36C10B18Q3117-001.docx
DOCX document 1 MB Posted
- Attached to
- VA. GOV Modernization Federal contract opportunity
- Solicitation number
- 36C10B18Q3117
About this file
36C10B18Q3117 Attachment 001 - VA Enterprise Cloud (VAEC) Technical Reference Guide (Attachment 001).docx
View the file
Other files for this federal contract opportunity
| File | Type | Posted |
|---|---|---|
| 36C10B18C2760-000.docx | DOCX document | |
| 36C10B18Q3117-005.docx | DOCX document | |
| 36C10B18Q3117-004.docx | DOCX document | |
| 36C10B18Q3117-000.docx | DOCX document | |
| 36C10B18Q3117-003.pdf | ||
| 36C10B18Q3117-002.docx | DOCX document |
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
ATTACHMENT 001
DEPARTMENT OF
VETERANS AFFAIRS
VA Enterprise Cloud (VAEC) Technical Reference Guide for Acquisition Support
Page iii of 10
Table of Contents
| 1 | VAEC ENVIRONMENT OVERVIEW | 4 |
| 2 | VAEC ARCHITECTURE | 4 |
| 2.1 | CSP ENVIRONMENT | 4 |
| 2.2 | VAEC SOFTWARE INSTALLATION POLICY | 5 |
| 2.3 | VAEC MANAGEMENT TOOLS | 5 |
| 2.3.1 | VA Enterprise Cloud Operational Tools (VAECOT) | 5 |
| 2.3.2 | VAEC Cloud Service Provider (CSP)-native Tools | 5 |
| 2.3.3 | VAEC Other VA Tools | 5 |
| 3 | VAEC CONNECTION TO THE VA NETWORK | 6 |
| 4 | VAEC GENERAL SUPPORT SERVICES | 7 |
| 5 | SERVICE LEVEL AGREEMENTS (SLAS) | 8 |
| 6 | AUTHORITY TO OPERATE (ATO) | 8 |
| 7 | VAEC-AWS AMAZON WEB SERVICES (AWS) INTRODUCTION | 10 |
| 7.1 | VAEC-AWS ARCHITECTURE | 10 |
| 7.2 | VAEC-AWS GENERAL SUPPORT SERVICES | 10 |
| 7.3 | VAEC-AWS DEPLOYED PRODUCTION APPLICATION LISTS | 10 |
| 8 | VAEC-AZURE INTRODUCTION | 10 |
| 8.1 | VAEC-AZURE ARCHITECTURE | 11 |
| 8.2 | VAEC-AZURE GENERAL SUPPORT SERVICES | 11 |
| 8.3 | VAEC-AZURE DEPLOYED PRODUCTION APPLICATION LISTS | 12 |
Table of Figures
| Figure 1 - VAEC | 4 |
| Figure 3 - Current VAEC Simlified Architecture showing Core services | 8 |
| Figure 4 - VAEC Security Control Inheritance | 8 |
| Figure 5 - VAEC-AWS Simplified Architecture | 10 |
| Figure 6 - VAEC-Azure Simplified Architecture | 11 |
Tables of Tables
| Table 1 - VAEC GSS | 7 |
| Table 2 - VAEC-AWS GSS | 10 |
| Table 3 - VAEC-AWS FedRAMP Common Services | 10 |
| Table 4 - VAEC-Azure GSS | 11 |
| Table 5 - VAEC-Azure FedRAMP Common Services | 12 |
Working Draft - Pre-decisional, deliberative document. Internal VA User Only
· VAEC Environment Overview The Department of Veterans Affairs (VA) is embracing a “Cloud First” policy and Information Technology (IT) modernization initiatives as established by the Federal Chief Information Officer (CIO).
The VAEC will leverage the full spectrum of cloud services to efficiently provide high-quality, Government and service provider managed, rapidly delivered, innovative, secure, scalable, flexible, and modular environment to service applications for Veterans. The VAEC will provide VA the ability to use the latest technologies to deliver services to our Veterans in ways they are accustomed receiving them.
