P09_PWS_ZeroFox subscription for Executive Protection.pdf

PDF 225 KB Posted

Attached to
7J20--IN3022 - Zero Fox Cybersecurity (VA-23-00105819) Federal contract opportunity
Solicitation number
36C79123Q0038
Issued by
Department of Veterans Affairs Veterans Health Administration Veterans Integrated Service Network 19

About this file

This performance work statement outlines requirements for the Department of Veterans Affairs to procure two software licenses and related services for an external cybersecurity platform to support executive protection functions. The contractor must provide a cloud-based security product to monitor online and dark web threats, alert on physical risks based on location, remove personally identifiable information from data brokers, and offer 24/7 managed services and support. Specifically, the contractor is required to deliver two ExecutiveProtectPR-G licenses for monitoring digital threats, one ManagedPlatformG license including alert services and intelligence collection, one TD-60-G license for 60 annual takedowns, and three OnDemand Investigation credits. The period of performance is 12 months from award at locations to be determined. The firm fixed price contract will be evaluated on deliverables submitted on time and accurately meeting requirements.

The related federal contract opportunity provides further details on the solicitation number, name, type, agency, and other administrative information pertaining to this procurement.

View the file

Other files for this federal contract opportunity

Other files attached to 7J20--IN3022 - Zero Fox Cybersecurity (VA-23-00105819), newest first.
File Type Posted
36C79123Q0038 0001.pdf PDF
OPPORTUNITIES-DESCRIPTION.docx DOCX document
36C79123Q0038_2.docx DOCX document

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

Performance Work Statement (PWS)

A. GENERAL GUIDANCE

1. Title of Project:

Department of Veterans Affairs, Office of Human Resources and Administration/Operations, Security, and Preparedness, Office of Security and Law Enforcement (HRA/OSP/OSLE), External Cybersecurity Platform for Executive Protection (Zerofox).

Background The Department of Veterans Affairs (VA) Office of Human Resources and Administration (HRA), Office of Operations, Security and Preparedness (OSP), Office of Security and Law Enforcement (OSLE) is responsible for developing policies, procedures and standards that govern VA’s infrastructure protection, personal security, and law enforcement programs, protecting Veterans, visitors, and staff on Department facilities and grounds.

OSLE works regularly with several Federal law enforcement agencies in areas such as information sharing, training, planning and policy development. A new law requires OSLE to report police information to congress, consequently requiring for OSLE to purchase a license for usage as an external platform, separate from the VA network system. OSLE’s mission is to effectively deliver quality service to ensure the protection and security of key VA officials by integrating continuous surveillance and the vetting of threats by subject matter experts in physical security. The evolution of modernized laws and regulations expanded OSLE’s responsibility in an ever-changing, fast-paced environment. Demanding the necessity for OSLE to acquire two (2) software licenses for a cyber security platform designed to achieve various established objectives.

2. Scope of Work The Contractor shall possess a software license solution for use as an external cybersecurity platform, separate from the VA network. The Contractor possesses the Executive Protection program, which is a security solution that safeguard senior officials and other high value targets from physical and cyber threats. The Contractor shall provide a robust cloud security product that will (1) monitor the internet by finding and removing fraudulent profiles and content; monitor the dark web for data leakage, theft and malicious activity; (2) alert potential physical threats to the executive based on geographic proximity;

(3) remove PII from data broker sites and include (4) real-time 24/7 continuous managed services and support. The Contractor shall provide a unified infrastructure that will better protect the Office of Security and Law Enforcement (OSLE), the Secretary, Deputy Secretary, or any other Senior VA Official, as required, from on-line threats. The Contract shall provide:

• Two (2) EXECPROTECTPR-G: Monitor digital channels and real-world events that endanger personal safety for very high-profile individuals.

• One (1) MANAGEDPLATFORMG: MANAGEDPLATFORMG: OnWatch Government offers core support for Digital Risk Protection in the public sector including:

o OnWatch Alert: Our team of global SOC first-line threat experts provides 24x7x365 managed services to review, validate, and escalate incidents and prioritize threats on your behalf. Includes: Platform launch configuration and setup, 24x7 managed alert service, standard configuration support and platform tuning, access to advisories, vulnerabilities, strategic intelligence reports and news, 24x7 customer support, and Online, on-demand access to ZeroFox University o Global Intelligence Collection (GIC): Automated and human intelligence collection for protected assets from all relevant OSINT (Surface) and Deep/ Dark Web data sources including major and regional social networks, surface, deep and dark web, covert communication channels, paste sites, e-marketplaces, mobile app stores, blogs, news, job and review sites and forums, code shares, vulnerability databases and more.

o AI Analysis Engine o Finished Intelligence & Vulnerability Advisories Specific to Public Sector as well as other industries o Unlimited users within the agency (NTE two times the number of protected assets) o Unlimited user access within the agency to ZeroFox online training o Platform compliance to social network terms of service, Privacy Act and

First Amendment concerns o Specialized training for customer support around unique public sector policy constraints.

