Amendment 008 RFP.pdf
PDF 4 MB Posted
- Attached to
- NIST Computer and Information Security Services IDIQ Federal contract opportunity
- Solicitation number
- SB1341-12-RP-0019
View the file
Other files for this federal contract opportunity
| File | Type | Posted |
|---|---|---|
| Amendment 008 vuln-model-web-service.zip | ZIP file | |
| Amendment 008 Questions Responses.pdf | ||
| Amendment 007 Questions Responses.pdf | ||
| Amendment 006 RFP.pdf | ||
| Amendment 006 Questions Responses.pdf | ||
| Amendment 005 Questions Responses.pdf | ||
| Amendment 004 Questions Responses.pdf | ||
| Past Performance Information Questionnaire- Final.doc | DOC document | |
| Pre-proposal Conference Registrants.xls | XLS spreadsheet | |
| RFP SB1341-12-RP-0019.pdf |
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
SOLICITATION, OFFER AND AWARD 1. THIS CONTRACT IS A RATED
ORDER UNDER DPAS (15 CFR 700)
RATING
PAGE OF
PAGES
2. CONTRACT NUMBER 3. SOLICITATION NUMBER 4. TYPE OF SOLICITATION 5. DATE ISSUED 6. REQUISITION/PURCHASE NUMBER
SB1341-12-RP-0019 SEALED BID (IFB)
NEGOTIATED (RFP)
NB773000-12-00235
NB773000-12-00235
7. ISSUED BY CODE 000SB 8. ADDRESS OFFER TO (If other than Item 7)
NATIONAL INST OF STDS AND TECHNOLOGY
100 BUREAU DRIVE STOP 1640
BUILDING 301 ROOM B129
GAITHERSBURG MD 20899-1640
NATIONAL INST OF STDS AND TECHNOLOGY
100 BUREAU DRIVE STOP 1640
BUILDING 301 ROOM B129
GAITHERSBURG MD USA
NOTE: In sealed bid solicitations "offer" and "offeror" mean "bid" and "bidder".
SOLICITATION
9. Sealed offers in original and 4 copies for furnishing the supplies or services in the Schedule will be received at the place specified in Item 8, or if handcarried, in the depository located in NIST Building 301 Room B164 100 Bureau Drive Stop 1640 Gaithersburg, MD 20899-1640 until 12:00
PM ET
local time JUN 11, (Hour) (Date)
CAUTION - LATE Submissions, Modifications, and Withdrawls: See Section L, Provision No. 52.214-7 or 52.215-1. All offers are subject to all terms and conditions contained in this solicitation.
10. FOR
INFORMATION CALL
A. NAME
KEITH BUBAR
B. TELEPHONE (NO COLLECT CALLS)
301-975-8329
C. E-MAIL ADDRESS
KBUBAR@MAIL.NIST.GOV
11. TABLE OF CONTENTS
(X) SEC. DESCRIPTION PAGES(S) (X) SEC. DESCRIPTION PAGE(S)
PART 1 - THE SCHEDULE PART II - CONTRACT CLAUSES
X A SOLICITATION/CONTRACT FORM 1 - 1 X I CONTRACT CLAUSES 55 - 75
X B SUPPLIES OR SERVICES AND PRICES/COSTS 2 - 26 PART III - LIST OF DOCUMENTS, EXHIBITS AND OTHER ATTACH.
X C DESCRIPTION/SPECS./WORK STATEMENT 27 - 33 X J LIST OF ATTACHMENTS 76 - 102
D PACKAGING AND MARKING - PART IV - PRESENTATIONS AND INSTRUCTIONS
X E INSPECTION AND ACCEPTANCE 34 - 34 X K REPRESENTATIONS, CERTIFICATIONS AND OTHER 103 - 113
X F DELIVERIES OR PERFORMANCE 35 - 35 STATEMENTS OF OFFERORS
X G CONTRACT ADMINISTRATION DATA 36 - 41 X L INSTRS., CONDS., AND NOTICES TO OFFERORS 114 - 123
X H SPECIAL CONTRACT REQUIREMENTS 42 - 54 X M EVALUATION FACTORS FOR AWARD 124 - 128
OFFER
NOTE: Item 12 does not apply if the solicitation includes the provisions at 52.214-16, Minimum Bid Acceptance Period.
12. In compliance with the above, the undersigned agrees, if this offer is accepted within calendar days (60 calendar days unless a different period is inserted by the offeror) from the date for receipt of offers specified above, to furnish any or all itmes upon which prices are offered at the price set opposite each item, delivered at the designated point(s), within the time specified in the schedule.
13. DISCOUNT FOR PROMPT PAYMENT
(See Section I, Clause No. 52.232-8)
10 CALENDAR DAYS (%) 20 CALENDAR DAYS (%) 30 CALENDAR DAYS (%) CALENDAR DAYS (%)
14. ACKNOWLEDGMENT OF AMENDMENTS AMENDMENT NO. DATE AMENDMENT NO. DATE
(The offeror acknowledges receipt of amendments to the SOLICITATION for offerors and related documents numbered and dated):
CODE FACILITY 16. NAME AND TITLE OF PERSON AUTHORIZED TO SIGN OFFER
15A. NAME AND
ADDRESS OF
OFFEROR
DUNS: (Type or print)
15B. TELEPHONE NUMBER
15C. CHECK IF REMITTANCE ADDRESS IS DIFFERENT FROM
ABOVE - ENTER SUCH ADDRESS IN SCHEDULE.
