ECMO Cloud Service Draft SOO.pdf

PDF 1 MB Posted

Attached to
ECMO Army Cloud Common Shared Services Provider RFI Federal contract opportunity
Solicitation number
W52P1J-21-R-CSSP
Issued by
Department of the Army Materiel Command Joint Munitions Command

View the file

Other files for this federal contract opportunity

Other files attached to ECMO Army Cloud Common Shared Services Provider RFI, newest first.
File Type Posted
Mandatory Implementation of Army Data Services Requirements Memo.pdf PDF
ECMO Cloud Service RFI.pdf PDF

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

DRAFT 1

Army Cloud Common Shared 2

Services Provider 3

Statement of Objectives (SOO) 4

Army Enterprise Cloud 6

Management Office (ECMO) 7

4 November 2020 9

Contents 11

1. Overview ................................................................................................................................................... 3 12

2. Background ............................................................................................................................................... 3 13

3. Scope ......................................................................................................................................................... 3 14

4. Period and Place of Performance ............................................................................................................. 3 15

5. Data Storage, Data Rights, and Data Ownership ...................................................................................... 3 16

6. Enterprise Cloud Common Shared Services Provider Objectives and Requirements .............................. 4 17

6.1. Objective 1: Deploy IL 6 common services in Microsoft Azure .......................................................... 4 18

6.2. Objective 2: Initial Assessment of cARMY ......................................................................................... 4 19

6.3. Objective 3: Operations, Maintenance and Continual Enhancement of cARMY .............................. 4 20

6.4. Objective 4: Customer Onboarding ................................................................................................... 5 21

6.5. Objective 5: Customer Support (Help Desk) ...................................................................................... 6 22

6.6. Objective 6: Service Level Agreements .............................................................................................. 6 23

6.7. Objective 7: Additional CSP environment development and support ............................................... 7 24

6.8. Objective 8: Training .......................................................................................................................... 7 25

6.9. Objective 9: Program Management ................................................................................................... 7 26

6.10. Objective 10: Subcontract Management ......................................................................................... 7 27

6.11. Objective 11: Cloud Service Offerings (CSOs) and Software Licensing Approach ........................... 7 28

6.12. Cyber Security Requirements .......................................................................................................... 7 29

7. cARMY Minimum Viable Product (MVP) List ............................................................................................ 8 30

1. Overview 33

This document describes the Army’s objectives and requirements to provide a state-of-the-art set 34 of Enterprise Common Shared Services for Army’s multi-cloud environment. 35

2. Background 36

To gain the competitive advantage needed to win on the battlefield in the Information Age, the 37

Army must operationalize its data and invest in resilient information ecosystems designed to 38 provide and protect critical information for the Joint Forces. The Army’s ability to master the 39 application of cloud computing is a critical enabler in the pursuit to operationalizing data by using 40

Artificial Intelligence (AI) and Machine Learning (ML), to use personnel, equipment, and logistics 41 efficiently to accomplish the mission and in cyberspace warfare to protect the force and mission 42 resources. The Army’s vision for leveraging the cloud is to maintain information superiority and 43 to deliver digital overmatch. Therefore, the Army must leverage commercial cloud efficiently and 44 effectively in a manner that enhances the mission effectiveness of its military personnel and its 45 supporting platforms and systems. To do this, Army requires a standardized, secure, trusted, agile 46 and resilient set of shared services for general-purpose Mission Owner cloud use. 47

3. Scope 48 cARMY is the Army’s Enterprise Cloud Environment, managed by Headquarters Department of 49 the Army (HQDA)/Chief Information Office (CIO) Enterprise Cloud Management Office 50

(ECMO). cARMY currently offers authorized and operational common shared services in 51

Amazon Web Services (AWS) at Department of Defense (DoD) Information Impact Level (IL) 2, 52

4 and 5. Additionally, ECMO has contracts in place to develop common services in AWS at IL 6 53 and Microsoft Azure at IL 2, 4 and 5 with expected delivery prior to this acquisition being awarded. 54

