RFP__Amendment_0001_Attachment_3_Task_Order_PWS_080218.pdf

PDF 145 KB Posted

Attached to
DDS Crowdsourced Vulnerability Discovery & Disclosure Services (CVDD) FA2 Federal contract opportunity
Solicitation number
HQ003418R0202
Issued by
DOD Washington Headquarters Service

About this file

RFP Amendment 0001_Attachment 3 Task Order PWS

View the file

Other files for this federal contract opportunity

Show all 14

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

PERFORMANCE WORK STATEMENT

CROWDSOURCED VULNERABILITY DISCOVERY AND DISCLOSURE SERVICES

Functional Area (FA) 2 Task Order 1

1. PROJECT TITLE

This document provides the Performance Work Statement (PWS) for Functional Area (2) for the

Department of Defense Crowdsourced Vulnerability Discovery and Disclosure Services.

2. SCOPE

This FA2 Task Order (TO) will be to conduct private crowdsourced vulnerability discovery and disclosure activities against a software prototype that will replace a legacy military relocation system.

Testing will be done in the production environment.

● The prototype is a single web-based application built primarily in Go for the backend APIs and other back-end systems. The frontend of a Javascript application that calls the bankend APIs.

These applications are containerized and run inside Amazon Web Services (AWS)’s Elastic

Container Service (ECS), and users Amazon’s Relational Database Service (RDS) as its managed database instance. These servers are fronted by an Application Load Balancer (ALB) that receives and distributes traffic across the ECS instances.

● The assessment will comprise of 5-10 user roles within the system.

● The assessment will include a static source code analysis of approximately 200,000 lines of code.

● Researchers would primarily access the platform app via VPN credentials provided in advance, with web-based accessibility in scope for additional vulnerability discovery activity.

● Platform connectivity will require a VPN within a DoD network and a perimeter VPN at the edge of the contractor VPC for the Site-to-Site VPN tunnel that all researchers will use for testing.

● Contractor platform will monitor all network traffic and associated challenge activities to the maximum extent possible to control testing, and to validate vulnerabilities.

These are sensitive Government assets, therefore, the FA2 contractor will have to maintain a private community of skilled and trusted researchers including citizens of the United States, Five Eyes (FVEY –

Australia, Canada, New Zealand, UK and US) and North Atlantic Treaty Organization (NATO -- Albania, Belgium, Bulgaria, Canada, Croatia, Czech Republic, Denmark, Estonia, France, Germany, Greece, Hungary, Iceland, Italia, Latvia, Lithuania, Luxembourg, Montenegro, Netherlands, Norway, Poland, Portugal, Romania, Slovakia, Slovenia, Spain, Turkey, the United Kingdom, the United States) and

NATO countries abiding by the eligibility criteria established by DoD. The private community of researchers must be diverse in skillset, and able to conduct source code analysis, reverse engineering, and network and system exploitation. The challenge phase itself will last no more than four (4) weeks.

Access to the asset and the asset owners will be provided to the contractor upon task order award.

3. GENERAL REQUIREMENTS Contractor is required to comply with the IDIQ Performance Work

Statement. There are no additional general requirements for this TO.

4. PERFORMANCE REQUIREMENTS

4.1. Transition Activities

● Transition-In: At the commencement of the period of performance, the contractor is responsible during the PREPARATION phase of the process, for the following transition-in activities:

o Identify appropriate triage team, and technical lead for the designated challenge.

o Identify researchers that may be best suited with adequate skillset, especially for source code challenge, to recruit.

● Transition-Out: At the end of the task order period of performance, the contractor is responsible for the following transition-out activities:

o Deliver a final report that rolls up all data from end of each phase status reports, including activity metrics and coverage analytics, researcher vulnerability discovery and remediation metrics, vulnerability submission volume, triage speed, signal-to-noise ratio, and patch effectiveness and lessons learned from the challenge.

o Delete all vulnerability reports from the platform on the last day of each task order’s period of performance.

4.2. Task Execution

For this effort, the challenge phase itself will be a 4 week duration. All unclassified vulnerability assessments for the specific asset relative to this effort will be provided to the contractor by the DoD. The platform must include a secure portal for full packet capture capabilities to enable auditability and continuous monitoring of researcher activities. The contractor’s platform will be the mechanism for:

● Providing comprehensive vulnerability report triaging, validation, and prioritization within 48 hours of submission, and reporting to the DoD Remediation Teams to ensure it can patch the vulnerability as soon as possible;

● Providing the secure portal through which all testing occurs with full packet capture capabilities to enable continuous monitoring and auditability;

● Researchers to submit all vulnerability reports;

● Participants to apply to participate in the challenge and to submit vulnerability reports;

● Conducting all management and coordination with researcher community and project management and coordination with DoD Remediation Teams;

● Coordinating the disclosure of vulnerabilities affecting third party organizations/vendors. This requirement will be limited to U.S., FVEY citizens who have passed criminal background checks.

No participant may be a dual citizen of a non-FVEY or non-NATO nation. It is the sole responsibility of the contractor to communicate and coordinate with the researchers. Researcher capacity will be limited to approximately 70-100 of the most highly-skilled researchers. The contractor is expected to recruit researchers with extensive experience against these assets (e.g.

static and dynamic testing and computer network exploitation). For this requirement, the challenge will be divided between three (3) distinct phases. The phases, PREPARATION, CHALLENGE, and POST-CHALLENGE, will vary in length as described below. In addition to the requirements identified in the IDIQ PWS, the Contractor shall conduct:

1. Preparation Phase in which the contractor conducts activities to tailor their existing platform for the challenge, invite and vet researchers, per DoD’s requirement, define and then communicate the challenge scope, handle press associated with each specific challenge, and define challenge rules and requirements.

