15
SCHEDULE M Date: 9/12/2014 CAROUSEL INDUSTRIES PRICELIST - STATE OF NJ MANAGED SERVICES SmartPoint Guard DETECT Scanning and Penetration Testing Services Product Code One Time Set Up Fee Compliance certified vulnerability scanning and penetration testing against your internal or external network posture to identify potential threats and weakness PCI-ASV Network Scanning (and other industy compliance) Scan up to 255 IP addresses on customer's own network CG-IPCI 255 1,588.02 $ Scan up to 512 IP addresses on customer's own network CG-IPCI 512 2,864.82 $ Scan up to 1024 IP addresses on customer's own network CG-IPCI1024 4,780.02 $ Scan up to 3000 IP addresses on customer's own network CG-IPCI3000 7,972.02 $ Enterprise Vulnerability Scanning - External (public IP addresses) Web based vulnerability scanning for 64 IP addresses CG-EVSS/64 630.42 $ Web based vulnerability scanning for 128 IP addresses CG-EVSS/128 949.62 $ Web based vulnerability scanning for 256 IP addresses CG-EVSS/256 1,588.02 $ Web based vulnerability scanning for 512 IP addresses CG-EVSS/512 2,864.82 $ Enterprise Vulnerability Scannning - Internal (private IP addresses) Web based vulnerability scanning for 64 IP addresses CG-EVSSI/64 2,386.02 $ Web based vulnerability scanning for 128 IP addresses CG-EVSSI/128 3,184.02 $ Web based vulnerability scanning for 256 IP addresses CG-EVSSI/256 4,780.02 $ Web based vulnerability scanning for 512 IP addresses CG-EVSSI/512 7,972.02 $ On-Demand Penetration Testing (via self-managed web portal) On-Demand Penetration Testing - up to 255 hosts and 7 day access CG-PenTest/OD 6,376.02 $ On-Demand Web Application Testing - up to 255 hosts and 7 day access CG-PenTest/WA 7,972.02 $ YEAR 1 PRICING WITH 5% DISCOUNT Discount pricing applies to orders placed within the first year of the State Contract term YEAR 1 PRICING WITH 5% DISCOUNT Carousel Industries - State of New Jersey Price List Page 1

MANAGED SERVICES - New Jersey€¦ · Managed Penetration Test - up to 64 IP addresses CG-PenTest/MPT $ 12,760.02 Managed Web Application Test - up to 10 URLs CG-PenTest/MWA $ 15,952.02

  • Upload
    others

  • View
    2

  • Download
    0

Embed Size (px)

Citation preview

Page 1: MANAGED SERVICES - New Jersey€¦ · Managed Penetration Test - up to 64 IP addresses CG-PenTest/MPT $ 12,760.02 Managed Web Application Test - up to 10 URLs CG-PenTest/MWA $ 15,952.02

SCHEDULE M Date: 9/12/2014CAROUSEL INDUSTRIES PRICELIST - STATE OF NJ

MANAGED SERVICES

SmartPoint Guard DETECT

Scanning and Penetration Testing Services Product Code

One Time

Set Up Fee Compliance certified vulnerability scanning and penetration testing

against your internal or external network posture to identify

potential threats and weaknessPCI-ASV Network Scanning (and other industy compliance)

Scan up to 255 IP addresses on customer's own network CG-IPCI 255 1,588.02$

Scan up to 512 IP addresses on customer's own network CG-IPCI 512 2,864.82$

Scan up to 1024 IP addresses on customer's own network CG-IPCI1024 4,780.02$

Scan up to 3000 IP addresses on customer's own network CG-IPCI3000 7,972.02$

Enterprise Vulnerability Scanning - External (public IP addresses)

Web based vulnerability scanning for 64 IP addresses CG-EVSS/64 630.42$

Web based vulnerability scanning for 128 IP addresses CG-EVSS/128 949.62$

Web based vulnerability scanning for 256 IP addresses CG-EVSS/256 1,588.02$

Web based vulnerability scanning for 512 IP addresses CG-EVSS/512 2,864.82$

Enterprise Vulnerability Scannning - Internal (private IP addresses)

