RFP 70RTAC22R00000010 J.3 - Cert of IDIQ VDDP Platform Compliance.pdf

PDF 71 KB Posted

Attached to
Solicitation for Hack DHS: Crowdsourced Vulnerability Assessment Services (CVAS) Federal contract opportunity
Solicitation number
70RTAC22R00000010
Issued by
Department of Homeland Security Office of Procurement Operations

About this file

This document is a request for proposal for crowdsourced vulnerability assessment services issued by the Department of Homeland Security. The solicitation seeks proposals to own and operate a vulnerability discovery and disclosure platform that can securely accept and triage vulnerability reports from approved researchers, ensure reports are clear and of high quality, implement continuous monitoring and auditing of researchers, facilitate communication among researchers and government remediators, manage researcher accounts, display relevant metrics on assessments, and apply tools to triage reports. Offerors must certify that their platform meets these minimum requirements to be considered technically acceptable. The attached pricing template requires proposed fixed prices for assessment services over the potential five-year ordering period. Proposals are due by the specified date, and the department intends to award an indefinite-delivery/indefinite-quantity contract for crowdsourced vulnerability testing of its internet-facing systems and websites.

View the file

Other files for this federal contract opportunity

Show all 12

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

Request for Proposal 70RTAC22R00000010

Attachment J.3

Offeror Certification of

IDIQ Vulnerability Discovery and Disclosure Platform Compliance vulnerabiliIDIQ Vulnerability Discovery and Disclosure Platform Compliance

This checklist will be used for Phase 1 of the evaluation process described in the RFP, Section M. EVALUATION, subsection M.1. The Offeror shall complete this checklist and have certified it with the corporate signatory authority.

If responses are not noted on this checklist, it will be assumed that the Offeror’s proposal provides no response for this requirement. Absence of meeting the criteria for IDIQ Vulnerability Discovery and Disclosure Platform Compliance will be considered as a failure to meet that requirement and the Offeror’s proposal will be deemed non-responsive and removed from further consideration for award.

Instructions: The requirements are listed in the left-hand column. Please identify any requirements from items a) through h) your firm can meet by marking Yes or No. Failure to comply with ANY of the minimum IDIQ Vulnerability Discovery and Disclosure Platform Compliance requirements listed below will result in a technically unacceptable submission and rejection of the proposal. Thus, no further evaluation of the Offeror’s submission will be conducted.

Offeror Name:_____________________

Minimum Requirements for IDIQ Vulnerability Discovery and Disclosure Platform Compliance

Offeror shall mark

Yes or

No

a) The Offeror owns and operates the platform that will be used to meet the following minimum requirements (b through h):

b) The Offeror has an existing capability to securely accept and display vulnerability reports from researchers.

c) The Offeror has existing capability to ensure that vulnerability reports, transmitted to Government remediators, are clear and of high quality. This will ensure that Government personnel can immediately remediate identified vulnerabilities.

d) The Offeror has an existing capability to implement continuous monitoring as well as auditing tools, to monitor and assess, researcher behavior.

e) The Offeror has an existing capability to facilitate effective communication between the triage team and researchers and between the triage team and Government remediators. This may include corresponding, separately, with multiple teams.

f) The Offeror has an existing capability to actively manage researchers on the assessment, for example, the ability to immediately remove or disable a researcher’s account.

g) The Offeror has an existing capability to display relevant metrics on the ongoing state of the assessment, including but not limited to, the total number of vulnerability reports, broken down by criticality, process stage, etc.

h) The Offeror has an existing capability to apply tools and processes, automated as well as manual, to triage reports for the Government. This includes de-duplication of reports.

Request for Proposal 70RTAC22R00000010

Attachment J.3

Offeror Certification of

IDIQ Vulnerability Discovery and Disclosure Platform Compliance

In response to RFP Section L, I hereby certify that the information entered in the checklist above is current and accurate.

Signature: __________________________ Date: ____________

Print Full Name: _________________________________

Position Title: ___________________________________

Offeror Name:
Offeror shall mark Yes or Noa The Offeror owns and operates the platform that will be used to meet the following minimum requirements b through h:
Offeror shall mark Yes or Nob The Offeror has an existing capability to securely accept and display vulnerability reports from researchers:
Offeror shall mark Yes or Noc The Offeror has existing capability to ensure that vulnerability reports transmitted to Government remediators are clear and of high quality This will ensure that Government personnel can immediately remediate identified vulnerabilities:
Offeror shall mark Yes or Nod The Offeror has an existing capability to implement continuous monitoring as well as auditing tools to monitor and assess researcher behavior:
Offeror shall mark Yes or Noe The Offeror has an existing capability to facilitate effective communication between the triage team and researchers and between the triage team and Government remediators This may include corresponding separately with multiple teams:
Offeror shall mark Yes or Nof The Offeror has an existing capability to actively manage researchers on the assessment for example the ability to immediately remove or disable a researchers account:
Offeror shall mark Yes or Nog The Offeror has an existing capability to display relevant metrics on the ongoing state of the assessment including but not limited to the total number of vulnerability reports broken down by criticality process stage etc:
Offeror shall mark Yes or Noh The Offeror has an existing capability to apply tools and processes automated as well as manual to triage reports for the Government This includes deduplication of reports:
Date:
Print Full Name:
Position Title:

File details come from the government source that posted it. Updated .