Attachment_A-_PWS.docx

DOCX document 93 KB Posted

Attached to
Archive Storage System and Storage System Services Federal contract opportunity
Solicitation number
EDEICM16Q0010
Issued by
Department of Education Contracts and Acquisition Management

About this file

Attachment A-Performance Work Statement

View the file

Other files for this federal contract opportunity

Other files attached to Archive Storage System and Storage System Services, newest first.
File Type Posted
EDEICM16Q0010.pdf PDF
Attachment_B-_Pricing_Spec_Sheet.xlsx XLSX spreadsheet

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

United States Department of Education Office of the Chief Information Officer

Archive Storage System and Storage System Administration Support

Performance Work Statement (PWS) August 10, 2016

Table of Contents

Introduction3
Background3
Scope of Work3
Task 1 – Procurement and Integration of the Archive Storage System3
Task 2 – Storage System Administrator5
Delivery Schedule/Period of Performance5
Place of Performance6
Assumptions6
Constraints6
FISMA Requirements7
Compliance with ED IT Security Policy8
Reporting of Data Security Breaches10
ED Project Manager10

Introduction The U.S. Department of Education (Department) was created in 1980 by combining offices from several federal agencies. The Department’s mission is to promote student achievement and preparation for global competitiveness by fostering educational excellence and ensuring equal access.

The Office of the Chief Information Officer (OCIO) provides the technological solutions that enable the Department to deliver world-class service to schools, students and their families. To accomplish its mission, OCIO advises and assists the Secretary and other senior officers in acquiring information technology (IT) and managing information resources. OCIO helps these leaders comply with the best practices in the industry and applicable federal laws and regulations, including the Clinger Cohen Act, the Government Paperwork Reduction Act and the Federal Information Security Management Act. In addition, the agency's Chief Information Officer is charged with establishing a management framework that leads the agency toward more efficient and effective operations, including improved planning and control of IT investments.

Background

The Department has several terabytes (TB) of files on production storage systems that are more than 5 years old. With this effort the Department is seeking to reduce the number of archive files within the Department’s leased production storage systems as a method to save monthly storage costs, and to become compliant with the current Records Management policies. This effort will be led by the Department and will consist of the deployment of an Archive Storage System to house the archive data, along with efforts to identify, transfer and remove the archive files from the leased production storage systems. The identification, transferring and removing of archive files from the production storage systems will be completed by the Department and will continue on an ongoing basis. Doing so will ensure compliance with the Department’s Records Management policies.

The Department will work with our primary support contractor to ensure the necessary data access is provided to permit the Department with the ability to identify, transfer and remove the archive files throughout the EDUCATE environment on a continuing basis to ensure compliance with the Department’s Records Management policy. The Department also requires our primary support contractor to enable availability of the Archive data to all users through standard drive letter mapping at login. This will enable all Department end users with a familiar method to access their Archive files after they are moved to the Archive Storage System.

Scope of Work

The purpose of this Performance Work Statement (PWS) is to obtain the Archive Storage System, the services to have it installed and configured by the OEM vendor, and to obtain up to 960 hours of Storage System Administrator assistance to perform the data moves on behalf of the Department.

Task 1 – Procurement and Integration of the Archive Storage System The Contractor shall:

· Work with the Department’s primary support contractor to ensure delivery and installation of the system is completed as scheduled.

· Provide hardware and software support for the Archive Storage System for 36 months. This will include remote and onsite technical support when required. Drive retention for 36 months is also required for data security reasons.

· Configure remote external monitoring for the Archive Storage System hardware to ensure that hardware, drive, and other potential system failures are directly sent to the OEM vendor for resolution.

· Ensure the offered product will serve as a network attached storage (NAS) device running a Windows like file server capability. This will include joining the Archive Storage System to the ED.GOV domain to ensure file system permissions remain consistent once data is moved to the Archive Storage System.

· Procure a product that will have no less than 102 TB of usable space across 10K SAS and 7.2K NL-SAS disks. There is to be one usable disk pool configured for the at least 102 TB of usable space.

· Ensure the IOPS (Input/Output Operations Per Second) of the system are no less than 3300

· Deliver the Archive Storage System in a 40U rack that includes at least two power distribution units (PDU). Twist lock L6-30 connections for the PDUs are required.

