SOO_C3E_Draft_Final.pdf
PDF 255 KB Posted
- Attached to
- C3E Request for Information Federal contract opportunity
- Solicitation number
- CDMM250001
About this file
This document is a Draft Statement of Objectives (SOO) for the Cohesive Cloud Environment (C3E) contract, issued by the Secretary of the Air Force Office of Competitive Activities (SAF/OC). The SOO outlines five key Lines of Effort: 1) C3E NIPR Baseline, which includes establishing a virtual user collaboration environment, CDMM hosting platform, identity and access management, integrated development environment, and DevSecOps pipeline; 2) C3E Sustainment, involving migration and development of CDM technologies, enhancing collaboration tools, and optimizing cloud infrastructure; 3) JWICS OC C3E KM Baseline deployment; 4) JWICS OC C3E KM Sustainment; and 5) Cyber Data Reconnaissance and Exploitation (CDRE), focused on identifying and hardening critical cybersecurity weaknesses.
The contract period is one base year with four one-year option periods, with all work to be performed in contractor facilities. The primary objective is to create an enterprise-class, multi-cloud environment that enables swift deployment of secure operational mission capabilities, supports mission data sharing and collaboration, and enhances the Department of the Air Force's ability to predict, detect, and respond to threats. Key technical requirements include multi-cloud infrastructure, containerized application environments, advanced data management services, automated workflows, continuous security enhancement, and integration of artificial intelligence and machine learning capabilities to improve cybersecurity posture and operational effectiveness.
View the file
Other files for this federal contract opportunity
| File | Type | Posted |
|---|---|---|
| C3E_RFI Response to Vendor Questions_16Apr25.pdf | ||
| C3E RFI_26Mar25.pdf |
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
Cohesive Cloud Environment (C3E)
DRAFT STATEMENT OF OBJECTIVES (SOO)
(For RFI Purposes Only)
14 March 2025
1. SCOPE
C3E supports the rapidly evolving mission landscape, by creating enterprise-class, multi-cloud, multi-domain application hosting, development, collaboration, cybersecurity, and mission data discovery and access solutions that enable swift deployment of secure operational mission capabilities, sharing mission data and collaborating to inform decision-making, and rapidly predict, detect, and respond to threats from our adversaries.
2. PERIOD AND PLACE OF PERFORMANCE
Period of Performance is a one (1) year Base Period and four (4) one (1) year Option Periods.
Estimated Performance Start is TBD. Government space is not available; all contracted work must be accomplished in Contractor facilities.
3. BACKGROUND
The Secretary of the Air Force Office of Competitive Activities (SAF/OC) Concepts, Development, and Management (CDM) Program Office conducts the planning and acquisition of cost-effective, critical capabilities to support the war-fighting mission of Combatant
Commanders (CCDRs) and various DoD and US Government Departments and Agencies.
Meeting the evolving mission needs of our customers historically required developing specialized technological silos of excellence. While this approach effectively delivered rapid solutions tailored to specific customer requirements, it resulted in significant duplication of resources and technologies across SAF/CDM. This siloed approach has created a cost-prohibitive environment and hindered cross-functional collaboration. Furthermore, existing solutions lack the capability to effectively discover, store, process, and disseminate information at the highest classification levels in support of SAF/OC and the Secretary of the Air Force’s (SECAFs) vision.
This deficiency has resulted in degraded communication and awareness across the Department of the Air Force (DAF) and slower, less effective action on critical initiatives.
To address these challenges, this requirement seeks industry solutions that break down information silos, foster collaboration across programs, and enable the rapid deployment of secure operational mission capabilities within a cost-effective, standardized environment.
Solutions must leverage modern cloud infrastructure and services to ensure high availability, scalability, and enhanced security while improving contract and acquisition efficiencies.
Solutions will enable the SAF/OC to effectively manage information across the DAF, including at the TS/SCI classification level, to enhance communication and awareness of SAF/OC efforts.
Ultimately, proposed solutions should streamline the deployment of mission-critical information, accelerating both SAF/OC, CDM, and DAF mission execution in support of the 24 key decisions for reoptimizing for Great Power Competition (GPC).