Web based vulnerability scanning for 64 IP addresses CG-EVSSI/64 2,386.02$

Web based vulnerability scanning for 128 IP addresses CG-EVSSI/128 3,184.02$

Web based vulnerability scanning for 256 IP addresses CG-EVSSI/256 4,780.02$

Web based vulnerability scanning for 512 IP addresses CG-EVSSI/512 7,972.02$

On-Demand Penetration Testing (via self-managed web portal)

On-Demand Penetration Testing - up to 255 hosts and 7 day access CG-PenTest/OD 6,376.02$

On-Demand Web Application Testing - up to 255 hosts and 7 day access CG-PenTest/WA 7,972.02$

YEAR 1 PRICING WITH 5% DISCOUNTDiscount pricing applies to orders placed within

the first year of the State Contract term

YEAR 1 PRICING WITH 5% DISCOUNT

Carousel Industries - State of New Jersey Price List Page 1

Page 2: MANAGED SERVICES - New Jersey€¦ · Managed Penetration Test - up to 64 IP addresses CG-PenTest/MPT $ 12,760.02 Managed Web Application Test - up to 10 URLs CG-PenTest/MWA $ 15,952.02

Managed Penetration Testing - Internal/External

Managed Penetration Test - up to 64 IP addresses CG-PenTest/MPT 12,760.02$

Managed Web Application Test - up to 10 URLs CG-PenTest/MWA 15,952.02$

SmartPoint Guard PROTECT Managed

Perimeter Security Services Product Code One Time

Set Up Fee

Monthly

Recurring

Co-Managed

Monthly

Recurring 24/7 Management of perimeter related network security devices, such as

firewalls, IPS and UTMs, with alerting and reporting.

IDP/IPS for best of breed hardware

MIDP SME with up to 100Mbps throughput CG-MIDP/S 4,548.60$ 1,588.02$ 1,111.61$

MIDP Corporate with up to 1Gbps throughput CG-MIDP/C 9,108.60$ 2,864.82$ 2,005.37$

MIDP Enterprise with >1Gbps throughput CG-MIDP/E 11,388.60$ 3,716.02$ 2,601.21$

For co-managed services reduce MR by 30% CG-CMIDP

IDP/IPS with Clone Systems hardware *****

MIPS with Hardware/software - SME with up to 100Mbps throughput CG-MIPS/S 5,688.60$ 1,428.42$ NA

MIPS with Hardware/software - Corporate with up to 1Gbps throughput CG-MIPS/C 9,488.60$ 1,893.92$ NA

MIPS with Hardware/software - Enterpise >1Gbps CG-MIPS/E 11,388.60$ 2,705.22$ NA

UTM/Next Gen FW Services for best of breed hardware

MUTM SME with up to 100Mbps throughput CG-MUTM/S 4,548.60$ 1,905.62$ 1,333.94$

MUTM Corporate with up to 1Gbps throughput CG-MUTM/C 9,108.60$ 3,437.78$ 2,406.45$

MUTM Enterprise with >1Gbps throughput CG-MUTM/E 11,388.60$ 4,459.22$ 3,121.46$

For co-managed services reduce MR by 30% CG-CMUTM

Firewall for best of breed hardware

MFW SME with up to 100Mbps throughput CG-MFW/S 3,408.60$ 1,268.82$ 888.17$

MFW Corporate with up to 1Gbps throughput CG-MFW/C 4,548.60$ 1,588.02$ 1,111.61$

MFW Enterprise with >1Gbps throughput CG-MFW/E 5,688.60$ 2,066.82$ 1,446.77$

For co-managed services reduce MR by 30% CG-CMFW

VPN for best of breed hardware

MVPN Monitoring Service CG-MVPN 1,508.60$ 750.12$ 525.08$

For co-managed services reduce MR by 30% CG-CMVPN

YEAR 1 PRICING WITH 5% DISCOUNT

Carousel Industries - State of New Jersey Price List Page 2

Page 3: MANAGED SERVICES - New Jersey€¦ · Managed Penetration Test - up to 64 IP addresses CG-PenTest/MPT $ 12,760.02 Managed Web Application Test - up to 10 URLs CG-PenTest/MWA $ 15,952.02

SmartPoint Guard CORRELATE

Managed Perimeter Security Services Product Code

One Time

Set Up Fee Monthly

Recurring Base

Monthly

Recurring per

Host

Centralized security intelligence in real-time by correlating various events

and incidents from all network devices using log management.

