RFP_Amendment_0001_Attachment_2_IDIQ_PWS_080218.pdf
PDF 185 KB Posted
- Attached to
- DDS Crowdsourced Vulnerability Discovery & Disclosure Services (CVDD) FA2 Federal contract opportunity
- Solicitation number
- HQ003418R0202
- Issued by
- DOD Washington Headquarters Service
About this file
RFP Amendment 0001_Attachment 2 IDIQ PWS
View the file
Other files for this federal contract opportunity
| File | Type | Posted |
|---|---|---|
| RFP_Attachment_7_DD254_Revised_copy_(2).pdf | ||
| RFP_Attachment_7_DD254_Revised.pdf | ||
| RFP_Amendment_Attachment_5_CLINs_IDIQ_Provisions_and_Clauses.pdf | ||
| RFP_Amendment_0001_Attachment_1_HQ0034-18-R-0202_080218.pdf | ||
| RFP_Amendment_0001__Attachment_8___Questions_FINAL_080118_(002).pdf | ||
| RFP__Amendment_0001_Attachment_3_Task_Order_PWS_080218.pdf | ||
| RFP_Amendment_0001_Attachment_4_Task_Order_Pricing_Template_v2.xlsx | XLSX spreadsheet | |
| FINAL_RFP_Attachment_7_DD254.pdf | ||
| RFP_Attachment_4_Task_Order_Pricing_Template.xlsx | XLSX spreadsheet | |
| FINAL_RFP_Attachment_1_HQ0034-18-R-0202.pdf | ||
| FINAL_RFP_Attachment_5_CLINs_IDIQ_Provisions_and_Clauses.pdf | ||
| FINAL_RFP_Attachment_2_IDIQ_PWS.pdf | ||
| FINAL_RFP_Attachment_3_Task_Order_PWS.pdf | ||
| FINAL_RFP_Attachment_6_Task_Order_Provisions_and_Clauses.pdf |
Show all 14
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
PERFORMANCE WORK STATEMENT
Functional Area (FA) 2
1. PROJECT TITLE
This document provides the Performance Work Statement (PWS) for Functional Area (FA) 2 of the Indefinite Delivery/Indefinite Quantity (IDIQ) contract vehicle for Department of
Defense (DoD) Crowdsourced Vulnerability Discovery & Disclosure Services.
2. BACKGROUND
The DoD’s computer networks and systems support the nation’s defense and are critical both for daily business operations and mission-critical activities. Maintaining the security and integrity of the DoD’s networks and systems is a matter of national security and requires the continuous identification and remediation of vulnerabilities that can be exploited by malicious cyber actors. As part of its responsibility to the public, DoD is constantly considering innovative and diverse approaches to meet this goal. To support DoD’s continual efforts to remain at the forefront of rapidly evolving technologies, and to maintain the highest levels of integrity and security required of its IT infrastructure, DoD has identified an emerging need to leverage a diverse pool of innovative information security researchers
(herein called “researcher”), via crowdsourcing, for vulnerability discovery, coordination, and disclosure activities.
3. PURPOSE & OBJECTIVE
Assisted by the private sector, the Government intends to use existing commercial crowdsourcing expertise and best practices, tailored for the Government’s use, to support the
DoD in applying the crowdsourcing methodology to enhance its information security.
To support this objective, the DoD intends to partner with commercial firm(s) with extensive experience with administering crowdsourced vulnerability discovery and disclosure activities as a service. Under the resulting task order(s), the firm will host crowdsourced security activities on behalf of the DoD.
4. SCOPE
The scope of work, under the resulting IDIQ contract vehicle, is to conduct crowdsourced vulnerability discovery and disclosure (CVDD) services across the full range of networks, systems, and information, including web applications, software, source code, software-embedded devices and other technologies as solicited across the whole Department of
Defense. Work performed under the resulting IDIQ contract vehicle will be categorized under one functional area as detailed below.
