Solicitation 19L16025Q0005 _DT Internet Services.pdf

PDF 1 MB Posted

Attached to
Amended DT Internet Services Solicitation Federal contract opportunity
Solicitation number
19L16025Q0005
Issued by
Department of State

About this file

This is a Request for Quotations (RFQ #19L16025Q0005) issued by the U.S. Embassy in Monrovia, Liberia for Internet Services. The government intends to make multiple awards for Primary and Secondary (backup) Internet services, with a base period of one year (estimated August 8, 2025 through August 7, 2026) and four one-year option periods, plus a potential 6-month extension.

The required services include three dedicated 80 Mbps Internet channels with fault tolerance in the last mile and HSRP protocol: 1) OpenNet-VNET, 2) DIN-Embassy, and 3) Internet DTS-PO. Technical requirements specify fiber optic connectivity to the Embassy's TSEF DMAC Room, 1:1 connection ratio, unfiltered access without NAT or firewalls, and support for all IP protocols. Quotes are due by February 28, 2025 at 1600 GMT and must be submitted electronically to monroviabids@state.gov. Bidders must be registered in SAM.gov and submit completed SF-1449, pricing, representations/certifications, and cybersecurity supply chain risk management documentation. The contract will be awarded on a best value basis using FAR 13 Comparative Evaluation procedures.

View the file

Other files for this federal contract opportunity

Other files attached to Amended DT Internet Services Solicitation, newest first.
File Type Posted
Amended No. 2 19L16025Q0005 solicitation.pdf PDF
SF-30 DT Internet Svs 19L16025Q0005.pdf PDF
CERTIFICATION REGARDING COMPLIANCE WITH APPLICABLE FEDERAL ANTI-DISCRIMINATION LAW.pdf PDF
Amendment No.1 _19L16025Q0005.pdf PDF

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

U.S. Embassy Monrovia

Date: January 24, 2025

Dear Prospective Quoter:

Subject: Request for Quotations number 19L16025Q0005

Enclosed is a Request for Quotations (RFQ) for Internet Services. In order to submit a quotation, follow the instructions in Section 3 of the solicitation, complete the required portions of the attached document, and submit it to the address shown on the Standard Form 1449 that follows this letter.

The Government intends to make multiple awards from this Solicitation. The intention is to award a

Primary and Secondary (back-up) Internet Services contract to responsible contractors whose quotations conform to the solicitation and represents the best value to the Government, price and other factors considered utilizing FAR 13 Comparative Evaluation.

Quotations are due by February 28, 2025, at 1600 GMT. No quotations will be accepted after this time.

Proposals must be in English and incomplete proposals will not be accepted.

Your quotation must be submitted electronically to monroviabids@state.gov. It is important to make sure the submission is made in specific size and format; in MS-Word 2007/2010 or MS-Excel 2007/2010 or

Adobe Acrobat (pdf) file format. The file size must not exceed 30MB. If the file size should exceed the

30MB, the submission must be made in separate files and attached to separate emails with less than

30MB each.

In order for a quotation to be considered, you must also complete and submit the following:

1. SF-1449

2. Section I, Pricing

3. Section 5 Representations and Certifications

4. Additional information as required in Section 3

5. Proof of SAM Registration

6. CYBERSECURITY SUPPLY CHAIN RISK MANAGEMENT (C-SCRM) C-

SCRM Questionnaire and C-SCRM Software Producer Attestation Form

Offerors shall be registered in the SAM (System for Award Management) database at https://www.sam.gov prior to submittal of their offer/proposal as prescribed under FAR 4.1102. Failure to be registered at time of proposal submission may deem the offeror’s proposal to be considered non-responsible and no further consideration will be given. Therefore, offerors are highly encouraged to register immediately if they are interested in submitting a response to this requirement.

Sincerely, Megan A. Biek

Contracting Officer

Enclosure:

mailto:monroviabids@state.gov https://www.sam.gov/

REQ# 19L16025Q0005 - DT INTERNET SERVICES SOLICITATION

TABLE OF CONTENTS

SECTION 1 - THE SCHEDULE

* SF 1449 cover sheet

* Continuation To SF-1449, RFQ Number 19L16025Q0005, Prices, Block 23

* Continuation To SF-1449, RFQ Number 19L16025Q0005, Schedule Of Supplies/Services, Block 20 Description/Specifications/Work Statement

* Attachment 1, CYBERSECURITY SUPPLY CHAIN RISK MANAGEMENT (C-

SCRM) SOFTWARE PRODUCER ATTESTATION FORM

SECTION 2 - CONTRACT CLAUSES

* Contract Clauses

* Addendum to Contract Clauses - FAR and DOSAR Clauses not Prescribed in Part 12

SECTION 3 - SOLICITATION PROVISIONS

* Solicitation Provisions

* Addendum to Solicitation Provisions - FAR and DOSAR Provisions not Prescribed in

Part 12

SECTION 4 - EVALUATION

* Evaluation

* Addendum to Evaluation - FAR and DOSAR Provisions not Prescribed in Part 12

SECTION 5 - OFFEROR REPRESENTATIONS AND CERTIFICATIONS

* Offeror Representations and Certifications

* Addendum to Offeror Representations and Certifications - FAR and DOSAR Provisions not Prescribed in Part 12

SOLICITATION/CONTRACT/ORDER FOR COMMERCIAL

ITEMS

OFFEROR TO COMPLETE BLOCKS 12, 17, 23, 24, & 30

1. REQUISITION NUMBER

2. CONTRACT NO.

3. AWARD/EFFECTIVE

DATE

4. ORDER NUMBER

5. SOLICITATION NUMBER

19L16025Q0005

6. SOLICITATION ISSUE

DATE: January 24,

7. FOR SOLICITATION

INFORMATION CALL:

a. NAME

Mr. Abraham Kuehl – Procurement

Supervisor

b. TELEPHONE NUMBER(No collect calls)

+231 77 677 7000

8. OFFER DUE DATE/ LOCAL TIME

February 28, 2025 @

1600 GMT

9. ISSUED BY

CODE

10. THIS ACQUISITION IS UNRESTRICTED OR SET ASIDE:____ %

FOR:

SMALL BUSINESS WOMEN-OWNED SMALL BUSINESS

HUBZONE SMALL

BUSINESS

(WOSB) ELLIGIBLE UNDER THE WOMEN-OWNED

SMALL BUSINESS PROGRAM NAICS:

SERVICE-DISABLED

VETERAN-OWNED

SMALL BUSINESS

EDWOSB

8 (A) SIZE STANDARD:

11. DELIVERY FOR FOB

DESTINATION UNLESS BLOCK

IS MARKED

SEE SCHEDULE

12. DISCOUNT TERMS 13a. THIS CONTRACT IS A

RATED ORDER UNDER

DPAS (15 CFR 700)

13b. RATING

14. METHOD OF SOLICITATION

RFQ IFB RFP

15. DELIVER TO CODE 16. ADMINISTERED BY CODE

Same as BLOCK# 9

17a. CONTRACTOR/

OFFERER

TELEPHONE NO.

