USAGM-Zero Trust Architecture (ZTA) Services Solicitation.pdf
PDF 498 KB Posted
- Attached to
- Zero Trust Architecture Services Federal contract opportunity
- Solicitation number
- 951700-23-R-0018
- Issued by
- US Agency for Global Media
About this file
This solicitation requests proposals for zero trust architecture services. Offerors must provide pricing in an attached spreadsheet by August 11, 2023. The U.S. Agency for Global Media seeks a contractor to assist in transitioning the agency to a zero trust architecture in compliance with NIST and OMB guidance. The contractor will identify tools, conduct assessments, develop implementation plans, and prototype solutions across identity, device, network, application, data, governance, visibility and analytics domains. The contractor must demonstrate experience integrating various zero trust tools and implementing capabilities across multiple domains. The technical proposal is limited to 10 pages and past performance to 5 pages, with price submitted separately.
View the file
Other files for this federal contract opportunity
| File | Type | Posted |
|---|---|---|
| SF 1449 RFP 951700-23-R-0018.pdf | ||
| ZTA Pricing Spreadsheet v4.xlsx | XLSX spreadsheet | |
| SF 30 RFP 951700-23-R-0018 A04.pdf | ||
| SF 1449 RFP 951700-23-R-0018.pdf | ||
| USAGM-Zero Trust Architecture (ZTA) Services Solicitation Final (Aug 2023).pdf | ||
| RFP 951700-23-R-0018 A03.pdf | ||
| USAGM-Zero Trust Architecture (ZTA) Services Solicitation 7-10-2023.pdf | ||
| SF 30 RFP 951700-23-R-0018 A02.pdf | ||
| ZTA Pricing Spreadsheet v3.xlsx | XLSX spreadsheet | |
| SF 1449 RFP 951700-23-R-0018.pdf | ||
| SF 30 RFP 951700-23-R-0018 A01.pdf | ||
| RFP 951700-23-R-0018.pdf | ||
| ZTA Pricing.xlsx | XLSX spreadsheet |
Show all 13
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
US Agency for Global Media
Solicitation for
Zero Trust Architecture Services
July 2023
Source-Selection-Sensitive Page 2 of 51 For Official Use Only
A Solicitation/Contract Form
SF 1449 RFP
951700-23-R-0018.pd
Source-Selection-Sensitive Page 3 of 51
B Supplies or Services and Prices/Costs
B.1 Pricing Spreadsheet
The Contractor shall enter prices using the Pricing spreadsheet provided in Section J.1 of this solicitation.
Source-Selection-Sensitive Page 4 of 51
C Description/Specifications/Statement of Work.
1. BACKGROUND
The U.S. Agency for Global Media (USAGM), Office of the CIO, strives to provide high quality, effective, and efficient Information Technology (IT) services to offices within the agency. Executive Order 14028 requires Federal Agencies to enhance their cybersecurity and reinforce defenses against increased threats to technology infrastructure with the implementation of an environment based on zero trust principles.
With this as a background, USAGM has initiated a Zero Trust Architecture (ZTA) Program, which will oversee all aspects of transitioning the agency to a Zero Trust approach, as described in NIST SP 800-207. To do this, USAGM is looking for a Contractor that has the knowledge and experience to help us on the journey to architect an infrastructure that meets the requirements for an architecture that is based on zero trust principles and designed to prevent data breaches and limit internal lateral movement.
The foundational tenet of the Zero Trust Model is that no actor, system, network, or service operating outside or within the security perimeter is trusted. Instead, every attempt at access, change of authorization, and connection must be verified. It is a paradigm shift of how USAGM secures its infrastructure, networks, and data, from Implicit Trust granted at the perimeter to Zero Trust with continual verification of each user, device, application, and transaction. ZTA is an enterprise cybersecurity architecture that incorporates Zero Trust concepts that are focused on component relationships, workflow planning, and access policies.
USAGM faces an increasing number of users who are permanently working outside the protections of network security appliances at the USAGM boundary. Therefore, the switch to ZTA is timely because we have a new requirement to ensure the security of both the internal and external users who utilize the USAGM Information Systems.
However, the mission of USAGM is to broadcast news to many countries in many languages, and many of our broadcasting systems are legacy systems that were not designed to manage modern day security threats. These systems provide unique challenges in a move to a ZTA, and internal network isolation will remain important for USAGM moving forward.
Currently USAGM utilizes Azure Active Directory (AAD) as its principal Single Sign On (SSO) and identity management solution. While the push to integrate all Agency applications to SSO or transition them to Passwordless or PIV operation has been ongoing, at this point there are still several systems/applications that are not part of this more secure technology. USAGM envisions that the current AAD implementation can be modernized and paired with other Identity Governance tools to give the USAGM a true zero trust enterprise Identity solution.
USAGM has also recently deployed a new IT Service Management, IT Asset Management solution (ITSM/ITAM) from Ivanti. USAGM envisions that the vendor will build ZTA Device Governance principles and policy on this foundation.
Source-Selection-Sensitive Page 5 of 51
USAGM has started a broader Agency WAN transition to Software Defined Wide Area Network (SD WAN) technology from Multiprotocol Label Switching (MPLS) based on CISCO technology. We are envisioning that as part of our ZTA transition, our SD WAN technology can be paired with different security technologies, such as Secure Access Service Edge (SASE), to give the USAGM a true zero trust network based on the user’s identity, location, or device and access permissions. Containerized application security stacks augment SASE solutions to achieve enhanced conditional access and implement data centric security protections.
