Performance Work Statement.pdf
PDF 347 KB Posted
- Attached to
- Cyber Security Support Services Federal contract opportunity
- Solicitation number
- NOF-0008
About this file
This document is a Performance Work Statement (PWS) for a federal contract opportunity to acquire Cybersecurity Support Services for the transformation, implementation, operation, and maintenance of the Office of the Chief Information Security Officer (OCISO) Cybersecurity Program at the Department of Housing and Urban Development (HUD).
The key objectives of the contract include establishing and operating a Security Architect Review (SAR) and Security Systems Engineering (SSE) program, a Data Security Program, an Identity, Credential, and Access Management (ICAM) program, a Zero Trust Architecture program, a Cybersecurity Supply Chain Risk Management program, an Information System Security Officer (ISSO) support function, a Governance, Risk, and Compliance program, a Security Operations Center, and an Enterprise Vulnerability Management/Continuous Diagnostics and Mitigation program. The contract has a one-year base period and two one-year option periods, with a maximum 60-day mandatory assessment period upon award. The government may exercise FAR clause 52.217-8 to extend services. Proposals should include key personnel with specific cybersecurity certifications. There is potential for organizational conflicts of interest related to this effort.
View the file
Other files for this federal contract opportunity
| File | Type | Posted |
|---|---|---|
| Draft RFI CyberSecurity (1).pdf |
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
pg. 1
STATEMENT OF OBJECTIVES (SOO)
FOR
Office of the Chief Information Security Officer (OCISO) Cybersecurity Program
Transformation
AT
U.S. Department of Housing and Urban Development
September 11, 2024
Version 2.0
DRAFT
pg. 2
Table of Contents
SECTION I
1.0 DESCRIPTION OF SERVICES
1.1 General
1.1.1 Background
1.2 Scope
SECTION II
2.0 PROBLEM STATEMENT
2.1 Applicable Regulations (if any)
2.2 Objective(s)
2.3 Final Outcome
SECTION III
3.0 DELIVERBALE / PERFORMANCE THRESHOLDS
SECCTION IV
4.0 DELIVERABLES
SECTION V
5.0 TIMELINE, STAKEHOLDER (collaborating offices)
5.1 Timeline
5.2 Stakeholders (Collaborating Offices)
SECTION VI
6.0 GENERAL INFORMATION
6.1 Location
6.2 Travel (TDYs)
6.3 Identify Known or Possible Conflicts of Interest
6.4 Security and Training Requirements
SECTION VII
7.0 APPENDIX 1
7.1 DEFINITIONS, ABBREVIATIONS, AND ACRONYMS)
7.2 ACRONYMS............................................................... Error! Bookmark not defined.
pg. 3
SECTION I
1.0 DESCRIPTION OF SERVICES
1.1 General. The U.S. Department of Housing and Urban Development’s (HUD’s) mission is to provide safe, decent, affordable housing for the American people while being good stewards of taxpayer dollars. The vision is to continually seek to improve how HUD effectively and efficiently delivers programs of value for those HUD is charged to serve.
1.1.1 Background. The U.S. Department of Housing and Urban Development’s (HUD’s) Office of the Chief Information Security Officer (OCISO) is seeking support in modernizing the cybersecurity program to include audit management policies and processes, capabilities, and services. OCISO is entrusted to implement, manage, and operate an enterprise cybersecurity program to protect HUD’s information and systems, while enabling the Department’s core programs. HUD requires an enterprise-wide approach to coordinate cybersecurity oversight, reporting, management, and implementation. An enterprise-wide approach affords HUD the opportunity to become more proactive in seeking vulnerabilities/deficiencies in its information systems/assets, increasing employee/contractor cybersecurity knowledge, adjusting cybersecurity training, and enhancing reporting to internal and external stakeholders. As the cyber threat landscape evolves, presenting increasingly sophisticated cyber risks, HUD requires a mature and agile cybersecurity program equipped with the necessary strategy or roadmap with defined goals and milestone for the program, Department level support, qualified resources, and well-defined, risk-informed strategy that will enable HUD’s mission and protect U.S. citizens.
In early 2019, the Office of the Chief Information Officer (OCIO) sought contractor support services for a discovery effort to understand the current state of HUD’s cybersecurity posture and the maturity of its cyber program. In this discovery exercise, also known as HUD’s Cyber
Program Phase I (Phase I), the contractor assessed HUD’s current risk environment, critical IT assets, and existing vulnerabilities identified by the Government Accountability Office (GAO) and the Office of Inspector General (OIG). During HUD’s Cyber Program Phase II (Phase II), OCIO, OCISO, and with contractor-support continued this collaboration, formalizing the foundation of a mature HUD cyber program by integrating advanced cybersecurity technologies, processes, and policies across the Department.