Functional Area 2 (FA2) activities may involve:
● Researchers conducting auditable crowdsourced vulnerability discovery and disclosure activities through a secure portal on the contractor’s platform against a variety of sensitive but Internet-connected assets, and non-Internet connected assets. Assets could include closed networks, software-embedded devices, proprietary source code, or other private or internal systems not generally accessible via the public Internet;
● Testing content hosted on contractor’s infrastructure, through its secure platform in a controlled environment or repository;
● Testing content hosted by DoD through a secure contractor portal where IP addresses are logged and/or directly provisioned by the contractor and other data, potentially including keystrokes, are captured;
● The platform must have a secure portal capable of continuous monitoring and auditing of researcher activities;
● Scoped Time-boxed and continuous crowdsourced efforts ranging from 25 to 200 total participants;
● All activities under FA2 will include commercial background check requirements as a condition of researcher participation, which will be contractor responsibility.
● Generation of high-quality vulnerability reports that enable DoD to efficiently remediate asset vulnerabilities;
● Provide comprehensive vulnerability triaging, validation, and prioritization within 48 hours of submission, and reporting to the DoD Asset Owner to ensure it can patch the vulnerability as soon as feasible;
● Ability to create customized vulnerability workflow management and track vulnerabilities throughout the remediation lifecycle;
● Assist the DoD Asset Owner in identifying and developing mitigation approaches for discovered vulnerabilities;
● Ability to provide a means to easily export vulnerability reports to other systems (JIRA, etc.) and synchronize vulnerability remediation statuses between multiple systems through common format (deliverable format will be identified at each Task Order PWS);
and
● Conduct all management and coordination with researcher community, and project management and coordination with DoD Remediation Team.
The government expects approximately 8 time boxed challenges and 5 continuous challenges for FA2 during the first year of the contract, and up to 8 for time boxed challenges and 5 for continuous challenges if the option year is exercised. There may be FA2 task orders with overlapping periods of performance and challenge phases. The period of performance is expected to vary per task order with an average duration of three (3) to twelve (12) months.
Upon IDIQ contract award, there will be a three week “Transition Phase” where the contractor implements key personnel, builds the initial triage team, and sets up billing and invoice accounts.
Each FA2 challenge will be divided between three (3) distinct phases. The phases, PREPARATION, CHALLENGE, and POST-CHALLENGE, will vary in length and depends on the scope of the challenge.
Further details, specific to each phase, are listed in this section of the PWS.
Below, organized by phase, are contractor requirements relative to the CVDD services provided.
Although the contractor may move an activity to different phases shall include:
PREPARATION PHASE. The contractor must:
○ Strategically recruit the best-suited researchers based on their proven experience, and their known skillset, given the challenge (source code, operational functionality).
○ Conduct criminal background checks on all researchers before granting them access to any DoD information.
○ Working with the DoD Asset Owner, and other Tech Stakeholders, develop the asset scope of the challenge.
○ Working with DoD Asset Owner, and other Tech Stakeholders, develop the specific technical parameters for the challenge.
○ Determine payment amounts for researchers based on contractor’s prior experience, and industry best practices. Socialize payment amounts to the researchers.
○ Assist drafting and once finalized, distribute scope of the challenge and the technical parameters (i.e., rules of engagement and restrictions, including legal parameters) to the researchers.
○ Tailor existing platform to the specific challenge environment for researchers to report vulnerabilities, for triage personnel to coordinate and communicate with the researchers, and for the remediation team to view vulnerability report details.
CHALLENGE PHASE. The contractor must:
○ Communicate vulnerability discovery and disclosure rules of engagement and legal parameters to researchers.
○ Communicate vulnerability reporting standards and requirements to researchers.
○ Conduct full packet capture of all researcher activities.
○ Integrate appropriate controls over researcher traffic, include a secure portal for full packet capture capabilities to enable auditability and continuous monitoring of researcher activities.
○ Flag improper, suspicious, or out-of-scope testing conducted by researchers for DoD.
○ Use existing platform to receive and aggregate vulnerabilities identified by researchers, and ensure vulnerability reports are of high-qualify enabling efficient remediation efforts.
○ Complement researcher efforts with automated testing tools for source code analysis, host and application scanning, and vulnerability analysis, if applicable.
○ Ensure subcontractors and security researchers adhere to rules and restrictions as consented to prior to registration and throughout the whole challenge.
○ Triage incoming vulnerability reports through both automated and manual techniques based on severity to identify submissions most impactful to the DoD asset owner and communicate and assign those vulnerabilities to the DoD Remediation Team based upon mutually agreed upon escalation policies.
