Attachment 2 - SOO 29June2020.pdf

PDF 158 KB Posted

Attached to
Software DevSecOps Services Basic Ordering Agreement (Onboarding) Federal contract opportunity
Solicitation number
FA8307-20-R-0112
Issued by
Department of the Air Force Materiel Command Lifecycle Management Center Joint Base San Antonio

View the file

Other files for this federal contract opportunity

Other files attached to Software DevSecOps Services Basic Ordering Agreement (Onboarding), newest first.
File Type Posted
Attachment 6 - Revised QAs 5Aug2020.pdf PDF
Attachment 1 - Revised ITO DevSecOps 5Aug2020.pdf PDF
Attachment 5 - Revised Provisions and Clauses 5Aug20.pdf PDF
AMA QAs 5Aug2020.pdf PDF
Attachment 6 - QAs Final 30July2020.pdf PDF
Attachment 1 - Revised ITO DevSecOps 30July2020.pdf PDF
BOA RFQ Cover Letter - SW DevSecOps.pdf PDF
Attachment 6 - QA Template.docx DOCX document
Attachment 5 - Provisions and Clauses - SW DevSecOps.pdf PDF
Attachment 3 - Labor Category.pdf PDF
Attachment 4 - BOA Guide SW DevSecOps 10Jan20.pdf PDF
Attachment 1 - ITO DevSecOps 15July2020.pdf PDF
Show all 12

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

FA8307-20-R-0112

Attachment 2 29 June 2020

Statement of Objectives - Software DevSecOps Services

The contractor shall support LevelUP Platform One and LevelUP Platform One pathfinder product development through technical services of full-stack DevSecOps engineers, Cloud engineers, infrastructure engineers, and other key personnel to include: software engineers, programmers, developers, trainers and consultants. This includes but is not limited to software engineers, programmers, architects, Cloud architects, and developers that support the Government in constructing a secure, reliable, resilient, and assured set of software applications on the supporting Government and commercial tools and platforms. The contractor may also be required to assist in virtualizing and/or containerizing existing applications onto the cloud platform. These services will support the Government in constructing a secure, reliable, resilient, and assured set of software applications with supporting Government and commercial tools and platforms.

In addition, the Offeror shall propose their strategy to build and operate multi-tenant shared services that support software development teams, such as event streams, databases, data analytics, message queues, storage, and logging.

The contractor shall implement agile principles and lean startup practices to employ continuous delivery and instill a team dynamic that responds well to change. The contractor may work with various Government and commercial tools and platforms such as, but not limited to, Cloud Native Computing Foundation (CNCF) compliant Kubernetes distributions, Istio, KNative, Openshift, and VMware products. The contractor may embed with engineers (product dependent) to familiarize themselves with Platform One at locations to include: San Antonio, TX, Colorado Springs, CO, and Odgen, UT as well as other locations specified at a later date.

The Software DevSecOps BOA is structured to support platform development teams, platform & product onboarding teams, product development teams (applications), site reliability engineers, cybersecurity teams, and information technology support & operations.

For all teams, the contractor must provide qualified manpower within ten (10) business days of Government request or of a vacancy. If a key personnel position is identified at the order level, the contractor shall minimize the operational burden. All labor category mixes will be determined at the order level. Key Personnel are identified the order level.

The contractor shall follow the guidance provided by the DoD Enterprise DevSecOps initiative.

The contractor shall provide support to platform development teams in the following area(s):

• Ensure platform environments on multiple networks and classifications are stable, reliable, and available.

• All work must follow infrastructure as code best practices.

• Propose and implement solutions for developing, operating, and maintaining the Platform One or

Platform One pathfinder platform, regardless of underlying infrastructure.

• Hardening of containers following DoD best practices.

• Develop and maintain required automation and tooling to quickly deploy and manage applications.

• Oversee operational maturity of services through automated flows, streamlined planned changes, and proactively ensuring reliability.

