RFI - Hack DHS CVAS.pdf
PDF 134 KB Posted
- Attached to
- Hack DHS: Crowdsourced Vulnerability Assessment Services (CVAS) Federal contract opportunity
- Solicitation number
- 70RTAC22RFI000001
About this file
This Request for Information (RFI) solicits responses from potential vendors regarding crowdsourced vulnerability assessment services for the Department of Homeland Security's (DHS) Hack DHS program. DHS seeks to establish an ordering vehicle to procure said services on an ongoing basis to support proactively protecting DHS computer networks and systems that are critical to both daily operations and national security. The RFI provides background on the SECURE Tech Act authorizing DHS to conduct bug bounty programs and compensate security researchers for evaluating DHS information systems. Interested vendors should respond by March 17th with company and socioeconomic information, relevant contract vehicles, and descriptions of similar past project experience for DHS to conduct market research on establishing a future contract vehicle. Responses are limited to two pages using Times New Roman 12-point font.
View the file
Other files for this federal contract opportunity
| File | Type | Posted |
|---|---|---|
| DRAFT PWS - Hack DHS CVAS.pdf |
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
U.S. Department of Homeland Security
Washington, DC 20528
REQUEST FOR INFORMATION (RFI)
Department of Homeland Security (DHS)
Hack DHS: Crowdsourced Vulnerability Assessment Services (CVAS)
THIS IS A REQUEST FOR INFORMATION (RFI) ONLY. Under the auspices of the EAGLE
Next Generation (Next Gen) Program that focuses on effectively and efficiently addressing
DHS's diverse information technology (IT) service needs, this RFI supports the Department's efforts towards balancing the use of existing Government-wide Acquisition Contracts (GWACs) in conjunction with the creation of a portfolio of IT services contract vehicles with a specialized, targeted scope (See Attached Draft PWS).
This RFI is for planning purposes only and shall not be construed as an obligation on the part of the Government. This is NOT a Request for Quotations or Proposals. No solicitation document exists, and the Government may or may not issue a formal solicitation as a result of the responses received to this RFI.
The Government will not pay for any response or demonstration expenses. All costs incurred responding to this RFI will be solely at the interested party's expense. Failure to respond to this
RFI will not preclude participation in any future solicitation. Any information received will become the property of the Government and will not be returned to the submitter. Interested parties are responsible for adequately marking proprietary or sensitive information.
Government technical experts drawn from staff within DHS and other federal agencies may review responses. The Government may use selected support contractor personnel to assist in the review of the RFI responses. These support contractors will be bound by appropriate non-disclosure agreements to protect proprietary information.
I. INTRODUCTION
The purpose of this Request for Information (RFI) is to conduct market research to identify qualified and interested sources that could provide the services stated in the drat Performance
Work Statement (PWS), which will help the Government determine feasibility to establish a
Department-wide ordering vehicle to procure commercial Crowdsourced Vulnerability
Assessment Services (CVAS).
II. BACKGROUND
In accordance with Public Law 115-390, “SECURE Technology Act”, the Secretary of the
Department of Homeland Security (DHS) approved a multi-year program to execute bug bounties using proven crowd-sourced cybersecurity assessment methodologies on December 14, 2021. A bug bounty is a crowd-sourced penetration test, where security researchers are incentivized to find vulnerabilities (bugs) in systems in return for financial payments (bounties).
Bug bounties are tightly controlled and monitored engagements facilitated by a vendor and the
DHS Chief Information Security Officer (CISO).
The SECURE Tech Act permits DHS to provide compensation to security researchers who evaluate DHS’s information systems by mimicking malicious behavior. The program draws from industry best practices and on lessons learned from the highly successful “Hack the Pentagon” program at the Department of Defense (DoD). DoD was the first Federal entity to launch this program, however, Bug bounties are commonly used as a best practice in the private sector, e.g., Facebook, Apple, Intel, and Goldman Sachs.
The Hack DHS program has been approved and authorized by the Secretary and DHS needs to procure services in support the program throughout future years. The procured services will assist in proactively protecting DHS’s computer networks and systems that support the mission essential and high valued assets that are critical both for daily business operations and activities.
Maintaining the security and integrity of DHS networks and systems is a matter of national security and requires the continuous proactive activities to identify and remediate vulnerabilities that can be exploited by malicious cyber actors. As part of its responsibility to the public at large, DHS is constantly considering innovative and diverse approaches to meet this goal. To support
DHS’s continual efforts to remain at the forefront of rapidly evolving technologies, and to maintain the highest levels of integrity and security required of its IT infrastructure, DHS has identified an emerging need to leverage a diverse pool of innovative information security researchers (herein referred to as “researcher”), via crowdsourcing, for vulnerability discovery, coordination, and disclosure activities.
III. SUBMISSION REQUIREMENTS
Responses from “all” sources are requested. Other than Small Businesses, Small Businesses, 8(a) small businesses, HUBZone small businesses, Service-Disabled Veteran-Owned Small
Businesses, Woman-Owned Small Businesses and Economically Disadvantaged Women-Owned
Small Businesses are encouraged to respond.
Responses shall be a maximum of two (2) pages and include the following information:
1) Company name and address
2) Business size/socio-economic category under NAICS Code 541519
3) Points of contact including phone numbers and email addresses
4) Company CAGE code and DUNS number
5) Identify contract vehicles available to DHS through which your services are provided such as government-wide contracts including General Services Administration Federal
Supply Schedule etc.
6) A description of corporate experience for similar contracts and/or projects in the private and/or public sectors, including entity name, period of performance, total value, and brief summary of scope. This information must demonstrate how the firm’s corporate experience is relevant to the CVAS requirements.
Submissions shall be made using Microsoft Office applications. Font shall not be smaller than
12-point Times New Roman. Please provide your response to this RFI no later than 12 pm
Eastern Time on March 17, 2022 to Sohl Han, at Sohl.Han@hq.dhs.gov and LaKeisha Johnson, at Lakeisha.Johnson@hq.dhs.gov. Any questions and inquiries must be submitted via email at the email addresses above.
The Government reserves the right to hold one-on-one meetings as a result of responses received from this RFI as part of its market research. Meetings may be held in particular with companies who provide comprehensive and relevant responses to the RFI.
Attachment: Draft PWS mailto:Sohl.Han@hq.dhs.gov mailto:Lakeisha.Johnson@hq.dhs.gov
File details come from the government source that posted it. Updated .