○ Identify duplicate vulnerability reports, and filter out other reports that are ineligible or out of scope, preferably utilizing existing automation tools.
○ Ensure submitted vulnerability reports are complete, and contain a severity assessment, description, detailed reproductive steps, and recommended remediation fix so DoD can remediate the vulnerability when it is reported.
○ Engage with personnel responsible for operating, securing and defending the DoD asset on discovered vulnerabilities and facilitate communications between DoD personnel and subcontractors, independent persons or entities, and researchers.
○ Ensure all identified vulnerabilities are communicated securely to DoD, adhering to common international standards for the secure transmission of sensitive security data.
○ Have the technical capability (i.e., an Application Program Interface (API)) to export vulnerability reports into many systems (i.e., JIRA), or other dedicated vulnerability management or ticketing system.
○ Assist the designated DoD Remediation Team with validating vulnerability reports.
○ Coordinate the disclosure of vulnerabilities with a multi-vendor/multi-party impact, as necessary. Third-party suppliers of software or hardware technology that may be affected by disclosing certain vulnerabilities may be common and require unique expertise.
POST CHALLENGE PHASE. The contractor must:
○ Coordinate with researchers and the designated DoD Remediation Team to ensure open vulnerability reports are adjudicated and closed out to the level of satisfaction of DoD personnel.
○ As appropriate, provide packet capture and other logs to DoD.
○ Write a final report.
○ Manage and facilitate the secure, legal payment of monetary and non-monetary awards to researchers for validated and qualifying vulnerability reports.
○ The contractor will effectively communicate and coordinate with prospective as well as current researchers to ensure smooth user experience.
DURATION OF ALL PHASES. The contractor must:
○ During the whole period of performance, the contractor will effectively communicate and coordinate with prospective researchers to ensure smooth user experience;
○ Communicate electronically with researchers at each stage of the vulnerability life cycle, including initial receipt, remediation, and acknowledgement/reward,
○ Securely manage the storage and distribution of credentials to researchers to enable remote vulnerability discovery and disclosure activities against assets that require trusted relationships/connections,
○ Ensure that the vulnerability discovery and disclosure process can adhere to common international standards for handling vulnerability data, such as ISO 29147 and ISO
30111, and
○ Deliver status reports at the end of the PREPARATION, CHALLENGE, and POST-
CHALLENGE phases. Deliver final report at the end of the task order.
○ Notify DoD within 12 hours if a researcher violates the rules of engagement of restrictions. Contractor will be required to submit additional information requested about such action.
5. TRANSITION ACTIVITIES
Transition (in and out) activities will be specified at the task order level. They will consist of activities that the contractor is expected to do to prepare for beginning work in the PREPARATION PHASE and activities that the contractor is expected to do before ending performance under a task order.
6. GENERAL REQUIREMENTS
This section describes the general requirements for this effort. The following subsections provide details of various considerations.
6.1 Non-Personal Services
In accordance with FAR 37.101, this contract is a non-personal services contract. Contractor personnel rendering the services shall not be subject, either by the contract’s terms or by the manner of its administration, to the continuous supervision and control of a Government officer or employee. The contractor shall immediately notify the Contracting Officer’s Representative and the Contracting Officer if, through contract administration, the actions of a Government employee will result in the performance of a personal services contract.
6.2 Inherently Governmental Functions
No inherently governmental functions as defined in FAR 2.101 and FAR 7.5 shall be performed by the contractor under this contract. Contractor employees shall not participate in any deliberations or meetings intended to exercise an inherently governmental function. All final determinations such as binding the
United States to take or not take action, selecting program priorities, and providing direction to Federal employees shall be made by the government. The contractor shall immediately notify the Contracting
Officer’s Representative and the Contracting Officer if performance of an activity would result in the performance of an inherently governmental function.
6.3 Business Relations
The contractor shall integrate and coordinate all activity to execute the requirements specified herein and at the task order level. The contractor shall manage the timeliness, completeness, and quality of the contract and task order deliverables. The contractor shall provide corrective action plans, proposal submittals, timely identification of issues, and effective management of all contractor personnel
(including subcontractors). The contractor shall seek to ensure customer satisfaction and professional and ethical behavior of all contractor personnel.
