ID11160019_-_RFP_DotGov_5-17-16.docx

DOCX document 191 KB Posted

Attached to
Dot. Gov Domain Name Registration and Analytical Reporting Services Federal contract opportunity
Solicitation number
ID11160019
Issued by
General Services Administration Federal Acquisition Service Assisted Acquisition Services

About this file

Amended RFP

View the file

Other files for this federal contract opportunity

Other files attached to Dot. Gov Domain Name Registration and Analytical Reporting Services, newest first.
File Type Posted
GSA_Subcontracting_Plan.doc DOC document
ID11160019_-_RFP_DotGov_5-17-2016.pdf PDF
SF30_Amendment_003.pdf PDF
ID11160019_-_RFP_DotGov_5-5-16.pdf PDF
SF_30_Amendment_002.pdf PDF
SF30_Amendment_001.pdf PDF
GSA_Subcontracting_Plan.doc DOC document
ID11160019_-_DotGov_Questions_GSA_Response.pdf PDF
ID11160019_-_RFP_DotGov_5-5-16.pdf PDF

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

SECTION M – EVALUATION FACTORS FOR AWARD

REQUEST FOR PROPOSAL (RFP)

ISSUED TO:

ISSUED BY:

General Services Administration National Capital Region 7th & D Streets, SW Washington, D.C. 20407

DOT.GOV

Domain Name Registration and Analytical Reporting Services

IN SUPPORT OF:

THE GENERAL SERVICES ADMINISTRATION (GSA)

OFFICE OF GOVERNMENT-WIDE POLICY (OGP)

OFFICE OF INFORMATION, INTEGRITY, AND ACCESS (OIIA)

NCR Project Number ID11160019

B.1 GENERAL

The work shall be performed in accordance with all Sections of this RFP. The principal nature of the requirements described in this solicitation is consistent with services performed by industries in the 518210 with a size standard of $32.5 mil.

The services in this solicitation are best represented by PSC Code D322.

B.2 ORDER TYPES

The contractor shall perform the effort required by this RFP on a Firm-Fixed-Price (FFP) basis for CLINs 0001, 1001, 2001, 3001, 4001. The work shall be performed in accordance with all Sections of this RFP.

B.3 SERVICES AND PRICES/COSTS

The following abbreviations are used in this price schedule:

CLIN
Contract Line Item Number
FFP
Firm-Fixed-Price

B.3.1 BASE PERIOD:

FFP CLIN

CLIN
Description
QTY
Unit
Total Firm Fixed Price
0001
Domain System and Analytical Reporting Services – Base Year
12
Months
$
1001
Domain System and Analytical Reporting Services – Option Year One
12
Months
$
2001
Domain System and Analytical Reporting Services – Option Year Two
12
Months
$
3001
Domain System and Analytical Reporting Services – Option Year Three
12
Months
$
4001
Domain System and Analytical Reporting Services – Option Year Four
12
Months
$

GRAND TOTAL $_______________

SECTION B – SUPPLIES OR SERVICES AND PRICES/COSTS

Request for Proposal ID11160019 PAGE B-2

C.1 BACKGROUND

The General Services Administration (GSA), Office of Government-wide Policy (OGP) and Office of Information, Integrity, and Access (OIIA), is responsible for the policy, operations, management and direction of the .Gov Internet Domain Registry and also is responsible for the (only).Gov Registrar Service for domain name registrations by Federal agencies, State and Local governments, and Native Sovereign Nations (NSNs).

As the designated sponsor of the .Gov generic Top Level Domain (gTLD), GSA is the official “policy authority” vice internet Corporation for Assigned Names and Numbers (vice ICANN). GSA’s registry and registrar requirements confirm with those of ICANN, unless otherwise specified in this Statement of Objectives (SOO). Registration requests are serviced by way of web-enabled applications hosted at https://dotgov.gov. Currently, there are approximately 5,000-6,000 domains within the .Gov gTLD.

C.1.1 STATEMENT OF OBJECTIVES

The GSA is seeking contractor support to manage, and perform the functions of a Domain Name Registry and Registrar Service for Federal agencies, State and Local governments, and NSNs under the sponsored gTLD of .gov (provide gTLD as a service). Under the direction and oversight of the .gov Policy Authority, the Contractor shall be responsible for:

· Performing all responsibilities associated with operating, managing and maintaining the exclusive domain name registry and registrar services for the .gov gTLD to include but not limited to:

· Perform Registrar services to assist in registration of domains.

· Hosting the website portal https://dotgov.gov.

· Help Desk: To include acceptance and storage of Authorization letters, setting up point of contact (POC) accounts, assisting customers with accounts, registration, and domain management operations.

· Access to data: The Contractor will provide mechanisms for the GSA project management staff to query and run reports on the domain database to include but are not limited to:

· Individual domain query;

· Query by user;

· Query by agency;

· Weekly Report of domain activity (Registrations, Renewals, Deletions, Activations);

· Yearly report (Registrations, Deletions, Activations); and

· Report by Type of domain (Federal, NSN, State, County or City)

· Perform registry operations to include but limited to maintaining and safeguarding the database of all domain information and zone files.

· Employ and assist customers in establishing and managing Domain Name System Security (DNSSEC) services, to include all key management and rollover.

