JA SANS Training.pdf

PDF 213 KB Posted

Attached to
SANS Advanced Computer Long Courses Federal contract opportunity
Solicitation number
FY22-070
Issued by
Department of Homeland Security Office of Procurement Operations

View the file

Other files for this federal contract opportunity

Other files attached to SANS Advanced Computer Long Courses, newest first.
File Type Posted
Synopsis.pdf PDF

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

JUSTIFICATION AND APPROVAL FOR OTHER THAN FULL AND OPEN

COMPETITION IAW 41 U.S.C. 3304(a)(1)

J&A No: FY22-070

Pursuant to the requirements of the Competition in Contracting Act (CICA) as implemented by the Federal Acquisition Regulation (FAR) Subpart 6.3 and in accordance with the requirements of FAR 6.303-1, the justification for the use of the statutory authority under FAR Subpart 6.3 is justified by the following facts and rationale required under FAR 6.303-2 as follows:

1. Agency and Contracting Activity. The Department of Homeland Security (DHS), Office of Procurement Operations (OPO), Cybersecurity and Infrastructure Security Agency Acquisition Division (CISAAD) proposes to enter into an agreement on a basis of other than full and open competition with Escal Institute of Advanced Technologies, Inc., dba SANS Institute, on behalf of the Cybersecurity and Infrastructure Security Agency (CISA), Cybersecurity Division (CSD), Threat Hunting (TH) Subdivision, for SANS training courses.

2. Nature and/or Description of the Action being Approved.

(a) Nature of Action: CISAAD intends to procure on a sole-source basis online and in-person training courses provided exclusively by the SANS Institute to achieve mission-critical knowledge and readiness.

(b) Name and Address of the Contractor:

The Escal Institute of Advanced Technologies, Inc. /dba SANS Institute (“SANS”) 11200 Rockville Pike, Suite 200, North Bethesda, MD 20852.

(c) Contract Type: A Single-Award, Firm-Fixed Price (FFP) Blanket Purchase Agreement (BPA)

(d) Estimated Total Value (including options): The estimated total value is $4,105,997.00.

Ordering Period Ordering Period Dates Ceiling Amount Base Period 06/21/2022 – 06/20/2023 $1,081,784.00

Option Period 1 06/21/2023 – 06/20/2024 $1,406,893.00 Option Period 2 06/21/2024 – 06/20/2025 $1,617,320.00

Total Value Including All Options $4,105,997.00

(e) Type of Funding: One-Year, Operations and Support (O&S)

(f) Year of Funding:

FY 2022 for courses ordered between 06/21/2022-09/30/2022 FY 2023 for courses ordered between 10/01/2022-09/30/2023 FY 2024 for courses ordered between 10/01/2023-09/30/2024 FY 2025 for courses ordered between 10/01/2024-06/21/2025

(g) Solicitation Number:

COMPETITION IAW 41 U.S.C. 3304(a)(1)

J&A No: FY22-070

(h) Background Information About the Requirement:

As a component of the Cybersecurity and Infrastructure Security Agency’s (CISA) Cybersecurity Division (CSD), Threat Hunting (TH) is the front line in identifying and tracking threats; detecting malicious activity in Federal civilian executive branch, critical infrastructure, and partner networks; proactively hunting for malicious cyber activity; and responding to cyber incidents. TH leads the Federal response by serving as its primary operational arm in the execution of the asset response mission delegated to DHS in Presidential Policy Directive 41 (PPD-41).

