Procurement Summary
Country: USA
Summary: System Log Correlation Software And Support Services
Deadline: 27 Jan 2017
Posting Date: 13 Jan 2017
Other Information
Notice Type: Tender
TOT Ref.No.: 10374778
Document Ref. No.: NIHLM2017935MAH
Competition: ICB
Financier: Self Financed
Purchaser Ownership: -
Tender Value: Refer Document
Purchaser's Detail
Name: Login to see tender_details
Address: Login to see tender_details
Email: Login to see tender_details
Login to see detailsTender Details
This is a combined synopsis/solicitation for commercial items prepared in accordance with the format in subpart 12.6, as supplemented with additional information included in this notice. This announcement constitutes the only solicitation; proposals are being requested and a written solicitation will not be issued. This solicitation is being issued as request for quotations (rfq) nihlm2017935mah. The resultant order will be a firm-fixed price contract.
In accordance with far parts 12 and 13.5, the national institutes of health (nih) intends to procure system log correlation software and support services for nih s business system (nbs). This acquisition is full and open. The north american industry classification system (naics) code is 541511 - custom computer programming services.
Background information
the national institutes of health (nih) is comprised of the office of the director (od) and 27 institutes and centers. The od is the central office at nih. The od is responsible for setting policy for nih and for planning, managing, and coordinating the programs and activities of all the nih components.
The nih business system (nbs) program is committed to fostering nih s mission through the following provisions:
-c secure, accurate, and timely business transaction capabilities that enable the nih scientific community and supporting organizations to acquire needed assets, goods and services;
-c accurate source information that facilitates knowledgeable decision making by the nih management community regarding budgets, finance, acquisitions, supply/replenishment, property, grants, and travel; and
-c improving transparency and accountability of all nbs accounting data.
The nbs software applications are currently comprised of the following:
-c oracle e-business suite (federal administrator, general ledger, payables, i-procurement, purchasing, receivables, order management, warehouse management, inventory, i-supplier (internal and external facing), and project accounting (costing and billing);
-c oracle governance, risk and compliance (grc) suite which includes the access application controls governor (aacg), configuration controls governor (ccg), preventative controls governor (pcg), transaction controls governor (tcg), and grc manager and intelligence for nih-wide enterprise risk assessment;
-c kofax invoice document management application;
-c sunflower asset management application;
-c compusearch prism contract management module;
-c gsa e-travel system - concur (cge) web-based travel manager application;
-c nih patient travel module;
-c smartpay ii purchase card module;
-c inter/intra agency agreements and reimbursable agreements;
-c interfaces, including web interfaces that enable sharing or exchange of data with other business systems; and
-c rapid esuite.
The nbs also includes special purpose peripheral devices employed for data capture or output, such as hand-held scanners and wireless printers, and supporting tools and modules that facilitate operations, maintenance and support, such as appworx production operations scheduler. The scope of the nbs program includes the following:
-c operations support and maintenance of the following nbs components: federal administrator, finance, acquisitions, supply, property, travel (employee, patient and sponsored travel), i-supplier, project accounting, grants integration, and other nbs web interfaces, foreign and federal grants, fellowship pay, animal procurement, and service and supply fund;
-c enhancement or upgrade of nbs functionality in response to demands that arise from congressional, office of management and budget (omb), dhhs initiatives/requirements, mandatory policies, the user community, from findings during ongoing operations, from the software contractors, and other authorities which require system and data security and privacy;
-c compliance with the dhhs enterprise performance life cycle (eplc) framework and nbs specific tailoring of eplc project activities and documentation as approved by the nbs contracting officer s technical representative (cotr) for nbs o&m projects;
-c business consulting, communication, job aids and training to nih institutes and centers with respect to nbs functionality, i.e., acquisition, logistics, budget, finance, and travel;
-c operations support and maintenance of community portals on the nih intranet that are designed to communicate with various segments of the nbs user community; and
-c coordination and compliance with nih enterprise architecture requirements.
