PROTECTS RFQ 24-Q-00009.docx

DOCX document 96 KB Posted

Attached to
DRAFT RFQ PROTECTS Federal contract opportunity
Solicitation number
2032H5-24-Q-00009
Issued by
Department of the Treasury Internal Revenue Service

About this file

This is a draft request for quote (RFQ) from the Department of the Treasury seeking professional cybersecurity services. The RFQ solicits feedback on draft documentation from capable vendors by February 2, 2024. If finalized, the RFQ would result in multiple blanket purchase agreements for cybersecurity services across eight one-year ordering periods. Services include security operations, vulnerability management, incident response, threat intelligence, and security engineering. Pricing is requested using the GSA MAS IT schedule for labor categories under SINs 54151HACS and 54151S. Awards are anticipated for both a small business pool and an unrestricted pool.

View the file

Other files for this federal contract opportunity

Other files attached to DRAFT RFQ PROTECTS, newest first.
File Type Posted
Attachment 2 - PROTECTS PWS.docx DOCX document
Attachment 4 - Questions and Answers Template.xlsx XLSX spreadsheet
Attachment 1 - Price Template.xlsx XLSX spreadsheet
Attachment 9 - Ordering Guide.docx DOCX document
Attachment 1 MSS Template.docx DOCX document
Attachment 3 - PROTECTS Provisions and Contract Clauses.docx DOCX document
Attachment 8 - Mock Scenario.docx DOCX document
Attachment 5 - PROTECTS Resume Template.docx DOCX document
Attachment 6 - PROTECTS Labor Category Descriptions.xlsx XLSX spreadsheet
Attachment 7 - PROTECTS Demonstrated Corporate Experience.xlsx XLSX spreadsheet

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

PROviding Treasury Enterprise Cybersecurity Technology & Services (PROTECTS) Professional Cyber Services Solicitation Number: 2032H5-24-Q-00009

The Department of Treasury is seeking feedback from capable vendors for this draft request for quote (RFQ) for PROviding Treasury Enterprise Cybersecurity Technology and Services (PROTECTS). Treasury encourages and appreciates comments and or questions related to the draft RFQ and its attachments. Response to this RFQ shall be made through attachment 4. The Treasury may or may not release answers to the questions received. All industry feedback will be reviewed and considered. Questions and comments are due on February 02, 2024, at 10:00 am EST.

Responses to this notice shall not be considered proposals and cannot be accepted by the Government to form a binding contract. No reimbursement will be made for any costs associated with providing information in response to this draft RFQ. The Government will not pay for any information provided because of this market survey. Quotes/proposals are not being accepted currently.

REQUEST FOR QUOTE (RFQ)

Request for Quotations Number 2032H5-24-Q-00009

Issued to:

Contractors under the General Services Administration (GSA) Multiple Award Schedule Information Technology (MAS IT), Highly Adaptive Cybersecurity Services (HACS) Special Item Number (SIN) 54151HACS and IT Professional Services SIN 54151S

The Contractor’s Basic GSA Schedule contract is applicable to the order awarded under this RFQ.

Conducted under Federal Acquisition Regulation (FAR) 8.4

Issued by:

Department of Treasury

12 January 2024

NOTICE TO PROSPECTIVE QUOTERS

Agency Contact: Jon Carney, Contracting Officer

DRAFT RFQ Issue Date: 12 January 2024

Questions Due Date: 02 February 2024

Questions Due Date: All questions or requests for clarification, citing the specific solicitation section, shall be posted on GSA eBuy by 02 February 2024 via attachment 4.

The contract specialist shall be the sole point of contact (POC) for answering questions regarding the RFQ. Answers to all written questions will be provided to all prospective contractors, giving due regard to the proper protection of proprietary information and without reference to the source of the question. In posing questions, vendors must cite the relevant section, paragraph, and page number. Statements expressing opinions, sentiments, or conjectures are not considered valid inquiries and will not receive a response. Further, vendors are reminded that hypothetical questions aimed at receiving a potential “evaluation decision” will not be addressed.

Quote Due Date: TBD via eBuy

The quoter will submit a signed cover letter by an authorized company negotiator to constitute agreement with all terms and conditions of this RFQ.

The Department of Treasury intends to establish a multiple-award Blanket Purchase Agreement (BPA) under General Services Administration (GSA). The Request for Quote (RFQ) will be solicitated under Special Item Number (SIN) 54151HACS and 54151S.

At the time of award for this order and prior to the exercise of order options years, the Quoters must have a valid GSA schedule contract in effect that covers the appropriate performance year. Failure to comply will result in the Quoters being ineligible for award or in the case of options the order may not be renewed. The Quoters shall notify the Contracting Officer no later than 12 months before its contract expiration whether they will be establishing a new contract, extend its current contract or establishing a new contract with a different socioeconomic status. The Quoters must have BOTH 54151HACS and 54151S SINS to be considered responsive.

The order established as a result of this RFQ will be based on the Quoters current contract and discounts provided. In the event that the successful Quoter has their current contract canceled or it expires, or is awarded a new contract, the Government reserves the right to transfer the new contract if the current contract is canceled or expired and a new one has been awarded, but prior to doing that the Contracting Officer must ascertain that the new contract does not contain terms and conditions unfavorable to the agency and new price reductions are negotiated.

Requirement details, agency specific, GSA Schedule terms and conditions, and FAR Clauses will be incorporated and applicable to this order.

1.0 Authority

1.1 Pursuant to FAR subpart 8.405-3, Ordering activities may establish Blanket Purchase Agreements (BPAs) under any schedule contract to fill repetitive needs for supplies or services. Ordering activities shall establish the BPA with the schedule contractor(s) that can provide the supply or service that represents the best value.