17. SIGNATURE 18. OFFER DATE
AWARD (To be completed by Government)
19. ACCEPTED AS TO ITEMS NUMBERED 20. AMOUNT 21. ACCOUNTING AND APPROPRIATION
See Schedule
22. AUTHORITY FOR USING OTHER THAN FULL AND OPEN COMPETITION:
10 U.S.C 23004(c) ( ) 41 U.S.C 253(c) ( )
23. SUBMIT INVOICES TO ADDRESS SHOWN IN
(4 copies unless otherwise specified)
ITEM
24. ADMINISTERED BY CODE 25. PAYMENT WILL BE MADE BY CODE
26. NAME OF CONTRACTING OFFICER(Type or print) 27. UNITED STATES OF AMERICA 28. AWARD DATE
(Signature of Contracting Officer)
IMPORTANT - Award will be made on this Form, or on Standard Form 26, or by other authorized official written notice. (Must be fully completed by offeror)
AUTHORIZED FOR LOCAL REPRODUCTION
Previous edition is unusable
STANDARD FORM 33 (REV. 9-97)
Prescribed by GSA - FAR (48 CFR) 53.214(c)
SCHEDULE Continued
ITEM NO. SUPPLIES/SERVICES QUANTITY UNIT UNIT PRICE AMOUNT
0001 Base Period
Contractor performance of requirements as specified in the Performance Work Statement in Section C.
PR NUMBER: NB773000-12-00235
1.00 LO
0002 Option Period 1
Contractor performance of requirements as specified in the Performance Work Statement in Section C.
0003 Option Period 2
0004 Option Period 3
0005 Option Period 4
Table of Contents
SECTION B SUPPLIES OR SERVICES AND PRICES/COSTS
B. 1 SCHEDULE OF LABOR CATEGORIES
B. 2 SCHEDULE OF LABOR RATES
B. 3 MINIMUM AND MAXIMUM CONTRACT AMOUNTS
SECTION C DESCRIPTION/SPECIFICATIONS/WORK STATEMENT
C. 1 IDIQ PERFORMANCE WORK STATEMENT
SECTION E INSPECTION AND ACCEPTANCE
E. 1 52.246-4 INSPECTION OF SERVICES--FIXED-PRICE (AUG 1996)
E. 2 52.246-6 INSPECTION--TIME-AND-MATERIAL AND LABOR-HOUR (MAR 2001)
SECTION F DELIVERIES OR PERFORMANCE
F. 1 52.242-17 GOVERNMENT DELAY OF WORK (APR 1984)
F. 2 1352.270-70 PERIOD OF PERFORMANCE (APR 2010)
F. 3 52.242-15 STOP-WORK ORDER (AUG 1989)
SECTION G CONTRACT ADMINISTRATION DATA
G. 1 1352.245-70 GOVERNMENT FURNISHED PROPERTY (APR 2010)
G. 2 IDIQ CONTRACT INFORMATION
G. 3 NIST FAC P/PM
G. 4 1352.201-70 CONTRACTING OFFICER?s AUTHORITY (APR 2010)
G. 5 1352.201-72 CONTRACTING OFFICER?s REPRESENTATIVE (C0R) (APR 2010)
G. 6 1352.216-76 PLACEMENT OF ORDERS (APR 2010)
SECTION H SPECIAL CONTRACT REQUIREMENTS
H. 1 SECURITY REQUIREMENTS FOR IT LOW RISK
H. 2 1352.239-72 SECURITY REQUIREMENTS FOR INFORMATION TECHNOLOGY RESOURCES (APR 2010)
H. 3 1352.209-72 RESTRICTIONS AGAINST DISCLOSURE (APR 2010)
H. 4 KEY PERSONNEL
H. 5 NIST LOCAL-40 BILLING INSTRUCTIONS FOR DELIVERY/TASK ORDERS
H. 6 NIST LOCAL-36 TRAVEL NOTE
H. 7 NIST LOCAL-07 COMPUTER SECURITY POLICY
H. 8 1352.231-71 DUPLICATION OF EFFORT (APR 2010)
H. 9 1352.228-72 DEDUCTIBLES UNDER REQUIRED INSURANCE COVERAGE- FIXED PRICE (APR 2010)
H. 10 1352.209-74 ORGANIZATIONAL CONFLICT OF INTEREST (APR 2010)
H. 11 1352.209-73 COMPLIANCE WITH THE LAWS (APR 2010)
H. 12 1352.208-70 RESTRICTIONS ON PRINTING AND DUPLICATING (APR 2010)
H. 13 CONVERSION OF CONTRACT TYPE
H. 14 1352.228-70 INSURANCE COVERAGE (APR 2010)
H. 15 1352.237-70 SECURITY PROCESSING REQUIREMENTS - HIGH OR MODERATE RISK CONTRACTS (APR
2010)
H. 16 1352.239-71 ELECTRONIC AND INFORMATION TECHNOLOGY (APR 2010)
H. 17 1352.216-74 TASK ORDERS (APR 2010)
SECTION I CONTRACT CLAUSES
I. 1 LIMITATIONS ON COST FOR LABOR HOUR TASK ORDERS
I. 2 52.252-2 CLAUSES INCORPORATED BY REFERENCE (FEB 1998)
I. 3 52.245-1 GOVERNMENT PROPERTY (AUG 2010)
I. 4 52.237-3 CONTINUITY OF SERVICES (JAN 1991)
I. 5 52.232-20 LIMITATION OF COST (APR 1984)
I. 6 52.232-18 AVAILABILITY OF FUNDS (APR 1984)
I. 7 52.232-7 PAYMENTS UNDER TIME-AND-MATERIALS AND LABOR-HOUR CONTRACTS (FEB 2007)
I. 8 52.227-17 RIGHTS IN DATA--SPECIAL WORKS (DEC 2007)
I. 9 52.217-9 OPTION TO EXTEND THE TERM OF THE CONTRACT (MAR 2000)
I. 10 52.217-8 OPTION TO EXTEND SERVICES (NOV 1999)
I. 11 52.216-22 INDEFINITE QUANTITY (OCT 1995)
I. 12 52.216-19 ORDER LIMITATIONS (OCT 1995)
I. 13 52.216-18 ORDERING (OCT 1995)
I. 14 52.212-5 CONTRACT TERMS AND CONDITIONS REQUIRED TO IMPLEMENT STATUTES OR EXECUTIVE ORDERS--
COMMERCIAL ITEMS (MAR 2012)
