36C10B18Q3117-001.docx

DOCX document 1 MB Posted

Attached to
VA. GOV Modernization Federal contract opportunity
Solicitation number
36C10B18Q3117
Issued by
Department of Veterans Affairs Technology Acquisition Center Austin

About this file

36C10B18Q3117 Attachment 001 - VA Enterprise Cloud (VAEC) Technical Reference Guide (Attachment 001).docx

View the file

Other files for this federal contract opportunity

Other files attached to VA. GOV Modernization, newest first.
File Type Posted
36C10B18C2760-000.docx DOCX document
36C10B18Q3117-005.docx DOCX document
36C10B18Q3117-004.docx DOCX document
36C10B18Q3117-000.docx DOCX document
36C10B18Q3117-003.pdf PDF
36C10B18Q3117-002.docx DOCX document

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

ATTACHMENT 001

DEPARTMENT OF

VETERANS AFFAIRS

VA Enterprise Cloud (VAEC) Technical Reference Guide for Acquisition Support

Page iii of 10

Table of Contents

1VAEC ENVIRONMENT OVERVIEW4
2VAEC ARCHITECTURE4
2.1CSP ENVIRONMENT4
2.2VAEC SOFTWARE INSTALLATION POLICY5
2.3VAEC MANAGEMENT TOOLS5
2.3.1VA Enterprise Cloud Operational Tools (VAECOT)5
2.3.2VAEC Cloud Service Provider (CSP)-native Tools5
2.3.3VAEC Other VA Tools5
3VAEC CONNECTION TO THE VA NETWORK6
4VAEC GENERAL SUPPORT SERVICES7
5SERVICE LEVEL AGREEMENTS (SLAS)8
6AUTHORITY TO OPERATE (ATO)8
7VAEC-AWS AMAZON WEB SERVICES (AWS) INTRODUCTION10
7.1VAEC-AWS ARCHITECTURE10
7.2VAEC-AWS GENERAL SUPPORT SERVICES10
7.3VAEC-AWS DEPLOYED PRODUCTION APPLICATION LISTS10
8VAEC-AZURE INTRODUCTION10
8.1VAEC-AZURE ARCHITECTURE11
8.2VAEC-AZURE GENERAL SUPPORT SERVICES11
8.3VAEC-AZURE DEPLOYED PRODUCTION APPLICATION LISTS12

Table of Figures

Figure 1 - VAEC4
Figure 3 - Current VAEC Simlified Architecture showing Core services8
Figure 4 - VAEC Security Control Inheritance8
Figure 5 - VAEC-AWS Simplified Architecture10
Figure 6 - VAEC-Azure Simplified Architecture11

Tables of Tables

Table 1 - VAEC GSS7
Table 2 - VAEC-AWS GSS10
Table 3 - VAEC-AWS FedRAMP Common Services10
Table 4 - VAEC-Azure GSS11
Table 5 - VAEC-Azure FedRAMP Common Services12

Working Draft - Pre-decisional, deliberative document. Internal VA User Only

· VAEC Environment Overview The Department of Veterans Affairs (VA) is embracing a “Cloud First” policy and Information Technology (IT) modernization initiatives as established by the Federal Chief Information Officer (CIO).

The VAEC will leverage the full spectrum of cloud services to efficiently provide high-quality, Government and service provider managed, rapidly delivered, innovative, secure, scalable, flexible, and modular environment to service applications for Veterans. The VAEC will provide VA the ability to use the latest technologies to deliver services to our Veterans in ways they are accustomed receiving them.

VAEC provides administrative support of the overall VAEC while the application owner administers and manages their own virtual environment in a self-service model. The VAEC provides the configuration management services to manage development and deployment activities.

· VAEC Architecture The architecture will consist of multiple CSP environments that offer Infrastructure-as-a-Service (IaaS), Platform-as-a-Service (PaaS), and/or Software-as-a-Service (SaaS). The figure below depicts the high level VAEC. VAEC supports development, non-production (e.g. Pre- Prod, Staging, etc.) and production level environments. The graphics and sections below will provide greater detail into these areas including core services, tools and capabilities.

CSP Environment As of the date of this document the available VAEC CSP environments are:

· Microsoft Azure Government Cloud

· Amazon Web Services (AWS) Government Cloud

FIGURE 1 - VAEC

VAEC Software Installation Policy Any software installed on virtual machines (VM) operating in the VAEC at the IaaS or PaaS level s must be VA Technical Reference Model (TRM) compliant or have an approved waiver.

VAEC Management Tools The VAEC will be managed by a set of VA Enterprise Cloud Operational Tools (VAECOT) (ETA Q3 FY2018), Cloud Service Provider (CSP)-native tools and other VA tools.

VA Enterprise Cloud Operational Tools (VAECOT) The VAEC operational tools are part of the overall VAEC architecture, and consist of the following:

1. Self-Service Cloud Service Catalog

2. Provisioning Orchestration Deployment

3. Access and Security Management

4. Resource and Accounting Management

5. Cloud Access Security Broker (CASB)

6. Application Programming Interface (API) Gateway VAEC Cloud Service Provider (CSP)-native Tools When appropriate and approved by VA, contractor access to and utilization of the individual CSP management interfaces will be provided.

VAEC Other VA Tools VA also uses numerous tools to manage its infrastructure. VA maintains a TRM listing tools approved for use on the VA network.

· VAEC Connection to the VA Network The VAEC environments use a common Trusted Internet Connections (TIC) compliant connection mechanism as shown in Figure 2. The connections are high bandwidth (e.g. 10 Gb), fully redundant, encrypted connections with load balancers and firewalls as necessary to the respective endpoints.