SIEM Services - Log correlation, analytics, and real-time reporting

includes Log Management Service

SIEM up to 100 hosts CG-SIEM-100 3,408.60$ 1,027.03$ 31.02$

SIEM up to 500 hosts CG-SIEM-500 4,548.60$ 1,441.99$ 20.64$

SIEM up to 1000 hosts CG-SIEM-1000 11,388.60$ 2,064.43$ 10.27$

SIEM >5000 hosts CG-SIEM-5000 15,188.60$ 4,139.23$ 6.12$

SmartPoint Guard COLLECT Managed

Perimeter Security Services Product Code

One Time

Set Up Fee Monthly

Recurring Base

Monthly

Recurring per

Host Real-time monitoring alerting and reporting of logs collected from multiple

devices across the entire network.

Log Management - Log collection, storage, monitoring, alerting, and

reporting in real-time

LOGM up to 100 hosts CG-LOGM-100 3,408.60$ 790.02$ 23.86$

LOGM up to 500 hosts CG-LOGM-500 4,548.60$ 1,109.22$ 15.88$

LOGM up to 1000 hosts CG-LOGM-1000 11,388.60$ 1,588.02$ 7.90$

LOGM 5000+ hosts CG-LOGM-5000 15,188.60$ 3,184.02$ 4.71$

HIDS Host-based Intrusion Detection Services

HIDS up to 100 hosts CG-HIDS-100 3,408.60$ 790.02$ 23.86$

HIDS up to 500 hosts CG-HIDS-500 4,548.60$ 1,109.22$ 15.88$

HIDSup to 1000 hosts CG-HIDS-1000 11,388.60$ 1,588.02$ 7.90$

HIDS 5000+ hosts CG-HIDS-5000 15,188.60$ 3,184.02$ 4.71$

YEAR 1 PRICING WITH 10% DISCOUNT

YEAR 1 PRICING WITH 5% DISCOUNT

Carousel Industries - State of New Jersey Price List Page 3

Page 4: MANAGED SERVICES - New Jersey€¦ · Managed Penetration Test - up to 64 IP addresses CG-PenTest/MPT $ 12,760.02 Managed Web Application Test - up to 10 URLs CG-PenTest/MWA $ 15,952.02

SCHEDULE M Date: 9/12/2014CAROUSEL INDUSTRIES PRICELIST - STATE OF NJ

MANAGED SERVICES

SmartPoint Guard DETECT

Scanning and Penetration Testing Services Product Code

One Time

Set Up Fee Compliance certified vulnerability scanning and penetration testing

against your internal or external network posture to identify

potential threats and weaknessPCI-ASV Network Scanning (and other industy compliance)

Scan up to 255 IP addresses on customer's own network CG-IPCI 255 1,671.60$

Scan up to 512 IP addresses on customer's own network CG-IPCI 512 3,015.60$

Scan up to 1024 IP addresses on customer's own network CG-IPCI1024 5,031.60$

Scan up to 3000 IP addresses on customer's own network CG-IPCI3000 8,391.60$

Enterprise Vulnerability Scanning - External (public IP addresses)

Web based vulnerability scanning for 64 IP addresses CG-EVSS/64 663.60$

Web based vulnerability scanning for 128 IP addresses CG-EVSS/128 999.60$

Web based vulnerability scanning for 256 IP addresses CG-EVSS/256 1,671.60$

Web based vulnerability scanning for 512 IP addresses CG-EVSS/512 3,015.60$

Enterprise Vulnerability Scannning - Internal (private IP addresses)

Web based vulnerability scanning for 64 IP addresses CG-EVSSI/64 2,511.60$

Web based vulnerability scanning for 128 IP addresses CG-EVSSI/128 3,351.60$

Web based vulnerability scanning for 256 IP addresses CG-EVSSI/256 5,031.60$

Web based vulnerability scanning for 512 IP addresses CG-EVSSI/512 8,391.60$

On-Demand Penetration Testing (via self-managed web portal)

