Response to Offeror Questions document.pdf

PDF 312 KB Posted

Attached to
Penetration Testing State and local contract opportunity
Solicitation number
25RFP13436
Issued by
Minnehaha County, South Dakota

About this file

This document is a comprehensive response to offeror questions for a Penetration Testing Request for Proposal (RFP #25RFP13436) issued by the South Dakota Bureau of Information & Technology (BIT). The RFP seeks separate proposals for red team and purple team cybersecurity exercises covering web applications, networks, and computer systems within the Executive Branch. The purple team exercise will require at least one blue team contractor staff on-site in Sioux Falls, SD to identify attack simulations in near real-time, with the overall exercise expected to last 1-2 weeks. Proposals are due by June 30, 2025, and the contract will have an initial two-year term. Contractors are expected to conduct comprehensive security assessments using industry-recognized frameworks such as CIS, EPSS, CVSS, and MITRE ATT&CK™/D3FEND™.

The RFP is structured as a competitive bidding process where costs will be a required evaluation factor, and offerors can submit proposals for one or both exercises. No specific budget has been disclosed, with the state indicating that costs will be evaluated independently from the technical proposal. Contractors must comply with extensive security protocols, including background investigations, multi-factor authentication, and adherence to the state's Information Technology Security Policy. The assessment will focus on potential targets across the Executive Branch, with an emphasis on simulating real-world threats and measuring the effectiveness of people, processes, and technology used to defend the environment. Notably, physical penetration testing is explicitly excluded from the scope, and the state will require comprehensive reporting that includes detailed information about attack simulations, successful and unsuccessful attempts, and recommendations for improving the security posture.

View the file

Other files for this state and local contract opportunity

Other files attached to Penetration Testing, newest first.
File Type Posted
RFP Document.pdf PDF
Attachment C Contractor Security Acknowledgement Form (002).docx DOCX document
Attachment A Certificate of Media Santization (002).docx DOCX document
Attachment B ITSP.pdf PDF
Attachment B ITSP.pdf PDF
Attachment A Certificate of Media Santization (002).docx DOCX document
Attachment C Contractor Security Acknowledgement Form (002).docx DOCX document
RFP Document.pdf PDF

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

RESPONSE TO EMAILED INQUIRIES

STATE OF SOUTH DAKOTA

Bureau of Information & Technology (BIT)

700 Governors Drive Pierre, SD 57501

June 13, 2025

RFP #: 25RFP13436 Penetration Testing

Proposals Are Due No Later Than June 30, 2025

1. How do we obtain an invitation to bid?

All vendors are able to bid. An invitation is not necessary. You can find the RFP here and submit proposals by following the instructions in RFP Section 1.4.

2. In the RFP documents, the following clause has been mentioned:- "Upon the State’s request, the offeror may be required to submit a copy of its most recent audited financial statements".

Is this mandatory or not? Can we submit the D&B(sDun & Bradstreet) report in lieu of these statements?

As stated in Section 6.13, the offeror may be required to submit its audited financial statements.

You may submit additional documentation with your proposal to address requirements within the RFP.

3. Would it be possible to have a phone call to discuss the scope and intent of the exercise?

No.

4. How many web applications, network segments, and endpoints are included in the assessment?

This is determined based on the tool, the cost, and the time built into the Contractor’s proposal.

5. Are there any cloud-based environments or third-party integrations that need testing?

Possibly. This is determined based on the tool, the cost, and the time built into the Contractor’s proposal.

6. What is the estimated number of privileged accounts or user roles across systems?

Please be advised that the state is unable to share sensitive information prior to the signing of a contract. This policy ensures the protection of sensitive information. We are committed to providing all necessary information once a formal agreement is in place.

7. Will APIs be included in the scope, and if so, how many?

Possibly. We are committed to providing all necessary information once a formal agreement is in place.

8. What is the estimated number of web applications, networks, and computer systems included in the assessment scope?

https://postingboard.esmsolutions.com/3444a404-3818-494f-84c5-2a850acd7779/eventDetail/13436

9. Can you provide a breakdown of the types of systems in scope (e.g., web servers, database servers, endpoints, cloud environments)?

10. Will the test include endpoints such as workstations and mobile devices? If so, how many are expected?

11. How many external-facing assets will be tested, and do they include cloud-based environments?

12. What authentication mechanisms are used across applications and systems?

This question is not relevant to the scope of this RFP and submission of a proposal.

13. Will testing cover both on-premises and cloud-based infrastructure?

14. Are any legacy systems included in the scope? If so, what security challenges are associated with them?

15. How many unique user roles or privilege levels exist across applications and systems?

16. Will there be a need to simulate attacks against APIs? If so, how many APIs are in scope?

We are committed to providing all necessary information once a formal agreement is in place.

17. Are there specific restrictions on testing critical infrastructure or high-risk systems?

Refer to Section 3 Scope of Work. Note: Physical penetration testing is not included in the scope.

The scope is limited to the Executive Branch.

18. Are there specific external-facing assets (such as web applications) that are considered a priority for testing?

19. Will access to internal network environments be provided to assess lateral movement and access controls?

20. Are there any compliance frameworks or specific security standards the State prefers the assessment to align with?

Refer to RFP Section 3 Scope of Work. Assessments should be based on the most recent version of industry-recognized frameworks or scoring systems such as CIS, EPSS, CVSS, MITRE

ATT&CK™/D3FEND™.

21. Will there be any required collaboration with existing IT teams or security personnel during the assessment?

Yes.

