DHS CISA Insights Program Updated Draft SOW - 4-21-2023.pdf
PDF 709 KB Posted
- Attached to
- CISA Insights Program Support Federal contract opportunity
- Solicitation number
- PCCS-23-40003
View the file
Other files for this federal contract opportunity
| File | Type | Posted |
|---|---|---|
| DHS CISA Insights Program Support Draft SOW.pdf | ||
| DHS CISA SSN Insights Program Support.pdf |
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
DEPARTMENT OF HOMELAND SECURITY
CYBERSECURITY AND INFRASTRUCTURE SECURITY AGENCY
VULNERABILITY MANAGEMENT
Insights Program Management Support
Statement of Work
April 2023
1.0 GENERAL
1.1 BACKGROUND
The Cybersecurity and Infrastructure Security Agency’s (CISA’s) mission is to lead the national effort to protect and enhance the resilience of the nation’s physical and cyber infrastructure. CISA’s vision is a secure and resilient critical infrastructure for the American people. CISA plays two key roles: the operational lead for Federal Cybersecurity, or the Federal “dot gov” and as the national coordinator for Critical Infrastructure Security and Resilience.
CISA’s organizational structure includes the Cybersecurity Division (CSD), Emergency Communications Division (ECD), Infrastructure Security Division (ISD), Integrated Operations Division (IOD), Stakeholder Engagement Division (SED), and the National Risk Management Center (NRMC).
The CSD leads the Nation’s strategic and unified work to strengthen the security, resilience, and workforce of the cyber ecosystem to protect critical services and the American way of life. Our nation faces unprecedented cybersecurity risk. Increasingly sophisticated adversaries, widespread vulnerabilities in commonly used software and hardware, and broad dependencies on networked technologies threaten the provision of National Critical Functions upon which the American people depend. The CSD organization serves a critical and foundational role in managing and, over time, reducing this risk. The future toward which CSD must drive is a cybersecurity environment in which malicious actors face insurmountably high costs to execute damaging intrusions, vulnerabilities are remediated prior to production deployment or rapidly identified before exploitation, and technology is designed and used to reduce the most harmful and systemic consequences of cyber intrusions.
Within CSD, The Vulnerability Management (VM) Sub-Division’s mission is to enable cyber risk reduction to proactively strengthen national infrastructure resilience. VM’s goal is to set conditions for operators, senior leaders, Sector Risk Management Agencies (SRMAs), Critical Infrastructure (CI), Federal Civilian Enterprise Branch (FCEB), State, Local Tribal and Territorial (SLTT), and other partners to provide useful, timely, relevant, and actionable risk information to influence risk reduction actions throughout the cybersecurity risk management life cycle. VM’s essential mission areas include technology safety, security and quality;
understanding vulnerabilities to minimize attack risk; measure and assess attack surface;
prioritize vulnerabilities; measure and assess cyber risk; prioritize risk practices; education, awareness, and training; and enabling support.
The Insights Branch mission is to reduce vulnerability risk and attack surface exposure through continuous data analysis to enable crucial infrastructure resiliency and stakeholder visibility into cyber threats. Insights is comprised of five sections: Cross Functional Planning and Coordination, Data Statistics and Visualization, Mitigation Insights, Risk Insights, and Performance Insights. The sections work together to implement VM’s mission by developing and disseminating analytic content to stakeholders that enable data-driven decisions and influence operational behaviors to reduce the attack surface and enhance cyber resiliency.
Insights’ activities include advising stakeholders on best practices for data management, risk reduction, and vulnerability mitigation to enhance their cybersecurity posture by improving prioritization, decision making, and mission resilience. Insights works with CISA outreach offices to deliver informative written analytic products to a broad array of stakeholders and partners across CISA and the FCEB, SLTT, CI and private sectors. Insights routinely works with Intelligence Community (IC) partners to integrate unclassified intelligence reports with VM data and turn them into actionable unclassified products. Insights is also projected to expand its mission scope to enrich classified products with unclassified data that is unique to VM for IC consumption to enable intragovernmental cyber defense.
Insights also works with the Federal Acquisition Security Council (FASC) to assess products and technologies that may present a significant risk to the Federal Government, SLTT or CI sectors.
Insights’ assessors work with IC partners to produce classified and unclassified analyses, which are provide to the FASC Council to make decisions on Federal Exclusion and Removal Orders of products.
Insights applies processes to achieve the objectives of new legislation, leadership priority, or other operationally directed work. For example, the Cyber Incident Reporting for Critical Infrastructure Act of 2022 (CIRCIA) became law with the FY22 Omnibus Appropriations bill, H.R. 2471. CIRCIA requires any “covered entity” that experiences a “covered cyber incident” to report such incident to CISA within 72 hours. CISA must issue a final rule within 3.5 years and so must organize internally to conduct the rulemaking, engage with stakeholders, enable our internal people, processes, and technologies to receive and action reports, analyze the incident reports, and produce threat reports using the incident reports.
Insights has a key role in implementing the Cyber Incident Reporting for Critical Infrastructure Act of 2022 (CIRCIA) legislation by leading the analysis of cyber-risk landscape and analytic trends on reported incidents, planning analytic products, coordinating within VM and external to VM for product and planning development, and generating products for a legislative audience.