On-Demand Penetration Testing - up to 255 hosts and 7 day access CG-PenTest/OD 6,711.60$

On-Demand Web Application Testing - up to 255 hosts and 7 day access CG-PenTest/WA 8,391.60$

POST YEAR 1 PRICINGApplies to orders placed in Year 2 of the State

Contract term or later

POST YEAR 1 PRICING

Carousel Industries - State of New Jersey Price List Page 4

Page 5: MANAGED SERVICES - New Jersey€¦ · Managed Penetration Test - up to 64 IP addresses CG-PenTest/MPT $ 12,760.02 Managed Web Application Test - up to 10 URLs CG-PenTest/MWA $ 15,952.02

Managed Penetration Testing - Internal/External

Managed Penetration Test - up to 64 IP addresses CG-PenTest/MPT 13,431.60$

Managed Web Application Test - up to 10 URLs CG-PenTest/MWA 16,791.60$

SmartPoint Guard PROTECT Managed

Perimeter Security Services Product Code One Time

Set Up Fee

Monthly

Recurring

Co-Managed

Monthly

Recurring 24/7 Management of perimeter related network security devices, such as

firewalls, IPS and UTMs, with alerting and reporting.

IDP/IPS for best of breed hardware

MIDP SME with up to 100Mbps throughput CG-MIDP/S 4,788.00$ 1,671.60$ 1,170.12$

MIDP Corporate with up to 1Gbps throughput CG-MIDP/C 9,588.00$ 3,015.60$ 2,110.92$

MIDP Enterprise with >1Gbps throughput CG-MIDP/E 11,988.00$ 3,911.60$ 2,738.12$

For co-managed services reduce MR by 30% CG-CMIDP

IDP/IPS with Clone Systems hardware *****

MIPS with Hardware/software - SME with up to 100Mbps throughput CG-MIPS/S 5,988.00$ 1,503.60$ NA

MIPS with Hardware/software - Corporate with up to 1Gbps throughput CG-MIPS/C 9,988.00$ 1,993.60$ NA

MIPS with Hardware/software - Enterpise >1Gbps CG-MIPS/E 11,988.00$ 2,847.60$ NA

UTM/Next Gen FW Services for best of breed hardware

MUTM SME with up to 100Mbps throughput CG-MUTM/S 4,788.00$ 2,005.92$ 1,404.14$

MUTM Corporate with up to 1Gbps throughput CG-MUTM/C 9,588.00$ 3,618.72$ 2,533.10$

MUTM Enterprise with >1Gbps throughput CG-MUTM/E 11,988.00$ 4,693.92$ 3,285.74$

For co-managed services reduce MR by 30% CG-CMUTM

Firewall for best of breed hardware

MFW SME with up to 100Mbps throughput CG-MFW/S 3,588.00$ 1,335.60$ 934.92$

MFW Corporate with up to 1Gbps throughput CG-MFW/C 4,788.00$ 1,671.60$ 1,170.12$

MFW Enterprise with >1Gbps throughput CG-MFW/E 5,988.00$ 2,175.60$ 1,522.92$

For co-managed services reduce MR by 30% CG-CMFW

VPN for best of breed hardware

MVPN Monitoring Service CG-MVPN 1,588.00$ 789.60$ 552.72$

For co-managed services reduce MR by 30% CG-CMVPN

POST YEAR 1 PRICING

Carousel Industries - State of New Jersey Price List Page 5

Page 6: MANAGED SERVICES - New Jersey€¦ · Managed Penetration Test - up to 64 IP addresses CG-PenTest/MPT $ 12,760.02 Managed Web Application Test - up to 10 URLs CG-PenTest/MWA $ 15,952.02

SmartPoint Guard CORRELATE

Managed Perimeter Security Services Product Code

One Time

Set Up Fee Monthly

Recurring Base

Monthly

Recurring per

Host

Centralized security intelligence in real-time by correlating various events

and incidents from all network devices using log management.

