RFI Response Form.docx

DOCX document 20 KB Posted

Attached to
Enterprise Data Loss Prevention (E-DLP) Federal contract opportunity
Solicitation number
FA877320R0003
Issued by
Department of the Air Force Space Command

About this file

This document contains a request for information response form and details of a related federal contract opportunity for an Enterprise Data Loss Prevention solution.

The request for information form seeks vendor responses on topics including recommended NAICS codes, past performance with cross domain solutions and cloud services, experience deploying at large scale for 800,000 endpoints and 1.2 million users, tiered console implementations, and capabilities for detecting low and slow data exfiltration, automated policy changes, user coaching, and risk dashboards. It also requests details on discovery capabilities for structured and unstructured content in on-premises and cloud repositories, endpoint detection methods and operating system support, email and web traffic monitoring integration, and network and storage data loss prevention.

The related federal contract opportunity is a pre-solicitation notice from the Department of the Air Force Space Command seeking a vendor to conduct a proof of concept for an Enterprise Data Loss Prevention program at a single Air Force base, including at least 100 users, multiple data owners, and capabilities to protect data at rest, in transit, and in use across endpoints, email, networks, clouds, and storage.

View the file

Other files for this federal contract opportunity

Other files attached to Enterprise Data Loss Prevention (E-DLP), newest first.
File Type Posted
E-DLP REQUEST FOR INFORMATION .pdf PDF
E-DLP Proof of Concept Objectives v6-3.pdf PDF

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

ATTACHMENT 1

RFI RESPONSE FORM

Company Name and Address:

Cage Code:

Socio-Economic Status:

Company Point of Contact:

Acquisition:

What NAICS code do you recommend for this requirement?

Do you currently operate under any GWAC, MAC, or SBIR contract? If so, what labor categories would you recommend?

What evaluation factors do you recommend for this requirement? Past Performance, Technical, etc.

What contract type do you recommend for this acquisition? FFP, CPFF, etc.

General:

The Air Force requires an E-DLP solution that employs a Cross Domain Solution (CDS) in order aggregate and correlate alerting across multiple networks/classifications (e.g., NIPR, SIPR, JWICS). Describe your past experience integrating your E-DLP solution in a CDS environment.

Which components of your E-DLP solution, if any, require the use of cloud-based services?

How would you plan to implement your E-DLP solution, at scale, for the Air Force which has over 800K endpoints, 1.2 million users, worldwide? Describe your deployment experience with Fortune 100 companies.

Does your solution support a tiered or multi-console implementation that allows policy grouping, role-based access based on the console instance, incident response coordination, event coordination, etc.?

Briefly describe specifically how your E-DLP solution can account for the difficult adversary scenario of “low and slow” data exfiltration.

Briefly describe how your E-DLP solution can make automated and/or recommended changes to security policies based on observed/learned behavior (e.g., Unsupervised Learning) or the ability to train the system on specific policy use cases (e.g., Supervised Learning).

Briefly describe how your E-DLP solution provides employees “real time coaching” for safe handling of sensitive information when a violation is committed.

Briefly describe how your E-DLP solution calculates and presents a “Risk Dashboard,” based on factors such as top threats rated by impact, riskiest users and entities, likelihood of threat impact, etc.

Discovery: Ability to discover data in structured, unstructured, or semi-structured content types, in on-premises and cloud-hosted repositories.

Do you offer your DLP discovery product as a:

· Hardware appliance

· Software or virtual appliance

· Software installation (agent-based installation)

Please list the Oss, file systems, databases, document management systems and other repositories you can scan.

Which document management systems can the discovery component monitor for policy violations?

Which database management systems can the discovery component monitor for policy violations?

Please provide the type of discovery scanning you support (e.g., full, differential, or partial repository sampling?)

What mechanisms do you support to regulate/minimize discovery workloads on the network and repository resources?

What is your recommended discovery scan policy for different repositories/use cases?

Detail discovery performance in MB/GB/TB scanned/hour (describe assumptions and architecture)

Describe your distributed DP scanning methodology: Can many DLP scanning agents load share the scanning and how?

Do you offer content discovery in for Office 365/Exchange Online/Teams cloud-hosted services?