1.2 OBJECTIVE
The objective is to provide cyber security risk reduction services that enhance Insight’s capabilities, leveraging private sector best practices, knowledge, and innovation that will achieve Insight’s mission requirements. The purpose of the SOW is to specify the work outcomes required of the Contractor to provide support at a level that assures a high probability of their availability and performance to meet the needs of the Insights Branch. Insights has taken important steps to improve its programs and products, and the processes supporting these efforts to achieve its programmatic objectives and mission.
1.2 SCOPE
Insights’ mission is to provide technical cyber risk reduction and also seeks to achieve optimal performance through innovation and transformative approaches that will advance the performance and capabilities of the branch. Insights requires a Contractor with the technical file://hqnas/SHARED/G-A/G-ACS/CAAT%20Team/TOOLBOX/SCOPE%20PARAGRAPHS.doc knowledge and experience required to produce actionable, timely, relevant, and accurate data-driven analysis and risk reduction guidance.
As mission products and solutions are developed, the Contractor shall keep end-state implementation in mind, so that solutions can be implemented to the Department of Homeland Security (DHS) CISA operating environment (both from a technical and business/policy perspective). Throughout performance, the Government will provide information on DHS policies, procedures, security parameters, and other information to support this requirement.
2.0 SPECIFIC REQUIREMENTS/TASKS
The Contractor shall provide enhanced Insights’ capabilities, leveraging private sector best practices, knowledge, and innovation that will result in improved impact of Insights analytic products and advisory activities to their stakeholder base. The Contractor shall provide support at a level that assures a high probability of their availability and performance to meet the needs of the Insights Branch. Insights has taken important steps to improve its programs and products, and the processes supporting these efforts to achieve its programmatic objectives and mission.
2.1 TASK ONE: Program and Product Management
Activities in this task may also occur in an “ad-hoc” or “operational” tempo in response to Requests for Information (RFIs) from leadership or stakeholders due to emerging cyber threats, cyber events, and cyber incidents, or enhanced coordination procedures (ECP).
Responses to these priority activities need to be timely and thorough and may require evening or weekend support.
The Contractor shall develop, manage, and provide various programmatic and communications-based documentation that support and enable projects and activities across the branch. This will include presentations and products designed for various levels of leadership as well as the tailoring and management of specific services within the entire contract.
2.1.1 The Contractor shall provide program and product management that includes program management documentation and conduct program management activities across all Insights Sections in coordination with Insights’ Program and Product Management federal staff. The documentation and activities shall include agile project management approaches that deliver business value. The Contractor shall:
2.1.1.1 Produce reports, briefings, and communication materials in response to
Insights’ stakeholder requests and Branch guidance. Examples include but are not limited to annual reports, Branch-level slides on specific cyber topics, talking points for leadership engagement, and other materials as driven by the Government provided schedule. Reports can be recurring or ad hoc requirements.
2.1.1.2 In coordination with and with the guidance of the Government, the Contractor shall develop risk reduction products that enhance the ability of Federal and Stakeholder Systems. These products shall withstand cyberattacks and incidents by measuring the effectiveness of CISA cyber defense guidance, standards, and directives.
2.1.1.3 Design and develop talking points, briefings, and infographics, including conducting briefing dry runs for presenters as needed and shall tailor the content as needed.
2.1.1.4 Develop program management materials to include but not limited to
Charters (program, project, product), Concept of Operations (CONOPS), Standard Operating Procedures (SOPs), Workflow Processes, Program Management processes, schedule management processes, and other documentation using Government provided templates, and propose areas for improvement to the Government. These Program Management documents may be developed for use at the Division, Sub-Division, Branch and/or Section level. The materials are delivered on ad-hoc schedules with varying delivery timelines with up to twenty annually. The Contractor, in coordination with the Government, shall develop a Program Management Documentation Work plan to outline the documents required.
2.1.1.5 Conduct business process improvement activities, including research, documentation, and evaluation that identify areas for process automation within the Insights Branch. Examples include obtaining feedback related to disseminated analytic products or information through surveys, focus groups or other applicable means.
2.1.2 Develop and maintain communication materials, including content and presentations for CISA to use to communicate with stakeholder groups. The Contractor shall:
2.1.2.1 Develop talking points, executive communications, tasker responses, and other status updates on the Insights mission and products.
2.1.2.2 Update and implement an Insights Communication Plan (currently produced on an annual basis), which is designed to enhance outreach to internal CISA stakeholders across CISA Divisions and External Affairs (EA) for their communications with external stakeholders (FCEB, SLTT, Critical Infrastructure).
2.1.2.3 Tailor the content to suit each intended stakeholder that will provide customized and accurate reports for each audience.
2.1.3 The Contractor, in coordination with the government shall leverage user experience concepts and graphic design best practices that will assist in the development of product templates and wireframes for the visual presentation and conveyance of finished products for intended audiences.
2.1.4 The Contractor shall conduct customer experience (CX) activities to improve Insights’ products and services effectiveness, customer satisfaction, and risk reduction efficiency. The Contractor shall collaborate and provide integrated feedback from key decision makers throughout the solution process.