SIEM Services - Log correlation, analytics, and real-time reporting

includes Log Management Service

SIEM up to 100 hosts CG-SIEM-100 3,588.00$ 1,081.08$ 32.65$

SIEM up to 500 hosts CG-SIEM-500 4,788.00$ 1,517.88$ 21.73$

SIEM up to 1000 hosts CG-SIEM-1000 11,988.00$ 2,173.08$ 10.81$

SIEM >5000 hosts CG-SIEM-5000 15,988.00$ 4,357.08$ 6.44$

SmartPoint Guard COLLECT Managed

Perimeter Security Services Product Code

One Time

Set Up Fee Monthly

Recurring Base

Monthly

Recurring per

Host Real-time monitoring alerting and reporting of logs collected from multiple

devices across the entire network.

Log Management - Log collection, storage, monitoring, alerting, and

reporting in real-time

LOGM up to 100 hosts CG-LOGM-100 3,588.00$ 831.60$ 25.12$

LOGM up to 500 hosts CG-LOGM-500 4,788.00$ 1,167.60$ 16.72$

LOGM up to 1000 hosts CG-LOGM-1000 11,988.00$ 1,671.60$ 8.32$

LOGM 5000+ hosts CG-LOGM-5000 15,988.00$ 3,351.60$ 4.96$

HIDS Host-based Intrusion Detection Services

HIDS up to 100 hosts CG-HIDS-100 3,588.00$ 831.60$ 25.12$

HIDS up to 500 hosts CG-HIDS-500 4,788.00$ 1,167.60$ 16.72$

HIDSup to 1000 hosts CG-HIDS-1000 11,988.00$ 1,671.60$ 8.32$

HIDS 5000+ hosts CG-HIDS-5000 15,988.00$ 3,351.60$ 4.96$

POST YEAR 1 PRICING

Carousel Industries - State of New Jersey Price List Page 6

Page 7: MANAGED SERVICES - New Jersey€¦ · Managed Penetration Test - up to 64 IP addresses CG-PenTest/MPT $ 12,760.02 Managed Web Application Test - up to 10 URLs CG-PenTest/MWA $ 15,952.02

SCHEDULE M Date: 9/12/2014CAROUSEL INDUSTRIES PRICELISTCAROUSEL INDUSTRIES PRICELIST - STATE OF NJ

Service ID Product Name Unit State of NJ Pricing

ACS-0001 PCI Report on Compliance (ROC) Issuance

SAQ Level A & B 20,852$

SAQ Level C 23,209$

SAQ Level D 27,332$

ACS-0007 Cross Compliance Mapping

ACS-0007 Regulatory Mappings 2 5,522$

ACS-0007 Regulatory Mappings 3 8,053$

ACS-0007 Regulatory Mappings 4 10,583$

ACS-0007 Regulatory Mappings 5 13,114$

ACS-0008 PCI Dataflow with Gap

ACS-0008 Processes 1 11,102$

ACS-0008 Processes 4 18,586$

ACS-0008 Processes 8 14,719$

ACS-0024 Training

Customized Price based on Number of Days ICB (see Note 1)

ACS-0025 Continual Compliance

Annual Continual Compliance 3,742$

ACS-0027 Time & Materials

Variable Bill Rate ICB (see Note 1)

ACS-0028 Customized Service

Customized based on Assessment ICB (see Note 1)

ACS-0030 Privacy Gap Assessment

Business Processes 1 12,266$

Business Processes 4 18,642$

ACS-0031 PCI Remediation Roadmap

PCI Remediation Roadmap 5,405$

SecureState Professional Services Price Guide

Audit/Compliance

Carousel Industries - State of New Jersey Price List Page 7

Page 8: MANAGED SERVICES - New Jersey€¦ · Managed Penetration Test - up to 64 IP addresses CG-PenTest/MPT $ 12,760.02 Managed Web Application Test - up to 10 URLs CG-PenTest/MWA $ 15,952.02

ACS-0032 VISA PIN/TR-39 Audit

VISA PIN/TR-39 Audit (Customized) ICB (see Note 1)

ACS-0033 HIPAA/HITECH Package

HIPAA Privacy/Security Rule w/HITECH Components (1 business

process) 20,374$

HIPAA Privacy/Security Rule w/HITECH Components (2 business

process) 23,423$

HIPAA Privacy/Security Rule w/HITECH Components (3 business

process) 26,473$

ASC-0001 Customized Service

Customized based on Assessment ICB (see Note 1)

