State Dept. seeks network detection and response services

On May 29, the U.S. Department of State issued a sources sought notice for network detection and response. Responses are due by 1:00 p.m. Eastern on June 12.

The Office of Cyber Monitoring and Operations within the Department of State’s Bureau of Diplomatic Security, Directorate of Cyber and Technology Security manages a comprehensive portfolio of cybersecurity tools deployed to secure the Department of State’s (DOS) networks and data.

The DOS Cyber Protection program requires the capability to monitor network traffic to rapidly detect, assess and act upon anomalous activity on the Department’s networks.  The ideal solution will baseline normal network activity, evaluate network packet metadata, and leverage threat intelligence to identify and escalate potential threat activity.  The Department needs a solution that will leverage advances in Artificial Intelligence and Machine Learning to streamline threat detection and response actions.

The scope of the Department’s monitoring and incident response responsibilities encompasses a hosted environment (network) that includes but is not limited to: 1) on-prem Sensitive but Unclassified (SBU); 2) SBU Azure Cloud environments, and 3) SBU AWS cloud environments.  Various applications and services are hosted through multiple cloud service models such as IaaS, PaaS, and SaaS.

In addition, the Department recognizes the need for any network detection and response capability to include a strategy and scalable capacity to monitor multiple disparate environments.  These environments include: air-gapped networks; dedicated internet networks (DINS); Demilitarized Zones (DMZs) hosted domestically and overseas (not connected to the enterprise network); and multiple, distinct Cloud Service Providers (CSPs) such as Google Cloud, AWS Commercial, AWS GovCloud, Azure Commercial, and Microsoft Azure Government (MAG).

Contractor solutions shall not include managed service elements outside the scope of SaaS hosting. The contractor solution shall be turned over to the Department for daily management and operations.

Review the State Dept. network detection and response sources sought.

Source: SAM

IC News brings you business opportunities like this one each week. If you find value in our work, please consider supporting IC News with a subscription.