ID11160019_-_DotGov_Questions_GSA_Response.pdf
PDF 297 KB Posted
- Attached to
- Dot. Gov Domain Name Registration and Analytical Reporting Services Federal contract opportunity
- Solicitation number
- ID11160019
About this file
GSA Response to Vendor Questions
View the file
Other files for this federal contract opportunity
| File | Type | Posted |
|---|---|---|
| GSA_Subcontracting_Plan.doc | DOC document | |
| ID11160019_-_RFP_DotGov_5-17-2016.pdf | ||
| SF30_Amendment_003.pdf | ||
| ID11160019_-_RFP_DotGov_5-5-16.pdf | ||
| SF_30_Amendment_002.pdf | ||
| SF30_Amendment_001.pdf | ||
| GSA_Subcontracting_Plan.doc | DOC document | |
| ID11160019_-_RFP_DotGov_5-17-16.docx | DOCX document | |
| ID11160019_-_RFP_DotGov_5-5-16.pdf |
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
Question
No
Proposal
Section Section Title Question Responses from Government
Section C.3.1 of the RFP states that "[the contractor shall facilitate Government and contractor communications; use industry best-standards and proven methodologies to track and
- Can the GSA please clarify "continuous monitoring and evaluation by the Government"?
GSA provides guidance on through the GSA IT
Security Procedural guide: Federal information
Security Modernization Act (FISMA)
Implementation, CIO-IT Security-04-26 DTD
May 9, 2016 and the GSA IT Security
Procedural Guide Plan of Action and
Milestones (POA&M), CIO-IT Security-09-44
Rev 3, and Maintaining the Assessment and
Acredition (A&A).
Section C.3.2.1 of the RFP states that the “GSA will provide a portal to access Internet Domain and Web information to include web policies, OMB Memoranda, How to procure Web Services,
- Can the GSA clarify that the GSA will maintain the content and host the portal referenced in
Section C.3.2.1 separately from the dotgov.gov portal that the contractor ?
Section C.3.8 of the RFP states that “..written procedures must explain in detail the new
DNSSEC implementation with detailed procedures on exactly what the current .Gov registrants
2 C3.2.1
GSA landing Portal with Two factor authentication
DOT.GOV RFP – Questions RFP# ID11160019
Domain Name System
Security
C.3.1 Program
Management Support
Yes, GSA will host and maintain a portal or marketplace that pulls together web services, tools to develop and maintain websites, web-site policies and Office of Management and
Budget (OMB) memoranda with the included
"button"/access point to .gov domain registration and renewal (the dotgov.gov portal) that the Contractor will maintain.
C3.8
The current information in the FAQ section is adequate. If a new contract is to provide the
Trust Anchor and Signing Service, they need to provide information and processes required by delegation holders / users to interface with them to get their zone signed. The procedure will only identify information or activities / processes that the contractor requires for providing the services.
C.3.1.1
Subtask 1 Kick-off Meeting
Section C.3.1.1 states that the “GSA shall outline all the security testing required for accreditation”. Can the GSA please clarify that if a contractor currently has an A&A certification, such certification is sufficient to meet this requirement or whether such contractor would need to obtain a new A&A certification at the time of contract award?
If the current Contractor is awarded the contract, the current A&A is good through the timeframe of that A&A which expires in July
2017. The Current A&A is only authorized for the current Contractor. Any new Contractor will require a new Assessment and
Acreditation (A&A).
5 C.3.2.1
Subtask 1 - GSA
Landing Portal with
Two Factor
Authentication
Section C.3.2.1 of the RFP states that "GSA will provide strong two-factor authentication through the OMB's https:\\www.max.gov for all registrants and Federal agency users to include support for authentication to the website via PIV and CAC credentials. Compliance may be achieved through an assertion based model aligned with NIST SP 800-63 Section 9 to include support for SAML 2.0 Web SSO Standards and one or more integrations with a government
Authentication service;"
- Can the GSA please clarify that if integration with a government authentication service is
GSA will be responsible for entering into an
MOU and ISA with MAX.gov for authentication.
6 C.3.2.1
Subtask 1 - GSA
Landing Portal with
Two Factor
Authentication
Can the GSA clarify whether the migration to Two Factor Authentication will require any re-certification related to A&A activities?
No, the A&A is boundary driven and the MAX two factor authentication services have their own A&A
Section C.3.5 of the RFP states that “[g]eneral support system infrastructure will also be
Can the GSA please clarify that only systems identified in the .gov boundary scoping document as part of the A&A certification package would be included in the general support system
Correct, the boundry is only the infrastructure maintained by the Contractor.
- Can the GSA please clarify if the GSA will create written procedures for DNSSEC implementation that the contractor will "maintain and update"?
Domain Name System
Security
C3.8
C.3.5 Task 5 – System
Security
Section C.3.2.1 states that GSA/MAX (i.e., max.gov) will provide all login accounts and passwords. The assumption is that .gov customers will contact the vendor for all other issues.
How will .gov customers be informed about the support provided by GSA/MAX and the support provided by the vendor and whether such customer should contact GSA/MAX or the vendor based on the issue such customer has?
The Government will identify clearly on the website how to get support for specific issues.
For login/password support, the customer will be directed to contact MAX support. The customer will be directed to contact the
Vendor via registrar@dotgov.gov / 1-877-REG-
GOVT for all other domain related questions.
Can the GSA please clarify how max.gov will support .gov customers?
MAX will support .gov customers with login / password set-up, reset, and account creation.
The MAX authentication tool will be used as the login for agency representatives to access their domain information registered with dotgov.gov.
*What are the support hours and service levels for max.gov?
Support hours: Weekdays available 24 hours, and live support available 8:30AM-9:00PM.
Weekends available all hours except Sundays from 2:00 AM-8:00 AM Eastern Time (ET), and live support available 9:00 AM-6:00 PM
(ET)(responses shall be within 1 hour from issue/outage). There is a snapshot (read-only mirror) site available during outage hours.
* Will there be escalation management between max.gov and contractor?
If there is a situation that would need escalation contact starts at the MAX help desk level, then escalates to the production teams and GSA as needed. Also the Contractor is welcome to contact MAX support directly if there is an issue. Max.gov has in place a snap-shot (read-only) mirror site that is available during outages.
C.3.2.1
Subtask 1
GSA Landing Portal with Two Factor
Authentication
* Will they offer online assistance for .gov customers on their site?
MAX has email and phone support as listed above, as well as some help and documentation pages on MAX.gov.
Section C. 3.2 (tenth sub bullet) of the RFP states that “Frequently Asked Questions (FAQs)”?
Can the GSA please clarify if the contractor or GSA are responsible for creating the content associated with the FAQs?
FAQ's content will be developed by both GSA and the Contractor, as certain FAQ's are related specifically toward OMB guidance or
MAX Authentication. GSA will provide these responses and share all the FAQ's already published.
Has a contractor performed similar work to this for the government in the past? If available, please provide the incumbent contract number.
Work is currently being performed under
GS11Q16BJC0001
Section
C.3.2
Website Management and Administration
C.3.2.1
Subtask 1
GSA Landing Portal with Two Factor
Authentication
File details come from the government source that posted it. Updated .