Under the President’s Cybersecurity National Action Plan (CNAP) drafted in 2016, Department of Homeland Security (DHS) was tasked to develop training and qualifications standards to ensure TH personnel has qualified individuals and teams conducting incident response activities. TH, as the Department’s primary operational arm in the execution of the asset response mission delegated to DHS in Presidential Policy Directive 41 (PPD-41), is responsible for the implementation of this training and qualification program, and the establishment of integrated cyber defense teams (CDTs) to ensure that the Federal executive branch workforce is proficient in responding to cyber incidents. Ensuring the security of the homeland requires the knowledge, skills, and abilities to interact with multiple federal departments and agencies, as well as operationally collaborate across federal, state, local, tribal, territorial governmental organizations, and the private sector. To successfully accomplish the task of securing the homeland through cyber and communications requires a prioritized list of specific criteria consisting of training, certifications, and qualifications. TH supports this mission by continuing to define, develop, and implement programs to increase employee access to training opportunities that enhance skills required to perform the CISA mission. The strategy includes the general TH Subdivision education requirements, mandatory training for all TH personnel, Branch-specific training (i.e., Engagement Lead training), Section-specific Task-to-Training Matrix (TTM) that documents the tasks performed within the section and the associated training, and Section-specific training requirements. GIAC certifications are identified in TH training strategy based on operational requirements and such certifications are needed based on individual job descriptions due to the nature of Threat Hunting Sub-Division Operational activities.

All Branches within the TH Subdivision need training and certifications in cyber-related disciplines. In conjunction with Idaho National Laboratory, the TH Subdivision has been tasked with building a Training Program Strategy that includes the general TH education requirements, mandatory training for all TH personnel, Engagement Team Member requirements, Engagement Lead Program, section competency levels; and section-specific job analysis data and training requirements. In order to build this Strategy, TH requires its workforce to have the necessary training and certifications to efficiently conduct their duties and be easily recognized as trained professionals and subject matter experts in their assigned fields.

COMPETITION IAW 41 U.S.C. 3304(a)(1)

J&A No: FY22-070

3. Description of Supplies/Services:

The requirement is to access and take SANS Advanced Computer Long Courses as part of the TH Training Program Strategy. Certifications are required by DHS Policy Instruction 403-251-01- 002 (Instruction for the Administration of Retention Incentives for the Cybersecurity Workforce) dated October 16, 2020. Specific job fields and certifying bodies are listed in the National Cybersecurity Workforce Framework for positions related to the TH mission, and no other certifications meet DHS requirements. The services provided in the sole-source agreement will assist TH in providing certifications in the following areas: Certified Forensic Examiner, Certified Forensic Analyst, Certified Intrusion Analyst, Reverse Engineering Malware, and Certified Incident Handler. These fields cover the following work roles within the agency: Cyber Investigations, Digital Forensics, Incident Response Investigation, Incident Response Forensics, Cyber Operations Officers, and others.

4. Identification of Statutory Authority Permitting Other Than Full and Open Competition.

The statutory authority permitting other than full and open competition is 41 U.S.C.3304(a)(1) implemented by FAR 6.302-1, entitled “Only One Responsible Source and No Other Supplies or Services Will Satisfy Agency Requirements.”

5. Identification of Exception to the Buy American Statute

Exception to the Buy American Statute does not apply to this requirement.

6. Demonstration that the proposed contractor’s unique qualifications or the nature of the acquisition requires use of the authority cited.

HS Policy Instruction 403-251-01-002 dated October 16, 2020, established the Cybersecurity and Infrastructure Security Agency (CISA) Office of Chief Human Capital Officer (OCHCO) implementation policy regarding retention incentives for the CISA cybersecurity workforce.

Section V E(5) of the policy states: “Using the employee individual development plan, they must ensure all mandatory-documented certification training needs are met,” and Section V G(3) states:

“Maintaining their certifications as current and in good standing, which will be part of the basis for a retention incentive or notifying their supervisors and Chief Human Capital Officer (CHCO) or designated program office before certifications expire.”

GIAC’s certifications and SANS courses are part of Threat Hunting’s curriculum. GIAC certifications are identified in TH training strategy based on operational requirements. GIAC certifications are needed based on individual job descriptions due to the nature of Threat Hunting Sub-Division Operational activities and therefore such certifications are required to qualify for Cybersecurity Retention Incentive as stated in Section V E(5).

