15T0213_0001.pdf
PDF 54 KB Posted
- Attached to
- SOLE SOURCE - CORE SECURITY - VULNERABILITY MANAGEMENT SOFTWARE AND RELATED MAINTENANCE SUPPORT Federal contract opportunity
- Solicitation number
- N0016415T0213
About this file
15T0213_0001
View the file
Other files for this federal contract opportunity
| File | Type | Posted |
|---|---|---|
| 15T0213_FBO.pdf | ||
| 15T0213_sol.pdf |
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
N00164-15-T-0213
AMENDMENT OF SOLICITATION/MODIFICATION OF CONTRACT
Except as provided herein, all terms and conditions of the document referenced in Item 9A or 10A, as heretofore changed, remains unchanged and in full force and effect.
15A. NAME AND TITLE OF SIGNER (Type or print)
30-105-04EXCEPTION TO SF 30
APPROVED BY OIRM 11-84
STANDARD FORM 30 (Rev. 10-83) Prescribed by GSA
FAR (48 CFR) 53.243
The purpose of this amendment is to delete the requirement for training.
1. CONTRACT ID CODE PAGE OF PAGES
1 7
16A. NAME AND TITLE OF CONTRACTING OFFICER (Type or print)
16C. DATE SIGNED
BY 29-Aug-2015
16B. UNITED STATES OF AMERICA15C. DATE SIGNED15B. CONTRACTOR/OFFEROR
(Signature of Contracting Officer)(Signature of person authorized to sign)
8. NAME AND ADDRESS OF CONTRACTOR (No., Street, County, State and Zip Code) X N00164-15-T-0213
X 9B. DATED (SEE ITEM 11)
27-Aug-2015
10B. DATED (SEE ITEM 13)
9A. AMENDMENT OF SOLICITATION NO.
11. THIS ITEM ONLY APPLIES TO AMENDMENTS OF SOLICITATIONS
X The above numbered solicitation is amended as set forth in Item 14. The hour and date specified for receipt of Offer is extended, X is not extended.
Offer must acknowledge receipt of this amendment prior to the hour and date specified in the solicitation or as amended by one of the following methods:
(a) By completing Items 8 and 15, and returning 1 copies of the amendment; (b) By acknowledging receipt of this amendment on each copy of the offer submitted;
or (c) By separate letter or telegram which includes a reference to the solicitation and amendment numbers. FAILURE OF YOUR ACKNOWLEDGMENT TO BE RECEIVED AT THE PLACE DESIGNATED FOR THE RECEIPT OF OFFERS PRIOR TO THE HOUR AND DATE SPECIFIED MAY RESULT IN
REJECTION OF YOUR OFFER. If by virtue of this amendment you desire to change an offer already submitted, such change may be made by telegram or letter, provided each telegram or letter makes reference to the solicitation and this amendment, and is received prior to the opening hour and date specified.
12. ACCOUNTING AND APPROPRIATION DATA (If required)
13. THIS ITEM APPLIES ONLY TO MODIFICATIONS OF CONTRACTS/ORDERS.
IT MODIFIES THE CONTRACT/ORDER NO. AS DESCRIBED IN ITEM 14.
A. THIS CHANGE ORDER IS ISSUED PURSUANT TO: (Specify authority) THE CHANGES SET FORTH IN ITEM 14 ARE MADE IN THE
CONTRACT ORDER NO. IN ITEM 10A.
B. THE ABOVE NUMBERED CONTRACT/ORDER IS MODIFIED TO REFLECT THE ADMINISTRATIVE CHANGES (such as changes in paying office, appropriation date, etc.) SET FORTH IN ITEM 14, PURSUANT TO THE AUTHORITY OF FAR 43.103(B).
C. THIS SUPPLEMENTAL AGREEMENT IS ENTERED INTO PURSUANT TO AUTHORITY OF:
D. OTHER (Specify type of modification and authority)
E. IMPORTANT: Contractor is not, is required to sign this document and return copies to the issuing office.
14. DESCRIPTION OF AMENDMENT/MODIFICATION (Organized by UCF section headings, including solicitation/contract subject matter where feasible.)
10A. MOD. OF CONTRACT/ORDER NO.
