RFI - Hack DHS CVAS.pdf

PDF 134 KB Posted

Attached to
Hack DHS: Crowdsourced Vulnerability Assessment Services (CVAS) Federal contract opportunity
Solicitation number
70RTAC22RFI000001
Issued by
Department of Homeland Security Office of Procurement Operations

About this file

This Request for Information (RFI) solicits responses from potential vendors regarding crowdsourced vulnerability assessment services for the Department of Homeland Security's (DHS) Hack DHS program. DHS seeks to establish an ordering vehicle to procure said services on an ongoing basis to support proactively protecting DHS computer networks and systems that are critical to both daily operations and national security. The RFI provides background on the SECURE Tech Act authorizing DHS to conduct bug bounty programs and compensate security researchers for evaluating DHS information systems. Interested vendors should respond by March 17th with company and socioeconomic information, relevant contract vehicles, and descriptions of similar past project experience for DHS to conduct market research on establishing a future contract vehicle. Responses are limited to two pages using Times New Roman 12-point font.

View the file

Other files for this federal contract opportunity

Other files attached to Hack DHS: Crowdsourced Vulnerability Assessment Services (CVAS), newest first.
File Type Posted
DRAFT PWS - Hack DHS CVAS.pdf PDF

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

U.S. Department of Homeland Security

Washington, DC 20528

REQUEST FOR INFORMATION (RFI)

Department of Homeland Security (DHS)

Hack DHS: Crowdsourced Vulnerability Assessment Services (CVAS)

THIS IS A REQUEST FOR INFORMATION (RFI) ONLY. Under the auspices of the EAGLE

Next Generation (Next Gen) Program that focuses on effectively and efficiently addressing

DHS's diverse information technology (IT) service needs, this RFI supports the Department's efforts towards balancing the use of existing Government-wide Acquisition Contracts (GWACs) in conjunction with the creation of a portfolio of IT services contract vehicles with a specialized, targeted scope (See Attached Draft PWS).

This RFI is for planning purposes only and shall not be construed as an obligation on the part of the Government. This is NOT a Request for Quotations or Proposals. No solicitation document exists, and the Government may or may not issue a formal solicitation as a result of the responses received to this RFI.

The Government will not pay for any response or demonstration expenses. All costs incurred responding to this RFI will be solely at the interested party's expense. Failure to respond to this

RFI will not preclude participation in any future solicitation. Any information received will become the property of the Government and will not be returned to the submitter. Interested parties are responsible for adequately marking proprietary or sensitive information.

Government technical experts drawn from staff within DHS and other federal agencies may review responses. The Government may use selected support contractor personnel to assist in the review of the RFI responses. These support contractors will be bound by appropriate non-disclosure agreements to protect proprietary information.

I. INTRODUCTION

The purpose of this Request for Information (RFI) is to conduct market research to identify qualified and interested sources that could provide the services stated in the drat Performance

Work Statement (PWS), which will help the Government determine feasibility to establish a

Department-wide ordering vehicle to procure commercial Crowdsourced Vulnerability

Assessment Services (CVAS).

II. BACKGROUND

In accordance with Public Law 115-390, “SECURE Technology Act”, the Secretary of the

Department of Homeland Security (DHS) approved a multi-year program to execute bug bounties using proven crowd-sourced cybersecurity assessment methodologies on December 14, 2021. A bug bounty is a crowd-sourced penetration test, where security researchers are incentivized to find vulnerabilities (bugs) in systems in return for financial payments (bounties).

Bug bounties are tightly controlled and monitored engagements facilitated by a vendor and the

DHS Chief Information Security Officer (CISO).

The SECURE Tech Act permits DHS to provide compensation to security researchers who evaluate DHS’s information systems by mimicking malicious behavior. The program draws from industry best practices and on lessons learned from the highly successful “Hack the Pentagon” program at the Department of Defense (DoD). DoD was the first Federal entity to launch this program, however, Bug bounties are commonly used as a best practice in the private sector, e.g., Facebook, Apple, Intel, and Goldman Sachs.

The Hack DHS program has been approved and authorized by the Secretary and DHS needs to procure services in support the program throughout future years. The procured services will assist in proactively protecting DHS’s computer networks and systems that support the mission essential and high valued assets that are critical both for daily business operations and activities.

Maintaining the security and integrity of DHS networks and systems is a matter of national security and requires the continuous proactive activities to identify and remediate vulnerabilities that can be exploited by malicious cyber actors. As part of its responsibility to the public at large, DHS is constantly considering innovative and diverse approaches to meet this goal. To support

DHS’s continual efforts to remain at the forefront of rapidly evolving technologies, and to maintain the highest levels of integrity and security required of its IT infrastructure, DHS has identified an emerging need to leverage a diverse pool of innovative information security researchers (herein referred to as “researcher”), via crowdsourcing, for vulnerability discovery, coordination, and disclosure activities.

III. SUBMISSION REQUIREMENTS

Responses from “all” sources are requested. Other than Small Businesses, Small Businesses, 8(a) small businesses, HUBZone small businesses, Service-Disabled Veteran-Owned Small

Businesses, Woman-Owned Small Businesses and Economically Disadvantaged Women-Owned

Small Businesses are encouraged to respond.

Responses shall be a maximum of two (2) pages and include the following information:

1) Company name and address

2) Business size/socio-economic category under NAICS Code 541519

3) Points of contact including phone numbers and email addresses

4) Company CAGE code and DUNS number

5) Identify contract vehicles available to DHS through which your services are provided such as government-wide contracts including General Services Administration Federal

Supply Schedule etc.

6) A description of corporate experience for similar contracts and/or projects in the private and/or public sectors, including entity name, period of performance, total value, and brief summary of scope. This information must demonstrate how the firm’s corporate experience is relevant to the CVAS requirements.

Submissions shall be made using Microsoft Office applications. Font shall not be smaller than

12-point Times New Roman. Please provide your response to this RFI no later than 12 pm

Eastern Time on March 17, 2022 to Sohl Han, at Sohl.Han@hq.dhs.gov and LaKeisha Johnson, at Lakeisha.Johnson@hq.dhs.gov. Any questions and inquiries must be submitted via email at the email addresses above.

The Government reserves the right to hold one-on-one meetings as a result of responses received from this RFI as part of its market research. Meetings may be held in particular with companies who provide comprehensive and relevant responses to the RFI.

Attachment: Draft PWS mailto:Sohl.Han@hq.dhs.gov mailto:Lakeisha.Johnson@hq.dhs.gov

File details come from the government source that posted it. Updated .