Within the last two years (end of 2022 - present), the OCISO has doubled in manpower and working on progress with enterprise cyber solutions and milestones mandated from EO 14028.
There are still some challenges with becoming more proactive in seeking vulnerabilities/deficiencies in its information systems/assets, increasing cybersecurity knowledge, implementing the supply chain risk management program, updating cybersecurity training, and enhancing reporting to internal and external stakeholders.
1.2 Scope.
Program Goals: To acquire Cybersecurity Support Services for the transformation, implementation, operation, and maintenance of the OCISO Cybersecurity Program. Specific requirements are Cybersecurity Program Management, Security Architecture, Security
pg. 4
Operations Center, Governance, Risk, and Compliance (GRC), Cyber Strategic Initiatives, and
Vulnerability Management/Continuous Diagnostics and Mitigation. These services are required to provide the Department a sustainable organic proactive and reactive cybersecurity policies and processes to protect HUD’s operating environment against a dynamic threat environment.
Program Efficiencies: OCISO will continue to improve on a mature proactive cyber strategy and roadmap that is realistic and executable.
Change Areas: OCISO will build out newer domains such as its Information System Security
Officer (ISSO) support, proactive vulnerability management, and Security Architecture and
Innovation. Additionally, OCISO will improve existing functions, such as Information
Security Continuous Monitoring (ISCM) program and leverage automated mechanism. The program needs an effective governance function for communication across all program offices and to improve processes for responding to cyber incidents.
Program Risks: Push back from hiring due to re-organization approvals and past stagnant actions to hire when available and lack of funding due to past mishandling of budget allocations.
Due to the dynamic nature of transformations, modifications to increase the level of support are highly likely. The contractor should be prepared to increase support based on the needs of the
Government. Any increase in scope will have to be determined fair and reasonable. FAR
Clause 52.217-8 will be included in this contract.
SECTION II
2.0 PROBLEM STATEMENT
Currently OCISO lacks strategic development and planning, governance, enterprise risk management, cyber transformation, and process improvement and innovation. There is a lack of policy development, knowledge management, zero trust design and implementation, progression with logging and program plan and action development of an enterprise cybersecurity program to protect HUD's information and systems, while enabling the Department's core programs.
The Contractor shall provide all services, materials, supplies, equipment, travel, and project supervision, as required in connection with this Statement of Objective (SOO).
2.1 Applicable Regulations (if any).
2.2 Objective(s).
2.2.1 Mandatory Assessment Period (Maximum 60 days from contract award). The contractor shall complete an assessment of the program to ensure the proposed solution is the most advantageous. After completing the assessment, the contractor can make a one-time adjustment to the proposed solution with up to 15% increase or unlimited decrease in price or tasks.
2.2.2 Security Architecture and Innovation:
pg. 5
• Establish and operate a Security Architect Review (SAR) and Security Systems
Engineering (SSE) program that will establish and enforce security controls for HUD’s
IT transformational projects to reduce risks prior to deployment and improve assessment turnarounds.
• Establish and implement a SAR capability that incorporates security into the software development life cycle (SDLC), establishes roles and responsibilities for security activities, and implements security configurations to prevent project delays and reduce vulnerabilities.
• Conduct research on security technologies, processes and procedures including exploring the latest advancements in security solutions, evaluation their effectiveness, and understanding how security solutions can be integrated into existing frameworks.
• Perform security reviews of HUD’s planned and existing architecture.
• Establish, implement, and evaluate HUD-specific security architecture and SSE principles standards, policies, procedures, and processes against industry best practices to provide perimeter security, network security, endpoint security, application security, physical security, and data security for all ~300,00 IT assets. Currently HUD OCISO doesn’t have any existing policies and procedures that we could provide from the past to provide a current listing for reference.
• Maintain security models and artifacts in HUD’s enterprise architecture and cybersecurity repositories. We currently do not have a repository or any security models and artifacts to reference our way forward from past contracts, due to unorganized turnovers within the office. There was a previous contractor (ManTech), but we don’t have all those documents at our disposal or the location of those documents to reference. Review the proposed architecture for all planned and existing cybersecurity solutions, that provide protection for the Department’s General Support Systems (GSS), Major Applications
(Mas), Minor Applications and Cloud Service Provider (CSP) Services and assess the extent to which these solutions are properly architected and engineered. HUD OCISO can provide what we can find, but we don’t have a central repository of past documentation and work done by previous customers.
• Research, analyze and recommend innovative technologies, processes, and procedures for entire cybersecurity program.
• Develop mechanisms for integration and information sharing between the SAR/SSE and other HUD stakeholders.