• Utilize commercial best practices in agile and DevSecOps (CI/CD) software development.

The primary place of performance for the platform development teams is currently in Colorado Springs, Colorado. The place of performance will be determined at the order level, work may or may not be at a Government or contractor site depending on the requirement. The work could be performed virtually if allowed at the order level.

The contractor shall provide support to platform & product onboarding teams in the following area(s):

• Ensure external Government & Government contractor teams can onboard platform & product teams to the Platform One platform ensuring platform environments on multiple networks are stable, reliable, and available. Please note: this does not require initiating or managing Government led agreements or contracts.

• Hardening of containers following DoD best practices.

• Develop and maintain required automation and tooling to quickly deploy and manage applications.

• Propose and implement solutions for onboarding external Government and Government contractor teams products and platforms.

• Utilize commercial best practices in agile and DevSecOps (CI/CD) software development.

The primary place of performance will be dependent on external Government and Government contractor teams products and the location is expected to vary. The work could be performed virtually if allowed at the order level.

The contractor shall provide support to product development teams in the following areas:

• Ensure all new development will adhere to authority to operate (ATO), continuous authority to operate (C-ATO) or other approved Government authorization official requirements.

• Work-off prioritized story points as directed by the product owner.

• Develop secure and reliable and resilient set of software applications whether refactoring or re-hosting existing applications or developing new applications.

• Develop and maintain required automation and tooling to quickly deploy and manage applications.

• Utilize commercial best practices in agile and DevSecOps (CI/CD) software development.

The primary place of performance will be dependent on external Government and Government contractor teams products and the location is expected to vary. The work could be performed virtually if allowed at the order level.

The contractor shall provide support to cybersecurity teams in the following areas:

• Analyze the security of LevelUP or LevelUP pathfinder applications and services and release and deployment pipelines.

• Discover and address security issues, build security automation and quickly react to new threats.

• Provide a robust security strategy that emphasizes ability to perform design and code reviews and security-related tasks that mitigate risks.

• Keep up with Kubernetes cybersecurity threats and best practices to harden and secure

Kubernetes clusters at scale.

• Demonstrate working with product developers to drive toward a solution that enables developers to operate quickly while maintaining compliance with Platform One’s or Platform One pathfinder’s C-ATO.

• Ability to perform cyber penetration analysis (pen-testing) and red teaming/blue teaming.

The contractor shall provide support to information technology support & operations in the following areas:

• Ensure platform and network environments are compliant with the DoD Enterprise DevSecOps guidance, automated, stable, reliable, and available.

• Support required automation and tooling to quickly deploy and manage applications.

• Support a 24 hour operations and/or business hour (0830-1630) help desk.

Descriptions:

Continuous Integration/Continuous Delivery (CI/CD) Pipeline: Continuous integration establishes a consistent and automated way to build, package, and test applications. Continuous delivery automates the delivery of applications to selected infrastructure environments.

Platform development teams: develops and maintains the CI/CD pipeline as well as platform environment compliant with the CNCF requirements for Kubernetes such as Kubernetes upstream, D2IQ Kubernetes, Openshift, VMWare PKS Essentials, etc. They ensure a modern and secure foundation upon which all product teams develop and deploy containerized applications to. The majority of the platform engineering team should be co-located.

Platform and product onboarding teams: Supports platform and product teams from multiple Government and Government contractor organizations onboard from a technical and operational perspective onto a Platform One or Platform One pathfinder platform. Following onboarding, the team provides continued support as required. This may require long-term onsite support.

Product development teams: Develop secure and reliable and resilient set of software applications whether refactoring or re-hosting existing applications or developing new applications at the Government’s request.

Cybersecurity teams: Discover and address security issues, build security automation and quickly react to new threats.

Information technology support & Operations teams: Provides technical and operational support to ensure Platform One’s or a Platform One pathfinder’s systems are secure, reliable, and resilient.

File details come from the government source that posted it. Updated .