Hour Contracts orders placed under this contract.

5. RESPONSIBILITIES OF THE CONTRACTOR

The Contractor shall comply with all laws, ordinances, and regulations (Federal, State, City, or otherwise) covering work of this character. If the end product of a task order is software, then FAR

52.227-14 (MAY 2014) Rights in Data – General, may apply.

The Contractor shall comply with contract clause (52.204-21) to the Federal Acquisition Regulation

(FAR) for the basic safeguarding of contractor information systems that process, store, or transmit

Federal data received by the contract in performance of the contract. This includes contract documents and all information generated in the performance of the contract.

6. RESPONSIBILITIES OF THE ORDERING ACTIVITY

Subject to the ordering activity’s security regulations, the ordering activity shall permit Contractor access to all facilities necessary to perform the requisite Highly Adaptive Cybersecurity Services.

7. INDEPENDENT CONTRACTOR

All Highly Adaptive Cybersecurity Services performed by the Contractor under the terms of this contract shall be as an independent Contractor, and not as an agent or employee of the ordering activity.

8. ORGANIZATIONAL CONFLICTS OF INTEREST

a. Definitions.

“Contractor” means the person, firm, unincorporated association, joint venture, partnership, or corporation that is a party to this contract. “Contractor and its affiliates” and “Contractor or its affiliates” refers to the Contractor, its chief executives, directors, officers, subsidiaries, affiliates, subcontractors at any tier, and consultants and any joint venture involving the Contractor, any entity into or with which the Contractor subsequently merges or affiliates, or any other successor or assignee of the Contractor.

An “Organizational conflict of interest” exists when the nature of the work to be performed under a proposed ordering activity contract, without some restriction on ordering activities by the

Contractor and its affiliates, may either (i) result in an unfair competitive advantage to the

Contractor or its affiliates or (ii) impair the Contractor’s or its affiliates’ objectivity in performing contract work.

b) To avoid an organizational or financial conflict of interest and to avoid prejudicing the best interests of the directors, subsidiaries and subcontractors at any tier when placing orders against schedule contracts. Such restrictions shall be consistent with FAR 9.505 and shall be designed to avoid, neutralize, or mitigate organizational conflicts of interest that might otherwise exist in situations related to individual orders placed against the schedule contract. Examples of situations, which may require restrictions, are provided at FAR 9.508.

9. INVOICES

The Contractor, upon completion of the work ordered, shall submit invoices for Highly Adaptive

Cybersecurity Services. Progress payments may be authorized by the ordering activity on individual orders if appropriate. Progress payments shall be based upon completion of defined milestones or interim products. Invoices shall be submitted monthly for recurring services performed during the preceding month.

10. RESUMES

Resumes shall be provided to the GSA Contracting Officer or the user ordering activity upon request.

11. APPROVAL OF SUBCONTRACTS

The ordering activity may require that the Contractor receive, from the ordering activity's

Contracting Officer, written consent before placing any subcontract for furnishing any of the work called for in a task order.

12. DESCRIPTION OF HIGHLY ADAPTIVE CYBERSECURITY SERVICES AND PRICING

Gritter Francona will provide personnel and services covering a range of Information Assurance issues, to include cybersecurity, policy, governance, technical implementation, penetration testing, vulnerability assessments, exercises (operational and table top), Risk Management Framework, assessments, high value asset assessments, and others as identified. Our experienced team can provide a full range of these services to include assistance in scoping, implementing, assessing, and auditing. We can work with any technical solution implemented and place a focus on looking at processes and applicable security controls to your unique situation.