1.2 SET ASIDE INFORMATION (If applicable)

Pursuant to FAR 8.405-5, this acquisition will be partially set aside for small business. The BPA will be broken into two separate pools; one reserved for large business and the other reserved for small business. The Treasury intends to award to three (3) vendors for each pool. GSA and/or Treasury reserves the right to add more vendors during the evaluation process.

Task Orders will be issued based on responses to individual request for information (RFI). Every vendor will have an opportunity to respond to the RFI. Upon review of the responses to the RFI, the contracting officer will, at their discretion, determine which pool to send the RFQ to. More information can be found in Attachment 9, Draft Ordering Guide.

1.3 NORTH AMERICAN INDUSTRY CLASSIFICATION SYSTEM (NAICS) CODE AND SIZE STANDARD

The principal nature of the requirements described in this solicitation is consistent with services performed by industries in the 541990 – All other Professional, Scientific and Technical Services.

1.4 PRODUCT SERVICE CODE (PSC)

The services in this solicitation are best represented by PSC code: DJ01 – IT and Telecom – Security and Compliance Support Services (Labor).

1.5 TYPE OF SERVICES

The type of services under this solicitation are: The PROTECTS Professional Cyber Services, known as ‘PROTECTS’, will serve as a tool to provide enterprise-wide cybersecurity services. PROTECTS will conduct proactive and reactive cybersecurity services and operate Security Operations Centers (SOCs) to monitor, detect, and respond to cybersecurity threats to their networks, information processing systems, and sensitive data as described in the Performance Work Statement (PWS). The contractor shall provide, all management, supervision, hardware, software, and labor to support this BPA contract. This BPA will also include managed services.

The types of orders are expected to be Firm Fixed Price (FFP), Labor Hour (LH), Managed Services ( MSS) or a combination of each. Each task order will specify which type of service is requested.

1.6 EXTENT OF COMPETITION

This solicitation is issued in accordance with FAR 8.405-5.

1.7 SECURITY CLEARANCES

Security clearance requirements will be detailed in specific TOs. At a minimum, all positions on this BPA require a minimum of a Minimum Background Investigation (MBI). Additionally, some positions on this BPA may require access to SECRET and TOP SECRET in some TOs.

1.8 PERFORMANCE LOCATION(S)

The primary work location will be determined at the task order level. Commuting expenses will not be paid by the Government. HACS may also include performance at other designated locations. The specific place of performance for each activity will be as mutually agreeable to the Government and the contractor.

1.9 PERIOD OF PERFORMANCE

Eight 12-month ordering periods beginning the day of award. Contractors must ensure that their MAS IT covers the full amount of ordering periods.

Actual contract dates will be filled in prior to award.

Ordering Period 1:
2024 – 2025
Ordering Period 2:
2025 – 2026
Ordering Period 3:
2026 – 2027
Ordering Period 4:
2027 – 2028
Ordering Period 5:
2028 – 2029
Ordering Period 6:
2030 – 2031
Ordering Period 7:
2032 – 2033
Ordering Period 8:
2034 – 2035

1.10 OBSERVANCE OF FEDERAL HOLIDAYS

The contractor shall observe Federal holidays and other days identified in this section unless otherwise indicated in individual contracts. The Government observes the following days as holidays:

(1) New Year's Day (January 1)

(2) Birthday of Martin Luther King, Jr. (Third Monday in January)

(3) Washington's Birthday (Third Monday in February)

(4) Memorial Day (Last Monday in May)

(5) Juneteenth (June 19)

(6) Independence Day (July 4)

(7) Labor Day (First Monday in September)

(8) Columbus Day (Second Monday in October)

(9) Veterans Day (November 11)

(10) Thanksgiving Day (Fourth Thursday in November)

(11) Christmas Day (December 25)

In addition to the days designated as holidays, the Government may also observe the following days:

1. Any day designated by Federal Statute; Executive Order; or President’s Proclamation

Notwithstanding holidays and Government closures, the contractor shall perform in accordance with the terms established in the associated contract.

1.11 OVERTIME

Overtime hours can only be approved by the Contracting Officer’s Representative (COR). Overtime will be in accordance with the underlying GSA Schedule contract.

2.0 SERVICES AND PRICES/COSTS

The quoter is required to price each ordering period. The rates must be at or below the rates listed on the contractor’s MAS IT.

The work shall be performed in accordance with all sections of this RFQ and the quoter’s contract awarded under the GSA MAS IT HACS SIN. The contractor must be listed within the HACS SIN. Quotes that are not associated with an active GSA MAS IT contract with the awarded HACS SIN will not be considered. Release of this RFQ does not guarantee issuance of an award.

2.1 CONTRACT LINE-ITEM NUMBER (CLIN) STRUCTURE

Refer to the Performance Work Statement (PWS) under Attachment 2 for a complete description of the requirements. The Government reserves the right to make an award for any or all the contract line items listed below.

All proposed rates must be for the Government’s site.

Ordering Periods - 12 Months each Indicate all applicable MAS IT labor categories, rates, and any discounts offered. When there are several levels of a given labor category in an MAS IT contract, please indicate which level you are referencing in your pricing matrix. Also, this is to be reflected in the ordering period(s).

See Attachment 1 for PROTECTS Price Template

3.0 Performance Work Statement (PWS)

3.1 See Attachment 2 for PROTECTS Performance Work Statement (PWS)

4.0 DELIVERABLES, INSPECTION, AND ACCEPTANCE

4.1 SCOPE OF INSPECTION

All deliverables will be inspected by the COR for content, completeness, accuracy and conformance under this agreement and the specifics of the project.