DoD expects the PREPARATION PHASE not to exceed four (4) weeks.

2. Challenge Phase in which the contractor receives vulnerability reports that researchers submit to the platform, filters out duplicate and out of scope vulnerability reports, triages incoming reports for severity, assists the DoD remediation team in validating reports, and manages the coordination of third party disclosures. DoD expects the CHALLENGE PHASE not to exceed four (4) weeks.

3. Post Challenge Phase in which the contractor coordinates with researchers and the government to ensure vulnerabilities have been closed, manages the compensation, both financial and non-financial, to the researchers, and provides any final deliverables/metrics to the government on challenge performance.

DoD expects that POST CHALLENGE PHASE not to exceed four (4) weeks.

The Contract is responsible for Delivering status reports at the end of the PREPARATION, CHALLENGE, and POST-CHALLENGE Phases.

5. SPECIAL REQUIREMENTS

In addition to the Special Requirements identified in the IDIQ PWS, the following requirements apply to this TO.

5.1. Government Furnished Materials

The Government will provide technical information, material and forms unique to the Government for supporting the task. The DoD will provide the results of the most recent penetration test or security assessment to the contractor prior to the Challenge Phase. Government unique information, including software, system configuration files, IP ranges, and other Government unique information related to this requirement, which is necessary for contractor performance, will be provided to the contractor. If access to services on any DoD internal networks (i.e., NIPRNet) is required, the Government will ensure any access is remotely available to the contractor to make the challenge successful. The COR will be the point of contact for identification of any required information to be supplied by the Government. Government

Furnished Materials also includes any information received during the challenge from Government employees.

5.2. Security

The contractor will have escorted access to DoD facilities for any physical meetings required and will complete Non-Disclosure Agreements (NDAs) for all contractor employees and subcontractor employees with access to vulnerability information.

Although it is not expected that any contractors or sub-contractors will be performing duties within an

Army controlled installation, facility, or area, all contractor employees, to include subcontractor employees, requiring access to Army installations, facilities and controlled access areas shall complete

Antiterrorism (AT) Level I awareness training within 14 calendar days after contract start date or effective date of incorporation of this requirement into the contract, whichever is applicable. The contractor shall submit certificates of completion for each affected contractor employee and subcontractor employee, to the COR within 14 calendar days after completion of training by all employees and subcontractor personnel. AT level I awareness training is available at this website: http://jko.jten.mil.

Contracted researchers will not require Common Access Cards (CACs).

Researchers will be allowed virtual access to the target system, GCSS-Army, via a contractor-controlled portal. Contractor and all associated sub-contractors employees shall comply with adjudication standards and procedures using the National Crime Information Center Interstate Identification Index (NCIC-III) and Terrorist Screening Database (TSDB) (Army Directive 2014-05/AR 190-13), applicable installation, facility and area commander installation/facility access and local security policies and procedures

(provided by government representative), by restrictions placed within the challenge rules and requirements., as described in section 4.2 above. Per AR 530-1 Operations Security, the contractor employees must complete Level I OPSEC Awareness training.

Background Checks

Conduct or confirm that criminal background checks on all researchers before granting them access to any DoD information. In addition to the normal background check requirement, Contractor must ensure that researchers are U.S., FVEY, or NATO country persons.

6.0. Deliverables

Deliverables of the FA2 task order shall be submitted to the COR. All deliverables shall be submitted using Microsoft Office suite of tools (e.g. MS Word, MS Excel, MS PowerPoint), or Adobe PDF format, unless otherwise specified by the COR. Electronic submission shall be made via email, unless otherwise agreed to by the Contracting Officer’s Representative. The Contracting Officer’s Representative may reject or require correction of any deficiencies in the deliverables. In the event of a rejected deliverable, the contractor will be notified in writing by the Contracting Officer’s Representative of the specific reasons for rejection.

PWS

Reference

Deliverable Title Delivery Time Frequency

5.2 Non Disclosure Agreement As requested Once

4 Reports after each phase. For the Final Report it must contain vulnerability report summary, challenge metrics, lessons learned, recommendations for future task orders

End of the Period of

Performance for this task order, or by a date determined by the

COR

Once

4 Challenge Activity Logs, Vulnerability Reports End of the Period of

Performance for this task order, or by a date determined by the

COR

Once

7.0. PERFORMANCE REQUIREMENTS SUMMARY

Performance metrics are detailed in the table below:

Requirement Performance Standard Acceptable Quality

Level

Surveillance Method

Provide support personnel to meet each task order PWS requirement

All contractor personnel possess the skills needed to perform the required tasks as specified in the

PWS

The contractor attracts and maintains a stable researcher base that effectively supports the task order requirements

24 hours prior to each challenge commencing

If security requirements apply to the task order, all documentation is submitted to the government in a timely manner so that no contractor caused delays are apparent in commencing a FA2 challenge

The contractor's deliverables are complete and on time

COR review/ government personnel feedback

Triage Personnel &

Capabilities to meet each task order PWS requirement

Contractor has extensive and experienced personnel on hand as well as proprietary automated tools

The contractor’s personnel use a combination of automated and manual methods to triage vulnerability reports within 48 hours of receipt

COR review/ government personnel feedback

Strategic communications and ability to handle public relations

Contractor has experienced personnel capable of handling both discreet communications on sensitive issues and public communications

Contractor has experienced personnel that handle strategic messaging. No more than

24 hours pass prior to social media responses issues for 95% of negative hacker posts

COR review/ government personnel feedback

File details come from the government source that posted it.