22. Could you clarify the expected differences in reporting and documentation between the red and purple team exercises?

Purple team exercises should include any blue team related items such as any improvements made along the way or significant findings that yield value to BIT.

23. Will the purple team exercise require continuous engagement with BIT's security team, or will interactions be scheduled at specific intervals?

Continuous is preferred but can be discussed on what works best for the engagement between BIT and the Contractor.

24. Is there a preferred method for logging and reporting attack simulations in near real-time during the purple team exercise?

It is preferred that all events are timestamped and contain useful details that can best reveal the attack simulations for on-going analysis and that the data can be exported to JSON/CSV or other ingestible type formats.

25. For the red team exercise, are there any specific "rules of engagement" regarding exploit techniques, privilege escalation, or persistence methods?

26. Are there preferred security frameworks that should be referenced in the findings (e.g., MITRE ATT&CK™, CIS benchmarks, CVSS scoring)?

Refer to RFP Section 3, Scope of Work. Assessments should be based on the most recent version of industry-recognized frameworks or scoring systems such as CIS, EPSS, CVSS, MITRE

27. What level of detail should the technical report provide regarding indicators of compromise and threat simulations?

As much detail as possible since these reports will be used for on-going analysis and retrospective look back to the environment to understand what took place during the simulations.

28. Will BIT provide sample attack scenarios or past assessment results to benchmark against?

29. Are there any mandatory security controls that should be validated outside of penetration testing, such as incident response procedures?

30. Will the State require follow-up assessments, and if so, what would be the expected intervals?

Refer to RFP Section 1.1.3 Description of Components or Phases and 1.13 Length of Contract.

31. Should our proposal include post-engagement consultations or support for remediation efforts?

No. Refer to Section 3 Scope of Work. The Final Report should include detailed documentation of response and recommendations for improvement.

32. Are there specific cybersecurity training objectives that should be integrated into the testing process?

33. Will BIT handle any media inquiries or external communication if significant vulnerabilities are discovered?

34. Can you confirm if the term "Red Team" in this RFP includes physical penetration testing, or is it limited to network and application testing only?

Refer to RFP Section 1.1.4.

35. Are there any specific activities or techniques that you expect to be included or excluded in the Red Team engagement? For example, social engineering, phishing, or vishing?

Yes. Refer to RFP Section 1.1.4.

36. Can you provide a general range or estimate of the Internal and External network's size and the number of endpoints to be tested?

37. Are there any specific internal networks or systems that are excluded from the scope of this engagement?

Refer to Section 3 Scope of Work and Section 1.1.4. The scope is limited to the Executive Branch.

38. Are there any time constraints for scanning (e.g., 8pm-6am)?

Prior to testing, time frames and blackout dates will be discussed with BIT. Testing will be done on days the state is open for business and during regular business hours (8AM to 5PM Central Time).

39. Will the State provide internal network access, and if so, what are the specific parameters for this access?

40. Are there any restrictions on the use of credentials obtained during external testing when performing internal testing?

41. What is the expected duration of the Red Team engagement? Is there a preferred timeframe for completing the testing?

42. Are there any specific deadlines or milestones that we need to be aware of?

Refer to RFP Section 1.3 Schedule of Activities.

43. What format and level of detail are expected in the final report? Are you looking for an internal vulnerability report or is it focused on the success and failures of the Red Team activities?

The final report must include detailed information about the red team's activities (timestamps, screenshots, tools used, etc.), as well as what was successful/unsuccessful attempts, and any relevant findings that could help BIT understand the work performed and how BIT can improve their security posture.

44. Are there any specific reporting frameworks or standards (e.g., MITRE ATT&CK) that the State prefers for this engagement?

Refer to RFP Section 3, Scope of Work. Assessments should be based on the most recent version of industry-recognized frameworks or scoring systems such as CIS, EPSS, CVSS, MITRE

45. Who will be the primary point of contact for this engagement, and what is the expected level of involvement from the State's team?

The primary point of contact in RFP Section 2.1 along with those mentioned in RFP Section 5.2 will be assigned after the contract is awarded and finalized.

46. How many State (blue team) members will be aware of the red team testing?

47. Will there be a need for on-site presence during the testing, or can the engagement be conducted remotely?

Refer to Section 3 of the Scope of Work. A red team exercise may be conducted remotely, but a purple team exercise will require at least one blue team staff on-site in Sioux Falls, SD, during the exercise to identify the attack simulations in near real-time.

48. Can you provide more details on the Information Technology Security Policy (Attachment B) and any specific requirements we need to comply with?

The vendor would have to comply with the applicable requirements of the Information Technology Security Policy.

49. The RFP mentions the need for references from past projects. Can you confirm if we need to provide references specifically for Red Team engagements, or can we include other relevant security assessments?

Please provide any references relevant to the Scope of Work in Section 3 of the RFP.

50. Are there any budget constraints or expectations that we should be aware of when proposing our services?

51. Are there any other specific requirements or expectations that we should be aware of that are not explicitly mentioned in the RFP?

52. Please share the asset list (make & count – web apps, networks & computer systems) under scope This is determined based on the tool, the cost, and the time built into the Contractor’s proposal.

Please be advised that the state is unable to share sensitive information prior to the signing of a contract. This ensures the protection of sensitive information. We are committed to providing all necessary information once a formal agreement is in place.

53. Since only consulting project manager and security lead are assigned to the bidder, should we assume that we are only responsible for program management & execution aspects when the actual cybersecurity testing will be done by BIT team?

