Attachment_2_-_SOO_SW_DevSecOps.pdf

PDF 31 KB Posted

Attached to
Software DevSecOps Services Blanket Purchase Agreement Federal contract opportunity
Solicitation number
fa8307-19-R-0133
Issued by
Department of the Air Force Materiel Command Lifecycle Management Center Hanscom Air Force Base

About this file

BPA ATTACHMENT 2 - SOO SW DEVSECOPS

View the file

Other files for this federal contract opportunity

Other files attached to Software DevSecOps Services Blanket Purchase Agreement, newest first.
File Type Posted
Attachment_1_-_ITO_SW_DevSecOps_9Oct19.pdf PDF
Revised_Provisions_and_Clauses_-_DevSecOps.docx DOCX document
Amendment_5_-_SW_DevSecOps_(133).pdf PDF
BOA_RFQ_Cover_Letter_-_SW_DevSecOps_9Oct19.pdf PDF
FA830719R0133.pdf PDF
LevelUP_AMA_03Oct19.pdf PDF
Attachment_4_-Q&A_AMA_3Oct2019.pdf PDF
Attachment_4_-Q&A_AMA_25Sep2019.pdf PDF
LevelUP_AMA_25Sep19.pdf PDF
BPA_RFQ_Cover_Letter_-_SW_DevSecOps_clean.pdf PDF
Attachment_1_-_ITO_SW_DevSecOps_clean.pdf PDF
Attachment_4_-_Q&A_DevSecOps.pdf PDF
BPA_Guide_SW_DevSecOps_v2_tracked.pdf PDF
BPA_RFQ_Cover_Letter_-_SW_DevSecOps_tracked.pdf PDF
Amendment_3_-_SW_DevSecOps_(133).pdf PDF
FA830719R0133_-_SW_DEVSECOPS.pdf PDF
Attachment_1_-_ITO_SW_DevSecOps_tracked.pdf PDF
AMA_QA_Report_(9.25.19).pdf PDF
Attachment_E_-_Sample_DD254.pdf PDF
Attachment_G_-_Labor_Category_LevelUP.pdf PDF
Attachment_D_-_On_Off_Ramp_Procedures.pdf PDF
Attachment_5_-_BPA_Guide_SW_DevSecOps.pdf PDF
Attachment_6_-Provisions_and_Clauses_-_SW_DevSecOps.pdf PDF
BPA_RFQ_Cover_Letter_-_SW_DevSecOps.pdf PDF
Attachment_1_-_ITO_SW_DevSecOps.pdf PDF
Attachment_4_-_Q&A_Template.docx DOCX document
Attachment_F_-_Key_Personnel_Information.pdf PDF
Attachment_3_-_Pricing_Sheet.xlsx XLSX spreadsheet
Show all 28

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

FA8307-19-R-0133

Attachment A

13 September 2019

Statement of Objectives - Software DevSecOps Services

The contractor shall support LevelUP and LevelUP pathfinder product development through technical services of full-stack DevSecOps engineers, Cloud engineers, infrastructure engineers, and other key personnel. This includes but is not limited to software engineers, programmers, architects, Cloud architects, and developers that support the Government in constructing a secure, reliable, resilient, and assured set of software applications on the supporting Government and commercial tools and platforms.

The contractor may also be required to assist in virtualizing and/or containerizing existing applications onto the cloud platform.

In addition, the offeror shall propose their strategy to build and operate multi-tenant shared services that support software development teams, such as event streams, databases, data analytics, message queues, storage, and logging.

The contractor shall implement agile principles and lean startup practices to employ continuous delivery and instill a team dynamic that responds well to change. The contractor may work with various Government and commercial tools and platforms such as, but not limited to, CNCF compliant Kubernetes distributions, Istio, KNative, Openshift, and VMware products. The contractor may embed with engineers (product dependent) to familiarize themselves with LevelUP at locations to include: San Antonio, TX, Colorado Springs, CO, and Odgen, UT as well as other locations specified at a later date.

The Software DevSecOps BPA is structured to support platform development teams, platform & product onboarding teams, product development teams (applications), site reliability engineers, cybersecurity teams, and information technology support & operations.

For all teams, the contractor must provide qualified manpower within ten (10) business days of Government request or of a vacancy. If a key personnel position is identified at the call level, the contractor shall minimize the operational burden.

