Amd_2_-_Q&A_2-3-17.pdf
PDF 41 KB Posted
- Attached to
- IT Security Services Federal contract opportunity
- Solicitation number
- RFP-ADF-OIT-17-0001
About this file
Amendment 2 - Q&A
View the file
Other files for this federal contract opportunity
| File | Type | Posted |
|---|---|---|
| Amd_3_-_QA.pdf | ||
| Volume_3_-_Technical_Approach_&_Proj_Pln_&_Sch_(Amd_2).doc | DOC document | |
| RFP-ADF-OIT-17-0001(Amd_2).pdf | ||
| Attch_A_(1-3)_-_Pricing_Sheet_(Amd_2).xlsx | XLSX spreadsheet | |
| Amd_1_-_Q&A.pdf | ||
| IPP_Waiver_Form.pdf | ||
| Volume_1_-_Contractual_Documents.docx | DOCX document | |
| Attch_B_-_Nondisclosure_Agreement.pdf | ||
| Volume_5_-_Past_Performance.docx | DOCX document | |
| Volume_3_-_Technical_Approach.doc | DOC document | |
| Volume_4_-_Quality_Control_Plan.doc | DOC document | |
| RFP-ADF-OIT-17-0001.pdf | ||
| Volume_2_-_Experience_&_Capabilities.docx | DOCX document | |
| Attch_A_(1-3)_-_Pricing_Sheet.xlsx | XLSX spreadsheet |
Show all 14
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
Amendment 2- Q&A Department of the Treasury, Bureau of Fiscal Service
Division of Procurement RFP-ADF-OIT-17-0001 – IT Security Services
Questions and Answers (Q&A)
1. What are the page limits for different sections? The Q&A did not provide clarification on the exact numbers for Technical Proposal that consists for 4 sub categories within it.
Answer: There is not a page limit for the technical or management response. Please refer to page 25 of the solicitation where it states “Offerors shall submit a complete proposal package in the following Volumes as separate attachments with as little duplication of information as possible.”
Please also see the answer to question 1 in Amd-1 Q&A.
2. Are any key personnel required? The solicitation says “TBD”, but the instructions require description of key personnel’s past experience. Please clarify.
Answer: Yes, key personnel needs to be specified in the proposal along with their qualifications and past experience. The section in the solicitation where it states “TBD” is where the Government will identify the successful awardee’s key personnel upon awarding of the contract.
3. Does the government have any Level of Effort (LOE) in mind for this contract? Basically, we want to know if the government has estimated the number of people that will be supporting this effort for Tasks 6.1, 6.2 and 6.3. now (RFP PWS Section 6.2, 6.3, and 6.4, inclusive of the new 6.1)
Answer: The Government anticipates that the majority of work, if not all of it, can be performed by one individual who has at least the minimum qualifications stated in PWS Section 7.0 on a less than full-time continuous basis for each period executed under the contract.
4. Continuous Monitoring Plan The following are mechanisms that are to be monitored or assured implemented by the contractor to address security impacts.
Does USADF have the following tools ?
o Event Management tool – SIEM Yes, but DHS is about to upgrade and replace as part of the CDM initiative o Intrusion Prevention tool Yes, but DHS is about to upgrade as part of the CDM initiative o End Point Security tools – Anti Virus Yes, McAfee EPO o Patch Management tool Yes, Heat EMS o Vulnerability Scan tool Yes, Nessus
If the tools are not available does the Contractor needs to procure them?
Answer: All tools are available, if any isn’t; the agency is going to get them as part of DHS CDM program
5. Total # of users at this location are 50 – Is that correct?
Answer: Yes, below 50
6. What Infrastructure does USADF have now?
Answer: Key applications are Cloud-based. Microsoft Office 365 cloud and the database is also subscription cloud-based residing in AWS.
7. How many Laptops / Desktops do they have?
Answer: Mostly laptops about 42 and 1 desktop
8. Do they need support international as there are 70 contractors in various parts of the world?
Answer: There are 35 personal service contractors overseas. Other than the annual security awareness training, there is no other requirement.
9. Is USADF looking for 24 x 7 – Security Monitoring as part of Continuous monitoring Task?
Answer: No.
10. Is multi-factor authentication currently implemented?
Answer: Office 365 does offer MFA. Looking to implement it at HQ with PIV (logical access)
11. Does USADF inherit any security controls?
Answer: FedRamp ATOs from Microsoft Office 365 cloud and AWS
12. What is the current USADF security toolset?
Answer: Need clarity here.