SANS is the only organization that provides the GIAC certification programs required to qualify for retention incentives for the CISA cybersecurity workforce as stated in DHS Policy instruction 403-251-01-002. SANS training and the required certifications are sole source products, COMPETITION IAW 41 U.S.C. 3304(a)(1)

J&A No: FY22-070 manufactured, sold, and distributed exclusively by SANS. Other companies/schools/training providers are precluded from producing or reselling SANS products and services. SANS has the exclusive and copyright protection to produce, sell, and deliver SANS products and services. Only SANS can offer the official SANS Curriculum and SANS Certified Instructors to deliver training on any SANS class, including all certification preparation courses. As the only provider of the courses that qualify for a GIAC certification, the contract will be awarded under the authority of

FAR 6.302-1.

SANS training courses are unique and proprietary, developed to address specific cybersecurity topics and issues, Additionally, SANS training courses are updated and revised to address emerging risks and active threats. Cybersecurity environments and infrastructures are continuously evolving with new technology, techniques, and tools, and CISA TH personnel are required to understand these changes to protect them.

Other providers of cybersecurity training courses are available in the commercial marketplace;

however, none are authorized to certify personnel for GIAC certification and none of their training courses count towards GIAC certifications. The GIAC certifications were determined to be one of the certifications that CISA personnel can obtain to meet training requirements and mission needs.

Section V E(5) of DHS Policy Instruction 403-251-01-002 states “Using the employee individual development plan, they must ensure all mandatory-documented certification training needs are met” and section V G(3) states “Maintaining their certifications as current and in good standing, which will be part of the basis for a retention incentive or notifying their supervisors and Chief Human Capital Officer (CHCO) or designated program office before certifications expire.” It is common industry practice for someone to take an associated training before attempting to pass an exam. GIACs certifications and SANS courses are part of the curriculum. GIAC certifications are required to qualify for Cybersecurity Retention Incentive.

Affording CISA TH personnel the opportunity to gain access to SANS training courses will increase CISA’s ability to protect cybersecurity environments and infrastructures, and respond to active threats and emerging risks. If CISA TH personnel cannot take SANS training courses, there will be a significant degradation of Incident Response services provided by TH to CISA’s Federal partners and private sector organizations. GIAC certifications are included in Threat Hunting analysts position descriptions (PDs) as required certifications. Failure to obtain and retain GIAC certifications will render an individual unfit to perform his/her job. To successfully accomplish the task of securing the homeland against cyber threats, a prioritized list of specific criteria consisting of training, certifications, and qualifications is required. GIAC certifications are part of TH training strategy. The strategy includes the general TH education requirements, mandatory training for all TH personnel, the Engagement Team Member requirements, the Engagement Lead Program, section competency levels, and finally section-specific job analysis data and training requirements.

If CISA TH personnel cannot take SANS training courses, TH personnel will not have the means to acquire GIAC certifications as described in their position description and as outlined in their training strategy. Additionally, as mentioned before, no training courses offered by any other

COMPETITION IAW 41 U.S.C. 3304(a)(1)

J&A No: FY22-070 vendor will be accepted by SANS for its GIAC certification programs.

7. Description of Efforts Made to Ensure that Offers are Solicited from as Many Potential Sources as is Practicable.

A synopsis will be posted in accordance with FAR Subpart 5.2, identifying the proposed contract action and requirement, within one business day of the approval of this Justification and Approval (J&A), estimated around May/June 2022. If an interested party responds to the synopsis indicating they can meet the requirement, a competitive procurement will be considered.

8. Determination by the Contracting Officer that the Anticipated Cost to the Government will be Fair and Reasonable.

The Contracting Officer will conduct a price analysis in order to determine anticipated prices will be fair and reasonable in accordance with FAR 15.404-1(b). Specifically, the Contracting Officer will review historical data of prices paid to the SANS Institute and other vendors offering similar training courses, taking into consideration inflation rates, economies of scale (e.g., group discounts), and the subject matter.

9. Description of Market Research.

Market research was conducted from 10/01/2021 through 01/15/2022. Market research included a review of available contract vehicles and sourcing strategies that would potentially offer the services to meet the requirements. This included a review of DHS Department-wide vehicles, General Services Administration (GSA) Federal Supply Schedules (FSS), and Government-wide Acquisition Contracts (GWACs).