· Performing all responsibilities at a service level that ensures high security, high stability, and high resiliency of registry services and the integrity, availability, and confidentiality of .gov zone file data.

· Perform all responsibilities associated with the collection of domain name registration and renewal fees.

· Perform Domain Name System (DNS) Resolution:

· Minimum DNS resolution to average volume of 8 billion transactions, with the ability to surge at least five (5) times to 40 billion transactions per month.

· DNS attack mitigation capabilities

· A minimum of five (5) dedicated resolution centers throughout the Continental United States (CONUS) are required to maximize resolution performance.

C.1.2 AGENCY MISSION

The GSA provides, as one of its business lines, an Internet Domain Registration Service for Federal, States and Local Governments, and Native Sovereign Nations (NSNs). Domain registrations (DOTGOV and .FED.US) were delegated to the GSA by the National Science Foundation through consensus of the Federal Network Counsel and Department of Commerce on October 1, 1997.

C.2 SCOPE

The .Gov registry and registrar is a major information system and categorized at a Federal Information Processing Standard ( FIPS) 199 High Impact, and thorough security test & evaluation (or security assessments) will be required as part of the authorization process.

GSA requires that various tasks be performed as part of three key processes:

· Preparation;

· Certification; and

· Authorization.

The completion of these activities will assure that appropriate security and availability measures are identified and implemented to counter threats and vulnerabilities to the .gov gTLD, as well as to promote secure information sharing.

The registry, including registry infrastructure services, registrar, registrant support services and related services must be reliable, secure, and remain in compliance with government and industry requirements as outlined in this SOO. Additionally, the contractor shall use verifiable business practices, physical and logical security controls, and management controls to ensure the security, stability, and resiliency of the systems and the confidentiality, integrity, and availability of the data.

The contractor shall demonstrate the capacity to operate a fully functional gTLD registry, within the global DNS pursuant to all requirements, policies, and practices prescribed for TLDs under pertinent Request For Comments (RFCs) under the authority of ICANN, Internet Assigned Numbers Authority (IANA), and related policy bodies.

C.3. OBJECTIVES

C.3.1. Task 1 - Program Management Support The contractor shall provide program management support that includes the management and oversight of all activities performed by contractor personnel, including subcontractors, to satisfy the requirements identified in this SOO. The contractor shall identify a Program Manager (PM) by name that shall provide management, direction, administration, quality assurance, and leadership of the execution of the .Gov requirement.

The contractor shall facilitate Government and contractor communications; use industry best-standards and proven methodologies to track and document .Gov requirements and activities to allow for continuous monitoring and evaluation by the Government; and ensure all support and requirements performed are accomplished in accordance with the SOO. The contractor shall notify the Contracting Officer Representative (COR) and Government Program Manager (PM) of any technical, financial, personnel, or general managerial problems encountered throughout the period of performance (PoP).

The contractor shall provide strategic enterprise-level guidance that integrates support across all task areas; ensure support is in accordance with the SOO requirements.

C.3.1.1 Subtask 1 - Kick-Off Meeting The contractor shall schedule and coordinate a Project Kick-Off meeting at the location approved by the Government within ten (10) business days after contract award. The meeting will provide an introduction between the contractor personnel and Government personnel who will be involved with the requirement. The meeting will provide the opportunity to discuss technical, management, and security issues, and travel authorization and reporting procedures. At a minimum, the attendees shall include Key contractor Personnel, representatives from the GSA OGP, other relevant Government personnel, and the COR.

GSA shall outline all the security testing required for accreditation (if required), and the contractor shall discuss their understanding of the project, and review the background information and materials provided by the government. Discussion shall also include the scope of work to be performed, the deliverables to be produced, how contractor work efforts will be planned and organized, and what assumptions are being made jointly by the government and the contractor before work commences. A concerted effort shall be made by the contractor to gain a thorough understanding of the government’s expectations.

C.3.1.2 Subtask 2 – Briefings Upon request, the contractor shall prepare a summary briefing and present it to the GSA .Gov Program Management team. The Department of Homeland Security (DHS) and other federal entities and their representatives may attend the briefings. Details of this briefing shall be on the results of efforts performed under this contract. In addition, the contractor shall provide a quarterly formal program review briefing, known as the .Gov In-Progress Review (IPR) ninety (90) days following each formal review; the operator shall file updated pertinent performance statistics and DNSSEC activity. Briefings will be conducted at a minimum of once per quarter and may occur more frequently to meet the needs of the Government.

C.3.1.3 Subtask 3 - Meetings The contractor shall attend meetings and briefings with government/Non-government entities as requested by the government. Generally all meetings and briefings will be conducted at the .Gov Program Office located in Washington, DC or contractor’s site, but the government may stipulate other meeting and briefing locations, or may request teleconferences as appropriate. Meetings may be held at Contractor’s facility if consent by DotGov Program Manager is granted. Meetings will be conducted at a minimum of once per month.

C.3.1.4 Subtask 4 – Quarterly Revenue Reports The contractor shall be required to provide Quarterly Revenue Reports on the 15th of the month following the last business day of the quarter. The contractor shall submit a Quarterly Revenue Report identifying revenue delineated by source and revenue type. Also required are registration fees if any, in arrears.