4. PERFORMANCE OBJECTIVES
4.1. Line of Effort 1: C3E NIPR Baseline
ProServ has delivered a C3E NIPR Baseline in the DAF Cloudworks Environment. The contractor shall receive the ProServ baseline and continue development as needed. This current state deployment baseline includes:
4.1.1. Virtual User Collaboration Environment
4.1.1.1. Public Key Infrastructure (PKI) access to the environment
4.1.1.2. End Users ability to access data and applications on all enclaves they are authorized to access
4.1.1.3. Persistent storage mechanism to maintain user environment and settings
4.1.2. CDMM Hosting Platform
4.1.2.1. Standardized platform deployment using Infrastructure as Code (IaC) capabilities such as Terraform/Terragrunt
4.1.2.2. Standard platform components, services, and Application Programming
Interfaces (APIs) for consistent and efficient development across teams.
4.1.2.3. Ability for tenant applications to access CSP resources such as Simple
Storage Service(S3) and Relational Database Service (RDS)
4.1.3. Identity and Access Management Solution (IdAMS)
4.1.3.1. Integration with GeoAxIS, Defense Enrollment Eligibility Reporting
System (DEERS), AccessIT or similar
4.1.3.2. Integration with security specific systems that provide information regarding user attributes/accesses
4.1.4. Integrated Development Environment (IDE)
4.1.4.1. On-demand deployment of IDE as needed
4.1.4.2. PKI-based access control
4.1.4.3. Persistent storage mechanism to maintain user environment and settings
4.1.4.4. Linux desktop environment
4.1.4.5. Common development tools such as VSCode, Amazon Web Services
(AWS) Command Line Interface (CLI), Docker, Python, etc.
4.1.4.6. Access to common CSP services such as RDS and S3
4.1.4.7. Ability to deploy IDE to Graphics Processing Unit (GPU) instances to enable use of GPU during development and testing
4.1.5. DevSecOps Pipeline
4.1.5.1. Supports automated testing, code quality checks, code and container vulnerability scanning, and release management capabilities
4.1.5.2. Integrated version control, automated build processes, and deployment scripts to enable faster and more reliable software releases
4.1.5.3. Container registry with container image vulnerability scanning capabilities
4.1.5.4. Implement monitoring and logging to rapidly detect and resolve pipeline issues
4.1.6. Data Management Services
4.1.6.1. CDMM data mesh architecture that enables access to various data repositories and services
4.1.6.2. Data discovery and retrieval API for integration of data repositories, KD tools, Query/Retrieval UI etc.
4.1.6.3. Data Ingest and Normalization solution to ingest data into the CDMM
Data Lake/streaming service
4.1.6.4. CDMM Data Lake for data storage
4.1.7. Service Training Materials
4.1.7.1. Training documents/Standard Operating Procedures (SOPs)
4.2. Line of Effort 2: C3E Sustainment
The Contractor is responsible for all services currently deployed in 4.1. In addition, the
Contractor shall develop and sustain:
4.2.1. Migration and Development of CDM Technologies within C3E
4.2.1.1. Provide intake, pre-acquisition, acquisition, development, implementation, and sustainment & maintenance support
4.2.1.2. Collaborate with stakeholders to identify new, innovative technologies to enhance mission capabilities
4.2.2. Virtual User Collaboration Environment
4.2.2.1. Collaboration and business tools identified
4.2.2.2. Access to CDM data and capability catalog
4.2.2.3. Access to CDM data query/retrieval services
4.2.2.4. Access to CDM data visualization User Interface (UI)
4.2.2.5. Automated workflow for requesting, approving, and adding applications/tools that are not on the baseline
4.2.2.6. Automated workflow to request and receive environment
4.2.3. CDMM Hosting Platform
4.2.3.1. Optimization of cloud resource usage by implementing a container orchestration service that allows resource quotas and horizontal auto-scaling
4.2.3.2. Ensure platform can be seamlessly deployed across infrastructure provided by multiple Cloud Service Providers (CSPs)
4.2.3.3. Resilient multi-Availability Zone (AZ) and multi-region architecture with cluster and persistent volume backup and restoration
4.2.3.4. Kubernetes security capabilities and tools such as Kubernetes Identity and
Access Management (KIAM) to enable secure multi-tenant cluster/application access to cloud-native services
4.2.4. Integrated Development Environment (IDE)
4.2.4.1. Automated workflow to request and receive IDE
4.2.4.2. Automated workflow for requesting, approving, and adding applications/tools that are not on the IDE baseline
4.2.5. Knowledge Dominance (KD) Discovery and Visualization Services
4.2.5.1. CDMM Capability and Data Catalog with information about CDMM capabilities and data sets including links, schemas, access methods, etc.