I. 15 52.253-1 COMPUTER GENERATED FORMS (JAN 1991)
I. 16 52.245-9 USE AND CHARGES (AUG 2010)
I. 17 52.244-5 COMPETITION IN SUBCONTRACTING (DEC 1996)
I. 18 52.244-2 SUBCONTRACTS (OCT 2010)
I. 19 52.242-13 BANKRUPTCY (JUL 1995)
I. 20 52.237-2 PROTECTION OF GOVERNMENT BUILDINGS, EQUIPMENT, AND VEGETATION (APR 1984)
I. 21 52.233-4 APPLICABLE LAW FOR BREACH OF CONTRACT CLAIM (OCT 2004)
I. 22 52.233-3 PROTEST AFTER AWARD (AUG 1996)
I. 23 52.233-1 DISPUTES (JUL 2002)
I. 24 52.232-17 INTEREST (OCT 2010)
I. 25 52.232-11 EXTRAS (APR 1984)
I. 26 52.232-8 DISCOUNTS FOR PROMPT PAYMENT (FEB 2002)
I. 27 52.232-1 PAYMENTS (APR 1984)
I. 28 52.229-3 FEDERAL, STATE, AND LOCAL TAXES (APR 2003)
I. 29 52.228-5 INSURANCE--WORK ON A GOVERNMENT INSTALLATION (JAN 1997)
I. 30 52.227-1 AUTHORIZATION AND CONSENT (DEC 2007)
I. 31 52.224-2 PRIVACY ACT (APR 1984)
I. 32 52.224-1 PRIVACY ACT NOTIFICATION (APR 1984)
I. 33 52.223-6 DRUG-FREE WORKPLACE (MAY 2001)
I. 34 52.223-5 POLLUTION PREVENTION AND RIGHT-TO-KNOW INFORMATION (MAY 2011)
I. 35 52.222-22 PREVIOUS CONTRACTS AND COMPLIANCE REPORTS (FEB 1999)
I. 36 52.215-2 AUDIT AND RECORDS--NEGOTIATION (OCT 2010)
I. 37 52.212-4 I CONTRACT TERMS AND CONDITIONS--COMMERCIAL ITEMS (FEB 2012)--ALTERNATE I (OCT
2008)
I. 38 52.212-4 CONTRACT TERMS AND CONDITIONS--COMMERCIAL ITEMS (FEB 2012)
I. 39 52.209-7 INFORMATION REGARDING RESPONSIBILITY MATTERS (FEB 2012)
I. 40 52.209-6 PROTECTING THE GOVERNMENT`s INTEREST WHEN SUBCONTRACTING WITH CONTRACTORS
DEBARRED, SUSPENDED, OR PROPOSED FOR DEBARMENT (DEC 2010)
I. 41 52.204-10 REPORTING EXECUTIVE COMPENSATION AND FIRST-TIER SUBCONTRACT AWARDS (FEB 2012).. 74
I. 42 52.204-9 PERSONAL IDENTITY VERIFICATION OF CONTRACTOR PERSONNEL (JAN 2011)
I. 43 52.204-4 PRINTED OR COPIED DOUBLE-SIDED ON POSTCONSUMER FIBER CONTENT PAPER (MAY 2011)... 74
I. 44 52.203-12 LIMITATION ON PAYMENTS TO INFLUENCE CERTAIN FEDERAL TRANSACTIONS (OCT 2010)
I. 45 52.203-10 PRICE OR FEE ADJUSTMENT FOR ILLEGAL OR IMPROPER ACTIVITY (JAN 1997)
I. 46 52.203-8 CANCELLATION, RESCISSION, AND RECOVERY OF FUNDS FOR ILLEGAL OR IMPROPER ACTIVITY
(JAN 1997)
I. 47 52.203-7 ANTI-KICKBACK PROCEDURES (OCT 2010)
I. 48 52.203-6 I RESTRICTIONS ON SUBCONTRACTOR SALES TO THE GOVERNMENT (SEP 2006)-- ALTERNATE
I (OCT 1995)
I. 49 52.203-5 COVENANT AGAINST CONTINGENT FEES (APR 1984)
I. 50 52.203-3 GRATUITIES (APR 1984)
I. 51 52.202-1 DEFINITIONS (JAN 2012)
SECTION J LIST OF ATTACHMENTS
J. 1 PAST PERFORMANCE QUESTIONNAIRE
J. 2 FORMAT FOR SUBMITTING QUESTIONS
J. 3 TASK ORDER 1 PWS
SECTION K REPRESENTATIONS, CERTIFICATIONS AND OTHER STATEMENTS OF OFFERORS
K. 1 52.219-1 SMALL BUSINESS PROGRAM REPRESENTATIONS (APR 2011)
K. 2 52.204-8 ANNUAL REPRESENTATIONS AND CERTIFICATIONS (MAR 2012)
K. 3 52.212-3 OFFEROR REPRESENTATIONS AND CERTIFICATIONS--COMMERCIAL ITEMS (FEB 2012)
SECTION L INSTRUCTIONS, CONDITIONS, AND NOTICES TO OFFERORS
L. 1 52.233-2 SERVICE OF PROTEST (SEP 2006)
L. 2 1352.233-70 AGENCY PROTESTS (APR 2010)
L. 3 PROPOSAL PREPARATION/SUBMISSION INSTRUCTIONS
L. 4 INQUIRIES
L. 5 52.252-1 SOLICITATION PROVISIONS INCORPORATED BY REFERENCE (FEB 1998)
L. 6 52.212-1 INSTRUCTIONS TO OFFERORS--COMMERCIAL ITEMS (FEB 2012)
L. 7 52.216-27 SINGLE OR MULTIPLE AWARDS (OCT 1995)
L. 8 52.216-1 TYPE OF CONTRACT (APR 1984)
SECTION M EVALUATION FACTORS FOR AWARD
M. 1 EVALUATION FACTORS FOR AWARD
M. 2 52.217-5 EVALUATION OF OPTIONS (JUL 1990)
SECTION B
SUPPLIES OR SERVICES AND PRICES/COSTS
B. 1 SCHEDULE OF LABOR CATEGORIES
SCHEDULE OF LABOR CATEGORIES
The following section details the labor categories that will be applied to this IDIQ contract. The labor categories described here are required for this contract. Each labor category has a description of the type of work to be performed under each, the minimum experience requirements, and minimum education requirements. The description of the work to be performed under each labor category is a generalized description and may be expanded upon under individual task orders, where the work will be better defined.