Escalated GSA Proposed Prices w/2% escalation rate including IFF

Labor Category year 1 year 2 year 3 year 4 year 5

Level 1 $77.80 $79.36 $80.94 $82.56 $84.21

Level 2 $105.73 $107.84 $110.00 $112.20 $114.45

Level 3 $112.22 $114.46 $116.75 $119.09 $121.47

Level 4 $140.74 $143.55 $146.43 $149.35 $152.34

Level 5 $183.25 $186.92 $190.65 $194.47 $198.36

Level 6 $293.20 $299.06 $305.05 $311.15 $317.37

Professional Services

Labor Category Descriptions and Relevant Experience

Company Proprietary Information Version 1

LEVEL 1 – Professional Services Job Performance Self-Improvement Organizational Contribution

Years of Experience 0-3

Education Associates or Bachelor’s degree in IT or

Information Security preferred.

Continuing

Education

Instructor led:

• Conferences

• Seminars

• College/university courses

• E-Learning (instructor led)

Self-paced:

• e-Learning (self-paced)

• Videoconferences

• Webcasts

• Audiocasts

• Podcasts

Activities • Attends 2-3 company sponsored webinars/brown bags

• Participates in 2-3 company social events

• Participation in industry association/forums

Alternatively, HS degree minimum plus 2-3 years’ relevant subject matter experience; or equivalent training/certifications.

o Chapter Meetings o Local seminars/events/expos

• Contributes at least 1-2:

o Webinar o Brown Bags o White Paper o Blog

• Contributing/supporting company recruiting efforts

Performance metrics

85-90% billing utilization Certifications

Recommended

In lieu of education: GPEN, OSCP, CEH or other desired/relevant certifications

Business

Development

• Understands basic steps in sales process

• Supports practice business development activities

• Demonstrates knowledge of Company products and services

Tasks

• Ensures quality deliverables

• Provide timely deliverables to clients

• Completes initial training as defined

• Completes, prioritizes, resolves and/or escalates routine problems and root cause analysis

• Documents and communicates project and service-related problems using appropriate tools and processes with an appropriate level of detail

• Completes most work with guidance and direction

• Performs and may lead tactical work (e.g., daily service work and/or project tasks)

• Develops a working knowledge of applicable security software, tools, processes, procedures and environment

• Review and understand governing regulations, policies, frameworks, executive orders and other materials relevant to the cybersecurity, information assurance, and information technology fields

• Understands the fundamentals of the customer’s business

• Demonstrates ability to interact with customers

For Compliance, work with senior member to develop skillset in the following:

• Review, develop and implement Information Security related policies.

• Perform industry and regulatory program and risk assessments.

• Review requirements for security certifications

• Stay up to date on security issues

• Demonstrates a commitment to acquiring new capabilities on your own.

• Solicits performance feedback from colleagues and reviewers acting on areas for development.

• Supports Company's training initiatives by attending a minimum of 32 advancement hours per year

• Maintains expected levels of personal productivity

• Works well with others

• Adheres to and is an advocate of company core values

• Works as a team

• Promotes teamwork

• Participates in/contributes positively to work/team environment

• Security Awareness development and training

• Social Engineering & Phishing exercises

• Incident Response plan development & testing

• Leading Incident Response teams

• Vendor Security assessments

• Building information security frameworks

• Implementing Information security frameworks

For technical, work with Senior member to develop skillset in the following:

• Public Information Data Mining

• Network Reconnaissance Techniques

• Vulnerability Identification

• System and Application Exploitation

• Software Security Assessments (thick client)

• Wireless Vulnerability Testing

• Vulnerability Assessments

• Database security reviews

• OWASP web application assessments

• Experience with Linux and scripting languages (bash, perl, PHP, etc.)

• Internal & external Penetration testing

• Wireless test

• War-dialing,

• Social-engineering

• Internal, External and application vulnerability assessments

• Perform White-Box and Black-Box Web Application Security

Assessments

• Review application source code and database SQL and stored procedure code for potential vulnerabilities and exploits.

• Product and embedded device assessments.

• Mobile App Assessments

• Identify vulnerabilities as they relate to regulations such as ISO, PCI, HITRUST, and/or HIPAA

KSAs

• Excellent written and oral communications skills

• Knowledge of industry specific regulations governing the cybersecurity landscape in which the consultant is operating, I.e. NIST SP-800-37, FISMA, etc.

