SOURCES SOUGHT
L -- Information System Security Manager
- Notice Date
- 8/7/2013
- Notice Type
- Sources Sought
- NAICS
- 541513
— Computer Facilities Management Services
- Contracting Office
- Department of the Air Force, Air Education and Training Command, JBSA Lackland - 802d Contracting Squadron, 1655 Selfridge Avenue, JBSA Lackland, Texas, 78236-5253, United States
- ZIP Code
- 78236-5253
- Solicitation Number
- F2MTCW3142A001
- Archive Date
- 8/28/2013
- Point of Contact
- Michael V. Doerr, Phone: 210-925-9124, Shandi L. Speedy, Phone: 2109259123
- E-Mail Address
-
michael.doerr@us.af.mil, shandi.speedy@us.af.mil
(michael.doerr@us.af.mil, shandi.speedy@us.af.mil)
- Small Business Set-Aside
- N/A
- Description
- This is a SOURCES SOUGHT NOTICE (not a presolicitation notice pursuant to FAR Part 5). The Department of the Air Force, 802nd Contracting Squadron, JBSA-Lackland, TX, is seeking sources to perform services for an Information System Security Manager or ISSM. This notice is for planning purposes only and shall not be construed as a formal solicitation or an obligation on the part of the Government to acquire any products or services. The Government is not liable for any costs incurred by interested parties in responding to this request for information. The purpose of this request for information is to determine the capability of potential sources and the availability of commercial sources pursuant to FAR Part 10. Large and small businesses are encouraged to participate in this survey. DESCRIPTION OF SERVICES: The contractor shall plan, develop, and evaluate IT system security techniques and system support plans and provide technical expertise in implementing security standards and guidelines outlined in National Security Agency (NSA), Department of Defense (DoD) and Air Force instructions, manuals and policies to provide security guidance and information to new or existing systems throughout their lifecycle. The contractor shall be certified IAW DOD 8570.01 to accomplish the task outlined in this PWS. The certification must be one of the following: -ISC2 Certified Authorization Professional - CAP (Level 1/2) -SANS GIAC Security Leadership Certification - GSLC (Level 1/2) -ISACA Certified Information Security Manager - CISM (Level 2/3) -ISC2 Certified Information Systems Security Professional - CISSP (Level 2/3) The required subtasks include but are not limited to: -Ensure system security requirements are achieved and provide security Certification & Accreditation (C&A) packages for Designated Approval Authority (DAA) signature. -Provide technical security evaluations on new products, update existing C&A packages to maintain validity, and conduct security testing, in accordance with the latest security products and processes. -Define and validate technical security requirements for proposed IT systems and document system security design approaches and/or determine if system design approaches meet mission security requirements. -Review and analyze new or revised security-related documentation, formal correspondence, technical reports, and recommendations related to IT security for security-related guidance and requirements and present results in a report. -Develop recommendations based on analysis of IT system security documents and actual posture, and ensure defects are identified. -Analyze network security scans and recommend fixes for vulnerabilities discovered in the application and document in a Test Analysis Report. -Monitor network penetration activities and review security data files and document in a Test Analysis Report. -Monitor DISA/NSA Security Technical Implementation Guides (STIG) and associated processes for implementation including Security Readiness Reviews (SRR) and document in a Test Analysis Report. -Develop C&A packages for customers using standardized approaches and documentation, tailor C&A activities based on required level of effort and applicability of various tasks, and reuse of technical (and non-technical, if applicable) analyses from previous C&A efforts related to reaccreditations of similar systems based on the DOD Information Assurance Certification and Accreditation Process (DIACAP) or the most current DOD guidance. (CDRL A001-1) The NAICS Code for this requirement is 541513. All potential contractors must be registered in the System for Award Management (SAM) database with a commercial and government entity code (CAGE Code). Responses should contain company name, address, point of contact, cage code, phone number, DUNS number, Business Size, and GSA schedule (if applicable). Interested sources shall submit their responses via e-mail to SSgt Michael V. Doerr at, michael.doerr@us.af.mil. Responses must be received no later than 1:00 PM, CST, 13 August 2013.
- Web Link
-
FBO.gov Permalink
(https://www.fbo.gov/spg/USAF/AETC/LackAFBCS/F2MTCW3142A001/listing.html)
- Place of Performance
- Address: JBSA-Lackland, TX, Lackland AFB, Texas, 78236, United States
- Zip Code: 78236
- Zip Code: 78236
- Record
- SN03140396-W 20130809/130807235651-6ec008605026c0de545cd5f23e5ebbbd (fbodaily.com)
- Source
-
FedBizOpps Link to This Notice
(may not be valid after Archive Date)
| FSG Index | This Issue's Index | Today's FBO Daily Index Page |