JAR.pdf

PDF 78 KB Posted

Attached to
Sensage Software Federal contract opportunity
Solicitation number
HC1028-11-T-0340
Issued by
Defense Information Systems Agency

View the file

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

Enclosure 12a, J&A (Part 6) Page 1 of 8 Pages

8Oct2010/Version 1.4

Purchase Request Numbers: DIAMZ12230, DIAMZ12075

JUSTIFICATION FOR OTHER THAN FULL AND OPEN COMPETITION

Justification for OTFAOC Number: JA11-108

Upon the basis of the following justification, I, as Procuring Activity Competition Advocate, hereby approve the use of other than full and open competition of the proposed contractual action pursuant to the authority of 10 U.S.C. § 2304(c)(1), and regulatory authority of FAR Subpart 6.302-1(c), only one responsible source and no other supplies or services will satisfy agency requirements under the authority for brand name.

JUSTIFICATION

1. Agency and Contracting Activity:

a) Requiring Activity:

Defense Information Systems Agency (DISA)

Program Executive Office –Mission Assurance (PEO-MA) IA33

6910 Cooper Ave

Ft. Meade MD 20755

b) Contracting Activity:

DISA/Defense Information Technology Contracting (DITCO) PL8321

2300 East Drive

Scott AFB, IL 62225-5406

2. Nature/Description of Action(s):

a. This justification and approval (J&A) is to procure Brand Name SenSage Log Aggregation

Software which includes the Scalable Log Server (SLS) Database, Data Collectors, Interfaces and

Installation/Configuration. DISA is establishing a Long Term Data Analysis & Storage capability at the

Community Data Center (CDC). DISA will conduct a data analysis and long term storage pilot at the

CDC by installing the SenSage product and putting data logs through SenSage in order to fully evaluate the performance of the SenSage Log Aggregation tool in the CDC environment. DISA will perform stress testing on the system as well as have a defined set of test users during the pilot period. SenSage will be installed in a test configuration which we estimate to be representative of one-tenth of the final configuration. The testing of this test configuration will help us determine how large the final configuration would need to be to handle 100% of the data logs.

b. This contract will be awarded as a Firm Fixed Price (FFP) contract to SenSage, Inc., a small business and the original equipment manufacturer (OEM). This will be purchased as an Open Market purchase order as the OEM confirmed they are the only reseller and that the maintenance is not found on any contract vehicle. The applicable North American Industry Classification System (NAICS) code is

511210. The Period of Performance is for one year estimated to begin on 23 August 2011 through 22

August 2012.

Page 2 of 8 Pages

3. Description of Supplies/Services:

a. This requirement is for a Log Aggregation capability for the CDC at the Warner Robbins DISA facility. This Log Aggregation capability will aggregate the system logs from various DISA deployed security devices such as web filters, sensors, proxy servers, etc. Specifically the SenSage tool will provide the specific capabilities listed below:

i. Provide the data compression to allow for long term storage in order to decrease to amount of storage required. It will allow DISA to utilize standard capacity on demand storage devices in order to provide the long term data retention.

ii. Allow for long term trending of security device system logs. This will allow DISA to examine log traffic over time to uncover additional security threats.

iii. Store and allow for querying across all security data logs in order to support forensic investigation.

b. The following table provides the product descriptions, required quantities and Government

Independent Government Cost Estimate (IGCE) for this procurement:

4. Identification of Statutory Authority:

Only one responsible source and no other supplies or services will satisfy agency requirements under the authority of 10 U.S.C. § 2304(c)(1), and regulatory authority of FAR Subpart 6.302-1(c), only one responsible source and no other supplies or services will satisfy agency requirements under the authority for brand name.

5. Demonstration of Contractor’s Unique Qualifications:

a. The software licensing, maintenance and purchase of the additional brand name proprietary software products are only available from SenSage and no other type of software will satisfy the

Agency requirements. SenSage owns all proprietary rights to the source code and have no authorized resellers of this product, per SenSage letter dated 18 May 2011. No other vendor or distributor/reseller can legally obtain access to the software and no other vendor can make duplicate copies since copyright and patent laws protect it. The software acquired and maintained through this purchase will support all equipment augmentations and all government owned software processing environments. The proposed acquisition is for an expansion of the SenSage software which is already deployed.

