HQ0034-20-R-0264 QandA_Amendment 01.pdf

PDF 161 KB Posted

Attached to
DNS Resolver Services Federal contract opportunity
Solicitation number
HQ0034-20-R-0264
Issued by
DOD Washington Headquarters Service

About this file

This document contains questions and answers related to a solicitation for DNS resolver services. The solicitation seeks a vendor to provide DNS resolution, threat intelligence integration, and data analysis capabilities for the Department of Defense. Key requirements include providing DNS resolution with 99.999% uptime, integrating threat intelligence from both open and commercial sources, storing and retaining query logs and analytics data for a minimum of six months to one year in a FedRAMP High compliant data lake, and providing a real-time dashboard and help desk support. The response deadline was initially August 7, 2020 but has not been extended. This is a new requirement not associated with any current or past contracts.

View the file

Other files for this federal contract opportunity

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

Received as of 7/30/2020 | 3pm EST

Question

No.

Question

Category

Section, Paragraph, or Attachment Page # Question/Comment/Clarification Answer Change

1 Synopsis

PWS

Appendix 2

Evaluation Technical Factor 1, Section B, VI

PWS Appendix 2, Pg. 11, Section 4.4

Pg. 6

Pg. 11, Section 4.4

Would the Government consider removing the requirement that the proposed

DNS Resolver Service, analytic capability and control interface be accredited at

FedRAMP High or IL4? It appears there is only a single FedRAMP certified

DNS Resolver on the market with the required credentials, thus making this a sole-source requirement. Doing so would enable increased competition among commercial off the shelf solutions that offer market-leading security efficacy. To ensure a secure solution, we recommend instead that any proposed DNS

Resolver Services, analytic capability and control interface be required to meet/exceed other Federal security requirements such as 2FA, ACL restrictions, data privacy, etc.

Vendors that can show that their solution is FedRamp Ready at the time of the contract award will be given flexibility on timeline for accreditation. In addition, the government only requires the datalake to be FedRamped, not the DNS resolver itself.

Y

2 Synopsis

PWS

Appendix 2

Evaluation Technical Factor 1, Section B, VI

PWS Appendix 2, Pg. 11, Section 4.4

Pg. 6

Pg. 11, Section 4.4

... our solution would require an extended timeframe to design, implement and ultimately accredit in line with chosen security standards (in this case FedRamp

High or IL-4). Would DDS consider awarding this contract on the basis that the earliest a solution could be made available for security accreditation would be

March 2021?

Vendors that can show that their solution is FedRamp Ready at the time of the contract award will be given flexibility on timeline for accreditation. In addition, the government only requires the datalake to be FedRamped, not the DNS resolver itself.

Y

3 PWS Security/Classification Pg. 14 Could this contract be awarded to a non US entity, assuming that the non US entity was able to comply with the requirements including the

Security/Classification requirement that all personnel performing on this contract are US citizens?

Yes. N

4 Synopsis/

Solicitation

Sect. 1 (1)(a)

Sect. 1 (1)(b)(vi), Pg. 5

Pg. 6

The FedRamp requirement is therefore limiting if we are to provide a globally available recursive DNS resolver service. For a globally available recursive DNS resolver service with a data lake, will the government accept a solution where:

i) no data is stored at the recursive DNS resolver and

ii) the recursive DNS resolver resides in the CSP infrastructure both inside and outside the US and

iii) the recursive DNS resolver is not FedRAMP high nor IL4 certified and

iv) the data lake with query data from the recursive DNS resolver resides in a

FedRAMP High or IL4 compliant infrastructure such as Azure, AWS, Google

Cloud Platform, etc?

Vendors that can show that their solution is FedRamp Ready at the time of the contract award will be given flexibility on timeline for accreditation. In addition, the government only requires the datalake to be FedRamped, not the DNS resolver itself.

Y

5 Will the government grant a waiver for the requirement that the recursive DNS resolver, with no data stored on the resolver, be FedRamp High or IL4 compliant? If the answer is no, will the Government accept commercially reasonable action by the recursive DNS provider to meet the IL4 or FedRAMP

High requirements greater than 30 days after contract award?

Vendors that can show that their solution is FedRamp Ready at the time of the contract award will be given flexibility on timeline for accreditation. In addition, the government only requires the datalake to be FedRamped, not the DNS resolver itself.

Y

HQ0034-20-R-0264 Q&A (rev2 Combined List)

6 Synopsis/

Solicitation

Technical Factor 1 Pg. 6, Para. 2, (a)(ii) Does the government have anticipated timelines for the growth so we can adjust pricing by year to reflect volume? Will the government amend the solicitation to cap the number of requests to 3 billion queries per day?