4.2.5.2. Generative Artificial Intelligence (AI) and Large Language Model (LLM) capabilities that enable natural, user-focused interactions with data
4.2.5.3. Integrated with data discovery and retrieval API to enable rapid query, discovery, and retrieval of data stored in the data repositories
4.2.5.4. PKI-based access to all tools (and CLI access to SCM)
4.2.5.5. Self-service data visualization/dashboard tools that enable users to create dashboards with the data they need to make informed decisions
4.2.6. Data Management Services
4.2.6.1. CDMM Data Streaming solution to stream data in real time
4.2.6.2. Data governance tools that enable data owners to quickly implement data governance and security requirements such as data tagging to ensure compliance with regulations, and protection of sensitive information
4.2.6.3. Data visualization and reporting/compliance tools
4.2.7. Continuous Enhancement Framework
4.2.7.1. Ability to assess innovative technology to determine if there is a place for it within the baseline
4.2.7.2. Service Desk: Method for collecting user feedback to identify pain points, areas for improvement, and new feature requests
4.2.7.3. Method to evaluate user experience and make service improvements based on analysis
4.2.8. Service Training Materials
4.2.8.1. Training videos
4.2.8.2. Office Hours and User Forum events
4.2.9. Simplified Service Cost Model
4.2.9.1. Menu of services and their cost
4.2.9.2. Method for reviewing cloud consumption costs in real time
4.2.9.3. Method for selecting only the services users require
4.2.10. Automated Workflow for Service Delivery
4.2.10.1. Automated workflows that enable users to submit requests for hosting, DevSecOps, IdAMS, user environment, and monitoring services while capturing the required information to automatically approve and deploy these services for the user
4.2.10.2. Workflows will include an automated mechanism for soliciting approval from requestor organization and CDMM to ensure funding in place to cover requested resources
4.2.10.3. Workflows will include a one button approval mechanism for approvers
4.2.10.4. Workflows will include an automated mechanism for provisioning requested services using IaC following approval
4.2.10.5. Alerts will be sent to Platform team in the event of a failure in the workflow
4.2.10.6. Dashboards capturing workflow metrics will be available to CDMM leadership
4.2.11. Automated Metrics, Monitoring, Alerting, and Response Services
4.2.11.1. Self-service, custom metrics dashboards, alerts, and automated response to specified alerts
4.2.11.2. Incorporates audit logs and enables visualization of auditable events to comply with information security requirements
4.2.11.3. Supports access control for multi-tenancy to ensure sensitive audit and monitoring data is only accessible to the application/system owner
4.3. Line of Effort 3: JWICS OC C3E KM Baseline
Similar to 4.1, ProServ will deliver a JWICS OC C3E KM Baseline in the DAF
Cloudworks Environment. The contractor shall receive the ProServ baseline and continue development as needed. Estimated time for delivery from ProServ is TBD. This deployment baseline includes:
4.3.1. Baseline C3E Architecture and Services
4.3.1.1. Deployment of baseline C3E architecture into the DAF Cloudworks TS
AWS Account
4.3.1.2. Tailoring of C3E for TS environment constraints
4.3.1.3. Update existing documentation, user guides, and training for solution handoff
4.3.1.4. Support for ATO BOE inputs
4.4. Line of Effort 4: JWICS OC C3E KM Sustainment
The Contractor is responsible for all services deployed in 4.3. In addition, the Contractor shall develop and sustain all services in 4.2, utilizing JWICS.