CODE FACILITY

CODE

18a. PAYMENT WILL BE MADE BY:

Financial Management Officer

US Embassy Monrovia

Email: MonroviaInvoices@state.gov

CODE

17b. CHECK IF REMITTANCE IS DIFFERENT AND PUT SUCH

ADDRESS IN

OFFER

18b. SUBMIT INVOICES TO ADDRESS SHOWN IN BLOCK 18a UNLESS BLOCK

BELOW IS CHECKED SEE ADDENDUM

19.

ITEM NO.

20.

SCHEDULE OF SUPPLIES/SERVICES

21.

QUANTITY

22.

UNIT

23.

UNIT PRICE

24.

AMOUNT

BASE YEAR TOTAL PRICE

FIRST OPTION YEAR TOTAL PRICE

SECOND OPTION YEAR TOTAL PRICE

THIRD OPTION YEAR TOTAL PRICE

FOURTH OPTION YEAR TOTAL PRICE

OPTION TO EXTEND 6 MONTHS (FAR 52.217-8)

YEAR

YEAR

YEAR

YEAR

YEAR

MONTHS

(Use Reverse and/or Attach Additional Sheets as Necessary)

25. ACCOUNTING AND APPROPRIATION DATA

26. TOTAL AWARD AMOUNT (For Govt. Use

Only)

27a.SOLICITATION INCORPORATES BY REFERENCE FAR 52.212-1, 52.212-4. FAR 52.212-3 AND 52.212-5 ARE ATTACHED.

ADDENDA

ARE ARE NOT

ATTACHED

27b.CONTRACT/PURCHASE ORDER INCORPORATES BY REFERENCE FAR 52.212-4. FAR 52.212-5 IS ATTACHED. ADDENDA ARE ARE NOT

ATTACHED

28. CONTRACTOR IS REQUIRED TO SIGN THIS DOCUMENT AND RETURN ____

COPIES TO ISSUING OFFICE. CONTRACTOR AGREES TO FURNISH AND

DELIVER ALL ITEMS SET FORTH OR OTHERWISE IDENTIFIED ABOVE AND ON

ANY ADDITIONAL SHEETS SUBJECT TO THE TERMS AND CONDITIONS

SPECIFIED HEREIN.

29. AWARD OF CONTRACT: REF. _________________ OFFER DATED

____________. YOUR OFFER ON SOLICITATION (BLOCK 5), INCLUDING

ANY ADDITIONS OR CHANGES WHICH ARE SET FORTH HEREIN, IS

ACCEPTED AS TO ITEMS:

30a. SIGNATURE OF OFFEROR/CONTRACTOR 31a. UNITED STATES OF AMERICA (SIGNATURE OF CONTRACTING OFFICER)

30b. NAME AND TITLE OF SIGNER (Type or print)

30c. DATE SIGNED

31b. NAME OF CONTRACTING OFFICER (Type or print)

31c. DATE SIGNED

AUTHORIZED FOR LOCAL REPRODUCTION STANDARD FORM 1449 (REV. 02/2012)

AMERICAN EMBASSY MONROVIA

502 Benson Street, ATTN: GSO/PROCUREMENT

MONROVIA, LIBERIA

Phone: (+231) 77-677-7000

Fax: (+231) 77-677-7370

AMERICAN EMBASSY MONROVIA

X

X

X

X

X

X

X

PREVIOUS EDITION IS NOT USABLE Computer Generated Prescribed by GSA - FAR (48 CFR) 53.212

19.

ITEM NO.

20.

SCHEDULE OF SUPPLIES/SERVICES

21.

QUANTITY

22.

UNIT

23.

UNIT PRICE

24.

AMOUNT

32a. QUANTITY IN COLUMN 21 HAS BEEN

RECEIVED INSPECTED ACCEPTED, AND CONFORMS TO THE CONTRACT, EXCEPT AS NOTED:

32b. SIGNATURE OF AUTHORIZED GOVERNMENT

REPRESENTATIVE

32c. DATE 32d. PRINTED NAME AND TITLE OF AUTHORIZED

GOVERNMENT

REPRESENTATIVE

32e. MAILING ADDRESS OF AUTHORIZED GOVERNMENT REPRESENTATIVE 32f. TELEPHONE NUMBER OF AUTHORIZED GOVERNMENT

REPRESENTATIVE

32g. E-MAIL OF AUTHORIZED GOVERNMENT REPRESENTATIVE

33. SHIP NUMBER 34. VOUCHER

NUMBER

35. AMOUNT VERIFIED

CORRECT FOR

36. PAYMENT 37. CHECK NUMBER

PARTIAL FINAL

COMPLETE PARTIAL

FINAL

38. S/R ACCOUNT NO.

39. S/R VOUCHER

NO.

40. PAID BY

41.a. I CERTIFY THIS ACCOUNT IS CORRECT AND PROPER FOR PAYMENT 42a. RECEIVED BY (Print)

41b. SIGNATURE AND TITLE OF CERTIFYING OFFICER

41C. DATE

42b. RECEIVED AT (Location)

42c. DATE REC’D (YY/MM/DD) 42d. TOTAL CONTAINERS

AUTHORIZED FOR LOCAL REPRODUCTION STANDARD FORM 1449 (REV. 02/2012)

PREVIOUS EDITION IS NOT USABLE Computer Generated Prescribed by GSA - FAR (48 CFR) 53.212

SECTION 1 - THE SCHEDULE

CONTINUATION TO SF-1449, RFQ NUMBER 19L16025Q0005, PRICES BLOCK 23

I. SCOPE OF SERVICES

The Contractor shall complete all work, including furnishing all labor, material, equipment, and services, unless otherwise specified herein, required under this contract for stated services within the time specified herein. The price listed below shall include all labor, materials, overhead, and profit. In consideration of satisfactory performance of all scheduled services required under this contract, the Contractor shall be paid a firm fixed price for all services.

II. BASE PERIOD

The contract will be for a one-year period from the date of the contract award and a notice to proceed with four option years.

1. The Contractor shall furnish all engineering, labor, tools, equipment, materials, supplies and services to provide the required circuit as specified under Section 1, hereof.