13. Is the cloud-based Grant Management Systems FedRamp authorized?
Answer: Yes
14. In reference to the three past performance customers required and if the prime has a major portion of this work being performed on one contract. Can the performance be a combination of the Prime and subcontractor?
Answer: Yes, please be sure to describe your company’s roles in the work.
15. What are the different operation systems, network devices, appliances, systems, etc. that are in scope?
What is the approximate number of devices and servers?
Answer: All Microsoft Environment. USADF uses also government approved shared services at DOI and Treasury in addition to cloud services. Very little is done here at HQ.
16. Does USADF have security policies, baseline configurations, etc. in place?
Answer: Yes.
17. Does USADF have continuous monitoring tools in place for incorrect configurations, missing patches, vulnerabilities, etc.?
Answer: Nessus and HEAT EMS
18. Has a contractor performed similar work to this for the government in the past? If available, please provide the incumbent contract number. If you are unable to provide a contract number, is it safe to assume this is a new requirement for the government?
Answer: This is a new requirement.
19. According to section 6.1.6 Deliverables now (RFP PWS Section 6.2.6); the contractor shall produce a security risk assessment for the General Support System and the Grant Management Database System.
Are you able to say if these are the only two systems for which the contractor will be responsible? If not, can you provide the number of systems?
Answer: These are the only 2 systems that the contractor will be assessing. Be mindful that GSS constitute Local Area networking devices (firewall, switches, about 50 laptops, 2 AD and a few security functional servers) and Office 365 government cloud.
20. What kind of contract vehicle is required to win the work?
Answer: Per PWS Section 5.0, the Government intends on awarding a firm-fixed price contract.
Please also see the note in the Instruction to Offerors Section C(1) Price Proposal.
21. How many platforms & network environments (including databases & systems) are in scope for this project?
Answer: Grant Management database is a cloud-based internet accessible subscription application on Amazon Web Services government cloud and the other is all Microsoft, and network is Cisco platform.
22. In order to assist with the level of effort analysis, would the government provide the number of USADF systems to be certified and for each of the systems: the size of each system, the volume of activity and the number of end users.
Answer: 1 GSS & 1 PSS. All are FedRamp ATO approved so that lessens the number of security controls to be assessed
23. Respectfully request a 10 day extension to the due date.
Answer: The due date has been extended to 10:00 am on February 13, 2017.
24. Respecting the effort placed on creating templates for each submission volume, to aide in the states evaluation of responses, may the vendor modify any of the templates as follows:
a) include the addition of a cover page,
b) include the addition of tables of contents and tables of exhibits
c) customization of header or footer sections
d) modification of font type, size, color?
Answer: Yes.
25. In all of the Volume Templates there is an area in the header Offeror: ?????. What information should be entered into Offeror: ?????? area of each of the volume response templates?
Answer: Offeror: Please insert your “Company’s Name” in place of the ???.
26. Would the government accept an IRS Entity Identification Number (EIN) number or CAGE code as a valid response to Question 3?
Answer: No. Typically, the vendor’s Unique Entity Identifier Number is a D&B D-U-N-S number.
27. If the offeror provides a Unique Entity Identification Number in response to question 3, does the offeror need to answer sub questions 3a through 3j in their response?
Answer: No. 3a-3j is being provided to assist offerors in preparing for their correspondence with another entity in obtaining their Unique Entity Identifier Number.
28. Where is the cloud service located? (PWS 7.2, letter F)
Answer: Public Cloud. Microsoft Office Multi-tenant Government cloud and AWS Government Cloud
29. Who is the cloud service provider?
Answer: Please see response to question number 28.
30. Is the cloud service FedRAMP approved/compliant? (PWS 6.1.2, letter E) now (RFP PWS Section 6.2.2, letter E)
Answer: Yes
31. How big is the GSS? Is the GSS international? (PWS 6.2.) now (RFP PWS Section 6.3)
Answer: GSS consist of a Local Area Network in D.C. No the GSS isn’t international.
32. Can you affirm the following date of 15 April 2017 from Deliverable PWS (6.3.4, letter D) now (RFP PWS Section 6.4.4, Letter D).
a. Revise and Update the following security packages for both the program and general support systems to reflect USADF current operating environment, FISMA and NIST control requirements. These reports shall be delivered to the CISO by April 15th, 2017.
Answer: The date of April 15th still stands.
33. What is the number of information systems within scope that require Authority To Operate? (PWS 6.3.4, letter F) now (RFP PWS Section 6.4.4, letter F)
Answer: The GSS is the local area network. Agency uses shared and cloud services
34. Are we required to adhere to the font given in the templates, which is Arial 9.5?
Answer: No.
