DOI_Cloud_Policy_-_FINAL.pdf
PDF 113 KB Posted
- Attached to
- NASIS for BIE Federal contract opportunity
- Solicitation number
- 140A1619Q0071
About this file
DOI Cloud Policy
View the file
Other files for this federal contract opportunity
| File | Type | Posted |
|---|---|---|
| Q&A_FINAL.pdf | ||
| Sol_140A1619Q0071_Amd_0001.pdf | ||
| RDD_-_FINAL_1.4.pdf | ||
| B08_Solicitation_140A1619Q0071.pdf | ||
| SOW_-_FINAL_PRESOLICITATION.docx | DOCX document | |
| Sol_140A1619Q0071.pdf | ||
| RDD_Crosswalk.xlsx | XLSX spreadsheet | |
| Federal_Cloud_Policy_-_FINAL.pdf |
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
United States Department of the Interior orFICE OF THE SECRETARY Washinsrron, DC 20240
AUG D 7 2018
Memorandum
To: Bureau Assistant Directors Associate Chief Information Officers Bureau Procurement Chiefs
From: Sylvia Bums Chief Information Officer � �
�:::��°Fric�ll!'-2 0 � ;_, ....-__,/a._-/ /
Property Management and Senior Procurement Executive
Subject: Acquisition of Information Technology Cloud Services/Mandatory Use of Pre Approved Cloud Hosting Services and Contracts
This policy updates and replaces the "Mandatory Use Policy for the Department of the Interior (DOI) Foundation Cloud Hosting Services Contracts," dated September 27, 2016. Bureaus and offices are required to obtain cloud-based services using approved enterprise-wide cloud hosting solutions or contracts. The current list of DOI approved enterprise-wide cloud hosting solutions and contracts are available on the DOI Cloud Intranet site at https://sites.google.com/a/ios.doi.gov/cloud/home?pli=1. The solutions are listed under the DOI Cloud Services Portfolio tab, and are separated by categories: Infrastructure as a Service, Platform as a Service, and Software as a Service.
All cloud procurements, including those that are issued against one of the approved enterprise wide cloud hosting solutions, must be approved by the bureau or office Associate Chief l!].formation Officer (ACIO). ACIOs are responsible for ensuring that the cloud procurement is registered prior to acquisition of services outside of the approved list. This requirement applies to all acquisitions, including those planned to be set-aside under the Buy Indian Act or other similar legislation.
If an ACIO wants to proceed with an acquisition without using one of the approved enterprise wide cloud hosting solutions, that acquisition action must be approved by the DOI Chief Information Officer (CIO) and Senior Procurement Executive. The ACIO must submit the action for review and approval as early as possible in the acquisition planning process, and prior to release of the solicitation or any equivalent request for offers from the marketplace. This requirement applies to all acquisitions, including those planned to be set aside under the Buy Indian Act or other similar legislation.
The ACIO must include and maintain the following components within the contract award:
• Service level metrics reporting;
• Penalties for not meeting service level metrics;
• e-Discovery requirements;
• Data retention and destruction policies;
• Controlled Unclassified Information (CUI) requirements as specified in 32 CFR 2002;
• Data privacy requirements;
• Incident handling practices;
• Federal Risk and Authorization Management Program (FedRAMP);
• Information Technology {IT) system security controls verified via third party certification
(FedRAMP 3PAO); and
• All other IT security and privacy requirements as specified in the existing Foundation
Cloud Hosting Services (FCHS) contract section J - Attachments 1-4. (For more information see the Reading Room on the DOI Cloud Intranet)
Please visit the DOI Cloud Intranet using the link provided above for additional information or to download the DOI Cloud Services Registration/Waiver Request Form.
cc: CLT Members IMTLT Members
File details come from the government source that posted it.