Market Research revealed that SANS training and the required certifications are sole source products, manufactured, sold, and distributed exclusively by SANS. SANS is the only organization that provides the GIAC certification programs required to qualify for retention incentives for the CISA cybersecurity workforce as stated in DHS Policy instruction 403-251-01-

002. Section V E(5) of DHS Policy Instruction 403-251-01-002 states “Using the employee individual development plan, they must ensure all mandatory-documented certification training needs are met” and section V G(3) states “Maintaining their certifications as current and in good standing, which will be part of the basis for a retention incentive or notifying their supervisors and Chief Human Capital Officer (CHCO) or designated program office before certifications expire.” It is common industry practice for someone to take an associated training before attempting to pass an exam. GIACs certifications and SANS courses are part of the curriculum.

GIAC certifications are required to qualify for Cybersecurity Retention Incentive.

SANS training and the required certifications are sole source products, manufactured, sold, and distributed exclusively by SANS. No other company makes a similar or competing product. Other companies/schools/training providers are precluded from producing or reselling SANS products and services. SANS has the exclusive and copyright protection to produce, sell, and deliver SANS products and services. Only SANS can offer the official SANS Curriculum and SANS Certified Instructors to deliver training on any SANS class, including all certification preparation courses.

COMPETITION IAW 41 U.S.C. 3304(a)(1)

J&A No: FY22-070 The National Initiative for Cybersecurity Careers and Studies (NICCS) Education and Training Catalog is a central location where cybersecurity professionals across the nation can find over 6,000 cybersecurity-related courses. Anyone can use the interactive map and filters to search for courses offered in their local area so they can add to their skill set, increase their level of expertise, earn a certification, or even transition into a new career. All of the courses are aligned to the specialty areas of The Workforce Framework for Cybersecurity (NICE Framework). The NICCS training catalog was utilized as part of market research to identify certifies bodies listed in the National Cybersecurity Workforce Framework providing GIAC certifications. Results came back with SANS being the only vendor. GIAC certifications are sole source products manufactured, sold, and distributed by the Escal Institute (SANS).

Market research explored small business capabilities, but given copyright protections, other companies/schools/training providers are precluded from producing or reselling SANS products and services. Market research examined the feasibility of awarding a stand-alone contract for the SANS Training requirement using a sole source award under a Firm-Fixed Price (FFP) Blanket Purchase Agreement (BPA) contract type. Given that the Escal Institute of Advanced Technologies, Inc. /dba SANS Institute (“SANS”) has the exclusive and copyright protection to produce, sell, and deliver SANS products and services, a stand-alone sole source award is the preferred approach to fulfill the requirement.

Market research has shown that the services required by CISA/CSD/TH are available from only one responsible source and no other type of services will satisfy the requirements.

10. Any Other Facts Supporting the Use of Other Than Full and Open Competition.

11. A Listing of the Sources, if Any That Expressed, in Writing, an Interest in the

Acquisition.

None

12. A Statement of the Actions, if Any, the Agency May Take to Remove or Overcome Any Barriers to Competition Before Any Subsequent Acquisition for Supplies or Services Required.

Given that the Escal Institute of Advanced Technologies, Inc. /dba SANS Institute (“SANS”) has the exclusive and copyright protection to produce, sell, and deliver SANS products and services, competition is not anticipated. However, market research will continue to identify sources that can meet the requirement in the event “SANS” allows partners access to its products and services in the future.

COMPETITION IAW 41 U.S.C. 3304(a)(1)

J&A No: FY22-070

13. Contracting Officer’s Certification. I certify that the data supporting the recommended use of other than full and open competition is accurate and complete to the best of my knowledge and belief.

Contracting Officer Date

14. Technical/Requirements Personnel Certification. I certify this requirement meets the Government’s minimum need and that the supporting data, which forms a basis for this justification, is complete and accurate.

Technical Representative Date

APPROVAL:

Contracting Officer Date

Procurement Activity Advocate for Competition Date or Alternate Designee

File details come from the government source that posted it. Updated .