C.3.1.5 Subtask 5 – Ad-Hoc Reports and Queries The Government may request a special report on .gov data and/or activities such as, but not limited to: database queries relating to total number of domains supported by the system; domains owned by a particular agency or state/county/local or NSN government; approved domain names in the database or for a particular agency or state/county/local or NSN government. The number of reports will not exceed 1 per month or 12 in a year. The Government may also request backup or recovery of specific or all records. The Contractor shall provide periodic performance reports such as weekly, monthly and yearly reports to denote additions, deletions, registrations, overdue payments, and domain totals by category, to be made available to Management personnel online and on demand. These reports should be able to be run by Government personnel through a menu of options.

C.3.2. Task 2 – Website Management and Administration The Website (www.dotgov.gov) is the entry point for .gov Internet domain management and registration services. The Contractor shall host the Website and provide the requisite network management services as appropriate for the level of mission criticality and information sensitivity. The Contractor shall also be proactive and make recommendations for improving the level of service, content quality, and value to the Government.

At a minimum, the Contractor shall perform the following work requirements:

· Operation and maintenance of the http://www.dotgov.gov registration Website and supporting infrastructure. A redundant failover/backup site shall also be provided. In the event of a catastrophic failure or other service disruption at the primary site, the failover/backup site shall continue all operations with limited interruption.

· Operation and maintenance of the WHOIS directory service.

· Operation and maintenance of the DNSSEC analyzer tool for agencies to determine if a .gov domain name is signed with a Domain Name System Security Extension.

· Operation and maintenance of provisioning systems to a minimum 99.9% uptime per month, and resolution systems to 100% per month.

· Location of all provisioning sites within the continental United States (CONUS).

· Operation and maintenance of at least one failover/backup site for the registrar, registry, and all related systems, with the ability to failover all resolution sites within 10 minutes, and 100% of all services within 90 minutes. The failover/backup site shall be hosted on a separate power grid and telecommunications network and not less than 100 miles from the primary site. The Contractor should also take into consideration any other factors that may be relevant (e.g. seismic zones) to best ensure that the failover site is at a location that will remain operational in the event the primary site is not.

· Development and maintenance of a disaster recovery/continuity of operations plan in accordance with National Institute of Standards and Technology (NIST) Special Publication (SP) 800-34.

· The website will be able to show / report fees per domain per their respective group of Federal agency, State and Local governments, or NSN jurisdiction(s).

· Development and submission of regular audits and reports (including modifying filing, archiving, and securely submitting the .gov zone file to the respective root name servers).

· Frequently Asked Questions (FAQs):

· Responsiveness to ad hoc requests for additional zone file updates as a result of an emergent, high priority domain name request, to be available within one hour to the Internet upon notification by the government.

· A Strong two-factor authentication meeting NIST SP 800-63 Level of Assurance 4 requirements for all Privileged users involved in managing the solution infrastructure inclusive but not limited to any databases, websites, servers, or hosting environment involved in solution delivery and operations;

Any website or web application development must meet the following requirements.

The websites or web applications must work correctly in all GSA supported browsers and platforms. This includes:

· Internet Explorer 9 and above on Microsoft Windows

· The two latest versions of Google Chrome on Microsoft Windows and Mac OS X

· The two latest versions of Mozilla Firefox on Microsoft Windows and Mac OS X

· Safari 6 and above on Mac OS X

· iPhone, iPad, Android phones and tablets

The websites or web applications must meet Web Content Accessibility Guidelines (WCAG) 2.0 A, AA, and select AAA standards. The site must use well-formed, semantic code, including HTML5, CSS3, and unobtrusive scripting.

C.3.2.1 Subtask 1 - GSA Landing Portal with Two Factor Authentication No later than 6 months past contract award GSA will activate a new Web Services landing page. GSA will provide a portal to access Internet Domain and Web information to include web policies, OMB Memoranda, How to procure Web Services, etc., and a Domain Registration and Domain Management Button / Icon. GSA will provide user authentication and login mechanism for all users.

· Seamless integration and transition from bifurcated system of GSA hosted information to Contractor hosted information and database systems with Contractor adhering to use of GSA federal web policies

· GSA will provide strong two-factor authentication through the OMB’s https:\\www.max.gov for all registrants and Federal agency users to include support for authentication to the website via PIV and CAC credentials. Compliance may be achieved through an assertion based model aligned with NIST SP 800-63 Section 9 to include support for SAML 2.0 Web SSO Standards and one or more integrations with a government Authentication service;

· GSA / MAX will provide all login accounts w/ temporary passwords. All password reset and update will be serviced through MAX authentication services.

C.3.3. Task 3 – .GOV Help Desk Support and Domain Management C.3.3.1 Subtask 1 – Help Desk Support The contractor shall provide the necessary support to assist in resolving customer issues. The contractor will staff a live program help desk and provide customer service via a toll-free number and e-mail. The contractor must initiate either a return phone call or an e-mail reply to the customer within two business hours of initial contact by the customer. At present, an average of six hundred (600) helpdesk calls/emails are serviced each month and the customer database consists of approximately 13,000 customers. The contractor shall keep an electronic log of all calls/emails received by the .Gov helpdesk. Help Desk Hours will be manned from 7 AM to 7 PM M- F EST. Emergency notification and assistance will be available 24/7/365.

The Contractor will provide timely support from a Help Desk, with public switch telephone network (PSTN) voice and, email. The Contractor shall also maintain such specialized communications facilities as may be required to support sensitive, security related registrants’ services, such as satellite phones.