While the current USAGM OCIO projects underway will raise USAGM’s ZTA Maturity, USAGM envisions that the selected vendor from this RFP will tie together all ZTA efforts, guide USAGM in the selection of gap filling ZTA tools and perform the implementation of these tools as detailed in the Scope of work section. It is envisioned this contract will bring USAGM to a fully optimized state across all ZTA domains based on the CISA Maturity Model.
2. APPLICABLE DOCUMENTS
The Contractor shall comply with the following documents in the performance of this effort:
1. Executive Order 14028, Improving the Nation’s Cybersecurity
2. Office of Management and Budget (OMB) M-22-09, Federal Zero Trust Strategy
3. National Institute of Standards and Technology (NIST) Special Publication (SP) 800-207, Zero Trust Architecture
4. Zero Trust Maturity Model Version 2.0 (cisa.gov) Department of Defense (DoD) Zero Trust
Maturity Model
3. SCOPE OF WORK
With this RFP, USAGM is looking for a System Integrator that can move the agency to an Optimal maturity level in most aspects of the domain areas. The Contractor shall assist and enable USAGM to comply with OMB M-22-09, Federal Zero Trust Strategy, Executive Order 14028, Improving the Nation’s Cybersecurity, NIST SP 800-207, ZTA, and subsequent OMB Memos, Directives, Policies, and Guidance on implementing the tenants and capabilities of Zero Trust.
Currently USAGM is performing a ZTA assessment and will create a roadmap for implementation. Building upon this effort, the Contractor shall identify the best practice solutions for the Identity, Devices, Networks, Applications, and Data pillars, as well as establish governance processes that will avoid organizational silos and reduce duplication of effort. The selected solutions shall include Visibility and Analytics as well as Orchestration and Automation pillars, which were identified since the original ZTA guidance was released. The Contractor shall develop implementation/engineering plans for use cases across all Zero Trust pillars.
Once the Contractor has completed the identification of best practice solutions and after approval by USAGM, the Contractor shall update the USAGM ZTA roadmap and prepare to prototype the ZTA tools and processes. USAGM intends to prototype all https://www.nist.gov/itl/executive-order-14028-improving-nations-cybersecurity https://www.google.com/url?sa=t&rct=j&q=&esrc=s&source=web&cd=&cad=rja&uact=8&ved=2ahUKEwjagPvCjOH9AhVrnGoFHQHeBjsQFnoECAgQAQ&url=https%3A%2F%2Fwww.whitehouse.gov%2Fwp-content%2Fuploads%2F2022%2F01%2FM-22-09.pdf&usg=AOvVaw2rR4qQSBucQCCfjP5Nclu8 https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-207.pdf https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-207.pdf https://www.cisa.gov/sites/default/files/2023-04/zero_trust_maturity_model_v2_508.pdf https://dodcio.defense.gov/Portals/0/Documents/Library/(U)ZT_RA_v2.0(U)_Sep22.pdf https://dodcio.defense.gov/Portals/0/Documents/Library/(U)ZT_RA_v2.0(U)_Sep22.pdf
Source-Selection-Sensitive Page 6 of 51 recommended tools and processes throughout the execution of this contract, leveraging commercial best practices where applicable.
The Contractor shall procure and install the tools/systems/capabilities needed for the prototypes on the USAGM Information Systems, including but not limited to tools for Identity Management, Governance, Role Based Access Control (RBAC), and Privileged Access Management (PAM). Also required will be zero trust SASE capability, integrated software defined (SD) Wide Area Network (WAN) technology, Customer Edge Security Stacks, and Application Security Stacks. Initial procurement for the licensing of the prototype is part of this contract.
Once a prototype effort is completed successfully, the Contractor will provide results and a recommendation for the tool. USAGM will then buy the recommended tool and the licenses for all end users and the Contractor will implement the selected tool.
For any installation in the USAGM environment, the Contractor will follow the USAGM Change Management process, including creating a Change Request (CR) and supporting the Program Manager during the presentation to the Change Advisory Board
(CAB).
The Contractor shall provide direct support to the USAGM ZTA Program Manager and work with tool vendors and the ZTA Pillar Leads to implement the new capabilities in the USAGM operational environment, starting with USAGM’s most critical information systems, while minimizing disruption to move USAGM’s assessed implementation from Traditional to Advanced, then to Optimal capabilities per OMB, CISA directives, and DoD guidance.
The Contractor shall support the governance pillar in creating, implementing, and providing support for the necessary requirements and outcomes of the ZTA assessment and above-mentioned mandates.
Throughout this process, the Contractor shall provide all necessary training to USAGM staff in the use of the tools. The staff will consist of members of the IT team, including Global Networks, Network Control Center, Enterprise Platforms and Storage, Information Security Management, Enterprise Applications, Computer Systems Support, and Enterprise Telecommunications.
It is of upmost importance to gain user acceptance of the changes that will have to occur to succeed, which means that the Contractor will support Organizational Change Management (OCM) efforts to drive user adoption.
3.1 USAGM Environment
USAGM has six entities: Voice of America (VOA), Office of Cuba Broadcasting (OCB), Radio Free Europe/Radio Liberty (RFERL), Radio Free Asia (RFA), Middle East Broadcasting Networks, Inc. (MBN), and the Open Technology Fund (OTF). USAGM manages the infrastructure and many of the systems, but each entity has some systems that USAGM does not control. During the course of the contract, the Contractor will provide options for segmentation and micro segmentation of these systems.
Source-Selection-Sensitive Page 7 of 51
3.1.1 Users
The six entities have approximately 3,500 end users and 10,000 end points. Users are mainly located in the Washington, DC area, but USAGM operates about 12 transmitting facilities, which are mostly (most overseas) and approximately 24 overseas news bureaus, which creates some unique challenges.
