RFP_Attachment_4.M_-_CCE_Services_Description_V4.1_MAR_2019.pdf

PDF 1 MB Posted

Attached to
Request for Proposal (RFP) Item Master Logistics Capability Initiative (IMLCI) Federal contract opportunity
Solicitation number
FA8770-20-R-0004
Issued by
Department of the Air Force Materiel Command Lifecycle Management Center Maxwell Air Force Base

About this file

This document describes common cloud computing services available through the United States Air Force Cloud Computing Environment version 2.0 program. The CCE 2.0 provides a set of core services to mission applications including automated deployment pipelines, identity and access management, enterprise integration, email services, collaboration tools, continuous improvement processes, environment provisioning in AWS or Azure, integration with the Cyber Security Service Provider, automated security and vulnerability management, compliance and accreditation support. These services are available to applications hosted within CCE 2.0 accounts and are managed by the core CCE team to provide standardized, secure capabilities without requiring customization by application owners. The document outlines the key services available in each of these categories to streamline application migration, operations and security within the CCE 2.0 environment.

Attachment 4.M - CCE Services Description V4.1 MAR 2019

View the file

Other files for this federal contract opportunity

Other files attached to Request for Proposal (RFP) Item Master Logistics Capability Initiative (IMLCI), newest first.
File Type Posted
Questions and Answers - 5 Dec 19.pdf PDF
Questions and Answers - 26 Nov 19.pdf PDF
Questions and Answers - 20 Nov 19.pdf PDF
Questions and Answers - 14 Nov 19.pdf PDF
Questions_and_Answers_-_4_Nov_19.pdf PDF
Questions_and_Answers_-_22_Oct_19.pdf PDF
RFP_Attachment_04_-_Technical_Data_Package_(TDP)_Base_Document.docx DOCX document
RFP_Attachment_11_-_TEP_Workbook_v.2.xlsx XLSX spreadsheet
Questions_and_Answers_-_21_Oct_19.pdf PDF
Questions_and_Answers_-_17_Oct_19.pdf PDF
Questions_and_Answers_-_16_Oct_19.pdf PDF
Questions_and_Answers_-_15_Oct_19.pdf PDF
RFP_Attachment_5_-_Section_L_-_Instructions,_Conditions,_and_Notices_to_Offerors_or_Respondents.pdf PDF
RFP_Attachment_4.B_-_ManageItemMaster.pdf PDF
RFP_Attachment_4.D_-_AssignManagementInformationToIM_ARLineItem.pdf PDF
RFP_Attachment_10_-_SOO-CLIN_Matrix.xlsx XLSX spreadsheet
RFP_Attachment_2_-_ITFR_Capability_Assertion_List.xlsx XLSX spreadsheet
RFP_Attachment_4.K_-_TermsDefinitionsAcronyms.docx DOCX document
RFP_Attachment_4.F_-_ExecuteProvisioning.pdf PDF
RFP_Attachment_6_-_Section_M_-_Evaluation_Factors_for_Award.pdf PDF
RFP_Attachment_9_-_Quality_Assurance_Surveillance_Plan_(QASP).pdf PDF
RFP_Attachment_4.L_-_Interface_Information.docx DOCX document
RFP_Attachment_1_-_Statement_of_Objectives_(SOO).pdf PDF
RFP_Attachment_4.H_-_Activities.xlsx XLSX spreadsheet
RFP_Attachment_4.J_-_DataReferenceModel.xlsx XLSX spreadsheet
RFP_Attachment_12_-_Basic_IDIQ_Model_Contract.pdf PDF
RFP_Attachment_8_-_Product_Eval_Supplement.xlsx XLSX spreadsheet
RFP_Attachment_3_-_Requirements_List.xlsx XLSX spreadsheet
RFP_Attachment_4.C_-_ManageItemMasterAssistanceRequest.pdf PDF
RFP_Attachment_11_-_TEP_Workbook.xlsx XLSX spreadsheet
RFP_Attachment_4.E_-_ManageFederalCatalogAction.pdf PDF
RFP_Attachment_4.A_-_IMLCI101Brief.pptx PPTX presentation
RFP_Attachment_4.I_-_InformationAssets.xlsx XLSX spreadsheet
RFP_Attachment_7_-_Contract_Data_Requirements_List_(CDRL).pdf PDF
RFP_Attachment_4.G_-_ProcessNames.xlsx XLSX spreadsheet
Show all 35