No. Reference RFP Section 3 Scope of Work.

54. What is the recommended timeline assuming we are only program managing this? We would need clarity as we do not know the lay of the land. Alternatively, should we also propose a rate card for the stated roles?

Refer to Section 3 Scope of Work.

55. Can incidental expenses like travel be billed separately with original receipts?

No. Refer to RFP Section 7 Cost Proposal. The offeror must include all costs related to the required services as part of the proposal.

56. External Scope: How many public-facing IP addresses and domains are in scope for the external penetration test?

57. Internal Scope: How many internal network segments and total IP addresses are in scope for the internal penetration test?

58. Web Applications: How many web applications are in scope, and what is their complexity

(e.g., number of pages, authentication mechanisms, use of APIs, multi-tenancy)?

59. Timestamp Requirements: Are minute-by-minute activity timestamps required for all testing phases, including automated enumeration and discovery scanning, or only for manual testing efforts?

Yes. It is preferred that all events are timestamped and contain useful details that can best reveal the attack simulations for on-going analysis and that the data can be exported to JSON/CSV or other ingestible type formats.

60. Custom Applications: Are there any custom or proprietary applications in scope? If so, how many (estimated)?

61. Cloud Integrations: Are there any cloud platforms that are integrated with the environment (e.g., AWS, Azure, GCP, SaaS)? How many cloud accounts, services, or integrations are in scope for testing, and what types of resources are included (e.g., storage, compute, IAM, APIs)?

62. User Accounts: Will test accounts with varying privilege levels (e.g., administrator, standard user) be provided for web and internal testing, or will testing be conducted exclusively from a low-privilege perspective?

63. Testing Restrictions: Are there any constraints or limitations on testing (e.g., production-only environments, blackout periods, systems that must not be scanned or touched)?

Yes. The Contractor must coordinate with BIT on timeframes to ensure testing is not completed during blackout periods.

64. Previous Testing: Has a penetration test been conducted previously? If so - and if SD IT is willing to share - when was the last assessment performed, and were there any significant findings?

65. Regarding External Penetration Testing:

a. What is the total number of external IPs ?

This is determined based on the tool, the cost, and the time built into the Contractor’s

66. Regarding Internal Network Penetration / Vulnerability Testing:

a. What is the total number of internal devices ?

This is determined based on the tool, the cost, and the time built into the Contractor’s proposal.

b. Do you require credentialed scanning ?

This question is not relevant to the scope of this RFP and submission of a proposal.

c. How are the assets separated - broadcast domains ? By VPNs ? By VLANS ?

d. This question is not relevant to the scope of this RFP and submission of a proposal.

e. What are the subnet sizes ?

This question is not relevant to the scope of this RFP and submission of a proposal.

f. Do you utilize Microsoft Intune ?

This question is not relevant to the scope of this RFP and submission of a proposal.

g. Do you utilize site-to-site VPNs ?

67. Regarding Application Security Penetration Testing:

a. How many applications are in-scope ?

b. Will application testing take place in a Production or Quality Assurance (QA) environment ?

c. Will login credentials be provided for testing each of the roles supported by the application ?

d. Approximately how many pages comprise each application ?

68. Is Wireless Penetration Testing in-scope ? If so, how many sites are in-scope ?

69. Do you require an assessment of your Information Security (IS) Policies and Procedures ?

a. If so, how many are presently defined and implemented, and are there any that need to be developed ?

70. Might you be interested in a NIST CSF 2.0 Framework Assessment?

71. Might you need any security awareness training

72. Is Social Engineering testing in-scope:

a. If so, how many users need to be targeted?

b. Which types of Social Engineering are you requiring?

73. Might any of the following assessments also be in-scope ?

a. Server Evaluation Assessment (Physical and Virtual)

b. Database Security Review and Assessment

c. Microsoft AD, Azure AD and O365 Configuration Assessment

d. Mobile Device Management Assessment

e. Firewall Assessment

f. Network Architecture Evaluation

g. Email Security Assessment

74. Assets in Scope - While the RFP broadly defines the assessment to include web applications, networks, and computer systems within the Executive Branch, could you please clarify which specific assets or systems will be included in the Purple Team exercise?

IT in the state is centralized under BIT. This is determined based on the tool, the cost, and the time built into the Contractor’s proposal.

75. Attack Simulation Prioritization - The RFP mentions a “wide array of common and advanced attack simulations.” How will these simulations be selected or prioritized? Will the State provide predefined scenarios, or is the contractor expected to propose them?

The state will not predefine scenarios. The contractor is expected to propose scenarios.

76. Exercise Duration - What is the anticipated duration (in days or weeks) of the Purple Team exercise itself? This detail is critical for estimating resource requirements and travel arrangements for on-site personnel.

The Purple Team exercise itself is expected to take 1 – 2 weeks with time allotted for report preparation, submission and review.

77. Team Size Expectations - In addition to the requirement that “at least one contractor staff be on-site in Sioux Falls,” does the State have expectations for the overall size or structure of the Purple Team (e.g., total number of analysts, remote vs. on-site staff)?

No. Refer to RFP Section 3 Scope of Work.

78. State Blue Team Participation - What level of participation is expected from the State’s internal blue team during the exercise? Can you clarify how many BIT analysts will be available, and what roles or skill sets they will contribute?

For the purple team exercise, the blue team is expected to be operating alongside / during the same time as the red team. We will not divulge how many BIT analysts will be involved.

