ATO Cybersecurity Testing (DRAFT SIR)

Closed Pre-Solicitation Posted

A newer special notice was posted. See the latest special notice from .

Solicitation number
693KA8-20-R-00017
Agency
Headquarters Federal Aviation Administration, Department of Transportation
Responses due
Set-aside
Total Small Business

Opportunity facts

NAICS code
541519 Other Computer Related Services
PSC
D399 It And Telecom- Other It And Telecommunications

Notice details come from SAM.gov. Updated .

About this opportunity

The Federal Aviation Administration is seeking to establish an independent risk assessment and cybersecurity testing services contract to meet its continuous monitoring requirements under the Federal Information Security Management Act and other directives. Services will include program management, security assessments, vulnerability analysis, penetration testing, aircraft testing, and specialized assessments across multiple FAA facilities nationwide. Interested small businesses may submit feedback on the draft solicitation and attachments by July 31, 2020 to inform finalization. Responses will be evaluated based on reference to specific document sections and pages.

This pre-solicitation notice establishes a small business set-aside, with a period of performance of one base year plus four option years. The contract will utilize time-and-materials pricing for various labor categories and other direct costs. Services will support over 100 FAA information systems categorized under NIST standards for potential confidentiality, integrity and availability impacts. The NAICS code is 541511 and PSC code is D302. The total contract value is estimated between $50-100M over the five-year period of performance.

Notice text

2 versions

Update #2 · Latest ·

The FAA is currently in the planning stages of a Small Business Set-Aside.

Background:

Market Survey / Request for Information #34910 was posted in October 2019 for the purpose of soliciting
feedback from Industry. This posting closed November 2019 and the FAA is not looking for any further input pertaining to this Market Survey.

Introduction:

The sustainment of Independent Risk Assessment capabilities, Information Systems Security (ISS)
Assurance and the performance of penetration testing are key components in meeting Office of
Management and Budget’s (OMB) continuous monitoring requirement, Federal Information Security
Management Act (FISMA), and Executive Order 13636 and its implementation through Presidential
Policy Directive (PPD-21) and the ATO Cyber Security Strategic Plan.

Objective: 

The objective of this posting is to provide Industry with the opportunity to have a preliminary review of the DRAFT SIR and available attachments.  

Response Guidance:
The FAA intends to review all responses received and to use the informtion towards maturing the FINAL SIR PACKET.  The FAA may determine not to respond to one or any comment, question, or other feedback received from interested parties.  All information received will become the property of the FAA unless otherwise marked.

Industry is to provide their comments, questions, concerns cross-referecing the document/section/page if possible in writing. The FAA will post their responses  NLT at the time of the posting of the Official SIR. Please note that the Official SIR will also allow an opportuntiy for clarity and additional information pertaining to Q&A will be made available in that post.

The FAA also asks that when submitting your Q&As to please provide a copy of your SAM registration. 

Please sunmit your written Q&As via email to Contracting Officer, Leslie.fisher@faa.gov,  NLT 3 pm. EST., July 31, 2020 . Please, do not call the Contracting officer or program office. The FAA is not entertaining individual conference calls or any  other requests for meetings or one-on-one calls. 

Interested parties are advised that all costs associated with responding to this announcement are the responsibility of the responding party.

Update #1 ·

The FAA is currently in the planning stages of a Small Business Set-Aside.

Background:

Market Survey / Request for Information #34910 was posted in October 2019 for the purpose of soliciting
feedback from Industry. This posting closed November 2019 and the FAA is not looking for any further input pertaining to this Market Survey.

Introduction:

The sustainment of Independent Risk Assessment capabilities, Information Systems Security (ISS)
Assurance and the performance of penetration testing are key components in meeting Office of
Management and Budget’s (OMB) continuous monitoring requirement, Federal Information Security
Management Act (FISMA), and Executive Order 13636 and its implementation through Presidential
Policy Directive (PPD-21) and the ATO Cyber Security Strategic Plan.

Objective: 

The objective of this posting is to provide Industry with the opportunity to have a preliminary review of the DRAFT SIR and available attachments.  

Response Guidance:
The FAA intends to review all responses received and to use the informtion towards maturing the FINAL SIR PACKET.  The FAA may determine not to respond to one or any comment, question, or other feedback received from interested parties.  All information received will become the property of the FAA unless otherwise marked.

Industry is to provide there comments, questions, concerns crossreferecing the document/section/page if possible. The FAA will post their response NLT the posting of the Official SIR. Please note that the Official SIR will allow an opportuntiy for clarity and additional information will be made available at that time. The FAA also asks that when submitting your Q&As to please provide a copy of your SAM registration. 

Please email Contracting Officer, Leslie.fisher@faa.gov,  NLT 3 pm. EST., July 31, 2020 . Please,  we ask that you not call the Contracting officer or program office. The FAA is not entertaining individual conference calls or other like contact.


Interested parties are advised that all costs associated with responding to this announcement are the responsibility of the responding party.

Attachments

Files attached to this notice, newest first
File Type Posted
Attachment _ FISMA Systems.xlsx XLSX spreadsheet
Attachment L002 - Section B - Price Worksheet.xlsx XLSX spreadsheet
Attachment L003 - Past Performance Questionnaire.docx DOCX document
J Attach J002 - Labor Category Descriptions and Qualifications.docx DOCX document
Attachment L001 - Q and A Template (1).xlsx XLSX spreadsheet
Cybersecurity Testing DRAFT SIR _ 693KA8-20-R-00017.pdf PDF
Attachment _ NIST.FIPS.199.pdf PDF

Notice history

Notices posted for this opportunity, newest first
Notice Type Posted
Single Source Notification _ SPECIAL NOTICE Latest special notice Special Notice
Notice of award - cybersecurity test - notice of award Solicitation
ATO Cybersecurity Testing (DRAFT SIR) This notice · Original Pre-Solicitation

On GovTribe

Work this opportunity on GovTribe

  • Track it in your pipeline
  • Find teaming partners
  • Similar opportunities
  • Ask GovTribe AI about this opportunity