3.1.2 Systems
The USAGM infrastructure is a mix of on premises, cloud, single instance cloud, legacy, and business partnered systems. Many of the legacy systems used by broadcasters were not designed for modern security threats, and some of them cannot be secured as needed. These types of systems must be segmented to ensure the security of all other systems.
4. PROJECT MANAGEMENT
4.1 CONTRACTOR PROJECT MANAGEMENT PLAN
The Contractor shall deliver a Contractor Project Management Plan (CPMP) that lays out the Contractor’s approach, timeline, and tools to be used in execution of this contract. The CPMP should take the form of both a narrative and graphic format that displays the schedule, milestones, risks, and resource support. The CPMP shall also include how the Contractor will coordinate and execute planned, routine, and ad hoc data collection reporting requests as identified within the Statement of Work. The initial baseline CPMP shall be concurred upon and approved by the USAGM Program Manager (PM). The Contractor shall update and maintain the USAGM PM approved CPMP throughout the Period of Performance (PoP).
The Contractor shall, as part of the CPMP, implement a process so that every deliverable has a timeline for the Government to review and provide feedback to the Contractor to ensure the deliverables meet the expected and intended quality of the contract.
Deliverable:
A. Contractor Project Management Plan (within 15 calendar days of contract award) B. Project Management Documents
4.2 CONTRACTOR SCHEDULE
The Contractor shall create a Contractor Project Schedule that meets the requirements of the USAGM project schedule, which is based on the GSA Technology Modernization Fund (TMF) submission.
A. Contractor Project Management Plan (draft within 15 calendar days of contract award, first baseline within 30 calendar days of contract award)
4.3 RISK MANAGEMENT PLAN
The Contractor shall provide a Risk Management Plan that outlines how the Contractor will identify potential risks to the project, estimate the impact and probability of
Source-Selection-Sensitive Page 8 of 51 occurrences, as well as define responses, resource and timeline impact, escalation, and reporting to Government.
A. Risk Management Plan (within 30 calendar days of contract award)
4.4 REPORTING REQUIREMENTS
In addition to the quarterly Contractor’s Progress, Status, and Management Report at the basic contract level, the Contractor shall attend a weekly teleconference meeting with the USAGM OCIO staff to discuss and document any issues, pending deliverables, or other pertinent topics concerning the task areas. The Contractor shall also schedule and coordinate a Weekly Status Meeting to review the status of each task, provide recommendations on next steps, and alert USAGM of any risks, impediments, or urgent issues that arise, along with suggested mitigation actions. During the Weekly Status Meetings, the Contractor shall create meeting minutes utilizing the OneNote function in Microsoft Project Online. The Contractor shall ensure the minutes contain notes on all significant discussions. The Weekly Status Meeting will include a quadrant (quad) chart in Microsoft PowerPoint format that describes (1) recent accomplishments, (2) planned activities, (3) a timeline of upcoming milestones and deliverables for the next quarter and updates on a rolling basis, and (4) risks and suggested mitigation actions. The Government PM will provide the Contractor a template of the quad chart after award.
The Contractor shall keep in communication with the Program Manager of the ZTA Program, so that as issues arise, they are articulated to the respective parties to prevent escalation of outstanding issues.
The Contractor shall utilize the Microsoft SharePoint repository that is created through Microsoft Project Online, which will be provided by OCIO to support the monitoring and management for this ZTA Program. The repository shall be the main location where all documentation related to this program is kept, including copies of deliverables as well as formal and informal work products.
The Contractor shall provide a Monthly Progress Report in electronic form in Microsoft Word and Project formats. The report shall reflect information as of the last day of the preceding month. The Monthly Progress Reports shall cover all work completed during the reporting period and work planned for the subsequent reporting period. The Monthly Progress Report shall also identify any problems that arose and their resolution as well as potential risks and suggested mitigations. If problems have not been completely resolved, the Contractor shall provide an explanation, including its plan and timeframe for resolving the issue. The Monthly Progress Report shall also include an itemized list of all Electronic and Information Technology deliverables. The Contractor shall monitor performance against the CPMP and the Project Schedule and report any deviations.
Deliverables:
A. Weekly Meeting Minutes and Quad Chart (Weekly, Ongoing) B. PMR Status Reports (Weekly Ongoing) C. Monthly Progress Report (Monthly Ongoing)
Source-Selection-Sensitive Page 9 of 51
4.5 TECHNICAL KICKOFF MEETING
A technical kickoff meeting including the Contractor and USAGM personnel will be held within 10 calendar days after the contract award. The Contractor shall coordinate the date, time, and location (can be virtual) with the Contracting Officer (CO), the USAGM PM, the Contract Specialist (CS), and the COR. The Contractor shall provide a draft agenda to the CO and USAGM PM at least five (5) calendar days prior to the meeting.
Upon Government approval of a final agenda, the Contractor shall distribute to all meeting attendees. During the kickoff meeting, the Contractor shall present, for review and approval by the Government, the details of its intended approach, work plan, and project schedule for each effort via a Microsoft Office PowerPoint presentation. At the conclusion of the meeting, the Contractor shall update the presentation with a final slide entitled “Summary Report,” which shall include notes on any significant issues, agreements, or disagreements discussed during the kickoff meeting. The Contractor shall submit the final updated presentation to the CO for review within three (3) calendar days after the meeting.
A. Kickoff Meeting (within 10 calendar days after contract award)
4.6 ONBOARDING AND OFFBOARDING
The Contractor shall manage the onboarding of its personnel under this contract.