Data Security Program:
pg. 6
• Initiate and operate a Data Security Program (DSP) aimed at safeguarding the organization's sensitive information assets and ensuring compliance with data security laws, policies, and regulations.
• Develop data security policies, procedures, and standards that address identified risks and compliance requirements.
• Analyze potential data security risks and evaluate data security measures.
• Research and identify data security solutions such as data encryption, data loss prevention (DLP), cloud access security brokers (CASB), etc.
• In coordination with the Chief Data Officer and Zero Trust Program Office, identify and classify data, establish data movement monitoring, and implement data access controls defining who can access data based on attributes such as role, office, security clearance, location, etc.
• Currently HUD OCISO does not have any existing data security program policies, procedures, or artifacts that we could provide.
Identity, Credential, and Access Management (ICAM) Program:
• Establish and operate an Identity, Credential, and Access Management (ICAM) program, tailored to bolster the organization's security posture and operational efficiency by reducing security vulnerabilities and streamlining user access across all systems. This enterprise program is a federal requirement that is HUD is currently delinquent in accordance with federal regulations.
• Develop policies, procedures and standards to effectively manage digital identities, credentials, and access controls across all systems and platforms in accordance with laws, policies, and regulations.
• Create and maintain the ICAM strategic plan.
• Implement a governance structure that defines roles and responsibilities within the
ICAM framework and ensures accountability.
• Analyze potential identity security risks and evaluate identity security measures.
• Research and identify security solutions such as phishing-resistant Multi Factor
Authentication, Identity Governance and Administration (IGA), Federated Identity
Management and Risk-based Authentication.
• In coordination with Enterprise Architecture, develop and maintain ICAM capabilities and technologies roadmaps.
• Develop and maintain ICAM implementation plan.
• Monitor the deployment of ICAM solutions across HUD, ensuring integration with existing IT infrastructure.
• Report on ICAM solution metrics.
pg. 7
• Coordinate with IT and security teams to implement ICAM technologies.
Zero Trust Architecture Program:
• Create and operate a Zero Trust Architecture (ZTA) Program, tasked with providing expert guidance, governance, and oversight for the organization's transition to a Zero
Trust security model. The program will be responsible for defining the strategic direction, policies, and standards necessary to implement a Zero Trust framework, emphasizing the core principle of "never trust, always verify."
• Create and maintain the Zero Trust strategic plan.
• Implement a governance structure that defines roles and responsibilities within the Zero
Trust framework and ensures accountability.
• Analyze Zero Trust requirements and identify and evaluate security measures to meet the requirement.
• Research and identify Zero Trust technical and procedural solutions.
• In coordination with Enterprise Architecture, develop and maintain Zero Trust capabilities and technologies roadmaps.
• Develop and maintain Zero Trust implementation plan.
• Monitor the deployment of Zero Trust solutions across HUD, ensuring integration with existing IT infrastructure.
• Develop and provide training to promote awareness of Zero Trust initiatives and processes.
• Report on Zero Trust solution metrics.
• Coordinate with IT and security teams to implement Zero Trust technologies.
2.2.3 Strategic Initiatives (SI):
• Manage and govern the cybersecurity supply chain risk management (SCRM) program.
Update existing SCRM procedure. SCRM to provide HUD with a framework to proactively manage supply chain risks from a cybersecurity perspective and to adhere to federal regulations.
• Identify and prioritize exiting supply chain vendors into risk levels based on services provided by vendors. This includes the documented process and the identifying the risk designation of each vendor in the Cyber Security Assessment Management (CSAM) toolkit.
• Conduct up to 50 security risk assessments annually against third parties to satisfy the
NIST SP 800-53 Rev. 5 Supply Chain Risk Management (SR) controls at the system-level.
pg. 8
• Integrate security-related, supply chain risk management (SCRM) concepts into the
Information Security Continuous Monitoring (ISCM) as part of the transition to National
Institute of Standards and Technology (NIST) Special Publication (SP) 800-53 Rev. 5 transition to address untrustworthy suppliers, insertion of counterfeits, tampering, unauthorized production, theft, insertion of malicious code, and poor manufacturing and development practices throughout the SDLC.
• Support the implementation of OMB M-22-18 and the integration of the Secure Software
Development Form into the SDLC and ISCM.
• Support HUD to establish a Cybersecurity workforce strategy and implementation plan that can obtain and maintain industry certifications and academic credentials for the
Departments cybersecurity workforce.
• For each key role (up to 4), establish certificate pathway to include establishing training requirements, accountability, and tracking.
