Amendment_3.docx

DOCX document 16 KB Posted

Attached to
Information Security Assessment Federal contract opportunity
Solicitation number
SP7000-14-Q-0002
Issued by
Defense Logistics Agency

About this file

Amendment 3.

View the file

Other files for this federal contract opportunity

Other files attached to Information Security Assessment, newest first.
File Type Posted
Amendment_5.docx DOCX document
Amendment_4.docx DOCX document
Amendment_1.docx DOCX document
RA_Instructions.pdf PDF
SP700014Q0002.pdf PDF
PWS.pdf PDF

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

The purpose of this amendment is to provide answers to questions from prospective offerors and to provide the date in which questions will no longer be accepted.

Question 1: In Section 5, "it is stated that the period of performance for each vulnerability assessment/penetration test shall be three weeks in duration per each assessment/penetration test. Not to exceed a maximum total of six weeks, on a per annum basis. The actual timeframe for each vulnerability assessment/penetration test will be determined at a later date and mutually agreed upon by the Government and contractor." Can Government provide an estimate of how many assessments are conducted / needed per year? For instance, are the assessments done monthly, quarterly, semi-annually or annually?

Answer 1: Please see the "Scope" section of the PWS, paragraph 3.

Question 2: Section 7. mentions "Secret, and TS/SCI clearances may be required on a case by case basis". Can Government clarify if the type of clearance needed is dependent on the DLA enclave worked is performed at and / or systems assessed?

Answer 2: Dependent upon the enclave assessed. Currently there are no networks in DLA that are classified above the SECRET level.

Question 3: As a follow-up clarification to Question 18, we would like to know:

i. If "Windows with some Solaris/UNIX/flavors of UNIX Intermixed" systems are desktops or servers? If servers, what applications (COTS or GOTS) and databases are run on them?

ii. Can Government provide number of systems (desktops, servers, databases, applications, web servers, network technology components) that CND expects to be assessed as part of this PWS?

Answer 3:

(i) - The majority of the enclaves in DLA have both desktops and servers connected. No two networks are identical. Dependent upon the mission supported by the local enclave the applications supported and databases in use will vary.

(ii) - As stated above no two local area networks are the same. Dependent upon the mission supported the network can vary in size, e.g., anywhere from 500 nodes connected to upwards to over 4,000 nodes connected (be mindful the numbers provided are estimates)

Question 4: As a follow-up clarification to Question 8, which indicates ". Based on known requirements a minimum of three people would be required with reach back capability to the selected contractor ...", can government specify any additional qualification expectations regarding these personnel in addition to CEH certification requirements, and skills mentioned in Section 12.1 "Contractor Capability"? For instance, does one of the personnel need to be IAM or IAO or their equivalent?

Answer 4: IAO, IAM or equivalent not required.

Question 5: Section 13.2.2 NON-PRICE PROPOSAL in the amendment talked about needing a valid/current certificate of successful completion of Certified Ethical Hacker (CEH) or an equivalent course. Can Government:

i. Comment whether they will be willing to allow completion of CEH certification within 180 days of contract award?

ii. Comment on what they will consider as other possible equivalents to CEH?

Answer 5:

(i) - CEH is required at contract award

(ii) - GPEN The period in which questions will be received ends 29 October 2013 at 16:00 hours ET.

File details come from the government source that posted it. Updated .