FINAL_RFP_Attachment_3_Task_Order_PWS.pdf
PDF 144 KB Posted
- Attached to
- DDS Crowdsourced Vulnerability Discovery & Disclosure Services (CVDD) FA2 Federal contract opportunity
- Solicitation number
- HQ003418R0202
- Issued by
- DOD Washington Headquarters Service
About this file
RFP Attachment 3_Task Order PWS
View the file
Other files for this federal contract opportunity
| File | Type | Posted |
|---|---|---|
| RFP_Attachment_7_DD254_Revised_copy_(2).pdf | ||
| RFP_Attachment_7_DD254_Revised.pdf | ||
| RFP_Amendment_Attachment_5_CLINs_IDIQ_Provisions_and_Clauses.pdf | ||
| RFP_Amendment_0001_Attachment_2_IDIQ_PWS_080218.pdf | ||
| RFP_Amendment_0001_Attachment_1_HQ0034-18-R-0202_080218.pdf | ||
| RFP_Amendment_0001__Attachment_8___Questions_FINAL_080118_(002).pdf | ||
| RFP_Amendment_0001_Attachment_4_Task_Order_Pricing_Template_v2.xlsx | XLSX spreadsheet | |
| RFP__Amendment_0001_Attachment_3_Task_Order_PWS_080218.pdf | ||
| FINAL_RFP_Attachment_7_DD254.pdf | ||
| FINAL_RFP_Attachment_6_Task_Order_Provisions_and_Clauses.pdf | ||
| RFP_Attachment_4_Task_Order_Pricing_Template.xlsx | XLSX spreadsheet | |
| FINAL_RFP_Attachment_1_HQ0034-18-R-0202.pdf | ||
| FINAL_RFP_Attachment_5_CLINs_IDIQ_Provisions_and_Clauses.pdf | ||
| FINAL_RFP_Attachment_2_IDIQ_PWS.pdf |
Show all 14
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
PERFORMANCE WORK STATEMENT
CROWDSOURCED VULNERABILITY DISCOVERY AND DISCLOSURE SERVICES
Functional Area (FA) 2 Task Order 1
1. PROJECT TITLE
This document provides the Performance Work Statement (PWS) for Functional Area (2) for the
Department of Defense Crowdsourced Vulnerability Discovery and Disclosure Services.
2. SCOPE
This FA2 Task Order (TO) will be to conduct private crowdsourced vulnerability discovery and disclosure activities against a software prototype that will replace a legacy military relocation system.
Testing will be done in the production environment.
● The prototype is a single web-based application built primarily in Go for the backend APIs and other back-end systems. The frontend of a Javascript application that calls the bankend APIs.
These applications are containerized and run inside Amazon Web Services (AWS)’s Elastic
Container Service (ECS), and users Amazon’s Relational Database Service (RDS) as its managed database instance. These servers are fronted by an Application Load Balancer (ALB) that receives and distributes traffic across the ECS instances.
● The assessment will comprise of 5-10 user roles within the system.
● The assessment will include a static source code analysis of approximately 200,000 lines of code.
● Researchers would primarily access the platform app via VPN credentials provided in advance, with web-based accessibility in scope for additional vulnerability discovery activity.
● Platform connectivity will require a VPN within a DoD network and a perimeter VPN at the edge of the contractor VPC for the Site-to-Site VPN tunnel that all researchers will use for testing.
● Contractor platform will monitor all network traffic and associated challenge activities to the maximum extent possible to control testing, and to validate vulnerabilities.
These are sensitive Government assets, therefore, the FA2 contractor will have to maintain a private community of skilled and trusted researchers including citizens of the United States, Five Eyes (FVEY –
Australia, Canada, New Zealand, UK and US) and North Atlantic Treaty Organization (NATO -- Albania, Belgium, Bulgaria, Canada, Croatia, Czech Republic, Denmark, Estonia, France, Germany, Greece, Hungary, Iceland, Italia, Latvia, Lithuania, Luxembourg, Montenegro, Netherlands, Norway, Poland, Portugal, Romania, Slovakia, Slovenia, Spain, Turkey, the United Kingdom, the United States) and
NATO countries abiding by the eligibility criteria established by DoD. The private community of researchers must be diverse in skillset, and able to conduct source code analysis, reverse engineering, and network and system exploitation. The challenge phase itself will last no more than four (4) weeks.