The ECMO requires an Enterprise Cloud Common Shared Services Provider to takeover, expand 55 and continuously improve upon cARMY Cloud Common Shared Services in order to reduce 56 complexity, increase security, eliminate duplication of effort, and increase Army-wide adoption of 57 cloud computing technologies. This work may include extending these services into additional 58

Cloud Service Provider (CSP) regions, additional CSPs, and classifications as customer priority 59 dictates. The Army desires that cloud access and infrastructure be brokered by automated, on-60 demand, self-service, templated designs and services to the maximum extent possible, as is done 61 in the commercial world. As efficiencies are gained and environments are optimized, cARMY 62 will be the enduring cloud footprint for all Army general-purpose needs. 63

4. Period and Place of Performance 64

The base Period of Performance will be one (1) year from date of award with four (4) one (1) year 65 options. 66

Place of performance may be on Government premises at Fort Belvoir, VA or other Government 67 owned or leased facilities or off premises at Contractor provided facilities. 68

5. Data Storage, Data Rights, and Data Ownership 69

The Contractor must maintain all data within the legal jurisdiction of the United States IAW 70

DFARS 239.7602-2(b). All data, including but not limited to documents, administrative data, 71 support data, and billing data, transmitted via the system or maintained in the system shall reside 72 at all times in servers located in the United States or in servers of which the operation and 73 maintenance are subject only to the laws of the United States. Data transmitted must only be 74 subject to disclosure pursuant to U.S. Federal law and not the laws of any other jurisdiction or 75 foreign nation. All DoD information/data placed or created by DoD users in a Cloud Service 76

Provider’s (CSP) Cloud Service Offering (CSO) is owned by the DoD, the Mission Owner, and/or 77 their Information Owner. The CSP has no rights to the DoD’s information/data. For more 78 information on data storage, data rights, and data ownership requirements refer to Section 5.2, 79

Legal Considerations, in the DoD Cloud Computing Security Reference Guide (SRG) v1r3. 80

6. Enterprise Cloud Common Shared Services Provider Objectives 81 and Requirements 82

Enterprise Common Shared Services are those services that support application operations in the 83 cloud or in data centers, such as domain name services (DNS), network time protocol (NTP), 84 remote access, file transfer, directory services, authentication and access, etc. The services can be 85 provided by the Government or by contractors but must be approved for operation by a 86

Government Authorizing Official (AO) using the DoD Risk Management Framework (RMF). 87

These services are provided by cARMY for all tenant projects, applications, and services of the 88 cARMY hosting environment or any other approved cloud hosted project and are not managed by 89 the application owner; however, the application owner can inherit controls from the environment 90

Authorization to Operate (ATO). The objective of this solicitation is to not only maintain, enhance 91 and develop Enterprise Common Shared Services but also identify, test, document, and inculcate 92 common processes, tools and procedures to minimize burden on Army Application owners 93 working through the RMF process. Implied in this effort is the need for the continuous integration, 94 testing, deployment, and updating of the environment’s ATO. 95

The following is a list of objectives and requirements that must be met by the contractor as part of 96 the response to the solicitation: 97

6.1. Objective 1: Deploy IL 6 common services in Microsoft Azure 98

The contractor shall build and deploy IL6 common services in Microsoft Azure with the goal of 99 parity to IL2/4/5 Azure and IL6 AWS Common Shared Services in cARMY to the extent that it is 100 reasonable and incorporates commercial best practices. The list of services required is included in 101 the “cARMY Minimum Viable Product List” section. 102

6.2. Objective 2: Initial Assessment of cARMY 103

The contractor shall provide an initial assessment of the existing set of cARMY Common Shared 104

Services to identify gaps or potential improvements and recommendations for modifications to 105 managed services. Improvements and recommendations will only be implemented at the 106 discretion and direction of the Government. 107