The awarded contract encompasses the provision of the listed services only for

DoDIN. The PWS advises offerors of the potential for the addition of other user bases during contract performance. Should the Government need service for additional user bases, it will execute a bilateral contract modification which will include a negotiated increase in contract price for the additional services. As such, Offerors should not base their proposed firm fixed price on providing service to any user bases beyond DoDIN.

As stated in the solicitation, the Government estimates that DoDIN’s query load is an average of 400M per day. The scope of the initial contract (prior to any modification adding additional users) is to provide DoDIN with the DNS resolver services that it requires. Therefore, if DoDIN’s query load turns out to be somewhat higher than 400M/day, such usage is included in the contract’s firm fixed price. However, if DoDIN’s query load were to significantly exceed the stated estimate of 400M/day, the contractor would be entitled to an equitable adjustment of price.

Y

7 PWS Appendix 2 Pg. 1, Pg. 3 Given the importance of increasing security efficacy through cloud-based, commercially-provided DNS Resolver Services and the varying levels of vendor capabilities, would the Government consider including 3 rd party efficacy testing in their evaluation criteria?

The Government will not add third party testing to its evaluation N

8 PWS Appendix 2, Para. 2 Pg. 2 Please provide further details on the prototype? For example: What are the

CPU, Memory, and Storage requirements? What Operating System does this prototype run on? Was one instance used for the Pilot or multiple instances?

The prototype was to evaluate the feasibility of combining commerical and government threat intellegence. Information about the prototype is not necessarily applicable to this Performanace Work Statement.

N

9 Please detail the threat sources that were used with the prototype. The prototype was to evaluate the feasibility of combining commerical and government threat intellegence. Information about the prototype is not nessiesaly applicatle to this Performanace Work Statement.

N

10 What cloud environment was used for the prototype? Was there also a "data lake" provided and if so, what was used to provide the "data lake"?

The prototype was to evaluate the feasibility of combining commerical and government threat intellegence. Information about the prototype is not nessiesaly applicatle to this Performanace Work Statement.

N

11 PWS Appendix, Para. 3a Pg. 2 For the system to receive real time threat information, what integrations need to be accessible ?

The contractor shall have the ability to support up to 10 USG sources of domains in a variety of methods (rsync, SMTP, and STIX). [See PWS]

N

12 How many agencies/partners will be connecting to service? The Government does not have a firm maximum figure for the number of user bases that it might add by modification to the contract. However, the contractor must have the capability of scaling up from only DoDIN to the entirety of the federal government. The Government estimates that the entirety of the federal government would not surpass 3 billion queries per day.

N

13 What are the bandwidth requirements for agencies that will connect to the service?

The Government does not have a firm maximum figure for the number of user bases that it might add by modification to the contract. However, the contractor must have the capability of scaling up from only DoDIN to the entirety of the federal government. The Government estimates that the entirety of the federal government would not surpass 3 billion queries per day.

N

14 PWS Appendix, Para. 3b Pg. 2 Are VPN tunnels going to be required for some organizations to access this service?

No N

15 How much continuous traffic must a single prototype accept/process before a performance impact?

“The Government does not have a firm maximum figure for the number of user bases that it might add by modification to the contract. However, the contractor must have the capability of scaling up from only DoDIN to the entirety of the federal government. The Government estimates that the entirety of the federal government would not surpass 3 billion queries per day.”

N

16 PWS Appendix, Para. 3c Pg. 2 What is the length of time that data needs to be stored? The contractor shall migrate all information that has aged “six months”, barring any active processing conditions, to retained in long-term cloud storage (i.e., “cold storage”) for a period of one year. The long-term cloud storage shall have the capability to retrieve the information of the

Government’s choosing.

N

17 Does the prototype already have the ability for users to query logs or will that require development by the contractor?

The prototype was to evaluate the feasibility of combining commerical and government threat intellegence. Information about the prototype is not nessiesaly applicatle to this Performanace Work Statement.

N

18 Who will be charged with implementing the Access controls identified? While the government will decide who has access, please note that the access controls themselves will be evaluated under technical requirement two.

N

19 What are the security requirements and means for accessing the website/webportal/dashboard for downstream clients?

The vendor will comply with all government standards for security. Government will screen downstream clients before onboarding. At minimum, there will be a requirement for strong multi-factor autheentication support

N

20 PWS Appendix, 4.1.1 Pg. 3 What are the "blocking services" requirements? Are these services to be user-initiated block or system triggered?