2. Prices. In consideration of satisfactory performance of the services required under this contract, the Contractor shall be paid a firm fixed price (FFP) per month as stated in the schedule below in USD.

JAMES ZADROGA 9/11 VICTIMS HEALTH AND COMPENSATION ACT OF

2010 NOTICE: UNLESS A WAIVER OR EXCEPTION APPLIES, PAYMENTS

SUBSEQUENT TO THIS PROCUREMENT ARE SUBJECT TO AN EXCISE

TAX OF 2% PERSUANT TO 26 U.S.C. 5000C.

2.1 VALUE ADDED TAX

VALUE ADDED TAX. Value Added Tax (VAT) is not applicable to this contract and shall not be included in the CLIN rates or Invoices because the U.S. Embassy has a tax exemption certificate from the host government.

2.2. The firm fixed-prices are in USD.

BASE YEAR: ESTIMATED AUGUST 8, 2025 THROUGH AUGUST 7, 2026

Contract

Line

Item # Description of Services

Number of

Months Monthly Price Total Firm-Fixed Price

OpenNet-VNET _ One (1) dedicated Internet channel at minimum 80 Mbps providing fault tolerance in the last mile. HSRP protocol is required

Initial Installation (Non-

Recuring)

DIN-EMBASSY _ One (1) dedicated Internet channel at minimum 80 Mbps providing fault tolerance in the last mile. HSRP protocol is required.

Initial Installation (Non-

Recuring)

Internet DTS-PO _ One (1) dedicated Internet channel at minimum 80 Mbps providing fault tolerance in the last mile. HSRP protocol is required

Initial Installation (Non-

Recuring)

SUB-TOTAL

PLUS VAT (IF APPLICABLE)

GRAND TOTAL FOR BASE YEAR

OPTION YEAR 1: ESTIMATED AUGUST 8, 2026 THROUGH AUGUST 7, 2027

Item # Description of Services

Number of

Months Monthly Price Total Firm-Fixed Price

OpenNet-VNET _ One (1) dedicated Internet channel at minimum 80 Mbps providing fault tolerance in the last mile. HSRP protocol is required

DIN-EMBASSY _ One (1) dedicated Internet channel at minimum 80 Mbps providing fault tolerance in the last mile. HSRP protocol is required.

Internet DTS-PO _ One (1) dedicated Internet channel at minimum 80 Mbps providing fault tolerance in the last mile. HSRP protocol is required

SUB-TOTAL

GRAND TOTAL FOR OPTION YEAR 1

OPTION YEAR 2: ESTIMATED AUGUST 8, 2027 THROUGH AUGUST 7, 2028

Item # Description of Services

Number of

Months Monthly Price Total Firm-Fixed Price

OpenNet-VNET _ One (1) dedicated Internet channel at minimum 80 Mbps providing fault tolerance in the last mile. HSRP protocol is required

DIN-EMBASSY _ One (1) dedicated Internet channel at minimum 80 Mbps providing fault tolerance in the last mile. HSRP protocol is required.

Internet DTS-PO _ One (1) dedicated Internet channel at minimum 80 Mbps providing fault tolerance in the last mile. HSRP protocol is required

SUB-TOTAL

GRAND TOTAL FOR OPTION YEAR 2

OPTION YEAR 3: ESTIMATED AUGUST 8, 2028 THROUGH AUGUST 7, 2029

Item # Description of Services

Number of

Months Monthly Price Total Firm-Fixed Price

OpenNet-VNET _ One (1) dedicated Internet channel at minimum 80 Mbps providing fault tolerance in the last mile. HSRP protocol is required

DIN-EMBASSY _ One (1) dedicated Internet channel at minimum 80 Mbps providing fault tolerance in the last mile. HSRP protocol is required.

Internet DTS-PO _ One (1) dedicated Internet channel at minimum 80 Mbps providing fault tolerance in the last mile. HSRP protocol is required

SUB-TOTAL

GRAND TOTAL FOR OPTION YEAR 3

OPTION YEAR 4: ESTIMATED AUGUST 8, 2029 THROUGH AUGUST 7, 2030

Item # Description of Services

Number of

Months Monthly Price Total Firm-Fixed Price

OpenNet-VNET _ One (1) dedicated Internet channel at minimum 80 Mbps providing fault tolerance in the last mile. HSRP protocol is required

DIN-EMBASSY _ One (1) dedicated Internet channel at minimum 80 Mbps providing fault tolerance in the last mile. HSRP protocol is required.

Internet DTS-PO _ One (1) dedicated Internet channel at minimum 80 Mbps providing fault tolerance in the last mile. HSRP protocol is required

SUB-TOTAL

GRAND TOTAL FOR OPTION YEAR 4

OPTION TO EXTEND FOR 6 MONTHS (FAR 52.217-8) ESTIMATED AUGUST 8, 2030

THROUGH FEBRUARY 7, 2031

Contract

Line

Item # Description of Services

Number of

Months Monthly Price Total Firm-Fixed Price

OpenNet-VNET _ One (1) dedicated Internet channel at minimum 80 Mbps providing fault tolerance in the last mile. HSRP protocol is required

DIN-EMBASSY _ One (1) dedicated Internet channel at minimum 80 Mbps providing fault tolerance in the last mile. HSRP protocol is required.

Internet DTS-PO _ One (1) dedicated Internet channel at minimum 80 Mbps providing fault tolerance in the last mile. HSRP protocol is required

SUB-TOTAL

GRAND TOTAL FOR OPTION YEAR 4

GRAND TOTAL CONTRACT PRICE, INCLUDING ALL OPTION YEARS

Base Period Total Price

First Option Year Total Price

Second Option Year Total Price

Third Option Year Total Price

Fourth Option Year Total Price

Option to Extend for 6 months (FAR 52.217-8)

GRAND TOTAL FIRM-FIXED PRICE

FOR BASE YEAR PLUS ALL OPTION YEARS

CONTINUATION TO SF-1449, RFQ NUMBER 19L16025Q0005

SCHEDULE OF SUPPLIES/SERVICES, BLOCK 20

DESCRIPTION/SPECIFICATIONS/WORK STATEMENT

I. SCOPE OF WORK

The purpose of this firm fixed price purchase order is to obtain Primary VPN, DIN, DTSPO, Secondary VNET Internet Services, and Circuitry for the U.S. Embassy Monrovia.