6.3. Objective 3: Operations, Maintenance and Continual Enhancement of cARMY 108

The contractor shall provide a managed services approach to operate, configure, design, develop, 109 authorize and enhance the cARMY Common Shared Services in AWS and Microsoft Azure, and 110 potentially future CSPs. In line with the Army Cloud Plan1, the Army intends to maximize use of 111

Software as a Service (SaaS) and Platform as a Service (PaaS) cloud offerings and the contractor 112 shall develop and operate the Common Shared Services with a focus on these services models. 113

However, the contractor shall ensure that the common shared services also support application 114 owners using Infrastructure as a Service (IaaS) cloud offerings. The initial list of required 115

Common Shared Services can be found in the “cARMY Minimum Viable Product List” section. 116

The contractor shall expect the list of required services to increase over time. The contractor shall 117 maintain service descriptions in the ECMO service catalog. The contractor shall ensure that all 118 current architectures are maintained in a government repository and that all common services are 119 appropriately licensed. The contractor shall provide to the Government the root cloud account 120 credentials, and any associated credentials required for the highest level of privileged access. 121 The contractor shall maximize the use of machine-based automation, infrastructure-as-code (IaC) 123 and configuration-as-code (CaC), within the operation of the common services to include tenant 124 onboarding and tenant request fulfillment. The contractor shall ensure that the customer-facing 125 portion of the common shared services be the same regardless of the CSP, however, CSP-specific 126 backend interfaces are expected. The vendor will be responsible for securing systems which they 127 are responsible for, according to the DoD Security Technical Implementation Guide (STIG). 128

Anything with a DoD STIG should be automated and orchestrated to the greatest extent possible. 129

The contractor shall use modern software development methodologies (e.g., agile) to support rapid 130 delivery of standardized, reliable, integrated and secure mission capabilities (IAW AFARS Part 131

5139, Appendix HH). The contractor shall employ continuous integration and outreach to ensure 132 customer satisfaction with services offered. 133

The contractor shall comply with the 10 April 2020, “Mandatory Implementation of Army Data 134

Services Requirements Memo,” as shown in Appendix A. 135

6.4. Objective 4: Customer Onboarding 136

The contractor shall assist customers as they onboard to the cARMY environment, however, the 137 contractor shall maximize the use of self-service onboarding capabilities where possible. Below 138 is a high-level ECMO onboarding process chart, using the Army’s Reception, Staging, Onward 139

Movement and Integration (RSOI) framework. The ECMO Cloud Solutions teams is responsible 140 for the Reception and the Staging phase up to the Environment Configuration task. The cARMY 141 onboarding team shall execute the remainder of the process beginning with the Environment 142

Configuration task. The contractor must work to establish a smooth hand off between the ECMO 143

Cloud Solutions team and the cARMY environment onboarding team. 144

1 https://api.army.mil/e2/c/downloads/2020/09/11/81bb912e/the-army-cloud-plan-2020-final2.pdf

6.5. Objective 5: Customer Support (Help Desk) 146

The contractor shall provide Tier 0/2/3 Help Desk support for the cARMY Common Shared 147

Services environment. Tier 1 shall be provided by the Army Enterprise Service Desk (AESD). 148

The contractor shall propose the workflow and key interface processes to take advantage of the 149

AESD Business to Business (B2B) relationship. The contractor shall coordinate a B2B interface 150 with the AESD during the first 90 days of contract execution. The contractor shall build self-151 service capabilities for customers to include chat operations and chat bots. The contractor shall 152 provide and execute a plan to reduce the number of human help desk interactions needed over 153 time. The contractor shall supply 24/7/365 support at Tier 0 and 2. The contractor shall supply 154

Tier 3 regular support on an 8/5 basis, with on-call support on a 24/7/365 basis. 155

6.6. Objective 6: Service Level Agreements 156

The contractor shall propose a Service Level Agreement (SLA) to cover support, services, 157 reporting, maintenance, licenses, backups, recovery procedures, security levels, cybersecurity 158 controls, authorization, performance metrics, demarcation points, security boundaries and service 159 continuity. The contractor and government will mutually agree upon the final SLA. There may 160 be some priority systems/applications which require unique SLAs in addition to the overarching 161