· Provide product installation, configuration and integration by the OEM vendor following best practices.

· Ensure the Archive Storage System contains at least two 10GB Ethernet SFP fiber interfaces per storage processor (SP). Two storage processors are required within the Archive Storage System to ensure availability.

· Ensure that data will be presented to the Department customers as Read Only. Once the data is moved to the Archive Storage Unit it is to become Read Only.

· Ensure all Department data will be encrypted at rest using FIPS 140-2 validated cryptography

· The OEM System Integrator reporting to the Plano Technology Center must be already cleared with either a High Risk (6c) clearance or a Top Secret security clearance.

· Provide an Archive Storage System with specifications similar to an EMC Unity 300 Hybrid storage system (or brand name equivalent solution) operating as a Network Attached Storage (NAS) device. The vendor part specifications or brand name equivalent solution(s), to include hardware, software, integration support and professional services are in the table below for reference.

Line
Mfg Item
Description
Qty
1
D3123AD
UNITY 3U 15X3.5 DRIVE DAE EMC RCK
3
2
40U-PWR-US
CAB QUAD POWER CORD US TWISTLOCK
2
3
D3SFP10I
UNITY 4X10GB SFP ISCSI/ETH CONNECTION
1
4
D3-VS07-4000
UNITY 4TB NLSAS 15X3.5 DRIVE
34
5
40U-RACK-DOOR
40U RACK W/DOOR
1
6
D3-2S10-1200
UNITY 1.2TB 10K SAS 25X2.5 DRIVE
15
7
D3FC-2S12FX-200
UNITY 200GB FAST CACHE 25X2.5 DRIVE
3
8
D3SP-S6X1200-10K
UNITY SYSPACK 6X1.2TB 10K SAS 25X2.5
1
9
D31D24AD25
UNITY 300 2U DPE 25X2.5 DRIVE EMC RCK
1
10
PS-BAS-UXIMFAST
FAST IMPLEMENTATION
1
11
PS-BAS-UXHWIN
HARDWARE INSTALLATION
1
12
PS-BAS-UXIMB
BASE IMPLEMENTATION
1
13
PS-BAS-UXIMAV
CAVA IMPLEMENTATION
1
14
PS-BAS-PMUSD
USD PROJECT MANAGER - BLOCK OF TIME
1
15
M-PREHWE-004
PREMIUM HARDWARE SUPPORT - 36 months
1
16
M-PARTRT-PR3-UNTY
PARTS RETENTION UPLIFT UNTY - 36 months
1

Task 2 – Storage System Administrator The Contractor shall provide Storage System Administrator support services for up to 6 MONTHS OF FULL TIME SUPPORT to primarily migrate the identified archive storage data from Windows based file servers to the procured Archive Storage System. The Storage System Administrator will manage the Archive Storage System and perform the data migrations within a LAN environment. The Storage System Administrator must be proficient with a Windows file server environment, and have a background managing a Storage System comparable to what is being requested. A high level architect or engineer is not required, but someone who can handle the task of data migrations and basic system administration. The amount of data to be migrated will be about 50TB and the current user and group permissions on files and folders moved must be maintained during migration.

The Storage System Administrator must be already cleared with either a High Risk (6c) clearance or a Top Secret security clearance.

Delivery Schedule/Period of Performance

The Contractor shall coordinate with the Department’s primary support contractor for system installation by November 18, 2016.

CLIN
Deliverable
Deliverable / Service
Due Date
1
Project Coordination/Kick-Off Meeting
Service
One Business Day After Contract Award
1
Submit all required security clearance forms so current clearances can be validated for the OEM System Integrator(s) assigned to the effort
Service
15 Days After Contract Award
1
Coordinate with the Department’s primary support contractor to deploy the COTS Archive Storage System based on OEM vendor best practices
Service
15 Business Days After System Delivery
1
Delivery of the Archive Storage System to the Plano Technology Center
Deliverable
No Later Than 03 October 2016
1
Install and integrate the Archive Storage System to the ED.GOV environment.
Service
30 Business Days after Acceptance/Receipt of Hardware at the Plano Technology Center
1
Support Contract in place for technical and hardware support.
Deliverable
15 Business Days After System Delivery
2
Submit all required security clearance forms so current clearances can be validated for the proposed Storage System Administrator
Service
15 Days After Contract Award
2
Cleared Storage System Administrator reports to the 550 12st SW, DC location
Service
No Later Than 31 October 2016

Place of Performance

The Archive Storage System delivery, and the integration tasks to be completed by the OEM vendor will be performed at the Dell Solutions Federal Government Plano Technology Center (PTC), 2300 West Plano Parkway, Plano, TX.