The local Telecommunication’s Internet Service Provider (ISP) contracting firm must provide dedicated internet services and circuitry for connecting American Embassy Monrovia

THIS IS THE LIST OF REQUIRED SERVICES:

SERVICE: OpenNet-VNET

NAME: OpenNet Plus (VPN through the Internet) at the U.S. Embassy

DESCRIPTION: VNET _ One (1) dedicated Internet channel at minimum 80 Mbps providing fault tolerance in the last mile. HSRP protocol is required

TYPE OF

SERVICE:

Dedicated Internet Channel

LOCATION: U.S. Embassy Monrovia. 502 Benson Street, Monrovia, Liberia

THE PROVIDED INTERNET SERVICE SHALL COMPLY WITH THE FOLLOWING

REQUIREMENTS:

Internet Services Quality

This internet circuit shall be high-end, professional grade service that differs from the residential service. ENM requires dedicated (not shared or bundled) Internet Bandwidth, 24/7, “always-on” with unlimited usage. Fiber optic, terrestrial connectivity is preferred. The local ISP access circuit to the Post must meet the following specifications/requirements for connectivity.

Internet Service Provider (ISP) must provide Fiber Optic connectivity to the very end at the U.S. Embassy- Monrovia [Note to Contracting Officer: INSERT CITY’S NAME] compound

Telecommunications Service Entrance Facilities (TSEF) DMAC Room.

The ISP must be proactive by informing the US Embassy Monrovia minutes when the circuit goes down.

A /28 subnet static Public IP addresses for VPN equipment, network mask, and default gateway

IP address.

ISP interface connectors: LC fiber connector (MM-multimode) – Gigabit interface. Internet

Service Provider (ISP) must provide all data media converters or transmission devices in all cases.

ISP availability: "Always on". Bandwidth sharing between other non-Embassy customers is not allowed. Connection Ratio must be 1/1.

ISP connection: IPs must NOT use Network Address Translation (NAT).

ISP must permit all IP protocols (including but not limited to ICMP, UDP, TCP, and IPSEC) to transit without filters or proxies. Unfiltered access to the Internet is required without ISP firewall blocking or stateful inspection.

ISP must permit installation of Customer VPN encryption devices on circuit.

ISP must permit ping and trace route traffic from 169.252.0.0/16 and 169.253.0.0/16 to the ISP connection (LC fiber Gigabit MM router interface which terminates Customer VPN encryption device).

High quality performance, the following parameters in a vendor’s Service Level Agreement

(SLA) should be used:

a. Packet Loss <=.5%

b. Availability of 99.9%.

Internet Service Provider (ISP) Round Trip Time (RTT) reports the total time in milliseconds

(ms) time to send a small data packet and obtain a reply back; must be the faster than 200ms for the Round Trip Time (RTT) for internet service. Also, RTT must be faster than 7ms for local data services (for instance: point-to-point channels or web pages accessed through the Liberia

Network Access Point (NAP).

Internet Service Provider (ISP) must provide detailed network topology map that shows all possible paths ISP use for the internet traffic between ISP hub in Monrovia, Liberia and the ISP hub in United States of America (USA).

Internet Service Provider (ISP) must have redundancy in the Internet backbone between

Monrovia, Liberia and USA. For instance, If NAP of the host country’s backbone fail, NAP

Americas, NAP Sprint, or any other alternate backbone paths shall be available.

Internet Service Provider (ISP) must provide fault-tolerance Fiber Optic connectivity to the very end at the U.S. Embassy Monrovia compound Telecommunications Service Entrance Facilities

(TSEF) Room.

Network Devices

The network devices shall comply with the following characteristics:

Must not have ZTE, Huawei, Xiaomi and affiliated branded products in use on the internet connection. Post may not enter into contract (or extend or renew contract) with an entity that uses above mentioned equipment, system, or service that uses covered telecommunications equipment or services as a substantial or essential component of any system, or as critical technology as part of any system.

Service Support and Contingencies

ISP must warrant service support 7X24X365.

ISP must warrant service support on site if necessary 7X24X365, services must be coordinated directly with Embassy’s Contracting Office Representative (COR) or Information Technology

(IT) representative from the Embassy Information Systems Center (ISC).

ISP should have direct connection capability with major United States of America (U.S.A) telecommunication providers (ISPs) at Internet tier 1 level, having alternative line channels or backups in case of main Internet path malfunctioning, if local conditions permit.

ISP must provide a central Information Technology (IT) point of contact (POC) in order to promptly coordinate technical issues during the initial installation process.

SERVICE: DIN – EMBASSY

NAME: Dedicated Internet Network for U.S. Embassy Monrovia.

DESCRIPTION: DIN _ One (1) dedicated Internet channel at minimum 80 Mbps providing fault tolerance in the last mile. HSRP protocol is required.

TYPE OF

SERVICE:

Dedicated Internet Channel

LOCATION: U.S. Embassy Monrovia. 502 Benson Street, Monrovia, Liberia

Internet Services Quality

Internet Service Provider (ISP) must provide dedicated leased channel high-speed access to the

Internet. Twenty-four (24) hours uplink. Post Internet Service Provider (ISP) connection must be

"always on” and must not require the installation of any custom software on the client side.

For Internet Services the Internet Service Provider (ISP) must guarantee full contracted bandwidth availability 24X7X365 from the originator side to the ISP’s internet gateway.

Bandwidth sharing between other non-Embassy customers is not allowed. Connection Ratio must be 1/1.

(ms) time to send a small data packet and obtain a reply back; must be the faster than Xms for the Round Trip Time (RTT) for internet service. Also, RTT must be faster than Xms for local data services (for instance: point-to-point channels or web pages accessed through the [Note to

Contracting Officer: INSERT NAME OF HOST COUNTRY] Network Access Point (NAP).

transit without filters or proxies. Unfiltered access to the Internet is required without ISP firewall

ISP must provide Fiber Optic connectivity to the very end at the U.S. Embassy- Monrovia [Note to Contracting Officer: INSERT CITY NAME] compound Telecommunications Service

Entrance Facilities (TSEF) Room. Internet Service Provider (ISP) must provide router(s) and

Data media converters or transmission devices in all cases to allow for connecion to customer equipment.

Network Identification

A /28 subnet static Public IP addresses, network mask, and default gateway IP address.

uses above mentioned equipment, system, or service that uses covered telecommunications

(IT) representative from the Embassy Information Systems Center (ISC).

ISP should have direct connection capability with major United States of America (U.S.A) telecommunication providers (ISPs) at Internet tier 1 level, having alternative line channels or backups in case of main Internet path malfunctioning, if local conditions permit.

ISP must provide a central Information Technology (IT) point of contact (POC) in order to promptly coordinate technical issues during the initial installation process.

SERVICE: Internet DTS-PO

NAME: Dedicated Internet Channel for U.S. Embassy Monrovia.

