FCHS2_Section_C_Statement_of_Work.pdf

PDF 360 KB Posted

Attached to
DOI Foundation Cloud Hosting Services (FCHS2) Federal contract opportunity
Solicitation number
140D0423R0002
Issued by
Department of the Interior Departmental Offices Interior Business Center

View the file

Other files for this federal contract opportunity

Other files attached to DOI Foundation Cloud Hosting Services (FCHS2), newest first.
File Type Posted
Sol_140D0423R0002_Amd_0008.pdf PDF
FCHS2_Section_J_Attachment_9_Question_and_Answer_Amd_0008_0008.pdf PDF
Sol_140D0423R0002_Amd_0007.pdf PDF
Sol_140D0423R0002_Amd_0006.pdf PDF
140D0423R0002_0006_0006.pdf PDF
Sol_140D0423R0002_Amd_0005.pdf PDF
Sol_140D0423R0002_Amd_0004.pdf PDF
FCHS2_Section_J_Attachment_07a_Usage_Summary_of_June_2023_Cloud_Services_Amd0003_0003.xlsx XLSX spreadsheet
Amendment_0003_Q_A__Consolidation_Sections_0003.pdf PDF
FCHS2_Section_J_Attachment_07b_Example_Invoice_Template_Amd0003_0003.xlsx XLSX spreadsheet
Sol_140D0423R0002_Amd_0003.pdf PDF
FCHS2_Section_J_Attachment_9_Question_and_Answer_Template_Amd0002_0002.xlsx XLSX spreadsheet
FCHS2_Section_J_Attachment_8_IDIQ_Pricing_Template_Amd0002_0002.xlsx XLSX spreadsheet
FCHS2_Section_J_Attachment_4_Subcontracting_Plan_Template_Amd0002_0002.pdf PDF
RFP_140D0423R0002_Amd0002_0002.pdf PDF
FCHS2_Section_J_Attachment_05_Day_One_BIA_EUMS_Amd0002_0002.pdf PDF
FCHS2_Section_J_Attachment_3_Past_Performance_Questionnaire_Amd0002_0002.pdf PDF
FCHS2_Section_J_Attachment_07_Day_One_USDA_DISC_Amd0002_0002.pdf PDF
FCHS2_Section_J_Attachment_2_OCIO-PAM_Memo_DOI_IT_Baseline_Compliance_Contract_Guidelines_0002.pdf PDF
FCHS2_Section_J_Attachment_06_Day_One_OCIO_GeoPlatform_Amd0002_0002.pdf PDF
FCHS2_Section_J_Attachment_01_Security_Objectives_Service_Level_Agreements_Amd0002_0002.docx DOCX document
Sol_140D0423R0002_Amd_0002.pdf PDF
FCHS2_Section_J_Attachment_0-Amd_0001_0001.pdf PDF
FCHS2_Section_J_Attachment_10-Question_and_Answer_Template_0001.xlsx XLSX spreadsheet
Sol_140D0423R0002_Amd_0001.pdf PDF
FCHS2_Section_L_Instructions__Conditions__Notices.pdf PDF
FCHS2_Section_J_Attachment_7_Day_One_NPS_Volunteer.pdf PDF
FCHS2_Section_J_Attachment_3_Past_Performance_Questionnaire.pdf PDF
FCHS2_Section_J_Attachment_0.pdf PDF
FCHS2_Section_I_Contract_Clauses.pdf PDF
FCHS2_Section_G_Contract_Administration_Data.pdf PDF
FCHS2_Section_K_Representations__Certifications__and_Other_Statements_of_Offeror.pdf PDF
FCHS2_Section_B_Supplies__Services_and_Costs.pdf PDF
FCHS2_Section_J_Attachment_8_Day_One_OCIO_GeoPlatform.pdf PDF
FCHS2_Section_J_Attachment_6_Day_One_NPS_CLP.pdf PDF
FCHS2_Section_J_Attachment_5_Day_One_BIA_EUMS.pdf PDF
FCHS2_Section_M_Evaluation_Factor_for_Award.pdf PDF
FCHS2_Section_J_Attachment_4_Subcontracting_Plan_Template.pdf PDF
FCHS2_Section_E_Inspection_and_Acceptance.pdf PDF
Sol_140D0423R0002.pdf PDF
FCHS2_Section_F_Deliverables_or_Performance.pdf PDF
FCHS2_Section_J_Attachment_9_Day_One_USDA_DISC.pdf PDF
FCHS2_Section_J_Attachment_2_OCIO-PAM_Memo_DOI_IT_Baseline_Compliance_Contract_Guidelines.pdf PDF
FCHS2_Section_J_Attachment_1_Security_Objectives_-_Service_Level_Agreements.pdf PDF
FCHS2_Section_H_Special_Contract_Requirements.pdf PDF
FCHS2_Section_D_Packaging_and_Marketing.pdf PDF
Show all 46