2. AMENDMENT/MODIFICATION NO. 5. PROJECT NO.(If applicable)
6. ISSUED BY
3. EFFECTIVE DATE
29-Aug-2015
CODE
NAVAL SURFACE WARFARE CENTER CRANE DIV
T. BROUGH (812-854-4247)
BLDG 3373
300 HIGHWAY 361
CRANE IN 47522-5001
N00164 7. ADMINISTERED BY (If other than item 6)
4. REQUISITION/PURCHASE REQ. NO.
CODE
See Item 6
FACILITY CODECODE
teresa.brough@navy.milEMAIL:812-854-4247TEL:
TERESA D. BROUGH / CONTRACTING OFFICER
SECTION SF 30 BLOCK 14 CONTINUATION PAGE
The following items are applicable to this modification:
SECTION SF30 - SF 30 CONTINUATION SHEET
SUMMARY OF CHANGES -REV
SUMMARY OF CHANGES
SECTION SAP - SAP CONTINUATION SHEET
CLIN 0001
The CLIN extended description has changed from in accordance with Statement of Work herein.
FROM: Brand Name Only: Core Security, Boston MAP/N GVT-CIE-M-100-SP/N GVT-CIEN-PS to include 100 assets (1 controller/1auditor)1 year maintenance support, implementation, configuration & delivery, 2 day training class for up to 5 attendees to.
TO: Brand Name Only: Core Security, Boston MAP/N GVT-CIE-M-100-SP/N GVT-CIEN-PS to include 100 assets (1 controller/1auditor) implementation, configuration, delivery and 1 year maintenance support/license in accordance with Statement of Work herein.
The following have been modified:
STATEMENT OF WORK
Statement of Work for
Penetration Testing & Vulnerability Management
1. Scope This Statement of Work (SOW) sets forth the requirements for implementation of a Penetration Testing and vulnerability management tool to proactively address security threats from real attacks a hacker would use.
2. Applicable Documents
2.1 Department of Defense (DoD)/Department of the Navy (DoN) Regulations, Directives and
Instructions DoDD 8500.01E
Information Assurance 23 Apr 2007
DoDI 8500.2 Information Assurance Implementation 06 Feb 2003 DoDD 8510.01
DoD Information Assurance Certification and Accreditation Process
(DIACAP)
28 Nov 2007
DoDI 8520.02 Public Key Infrastructure (PKI) and Public Key (PK) Enabling 24 May 2004 DoDD 8570.01
Information Assurance Training, Certification, and Workforce Management
23 Apr 2007
DoN CIO
MEMO 02-10
Department of the Navy Chief Information Officer Memorandum, Information Assurance Policy
26 Apr 2010
OSD DOT&E
Memorandum of 1 Aug 2014
OSD DOT&E- Procedures for Operational Test and Evaluation of Cybersecurity in Acquisition Programs
1 Aug 2014
2.2 Secretary of the Navy (SECNAV) and Office of the Chief of Naval Operations (OPNAV) Instructions
SECNAVINST
5510.34A
DISCLOSURE OF CLASSIFIED MILITARY INFORMATION
and CONTROLLED UNCLASSIFIED INFORMATION to
FOREIGN GOVERNMENTS, INTERNATIONAL
ORGANIZATIONS, and FOREIGN REPRESENTATIVES
08 Oct 2004
SECNAV M-5239.1 Information Assurance Manual Nov 2005 SECNAV M-5510.36 Department of the Navy Information Security Program June 2006
SECNAVINST
5510.36A
DEPARTMENT of the NAVY (DoN) INFORMATION
SECURITY PROGRAM (ISP) INSTRUCTION
06 Oct 2006
2.3 Naval Sea Systems Command (NAVSEA) and PEO Littoral Combat Ship and PEO Integrated
Warfare Systems (PEO IWS) Regulations, Directives and Instructions MIL-HDBK-1785 System Security Engineering Program Management
Requirements 01 Aug 1995
9010 Ser IWS/2a·233
Naval Open Architecture Contract Guide Book for Program Managers Version 2.0
30 Jun 2010
N/A Joint Software Systems Safety Handbook 27 Aug 2010 N/A Risk Management Guide for DoD Acquisition, 6th Edition, Version 1.0 Aug 2006
SPAWAR
Memorandum Ser 5.0/1274
Qualification Standards and Registration Procedures for Navy Validators
18 Mar 2010
3. Requirements The Naval Surface Warfare Center, Crane Division requires the ability to identify and prioritize vulnerabilities coming from a large number of assets deployed as part of government operations. The contractor shall provide software, installation and implementation of a vulnerability management tool with the following goals:
1. Consolidation, normalization and prioritization of web and network scanner results
2. Integration with technologies such as web and network scanners (Nessus), GRC solutions and other technologies important to Naval Surface Warfare Center (NSWC).