4.2 BASIS OF ACCEPTANCE

The basis for acceptance shall follow the requirements set forth in the PWS, the contractor's quote and other terms and conditions of the contract. Deliverable items rejected shall be corrected in accordance with the applicable provisions.

(1) Reports, documents, and narrative type deliverables will be accepted when all discrepancies, errors or other deficiencies identified, in writing, by the Government have been corrected.

(2) If the draft deliverable is adequate, the Government may accept the draft and provide comments for incorporation into the final version.

(3) All the Government's comments to deliverables must either be incorporated in the succeeding version, or the contractor must demonstrate, to the Government's satisfaction, why such comments should not be incorporated.

(4) If the Government finds that a draft or final deliverable contains spelling errors, grammatical errors, improper format, or otherwise does not conform to the requirements stated within this contract, the document may be immediately rejected without further review and returned to the contractor for correction and re-submission. If the contractor requires additional Government guidance to produce an acceptable draft, the contractor shall arrange a meeting with the COR.

The contractor shall deliver all formal products concurrently to the Bureau/DO Task Lead, GTM, COR and CO as required. Electronic transmission shall be the primary delivery mechanism; however, hard copies will be provided as appropriate. All products shall be scanned for malware prior to submission.

Completeness – Initial requirements (as identified) are satisfied in all sections.

Accuracy – Documents shall be accurate in presentation, technical content, and adherence to accepted elements of style.

Clarity—Documents shall be clear and concise; project management and terms shall be used, as appropriate. All diagrams shall be easy to understand and be relevant to the supporting narrative.

Specification Validity—all deliverables must satisfy the requirements of the U.S. Government as specified herein.

File Editing—All text and diagrammatic files shall be provided in Microsoft Office Version 2010 or higher (Word, Excel, PowerPoint, Visio, etc.) so that they can be edited by the U.S. Government.

Format—Documents shall be submitted electronically whenever possible. Hardcopies shall be provided upon request. The document’s format may change from Subtask to Subtask.

Timeliness—Deliverables shall be submitted on or before the due date specified in the Schedule of Deliverables Section of this Proposal or submitted in accordance with a later scheduled date determined by mutual agreement between the GTM and the contractor Project Leader.

Generally, all work performed under a TO shall comply with Bureau/DO directives, instructions, and standards. Exceptions may be made on a case-by-case basis. Additional and unique acceptance criteria to specific deliverables shall be specified at the TO level.

The GTM or COR shall notify the contractor of deliverable acceptance or provide comments in writing within ten (10) Government workdays of receipt of a deliverable. Within ten (10) Government workdays, the contractor shall resubmit the final deliverable to the GTM, COR and CO, if necessary.

4.3 DRAFT AND FINAL DELIVERABLES

All deliverables shall meet professional standards and meet the requirements set forth in contractual and task order documentation. The contractor shall provide all deliverables in electronic format to the Bureau/DO, and other than software, all documents shall be provided using Microsoft Word, Excel, PowerPoint, Visio, or as otherwise needed (such as in Tableau or Adobe .pdf) formats pursuant to the following schedule. The deliverables are not to be separately priced but shall be included in the monthly price.

All electronic artifacts shall be delivered through encryption-protected channels according to the specifications within the FIPS 140 series and other Federal, Treasury, and Bureau/DO guidelines, regulations, and requirements. Specifically, cryptomodules used for encrypting electronic artifacts must be listed by NIST as having been validated under the requirements of FIPS 140-2 (if validated prior to September 22, 2019, and not used after September 22, 2026) or FIPS 140-3 and its approved successor FIPS 140 standards. Electronic artifacts must be protected at rest and in transmission in accordance with appropriate Bureau/DO policies.

The contractor will write documentation in clear, concise language that is verifiable. The contractor shall produce final documents without typographic and grammatical errors. All documents shall be formatted according to standards provided by the Government. The contractor shall send all electronic deliverables to the designated Bureau/DO Task Lead/Government Technical Monitor (GTM)/COR, with copies of monthly, quarterly, and annual formal deliverables also sent to the Contracting Officer (CO).

All written deliverables require at least two iterations – a draft and a final. The final document must be approved and accepted by the Government prior to payment submission. The contractor shall submit draft and final documents, using prescribed formats to the Government electronically. The Government requires ten (10) business days for review and submission of written comments to the contractor on draft documents. The contractor shall revise the deliverables to make any necessary corrections and incorporate the Government’s comments into final deliverables before submission. Upon receipt of the Government’s comments, the contractor shall have ten (10) business days to incorporate the Government’s comments and/or change requests and to resubmit the deliverable in its final form.

Any issues that cannot be resolved by the contractor in a timely manner shall be identified and referred to the COR.

The following table provides the initial contractor work product delivery schedule and should not be considered all inclusive. Additions and adjustments to deliverables, schedules and frequency will be made within specific TOs.