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

Rob Gordon

11/26/2018

Version 3

USAF CCE 2.0 Service Overview

Distribution A. Approved For Public Release

2USAF CCE

CCE 2.0 Provided Core Services

The CCE 2.0 Provides a set of common services that allow mission applications to harness the power of the Cloud. These services provide benefits at all phases of the application lifecycle and include the following capabilities:

• Automated Deploy Pipeline

• Identity / Access Management

• Enterprise Integration Services

• SMTP & Relay Services

• Collaboration & Support Services

• Continuing Improvement

• Environment Provisioning

• CSSP Integration

• Automated Security & Vulnerability management Services

• Compliance & Accreditation Support

3USAF CCE

CCE 2.0: Environment Provisioning

The CCE 2.0 provides mission applications with an set of operational environments in either the AWS or Azure clouds. These environments are owned and operated by the Mission Application team , but CCE provides a set of value-added services from the onset

Services Provided

• Integration, Test, and Production Environment Provisioning (AWS and Azure). Environments are 100% isolated at both the environment and mission application level

• Built in default security groups, networking configuration, and ingress/egress management that allow for ATO compliance inheritance

• Admin user management, including role-based user access and 2875 processing

• Environments come pre-integrated with other common services (deployment pipeline, compliance tooling, security scanning services)

• Access to cloud migration specialists, reusable scripts & components, and support for common services

4USAF CCE

CSSP Integration

In addition to providing access to cloud compute resources, all CCE 2.0 accounts come pre-configured with Cyber Security Service Provider (CSSP) integration through Army Research Lab (ARL) – ensuring that CCE 2 operational environments are properly protected.

Services Provided

• Automated networking log streaming to CSSP for all CCE hosted mission applications

• Capability provided without the need for any mission application action.

Service is applied consistently across all accounts in a 100% automated manner.

• Capability fully supports the elastic model inherent to cloud architecture. Resources that are added as a result of auto-scaling events are automatically sent to ARL

5USAF CCE

Automated Security & Vulnerability Management Services

All CCE 2 hosted environments receive access to a suite of common security tools and capabilities

Services Provided

• Vulnerability scanning – both on-demand (centrally managed ACAS) and continuous leveraging CSP-provided offerings (AWS Inspector, Azure Security Center)

• Boundary Protection and Web Application Firewall (WAF) provided via Akamai GCDS common service – supplemented by CSP-provided capabilities (AWS GuardDuty, Azure Security Center)

• Anti-Virus, Anti-Malware, Anti-Ransomware for all CCE hosted resources (Trend Deep Security)

• Host-based Intrusion Protection, file integrity monitoring, and Log monitoring (Trend Deep Security)

• Automated reporting on hardware/software inventory, patch compliance status, and O/S + software versioning (Trend Deep Security)

• All of the above capabilities are provided by CCE 2, but it is the responsibility of the Mission Application owner to configure the tools so that they are tailored to their specific needs. CCE provides & maintains sample configuration scripts to aid in this process.

6USAF CCE

CCE 2.0: Compliance & Accreditation Services

The CCE 2.0 provides a host of services that accelerate the accreditation process and ensure continuing compliance with security controls

Accreditation Services

• Inherit controls from CSPs in both AWS and Azure at IL-4 and IL-5 level

• Inherit controls from ATO’ed CCE enclave

• Leverage Xacta 360 and EMASS tools for managing and reporting on control inheritance

• CCE provided ACAS scanning for all hosted applications

• CCE provides reference library of pre-hardened platform configurations

Real-Time Compliance

• Trend deep security provides real-time monitoring / alerting of system status, as well as real-time notification of changes

• CSP Capabilities (Inspector, OMS, Cloudwatch) provide additional cloud-native compliance monitoring and alerting services.