79. Coordination with Red Team - If separate vendors are selected for the Red and Purple Team exercises, are there any specific integration or coordination expectations between the two efforts (e.g., sharing of tools, timelines, or results)?

80. Preferred Scenarios or Attack Chains - Are there any specific threat scenarios, adversary emulations, or attack chains that BIT would like to prioritize to assess detection and response capabilities?

81. Has South Dakota lost USG cybersecurity support with recent DHS/CISA downsizing? If so, what support was lost?

82. Are you receiving services from Dakota State University? If so, which services?

83. Is funding for this effort from Senate Bill 187?

84. What was the annual spend for the previous year on this Project?

85. If this is a new Contract, What is the annual Budget for this?

This is a competitive bidding process as required by state law and costs will be a required evaluation factor.

86. Are you open to a hybrid delivery model with a mix of offshore and onshore resources?

No. Refer to Section 2.30 (B).

87. Work will be onsite or remote?

Refer to RFP Section 3 Scope of Work. A red team exercise may be conducted remotely, but a purple team exercise will require at least one blue team contractor staff on-site in Sioux Falls, SD, during the exercise to identify the attack simulations in near real-time.

88. Can you please give us an extension of 1-2 weeks to submit our proposal?

89. Red-Team Scoping Questions:

a. What specific data or systems can be considered ‘flags’ or targets to be c compromised?

This is determined based on the tool, the cost, and the time built into the Contractor’s proposal.

b. What is the level of realism desired in the exercise? (Full-scope emulation or focused testing of specific attack vectors?

90. Web App Scoping Questions:

a. How many are there in total? What is the approximate number of pages per application?

This is determined based on the tool, the cost, and the time built into the Contractor’s proposal.

b. What is the level of access that will be given for testing?

This is determined based on the tool, the cost, and the time built into the Contractor’s proposal.

Are internal web applications in scope for exploitation?

This is determined based on the tool, the cost, and the time built into the Contractor’s proposal.

Will the source code be available?

91. Network Pen Testing Scoping Questions:

a. How large is the network? What is the IP space?

This is determined based on the tool, the cost, and the time built into the Contractor’s proposal.

b. Is stealth required for testing the security operation center’s response?

This is determined based on the tool, the cost, and the time built into the Contractor’s

c. Are there any time restrictions for testing? (e.g., outage windows or business hours)

Prior to testing, time frames and blackout dates will be discussed with BIT. Testing will be done on days the state is open for business and during regular business hours (8AM to 5PM Central Time).

d. How many active internal IPs are in scope? What kind of software/hardware/OS can we expect (roughly speaking)?

This is determined based on the tool, the cost, and the time built into the Contractor’s proposal.

e. Is social engineering included in the scope of this assessment? If so, what activities (email phishing, phone pretexting, vishing, and/or tailgating) are desired?

92. Purple Team Scoping Questions:

a. What is the expected briefing cadence for the purple team?

During any purple team testing, the blue team must be working alongside BIT staff to observe attacks as they occur.

b. What is the level of realism desired in the exercise? (Full-scope emulation ore focused testing of specific attack vectors?)

This is determined based on the tool, the cost, and the time built into the Contractor’s proposal.

c. What hours will we be allowed to perform the activities?

Prior to testing, time frames and blackout dates will be discussed with BIT. Testing will be done on days the state is open for business and during regular business hours (8AM to 5Pm Central Time).

93. General –

a. Please provide contract award amounts and/or level of effort for the previous cybersecurity third party security assessments of the state.

This question is not relevant to the scope of this RFP and submission of a proposal.

b. What is the expected budget for this assessment?

This is a competitive bidding process as required by state law and costs will be a required evaluation factor.

94. Section 2.31, N. Data Sanitization, Page 15

a. Regarding the sanitization of data from the vendor, are vendor attestation to sanitization sufficient or must a Certificate of Sanitization be provided from a third party?

The vendor will be required to comply with the requirements of the contract.

95. Section 2.31, N. Data Sanitization, Page 15, Section 2.35 Access Attempts, Page 16

a. Data Sanitization requirements appear to contradict requirements for maintaining

Access Attempts and access logs for 7 years. What are the actual retention requirements? Are summary level reports acceptable to be retained as support for work completed?

As stated in the RFP under Section 2, “The offeror must indicate in its response, any issues it has with specific contract terms.”

96. Background Investigations, Page 18

a. Would evidence of 3rd party background investigation with be acceptable for participation on the project?

Potentially.

97. Section 2.37, Multi-factor Authentication for Hosted Systems, page 19

a. Please define if internal applications used internally to a vendor and supported by a cloud platform required to have Multifactor Authentication.

98. Section 1.1.3 – Description of Components or Phases: Red/Purple Team

a. Please provide the number of facilities to be tested (e.g. main office, data center, admin center, etc.)

This is determined based on the tool, the cost, and the time built into the Contractor’s proposal.

b. Please provide the number of remote facilities/branches to be tested.

This is determined based on the tool, the cost, and the time built into the Contractor’s proposal.

c. Is dumpster diving in scope?

No.

d. Do you wish CLA to test physical security controls (RFID badges, door locks, etc.)

No.

Please provide the number of active public IP addresses in use (have a service exposed to the Internet) This is determined based on the tool, the cost, and the time built into the Contractor’s proposal.

e. Please provide the remote access services for employees (e.g. VPN, RDP, VDI, etc.)

This is determined based on the tool, the cost, and the time built into the Contractor’s proposal.

f. Please provide the web-based services (websites/web applications) exposed to the Internet.