TASK
DELIVERABLE
FREQUENCY
SCHEDULE
2.2
Meeting Briefings/ Presentations
As needed
No later than (NLT) three (3) business days prior to scheduled meeting
2.2.1
SOC Support Services Program Management Plan
Annually
NLT fifteen (15) calendar days after award and annually thereafter
2.2.1
TO Status Updates
Weekly
Fridays
2.2.1
TO Status Reports
Monthly
NLT 15th of each month
2.2.1
TO Quarterly Performance Reports
Quarterly
Quarterly intervals starting NLT sixty (60) business days after award
2.2.2
SOC Communications Plan
Annually
NLT fifteen (15) calendar days after award and annually thereafter
2.2.3.2
SOC Incoming Transition Plan
As needed
NLT fifteen (15) business days after award
2.2.3.3
SOC Outgoing Transition Plan
As needed
NLT ninety (90) days prior to end of TO
2.2.5.1
Contractor SOC Performance and Investment Metrics Program Summary Briefings
Bi-weekly
Bi-weekly intervals starting NLT fifteen (15) business days after award
2.2.5.1
Contractor SOC Performance and Investment Metrics Report
Quarterly
Quarterly intervals starting NLT sixty (60) business days after award
2.3
Daily Summary Informal Reports
Daily
Daily intervals starting three (3) business days after award
2.3
Incident Analysis Reports
As needed
NLT fifteen (15) business days after task assignment
2.3, 2.4.1, 2.4.2, 2.4.4, 2.6
Automated reporting and query interface(s) for status and events: e.g., ticketing; system configuration data; vulnerability scan data; threats and vulnerability repository; audit logs; inventory data
Updated at no more than thirty (30) min intervals
Available 24h x 365 days/yr., starting five (5) business days after award
2.3, 2.6.5, 2.6.6, 2.6.7, 2.6.8, 2.6.9
Tactical Configuration Change Documentation
As needed
As soon as practical, but not to exceed four (4) hours.
2.3.4
Forensic DMA Report of Findings
As Needed
NLT fifteen (15) business days after task assignment
2.3.6
Fly-Away Kit
Annually
NLT fifteen (15) calendar days after award and annually thereafter
2.3.7
Information Systems Continuity and Disaster Recovery Plans
As needed
NLT thirty (30) business days after task assignment
2.4.1
Network Map
Quarterly
Quarterly intervals starting NLT sixty (60) business days after award
2.4.2
Vulnerability Scanning Risk Assessment
Weekly
NLT three (3) business days after completion of scan
2.4.3
Vulnerability Assessment Report of Findings
Per assessment
NLT fifteen (15) business days after conclusion of assessment
2.4.3.1
Phishing Assessment Report
Per assessment
NLT fifteen (15) business days after conclusion of assessment
2.4.3.2
Wireless Assessment Report
Per assessment
NLT fifteen (15) business days after conclusion of assessment
2.4.3.3
Web Application Assessment Report
Per assessment
NLT fifteen (15) business days after conclusion of assessment
2.4.3.4
OSSA Report
Per assessment
NLT fifteen (15) business days after conclusion of assessment
2.4.3.5
Database Assessment Report
Per assessment
NLT fifteen (15) business days after conclusion of assessment
2.4.4
Bureau/DO Vulnerability Alerts
As needed
Timelines based on severity and Bureau/DO guidance
2.5.1
Adversary Threat Set Profiles
Weekly
Weekly intervals starting NLT ten (10) business days after award
2.5.2
Bureau/DO Specific Intelligence Tippers
As Needed
As soon as practical
2.5.2
Cyber Intelligence Reports
Weekly
Weekly intervals starting NLT ten (10) business days after award
2.5.2, 2.6.10, 2.7.1, 2.7.2
Training and Exercise support materials
As needed
NLT twenty (20) business days after task assignment
2.5.3
Threat Hunting Analysis Report
Per mission
NLT twenty (20) business days after task assignment
2.5.4
Summary Reports
Daily
Daily intervals starting three (3) business days after award
2.5.5
Penetration Testing Report of Findings
Per assessment
NLT fifteen (15) business days after conclusion of assessment
2.5.5
Rules of Engagement
Per assessment
NLT thirty (30) days prior to assessment start
2.6.1
Cybersecurity Architecture and Strategy Recommendations
As needed
NLT twenty (20) business days after task assignment
2.6.2
SAR Report
As needed
NLT thirty (30) business days after task assignment
2.6.3
Market Research Reports for New Hardware and Software
As needed
NLT twenty (20) business days after task assignment
2.6.3
Automation and Orchestration Playbooks
As needed
NLT thirty (30) business days after task assignment
2.6.3
Change and Release Design Documentation
As needed
NLT twenty (20) business days after task assignment
2.6.3
SOC Tool Engineering Design Documentation
As needed
NLT thirty (30) business days after task assignment
2.6.3
Test Plans for New and Existing Security Solutions
As needed
NLT twenty (20) business days after task assignment
2.6.3
“End-to-End” Configuration Flow Diagrams
As needed
NLT twenty (20) business days after task assignment
2.6.4
ISSE operations modifications recommendations
As needed
NLT twenty (20) business days after task assignment
2.6.4
ISSE alternative operations solutions documentation
As needed
NLT twenty (20) business days after task assignment
2.6.4
ISSE end-to-end architecture tradeoff assessment
As needed
NLT forty-five (45) business days after task assignment
2.6.4
ISSE strategic plans
As needed
NLT forty-five (45) business days after task assignment
2.6.4
ISSE tactical plans
As needed
NLT fifteen (15) business days after task assignment
2.6.4
ISSE implementation plans and strategies
As needed
NLT thirty (30) business days after task assignment
2.6.4
ISSE standards
As needed
NLT forty-five (45) business days after task assignment
2.6.4
ISSE new program requirements recommendations
As needed
NLT twenty (20) business days after task assignment
2.6.4
ISSE operations technology recommendations and capabilities
As needed
NLT thirty (30) business days after task assignment
2.6.5
Ports, Protocols, and Services Matrix
Monthly
NLT 15th of each month
2.6.5, 2.6.6
Filtering Rules / Exceptions Validation Results Report
Quarterly
Quarterly intervals starting NLT sixty (60) business days after award
2.6.5, 2.6.6, 2.6.7, 2.6.8
Standard operating procedures (SOPs) and maintenance documentation
Annually
NLT thirty (30) business days after award and annually thereafter
2.6.9
Detection Signature Review Results Report
Quarterly
Quarterly intervals starting NLT sixty (60) business days after award
2.6.11
SOC Technology Prototypes
As needed
Sixty (60) to ninety (90) days after task assignment
2.7.2
Basic Cyber Range Capability
Daily
Daily intervals starting NLT thirty (30) business days after award
2.7.2
Expanded Cyber Range Capability
Quarterly
Quarterly intervals starting NLT sixty (60) business days after award
2.7.3
Routine Knowledge Capture
Daily
Daily intervals starting NLT ten (10) business days after award
2.7.3
Knowledge management content
As needed
NLT ten (10) business days after task assignment

Note: The contractor shall deliver electronically to the email addresses detailed in the specific task order via means required by applicable Bureau/DO policies for secure email transmission.