Do you offer content discovery in the Microsoft OneDrive cloud-based storage environment and SaaS applications like ServiceNow?

How does your E-DLP solution address assessing encapsulated data (e.g., encoding via rar, zip, etc.)?

What methods of support do you provide customers for rule tuning and other employment considerations?

DLP for Endpoint: How do you detect, assess, and classify data in use and storage in an endpoint?

Do you use content-aware detection techniques?

Do you have native User/Entity Behavior Analytics? If so, describe your capabilities. If not, what third-party UEBA vendors can you integrate with?

What file types can you detect, assess and classify?

What file types can you deal with for internal content analysis? EDI file?

What operating systems?

What copy and paste controls exist?

How do you manage saving content to different locations (e.g., local folders, remote file shares, removable drives, cloud storage)?

List removable media and device types supported.

What capabilities does your DLP endpoint have to control applications?

How much of the DLP endpoint agent detection logic will work disconnected from the Internet or the DLP management system?

Briefly describe the content-aware capabilities of the endpoint agent when it is not connected to the server/network?

List the features of the endpoint agent that address performance impact and latency on the local system.

Briefly describe agent/server connectivity requirements (e.g., frequency, amount of data per day) and ability to connect via proxies.

Briefly describe options to deploy and update DLP endpoint agents, and monitor their health for all platforms supported.

Briefly describe how your DLP endpoint agents are self-protected against tampering for all platforms supported. How easily can your DLP endpoint be disabled by a user?

What is your web browser support and does it have any known limitations or incompatibilities with the DLP endpoint software?

How do you handle mobile devices? Which ones?

How do you handle printers?

Can you handle mobile devices, printers, and virtual machines as endpoints?

How do you handle email, removable devices, and browser use on the endpoint?

How do you define user roles within DLP policies?

What kind of reporting does your solution offer?

What actions are taken when sensitive data is found? Customizable, user driven?

DLP for Email:

Briefly describe any embedded/native mail transfer agent (MTA) functionality for DLP for email.

List third-party MTA/secure email gateway integration used in production deployments.

List any third-party email (or other) encryption integration used in production deployments Describe email quarantine capabilities

Briefly describe any native (non-third-party) email encryption support.

Does the product support internal (within the Air Force) email monitoring? For which email servers?

Does the product support email monitoring from within the email server itself? For which email servers?

Does the product support email monitoring for an email service that is hosted in the cloud, such as Office 365/Exchange Online, Gmail/Google Apps, etc?

Other than encryption, are there any factors (such as file attachments larger than 25mb) that limit your product’s ability to natively inspect email attachments?

DLP for Web Traffic:

Which web proxy vendors and products do you support?

Can you perform native Internet Content Adaptation Protocol (ICAP) integration with an existing web proxy?

Does your product support in-line use in the absence of a proxy?

If you can monitor additional ports/protocols besides HTTP/HTTPS via ICAP for content inspection, please describe how you do this (e.g., protocol analysis)

Does your product have a native capability to inspect encrypted traffic? If yes, briefly describe the capabilities, restrictions, and requirements.

Can your DLP product integrate with a product that can perform offloading of Secure Sockets Layer (SSL)/Transport Layer Security (TLS) traffic (such as Blue Coat Netronome, F5, A10, Gigamon, or Ixia)?

Does your product support a deployment in a hosted cloud environment such as Amazon Web Services or Microsoft Azure?

DLP for Network:

How do you detect, assess and classify data in motion, over a variety of network ports and protocols, on a network?

a. Email, webmail

b. HTTP/HTTPS

c. Instant Messaging

d. File Transfer

e. Social Media/Internet-based Capabilities

f. Full/partial decryption

Are you able to identify and parse protocols, regardless of the port they are running on (e.g., HTTP running on nonstandard ports other than 80, 8080, 443)?

Approach for N-S and E-W traffic

Are you able to identify and parse protocols, regardless of the port they are running on (e.g., HTTP running on nonstandard ports other than 80, 8080, 443)?

DLP for Storage:

How do you detect, assess and classify data at rest in storage, on premises and in cloud-hosted storage?

a. File servers

b. Databases

c. Share point

d. Network Attached Storage

e. Cloud apps

f. Microsoft’s cloud based email

File details come from the government source that posted it. Updated .