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

Foundation Cloud Hosting Services II (FCHS2) Section C

C-1

SECTION C – STATEMENT OF WORK REQUIREMENTS

C.1 Overview This Statement of Work describes the requirements under the Department of the Interior (DOI/Department/Agency) ten-year Government-wide multi-award, Indefinite Delivery Indefinite Quantity (IDIQ) delivery order contract per the Federal Acquisition Regulation (FAR) section 16.504(a) (48 CFR 16.504). The Department requires cloud license and support services as described this Statement of Work (SOW) for Infrastructure, Platform, Software, and other as a Service cloud environment. This SOW describes the Departments next generation contract vehicle requirements called FCHS2.

The Department has learned a great deal in the ten years of our first FCHS contract, and the industry has dramatically matured in their cloud service offerings. The first contract was focused on single large IT Systems prepared for cloud migration. These early “Cloud First” adoptions provided opportunity to initiate single agency-wide enterprise solutions. This follow-on FCHS contract is shifting to multiple service provider focus and integration among our solutions and a hybrid model hosting environment vision. Providing interoperability and data integrations between multiple technologies and services across the Department bureaus and offices. The Department is seeking a small cadre of single integrators with vast resources to innovate our business processes and enable solutions across multiple platforms.

C.1.1 Background The Department of the Interior began the initial FCHS contract ten years ago to launch the cloud adoption movement. The Department offered assisted acquisition services government wide to foster agency enterprise environments. Cloud migrations grew by 50% annually and today’s FCHS landscape supports several multi-agency environments.

Since 2013, the Department has provided assisted acquisition services by technical service lines to federal agencies in accordance with the Government Management and Reform Act (GMRA) of 1994. The Department has been managing these services aligned with the Federal Cloud Computing Strategy. The FCHS2 next generation requirements are similar and require expertise in cloud services based on the requirements and objectives below.

C.1.2 Current Cloud Service Offering (CSO) Investments Over time the Department and other Agencies cloud computing has increased Cloud Service Offerings (CSO) exponentially. Over the last decade cloud adoption has increased remarkedly and over the last couple years has exploded as work went virtual and agencies adapted to remote work. Ever more present is the need to connect current CSO’s with autonomous internet of things (IoT) infrastructure and access with ultra-fast networks and augmented or virtual reality devices.

Behind the expanding cloud smart adoption is a paralleled initiative to replace legacy and local area network applications to virtual enterprise solutions to consolidate, optimize, and close physical data centers. Going forward, the biggest CSO increase will be in the emerging FedRAMP SaaS and Government community collaboration opportunities that meet an increasing driver of sustainability in cloud innovation.

https://cloud.cio.gov/strategy/ https://cloud.cio.gov/strategy/

C-2

C.1.3 Current Environment The Department is a federal executive department, established in 1849 and responsible for the administration of lands, minerals, and other resources of the United States. The Departments mission is protecting and managing the nation’s natural resources and cultural heritage for the benefit of the American people; providing scientific information about those resources and natural hazards; and exercising the nation’s trust responsibilities and special commitments to American Indians, Alaska Natives, and island territories under U.S. administration.

The Department oversees 420 million acres of federal lands, nearly 55 million acres of tribal lands, more than 700 million acres of subsurface minerals, and about 2.5 billion acres of the outer continental shelf. To resource this mission, the Department averages 63,000 employees throughout 11 Bureaus and 30+ Offices and Programs.

