The Defense Information System Agency (DISA) is issuing a Request for Information (RFI) to gather industry input for a future Endpoint Security Event Management System supporting the Army’s Unified Network Zero Trust Architecture. The effort will involve operating, maintaining, and securing a global endpoint ecosystem, enforcing Comply‑to‑Connect policies, building a hybrid‑cloud Security Information and Event Management (SIEM) environment, and supporting advanced data‑science workloads at multiple Regional Cyber Centers, with the primary performance site at the Global Cyber Center, Ft. Huachuca, AZ.
• Scope includes Endpoint Detection & Response (Microsoft Defender, Elastic Defend), automated malware quarantine, default‑deny application controls, and post‑quantum cryptography readiness assessments.
• Enforcement of the 5‑step Comply‑to‑Connect (C2C) framework integrating Forescout, ICAM, and vulnerability‑management tools.
• Construction of a federated USIEM ecosystem using Elastic Stack, Kubernetes, Apache Kafka, and Cribl, with data pipelines feeding the Army’s Big Data Platform (Gabriel Nimbus).
• Operation of the “NETCOM Edge” collaborative development environment for high‑performance storage, GPU compute, and secure Python package repositories.
• The RFI requests a 3‑page white paper describing technical approach, risk mitigation, and relevant experience in at least three of the listed capability areas.
• Responses due by 3:00 PM EDT on 9 Oct 2026; questions due by 3:00 PM EDT on 5 Oct 2026.
• No funding is attached to the RFI; the information will inform a future solicitation likely to be a multi‑year, multi‑award contract.