C.3.3.2 Subtask 2 – Domain Management Services The contractor shall provide services including, but not limited to:

· 24/7/365 technical assistance to registered points of contact, auditing and reporting, modifying, filing/archiving, and securely submitting the .Gov zone file to the respective root-nameservers. Data input by contractor shall be checked for validity to insure the correct .Gov domain name is activated for the customer.

The zone file updates shall be submitted at a minimum twice daily, to include all DNSSEC records. The GSA PM may request an additional zone file update as a result of an emergent, high priority domain name request, which must be pushed out to the Internet upon notification by the Government.

C.3.4. Task 4 – Dynamic Domain Name System and Analytical Reporting Services The Contractor shall provide a comprehensive subscription service for dynamic DNS analytic and reporting services in direct support of managing the .gov domain space for the government. Data points that satisfy the robustness of the subscription service are listed below. The subscription shall be secured, including encryption at rest and in transport. The scope of services to be acquired from this subscription includes:

· Summary and detailed reporting data for metrics such as DNS traffic data,

· Performance indicators to facilitate the identification of performance and usage trends,

· Technical support and tool enhancements,

· Special ad hoc reports to meet dynamic government requirements, (e.g. rate of IPV6 adoption by federal agencies.)

There will be a minimum of one report per month with an option of at least 12 ad-hoc reports per year.

Reports must be made available in machine-readable data formats, such as JSON or CSV.

Data points to be collected, recorded, and reported should include:

· Functionality (e.g. determine whether a given domain is functional);

· Geographic location of all servers that directly host web services on the .gov gTLD (this pertains to servers directly in support of the services, i.e. the standard caching of DNS information by edge service providers is exempt);

· Ownership and fee collection status of .gov domains ;

· Web server hosting details;

· Domain redirects, and if so, to where;

· DS Records (where they exist),;Certificates, issuer, date of expiration;

· Certificate, type and provider;

· IPv6 adoption analysis;

· Traffic scores;

· List of subdomains;

· Possible security identifiers, showing trends toward malware or dysfunction; and

· Statistics on potentially malicious traffic designed to either exploit the DNS system itself or as other indicators of compromise, and such potentially malicious command and control servers.

Other potential metrics may be discussed, defined, and agreed to by the Contractor and the Government over the life of the contract. In addition, the Contractor is expected to propose potentially valuable metrics based on industry experience and best practices.

Government data rights of software deliverables shall be in accordance with FAR 52.22719 Commercial Computer Software License and/or FAR 52.22714 Rights in Data General. Ownership of data entered into any and all systems, system documentation, all deliverables produced in the performance of this contract, and other related system information shall reside with the Government.

C.3.5. Task 5 – System Security C.3.5.1. Subtask 1 – Information Security Requirements The Contractor shall be responsible for adhering to all NIST Special Publications and Standards, Office of Management and Budget (OMB) circulars and memoranda, the Federal Information Security Management Act of 2002 (FISMA), and all revisions and updates thereof.

The Contractor shall provide all Assessment and Accreditation (A&A) support documentation to support the testing of the security controls of the system at the FIPS 199 High Impact level; as well as to ensure the system's functional needs satisfies Federal security mandates for the processing of Controlled Unclassified Information (CUI) and protection of sensitive data.

All medium and high findings/vulnerabilities shall be remediated prior to the Accreditation decision by the Authorizing Official.

The contractor shall ensure that the documentation remains current throughout the system life cycle. Re-certification is required every three (3) years or any time that sufficient changes to the system's software, hardware, or firmware has occurred. GSA will contact the Program manager to ensure a update to the A&A is accomplished. The GSA program manager and the Contractor will work to accomplish the task by the end of the 3 year ATO date.

The contractor shall support the testing of the security controls in the system in accordance with the most current version of NIST 800-53 (currently revision 4) and NIST 800-53A. In addition, the contractor will need to be prepared to host penetration testing activities, including the use of government red teams. The contractor shall include their primary and backup (or “failover”) sites as both will be reviewed and tested.

Automated scans can be performed by government personnel or agents acting on behalf of the government using government operated equipment and government specified tools. GSA will schedule the Scan with the Contractor. If the Contractor chooses to run its own automated scans or audits, results from these scans may, at the Government’s discretion, be accepted in lieu of government performed vulnerability scans. In these cases, scanning tools and their configuration shall be approved by the government. In addition, the results of Contractor-conducted scans shall be provided, in full, to the Government.

Review activities include but are not limited to: operating system vulnerability scanning, web application scanning, and database scanning of applicable systems that support the processing, transportation, storage, and security of federal information. General support system infrastructure will also be included and verified.

The Contractor shall initiate work on this A&A requirement by meeting with key client agency representatives (GSA PM and GSA IT Security), to include GSA’s A&A Contractor, to ensure that a common understanding of the requirements, expectations, and ultimate end products exists between all parties. The Office of the Chief Information Officer (OCIO) and A&A Contractor shall conduct all the security testing required for accreditation.