Both. The government will provide block lists that will be used to supplement commercial threat intellegence. The expectation is that block lists will be updated constantly based on threat intellegence.

N

21 Who determines what domains are classified as a security threat? The government. The government will provide block lists that will be used to supplement commercial threat intellegence. The expectation is that block lists will be updated constantly based on threat intellegence.

N

22 Does the prototype already have a built-in portal for self-service policy creation?

Will that need to be developed by the contractor?

The prototype was to evaluate the feasibility of combining commerical and government threat intellegence. Information about the prototype is not nessiesaly applicatle to this Performanace Work Statement.

N

23 How are systems currently accessing the commercial security feeds and prototype?

The prototype was to evaluate the feasibility of combining commerical and government threat intellegence. Information about the prototype is not nessiesaly applicatle to this Performanace Work Statement.

N

24 Is there an existing framework for integrating threat sources? No. That is something the government expects the vendor to provide. N

25 If the tool is only used for security threats, why is the contractor involved in content filtering referenced in 4.2.3?

There is no content filtering requirement. The requirement is only that the solution does not interfere with content filtering at the client level.

N

26 Please quantify the expected user base for the service? “The Government does not have a firm maximum figure for the number of user bases that it might add by modification to the contract. However, the contractor must have the capability of scaling up from only DoDIN to the entirety of the federal government. The Government estimates that the entirety of the federal government would not surpass 3 billion queries per day.”

N

27 PWS Pg. 4 What is the number of estimated user accounts? The Government does not have a firm maximum figure for the number of user bases that it might add by modification to the contract. However, the contractor must have the capability of scaling up from only DoDIN to the entirety of the federal government. The Government estimates that the entirety of the federal government would not surpass 3 billion queries per day.

N

28 What will the process be to add additional customers? The government will screen new potential customers and then the vendor will be expetected to onboard them onto the service at the government's instruction.

29 What time period is required for getting immediate customers online with the service?

The DNS Resolver Service shall have the capability, with no restrictions, to accommodate additional customers as directed by the government, which include, but are not limited to: other non-DoD federal agencies, state and local governments, and organizations for whom the Government has authority for providing cyber security services. Vendor shall provide immediate customers online with service no longer than 48 hours after the government notifies the vendor of a new set of customers.

N

30 Would you further define the phrase "split VPN users"? This is a well defined industry term N

31 PWS Appendix 4.2.1 Pg. 4 How many threat feeds are required? Are there specific threat feeds the government would prefer to be used? Can these threat feeds include both open-source or commerically-paid sources?

The government reserves the right to request as many threat feeds as requried by the government needs. Threat feeds should include both open source and commericlally paid sources.

N

32 Will details of the pilot be provided to determine the number of instances required?

The prototype was to evaluate the feasibility of comboining commerical and government threat intellegence. Information about the prototype is not neccesarily applicable to this Performanace Work Statement.

N

33 What are the real-time dashboard requirements? Are there certain tools to be used or information which needs to be shown?

The expectation is when an administor logs into the system, there will be information provided on the domains blocked, expections to the block lists allowed, and performance metrics.

N

34 How many users at one time are expected to access the dashboard? The expectation is that this service will need the ability to scale. Therefore systems that are limited by the numbers of users will be evailabted less favoriably.

N

35 What are the "performance thresholds" required to provide the service? The data lake service shall maintain availability in a fully operational state of no less than 99.99% of the time within any annual period. The DNS resolvers must be capable of maintaining all logs and analytics data in an event where the data lake is not available. The DNS resolver service shall maintain availability in a fully operational state of no less than 99.999% of the time within any annual period.

N

36 PWS Appendix 4.2.1.1 Pg. 5 Define "optimal routing" requirements. This is a well defined industry term N

37 PWS Appendix 4.2.2.2 Pg. 5 Will a front-end for the service need to be built by the contractor that can apply global policies?

Yes. N

38 Are their location requirements for the redundant locations besides sub 60ms failover latency?

No. N

39 Is there a requirement to export and/or transfer information from the data lake downstream. If so, what are those requirements/processes?

Yes, please refer to PWS N

40 Who will administer the "different" rulesets for customers needing something besides the global policy?

The government will provide expections to global policy. N

41 Will any government personnel be given administrative rights over the tool? Yes. N

42 Pg. 6 How often will customer policies be updated? Would there be an SLA to upgrading individual customer policies?

The government expects the policies to be adaptable based on government needs.

The government does anticipate requireing an SLA.