Contractor requirements
independently, and not as an agent of the government, the contractor shall furnish all necessary labor, materials, supplies, equipment, and services necessary to provide all work and deliverables stated in the attached statement of work (sow). All work performed under this procurement shall be monitored by the contracting officer s representative (cor).
Contractor tasks
task 1 - tenable log correlation engine licensing
the contractor shall provide the government one (1) commercial off-the-shelf perpetual application security information and event management (siem) known as tenable log correlation engine license and services the following:
quantity description
1 lce - on premise - 1tb - perpetual licenses
task 2 - annual maintenance service
the contractor shall provide annual maintenance and support services as follows:
quantity description
1 lce - on premise - 1tb annual maintenance support services
-c provide major product and technology releases
-c provide updates, fixes, security alerts, data fixes, and critical patch updates during the contract term with immediate download passwords
-c provide software license replacement for accidently damaged or malfunctioning hardware keys (not including lost keys)
-c provide certification that licenses are capable with most new cots application products
-c provide 24x7 technical support
task 3 - requirements analysis
the contractor shall conduct activities including, but not limited to, performing detailed requirements analysis to determine complete scope and solution to implement the tenable log correlation engine application within the nbs enterprise infrastructure and provide all of the reports, alerts, and enhancements for the security events listed in table 1. Each of the security events shall be included in a daily report for nbs security team, and optionally, a real-time alert. There shall be a mechanism for recording acknowledgement of the report by any of several methods. The acknowledgment shall include the date, time, id of the user, and a pointer to the report. Acceptable methods include a hypertext link, sharepoint workflow, reply email to a central account, or other similar.
The deliverable of this phase shall be a detailed requirements document.
Task 4 - implementation, deployment, and integration
upon approval of the requirements document, the contractor shall provide the services to implement, deploy, and integrate the resulting reports, alerts and enhancements.
1. Custom reports/alerts/enhancements to the log correlation engine application - provide consulting services onsite for the following:
a. Lce project schedule - the contractor shall provide a proposed project schedule for implementations. The schedule shall include the following:
i) estimated time range for implementation, deployment, and integration; and
ii) pricing and payment terms for yearly maintenance.
B. Lce general architecture - the contractor shall provide a general architecture document that shall include monitoring of all nbs desktops, servers, databases, major applications, and existent security platforms. The architecture shall include forwarding logs to nih incident response team (irt) and hhs. The architecture shall consider disaster recovery capabilities, local storage for 30 days of correlated events for on-demand queries, as well as secured network storage for long term storage of logs (i.e. Minimum 12 months).
C. The integrated product requires collecting, analyzing, and monitoring specific events on the internal nih business system network. The events listed in table 1 shall be collected, analyzed, monitored, and stored.
D. Integration of lce - the contractor shall work with cit server hosting group and cit desktop support group to deploy tenable lce clients on all nbs endpoints (i.e. Desktops and servers). The contractor shall collaborate with cit networking group to direct and allow traffic through internal firewalls from all nbs endpoints to the lce.
E. Configure - all services, efforts, functionality, and documentation shall be deemed to be "solution support materials": the contractor shall ensure that initial configuration eliminates or reduces the level of false positives alerts generated by lce. The contractor shall ensure the configuration integrates with other existent security platforms including endpoint security, vulnerability scanning tools, and firewalls. The initial configuration shall be comprised by enabling default rules and policies as well as custom rules and policies based on nbs-specific requirements.
F. Provide installation scripts - the contractor shall provide nbs with installation scripts and instructions on how to execute the scripts to install the enhancements into nih s existing enterprise system environment.
G. Provide initial installation support - the contractor shall provide nih with remote support for nih s execution of the installation scripts in an initial tenable lce test environment. This remote support shall be provided on a single day.