b. DISA has deployed the SenSage product in its infrastructure and the integration took approximately one and a half years to complete. It would not be feasible or cost effective at this point to start over with a new tool. An extensive amount of technical expertise has been developed at the computing centers based on the existing infrastructure. Continued use of the SenSage software is required to maintain the current productivity and efficiency levels of the DISA data centers.

i. Utilizing the same log aggregation tool for both the DECC and CDC will allow for seamless integration between the two sites as we wouldn’t need to purchase an additional tool to integrate the two products. Analysts who commonly will query both data bases will not need to be trained on two different databases, have two

Page 3 of 8 Pages different consoles at their workstations and will be able to correlate the data between the two databases.

ii. The SenSage tool provides a very flexible interface and will provide alerts up to the real time alerting tool which DISA has already implemented (ArcSight). This will allow us to take full advantage of not only our new SenSage tool but also the existing ArcSight infrastructure that DISA already has in place.

iii. The SenSage tool has already been awarded an Initial Authority To Operate (IATO) and is currently completing its Authority To Operate (ATO). This will eliminate approximately five months worth of Certification and Accreditation activities. If another product were selected, then these certification and accreditation activities would need to be repeated. A five month delay in providing the analysts with the information that they require to do their analysis would leave the network unprotected.

c. In addition, SenSage is the only solution that can fulfill this requirement without substantial duplication of cost to the Government that is not expected to be recovered through competition.

Significant costs expended on program delays, technical reviews, business cases, functional replacements of installed inventory, training and implementations of new products would far outweigh any benefit gained even if another competitive choice was readily available.

d. DISA has determined that the SenSage software is the only product on the market that could meet its operational need. If this J&A is not approved and DISA went forward with an acquisition that they fully believe SenSage would successfully win, it would result in approximately a nine month impact to the schedule. Currently the operational analysts are constricted to real time alerts produced by the Arcsight tool but have no ability to query over time which is a real operational impact.

6. FedBizOpps Announcement/Potential Sources:

a. IAW FAR 5.201, DITCO will post the intention to award a sole source contract to SenSage on the FedBizOpps website. The following statement will be included in the posting: all responsible sources may submit a capability statement, proposal, or quotation, which shall be considered by the agency.

b. DISA does not anticipate any other qualified sources; however, should any responses be received, they will be evaluated to determine if they are fully responsive to the Government's stated minimum requirements and will be considered by DISA prior to proceeding with an award. This proposed procurement is the only known approach to license and maintain the proprietary software.

7. Determination of Fair and Reasonable Cost:

Determination of fair and reasonable cost for this particular requirement will be based on fair market value, Independent Government Cost Estimate (IGCE), and comparison to commercial price lists. The

Contracting Officer will determine the ultimate price fair and reasonableness.

8. Market Research:

Page 4 of 8 Pages

a. Market Research was conducted in April 2011, as follow up to the research previously performed. In 2009 the research led the customer to the conclusion that SenSage could provide a log management solution that would meet Security Technical Implementation Guide (STIG) requirements.

The requirement was issued on NASA SEWP for brand name or equal. After technical evaluation of the lowest quoted product, LogLogic 4, a determination was made the software did not meet the

Government requirements. The SenSage solution, offered by Alvarez and Associates, was the next lowest quote and was found to be technically acceptable. One additional quote was received for the

Sensage solution, however it was a higher price. Sensage has confirmed that this particular SenSage software product bundles proposed for the DISA, CDC Pilot Program are not currently available from any SenSage Resellers, and SenSage only offers this software product via the open market.

b. To further the research and identify what products are available in the market, DISA PEO-MA contracted with Gartner Research.

c. The market research looked at twenty-three products to include those such as: ArcSight, CA

Audit, Cisco MARS, IBM, Log Logic, NetIQ, Novell, SenSage, RSA and Symantec. This market research was initially completed in 2009 in support of the initial acquisition and was repeated in 2011 to verify any market changes. DISA has utilized additional Gartner Research in order to ensure that the

Market Research was still relevant and accurate.

d. Gartner released updated Market Research on 12 May 2011 which included the following characterizations unique to the SenSage product in comparison to other products in the market place:

i. The SenSage solution is optimized for precision analytics and compliance reporting for a large event data store, and the company has successfully pursued large deployments that require this capability.

ii. SenSage is optimized for organizations that require high-volume event collection, monitoring, analytics and reporting for large amounts of log data over long periods for audit, compliance and internal investigations.