• Implement governance to manage the execution of the certificate pathways across roles to include coordination with
• Support Information System Security Officer (ISSO) function to include supporting ATO package development for approximately 30 major applications and General Support
Systems. Packages should be developed in accordance with NIST SP 800-53 Rev. 5
• Develop implementation plan and strategy to centralize the ISSO Support function under
OCISO.
2.2.4 Governance, Risk, and Compliance:
• Develop a new dashboard with views to support Risk Management Framework and the
Cybersecurity Framework (CSF), establish new performance metrics, and develop APIs with existing data sources to automate functionality.
• Define views and processes to leverage information from the CDM dashboard to support reporting to include training key stakeholders.
• Support automation of existing processes through development of Power Apps. Redesign
OCISO HUD@Work page and template and knowledge repositories (both internal and external).
• Provide analysis and review of new and emerging federal information security and privacy policies, directives, and mandates within the timeframes specified by HUD.
• Determine policy/procedures ownership and track the associated implementation timelines to ensure adherence to the requirements.
• Conduct market research and establish a roadmap and requirements for a modernized
Governance Risk and Compliance (GRC) tool.
pg. 9
• Assist in the agency-led High Value Asset (HVA) assessments in compliance with the
Cybersecurity and Infrastructure Security Agency (CISA) Assessment Evaluation and
Standardization (AES) Program.
• Update and enhance HUD’s Entity-Wise Business Impact Analysis (EWBIA).
2.2.5 Security Operations Center (SOC):
• Real-time Alert Monitoring and Triage: Monitor and triage incoming security alerts in real-time, prioritizing based on severity and potential impact.
• Incident Reporting: Promptly document and report security incidents following established procedures, ensuring accurate and comprehensive reporting for further analysis and response.
• Incident Analysis and Investigation: Conduct thorough analysis and investigation of security incidents to determine root causes, attack vectors, and potential impact on systems and data.
• Containment, Eradication, and Recovery: Implement effective containment strategies to prevent further spread of security incidents, eradicate threats from affected systems, and facilitate timely recovery of impacted assets.
• Incident Coordination: Coordinate response efforts across relevant teams and stakeholders, ensuring clear communication and collaboration to mitigate security incidents efficiently.
• Forensic Artifact Analysis, Malware Analysis: Perform in-depth forensic analysis of digital artifacts and conduct malware analysis to understand the nature of security threats and develop effective countermeasures.
• Cyber Threat Intelligence Collection, Processing, and Fusion: Collect, process, and fuse threat intelligence from various internal and external sources to gain insights into emerging threats, attacker tactics, techniques, and procedures (TTPs).
• Cyber Threat Intelligence Analysis and Production: Analyze gathered threat intelligence to identify patterns, trends, and indicators of compromise (IOCs), producing actionable intelligence reports to inform defensive strategies.
• Cyber Threat Intelligence Sharing and Distribution: Share relevant threat intelligence with peer organizations, industry groups, and government agencies to enhance collective defense and improve overall cybersecurity posture.
• Threat Hunting: Proactively search for signs of malicious activity within the network environment, utilizing advanced techniques and tools to detect and mitigate threats before they escalate.
• Sensor and Analysis Tuning: Continuously fine-tune security sensors and analytical tools to improve detection capabilities and reduce false positives, enhancing the overall effectiveness of threat detection and response.
pg. 10
• Custom Analytics and Detection Creation: Develop and deploy custom analytics and detection mechanisms tailored to the organization's specific threat landscape, leveraging advanced data analytics and machine learning techniques.
• Machine Learning: Explore and utilize machine learning algorithms to enhance threat detection, prediction, and response capabilities, enabling more adaptive and proactive cybersecurity defenses.
• Adversary Emulation and Red Teaming: Develop and execute sophisticated adversary emulation exercises and red team engagements to simulate realistic attack scenarios, evaluate defensive capabilities, and identify vulnerabilities across people, processes, and technologies. Through these exercises, the SOC aims to proactively enhance detection, response, and mitigation strategies while fostering a culture of continuous improvement in cybersecurity posture.
• Purple Teaming: Facilitate collaborative engagements between red and blue teams to foster knowledge sharing, mutual understanding of tactics, techniques, and procedures
(TTPs), and the iterative refinement of defensive strategies. By leveraging purple teaming exercises, the SOC seeks to strengthen detection and response capabilities, optimize security controls, and enhance overall resilience against advanced threats. The SOC will systematically assess the severity and potential impact of identified vulnerabilities, prioritize remediation efforts based on risk factors, and provide actionable insights to relevant stakeholders for timely mitigation.
• Continuous Improvement and Knowledge Sharing: Foster a culture of continuous improvement within the SOC by promoting knowledge sharing, skills development, and cross-functional collaboration. Regular debriefs, post-incident analyses, and lessons learned sessions will be conducted to identify areas for enhancement, disseminate best practices, and ensure alignment with industry standards and emerging trends.