Program Manager (Contract Level)
Minimum/General Experience:
This position requires a minimum of 10 years general project management experience and 5 years IT experience in computer security. Experience includes increasing responsibilities in information systems design and management.
Functional Responsibilities: Duties may include but are not limited to: Serves as the program manager for the IDIQ contract as a whole. Serves as program manager for a large, complex task order (or a group of task orders affecting the same common/standard/migration system) and shall assist the
Government Program Manager in developing/presenting project materials by and between the Contracting Officer (CO), the
Federal Acquisitions Contract – Project/Program Manager (FAC-
P/PM), the contract-level Contracting Officer’s Representative
(COR), the task order-level COR(s), ordering activities of the management personnel and customer agency representatives. The
Program Manager is responsible for the overall management of all task order(s) and ensuring that the technical solutions and schedules of the task orders are implemented in a timely manner.
Performs enterprise wide horizontal integration planning and interfaces to other functional systems. The Program Manager may also supervise Project Managers at the task order level.
Minimum Education: Must either be certified as a.) Project
Management Professional (PMP) by the Project Management
Institute (PMI) or other such credentialing organization, or b.)
Have been or currently are certified as a FAC- Program/Project
Manager (P/PM) (any level) or c.) Must demonstrate the ability to fully use Microsoft Project to demonstrate project performance.
Education and experience requirements may be substituted with:
1. A Bachelors degree in computer science/engineering technology, software/programming, social sciences, mathematics or business/finance can be substituted for 2 years general project management experience and 2 years IT experience.
2.) Ph. D. or Master’s Degree (in subjects described above) can be substituted for 1 additional year general project management and 1 additional year IT experience managing IT projects.
3. No degree and 12 years experience of project management with
8 years specialized in IT projects.
Project Manager (Task Order Level)
Minimum/General Experience:
This position requires a minimum of 6 years general project management experience and 3 years IT experience in computer security. Experience includes increasing responsibilities in information systems design and management.
limited to: Serves as project manager for a large, complex task order and shall assist the Program Manager in working with the ordering activity Contracting Officer (CO), the Federal
Acquisitions Contract – Project/Program Manager (FAC-P/PM), the contract-level Contracting Officer’s Representative (COR), and the task order-level COR(s), ordering activity management personnel and customer agency representatives. The Project
Manager is responsible for the overall management of the specific task order(s) and insuring that the technical solutions and schedules in the task order are implemented in a timely manner. Performs enterprise wide horizontal integration planning and interfaces to other functional systems.
Minimum Education: Must either be certified as a.) Project
Management Professional (PMP) by the Project Management
Institute (PMI) or other such credentialing organization, or b.)
Have been or currently are certified as a FAC- Program/Project
Manager (P/PM) (any level) or c.) Must demonstrate the ability to fully use Microsoft Project to demonstrate project
1. A Bachelors degree in computer science/engineering technology, software/programming, social sciences, mathematics or business/finance can be substituted for 2 years general experience and 2 years IT experience.
2.) Ph. D. or Master’s Degree (in subjects described above) can be substituted for 1 year general project management and 1 year IT experience managing IT projects.
3. No degree and 10 years experience of project management with
5 years specialized in IT projects.
Technical Subject Matter Specialist (Senior)
Minimum/General Experience: This position requires 12 years of intensive and progressive experience in the applicable specialty field or, if the subject matter is less than 10 years old, the position requires being involved in the subject matter since the inception of the subject matter limited to: Applies subject matter knowledge to high level analysis, collection, assessment, design, development, modeling, simulation, integration, installation, documentation, and implementation. Resolves problems, which require an intimate knowledge of the related technical subject matter. Applies principles and methods of the subject matter to specialized solutions. Includes but not limited to; identity management, biometrics, industrial controls, electronic voting, cloud computing, cyber security, cryptography, virtualization, PKI, XML, applied IT policy and compliance, networking, business processes, security automation, and logistical support activities.
Minimum Education: A Bachelor’s degree from an accredited college or university with a curriculum or major field of study which is closely related to the work to be automated, and/or in a computer science, information system, a physical science, engineering or a mathematics-intensive discipline.
1. 1. A Master’s Degree (in subjects described above) and 8 years of specialized experience in a field closely related to the field applicable to the task order.
2. No degree and 15 years of intensive and progressive experience in the applicable specialty field.
3. An applicable certificate of training with two years undergraduate work can be considered equivalent to a
Bachelor’s degree.
Technical Subject Matter Specialist (Intermediate)
Minimum/General Experience: This position requires 8 years of intensive and progressive experience in the applicable specialty field or, if the subject matter is less than 8 years old, the position requires being involved in the subject matter since the inception of the subject matter.
limited to: Applies subject matter knowledge to high level analysis, collection, assessment, design, development, modeling, simulation, integration, installation, documentation, and implementation. Resolves problems, which require an intimate knowledge of the related technical subject matter. Applies principles and methods of the subject matter to specialized solutions. Includes but not limited to; identity management, biometrics, industrial controls, electronic voting, cloud computing, cyber security, cryptography, virtualization, PKI, XML, applied IT policy and compliance, networking, business processes, security automation, and logistical support activities.
which is closely related to the work to be automated, and/or in
1. 1. A Master’s Degree (in subjects described above) with applicable experience in a field closely related to the field applicable to the task order.
1.2. No degree and 10 years of intensive and progressive
experience in the applicable specialty field.