2.1.5 The Contractor, in coordination with the Government, shall produce reports that are required by legislation. These reports shall include materials and content from briefings, public reports, internal reports, and trend analysis products. The Contractor shall participate in working groups, planning forums, and coordinate across CISA to plan and deliver these outputs. For example, CIRCIA legislation requires monthly reports on the national cyber landscape and quarterly reports on covered cyber incidents.
2.1.6 The Contractor shall update and manage a Common Workflow Framework for requesting intake triage, product output development, resource tracking, and workflow management across the Branch’s functions. Primary workflow tools used by Insights include ServiceNow and SharePoint.
The Contractor shall:
2.1.6.1 Ensure that all Insights product development, Request for Information
(RFI) and support requests follow a defined process that effectively communicates initial feedback to the requestor within a government determined period of time. Ensure that the overall process and status is transparent at all times with status available to the Insights Branch on a real-time basis.
2.1.6.2 Serve as the Insights Intake process email inbox primary point of contact, as well as ServiceNow managers. Ensure the triaging of requests, providing feedback to requestors, and tracking deliverable timelines. The Contractor shall manage operational and steady state ingress and egress, to include records retention policies, production lifecycles, database and repository management, agency level coordination, scheduling, project management, process automation, and creating process workflows.
2.1.6.3 Conduct and manage Branch Production processes, including production meetings, product coordination across the Sections, customer requirements discussions, stakeholder coordination, and other collaboration forums.
2.1.6.4 Develop and maintain a SharePoint product repository for all existing and new products produced for Insights using Government network approved software. The Contractor shall ensure proper version control, transparency, and accessibility for the stakeholders. The Contractor shall update the repository with new content within one (1) week of product finalization and provide quarterly reviews to ensure the repository is up to date. The repository will be subject to Branch-wide continuous process improvements.
2.1.6.5 Incorporate behavioral science and behavioral economics approaches into product development strategies and provide advice on how to improve CISA products and services for more effective risk reduction advice. The Contractor shall implement the recommendations listed in the “FY22 Insights Behavioral Science White Paper” that will be provided by the Government.
2.1.6.6 Provide publications production support for Cross-Functional Planning and Coordination (CFPC) publications, specifically (a) technical writing and editing of updated and new products and publications, and (b) graphics support for these publications with focus on Infographics and other graphic enhancements. This will be used, in both printed and social media.
2.1.7 The Contractor shall in coordination with the Government conduct internal training and meeting forums. The Contractor shall:
2.1.7.1 Plan, organize, and conduct training twice a year for Insights Federal and
Contractor staff. This training with assist individuals in learning about topics that will apply to our mission space and improve overall team analytic tradecraft and innovation.
2.1.7.2 Plan, organize, and conduct Insights Offsite meetings, including agenda development, meeting logistics, and meeting facilitation. Offsites will occur quarterly or as needed.
2.1.7.3 Develop after-action reports, retrospective meetings, product roadmaps, and gap analysis.
2.1.7.4 Develop a communications plan and maintain a stakeholder contact roster to effectively plan, track, and collaborate with cross-agency partners.
2.1.8 The Contractor shall support VM Data as a Service (DaaS) and VM data initiatives, providing support in the scope of the task activities listed above.
2.2 TASK TWO: Data Integration and Analysis
The Contractor shall analyze CISA, cybersecurity, public, and commercially available data and generate analytic outputs for vulnerability and risk intelligence reports for the
Government’s review and distribution to Insights’ stakeholders. This involves performing the following activities in an integrated manner.
Activities in this task may also occur in an “ad-hoc” or “operational” tempo in response to Requests for Information (RFIs) from leadership or stakeholders due to emerging cyber threats, cyber events, and cyber incidents, or enhanced coordination procedures (ECP).
Responses to these priority activities need to be timely and thorough and may require evening or weekend support.
2.2.1 Analytic Planning and Innovation. The Contractor shall identify, operate, maintain, and enhance the tools, processes, and methods needed to address analytical questions and use-cases on vulnerability and risk intelligence products and functions across the branch. Cyber topics may include security at scale analysis, ecosystem response analysis, attack surface evaluation analysis, and cyber resilience analysis. The Contractor shall:
2.2.1.1 Measure the maturity of risk analytics and the cross-agency accessibility of risk data, tailoring risk analytic capabilities and methodologies that will provide situational awareness and risk-reduction recommendations for CISA stakeholders.
2.2.1.2 Identify how to incorporate new analytic technologies such as machine learning, analytic tools, and analytic platforms into Insights work activities leveraging CSD-maintained analytic environments. For example, the Capability Delivery (CD) Sub-Division Analytic Environment (AE).
Additionally, the Contractor shall document the approach in a Data Analytics Strategy and Roadmap.
2.2.1.3 Identify, analyze, and correlate information from existing data sources, products, and visualizations to develop prescriptive and action-oriented analytics leveraging new analytic technologies (e.g., Machine learning), tools, and platforms. The analysis will leverage the use of Python and other scripting languages. The Government will review the information prior to implementation.