This is determined based on the tool, the cost, and the time built into the Contractor’s proposal.

g. Are there any systems hosted by a 3rd party that you are going to get permission to include in the scope of the external testing? Describe these systems.

This is determined based on the tool, the cost, and the time built into the Contractor’s proposal.

h. Please provide the approximate number of servers This is determined based on the tool, the cost, and the time built into the Contractor’s proposal.

i. Please provide the approximate number of workstations This is determined based on the tool, the cost, and the time built into the Contractor’s proposal.

j. Please provide the approximate number of other devices connected to internal network (networking equipment, printers, IP cameras, etc.)

k. Please provide the approximate number Active Directory domains This is determined based on the tool, the cost, and the time built into the Contractor’s proposal.

l. Can all internal systems be tested/interacted with from one, central location?

This is determined based on the tool, the cost, and the time built into the Contractor’s proposal.

m. How many personnel and contractors support the state’s security operations center, monitoring of logging, and incident response?

99. Could the BIT please confirm whether this is a new initiative or an existing engagement?

100. Could the BIT provide an estimated budget or a Not-to-Exceed (NTE) amount for this contract?

This is a competitive bidding process as required by state law and costs will be a required evaluation factor.

101. Could the BIT please provide the anticipated project timeline, including key milestones and the overall expected duration of the engagement?

Refer to RFP Section 1.13 Length of Contract and RFP Section 3 Scope of Work.

102. Could the BIT please clarify whether it intends to award this RFP to a single vendor or multiple vendors? If multiple awards are anticipated, could the BIT specify the expected number of vendors to be selected?

Refer to RFP Section 3 Scope of Work.

103. Given the scope of your external network, can you please specify the number of IP addresses and websites/applications that need to be evaluated?

104. Can BIT provide the number of internal IPs? If possible, please share the following details: Internal hosts, servers, network devices, and web applications that need to be assessed.

105. What is the desired scope of the web application assessments? Will the testing include functional testing, vulnerability scanning, or penetration testing?

106. Can you provide an estimate of the total number of web applications, including a breakdown of external-facing and internal-only applications? If possible, please rank with count or percentage (%) the web applications based on their criticality (e.g., high, medium, low).

107. Are there any third-party systems or platforms included in the scope? If yes, please elaborate!

108. Are there specific compliance standards that must be addressed (e.g., PCI DSS, HIPAA, NIST)?

109. What is the expected start date and duration of the engagement? Are there any strict deadlines?

Refer to Section 1.13 Length of Contract.

110. Will testing be performed in production, staging, or test environments?

111. Is there a preferred pricing model? (Fixed fee, T&M, per asset/IP, per app, per test round, etc.)

Refer to RFP Section 7 Cost Proposal.

112. Is the vendor required to do a retest after the IT department has remediated the vulnerabilities?

No. Refer to RFP Section 3 Scope of Work. The Final Report should include detailed documentation of response and recommendations for improvement.

113. Are there budgetary constraints or thresholds we should be aware of? What is the budget for this RFP?

114. Do you expect this to be a one-time engagement or a multi-year or recurring contract (e.g., quarterly testing)?

Refer to Section 1.13 Length of Contract.

115. Is there any subcontracting goal? If yes, is there any goal?

116. Are subcontractors permitted, or must all work be performed by internal personnel only?

117. For the purple team exercise, Does the Bureau have a scenario in mind? Is the vendor required to plan the execution?

The state will not predefine scenarios. The contractor is expected to propose scenarios.

118. What cyber security tools are in place? SIEM, EDR, etc.

Please be advised that the state is unable to share sensitive information prior to the signing of a contract. This policy ensures the protection of sensitive information. We are committed to providing all necessary information once a formal agreement is in place.

119. Please provide the count:

a. Total number of employees

Please be advised that the state is unable to share sensitive information prior to the signing of a contract. This policy ensures the protection of sensitive information. We are committed to providing all necessary information once a formal agreement is in place.

b. Total count of SMEs in the IT Department, with the vendor required to work with.

We will not divulge how many BIT analysts will be involved.

c. How many training sessions are required for “Improving defender training” Page 2.

120. Can you confirm the number and types of assets (e.g., web apps, networks, systems) expected to be tested for both the red team and purple team engagements?

121. Will test accounts or credentials be provided for internal systems or web applications during testing?

122. Are there any third-party services or cloud environments included within the assessment scope?

123. Will access be provided during the red team assessment via VPN or another secure remote access method?

124. What is the preferred method for securely exchanging assessment data, findings, and reports with BIT during and after testing?

We prefer using our Teams tenant for storing all data, findings and reports if possible. If not, a secure file storage portal that we can access and fully control the data will suffice.

125. Are there any blackout dates we should be aware of when proposing the testing window?

Prior to testing, time frames and blackout dates will be discussed with BIT.

126. Does the State expect separate reports for red and purple team exercises if awarded to the same vendor, or a combined report?

Yes. Separate reports.

127. What is the State’s anticipated budget range for each exercise (red team and purple team), or is there a not-to-exceed amount already established?

128. Has the State conducted similar red/purple team exercises in the past? If so, are there any lessons learned or priorities based on past findings that should shape our approach?

129. Does the State have a preferred number of consultants it would like to see involved in executing the red and purple team assessments?

130. Is there any limitation on the technology stack?

131. Would it be possible for the Klinic to grant a two-week extension for the submission?

No extensions for submissions will be allowed. Refer to Section 1.3 Schedule of Activities for the deadline for proposal submission.

