Pre-_Soliciation_SYNOPSIS__.pdf
PDF 40 KB Posted
- Attached to
- Risk Management Services- IDIQ Federal contract opportunity
- Solicitation number
- R17PS00246
View the file
Other files for this federal contract opportunity
Show all 14
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
PRE-SOLICITATION - SYNOPSIS
The Bureau of Reclamation (BOR), intends to award a multiple award IDIQ for the USBR Risk Management Services Group.
The following labor capabilities may be required under this requirement:
CDM: Expert level knowledge of and experience with CDM activities related to Hardware Asset Management, Software Asset Management, Configuration Setting Management, Vulnerability Management and Operational Security Management. Mastery of and skill in applying the configuration, implementation, managing and monitoring of security event correlation tools (e.g., IEM, SIEM, Splunk etc.), performing data reduction and assessing the robustness of security systems and designs. Expert knowledge interpreting and incorporating data from multiple tool sources and identifying systemic security issues based on the analysis of vulnerability and configuration data. Expert knowledge of intrusion detection tools, applications and techniques for detecting host and network-based intrusions
FISMA: Expert level knowledge of and experience with FISMA-related activities to include system security plans, contingency plans, incident response plans, configuration management plans, security control requirements and assessments, Plan of Action and Milestones (POA&M), and training requirements.
ICS: Expert knowledge and experience with configuring and operating ICS technology components (Remote Terminal Units (RTU), Programmable Logic Controllers (PLCs), relays, sensors, switches etc.), ICS protocols (Modbus, Profibus, Common Industrial Protocol etc.) and ICS systems (Supervisory Control and Data Acquisition (SCADA), Physical Access Control Systems (PACS), Building Automation Systems (BAS) etc.) components.
ISSO: Expert knowledge and experience with performing all ISSO-related tasks to include the following for all assigned systems; ensuring that the appropriate operational security posture is maintained; serving as a principal security advisor on all matters, technical and otherwise;
developing security procedures; continuous monitoring of security controls to ensure that they continue to be implemented correctly, operating as intended and producing the desired outcome with respect for meeting the security requirements; developing and updating the system security plan and all relevant components; assessing the security impact of changes; conducting annual assessment activities in accordance with Mid-Year and Annual Assurance Statement requirements; managing the POA&M process; providing the required system access, information and documentation to security control assessors; and leading required A&A activities.
Privacy: Expert knowledge and experience with Privacy Act-related activities to include Privacy Impact Assessments PIA, personally identifiable information (PII), PII breach procedures and recovery methods, privacy control requirements and assessments and training requirements.
Network security: Expert knowledge of network security architecture concepts to include topology, protocols, components, and principles (e.g., application of Defense-in-Depth) and the common attack vectors on the network layer. Skill in network mapping and recreating network topologies, protecting a network against malware, detecting host and network-based intrusions, reading and interpreting signatures, performing packet-level analysis and network traffic analysis. Knowledge and skills to configure, use and monitor network protection components (e.g., Firewalls, VPNs, network intrusion detection systems).
Vulnerability management: Expert knowledge of system and application security threats and vulnerabilities (e.g., buffer overflow, mobile code, cross-site scripting, PL/SQL and injections, race conditions, covert channel, replay, return-oriented attacks, and malicious code) and malware analysis concepts and methodology. Skill in conducting vulnerability/penetration scans, recognizing vulnerabilities and preparing technical vulnerability, risk and security impact analyses. Expert knowledge of new and emerging technologies, programming language structures and logic, Unix/Windows command line, ports and services and penetration testing principles, tools, and techniques (e.g., metasploit, neosploit, etc.). Knowledge of different classes of attacks (e.g., passive, active, insider, close-in, distribution, etc.) and different operational threat environments (e.g., first generation [script kiddies], second generation [non-nation state sponsored], and third generation [nation state sponsored]). Knowledge of different types of network and general attack stages (e.g., footprinting and scanning, enumeration, gaining access, escalation of privileges, maintaining access, network exploitation, covering tracks, etc.).
System Administration: Expert knowledge of Windows, Linux and Unix system configuration and administration, anti-virus software, patch management, optimization techniques, common protocols (SNMP, HTTP, HTTPS, SMTP, NTP, LDAP, KERBEROS, RADIUS, SFTP etc.), and scripting techniques.
This requirement will be full and open.
The applicable North American Industry Classification System (NAICS) code is 541519 Other Computer Related Services
The solicitation and any amendments to the solicitation will be available through the Federal Business Opportunities (FBO) (www.fedbizopps.gov) website. The extent of the work will be described in the solicitation. As a result of this Pre-solicitation notice, the Department of the Interior, Bureau of Reclamation, anticipates releasing the Request for Proposal (RFP) on or about 09/11/2017 on fedbizops.gov. The due date for receipt of quotes will be specified in the RFQ. This requirement will be solicited and awarded using the method outlined in FAR Part 15.
No further information will be available before the solicitation is posted.
Offerors are required to have an active record in the System for Award Management (SAM) to be eligible for contract award. Offerors may register on SAM at https://www.sam.gov. Written questions may be submitted to Christina Mohamed via email at cmohamed@usbr.gov. Only written questions will be accepted and addressed.
Contracting Office Address:
Denver Federal Center Building 56, Room 1040 Denver, Colorado 80225 United States Primary Point of Contact:
Christina Mohamed cmohamed@usbr.gov Phone: 303-445-2110 mailto:vmccoy@usbr.gov
File details come from the government source that posted it. Updated .