The Contractor shall comply with all the requirements referenced in the GSA publication: "Security Language for IT Acquisition Efforts - CIO IT Security 09-48[footnoteRef:1].” The Contractor shall provide only personnel who have completed and passed a Federal National Agency Check with Inquiries (NACI) background investigation. The Contractor shall provide and support overall Infrastructure Security efforts which include all aspects of Technical, Operational, & Management Security. This task requires the Contractor to manage the current and future security efforts without compromising security. [1: Security Language for IT Acquisition Efforts - CIO IT Security 09-48 - GSA guidance on purchasing IT Products and Services]

The Contractor shall assist GSA in the compilation and documentation of the potential risks, and assist in the development of a Risk Management Plan. The risk management plan shall be reviewed with the COR and DotGov Program Manager at least semi-annually. This plan shall identify the potential risks and probability of occurrence consistent with the environment proposed.

All data shall be protected against unauthorized disclosure, modification, theft, and destruction in accordance with all applicable National Institute of Science and Technology (NIST) guidelines, but in particular NIST SP 800-81-2.

The Contractor shall be responsible for providing documentation that demonstrates that the system has been certified to be in compliance with all applicable NIST, GSA and Federal regulations and guidance throughout the life of the contract. The Contractor shall maintain the documentation and ensure that the documentation remains current throughout the system life-cycle.

· All requisite A&A support documentation shall be completed on demand within the timeline of each A&A segment as outlined in the A&A deliverables list and delivered to the COR for review and forwarding to the GSA Approving Official (AO) for the accreditation decision.

The contractor shall be responsible for correcting any identified security short-falls within the time specified by the OCIO, Information Security Office. The AO is the GSA Chief Information Officer (CIO).

The contractor shall be responsible for reporting cyber security incidents to the US -CERT. through the OCIO Information Security Office.

C.3.5.2. Subtask 2 – A&A Deliverables:

In completing and documenting the various A&A-related tasks, the contractor shall be required to develop and maintain the following A&A required documents in accordance with applicable National Institute of Science and Technology (NIST) Special Publications and/or GSA guidelines:

1. The System Security Plan shall be prepared no later than 120 days after award and undated annually or as system/environmental changes occur in accordance with the most current version of NIST Special Publication 800-18, Guide for Developing Security Plans for Information Technology Systems. The SSP shall include as appendices:

· A completed GSA 800-53 Control Tailoring worksheet included in Appendix A of GSA Procedural Guide - CIO IT Security 09-48 "Security Language for IT Acquisition Efforts". Column E of the worksheet titled "Contractor Implemented Settings" shall document all contractor implemented settings that are different from the GSA defined setting and where the GSA defined setting allows a contractor determined setting).

· Required policies and procedures across 18 control families mandated per FIPS 200,

· Rules of Behavior,

· Interconnection Agreements (in accordance with NIST Special Publication 800-47),

· System architecture documentation,

· Network architecture diagram including IP addresses and subnets for individual devices,

· List of web applications and web services, including descriptions and corresponding URLs

· List of servers, including descriptions of the applications and information residing on each server

· List of database management systems (e.g. Oracle, SOL Server, Sybase) including descriptions.

· Vulnerability scanning practices

· Patch Management process

2. Contingency Plan (including a Disaster Recovery Plan) - The contingency plan shall be prepared in accordance with NIST 800-34.

3. Contingency Test, Test Plan, and Contingency Test Report shall be prepared in accordance with the most current version of GSA CIO IT Security Procedural Guide CIO-IT Security-06-29 (Contingency Plan Testing)

4. Configuration Management Plan - The configuration Management Plan shall be prepared in accordance with the most current version of GSA CIO-IT Security Procedural Guide: 01-05 (Developing a Configuration Management).

5. Business Impact Analysis - Identify key business processes affected by different levels of disaster or service interruption and impact these services would have to GSA and its customers in the case of each scenario.

6. Business Continuity Plan - identify key processes, personnel and relying systems that must be available in the case of a major disaster, provide planning and recommendations for continuing service.

7. Plan of Actions & Milestones - Provide methodology for identifying, tracking and remediating POAMs.

8. Lessons Learned Report - This report shall contain any information including GSA's methodology that could improve the process.

C.3.5.3. Subtask 3 – High Impact System Requirements The contractor should provide in the proposal, at a minimum, plans, approximate timeframes and methodologies for accomplishing each of the following milestones and components of a High Impact system. ·

· FIPS 199 High - [confidentiality, integrity, availability] at highest level of Interoperable agency customers are the driver (multifactor authentication for access and changes);

· Continuous monitoring by Contractor - at multiple levels (i.e. full packet capture, I/ E points from the accreditation boundary of the system);

· Root cause evaluation capability within a 3 hours;

· Controlled environments in accordance with FIPS;

· Publication controls and release controls limited to government approval only;

· Operation of the system based on FIPS 199 High Impact Level;

· Dedicated ISSO at Contractor;

· Full and complete DNSSEC tested implementation;

· Automated logging - (i.e. NIST controls - CM family and AU family);

· Tiered administrative override checks and balances;

· Automated process controls/not manual;

· Full test suite capabilities; and

· 24/7 on call technical support.

C.3.5.4. Subtask 4 – Authority to Operate (ATO) The contractor shall provide evidence of their capability to obtain an Authority to Operate (ATO) by the target transition date unless an ATO already exists, as approved by GSA in the contractor’s transition plan. The contractor shall document and demonstrate that the registry, registrar, and related systems adhere to HIGH security controls as identified by the Federal Information Security Management Act (FISMA) and any successor acts. The contractor shall maintain all documentation supporting FISMA compliance and ensure that documentation and system controls remain current throughout the system life-cycle, in accordance with GSA OCIO-IT Security-09-48, “Security Language for IT Acquisition Efforts.”