Onboarding includes steps to obtain a USAGM Personal Identity Verification (PIV) card, network, and email account, complete USAGM mandatory training for Contractors, initiate background investigations, and gain physical and logical access. In addition, the Contractor shall identify individuals who may require elevated privileges, if appropriate.
A Contract Lead (single Contractor Onboarding Point of Contact (POC)) shall be designated by the Contractor that performs onboarding/offboarding activities and tracks the onboarding status of all Contractor personnel. The Contractor Onboarding POC shall be responsible for accurate and timely submission of all required USAGM onboarding paperwork to the USAGM COR. The Contractor Onboarding POC shall be responsible for tracking the status of all its personnel’s onboarding activities to include the names of all personnel engaged on the task, their initial training date for USAGM Privacy and Information Security training, and their next required training date. The Contractor Onboarding POC shall also report the status of the personnel level in the Weekly Meeting Minutes.
The Contractor shall manage the offboarding process for USAGM access and individual system/environment access for all Contractor personnel. Personnel The Contractor shall prepare all forms necessary for termination of access to USAGM information systems, in accordance with USAGM guidance. The Contractor shall assist in confirming whether the GFE equipment, associated documentation, and PIV card have been returned to the proper receiving authorities in accordance with USAGM policy.
Deliverable:
A. On/Off-boarding Monthly Status Report (monthly ongoing)
Source-Selection-Sensitive Page 10 of 51
4.7 CONTRACTOR TRAINING
The Contractor shall submit the completed Training Certificates for USAGM Privacy and Information Security Awareness, and signed copies of the Rules of Behavior provided with the Information Security Assessment training. The Contractor shall provide newly obtained certificates as part of the Weekly Status Report.
Deliverable:
A. Security Training Certificates and Signed Rules of Behavior (within 7 calendar days of system access for all Contractor personnel.).
5. ZERO TRUST PROGRAM MANAGEMENT SUPPORT
The Contractor shall provide the Zero Trust Program support for Zero Trust initiatives, Zero Trust related operational directives, and Executive Orders, working across all USAGM OCIO Service Lines and ZTA Pillar Teams. The Contractor shall assist the Government PM in scoping, preparation, assessing, risk management, and consulting on best practices.
The Contractor shall create a ZTA Communication Plan to account for the ZTA activities as they evolve. This shall include a detailed plan for Organizational Change Management (OCM). The Contractor shall support the ZTA Program Manager with the execution of the plan. Zero Trust will create a lot of change within USAGM, and it will be important to manage this change proactively.
The Contractor shall assess, evaluate, and make recommended changes to modify the existing ZTA Roadmap, and produce other Standard Operating Procedures (SOP) related to Zero Trust implementation at USAGM. These documents will also provide an overarching implementation plan to address USAGM Strategy in accordance with the guidance/directives mentioned previously. The Contractor shall assist in answering ZTA and EO 14028 data calls, updating ZTA related dashboards and trackers, and produce other ZTA metric support as needed.
The Contractor shall create, manage, and update a ZTA dashboard that will contain information on all tasks related to EO 14028, OMB M-22-09 and subsequent and forthcoming mandates and Binding Operational Directives (BODs), as well as work related to all areas of the contract. The Contractor shall provide weekly updates to the dashboard and produce any ad hoc views required by the USAGM PM.
Deliverables:
A. ZTA Communication Plan B. ZTA Concept of Operations C. ZTA Standard Operating Procedures D. ZTA Dashboard Updates
5.1 ONGOING ZERO TRUST MATURITY ASSESSMENT
The Contractor shall conduct an ongoing monthly Zero Trust assessment of USAGM against the CISA Zero Trust Maturity Model. The assessment shall be updated monthly based on USAGM’s progress against implementing Zero Trust capabilities and the
Source-Selection-Sensitive Page 11 of 51 changing requirements as they emerge from DHS, OMB, CISA, BOD, and NIST directives, as well as modern technology and systems deployed at USAGM. The Contractor shall produce a Monthly Maturity Scorecard using the assessment created by USAGM in 2023 as a baseline. If the Contractor identifies changes to the existing assessment, these changes may be incorporated into the baseline. The Maturity Scorecard shall outline, by pillar, the percentage achieved in each pillars’ capabilities that are at least traditional, advanced, or optimal as well as highlighting targeted areas for improvement that are a priority or dependency.
The Contractor shall produce a PowerBI or equivalent Maturity Dashboard for the Monthly Maturity Scorecard. At the PM’s direction, the Contractor may use the using the assessment created by USAGM in 2023 as a baseline. If the Contractor identifies changes to the existing assessment, these changes may be incorporated into the baseline. The dashboard shall have tables showing each pillars’ capability grouping measurements with drilldowns or popups where the user can understand which capabilities are in place, partially in place, and not in place. The Contractor shall work with the PM on building the initial dashboard and updating the data from the Monthly Maturity Scorecard and underlying data.
The Contractor shall produce a Quarterly Maturity Detailed Report based upon the assessment results that will cover the assessment approach using the CISA Maturity Model. The Contractor shall provide an Assessment Summary and detail any capability challenges in or across the pillars with recommended next steps and actions to achieve greater maturity. The Contractor shall also produce a Gap Analysis and a ZTA Roadmap Capability Weighted Prioritization to target ZTA with overall recommendations. The Quarterly Maturity Detailed Report shall also include a complete breakdown by pillar and capability with measurements taken and scoring assigned with traceability to the overall percentage.
Deliverables in this section shall have the required granularity to understand what the maturity measure is, how USAGM is complying with the measures and what USAGM needs to do to bring the capability to Advanced and Optimal. Additionally, each measure shall provide direct reference back to the applicable Maturity Model (CISA, DoD) elements as well as USAGM Strategic Goal mappings.