3. An applicable certificate of training with 2 years
Security Engineer (Senior) Minimum/General Experience: 10 years experience in technology oriented security engineering support related to hardware, software, O/S and/or processes.
Functional Responsibility: Duties may include but are not limited to: network security design engineering, intrusion detection/prevention engineering design and/or execution, environment risk assessments, network security architectural engineering, operating system security and operational security process engineering; providing direction to intermediate and junior staff on the tasks needed to implement security objectives.
which is closely related to the work to be automated, and/or in
1. A Master’s Degree (in subjects described above)from an accredited college or university with 8 years of applicable experience.
2. No degree and 12 years of directly applicable experience coupled with an industry or vendor technical certification
(i.e. CISSP, CIPA, MCSE, MCSA, CCNA, CCNE, SCSA, etc.)
Security Engineer (Intermediate) Minimum/General Experience: 4 years experience in technology oriented security engineering support related to hardware, software, O/S and/or processes.
Functional Responsibility: Duties may include but are not limited to: network security design engineering, intrusion detection/prevention engineering execution, environment risk assessments, network security architectural engineering, operating system security and operational security process engineering; providing direction to junior staff on the tasks needed to implement security objectives.
college or university with a curriculum or major field of study which is closely related to the work to be automated, and/or in
1. A Master’s Degree (in subjects described above) from an accredited college or university with 2 years of applicable experience in a field closely related to the field applicable to the task order.
2. No degree and 7 years of directly applicable experience coupled with and industry or vendor technical certification
(i.e. CISSP, CIPA, MCSE, MCSA, CCNA, CCNE, SCSA, etc.)
3. An applicable certificate of training with 2 years
Lead Vulnerability Analysis Specialist Minimum/General Experience: This position requires a minimum of
5 years experience, of which at least 2 years must be specialized in scoring vulnerabilities and at least 1 year working with the Common Vulnerability Scoring System (CVSS).
Must demonstrate the ability to work independently or under only general direction.
limited to: Analyzes configuration settings, vulnerabilities, patches and applies standardized scoring models. Must demonstrate good written and verbal communication skills for client interactions. May provide daily supervision and direction to support staff.
college or university in computer science/systems, information systems/technology, engineering/engineering technology, software engineering/programming, management, natural sciences, social sciences, mathematics or business/finance.
1. 1. A Master’s Degree (in subjects described above) from an accredited college or university with 3 years of general experience of which at least 12 years are specialized experience and at least 1 year working with the Common
Vulnerability Scoring System (CVSS).in a field closely related to the field applicable to the task orderin scoring vulnerabilities using CVSS.
1.2. No degree and at least 8 years of experience, 4 of
which must be specialized in scoring vulnerabilities and at least 2 years working with the Common Vulnerability Scoring
System (CVSS).
Analysis Specialist
5 years experience, of which at least 2 years must be specialized in scoring vulnerabilities and at least 1 year working with the Common Vulnerability Scoring System (CVSS).
Must demonstrate the ability to work independently or under only general direction.
limited to: Analyzes configuration settings, vulnerabilities, patches and applies standardized scoring models. Must demonstrate good written and verbal communication skills for client interactions. May provide daily supervision and direction to support staff.
Minimum Education: Associates Degree, IT industry certification in a platform or applications (i.e. MCSA, MSCE, CCNA, CCNE, SCSA, etc.) or demonstrated work experience in vulnerability analysis.
1. 1. A Bachelors Degree from an accredited college or university with 2 years of general experience and at least
1 year specialized experience scoring vulnerabilities.in a field closely related to the field applicable to the task order
2. No degree and at least 5 years of experience, 3 of which must be specialized in scoring vulnerabilities and at least
1 year working with the Common Vulnerability Scoring System
(CVSS).
Developer (Lead)
5 years of increasingly complex and progressive experience in performing systems analysis, development, and implementation for business, mathematical, engineering or scientific settings using a variety of information technology resources. Requires experience with current technologies and, where required for the task, emerging technologies. Have experience with object or functionally-oriented programming languages.
limited to: Formulates and defines system scope and objectives.
Prepares detailed specifications for programs. Designs, codes, tests, debugs, and documents programs. Works at the highest technical level of all phases of applications, systems analysis and programming activities including the installation of enhancements, security features, and analytical tools. Provides guidance and training to less experienced analysts/programmers.
which provides substantial knowledge useful in managing large, complex projects closely related to the work to be automated, and/or in a computer science, information system, a physical science, engineering or a mathematics - intensive discipline, or an applicable training certificate from an accredited training institution.
accredited college or university with 3 years experience in a field closely related to the field applicable to the task order.
2. No degree and 9 years of directly related experience.
Developer (Intermediate)
5 years experience, of which at least 3 years must be specialized. Specialized experience includes: experience as an applications programmer on data base management systems, knowledge of computer equipment and ability to develop complex software to satisfy design objectives. Have experience with object or functionally-oriented programming languages.
Demonstrated ability to work independently or under only general direction.
limited to: Analyzes functional business applications and design specifications for functional activities. Develops block diagrams and logic flow charts. Translates detailed design into computer software. Tests, debugs, and refines the computer software to produce the required product. Prepares required documentation, including both program-level and user-level documentation. Enhances software to reduce operating time or improve efficiency. May take direction from application engineer to ensure program deadlines are met.
systems/technology, engineering/engineering technology, software accredited college or university and 4 years general experience of which at least 2 years must be specialized experience.
2. No degree and 6 years of general experience of which at least 4 years must be specialized experience.
Developer (Junior) Minimum/General Experience: This position is for those who have demonstrated interest and accomplishment in code development, but have minimal professional experience. IT industry certification in a platform or applications (i.e. MCSA, MSCE, CCNA, CCNE, SCSA, etc.) or demonstrated work in an open source project.
limited to: Participates in the design of software tools and subsystems to support reuse and domain analysis. Assists
Applications Engineer and Applications Programmer to interpret software requirements and design specifications to code, and integrate and test software components.
Minimum Education: High School Diploma.