Before operation, the contractor shall obtain and maintain a valid certification and accreditation (A&A) from the GSA Authorizing Official. All medium and high findings/vulnerabilities shall be remediated, or have appropriate mitigating compensations, before an accreditation decision by the GSA Authorizing Official. The contractor shall ensure that the documentation remains current throughout the system life-cycle. For any identified shortfalls, the provider shall document a plan of actions and milestones (POA&M) as well as outlining compensating and mitigating controls for approval by the GSA Authorization Official, COR, and any other necessary government representative designated by the COR.

In addition to the above, the contractor shall employ code analysis tools to examine the software used for common flaws and document results in a Code Review Report. The Code Review Report shall be submitted as part of the security authorization package (reference NIST 800-53 control SA-11, Enhancement 1 for additional details).

The contractor shall mitigate all security risks found during authorization and subsequent continuous monitoring activities. All high-risk vulnerabilities must be mitigated within thirty (30) days and all moderate risk vulnerabilities must be mitigated within ninety (90) days from the date vulnerabilities are formally identified, unless otherwise approved by the government. The government will determine the risk rating of vulnerabilities.

Maintenance of the security authorization to operate will be through continuous monitoring of security controls of the contractor's system and its environment of operation to determine if the security controls in the information system continue to be effective over time in light of changes that occur in the system and environment. Through continuous monitoring, security controls and supporting deliverables are updated and submitted to GSA per the deliverable schedule. The submitted deliverables shall provide a current understanding of the security state and risk posture of the information systems and to allow GSA authorizing officials to make credible risk-based decisions regarding the continued operations of the information systems and initiate appropriate responses as needed when changes occur.

C.3.6 Task 6 – Registrar Fees and Services The contractor shall provide a system for collecting fees for services. Activities include, but are not limited to: assessing fees from customer agencies; issuing notifications of delinquent accounts; resolving credit card disputes; and coordinating financial transactions.

The Contractor will collect all fees from the entities directly, and all collected fees shall be kept by the Contractor. Collection of fees for domain registration applies only to new and annual renewals.

The Contractor shall be responsible for management of the root .gov domain and registration of 2nd level domains only (for example, gsa.gov). Fees must only be assessed on 2nd level domains. Monies collected shall be recorded for review during government domain approval process, tracked, and reported to the government at a minimum quarterly (see "Quarterly Revenue Reports" in Section 4.1.5 above). For reporting purposes, fees from entities of the Federal Government (Legislative, Executive, and Judicial branches, and Native Sovereign Nations) will be flagged with a marker which is distinct from the non-federal entities (State and Local governments). The Contractor shall be responsible for collecting and processing fees for payment when registering a new domain name or renewing an existing domain name. Fees shall not be collected through PayPal portal as Federal agency credit cards cannot access PayPal.com.

Registrations are processed and approved based on established criteria, detailed in both the Federal Networking Council Request For Comments (RFC) 2146, May 1997 and 41 CFR Part 102-173, and in accordance with the guidance and direction of the .Gov Policy Authority. Other policies that must be adhered to by agencies in the Federal Executive Branch include OMB Memorandum M-11-24, M-05-04, and M-08-23.

The per-registration and renewal price shall comply with 41 CFR Part 102-173 “Internet GOV Domain” (for the base year). Fees are set by the Government; presently, fees for both new registrations and renewals are $125.00/year. OGP proposes to increase the fee assessed to registrants of .gov domain names from the current $125 to $400 per annum for new registrations and annual renewals. The proposed fee would go into effect on January 1, 2017. The Contractor is encouraged to illustrate their use of commodity and industry best practices to provide cost-effective solutions for customer care and billing and payment processing for fee collection.

C.3.7 Task 7 – Contingency Planning Implementation and Testing The awarded contractor shall develop a Contingency Plan which documents the strategy and testing focusing on service restoration and data recovery in the event of unforeseen circumstances (See 7a - A&A Guidance). The Contingency Plan shall be prepared in accordance with NIST 800- 34 & GSA CI0-17 Security -06-29 {available from GSA-FAS-CIO via CD). Identify frequency and type of testing to be provided. For example, once a year, a table top exercise will be conducted followed by a true system test six months later. and witnessed by GSA personnel.

C.3.8 Task 8 – Domain Name System Security (DNSSEC) The government's preference is for any incoming contractor to follow the current DNSSEC security measures solution for the .Gov Top Level Domain (TLD) system. Current .Gov DNSSEC implementation information is available at www.dotgov.gov under the DNSSEC tab. However, other solutions will be considered if they meet the DNSSEC standard, but any agencies current implementation should not be interrupted. There are approximately 1200 agency domains which have implemented DNSSEC. The Department of Homeland Security (DHS) will be advising GSA concerning DNS Security.

Delegation holders may require limited technical assistance implementing DNSSEC in accordance with the Office of Management and Budget (OMB) policy. The current OMB policy is found at:

http:/lwww.whitehouse.gov/omb/assets/omb/memoranda/fy2008/m08-23.pdf.