ASC-0002 INFOSEC CMMI Assessment

Lines of Business up to 5 13,690$

Lines of Business up to 10 18,015$

Lines of Business up to 15 22,432$

ASC-0003 INFOSEC Business Process Assessment

Applications to Flow 1 13,001$

ASC-0006 Security Architecture Blueprint

Lines of Business without INFOSEC (5) 7,484$

Lines of Business without INFOSEC (10) 11,227$

Lines of Business without INFOSEC (15) 14,969$

ASC-0007 Steering Committee Meetings

Variable Bill Rate ICB (see Note 1)

IR-0002 Incident Response-Scope

Incident Response - Scope (1 day) 3,714$

IR-0004 Time & Materials

Variable Bill Rate ICB (see Note 1)

IR-0006 Customized Service

Customized based on Assessment ICB (see Note 1)

Advisory Services

Incident Response

Carousel Industries - State of New Jersey Price List Page 8

Page 9: MANAGED SERVICES - New Jersey€¦ · Managed Penetration Test - up to 64 IP addresses CG-PenTest/MPT $ 12,760.02 Managed Web Application Test - up to 10 URLs CG-PenTest/MWA $ 15,952.02

IR-0007 Data Discovery

10 Servers 25 Desktops 6,064$

25 Servers 100 Desktops 17,325$

50 Servers 200 Desktops 25,988$

100 Servers 500 Desktops 49,896$

Procedures 20 33,680$

IR-0008 Argus Threat Briefing

1 Appliance with 1 Month Capture/Analysis 6,237$

2 Appliance with 1 Month Capture/Analysis 9,702$

3 Appliance with 1 Month Capture/Analysis 13,167$

4 Appliance with 2 Month Capture/Analysis 16,632$

5 Appliance with 2 Month Capture/Analysis 20,097$

IR-0009 Incident Response Testing

Limited Scope, Remote 3,119$

Limited, Onsite 6,486$

Full Tabletop Onsite 11,227$

PPS-0001 External Attack and Penetration

Active IP Addresses 5 4,366$

Active IP Addresses 10 7,235$

Active IP Addresses 15 10,104$

Active IP Addresses 20 12,973$

Active IP Addresses 25 15,842$

Active IP Addresses 30 18,711$

Active IP Addresses 35 21,580$

Customized above 35 IPs ICB (see Note 1)

PPS-0002 Internal Attack and Penetration

Active Hosts (1 Class C) 10,956$

Active Hosts (2 Class C) 16,611$

Active Hosts (3 Class C) 22,266$

Customized ICB

PPS-0003 Physical Attack and Penetration

Facilities - 1 5,613$

Facilities - 2 8,732$

Facilites more than 2 (Customized) ICB (see Note 1)

Profiling/Penetration

Carousel Industries - State of New Jersey Price List Page 9

Page 10: MANAGED SERVICES - New Jersey€¦ · Managed Penetration Test - up to 64 IP addresses CG-PenTest/MPT $ 12,760.02 Managed Web Application Test - up to 10 URLs CG-PenTest/MWA $ 15,952.02

PPS-0004 Social Engineering - Telephone

People to Call 10 3,493$

More than 10 Customized

PPS-0005 Social Engineering - Thumb drive/CDs

Facilities - 1 5,613$

Facilites more than 1 (Customized) ICB (see Note 1)

PPS-0007 Wireless Assessment

Facilities - 1 5,364$

Facilites more than 1 (Customized) ICB

PPS-0008 Web Application Security Blackbox

Functional Pages 5 1,659$

Functional Pages 10 2,320$

Functional Pages 20 3,642$

Functional Pages 30 4,965$

More than 30 Pages Customized ICB (see Note 1)

PPS-0009 Web Application Security Greybox

Functional Pages 10 5,988$

Functional Pages 20 10,977$

Functional Pages 30 15,967$

Functional Pages 40 20,956$

Functional Pages 50 25,946$

PPS-0012 Training

Customized Price based on Number of Days ICB (see Note 1)

