Amendment_4.docx
DOCX document 20 KB Posted
- Attached to
- Information Security Assessment Federal contract opportunity
- Solicitation number
- SP7000-14-Q-0002
- Issued by
- Defense Logistics Agency
About this file
Amendment 4
View the file
Other files for this federal contract opportunity
| File | Type | Posted |
|---|---|---|
| Amendment_5.docx | DOCX document | |
| Amendment_3.docx | DOCX document | |
| Amendment_1.docx | DOCX document | |
| RA_Instructions.pdf | ||
| PWS.pdf | ||
| SP700014Q0002.pdf |
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
The purpose of this amendment is to provide answers to questions from prospective offerors.
Question 1: What sort of environment will we be operating on to do our PT? Would the PT be a full PT or just a passive one? Will the IDS be told where the PT is coming from and ignore the attempts? Or will we be provided with a copy of production?
Answer 1: Production unclassified and in some instances classified networks. Typical network infrastructure devices such as firewalls, routers, switches, etc., are in place in addition to workstations (Windows) and servers (Windows, UNIX/Solaris/Flavor of UNIX intermixed). A full penetration test/vulnerability assessment. No special permissions or access (other than network access) will be granted for any given assessment. Additionally any defensive mechanism that is in place such as an IDS will not be aware of the testing that will occur.
Question 2: The PWS suggests that any testing is 'surface'. That is, it is OS, Network and DB Server only and does not delve into attempts to compromise the database server with SQL Injection or similar attacks? Is this correct or is the scope wider?
Answer 2: Compromise of assets is permitted if access is gained.
Question 3: Will we be provided with details on the number of servers, machines, types and so on ahead of time so that we can propose a level of effort that addresses the specific environment?
Answer 3: No. Each enclave is different and varies in size. The type of information requested can only be provided when a decision has been as to which network will be assessed.
Question 4: Will we be provided with network topology details or will we be expected to fully enumerate the front-end topologies based upon the systems to be vulnerability tested? What of the network infrastructure is under direct control or DoD-direct control, and will that organization be part of the memorandum which governs the VAA/PT process?
Answer 4: Network topologies will not be provided. However, the network range(s) for the network(s) that are in scope for a specific assessment will be provided and documented in the rules of engagement document prior to the commencement of an assessment. Networks to be assessment fall under the purview and control of the Defense Logistics Agency.
Question 5: Is there a preferred tool suite which is expected or is the VAA/PT team free to propose OS, network, and DB tools to ensure best-fit scanning?
Answer 5: No preferred tool suites. Tools will be discussed and agreed upon prior to any assessment.
Question 6: Building upon Question/Answer #6, it is apparent DLA wishes to have web application penetration testing (vulnerability assessment ) performed. How many websites and approximately how many pages per website would be included within the scope of work?
Answer 6: No two enclaves in DLA are the same. Some networks have web applications and some do not.
Question 7: Question/Answer #18 roughly speaks to the scope, but it is not enough to gauge the level of effort needed to determine the workforce required for the job. My questions are:
a. How many systems are required to be scanned? Hundreds? Thousands?
b. Approximately how many subnets need to be scanned?
c. Will firewall configurations need to be reviewed?
d. Is wireless discovery and vulnerability scanning required?
Answer 7:
a. Hundreds: Yes, some networks in DLA have less than 700 assets connected. Thousands: Yes, some networks in DLA have in excess of 1000 assets connected. However, the average network size for enclaves exceeding 1000 assets would be somewhere in the vicinity of 3,000 to 4,500 assets.
b. Varies, this is dependent upon the network that has been chosen to be assessed.
c. No
d. No
Question 8: Do you require the cost proposal be separate from the technical proposal?
Answer 8: No.
Question 9: In regard to to section 12.3. What other certification would be consider equivalent to a CEH. Is possible to waive this requirement based on contractor work experience, professional references and previous work? There is a statement in 13.1 of amendment 1, that says "The non-price factors that will be evaluated are Past Performance and Certifications. Past Performance is equal to Certifications." but I want to be sure I am interpreting to indicate that specific certification are not required if there is relevant prior work and experience.
Answer 9: GPEN. No
Question 10: Is "past performance" limited to government / public work (i.e. is private sector ok?)
Answer 10: No, past performance is not limited to government/public work.
Question 11: What is the expected amount of time the contractor should expect to be onsite in the Ohio facilities?
Answer 11: Please see the "Period of Performance" section of the PWS, paragraph 5.
Question 12: In particular, we want to know if we have to write anything in a technical proposal in addition to providing the past performances and copies of CEH certifications since it appears that no evaluation weight is given to anything other than past performance, certifications, and to some extent, descriptions of personnel skill sets.
Answer 12: It is the contractor’s discretion as to what additional information they choose to provide above and beyond what has been asked for in the solicitation.
File details come from the government source that posted it. Updated .