3. Ability to prioritize vulnerabilities coming from a large number of assets deployed as part of Marine Corp IT Operations.
4. Importing Tenable Nessus vulnerability data
5. Importing Metasploit vulnerability data
6. Prioritize vulnerabilities with exploit matching and attack paths
7. Validate prioritized exploits in an automated fashion (web and network)
8. Provide Multi-Vector Penetration Testing ability on existing and developmental USMC Intelligence programs
9. Provide automated vulnerability remediation capabilities
10. Provide outsider threat testing which protects the systems from potential hacks and attacks which could render the DoD system useless.
11. Allows plug in software that is already owned by the DoD thus enhancing the protective measure and maintain compliance.
3.1 Software Requirements
The contractor shall deliver a software package that meets the above goals and is in accordance with all DoD Information Assurance, Information Technology and Cyber Security requirements listed herein. This specific software is required to meet mandate described in OSD DOT&E Memorandum of 01 Aug 2014 which introduces a two phase Cybersecurity Test and Evaluation requirement; (1) Cooperative Vulnerability and Penetration
Assessment and (2) Adversarial Assessment. The software shall provide visibility to insider threats by collecting and prioritizing data from Tenable Nessus in order to:
* Provide prioritization thru exploit matching and attack paths
* Provide validation with automated pen testing of network and web targets
* Network Attack
* Web Attack
Cyber Security continues to be escalated across the DoD. Latest initiative is rapid certification that applies to:
* Tier 3 - Servers, Workstations, Applications
* Tier 2 - Marine DNS, POP Services
* Tier 1 - Backbone, cached services, etc
3.2 Training, Installation and Implementation
The contractor shall provide installation, and implementation of the solution and methodology within the Naval Surface Warfare Center (NSWC) environment within 60 days of the effective date of the contract. The contractor shall coordinate the installation with the Government POC listed herein within 10 days after award of the contract.
Training shall consist of minimum two day Support shall include professional instruction on the installation, setup and execution of the Core Impact software.
3.3 Annual Support Maintenance
Contractor shall provide support maintenance to ensure software remains in compliance with all Information Assurance and Cyber Security DoD initiatives.
4.0 Contract and Technical Points of Contact
Contract POC: Teresa Brough teresa.brough@navy.mil , Technical POC: Bryan Daugherty bryan.daugherty@navy.mil.
5.0 Period of Performance
Delivery of software, installation and implementation shall be completed within sixty days after contract award.
Maintenance Options for Years 2 – 5; 12 month period.
(End of Summary of Changes)
SUMMARY OF CHANGES
SECTION SAP - SAP CONTINUATION SHEET
CLIN 0001
The CLIN extended description has changed from in accordance with Statement of Work herein.Brand Name Only: Core Security, Boston MAP/N GVT-CIE-M-100-SP/N GVT-CIEN-PSto include 100 assets (1 controller/1auditor)1 year maintenance supportimplementation, configuratino & delivery2 day training class for up to 5 attendees to in accordance with Statement of Work herein.Brand Name Only: Core Security, Boston MAP/N GVT-CIE-M-100-SP/N GVT-CIEN-PSto include 100 assets (1 controller/1auditor)1 year maintenance support/license. .
The following have been modified:
STATEMENT OF WORK
Statement of Work for
Penetration Testing & Vulnerability Management
1. Scope This Statement of Work (SOW) sets forth the requirements for implementation of a Penetration Testing and vulnerability management tool to proactively address security threats from real attacks a hacker would use.