• Integration of Threat Intelligence: Integrate actionable threat intelligence derived from internal and external sources into adversary emulation, red teaming, and vulnerability analysis workflows. By leveraging real-time insights on emerging threats, attacker TTPs, and exploit techniques, the SOC aims to enhance proactive detection, threat hunting capabilities, and strategic decision-making to stay ahead of evolving cyber threats.
• Metrics and Reporting: Define key performance indicators (KPIs) and metrics to measure the effectiveness of expanded SOC operations, including the success rate of adversary emulation exercises, vulnerability remediation timelines, and overall improvement in defensive capabilities. Regular reporting to executive leadership and stakeholders will provide visibility into the SOC's contribution to risk reduction, incident response readiness, and organizational resilience.
• Compliance and Regulatory Alignment: Ensure that expanded SOC operations adhere to relevant industry regulations, compliance requirements, and best practices. By maintaining alignment with regulatory frameworks and industry standards, such as
GDPR, HIPAA, PCI DSS, and NIST Cybersecurity Framework, the SOC will demonstrate a commitment to safeguarding sensitive information, protecting customer privacy, and mitigating legal and regulatory risks.
pg. 11
2.2.6 Enterprise Vulnerability Management/Continuous Diagnostics and Mitigation:
• Coordinate with HUD’s CDM Integrator, to align CDM capabilities with HUD’s cybersecurity strategy and roadmap. The Vulnerability Management and CDM program will need maturation to help reduce agency wide risks and improve alignment with
HUD’s cybersecurity goals.
• Develop and maintain SOPs to guide how HUD utilizes the existing hardware asset management (HWAM), software asset management (SWAM), Configuration Settings
Management (CSM), and Vulnerability Management (VUL) tools to reduce CDM
Agency-Wide Adaptive Risk Enumeration (AWARE) scores and improve FISMA metrics.
• Manages account/access/managed privileges (PRIV), trust determination for people granted access (TRUST), credentials and authentication (CRED), and security-related training (BEHAVE).
• Vulnerability Report Intake and Analysis: Establish streamlined processes for the intake, prioritization, and analysis of vulnerability reports from the Vulnerability Management
Team and other various sources, including automated scanning tools, security researchers, and internal assessments.
• Manages network and perimeter components, host and device components, data at rest and in transit, and user behavior and activities. This includes management of events
(MNGEVT); operate, monitor, and improve (OMI); design and build-in security (DBS);
boundary protection (BOUND); supply chain risk management (SCRM); and ongoing authorization.
• Manages the protection of data through the capabilities: data discovery/classification
(DISC), data protection (PROT), data loss prevention (DLP), data breach/spillage mitigation (MIT), and information rights management (IRM).
• Develop the CDM Operational Methodology that includes a continuous process for discovering assets and risks, monitoring environmental changes, analyzing and reporting risks to stakeholders, and to mitigate cyber risks.
• Utilize the suite of CDM tools and capabilities to identify risks to the security of the enterprise.
• Analyze HUD’s existing CDM tools, recommend additional coverage and requirements based on HUD’s cybersecurity strategy, and standardize how CDM tools are operated.
• Analyze unused or misused licenses and provide recommendations to user license management.
• Develop actionable risk reports utilizing the CDM tools from data generated by CDM tools.
pg. 12
2.2.7 Optional:
Depending on available funding, HUD would like to turn to the below optional support once funding is available to support the below activities. Currently our current customer is providing the services, but HUD will need more qualified and quality work in order to sustain the program.
SI Surge Support:
• Provide cybersecurity training, awareness, and communications support.
• Develop an annual training and awareness plan. Conduct Incident Response Exercises
(tabletop and live scenarios).
• Update existing training courses and develop new trainings (all trainings should be delivered as SCORM files unless otherwise specified by the Government).
• Execute awareness campaigns to include HUD-wide Lunch and Learns.
• Support ISSO forum, developing materials and coordinating.
• Perform an annual Enterprise Cyber Security Roles Analysis (ECRA).
• Develop and update training procedures and program charter.
• Support reporting on training completions.
GRC Surge Support:
• Draft and update information security policies, procedures, processes, standards, technical guidance, and templates, shepherd them through the appropriate review process, and provide training to key stakeholders.
• Support cybersecurity risk management to assist the Department to better understand, manage, and reduce its cybersecurity risks.
• Provide assessment support for initial ATOs, re-authorization, and ISCM. Establish automated testing mechanisms to enhance assessment support.
• Manage and evaluate POA&M closure requests.