2.2.1.4 Discover relationships between disparate data elements using machine learning / artificial intelligence) for enhanced analytics as well as assess relationships based on feasibility factors (e.g., data availability, data quality). The Contractor shall generate a list of proposed analyses based on data gathered and newly identified relationships for the government to review and incorporate.
2.2.1.5 Identify opportunities to exploit advanced analytics such as Artificial
Intelligence (AI) and Machine Learning (ML) for Insights’ mission areas;
leverage simulations, modeling, and scientific thought leadership to advance analytical capabilities, including the enhancement of analytical products by including predictive value-add to the information presented.
2.2.1.6 In coordination with the Government, define forward leaning data and analytics strategy, vision, and roadmap that will provide CISA leaders with all-source information that supports data-driven predictions; identify modern analytics technologies for the Insights analytics platform and technology stack; and lead expert discussions on data analytics maturity and outcome planning sessions to bring data planning into implemented measurable outcomes. The Contractor shall:
2.2.1.6.1 Develop and implement a Data Integration and Analysis of
Correlated Data Sources Plan in coordination with the Government. Analysis proposals should include at a minimum, predictive and action-oriented analytics. The plan shall contain information for data scientists to perform the analyses.
2.2.1.6.2 Perform qualitative and quantitative analyses to identify opportunities for data model enhancement and expansion. The Contractor shall recommend new and innovative methods to improve data management. The Contractor shall develop a conceptual Mapping and Data Integration Plan, which defines the relationship across CISA data holdings, including CIRCIA.
2.2.1.6.3 Develop analytic planning documents related to CI , FCEB, SLLT, and CIRCIA. The Contractor shall use available data to perform regular analysis on FCEB, SLTT, CI entities, and CIRCIA related data which will be used to guide assessment prioritization and integrated with cyber data.
2.2.2 Operational Support. The Contractor shall Conduct planned and ad-hoc activities supporting data analysis processes, including but not limited to collecting data, querying data, normalizing data, performing analysis using analytic and statistical tools, generating analytic output and visualizations, identifying actionable recommendations, and documenting analytic output in communication materials, including interactive outputs format such as dashboards. Cyber topics may include security at scale analysis, ecosystem response analysis, attack surface evaluation analysis, and cyber resilience analysis. The Government will provide the tools to use on the CISA network and expand tool options based on recommendations from the Contractor. Current tools that the Contractor shall be utilizing are Python programming language, the R programming language, AWS Sagemaker, Jupyter Notebooks, Zeppelin, AWS Redshift, Tableau (server, desktop, Web Data Connector). The Contractor shall:
2.2.2.1 Leverage innovative tools and approaches to organize qualitative and quantitative data for analysis. The Contractor shall also make recommendations to the government on how to improve data quality.
2.2.2.2 Perform ad-hoc and on-demand data queries and reports in existing internal and external databases and merge disparate data sets to analyze and display key cyber performance metrics and measures. These cyber performance metrics and measures will be focused on measuring outcomes and impacts as well as other metrics and measures. The Contractor shall conduct these data collection activities on both federal and commercial data sources.
2.2.2.3 Provide support to effectively manage and administer Insights projects and activities, software, and toolsets, including maintaining access lists of who has software and accounts and providing updates as needed.
2.2.3 Product Support. The Contractor shall support Insights steady-state analytic products by developing and executing data analyses. In addition, the Contractor shall continuously assess opportunities to automate and improve steady-state product development. The Contractor shall:
2.2.3.1 Maintain, update, and propose enhancements to Insights analytic products that support a current cyber threat or cyber priority, using all-source data analysis to support the research and development. Cyber topics may include security at scale analysis, ecosystem response analysis, attack surface evaluation analysis, and cyber resilience analysis.
2.2.3.2 Maintain steady-state products including products developed by Cross-functional Planning and Coordination, Risk Insights, Mitigation Insights, Performance Insights, and/or Vulnerability Management and/or Cybersecurity Division leadership.
2.2.3.3 Support operationalizing analytical solutions from Federally Funded Research and Development Centers (FFRDCs), National Laboratories and other Government partners into new or existing Insights’ products and services. Develop analyses and visualizations using CISA data for monthly briefings and quarterly report trend analysis of incidents reported.
2.2.4 Analytic Development. Guided by analytic planning and innovation efforts, the Contractor shall conduct analysis and develop visualization tools, techniques, and models under government guidance as well as provide recommendations to the Government for implementation. The Contractor shall:
2.2.4.1 Conduct analyses that will be tailored to the analytic problem set and data, such as exploratory analysis, prescriptive analysis, predictive analysis, descriptive statistics, data visualizations, and models and algorithms to measure relationships between variables. In performing these analyses, the Contractor shall leverage innovative methods to include but not be limited to machine learning, natural language processing, and graph analytics. The Contractor shall propose use cases and minimally viable products (MVPs) and these use cases will be approved by the Government.
2.2.4.2 Utilize Python, R, and other scripting languages in addition to Tableau, PowerBI, and other business intelligence applications when applicable.
The Contractor shall make visualizations available to stakeholders via multiple platforms and media (e.g., print, email, web, and PDF). In addition, the Contractor shall visualize summaries of data analysis findings via interactive dashboards (e.g., Tableau, PowerBI). The Contractor shall tailor products and services to the technical level of the intended audience.