4.5. Line of Effort 5: Cyber Data Reconnaissance and Exploitation (CDRE)
4.5.1. The Contractor shall identify and harden critical weaknesses not visible with current requirements for our networks and weapons systems. The Contractor shall aggressively modernize integrated deterrence approaches to existing cybersecurity tools and data traditionally discarded.
4.5.1.1. Capture discarded data
4.5.1.2. Analyze discarded data
4.5.1.3. Exploit discarded data and baselines
4.5.1.4. Provide reconnaissance to mitigate and fix
4.5.1.5. Disseminate findings
4.5.1.6. Secure systems at scale
4.5.1.7. Enhance resilience and operations
4.5.2. Business Outcomes include:
4.5.2.1. CDM operations will be significantly more difficult to breach
4.5.2.2. Greater visibility into cybersecurity posture
4.5.2.3. Defend / Hunt Forward TTPs (partnership & apps)
4.5.2.4. Repeatable and scalable architecture and methodology
4.5.2.5. Identify vulnerabilities, understand adversarial tactics, and extract insights from cyber data
4.5.2.6. Conceal and reveal strategy and input
4.5.3. Technical Outcomes include:
4.5.3.1. Hardened baselines and exploitation reporting
4.5.3.2. Outcomes informed by AI/ML
4.5.3.3. Removal of analysis paralysis
4.5.3.4. Advanced analysis of threats, anomalies, user behavior
4.5.3.5. Test environment for advanced cyber concepts
4.5.3.6. Optimization of existing security tools and enhancing how humans perform technical cybersecurity
4.5.3.7. Identify data sources with exploits and attack vectors not currently known or factored
5. CDRLs / MILESTONES
Milestones are TBD and will be updated in the Draft RFP.
6. OPERATING CONSTRAINTS
6.1. LOE 4 is contingent on LOE 3
6.2. Milestones are contingent on approval from Govt COR and follow in consecutive order
(i.e. Milestone 2 does not begin until Milestone 1 is completed and approved)
6.3. LOE 5 may conflict with current RMF process
6.4. Post-award management will follow a Scaled Agile Framework (SAFe) methodology
6.4.1. Milestone(s) may be contingent on Government acceptance of preceding milestone(s)
Attachment A: C3E Vision
Attachment B: Potential Labor Descriptions
ISSM: A contracted ISSM (Information Systems Security Manager) is responsible for overseeing the security posture of designated information systems, ensuring compliance with
DoD cybersecurity policies and standards by managing risk assessments, implementing security controls, conducting continuous monitoring, and advising leadership on security matters, all while acting as the primary point of contact for system security concerns within their assigned area of responsibility; essentially serving as a contracted expert to maintain and enhance the security of DoD information systems.
ISSE: Information Systems Security Engineer (ISSE) is responsible for designing, implementing, and maintaining security measures across the information system, ensuring compliance with security regulations and standards by assessing system vulnerabilities, mitigating risks, and developing security architectures to protect sensitive data throughout the system lifecycle. Collaborates with system engineers to integrate security into new projects.
Architect: Cloud Architect is responsible for designing, implementing, and managing cloud computing strategies, ensuring compliance with security regulations and standards while optimizing cloud infrastructure to meet mission needs, including selecting appropriate cloud services while considering cost-efficiency and performance requirements.
Administrator: Cloud Administrator is responsible for managing, monitoring, and maintaining cloud infrastructure, ensuring secure and compliant operations by implementing strict security protocols, managing user access, troubleshooting issues, optimizing resource allocation, and staying updated with DoD regulations to support mission-critical applications within a highly sensitive environment; often collaborating with other IT teams to maintain system integrity and performance.
Engineer: Cloud Engineer is responsible for designing, implementing, and managing cloud-based infrastructure and applications, ensuring compliance with strict security regulations, while collaborating with various teams to deliver mission-critical systems, requiring expertise in areas like Infrastructure as Code (IaC), containerization, and network security to optimize performance and maintain operational resilience across the cloud environment.
File details come from the government source that posted it. Updated .