All deliverables will meet requirements as described under the tasks in clear, concise, well-written language, and in accordance with the applicable PWS. Accordingly, the quality measures (acceptance criteria) as set forth below will be applied to each work product or deliverable received from the contractor under this Proposal.

Services Delivery Summary (SDS) The Services Delivery Summary (SDS) represents the most important BPA objectives that, when met, shall ensure BPA performance is satisfactory. Although not all PWS requirements are listed in the SDS, the contractor is fully expected to comply with all requirements in the PWS. Additions and adjustments to performance objectives and thresholds may be made within specific TOs.

Task
Performance Objective
Performance Threshold
2.2
Trip Reports
98% of the time Trip Reports are received within five (5) business days after completion of travel and contains all details related to the trip and information on the traveler.
2.2
Meeting/Conference Minutes
98% of the time minutes are provided within two (2) business days upon request by the Government and contain all results and impacts of the meeting/conference.
2.2.2
Staffing Level and Retention
Positions are staffed at >90% of plan measured monthly.
2.2.2
Staff Certifications
100% of contractor staff hold required certifications.
2.2.2
Staff Mix
Staff resource mix is maintained within 20% of originally awarded resource mix.
2.2.5.2, 2.6.5, 2.6.6, 2.6.7, 2.6.8, 2.7.3
Process and Procedure Documentation Quality
98% of the time, documentation accurately reflects current operational processes and procedures; tool and system references; organizational references and contact information; and policy references.
2.2.5.2, 2.6.5, 2.6.6, 2.6.7, 2.6.8, 2.7.3
Process and Procedure Documentation Timeliness
No more than one (1) late document per month and no more than five (5) days late. For final deliverables, no more than two sets of corrections/edits and all corrections must be accomplished within two (2) days, or other such time periods as mutually determined between the government and the tasked contractor.
2.3, 2.4, 2.5, 2.6
Security Operations
100% of the time, no successful intrusions into the networks under the contractor’s control due to negligence or deviation from established procedures in performing actions specified by this task.
2.3, 2.4, 2.5, 2.6
On-the-Job Skills Practical Evaluation
100% of the time, evaluations are completed prior to contractor staff being granted privileged access to SOC systems.
2.3.1
Incident Response
95% of the time, review all incidents flagged by monitors within fifteen (15) minutes of detection.
2.3.1, 2.3.2, 2.3.3, 2.3.4, 2.3.5, 2.3.6
Incident Tickets Generation, Assignment, Acknowledgement, Notification, Escalation, and Resolution
95% of the time incident ticket generation, assignment, acknowledgement, notification, escalation, and resolution occurs within standard timeframes established by Bureau/DO.
2.3.1, 2.3.2, 2.3.3, 2.5.1, 2.5.2
On-call Support
Ops Center is able to contact the on-call technician nine (9) of every ten (10) attempts made outside of normal duty hours.
2.3.6
Fly-Away Incident Response
98% of the time, team is ready to deploy within twenty-four (24) hours of notification.
2.4, 2.6.2
Accurate and timely security assessments, in prescribed format, in accordance with the engineering principles outlined in NIST SP 800-160
Content: No more than one (1) deviation per month from established principles and directives. 100% of assessments will address all required elements and consider security functionality from existing Bureau/DO Enterprise Architecture.

Format: No more than one (1) late document per month and no more than five (5) days late. For final deliverables, no more than two sets of corrections/edits and all corrections must be accomplished within two (2) days, or other such time periods as mutually determined between the government and the tasked contractor.

2.4.1, 2.4.2, 2.4.3.1, 2.4.3.2, 2.4.3.3, 2.4.3.4, 2.4.3.5
Accurate and timely configuration of vulnerability management and scanning environment resources as required by vulnerability management plan and government requirement
No more than three (3) total days delay per month to all vulnerability management activities attributable to improper or late configuration of environments. All improper configurations identified and corrected within 1 workday
2.6.5, 2.6.6, 2.6.7, 2.6.8
Uptime for Cyber/Information Security Infrastructure Mechanisms
99.9% availability as measured per month must be maintained for all cyber security defense, and intrusion detection monitoring, incident management and change management services (e.g., firewall protection service for a specific area of coverage must be operational 99.9% of the time).
2.6.5, 2.6.6, 2.6.7, 2.6.8
Unplanned Outage or Operational Anomalies Notifications
100% of the time, provide notification to the customer IT Operations Center for unplanned outages and / or operational anomalies within fifteen (15) minutes of detection.
2.6.5, 2.6.6, 2.6.7, 2.6.8
Software and Operating System Versions
100% of the time security mechanisms are running supported software versions and are up to date (deployed within ten (10) days from vendor release) on security vulnerability patches with any exceptions approved by government in writing
2.6.5, 2.6.6, 2.6.7, 2.6.8, 2.7.2
Planned Downtime Coordination and Execution
100% of the time, planned downtime must be scheduled at least a week in advance and executed in a manner that remaining online infrastructure can compensate for the offline system.
2.7.2
Cyber Range Environment
95% of the time, the cyber range environment is operational to support training and exercise events.