DESCRIPTION: DTS-PO _ One (1) dedicated Internet channel at minimum

80 Mbps providing fault tolerance in the last mile. HSRP protocol is required.

TYPE OF SERVICES: Dedicated Internet Channel

LOCATION: U.S. Embassy Monrovia. 502 Benson Street, Monrovia, Liberia

Internet Services Quality

This internet circuit shall be high-end, professional grade service that differs from the residential service. ENM requires dedicated (not shared or bundled) Internet Bandwidth, 24/7, “always-on” with unlimited usage. Fiber optic, terrestrial connectivity is preferred. The local ISP access circuit to the Post must meet the following specifications/requirements for connectivity.

Internet Service Provider (ISP) must provide Fiber Optic connectivity to the very end at the U.S. Embassy- Monrovia [Note to Contracting Officer: INSERT CITY’S NAME] compound

Telecommunications Service Entrance Facilities (TSEF) DMAC Room.

The ISP must be proactive by informing the US Embassy Monrovia minutes when the circuit goes down.

A /28 subnet static Public IP addresses for VPN equipment, network mask, and default gateway

IP address.

ISP interface connectors: LC fiber connector (MM-multimode) – Gigabit interface. Internet

Service Provider (ISP) must provide all data media converters or transmission devices in all cases.

ISP availability: "Always on". Bandwidth sharing between other non-Embassy customers is not allowed. Connection Ratio must be 1/1.

ISP connection: IPs must NOT use Network Address Translation (NAT).

transit without filters or proxies. Unfiltered access to the Internet is required without ISP firewall

ISP must permit installation of Customer VPN encryption devices on circuit.

ISP must permit ping and trace route traffic from 169.252.0.0/16 and 169.253.0.0/16 to the ISP connection (LC fiber Gigabit MM router interface which terminates Customer VPN encryption device).

(ms) time to send a small data packet and obtain a reply back; must be the faster than 200ms for the Round Trip Time (RTT) for internet service. Also, RTT must be faster than 7ms for local data services (for instance: point-to-point channels or web pages accessed through the Liberia

Network Access Point (NAP).

Internet Service Provider (ISP) must provide detailed network topology map that shows all possible paths ISP use for the internet traffic between ISP hub in Monrovia, Liberia and the ISP hub in United States of America (USA).

Internet Service Provider (ISP) must have redundancy in the Internet backbone between

Monrovia, Liberia and USA. For instance, If NAP of the host country’s backbone fail, NAP

Americas, NAP Sprint, or any other alternate backbone paths shall be available.

Internet Service Provider (ISP) must provide fault-tolerance Fiber Optic connectivity to the very end at the U.S. Embassy Monrovia compound Telecommunications Service Entrance Facilities

(TSEF) Room.

uses above mentioned equipment, system, or service that uses covered telecommunications

(IT) representative from the Embassy Information Systems Center (ISC).

ISP should have direct connection capability with major United States of America (U.S.A) telecommunication providers (ISPs) at Internet tier 1 level, having alternative line channels or backups in case of main Internet path malfunctioning, if local conditions permit.

ISP must provide a central Information Technology (IT) point of contact (POC) in order to promptly coordinate technical issues during the initial installation process.

II. GENERAL:

A. Inspection and Acceptance. Unless specified in the Contract, the Government shall require a period not to exceed 24 hours in order to perform testing to determine acceptance of the required circuit under Section C. The U.S. destination point or the U.S. foreign post shall conduct the testing.

B. Term of Contract: The required circuits shall be installed and delivered to the

Destination Point on or before 60 Days after Contract Award. Upon successful installation and acceptance by the Government of the required circuit under Section C, the Contractor shall be provided, in writing, notice to proceed and shall provide contractual services for a twelve (12) month period, commencing on the date specified in the notice to proceed.

C. The Contractor agrees that the work and services set forth in this contract shall be performed during the period commencing the effective date of this contract and shall continue through the end of the twelve month period of service (CLIN 1 through 8), excluding the exercise of any option.

D. Option CLINs, (e.g. First Option Year CLINS 7-9), if exercised, as reflected in Section 1, shall be for Twelve (12) months each, commencing at the expiration of the previous period of performance or a negotiated period.

E. An Invoice, suitable for payment, shall contain, but not limited to, the following information:

1. Name of Contractor;

2. Date of Invoice;

3. Original Invoice Number (Consecutive numbers);

4. Contract number;

5. Task or Delivery Order number, as applicable;

6. Government Specific Accounting and Appropriation Data (Funding Cite.)

(Example: 19X0113-2015-X75041-180100-5327-2332);

7. Contract Line Item Number (CLIN) of item or service provided;

8. Description of the item, or service actually provided;

9. Period of performance of service or date item is provided;

10. Block/Space reserved for COR acceptance signature and date;

11. Signature, Name and Phone number of Company representative authorized to sign invoices;

12. Remit to address

13. Name, phone number and Mailing address to whom any disputed invoices should be addressed;

14. Credits with explanation and period covered.

Failure to submit Invoices which do not identify this information shall be returned without payment to the Contractor for correction.

E. The circuit described above is exempt, under Article 34 of the Vienna Convention on

Diplomatic Relations, from the Special Access Surcharges or foreign taxes, including Value

Added Taxes.

F. Authorized Instruction to Contractor

a. No person or agency other than the Contracting Officer (CO) is authorized to give instruction, orders or directions on behalf of the Government to the Contractor or his employees, unless such person or agency is authorized in writing by the CO to so act. The authority of such person or agency is strictly limited to the written authorization provided by the CO. The duty is upon the Contractor to determine the authority of such person or agency. Any questions regarding the authority of such person or agency should be directed to the CO in writing.

b. Contracting Officer’s Representative (COR): The CO may designate and authorize a representative(s) to act on his/her behalf under this contract. Such representative(s) as may be appointed shall be designated by a letter from the CO and a copy of the letter shall be given to the Contractor. The COR shall represent the CO as specified in his/her delegation of authority letter. The COR shall not be authorized to issue change orders or adjustments.

Changes in the Scope of Work/Specifications or any increase or decrease in the work called for by this contract shall be made by the CO by an executed modification to this contract.

“Reserved” S.

G. Release of Information

1. The Contractor’s organization shall clear with the Information Office listed below any public release of information on this contract. This information includes news stories, articles, sales literature, advertisements, radio-TV spots, etc.

