841913833_DAR_Sole_Source_JA_3_Sep_2019_REDACTED_2.pdf

PDF 200 KB Posted

Attached to
Data-At-Rest (DAR) Email Solution Federal contract opportunity
Solicitation number
HC108419R0021
Issued by
Defense Information Systems Agency

About this file

DAR Sole Source Justification & Approval (REDACTED)

View the file

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

Page 1 of 8 Pages

JUSTIFICATION FOR OTHER THAN FULL AND

OPEN COMPETITION (OTFAOC)

Federal Acquisition Regulation (FAR) Part 6 Justification & Approval (J&A), Supporting Procurements under FAR Part 12, and FAR Part 15

Purchase Request Number: 841913833 Contract Number: To Be Determined (TBD) Procurement Title: Department of Defense (DoD) Mobility Classified Capability – Secret (DMCC-S) Data-at-Rest (DAR) Solution Estimated Value:

Statutory Authority: 10 U.S.C. 2304(c)(1) and FAR 6.302-1

JUSTIFICATION FOR OTHER THAN FULL AND OPEN COMPETITION (OTFAOC)

Justification for OTFAOC Number: Not Applicable (N/A)

Upon the basis of the following justification, I, as the Contracting Officer, hereby approve the use of other than full and open competition of the proposed contractual action pursuant to the authority of 10 U.S.C. 2304(c)(1) and (FAR) 6.302-1, only one responsible source and no other supplies or services will satisfy agency requirements.

1. REQUIRING AGENCY AND CONTRACTING OFFICE:

Requiring Agency:

Defense Information Systems Agency (DISA) Mobility Portfolio Management Office (PMO)/Cyber Directorate (ID1) 6906 Cooper Avenue Ft Meade, Maryland 20755

Contracting Office:

Defense Information Technology Contracting Organization

(DITCO)/PL8414

2300 East Drive Scott Air Force Base, Illinois 62225

2. NATURE/DESCRIPTION OF ACTION(S):

The nature of this requirement is to procure a secure Transport Layer Security (TLS) Exchange ActiveSync email capability with DAR to meet DMCC-S capability enhancements in support of the DoD’s DMCC-S offering for wireless devices and services. The DAR solution will be met by using an Android data file encryption protection that is National Security Agency (NSA) National Information Assurance Partnership (NIAP) approved and listed on the Commercial Solutions for Classified (CSfC) Components List. Certification will require validation against the Application Software Protection Profile (PP), Email Client PP, the Functional Package for TLS and any additional selections set by the CSfC components list. The email client is also supported by a secure file editor that supports Microsoft Exchange ActiveSync protocol. The

Page 2 of 8 Pages email client allows the user the ability for viewing, creating, editing and storing documents securely on a DMCC-S device within the protected DAR email client file encryption container.

The recommendation is to execute a new firm fixed price (FFP) sole-source contract to Cyber Reliant Corp, doing business as Trivalent, utilizing open market procedures. The period of performance will consist of a one-year base period, and one, 6-month option period, estimated to begin on September 23, 2019. The total contract value for this requirement is estimated at

. The contract base year will be fully funded at the time of award, utilizing Fiscal Year 2019 Operations and Maintenance funds.

Period Period of Performance Estimated Price Base Year September 23, 2019 – September 22, 2020 Option Period 1 September 23, 2020 – March 22, 2021 Total

3. DESCRIPTION OF SUPPLIES/SERVICES:

(a) The DISA ID Mobility PMO has the requirement to procure security enhancements to enable a DAR email exchange client on the DMCC-S devices offering, while maintaining CSfC compliance. This sole source justification is for the acquisition of a DMCC-S DAR email with a secure file editor capability enhancement.

The Mobility PMO currently delivers its customers the DMCC-S capability that provides access to specific SIPRNet based Enterprise Services. However, the DMCC-S program provides secure calling and web mail with no DAR capabilities. This DMCC-S non- DAR email capability is a web-based version that has limited mobile screen viewing capability, minimal user features and file attachment view only.

The program is now seeking technologies to expand the DMCC-S offering to include DAR with a NIAP and CSfC certified solution that can be provided to the classified user community. The solution is required to be listed as an application(s) on the CSfC components list and compliant with the CSfC DAR Capability Package (DARCP) and TLS Application Selection. The application(s) is required to be CSfC Certified, or be in the process of receiving CSfC certification, integrate with Android OS 6 and higher, pass the Mobility PMO application vetting process, and be approved by the DISA Authorizing Official (AO).

