The Networx contracts require a basic level of security management for its contractors that ensures compliance with Federal Government generally accepted security principles and practices, or better. The contracts employ adequate and reasonable means to ensure and protect the integrity, confidentiality, and availability of Networx services, Operational Support Systems (OSS), and Government information transported or stored in the contractor's Networx services infrastructure. These requirements are detailed in Section C.3.3.2 Security Management of the Networx contracts.
In addition to this mandatory level of security, the Networx contracts provide additional security services that may be ordered on a fee-for-service basis. These are:
The Managed E-Authentication Service (MEAS) offering is described below.
MEAS enables an individual to remotely authenticate his or her identity to an Agency Information Technology (IT) system. The service provides validation and verification of users via tokens and certificates. MEAS allows Agencies to securely conduct electronic transactions and implement E-Government initiatives via the Internet and other networks. The MEAS contractor provides and manages the authentication systems.
The diagram below illustrates a sample token-based MEAS implementation.
The following diagram illustrates a certificate-based MEAS implementation.
Note that illustrative hardware such as routers and firewalls depicted in the diagrams are not provided as part of the MEAS.
MEAS builds on the FTS2001 contracts offerings. The service connects to and interoperates with the Agency networking environment, including Demilitarized Zones (DMZs) and secure LANs as required by the Agency. The service also supports connectivity to extranets and public networks such as the Internet.
MEAS enables the remote authentication of individual users over a network for the purpose of electronic government and commerce. MEAS technical capabilities are defined in three major categories that are further detailed in Sections C.2.10.6.1.4.1, C.2.10.6.1.4.2 and C.2.10.6.1.4.3 of the Networx contracts.
Design and Engineering Services
Token-Based Implementation Management
Token-Based Implementation
Token-Based Management
Certificate-Based Implementation and Management
Certificate-Based Implementation
Certificate-Based Management
The MEAS feature set is described in Section C.2.10.6.2 of the Networx contracts. It consists of:
MEAS is required to support the User-to-Network Interfaces (UNIs) defined in applicable Networx services, for example:
Each Networx contractor may provide variations or alternatives to the offering and pricing for MEAS. The specific details can be found within each Contractor's Networx contract files and pricing notes for MEAS.
For more information on the general MEAS specifications and requirements, please refer to Section C.2.10.6 of the Networx contract for technical specifications and Section B.2.10.6 for pricing.
MEAS provides various methods (e.g., tokens, digital certificates, biometrics, e-signatures) for the authentication, validation, and verification of users over an Agency's systems and networks. Any required software components are included in the service prices. MEAS provides the following components:
MEAS builds on the FTS2001 contracts offerings.
Price components required for service are:
* Some or all price components are priced on an Individual Case Basis (ICB). CLINs with ICB prices are not available in the unit pricer.
Each Networx contractor may provide variations or alternatives to the offering and pricing for MEAS. The specific details can be found within each Contractor's Networx contract files and pricing notes for MEAS.
For more information on the general MEAS specifications and requirements, please refer to Section C.2.10.6 of the Networx contract for technical specifications and Section B.2.10.6 for pricing.