Sol_140D0423R0002_Amd_0004.pdf
PDF 3 MB Posted
- Attached to
- DOI Foundation Cloud Hosting Services (FCHS2) Federal contract opportunity
- Solicitation number
- 140D0423R0002
View the file
Other files for this federal contract opportunity
Show all 46
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
(x)
140D0423R0002 x x
1 copies of the amendment; (b) By acknowledging receipt of this amendment on each copy of the offer submitted ; or (c) By separate letter or electronic communication which includes a reference to the solicitation and amendment numbers. FAILURE OF YOUR ACKNOWLEDGEMENT TO BE
RECEIVED AT THE PLACE DESIGNATED FOR THE RECEIPT OF OFFERS PRIOR TO THE HOUR AND DATE SPECIFIED MAY RESULT IN REJECTION OF YOUR
OFFER. If by virtue of this amendment you desire to change an offer already submitted , such change may be made by letter or electronic communication, provided each letter or electronic communication makes reference to the solicitation and this amendment, and is received prior to the opening hour and date specified.
x
Herndon VA 20170
D14
Suite 2000A 381 Elden Street Acquisition Services Directorate Interior Business Center, AQD
08/17/20230004
13. THIS ITEM ONLY APPLIES TO MODIFICATION OF CONTRACTS/ORDERS. IT MODIFIES THE CONTRACT/ORDER NO. AS DESCRIBED IN ITEM 14.
12. ACCOUNTING AND APPROPRIATION DATA (If required) is not extended.is extended, Items 8 and 15, and returning
Offers must acknowledge receipt of this amendment prior to the hour and date specified in the solicitation or as amended , by one of the following methods: (a) By completing
The above numbered solicitation is amended as set forth in Item 14. The hour and date specified for receipt of Offers
11. THIS ITEM ONLY APPLIES TO AMENDMENTS OF SOLICITATIONS
FACILITY CODE CODE
10B. DATED (SEE ITEM 13)
10A. MODIFICATION OF CONTRACT/ORDER NO.
9B. DATED (SEE ITEM 11)
9A. AMENDMENT OF SOLICITATION NO.
CODE
8. NAME AND ADDRESS OF CONTRACTOR (No., street, county, State and ZIP Code)
7. ADMINISTERED BY (If other than Item 6)CODE 6. ISSUED BY
PAGE OF PAGES
4. REQUISITION/PURCHASE REQ. NO.3. EFFECTIVE DATE2. AMENDMENT/MODIFICATION NO. 5. PROJECT NO. (If applicable)
1. CONTRACT ID CODE
AMENDMENT OF SOLICITATION/MODIFICATION OF CONTRACT
04/20/2023
CHECK ONE A. THIS CHANGE ORDER IS ISSUED PURSUANT TO: (Specify authority) THE CHANGES SET FORTH IN ITEM 14 ARE MADE IN THE CONTRACT
B. THE ABOVE NUMBERED CONTRACT/ORDER IS MODIFIED TO REFLECT THE ADMINISTRATIVE CHANGES (such as changes in paying office, C. THIS SUPPLEMENTAL AGREEMENT IS ENTERED INTO PURSUANT TO AUTHORITY OF:
D. OTHER (Specify type of modification and authority) appropriation data, etc.) SET FORTH IN ITEM 14, PURSUANT TO THE AUTHORITY OF FAR 43.103(b).
E. IMPORTANT: Contractor is not is required to sign this document and return __________________ copies to the issuing office.
ORDER NO. IN ITEM 10A.
14. DESCRIPTION OF AMENDMENT/MODIFICATION (Organized by UCF section headings, including solicitation/contract subject matter where feasible.)
The purpose of Amendment 0004 is as follows:
1. Phase II proposal submission due date is changed FROM: September 15, 2023, TO: September
29, 2023. The time remains unchanged.
2. The following RFP documents/sections are revised - Section F, Section J Attachment 5, Section J Attachment 6, Section J Attachment 7, and Section L.
3. Offerors are advised to carefully review the questions and answers provided as well as all attachments to this document.
Continued ...
16A. NAME AND TITLE OF CONTRACTING OFFICER (Type or print)15A. NAME AND TITLE OF SIGNER (Type or print)
15C. DATE SIGNED 16B. UNITED STATES OF AMERICA 15B. CONTRACTOR/OFFEROR 16C. DATE SIGNED
(Signature of person authorized to sign) (Signature of Contracting Officer)
Tonya Lovelace
STANDARD FORM 30 (REV. 11/2016)
Prescribed by GSA FAR (48 CFR) 53.243
Previous edition unusable
Except as provided herein, all terms and conditions of the document referenced in Item 9 A or 10A, as heretofore changed, remains unchanged and in full force and effect .
ITEM NO. SUPPLIES/SERVICES QUANTITY UNIT UNIT PRICE AMOUNT
NAME OF OFFEROR OR CONTRACTOR
2 172
CONTINUATION SHEET
REFERENCE NO. OF DOCUMENT BEING CONTINUED PAGE OF
(A) (B) (C) (D) (E) (F)
140D0423R0002/0004
4. All other terms and conditions remain unchanged.
NSN 7540-01-152-8067 OPTIONAL FORM 336 (4-86)
Sponsored by GSA
FAR (48 CFR) 53.110
Foundation Cloud Hosting Services II (FCHS2) – Amendment 0004 Section F
F-1
SECTION F - DELIVERABLES OR PERFORMANCE
F.1 FAR 52.252-2 Clauses Incorporated by Reference (FEB 1998) This contract incorporates one or more clauses by reference, with the same force and effect as if they were given in full text. Upon request, the Contracting Officer will make their full text available. Also, the text of a clause may be accessed electronically at this address:
https://www.acquisition.gov/browse/index/far
Clause Title Date
52.242-17 Government Delay of Work APR 1984 52.247-34 F.o.B Destination NOV 1991
F.2 Term of the Contract The base term of this contract will be two years from date of award, anticipated for March 2024 through March 2026. This is the base period of performance (PoP) for this contract.
