IT_Security.pdf
PDF 105 KB Posted
- Attached to
- FEMA INFORMATION TECHNOLOGY INDUSTRY DAY Federal contract opportunity
- Solicitation number
- HSFE30-15-S-0001
About this file
Information Technology Security
View the file
Other files for this federal contract opportunity
Show all 44
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
Industry Day Questions IT - Security
Question Answer
Will the Government be using TABSS, Domain 1, Track 3 – 8a for the IT/Information Security procurements (ISSO, SOC, Assessment and
Authorization Support)?
FEMA will not be using Technical, Acquisition and Business Support Services (TABSS) IDIQ, Domain
1, Track 3 for any of the Cyber Security solicitations.
Can FEMA provide a more detailed timing/schedule of procurements, AND any
Conflicts of Interest among the procurements, to allow bidders to appropriately develop procurement strategies and teaming? For example, will the ISSO support contract and the Assessment and Authorization support contract be mutually exclusive?
The IT Security contracts are scheduled to be released late Spring 2015 subject to finalization of requirements and CIO approvals. Vendors may submit proposals against all IT Security SOWs. If a vendor wins the SOC or A&A contract, they will not permitted to prime or subcontract to any of the other IT Security contracts. The winner of ISSO and EM&T SOW can serve as a prime and subcontractor to each other; however, selectee cannot prime on another OCIO contract. This OCI does not preclude the vendor from being a subcontractor on another OCIO contract.
Additional information will be available prior to release of non-IT Security contracts.
What are the security artifacts that ADES needs to provide to support the Information Technology
Security contract?
Prior to releasing the final SOWs, the government will evaluate and release SOWs based upon the government requirements.
What other A&A responsibilities will the ADES contractor have?
Prior to releasing the final SOWs, the government will evaluate and release SOWs based upon the government requirements.
Question Answer
The Assessment and Authorization Support SOW’s section 1.0, Introduction, briefly describes a set of services and support requested by the Government, including A&A Support (Security
Independent Verification and Validation) and A&A Support (Cyber Security Resiliency). • Section 2.2, Task 2, Agent of the Certifying Authority/Risk Executor Support Services, includes activities that overlap ISSO services (“functions that may potentially overlap with existing ISSM/ISSO personnel functions assigned to Information Systems”).
• Section 2.3, Task 3, Documentation Management, Policy, Guidance and Publication
Support, includes activities that overlap with ISSO services, including “The Offeror shall develop new security documentation as required by the Government and maintain existing NIST/DHS
Security Authorization.”
Prior to releasing the final SOWs, the government
Question Answer
Given the current description of sections 2.2 and 2.3, Mission/Objectives/Goals, and FEMA’s desire to have independent verification and validation of management, operational, and technical security controls, there is an inherent OCI for a vendor performing services across both task areas. Based on the desire for independence, would FEMA move requirements from Section 2.3, Task 3, A&A
Support (Cyber Security Resiliency), to the ISSO SOW to maintain independent and nonbiased assessments of documentation management, policy, guidance, and publication support services?
The task will not be moved to ISSO SOW. The vendor may be required to draft security artifacts in support of expedited authorization effort.
The Emerging Technology and Modernization SOW relates primarily to Cyber Security. Is this intentional or will there be further clarification on supporting FEMA IT system modernization with emerging technologies from an IT Architecture perspective?
The Emerging Technology & Modernization SOW will not expand to support other FEMA IT system modernization efforts. The vendor will be consulting on cyber security topics, such as but not limited to security architecture, new technology, etc.
Analytics à consider implementing solutions to crunch data to understand emerging threats.
FEMA is open to considering all solutions that will enable FEMA mission.
Incumbent information for reach of the program areas? Contractor name and contract number.
IBM - HSFEHQ-08-J-2009
eGlobalTech - HSFEHQ-10-D-0390 BAE Systems - HSFE30-14-J-0354
NSS Plus - HSFE30-14-J-0354 Will you consider a mid-size NAICS code such as
5177110 (up to 1500)? This is still la small business code but allows you to draw from allurer company pool.
Prior to releasing the final SOWs, the government
Question Answer
Will you post the attendees list?
Yes, FEMA already posted the attendees on
FBO.gov.
Would you entertain demos of capabilities such as Cyber Threat Analysis on Inside Threat Analysis prior to the RFP in order to determine if you are interested in incorporating these requirements in the RFP?
The government may entertain demos of capabilities as time permits.
Is there an opportunity for at least one of the IT solicitations to be full & open?
Prior to releasing the final SOWs, the government will evaluate and release SOWs based upon the government requirements.
Recognizing that FEMA is seeking to procure IT – Security services vice socio-economic set-aside, will RFI or sources be used to facilitate FAR 10
Market Research to inform the socio-economic set-aside selection.
