RFI Questionnaire Cyber Range.xlsx
XLSX spreadsheet 42 KB Posted
- Attached to
- RFI Cyber Range Federal contract opportunity
- Solicitation number
- 2501
- Issued by
- Administrative Office of the U.S. Courts
About this file
This is a Request for Information (RFI) questionnaire from the Administrative Office of the U.S. Courts seeking information about cyber range services. The questionnaire requires vendors to rate their capabilities on a 0-4 scale across multiple functional areas including cyber range environment features, security compliance, and implementation capabilities.
The questionnaire covers specific technical requirements including the ability to conduct live virtual training events, support for up to 25 simultaneous students, integration of various cybersecurity tools (Qualys, Nessus, Splunk, etc.), multi-cloud support, and concurrent lab scenarios. Key security requirements include FedRAMP certification, SSO/SAML integration, data encryption, and role-based access control. Vendors must also detail their implementation support, training capabilities, and ability to provide pre-packaged cybersecurity curriculum content. Responses are due by 12:00 PM Eastern on February 26, 2025, and should be submitted via email to Vanessa Jackson. The intended NAICS code is 611420 (Computer Training) and PSC code is DF10 (IT and Telecom - IT Management As A Service).
View the file
Other files for this federal contract opportunity
| File | Type | Posted |
|---|---|---|
| CyberRange_RFI_Required Capabilities.pdf |
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
Instructions to the Vendor
| Instructions for Completion of the Questionnaire |
| Vendors should complete the following capabilities worksheet by answering each question based on the answers below. |
| 0 Functionality not provided |
| 1 Functionality provided; however, requires customized integration with third party |
| 2 Functionality provided by the vendor, but requires customization |
| 3 Functionality provided seamlessly by third-party product |
| 4 Functionality provided out of the box |
0 — Functionality not provided: Not included in the proposed application.
1 — Functionality provided; requires customized integration with third party: Vendor has established a relationship with a business partner to provide this functionality, but it requires customization or workarounds.
2 — Functionality provided by the vendor but requires customization: The functionality can be accomplished with the vendor’s product, but some customization or workaround is required.
3 — Functionality provided seamlessly by third-party product: The vendor has established a relationship (for example, as an OEM) with a business partner to provide this functionality, which is integrated in its database management system (DBMS) and requires no customization or workaround.
4 — Functionality provided out of the box: The vendor provides the functionality from its own codebase. No customization or workaround is required.
Additional Notes to the Vendor:
When providing responses, the guide below should be followed. The comments column is provided for clarification when necessary.
Vendors are cautioned not to indicate functionality as "included in standard offering" when, in fact, that particular function is in development. If this is the case, then vendors should note this fact in the comments column and indicate the expected date such features will be made available.
Questionnaire
| Digital Adoption Platforms RFI Questionnaire | |||
| Use Cases | |||
| Criterion | Description | Vendor Response | Comments |
| Cyber Range Environment | The cyber range should allow for trainers to conduct live, virtual training events with congruent operating models supporting custom hands-on training on cybersecurity tools. The operating models need to include accurate, simulated court network environments for realistic training events. |
| Capabilities | |||
| Criterion | Description | Vendor Response | Comments |
| Customization | Ability to provide an environment which can be customized on demand to match intel-driven requirements | ||
| Incorporate cyber tools | Ability to incorporate independent cyber tools into the cyber environment for cyber professionals to respond to/engage with various threat scenarios, including but not limited to: | ||
| · Patch and Asset Management – KACE K1000 or Qualys | |||
| · Vulnerability Scanning – Tenable’s Security Center - Nessus | |||
| · Endpoint Protection Service – Trend Micro Apex One | |||
| · National Logging Service – Splunk – 9.x | |||
| · Firewall Service – Palo Alto | |||
| · Web Base Threat Protection - Forcepoint | |||
| Concurent Labs | Capability to have concurrent range scenarios and/or labs running at any given time | ||
| 24/7 access | Allows participants on-premises and remote to access any given scenario and labs simultaneously | ||
| Blue and Red team scenarios | Ability for blue and red cyber teams to simultaneously engage in scenarios | ||
| Present Representations | Ability to represent blue and red representations at various levels of fidelity from hardware-in-the-loop to network models of systems, to include representations of components and systems | ||
| Multi-Cloud Support | Support for across multiple cloud providers (e.g., AWS, Azure, GCP) and hybrid environments. | ||
| User-Friendly Interface | Intuitive dashboard and reporting features for ease of use and quick insights. | ||
| Generate multiple environments | Ability to generate multiple environments to support different scenarios and different users | ||
| Mission design | Ability for mission planners/white teams to design and execute missions with an intuitive graphical user interface, record/playback scenarios, and export time-sequenced scenario data for further analysis | ||
| Collaboration Tools | Features that enable teams to collaborate effectively on governance activities and incident management. | ||
| Replicate and employ threats at scale. | Ability to replicate and employ threats at scale either pre-planned or in real-time | ||
| Support congruent operating models | Ability to support congruent operating models supporting blue and red representations simultaneously for large-scale and team/mission-focused scenarios | ||
| Pre-packaged content | Ability to purchase or subscribe to pre-packaged content ready to be integrated into curriculum for key cybersecurity topics including, but not limited to, cryptography, network security, computer security, software security, offensive security, defensive security, digital forensics on network traffic and digital devices, and incident response. | ||