C.1.4 Government Wide FCHS2 is Government wide and extends all requirements within this statement of work to other Federal and Government agencies. The Department objective is seeking Contractors, who have demonstrated results as being an industry innovator. One that continues to leverage security, interoperability, portability, reliability, and resiliency. Stepping up as leaders in the adoption of automation and artificial intelligence to partner with multiples of agencies. Offering cloud services already poised to exceed the toughest cyber security initiatives, including IPv6, quantum computing, and initiating trusted internet connectivity in hybrid cloud environment. Offering

C-3 ingenuity technology solutions that navigate the intensifying impacts of climate change and supply chain disruptions.

To begin this journey, the Department is identifying today’s existing and commonly requested cloud service offerings and associated support services in Table 1 below. The Federal Government is seeking and prioritizing FedRAMP authorized (or ready) cloud solutions that align IT strategies with enterprise business objectives. Department Chief Information Officers require transparent, inclusive, agile, and systematic approaches to IT strategy development to meet ever-changing mission needs. The Department is seeking Contractor solutions that

• Reflect all IT and digital efforts across Agency’s enterprises and to be a shared effort for the respective Lines of Business (LOB),

• Lay the groundwork to prepare, develop, and bring together diverse Agency stakeholders,

• Employ a Human-Centered Design (HCD) systematic and agile approach to migrate legacy into state-of-the-art and integrated enterprise environments,

• Provide partnership support from start of strategy throughout lifecycle and decommissioning.

C.1.5 Current Operational Constraints – Adoption Barriers The Department requires support to reduce the gap of current cloud adoption barriers. DOI identifies two leading constraints that challenge a larger scale of cloud adoption and migration, specifically:

1) Enterprise Cloud Hosting Environment is listed as a barrier because the Department enterprise cloud environment is not fully matured at the time of this request. The Department is undergoing major modernization initiatives, including implementing zero-trust and Trusted Internet Connection (TIC) 3.0 parameters, maturing a Microsoft Azure AD tenant and Secure Access Service Edge (SASE) to OpenID Connect (OIDC) on Microsoft’s platform authentication, modernizing existing Agency-wide Enterprise hybrid tenants, and improving ingress/egress traffic performance.

2) Geographically Dispersed Employees and Public and adequate performance are challenging because Agency on-premises data centers are sprawled throughout the continental United States, territories, and other countries. Data centers are sometimes located in extreme remote areas, yet employees need access to complete mission, legal, and technical requirements at those geographic locations. Many have limited or no secured, high-speed, bandwidth, as well as federated cloud technical solutions available to migrate legacy applications to the cloud.

C.2 Business Objectives One primary business objective of why this FCHS2 contract is initiated is to harden the resilience of our agencies IT systems. Migrating from on-premises infrastructures to the cloud will improve the ability to react to failures while maintaining functionality. To increase disaster recovery options such as initiating multiples of geo-replications or performing load balancing.

https://www.federalregister.gov/documents/2022/11/14/2022-24569/federal-acquisition-regulation-disclosure-of-greenhouse-gas-emissions-and-climate-related-financial

C-4

To manage a broader range of virtual environment compute services throughout the IT systems life cycle and well before obsolescence.

Cloud service offerings are required for both existing and new cloud-based IT systems.

Licensing and labor services will be sought from both the prime Contractor and their sub-contract plans to help customers meet a wide variety of requirements and contract thresholds.

Agencies are seeking strong and time-tested partnerships between primes and sub-contractors in order to deliver mission facing services among multi-cloud environments, sometimes offered through multiples of resellers.

• Existing cloud systems periodically require task order renewals, migrations, technology refreshes, or integrations from one service offering to another.

• New cloud service requests more often require support or coordination that includes discovery, on-premise server consolidation, data migration into newly provisioned environment, and/or previous cloud decommissioning.

• Several task orders will require some level of affordable and efficient ongoing support services that would be considered level II or II help service support. Agencies require structured and artificial intelligence (AI) software development (DevOps), automated monitoring, and tools that promote the systematic clearing of cyber security vulnerabilities.

• Priority will be given to innovations that offer solutions to existing Department tenants first, not just single solutions, and how agencies can marry the business across multiple investments.

C.2.1 Achieving Net-Zero Business objectives include using cloud service providers with net-zero cloud strategies.