N

43 PWS Appendix 4.2.1.3 Pg. 6 What organization will be in charge of making/approving global policy changes? The government will provide expections to global policy. N

44 Can the government provide guidance on these factors?If not, will the government accept a variable rate rather than FPP for Helpdesk support?

The Government will not accept a variable rate for helpdesk support N

45 Does the government have a preferred Helpdesk ticketing system? No N

46 Are there other SLA’s required for the Helpdesk other than the 2 hour response time?

While the government does not have a particular perferred method, please note that workability of the solution is something that will evaluated

N

47 PWS Appendix 4.2.2 Pg. 6 Are there certain threat intel sources that are required? Are there a minimum amount of various intel sources?

The government reserves the right to request as many threat feeds as requried by the government needs. Threat feeds should include both open source and commericlally paid sources.

48 Will the utilization of threat intel be the responsibility of contractor to block/unblock?

This will be a shared responsbility between the government and the vendor. N

49 What method is required for the downstream client to request a block/unblock to the service?

While the government does not have a particular perferred method, please note that technical requirement two specially evaluates user experience.

N

50 Pg. 7 Will the unblock/block of threat intel need to be human initiated or automatically done by system?

Both. The government will provide block lists that will be used to supplement commercial threat intellegence. The expectation is that block lists will be updated constantly based on threat intellegence. The government will require the ability to quickly unblock domains idenfited by end users.

N

51 PWS Appendix 4.2.2.1 Pg. 7 Will the contractor perform the analysis of the sinkhole data? This will be a shared responsbility between the government and the vendor. N

52 Will customers require access to sinkholes for troubleshooting? Yes, the government will require access to sinkholes. N

53 What are the requirements for housing/storing, accessing the data, and involving downstream organizations in sinkholing?

Please refer to 4.2.5.1 Data Lake Infrastructure N

54 What information is required to be gathered when using sinkholes? The government expects the solution to provide comprehensive information and this will be taken into account during evaluation under technical requirement one.

N

55 How many sinkholes need to be usable at any given time? As many as the government requires to respond to threats. N

56 PWS Appendix 4.2.2.2 Pg. 7 What means is already being used to identify and evaluate feeds before introducing them to production?

There is not a current means being used to identify and evaulate feeds before production. This will be a new service.

N

57 Will there be different threat feeds used based on each organization? No N

58 Will government furnished information be manually incorporated into the DNS blocking?

This should be programatic N

59 How long must threat intelligence data be preserved? See 4.2.5.1 Data Lake Infrastructure in PWS N

60 PWS Appendix 4.2.3 Pg. 8 Is there a communication or protocol framework to be used for communication with downstream protections?

There is no a current framework at this time. N

61 Does the service have the ability to initiate a block or will that need to be developed?

The prototype was to evaluate the feasibility of comboining commerical and government threat intellegence. Information about the prototype is not nessiesaly applicatle to this Performanace Work Statement.

N

62 Are content filtering subscriptions planned for a later deployment and not a requirement initially?

The government does not intend this service to block content, the only requirement is that this service does not prevent blocking content at client level.

N

63 PWS Appendix 4.2.4 Pg. 8 In addition to a real-time dashboard, ticketing/communication portal, there needs to be the front end of the data lake for querying and reporting separate from those webpages?

While the government does not have a particular perferred method, please note that workability of the solution is something that will evaluated

N

64 What are the datapoint requirements for generating reports? While the government does not have a particular perferred method, please note that workability of the solution is something that will evaluated.

N

65 How should alerts be provided to the customer? Through the portal or some other means?

While the government does not have a particular perferred method, please note that workability of the solution is something that will evaluated

N

66 Is PKI/CAC authentication methods requirements for supporting MFA? Strong multifactor authentication is required N

67 PWS Appendix 4.2.5 Pg. 9 Are there specific analytical information required for the data lake/dashboard? If so, what are they?

While the government does not have a particular perferred method, please note that workability of the solution is something that will evaluated

N

68 Based on the Pilot and prototype, how much storage wold be required to keep six months worth of logs?

The prototype was to evaluate the feasibility of comboining commerical and government threat intellegence. Information about the prototype is not nessiesaly applicatle to this Performanace Work Statement.

N

69 PWS Appendix 4.2.5.1 Pg. 9 Do we need explicit written consent to remove data after one year? Yes; at which time government may request export of data prior to deletion N

70 PWS Appendix 4.2.5.2 Pg. 10 How many users should be expected to have access to the data lake as opposed to using the dashboard/portal?