| Training events | Training events should support up to 25 students at the same time, with the ability to rotate to a different group of students each month |
| Security, Compliance, Architecture | |||
| Criterion | Description | Vendor Response | Comments |
| User access security management | Security is managed via integration with the corporate identity provider and automated as much as possible. Role based configuration is used for aggregation and anonymization. | ||
| Security level | The administrative security is provided down to a table/field level. | ||
| User authentication | The vendors product must support standards based modern authentication to the Judiciary's IDP. | ||
| Role-based security | Role-based access control (RBAC)for admins and end user roles is supported. | ||
| Data transmission and storage | Data is secured during transmission | ||
| Data encryption | Encryption is provided both in transit and at rest. | ||
| Password encryption | Passwords are encrypted. Please describe the password policy. | ||
| Password policy | User password change requirements are supported and are configurable by compensation administrators. | ||
| Ability to support Firefox 52.x or higher | Firefox is supported. | ||
| Ability to support Chrome 63.x or higher | Chrome is supported. | ||
| Ability to support Microsoft Edge Version 108.0.1462.54 or higher | Microsoft Edge is supported. | ||
| Ability to support Safari 10.x or higher | Safari is supported. | ||
| Cloud VPN Support | Cloud VPN is supported. The current implemtation is through Zscaler. | ||
| Zero footprint (excluding browser plug in) | No software or data requirements for client access beyond a browser. | ||
| Maintenance windows | A standard maintenance window and schedule are provided. | ||
| Data privacy | Data privacy is ensured. Provide documentation explaining how the vendor handles data. | ||
| Data rights | In the event that the company decides to transition to a different solution, it is able to retrieve its data. | ||
| Data separation | Data is separated and secured from other tenants. | ||
| Data protection | Data is protected from other users on the same (cloud) server (if shared). | ||
| Data access | Access to the company's data is limited. | ||
| Incident procedures | There are security and operational incident response procedures. | ||
| Incident notification | Vendor will notify us of security incidents. Please describe the response time and notification procedure in the Comments section. | ||
| Incident reports | Post-incident/root cause analysis reports will be provided. | ||
| Incident SLA | Vendor provides an SLA on incident handling notifications. | ||
| Data destruction on termination | Data will be destroyed if agreement is terminated. | ||
| Private and sensitive information | The export of private and sensitive information is limited. | ||
| Information security policy | Vendor has an information security policy. | ||
| US Governent | Vendor is FedRamp certified | ||
| Vendor assessments | Vendor assessments are performed by a third party. | ||
| Vendor assessment reports | Reports produced as part of such assessments can be reviewed by our organization. | ||
| Security audit | Our organization is able to periodically audit the vendor's security practices. | ||
| Audit results for the past two years | Vendor is willing to share the external audit results for the last two years. | ||
| Disaster recovery | There is a separate disaster recovery site. | ||
| Backups and encryption | Backups are encrypted and routinely tested. | ||
| Hosting Service | Vendor uses tier 1 services such as AWS. List providers used for hosting infrastrucutre services, authentication, application monitoring and Content Delivery Network (CDN) |
| General Capabilities | |||
| Criterion | Description | Vendor Response | Comments |
| End user UI ease of navigation | Supports ease of use features for both end users, content curators and administrators of the platform. | ||
| Ease of administration and structure, governance | Information is structured and governed with in the platform. | ||
| User community | Online community for support and ideas for all vendor customers. | ||
| User feedback | Ability for users to post feedback on materials. This can include ratings but is meant to determine more specific feedback via written form. | ||
| Change management | Administrative training for management of solution including reporting and analysis is provided. | ||
| Customer support | Support is provided 24/7 and is included in the subscription costs. A designated POC is provided. | ||
| Data storage | Unlimited data storage is provided. | ||
| Scalable architecture | The proposed solution architecture scales (users,roles, business units, geographies, etc.). | ||
| Business continuity | Business continuity plans and policies are provided. | ||
| Solution is low/no code | The proposed Cyber Range is low/no code for content builders (back end resources) | ||
| Solution is role based | Solution provides diferent administrative and end user roles and there is no limit to the number of roles that can be configured. List role access. | ||
| Compliance for people with disabilities | The platform supports people with disabilities, confirming to acts like the Americans with Disabilitis act. |
| Integration and Platform Capabilities | |||
| Criterion | Description | Vendor Response | Comments |
| SSO/SAML integration | Supports SSO/SAML integration. | ||
| LDAP integration | Supports LDAP integration. | ||
| Integration to portals | Supports integration to portals | ||
| Integrations and APIs | Supports open API integration to other systems. Please list any that are provided out of the box in the comments column | ||
| CI/CD | Incorporate the judiciary continuous integration and continuous deployment (CI/CD) pipeline. |
| Implementation, Configuration, Kick-off support | |||
| Criterion | Description | Vendor Response | Comments |
| Training | Vendor provided training for Training Division staff. | ||
| Set-up, configuration, and deployment | Vendor must include setup, configuration, and deployment support to assist with training and rapid deployment of the product during the base year only. |
File details come from the government source that posted it. Updated .