The work location for the Storage System Administrator will be at the Department’s Potomac Center Plaza location (550 12st SW, Washington, DC 20202).

Assumptions

1. The Department’s current file storage is Microsoft Windows File Servers or CIFS NAS devices.

2. The same folder structure and permissions will to be maintained as data is migrated to the Archive Storage System.

3. Data that make up the targeted user home and team share drives are currently stored in the two Dell Solutions Federal Government (DSFG) data centers, the UCP building in Washington, DC, and on the Regional Office local file servers.

4. The Department Project Manager will serve as the primary coordinator between the OEM storage vendor, the Storage System Administrator and the Department’s primary services contractor.

5. The Department will provide all resources and information required for successful installation of the Archive Storage System by the OEM vendor, with the exception of the four multimode OM4 fiber cables needed for the 10 GBE SFP network connectivity. Those cables have been requested from the primary support contractor as the needed lengths are currently unknown.

6. The Department and its subcontractors will be responsible for obtaining Enterprise Architecture Review Board approval for the installation, as required.

Constraints

1. Security Clearance: Personnel supporting this Contract shall not process classified information, but will require a High Risk Public Trust (6c) clearance to support the project.

2. Conduct of Contractor Personnel: If the Contracting Officer finds it to be in the best interest of the Government he/she may at any time during the performance of this contract order the Contractor to remove any personnel from further performance under this contract for reasons of their moral character, unethical conduct, security reasons, or for violation of installation regulations. In the event that it becomes necessary to replace any Contractor personnel for any of the above reasons, the Contractor shall bear all costs associated with such removal, including the costs for the replacement of any personnel so removed. These costs shall not be chargeable to the Government.

FISMA Requirements The Contractor, and all Subcontractors, shall comply with the Department’s IT security policy requirements, specifically those set forth in the ‘Handbook for Information Assurance Security Policy (OCIO-01)’, and other applicable procedures and guidance. The Contractor, and all Subcontractors, shall develop and implement management, operational and technical security controls to assure required levels of protection for information systems. The Contractor, and all Subcontractors, shall further comply with all applicable Federal IT security requirements including, but not limited to, the Federal Information Security Management Act (FISMA) of 2002, Office of Management and Budget (OMB) Circular A-130 Appendix III, Homeland Security Presidential Directives (HSPD), and the National Institute of Standards and Technology (NIST) standards and guidance.

These security requirements include, but are not limited to, the successful Certification and Accreditation (C&A) or Security Authorization (SA) of the system (includes commercially owned and operated systems managed by the commercial vendor and its Subcontractors, supporting Department programs, contracts, and projects); obtaining a full Authority to Operate (ATO) before being granted operational status; performance of annual self-assessments of security controls; annual Contingency Plan testing; performance of periodic vulnerability scans; updating all information system security documentation as changes occur; and other continuous monitoring activities, which may include, mapping, penetration and other intrusive scanning. Full and unfettered access for the Department’s third party Managed Security Services Provider (MSSP)[footnoteRef:2] must be granted to access all computers and networks used for this system. Additionally, when there is a significant change to the system’s security posture, the system (Federal and commercial - prime and Subcontractors included) must have a new C&A or SA, with all required activities to obtain a new ATO, signed by the Authorizing Official (AO). [2: ]

System security controls shall be designed and implemented consistent with NIST SP 800-53 Rev 4, ‘Recommended Security Controls for Federal Information Systems and Organizations.’ All NIST SP 800‐53 controls must be tested / assessed no less than every 3 years, according to Federal and Department policy. The risk impact level of the system will be determined via the completion of the Department's inventory form and shall meet the accurate depiction of security categorization as outlined in Federal Information Publishing Standards (FIPS) 199, ‘Standards for Security Categorization of Federal Information and Information Systems.’