2.2.4.3 Conduct quarterly and annual data activities related to the Federal
Information Security Modernization Act (FISMA) reporting from Departments and Agencies (D/As) to CISA. These activities include gathering the data from the Government’s existing FISMA data collection system and utilizing scripting language to generate the Quarterly Federal Information Security Modernization Act (FISMA) data master file (Datamart). Conduct data cleansing activities to normalize the data into the master file. The Contractor shall subsequently use the master file as a data source for Insights analytics and visualizations.
2.2.4.4 Develop and implement a self-service Analytic platform (using
Dashboard-type visualizations and data servicing tools) with Government guidance for users to access and analyze various data sources.
Requirements: data discovery, storage and integration; data cleaning and filtering; user interface and customizable operations; self-help data visualization and reporting.
2.2.5 The Contractor shall support VM Data as a Service (DaaS) and VM data initiatives.
2.3 TASK THREE: Risk Insights
The Contractor shall be focused on drawing insights from proactive vulnerability hunting (identification of vulnerabilities) among defined stakeholder attack surfaces (ecosystems) that may significantly impact a US critical infrastructure sector or national critical function if targeted and compromised. The goal is to produce vulnerability and risk intelligence in the form of written analysis, briefings, and other media that apprise CISA leadership, policymakers, and cybersecurity community partners of active and strategic national cybersecurity vulnerability concerns and spur action to reduce risk.
The Contractor shall provide a staffing approach that includes expertise and technical capability across attack surface analysis, vulnerability analysis, threat and risk intelligence, intelligence writing, risk analysis and research topics. Cyber topics may also include security at scale analysis, ecosystem response analysis, attack surface evaluation analysis, and cyber resilience analysis. When directed by the Government to provide risk management analysis the Contractor shall incorporate cyber threat intelligence (CTI) principles into the process when applicable.
The Contractor shall have knowledge of vulnerability assessment/management tools similar to Tenable Nessus, Qualys, AppDetective and be able to work with the associated data outputs from these tools. The Contractor shall be familiar with using attack surface management tools like, BitSight, LookingGlass, BlackKite and other tools. These tools shall allow the Contractor to research vulnerabilities and gather data to inform written analysis. The Contractor shall also have user knowledge of Microsoft O365 applications (Teams, Word, Excel, PowerPoint, Outlook, SharePoint).
Activities in this task may also occur in an “ad-hoc” or “operational” tempo in response to Requests for Information (RFIs) from leadership or stakeholders due to emerging cyber threats, cyber events, and cyber incidents, or enhanced coordination procedures (ECP).
The Contractor shall:
2.3.1 Perform informed attack surface analysis and vulnerability hunting activities, leveraging open-source and commercial tools such as Tenable, Shodan, and others to aid in the production of analytic vulnerability and risk intelligence products.
When applicable, the Contractor shall search and utilize government and commercial cyber data feeds including but not limited to Looking Glass, Mandiant, BitSight, Shodan, Black Kite, and other resources. These government and commercial cyber data feeds will be used to identify and evaluate cyber vulnerability and risk. Access to these data sources will be provided by CISA.
2.3.1.1 Provide risk reduction advice in coordination with the Government to enable stakeholders to proactively mitigate threats on their critical networks before damaging intrusions occur, measuring the effectiveness of key efforts in cyber analytics and vulnerability hunting to reduce the time-to-remediate vulnerabilities.
2.3.1.2 Provide Subject Matter Expert(SME )support to analyze vulnerability, threat, and impact information from government, open source, and commercial sources to make analytic judgments and vulnerability and risk management recommendations. The Contractor shall attend meetings and provide briefings on behalf of the Government when needed.
2.3.1.3 Provide SME level knowledge of National Institute of Standards & Technology (NIST) Cybersecurity Framework (CSF) and MITRE
Adversarial Tactics, Techniques, and Common Knowledge (ATT&CK)/Threat Frameworks. This knowledge will be incorporated into all analysis and reporting as required to enable a common operating picture with cybersecurity partners.
2.3.1.4 Perform data queries in government and commercial databases and merge disparate data sets to analyze and assess stakeholder attack surfaces at an organizational, sector, or national critical function level. The Contractor shall compile findings to generate products focused on the reduction of known vulnerabilities for the Government’s review.
2.3.1.5 Provide SME level personnel with experience and knowledge of intelligence analysis production to advise the Government in implementing standardized processes for production of unclassified vulnerability and risk intelligence as well as leverage their expertise to produce briefings and written products that communicate complex technical information for technical and non-technical audiences.
2.3.1.6 In addition to unclassified activities, the Contractor shall coordinate with IC partners to downgrade intelligence reports and leverage them in combination with unclassified CISA information to produce actionable unclassified products. The Contractor shall coordinate information sharing with IC partners to enrich joint classified products for IC consumption.
2.3.1.7 The Contractor shall collaborate with commercial data vendors and intelligence community partners in order to enhance Insights’ products and to develop Requests for Information (RFIs) for commercial vendor research. This is all to generate data to add to Insights’ analysis.