35. How many key personnel is the Agency expecting for this solicitation?
Answer: Please see the answer to question 3 above.
36. The PWS states “the program and general support systems” in several places. Please specify how many systems there are in total which need the Security Engineering Services.
Answer: There is one Database which is also cloud-based that constitute PSS. The GSS is the local area network. We use Microsoft Office 365 cloud which is FedRamp approved ATO.
37. Please specify the approx. quantity of Security Assessments which need to be performed yearly.
Answer: Updates to existing security assessments or maintenance of CMP. USADF doesn’t anticipate adding any new system in a few years but there might be upgrades to its network infrastructure.
38. Is our understanding correct the Agency needs two A&A’s (Accreditation and Authorization)? One for the GSS and one for the Grant Management Database System? Or are there sub systems which need a separate A&A?
Answer: No
39. Would the government consider extending the due date for the response to be 1 week after questions are answered/posted?
Answer: Please see answer to question number 23.
40. How many FTEs are currently required to cover the defined requirements? What are the position titles and/or labor categories involved?
Answer: Please see the answers to question 3 and 8 above. The Government is anticipating an IT Security Analyst who has at least the minimum qualifications stated in PWS Section 7.0.
41. How many GSS systems are in scope? (RFP 6.1.6), now (RFP PWS Section 6.2.6)
Answer: 1
42. In addition to the Grant Management Database System, how many major applications are in scope?
(RFP 6.1.6) now (RFP PWS Section 6.2.6)
Answer: None. USADF has outsourced other to Shared Service providers
43. What are the impact levels/security categories for the in scope systems (e.g. low, moderate, high)?
(RFP 6.1.6) now (RFP PWS Section 6.2.6)
Answer: For now, it’s rate Low.
44. What are the key technologies for the in scope systems (data bases, application languages/platforms, operating systems, etc.)? (RFP 6.1.6) now (RFP PWS Section 6.2.6)
Answer: Windows 7, 10, Windows 2008 and r12. Database is a subscription cloud-based, hosted on AWS by the application vendor.
45. What scanning/monitoring tools are currently being used? (RFP 6.2) now (RFP PWS Section 6.3)
Answer: Heat EMS, Nessus scanner
46. What are the minimum number of resumes/key personnel required to be included in the proposal? (RFP 8.0)
Answer: Please see the answer to question 3 above.
47. Will contractor personnel have lead/supervisory responsibilities or is this primarily a staff augmentation effort that will be supervised by government personnel? (RFP 8.0)
Answer: The Contractor will be responsible for ensuring their assigned key personnel complete the tasks and corresponding deliverables within the time frames agreed upon. The Government will only be providing technical directions in accordance with DTAP 1052.201-70 Contracting Officer’s Representative (Cor) Appointment and Authority found on pages 4-5 of the RFP.
48. Are we correct to assume that our proposal response shall be formatted exactly as defined by the 6 volume templates? Are there page limitations on any of the volumes?
Answer: Please see answer to questions 1 and 34.
49. Please describe the key application interfaces of the Grant Management System.
Answer: GMS is web interface. USADF is only allowed Access controls (Administrative management of users) Any updates and changes goes through the software vendor.
50. What associated systems are managed by third party service providers? Who are the third party service providers, if any?
Answer: None
51. What is the structure of the office that currently supports USADF IT?
Answer: Small IT shop.
52. What platforms are in scope (e.g. databases, operating systems, middleware)? (RFP 6.1) now (RFP PWS Section 6.2)
Answer: Microsoft and Cisco shop.
53. What configuration management tools are available? (RFP 6.1) now (RFP PWS Section 6.2)
Answer: None
54. What tool(s) support the 14 processes of the continuous monitoring plan? (RFP 6.2) now (RFP PWS Section 6.3)
Answer: Event Log Analyzer, McAfee EPO, McAfee IPS, Heat EMS AND Nessus scanner
55. What security policies, guidelines, and procedures are available? (RFP 6.3) now (RFP PWS Section 6.4)
Answer: Please see answer to question number 3.
56. What types of risk/security assessments are currently performed (RFP 6.3) now (RFP PWS Section 6.4)
Answer: RAR, SSP, SCA, SAP
Please also see the amendment to the RFP to add PWS Section 6.1 for a Bi-Weekly Meeting and Project Plan & Schedule, as well as the corresponding parts in the Instructions to Offerors and Evaluation Criteria.
File details come from the government source that posted it. Updated .