Providers who’ve demonstrated success with net-zero emissions, cutting carbon emissions through power purchase agreements (PPA), renewable energy certificates (RECs), or other renewable energy methodologies. Cloud service centers should plan and implement low-PUE data centers, energy-efficient cooling systems, and power-efficient compute and storage infrastructure. They should preference deployment from pre-built Green IT accelerators to achieve FedRAMP approved net-zero cloud environments.

As stated in the Fourth National Climate Assessment (https://nca2018.globalchange.gov/) and the Intergovernmental Panel on Climate Change (IPCC) Sixth Assessment Report (https://www.ipcc.ch/report/ar6/wg2/), the intensifying impacts of climate change present physical risks, such as increased extreme weather risk leading to supply chain disruptions, and increasing risks to infrastructure, investments, and businesses. The global, rapid shift away from carbon-intensive energy sources and industrial processes towards decarbonized, climate-resilient economies will help to mitigate these risks while also enhancing U.S. competitiveness and economic growth and creating well-paying job opportunities for American workers.

C-5

C.2.2 Attributes Objectives target Federal CIO initiatives including technology modernization, oversight and reform for cloud IT systems that meet the National Institute of Science Technology definition of cloud computing Specialist Publication 800-145. Public Cloud is the most common deployment model, but others could include Private, Community, and Hybrid configurations. More commonly is Agencies requirement to increase hybrid solutions that blur the distinction between public and private cloud instances and offer consistent zero-trust authentication services across multiples of environments.

Cloud computing models shall enable ubiquitous, convenient, on-demand network access to a shared pool of configurable computing resources (e.g., networks, servers, storage, applications, and services) that can be rapidly provisioned and released with minimal management effort or service provider interaction. They shall represent the “Cloud Smart” five essential characteristics, three service models, and four deployment models.

The Department measures services based upon the Cloud Service Offerings ability to demonstrate

1) On-demand self-service capacity and automated triggers and thresholds to minimize manual management.

2) Broad network access through the Continental United States, including Alaska, Hawaii, and US territories.

3) Resource Pooling to serve multiple front-end users and back-end administrators or integrated applications, including delivering and supporting multi-tenant and multi-cloud service offering environments.

4) Rapid elasticity to automatically scale up or down compute, network, and storage provisions, as demands dictate and flex on a recurring basis.

5) Measured and metered services to automatically control and optimize resources, incidents, network health, usage, costs, thresholds, triggers, and integration success tracking to name a few.

6) Rapid recovery and failover in the event of an outage

C.2.3 Services The type of service models required are predominantly Infrastructure as a Service (IaaS), Platform as a Service (PaaS) and Software as a Service (SaaS), but other similar or “... as a Service” models can be included within these requirements. Serverless cloud or “functions-as-a-service” are increasingly sought after. Agencies require Contractors to offer innovations like how to switch to “pay-as-you-go” services while navigating the not so state-of-the-art confines of Federal acquisition limitations.

Individual task orders will identify the service requirements that include cloud licenses, services, or both. SaaS applications are expected to be the fastest growing in numbers, especially among availability within the FedRAMP Marketplace.

https://nvlpubs.nist.gov/nistpubs/Legacy/SP/nistspecialpublication800-145.pdf

C-6

Within the scope of objectives, Department programs may periodically request to sponsor new Cloud Service Offerings to achieve their FedRAMP authorization. Sponsorship may be performed independently from the task order and require license only services or may include the request for Contractor support services such as forming an Assessment and Authorization (A&A) partnership to achieve authorization.

The Department prioritizes new or migrating IT Systems to first seek and join existing enterprise cloud instances as opposed to duplicating and stove piping the same provider into multiple and similarly situated tenants. Contractor proposals should leverage the Department’s priority to enable efficiencies, improve and/or replicate operational standards and security practices, and leveraging hybrid-solutions in existing DOI cloud tenants.

C.2.4 Application and Data Management Services Application Development and Data Management task orders will range from license only to partial or full Contractor application development, instance start up, and ongoing management.

Agencies have multiples of on-premise applications that will seek cloud adoption within the life of this contract. Individual task orders will identify the applications and support specifics of both the current and proposed environments.