The Contractor shall produce, as part of the ZTA Roadmap, a Capability Weighted Prioritization that considers the threat risk factors outlined in NIST SP 800-207, dependency of capability, and contributory value towards USAGM Zero Trust Strategy to inform the PM, and USAGM OCIO Leadership as to the next steps in the Zero Trust journey.
Deliverables:
A. Monthly Maturity Scorecards B. Maturity Dashboard C. Quarterly Maturity Detailed Report D. Assessment Summary E. Gap Analysis F. ZTA Roadmap Capability Weighted Prioritization
Source-Selection-Sensitive Page 12 of 51
5.2 ZERO TRUST ARCHITECTURE USE CASE SUPPORT
The Contractor shall build ZTA Use Cases that build upon USAGM’s architecture from the ZTA Roadmap, OMB and CISA memos and directives, PM and OCIO Pillar Leads input, as well as Chief Information Security Officer and CIO strategy, the changing requirements as they emerge from DHS, OMB, CISA, BOD, and NIST directives as well as new technology and systems deployed at USAGM.
The ZTA Use Cases shall document, in detail, how USAGM needs to implement the capabilities on the target architecture at the conceptual, logical, and implementation layer. ZTA Use Cases shall often include more than one capability from the CISA Maturity Model, for example Isolation might include segmentation, identity enhancements, and device hardening. It is expected that the Contractor will produce up to 12 ZTA Use Cases during the contract duration. The ZTA Use Cases shall often include architecture diagrams showing system and network components, information flows, ports, protocols, interconnections, policy decision and enforcement points, and other common industry practices of ZTAs. The Contractor shall work with the ZTA Pillar Leads and function as an expert consultant to determine if existing toolsets can be utilized or if a new tool is required. The Contractor shall remain tool brand agnostic and not offer specific branding. The Contractor shall produce Tool Capability Analysis Reports.
The Contractor shall work with the PM to document any decisional issues that need governance approval or escalation to USAGM’s Executive Leadership or the Change Advisory Board (CAB). The Contractor shall produce Governance Decision Issue Briefs.
The Governance Decision Issue Brief documents may be in the form of a decision whitepaper, brief, or presentation with multiple recommended courses of action. For example, a decision may need governance approval on a Policy Decision Point on the level of access to a system based on the device health.
Deliverables:
A. ZTA Use Cases B. Tool Capability Analyses Reports C. Governance Decision Issue Briefs
6. ZTA SYSTEM IMPLEMENTATIONS
The Contractor shall build ZTA Engineering and Implementation Plans. The ZTA Engineering and Implementation Plans shall include how to implement the ZTA Use Cases on USAGM information systems. The ZTA Engineering and Implementation Plans shall include how to develop, evaluate, and deploy the ZTA Use Case capabilities onto the system utilizing the target architecture. The ZTA Engineering and Implementation Plans shall include all major variations to cover USAGM information systems, starting with the critical systems, which are a mix of on premises, cloud, single instance cloud, legacy, and business partnered systems. In the cases where a system is a system of systems, the implementation shall include all parts of the system to include minor application components. The ZTA Engineering and Implementation Plans shall be updated based on new cases, as well as lessons learned from deployments and stakeholder and system owner feedback.
Source-Selection-Sensitive Page 13 of 51
The Contractor shall assist the ZTA Pillar lead, system stakeholders, owners, and Information System Security Officers (ISSOs) to deploy the Zero Trust target architecture. The Contractor shall produce an Implementation Schedule as well as Implementation Test Plans. This includes assisting with building individual project schedules, test plans, regression testing, and deployment support. The Contractor shall assist in completing a system impact analysis to determine if the changes warrant a “major system change” and reissuance of Authority to Operate. The Contractor shall produce a Zero Trust System Analysis and Implementation Report documenting the ZTA Use Cases and target architectures implemented, any deviations, issues, and lessons learned noted.
A. ZTA Engineering and Implementation Plans B. ZTA System Implementation Schedule C. ZTA System Implementation Test Plans D. ZTA System Impact Analysis and Implementation Reports
6.1 Operations and Maintenance (O&M)
The Contractor shall be responsible for O&M for all installed ZTA tools for 12 months after installation. The Contractor shall monitor the systems and provide a weekly analysis of the monitoring results. The Contractor shall collaborate with the IT teams, which may include Global Networks, Network Control Center, Enterprise Platforms and Storage, Information Security Management, Enterprise Applications, Computer Systems Support, and Enterprise Telecommunications to perform all O&M activities and work with the TSI Project Management Office (PMO) to incorporate O&M tasks into the O&M schedule.
The Contractor shall develop detailed SOPs for all new ZTA tools and processes.
A. ZTA Engineering and Implementation Plans
6.2 Training
The Contractor shall provide hands on training during installation and O&M of the ZTA tools to the IT team, which may include Global Networks, Network Control Center, Enterprise Platforms and Storage, Information Security Management, Enterprise Applications, Computer Systems Support, and Enterprise Telecommunications.
6.3 Surge Support (Optional)
The Contractor may be required to provide surge support for the IT teams, including Global Networks, Network Control Center, Enterprise Platforms and Storage, Information Security Management, Enterprise Applications, Computer Systems Support, and Enterprise Telecommunications.
Source-Selection-Sensitive Page 14 of 51
7. GENERAL REQUIREMENTS
7.1 PERFORMANCE METRICS
The table below defines the Performance Standards and Acceptable Levels of Performance associated with this effort.