System security documentation shall be developed to record and support the implementation of the security controls for the system. This documentation shall be maintained for the life of the system, published to and available within the Department’s system of record for FISMA reporting. The Contractor, and all Subcontractors, shall review and update the system security documentation at least annually and after significant changes to the system, to ensure the relevance and accurate depiction of the implemented system controls and to reflect changes to the system and its environment of operation. Security documentation must be developed in accordance with the NIST 800 series and the Department’s policy and guidance.

The Contractor, and all Subcontractors, shall allow Department employees (or Department designated third party Contractors) access to the hosting facility to conduct C&A/SA activities to include control reviews in accordance with NIST SP 800‐53, Rev. 4 and NIST SP 800‐53A. The Contractor, and all Subcontractors, shall be available for interviews and demonstrations of security control compliance to support the C&A/SA process and continuous monitoring of system security. In addition, if the system is rated as ‘Moderate’ or ‘High’ for FIPS 199 risk impact, vulnerability scanning and penetration testing shall be performed on the hosting facility and application as part of the C&A/SA process. Appropriate access agreements will be reviewed and signed before any scanning or testing occurs.

Identified deficiencies between required NIST SP 800‐53 Rev. 4 controls and the Contractor’s, and all Subcontractor’s implementation, as documented in the Risk Assessment Report, System Security Plan (SSP) and Security Assessment Report (SAR), shall be tracked for mitigation through the development of a Plan of Action and Milestones (POA&M) in accordance with the ‘Handbook for Information Assurance Security Policy.’ Depending on the severity of the deficiencies, the Department may require remediation before an ATO is issued.

All awarded IT contracts shall ensure that:

1. Their IT product/system is monitored during all hours of operations using entrusted detection/prevention systems;

2. Their IT product/system has current antiviral products installed and operational;

3. Their IT product/system is scanned on a reoccurring basis;

4. Vulnerabilities are remediated in a timely manner on their IT product/system; and

5. Access/view for cybersecurity situational awareness on their IT product/system is made available to the Department’s Cyber Incident Response Capability (CIRC).

Compliance with ED IT Security Policy The Contractor, and all Subcontractors, shall comply with the Department’s IT security policy requirements, specifically those set forth in the ‘Handbook for Information Assurance Security Policy (OCIO-01)’, and other applicable procedures and guidance. The Contractor, and all Subcontractors, shall develop and implement management, operational and technical security controls to assure required levels of protection for information systems. The Contractor, and all Subcontractors, shall further comply with all applicable Federal IT security requirements including, but not limited to, the Federal Information Security Management Act (FISMA) of 2002, Office of Management and Budget (OMB) Circular A-130 Appendix III, Homeland Security Presidential Directives (HSPD), the National Institute of Standards and Technology (NIST) standards and guidance, and the Federal Risk and Authorization Management Program (FedRAMP) requirements and guidance.

These security requirements include, but are not limited to, the successful Security Authorization (SA) of the system (includes commercially owned and operated systems managed by the commercial vendor and its Subcontractors, supporting Department programs, contracts, and projects); obtaining a full Authority to Operate (ATO) before being granted operational status; performance of annual self-assessments of security controls; annual Contingency Plan testing; performance of periodic vulnerability scans; updating all information system security documentation as changes occur; and other continuous monitoring activities, which may include, mapping, penetration and other intrusive scanning. Full and unfettered access for the Department’s third party Managed Security Services Provider (MSSP) must be granted to access all computers and networks used for this system. Additionally, when there is a significant change to the system’s security posture, the system (Federal and commercial prime- and sub- contractors included) must have a new SA, with all required activities to obtain a new ATO, signed by the Authorizing Official (AO).

In accord with OMB Memorandums M-05-04, and M-15-13, and M-08-23, and with the NIST SP 800-44, all publicly accessible Federal websites and web services must have HTTPS enabled, and shall only provide service over a secure connection, and e-mail applications must have SMTP enabled.

System security controls shall be designed and implemented consistent with NIST SP 800-53 Rev 4, ‘Recommended Security Controls for Federal Information Systems and Organizations.’ All NIST SP 800-53 controls must be tested / assessed no less than every 3 years, according to federal and Department policy. The risk impact level of the system will be determined via the completion of the Department's inventory form and shall meet the accurate depiction of security categorization as outlined in Federal Information Publishing Standards (FIPS) 199, ‘Standards for Security Categorization of Federal Information and Information Systems.’

