SOURCES SOUGHT
D -- Information Assurance Support (IAS) for the United States Military Surface Deployment and Distribution Command
- Notice Date
- 2/3/2011
- Notice Type
- Sources Sought
- NAICS
- 541990
— All Other Professional, Scientific, and Technical Services
- Contracting Office
- Surface Deployment and Distribution Command (SDDC), ATTN: SDAQ, 200 Stovall Street, Alexandra, VA 22332-5000
- ZIP Code
- 22332-5000
- Solicitation Number
- W81GYE-11-R-0004
- Response Due
- 2/14/2011
- Archive Date
- 4/15/2011
- Point of Contact
- DeCarol Blocker, 6182205068
- E-Mail Address
-
Surface Deployment and Distribution Command (SDDC)
(decarol.blocker@us.army.mil)
- Small Business Set-Aside
- N/A
- Description
- ***This is NOT a Request for Proposal. This is a Request for Information.*** Background. The Surface Deployment and Distribution Command (SDDC) mission is to provide global surface deployment and distribution services to meet the nation's objectives. SDDC is one of the United States Transportation Command (USTRANSCOM) Transportation Component Commands (TCCs), which includes Military Sealift Command (MSC), and HQ Air Mobility Command (AMC). Information Assurance. Information Assurance (IA) is used to ensure the confidentiality, integrity and availability of SDDC systems and networks. IA also includes technology to provide non-repudiation and authentication technologies. Increasing attacks on networks, whether by hackers or a trusted insider, have required the development of standardized IA capabilities. These capabilities include, but are not limited to, hardware, software, firewall technologies, intrusion detection systems, anti-virus programs, configuration management, audit log analysis and training and awareness programs. The IA program within SDDC was developed to improve the overall total security of SDDC systems and to protect interfaces to the Global Transportation Network. Scope. The purpose of the proposed contract is to acquire specialized contractor technical support services to support day-to-day Information Assurance operations for SDDC G6 Automated Transport System Division (IMA). All functions and activities shall be task driven and work performed shall be IAW all applicable federal, state, and local regulations and guidelines, specifically AR 25-2, Information Assurance, DODD 8500.1, Information Assurance, and DODI 8500.2 Information Assurance Implementation. The Computer Security Act of 1987 established the requirement for every information system to be certified and accredited. The Contractor shall plan for all tasks identified in this PWS and gather all pertinent information. Contractor estimates and timelines shall be determined based on the deliverable due dates specified. The Contractor shall coordinate with the Government to ensure that all activities are well synchronized and integrated with other SDDC efforts. All reports, studies or policies identified in the PWS shall be prepared and submitted for Government approval or acceptance. The Contractor shall provide technical security expertise of DOD, USTRANSCOM and Department of Army (DA) directives, policies, and instructions to SDDC network personnel, Program Managers, and subordinate command personnel as directed. This work includes but is not limited to, ensuring compliance with the security policies, assessing impacts of integrated, interdependent, and interconnected SDDC network security posture and topology, executing technical test procedures and automated systems tools, as directed, reviewing security relevant documentation, and preparing technical white papers detailing the results of the security assessment and analysis. This work also includes participating in connection compliance efforts, ensuring compliance with policies and directives, participation in technical meetings, and the preparation of technical papers and reports. Specific Tasks. SDDC G6 IMA requires security documentation and engineering/security testing/auditing/intrusion detection services to support and maintain Certification and Accreditation (C&A) of the systems/programs identified. These services span a variety of information assurance activities necessary to complete a comprehensive evaluation of the technical and non-technical security features of the SDDC systems, Government-Off-The Shelf (GOTS) applications and network devices. Support required includes development and maintenance of required security documentation, validation and evaluation of security requirements, vulnerabilities and residual risks, as well as effective continuous security auditing and monitoring for suspicious activity of the information systems. SDDC Common Computing Environment (CCE) CCE is a program to modernize and centralize system administration and configuration management support to the SDDC unclassified computing environment on a common architecture. CCE currently includes the integration of SDDC systems into a multi-tiered architecture. SDDC is interested in expanding CCE to include application level administration and configuration management and migration of all SDDC web-based applications to a CCE architecture. On-going modernization has resulted in an optimized enterprise infrastructure of hardware, software, network, and telecommunications within the facilities at HQ SDDC, Scott AFB. The new enterprise architecture is based on a 3-tiered environment utilizing virtualized Solaris and Windows operating systems that includes a web layer, application layer and database layer. In addition, a NetAPP Storage Area Network (SAN) is utilized to manage storage. The current CCE environment consists of approximately 200 servers and 40 Cisco switches. CCE and SDDC systems require knowledge in the following areas: a. Veritas and Microsoft clusters b. Solaris 10, Windows 2003 Advanced Server and Windows 2008 Server with virtualization c. F5 load balancing d. NetApp 6080 Storage with redundancy e. Sun Java web/app servers f. Oracle 11g Database and Oracle app servers i. Oracle RDBMS with partitioning, Data Mining and OLAP Data Warehousing g. Cognos Application Server h. Informatica PowerCenter 7/8 i. SunOne Java enterprise system web servers, Cognos SSO SDK, Cognos Gateways for UNIX, Cognos Series 7 UpFront, Impromptu Web Reports, Impromptu Administrator, Access Manager, PowerPlay Enterprise Server, and PowerPlay Client for windows j. XML Schema Definitions (XSDs) and Web Service Description Languages (WSDLs) k. IIS and Apache Web servers l. Oracle and SQL database m. C, C++, SQL, SQL+, PLSQL, PHP, JAVA, Visual Basic 6, Visual Basic.NET, ASP, ASP.NET, XML, and other programming languages utilized by the supported SDDC G6 IMA systems Additionally, the contractor shall provide individuals that possess the skills to thoroughly analyze GOTS applications for security weaknesses or vulnerabilities introduced in the development process. PWS performance involves a working knowledge of programming languages listed above. The level of knowledge will be sufficient to provide a detailed security review to identify coding practices that could jeopardize the security of the supported systems. Require an excellent working knowledge in networking architecture, devices, technologies and protocols as well as practical experience in firewalls, VPNs and wireless technology. G6 IMA Systems/Applications - Integrated Computerized Deployment System (ICODES) - Integrated Surface Deployment Data Cleansing (ISDDC) - Global Operational Passenger System (GOPAX) - Cargo and Billing (CAB) - Integrated Booking System (IBS) - Transportation Financial Management System (TFMS) - Electronic Transportation Acquisition (ETA) - Carrier Appointment System (CAS) - SafetyNet - ICSS - Global Freight Management System (GFM) --Defense Table of Distances (DTOD) --Combined Data Toolset (CDT)/AMCADRE -- Pipeline Asset Tool (PAT) - Electronic Data Interchange (EDI) - Sharepoint ***This is NOT a Request for Proposal. This is a Request for Information.***
- Web Link
-
FBO.gov Permalink
(https://www.fbo.gov/notices/9fb277a203dc6134a543fa165c24e965)
- Place of Performance
- Address: Surface Deployment and Distribution Command (SDDC) 709 Ward Drive, Bldg 1990 Scott AFB IL
- Zip Code: 62225
- Zip Code: 62225
- Record
- SN02372331-W 20110205/110203234255-9fb277a203dc6134a543fa165c24e965 (fbodaily.com)
- Source
-
FedBizOpps Link to This Notice
(may not be valid after Archive Date)
| FSG Index | This Issue's Index | Today's FBO Daily Index Page |