• CCE applications provide centralized, real-time system log access to IA/compliance as well as Xacta

• Mission applications are responsible for configuring compliance tooling leveraging the provided tools.

Samples and reference documentation are provided by the CCE team to streamline the process

7USAF CCE

CCE 2.0: Automated Deployment Pipeline

The CCE 2 provides a fully automated, secure, and auditable deployment pipeline that accommodates both application and infrastructure deployments.

Artifact Management Services

• Centralized, secure, encrypted artifact management repository (Artifactory)

• Artifact vulnerability and virus scanning (Xray)

• Artifact version control and roll-back support

• User/Account management, CAC-based Federated

MFA

• Fully managed service with redundant storage, high availability, patching/updates, and operational monitoring.

Automated Deployment Tools & Services

• Deployment tools pre-configured in CCE environment (Jenkins, TFS) and managed by CCE team

• Pre-built integration between Artifactory and deployment tools

• All Deployments are 100% auditable

• Deployment of Application artifacts as well as Infrastructure as Code (IaC)

8USAF CCE

CCE 2.0: Identity / Access Management

The CCE 2 provides a comprehensive set of user identity management services that streamline and secure both administrator and end-user access to environments

Administrator IAM Services

• CAC authenticated, browser-based access to system resources via Apache Guacamole

• Role-based Access control to system resources via Active Directory

• Federated access to system resources, cloud management consoles, and CCE tooling via ADFS

• Centralized administrator access management / onboarding.

End User / Customer IAM Services

• Integration with Akamai’s GCDS services for CAC-based end user access to CCE hosted applications (SCCA Compliant CAP/VDSS)

• Federated SAML endpoint (GCDS)

• Legacy TAM replicated Header injection to support TAM-dependent applications

9USAF CCE

CCE 2.0: Enterprise Integration Services (ESB Adapter)

* Custom integrations require support/participation from mission application owner(s) and are subject to CCE review for feasibility/prioritization

The CCE 2 provides common services to support many common enterprise integration patterns

Enterprise Integration Services

• Secure File based data exchange between CCE hosted applications and external systems via AWS S3, Azure Blob Storage, and JBoss Fuse MM

• Secure Message based data exchange between CCE applications and external systems leveraging Azure Queues, AWS SQS, and JBoss Fuse MM

• CCE ESB team performs translation from SFTP, JMS, MQ to cloud native APIs as a common service

• CCE ESB team handles routing and bi-directional messaging between on-prem and CCE hosted systems

• Support for custom integrations as required by migrating applications*

10USAF CCE

CCE 2.0: SMTP & Relay Services

The CCE 2 leverages the existing USAF Office 365 solution to provide SMTP capability for hosted applications that require the ability to send emails

Services Offered

• SMTP Email server & relay services – accredited for use by IL-4 and IL-5 mission applications

• Support for both AWS and Azure Mission Applications

11USAF CCE

CCE 2.0: Collaboration & Support Services

The CCE 2 provides collaboration and support services streamline the application migration process.

Collaboration Services

• Web-based knowledge base content supporting mission app owners and application migration vendors (Confluence)

• Agile tooling to manage task completion, defect resolution, and over-all program health and status

(JIRA)

• Access to CCE 2 environment & migration experts for advice on best practices, recommended architecture, and effective operations.

Support Services

• Library of templates and scripts that have been pre-hardened and proven to work on the CCE 2 environment

• Reference Documentation on CCE supported cloud services, support FAQs, and best practices

• Support Help Desk for incident management of common services

• All Common services are continually updated, patched, secured, and monitored by the core team

12USAF CCE

CCE 2.0: Continuing Improvement

Because the CCE 2 is a continuously evolving program, we are constantly identifying opportunities to provide more capabilities and better service to our customers.

Service Expansion Roadmap

• Open Forums for CCE application stakeholders to request feature improvements and new service offerings

• Prioritized strategic roadmap that identifies new service candidates and maps them to a future-state roadmap.

• Strong partnerships with Partnering with CSP partners (AWS and MS Azure) to accelerate the availability of key service offerings in GovCloud

File details come from the government source that posted it. Updated .