2. The request for public release of information should be addressed to: Jeffrey L Biron, Contracting Officer at bironjl@state.gov

3. Limited Use of Data and Information. Performance of this contract may require the Contractor to access and use data and information proprietary to the Government agency or agency personnel, or which is of such a nature that its dissemination or use, other than in performance of this contract would be adverse to the interests of the Government or others. The Contractor and Contractor personnel shall not divulge or release data or information developed or obtained in performance of this contract, until made public by the Government, except to authorized Government personnel or upon written approval of the Contracting Officer. The Contractor will not use, disclose, or reproduce proprietary data which bears a restrictive legend, other than as required in the performance of this contract. Nothing herein shall preclude the use of any data independently acquired by the Contractor without such limitations or prohibit an agreement at no costs to the Government between the Contractor and the data owner provides for greater rights to the Contractor.

mailto:bironjl@state.gov

H. Circuit Downtime and Credits

Credits shall be assessed against the Contractor in those instances where the circuit during any given month or year that fail to achieve and sustain the minimum acceptance standards stated above.

1. Definitions:

Circuit Availability Acceptance Level: Yearly Circuit Availability Acceptance Level is computed by 365 calendar days times 24 (hours per day) times 99.7% acceptance level equals

8,716.20 hours annum. (365 x 24 = 8760 x 99.7% = 8,733.72). Monthly Circuit Availability is computed by the calendar days per month times 24 (hours per day) times 99.7% acceptance level

(example: 31 x 24 = 744 x 99.7% = 741.76).

Downtime: That period of time when the circuit becomes non-operational or unusable for communication or transfer of data or failures to meet the minimum acceptance standards. The maximum cumulative Annual downtime that shall be acceptable for corrective or preventative maintenance is 26.28 hours (8760 x .3%). The maximum cumulative Monthly downtime that shall be acceptable for corrective or preventative maintenance shall be .3% of the total available hours for the month (example: 31 x 24 = 744 x .3% = 2.23 hours).

Period of Downtime: Downtime shall commence at the time first attempt for contact is made by the Government (or its representative) to the Contractor’s Point of Contact and shall be annotated on the Remedy Ticket and shall continue until the circuit is returned into Service by the Government.

Downtime Credits: Monetary value returned to the Government for failure to meet the

Circuit availability requirements. Downtime Credits shall be assessed based on cumulative downtime time with the minimum assessment being one hour. Downtime credit shall be equal to the hourly or daily rate (as applicable) as identified in the schedule in Section B. There are two

(2) situations when circuit Downtime Credits can be accumulated:

1) Below Availability Level,

2) Extended Downtime.

2. Credit for Circuit Downtime by Situation

Below Availability Level: If the downtime accumulated for a circuit adds up to 26.28

(8760 x 0.3%) cumulative hours or more during any one contract year (365 calendar days) or depending on the number of hours for the month (example 744 x .3%) cumulative hours per month (example: 31 calendar day month) the Contractor shall grant a hourly credit to the

Government for each hour of downtime. Each additional one hour increment or portion thereof will be assessed as an additional hour.

Extended Downtime Credit(s): Cumulative time of more than 18 hours but not greater than 24 hours for any one outage shall be assessed at a daily rate. Any increment of 24 hours beyond the initial 24 hours of any one outage shall be assessed at the standards for the hourly rate up to 12 hours, however between 12 and 24 hours the credit shall be assessed at the daily rate.

3. Exceptions to Cumulating of Downtime

Cumulating of circuit downtime shall include all unscheduled downtime deemed to be the responsibility of the Contractor, with the following exceptions:

a. When the failure to perform arises out of causes beyond the control and without the fault or negligence of the Contractor or Sub-contractor as defined in the Termination for Default clause in Section I of this contract.

b. Malfunction of equipment, frequency fading and interference, errors of commission and/or omission by the Contractor or Sub-contractor, and commercial power surges or failures are considered to be normal hazards of the industry and therefore do not qualify as causes beyond the control of the Contractor or Sub-contractor. The Contractor shall be charged with credits for all reported outages determined “no trouble found” or “came clear while testing” but which exceed 45 minutes.

The Contracting Officer shall make final determination as to whether downtime is the responsibility of the Contractor. If requested by the Contracting Officer, the Contractor shall provide documentation to support claims of excusable downtime. For downtime determined to be the Contractor’s responsibility, the Contracting Officer may elect to assess a credit for each instance of non-performance.

4. Payment Reduction for Downtime Credits

When Circuit Downtime credit(s) is owed to the Government, the total number of creditable hours shall be accumulated for the month and will be deducted from the payment due the Contractor in the month they accrued.

5. Trouble Escalation Procedure

a. The Government shall refer the problem to the carrier after performing tests as prescribed in the Trouble Analysis procedure. Obtain the name of the carrier test person and a carrier ticket number; record this information on the Government’s Remedy Ticket.

b. After the trouble has been referred to the carrier for two (2) hours, recall the carrier for an update on the current trouble. Record the carrier’s response, the name of the individual you talked with, and the carrier ticket number on the Remedy Ticket.

c. After the trouble has been referred to the carrier for four (4) hours, recall the carrier for an update on the current trouble. If the carrier’s response is not satisfactory escalate the trouble to the carrier’s management. Record the carrier’s response, the name of the individual you talked with, and the carrier ticket number on the Remedy Ticket.

d. After the trouble has been referred to the Contractor for six (6) hours the COR shall escalate the trouble to the Contractor’s manager; also notify IRM/IMO and the Contracting Officer and the STATE IRM/ISC Office. Record the contractor’s response, the name of the individual you talked with, the Contractor ticket number, and the names of the IRM managers that were notified on the Remedy Ticket.

e. Continue to status the Contractor for the remainder of the outage or until you have received a problem resolved status.

6. Technological Refreshment

After contract award, the Government may; pursuant to FAR clause 52.212-4 - Contract Terms and Conditions –Commercial Items, paragraph (c), Changes; request changes within the scope of the contract. These changes may be required to improve performance or react to changes in technology.

The Contractor may propose for the Government’s technological refreshment, substitutions or additions for any provided products or services that may become available as a result of technological improvements. The Government may, at any time during the term of this contract or any extensions thereof, modify the contract to acquire products which are similar to those under the contract and that the Contractor has, or has not, formally announced for marketing purposes. This action is considered to be within the scope of the contract. At the option of the

Government, a demonstration of the substitute product may be required. The Government is under no obligation to modify the contract in response to the proposed additions or substitutions.

