PWS.pdf

PDF 31 KB Posted

Attached to
Information Security Assessment Federal contract opportunity
Solicitation number
SP7000-14-Q-0002
Issued by
Defense Logistics Agency

About this file

Performance Work Statement

View the file

Other files for this federal contract opportunity

Other files attached to Information Security Assessment, newest first.
File Type Posted
Amendment_5.docx DOCX document
Amendment_4.docx DOCX document
Amendment_3.docx DOCX document
Amendment_1.docx DOCX document
SP700014Q0002.pdf PDF
RA_Instructions.pdf PDF

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

DEFENSE LOGISTICS AGENCY INFORMATION SECURITY ASSESSMENT

PERFORMANCE WORK STATEMENT

1. BACKGROUND

The Department of Defense (DOD) depends on interconnected information systems and communications networks, including Defense Logistics Agency (DLA) systems and networks, for critical combat and business operations. Many of these systems and networks are interconnected through the public telecommunications infrastructure, including the Internet, and they are being targeted by an increasing variety of cyber attacks. If successful, these attacks could result in the loss or corruption of critical data, damage to information systems, or disruption of military operations, both day-to-day operations and operations in times of crisis. According to DOD officials, thousands of potential cyber attacks are launched against DOD systems and networks each day, though very few are successful in accessing computer and information resources.

Like other DOD organizations, the DLA relies on a range of incident response activities to safeguard systems, networks, and information from attack. These activities involve the use of various computer security tools and techniques as well as the support of systems and technical specialists. Incident response activities can be grouped into four broad categories:

• Preventive activities

• Detection activities

• Investigative and diagnostic activities

• Event handling and response activities

Preventive activities are aimed at stopping cyber attacks or minimizing the likelihood that attacks will be successful in penetrating systems or networks through exploiting known vulnerabilities.

Preventive activities include (1) vulnerability assessments of the security of DOD systems and networks, (2) using technical experts to try to surreptitiously gain access to systems and networks, thus exposing security weaknesses before adversaries can exploit them, and (3) alerting system administrators to identified vulnerabilities.

At present, DLA's computer network defense activities do not include use of an outside entity to perform independent activities that focus on identifying network and system vulnerabilities in order to improve Computer Network Defense (CND) readiness. Additionally, DLA’s computer network defense activities do not include a means to measure the effectiveness of its Computer Network Defense Service Provider (CNDSP) and how well the various layers of CND coordinate to detect and respond to unauthorized activity.

The Defense Logistics Agency (DLA) has an immediate need to procure Vulnerability Analysis and Assessment (VAA) services in accordance with DoDI 6510.01. The DLA Computer Emergency Response Team (DLA CERT) is the Computer Network Defense Service Provider (CNDSP) for the Defense Logistics Agency. In addition to incident response DLA CERT performs other cyber security related activities in support of the DLA Information Assurance Program.

2. OBJECTIVES

This Performance Work Statement (PWS) requires contractor personnel to be highly knowledgeable and skilled in computer and network technology, network protocols and communications, firewalls, intrusion detection devices, and information systems security. The Contractor will utilize their knowledge, skills and abilities in conjunction with best practices to assess infrastructure, networks and information systems through the use of assessment tools and assessment techniques.

The primary objectives of this PWS are to:

• Identify vulnerabilities that could jeopardize operations and sensitive information

• Gauge CND operational readiness of the CNDSP and the networks that sustain operations

• Gauge effectiveness of current security policies and practices

3. SCOPE

The DLA IA Program is responsible for establishing and maintaining an effective IA operational environment that is based on guidance set forth in DOD and DLA policy, directives, regulations, and instructions. As the operational arm of the DLA IA Program, DLA CERT performs computer network defense services for DLA and its Tier 3 organizations that include, but not limited to, evaluating projects, programs, and enclaves for system vulnerabilities in the areas of information warfare, information assurance, and information surety.

The contractor will perform two vulnerability assessments/penetration tests annually for DLA.

One against the CNDSP’s local area network/infrastructure which will include the CNDSP’s gateway and one other DLA enclave to be selected and identified on an annual basis. To ensure a clear understanding of the activities that will be performed during the vulnerability assessment/penetration test a Rules of Engagement (RoE) document will be drafted and agreed to by all concerned parties prior to commencement of the aforementioned activity.

4. SPECIFIC TASKS

The contractor(s) shall be responsible for providing qualified personnel to perform the following tasks as directed by the DLA Computer Network Defense Lead.

Task 1 –Provide assessment and remediation recommendations of infrastructure, networks and information systems

The contractor will conduct a vulnerability assessment/penetration test of the targeted environment using commercially available tools or customized assessment products. The vulnerability assessment/penetration test shall be performed from an internet based attacker’s point of view as well as from the perspective of an attacker with access to the internal network.