Information Engineer (Senior)
10 years experience, of which at least 8 years must be specialized. Specialized experience includes information systems development, functional and data requirements analysis, systems analysis and design, programming, program design and documentation preparation. The following experience is also required: demonstrated experience in the implementation of information engineering projects; systems analysis, design and programming, systems planning, business information planning, and business analysis. Must demonstrate the ability to work independently or under only general direction.
limited to: Applies business process improvement practices to re-engineer methodologies/principles and business process modernization projects. Applies, as appropriate, activity and data modeling, transaction flow analysis, internal control and risk analysis and modern business methods and performance measurement techniques. Assists in establishing standards for information systems procedures. Develops and applies organization-wide information models for use in designing and building integrated, shared software and database management systems. Constructs sound, logical business improvement opportunities consistent with corporate information management guiding principles, cost savings, and open system architecture objectives. May provide daily supervision and direction to staff.
systems/technology, engineering/engineering technology, software accredited college or university and 8 years general experience of which at least 6 years must be specialized experience.
2. A Ph.D. (in subjects described above) from an accredited college or university and 6 years of general experience of which at least 5 years must be specialized.
3. No degree and 13 years of general experience of which at least 11 years must be specialized experience.
Information Engineer (Intermediate)
6 years experience, of which at least 4 years must be specialized. Specialized experience includes information systems development, functional and data requirements analysis, systems analysis and design, programming, program design and documentation preparation. The following experience is also required: demonstrated experience in the implementation of information engineering projects; systems analysis, design and programming, systems planning, business information planning, re-engineer methodologies/principles and business process modernization projects. Applies, as appropriate, activity and data modeling, transaction flow analysis, internal control and risk analysis and modern business methods and performance measurement techniques. Assists in establishing standards for information systems procedures. Develops and applies organization-wide information models for use in designing and building integrated, shared software and database management systems. Constructs sound, logical business improvement opportunities consistent with corporate information management guiding principles, cost savings, and open system architecture systems/technology, engineering/engineering technology, software accredited college or university and 6 years general experience of which at least 3 years must be specialized experience.
2. A Ph.D. (in subjects described above) from an accredited college or university and 3 years of general experience of which at least 2 years must be specialized.
3. No degree and 8 years of general experience of which at least 5 years must be specialized experience.
Information Engineer (Junior)
3 years experience, of which at least 2 years must be specialized. Specialized experience includes information systems development, functional and data requirements analysis, systems analysis and design, programming, program design and documentation preparation. The following experience is also required: demonstrated experience in the implementation of information engineering projects; systems analysis, design and programming, systems planning, business information planning, re-engineer methodologies/principles and business process modernization projects. Applies, as appropriate, activity and data modeling, transaction flow analysis, internal control and risk analysis and modern business methods and performance measurement techniques. Assists in establishing standards for information systems procedures. Develops and applies organization-wide information models for use in designing and building integrated, shared software and database management systems. Constructs sound, logical business improvement opportunities consistent with corporate information management guiding principles, cost savings, and open system architecture systems/technology, engineering/engineering technology, software accredited college or university and 3 years general experience of which at least 1 years must be specialized experience.
2. No degree and 4 years of general experience of which at least 2 year must be specialized experience.
Application Engineer (Senior)
10 years experience managing or performing software engineering activities, of which at least 8 years must be specialized.
Specialized experience includes: demonstrated experience with programming languages in the design and implementation of systems and using database management systems. General experience includes increasing responsibilities in software engineering activities. Knowledgeable of applicable standards.
limited to: Leads the application of a systematic, disciplined, quantified engineering approach to the development, operation and maintenance of software. Analyzes and studies complex system requirements. Designs software tools and subsystems to support software reuse and domain analyses and manages their implementation. Manages software development and support using formal specifications, data flow diagrams, other accepted design techniques and, when appropriate, Computer Aided Software
Engineering (CASE) tools. Estimates software development costs and schedule. Reviews existing programs and assists in making refinements, reducing operating time, and improving current techniques. Supervises software configuration management.
systems/technology, engineering/engineering technology, software accredited college or university and 8 years general experience of which at least 6 years must be specialized experience.
2. No degree and 13 years of general experience of which at least 11 years must be specialized experience.
Applications Engineer (Intermediate)
6 years experience, of which at least 4 years must be specialized. Specialized experience includes: experience as an applications programmer on data base management systems, knowledge of computer equipment and ability to develop complex software to satisfy design objectives. Demonstrated ability to work independently or under only general direction.
limited to: Applies a systematic, disciplined, quantified engineering approach to the development, operation and maintenance of software. Analyzes functional business applications and design specifications for functional activities. Develops block diagrams and logic flow charts.
Translates detailed design into computer software. Tests, debugs, and refines the computer software to produce the required product. Prepares required documentation, including both program-level and user-level documentation. Enhances software to reduce operating time or improve efficiency. May provide technical direction to programmers to ensure program deadlines are met.
systems/technology, engineering/engineering technology, software accredited college or university and 4 years general experience of which at least 3 years must be specialized experience.
2. No degree and 10 years of general experience of which at least 8 years must be specialized experience.
Software Systems Engineer (Lead) Minimum/General Experience: This position requires 7 years of increasingly complex and progressive experience in performing systems analysis, development, and implementation of business, mathematical, or scientific settings using a variety of information technology resources. Requires experience with current technologies and, where required for the task, emerging technologies. Must have managed or had significant involvement with complex or substantive information technology projects including one year of experience demonstrating management and supervision capabilities.
limited to: Formulates and defines specifications for operating system applications or modifies and maintains existing applications using engineering releases and utilities from the manufacturer. Responsible for program design, modeling, simulation, coding, testing, debugging and documentation.
Responsible for applications dealing with the overall operating system, such as sophisticated file maintenance routines, large telecommunications/communications networks, computer accounting and advanced mathematical/scientific software packages.
Instructs, directs, and checks the work of other task personnel.