• One (1) TD-60-G: Universal takedowns (60/yr.) for any applicable impersonating or malicious account/site/content and other terms of service violations including from social networks, mobile app stores, paste sites, domains, code shares, and others. Rapidly Identify and automate the removal of malicious sites and content across the public attack surface with visibility over the entire process.

• Three (3) ODI-ANALYSISCREDIT1-G: OnDemand Investigation credits, which include incident support and RFI response and a variety of assessments and investigations, including Executive Threat Assessments, Persons of Interest Investigations, Background Checks, Third-Party Assessments, Travel Assessments, Geopolitical and Strategic Assessments, or Digital Asset Inquiry, Transaction, & Recovery.

3. Period of Performance (POP)

• The period of performance will begin the day of Contract Award and shall be a total of 12 months.

4. Place of Performance

• N/A.

5. Specific Tasks

• The Contractor will provide all the necessary resources to accomplish the deliverables outlined in the Performance Work Statement (PWS).

• Task 1 – Provide full time in house “takedown” team Vendor will provide a full time 24x7x365 in house “takedown” team that works on the behalf of Veteran’s Affairs to remove malicious impersonating profiles, dangerous posts or other content affecting Veteran’s Affairs and/or key VA officials.

o Identify and alert on risks which are analyzed and escalated based on identified risk, context, and perpetrator details.

o Remediate and remove threats that violate the terms of service of the digital platforms. Ensures that all remediation is handled by managed services or configured to automatically queue as requested by customer.

o Hide offensive comments quickly to mitigate any brand reputation damage.

Hiding of these comments/posts of customer-owned accounts makes them invisible to the public without notifying the original poster or fully removing the content, so that the comment can still be properly addressed.

o Block malicious profiles from posting to University owned pages by blocking the fraudulent accounts.

o Delete harmful content such as comments, posts, and profiles that violate Terms of Service (e.g., hate speech) and threaten the customer’s brand across digital channels.

6. Deliverable(s)

• The contractor shall provide OSLE representative with login instructions to platform.

• The contractor shall provide OSLE POC for training and assistance in using platform 24x7x365.

7. Type of Contract

• Firm Fixed Price Contract

8. Quality Assurance Surveillance Plan (QASP)

• The Government will evaluate the Contractor’s performance in accordance with the

Quality Assurance Surveillance Plan (QASP). This plan is primarily focused on what the Government must do to ensure the Contractor has performed in accordance with the performance standards. It defines how the performance standards will be applied, the frequency of surveillance, and the minimum acceptable defect rates.

Deliverable or Requirement

Performance Standard

Acceptable Quality Level

Surveillance Method Outcome

Deliverables & Work Product

100% of deliverables are submitted on-time and accurate requirement zero substantial rewrites

95% of deliverables are submitted on-time and accurate requirement zero substantial rewrites.

100% Inspection, Customer Satisfaction, Customer Complaints

For all tasks, the following applies:

Performance that meets or exceeds the AQL will result in a positive CPARS rating.

Performances that do not meet the required AQL may result in a negative CPARS rating.

9. Security Requirements

• No security clearances or special access is required.

10. Government Furnished Equipment (GFE)/Government-Furnished Information

• None

11. Risk Control

• Inspection by Government

12. General Requirements

• Changes to the statement of work are unlikely but can be made with acceptance by both sides.

• No Travel Required.

13. Government Responsibilities

• VA will provide access to the place of performance of installation and site visit.

14. Security Clause

• The Contractor will have no reason to access sensitive VA information or the VANTHCS computer network. The 6500.6 Appendix A Checklist Sections 2 (checklist table rows 1-7) is not applicable to this contract. Section 3 shall be signed by require signatories. Sensitive VA information is not contained within the system covered by this contract. The Contractor must not remove sensitive information from the VA. The Contractor shall have a current Business Associates’ Agreement with the VA. The Contractor will not have access to sensitive VA information nor the VA’s computer network. The C&A requirements do not apply, and that a Security Accreditation Package is not required.

Performance Work Statement (PWS)

File details come from the government source that posted it. Updated .