Performance Objective
Performance Standard Acceptable Levels of Performance
A. Technical/Quality of Product or Service
1. Shows understanding of requirements.
2. Efficient and effective in meeting requirements.
3. Meets technical needs and mission requirements.
4. Provides quality services/products.
Satisfactory or higher
B. Project Milestones and Schedule
1. Quick response capability.
2. Project tasks completed, reviewed, delivered in accordance with the milestone schedule established by USAGM and the Contractor.
3. Keeps schedule updated.
4. Notifies customer in advance of potential problems.
Satisfactory or higher
C. Staffing and Cost 1. Key personnel and SMEs are available and meet the qualifications needed.
2. Expertise and staffing levels of team members appropriate.
3. Personnel possess necessary knowledge, skills, and abilities to perform tasks.
4. Cost is managed and reported appropriately.
Satisfactory or higher
D. Management 1. Manages integration and coordination of all activities to execute effort.
2. Provides required status reports in a timely manner.
3. Manages risk proactively.
Satisfactory or higher
The COR will utilize a Quality Assurance Surveillance Plan (QASP) throughout the life of the contract to ensure that the Contractor is performing the services required by this PWS at an acceptable level of performance. The Government reserves the right to alter
Source-Selection-Sensitive Page 15 of 51 or change the QASP at its own discretion. A Performance Based Service Assessment will be used by the COR in accordance with the QASP to assess Contractor performance.
7.2 ACCEPTANCE AND ACCEPTANCE TEDTING
Prototype/POC of tools will be accepted based on satisfaction with functionality and ease of integration. The Contractor will provide monitoring results after each prototype/POC is completed.
Deliverables resulting from this solicitation will be accepted based in part on satisfaction with the Section 508 Chapter 2: Scoping Requirements standard. The Government reserves the right to assess Section 508 Compliance before delivery. The Contractor shall be able to demonstrate Section 508 Compliance upon delivery.
7.3 ORGANIZATIONAL CONFLICT OF INTEREDT
All functions related to Acquisition Support shall be on an advisory basis only. Please be advised that since the awardee of this contract will provide systems engineering, technical direction, specifications, work statements, and evaluation services, some restrictions on future activities of the awardee may be required. The Contractor and its employees, as appropriate, shall be required to sign Non-Disclosure Agreements.
7.4 Key Personnel
The proposal shall include resumes for any key personnel. Key personnel for this effort shall consist of:
• Project Manager
• Lead Security Architect
• Lead Network Security Engineer
• Cloud (Cyber) Security Engineer
• Solutions Architect
• Data and Application Security Engineer
• Compliance Engineer
• OCM Professional
Any changes that the Contractor plans to make to its proposed key personnel must be approved in advance in writing by USAGM.
8. PERFORMANCE DETAILS
8.1 PERFORMANCE PERIOD
The Period of Performance (PoP) shall be 12 months from the date of award (Base Period), with three 12-month Option Periods (OP). The overall PoP shall not exceed 48 months.
Source-Selection-Sensitive Page 16 of 51
8.2 PLACE OF PERFORMANCE
Efforts under this contract shall be performed at the Contractor facilities. The Contractor shall identify the Contractor’s place of performance in its proposal. The Contractor’s personnel shall be available to coordinate with USAGM staff on Federal Government business days and shall be responsive between the core hours of 8:00am and 5:00pm Eastern Time.
8.3 TRAVEL OR SPECIAL REQUIREMENTS
The Government does not anticipate travel to perform the tasks associated with the effort.
8.4 GOVERNMENT FURNISHED PROPERTY
The Government’s issuance of Government Furnished Equipment (GFE) is limited to Contractor personnel requiring direct access to the network. When necessary, the Government will furnish laptops for use by the Contractor to access USAGM networks, systems, or applications to meet the requirements of this Statement of Work. The overarching goal is to determine the most cost-effective approach to providing needed access to the USAGM environment coupled with the need to ensure proper Change Management principles are followed. Contractor personnel shall adhere to all USAGM system access requirements for on-site and remote users in accordance with USAGM standards, local security regulations, policies, and rules of behavior. GFE shall be approved by the COR and PM on a case-by-case basis prior to issuance.
8.5 SECURITY
The Contractor personnel shall have, at a minimum, a “Secret” clearance or be able to pass a “Noncritical-Sensitive” background investigation. All Contractor personnel must complete security paperwork for access to the infrastructure and complete the required Security Training.
Source-Selection-Sensitive Page 17 of 51
D Packaging and Marking
D.1 Preservation, Packaging and Packing Unless otherwise specified, all items shall be preserved, packaged, and packed in accordance with normal commercial practices, as defined in the applicable commodity specification. Packaging and packing shall comply with the requirements of the Uniform Freight Classification and the National Motor Freight Classification (issue in effect at time of shipment) and each shipping container or each item in a shipment shall be of uniform size and content, except for residual quantities. Where special or unusual packing is specified in a task order, but not specifically provided for by the contract, such packing details must be agreed to by USAGM and the Contractor.
Source-Selection-Sensitive Page 18 of 51
E Inspection and Acceptance
E.1 Performance Metrics The awarded contract will be closely monitored by the Contracting Officer’s Representative (COR) throughout the entire period of performance and will be reported on at minimum one time annually at the conclusion of each period of performance. The evaluation will be shared with the Contractor.
E.2 Inspection and Acceptance of Services The COR shall make inspection and acceptance of the services/products to be provided hereunder. USAGM has the right to inspect and approve all services/products under the contract.
If the Contractor fails to perform the required services/products at an acceptable level as determined by the COR, either from a performance or professionalism standpoint, the government reserves the right to terminate the contract.