iii. SenSage is a good fit for use cases that require compliance reporting or security analytics for a large event store with basic real-time monitoring requirements.

iv. None of the other sources reviewed had the above unique specialized characteristic of SenSage.

e. DISA also completed a one on one conference call with Gartner to further understand the results of the Gartner Market Survey and verify that SenSage was indeed the only vendor to meet our requirements. Gartner reiterated that only SenSage could handle the number of logs that we were going to be storing and querying.

f. The twenty- three products, identified in 8c of this document, were specifically examined during market research:

i. Prism Mircosystems is not a viable option because it is a Windows OS based system and focused on Windows platform analysis. Network and Web Content analysis does not fit their schemas and the audit volumes generated by the DISA network and its associated web audit logs are significantly larger and not part of the Windows OS logs so therefore would overload their system.

Page 5 of 8 Pages

ii. elQnetworks is a Security Incident and Event Manager (SIEM) solution that is an add on to their product suite that focuses on vulnerability monitoring and management. DISA’s required solution does not focus on vulnerability and monitoring. elQnetworks does not offer the collection, storage and analysis of large volumes of audit data.

iii. Tenable is not a viable option because it is focused on vulnerability assessment and analysis. Their solution has not been designed to scale to the petabyte levels that DISA will be working with.

iv. Q1Labs is an appliance that cannot be deployed to accommodate the data volumes of 2.3 PB every 90 days. Q1 Labs products for SIEM and Log

Management work separately and the Log Management produce is an add-on that is only a couple of years old and has limited production experience.

v. The LogMatrix NerveCenter product is not a viable solution as it is designed for transactional processing logs for retail and telecommunications companies.

NerveCenter is installed in a Windows domain and can monitor Windows applications. DISAs implementation will not be on Windows and must monitor logs from a significant number of boxes that are not Windows based.

vi. ArcSight is already part of the infrastructure in a complementary role and does not provide the capabilities we require for this log management solution.

vii. LogLogic was evaluated during the previous competitive purchase and was found to not meet the technical requirements.

viii. Splunk is gradually expanding its support for SIEM use cases. Splunk is not a viable solution because it does not process real-time monitoring.

ix. Cisco is not a viable solution due to its decision to freeze support for most of the non-Cisco event sources that have been supported by MARS.

x. CA is not a viable solution because its Enterprise Log Manager's network device support and security device support are extremely limited. Enterprise

Log Manager currently lacks incident management support and DISA requires external threat monitoring or System Event Monitoring capabilities beyond user activity monitoring which is not supported by CA.

xi. IBM is not a viable solution because although it provides basic integration between its two complementary solutions, organizations that need real-time event monitoring of host log events still need to deploy two technologies and

System Event Monitor capabilities are not best in class.

xii. LogRhythm has not supported large enterprise deployments and is an offering primarily to midsize businesses. The SIEM is composed of appliances that can be deployed in smaller environments.

xiii. NetForensics is not a viable solution as it needs to expand support for user activity monitoring beyond standard user activity reports to include predefined, user-oriented views or correlation rules.

xiv. NetIQ is not a viable solution because while it can be successfully used in event management for network and security devices, but it is not optimized for deployments that are primarily focused on this use case.

xv. EventTracker is not a viable solution as its capabilities are limited in specific areas that are more typical in larger enterprises' deployments. There is a lack of integration with enterprise configuration management database products and

Page 6 of 8 Pages

Information Assurance Management (IAM) products, and limited capabilities to monitor application-level activity.

xvi. NitroSecurity is not a viable solution because it is composed of numerous individual and independent components. NitroView Enterprise Security

Manager provides the primary interface for SIEM functions. NitroView ELM provides log management. NitroView DBM provides database monitoring and policy enforcement. NitroView ADM provides application data inspection and monitoring. NitroView Receiver is an event log collector. This is very similar to the ArcSight solution and does not provide the complementary long term, high volume storage DISA is needing.

xvii. Novell is not a viable solution because while Novell’s Sentinel provides user and resource access monitoring reports that are ultimately adapted to compliance reporting. DISA’s requirements expand beyond the compliance realm.

xviii. Trustwave is not a viable solution because it provides a managed service rather than a deployable solution.

xix. Quest Software is not a viable solution as its support for network devices and network-based security technologies is very limited, and the product lacks integration with vulnerability assessment and endpoint protection data sources.