SLA. 162

Production and non-production enterprise common services must be fully available for all cARMY 163 tenants in all production and non-production environments and regions at a rate of 99.9% per 164 contract year. The solution must contain mechanisms for capturing, visualizing, and securely 165 sharing near real-time availability information via Application Programming Interfaces (APIs) and 166 web-based capabilities. The contractor shall request government approval for any planned service 167 interruptions. 168

6.7. Objective 7: Additional CSP environment development and support 169

The Army may request the contractor to develop and support common services in additional Cloud 170

Service Provider (CSP) environments, based on cARMY customer requirements. 171

6.8. Objective 8: Training 172

The contractor shall provide training and access to training materials/user manuals to assist 173 personnel with use, administration, and management of the cARMY services. The contractor shall 174 provide all lesson plans and training material, in original and editable formats, to the Government. 175

6.9. Objective 9: Program Management 176

The contractor shall have a single point of contact for coordination with the Government Program 177

Management Office; successfully integrate and coordinate all activity needed to provide the 178 cARMY environment; provide corrective action plans, timely identification of issues, and effective 179 management of subcontractors; ensure it provides the appropriate management and resources to 180 ensure overall success of the program is achieved, including maintaining schedule, program 181 reviews, test events, training, deployment to designated locations, sustainment, quality, program 182 management, and risk management; maintain professional and ethical behavior of all contractor 183 personnel. The contractor shall maintain a project registry with all current systems/applications in 184 cARMY and in the onboarding process into cARMY. 185

6.10. Objective 10: Subcontract Management 186

The contractor shall be responsible for any subcontract management necessary to integrate work 187 performed on this requirement and shall be responsible and accountable for subcontractor 188 performance on this requirement. The prime contractor will manage work to ensure no 189

Organizational Conflict of Interest (OCI) considerations. The contractor shall ensure its personnel 190 and all subcontractors it employs in this effort have the appropriate security clearances. 191

Additionally, the contractor shall ensure its personnel and all subcontractors it employs in this 192 effort have the appropriate certifications in accordance with DoDD 8140 (previously DoDD 8570). 193

6.11. Objective 11: Cloud Service Offerings (CSOs) and Software Licensing 194

Approach 195

In response to this RFP, the contractor shall identify their proposed solution’s software licensing 196 requirements and identify its approach to leverage existing Army Purchased Licensing and Joint 197

Enterprise License Agreements/Enterprise Licensing Agreements (JELA/ELA) or cost savings 198 based on economies of scale/bulk purchasing. All licenses purchased under this contract will be 199 owned by the Government. The Government reserves the right to buy required software licenses 200 outside of this contract and provide as Government Furnished Equipment (GFE). 201

As with software licenses, the government reserves the right to buy CSOs needed for the common 202 shared services through a separate contract vehicle. 203

6.12. Cyber Security Requirements 204

The Contractor shall maintain administrative, technical, and physical safeguards and controls 205 required for the security level and services being provided in accordance with (IAW) the Cloud 206

Computing Security Requirements Guide (SRG) Version 1 Release 3 (v1r3), or latest version. The 207 solution must meet security standards and controls specified in DoDI 8500.01 (Cybersecurity) and 208

8510.01 (RMF). 209

The contractor will be responsible for generating and providing RMF required 210 authorization related documentation and artifacts to the cARMY Information System 211

Security Owner (ISO) and Manager (ISSM). The contractor will support the Assessment 212

& Authorization (A&A) process for cARMY 213

The contractor will be responsible for performing Cybersecurity vulnerability scans and 214 addressing all findings in accordance with DoD and Army directives and policies 215

The contractor will conduct Information Assurance Vulnerability Management (IAVM) 216

Monitoring and Response activities, to include development and production of all 217 necessary documentation to support these activities 218

The contractor will work with Army Future Command (AFC)'s Command, Control, 219

Communications, Computers, Cyber, Intelligence, Surveillance and Reconnaissance 220