The contractor will be responsible for providing the data rights/product line for the DAR application(s). The contractor will either modify a commercially available application(s) or develop a Government Off-The-Shelf (GOTS) application(s) to meet the specifications required for use by the CSfC DARCP and the CSfC TLS Application Selection. The contractor will be required to deliver 50 licenses upon completion of the first iteration of the application(s), with the option to procure additional licenses for additional testing and/or deployment.

Page 3 of 8 Pages

(b) The table below outlines the quantities and services associated with this requirement over the lifecycle of this contract:

DMCC-S DAR Solution Base Year Option Period 1

Description Quantity Quantity

NIAP Testing for CSfC for Android version 8 for secure email client 1 Each

NIAP Testing for CSfC for Android version 8 for secure file editor 1 Each Labor for NIAP CSfC Certification updates, administration, coordination. hours Labor Secure email Application DoD compliant classification marking hours NIAP testing, updates, and coordination for CSfC for Android for secure email client (labor) hours

NIAP testing, updates, and coordination for CSfC for Android for secure file editor (labor) hours

Option: Polaris License for File Editor Unlimited Unlimited

Option: Trivalent Protect Cryptographic Development Kit with email application- TP-CDK-Dev-E

50 50

Option: Trivalent Protect Cryptographic Development Kit with file viewer- TCM- CDK-Dev- F

50 50

Option: Trivalent Configuration Manager (TCM)- TCM-P 1 Each

4. IDENTIFICATION OF STATUTORY AUTHORITY:

Only one responsible source and no other supplies or services will satisfy agency requirements, 10 U.S.C.2304(c)(6), and the regulatory authority of FAR 6.302-1/DFARS 206.302-1.

5. DEMONSTRATION OF CONTRACTOR’S UNIQUE QUALIFICATIONS:

Due to the classified nature of DMCC-S, the technical requirements drive the certified profile and necessary security features. The DAR application(s) must be NIAP certified against the Software Protection Profile, DARCP and the CSfC TLS Application Selection. In addition, the application(s) must possess the ability to function after all lockdown features and settings similar to what is feasible in using Security Enhanced (SE)-Android security settings. Using any other non-NIAP certified application(s) would require a significant investment of both time and funding in meeting the DARCP as well as getting NIAP certified with the appropriate CSfC DAR and TLS Application Selections. The Trivalent suite of applications is currently the only NIAP approved suite of applications that can meet the security requirements and technical capabilities, while maintaining the current infrastructure.

Page 4 of 8 Pages

(a) Description of events.

(1) In the beginning of 2019, the DMCC-S PMO piloted a DAR program utilizing

Windows 10 (Win 10) tablets, which provides a DAR-enabled mobile device, specifically a Microsoft Surface book, into the hands of designated senior leaders across the department. The future of the Win 10 piloted device has yet to be decided, but it was able to prove that a DAR capability is necessary to provide the War-Fighter a much-required capability. The DAR device will run the mobile operating system (OS) Android 6 & 7 initially, which incorporates all current security enhancements, providing upgraded security layers to the mobile OS image. The DAR enhancement is expected to operate on later Android mobile OS versions as DMCC-S mobile devices are upgraded. Additionally, the DMCC-S program requires a current CSfC DAR Capability Package (DARCP) suite of applications.

The DISA PMO has the requirement to procure a NIAP CSfC certified DAR solution for the DMCC Program offering that will replace the current Outlook Web Access (OWA) implementation in place today. The DAR solution will require classified configurations to efficiently manage and maintain the current and approved DoD Information Network configuration. The vendor must also maintain certification in accordance with the Commercial Solutions for Classified (CSfC) Mobile Access Capability Package. This justification for OTFAOC will ensure the Mobility PMO can provide DAR and secure TLS communication on the DMCC devices.

(b) Justification.