This contract includes four two-year option periods, as shown below, for the renewal of the contract which may be unilaterally exercised by the Government. Each option period shall be exercised in accordance with Section I. See FAR 52.217-9, Option to Extend the Term of the Contract (MAR 2000). All terms and conditions applicable to the base period shall apply to the options unless otherwise agreed upon.
• Option Period One (OP1) – TBD
• Option Period Two (OP2) – TBD
• Option Period Three (OP3) – TBD
• Option Period Four (OP4) – TBD
IDIQ and Task Order (PoP): For those Task Orders issued before the expiration of the IDIQ, the period of performance may not extend for more than 12 months after the expiration of the IDIQ.
All orders must be placed prior to the expiration of the IDIQ.
Transition: If a transition period is required, it will be designated at the Task Order level and is applicable in accordance with FAR clause 52.237-3 Continuity of Services in Section I of the IDIQ contract.
F.3 Place of Performance Most of the work is performed remotely at the Contractor facilities unless otherwise stated in individual task orders. The bulk of tasks require services performed on the Internet by both Federal and Contractor staff from their respective stations. There may be rare instances, where individual task orders require on-site support, or a combination, such as overseeing legacy data migration, decommission on-site systems, or integrating into systems located at Agency data centers.
https://www.acquisition.gov/browse/index/far
F-2
The lead physical location of the Interior Business Center, Acquisition Services Directorate (AQD), Contracting Services is in Herndon, VA.
F.4 Meetings, Reports, and Other Deliverables In fulfillment of this contract, the Contractor shall be required to provide deliverables. All deliverables shall be submitted to the Contracting Officer’s Representative (COR), unless otherwise agreed upon or as stated in each Task Order.
Unless otherwise specified, the Government will have a maximum of ten (10) working days from the day the draft deliverable is received to review the document, provide comments back to the contractor, approve or disapprove the deliverable(s). The contractor will also have a maximum of ten (10) working days from the day comments are received to incorporate all changes and submit the final deliverable to the Government. All days identified below are intended to be workdays unless otherwise specified.
F.4.1 Orientation Briefing Within three (3) business days from date of award, the contractor shall schedule an orientation briefing/initial strategy session. Both parties will mutually agree upon the specific date, time, and location of the briefing. The Government does not desire an elaborate orientation briefing nor does it expect the contractor to expend significant resources in preparation for this briefing.
Rather, the intent of the briefing is to initiate the communication process between the Government and the contractor by introducing key participants, contact information and explaining their roles, reviewing communication ground rules, and assuring a common understanding of requirements and objectives, goals, constraints, policies, expected benefits, other relevant background information, and discussing near-term deliverables.
F.4.2 Deliverable Table Unless otherwise agreed upon, all deliverables shall be submitted to the Contract COR identified in Section G of this contract, with a copy of the transmittal letter to the Contracting Officer.
F-3
Reference Milestone/Deliverable Responsibility Timeline
F.8 Subcontracting Plan Reports accessible at www.esrs.gov
Contractor See F.8. Twice annually into eSRS at mid-year and end-year reporting periods
F.4.1 Orientation Briefing Schedule Contractor Schedule within 3 business days and hold within 15 business days from award date
C.2
C.3
Business Objectives - Establishing cloud services catalogs - activities and opportunities coordination, achieving net-zero strategies
Management Objectives: Promoting enterprise level and life-cycle longevity of cloud-based services
Contractor and Government Quarterly video call
C.5 Security Objectives: Conduct a Security Checkpoint of current and emerging Government security and privacy control requirements
Contractor and Government Quarterly video call
C.5.2.2 Provide summary of Secure Software Development Framework (SSDF) and EO 14028 Section 4e artifacts for new cloud service products
Contractor Required for each new
CSP
C.5.3 thru C.5.3.3
Performance Report. Provide performance defaults, settings, suggestions, and tiered options of provisional performance related services, including on-demand, fluctuations, and metrics
Contractor Required for each new
CSP
C.5.3.4 Continuous Monitoring Plan including, Security Assessment Plan/Report SAP/SAR, System Security Plan (SSP) Contractor
Required for each new CSP. Delivery may be satisfied through FedRAMP (sam.gov) portal C.5.4 thru C.5.4.3
Service Reliability Report. Deliver a Disaster Recovery (DR) Plan that includes defaults, settings, suggestions, and tiered options of backup, retention, restoration
Contractor Required for each new CSP tenant http://www.esrs.gov/
F-4
C.5.5 Data Management Report. Provide a list of security controls in the form of a Control Implementation Summary (CIS) and Customer Responsibility Matrix (CRM) spreadsheet that outlines each control and where the role responsibility resides between the cloud provider and customer
Contractor
Required for each new CSP. Delivery may be satisfied through FedRAMP (sam.gov) portal
F.6.1 Transition-Out Plan
Contractor no later than ninety (90) calendar days prior to the expiration of the contract period, unless another date is mutually agreed upon
F.5 Other Performance Requirements
F.5.1 Productive Direct Labor Hours The contractor can only charge the Government for “Productive Direct Labor Hours”.
