Attachment_1_-_JOFOC.pdf
PDF 69 KB Posted
- Attached to
- Saint Renewal Federal contract opportunity
- Solicitation number
- JPM18-027
About this file
Attachment 1 - JOFOC. Sole source justification - Saint Corporation.
View the file
Other files for this federal contract opportunity
| File | Type | Posted |
|---|---|---|
| JPM18-027_-_RFQ.pdf |
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
Attachment 1 - JOFOC – JPM18-027 1 | Page
Justification for Other Than Full and Open Competition (JOFOC)
This document sets forth the justification and approval for award of a contract or order by means providing for other than full and open competition per 41 U.S.C. § 253(c), and, as applicable, FAR 6.302, FAR 13.106-1, FAR 8.405, and FAR 16.505. Contracting without competition shall not be justified on the basis of a lack of advance planning or concerns related to availability of funds.
This form shall be used to support instances where competition will be limited to a single source, a limited number of sources, including where a brand name product is required.
Part 1 – Identification
1. Identification of Agency and the Contracting Activity.
The General Services Administration Office of Inspector General (OIG), Contracting Office (JPC), is responsible for this procurement, on behalf of the GSA Office of Inspector General, Information Technology (IT) Division (JPM).
Address: 1800 F Street, NW
Washington DC 20405
2. Nature and/or Description of the Action.
☒ New Contract PR Number: JPM18-027 ☐ Modification: Manufacturer: Saint Corporation ☐ GSA Schedule or GWAC Estimated Value (Base and all options):
☐ Other: identify Period of Performance: 6/10/2018 – 6/9/2021
This is sole source justification for award to the Contractor listed above.
3. Description of the Supplies or Services.
The purpose of this request is to renew the limited perpetual licenses and maintenance for the existing SAINT software that the General Services Administration, Office of Inspector General (GSA OIG) currently owns.
OIG has a requirement for a NIST validated, the Security Content Automation Protocol (SCAP) compliant security suite capable of performing asset discovery, vulnerability assessments, SCAP baseline compliance scans, and reporting for 1000 physically-distributed, networked devices. SAINT Security Suite allows OIG to meet the FISMA and GSA requirements to scan our network, perform security assessments, and make recommendations to JPM staff on how to mitigate or patch identified security vulnerabilities.
Description Part Number QTY Limited Perpetual License LPL 1 SAINT Subscription (1 Seat) ST- Sub-1S 2 Bracket 1,000 Base License B-1 ,000-BL 1
SCAP 1000 S-M-1000 1
SAINT box Model 400-32 Maintenance SB-400-32M 1
Period of Performance:
Base Year: 6/10/2018 – 6/9/2019 Option Year One: 6/10/2019 – 6/9/2020 Option Year Two: 6/10/2020 – 6/9/2021
Attachment 1 - JOFOC – JPM18-027 2 | Page
Part 2 – Justification & Approval
4. Identification of Statutory Authority.
Authority for Contracting Without Competition Up to $150,000 For this requirement up to $150,000, using simplified acquisition procedures under FAR part 13, the basis for contracting without providing for full and open competition is:
☒ Only one responsible source is reasonably available to meet OIG requirements. 41 U.S.C. § 6101(b); FAR 13.106-1 ☐ Product or service is reasonably available from only one source.
☒ OIG’s needs can only be satisfied by a brand-name product ☒ Source controls copyrights, patents or other exclusive licensing arrangements.
☐ Urgent circumstances; only one source can reasonably deliver by required date. Option years are not permitted.
☐ Source is expressly authorized or required by statute:
5. Demonstration of Contractor’s Unique Qualifications.
We are authorized to limit competition on the basis of the citation in section 4 because this procurement is to renew annual maintenance for a product that was open source selected.
The Federal Information Security Management Act of 2002 (FISMA) requires vulnerability scanning to be accomplished on a self-defined regular schedule, and GSA policy (2100.1i) requires scans to be completed at least quarterly.
SAINT Security Suite is a vulnerability management solution that is NIST SCAP v.1.2 validated as an Authenticated Configuration Scanner (ACS) for all 6 required platforms. This product provides JPM with the ability to scan our network for vulnerabilities in a timely, flexible and FISMA complaint manner. This annual maintenance ensures that it receives all updates and patches.
Procuring a new NIST validated, SCAP compliant security suite would be significantly more expensive than renewing maintenance. After reviewing several SCAP validated products listed on the NIST website, a new security suite is estimated to cost between $50,000 and $80,000. Replacing the currently implemented and deployed SAINT software would be significantly more expensive than renewing maintenance. In addition to the new software price, deploying new software would require configuration and deployment that would be disruptive to service.
The OIG has determined that only the specified item(s) to be acquired will satisfy the agency’s needs for additional or replacement items.
SAINT Corporation is the sole-source supplier of SAINT software. Resellers were identified, however, they are not eligible to sell SAINT software and maintenance to existing customers. See attached sole source provider letter from Saint Corporation.
6. Description of Efforts to Ensure Other Potential Sources Were Sought.
To increase competition, we will continue to evaluate similar software. SCAP validated products listed on the NIST website were reviewed. JPM reviews and reassess requirements continually in light of emerging technology.
7. Program Office Certification.
I certify that the description of the Government’s minimum needs, schedule requirements, and technical information that provide the basis for this justification are accurate and complete.
Attachment 1 - JOFOC – JPM18-027 3 | Page
Name Title Signature Date
File details come from the government source that posted it.