6.4 Contract Management
The contractor shall establish clear organizational lines of authority and responsibility to ensure effective management of the program and resources assigned to this requirement. The contractor must maintain continuity between the support operations at DoD and the contractor’s corporate offices.
6.5 Contract Administration
The contractor shall establish processes and assign resources to effectively administer the IDIQ contract and each task order. The contractor shall respond to Government requests for contractual actions promptly.
6.6 Subcontract and Independent Persons and Independent Persons/Entities Management
Contractors are encouraged to subcontract with entities to ensure full support of all required services as outlined in this IDIQ PWS. This could include additional triage capacity and security consultants for vulnerability validation, strategic communications, and penetration testing. Additionally, it is expected that individuals conducting the vulnerability discovery and disclosure are independent persons and entities.
Any firm with whom the Government contracts will be the sole point of contact between third party entities and the Government, unless otherwise specified by the Contracting Officer’s Representative
(COR). The contractor will be responsible for the supervision of the vulnerability disclosure, and assessment process, unless otherwise specified by the Government. Under no circumstances may the contractor represent to the independent third parties that the independent parties are working on behalf of
DoD or that the independent third parties have privity of contract with the DoD.
The contractor shall be responsible for any subcontract management to integrate work performed on this requirement and shall be responsible and accountable for subcontractor performance on this requirement.
The prime contractor will manage work distribution to ensure there are no Organizational Conflict of
Interest (OCI) considerations, as defined in FAR 9.5. Researchers will identify and submit vulnerability reports for the Government under this program. The contractor will manage the researchers and all communications necessary regarding vulnerability specifics between the Government and the contractor.
6.7 Contractor Personnel, Disciplines and Specialties
Successful performance under each task order will include the responsiveness of contractor personnel in the day-to-day output of work products. While the end product is vital to successful performance, day-to-day oversight also includes client interaction and responsiveness. The contractor is required to proactively maintain assigned tasks, and respond to all entities with professional business relative to the assigned tasks.
The contractor must maintain an adequate workforce for the uninterrupted performance of all tasks defined within the respective task order PWS. When hiring personnel, the contractor shall remember that the stability and continuity of the workforce are essential.
6.8 Travel
Work required by this PWS shall primarily take place remotely at the contractor’s facilities. Travel to the
DoD asset owner’s facility during the PREPARATION PHASE of each challenge during the duration of the IDIQ contract may be necessary for a one day or multi-day workshop with DoD Tech Stakeholders to determine and finalize the challenge. This facility will be within the continental United States. Travel shall be approved in advance by the Contracting Officer’s Representative. Travel shall not commence until written approval is received.
The contractor shall be reimbursed for actual allowable, allocable, and reasonable travel costs incurred during performance of this effort in accordance with the FAR 31.205-46 “Travel Costs.” Requests for approval of costs in excess of maximum per diem rates in accordance with the procedures in FAR 31.205-
46(a)(3) must be submitted to the Contracting Officer for final approval prior to commencement of travel.
6.9 Place of Performance/Events
The majority of the work associated with this effort is anticipated to be performed off-site at contractor facilities. However, some work may be performed on-site at Government facilities and will be identified at the task order level.
In certain cases, the contractor may have to coordinate and host live-hacking events.
6.10 Vulnerability Discovery & Disclosure Platform
The contractor must own and maintain a platform to facilitate vulnerability discovery and disclosure activities relative to FA2. Platform requirements are stipulated below:
FA2 Platform Requirements
Platforms, conducting work under FA2, must have:
● The capability to accept vulnerability reports from researchers.
● The capability to apply tools and processes, automated and manual, to triage reports for the
Government. This includes de-duplication of reports within 48 hours of receipt.
● The capability to ensure that vulnerability reports, transmitted to Government remediators, are clear and of high quality. This will ensure that Government personnel can immediately remediate identified vulnerabilities.
● The capability to facilitate effective communication between the triage team and researchers and between the triage team and Government remediators. This may include corresponding, separately, with multiple teams.
● The capability to facilitate the secure transmission and storage, of vulnerability information, and adhere to ISO standards.
● The capability to implement continuous monitoring as well as auditing tools, to monitor and assess, researcher behavior.
● The capability to capture and inspect encrypted researcher traffic, such as through a TLS interception proxy.