Cyber range environment supports at least five (5) concurrent users on a daily basis and expands to support fifteen (15) concurrent users quarterly for exercise events.

5.0 CONTRACT ADMINISTRATION INFORMATION/DATA

5.1 PROCURING CONTRACTING OFFICER (CO)

The procuring CO has overall responsibility for administering the contract. The procuring CO shall perform all contract administration. The name and contact information of the CO is:

Jon Carney Contracting Officer Phone: 585-262-1134 E-mail: Jonathan.w.carney@irs.gov

5.2 CONTRACTING OFFICER’S AUTHORITY

The CO is the only person authorized to approve changes in any of the requirements of the contract/task order.

5.3 CONTRACTING OFFICER’S REPRESENTATIVE (COR)

COR APPOINTMENT AND AUTHORIZATION. Should the CO appoint a COR, it shall be in writing for any contract/task order issued under this RFQ. The COR provides technical review of deliverables, invoice servicing, and facilitating payment. The name and contact information of the COR is:

Shawn Roskosky Contracting Officer’s Representative (Primary) Phone: 202-603-1776 E-mail: shawn.roskosky@treasury.gov

Ben Porter Contracting Officer’s Representative (Alternate) Phone: 202-436-5840 E-mail: bernard.porter@treasury.gov

Diago Stinson Contracting Officer’s Representative (Alternate) Phone: 202-924-4893 E-mail: diago.stinson2@treasury.gov

(1) The Department of Treasury COR will receive, for the Government, all work called for by the contract/task order and will represent the CO in the technical phases of the work. The COR will provide no supervisory or instructional assistance to contractor personnel.

(2) The Department of Treasury COR is not authorized to change any of the terms and conditions of the contract/task order. Changes in the scope of work shall be made only by the CO by properly executed modifications to the contract/task order. Additional responsibilities of the Department of Treasury COR include:

(a) Monitor the contractor’s performance to ensure compliance with the technical requirements of the contract/task order.

(b) Review and approval of progress reports, technical reports, etc. which require Government approval.

(c) Verify and certify that the items have been inspected and meet the requirements of the contract/task order.

(d) Notify the CO immediately if performance is not proceeding satisfactorily.

(e) Ensure that changes in work under the contract/task order are not initiated before written authorization or a modification is issued by the CO.

(f) Provide the CO a written request and justification for changes.

(g) Furnish interpretations relative to the meaning of technical specifications and technical advice relative to CO approvals.

(h) Inspect and accept service and deliverables, including visiting the place(s) of performance to check contractor performance, as authorized by contract/task order inspection clause on a non-interference basis. This may include, but is not limited to, evaluation of the following:

(i) Actual performance versus schedule and reported performance.

(ii) Changes in technical performance which may affect financial status, personnel or labor difficulties, overextension of resources, etc.

(iii) Verification that the number and level of the employees charged to the contract/task order are actually performing work under the contract/task order.

(i) At the completion of the contract/task order, advise the CO concerning the following:

(i) All articles and services required to be furnished and/or performed under the contract/task order have been technically accepted.

(ii) Contractor compliance with patent rights and royalties’ clauses of the contract/task order.

(iii) Recommend disposition of any Government furnished property in possession of the contractor.

(iv) Verify proper consumption and use of Government furnished property by the contractor.

(v) Prepare a performance report detailing compliance with requirements, quality assurance, timely completion, and any problems associated with the contract/task order.

(3) The contractor is advised that only the CO, acting within the scope of this contract/task order and the CO’s authority, has the authority to make changes which affect contract/task order prices, quality, quantity, or delivery terms.

(4) The Department of Treasury COR will furnish technical advice to the contractor to provide specific details, milestones to be met within the terms of the contract/task order, and any other advice of a technical nature necessary to perform the work specified in the contract/task order. The Department of Treasury COR shall not issue any instructions which would constitute a contractual change.

5.4 INVOICE SUBMISSION AND CONTENT

The contractor shall submit Request for Payments in accordance with IR1052.232-9001 Electronic Invoicing and Payment Requirements for the Invoice Processing Platform (IPP) (Jul 2019) Invoices shall be sent to the following:

www.ipp.gov

6.0 SPECIAL CONTRACT REQUIREMENTS

6.1 KEY PERSONNEL

This RFQ is not for a personal services contract. Accordingly, the quoter must designate appropriate and sufficient supervisory personnel to meet task outcomes. Quoter’s supervisor shall provide day-to-day supervision of all contract personnel including, but not limited to, work assignments and performance monitoring, coverage, payroll records, leave approval and monitoring, etc. At no time will contract personnel be supervised by Department of Treasury’s managers or other Department Office (DO) personnel. The Department of Treasury and DOs will provide, as needed by the quoter and its employees, limited assistance in the form of technical and policy guidance through the assigned COR.

The contractor shall provide and supervise the skilled personnel required for the effective and efficient performance of this contract. All proposed personnel performing risk and vulnerability testing shall hold a current, active, and favorably adjudicated U.S. Government background investigation, minimum Office of Personnel Management Tier 2 (Background Investigation)) in which Department of Treasury can accept reciprocity. The descriptions located in Attachment 6, HACS Labor Category Descriptions, represent the minimum requirements for each labor category. Experience refers to actual directly related and applicable experience.