“Productive Direct Labor Hours” are defined as those hours expended by Contractor personnel in performing work under this effort. This does not include sick leave, vacation, Government or contractor holidays, jury duty, military leave, or any other kind of administrative leave such as acts of God (i.e., hurricanes, snowstorms, tornadoes, etc.), Presidential funerals or any other unexpected government closures.
F.5.2 Government Holidays The following Government holidays are normally observed by Government personnel: New Year's Day, Martin Luther King’s Birthday, Presidential Inauguration Day (metropolitan DC area only), George Washington’s Birthday, Memorial Day, Juneteenth Day, Independence Day, Labor Day, Columbus Day, Veteran’s Day, Thanksgiving Day, Christmas Day, and any other day designated by Federal Statute, Executive Order, and/or Presidential Proclamation. Or any other kind of administrative leave such as acts of God (i.e., hurricanes, snowstorms, tornadoes, etc.), Presidential funerals or any other unexpected government closures. If a holiday falls on a Saturday, the preceding Friday will be treated as the holiday; and if a holiday falls on a Sunday the following Monday will be treated as a holiday.
F.6 Transition Plans
F.6.1 Transition Out At the end of the period of performance, the incumbent contractor shall transition activities to the incoming contractor with minimal disruption of services to the government. The contractor shall maintain sufficient qualified staff to meet all requirements of this effort services. The contractor shall submit an electronic phase-out plan to CORs no later than ninety (90) calendar days prior to the expiration of the contract period, unless otherwise agreed upon. The plan shall detail phase-
F-5 out activities to assure continuity of operations and the execution of a smooth and timely transition. Phase-out activities shall be coordinated through the COR. The outgoing contractor shall submit a weekly status report of phase-out activities to the COR beginning the 7th calendar day following the award of a successor contract until otherwise notified by the COR to discontinue.
F.7 Notice to the Government of Delays In the event the Contractor encounters difficulty in meeting performance requirements, or when it anticipates difficulty in complying with the contract delivery schedule or any date, or whenever the Contractor has knowledge that any actual or potential situation is delaying or threatens to delay the timely performance of this contract, the Contractor shall immediately notify the Contracting Officer (CO) and the COR, in writing, giving pertinent details, provided that this data shall be informational only in character and that this provision shall not be construed as a waiver by the Government of any delivery schedule or date or of any rights or remedies provided by law or under this contract.
(a) If the Contractor fails to respond in a timely manner to any portion of this contract, delay will be attributed to the Contractor. Although the period of performance may change due to the delay, the price may be subject to a downward adjustment.
(b) If the Government delays performance of this contract, the period of performance and/or price may be revised upon mutual agreement between the Government and the Contractor.
F.8 Subcontracting Plan Reports The Contractor shall submit a report for subcontracting under this particular contract and/or a summary report on subcontracts in all contracts between the Contractor and the Department of the Interior which contain subcontract goals for awards to small business, small, disadvantaged business concerns, HUB zone business, service-disabled veteran owned small businesses, or woman-owned business. Reports will be prepared and submitted electronically in accordance with the instructions at the electronic Subcontract Reporting System (eSRS) accessible at www.esrs.gov.
See Section J Attachment 4 for Subcontracting Plan Template
Individual Contract Report data (formerly Standard Form 294) is due on the 25th day following the close of the reporting period, unless the contract incorporates the contractor's approved, annual company-wide or division-wide commercial product plan. Summary Report data (formerly Standard Form 295) is due 30 days after the close of the Government's fiscal year.
Paper copies of these reports are no longer required.
http://www.esrs.gov/
Foundation Cloud Hosting Services II (FCHS2) – Amendment 0004 Section J
J-05 1
SECTION J – ATTACHMENT 05
SECTION 1 - INTRODUCTION DAY ONE USE CASE – BIA EUMS
EUMS – Electrical Utility Management System
The Department of the Interior (DOI) has prepared this Day One Use Case to support the Bureau of Indian Affairs (BIA), Division of Water and Power to manage billing, collections, and operations at two electrical facilities. BIA is requesting a proposal to migrate and modernize an on-premise “Albuquerque New Mexico” software application to the cloud.
BIA objective is to have a modernized version of the EUMS application operating and performing as a cloud-smart SaaS and hosted in its own instance on the existing Department of the Interior – Office of the Chief Information Officer (DOI OCIO) Microsoft Azure AD Commercial tenant.
Table of Contents
SECTION J – ATTACHMENT 05
SECTION 1 - INTRODUCTION DAY ONE USE CASE – BIA EUMS
Table of Contents
SECTION 2 – STATEMENT OF WORK
Task Order Title Project Summary Purpose Assumptions Current Environment Figure 1: Current EUMS Production Environment Architecture Proposed Environment Figure 2: Proposed EUMS Production Environment Architecture Hosting and Application Department of the Interior, Startup Azure Architecture Components Integrating DOI Microsoft Azure Applications with DOI External and On-Premise Networks Other Requirements Backup Systems and Capability Service Level Agreements (SLAs) Professional Services Milestone Activities:
Period of Performance Points of Contact
SECTION 3 - TASK ORDER TERMS AND CONDITIONS
SECTION 4 – INSTRUCTIONS TO QUOTERS
SECTION 5 – EVALUATION OF QUOTE
J-05 2
SECTION 2 – STATEMENT OF WORK
Task Order Title The Bureau of Indian Affairs (BIA) has a requirement to procure cloud support services that leverage a FedRAMP approved Microsoft Azure Infrastructure as a Service (IaaS) Cloud environment. BIA will obtain the Microsoft license service (Microsoft Virtual Machines (VMs), Storage, NetAPP, Backup, etc.)
only from another mandatory source blanket purchase agreement, but requires all the full technical support services as described below.