Center (C5ISR), or other government agency as directed by the government, to establish 221

Cyber Security Service Provider (CSSP) services (as required by DoDI 8530 and as 222 described by the DISA Cloud Computing Security Requirements Guide) for Army 223 applications hosted in commercial cloud 224

The contractor shall ensure that all data-at-rest and data in-transit is encrypted utilizing 225

NSA-approved encryption 226

The contractor will comply with the DoD Secure Cloud Computing Architecture (SCCA) 227

7. cARMY Minimum Viable Product (MVP) List 229

Service Name Service Description

1 Operating System Vulnerability Scanning

Operating System vulnerability scanning service (e.g., Assured Compliance Assessment Solution [ACAS])

2 IP Address Management Planning, tracking, and managing the Internet Protocol (IP) address space used in the cloud environment

3 Virtual Datacenter Security Stack (VDSS)

All VDSS components and services (e.g. Web Application Firewall, Reverse Proxy, etc.) listed in DISA cloud SRG and SCCA documents, and DoD enclave protection firewall

4 Key Management PKI certificate signing, administration, and key management

5 Network Infrastructure Management and Monitoring

Monitor, manage, and alert on events related to network utilization and availability

6 DDoS Protection Service Protects applications in the cloud environment from Distributed Denial of Service (DDoS) attacks

7 DNS Hosting, Caching, Recursion

DNS lookup for cloud-based applications and hierarchical DNS management delegated to mission owners

8 PKI Cert Validation Online Certificate Status Protocol (OCSP) responder to validate if PKI certificates are valid or revoked

9 Network Time Cybersecurity mandated accurate time source for DoD systems hosted in the cloud

10 Patch Management Patch repositories for common operating system patch files.

11 SMTP Relay Simple Mail Transport Protocol (SMTP) based email relay

12 Enterprise Directory Services Privileged administrative user and non-person entity Identity, Credential, and Access Management (ICAM) (e.g., Active Directory [AD], Lightweight Directory Access Protocol [LDAP])

13 Federated Access Management

User Identity, Credential, and Access Management

(ICAM)

14 Secure File Transfer Service

(SFTP)

Securely transfer large files to the cloud environment

15 Notification Services Alerting and notification (e.g., Short Message Service

[SMS])

16 Endpoint Monitoring Protects computing endpoints from malware and other cyber security threats (e.g., Host Based Security Service [HBSS])

17 Remote Privileged Access Secure administrative access from the Internet or DODIN to DoD servers in secure cloud enclaves.

18 Centralized Logging/Auditing Consolidated aggregation point for receiving and storing logs from systems and applications in the cloud environment

19 Security Information and Event Management (SIEM) and Log Analytics

Identifies and categorizes security related incidents and events

20 Data Dissemination Service Accelerates and consolidates data for transfer utilizing secure network tunnels.

21 Code Repository Code repository for source code configuration management to support a software factory

22 STIG Compliant Virtual Server Templates

A library which stores DISA Security Technical Implementation Guide (STIG) compliant virtual machine template images

23 License/Software Management Operating System (OS) level license management

24 Asset Management Services Discover and track assets such as resources, licensed software, etc. within the cloud environment

25 Cross Domain Solution (CDS) Automatically move appropriately vetted files between security classification levels

26 Cyber Security Service Provider (CSSP) Services

Standardized tools & processes to meet cloud cyber security requirements; primarily provided by C5ISR to cARMY tenants. Collaboration with cARMY cloud services ops team

27 Continuous Integration / Continuous Delivery/Deployment (CI/CD) Tools

Tools to enable the CI/CD pipeline (e.g., static and dynamic quality vulnerability load journey integration testing))

28 Enterprise Data Catalog and Service Registry

Data and service listing for data and service management and automated data processing

29 Container Platform Enabling container runtime services (e.g., container orchestration)

30 Budget and Cost Management Provides cloud cost and budget information to mission owners

31 Resource Management Portal Portal to manage compute and store resources

File details come from the government source that posted it. Updated .