Deliverable: Executive level briefing to be given at conclusion of on-site assessment

Deliverable: Executive Summary Report to be delivered within five (5) days of return from on-site assessment

Deliverable: Detail Finding Report to include remediation recommendations to be delivered within fifteen (15) days of return from on-site assessment

5. PERIOD OF PERFORMANCE

The period of performance for the PWS will be December 1, 2013 through November 30, 2014 with two (2) one (1) year options. The period of performance for each vulnerability assessment/penetration test shall be three weeks in duration per each assessment/penetration test.

Not to exceed a maximum total of six weeks, on a per annum basis. The actual timeframe for each vulnerability assessment/penetration test will be determined at a later date and mutually agreed upon by the Government and contractor.

6. PLACE AND TIME OF PERFORMANCE

Functions to be performed under this PWS will be conducted from the contractor’s facility, at the CNDSP’s location in Columbus, Ohio (Defense Supply Center Columbus, Network Operations Security Center) and, at the third DLA enclave to be determined and identified on an annual basis.

7. SECURITY

The work to be performed under this PWS will be conducted primarily in an unclassified environment. However, Secret, and TS/SCI clearances may be required on a case by case basis.

The Contractor shall comply with all DLA security requirements pursuant to DLA Regulation 5200.17, Security Requirements for Automated Information and Telecommunications Systems;

DOD 5220.22-M National Industrial Security Program; DOD 5200.28 Department of Defense Trusted Computer System Evaluation Criteria; DOD 5200.2R Personnel Security Program:

DLAR 5200.11 DLA Personnel Security Program.

The Contractor shall provide a list of all personnel (name, social security number, date and place of birth and IT Level) assigned to this effort. This list of personnel will be provided to the COR within three calendar days after award.

Program and system security, Computer Security (COMPUSEC), Communications Security (COMSEC), Compromising Emanations (TEMPEST), Operating Security (OPSEC) shall be considered and followed where applicable in the performance of the tasks. The Contractor shall follow public law, established Government regulations, and DOD procedures regarding protection of privacy information.

8. GOVERNMENT FURNISHED EQUIPMENT (GFE)

In support of this work, the government will provide the Contractor with:

• Office space, furniture for Contractor personnel to use while on-site in DLA Facilities

• All required policy and procedural documentation

9. PACKAGING, PACKING, AND SHIPPING INSTRUCTIONS

Documents shall be provided in only electronic format. Electronic formats must be Microsoft Office or Portable Document Format (PDF). Electronic copies of all deliverables will be provided to the COTR.

10. INSPECTION AND ACCEPTANCE CRITERIA

The Government will have fifteen (15) working days following delivery to review and accept or reject each deliverable. If the Government does not notify the Contractor of rejection of a deliverable within the specified time the Contractor may assume the deliverable has been accepted. In the event that a deliverable is rejected, the Contractor shall have fifteen (15) working days to correct the problem(s) to the Government's satisfaction.

11. ACCOUNTING AND APPROPRIATION DATA

An invoice is the Contractor's bill or written request for payment under the contract for supplies delivered or services performed. An invoice shall be prepared and submitted to the designated billing officer specified in the contract. The Contractor will be notified of any invoice defects within 7 days of receipt of the invoice at the designated billing office.

Invoices shall be sent to the Contracting Officer's Technical Representative (COTR) listed below for certification. Upon certification by the COTR, the invoice will be forwarded to the COR, who will forward the certified invoice to the payment office as stated on the contract.

12. OTHER PERTINENT INFORMATION OR SPECIAL CONSIDERATIONS

12.1 CONTRACTOR CAPABILITY

The contractor must provide personnel with experience to accomplish the tasks specified in this Performance Work Statement. The individuals must understand computer and network technology, network protocols and communications, and information systems security. The contractor personnel must possess the knowledge associated with:

1) Network vulnerabilities and exploitation techniques

2) Web application security and exploitation

3) Network protocols and vulnerabilities

12.2 PROTECTION OF DATA/NON-DISCLOSURE

Any vulnerabilities/findings identified and documented within the scope of the DLA IA Program, shall be encrypted in transmission and in its storage medium. DLA shall provide the contractor the necessary capability to encrypt and communicate securely. The contractor shall be obligated to abide by U.S. encryption export control laws. Contractor personnel are required to sign a non-disclosure agreement.

12.3 PROFESSIONAL TRAINING AND CERTIFICATION

Technical contractor personnel assigned to this contract should possess a Certified Ethical Hacker (CEH) certification or equivalent.

12.4 TRAVEL

Government has estimated travel dollars to support the tasks identified in this PSE. Travel expenses for contractor personnel will include airfare, hotel, M&I. Travel costs will be reimbursed in accordance with Joint Federal Travel Regulations.

File details come from the government source that posted it. Updated .