The contractor shall identify one person as the lead and key personnel who shall provide management, administrative, and technical interface between Government and contractor personnel in the day-to-day performance of the contract. An important element of this requirement is the ability for the contractor to provide expertise as needed.

The CO shall, in coordination with the COR, approve individuals designated as key personnel throughout the course of the contract.

All key personnel are subject to the following:

The key personnel specified in Attachment 6 are essential to work performance. At least 30 days prior to the contractor voluntarily diverting any of the specified individuals to other programs or contracts, the contractor shall notify the CO and shall submit a justification for the diversion or replacement and a request to replace the individual. The request must identify the proposed replacement and provide an explanation of how the replacement's skills, experience, and credentials meet or exceed the requirements of the contract/task order.

6.2 QUALIFICATIONS

The vendor shall clearly indicate offered qualifications and experience for all proposed key personnel as outlined in Attachment 5, PROTECTS resume template. The key personnel are Chief Cyber Security Engineer, Program Manager, SOC Project Manager as outlined in Attachment 6, PROTECTS Labor Category Descriptions.

6.3 KEY PERSONNEL REPLACEMENT

If an employee of the contractor is terminated for cause or separates from the contractor voluntarily with less than 30 days’ notice, the contractor shall provide the maximum notice practicable under the circumstances. The contractor shall not divert, replace, or announce any such change to key personnel without the written consent of the CO. The contract will be modified to add or delete key personnel as necessary to reflect the agreement of the parties.

Requests for replacement shall include:

· Detailed resume containing a description of position duties and qualifications, information about the qualifications of the individual(s) proposed, and any additional information requested by the CO in sufficient detail to permit the CO to evaluate the impact on the work the contractor is obligated to perform hereunder.

The Government reserves the right to review the qualifications of key personnel selected to work on this contract before assignment, including the contractor's proposed key personnel and any key personnel replacements The Government also reserves the right to reject proposed key personnel whom it determines not suitable for the program. The Government also reserves this right in certain circumstances when specific key personnel are required for specific tasks.

6.4 KEY PERSONNEL SUBSTITUTION

Replacement of key personnel can be disruptive and interfere with the Government’s ability to accomplish the efforts in a timely manner. The potential impacts of a key personnel replacement can sideline the mission and impact the goals of the affected program office for a substantial amount of time. The contractor shall not remove or replace any personnel designated as key personnel for this contract, without the written concurrence of the CO. Prior to utilizing other than personnel specified in response to this RFQ, the contractor shall notify the appropriate CO and COR. This notification shall be no later than 14 calendar days in advance of any proposed substitution, and shall include justification, including resume(s) and labor category of each proposed substitution(s) in sufficient detail to permit evaluation of the impact on contractor performance (What are the circumstances surrounding the individual’s departure? Give a reason why you believe it is in the Government’s best interest to accept such a change, and how the Government can expect to maintain continuity in the efforts that are ongoing at present, considering the retraining and re-familiarization with our organization and assigned tasks that inevitably has to happen with the introduction of any new individual). The Department of Treasury/DOs CO and COR reserve the right to determine that the proposed substitute personnel are unacceptable, or that the reduction of effort would be so substantial as to impair the successful performance of the work under the contract/task order, the contractor may be subject to default action as prescribed by FAR 52.212-4 Alt I.

6.5 PERSONNEL ASSIGNMENTS

All personnel are subject to the following:

(1) The contractor shall provide staff to ensure all work is performed on schedule and by following best commercial practices. The contractor may move around the personnel to different roles/responsibilities, if necessary, upon the CO and COR’s approval.

(2) The list of personnel set forth may be amended from time to time during the contract period of performance in order to either add or delete personnel.

6.6 PERSONNEL REQUIREMENTS

The contractor shall provide staff to ensure all work is performed on schedule in accordance with the deliverables list. All staff interfacing with the Government shall be fluent in the English language, verbal and written.

6.7 SECURITY REQUIREMENTS INFORMATION SECURITY REQUIREMENTS

All work that is associated with Government information, systems, and information security must be in compliance with the Federal Information Security Modernization Act (FISMA) of 2014 as implemented by Federal Information Processing Standards Publication 200 (FIPS 200), “Minimum Security Requirements for Federal Information and Information Systems.” This standard specifies minimum-security requirements Federal agencies must meet. The appropriate security controls and assurance requirements to be selected are described in the National Institute of Standards and Technology (NIST) Special Publication (SP) 800-53 Rev 4, “Security and Privacy Controls for Federal Information Systems and Organizations” and associated documents. Specific impact levels required (per FIPS 200) for government information and information systems may vary and will be specified as requirements are identified.

The U.S. Federal Government will conduct background checks and verify information submitted by the contractor employees, conduct fingerprint checks, and conduct other appropriate investigations. Investigations will include, but are not limited to, criminal record, credit worthiness, and prior work performance history. The contactor shall coordinate with the assigned COR to process background investigations for contractor staff supporting this effort.

The contractor shall comply with all information technology system security policies and procedures that apply to the Bureau/DO. All personnel providing services under the resultant TOs must meet all requirements to successfully complete the screening process. All contractor personnel providing support must achieve the basic screening process to work on-site.

Under Federal Information Security Modernization Act (FISMA), Government employees and contractors are subject to Federal information security laws, regulations, and policies. All contractor employees, providing support under the TO shall complete Bureau/DO mandatory training annually, which covers computer security, disclosure, privacy, and Unauthorized Access (UNAX). In addition, each individual contractor employee shall sign a non-disclosure form. The contractor shall provide written certification to the COR that this training was completed.

