Transcription of #1: Answers January 5, 2022
1 Cybersecurity Consulting Services RFP, Addendum #1: Questions & Answers January 5, 2022. RFP related inquiries received on or before January 4, 2022 are listed below along with the Authority's response. 1. Is our firm disqualified from participating if we are not DMBE certified? a. While we encourage participation from DMBE firms, it is not a requirement for this RFP. 2. Does the Cybersecurity Consulting Services solicitation need to integrate with existing operations, staff and/or systems? a. No 3. Is there a requirement and expectations for required cybersecurity continuous monitoring and risk remediation recommendation consultation support, subsequent to the hired supplier vulnerability analysis, threat identification and detection, cyberattack landscaping, evaluation of organizational governance documentation, cybersecurity awareness and training and recommended risk remediation get well plan? a. This RFP is intended to cover a one time risk and vulnerability assessment 4. Are there any special circumstances or "hot buttons" of which we should be aware?
2 A. None 5. What role will pricing play in the final decision for the Cybersecurity Consulting Services . contract award? What issues are of concern about pricing? Predictability? Risk/reward sharing? Cost reduction? a. Fees are one component of our overall evaluation, however we do have a limited budget and cost/benefit is always a consideration 6. Are there documents we should review or people we should speak with prior to responding? a. No, all information needed to respond is available in the RFP. 7. How many other diversity firms are competing? Which other firms are competing and which lawyers from those firms? a. We decline to speculate on the number or names of interested firms 8. Is there a current incumbent? How many incumbent vendors are on the existing contract for these services? a. There is not an incumbent 9. Are there technical evaluation requirements? a. See Section IV for evaluation and award criteria 10. What is the size and scope of the Virginia Resources Authority organization, in support of the Cybersecurity Consulting Services contract opportunity?
3 A. VRA has 16 total employees, with one person whose duties include oversight of the Authority's information technology. We utilize a third party firm for managed IT. services, including helpdesk and network support 11. Is this solicitation a re compete of an ongoing contract? If yes, can you please share the details of the incumbents? Can you please share the names of the incumbent suppliers on the existing contract? Could you please share the name of Current Suppliers (who are currently providing services to Virginia Resources Authority)? a. No, this is a new procurement 12. We would like to know if there are any eligibility criteria or requirements for suppliers to participate in the RFP Cybersecurity Consulting Services opportunity? a. There are no specific requirements for participation 13. Can a company submit a proposal as a prime vendor while being a sub contractor for another vendor ? a. Yes 14. Is there any preference to the incumbent vendors for this engagement? a. There is not an incumbent 15.
4 What listed personnel roles currently support the Virginia Resources Authority Cybersecurity Consulting Services opportunity? a. VRA's Director of Finance and Administration oversees the Authority's information technology assets. We utilize a third party firm for managed IT services, including helpdesk and network support. They will be utilized as a technical resource as needed. 16. How many candidates/resumes is a supplier allowed to submit to a single position request? a. We are not requesting specific positions in this engagement. See Section III B, Item 2 for instructions on supplying information on your engagement team 17. Are most (if not all) Cybersecurity Consulting Services personnel requests for full time, 40. hour/week positions? a. We are not requesting specific positions in this engagement 18. Where is the place of performance for the Cybersecurity Consulting Services opportunity? a. VRA's office is located in Richmond, Virginia 19. What specific background checks and/or drug screens are required for the Cybersecurity Consulting Services opportunity?
5 A. None outside of reference checks Page 2 of 27. 20. Will suppliers be required to supply any COVID 19 PPE? a. No 21. Please approximate how many live systems are externally (internet) facing. Ex. 5 External Hosts a. All VRA applications are only accessible through our VPN. 22. VRA mentions VMWare (presumably ESX) running on two of the servers but how many instances are running/active? a. We have six active virtual servers 23. Any cloud presence? If so, what services and how many endpoints? a. No cloud presence 24. Any in house developed software/web sites? a. None 25. Any external/regulatory drivers for the RFP? a. None 26. Any wireless footprint on site? And if so, is that a concern? a. Yes we have two Cisco Meraki MR33 access points and expect those to be included in the overall vulnerability assessment . 27. Is phishing or other social engineering training currently being performed? a. We have a subscription to Sophos Phish Threat and have periodically used it, but no formal plan or training schedule is in place 28.