System security documentation shall be developed to record and support the implementation of the security controls for the system. This documentation shall be maintained for the life of the system. The Contractor, and all Subcontractors, shall review and update the system security documentation at least annually and after significant changes to the system, to ensure the relevance and accurate depiction of the implemented system controls and to reflect changes to the system and its environment of operation. Security documentation must be developed in accordance with the NIST 800 series and the Department’s policy and guidance.

The Contractor, and all Subcontractors, shall allow Department employees (or Department designated third party Contractors) access to the hosting facility to conduct SA activities to include control reviews in accordance with NIST SP 800-53, Rev. 4 and NIST SP 800-53A. The Contractor, and all Subcontractors, shall be available for interviews and demonstrations of security control compliance to support the SA process and continuous monitoring of system security. In addition, if the system is rated as ‘Moderate’ or ‘High’ for FIPS 199 risk impact, vulnerability scanning and penetration testing shall be performed on the hosting facility and application as part of the SA process. Appropriate access agreements will be reviewed and signed before any scanning or testing occurs.

Identified deficiencies between required NIST SP 800-53 Rev. 4 controls and the Contractor’s, and all Subcontractor’s implementation, as documented in the Risk Assessment Report, System Security Plan (SSP) and Security Assessment Report (SAR), shall be tracked for mitigation through the development of a Plan of Action and Milestones (POA&M) in accordance with the ‘Handbook for Information Assurance Security Policy (OCIO-01).’ Depending on the severity of the deficiencies, the Department may require remediation before an ATO is issued.

Internet Protocol version 6 (IPv6) The Contract shall provide COTS solutions that are IPv6 capable. An IPv6 capable system or product shall be capable of receiving, processing, transmitting and forwarding IPv6 packets and/or interfacing with other systems and protocols in a manner similar to that of IPv4. Specific criteria to be deemed IPv6 capable are:

An IPv6 Capable system must meet the IPv6 base requirements defined by the USGv6 Profile and Testing program as found here http://w3.antd.nist.gov/usgv6/testing.html.

Systems being developed, procured or acquired shall maintain interoperability with IPv4 systems/capabilities.

Systems shall implement IPv4/IPv6dual-stack and shall also be built to determine which protocol layer to use depending on the destination host it is attempting to communicate with or establish a socket with.

If either protocol is possible, systems shall employ IPv6.

The Contractor shall provide IPv6 technical support for system development, implementation and management

System Development Standards:

Information systems shall be developed in accordance with the ED Lifecycle Management Framework (LCM), ACS-OCIO 1-106 All awarded contracts shall ensure that:

1. Their IT product/system is monitored during all hours of operations using entrusted detective/preventive systems;

2. Their IT product/system has current antiviral products installed and operational;

3. Their IT product/system is scanned on a reoccurring basis;

4. Vulnerabilities are remediated in a timely manner on their IT product/system; and

5. Access/view for cyber security situational awareness on their IT product/system is made available to the Department CIRC (cyber incident response capability).

Reporting of Data Security Breaches If there is a suspected or known breach/disclosure of PII due to lost, theft, intercepted transfer, or other, the Contractor must ensure that this breach is reported to the agency as soon as the Contractor has knowledge of it. Per Office of Management and Budget Memorandum M-06-19, Federal agencies have a requirement to report breaches of PII security to a Federal incident response center. OCIO must notify the department within 30 minutes of discovering the incident (and the agency should not distinguish between suspected or confirmed breaches). The data security plan must be written to reflect this requirement, and the Contractor must provide sufficient notification and documentation of the suspected loss, as it is understood at the time of notification to the agency for this requirement to be met. Follow-up reports of the final status of loss events will also be prepared by the Contractor within a reasonable period of time as advised by the OCIO COR.

ED Project Manager Justin Morgan Potomac Center Plaza 550 12th Street, Room 9105 Washington, DC 20024 Work: 202-245-7382 Cell: 202-568-1074 Justin.Morgan@ed.gov Archive Storage System Facility Housing – PWS 11 image1.png

File details come from the government source that posted it. Updated .