2.3.1.8 Evaluate current data holdings and availability to identify gaps and needs to improve current and future products.
2.3.2 Perform cybersecurity vulnerability and risk intelligence research and analysis leveraging CISA, open-source, commercial and other cybersecurity data sources in order to develop, written analytic vulnerability and risk intelligence products, including reports, briefings, estimates, infographics, and guidance, for FCEB, SLTT, CI and private sector stakeholders. The aforementioned products could be presented in either classified or unclassified settings depending on the data source.
Cyber topics may include security at scale analysis, ecosystem response analysis, attack surface evaluation analysis, and cyber resilience analysis. The Contractor shall:
2.3.2.1 Develop annual Cyber Risk Summaries for stakeholder groups, as defined by the government, with approximately 18 annually.
2.3.2.2 Provide information for the development of Vulnerability Notes as defined by the government. Vulnerability Notes are delivered ad-hoc at the request of the Government, with approximately 25 annually.
2.3.2.3 Develop monthly Vulnerability Snapshots for stakeholder groups as defined by the government, with approximately 72 annually.
2.3.2.4 Develop Cyber Vulnerability Intelligence Estimates (CVIEs) in coordination with the Government that evaluate systemic risks to national critical functions as they are identified by either the Contractor or the government during risk intelligence research and analysis. CVIEs are delivered ad-hoc at the request of the Government, with approximately 20 annually.
2.3.2.5 Develop quarterly Regional Vulnerability Reports for stakeholder groups, as defined by the Government. Develop infographics and analyses in coordination with the Government that highlight successful MITRE ATT&CK TTPs, Phishing Campaign Techniques, top vulnerabilities exploited and other cyber trend data. The Contractor shall complete at least two (2) infographics with analysis papers and one (1) Top CVE Advisory annually.
2.3.2.6 Develop technical reviews of products and services as determined by stakeholders, such as the Federal Acquisition Security Council, or as requested by the government for the government to review. The Contractor shall conduct technical analyses and report on security at the device-level and defect-level. The Contractor shall conduct digital footprints of the product(s) to discover where vulnerable products reside.
At the request of the Government, the Contractor shall deliver approximately fifteen (15) Digital Footprints annually on an ad hoc basis.
2.3.2.7 Develop content for risk advisories, white papers, infographics, other guidance documents and analytic products on various cybersecurity topics and issues on an ad-hoc basis as directed by the government. At the request of the Government, the Contractor shall deliver fifteen (15) Vulnerability and Risk Products annually on an ad hoc basis.
2.3.3 Provide vulnerability and risk research and development activities that are focused on understanding and contributing to risk reduction policies, standards, and strategies as well as contributing to the improvement and evolution of current vulnerability and risk intelligence analytic processes and methods. Cyber topics may include security at scale analysis, ecosystem response analysis, attack surface evaluation analysis, and cyber resilience analysis. The Contractor shall:
2.3.3.1 Engage in research and development of key performance indicators that identify risk and risk mitigation trends at the direction of the Government.
2.3.3.2 Produce case studies that evaluate the effectiveness of vulnerability management or other risk reduction policies, standards, or strategies as defined by the government.
2.3.3.3 Conduct research on risk quantification in coordination with the
Government to devise better ways to help stakeholders understand their risk posture and work to improve and apply in product deliverables.
2.3.3.4 Assist the government to develop project plans and information sharing for National Laboratories to help with risk-focused projects and activities.
2.3.4 Propose and establish risk analysis and intelligence product development cycles and processes.
2.3.4.1 Develop and maintain, templates, standard operating procedures, and other necessary materials that facilitate production.
2.3.4.2 Develop product and production planning roadmaps and schedules, after-action reports, retrospective meetings, and gap analysis.
2.3.5 Support the Government to research and identify vulnerable devices across the United States for the purposes of entity notification. The Contractor shall:
2.3.5.1 Use Government provided tools to perform research and risk assessment of vulnerable devices.
2.3.5.2 Generate administrative subpoena request forms using government and open-source tools.
2.3.5.3 Develop regional vulnerability reports to help CISA regions identify vulnerable devices in their region and make notifications.
2.3.5.4 Maintain an administrative subpoena targeting strategy plan document to help prioritize subpoena research and subpoena generation.
2.3.5.5 Assist the Government to perform vulnerable entity notifications and coordinate notifications with supporting CISA divisions and regions.
2.3.5.6 The Contractor shall assist the Government to create the Annual Congressional Administrative Subpoena Authority Report.
2.3.6 The Contractor shall develop analytic content using CISA data for monthly briefings and quarterly report trend analysis of incidents reported, incorporating content from other CISA stakeholders including trend analysis of TTPs, and intelligence gaps.
2.3.7 The Contractor shall support VM Data as a Service (DaaS) and VM data
2.4 TASK FOUR: Vulnerability Mitigation Planning
The Contractor shall provide tailored mitigation strategies and improvements plans, for vulnerabilities identified through CISA authorities and cyber security assessment services and to identify, acquire, and verify data requirements to achieve Insights’ analysis and analytic functions.
capability across risk reduction mitigation strategies, vulnerability all-source data analysis, market research, data standards, intelligence analysis and vulnerability research.