6 VRA mentions execution of Internal vulnerability scans and External vulnerability scans and penetration scans. Is the expectation for the selected vendor to perform penetration testing (manual testing) only on External systems? With vulnerability scanning (automated scanning). conducted on External and Internal systems? a. We do not have any specific expectation regarding the types of testing, but will let the vendor propose a scan/testing plan to meet our objectives 29. At what depth would VRA like us to evaluate the current Threat Posture? For example, a high level assessment to align to the appropriate cybersecurity framework? Or more in depth, similar to a Purple Team where we work with VRA to execute common attack vectors and analyze the response capabilities? a. We envision a high level assessment to align with the appropriate cybersecurity framework 30. Approximately how many policies and procedures are currently in use and need to be reviewed as part of this assessment ?
7 A. There are 21 current IT Policies and Procedures in place Page 3 of 27. 31. Is this task a several months engagement for one Vulnerability assessment effort or multi year (ongoing) Vulnerability assessment effort a. This RFP is intended to cover a one time risk and vulnerability assessment 32. What is the period of performance to allow us to plan the delivery. a. We would like to have the evaluation completed and all deliverables to VRA by May 1, 2022. 33. Is there an existing incumbent whose period of performance has come due a. No, this is a new procurement 34. Is this task coming up for rebid because previous period of performance is over a. No, this is a new procurement 35. Is this a new Cybersecurity initiative and/ or VRA wants a trusted vendor in its environment for as needed Vulnerability assessment . a. This is a new initiative 36. What is the notional length of time expected for a firm to perform cybersecurity risk and vulnerability assessment ? a. We would like to have the evaluation completed and all deliverables to VRA by May 1, 2022.
8 37. What is the maximum expense allotted by the VRA for this contract? a. $50,000. 38. What pre approval or clearances are required for vendor consultants to work at VRA offices and with VRA equipment and personnel? a. There are no pre approvals or clearances required 39. Would a Department of Defense (DoD) security clearance be adequate for these purposes? a. There are no pre approvals or clearances required 40. Provide a complete inventory of the items that must be included in the required cybersecurity risk and vulnerability assessment . a. All VRA technology and equipment were outlined on page 4 of the RFP, with the exception of two Cisco Meraki MR33 access points and two Cisco switches that were omitted 41. What is the physical location of each item on the inventory list? a. All items are located in VRA's office, with most items in a locked server closet 42. Do the VRA systems include any non standard or Industrial Controls equipment? Page 4 of 27. a. No 43. Please provide an organization chart that illustrates all of the management relationships at VRA.
9 And indicates the total number of employees. a. VRA has 16 total employees. Our organizational chart can be found on page five of our annual financial report, located here: . reports/. 44. What is the VRA budget for additional equipment that may be required for the execution of the cybersecurity risk and vulnerability assessment ? a. VRA has a total budget of $50,000 for this engagement 45. What are the hardware or software options that would not be acceptable to VRA? a. There are no specific restrictions however anything that may disrupt our normal business operations will not be permitted. We may rely on an outside third party for assistance with evaluating the impact of proposed software on VRA's network. 46. Referencing Item # 5 Timeframe and Deliverables in Section III. Proposal Preparation and Submission Instructions B. Specific Proposal Instructions on page 7 of 13 in Cybersecurity Consulting Services , what is the calendar timeframe ( number of months and weeks) for completion of the cybersecurity risk and vulnerability assessment that would be considered technically acceptable to VRA during evaluation of proposals?
10 With an understanding of the VRA calendar and timeframe expectations, vendors can propose a solution that best meets the VRA requirements. a. We would like to have the evaluation completed and all deliverables to VRA by May 1, 2022. 47. What price structure does VRA seek? a. Pricing should be fixed and fair and reasonable for the services performed 48. What "services must a vendor include in the proposal for the VRA requested pricing option[s] . in order to be evaluated as technically acceptable? a. The proposals should include everything outlined in the Proposed Scope of Services on pages 6 7. 49. What will VRA be looking for in the vendor proposals to confirm the required capacity and resources? a. This will be evaluated based on the information provided regarding the firm and engagement team 50. What and how must a vendor illustrate regarding the capacity and resources to perform to be evaluated as technically acceptable? a. This will be evaluated based on the information provided regarding the firm's approach to performing the scope of services Page 5 of 27.