Responsible for quality assurance review and the evaluation of existing and new software products.
which provides substantial knowledge useful in managing large, complex projects closely related to the work to be automated, and/or in a computer science, information system, a physical science, engineering or a mathematics-intensive discipline.
accredited college or university and 5 years of relevant experience in a field closely related to the field applicable to the task order.
2. No degree and 11 years of directly relevant experience in a field closely related to the field applicable to the task order.
Cryptographer (Senior) Minimum/General Experience: This position requires 10 years general experience and 5 years specialized experience is required. 10 years general experience includes all aspects of cryptography, and a mixture of experience from the mathematical disciplines and the demonstrated ability to work independently or under only general supervision.
5 years specialized experience includes developing cryptographic and hash algorithms including but not limited to triple DES, AES, SHA, etc. Demonstrated experience in developing, analyzing, testing, and researching Public Key Infrastructures using X.509 certificates, symmetric and public key algorithms, hash functions and quantum cryptography.
limited to: Performs complex analysis, design, development, integration, testing and debugging cryptographic and hashing algorithms. Apply cryptography-based solutions to contemporary use cases such as evaluating for FIPS 140 compliance, electronic voting, smart grid, health care, and resource constrained environments including but not limited to smart meters, smart cards, and medical devices. May supervise Intermediate
Cryptographers.
Minimum Education: A Ph.D degree from an accredited college or university in Cryptography, Computer Science, Engineering, Mathematics, or other related scientific or technical discipline is required.
1. A Master’s degree from an accredited college or university in Cryptography, Computer Science, Engineering, Mathematics, or other related scientific or technical discipline is required AND 10 years experience in a field closely related to the field applicable to the task order.
Cryptographer (Intermediate) Minimum/General Experience: This position requires 5 years general experience and 3 years specialized experience is required. 5 years general experience includes all aspects of cryptography, and a mixture of experience from the mathematical disciplines and the demonstrated ability to work independently or under only general supervision.
3 years specialized experience includes developing cryptographic and hash algorithms including but not limited to triple DES, AES, SHA, etc. Demonstrated experience in developing, analyzing, testing, and researching Public Key Infrastructures using X.509 certificates, symmetric and public key algorithms, hash functions, and quantum cryptography.
limited to: Performs complex analysis, design, development, integration, testing and debugging cryptographic and hashing algorithms. Apply cryptography-based solutions to contemporary use cases such as evaluating for FIPS 140 compliance, electronic voting, smart grid, health care, and resource constrained environments including but not limited to smart meters, smart cards, and medical devices..
Minimum Education: A Masters degree from an accredited college or university in Cryptography, Computer Science, Engineering, Mathematics, or other related scientific or technical discipline is required.
1. A Bachelors degree from an accredited college or university in Cryptography, Computer Science, Engineering, Mathematics, or other related scientific or technical discipline is required AND 5 years experience in a field closely related to the field applicable to the task order.
B. 2 SCHEDULE OF LABOR RATES
SCHEDULE OF LABOR RATES
The following is a schedule of the fully burdened hourly labor rates to be applied to each labor category under this IDIQ contract. When submitting a quotation or proposal for a task order under this contract, the Contractor must propose a fully burdened hourly labor rate that does not exceed the ceiling labor rate listed below for the corresponding labor category. The government may request that, and the Contractor may offer the Government discounted labor rates from the rates listed below. However, the rates listed below may not be exceeded. When preparing a quotation or proposal for a task order under this contract, the Contractor shall apply a rate not exceeding the ceiling fully burdened hourly labor rates associated with the period of the IDIQ contract during which the work will be performed, and the place of performance whether it be on-site or off-site.
Should the period of performance of a task order cross over between two or more periods of the IDIQ contract, the Contractor may propose multiple rates for separate periods within the task order period of
Labor Category Ceiling Fully Burdened Hourly Labor Rates per Contract
Period (On-Site (On) / Off-Site (Off))
Base
Period
Option
Period 1
Option
Period 2
Option
Period 3
Option
Period 4
On Off On Off On Off On Off On Off
Program Manager
(Contract Level)
Project Manager
(Task Order Level)
Technical Subject
Matter Specialist
(Senior)
Technical Subject
Matter Specialist
(Intermediate)
Security Engineer
Security Engineer
Lead Vulnerability
Analysis Specialist
Analysis Specialist
Developer (Lead)
Developer
Developer (Junior)
Information Engineer
(Junior)
Application Engineer
Application Engineer
Software Systems
Engineer (Lead)
Cryptographer
Cryptographer
B. 3 MINIMUM AND MAXIMUM CONTRACT AMOUNTS
1352.216-75 Minimum and maximum contract amounts.
As prescribed in 48 CFR 1316.506(a), insert the following clause:
MINIMUM AND MAXIMUM CONTRACT AMOUNTS (APR 2010)
During the term of the contract, the Government shall place orders totaling a minimum of $100,000.00 against each awarded Indefinite-Delivery, Indefinite-Quantity contract awarded. The amount of all orders awarded against all contracts awarded shall not exceed $70,000,000.00.
SECTION C
DESCRIPTION/SPECIFICATIONS/WORK STATEMENT
C. 1 IDIQ PERFORMANCE WORK STATEMENT
Performance Work Statement for ITL
I. BACKGROUND
The National Institute of Standards and Technology (NIST) is responsible for developing standards and Special Publications, including minimum requirements, that provide adequate information security for all agency operations and assets, but such standards and
Special Publications shall not apply to national security systems. With a new and re-energized national emphasis on information security, the NIST Information Technology
Laboratory’s (ITL) Computer Security Division (CSD) is uniquely positioned to ensure that new technology initiatives are selected, deployed and operated in a manner that does not increase the Risk to organizational missions, individuals and the Nation.