The Contract shall have knowledge of secure architecture and implementation of detection/protection mechanisms (e.g., firewalls, IDS/IPS, full-packet capture technologies) and vulnerability assessment/management using tools similar to Tenable Nessus, WebInspect, AppDetective. The Contractor shall be familiar with penetration testing tools (Kali Linux, Metasploit, Cobalt Strike, etc.) and familiar with performing Opensource research for vulnerabilities and prevalence within an organization (Google, Blogs, Social- Media, Forums, Shodan, BitSight).
Activities in this task may also occur in an “ad-hoc” or “operational” tempo in response to Requests for Information (RFIs) from leadership or stakeholders due to emerging cyber threats, cyber events, and cyber incidents, or enhanced coordination procedures (ECP).
2.4.1 The Contractor shall define and develop capabilities, which assist in the development and standardization of risk reduction mitigation strategies for CISA stakeholder groups. In coordination with the Government, the Contractor shall drive the mitigation of critical cyber vulnerabilities and measure the utilization and effectiveness of CISA’s cyber vulnerability assessments to increase identification and mitigation of vulnerabilities, reducing the window that adversaries have to exploit critical infrastructure. Cyber topics may include security at scale analysis, ecosystem response analysis, attack surface evaluation analysis, and cyber resilience analysis. The Contractor shall:
2.4.1.1 Contribute to reports, and identify gaps in risk reduction mitigation strategies, targeting both internal CISA CSD and external (FCEB, SLTT, CI and private) stakeholders.
2.4.1.2 Prepare reports of findings of the FCEB, SLTT and CI stakeholder departments and agencies who have undergone cybersecurity assessment(s), illustrating data graphically and translating complex findings into written text and presenting results for the Government’s review.
2.4.1.3 Perform a Root Cause and Risk Prioritization Analysis to determine the security posture of stakeholders’ operational cyber security environment and provide CISA with tools (process focused) and services to mitigate current and/or future vulnerabilities.
2.4.2 The Contractor shall develop tailored post-assessment mitigation plans for (High
Value Asset (HVA), Validated Architecture Design Review (VADR), Federal Incident Response Evaluation (FIRE), Risk and Vulnerability Assessment (RVA), Security Architecture Review (SAR), Cyber Hygiene (CyHY), and Phishing Campaign Assessment (PCA) products and services to the federal task leads standard in order to maximize “return on mitigation” and reduce the probability and impact of cybersecurity risks (to reduce potential for loss, damage, or destruction).
2.4.3 The Contractor shall document identified vulnerability mitigation challenges of CISA stakeholders including FCEB, SLTT, CI and Private Sector in a CISA Stakeholder Vulnerability and Mitigation Challenges deliverable. The Contractor shall gather data on the scope of the stakeholder’s vulnerabilities and potential risk impacts.
2.4.3.1 The Contractor shall review and analyze vulnerability data to identify trends and patterns and provide descriptive, actionable mitigation recommendations to assist CISA stakeholders including FCEB, SLTT, CI and Private Sector. The Contractor shall recommend risk management standards, cybersecurity policies, and design and implement vulnerability mitigations reporting and monitoring solutions. Cyber topics may include security at scale analysis, ecosystem response analysis, attack surface evaluation analysis, and cyber resilience analysis.
2.4.3.2 The Contractor shall provide technical mitigation advice for vulnerabilities, including responding to requests from VM and CISA for mitigation advice content to use in response to new vulnerability events or incidents.
2.4.3.3 The Contractor, in coordination with the Government, shall develop and maintain a mitigation register to prioritize vulnerability resolution with each organization.
2.4.4 The Contractor shall develop, design, and conduct qualitative and quantitative custom market research to identify new data sets in areas including, but not limited to, data requirements standardization and analysis, in order to meet branch requirements and improve upon products and services.
2.4.4.1 The Contractor shall plan, coordinate, document and administer all activities related to the integration of third-party data sources into current and future written analysis, briefings, and other media that apprise CISA leadership, policymakers, and cybersecurity community partners of active and strategic national cybersecurity vulnerability concerns.
2.4.4.2 The Contractor shall regularly assess current and potential data sets and data outputs from internal and external data sources for data quality parameters and provide recommendations to the government for improvement.
2.4.4.3 Per Government standards and systems, the Contractor shall develop a searchable VM Data Catalog that support Insights which describes each data set with access instructions and usage/sharing policies.
2.4.5 The Contractor shall support processes for CISA’s administrative subpoena authority; by researching cyber security vulnerabilities, documenting, and providing tailored mitigation strategies to resolve/ remediate cyber security vulnerabilities.
2.4.5.1 The Contractor shall assist and evaluate real-world threats/vulnerabilities using opensource methods and commercial tools to determine tailored mitigation strategies around targeted technologies in support of CISA’s cyber security authorities
2.4.5.2 The Contractor shall track all administrative subpoena requests and provide weekly status reports to the government.
2.4.5.3 The Contractor shall assist the Government to create the Annual Congressional Administrative Subpoena Authority Report.