PPS-0015 PCI Internal Penetration Test

Active Hosts (1 Class C) 3,652$

Active Hosts (2 Class C) 5,891$

Active Hosts (3 Class C) 8,129$

Active Hosts (4 Class C) 10,367$

Active Hosts (5 Class C) 12,606$

PPS-0016 PCI External Penetration Test

Active IP Addresses 10 4,216$

Active IP Addresses 20 7,027$

Active IP Addresses 30 9,838$

PPS-0018 Customized Service

Customized based on Assessment ICB (see Note 1)

Carousel Industries - State of New Jersey Price List Page 10

Page 11: MANAGED SERVICES - New Jersey€¦ · Managed Penetration Test - up to 64 IP addresses CG-PenTest/MPT $ 12,760.02 Managed Web Application Test - up to 10 URLs CG-PenTest/MWA $ 15,952.02

PPS-0021 Social Engineering - Email

People to Email 10 3,881$

More than 10 Customized ICB (see Note 1)

PPS-0022 Social Scan

Social Scan 6,930$

PPS-0023 External Pen Test Re-Evaluation of High Risk

Re-Evaluation of High Risk Findings of External Pen Test 1,260$

PPS-0025 Web Service Assessment

1-4 Endpoints 6,237$

5-10 Endpoints 9,009$

11-20 Endpoints 14,553$

PPS-0026 Black Box Mobile Application Assessment

1-15 Views 8,358$

16-31 Views 11,102$

31-50 Views 13,846$

PPS-0027 Mobile Device Attack & Penetration

Devices 1 6,098$

Devices 2 10,534$

Devices 3 14,969$

Devices 4 19,404$

more than 4 Customized ICB (see Note 1)

PPS-0029 Mobile/Web Veracode White Box

Services for App 1-50 MB 3,379$

Services for App 51-100MB 6,757$

Services for App 101-150 MB 10,136$

Services for App 151-200 MB 13,514$

Services for App 201-250 MB 16,893$

Services for App 201-300 MB 20,270$

Services for App 301-350 MB 23,649$

Services for App 351-400 MB 27,027$

Services for App 401-450 MB 30,406$

Services for App 451-500 MB 33,784$

more than 500 MB ICB (see Note 1)

PPS-0030 SDLC

Customized based on Assessment ICB (see Note 1)

Carousel Industries - State of New Jersey Price List Page 11

Page 12: MANAGED SERVICES - New Jersey€¦ · Managed Penetration Test - up to 64 IP addresses CG-PenTest/MPT $ 12,760.02 Managed Web Application Test - up to 10 URLs CG-PenTest/MWA $ 15,952.02

PPS-0031 White Box Veracode w/Unlimited Scans

Customized based on size of App ICB (see Note 1)

PPS-0032 Social Engineering - Phishing Awareness

1-50 Users 1,788$

51-200 Users 2,384$

201+ Users 2,980$

RI-0001 Customized Service

Customized based on Assessment ICB (see Note 1)

RMS-0002 Minimum Security Baselines (MSB)

Per Baseline 5,489$

RMS-0005 Security Policies and Procedures

Customized based on Assessment ICB (see Note 1)

RMS-0012 External Vulnerability Scan

Active IP Addresses 10 693$

Active IP Addresses 20 1,012$

Active IP Addresses 30 1,331$

Active IP Addresses 40 1,649$

Active IP Addresses 50 1,968$

RMS-0013 War-Dialing

Active Carriers - 10 4,643$

more than 10 - Customized ICB (see Note 1)

RMS-0016 Firewall Ruleset Review

Rulesets Small Enivronment 4,491$

Rulesets Large Environment 8,981$

RMS-0017 Network Architecture Review

Small Enivronment 9,910$

Large Environment 18,018$

RMS-0018 Qualys Self Service Scans

Customized based on number of IP Addresses ICB (see Note 1)

RMS-0023 External Vulnerability Scan w/Validation

10 Active IPs with Validation 1,017$

20 Active IPs with Validation 1,473$

30 Active IPs with Validation 1,929$

Research and Innovation

Risk Management

Carousel Industries - State of New Jersey Price List Page 12

Page 13: MANAGED SERVICES - New Jersey€¦ · Managed Penetration Test - up to 64 IP addresses CG-PenTest/MPT $ 12,760.02 Managed Web Application Test - up to 10 URLs CG-PenTest/MWA $ 15,952.02