VAEC provides administrative support of the overall VAEC while the application owner administers and manages their own virtual environment in a self-service model. The VAEC provides the configuration management services to manage development and deployment activities.
· VAEC Architecture The architecture will consist of multiple CSP environments that offer Infrastructure-as-a-Service (IaaS), Platform-as-a-Service (PaaS), and/or Software-as-a-Service (SaaS). The figure below depicts the high level VAEC. VAEC supports development, non-production (e.g. Pre- Prod, Staging, etc.) and production level environments. The graphics and sections below will provide greater detail into these areas including core services, tools and capabilities.
CSP Environment As of the date of this document the available VAEC CSP environments are:
· Microsoft Azure Government Cloud
· Amazon Web Services (AWS) Government Cloud
FIGURE 1 - VAEC
VAEC Software Installation Policy Any software installed on virtual machines (VM) operating in the VAEC at the IaaS or PaaS level s must be VA Technical Reference Model (TRM) compliant or have an approved waiver.
VAEC Management Tools The VAEC will be managed by a set of VA Enterprise Cloud Operational Tools (VAECOT) (ETA Q3 FY2018), Cloud Service Provider (CSP)-native tools and other VA tools.
VA Enterprise Cloud Operational Tools (VAECOT) The VAEC operational tools are part of the overall VAEC architecture, and consist of the following:
1. Self-Service Cloud Service Catalog
2. Provisioning Orchestration Deployment
3. Access and Security Management
4. Resource and Accounting Management
5. Cloud Access Security Broker (CASB)
6. Application Programming Interface (API) Gateway VAEC Cloud Service Provider (CSP)-native Tools When appropriate and approved by VA, contractor access to and utilization of the individual CSP management interfaces will be provided.
VAEC Other VA Tools VA also uses numerous tools to manage its infrastructure. VA maintains a TRM listing tools approved for use on the VA network.
· VAEC Connection to the VA Network The VAEC environments use a common Trusted Internet Connections (TIC) compliant connection mechanism as shown in Figure 2. The connections are high bandwidth (e.g. 10 Gb), fully redundant, encrypted connections with load balancers and firewalls as necessary to the respective endpoints.
During onboarding, the VAEC team will work with the project team to determine IP addressing requirements for each project environment and issue the required VA public and private IP addresses. Public inbound connectivity is blocked by default. Inbound public interfaces require VA approval. All inbound traffic must traverse the VA TIC. The VAEC team will assist with the approval process.
FIGURE 2 - HIGH-LEVEL NETWORK (FLOW) DIAGRAM
· VAEC General Support Services Each VAEC CSP environment provides general support services (GSS) to be leveraged by application/solutions hosted within the environment.
These services simplify migration and hosting of applications in the VAEC CSP environments. The table and graphic below shows the list of services available and how they relate to hosted applications.
TABLE 1 - VAEC GSS
| Common Services |
| Common Security and Scanning Tools |
· GitHub
· Ansible
· CA-Hub (monitoring) – APM (Data footprint)
· Identity Access Management (IAM)
· AD - Data Subnet
· DNS Server
· SMTP Relays
· ADFS- SSO Services
· Jump Box
· File Landing Zone
· Disaster recovery
· Backup
· VM Operating System image management
· Splunk SH
· Splunk Indexer
· Nessus
· BigFix
· McAfee
FIGURE 2 - CURRENT VAEC SIMPLIFIED ARCHITECTURE SHOWING CORE SERVICES
· Service Level Agreements (SLAs) Each VAEC environment provides access to standard services provided in accordance with the CSP’s standard SLAs between VA and the CSP (VAEC Standard SLAs).
