RFI Questionnaire Cyber Range.xlsx

XLSX spreadsheet 42 KB Posted

Attached to
RFI Cyber Range Federal contract opportunity
Solicitation number
2501
Issued by
Administrative Office of the U.S. Courts

About this file

This is a Request for Information (RFI) questionnaire from the Administrative Office of the U.S. Courts seeking information about cyber range services. The questionnaire requires vendors to rate their capabilities on a 0-4 scale across multiple functional areas including cyber range environment features, security compliance, and implementation capabilities.

The questionnaire covers specific technical requirements including the ability to conduct live virtual training events, support for up to 25 simultaneous students, integration of various cybersecurity tools (Qualys, Nessus, Splunk, etc.), multi-cloud support, and concurrent lab scenarios. Key security requirements include FedRAMP certification, SSO/SAML integration, data encryption, and role-based access control. Vendors must also detail their implementation support, training capabilities, and ability to provide pre-packaged cybersecurity curriculum content. Responses are due by 12:00 PM Eastern on February 26, 2025, and should be submitted via email to Vanessa Jackson. The intended NAICS code is 611420 (Computer Training) and PSC code is DF10 (IT and Telecom - IT Management As A Service).

View the file

Other files for this federal contract opportunity

Other files attached to RFI Cyber Range, newest first.
File Type Posted
CyberRange_RFI_Required Capabilities.pdf PDF

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

Instructions to the Vendor

Instructions for Completion of the Questionnaire
Vendors should complete the following capabilities worksheet by answering each question based on the answers below.
0 Functionality not provided
1 Functionality provided; however, requires customized integration with third party
2 Functionality provided by the vendor, but requires customization
3 Functionality provided seamlessly by third-party product
4 Functionality provided out of the box

0 — Functionality not provided: Not included in the proposed application.

1 — Functionality provided; requires customized integration with third party: Vendor has established a relationship with a business partner to provide this functionality, but it requires customization or workarounds.

2 — Functionality provided by the vendor but requires customization: The functionality can be accomplished with the vendor’s product, but some customization or workaround is required.

3 — Functionality provided seamlessly by third-party product: The vendor has established a relationship (for example, as an OEM) with a business partner to provide this functionality, which is integrated in its database management system (DBMS) and requires no customization or workaround.

4 — Functionality provided out of the box: The vendor provides the functionality from its own codebase. No customization or workaround is required.

Additional Notes to the Vendor:

When providing responses, the guide below should be followed. The comments column is provided for clarification when necessary.

Vendors are cautioned not to indicate functionality as "included in standard offering" when, in fact, that particular function is in development. If this is the case, then vendors should note this fact in the comments column and indicate the expected date such features will be made available.

