SOURCES SOUGHT
D -- Intrusion Protection Services
- Notice Date
- 4/5/2004
- Notice Type
- Sources Sought
- NAICS
- 541519
— Other Computer Related Services
- Contracting Office
- Social Security Administration, Deputy Commissioner for Finance, Assessment and Management, Office of Acquisition and Grants, 1710 Gwynn Oak Avenue, Baltimore, MD, 21207-5279
- ZIP Code
- 21207-5279
- Solicitation Number
- Reference-Number-SSA-04-KF003
- Response Due
- 4/20/2004
- Archive Date
- 5/5/2004
- Point of Contact
- Kathy Fain, Contract Specialist, Phone 410-965-4853, Fax 410-965-9560, - Kathy Fain, Contract Specialist, Phone 410-965-4853, Fax 410-965-9560,
- E-Mail Address
-
kathryn.fain@ssa.gov, kathryn.fain@ssa.gov
- Description
- This is a REQUEST FOR INFORMATION. Reference RFI-04-KF003 when responding to this announcement. The Social Security Administration (SSA) is seeking vendors capable of providing Intrusion Protection services. The place of performance is Baltimore, MD. The Intrusion Protection Service should at a minimum include the following components: 1) Compliance testing a weekly test of the SSA external network including SSA firewalls and web servers. This test identifies noncompliance to established computer and network security policy; 2) Vulnerability Evaluation a monthly test of the SSA external network including SSA firewalls and web servers. This in depth examination determines whether the firewalls or web servers are vulnerable to unauthorized access because of improper configuration or out of date operating system or application software; 3) Monthly Audit Reports an electronic copy and a hard copy report that documents the results of weekly compliance testing, monthly vulnerability evaluations and intrusion detection services; 4) Security Advisories a proactive search service that provides timely information about computer and network security vulnerabilities; 5) Technical support a group of top computer and network security experts available to answer specific security questions pertaining to SSA?s environment around the clock; 6) Real time Intrusion Detection Technology Commercially off the shelf technology that identifies attempts to gain unauthorized access to networked resources and DOS (denial of service) attacks, etc.. This feature has four components: a) Sensor Leading edge software running on standard hardware that is deployed at critical interconnection points on the SSA network. The IPS should have experience with a variety of sensors and Intrusion Detection Systems to include Netranger, Realsecure, NFR, Tivoli Cross-Site, Netprowler and other Scanning Tools. The sophisticated abilities of Internet hacker activity will require at least the above knowledge.; b) 24x7 monitoring a fully redundant operations center staffed with security experts dedicated to monitoring and reacting to security alarms; c) Incident Control and Recovery provides the containment and eradication of a security breach, the restoration of normal system operation, and the investigation into the cause of the breach. IPS will provide a solution to prevent this type of breach from occurring in the future; d) Investigation Services A team of experts trained in investigating security incidents, gathering and analyzing evidence, and developing a report of investigation; 7) IPS should work closely with a variety of security organizations around the world, both within the government community and outside. Two examples are: a)Forum of Incident Response and Security Teams (FIRST) A global organization established to foster cooperation and response coordination among computer security teams worldwide; b) Global Security Analysis laboratory (GSAL) A team of scientists and researchers in the United States and Europe devoted to identifying computer and network vulnerabilities and creating solutions to overcome security risks. In the response, vendors should identify the security organizations with which they associate on a regular basis. Vendors having the capability to meet the above requirements are invited to submit complete details. The responses must clearly state the ability to meet the above requirements. Interested parties must respond to this notice within 15 calendar days from date of this publication. Vendors should provide the names and contact information of customers. References may be checked. Vendors responding should indicate whether their services are available on the GSA Federal Supply Schedules. Pricing data may be submitted. This is not a request for proposal and the Government does not intend to pay for information submitted. Respondents will not be notified of the results of the evaluation of the data received. No contract award will be made on the basis of responses received; however, this information will be used in SSA?s assessment of capable sources. No Faxed responses. Requests for copies of a solicitation will not be honored or acknowledged. No formal solicitation is being issued at this time. Please submit electronic responses only to the contract specialist identified herein Original Point of Contact Kathy Fain, Contract Specialist, Phone 410-965-4853, Fax 410-965-9560, Email kathryn.fain@ssa.gov
- Record
- SN00560412-W 20040407/040405212953 (fbodaily.com)
- Source
-
FedBizOpps.gov Link to This Notice
(may not be valid after Archive Date)
| FSG Index | This Issue's Index | Today's FBO Daily Index Page |