Project Summary This requirement is a two-phased approach:
Phase 1: To provide all the technical support services to perform discovery of the existing EUMS environment located at the Albuquerque, New Mexico BIA data center. Discover includes application mapping and compatibility testing, and then migrate Electrical Utility Management System (EUMS) from the Albuquerque Data Center to the existing Enterprise DOI Microsoft Azure Commercial Cloud tenant. The existing Azure tenant is the DOI Enterprise Azure General Support System (GSS) integrated with their wide area network. The contractorvendor also shall upgrade to the latest Windows Server 2019 or Windows Server 2022. Phase 1 includes only required SaaS modernization, customization, and development services to the extent to meet the newly hosted compatibility requirements. BIA is seeking subject matter experts in Microsoft environments (on-prem and cloud) to perform the discovery, migration, and configuration of the newly created but completely unconfigured BIA Virtual Private Cloud (VPC) space. The contractorvendor will serve as lead technical support SME in this phase.
Phase 2: Once EUMS migrated and operational, Contractor shall link the modernized EUMS application to an already existing customer facing EUMS Customer Web Portal (CWP). Contractor will coordinate with BIA technicians and another 3rd party contractorvendor where the CWP resides to provision.
Contractor will partner with BIA technical staff to perform annual and ongoing PaaS/SaaS level continuous monitoring, application updates/ patches, backup and performance activities, technical support, etc. of new cloud instance. Extensive application development of a new EUMS application isn’t expected. Task orders at a later, undetermined date, may include a completely new SaaS.
BIA’s first priority objective is to join the existing DOI Enterprise Azure GSS. Under this priority, BIA will purchase Azure IaaS licenses through another Department mandatory purchase agreement to begin the project on an un-provisioned and un-configured instance of the existing DOI Enterprise Azure AD tenant. For a smoother start, the Contractor should provide a list of the Azure licenses they will need to perform the work so BIA can order and have these available. This list can also be determined in the early stages of Phase 1.
If this first priority is not viable, the Contractor shall propose a second priority to acquire and prepare a stand-alone DOI Microsoft Azure tenant or recommend an alternative cloud service environment. Under the second priority solution, the Contractor shall include all the cloud service provider licenses, including Azure if the that is the CSP recommendation. In either case, the BIA is requesting ownership of the tenant and the contractor shall coordinate and perform technical, development, and continuous monitoring services through task order(s) as detailed below.
J-05 3
Purpose Two of BIA-owned and managed electrical facilities, San Carlos Irrigation Project – Power Division (SCIP) and Colorado River Agency – Electrical Services (CRA-ES) utilize customized EUMS billing, collection, and operations, software developed by Continental Utility Solutions, Inc. which also incorporates the Elements asset and work management software developed by Novotx, LLC. This requirement will support a maximum of 20,000 external customers who will access EUMS through the
CWP.
BIA has a suite of technical staff who will be integrated in this project. They will partner with the Contractor to provide insight and access into the existing EUMS environment and support the successful development and implementation of the replacement EUMS. The contractor’s role shall be application migrator and integrator, as well as ongoing Azure environment support. The BIA team is well versed in the current operating environment and the EUMS application. The Contractor shall partner with BIA technical staff to support all security, assessment and authorization requirements. The expectation is for the contractor to lead the initial technical direction and perform the bulk of environment/application administration through the migration phase and over time as operations becomes steady state, then BIA integrated staff will take on more and more. The contractor should propose higher hours and support personnel through migration and initial configuration with reduced hours when achieve ongoing steady state.
BIA / OCIO Integrated Staff Contractor
System Administrators of existing on-premise Windows operating system and applications
Perform application mapping and coordination between existing on-premise environment to new cloud. Make all pre-migration configurations.
Provide all documentation, explanation, and technical lead of existing environment.
Incorporate existing into newly built architectural diagrams. Document artifacts, disaster recovery schedule, configuration settings, etc. of new environment.
Existing BIA team will perform EUMS and Elements application upgrades, patches, and tuning
Lead on upgrade / modernize Azure environment instances Windows, SQL Server, IIS and other compute services
Environment administration: Should have access and visibility into the entire environment from the start with plans on learning and achieving Azure training and certification(s) and eventually performing this lead role.
Environment administration: Initial lead in setup and administration of MS Azure instance. Mentor and training BIA Information Technology Specialist to take over after achieve production stage.
Application migration: Will coordinate application migration, timing, and access. Will have technical lead with on-premise environment
Application migration: will have technical lead on the Azure side
Coordinate contact information and current license, ownership, and other information as needed.
Lead the integration of the Customer web portal with Continental Utility Solutions.
Assumptions The Contractor shall be skilled in Microsoft Azure Commercial compute and support. Contractor shall be able to set security and performance thresholds that optimize the application, database, public facing web hosting, redundancy and load balancing, storage types including production and Dev/Test environments.
The Contractor shall be skilled in managing and integrating Windows environments, including SQL https://www.bia.gov/programs-services/power-utilities/scip-power https://www.bia.gov/programs-services/power-utilities/scip-power https://www.bia.gov/programs-services/utilities/colorado-river-agency-electrical
J-05 4
Server, ElementsXS, and other associated Microsoft environment applications described in this SOW.