40 Active IPs with Validation 2,385$

50 Active IPs with Validation 2,841$

60 Active IPs with Validation 3,297$

70 Active IPs with Validation 3,753$

80 Active IPs with Validation 4,209$

90 Active IPs with Validation 4,665$

over 90 IPs - Customized ICB (see Note 1)

RMS-0024 Internal Vulnerability Scan

Active Hosts (1 Class C) 3,013$

Active Hosts (2 Class C) 3,687$

Active Hosts (3 Class C) 4,360$

Active Hosts (4 Class C) 5,034$

RMS-0026 Time & Materials

Variable Bill Rate ICB (see Note 1)

RMS-0027 Internal Vulnerability Scan W/Validation

Active Hosts (1 Class C) 4,385$

Active Hosts (2 Class C) 6,431$

Active Hosts (3 Class C) 7,784$

Active Hosts (4 Class C) 9,830$

RMS-0028 Customized Service

Customized based on Assessment ICB (see Note 1)

RMS-0031 Device Interrogation & Configuration Review

One (1) Device

RMS-0032 ASV Full Service

(sold in blocks of four (4) - One Calendar year) Active IP Addresses 10 2,772$

Active IP Addresses 20 4,047$

Active IP Addresses 30 5,322$

Active IP Addresses 40 6,597$

Active IP Addresses 50 7,872$

Active IP Addresses 60 9,148$

Active IP Addresses 70 10,423$

Active IP Addresses 80 11,698$

Active IP Addresses 90 12,973$

Pre-Scan 1,247$

Re-Scan 1,247$

over 90 IPs - Customized ICB (see Note 1)

Carousel Industries - State of New Jersey Price List Page 13

Page 14: MANAGED SERVICES - New Jersey€¦ · Managed Penetration Test - up to 64 IP addresses CG-PenTest/MPT $ 12,760.02 Managed Web Application Test - up to 10 URLs CG-PenTest/MWA $ 15,952.02

RMS-0033 SecureTime

Customized based on Assessment ICB (see Note 1)

RMS-0034 Network Segmentation

Customized based on Assessment ICB (see Note 1)

RMS-0035 Remediation Roadmap Development

Customized based on Assessment ICB (see Note 1)

RMS-0036 SPM

Customized based on Assessment ICB (see Note 1)

RMS-0037 Vulnerability Management Program

Customized based on Assessment ICB (see Note 1)

Note 1: ICB = Individual Case Basis requiring a customer engagement based upon final Scope of Work. Pricing for ICB Custom

Engagements is derived using the SONJ Professional Services Labor Rates plus and associated travel and expense.

Carousel Industries - State of New Jersey Price List Page 14

Page 15: MANAGED SERVICES - New Jersey€¦ · Managed Penetration Test - up to 64 IP addresses CG-PenTest/MPT $ 12,760.02 Managed Web Application Test - up to 10 URLs CG-PenTest/MWA $ 15,952.02

SCHEDULE M Date: 9/12/2014CAROUSEL INDUSTRIES PRICELIST - STATE OF NJ

LABOR RATES - MANAGED & PROFESSIONAL SERVICESRegular Overtime Sun & Holiday

Mon - Fri 8am-5pm

Mon-Fri 5:01pm-7:59am all

day Sat All day

PROFESSIONAL - CLASS I $200/hr $300/hr $400/hrProject ManagerTechnicianAdministratorTrainerAnalyst - JuniorDeveloperSpecialistNetwork Administrator

PROFESSIONAL - CLASS II $275/hr $412/hr $550/hrSr Project ManagerEngineerSr Security SpecialistSr AnalystManagerCost Estimator / AnalystCustomer Service ManagerArchitectSr AdministratorSr DeveloperSr Network Administrator

PROFESSIONAL - CLASS III $350/hr $525/hr $700/hrProject DirectorTechnical Project ManagerSr ArchitectQuality Assurance ManagerExpert

Travel Expense $800

Daily Expense $250/day

Carousel Industries - State of New Jersey Price List Page 15