B02 RFQ STRATUS Pool 2 Attachment A - SOO.pdf

PDF 262 KB Posted

Attached to
USDA STRATUS Cloud Basic Ordering Agreement (BOA) Pool 2: Integration and Development Federal contract opportunity
Solicitation number
12314423Q0143
Issued by
Department of Agriculture Assistant Secretary for Departmental Management

About this file

This Statement of Objectives describes the scope of services sought under the USDA STRATUS Cloud Basic Ordering Agreement Pool 2 for integration and development support services. Services may include cloud governance, strategy, architecture, migration, security, platform operations, CI/CD pipeline engineering, identity and access management, change management, applications development and integration, discovery and design, training, operations and maintenance, sustainment, FedRAMP authorization assessment, and security assessment and authorization. Pricing will be established at the task order level. Task orders may include service level agreements delineating services, responsibilities, metrics, remedies, and change management. All work will be performed using agile methodologies, open standards, and DevSecOps practices.

View the file

Other files for this federal contract opportunity

Show all 16

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

SOLICITATION NO. 12314423Q0143

STRATUS CLOUD BASIC ORDERING AGREEMENT

POOL 2: INTEGRATION AND DEVELOPMENT SUPPORT SERVICES

ATTACHMENT A

STATEMENT OF OBJECTIVES

Attachment A ‐‐ Statement of Objectives

A.1 Objective

The objective of the STRATUS Pool 2 BOA is to obtain integration and development services including managed services. Services obtained under Pool 2 may include, but are not limited to, services in the following areas:

1. Governance

Cloud governance includes developing and updating policies, procedures, and controls to manage the use of cloud computing resources within an organization. It involves defining rules for the deployment and usage of cloud services and applications, as well as ensuring compliance with regulations and security requirements.

Effective cloud governance ensures that an organization is using cloud resources in a cost‐effective, secure, and compliant manner, while also maximizing the value of cloud investments. This includes managing access to cloud services, monitoring cloud usage, ensuring data privacy and security, and managing the lifecycle of cloud resources. By implementing a robust cloud governance framework, organizations can minimize risk and ensure that their cloud investments are aligned with their overall business strategy.

2. Cloud Strategy

Cloud strategy services refer to the suite of professional consulting services that assist organizations in devising a comprehensive plan for leveraging cloud technology. These services help determine cloud readiness, identify suitable cloud models, select appropriate cloud providers, and design a cloud architecture that meets specific business requirements. Cloud strategy services also cover the creation of a roadmap for cloud adoption, including migration planning, deployment, and management. Cloud strategy services help organizations optimize their cloud investments and accelerate their digital transformation journey while ensuring security, scalability, and cost‐effectiveness.

3. Cloud and Platform Architecture

Cloud architecture services refer to the set of tools and techniques used to design, deploy, and manage applications and services in cloud computing environments. Cloud architecture services also include other components that are essential for building and managing cloud infrastructure. These components include cloud‐centric network architecture, data services/API integration, container orchestration tools, serverless computing frameworks, and cloud‐native development platforms. Container orchestration tools such as

Kubernetes allow developers to deploy and manage containerized applications at scale, while serverless computing frameworks enable developers to run code without worrying about infrastructure management.

Cloud‐native development platforms provide a set of tools and best practices for building and deploying cloud applications, leveraging the benefits of cloud‐native architectures such as microservices, containers, and APIs.

Cloud architecture services also include data storage and processing tools such as databases, data warehousing, and big data processing frameworks that are optimized for cloud environments. These services help organizations to process and analyze large amounts of data in real‐time and make informed decisions based on insights gleaned from the data.

4. Cloud Migration

Cloud migration services support transferring digital assets such as data, applications, and infrastructure from an organization's on‐premises or other environments to cloud‐based solutions. This can involve moving resources to public cloud platforms, or to private cloud solutions. Cloud migration services typically involve a team of experts who assess an organization's existing infrastructure, identify which assets are suitable for migration, and develop a migration plan to ensure that the process is carried out efficiently and securely. These services also provide ongoing support to ensure that the organization's new cloud‐based solutions are performing optimally and meeting its business needs.

5. Cloud Security

Cloud security services include the measures and tools implemented to protect data, applications, and infrastructure stored in the cloud. These services help mitigate the risks associated with cloud computing, including data breaches, unauthorized access, and data loss. Cloud security services typically include encryption, network security, and threat detection and response. These services are customized to meet the specific needs of organizations, and help organizations ensure that their data and infrastructure remain secure while taking advantage of the scalability and flexibility of cloud computing.