Access to the asset and the asset owners will be provided to the contractor upon task order award.
3. GENERAL REQUIREMENTS Contractor is required to comply with the IDIQ Performance Work
Statement. There are no additional general requirements for this TO.
4. PERFORMANCE REQUIREMENTS
4.1. Transition Activities
● Transition-In: At the commencement of the period of performance, the contractor is responsible during the PREPARATION phase of the process, for the following transition-in activities:
o Identify appropriate triage team, and technical lead for the designated challenge.
o Identify researchers that may be best suited with adequate skillset, especially for source code challenge, to recruit.
● Transition-Out: At the end of the task order period of performance, the contractor is responsible for the following transition-out activities:
o Deliver a final report that rolls up all data from end of each phase status reports, including activity metrics and coverage analytics, researcher vulnerability discovery and remediation metrics, vulnerability submission volume, triage speed, signal-to-noise ratio, and patch effectiveness and lessons learned from the challenge.
o Delete all vulnerability reports from the platform on the last day of each task order’s period of performance.
4.2. Task Execution
For this effort, the challenge phase itself will be a 4 week duration. All unclassified vulnerability assessments for the specific asset relative to this effort will be provided to the contractor by the DoD. The platform must include a secure portal for full packet capture capabilities to enable auditability and continuous monitoring of researcher activities. The contractor’s platform will be the mechanism for:
● Providing comprehensive vulnerability report triaging, validation, and prioritization within 48 hours of submission, and reporting to the DoD Remediation Teams to ensure it can patch the vulnerability as soon as possible;
● Providing the secure portal through which all testing occurs with full packet capture capabilities to enable continuous monitoring and auditability;
● Researchers to submit all vulnerability reports;
● Participants to apply to participate in the challenge and to submit vulnerability reports;
● Conducting all management and coordination with researcher community and project management and coordination with DoD Remediation Teams;
● Coordinating the disclosure of vulnerabilities affecting third party organizations/vendors. This requirement will be limited to U.S., FVEY citizens who have passed criminal background checks.
No participant may be a dual citizen of a non-FVEY or non-NATO nation. It is the sole responsibility of the contractor to communicate and coordinate with the researchers. Researcher capacity will be limited to approximately 70-100 of the most highly-skilled researchers. The contractor is expected to recruit researchers with extensive experience against these assets (e.g.
static and dynamic testing and computer network exploitation). For this requirement, the challenge will be divided between three (3) distinct phases. The phases, PREPARATION, CHALLENGE, and POST-CHALLENGE, will vary in length as described below. In addition to the requirements identified in the IDIQ PWS, the Contractor shall conduct:
1. Preparation Phase in which the contractor conducts activities to tailor their existing platform for the challenge, invite and vet researchers, per DoD’s requirement, define and then communicate the challenge scope, handle press associated with each specific challenge, and define challenge rules and requirements.
DoD expects the PREPARATION PHASE not to exceed four (4) weeks.
2. Challenge Phase in which the contractor receives vulnerability reports that researchers submit to the platform, filters out duplicate and out of scope vulnerability reports, triages incoming reports for severity, assists the DoD remediation team in validating reports, and manages the coordination of third party disclosures. DoD expects the CHALLENGE PHASE not to exceed four (4) weeks.
3. Post Challenge Phase in which the contractor coordinates with researchers and the government to ensure vulnerabilities have been closed, manages the compensation, both financial and non-financial, to the researchers, and provides any final deliverables/metrics to the government on challenge performance.
DoD expects that POST CHALLENGE PHASE not to exceed four (4) weeks.
The Contract is responsible forDelivering status reports at the end of the PREPARATION, CHALLENGE, and POST-CHALLENGE Phases.
5. SPECIAL REQUIREMENTS
In addition to the Special Requirements identified in the IDIQ PWS, the following requirements apply to this TO.
5.1. Government Furnished Materials
The Government will provide technical information, material and forms unique to the Government for supporting the task. The DoD will provide the results of the most recent penetration test or security assessment to the contractor prior to the Challenge Phase. Government unique information, including software, system configuration files, IP ranges, and other Government unique information related to this requirement, which is necessary for contractor performance, will be provided to the contractor. If access to services on any DoD internal networks (i.e., NIPRNet) is required, the Government will ensure any access is remotely available to the contractor to make the challenge successful. The COR will be the point of contact for identification of any required information to be supplied by the Government. Government
Furnished Materials also includes any information received during the challenge from Government employees.