The .gov Domain Name Registration Services shall include procedures for record signing and managing zone updates using a validated FIPS 140-3 level 3 solution to distribute and manage the .gov DNSSEC key infrastructure to the DNS administrator. The service should include, but not be limited to:

· Key management system for the root .gov domain, maintaining security delegation information for second level domains; automation distribution;

· Support of incremental updates to the zone and an automated rollover management;

· Acquiring additional bandwidth to support zone clearing; and

· Key archiving for the top-level .gov domain (i.e. .gov only and NOT the approximately 5,600 second-level .gov domains).

The service shall assist in maintaining the chain of trust by adding the ability to securely track and verify .gov domains and to allow the domain administrator to upload secure delegation material (DNSKEY RRs) to their parent zone. The automated support services should consist of: testing; reporting; signing; release management; and notifications of configuration errors and expired signatures.

The contractor shall maintain and update the current written procedures and develop sample agency implementation requirements for posting on the .Gov Website www.dotgov. gov under the tab entitled DNSSEC implementation. These written procedures must explain in detail the new DNSSEC implementation with detailed procedures on exactly what the current .Gov registrants must do in order to comply with the DNSSEC implementation.

The DNSSEC solution was implemented by GSA in the .Gov top-level domain in February 2009. The contractor shall provide automated and manual technical support services to Federal Agencies, State, County, Local and NSN Government Technical IT Staff to implement the DNSSEC Secure Naming Infrastructure for second level .Gov domains. The support will be provided under the same time frame perimeters as Task 3 above. This will provide support for end user rollouts, upgrades, troubleshooting, and configuration with Federal, State, Local and NSN technical IT staff implementing the U.S. Government Secure Naming Infrastructure policies and procedures. The manual technical support services should consist of telephone support, signed name server configuration testing, troubleshooting, and rollout support as requested by end users through the GSA .Gov Helpdesk.

The DNSSEC service must adhere to the guidance and/or standards outlined in the following publications:

National Institutes of Standards and Technology's (NIST) Special Publication 800-53 revision 4, and 800-81 revision 2 (http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-81-2.pdf)

NIST Special Publication 800-57 (parts 1, 2 and 3), Recommendation for Key Management - Part 1 :.General, Part 2: Best Practices for Key Management Organization, and Part 3, Application-Specific Key Management Guidance (http://csrc.nist.gov/publicati ons/PubsSPs.html)

RFC 4033 R. Arends, R. Austein, M. Larson, D. Massey, S. Rose. DNS Security Introduction and Requirements. October 10, 2004. (http://www.ietf.org/rfc/rfc4033.txt)

RFC 4034 R. Arends, R. Austein, M. Larson, D. Massey, S. Rose. Resource Records for the DNS Security Extensions. March, 2005. (http://www.ietf.org/rfc/rfc4034.txt ).

RFC 4045 R. Arends, R. Austein, M. Larson, D. Massey, S. Rose. Protocol Modifications for the DNS Security Extensions . March, 2005. (http://www.ietf.org/rfc/rfc4045.txt)

In addition, the contractor shall implement a DNSSEC deployment solution that:

· Supports RFC5155 (http://www.ietf.org/rfc/rfc5155.txt);

· Supports existing encryption algorithms and migration to newly specified algorithms;

· Supports DNSSEC-aware Utilities;

· Complies with FIPS 140-3 level 3 (www.csrc.nist.gov/publications/PubsFI PS.html). Supports IPv6 (http://www.ietf.org/rfc/rfc2460.txt); and

· Ensures interoperability with IETF specified Internet protocols Supports Dynamic DNS updates that complies with NIST Special Publication 800-81 revision 2.

C.3.9 Task 9 – Transition-In/Out Services Transition-In:

The Contractor shall present a transition plan at the kickoff meeting on how it intends to transition in to the Registrar and Registry provider of the .Gov TLD. The plan will show at a minimum the following activity and milestones:

Website cutover;

Zone files transition to include shadow, joint and sole operation period;

DNSSEC Activities and Key Rollover;

Billing;

Failover facility;

Resolution plan;

Transition-Out:

The Contractor shall perform all services necessary to transition the work performed under this task order to the Government or another Contractor at the conclusion of this task order. The transition shall be performed without any interruption or degradation in any services. The Contractor shall perform all transition-out services necessary to provide a smooth and efficient transition.

The contractor shall provide a draft Transition-Out Plan within ninety (90) days of contract award. The Government will work with the contractor to finalize the Plan. The contractor shall ensure the transition to the next contractor is effectively facilitated and executed.

The contractor shall provide Transition-Out support when required by the Government. The Transition-Out Plan shall facilitate the accomplishment of a seamless transition from the incumbent to an incoming contractor/Government personnel at the expiration of the contract. The contractor shall provide a Transition-Out Plan to the Government and provide updates. The contractor shall identify, at a minimum, how it will coordinate with the incoming contractor and/or Government personnel to transfer knowledge regarding the following:

1. Project management processes

1. Points of contact

1. Location of technical and project management documentation

1. Status of ongoing technical initiatives

1. Appropriate contractor–to-contractor coordination to ensure a seamless transition.

1. Transition of Key Personnel

1. Schedules and milestones

1. Actions required of the Government.

1. A final invoice and close-out schedule with the dates and actions to be completed for contract close-out

In addition, the transition plan must incorporate the following specific steps:

· A shadow operation of not less than thirty (30) days. During this period, the contractor facilities shall not be connected but shall otherwise be fully operational and shall receive all inputs received by the incumbent.

