The document outlines a series of technical and operational inquiries for responding to a government Request for Proposal (RFP) related to Public Key Infrastructure (PKI) services. Key topics covered include the integration of hardware security modules (HSM), experience with generating certificate revocation lists (CRLs), and recommendations for enhancing PKI services. It also addresses the handling of key management, emergency operations, and the capabilities of the organization in maintaining government-owned systems.
Contractual elements are highlighted, including the ability to manage a successful contract transition, respond to Distributed Denial of Service (DDoS) attacks, and implement Supply Chain Risk Management (SCRM) practices. The security section emphasizes the importance of cybersecurity tools, incident response protocols, and disaster recovery plans, specifically in relation to Certificate Authorities (CAs).
Overall, the document serves as a comprehensive framework aimed at soliciting detailed responses from potential contractors about their qualifications and strategies concerning PKI operations, compliance standards, and security practices to ensure effective government collaboration in cybersecurity efforts.
The General Services Administration (GSA) has issued a Request for Information (RFI) and Sources Sought for Technical and Operations Support related to the Federal Public Key Infrastructure (FPKI). This initiative aims to gather insights from potential respondents regarding their capabilities in supporting FPKI, which was established under the E-Government Act of 2002 to enhance security and interoperability between various Certificate Authorities (CAs) used by federal, state, and local governments. The RFI emphasizes the need for experienced personnel to manage PKI capabilities and emerging technologies, ensuring alignment with federal security policies. Respondents are required to detail their experiences in areas such as PKI support, Publicly Trusted CAs, security management, and innovative technologies relevant to PKI. Responses will help refine the acquisition strategy and inform future procurement actions. Notably, this announcement serves as a preliminary information-gathering exercise, not a solicitation for proposals, and all submissions will become government property.