To authenticate into the DOI environment, which includes the DOI Enterprise Microsoft Azure GSS tenant, Contractors will first coordinate with the BIA Contracting Officer Representative (COR) to conduct a standard level federal background investigation and obtain a Department of the Interior PIV Card according to the Presidential Directive HSPD-12.
Contractor shall be skilled at configuring, hardening security, and integrating the API between the new environment and the utility Customer Web Portal.
Current Environment Below is a brief, high-level diagram and bullets of the BIA EUMS current environment and the Phase 2 configuration requirements. Upon award, BIA technical staff and Contractor technical staff will conduct a kick-off briefing that responds to more details regarding current environment. The briefing will begin a technical partnership and cover milestones, timelines, roles, and required activities going forward.
Figure 1: Current EUMS Production Environment Architecture
List of current environment infrastructure, systems, transactions
• Storage Systems o SAN – Storage Area Network o NAS – Network-Attached Storage o Backup Storage o Archival Storage
• Networks o Wide-Area Network Details and Sizing o System Interfaces and Network Boundaries o Number of Users o Transactional Traffic, such as Web Transactions, Database Transactions or Application
Transactions
J-05 5 o Network Security, such as Firewalls, Secure File Transfer or VPN
• Server Operating Systems o System Administration o Version
• Databases o Database Administration o Licensing o Version o Relational or Non-Relational
• Middleware
Network Diagram
Figure 2: Continental Utility Solutions, Inc. (CUSI) Current Network Diagram
J-05 6
Hosting Requirements Diagram
Figure 3: Continental Utility Solutions, Inc. (CUSI) Hosting Requirements Diagram
J-05 7
Architectural Requirements
Figure 4: Continental Utility Solutions, Inc. (CUSI) Architecture Requirements Diagram
Proposed Environment The proposed environment will be a ‘lift and shift’, and then upgrade the operating platform appropriately to Windows Server 2019 or 2022, and the associated subsystems, per the schematic. Then a separate Customer Web Portal hosted by the UMS provider will be connected via API soon after the deployment of the UMS servers by the contractor. BIA does not anticipate extensive modernization, nor application development requirements beyond bringing environment up to latest Microsoft versions and ensuring compatibility from an on-premise to cloud environment.
Contractor technical staff shall become a member of the Bureau/Office BIA EUMS technical team. They shall lead some services and coordinate and participate with BIA technical staff in others. This begins with the award kick-to session to complete the migration, configuration, development and provide ongoing production environment operational support services.
1. The Contractor shall ensure the EUMS application environment, performance, confidentiality, integrity, and availability shall be equal and/or improved from current on-premise environment.
2. Contractor shall describe in their proposal any migration benefits, improvements, or cautions BIA
J-05 8 should expect such as related to performance, redundancy, compatibility, data integrity, technology refreshes, etc.
Figure 5: Proposed EUMS Production Environment Architecture
Hosting and Application This section outlines the proposed operating environment requirements, parameters, and objectives. The Contractor shall provide their technical approach and cost estimates to meet these requirements. The BIA will acquire all Microsoft licenses through another Departmental mandatory source Blanket Purchase Agreement. However, the Contractor shall list in their proposal all the Microsoft license requirements they believe will be needed for BIA to partner in meeting these technical objectives. The Contractor shall also propose all other licenses and all the required support service hours, cost estimates and recommendations to meet the Project Summary phases above.
Below is a table of current file server sizes to assist in sizing the new operating environment and the associated technical expertise required. BIA is seeking additional and/or expanded configuration recommendations and associated cost scenarios (good, better, best) in order to serve 20,000 external customers and achieve optimal performance and on-demand agility, availability, and throughput between the differences of the current on-premise to cloud solution.
Servers Production Dev/Test
Application (Currently in .NET)
Windows Server 2016 2CPU’s, 24 GB RAM, Storage- C: drive 200 GB Same
Database
Windows Server 2016 – 4 CPU’s, 32 GB RAM, Storage – C:drive 80 GB, D: drive 60 GB, L drive 100 GB, O drive 200 GB
Same
J-05 9
RDP Client Server Windows Server 2016 – 4 CPU’s, 24 GB RAM, Storage – C: drive 100 GB, D: drive 100 GB
Same
Storage Systems Production Dev/Test
“Type” (GB or TB) Propose solution Propose solution “Type” (GB or TB) Propose solution Propose solution Back-up (GB or TB) Propose solution Propose solution Archive (GB or TB) Propose solution Propose solution
Network Production Dev/Test
Transport (ie, Dedicated, Internet, TIC, or None) Already covered by DOI Standard Already covered
Bandwidth - (MB or
GB)
Propose solution
Propose solution
Redundancy Already covered by DOI Standard Already covered Firewall Already covered by DOI Standard Already covered Internet Gateway Already covered by DOI Standard Already covered Layer 3 Switching Already covered by DOI Standard Already covered Interconnections Propose solution Propose solution Secure File Transfer None Security None
Department of the Interior, Startup Azure Architecture Components The Department of the Interior requires each new cloud application to first determine whether it can reside on the existing DOI Enterprise Microsoft Azure Commercial Cloud tenant. This section describes what the contractor can expect beginning and managing the EUMS project within the private BIA tenant space. The boundary configurations and activities below are managed by the Department’s Office of the Chief Information Officer (OCIO); not the BIA technical team. The BIA team is requesting the Contractor become the Azure subject matter expert representing the EUMS portion and assist in coordinating with the OCIO team and managing EUMS Azure aspects . Below are the Startup Azure Architecture Expectations.