• Knowledge of risk management processes (e.g., methods for assessing and mitigating risk)

• Knowledge of national and international laws, regulations, policies, and ethics as they related to cybersecurity

• Critical thinking and analytical skills

• Attention to detail

LEVEL 2 – Professional Services

Years of Experience 3-5

Education Associates or Bachelor’s degree in IT or

Information Security preferred.

Alternatively, HS degree minimum plus 4-6 years’ relevant subject matter experience; or equivalent training/certifications.

Continuing

Education

Instructor led:

• Conferences

• Seminars

• College/university courses

• E-Learning (instructor led)

Self-paced:

• e-Learning (self-paced)

• Videoconferences

• Webcasts

• Audiocasts

• Podcasts

Activities • Attends 2-3 company sponsored webinars/brown bags

• Participates in 2-3 company social events

• Participation in industry association/forums o Chapter Meetings o Local seminars/events/expos

• Contributes at least 1-2:

o Webinar o Brown Bags o White Paper o Blog

• Contributing/supporting company recruiting efforts

Meets certification CPE maintenance requirements

Performance 80-85% utilization Certifications See specific Career Path Business • Understands basic steps in sales process

• Supports practice business development activities

• Demonstrates knowledge of Company products and services metrics Recommended Development

CISSP, CGEIT, CRISC, C|CISO, CISM, CBCP,

GSEC,PCI ISA, GPEN, GWAPT, OSCP, CEH,

GISP, GCHIA, GCIH, Forensics, GCFA, ENCE, CFC, CCFP, PMO, CCSP, HCISPP, or other relevant certifications.

Tasks

• Start to Lead smaller client engagements with customers

• Participate product methodology development

• Ensures quality deliverables

• Provide project management to smaller engagements

• Provide timely deliverables to clients

• Independently provides security support and incident resolution to customers

• Leads tactical work and contributes to strategic work (e.g., creating something new or modifying something currently in existence to meet business or customer needs)

• Assists with developing or modifying operating policies and procedures

• Establishes and maintains business relationships and strategic partnering skills with internal and external contacts

• Review desired security certifications with your manager and agree on how to obtain.

• Stay up to date on security issues

• Demonstrates a commitment to acquiring new capabilities on your own.

• Solicits performance feedback from colleagues and reviewers acting on areas for development.

• Supports Company's training initiatives by attending a minimum of 32 advancement hours per year

• Maintains expected levels of personal productivity

• Works well with others

• Adheres to and is an advocate of company core values

• Works as a team

• Promotes teamwork

• Serves as an advisor to other areas

• Applies understanding of the evolving governance, compliance and regulatory landscape as it pertains to specific security capabilities or technologies to complete assignments

• Understands the fundamentals of the customer’s business

• Demonstrates ability to interact with customers

For Compliance, the obtain the ability to:

• Review, develop and implement Information Security related policies.

• Perform industry and regulatory program and risk assessments.

• Security Awareness development and training

• Social Engineering & Phishing exercises

• Incident Response plan development & testing

• Leading Incident Response teams

• Vendor Security assessments

• Building information security frameworks

• Implementing Information security frameworks

For technical, the obtain ability to achieve:

• Public Information Data Mining

• Network Reconnaissance Techniques

• Vulnerability Identification

• System and Application Exploitation

• Software Security Assessments (thick client)

• Wireless Vulnerability Testing

• Vulnerability Assessments

• Database security reviews

• OWASP web application assessments

• Experience with Linux and scripting languages (bash, perl, PHP, etc.)

• Internal & external Penetration testing

• Wireless test

• War-dialing,

• Social-engineering

• Internal, External and application vulnerability assessments

• Perform White-Box and Black-Box Web Application Security

Assessments

• Review application source code and database SQL and stored procedure code for potential vulnerabilities and exploits.

• Product and embedded device assessments.

• Mobile App Assessments

KSAs • •

• Experience with industry related audits and risk assessments, I.e. Healthcare

• Knowledge of industry specific regulations governing the cybersecurity landscape in which the consultant is operating, I.e. NIST SP-800-37, FISMA, etc.