National Industrial Security Program (NISP) Requirements The security requirements apply to the prime contractor and any subcontractors, herein “sub,” employed during this BPA; the language is written to the prime contractor, herein “contractor.” The security requirements also apply to tasks, work requests or other identified methods of requesting work that flow from this document. No contractor personnel may perform any work under this BPA until the Government grants specific permission to do so, regardless of existing clearance or investigation.

This BPA is categorized as classified at the overall level of Top Secret (Tier 5) with eligibility for Sensitive Compartmented Information (SCI) and requires the company to have, prior to bidding, and maintain, for the life of the contract, a favorable Facility Clearance per 32 CFR Part 117, “National Industrial Security Program Operating Manual (NISPOM)” at the same or higher level that is required per the BPA. The contractors must have all the correct “authorized accesses” (i.e.: Communications Security (COMSEC), etc.) specified on the Department of Defense Form (DD F) 254, Contract Security Classification Specification, already noted in the National Industrial Security System (NISS, or replacement) prior to bidding on the solicitation or be able to obtain them within six months after award.

Contractor Facility Security Officers (FSOs) shall ensure no work performance commences until they have received an approved DD F 254.

The contractor shall ensure it has appropriate permission from the government prior to flowing down any proscribed information or accesses to its subs and shall ensure that DD 254s for subs are appropriately filled out given the accesses allowed the contractor and requirements of the subs contract.

The contractor is responsible for obtaining the approval of the CO or authorized representative prior to release of any information received or generated under the contract, classified or unclassified, per 48 Code of Federal Regulations (CFR) 252.204-7000. The CO or authorized representative will direct the contractor to the appropriate office that has public release authority. Prime contractors shall serve as focal point for their subs’ public release requests and refer them to the CO or authorized representative.

The contractor shall not safeguard (store, handle, or process) Bureau/DO Classified National Security Information (CNSI) at their (or another contractor’s) facility.

6.8 PERSONNEL ACCESS TO GOVERNMENT INFORMATION AND

FACILITIES

For TOs requiring personnel clearances, contracted employees must have, prior to starting, and maintain favorably adjudicated security clearances at the Top Secret or Secret level, depending on the task, throughout the life of the BPA. Personnel security investigations conducted for access to CNSI shall be initiated by the contractor company through Department of Defense. Secret clearances must be favorably adjudicated at either the interim or final level. Top Secret clearances must be favorably adjudicated at the final level. The contractor shall provide a suitable, qualified, trained, and favorably adjudicated staff with the skills necessary to perform all support functions referenced in this BPA. Security/suitability requirements for personnel are found in Bureau/DO guidance, Treasury Directive Publication (TD P) 15-71, Executive Orders (EOs) 13526 and 12968, and 5 CFR 731. All contractors must be vetted and approved by Personnel Security to have a security clearance commensurate with the level of the contract prior to beginning work on any portion of this contract.

Any employee assigned to support the Bureau/DO shall comply with Personal Identity Verification One and Two (PIV-1, PIV-2) requirements as described in Homeland Security Presidential Directive 12 (HSPD-12), “Policy for a Common Identification Standard for Federal Employees and Contractors,” and “Federal Information Processing Standard 201-2, Personal Identity Verification Standards for Federal Employees and Contractors,” dated August 2013, or replacement document.

6.9 CONTROLLED UNCLASSIFIED INFORMATION (CUI) STORAGE AND

DISCLOSURE

Controlled unclassified information (CUI), data, and/or equipment will only be disclosed to authorized personnel on a need-to-know basis. The contractor shall ensure that appropriate administrative, technical, and physical safeguards are established to ensure the security and confidentiality of this information, data, and/or equipment is properly protected. When no longer required, this information, data, and/or equipment shall be returned to the Government. The Government will determine the fate of such information, data, and/or equipment. If the Government determines that such information, data, and/or equipment is to be sanitized, it shall be accomplished in accordance with NIST SP 800-88 Rev 1, “Guidelines for Media Sanitization.”

6.10 PROTECTION OF INFORMATION

The contractor shall be responsible for properly protecting all information used, gathered, or developed as a result of work under this contract. The contractor shall also protect all Government data, equipment, etc. by treating the information as sensitive. All information about the systems gathered or created under this contract should be considered as CUI. It is anticipated that this information will be gathered, created, and stored within the primary work location. If contractor personnel must remove any information from the primary work area, they shall protect it to the same extent they would their proprietary data and/or company trade secrets. The use of any information that is subject to the Privacy Act will be utilized in full accordance with all rules of conduct as applicable to Privacy Act Information.

6.11 CONFIDENTIALITY AND NONDISCLOSURE

The preliminary and final deliverables, all associated working papers, and any other materials generated by the contractor in the performance of the contract are the property of the U.S. Government and must be submitted to the COR at the conclusion of the contract. All documents produced for this project are the property of the U.S. Government and cannot be reproduced or retained by the contractor. All appropriate project documentation will be given to Department of Treasury/DOs during and at the end of this contract. The contractor shall not release any information without the written consent of the CO. Any request to the contractor for information relating to the resulting contract must be submitted to the CO for approval prior to release.

Personnel working on any of the described tasks, at the Government’s request, shall be required to sign formal nondisclosure and/or conflict of interest (COI) agreements to guarantee the protection and integrity of Government information and documents.

6.12 INDIVIDUAL NON-DISCLOSURE AGREEMENTS

The contractor’s employees assigned to any contract/task order under this contract/task order shall be required to sign contract specific Nondisclosure Agreements (NDAs) and/or Individual COI forms which become part of the Organizational Conflict of Interest (OCI) Plan.

6.13 GENERAL COMPLIANCE REQUIREMENTS

Dep…

This is the start of the file's text. The full file is on GovTribe.

File details come from the government source that posted it. Updated .