E.3 Quality Standards
(a) All services performed and products delivered under this contract shall be of the highest quality standards, consistent with best industry practices, to assure timely provision of services, optimum USAGM customer satisfaction, and adequate protection of government assets.
(b) If any of the services do not conform with contract requirements, the government may require the Contractor to perform the services again in conformity with contract requirements, at no increase in contract amount. When the defects in services cannot be corrected by re-performance, the government may-
a. Require the Contractor to take necessary action to ensure that future performance conforms to contract requirements; and
b. Unilaterally reduce the contract price to reflect the reduced value of the services performed.
(c) If the Contractor fails to promptly perform the services again or to take the necessary action to ensure future performance in conformity with contract requirements, the government may-
a. By contract or otherwise, perform the services and charge to the Contractor any cost incurred by the Government that is directly related to the performance of such service; or
b. Terminate the contract for cause.
Source-Selection-Sensitive Page 19 of 51
F Deliveries or Performance
F.1 Period of Performance
The period of performance of this contract is one-year Base Period and three (3) twelve-month Option Periods, as follows:
- Base Period: From [TBD] to [TBD]
- Option Period 1: From [TBD] to [TBD]
- Option Period 2: From [TBD] to [TBD]
- Option Period 3: From [TBD] to [TBD]
Actual ordering periods will be finalized at the award date.
F.2 Place of Performance
The Contractor shall perform all services solely at the Contractor’s facility/site at the following address:
Primary Place of Performance: [TBD]
Source-Selection-Sensitive Page 20 of 51
G Contract Administration Data The Contractor shall meet and comply with the requirements for contract administration and operational support for services in accordance with Section G Contract Administration Data of this contract. The Contractor shall support and comply with the following:
G.1 Requirements for Billing
The Contractor shall bill the agency directly for all charges incurred by the agency. The Contractor will be paid directly by the USAGM.
G.1.1 Invoice Submission
The government intends to use electronic invoicing. The Contractor shall submit payment requests electronically using the Invoice Processing Platform (IPP).
Information regarding IPP, including IPP Customer Support, is available at www.ipp.gov or any successor site and send a copy of the invoice to the Office of Contracts (OCO) and COR. The Contractor shall not submit, and the government will not accept paper invoices except as authorized by the OCO.
Any invoice that does not include the required information listed below will be sent back to the Contractor for revision.
An invoice shall include the following information to be considered a proper invoice:
● Name and address of the Contractor
● Invoice date and number
● Contract number, contract line-item number and, if applicable, the order number
● Description, quantity, unit of measure, unit price and extended price of the items delivered
● Shipping number and date of shipment, including the bill of lading number and weight of shipment if shipped on government bill of lading
● Terms of any discount for prompt payment offered
● Name and address of official to whom payment is to be sent
● Name, title, and phone number of person to notify in event of defective invoice
● Taxpayer Identification Number (TIN)
● Electronic funds transfer (EFT) banking information
G.2 Administrative Contracting Officer (ACO)
The Administrative Contracting Officer is:
United States Agency for Global Media (USAGM) Office of Contracts 330 Independence Avenue SW Cohen Building, Room 4360 Washington, DC 20237
Source-Selection-Sensitive Page 21 of 51
G.3 Contracting Officer’s Representative (COR)
The Contracting Officer’s Representative (COR) will be designated at the time of award.
G.4 Paying Office
The paying office for this contract is:
United States Agency for Global Media (USAGM) Office of the Chief Financial Officer 330 Independence Avenue SW Cohen Building, Room 4360 Washington, DC 20237
G.5 Government-Furnished Property During performance of individual service orders, the government may, at its discretion, provide the items listed below.
(a) Government Furnished Property: None
(b) Government Furnished Information (GFI). The government may provide information
(e.g., technical data, applicable documents, plans, regulations, specifications, etc.) in support of this contract.
(c) Government-Furnished Workspace. Such government-furnished workspace, if any, will be specified in the subsequent contract.
Source-Selection-Sensitive Page 22 of 51
H Special Contract Requirements
H.1 Standards of Conduct The Contractor shall ensure that personnel assigned to this contract observe the highest standards of personal and professional conduct. The Contractor is responsible for recruiting and hiring only those personnel who can maintain the standards of conduct required under this contract. Additionally, the Contractor is responsible for maintaining satisfactory standards of employee conduct and integrity and shall be held fully accountable for the conduct of its employees and its subcontractor’s employees (if any).
H.2 Safeguarding of Information The Contractor and its employees shall exercise the utmost discretion in regard to all matters relating to their duties and functions. They shall not communicate to any person any information known to them by reason of their performance of services under this contract which has not been made public, except in the necessary performance of their duties or upon written authorization of the Contracting Officer. All documents and records (including photographs, if any) generated during the performance of work under this contract shall be for the sole use of and become the exclusive property of the U.S.
Government. Furthermore, no article, book, pamphlet, e-mail, recording, broadcast, speech, television appearance, film or photograph concerning any aspect of work performed under this contract shall be published or disseminated through any media without the prior written authorization of the Contracting Officer. These obligations do not cease upon the expiration or termination of this contract. The Contractor shall include the substance of this provision in all contracts of employment and in all subcontracts hereunder.
H.3 Contractor Self-Identification All Contractor personnel attending meetings, answering government telephones, and/or working in other situations where their Contractor status is not obvious to third parties are required to identify themselves as such to avoid creating an impression in the minds of members of the public, or other government personnel that they are Government officials. Contractor personnel must also ensure that all documents or reports produced by them are suitably marked as Contractor products or that Contractor participation is appropriately disclosed. This direction shall be adhered to unless otherwise waived, in writing, by the cognizant Contracting Officer.
