RFI Attachment 1-Questionaire_RFI ESDIAB01_05-25-23.docx
DOCX document 31 KB Posted
- Attached to
- USCG Information Assurance (IA) Risk Management Framework (RMF) Services Federal contract opportunity
- Solicitation number
- 70Z04423IESDIAB01
View the file
Other files for this federal contract opportunity
| File | Type | Posted |
|---|---|---|
| RFI Vendor Question-Comment Summary - IA RMF RFI - v08-10-23.xlsx | XLSX spreadsheet | |
| RFI Attachment 6-Question-Comment Form - v1_05-22-23.xls | XLS spreadsheet | |
| RFI Attachment 4-Draft_IA-RMF-IDIQ_Labor Categories_V1_04-17-23.xlsx | XLSX spreadsheet | |
| RFI Attachment 3-Draft_IA-RMF-IDIQ_Scope of Work_20230525_v2.0.4.docx | DOCX document | |
| RFI Attachment 2 - Draft_IA-RMF-IDIQ_RFP_v4_05-22-23.docx | DOCX document | |
| RFI Attachment 5-Draft_IA-RMF_C5ISCTaskOrderPWS_v0.3_05-25-23.docx | DOCX document |
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
RFI #: 70Z04423IESDIAB01
Attachment 1 – Questionnaire
General
1. Name of Company, SAM.gov Unique Entity Identifier (UEI) number, and Cage Code.
2. Point of contact name, phone number and e-mail address
3. Size of business according to North American Industry Classification System (NAICS) Code 541519.
Pricing
4. What quantitative and qualitative information do you need from the government to assist you in forming a quality Basis of Estimate?
5. Are the labor categories and proficiency levels suitable for performance of the full Scope of Work described in the draft RFP? Please provide recommendations for additional labor categories, if applicable.
6. Should pricing proposals accommodate a difference in labor rates between all the locations associated with this contract?
7. Would it be consistent with industry standards to pre-price RMF services based upon the type of IT system or Platform IT? If so, how do you suggest structuring pricing given various factors affecting a system’s RMF coverage costs? (i.e. Financial system, Privacy system, USCG data center hosted, USCG developed vs COTS or GOTS, Cloud service provider, etc.)
8. A majority of staff positions for the Command, Control, Communications, Computers, Cyber and Intelligence Service Center (C5ISC) Task Order (TO) only require For Official Use Only (FOUO), while some who work on systems classified SECRET will require a SECRET clearance. Should pricing proposals accommodate a difference in labor rates between positions requiring a SECRET clearance and those that do not?
...vs
9. Do you anticipate a difference in price for staff on-site (Government facility) versus 100% off-site (contractor’s facility or other remote location), as well as a mixture (i.e. 2-3 days on-site per week)?
Technical
10. Do you suggest other ways to describe and organize these kinds of work in the Performance Work Statement (PWS): Information Technology (IT) systems, Platform IT, Platform IT systems, Labs, Command Cyber Readiness Inspection (CCRI).
11. How do the Information System Security Officer (ISSO) responsibilities and required knowledge and experience differ for systems under DevSecOps with a continuous Authority To Operate (ATO) model, versus systems requiring a traditional ATO cycle with continuous monitoring?
12. Do you have ISSO experience working in an Agile lifecycle? How do you propose the ISSO be involved in the development sprints to ensure a proactive cybersecurity approach?
13. What do you see as the ISSO Level of Effort (LOE) differences between performing a traditional 3-year ATO cycle and achieving maintenance of a Continuous ATO (via software factory and CI/CD pipeline approach)?
File details come from the government source that posted it. Updated .