• Azure Tenant: DOI provides a single tenant where all workloads, including the BIA EUMS instance(s) are placed. The DOI, Office of Chief Information Officer (OCIO) maintains the Azure Active Directory infrastructure and core network connectivity for all DOI Bureaus/Offices. The Contractor role is to partner with DOI technical staff to manage all other “above AD stack” configurations, e.g., compute, storage, application, disaster recovery, performance indicators, etc.
• Enterprise Agreements (Requirement): BIA will provide the Microsoft Azure Commercial licensing and identified as the instance owner.
• Management Groups: The root Management Group is maintained by OCIO, each Bureau/Office has a subgroup. Upon favorable adjudication of a standard federal background investigation and obtaining a Federal PIV CACI card according to HSPD-12, the Contractor will be included in the BIA EUMS sub-group. Permissions on the Bureau/Office subgroups are delegated to the Bureau/Office’s primary Azure points of contact. This allows the Bureau/Office to setup their subgroups and permissions as appropriate.
• Subscriptions (Requirement): Bureau/Office employees, including Contractors are responsible for the role-based access on the subscriptions. Each subscription requires at least one Bureau/Office employee to have the “owner” role on the subscription, often this is inherited from the
J-05 10
Management Group. The roles and incumbent names will be identified by both Government and Contractor during the kickoff-meeting commencing within days after award.
• Azure Regions (Requirement): All workloads must be deployed within the Continental United States (CONUS). Any region within CONUS is available for use without restrictions. US East and US West are considered as primary regions and are where most network connectivity is centralized.
• Network Access (Requirement): OCIO provides all network access to and from the Azure Tenant via redundant ExpressRoute circuits.
• Azure Points of Contact: Each Bureau/Office has a small list of designated contacts that act as liaisons between OCIO and the Bureau/Office. Information on the Azure environment and upcoming changes to that environment are communicated from OCIO through those designated contacts. OCIO has a small group of Azure Architects that oversee the DOI Azure environment, they act as consultants to contractorsvendors and Bureaus/Offices on an as needed basis. BSEE will identify Federal liaisons and other technical support coordinators during the kickoff-meeting commencing within days after award.
Integrating DOI Microsoft Azure Applications with DOI External and On-Premise Networks
• The OCIO Hub and Bureau/Office Spoke network architecture is currently in place within the DOI Azure Tenant. The centralized Hubs act as peering locations for traffic to cross over between spokes, the Internet, or on-premises networks. Peering between spokes within the same subscription and/or Bureau is allowed.
• Centralized hubs are in US East, and US West regions and are managed by OCIO. Centralized hubs have fully redundant ExpressRoute circuits for access to DOI on-premises networks and are managed by OCIO.
• The Contractor may consider configuring and collaborating an Azure AD business-to-business (B2B) connection between the new BIA EUMS environment and external guest Customer Web Portal. Contract developers can use Azure AD B2B APIs to customize the invitation process and use cross-tenant access settings to manage inbound/outbound traffic for users and applications.
• ExpressRoute is available to provide preferential access for users and API’s between the new BIA EUMS and their current on-premise EUMS, which may assist in the application mapping and migration services.
• Forced tunnelling to the internet on Azure resources is in place to comply with governmental security mandates. All traffic from/to the internet should flow through the centralized traffic hubs before being routed through the appropriate crossover points. Private endpoints should be utilized whenever possible to limit exposure to the Internet edge. Trusted Internet Connection (TIC) versions 2 and 3 are supported in the environment via the central traffic hubs. Route tables that include the default 0.0.0.0 route and to the Internet are propagated to all virtual networks.
• IP v4 & v6 addresses for virtual networks peered to the central hubs in Azure are provided by OCIO to each Bureau/Office and are treated as extensions of their on-premises network. IPv4 spaces are limited in nature and should be a consideration in architecture.
• OCIO employs centralized DNS servers that perform DNS forwarding for Azure domain spaces both within Azure and the on-premises environments. Private endpoint zones are located centrally to allow all Bureaus/Offices to easily manage custom DNS entries.
The Department of the Interior, Office of the Chief Information Officer (OCIO) provides the following guidelines for prospectus contractorsvendors who are submitting proposals for Information Technology Systems that will reside or interface with the DOI Enterprise Microsoft Azure Tenant. Prospectus contractorsvendors may propose one or more of their personnel to become a contractor agent or Bureau/Office technician. When the descriptions below stipulate “Bureaus/Offices are responsible”, this extends to include prospectus contractorvendor personnel.
J-05 11
This document is provided as a guide to common Azure implementations within the US Department of the Interior (DOI) and is intended to steer discussions and configuration for new Azure deployments with potential contractorsVendors. Unless otherwise noted, the information provided should be considered as DOI Best Practices and not as hard requirements.
Common Azure Architecture Components Azure Tenant - DOI provides a single tenant where all workloads should be placed. The Office of Chief Information Officer (OCIO) maintains the Azure Active Directory infrastructure and core network connectivity for all Bureaus/Offices.
The root Management Group is maintained by OCIO, each Bureau/Office has a subgroup. Permissions on the Bureau/Office subgroups are delegated to the Bureau/Office’s primary Azure points of contact. This allows the Bureau/Office to setup their subgroups and permissions as they see fit.
Each Bureau/Office has a small list of designated Points of Contacts that act as liaisons between OCIO and the Bureau/Office. Information on the Azure environment and upcoming changes to that environment are communicated from OCIO through those designated contacts.
OCIO has a small group of Azure Architects that oversee the DOI Azure environment and provide consultation to contractorsvendors and Bureaus/Offices on an as needed basis.