CSD conducts research and development in security management and assurance, cryptography and systems security, identity management and emerging security technologies. CSD plays a vital role in both national and international security standard setting. The division has the lead role in technologies and standards for Cloud
Computing, Identity Management and as a Government Wide Leader and national coordinator for the National Initiative for Cybersecurity Education (NICE). CSD leads technical government initiates including creating Special Publications for Smart Grid
Security, which identifies security requirements applicable to the Smart Grid, security-relevant use cases, logical interface diagrams and interface categories, vulnerability classes abstracted from other relevant cyber security documents, specific issues applicable to the Smart Grid, and privacy concerns. CSD also provides reference specifications in multiple areas, allowing others to leverage the division’s work to increase the security of their systems and products.
CSD, as a collaborator for both government and industry, coordinates with partners across the government, industry and the world. For example, CSD embraced international cooperation in our Secure Hash Algorithm (SHA-3) competition while working on a successor to the current government-approved hash algorithm.
Industry represents a key audience and partner in all of our work. The success of the
Security Content Automation Protocol (SCAP) program is dependent on CSD’s partnership with them. Several sectors of the Information Technology industry have advised CSD on the need for the program and its evolution. There was enthusiastic adoption from many industry partners and their continued support has allowed the division to move ahead with this program much more quickly than otherwise. As a result of such cooperation, CSD has created and is maintaining a significant repository of SCAP compliant security checklists for use with an ever-increasing number of security tools.
The responsibilities assigned to NIST, and by extension CSD, in the Federal Information
Security Management Act (FISMA) is to assist the federal agencies in securing their information systems and develop cyber security standard, guidelines and associated methods and techniques are major parts of the CSD portfolio of tasking and responsibility.
II. SCOPE OF WORK
The purpose of this vehicle is for the contractor to provide information security and cybersecurity services through an Indefinite-Delivery, Indefinite-Quantity (IDIQ) type contract. Task orders issued under this contract may be firm fixed price or labor hour type task orders. The type of task order will be clearly identified in each individual order.
The purpose of this contract is to gain technical expertise and consultation in multiple specified areas of cyber and information security to ensure that the NIST mission can be met to “provide standards, technology, tools, and practices to protect our nation’s information and information systems.”
NIST expects the requirements of its mission to expand and anticipates the need for support in meeting these requirements. The support needed to ensure a successful mission ranges from internal programmatic support to technical expertise and research consulting in a wide range of cyber and information security areas.
The intended outcome is for NIST to have the ability to ensure that support is available when needed for specific tasks, as they are identified through internal requirement and resource evaluation, so NIST can accomplish its mission, meet higher organizational expectations and provide cyber and information security mechanisms to reduce the risks to organizations, individuals and the Nation.
While the primary objective of this contract is to serve the consulting, engineering, research, and development of CSD, other divisions in ITL with related security work may also be authorized to use the vehicle, if necessary.
III. REQUIREMENTS
The specific tasks required of the contractor under this IDIQ contract will be detailed in individual task orders. However, the following section provides information on the types of tasks that the contractor will be required to perform. Specific areas anticipating support include but are not limited to:
Task 1: NIST SP 800 Series documents, NISTIRs, FIPS, DTRs. Specifics in each
Task Order (TO). Provide technical expertise and assistance in creating Computer and Cyber Security Standards, Special Publications, Derived Test Requirements
(DTRs) and NIST Inter-Agency Reports (NISTIRs). Input(s) shall be technically correct, relevant to subject matter and appropriate to designated audience (i.e. Federal
Government and Industry). Formats shall follow NIST CSD, ITL and Washington
Editorial Review Board (WERB) requirements.
Task 2: : Training, Education and Awareness Materials in multiple media formats. Specifics in each TO.
Provide technical expertise and assistance in creating Training, Awareness and
Outreach (TAO) materials to support the deliverables in Task 1 and/or pre-existing
Standards, Special Publications, DTRs, or NISTIRs. Type of media used to present deliverables to audiences may be multiple (i.e. .PPT. PDF, Streaming Media, PodCast, RSS, DVD, Web 2.0 technologies, etc.). Types of TAO may be multiple
(i.e. Quick Start Guides, FAQs, Captures of Presentations on digital media, brochures, posters, etc.)
Task 3: Data Models, Schemas, and Databases. Canned queries, standardized reports, and DBA services. Specifics in each TO. Provide Data Modeling, Data
Schema Design, Data Base Design, Data Transformation and Data Loading services.
This may include creation and/or maintenance of web enabled data presentation and input applications to support specific business needs. Service may also include the need for identification and authentication mechanism to control access to applications.
Service may also include the creation of extranets to organizations (i.e. the Open
Group, product vendors, etc.) and other agencies (i.e. Federal, State, and local governments) that work with NIST specified business partners for the exchange of data. Services may also include the creation of data models and loaded databases representing the information included in existing and newly created Standards, Special
Publications, DTRs and NISTIRs for posting to a website and download by customers.
Task 4: Information Technology applications to automate business process and provide standard reference materials. Specifics in each TO. Provide technical expertise and consultation to support software development, application development and application modeling support using generally acceptable design and development methodologies to support required business needs, create standard(s) reference tools and provide automation to developed and existing DTRs. Examples include the a.)
SCAPVAL and XCCDF reference implementations and b.) Updates and maintenance to the test content provided to NIST accredited labs for validation testing.
Task 5: Input, consultation and expertise in credentialing programs. Specifics in each TO. Provide technical expertise and consultation to support the development of an Individual and Organization Credentialing program to certify entities in the performance of tasks included in the software assurance, cryptography, security automation, and NIST CSD Risk Management Framework as defined in NIST SP800-
37, SP800-53, SP800-53A, etc..
Task 6: Recommendations on standards activities that reflect NIST and DOC strategic positions and interaction with Standards Development Organizations.
Specifics in each TO.
Provide technical expertise and consultation to support CSD in the identification, selection, constraining and/or harmonization of standards in existence and/or on the progression of standards under development by National, International and Other
Standards Development Organizations (SDOs). Provide technical expertise and assistance in creating technically correct input relevant to the subject matter of the standard…
This is the start of the file's text. The full file is on GovTribe.
File details come from the government source that posted it. Updated .