(1) Minimum Government requirements.

a) The DAR encrypted email application must be a full featured mobile application that supports Android 6.0 and 7.0 on the DMCC-S Samsung Galaxy S7 Custom Read-Only Memory (CROM) and Samsung Galaxy Tablet S3 CROM devices respectively.

b) The email application must be integrated with an NSA NIAP approved and CSfC Components Listed method of DAR file encryption. The DAR file encryption protects the email application file contents stored on the device.

c) The application, as required by the CSfC Mobile Access Capability Package (MACP) for providing the inner encrypted tunnel, will use NIAP certified TLS 1.2 per the CSfC TLS Application Selection in association with National Security Systems (NSS) Public Key Infrastructure (PKI) Secret Internet Protocol Router Network (SIPRNet) X-509v3 user certificates to securely connect and authenticate respectively to DoD Enterprise Email- Secret (DEE-S).

d) The fully integrated NIAP/CSfC DAR file encryption TLS email application can be an available Commercial off-the-Shelf (COTS) product, a modified COTS product, or an already completed/modified NIAP/CSfC DAR file encryption and TLS integrated customized Android Open Source Project email application. The intent is to require none to minimal application coding to meet the stated requirements.

Page 5 of 8 Pages

e) The integrated encryption email application shall provide an Exchange ActiveSync (EAS) interface that supports the required Application Programming Interfaces (APIs) and processes.

f) The email client is supported by a secure file viewer that supports Microsoft Exchange ActiveSync protocol and allows the user the ability for viewing, creating, editing and storing documents securely on a DMCC-S device within the protected DAR email client file encryption container.

g) The email client solution shall provide an automated classification marker when composing emails that is user selectable (e.g. SECRET, SECRET/NOFORN, etc.). Namely the user does not have to type into the email header & footer the desired classification marker, just select it when composing an email.

h) The application(s) must meet NIAP, CSfC DARCP and TLS Application requirements, used to enhance security, emphasizing the protection level of the device and tablet.

i) The application(s) must be compatible with SE Linux (SELinux)/Android and interact with the Android OS at the lowest level.

j) The application(s) must be compatible with devices and tablets on the CSfC components list, as well as the Mobile Iron Mobile Device Management (MDM), Samsung Knox server and Samsung Enterprise Mobility Management (EMM) server.

(2) Proposed sole source contractor. Trivalent meets all of the Government’s unique requirements. Trivalent’s product, Trivalent Protect for Android, is on the CSfC Components List for File Encryption and the NIAP Compliant Product List.

Trivalent has developed application(s) that are compatible with the DMCC-S devices and infrastructure that also meet the stringent security requirements.

(3) Discussion regarding cause of the sole source situation. The classified communication industry requires complex security policies such as CSfC certification and validation by NIAP for DAR and TLS. In addition to the limited offerings, the DMCC application(s) must be compatible with SELinux/Android OS, Mobile Iron MDM, Samsung Knox server and Samsung EMM server, creating a unique situation within the classified communications industry. Only Trivalent has met all of the security requirement and are compatible with all of the DMCC devices and infrastructure, including SELinux/Android OS, Mobile Iron MDM, Samsung Knox server and Samsung EMM server.

(4) Impact. Without execution of the plan indicated in this justification for OTFAOC, end users of the DMCC service will continue to be severely limited and restricted in their classified mobile communications that are necessary to complete mission objectives. Failure to provide the required DAR application(s) will hinder DISA’s ability to offer a classified mobile capability in support of operations for joint warfighters, national leaders, and coalition partners in sharing editable documents comparable to what is already a daily occurrence on SIPRNet. These application(s)

Page 6 of 8 Pages are critical to the usability of classified communication at the highest levels of the DoD, as well as in strategic field locations, globally.

6. FEDBIZOPPS ANNOUNCEMENT/POTENTIAL SOURCES:

The Government intends to synopsize this contract action in accordance with FAR Part 5 procedures and attach the justification for OTFAOC. The Government will also request and encourage other manufacturers, as well as offerors, to submit solutions that meet the Government’s baseline requirements for use on the DMCC Program. The Government will continue to conduct market research and review responses from potential sources to promote competition.

7. DETERMINATION OF FAIR AND REASONABLE COST:

The Contracting Officer will determine whether Trivalent’s proposed price is fair and reasonable before award. Other than certified cost and pricing data will be requested from the contractor with their price submission. Evaluation of the supporting price documentation will be analyzed.

Additionally, contractor-proposed pricing will be compared to an Independent Government Cost Estimate (IGCE) and other contracts for similar products, as well as previous procurements for this item. Based on this analysis, the Contracting Officer will determine whether the proposed price is fair and reasonable.