Requirements:
Enterprise Agreements - Bureaus/Offices are responsible for their own licensing and Enterprise Agreements (EA) and federal employees are directed to order from a DOI Microsoft Blank Purchase Agreement (BPA). Bureaus/Offices are required to be owners on the EA before they can be connected to the DOI Azure Tenant. The BPA is license only and does not provide technical, development, nor integration types of support services.
Subscriptions - Bureau/Office employees and contractors are responsible for the role-based access on the subscriptions. Each subscription requires at least one Bureau/Office employee to have the “owner” role on the subscription, often this is inherited from the Management Group.
Azure Regions - All workloads must be deployed within the Continental United States (CONUS). Any region within CONUS is available for use without restrictions. US East and US West are considered primary regions and where most network connectivity centralized.
Network Access - OCIO provides all network access to and from the Azure Tenant via redundant ExpressRoute circuits. For more information see the Microsoft Azure Networking section below.
Azure Active Directory & Identity OCIO manages and maintains all aspects of Azure Active Directory within the DOI tenant. Global Administrator roles are restricted to employees and contractors within OCIO. ContractorsVendors and Bureau Administrators will not be granted administrative access within Azure Active Directory. OCIO works closely through a documented change management process with the Bureaus/Offices to facilitate and accommodate changes.
Apart from SCIM, OCIO does not support synchronizing Active Directory to any other Cloud provider or Azure Tenant for the purposes of direct authentication.
Azure Active Directory is positioned as the primary authentication provider for all cloud services and providers, this includes but is not limited, SAML and OAuth for 3rd parties.
J-05 12
User Accounts - On-Premises Active Directory user accounts are synchronized with the DOI Azure tenant, this does not include service accounts or privileged accounts. In general, user accounts require Multi Factor Authentication using PIV access cards.
Guest Accounts - Guests accounts are allowed within the tenant and can be invited under approved applications. Guest accounts that are inactive for 90 days are automatically disabled and deleted.
Elevated Privilege Accounts - Elevated Privilege accounts are required to manage Azure resources and are created/maintained by OCIO. All contractors requiring access shall undergo a standard level federal background check per HSPD-12 regulations to meet authentication requirements before being given access to DOI resources. Elevated Privilege accounts are required to satisfy multifactor authentication which may include the use of PIV access cards and Government Furnished Equipment.
Service Principals - Service Principals in the form of Service Accounts, Application Registrations, and Enterprise Applications are managed by OCIO and are required to undergo security risk analysis before being provisioned. Bureaus/Offices can request Service Principals as needed using an established change management procedure with OCIO.
Administrative Units - Each Bureau/Office has a designated Administrative Unit (AU) within Azure Active Directory. Permissions to create and manage groups within those AUs are assigned to Bureau/Office personnel.
Groups - Security, Dynamic, Office 365 and Distribution groups can be created and managed within Azure Active Directory via Administrative Units. In some cases, on-premises Active Directory groups are synced to Azure Active Directory.
Microsoft Azure Networking Network Architecture - Generally, the Hub and Spoke network architecture is currently in place within the DOI Azure Tenant. The centralized Hubs act as peering locations for traffic to cross over between spokes, the Internet, or on-premises networks. Peering between spokes within the same subscription and/or Bureau is allowed. Centralized hubs are in US East, and US West regions and are managed by
OCIO.
ExpressRoute - Both centralized hubs have fully redundant ExpressRoute circuits for access to DOI on-premises networks and are managed by OCIO. The ExpressRoute endpoints are designated solely for use with the DOI Azure tenant and are not shared with other Tenants. Route tables that include IP Address space for on-premises resources via ExpressRoute are propagated to all peered virtual networks.
Internet Access - Forced tunnelling to the internet on Azure resources is in place to comply with governmental security mandates. All traffic from/to the internet should flow through the centralized traffic hubs before being routed through the appropriate crossover points. Private endpoints should be utilized whenever possible to limit exposure to the Internet edge. Trusted Internet Connection (TIC) versions 2 and 3 are supported in the environment via the central traffic hubs. Route tables that include the default 0.0.0.0 route and to the Internet are propagated to all virtual networks.
IP address space - IP v4 & v6 addresses for virtual networks peered to the central hubs in Azure are provided by OCIO to each Bureau/Office and are treated as extensions of their on-premises network. IPv4 spaces are limited in nature and should be a consideration in architecture.
DNS Resolution - OCIO employs centralized DNS servers that perform DNS forwarding for Azure
J-05 13 domain spaces both within Azure and the on-premises environments. Private endpoint zones are located centrally to allow all Bureaus/Offices to easily manage custom DNS entries.
Compliance and Security DOI encourages innovation and cloud adoption by taking a minimalist approach to hardening the resources found within the Bureau/Office subscriptions and leaves many of the decisions within the Bureau/Offices purview.
The requirements for Compliance and Security can shift quickly based on Government mandates and memo’s, please check with the Bureau/Office for any last-minute shifts to the information presented below.
Azure Policy - OCIO maintains a minimal list of enterprise-wide Azure Policies that are enforced across the entire tenant. Generally, they are targeted to secure the internet boundaries of the environment and are not a comprehensive list of recommended policies. Exemptions to the existing OCIO policies can be requested through the OCIO Change Management system and are evaluated on a case-by-case basis. The latest list of OCIO Azure Policies can be requested by the Bureau/Office designated Azure points of contact.
Bureaus/Offices are encouraged to layer additional Azure policies on their environments to fully secure their workloads.