132. Is PSRS open to exploring non-USA/offshore-based hybrid options to provide the requested services and solutions? Our clients typically want to leverage this option to get access to our global pool of cybersecurity professionals in a cost-efficient manner.

We are not sure what “PSRS” is, however, refer to Section 2.30 (B).

133. Is PSRS currently using any service providers that are assisting JTA in performing the requested services? If so, who are these providers?

Unable to respond due to acronyms not defined.

134. Information about the scale of the test - External Penetration Test - What size environment? (IP estimates)

135. How many Roles for the test (admin/ user, etc)?

136. How many web applications, Android and iOS mobile applications are involved in the scope of work?

137. What is the required frequency of the security testing?

Refer to RFP Section 3 Scope of Work. This is determined based on the tool, the cost, and the time built into the Contractor’s proposal.

138. 25RFP13436, Section 3 - Scope of work, Page No. 20

a. Asset Inventory & Environment Details

i. Can BIT provide an approximate number of web applications, systems, and network segments to be included in the assessment?

This is determined based on the tool, the cost, and the time built into the Contractor’s proposal.

ii. Are there any specific technologies (e.g., IIS, Apache, Linux, Windows Server, AD, VPN solutions, EDRs) in use that the vendor should be aware of?

This is determined based on the tool, the cost, and the time built into the contractor’s proposal.

iii. Will cloud-hosted systems (e.g., AWS, Azure, M365) be in-scope for red/purple team testing?

This is determined based on the tool, the cost, and the time built into the Contractor’s proposal.

iv. Is Wi-Fi testing part of the scope?

This is determined based on the tool, the cost, and the time built into the Contractor’s proposal.

b. Red vs. Purple Team Scope

i. Are the red and purple team exercises expected to target the same assets?

Yes.

ii. Should purple team testing simulate specific TTPs aligned with adversaries relevant to South Dakota’s threat profile?

Yes.

iii. What role will BIT staff play during purple team exercises — purely observatory or interactive?

Interactive.

c. Access & Rules of Engagement

i. What type of internal access will be provided — VPN, jump box, credentials or is the vendor required to send their test machines?

This is determined based on the tool, the cost, and the time built into the Contractor’s proposal.

ii. Are there any predefined “safe” or “do-not-test” zones?

We are committed to providing all necessary information once a formal agreement is in place.

iii. Can any social engineering scenarios (e.g., phishing, vishing) be included in the red team assessment?

Yes.

d. Incident Simulation Expectations

i. Are there specific incident response playbooks or attack scenarios BIT wants to simulate (e.g., ransomware, data exfiltration)?

The state will not predefine scenarios. The contractor is expected to propose scenarios.

ii. Will BIT’s blue team be tested in real-time, or will responses be retrospective (reviewed post-exercise)?

Real-time.

e. Assessment Frameworks

i. Is BIT expecting the use of a specific framework as primary (e.g., MITRE

ATT&CK vs. CVSS)?

Refer to RFP Section 3, Scope of Work. Assessments should be based on the most recent version of industry-recognized frameworks or scoring systems such as CIS, EPSS, CVSS, MITRE ATT&CK™/D3FEND™.

ii. provide baseline Will BIT security controls or previous assessment results to help align simulations?

Prior assessments are not relevant to the scope of this RFP. The state will not predefine scenarios. The contractor is expected to propose scenarios.

f. Reporting & Deliverables

i. Can BIT provide a template or rubric for the executive and technical reports?

This is determined based on the tool, the cost, and the time built into the Contractor’s proposal.

ii. Are there any specific compliance requirements (e.g., NIST, HIPAA, CJIS) that should be factored into recommendations?

Refer to RFP Section 3, Scope of Work. Assessments should be based on the most recent version of industry-recognized frameworks or scoring systems such as CIS, EPSS, CVSS, MITRE ATT&CK™/D3FEND™.

g. Contractual Details

i. What is the anticipated contract award date and estimated start date for the assessment?

Refer to RFP Section 1.13 Length of Contract and RFP Section 3 Scope of Work.

ii. Is this a firm-fixed-price contract, or will time-and-materials be considered?

Refer to RFP Section 7 Cost Proposal. As indicated, the offeror may submit multiple cost proposals for red and/or purple team exercise. The offeror’s proposal(s) must include all costs related to the required services, including third-party software licenses the State is expected to pay.

h. What is the budget range BIT has allocated for the red and purple team exercises?

This is a competitive bidding process as required by state law and costs will be a required evaluation factor.

Selection & Evaluation

i. What are the evaluation criteria and scoring weight for the technical proposal, sample report, and cost?

Refer to RFP Section 8 Proposal Evaluation and Award Process.

ii. Will preference be given to vendors that can provide both exercises?

No.

iii. Will on-site presence for purple team be expected for the full duration or specific key days?

The Purple Team exercise is expected to take 1 – 2 weeks with one at least purple team member on site for the entire exercise. Refer to Section 3 Scope of

Work. Additional time will be allotted for report preparation, submission and review.

i. Logistics & Coordination

i. Who will be the primary point of contact/project manager from BIT during the assessment?

The primary point of contact in RFP Section 2.1 along with those mentioned in RFP Section 5.2 will be assigned after the contract is awarded and finalized.

ii. What on-site facilities (e.g., Wi-Fi, secure workspace) will be available for the purple team?

We are committed to providing all necessary information once a formal agreement is in place.

iii. Can the work be performed offshore, or is onshore (U.S.-based) delivery required?