• Knowledge of risk management processes (e.g., methods for assessing and mitigating risk)

• Knowledge of national and international laws, regulations, policies, and ethics as they related to cybersecurity

• Applying hands on technical skills in vulnerability analysis, network security, or incident response

• Constructing and delivering written and verbal communications to all levels of the organization with clarity, to technical and non-technical people, to communicate status, open risks, and drive resolution and remediation of IT risks in a timely manner.

• Investigating risk and compliance issues and developing corrective actions and preventive measures.

• Knowledge of Industry Best-Practices (network and system architecture and configuration)

• Excellent written and oral communications skills

• Critical thinking and analytical skills

LEVEL 3 – Professional Services

Years of Experience 5-7

Education Associates or Bachelor’s degree in IT or

Information Security preferred.

Alternatively, HS degree minimum plus 6-10 equivalent training/certifications.

Continuing

Education

Instructor led:

• Conferences

• Seminars

• College/university courses

• E-Learning (instructor led)

Self-paced:

• e-Learning (self-paced)

• Videoconferences

• Webcasts

• Audiocasts

• Podcasts

Activities • Attends 2-3 company sponsored webinars/brown bags

• Participates in 2-3 company social events

• Participation in industry association/forums o Chapter Meetings o Local seminars/events/expos

• Contributes at least 1-2:

o Webinar o Brown Bags o White Paper o Blog

• Contributing/supporting company recruiting efforts

Meets certification CPE maintenance requirements

Performance 75-80% billing utilization Certifications See specific Career Path Business • Contributes to development of new work for an existing or new customer

• Supported proposal preparation for a new engagement metrics Recommended Development

CISSP, CGEIT, CRISC, C|CISO, CISM, CBCP,

GSEC,PCI ISA, GPEN, GWAPT, OSCP, CEH,

GISP, GCHIA, GCIH, Forensics, GCFA, ENCE, CFC, CCFP, PMO, CCSP, HCISPP, or other relevant certifications.

Tasks

• Lead client engagements with customers

• Understands the fundamentals of the customer’s business

• Demonstrates ability to interact with customers

• Participate product methodology development

• Ensures quality deliverables

• Mentors teams

• Provide project management to engagements

• Provide timely deliverables to clients

• Demonstrates sound judgement in making decisions with respect to matters of moderate to high complexity and importance

• Assists in budgeting and project planning

• Participates in and/or leads technology/capability reviews, evaluations, demonstrations, proofs of concept and implementations

• Applies broad-based knowledge of security technologies with an in-depth /specialized knowledge of at least one security tool to perform daily tasks.

• Conducts architecture reviews to ensure security issues are appropriately addressed

• Maintains security certifications

• Stay up-to-date on security issues

• Penetration testing certifications (such as GPEN or CEH) are a plus.

• CISSP certification a plus.

• Demonstrates a commitment to acquiring new capabilities on your own.

• Solicits performance feedback from colleagues and reviewers acting on areas for development.

• Supports Company's training initiatives by attending a minimum of 32 advancement hours per year.

• Maintains expected levels of personal productivity

• Works well with others

• Adheres to and is an advocate of company core values

• Works as a team

• Promotes teamwork

• Coordinates security related delivery activities and manages routine customer engagements

• Keeps abreast cybersecurity industry trends and best practices to modify processes to meet changing needs and influence the direction of solutions

• Mentors and trains Security Analysts and others

• May lead some strategic work and/or contributes to strategic work (e.g., cross departmental or enterprise initiatives)

For Compliance, the ability to:

• Review, develop and implement Information Security related policies.

• Perform industry and regulatory program and risk assessments.

• Security Awareness development and training

• Social Engineering & Phishing exercises

• Incident Response plan development & testing

• Leading Incident Response teams

• Vendor Security assessments

•…

This is the start of the file's text. The full file is on GovTribe.

File details come from the government source that posted it. Updated .