DOI_Cloud_Policy_-_FINAL.pdf

PDF 113 KB Posted

Attached to
NASIS for BIE Federal contract opportunity
Solicitation number
140A1619Q0071
Issued by
Department of the Interior Bureau of Indian Affairs Central Office

About this file

DOI Cloud Policy

View the file

Other files for this federal contract opportunity

Other files attached to NASIS for BIE, newest first.
File Type Posted
Q&A_FINAL.pdf PDF
Sol_140A1619Q0071_Amd_0001.pdf PDF
RDD_-_FINAL_1.4.pdf PDF
B08_Solicitation_140A1619Q0071.pdf PDF
SOW_-_FINAL_PRESOLICITATION.docx DOCX document
Sol_140A1619Q0071.pdf PDF
RDD_Crosswalk.xlsx XLSX spreadsheet
Federal_Cloud_Policy_-_FINAL.pdf PDF

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

United States Department of the Interior orFICE OF THE SECRETARY Washinsrron, DC 20240

AUG D 7 2018

Memorandum

To: Bureau Assistant Directors Associate Chief Information Officers Bureau Procurement Chiefs

From: Sylvia Bums Chief Information Officer � �

�:::��°Fric�ll!'-2 0 � ;_, ....-__,/a._-/ /

Property Management and Senior Procurement Executive

Subject: Acquisition of Information Technology Cloud Services/Mandatory Use of Pre Approved Cloud Hosting Services and Contracts

This policy updates and replaces the "Mandatory Use Policy for the Department of the Interior (DOI) Foundation Cloud Hosting Services Contracts," dated September 27, 2016. Bureaus and offices are required to obtain cloud-based services using approved enterprise-wide cloud hosting solutions or contracts. The current list of DOI approved enterprise-wide cloud hosting solutions and contracts are available on the DOI Cloud Intranet site at https://sites.google.com/a/ios.doi.gov/cloud/home?pli=1. The solutions are listed under the DOI Cloud Services Portfolio tab, and are separated by categories: Infrastructure as a Service, Platform as a Service, and Software as a Service.

All cloud procurements, including those that are issued against one of the approved enterprise wide cloud hosting solutions, must be approved by the bureau or office Associate Chief l!].formation Officer (ACIO). ACIOs are responsible for ensuring that the cloud procurement is registered prior to acquisition of services outside of the approved list. This requirement applies to all acquisitions, including those planned to be set-aside under the Buy Indian Act or other similar legislation.

If an ACIO wants to proceed with an acquisition without using one of the approved enterprise wide cloud hosting solutions, that acquisition action must be approved by the DOI Chief Information Officer (CIO) and Senior Procurement Executive. The ACIO must submit the action for review and approval as early as possible in the acquisition planning process, and prior to release of the solicitation or any equivalent request for offers from the marketplace. This requirement applies to all acquisitions, including those planned to be set aside under the Buy Indian Act or other similar legislation.

The ACIO must include and maintain the following components within the contract award:

• Service level metrics reporting;

• Penalties for not meeting service level metrics;

• e-Discovery requirements;

• Data retention and destruction policies;

• Controlled Unclassified Information (CUI) requirements as specified in 32 CFR 2002;

• Data privacy requirements;

• Incident handling practices;

• Federal Risk and Authorization Management Program (FedRAMP);

• Information Technology {IT) system security controls verified via third party certification

(FedRAMP 3PAO); and

• All other IT security and privacy requirements as specified in the existing Foundation

Cloud Hosting Services (FCHS) contract section J - Attachments 1-4. (For more information see the Reading Room on the DOI Cloud Intranet)

Please visit the DOI Cloud Intranet using the link provided above for additional information or to download the DOI Cloud Services Registration/Waiver Request Form.

cc: CLT Members IMTLT Members

File details come from the government source that posted it.