2. Applicable Documents
2.1 Department of Defense (DoD)/Department of the Navy (DoN) Regulations, Directives and
Instructions DoDD 8500.01E
Information Assurance 23 Apr 2007
DoDI 8500.2 Information Assurance Implementation 06 Feb 2003 DoDD 8510.01
DoD Information Assurance Certification and Accreditation Process
(DIACAP)
28 Nov 2007
DoDI 8520.02 Public Key Infrastructure (PKI) and Public Key (PK) Enabling 24 May 2004 DoDD 8570.01
Information Assurance Training, Certification, and Workforce Management
23 Apr 2007
DoN CIO
MEMO 02-10
Department of the Navy Chief Information Officer Memorandum, Information Assurance Policy
26 Apr 2010
OSD DOT&E
Memorandum of 1 Aug 2014
OSD DOT&E- Procedures for Operational Test and Evaluation of Cybersecurity in Acquisition Programs
1 Aug 2014
2.2 Secretary of the Navy (SECNAV) and Office of the Chief of Naval Operations (OPNAV) Instructions
SECNAVINST
5510.34A
DISCLOSURE OF CLASSIFIED MILITARY INFORMATION
and CONTROLLED UNCLASSIFIED INFORMATION to
FOREIGN GOVERNMENTS, INTERNATIONAL
ORGANIZATIONS, and FOREIGN REPRESENTATIVES
08 Oct 2004
SECNAV M-5239.1 Information Assurance Manual Nov 2005 SECNAV M-5510.36 Department of the Navy Information Security Program June 2006
SECNAVINST
5510.36A
DEPARTMENT of the NAVY (DoN) INFORMATION
SECURITY PROGRAM (ISP) INSTRUCTION
06 Oct 2006
2.3 Naval Sea Systems Command (NAVSEA) and PEO Littoral Combat Ship and PEO Integrated
Warfare Systems (PEO IWS) Regulations, Directives and Instructions MIL-HDBK-1785 System Security Engineering Program Management
Requirements 01 Aug 1995
9010 Ser IWS/2a·233
Naval Open Architecture Contract Guide Book for Program Managers Version 2.0
30 Jun 2010
N/A Joint Software Systems Safety Handbook 27 Aug 2010 N/A Risk Management Guide for DoD Acquisition, 6th Edition, Version 1.0 Aug 2006
SPAWAR
Memorandum Ser 5.0/1274
Qualification Standards and Registration Procedures for Navy Validators
18 Mar 2010
3. Requirements The Naval Surface Warfare Center, Crane Division requires the ability to identify and prioritize vulnerabilities coming from a large number of assets deployed as part of government operations. The contractor shall provide software, installation and implementation of a vulnerability management tool with the following goals:
12. Consolidation, normalization and prioritization of web and network scanner results
13. Integration with technologies such as web and network scanners (Nessus), GRC solutions and other technologies important to Naval Surface Warfare Center (NSWC).
14. Ability to prioritize vulnerabilities coming from a large number of assets deployed as part of Marine Corp IT Operations.
15. Importing Tenable Nessus vulnerability data
16. Importing Metasploit vulnerability data
17. Prioritize vulnerabilities with exploit matching and attack paths
18. Validate prioritized exploits in an automated fashion (web and network)
19. Provide Multi-Vector Penetration Testing ability on existing and developmental USMC Intelligence programs
20. Provide automated vulnerability remediation capabilities
21. Provide outsider threat testing which protects the systems from potential hacks and attacks which could render the DoD system useless.
22. Allows plug in software that is already owned by the DoD thus enhancing the protective measure and maintain compliance.
3.1 Software Requirements
The contractor shall deliver a software package that meets the above goals and is in accordance with all DoD Information Assurance, Information Technology and Cyber Security requirements listed herein. This specific software is required to meet mandate described in OSD DOT&E Memorandum of 01 Aug 2014 which introduces a two phase Cybersecurity Test and Evaluation requirement; (1) Cooperative Vulnerability and Penetration Assessment and (2) Adversarial Assessment. The software shall provide visibility to insider threats by collecting and prioritizing data from Tenable Nessus in order to:
* Provide prioritization thru exploit matching and attack paths
* Provide validation with automated pen testing of network and web targets
* Network Attack
* Web Attack
Cyber Security continues to be escalated across the DoD. Latest initiative is rapid certification that applies to:
* Tier 3 - Servers, Workstations, Applications
* Tier 2 - Marine DNS, POP Services
* Tier 1 - Backbone, cached services, etc
3.2 Installation and Implementation
The contractor shall provide installation, and implementation of the solution and methodology within the Naval Surface Warfare Center (NSWC) environment within 60 days of the effective date of the contract. The contractor shall coordinate the installation with the Government POC listed herein within 10 days after award of the contract.
Training shall consist of minimum Support shall include professional instruction on the installation, setup and execution of the Core Impact software.
3.3 Annual Support Maintenance
Contractor shall provide support maintenance to ensure software remains in compliance with all Information Assurance and Cyber Security DoD initiatives.
4.0 Contract and Technical Points of Contact
Contract POC: Teresa Brough teresa.brough@navy.mil , Technical POC: Bryan Daugherty bryan.daugherty@navy.mil.
5.0 Period of Performance
Delivery of software, installation and implementation shall be completed within sixty days after contract award.
Maintenance Options for Years 2 – 5; 12 month period.
File details come from the government source that posted it. Updated .