Refer to Section 2.30 (B). Onshore delivery is required.

j. Security & Confidentiality

i. Are there specific nondisclosure or data handling policies beyond standard confidentiality clauses?

Refer to Section 2 and the ITSP.

ii. Will vendors need to go through a state background check or clearance process before testing?

Yes

iii. Are there any citizenship requirements (e.g., U.S. citizen or U.S. person) for individuals performing the assessments?

No

iv. Is a security clearance required for any team members involved in the engagement?

No.

v. Will BIT require background checks or fingerprinting for on-site personnel?

Yes, refer to RFP Section 2.36(D).

k. Post-Engagement

i. Will there be a formal lessons-learned or debrief session with stakeholders beyond BIT?

No.

ii. Is there interest in follow-up services (e.g., blue team training, tabletop exercises, remediation validation)?

139. 25RFP13436, Section 2 - Standard Contract Terms and Conditions, 2.30 State Data – N Data Sanitization, Page No. 15

a. Do we have to submit Attachment A – Certificates of Sanitization for Offsite Data with proposal submission?

With Proposal Submission, No.

140. 25RFP13436, Section 5 - Resources, 5.3 Staff Resumes and References, Page No. 24

a. Three Professional References (name, telephone number, company name, relationship to employee). Do these need to be [VENDOR] references or outside of [VENDOR] references?

Refer to Section 5.3, the offeror will provide resume details for key personnel. Key personnel are defined in this section. Those key personnel will provide three professional references with the details as listed.

141. 25RFP13436, Section 1 - General Information, 1.1.2 Goals and Objectives, Page No. 2

a. BIT is seeking separate proposals and associated costs for both a red team exercise and a purple team exercise. Offerors may be selected for one or both exercises, and different offerors may be chosen for each exercise? Can we bid on only one exercise, or we need to bid on both?

Refer to RFP Section 3 Scope of Work. You have the option to bid on one or both exercises.

142. 25RFP13436, Section 3 - Scope of work, Page No. 20

a. Purple team exercise will require at least one blue team contractor staff on-site in

Sioux Falls, SD, during the exercise to identify the attack simulations in near real-time?

Yes.

Is this mandatory or can be done remotely?

Mandatory. It is required to have at least one blue team contractor staff on site in Sioux Falls, SD during the exercise.

b. How many Executive Branch entities are included in the assessment?

This is determined based on the tool, the cost, and the time built into the Contractor’s proposal.

c. What is the total number of users across the in-scope environment?

This is determined based on the tool, the cost, and the time built into the Contractor’s proposal.

d. How many endpoint systems (Windows/Linux/macOS) are in-scope for testing?

This is determined based on the tool, the cost, and the time built into the Contractor’s proposal.

e. How many web applications (internal and external) are included in the scope?

This is determined based on the tool, the cost, and the time built into the Contractor’s proposal.

f. Are the applications hosted in on-premises, cloud, or hybrid environments?

This is determined based on the tool, the cost, and the time built into the Contractor’s proposal.

g. Are APIs included in the scope? If yes, how many APIs and endpoints per API?

This is determined based on the tool, the cost, and the time built into the Contractor’s proposal.

h. How many internal and external IP addresses are within scope?

i. How many internal network segments or VLANs are in-scope?

proposal.

j. Which security tools are currently deployed (e.g., SIEM, SOAR, EDR, IDS/IPS, Threat Intel platform)?

We are committed to providing all necessary information once a formal agreement is in place.

k. What endpoint protection or EDR solutions are in use (e.g., Defender ATP, CrowdStrike, SentinelOne)?

We are committed to providing all necessary information once a formal agreement is in place.

l. Is there an established Security Operations Center (SOC) team?

We are committed to providing all necessary information once a formal agreement is in place.

m. Are existing detection rules, playbooks, or threat use cases already implemented? Yes.

Should we support in enhancing or building new ones?

For purple team exercise, Refer to RFP Section 3 Scope of Work.

n. Is your IT infrastructure primarily on-premises, cloud-based, or hybrid?

We are committed to providing all necessary information once a formal agreement is in place.

o. Which business units, systems, or critical applications should be prioritized for testing?

This is determined based on the tool, the cost, and the time built into the Contractor’s proposal.

p. Are third-party managed services or cloud-hosted platforms included in the scope (e.g., SaaS, IaaS) This is determined based on the tool, the cost, and the time built into the Contractor’s proposal.

q. Is this engagement a one-time Red and Purple Team exercise, or is a multi-phase/continuous engagement planned (e.g., 2 years)?

Refer to RFP Section 1.13 Length of Contract, within the 2 years this is determined based on the tool, the cost, and the time built into the Contractor’s proposal.

r. If ongoing, what is the preferred frequency of assessments (quarterly, biannually, annually)?

Annually.

s. Do you require agent based or agentless simulations?

No.

t. Is it a recompete? If yes, who is the incumbent.

This is a competitive bidding process as required by state law.

u. What is the value of the current contract?

This is a competitive bidding process as required by state law.

v. Can we get an extension of time?

No.

w. Is there any page limit for the technical response or sections

x. Can we engage offshore teams in the red and purple team exercises.

No. Refer to Section 2.30 (B).

143. Section 3 Scope of Work: Please clarify if the State intends for two separate proposals to be submitted. One for red team and the other for purple team?

Refer to RFP Section 3 Scope of Work. You have the option to bid on one or both exercises.