Such substitutions or additions may include any part of, or all of, a given product(s) provided that the following conditions are met and substantiated by documentation in the technological refreshment proposal:

a. The proposed product(s) shall meet all of the technical specifications of this document and conform to the terms and conditions cited in the contract.

b. The proposed product(s) shall have the capacity, performance, or functional characteristics equal to or greater than, the current product(s).

c. The proposal shall discuss the impact on hardware, services, and delivery schedules. The cost of the changes not specifically addressed in the proposal shall be borne entirely by the

Contractor.

d. Contractor has the right to withdraw, in whole or in part, any technological refreshment proposal prior to acceptance by the Government. Contractor will use commercially reasonable efforts to ensure that prices for substitutions or additions are comparable to replaced or discontinued products. If a technological refreshment proposal is accepted and made a part of this contract, an equitable adjustment, increasing or decreasing the contract price, may be required and any other affected provisions of this contract shall be made in accordance with FAR clause 52.212-4, paragraph (c), Changes, and other applicable clauses of the contract.

7. QUALITY ASSURANCE AND SURVEILLANCE PLAN (QASP)

This plan provides an effective method to promote satisfactory contractor performance. The QASP provides a method for the Contracting Officer's Representative (COR) to monitor Contractor performance, advise the Contractor of unsatisfactory performance, and notify the Contracting Officer of continued unsatisfactory performance. The Contractor, not the

Government, is responsible for management and quality control to meet the terms of the contract.

The role of the Government is to monitor quality to ensure that contract standards are achieved.

Performance Objective Scope of Work Para Performance Threshold

Services.

Performs all internet services set forth in the scope of work.

1. thru 6.

All required services are performed and no more than one

(1) customer complaint is received per month.

ATTACHMENT #1 - CYBERSECURITY SUPPLY CHAIN RISK MANAGEMENT (C-

SCRM) SOFTWARE PRODUCER ATTESTATION FORM

CYBERSECURITY SUPPLY CHAIN RISK

MANAGEMENT (C-SCRM) QUESTIONNAIRE

SECTION 1 - CONTACT INFORMATION

ITEM NO. ITEM DESCRIPTION

VENDOR

RESPONSE

1.1 Enter the name of your company.

1.2

Enter the name of the primary Point-Of-Contact (POC) for your company that the Government may contact to discuss the vendor inputs on this questionnaire.

1.3 Enter the job title of the primary POC.

1.4 Enter the phone number of the primary POC in the following format: (555) 555-5555

1.5 Enter the e-mail address of the primary POC.

SECTION 2 VENDOR RISK MANAGEMENT PLAN

ITEM NO. ITEM DESCRIPTION

VENDOR

RESPONSE

NIST SP

800-53 Reference

2.1 Does your organization identify its key supply chain threats?

IR-8, SR-7

2.2 Does your organization map key suppliers to your supply chain threats?

IR-8, SR-7

2.3

Do you have a policy or process to ensure that none of your suppliers or third-party components have an active exclusion record in the System for Award Management (https://sam.gov)?

SAM.gov

2.4 Does your organization have written SCRM requirements in contracts with your key suppliers?

SA-4

2.5 Does your organization verify that your suppliers meet SCRM requirements through contractual terms and conditions?

SR-6

SECTION 3 PHYSICAL AND PERSONNEL SECURITY

ITEM NO. ITEM DESCRIPTION

VENDOR

RESPONSE

NIST SP

800-53 Reference

3.1 Does your organization have policies for conducting background checks of your employees as permitted by the country in which your organization operates?

PE-2, PE-3

PS-3

3.2

Does your organization have procedures in place to prevent tampering of Information and Communications Technology (ICT) equipment stored as supply chain inventory?

SR-9

AC-1

3.3 Do you provide literacy training on recognizing and reporting potential indicators of insider threat?

AT-2(2)

CYBERSECURITY SUPPLY CHAIN RISK

MANAGEMENT (C-SCRM) SOFTWARE PRODUCER

ATTESTATION FORM

This form must be completed by the software producer.

ITEM NUMBER ITEM DESCRIPTION VENDOR RESPONSE

1.1 Enter the name of the software producer.

1.2

Provide a statement attesting that the software products listed in Item Number 1.3 of this form follow the secure development "practices" and "tasks" identified in

NIST SP 800-218. A

summary of these practices and tasks are provided below for reference from NIST SP 800-218. If you cannot attest to all practices and tasks, identify the ones that you attest to and the ones that you cannot attest to. For those practices and tasks that you cannot attest to, describe the practices that you have in place to mitigate those risks (i.e., risks for practices or tasks you cannon attest to), and provide a Plan of Action & Milestones (POA&M) detailing how your firm will reach compliance for those non-compliant practices and tasks.

1.3

A description of which product or products the statement provided for Item Number 1.2 refers to (preferably focused at the company or product line level and inclusive of all unclassified products sold to Federal agencies).

NIST SP 800-218, Table 1: The Secure Software Development Framework (SSDF) Version 1.1 Practices Tasks Notional

Implementation Examples

References

Define Security Requirements for Software Development (PO.1): Ensure that security requirements for software development are known at all times so that they can be taken into account throughout the SDLC and duplication of effort can be minimized because the requirements information can be collected once and shared. This includes requirements from internal sources (e.g., the organization’s policies, business objectives, and risk management strategy) and external sources (e.g., applicable laws and regulations).

PO.1.1: Identify and document all security requirements for the organization’s software development infrastructures and processes, and maintain the requirements over time.

Example 1: Define policies for securing software development infrastructures and their components, including development endpoints, throughout the SDLC and maintaining that security.

BSAFSS: SM.3, DE.1,

IA.1, IA.2

Example 2: Define policies for securing software development processes throughout the SDLC and maintaining that security, including for open-source and other third-party software components utilized by software being developed.

BSIMM: CP1.1,

CP1.3, SR1.1, SR2.2,

SE1.2, SE2.6

Example 3: Review and update security requirements at least annually, or sooner if there are new requirements from internal or external sources, or a major security incident targeting software development infrastructure has occurred.

EO14028: 4e(ix)

Example 4: Educate affected individuals on impending changes to requirements.

IEC62443: SM-7, SM-

NISTCSF: ID.GV-3

OWASPASVS: 1.1.1

OWASPMASVS: 1.10

OWASPSAMM: PC1-

A, PC1-B, PC2-A

PCISSLC: 2.1, 2.2

SCFPSSD: Planning the Implementation and Deployment of Secure Development Practices

SP80053: SA-1, SA-8,

SA-15, SR-3

SP800160: 3.1.2,

3.2.1, 3.2.2, 3.3.1, 3.4.2, 3.4.3

SP800161: SA-1, SA-

8, SA-15, SR-3

SP800181: T0414;

K0003, K0039, K0044, K0157, K0168, K0177, K0211, K0260, K0261, K0262, K0524; S0010, S0357, S0368; A0033, A0123, A0151

PO.1.2: Identify and document all security requirements for organization-developed software to meet, and maintain the requirements over time.