The technology is unsuitable for external threat monitoring or SIEM use cases that require more than the most basic support for network and security event sources. Organizations that require robust, real-time event management and a full-function security console for a security operations center should consider solutions that provide more function or flexibility to meet those requirements.

xx. RSA is not a viable solution because of its distributed appliance deployment versus a central consolidated solution.

xxi. Symantec is not a viable solution because it is not a good fit for implementations that require integration with specific IAM technologies beyond the narrow set of directory and network authentication technologies that is currently supported.

xxii. Tri Geo is not a viable solution because it lacks large-scale data collection and aggregation. It does not perform well where deployment requirements include extensive customization and integration with other IT management technologies.

g. The market research completed by both the Government and private sector supports that the

SenSage solution is the only solution that can meet the Government existing requirements and is recommended for this acquisition efforts. A technical review was conducted for all of the above items and they were found technically unacceptable.

h. The Government has determined that this can be met by a Small Business.

9. Any Other Supporting Facts:

a. DISA has purchased and currently has both Cisco MARS and ArcSight, deployed in the DISA infrastructure. DISA has determined that these products serve a complementary role to the SenSage tool. DISA is utilizing Cisco MARS as the aggregator of the Cisco appliances in the infrastructure. The

Page 7 of 8 Pages

Cisco MARS product then provides the logs up to the central aggregator capability which aggregates the

Cisco logs with the other products logs. Currently DISA has decided not to move forward with the

Cisco MARS product due to the high number of false positives which is unacceptable in the operational environment.

b. DISA is utilizing the ArcSight product in the CDC to provide the real time alerting capability.

ArcSight was originally purchased to provide both the real time alerting capability as well as the long term trending and storage capability. Over the past two years DISA has examined the ArcSight product to determine if it could be used to also provide this long term storage and log aggregation solution and has determined that it does not meet DISA’s requirements and the tool’s performance is greatly degraded when extending the use beyond its purpose. The ArcSight product quickly became overwhelmed by not only the quantity of data but also the rate of ingest of the data. DISA is currently working to take the operational data out of the ArcSight tool and plans on utilizing the SenSage tool to store the operational data as the ArcSight will not fulfill the Log Aggregation requirements.

c. SenSage is already deployed in the NIPRNet infrastructure and offers integration with the existing ArcSight solution. ArcSight has previously expressed interest in providing this capability to

DISA. DISA has already purchased and implemented the ArcSight capability at the CDC in the real time alerting capacity and has determined it does not fill the Log Aggregation requirements. DISA has worked with ArcSight to try to use the tool to fulfill the requirements multiple times and has determined that the tool cannot technically meet the requirements.

d. There are no other tools currently available that will meet DISA’s requirements. SenSage is already implemented and to replace it with the new system the Government would have to remove the already deployed software. Additional costs would be incurred by the Government in order to even consider a new tool.

10. Listing of Interested Sources:

To date, SenSage is the only interested source in this procurement. However, any responses to the

FedBizOpps announcement will be considered by DISA prior to proceeding with an award.

11. Actions Taken to Remove Barriers to Competition:

a. While the previous contracts were competed via the NASA SEWP contract vehicle, the solution being proposed for the expansion into the CDC is not available on any existing contract vehicle as it is customized for the CDC requirements. The CDC implementation of the SenSage product includes a custom interface that allows for the quierying across multiple clusters. This capability is not available in any of the versions on the NASA SEWP contract and is a custom solution for DISA.

b. SenSage has proprietary data rights that effectively preclude competing annual maintenance for this product. DISA is constantly surveying the market for alternatives to replace SenSage software for customer applications when economically feasible.

c. Future requirements can be developed to integrate with any functional equivalent rather than requiring only one specific product. However, future requirements take years to develop and are operational for many years after implementation and therefore this barrier removal is not immediate.

Page 8 of 8 Pages

d. Program Developers are looking for ways to mitigate the use of existing proprietary code to remove barriers to competition. While circumstances do not currently permit full and open competition for this acquisition, the Government will continue to look for ways to use products that are available from multiple vendors.

12. Reference to the Approved Acquisition Plan (AP)/Program Plan (PP):

An acquisition plan is not required for this procurement.

File details come from the government source that posted it. Updated .