The contractor shall follow the guidance provided by the DoD Enterprise DevSecOps initiative.

The contractor shall provide support to platform development teams in the following area(s):

• Ensure platform environments on multiple networks and classifications are stable, reliable, and available.

• All work must follow infrastructure as code best practices.

• Propose and implement solutions for developing, operating, and maintaining the LevelUP or

LevelUP pathfinder platform, regardless of underlying infrastructure.

• Hardening of containers following DoD best practices.

• Develop and maintain required automation and tooling to quickly deploy and manage applications.

• Oversee operational maturity of services through automated flows, streamlined planned changes, and proactively ensuring reliability.

• Utilize commercial best practices in agile and DevSecOps (CI/CD) software development.

The primary place of performance for the platform development teams is currently in Colorado Springs, Colorado; however, may be subject to change.

The contractor shall provide support to platform & product onboarding teams in the following area(s):

• Ensure external Government & Government contractor teams can onboard platform & product teams to the LevelUP platform ensuring platform environments on multiple networks are stable, reliable, and available. Please note: this does not require initiating or managing Government led agreements or contracts.

• Hardening of containers following DoD best practices.

• Develop and maintain required automation and tooling to quickly deploy and manage applications.

• Propose and implement solutions for onboarding external Government and Government contractor teams products and platforms.

• Utilize commercial best practices in agile and DevSecOps (CI/CD) software development.

The primary place of performance will be dependent on external Government and Government contractor teams products and the location is expected to vary.

The contractor shall provide support to product development teams in the following areas:

• Ensure all new development will adhere to authority to operate (ATO), continuous authority to operate (C-ATO) or other approved Government authorization official requirements.

• Work-off prioritized story points as directed by the product owner.

• Develop secure and reliable and resilient set of software applications whether refactoring or re-hosting existing applications or developing new applications.

• Develop and maintain required automation and tooling to quickly deploy and manage applications.

• Utilize commercial best practices in agile and DevSecOps (CI/CD) software development.

The primary place of performance will be dependent on external Government and Government contractor teams products and the location is expected to vary.

The contractor shall provide support to cybersecurity teams in the following areas:

• Analyze the security of LevelUP or LevelUP pathfinder applications and services and release and deployment pipelines.

• Discover and address security issues, build security automation and quickly react to new threats.

• Provide a robust security strategy that emphasizes ability to perform design and code reviews and security-related tasks that mitigate risks.

• Keep up with Kubernetes cybersecurity threats and best practices to harden and secure

Kubernetes clusters at scale.

• Demonstrate working with product developers to drive toward a solution that enables developers to operate quickly while maintaining compliance with LevelUP’s or LevelUP pathfinder’s C-

ATO.

• Ability to perform cyber penetration analysis (pen-testing) and red teaming/blue teaming.

The contractor shall provide support to information technology support & operations in the following areas:

• Ensure platform and network environments are compliant with the DoD Enterprise DevSecOps guidance, automated, stable, reliable, and available.

• Support required automation and tooling to quickly deploy and manage applications.

• Support a 24 hour operations and/or business hour (0830-1630) help desk.

Descriptions:

Continuous Integration/Continuous Delivery (CI/CD) Pipeline: Continuous integration establishes a consistent and automated way to build, package, and test applications. Continuous delivery automates the delivery of applications to selected infrastructure environments.

Platform development teams: develops and maintains the CI/CD pipeline as well as platform environment compliant with the CNCF requirements for Kubernetes such as Kubernetes upstream, D2IQ Kubernetes, Openshift, VMWare PKS Essentials, etc. They ensure a modern and secure foundation upon which all product teams develop and deploy containerized applications to. The majority of the platform engineering team should be co-located.

Platform and product onboarding teams: Supports platform and product teams from multiple Government and Government contractor organizations onboard from a technical and operational perspective onto a LevelUP or LevelUP pathfinder platform. Following onboarding, the team provides continued support as required. This may require long-term onsite support.

Product development teams: Develop secure and reliable and resilient set of software applications whether refactoring or re-hosting existing applications or developing new applications at the Government’s request.

Cybersecurity teams: Discover and address security issues, build security automation and quickly react to new threats.

Information technology support & Operations teams: Provides technical and operational support to ensure LevelUP’s or a LevelUP pathfinder’s systems are secure, reliable, and resilient.

File details come from the government source that posted it.