Sources sought
Network Detection and Response
CTS000010
Department of State, Acquisitions - Aqm Momentum.
Response deadline
June 12, 2025 at 1:00 PM EDT
Closed 463 days ago. Posted May 29, 2025. Scheduled to archive June 13, 2025.
Description
As published on SAM.gov.
The Office of Cyber Monitoring and Operations within the Department of State’s Bureau of Diplomatic Security, Directorate of Cyber and Technology Security manages a comprehensive portfolio of cybersecurity tools deployed to secure the Department of State’s (DOS) networks and data. This document outlines the requirements supporting the technical replacement and maturation of the Enterprise Network Detection and Response.
SCOPE Security Posture The DOS Cyber Protection program requires the capability to monitor network traffic to rapidly detect, assess and act upon anomalous activity on the Department’s networks. The ideal solution will baseline normal network activity, evaluate network packet metadata, and leverage threat intelligence to identify and escalate potential threat activity.
The Department needs a solution that will leverage advances in Artificial Intelligence and Machine Learning to streamline threat detection and response actions. Monitoring and Incident Response Responsibilities The scope of the Department’s monitoring and incident response responsibilities encompasses a hosted environment (network) that includes but is not limited to:
1) on-prem Sensitive but Unclassified (SBU);
2) SBU Azure Cloud environments, and 3) SBU AWS cloud environments. Various applications and services are hosted through multiple cloud service models such as IaaS, PaaS, and SaaS. Scalable Capacity In addition, the Department recognizes the need for any network detection and response capability to include a strategy and scalable capacity to monitor multiple disparate environments. These environments include:
air-gapped networks; dedicated internet networks (DINS); Demilitarized Zones (DMZs) hosted domestically and overseas (not connected to the enterprise network); and multiple, distinct Cloud Service Providers (CSPs) such as Google Cloud, AWS Commercial, AWS GovCloud, Azure Commercial, and Microsoft Azure Government (MAG). Contractor solutions shall not include managed service elements outside the scope of SaaS hosting. The contractor solution shall be turned over to the Department for daily management and operations. See attached sources sought for further details
Publications
Every notice SAM.gov issued under this solicitation number, oldest first. Each is a separate record on SAM.
May 29, 2025
Sources sought
Due June 12, 2025 at 1:00 PM EDT. SAM.gov, notice d4bdbd3a003a4a299ccab7558d03d25b
Points of contact
- Richard Crumcrumrb@state.gov2025060439
- Heather Keetonkeetonhf@state.gov7712046457
Also open from this buyer
- HAARP large scale blast testing and fragmentation characterizationSolicitationNAICS 541330Virginia19AQMM26Q0439Closes todaySep 18
- Local Guard Force - US Mission United Arab Emirates (UAE)PresolicitationNAICS 561612PR15904172-Pre-solicitationCloses todaySep 18
- DOS Overseas Furniture Install ServicesSolicitationSmall businessNAICS 238390Virginia19AQMM26R0279Closes todaySep 18
- ITP Classroom Construction,Comayagua, HondurasSources soughtNAICS 23622019AQMM26N0431Closes in 3 daysSep 21
- Cultural Property PrototypeCombined synopsis and solicitationSmall businessNAICS 54151119AQMM26Q0468Closes in 3 daysSep 21