6. Platform Operations and Engineering

Platform operations and engineering services include the management and maintenance of digital platforms, including software, hardware, and infrastructure, to ensure their optimal performance and functionality. This involves designing, implementing, and maintaining robust and scalable systems that can handle large volumes of traffic and data. Platform engineers create and manage secure and reliable systems that can support a range of applications and services, from simple websites to complex data analytics tools. They also monitor system performance and proactively identify and address issues to minimize downtime and ensure seamless operation.

7. CI/CD Pipeline Engineering

CI/CD pipeline engineering services include the design, development, and implementation of automated processes that allow for continuous integration and delivery of software applications. This includes creating a pipeline that automates the building, testing, and deployment of software code, ensuring that any changes or updates are thoroughly tested and integrated into the application. The process typically begins with source code management, followed by building, testing, and then deployment. These services aim to streamline the development process, reduce errors and bugs, and ultimately improve the quality of the software application.

CI/CD pipeline management enables development teams to rapidly iterate on their code and respond quickly to feedback, allowing for more efficient and effective software development.

8. Identity and Access Management (IAM)/User Management

Identity and Access Management (IAM), also known as User Management, is a framework of policies, processes, and technologies that facilitates the management of digital identities and their access to IT resources. IAM/User Management services enable organizations to manage and secure access to their data, applications, and systems by granting appropriate permissions and authentication to users based on their roles, responsibilities, and affiliations. These services ensure compliance, prevent data breaches, and streamline operations by providing centralized control and visibility into user access across different environments. Some common IAM/User Management services include user provisioning, single sign‐on (SSO), multi‐factor authentication (MFA), and access governance.

9. Change Management

Change management services for cloud include processes, tools, and strategies to manage and facilitate changes to cloud computing environments. These services help organizations optimize their cloud environments, ensure compliance, and minimize risks associated with changes. Effective change management services for cloud involve comprehensive planning, testing, communication, and documentation to ensure smooth transitions and minimal disruption to business operations. This may involve implementing new cloud technologies, upgrading existing cloud systems, or adjusting cloud configurations to meet changing business needs.

Change management services address both technology changes and behavior changes, including planning, implementing, and monitoring changes within an organization to ensure that they are successful and sustainable. This may include identifying the need for change, developing a strategy, communicating the change to stakeholders, and managing resistance to the change. The goal of change management is to facilitate a smooth transition to new processes, technologies, or systems while minimizing disruption to daily operations and maintaining the morale and productivity of employees. Effective change management requires a comprehensive approach that considers the unique culture, structure, and goals of the organization, and involves collaboration and communication among all stakeholders.

10. Applications Development and Integration

Application Development and Integration includes the process of creating and combining software programs to solve a particular business problem or to enhance the functionality of an existing system. It includes designing, developing, and deploying custom applications that can be integrated with existing software solutions.

Application development and integration can help organizations improve operational efficiency, reduce costs, and increase productivity. This may include identifying requirements, designing the application architecture, developing and testing the software, and integrating it with existing systems. This encompasses a range of technologies, including programming languages, APIs, databases, and development tools. Included in this area are SaaS and low/no‐code development practices where applications are created using visual interfaces, drag‐ and‐drop tools, and pre‐built templates and/or created on SaaS platforms and tools to simplify the software development process and make it possible for non‐technical users to build custom applications without the need for extensive programming skills.

11. Discovery, Framing, and Design

Discovery, framing, and design are steps in the problem‐solving and innovation process. Discovery refers to the initial stage of the process where the problem is identified, and relevant information is gathered. This may include conducting research, analyzing data, and exploring different perspectives to gain a comprehensive understanding of the problem. Framing may include defining the problem statement, identifying the key challenges, and setting clear goals for the project. These steps require critical thinking and a deep understanding of the problem to ensure that the solution is relevant and effective. The design stage involves ideating, prototyping, requirements definition and testing potential solutions. This stage requires creativity, experimentation, and collaboration to develop a viable solution that meets the goals set in the framing stage.

The design stage includes application of human‐centered and user experience (UX) design thinking and principles that put the needs and perspectives of the people who will use a product or service at the center of the design process to ensure that the end result is not only functional and efficient but also intuitive and satisfying to use, ultimately resulting in improved user experiences and outcomes.