Example 1: Define policies that specify risk-based software architecture and design requirements, such as making code modular to facilitate code reuse and updates; isolating security components from other components during execution; avoiding undocumented commands and settings; and providing features that will aid software acquirers with the secure deployment, operation, and maintenance of the software.

BSAFSS: SC.1-1,

SC.2, PD.1-1, PD.1-2,

PD.1-3, PD.2-2, SI,

PA, CS, AA, LO, EE

Example 2: Define policies that specify the security requirements for the organization’s software, and verify compliance at key points in the SDLC (e.g., classes of software flaws verified by gates, responses to vulnerabilities discovered in released software).

BSIMM: SM1.1,

SM1.4, SM2.2, CP1.1,

CP1.2, CP1.3, CP2.1,

CP2.3, AM1.2,

SFD1.1, SFD2.1,

SFD3.2, SR1.1,

SR1.3, SR2.2, SR3.3,

SR3.4

Example 3: Analyze the risk of applicable technology stacks (e.g., languages, environments, deployment models), and recommend or require the use of stacks that will

EO14028: 4e(ix) reduce risk compared to others.

Example 4: Define policies that specify what needs to be archived for each software release (e.g., code, package files, third-party libraries, documentation, data inventory) and how long it needs to be retained based on the SDLC model, software end-of-life, and other factors.

IEC62443: SR-3, SR-

4, SR-5, SD-4

Example 5: Ensure that policies cover the entire software life cycle, including notifying users of the impending end of software support and the date of software end-of-life.

ISO27034: 7.3.2

Example 6: Review all security requirements at least annually, or sooner if there are new requirements from internal or external sources, a major vulnerability is discovered in released software, or a major security incident targeting organization-developed software has occurred.

MSSDL: 2, 5

Example 7: Establish and follow processes for handling requirement exception requests, including periodic reviews of all approved exceptions.

NISTCSF: ID.GV-3

OWASPMASVS: 1.12

OWASPSAMM: PC1-

A, PC1-B, PC2-A,

PC3-A, SR1-A, SR1-

B, SR2-B, SA1-B, IR1-

A

PCISSLC: 2.1, 2.2,

2.3, 3.3

SCFPSSD: Establish Coding Standards and Conventions

SP80053: SA-8, SA-

8(3), SA-15, SR-3

SP800160: 3.1.2,

3.2.1, 3.3.1

SP800161: SA-8, SA-

15, SR-3

SP800181: T0414;

K0003, K0039, K0044, K0157, K0168, K0177, K0211, K0260, K0261, K0262, K0524; S0010, S0357, S0368; A0033, A0123, A0151

PO.1.3: Communicate requirements to all third parties who will provide commercial software components to the organization for reuse by the organization’s own software.

[Formerly PW.3.1]

Example 1: Define a core set of security requirements for software components, and include it in acquisition documents, software contracts, and other agreements with third parties.

BSAFSS: SM.1, SM.2,

SM.2-1, SM.2-4

Example 2: Define security-related criteria for selecting software; the criteria can include the third party’s vulnerability disclosure program and product security incident response capabilities or the third party’s adherence to organization-defined practices.

BSIMM: CP2.4,

CP3.2, SR2.5, SR3.2

Example 3: Require third parties to attest that their software complies with the organization’s security requirements.

EO14028: 4e(vi), 4e(ix)

Example 4: Require third parties to provide provenance data and integrity verification mechanisms for all components of their software.

IDASOAR: 19, 21

Example 5: Establish and follow processes to address risk when there are security requirements that third-party software

IEC62443: SM-9, SM-

components to be acquired do not meet; this should include periodic reviews of all approved exceptions to requirements.

MSSDL: 7

NISTCSF: ID.SC-3

OWASPSAMM: SR3-

A

SCAGILE: Tasks Requiring the Help of Security Experts 8

SCFPSSD: Manage Security Risk Inherent in the Use of Third- Party Components

SCSIC: Vendor Sourcing Integrity Controls

SP80053: SA-4, SA-9,

SA-10, SA-10(1), SA-

15, SR-3, SR-4, SR-5

SP800160: 3.1.1,

3.1.2

SP800161: SA-4, SA-

9, SA-9(1), SA-9(3),

SA-10, SA-10(1), SA-

15, SR-3, SR-4, SR-5

SP800181: T0203,

T0415; K0039; S0374;

A0056, A0161

Implement Roles and Responsibilities (PO.2):

Ensure that everyone inside and outside of the organization involved in the SDLC is prepared to perform their SDLC-related roles and responsibilities throughout the SDLC.

PO.2.1: Create new roles and alter responsibilities for existing roles as needed to encompass all parts of the SDLC. Periodically review and maintain the defined roles and responsibilities, updating them as needed.

Example 1: Define SDLC-related roles and responsibilities for all members of the software development team.

BSAFSS: PD.2-1,

PD.2-2

Example 2: Integrate the security roles into the software development team.

BSIMM: SM1.1,

SM2.3, SM2.7, CR1.7

Example 3: Define roles and responsibilities for cybersecurity staff, security champions, project managers and leads, senior management, software developers, software testers, software assurance leads and staff, product owners, operations and platform engineers, and others involved in the SDLC.

Example 4: Conduct an annual review of all roles and responsibilities.

IEC62443: SM-2, SM-

Example 5: Educate affected individuals on impending changes to roles and responsibilities, and confirm that the individuals understand the changes and agree to follow them.

NISTCSF: ID.AM-6,

ID.GV-2

Example 6:

Implement and use tools and processes to promote communication and engagement among individuals with SDLC-related roles and responsibilities, such as creating messaging channels for team discussions.

PCISSLC: 1.2

Example 7:

Designate a group of individuals or a team as the code owner for each project.

SCSIC: Vendor Software Development Integrity Controls

SP80053: SA-3

SP800160: 3.2.1,

3.2.4, 3.3.1

SP800161: SA-3

SP800181: K0233

PO.2.2: Provide role-based training for all personnel with responsibilities that contribute to secure development. Periodically review personnel proficiency and role-based training, and update the training as needed.

Example 1:

Document the desired outcomes of training for each role.

BSAFSS: PD.2-2

Example 2: Define the type of training or curriculum required to achieve the desired outcome for each role.

BSIMM: T1.1, T1.7,

T1.8, T2.5, T2.8, T2.9, T3.1, T3.2, T3.4

Example 3: Create a training plan for each role.

EO14028: 4e(ix)

Example 4: Acquire or create training for each role; acquired training may need to be customized for the organization.

IEC62443: SM-4

Example 5: Measure outcome performance to identify areas where

MSSDL: 1

changes to training may be…

This is the start of the file's text. The full file is on GovTribe.

File details come from the government source that posted it. Updated .