During onboarding, the VAEC team will work with the project team to determine IP addressing requirements for each project environment and issue the required VA public and private IP addresses. Public inbound connectivity is blocked by default. Inbound public interfaces require VA approval. All inbound traffic must traverse the VA TIC. The VAEC team will assist with the approval process.

FIGURE 2 - HIGH-LEVEL NETWORK (FLOW) DIAGRAM

· VAEC General Support Services Each VAEC CSP environment provides general support services (GSS) to be leveraged by application/solutions hosted within the environment.

These services simplify migration and hosting of applications in the VAEC CSP environments. The table and graphic below shows the list of services available and how they relate to hosted applications.

TABLE 1 - VAEC GSS

Common Services
Common Security and Scanning Tools

· GitHub

· Ansible

· CA-Hub (monitoring) – APM (Data footprint)

· Identity Access Management (IAM)

· AD - Data Subnet

· DNS Server

· SMTP Relays

· ADFS- SSO Services

· Jump Box

· File Landing Zone

· Disaster recovery

· Backup

· VM Operating System image management

· Splunk SH

· Splunk Indexer

· Nessus

· BigFix

· McAfee

FIGURE 2 - CURRENT VAEC SIMPLIFIED ARCHITECTURE SHOWING CORE SERVICES

· Service Level Agreements (SLAs) Each VAEC environment provides access to standard services provided in accordance with the CSP’s standard SLAs between VA and the CSP (VAEC Standard SLAs).

If the VA requirements for a given application/solution require more stringent SLAs between VA and project team (Project SLAs), it is the responsibility of the project team to meet all requirements using the VAEC Standard SLAs. This may require the project team to architect, deliver, and ensure that the required, more stringent Project SLAs are met using the VAEC Standard SLAs and maintaining this as it changes over time.

· Authority to Operate (ATO) The VAEC CSP Environments all have a US Federal Risk and Authorization Management Program (FedRAMP) High Certified VA ATO. VAEC provides access to the FedRAMP certified services of each CSP. Upon request, non-certified services can be made available.

The ATO for an application residing in the VAEC is separate from the VAEC CSP Environment ATO. Each project team is responsible for its application level ATO.

The ability of a VAEC application level ATO to inherit security controls covered by the VAEC CSP Environment ATO simplifies the application level ATO process. The common services provided by the VAEC environment and included VAEC environment ATO will support the application level security control requirements.

Please refer to the VAEC CSP’s website to determine which services are in scope, and have been fully assessed by third party auditors, resulting in a FedRAMP Certification, attestation, of compliance, or ATO.

FIGURE 3 - VAEC SECURITY CONTROL INHERITANCE

· VAEC-AWS Amazon Web Services (AWS) Introduction The VAEC-AWS environment is in the AWS GovCloud. The VAEC-AWS is connected to the VA network via AWS Direct Connect. Projects are provisioned one or more VPCs for their production, dev and any other required environments. The VAEC-AWS offers common services described above subject to any specific services described below. VAEC-AWS also provides access to the full suite of FedRAMP Certified AWS GovCloud Services by default. Access to Non FedRAMP Certified AWS GovCloud services may be provisioned upon request.

VAEC-AWS Architecture The VAEC-AWS environment consists of environments within one (1) geographic region with multiple availability zones provided by AWS GovCloud. A simplified view of the VAEC-AWS architecture is provided below. Detailed architectural information will only be provided post contract award and/or during project provisioning.

FIGURE 4 - VAEC-AWS SIMPLIFIED ARCHITECTURE

VAEC-AWS General Support Services The VAEC-AWS CSP environment provides general support services (GSS) to be leveraged by application/solutions hosted within the environment as described above in above VA Enterprise Cloud Operational Tools (VAECOT).

TABLE 2 - VAEC-AWS GSS

Common Services
Common Security and Scanning Tools
· None
· None

VAEC-AWS Deployed Production Application Lists

TABLE 3 - VAEC-AWS FEDRAMP COMMON SERVICES

FedRAMP High
FedRAMP Moderate
· None
· None

· VAEC-Azure Introduction The VAEC-Azure and AWS Environment use the same connectivity. The connection into VAEC-Azure end point is via VPN into the Azure Government GovCloud. Projects are provisioned one or more VPCs for their production, dev and any other required environments. The VAEC-Azure offers common services and specific services and access to the full suite of Azure GovCloud Services as well as the ability to leverage the VAEC-Azure ATO.

VAEC-Azure Architecture The VAEC-Azure environment consists of two geographic regions environments, one in Iowa and one in Virginia. A simplified view of the VAEC-Azure architecture is provided below. Detailed architectural information will only be provided post contract award and/or during project provisioning.

FIGURE 5 - VAEC-AZURE SIMPLIFIED ARCHITECTURE

VAEC-Azure General Support Services The VAEC-Azure CSP environment provides general support services (GSS) to be leveraged by application/solutions hosted within the environment as described above in above VA Enterprise Cloud Operational Tools (VAECOT).

TABLE 4 - VAEC-AZURE GSS

Common Services
Common Security and Scanning Tools
· None
· None

VAEC-Azure Deployed Production Application Lists

TABLE 5 - VAEC-AZURE FEDRAMP COMMON SERVICES

FedRAMP High
FedRAMP Moderate
· None
· None

image2.png image3.png image4.png image5.png image6.png image7.png image1.jpeg

File details come from the government source that posted it.