8. MARKET RESEARCH:

The Government posted a Sources Sought (Tracking Number: 841913833) on the Federal Business Opportunities (FBO) website on April 15, 2019, requesting responses from HUBZone, small and large businesses to gather information on any DAR encrypted email applications that would meet the Government’s security requirements. The Government received six responses, all of which were from small businesses. A team of product leads reviewed the responses.

The responses were evaluated against the required capabilities listed in section 5 (b) above. The results of the Sources Sought are detailed below:

Professional Stewards Services (PSS) provided a solution that combined two products consisting of the Blackberry Unified Endpoint Management (UEM) that is “integrated with an NSA NIAP approved method of encrypting and protecting the contents stored on the device.” In this case, it would be the KeyW BlackBerry Suite B DAR solution from the CSfC Components List. However, this approach would not be feasible, technically and operationally to provide a DAR email capability for the current CSfC End User Devices (EUDs). Currently Blackberry Enterprise Server (BES) 12.5 is NIAP approved and listed on the CSfC Components List but not the Blackberry UEM, which would be required on the EUD. Additionally, MobileIron is the current MDM deployed on DMCC-S devices, which would conflict with deploying the Blackberry UEM MDM Agent on the same mobile device. KeyW BlackBerry Suite B Data at Rest can only be deployed on mobile devices that utilize the Blackberry 10.3 operating system, which is not the current DMCC-S EUD operating system, which is Android. Therefore, the Blackberry Suite B DAR solution is not compatible with the current DMCC-S

Page 7 of 8 Pages configurations let alone mobile device operating system. PSS does not meet the capability areas identified in the Sources Sought.

Stryke Industries, LLC provided SDITDARPM for their encryption solution; however, this product is not listed on the NIAP Compliant Product List or the CSfC Components List for File Encryption. Additionally, the SDITDARPM product does not meet any of the capability areas identified in the Sources Sought.

Trivalent provided a DAR encrypted email solution, Trivalent Protect for Android.

Trivalent Protect for Android is on the CSfC Components List for File Encryption and NIAP Compliant Product List. Additionally, Trivalent’s solution meets all of the capability areas from the Sources Sought announcement. No other file encryption product is available for Android on the Samsung Galaxy S7 and Tab S3, the currently deployed DMCC-S devices. The solution meets all of the requirements.

Aerial Optic, LLC, CyTech, LLC, and Secured IT Solutions, LLC provided generic company capability statements and did not address any of the requirements in the Sources Sought.

Based on the market research, it has been determined that only Trivalent can fully support the Government’s need.

9. ANY OTHER SUPPORTING FACTS

None

10. LISTING OF INTERESTED SOURCES:

PSS

Stryke Industries, LLC Trivalent Aerial Optic, LLC CyTech, LLC Secured IT Solutions, LLC

11. ACTIONS THE AGENCY MAY TAKE TO REMOVE OR OVERCOME BARRIERS

THAT LED TO THE EXCEPTION TO FULL AND OPEN COMPETITION:

At this time, it is deemed only Trivalent’s DAR solution will meet the Government’s requirement. DISA will continue to assess other solutions capable of performing the level of services as this contract progresses. Prior to exercising any option periods, additional market research will be completed to ensure this strategy is still accurate.

12. REFERENCE TO THE APPROVED ACQUISITION PLAN (AP):

In accordance with exceptions under DISA Acquisition Regulations supplement 7.103 (S- 91)(1)(i), an AP is not required.

Page 8 of 8 Pages

TECHNICAL CERTIFICATION: I certify that the supporting data under my cognizance, which are included in the J&A, are accurate and complete to the best of my knowledge and belief.

NAME: Ethan Miller SIGNATURE:

TITLE/ORGANIZATION: Project Lead/ID1

PHONE:

REQUIREMENTS CERTIFICATION: I certify that the supporting data under my cognizance, which are included in the J&A, are accurate and complete to the best of my knowledge and belief.

NAME: Zach Salva SIGNATURE:

TITLE/ORGANIZATION: DMCC-S Project Management

CONTRACTING OFFICER CERTIFICATION: I certify that this justification is accurate and complete to the best of my knowledge and belief.

NAME: Angela K. Zang SIGNATURE:

TITLE/ORGANIZATION: Contracting Officer/DISA DITCO PL8414

ALL QUESTIONS REGARDING THIS JUSTIFICATION ARE TO BE REFERRED TO

Amanda Erlinger, Contract Specialist,

File details come from the government source that posted it.