Questionnaire

Digital Adoption Platforms RFI Questionnaire
Use Cases
CriterionDescriptionVendor ResponseComments
Cyber Range EnvironmentThe cyber range should allow for trainers to conduct live, virtual training events with congruent operating models supporting custom hands-on training on cybersecurity tools. The operating models need to include accurate, simulated court network environments for realistic training events.
Capabilities
CriterionDescriptionVendor ResponseComments
CustomizationAbility to provide an environment which can be customized on demand to match intel-driven requirements
Incorporate cyber toolsAbility to incorporate independent cyber tools into the cyber environment for cyber professionals to respond to/engage with various threat scenarios, including but not limited to:
· Patch and Asset Management – KACE K1000 or Qualys
· Vulnerability Scanning – Tenable’s Security Center - Nessus
· Endpoint Protection Service – Trend Micro Apex One
· National Logging Service – Splunk – 9.x
· Firewall Service – Palo Alto
· Web Base Threat Protection - Forcepoint
Concurent LabsCapability to have concurrent range scenarios and/or labs running at any given time
24/7 accessAllows participants on-premises and remote to access any given scenario and labs simultaneously
Blue and Red team scenariosAbility for blue and red cyber teams to simultaneously engage in scenarios
Present RepresentationsAbility to represent blue and red representations at various levels of fidelity from hardware-in-the-loop to network models of systems, to include representations of components and systems
Multi-Cloud SupportSupport for across multiple cloud providers (e.g., AWS, Azure, GCP) and hybrid environments.
User-Friendly InterfaceIntuitive dashboard and reporting features for ease of use and quick insights.
Generate multiple environmentsAbility to generate multiple environments to support different scenarios and different users
Mission designAbility for mission planners/white teams to design and execute missions with an intuitive graphical user interface, record/playback scenarios, and export time-sequenced scenario data for further analysis
Collaboration ToolsFeatures that enable teams to collaborate effectively on governance activities and incident management.
Replicate and employ threats at scale.Ability to replicate and employ threats at scale either pre-planned or in real-time
Support congruent operating modelsAbility to support congruent operating models supporting blue and red representations simultaneously for large-scale and team/mission-focused scenarios
Pre-packaged contentAbility to purchase or subscribe to pre-packaged content ready to be integrated into curriculum for key cybersecurity topics including, but not limited to, cryptography, network security, computer security, software security, offensive security, defensive security, digital forensics on network traffic and digital devices, and incident response.
Training eventsTraining events should support up to 25 students at the same time, with the ability to rotate to a different group of students each month
Security, Compliance, Architecture
CriterionDescriptionVendor ResponseComments
User access security managementSecurity is managed via integration with the corporate identity provider and automated as much as possible. Role based configuration is used for aggregation and anonymization.
Security levelThe administrative security is provided down to a table/field level.
User authenticationThe vendors product must support standards based modern authentication to the Judiciary's IDP.
Role-based securityRole-based access control (RBAC)for admins and end user roles is supported.
Data transmission and storageData is secured during transmission
Data encryptionEncryption is provided both in transit and at rest.
Password encryptionPasswords are encrypted. Please describe the password policy.
Password policyUser password change requirements are supported and are configurable by compensation administrators.
Ability to support Firefox 52.x or higherFirefox is supported.
Ability to support Chrome 63.x or higherChrome is supported.
Ability to support Microsoft Edge Version 108.0.1462.54 or higherMicrosoft Edge is supported.
Ability to support Safari 10.x or higherSafari is supported.
Cloud VPN SupportCloud VPN is supported. The current implemtation is through Zscaler.
Zero footprint (excluding browser plug in)No software or data requirements for client access beyond a browser.
Maintenance windowsA standard maintenance window and schedule are provided.
Data privacyData privacy is ensured. Provide documentation explaining how the vendor handles data.
Data rightsIn the event that the company decides to transition to a different solution, it is able to retrieve its data.
Data separationData is separated and secured from other tenants.
Data protectionData is protected from other users on the same (cloud) server (if shared).
Data accessAccess to the company's data is limited.
Incident proceduresThere are security and operational incident response procedures.
Incident notificationVendor will notify us of security incidents. Please describe the response time and notification procedure in the Comments section.
Incident reportsPost-incident/root cause analysis reports will be provided.
Incident SLAVendor provides an SLA on incident handling notifications.
Data destruction on terminationData will be destroyed if agreement is terminated.
Private and sensitive informationThe export of private and sensitive information is limited.
Information security policyVendor has an information security policy.
US GovernentVendor is FedRamp certified
Vendor assessmentsVendor assessments are performed by a third party.
Vendor assessment reportsReports produced as part of such assessments can be reviewed by our organization.
Security auditOur organization is able to periodically audit the vendor's security practices.
Audit results for the past two yearsVendor is willing to share the external audit results for the last two years.
Disaster recoveryThere is a separate disaster recovery site.
Backups and encryptionBackups are encrypted and routinely tested.
Hosting ServiceVendor uses tier 1 services such as AWS. List providers used for hosting infrastrucutre services, authentication, application monitoring and Content Delivery Network (CDN)
General Capabilities
CriterionDescriptionVendor ResponseComments
End user UI ease of navigationSupports ease of use features for both end users, content curators and administrators of the platform.
Ease of administration and structure, governanceInformation is structured and governed with in the platform.
User communityOnline community for support and ideas for all vendor customers.
User feedbackAbility for users to post feedback on materials. This can include ratings but is meant to determine more specific feedback via written form.
Change managementAdministrative training for management of solution including reporting and analysis is provided.
Customer supportSupport is provided 24/7 and is included in the subscription costs. A designated POC is provided.
Data storageUnlimited data storage is provided.
Scalable architectureThe proposed solution architecture scales (users,roles, business units, geographies, etc.).
Business continuityBusiness continuity plans and policies are provided.
Solution is low/no codeThe proposed Cyber Range is low/no code for content builders (back end resources)
Solution is role basedSolution provides diferent administrative and end user roles and there is no limit to the number of roles that can be configured. List role access.
Compliance for people with disabilitiesThe platform supports people with disabilities, confirming to acts like the Americans with Disabilitis act.
Integration and Platform Capabilities
CriterionDescriptionVendor ResponseComments
SSO/SAML integrationSupports SSO/SAML integration.
LDAP integrationSupports LDAP integration.
Integration to portalsSupports integration to portals
Integrations and APIsSupports open API integration to other systems. Please list any that are provided out of the box in the comments column
CI/CDIncorporate the judiciary continuous integration and continuous deployment (CI/CD) pipeline.
Implementation, Configuration, Kick-off support
CriterionDescriptionVendor ResponseComments
TrainingVendor provided training for Training Division staff.
Set-up, configuration, and deploymentVendor must include setup, configuration, and deployment support to assist with training and rapid deployment of the product during the base year only.

File details come from the government source that posted it. Updated .