At no time will any Contractor utilize letterhead for any correspondence between the Contractor and any other entity depicting or intimating that the Contractor is a member/employee of the U.S. Government, either as an individual or as a company/corporation.
Source-Selection-Sensitive Page 23 of 51
I Contract Clauses
52.217-8 Option to Extend Services (Nov 1999) The Government may require continued performance of any services within the limits and at the rates specified in the contract. These rates may be adjusted only as a result of revisions to prevailing labor rates provided by the Secretary of Labor. The option provision may be exercised more than once, but the total extension of performance hereunder shall not exceed 6 months. The Contracting Officer may exercise the option by giving written notice to the Contractor within the current period of performance.
(End of clause)
52.217-9 Option to Extend the Term of the Contract (Mar 2000)
(a) The Government may extend the term of this contract by written notice to the
Contractor prior to contract expiration, provided that the Government gives the Contractor a preliminary written notice of its intent to extend at least 15 days before the contract expires. The preliminary notice does not commit the Government to an extension.
(b) If the Government exercises this option, the extended contract shall be considered to include this option clause.
(End of clause)
52.203-17 Contractor Employee Whistleblower Rights and Requirement to Inform Employees of Whistleblower Rights (Apr 2014)
(c) (a) This contract and employees working on this contract will be subject to the whistleblower rights and remedies in the pilot program on Contractor employee whistleblower protections established at 41 U.S.C. 4712 by section 828 of the National Defense Authorization Act for Fiscal Year 2013 (Pub. L. 112-
239) and FAR 3.908.
(d) (b) The Contractor shall inform its employees in writing, in the predominant language of the workforce, of employee whistleblower rights and protections under 41 U.S.C. 4712, as described in section 3.908 of the Federal Acquisition Regulation.
(e) (c) The Contractor shall insert the substance of this clause, including this paragraph (c), in all subcontracts over the simplified acquisition threshold.
52.204-25 PROHIBITION ON CONTRACTING FOR CERTAIN TELECOMMUNICATIONS
AND VIDEO SURVEILLANCE SERVICES OR EQUIPMENT (AUG 2019)
(a) Definitions. As used in this clause— “Covered foreign country” means The People’s Republic of China.
“Covered telecommunications equipment or services” means–
Source-Selection-Sensitive Page 24 of 51
(1) Telecommunications equipment produced by Huawei Technologies Company or ZTE Corporation (or any subsidiary or affiliate of such entities);
(2) For the purpose of public safety, security of Government facilities, physical security surveillance of critical infrastructure, and other national security purposes, video surveillance and telecommunications equipment produced by Hytera Communications Corporation, Hangzhou Hikvision Digital Technology Company, or Dahua Technology Company (or any subsidiary or affiliate of such entities);
(3) Telecommunications or video surveillance services provided by such entities or using such equipment; or
(4) Telecommunications or video surveillance equipment or services produced or provided by an entity that the Secretary of Defense, in consultation with the Director of National Intelligence or the Director of the Federal Bureau of Investigation, reasonably believes to be an entity owned or controlled by, or otherwise connected to, the government of a covered foreign country.
“Critical technology” means–
(1) Defense articles or defense services included on the United States Munitions List set forth in the International Traffic in Arms Regulations under subchapter M of chapter I of title 22, Code of Federal Regulations;
(2) Items included on the Commerce Control List set forth in Supplement No. 1 to part 774 of the Export Administration Regulations under subchapter C of chapter VII of title 15, Code of Federal Regulations, and controlled-
(i) Pursuant to multilateral regimes, including for reasons relating to national security, chemical and biological weapons proliferation, nuclear nonproliferation, or missile technology; or
(ii) For reasons relating to regional stability or surreptitious listening;
(3) Specially designed and prepared nuclear equipment, parts and components, materials, software, and technology covered by part 810 of title 10, Code of Federal Regulations (relating to assistance to foreign atomic energy activities);
(4) Nuclear facilities, equipment, and material covered by part 110 of title 10, Code of Federal Regulations (relating to export and import of nuclear equipment and material);
(5) Select agents and toxins covered by part 331 of title 7, Code of Federal Regulations, part 121 of title 9 of such Code, or part 73 of title 42 of such Code; or
(6) Emerging and foundational technologies controlled pursuant to section 1758 of the Export Control Reform Act of 2018 (50 U.S.C. 4817).
“Substantial or essential component” means any component necessary for the proper function or performance of a piece of equipment, system, or service.
(b) Prohibition. Section 889(a)(1)(A) of the John S. McCain National Defense Authorization Act for Fiscal Year 2019 (Pub. L. 115-232) prohibits the head of an executive agency on or after August 13, 2019, from procuring or obtaining, or extending or renewing a contract to procure or obtain, any equipment, system, or service that uses covered telecommunications equipment or services as a substantial or essential component of any system, or as critical technology as part of any system. The Contractor is prohibited from providing to the Government any equipment, system, or service that uses covered telecommunications equipment or services as a substantial or essential component of any system, or as critical technology as part of any system, unless an exception at paragraph (c) of this clause applies or the covered telecommunication equipment or services are covered by a waiver described in Federal Acquisition Regulation 4.2104.
(c) Exceptions. This clause does not prohibit Contractors from providing—
(1) A service that connects to the facilities of a third-party, such as backhaul, roaming, or interconnection arrangements; or
(2) Telecommunications equipment…
This is the start of the file's text. The full file is on GovTribe.
File details come from the government source that posted it. Updated .