As many as the government requires to respond to threats. N

71 Should our eventual price proposal include estimations of cloud storage costs and data lake compute costs or will those be directly funded by the Government based upon their usage?

The price proposal should include these estimates. The pricing should be inclusive of all service.

N

72 Complying with the DISA SCCA and SRGs requires going through the CAP for an IL4 service. Is that the intention for how either the resolver or data lake would connect to the cloud service offering?

Just for the data lake N

73 In section 4.1.1, the RFQ says that only security threats will be blocked, but other parts of the solicitation mention Acceptable Use Policy and integrating with other Acceptable Use Policy efforts. Can the Government clarify whether the solution needs to include AUP categorization functionality?

The government does not anticipate needing to include AUP catagorization functionality. The government does not intend this service to block content, the only requirement is that this service does not prevent blocking content at client level.

N

74 In Section 4.2.5.1, the RFQ requires that downstream clients be hosted in the data lake. Can the Government give an example of the type or functionality of such a client?

Please refer to Technical Factor 1 N

75 Due to the IL4 requirements, does the login portal/customer dashboard need to support DOD PKI?

Strong multifactor authentication is required N

76 With the DoD enterprise as large as it is, can the Government clarify the role that they expect EDNS client subnet extensions to play and how that interacts with the anycast requirement?

Please refer to the Evaluation Technical Factor 1 N

77 Synopsis/

Solicitation

Instructions to Offerors Pg. 4 Are the explicit PWS requirements and method of surveillance text required to be included within our Technical response? If so, we would request that the page limit be extended to 30 pages.

The government views 30 pages as reasonable. An adjustment to the solicitation will be made to extend the page limit.

Y

78 Synopsis/

Solicitation

General Information

Original Date Offers Due: Aug 07, 2020 03:00 pm EDT beta.sam.gov Would the Government consider extending the due date to allow for time for responses to incorporate additional information, clarification(s), changes, etc. as a result of the answers provided for RFQ questions?

No N

79 Synopsis/

Solicitation

SF-1449, Pg. 20 Appendix 1 We note the incorporation of FAR 52.219-16 Liquidated Damages

Subcontracting Plan but query whether this is included in error as we cannot see the separate requirement to implement a Subcontracting Plan?

Correct, this clause was incorporated by error. Offerors are not required to submit the requirements of this clause with the proposal.

Y

80 Synopsis/

Solicitation

General Information beta.sam.gov To enable us to provide an appropriate response to the solicitation, we are requesting if an extension to the ‘Original Date Offers Due’ could be granted.

Our preferred response date would be August 31st.

No. N

81 Synopsis/

Solicitation

General Information beta.sam.gov The Government has requested contractors provide a response to Part I, Administrative, with unlimited page count. Please specify what information contractors are required to provide in the Part I response.

See provision 52.212-1(b) for details. N

82 Synopsis/

Solicitation

Price Evaluation Approach, Pg. 8 beta.sam.gov Please provide the Pricing Template and specify if this is to be submitted separately from Parts I and II, included within.

Please refer to Technical Factor 2, which states, "Offerors that are determined by the government to be viable competitors based on technical Factor 1: Written

Technical Solution Document and based on their performance in Technical Factor

2: Technical Usability Demonstration will be notified to complete Factor 3: Price.

N

83 N/A N/A N/A Is an incumbent contract or contractor associated to the requirement. If any, please provide the contractor's name and contract number?

This is a new requirement. Please review the PWS background section information.

N

84 N/A N/A N/A Could you please tell me if the Combined Synopsis/Solicitation posted as solicitation number HQ003420R0264 will be a follow-on requirement to any work performed currently or in the past, or will this be a new requirement?

No, Solicitation HQ003420R0264 is not a follow-on requirement to any work. This is a new requirement. Please review the PWS background section information.

N

85 N/A N/A N/A Could you please tell me if this is a new requirement, or if there is a current or previous contractor who has performed similar services? If available, can you please send along the incumbent contract or task order number?

This is a new requirement. Please review the PWS background section information.

86 N/A N/A N/A Considering the outstanding issues associated with submitted questions, contractors will require additional time to revise solutions and develop pricing that is most advantageous to the Government. Please extend the due date for proposals to 6 calendar weeks following the date when answers to questions and amended solicitation documents are available to contractors.

No. N

87 PWS Section 4.2.1.3

Section 4.2.4

Pg. 6

Pg. 8

Reporting - In addition to the requirement for ad-hoc reports specified, are there any periodic “canned” reporting requirements?

No. N

File details come from the government source that posted it. Updated .