If the VA requirements for a given application/solution require more stringent SLAs between VA and project team (Project SLAs), it is the responsibility of the project team to meet all requirements using the VAEC Standard SLAs. This may require the project team to architect, deliver, and ensure that the required, more stringent Project SLAs are met using the VAEC Standard SLAs and maintaining this as it changes over time.
· Authority to Operate (ATO) The VAEC CSP Environments all have a US Federal Risk and Authorization Management Program (FedRAMP) High Certified VA ATO. VAEC provides access to the FedRAMP certified services of each CSP. Upon request, non-certified services can be made available.
The ATO for an application residing in the VAEC is separate from the VAEC CSP Environment ATO. Each project team is responsible for its application level ATO.
The ability of a VAEC application level ATO to inherit security controls covered by the VAEC CSP Environment ATO simplifies the application level ATO process. The common services provided by the VAEC environment and included VAEC environment ATO will support the application level security control requirements.
Please refer to the VAEC CSP’s website to determine which services are in scope, and have been fully assessed by third party auditors, resulting in a FedRAMP Certification, attestation, of compliance, or ATO.
FIGURE 3 - VAEC SECURITY CONTROL INHERITANCE
· VAEC-AWS Amazon Web Services (AWS) Introduction The VAEC-AWS environment is in the AWS GovCloud. The VAEC-AWS is connected to the VA network via AWS Direct Connect. Projects are provisioned one or more VPCs for their production, dev and any other required environments. The VAEC-AWS offers common services described above subject to any specific services described below. VAEC-AWS also provides access to the full suite of FedRAMP Certified AWS GovCloud Services by default. Access to Non FedRAMP Certified AWS GovCloud services may be provisioned upon request.
VAEC-AWS Architecture The VAEC-AWS environment consists of environments within one (1) geographic region with multiple availability zones provided by AWS GovCloud. A simplified view of the VAEC-AWS architecture is provided below. Detailed architectural information will only be provided post contract award and/or during project provisioning.
FIGURE 4 - VAEC-AWS SIMPLIFIED ARCHITECTURE
VAEC-AWS General Support Services The VAEC-AWS CSP environment provides general support services (GSS) to be leveraged by application/solutions hosted within the environment as described above in above VA Enterprise Cloud Operational Tools (VAECOT).
TABLE 2 - VAEC-AWS GSS
| Common Services |
| Common Security and Scanning Tools |
| · None |
| · None |
VAEC-AWS Deployed Production Application Lists
TABLE 3 - VAEC-AWS FEDRAMP COMMON SERVICES
| FedRAMP High |
| FedRAMP Moderate |
| · None |
| · None |
· VAEC-Azure Introduction The VAEC-Azure and AWS Environment use the same connectivity. The connection into VAEC-Azure end point is via VPN into the Azure Government GovCloud. Projects are provisioned one or more VPCs for their production, dev and any other required environments. The VAEC-Azure offers common services and specific services and access to the full suite of Azure GovCloud Services as well as the ability to leverage the VAEC-Azure ATO.
VAEC-Azure Architecture The VAEC-Azure environment consists of two geographic regions environments, one in Iowa and one in Virginia. A simplified view of the VAEC-Azure architecture is provided below. Detailed architectural information will only be provided post contract award and/or during project provisioning.
FIGURE 5 - VAEC-AZURE SIMPLIFIED ARCHITECTURE
VAEC-Azure General Support Services The VAEC-Azure CSP environment provides general support services (GSS) to be leveraged by application/solutions hosted within the environment as described above in above VA Enterprise Cloud Operational Tools (VAECOT).
TABLE 4 - VAEC-AZURE GSS
| Common Services |
| Common Security and Scanning Tools |
| · None |
| · None |
VAEC-Azure Deployed Production Application Lists
TABLE 5 - VAEC-AZURE FEDRAMP COMMON SERVICES
| FedRAMP High |
| FedRAMP Moderate |
| · None |
| · None |
image2.png image3.png image4.png image5.png image6.png image7.png image1.jpeg
File details come from the government source that posted it.