• Support data calls to include quarterly Federal Information Security Modernization Act
(FISMA) self-reporting and ad hoc data calls from external entities such as OMB.
• Support cybersecurity audit management to include tracking, developing executive briefs, establishing Corrective Action Plans (CAPs), and supporting Prepared by Client (PBC) requests.
• Perform document compliance reviews such as Risk Based Decisions (RBDs), Memorandum of Understanding (MOU), Information Security Agreements (ISAs), etc.
• Provide tracking and monitoring of RBDs.
• Provide HVA governance support.
• Support the transition from NIST 800-53 Rev. 4 to Rev. 5. Develop reports and briefs for program offices, demonstrating compliance with HUD IT Security Policy.
pg. 13
• Perform annual retrospectives across all FISMA domains based on defined metrics and establish lessons learned.
2.2.8 Final Outcome. At the end of contract performance the OCISO Cybersecurity Program shall fully transform the OCISO project management and hiring process to include intern programs; make 75% progress or greater with the milestones within the EO 14028 to include implementation of Zero Trust; develop an executable cyber strategy; improve processes and complete backlog of audit recommendations; implement the Supply Chain Risk Management
Program within Strategic Initiatives and update cybersecurity training program; and provide knowledge and support to transform and develop processes and policies for the Vulnerability
Management and Continuous Diagnostic and Mitigation Program.
SECTION III
3.0 PERFORMANCE THRESHOLDS
All deliverables and performance that fall below the outlined thresholds below will be re-performed at no cost to the Government. Any task, performance, or deliverable(s) that is not corrected greater than 95% acceptance for accuracy and timeliness will be reflected negatively on the contractor’s past performance.
Any task or deliverable that is corrected at a level higher than 95% for accuracy and timeliness will be reflected positively on the contractor’s performance.
Performance
Objective
SOO
Paragraph Performance Threshold
Method of
Surveillance
SS – 1
Performance
Metrics
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
Establish a baseline with objective criteria to measure transformation progression. This is an iterative process. Changes are expected along the transformation journey. These metrics will be re-assed at the mid-point of the transformation. The final
Performance Metrics to provide the
Government with a way to clearly measure transformation success/failure and how to minimally maintain the change and/or adjust based on the performance metrics put in place.
100%
Surveillance
pg. 14
SECTION IV
4.0 DELIVERABLES / ACCEPTANCE CRITERIA
The Contractor shall provide deliverable(s) in a format mutually agreed upon by the Government and the Contractor. The following deliverables are not expected to change. Due Date intervals are not expected to change but actual dates may need to be revised depending on the actual contract start date.
Deliverables and Performance are not considered acceptable until the Government provides written notice of acceptance. This can be in the Monthly Status Report (bi-lateral signatures from the contractor and COR) and/or written acceptance via email.
pg. 15
DELIVERABLE –
Acceptance Criteria
DUE DATE SOO Paragraph DELIVERY
METHOD
Assessment Brief – acceptable when the briefing provides defendable recommendations to update/change the initial solution.
NLT 60 days after award
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
By email to COR in
PowerPoint/PDF briefing format
Performance Metrics
– acceptable when the performance measures are objective, executable, traceable, repeatable, and reliant on authoritative data.
DRAFT 1 - NLT 60
days after award
DRAFT 2 – NLT 30
days after mid-point of performance
FINAL – NLT 30
days prior to end task order period of performance
2.2.2
2.2.3
2.2.4
By email to COR in mutually agreed upon format
Program Management
Plans
60 days after award and thereafter monthly updated plans, if applicable
2.2.2
2.2.3
2.2.4
1 Electronic copy to the following: COR, PM, and HUD OCISO
TPOC
Cyber Risk
Dashboard &
Reporting
120 days after award
2.2.4 1 Electronic copy to the following: COR, PM, and HUD OCISO
TPOC
Cyber Training &
Awareness
Certification Pathway
90 days after award
2.2.3 1 Electronic copy to the following: COR, PM, and HUD OCISO
TPOC
HUD Cyber Strategy 90 days after award
2.2.2
2.2.3
2.2.4
PM, and HUD OCISO
TPOC
Procedures for M-22-
18 Compliance
90 days after award
2.2.3 1 Electronic copy to the following: COR, PM, and HUD OCISO
TPOC
pg. 16
Cyber Innovation
