SPECIAL NOTICE
R -- Identity Credentialing & Access Mgmt (ICAM) Subject Matter Expertise
- Notice Date
- 3/5/2013
- Notice Type
- Special Notice
- NAICS
- 541512
— Computer Systems Design Services
- Contracting Office
- Department of the Treasury, Bureau of the Public Debt (BPD), Division of Procurement, Avery 5F, 200 Third Street, Parkersburg, West Virginia, 26106-5312, United States
- ZIP Code
- 26106-5312
- Solicitation Number
- SS-FMS-13-0048
- Point of Contact
- M. Forbes, , G. Huffman,
- E-Mail Address
-
psb3@bpd.treas.gov, psb3@bpd.treas.gov
(psb3@bpd.treas.gov, psb3@bpd.treas.gov)
- Small Business Set-Aside
- N/A
- Description
- The Bureau of Fiscal Services (BPD), on behalf of the Financial Management Services (FMS) intends to issue an order to Deloitte Consulting LLC on a sole source basis, under authority of FAR 8.405-6 (b)(1), for Identity Credentialing and Access Management (ICAM) subject matter expertise to assist FMS' IBM Tivoli Identity Management (ITIM) developers and engineers with the (ITIM) full automation of user provisioning and security consulting services encompassing ICAM and related reporting. Since April of 2005, Deloitte has provided FMS with guidance and subject matter expertise surrounding its Identity Credentialing and Access Management program and a broad range of security and privacy services. Given the scope and timeline of services sought, the vendor's comprehensive knowledge of the current ICAM architecture, and more specifically IBM's Tivoli Identity Manager (ITIM), Deloitte is in the distinctive position of being able to perform critical time sensitive tasks within the targeted constrained time period without delay. Deloitte resources understand FMS' environment, culture, business and technical processes. Therefore this vendor is uniquely capable of providing the technical subject matter expertise around FMS' ITIM implementation and ICAM related inter-dependencies such as: • Requirements gathering (business and technical), architecture/design and implementation and support of the enterprise-wide Identity Management solution utilizing ITIM and CA SiteMinder, to include core objective of extending ITIM and legacy FMS' PIV Data Synchronization (PDS) to Legacy BPD; • Maintaining standardization of an Identity Management framework upon which logical application access can be requested, approved, and granted; and enablement of password management services (self-service, forgot password, expirations, and service desk lock/unlock); and management of LDAP (lightweight directory access protocol and Active Directory groups; • Full implementation of an advanced PIV Data Synchronization (PDS) Integration of FMS' (Fiscal Service) ITIM system with USAccess/HRConnect (HRC) at GSA; and technical implementation of LACS (logical access control) & PACS (physical access control) in accordance with Department of Treasury's FICAM (Federal Identity Credentialing and Access Management) Roadmap. Rare and specialized expertise of assembly line development using ITDI (IBM Tivoli Directory Integrator) as well as construction and integration of cloud-based web services, all in the furtherance of the PDS integrated solution and other application implementations; • Guidance and support on adherence to FICAM, NSTIC, NIST guidance, HSPD-12 directives and • Continued support for our ongoing HSPD-12 initiatives (Federation, PIV, PIV-I, and PKI, etc.); • Continued tier-3 assistance and Production support with the historical and technical knowledge of legacy FMS, legacy BPD and TWAI infrastructure and processes, along with the integration challenges that are continually arising from these areas • Expertise and proven track record of overcoming complex technical design challenges by offering solutions that are standardized enough to meet industry standards and EICAM practices, yet flexible enough to accommodate unique application-specific requirement nuances; • Continued demonstration of advanced knowledge of FMS' infrastructure solutions including Websphere, Siteminder, Load Balancers, LDAP, Unix and Microsoft operating systems, all crucial for successful implementation in a highly integrated environmentWith the benefit of Deloitte's expertise in the ICAM security arena and its support efforts to date, FMS has successfully: • Established an advanced enterprise-wide identity and access management solution with full delegated & self-administration capabilities, all within a common provisioning solution framework; • Engineered a robust provisioning solution, scalable for expansion throughout FMS, to include consolidation of three disparate, geographically dispersed provisioning solutions into one, significantly increasing the number of managed systems (600+ UNIX systems) and infrastructure (Active Directory, Lotus Notes, LDAP and various PACS) components with less development and engineering effort; • Automated On-Boarding & Maintenance of Employees and Contractors; Automated synchronization and consistency in data between HRC, ITIM, PACS with HRC being the authoritative source; Elimination of manual feeds for ITIM and for PACS; • Automated business process of Recertification; provided extensive self-service capabilities, delegated approvals and administration capabilities to individual's best suited to perform the functions; • Guided FMS in complying with IT Security standards and policies; • Enhanced security by enforcing separation of duties, providing mandatory approvals and preventing administrators from bypassing approval controls, eliminating silos of user administration, enabling Single Sign-On to the provisioning environment and providing reduced sign-on to web applications; There are three (3) critical initiatives and related deliverables associated with this requirement that will be at risk if a sole source order is not issued to Deloitte for ICAM support: 1) Consolidation of provisioning tools through the development and implementation of ITIM workflows. This effort primarily involves the migration of seven (7) UPS provisioned applications (TWAI applications) into ITIM prior to September 30, 2013. The absence of required SME support pertaining to development of ITIM workflows and account management controls within targeted timelines will negatively impact targeted application business customers by delaying migration and automation of provisioning workflows, required user recertification and other planned security controls to be implemented through integration with ITIM. Moreover, such delays will produce additional risk pertaining to FMS' ability to implement FICAM and enforce NIST 800-53 Security Controls. 