144. Section 3 Scope of Work: Can an approximate number of systems, IP addresses, and applications be provided?

145. Section 6.8.1: How many firm references are required?

There is not a specific number of references required.

146. Can you please provide an estimated scope of assets ( i.e. number of public IP’s, web applications, or internal systems) to help size proposal accurately ?

147. Beyond physical testing, are any techniques ( social engineering, phishing, etc) prohibited during the red or purple team exercises ?

148. Is there a target or not-to-exceed budget for this engagement ?

evaluation factor.

149. Can the State confirm whether this RFP represents a new initiative for penetration testing, or is it a continuation or renewal of a prior engagement?

150. If there is an incumbent, can you provide the name(s) of the contractor(s) or company(ies) currently or previously performing these services?

151. Can the State please share the contract value or budget range for the most recent engagement with the incumbent(s)?

This question is not relevant to the scope of this RFP and submission of a proposal. This is a competitive bidding process as required by state law and costs will be a required evaluation factor.

152. Section 1.1.2 of the RFP notes that BIT is seeking separate proposals and associated costs for both red team and purple team exercises, and that different offerors may be selected for each. Can the State please confirm that offerors are permitted to respond to only one of the two exercises (e.g., red team only), and that such a proposal will still be fully considered?

You have the option to bid on one or both exercises. Each exercise will be evaluated independently.

153. General Questions

a. How big is the State’s IT organization? How many staff members and departments does the State have?

We are committed to providing all necessary information once a formal agreement is in place.

b. Has the State adopted a security control framework? If yes, which one?

This question is not relevant to the scope of this RFP and submission of a proposal.

c. When was the State’s last assessment of this nature performed?

This question is not relevant to the scope of this RFP and submission of a proposal.

d. Does the State have documented IT policies, procedures, standards, and guidelines in place? If so, how many?

Yes, Refer to the ITSP included with the RFP.

e. Is there an incumbent and are they eligible to bid on this project? If so, who is the incumbent and what was the value of the contract?

This question is not relevant to the scope of this RFP and submission of a proposal.

f. What is the Sate’s budget for this project?

This is a competitive bidding process as required by state law and costs will be a required evaluation factor.

154. Internal/External Network Questions

a. External: What is the approximate number of active IPs in scope?

This is determined based on the tool, the cost, and the time built into the Contractor’s proposal.

b. Internal: What is the range of IP addresses in scope?

155. Red Team Testing Questions

a. Please provide the State’s definition of “red team” and list the services the organization expects to be included in the long-term red team test? For example, would we be allowed to conduct website surfing, social engineering activities, such as email phishing, and/or a physical site analysis?

Red teaming is the process of using Tactics, Techniques, and Procedures (TTPs) to emulate real-world threats with the goal of training and measuring the effectiveness of the people, processes, and technology used to defend an environment. Reference:

https://redteam.guide/docs/definitions/#red-teaming

Refer to Section 1.1.4 Scope of Components of Phases. Note: Physical penetration testing is not included in the scope.

156. Wireless Network Testing Questions

a. How many locations are in scope?

This is determined based on the tool, the cost, and the time built into the Contractor’s proposal.

b. How many controllers are in scope?

This is determined based on the tool, the cost, and the time built into the Contractor’s https://redteam.guide/docs/definitions/#red-teaming

c. If not controller-based, how many WAPS are there?

157. Web Application Testing Questions

a. How many URLs are to be tested?

This is determined based on the tool, the cost, and the time built into the Contractor’s proposal.

b. How many applications are to be tested?

158. Firewall Review Questions

a. How many firewalls does the State have in scope?

This is determined based on the tool, the cost, and the time built into the Contractor’s proposal.

b. How many of the firewalls are in HA (high availability) mode?

We are committed to providing all necessary information once a formal agreement is in place.

c. How many different kinds/brands of firewalls?

We are committed to providing all necessary information once a formal agreement is in place.

d. Is sampling by type/brand of firewall acceptable?

We are committed to providing all necessary information once a formal agreement is in place.

159. IT Risk Assessment Questions

a. How many enterprise applications are included in the scope of the risk assessment, e.g., for finance, payroll, and accounting systems, which are of critical value to the organization and accessed by users from multiple departments?

This is determined based on the tool, the cost, and the time built into the Contractor’s proposal.

b. How many databases that support the enterprise applications are included in the scope?

This is determined based on the tool, the cost, and the time built into the Contractor’s proposal.

c. How many operating systems are included in the scope?

This is determined based on the tool, the cost, and the time built into the Contractor’s proposal.

d. Do you use cloud services, on-premises infrastructure, or a hybrid environment?

160. Item 1.12, Page 2. Are we to submit two completely separate proposals for the two tasks you are seeking or will two write-ups within the same proposal be acceptable?

Two writeups within the same proposal will be acceptable as long as the different exercises and costs are clearly defined.

161. Clause 2.35 Access Attempts. The requirement to log all access attempts during a “red team” exercise, where making access attempts is part of the assignment may require significant manual work. Is this what you are requesting or can this particular clause be excluded?

All connection activity during the engagement, where the target of the connection is a State of South Dakota asset, should be logged to the best of the Contractor's ability.

162. Clause 2.36, A Security Incident Notification. Technically, during a “red team” exercise, going beyond pings and scans, or other broadcast attacks, etc. are exactly what the Contractor will be trying to do. Can this clause be tailored to the project to avoid triggering this clause?

This clause does not apply to the “red…

This is the start of the file's text. The full file is on GovTribe.

File details come from the government source that posted it. Updated .