· A joint operation of not less than thirty (30) days. During the joint operation period, the contractor facilities shall be capable of being fully connected to the network both for resolution and provisioning and shall function transparently.

· A sole operation of not less than fifteen (15) days. During the sole operation period, the incumbent operator shall provide at least one site capable of full demand resolution and one site capable of provisioning.

GSA shall review the readiness of, and approve the cut-over timing for, registry and registrar responsibilities. Service level requirements must be satisfied upon transition. Unless otherwise directed by GSA, any deficiencies below the minimal requirement shall require a reversion of service back to the incumbent until such time that any deficiency is resolved to the satisfaction of GSA

The contractor shall also establish and maintain effective communication with the incoming contractor/Government personnel for the period of the transition.

SECTION C – STATEMENT OF OBJECTIVES

Request for Proposal ID11160019 PAGE C-17

Version 08/14/12

D.1 Packaging and Marking All reports and deliverables should be submitted electronically through GSA’s electronic task order system (ITSS) at:

ITSS https://web.itss.gsa.gov/login

Identified below are the required electronic formats, whose versions must be compatible with the latest, commonly available version on the market.

· TextMicrosoft Word
· SpreadsheetsMicrosoft Excel
· BriefingsMicrosoft PowerPoint
· DrawingsMicrosoft Visio
· SchedulesMicrosoft Project
· PDFAdobe Acrobat Reader

SECTION D - PACKAGING AND MARKING

Request for Proposal ID11160019 PAGE D-1

E.1 PLACE OF INSPECTION AND ACCEPTANCE

Inspection and acceptance of all work performance, reports, and other deliverables under this RFP shall be performed by the Government Technical Representative (GTR) and/or Contracting Officer Representative.

E.2 SCOPE OF INSPECTION

All deliverables will be inspected for content, completeness, accuracy, and conformance to RFP requirements by the GTR and/or COR. Inspection may include validation of information, computations, valuations or software through the use of automated tools, testing, or inspections of the deliverables. The scope and nature of this inspection will be sufficiently comprehensive to ensure the completeness, quality, and adequacy of all deliverables.

The Government requires a period NTE 15 workdays after receipt of final deliverable items for inspection and acceptance or rejection.

E.3 BASIS OF ACCEPTANCE

The basis for acceptance shall be compliance with the requirements set forth in the RFP, the contractor’s proposal, and relevant terms and conditions of the contract. Deliverable items rejected shall be corrected in accordance with the applicable clauses.

Reports, documents, and narrative-type deliverables will be accepted when all discrepancies, errors, or other deficiencies identified in writing by the Government have been corrected.

If the draft deliverable is adequate, the Government may accept the draft and provide comments for incorporation into the final version.

All of the Government's comments on deliverables must either be incorporated in the succeeding version of the deliverable, or the contractor must demonstrate to the Government's satisfaction why such comments should not be incorporated.

If the Government finds that a draft or final deliverable contains spelling errors, grammatical errors, or improper format, or otherwise does not conform to the requirements stated within this RFP, the document may be immediately rejected without further review and returned to the contractor for correction and resubmission. If the contractor requires additional Government guidance to produce an acceptable draft, the contractor shall arrange a meeting with the COR.

E.4 DRAFT DELIVERABLES

The Government will provide written acceptance, comments, and/or change requests, if any, within 15 workdays (unless specified otherwise in Section F) from Government receipt of the draft deliverable. Upon receipt of the Government comments, the contractor shall have ten workdays to incorporate the Government's comments and/or change requests and to resubmit the deliverable in its final form.

E.5 WRITTEN ACCEPTANCE/REJECTION BY THE GOVERNMENT

The CO/COR will provide written notification of acceptance or rejection of all final deliverables within 15 workdays (unless specified otherwise in Section F). All notifications of rejection will be accompanied with an explanation of the specific deficiencies causing the rejection.

E.6 NON-CONFORMING PRODUCTS OR SERVICES

Non-conforming products or services will be rejected. Deficiencies will be corrected, by the contractor, within ten workdays of the rejection notice. If the deficiencies cannot be corrected within ten workdays, the contractor will immediately notify the COR of the reason for the delay and provide a proposed corrective action plan within ten workdays.

If the contractor does not provide products or services that conform to the requirements of this RFP, the Government will not pay the fixed price associated with the non-conforming products or services.

SECTION E - INSPECTION AND ACCEPTANCE

Request For Proposal ID11160019 PAGE E-2

Version 08/14/12

F.1 PERIOD OF PERFORMANCE

The period of performance (PoP) is one 12 month base year, and four 12 month option periods.

F.2 PLACE OF PERFORMANCE

The services specified by this contract shall be performed at the Contractor’s facilities. Occasional travel to the GSA Office listed below may be required at the government’s discretion:

General Services Administration Office of Government-wide Policy 1800 F Street, N.W.

Washington, DC 20405

F.3 CONTRACT SCHEDULE AND MILESTONE DATES

The Offeror shall provide a Deliverables Schedule as part of its solution. It shall be used by the GSA COR/GSA OGP Technical Point of Contact to monitor timely…

This is the start of the file's text. The full file is on GovTribe.

File details come from the government source that posted it. Updated .