● The capability to function as a secure portal capable of continuous monitoring and auditing of researcher activities, such as those logs collected through simple proxy logging, up to full PCAP captures as identified at the task order level.
The DoD requires the ability to continuously monitor individual researcher activity for the duration of the live-assessment, and the ability to audit researcher activity post-assessment. At a minimum, DoD requires the ability to know which individual researchers are accessing (or accessed) specific parts of an assessment at specific points in time. Further monitoring/auditing requirements may be indicated at the task order level.
6.11 Managing the Contract and Task Orders
The contractor shall maintain a single point of contact (POC) or Program Manager for the management and maintenance of the IDIQ contract. See also section 6.13 below. For each task order, researchers will identify and submit vulnerability reports for the Government. The contractor will manage the researchers and all communications necessary regarding vulnerability specifics between the Government and the contractor.
Certain DoD employees and other Federal Government employees are prohibited by law from receiving any financial reward as it may violate 18 U.S.C. 209 and the Joint Ethics Regulations, DoD 5500.07-R.
The contractor shall ensure that no prohibited individuals, including Government employees, receives financial compensation.
Each task order award will be a fixed-firm price payment for services to cover all contractor support and bounty payments. The bounty payout allocation is at the discretion of the contractor, but the challenge phase will remain active for the duration specified in the task order.
6.12 Managing Researchers
When managing Researchers under the performance of task orders the contractor(s) shall:
● Effectively communicate and coordinate with current and prospective researchers to ensure a smooth experience for participants over the full duration of the respective task order period of performance.
● Communicate electronically with researchers at each stage of the vulnerability lifecycle, including initial receipt, remediation, and acknowledgement/reward.
● Securely manage the storage and distribution of credentials to researchers to enable remote vulnerability discovery and disclosure activities against assets that require trusted relationships/connections.
● Ensure that the vulnerability discovery and disclosure process is capable of adhering to common international standards for handling vulnerability data, such as ISO 29147 and ISO 30111.
● Identify appropriate bounty amounts, pay researchers, and provide appropriate tax documentation for any monetary and/or nonmonetary bounties paid to researchers for each task order.
6.13 Key Personnel
The contractor shall designate a Program Manager as a single point of contact to the DoD with at least one year experience as an effective client manager. Before removing or replacing the Program Manager, the contractor shall (1) notify the Contracting Officer reasonably in advance and (2) submit justification
(including proposed substitutions) in sufficient detail to permit evaluation of the impact on this contract.
The contractor shall make no diversion without the Contracting Officer's (CO) written consent; provided that the CO may ratify in writing the proposed change, and that ratification shall constitute the CO's consent required by this document.
6.14 Identifying Contractor Employees
All contract personnel attending meetings and working where their contractor status is not obvious to third parties must identify themselves as such to avoid creating an impression in the minds of members of the public they are Government officials. They must also ensure that all documents or reports produced by contractors are suitably marked as contractor products or that contractor participation is appropriately disclosed.
7. SPECIAL REQUIREMENTS
This section describes the special requirements for this effort. These sub-sections explain various considerations on this effort.
7.1 Government Furnished Materials
The Government will provide technical information, material and forms, and, as necessary, hardware and software unique to the Government for supporting the task orders. The DoD will provide any results of the most recent penetration test, if applicable, to the contractor prior to each Challenge Phase.
Government unique information related to this requirement, which is necessary for contractor performance, will be provided to the contractor. The COR will be the point of contact for identification of any required information to be supplied by the Government. Government Furnished Materials also includes any information received during the challenge from Government employees. Additional detail is included in each Functional Area PWS.
7.2 Non Disclosure Agreements
If required, the contractor will have escorted access to DoD facilities for any physical meetings required.
A Non-Disclosure Agreement (NDA) (either government provided or contractor provided NDA that the
Government has approved) for all contractor employees and subcontractor employees with access to vulnerability information must be provided at the commencement of each task order. Additional security requirements may be required and identified in each respective task order. If the Contractor uses its NDA that has been approved by the Government, anytime the Contractor modifies its approved NDA) , the
Contractor agrees to provide the modified NDA to the Government. Further, the Government reserves the right to have individuals sign an additional DoD specific NDA.