12. Training

Training related to cloud services includes educating individuals on how to effectively use cloud‐based technologies and services. Training may include instruction on how to deploy, manage, and optimize cloud infrastructure and applications, as well as best practices for security and compliance in the cloud. Training may also cover topics such as cloud migration, hybrid cloud environments, and cloud‐native development. Training services can range from online courses to hands‐on workshops and may be tailored to specific cloud platforms or technologies.

13. Operations & Maintenance (O&M)

Operations and maintenance for cloud infrastructure and applications involves a range of activities aimed at ensuring the reliability, availability, and security of cloud‐based systems. O&M may include monitoring performance and usage, optimizing resource allocation, and resolving issues related to network connectivity, software bugs, and hardware failures. In addition, maintenance tasks may involve patching and upgrading software, implementing security controls, and conducting backups and disaster recovery tests.

14. Sustainment and Digital Product Management

Sustainment services related to the cloud include the ongoing management and support of cloud‐based systems and infrastructure. This may include monitoring, optimization, security, and cost management. Cloud sustainment services are essential for ensuring the continued reliability, performance, and availability of cloud‐ based systems, as well as for controlling costs and maximizing return on investment. Sustainment services ensure that cloud‐based systems remain up‐to‐date and aligned with the latest technology trends and best practices. Cloud sustainment services can help organizations optimize their cloud investments, reduce risk, and ensure that their cloud infrastructure is aligned with their business goals and objectives.

Operations and maintenance (O&M) focuses on the day‐to‐day tasks of keeping a system running, while sustainment takes a more holistic view and encompasses the broader set of activities involved in ensuring the long‐term success of the system.

All work will be accomplished using commercial practices, industry standards, and modern/agile‐based and

DevSecOps development and delivery, as well as human centered design principles. USDA will maximize utilization of open source and non‐government standards wherever practical. The contractor will work in team‐ based Agile environments.

The Contractor shall provide qualified personnel with relevant experience and domain knowledge in line with

Task Order requirements.

The Contractor will develop all major systems interfaces based on nonproprietary, widely supported, and consensus‐based standards (if available and suitable). The Contractor will provide authorized access, retention, integration, sharing, transfer, and conversion of Intellectual Property (IP) deliverables.

The Contractor will ensure that processes and tools are in place or as appropriate use existing tools in place to support product configuration management, data loss prevention, and data sharing and exchange.

The contractor will provide on‐going support for 'full stack approach' to digital product management, to include applying & managing of digital collaboration tools (ex. chat, wiki, team‐to‐enterprise view of work activities/outcomes), knowledge management, GitOps, user‐centric enhancements, and industry‐leading best practices.

15. FedRamp Authorization and 3PAO Assessor Services

The Readiness Assessment Report (RAR) services from a 3PAO allow USDA decision making when “on boarding” new CSPs. The RAR is based on 3PAO observations and 3PAO gathered evidence. The purpose of a 3PAO Readiness Assessment being delivered to USDA is to have a 3PAO attest to a CSP’s readiness for the FedRAMP authorization process. By completing a RAR, a CSP should be able to understand if their Cloud Service

Offering (CSO) has the key technical capabilities to obtain a FedRAMP authorization and any additional cyber security requirements imposed by USDA.

Further, 3PAO Assessor Services are required for DISC to maintain FedRAMP compliance with service offering presented under the FedRAMP Marketplace.

16. Security Assessment and Authorization (A&A) Services

These services allow USDA to continually assess the risk and magnitude of the harm that could result from the unauthorized access, use, disclosure, disruption, modification, or destruction of information or information systems. The USDA’s Six Step Risk Management Framework (RMF) Process Guide is used to direct the audit and assessment work.

A.2 Pricing

Competitive prices will be established at the Task Order level.

A.3 Performance Management and Service Level Agreement Requirements

The Offeror shall provide SaaS‐specific SLAs at the TO level, as applicable. TO‐level SLAs may include, but are not limited to:

a) A set of services the Contractor will deliver

b) A complete, specific definition of each service

c) The responsibilities of both parties (provider and consumer)

d) A set of metrics to determine whether the Contractor is delivering the service as promised

e) An auditing mechanism to monitor the service

f) The remedies available to both parties if the terms of the SLA are not met

g) A description of how the SLA will change over time

h) A mechanism to track SaaS license usage or utilization

File details come from the government source that posted it. Updated .