H. Nbs testing support - the contractor shall conduct user acceptance testing. The user testing may last up to 30 days, after the conclusion of the execution of the installation scripts in the initial tenable lce test environment. The contractor must remediate any testing failure with the 30 days requirement.
I. Migration support - the contractor shall provide remote support for nbs s migrations (after the installation of tenable lce application into the nbs infrastructure test environment) for up to two (2) additional environments (initial test to stage, stage to production) over one (1) day per environment. The migration support shall be provided in the same timeframe as the nih testing support.
J. Go-live support - the contractor shall provide remote support for the initial use of the enhancements outlined herein in a production environment at nih. This remote support shall be provided for up to five (5) business days immediately following the migrating of the enhancements into the production environment. The contractor shall provide 508 compliant documentations such as design document, requirements traceability matrix, system codes, configuration management, user and operation and maintenance documentation.
Documentation - the contractor must provide the government with knowledge transfer and standard operation documentation 14 days after deployment.
K. The contractor shall provide a stabilization period of 30 days from go-live date.
Task 5 - system configuration activities
the contractor shall perform all activities as describe in the tenable log correlation engine 4.4 administration and user guide as follows:
-c lce agents install for servers and desktops (unix, linux, solaris and windows)
-c basic configuration
-c storage configuration
-c ids configuration
-c load balancing configuration
-c configuring the primary lce server
-c advanced configuration options storage
-c lce web server
-c sensor names
-c clients
-c user tracking
-c host discovery and vulnerabilities
-c statistical alerts
-c resource usage and performance
-c dns caching
-c data forwarding
-c sending syslog messages to other hosts
-c syslog compliant messages
-c content of forwarded syslog messages
-c checksum forwarding
-c tcp syslog
-c correlation
-c tasl and plugins
-c excluding tasl files
-c excluding prm files
-c tasl parameters
-c event rules
-c email syntax
-c syslog syntax
-c custom command syntax
-c lce rule filters
-c lce shell command options
-c email/alerting/execution
-c debugging
-c debug mode
-c storing all logs with "save-all"
-c different file system
-c multiple plugin matches per log file "multiple-matches"
-c quick example
-c ssh keys
-c service control
-c feed settings
-c feed registration
-c plugin update
-c updating plugins (prm files) and tasl scripts
-c automatic plugin (prm files) and tasl updates
-c updating individual prm files
-c offline updates
-c web proxy
-c open required port for solaris servers syslogs to audit logging
task 6 - log correlation engine audit logging reports
the contractor shall ensure that the following report categories can be generated from software application:
categories
-c accounts, authentication & password audits
-c advanced persistent threats & malicious software
-c botnets
-c center for internet security
-c configuration & patch auditing
-c data leakage & file sharing
-c exploits & attack paths
-c file integrity monitoring
-c fisma/nist sp800-53 rev4 or most current version at time of the deployment.
-c logging, monitoring, & intrusion detection
-c mobile devices, usb devices & wireless
-c nessus scan monitoring
-c network monitoring
-c sans
-c software & it technology
-c vulnerability metrics
-c vulnerability reporting
-c web application security
task 7 - auditable events
the contractor shall create scripts for the following auditable events.
Nih security event logging policy au:
audit logging events
each information system shall generate audit records for the following events:
account logon events:
-c logon success
-c logon failure (failed user authentication - unknown user name or bad password; multiple login attempts / logon failures: account locked out)
-c logoff
account management:
-c account created
-c account deleted
-c account disabled
-c account expired
-c password changed
directory service:
-c object (user, machine, etc.) added to domain / directory
-c object removed from domain / directory
-c domain policy change
-c
filesystem events:
-c directory created
-c directory deleted
-c directory read
-c directory write
-c directory permissions changed
-c file created
-c file deleted
-c file read
-c file write
-c file permissions changed
-c object access
logging event:
-c event log full
-c event log overwritten
network events:
-c acl changed
-c traffic blocked at firewall
policy change
-c all
privilege use:
i
Documents
Tender Notice