7.3 Security
The overarching security requirements and contractor access to classified information shall be as specified in the DD Form 254. The contractor is required to obtain a facilities clearance to obtain access to classified information. Failure to obtain a Facilities Clearance will disqualify a contractor from bidding on task orders that require access to classified information. Access to classified information will be determined at the task order level.
As soon as possible, the contractor shall ensure its facility meets the requirements for a SECRET facility clearance and shall apply for a facility clearance no later than 30 days after award. As soon as practicable thereafter, the contractor’s designated program manager shall apply for a secret clearance. All other application for individual contractor employee clearances shall be agreed upon with the Government.
Throughout the contract, the Government will consider, but is not obligated to, defraying the cost associated with obtaining a secret clearance for up to five employees, and in no event shall the
Government’s cost deferment exceed $10,000.00 throughout the entire contract. The Contractor shall work with the COR to compile and complete all documentation necessary for the Facilities Clearance and/or the personnel secret clearances.
7.4 Documentation
Documents, data files, reports, correspondence, and all other documents and writings, regardless of the medium (or media) by which they were produced, preserved, stored, or created in or for purpose(s) of work performed under this PWS and contract, shall be delivered directly within the vulnerability reporting platform or other approved method as directed by written request from the COR (i.e. Email, API).
The contractor agrees to assume responsibility for protecting the confidentiality of Government records, which is not considered public information. Each contractor or employee of the contractor to whom information may be provided or disclosed shall be notified in writing by the contractor that such information may be disclosed only for purposes and to the extent authorized. The contractor shall release no information related to this contract to the public, media or other unauthorized persons or organizations unless the government has conducted the appropriate security review and granted written approval.
7.5 DoD Intellectual Property
The contractor may be granted limited written authority to use the official seal of the Department of
Defense (DoD), and the official seals of all DoD Components (Other DoD Seals) for limited purposes.
These purposes could include advertising the challenge on the challenge page in the platform, such as the eligibility page and the rules and the Challenge page. Use of all logos must be discontinued at the conclusion of each task order, or pending approval, the duration of the contract. Any contractor or subcontractor is not authorized to use the official seal of DoD and/or other DoD Seals without written pre-approval from DoD Public Affairs and the Contracting Officer for any purpose. The contractor is not authorized to create, publish, or distribute any physical or electronic material that contains both the official seal of DoD and the contractor’s name and/or logo.
7.6 Participation of Government Employees
The Government may request that certain Government employees participate in challenges. Specific details regarding government personnel participation will be definitized, in collaboration with the
Contractor, and specified at the task order level.
7.7 Background Checks
The contractor must have the ability to conduct criminal background checks for all registered participants.
The contractor may be required to contract a third party commercial firm to conduct a commercial background check to ensure DoD resources do not pay bounties to felons or terrorists. The FA2 contractor must conduct thorough background checks of every researcher before they are invited to participate in every/any challenge. This may include ensuring that researchers are U.S. persons (unless non-U.S.
persons are identified in the task order); are not felons; are not known terrorists, or an associate of a known terrorist or terrorist organization; are not listed on the U.S. Department of Treasury’s Specially
Designated Nationals List; or otherwise ineligible to conduct work for DoD.
7.8 508 Compliance
Any/all Electronic and Information Technology (EIT) developed, maintained, or used through this effort must meet the accessibility standards at 36 CFR 1194. 36 CFR 1194 implements Section 508 of the
Rehabilitation Act of 1973, as amended, and is viewable at http://www.section508.gov . The contractor shall comply with Section 508 of the Rehabilitation Act of 1973 and support the Government to ensure compliance with Section 508 throughout the development and implementation of this requirement.
8. DELIVERABLES
All deliverables will be designated at the task order level. All deliverables shall be submitted using
Microsoft Office suite of tools (for example, MS Word, MS Excel, MS PowerPoint), or Adobe PDF format, unless otherwise specified by the COR. Electronic submission shall be made via email, unless otherwise agreed to by the COR.
The COR may reject or require correction of any deficiencies in the task order deliverables. In the event of a rejected deliverable, the contractor will be notified in writing by the COR of the specific reasons for rejection.
PWS
Reference
Deliverable Title Delivery Time Frequency
5.2 Non Disclosure Agreement 5 days after contract
award
Once
9. PERFORMANCE REQUIREMENTS SUMMARY
Performance metrics shall be identified at the individual task order.
File details come from the government source that posted it.