Evaluation Process
90 days after award
2.2.2 1 Electronic copy to the following: COR, PM, and HUD OCISO
TPOC
Redesigned
HUD@Work Page and Knowledge
Repositories
90 days after award
2.2.4 Electronic copy to the
following: COR, PM, and HUD OCISO
TPOC
Analysis of New and
Emerging Federal
Policies/Directives
30 after award and thereafter continuous
2.2.4 Electronic copy to the
following: COR, PM, and HUD OCISO
TPOC
Updated HUD’s
Entity-Wise Business
Impact Analysis
(EWBIA)
90 days after award 2.2.4 Electronic copy to the following: COR, PM, and HUD OCISO
TPOC
Cyber Program
Roadmap
145 days after award
2.2.2
2.2.3
2.2.4
PM, and HUD OCISO
TPOC
Cybersecurity SCRM
Reviews
145 days after award
2.2.3 1 Electronic copy to the following: COR, PM, and HUD OCISO
TPOC
ATO Packages for
ISSO Supported
Systems
145 days after award
2.2.3
2.2.4
1 Electronic copy to the following: COR, PM, and HUD OCISO
TPOC
GRC Tool Roadmap and Requirements
145 days after award
2.2.4 1 Electronic copy to the following: COR, PM, and HUD OCISO
TPOC
HVA Assessments 145 days after award
2.2.4 1 Electronic copy to the following: COR, PM, and HUD OCISO
TPOC
Power Apps and
Operational Guides
145 days after award
2.2.4 1 Electronic copy to the following: COR,
pg. 17
SAR and SSE Charter 60 days after award 2.2.2 1 Electronic copy to the following: COR, PM, and HUD OCISO
TPOC
SAR and SSE
Standard Operating
Procedure Guides
90 days after award 2.2.2 1 Electronic copy to the following: COR, PM, and HUD OCISO
TPOC
Security Architecture
Framework
120 days after award 2.2.2 1 Electronic copy to the following: COR, PM, and HUD OCISO
TPOC
Security Models and
Artifacts
Security Architecture
Review Reports
PM, and HUD OCISO
DSP Charter 60 days after award 2.2.2
PM, and HUD OCISO
DSP Guides 120 days after award 2.2.2
PM, and HUD OCISO
DSP Policy 90 days after award 2.2.2
PM, and HUD OCISO
TPOC
Data Inventory and
Classification Report
PM, and HUD OCISO
TPOC
DSP Audit Plan &
Schedule
150 days after award 2.2.2
PM, and HUD OCISO
TPOC
DSP Compliance
Assessment Report
pg. 18
DSP Technology
Implementation
Roadmap
150 days after award 2.2.2
PM, and HUD OCISO
TPOC
ICAM Program
Charter
60 days after award 2.2.2
PM, and HUD OCISO
TPOC
ICAM Current State
Assessment
90 days after award 2.2.2
PM, and HUD OCISO
ICAM Strategy 120 days after award 2.2.2
PM, and HUD OCISO
TPOC
ICAM Policy &
Guide
150 days after award 2.2.2 1 Electronic copy to the following: COR, PM, and HUD OCISO
TPOC
Unified Identity
Management
Framework &
Workflows
120 days after award 2.2.2
ICAM Technology
Implementation
Roadmap
PM, and HUD OCISO
Zero Trust Strategy 90 days after award 2.2.2
PM, and HUD OCISO
TPOC
Zero Trust Policy 60 days after award 2.2.2 1 Electronic copy to the following: COR, PM, and HUD OCISO
TPOC
Zero Trust Technical
Guides
120 days after award 2.2.2 1 Electronic copy to the following: COR, PM, and HUD OCISO
TPOC
Zero Trust Training &
Campaign
150 days after award 2.2.2 1 Electronic copy to the following: COR,
pg. 19
Zero Trust
Governance
Framework
120 after award 2.2.2 1 Electronic copy to the following: COR, PM, and HUD OCISO
TPOC
Zero Trust
Technology
Implementation
Roadmap
150 days after award 2.2.2 1 Electronic copy to the following: COR, SECTION V
5.0 TIMELINE, STAKEHOLDER (collaborating offices)
5.1 Timeline. The period of performance is one 12-month base period and two 12-month option period unless FAR 52.217-8, Extension of Services is exercised.
Base Period: September 30, 2024 - September 29, 2025
Option Period 1: September 30, 2025 - September 29, 2026
Option Period 2: September 30, 2026 - September 29, 2027
5.2 Stakeholders (Collaborating Offices).
U.S. Department of Housing and Urban Development, Office of the Chief Information Officer
(OCISO).
pg. 20
SECTION VI
6.0 GENERAL INFORMATION
In support of the U.S. Department of Housing and Urban Development’s Office of the Chief
Information Security Officer mission, the identified tasks and/or outputs may take the form of information, advice, opinions, alternatives, analyses, evaluations, training, processes to eliminate waste, standardize best practices, reduce cycle times and reduce the cost of doing business, or recommendations to complement the Government’s technical expertise in accomplishing its mission and day-to-day activities. The contractor shall provide a workforce possessing the skills, knowledge, and training to satisfactorily perform the services required under this contract. The primary work location for contractor personnel will be at U.S. Department of Housing and Urban
Development’s Office of the Chief Information Security Officer. However, other CONUS work locations or travel may be required.