2.4.6 The Contractor shall support VM Data as a Service (DaaS) and VM data
2.5 TASK FIVE: Performance Insights (PI)
The Contractor shall provide the Insights Branch (VM) an organic and scalable capability that focuses on measuring performance and effectiveness across many Lines of Effort (LOE), including but not limited to products and services, legislative actions, organizational planning, implementation of AOP objectives, and mission focus surge events. Additionally, the PI Section will maintain capability development portfolio oversight, with all other sections in supporting roles leading projects, to ensure projects are meeting capability gap requirements in a timely manner.
capability across foundational traits for success, including Managing the oversight of capability developmental work, measuring and quantifying mission value and impact within workflow design, outputs and customer engagements, Establish, analyze and report on Measure of Effectiveness (MoE) and Measure of Performance (MoP) criteria, and assist with aligning section tasks to AOP and Agency strategy to ensure both current missions, and future mission needs are being accomplished.
Activities in this task may also occur in an “ad-hoc” or “operational” tempo in response to Requests for Information (RFIs) from leadership or stakeholders due to emerging cyber threats, cyber events, and cyber incidents, or enhanced coordination procedures (ECP).
2.5.1 The Contractor shall enable and mature Branch and Sub-Division mission focus that will result in overall accomplishment of reducing stakeholder risk through study and refinement of workflow value and effectiveness. The Contractor shall:
2.5.1.1 Perform work aligned to agency and branch Annual Operating Plan (AOP) tasks, maintain executive level tracking of R&D projects with technical leads within Insights, and support establishing any temporary Strategic Focus working groups, managed by the VM Leadership, to drive viable outputs to staffing goals, funding needs, and mission priorities.
2.5.1.2 Deliver a monthly Developmental Projects Requirements Traceability and Health Report, with a template coordinated with the government upon award, and Contractor proposing areas for improvement as the reports are delivered based on feedback from recipients.
2.5.1.3 Increase Insights’ readiness to respond to long term VM strategic focus mission changes that impact CISA Cyber mission space, by supporting strategic tasks and activities.
2.5.1.4 In coordination with the Government, measure the increase in and impact of key products and services available to different stakeholder groups.
2.5.1.5 The Contractor shall demonstrate the ability to engage in planning in conjunction with the government for long term goal accomplishment; as well as aggregate knowledge of new technologies, tools, and capabilities critical to long term success that the government can leverage.
2.5.1.6 Support legislative required efforts levied to the branch and perform key enabling functions from their existing required tasks as needed.
2.5.1.7 Prepare inputs for ad-hoc critical mission tasks that may arise during steady state work activities, causing a need to shift workflow priorities and focus during temporary surge requirements.
2.5.2 The Contractor shall support the Insights Strategy Cell, a cross-functional team collaborating on branch strategic initiatives that proactively assess future cyber issues and identify, implement, and support strategic work activities. Cyber topics may include security at scale analysis, ecosystem response analysis, attack surface evaluation analysis, and cyber resilience analysis.
2.5.3 The Contractor shall contribute to the development of outreach and coordination for analysis of Measures of Performance and Effectiveness, while maintaining oversight and alignment to capability development efforts. The Contractor shall:
2.5.3.1 Engage directly with external and internal stakeholders on performance auditing and coordination plans to evolve rending analysis, identifying long-term customer interactions and feedback opportunities, and emerging needs or refinement in our product lines and capability development projects.
2.5.3.2 Balance current process workflows with development efforts being conducted by national lab initiatives.
2.5.3.3 Prepare reports of findings of the FCEB and SLTT stakeholder departments and agencies who have received and utilized VM Insights cybersecurity products, analysis outputs or guidance, illustrating data graphically and translating complex findings into written text and presenting results for the Government’s review.
2.5.3.4 Deliver a monthly Measure of Performance and Effectiveness Summary Report, utilizing a template that has been approved and coordinated with the government. The Contractor shall propose areas for improvement as feedback comes back from stakeholders and on the content of the report.
2.5.3.5 Perform outreach discussions, with internal partners for data and process sharing opportunities to capitalize on existing tradecraft to further the MoP and MoE abilities of the section.
2.5.4 The Contractor shall examine and recommend process improvements on current mission outputs that evolves strategic vision plan execution through implementation of distinct Measure of Performance (MoP) and Measure of Effectiveness (MOE) criteria and audits. The Contractor shall:
2.5.4.1 Perform tasks that assists with force multiplying the operating traits of the
Performance Insights Sections, that is focused on both MoP and MoE functions along with Developmental Oversights for capability gaps. This will include executive level communications and planning inputs, roadmap POA&M development, process oversight, and structured task organization tracking.
2.5.4.2 Research and identify opportunity areas for branch-wide improvement, including scaling capabilities and process flows to all VM and CSD needs.
2.5.4.3 Provide support and perform Key Performance Indicator (KPI), Measure of Effectiveness (MoE), and Measure of Performance (MoP) analysis, while managing data captures to measure cyber program effectiveness, product impacts, and evaluate feedback across CSD requirements to reduce risk and enforce existing policies of accountability
2.5.4.4 Implement…
This is the start of the file's text. The full file is on GovTribe.
File details come from the government source that posted it. Updated .