Required Logging - OCIO currently retains centralized logs for Azure Active Directory, Azure Activity Logs and the centralized Firewalls in each hub. Logs for individual applications, virtual machines, databases, workloads etc. are the responsibility of each Bureau/Office.
Security Tools - While OCIO recommends security tools like Defender for Cloud, Azure Policy, and Azure Monitor, there are currently no centralized enforcement for specific security tools. Tools that have Enterprise-wide data access plugins (ie: Sentinel) can be deployed for specific subscriptions, but Azure Active Directory plugins, Office365 plugins or other data sources that could expose the entire enterprise to the tool, are prohibited for use outside of OCIO.
Other Requirements Contractor shall identify other licenses, requirements and service level agreement parameters in their proposal they believe are not covered above or elsewhere in this requirement. Specifically, BIA will bring the Azure and EUMS licenses, but does not have, nor presume to know whether the contractorvendor needs additional cloud services SaaS to perform the requirements in this task order. For example, to perform discovery, migration, or continuous monitoring. If this is the case, contractorvendor should include these in their proposal. The Contractor shall identify conditions or exceptions in their proposal they believe are to the best interest of the success of this project.
Other requirements identified are to provide the best support the estimated 20,000 users who access the application through the Customer Web Portal (CWP) and averages 20 – 50 concurrent users during normal daytime business hours. The Contractor will design an environment configured to support the system availability of 99.9% or greater per month.
Software License
• To assist in making sure the project has the correct Microsoft Azure licenses ordered, the Contractor shall identify the Azure licenses they will require to configure and support the project.
• The BIA is also covering the EUMS application licenses separately.
J-05 14
• The Contractor shall propose any additional licenses for operating systems, servers, databases, and applications, etc. to be provided by them.
Backup Systems and Capability Contractor shall propose and deliver a Disaster Recovery Plan for BIA EUMS environment that includes the type of storage, type of backup, and restoration performance objectives. BIA requests Contractor include in their proposal lower-priced archive storage tiers for older backups. Also, see the objectives in the FCHS2 Section J Attachment 1 Security Objectives Cybersecurity and Governance.
• Backup Contents o Applications – (i.e., 45 GB full, 1GB daily incremental) o Data – (i.e., 100 TB full, 50 GB daily incremental) (if running multiple applications, may want to list Data by application) o Other – (i.e., web pages, 100 GB full, 1GB daily incremental)
• Backup Retention Period and Archiving o EUMS data retention period is ten years from date of service meaning that any given day for ten years after date of service, BIA project staff may be required to provide reports and analytics from EUMS detailed data records.
o A full backup is preferred every 24-hours and to occur outside normal daytime access hours.
o BIA requires daily backups to be saved and available for retrieval for any given day within a two-month rolling timeframe.
o BIA requires a lower-tier backup solution for data older than 2 months o The EUMS environment shall have a fully redundant offsite solution.
• Recovery Time Objective (RTO).
o The required length of time for backup restoration:
o Within 24 hours for production environment o 72 hours for development and test environments
• Recovery Point Objective (RPO) o Revert back to prior state no older than 24 hours production
• Snapshot Capability o BIA/Contractor shall have the ability to make an on-demand copy of the system / data, such as before doing a system upgrade or data migration.
Service Level Agreements (SLAs) In addition to specific SLA’s within this task order, see SLA objectives in the FCHS2 Section J Attachment 1 Security Objectives Service Level Agreements.
Professional Services The Contractor shall provide a proposal description and pricing schedule that identifies their estimate hours and costs to complete the two phases of this project. They shall identify the professional services types, and their qualifications to maintain the confidentiality, availability, and integrity of the BIA EUMS application. The Contractor shall break out their tasks and schedules into major milestone such as the following:
Milestone Activities:
Activity Description Number of
Hours Cost per
Hour Conduct discovery, architectural diagram, application mapping, J-05 15 and solidify migration plan Configure and harden new EUMS environment Perform ‘lift and shift’ application migration Modernize new EMUS environment Establish connection to CWP Perform annual system administration services, e.g. ongoing support and partner in continuous monitoring activities
Period of Performance
This task order is aligned with the same base and option years of the primary FCHS2 contract. It includes a two-year base, plus four two-year options for a total of 10-years.
The period of performance begins on the first day of contract award.
Points of Contact The BIA EUMS Acquisition and Project team members names and contact information will be identified at the time of award.
SECTION 3 - TASK ORDER TERMS AND CONDITIONS
3.1 FAR 52.252-2 Clauses Incorporated By Reference (FEB 1998)
This contract incorporates one or more clauses by reference, with the same force and effect as if they were given in full text. Upon request, the Contracting Officer will make their full text available. Also, the full text of a clause may be accessed electronically at this address:
https://www.acquisition.gov/ .
o FAR 52.203-17 CONTRACTOR EMPLOYEE WHISTLEBLOWER RIGHTS AND
REQUIREMENT TO INFORM EMPLOYEES OF WHISTLEBLOWER RIGHTS (JUN
2020) o FAR 52.212-4 CONTRACT TERMS AND CONDITIONS – COMMERCIAL PRODUCTS AND COMMERCIAL SERVICES (DEC 2022) and it’s ALTERNATE I (NOV 2021) o FAR 52.232-18 AVAILABILITY OF FUNDS (APR 1984) o FAR 52.232-39 UNENFORCEABILITY OF UNAUTHORIZED…
This is the start of the file's text. The full file is on GovTribe.
File details come from the government source that posted it. Updated .