Contractor employees performing services under this contract shall be controlled, directed, and supervised at all times by the management personnel of the contractor. The contractor's management shall ensure that employees properly comply with the performance standards outlined in this Performance Work Statement and as required by the contracting officer or the contracting officer's representative (COR). Contractor employees shall be capable of performing independently and without the assistance of Government personnel. Actions of contractor employees shall not be interpreted or implemented in any manner which results in a contractor employee creating, modifying, or violating Federal policy, obligating the appropriated funds of the U.S. Government, overseeing the work of Federal employees, providing direct personal services to any Federal employee or otherwise violating the prohibitions set forth in Parts 7.5 and
37.1 of the Federal Acquisition Regulation (FAR). If the contractor feels that any actions constitute or are perceived to constitute personal services, it shall be the contractor’s responsibility to notify the COR immediately.
No contractor personnel will perform any work on this contract that can be defined as inherently governmental according to FAR Subpart 7.503(c). Contractor personnel will be performing tasks under FAR Subpart 7.503(d); however, contract personnel will be in a supporting role to the
Government task lead and will not be in a decision-making role. The Government will be the sole authority for decisions.
6.1 Location.
Remote but must be available for Senior Leader or requested onsite meetings/exercises online and/or in person (if applicable). Notification will be provided in advance.
6.2 Travel (TDYs)
There are no known travel requirements at this time. In the event travel is required, the
Government will modify the contract to increase the price to cover travel. Price shall be determined fair and reasonable.
6.3 Identify Known or Possible Conflicts of Interest
pg. 21
The contractor is not expected to have access to data that can be perceived as competition sensitive contract information or support the development of acquisition strategies. Output from this effort will be used by the System Integrator (SI) for application development purposes.
Performance on any of the tasks listed under this SOO MAY, by definition in FAR 9.5, be a
Conflict of Interest as either Impaired Objectivity or Unfair Competitive Advantage (unequal access to information). Due to the unknown task requests, it is impossible to complete a focused
OCI plan; however, if vendors either during the solicitation process, during the performance of a contract, or at any time become aware of an OCI, they shall immediately inform the Contracting office. This may result in a work stoppage until (if) the OCI can be neutralized or mitigated. If it cannot, the contract will be terminated immediately and re-competed. If a vendor does not inform the Contracting officer of an OCI that it has been made aware of, the Contracting office may terminate the contract, or request debarment.
6.4 Security and Training Requirements
The contractors will need access to government sensitive information and/or access to government information systems. They will require a Public Trust clearance.
Based on the division, the following professional certifications should be possessed and maintained by personnel actively working on tasks during entire PoP:
Certified Information Systems Security Professional (CISSP)
Project Management Professional (PMP)
Certified Information Systems Auditor (CISA)
Certified Information Security Manager (CISM)
Certified Ethical Hacker (CEH)
Certified Penetration Tester
Certified Vulnerability Assessor
GIAC Certified Forensic Examiner
GIAC Certified Incident Handler
Information Systems Security Officer (ISSO)
6.5 Data Rights
The copies of any Contractor generated records, files, documents, data, and work papers, provided to the Government in performance of this contract shall become and remain
Government property and shall be maintained and disposed of IAW the Federal Acquisition
Regulations. The copies of any Government generated records, files, documents, data, and work papers, provided to the Contractor in performance of this contract, or derivatives thereof, are and shall remain Government property, and shall be returned to the Government at the completion of this contract. Software licensing terms shall not conflict with Federal law or regulation. The
Government shall not be bound by any licensing terms or other restrictions on the use,
pg. 22 modification, reproduction, release, performance, or disclosure of software not incorporated by attachment or other appropriate mechanism.
SECTION VII
7.0 APPENDIX 1
7.1 DEFINITIONS, ABBREVIATIONS, AND ACRONYMS
Contracting Officer (CO). The duly appointed Government agent authorized to award or administer contracts. The contracting officer is the only person authorized to contractually obligate the Government.
Statement of Objective (SOO). A formal contracting document used to describe the goals and objectives expected from soliciting contractor work.
Organizational Conflict of Interest (OCI). Unequal access and competitive advantage are two conflicts that the government is aware of that could result from Non-Financial Recommendations
(NFR)
Performance Threshold. The minimum performance level of a performance objective required by the Government.
File details come from the government source that posted it. Updated .