FEMA hopes to release the final solicitation in the Spring 2015. Therefore, FEMA may not have time to request RFIs.
Defense Point Security – Will all technology be GFE within the SOC etc or will FEMA entertain CRE monitoring solutions?
All solutions and technologies within the SOC will be GFE.
Does FEMA expect this to be an FFP or T&M style contract?
Prior to releasing the final SOWs, the government
Question Answer
Will there be OCI language provided that would prevent vendors from receiving multiple tracks for example: Will the PMO provider be prohibited from primary additional tracks?
If a vendor wins the SOC or A&A contract, they will not permitted to prime or subcontract to any of the other IT Security contracts. The winner of
ISSO and EM&T SOW can serve as a prime and subcontractor to each other; however, selectee cannot prime on another OCIO contract. This OCI does not preclude the vendor from being an subcontractor on another OCIO contract.
Additional information will be available prior to release of non-IT Security contracts.
For small business set aside like SBA 8a, can you allow CMMI level II or ISO Certification requirements can be valid if SBA 8a firm can demonstrate their capabilities in such area from one of their teaming partners?
Neither, CMMI Level II nor ISO Certification is a requirement of the IT Security line of business.
Arch Reference Model – built internally or externally or combo? When will it be competed?
FEMA's Cyber Security Architecture model is being developed internally utilizing existing federal and contract staff.
Up to what date will you be taking meetings in advance of the RFP?
As time permits, FEMA may be taking meetings.
What is the best way to educate FEMA on a new capability for Mobile Device Security?
The offeror must determine how best to present new capabilities.
Question Answer
As a small business will it be possible to bid on all 4 subordinate areas within IT security? What might the boundaries be?
Yes, a vendor may bid on all 4 SOWs. However, if a vendor wins the SOC or A&A contract, they will not permitted to prime or subcontract to any of the other IT Security contracts. The winner of ISSO and EM&T SOW can serve as a prime and subcontractor to each other; however, selectee cannot prime on another OCIO contract. This OCI does not preclude the vendor from being a subcontractor on another OCIO contract.
Additional information will be available prior to release of non-IT Security contracts.
Do you plan to use any GSA Schedules or will this be an open set aside?
Prior to releasing the final SOWs, the government will evaluate and release SOWs based upon the government requirements.
Have you identified the socioeconomic set aside you plan on using for these acquisitions?
Not at this time. Prior to releasing the final SOWs, the government will evaluate and release SOWs based upon the government requirements.
We in house security products and would like to demo an introduce FEMA to Cyber Attack?
Due to time contracts, the government will not able entertain demos of capabilities.
Where is the draft SOW posted? FBO.gov
Would FEMA consider implementations data access and credentials in the network layer to streamline application development and enhance dynamic data access changes?
All solutions that support the FEMA mission will be considered.
Implementing shared service model for IT Security Assessment and Privacy.
All solutions that support the FEMA mission will be considered.
Question Answer
Business Integra been awarded the FAA Information Security Privacy Program of interest
FAA selected Business Integra because of our innovation Technology Offering of Shared Services for Security Assessment and Privacy.
All solutions that support the FEMA mission will be considered.
What is the estimated award value of the four security contracts?
The government is still developing the requirements for the SOW; this information is not available.
Would FEMA consider opening one of the procurements to other than small. Primary mid-size with short sub-contracting requirements?
Prior to releasing the final SOWs, the government will evaluate and release SOWs based upon the government requirements.
OCI between the various security procurements?
A vendor may bid on all 4 SOWs. However, if a vendor wins the SOC or A&A contract, they will not permitted to prime or subcontract to any of the other IT Security contracts. The winner of ISSO and EM&T SOW can serve as a prime and subcontractor to each other; however, selectee cannot prime on another OCIO contract. This OCI does not preclude the vendor from being an subcontractor on another OCIO contract.
Additional information will be available prior to release of non-IT Security contracts.
Size ($$ and FRE’s) conversely in each one of the tracks.
The government is still developing the requirements for the SOW; this information is not available.
Would FEMA consider biometrics such as voice prints and facial image as additional factors in validating identity of state, local, territorial, tribal and volunteers?
Prior to releasing the final SOWs, the government
Question Answer What are you worried about? What cyber security issues keep you up at night?
Our concerns are contained within Section 1.0 of all the SOWs.
In arisen situations, how do you balance the need to connect people and fast responders quickly with security?
All decisions are risk-based, which requires an understanding of FEMA's mission, the environment, security requirements, and other important factors.
How to do business with FEMA?
Please refer to http://www.fema.gov/pdf/privatesector/doing_b usiness_fema.pdf
IT - Security
File details come from the government source that posted it. Updated .