2) Further expansion of HSPD-12 initiatives through the extension of legacy FMS' PIV (Personal Identity Verification) Data Synchronization (PDS) solution to Legacy BPD (Bureau of the Public Debt). To streamline physical and logical access to resources, FMS successfully implemented a PIV Data Synchronization (PDS) process, integrating employee and contractor onboarding between HRConnect, USAccess and ITIM. Deloitte was instrumental in aiding FMS with the design, development, implementation and support of this solution. Deloitte's SME resources are currently assisting legacy BPD developer and IT resources in an effort to extend PDS functionalities for all Legacy BPD employee and contractor onboarding. If Deloitte services become unavailable during this ongoing project, the likelihood of project delays and immediate negative impact to bureau consolidation efforts is extremely high. For example, any further delay in extending PDS functionality throughout Fiscal Service will prevent full automation of employee and contractor onboarding, resulting in increasingly labor and resource intensive manual processes and rework once the solution is subsequently implemented. 3) Extension of ITIM provisioning to legacy BPD resources is an FMS and BPD strategic priority and a tactical initiative centered on aligning both agencies to Federal and Department of Treasury IT security mandates and guidance (e.g., TDP 85-01, NIST 800-53, FICAM and OMB M-11-11). This initiative dictates careful coordination with a variety of business stakeholders, Federal Program Agencies, application integrators and other stakeholders. Deloitte resources have a comprehensive working knowledge of ITIM and the Enterprise Architecture, due to the various levels of security and technical support it has provided in implementing ITIM and other segments of FMS' Identity and Access Management Program over the last eight years. A shift from Deloitte in providing this support will adversely impact requirements, development and ultimately application-specific integration with ITIM; the result of which will negatively impact application commitments and targeted account management controls. The outcome of such delay will require increased funding by the government to support interim operations and maintenance cost (at the application level) and will also require additional FTE time necessary to develop manual work-around processes within the EICAM division. The success of this project depends on uninterrupted SME support through a critical period of security guidance and knowledge transfer that runs through September 30, 2013. The absence of Deloitte resources during this time would have a cascading impact on these three critical and time sensitive projects, as well as other initiatives. Based on a preliminary assessment of the IAM vendor market and given the historical knowledge that Deloitte maintains as a leader in the IAM and Security Spaces, an alternative vendor would not be able to transition onto this project and complete deliverables within the allowable time-frame. To transition to another vendor at this time is not feasible given Deloitte's historical knowledge, active knowledge transfer activities and comprehensive knowledge of industry practices in the area of ICAM. Continued support with Deloitte will provide for structured and documented knowledge transfer to Government Personnel for a six month period allowing time for a longer term contract to be competed and awarded. It is the Governments intent is to issue a solicitation package in the next two months for a longer term vehicle for (ICAM) subject matter expertise to assist FMS' IBM Tivoli Identity Management (ITIM) developers and engineers with the (ITIM) full automation of user provisioning and security consulting services encompassing ICAM and related reporting. For this six month award, no solicitation package will be issued. This notice of intent to sole source is not a request for competitive quotations; however, the Government will consider responses received no later than 12:00 PM ET on March 11, 2013. Responses shall be submitted to PSB3@bpd.treas.gov; Attention: M. Forbes / G. Huffman. Responses shall include, at a minimum, the following information: 1. The name of your company; 2. Company DUNS No.; 3. POC name and contact information; 4. The specific service(s) that your company offers that fulfills the same function as the services to be included on this order or evidence that your company is capable of providing a renewal for the specific services mentioned above; and, 5. A description of the service(s) and your company's overall capabilities. It is your responsibility to demonstrate how your services(s) are capable of providing the same services that exists with Identity Credentialing and Access Management (ICAM) subject matter expertise to assist FMS' IBM Tivoli Identity Management (ITIM) developers and engineers with the (ITIM) full automation of user provisioning and security consulting services encompassing ICAM and related reporting mentioned above. The Government will not seek additional information from your company if you fail to provide sufficient evidence of having services cable of meeting the Government's needs. A determination by the Government not to compete the proposed acquisition based upon responses to this notice is solely within the discretion of the Government's Contracting Officer. Information received will normally be considered solely for the purpose of determining whether to conduct a competitive procurement.
- Web Link
-
FBO.gov Permalink
(https://www.fbo.gov/spg/TREAS/BPD/DP/SS-FMS-13-0048/listing.html)
- Place of Performance
- Address: Prince George's County, Maryland or Washington, DC, United States
- Record
- SN03003821-W 20130307/130305234700-8993dde3f00bebb7ded61c1f71cd057b (fbodaily.com)
- Source
-
FedBizOpps Link to This Notice
(may not be valid after Archive Date)
| FSG Index | This Issue's Index | Today's FBO Daily Index Page |