5.2. Security
The contractor will have escorted access to DoD facilities for any physical meetings required and will complete Non-Disclosure Agreements (NDAs) for all contractor employees and subcontractor employees with access to vulnerability information.
Although it is not expected that any contractors or sub-contractors will be performing duties within an
Army controlled installation, facility, or area, all contractor employees, to include subcontractor employees, requiring access to Army installations, facilities and controlled access areas shall complete
Antiterrorism (AT) Level I awareness training within 14 calendar days after contract start date or effective date of incorporation of this requirement into the contract, whichever is applicable. The contractor shall submit certificates of completion for each affected contractor employee and subcontractor employee, to the COR within 14 calendar days after completion of training by all employees and subcontractor personnel. AT level I awareness training is available at this website: http://jko.jten.mil.
Contracted researchers will not require Common Access Cards (CACs).
Researchers will be allowed virtual access to the target system, GCSS-Army, via a contractor-controlled portal. Contractor and all associated sub-contractors employees shall comply with adjudication standards and procedures using the National Crime Information Center Interstate Identification Index (NCIC-III) and Terrorist Screening Database (TSDB) (Army Directive 2014-05/AR 190-13), applicable installation, facility and area commander installation/facility access and local security policies and procedures
(provided by government representative), by restrictions placed within the rules of engagement and described in section 4.3 above and section 5.5 below. Per AR 530-1 Operations Security, the contractor employees must complete Level I OPSEC Awareness training.
Background Checks
Conduct or confirm that criminal background checks on all researchers before granting them access to any DoD information. In addition to the normal background check requirement, Contractor must ensure that researchers are U.S., FVEY, or NATO country persons.
6.0. Deliverables
Deliverables of the FA2 task order shall be submitted to the COR. All deliverables shall be submitted using Microsoft Office suite of tools (e.g. MS Word, MS Excel, MS PowerPoint), or Adobe PDF format, unless otherwise specified by the COR. Electronic submission shall be made via email, unless otherwise agreed to by the Contracting Officer’s Representative. The Contracting Officer’s Representative may reject or require correction of any deficiencies in the deliverables. In the event of a rejected deliverable, the contractor will be notified in writing by the Contracting Officer’s Representative of the specific reasons for rejection.
PWS
Reference
Deliverable Title Delivery Time Frequency
5.2 Non Disclosure Agreement As requested Once
4 Reports after each phase. For the Final Report it must contain vulnerability report summary, challenge metrics, lessons learned, recommendations for future task orders
End of the Period of
Performance for this task order, or by a date determined by the
COR
Once
4 Challenge Activity Logs, Vulnerability Reports End of the Period of
Performance for this task order, or by a date determined by the
COR
Once
7.0. PERFORMANCE REQUIREMENTS SUMMARY
Performance metrics are detailed in the table below:
Requirement Performance Standard Acceptable Quality
Level
Surveillance Method
Provide support personnel to meet each task order PWS requirement
All contractor personnel possess the skills needed to perform the required tasks as specified in the
PWS
The contractor attracts and maintains a stable researcher base that effectively supports the task order requirements
24 hours prior to each challenge commencing
If security requirements apply to the task order, all documentation is submitted to the government in a timely manner so that no contractor caused delays are apparent in commencing a FA2 challenge
The contractor's deliverables are complete and on time
COR review/ government personnel feedback
Triage Personnel &
Capabilities to meet each task order PWS requirement
Contractor has extensive and experienced personnel on hand as well as proprietary automated tools
The contractor’s personnel use a combination of automated and manual methods to triage vulnerability reports within 48 hours of receipt
COR review/ government personnel feedback
Strategic communications and ability to handle public relations
Contractor has experienced personnel capable of handling both discreet communications on sensitive issues and public communications
Contractor has experienced personnel that handle strategic messaging. No more than
24 hours pass prior to social media responses issues for 95% of negative hacker posts
COR review/ government personnel feedback
File details come from the government source that posted it.