Contractor solutions need to offer Federal agencies the capability to meet requirements for equitable access to its public by making data findable, accessible, interoperable, and reusable (FAIR) through the Agencies Enterprise Data Inventory. Contractors should propose and describe how they will:

1) implement basic data management best practices for all hosted systems, including data dictionaries, discovery metadata, and open web services

2) support requirement to manage and modernize Department data integration through emerging architectures such as data mesh,

3) how they will support interoperability through semantic technologies,

4) how they will include data management strategies such data mesh, metadata management strategies data to remain Findable, Accessible, Interoperable and Reusable (FAIR).

Contractors will be required to meet varying levels of technical objectives including, but not limited to:

1) Provide technical advisory services necessary to fully migrate the target applications and services to the cloud.

2) Provide cloud environments (e.g., IaaS, PaaS, etc.) for production, integration, development and sandbox purposes to support the complete systems lifecycle.

3) Provide post-deployment cloud support and/or governance services.

4) Clarify assign responsibility for authorizing individual instances of provisioning IaaS, etc., and for de-provisioning IaaS, etc., when no longer in use.

5) Provide open-standards based technologies whenever possible to provide interoperability.

Specific standards that should/must be utilized include:

a. Open Virtualization Format (OVF) – applicable only to IaaS virtual machines

b. Cloud Data Management Interface (CDMI)

c. Open Cloud Computing Interface (OCCI)

d. other standards as required

C-7

6) Provide additional resources for bandwidth, storage, software licenses, etc. as required supporting the migration beyond the amount normally planned for operations.

7) Provide migration and development operations status including milestones and support or implement specified migration testing plans and related rollback capabilities.

8) Provide backup, recovery and disaster recovery procedures and processes in the cloud environment for the target applications and services [Any other relevant details from existing business continuity plans (BCP).

9) Provide support for data storage tiers as specified within the target applications and services.

10) Provide complete support for prominent security objectives including IPv6, authentication that meets zero-trust parameters, etc. within the cloud environments provided.

C.3 Management Objectives Task orders require Contractor participation in the overall strategies and best value to the customer. Management objectives are to satisfy each task order while participating in structuring an enterprise approach to the Government’s portfolio of cloud services and capabilities.

Above and beyond individual task order specifics, Contractor shall meet no less than quarterly with key Government personnel to respond to management objectives to:

1) Seek and provide options that promote consolidating individual program IT Systems into enterprise solutions to build economies of scale in both management and cost;

2) Promote IT System longevity to obtain a fully realized return on investment by offering innovations to costs, schedule, performance, risk reduction, warranties, contracts and subcontracts, 3rd party vendors, and data management to deliver effective migration and support services;

3) Clearly identify the roles and responsibilities between the Cloud Service Provider, Government administrators, and the customer regarding ownership and management of covered services;

4) Coordinate with Program Management personnel to maintain clear visibility into short and long term expected program costs, schedules, technical performance, risks, and periodic reports throughout the life cycle of IT Systems, well beyond the initial year;

5) Provide meaningful reporting and analytics that provide Agency with up-to-date and comprehensive information regarding technical and management performance.

C.3.1 Business Management Contractors shall provide a past experience and performance of tightly managing deadlines, expedient invoicing/payment processing, quality task order quote preparedness, and conducting recurring customer change management or similar forums.

The Department is seeking Contractors who demonstrate their capacity to manage a large-volume of requests and quickly turn around task order proposals. The contractors should demonstrate highly functioning sales and support team, including hiring, training, and retaining personnel initiatives.

C-8

The Department is seeking Contractors who offer a broad catalog selection of license and support services along with reseller partnerships that would be available to federal agencies through FCHS2. For application development projects, DOI is seeking Contractors who implement a systematic business analysis Human-Centered Design (HCD) process including observation, ideation, prototyping, testing, iteration, and a return-on-investment (ROI) solution.

C.3.2 Establishing Cloud Services Catalogs One of the Cloud Program’s objective is to build cloud service catalog of approved cloud providers with their respective sub-applications and services. Catalog services are selected because they meet a “mission-support” requirement, can be adopted by multiple programs, and/or fulfill a gap to the Agency-wide cloud services portfolio of pre-approved cloud services.

Once approved, these individual cloud providers and/or services can more readily be included within existing task orders as they have been reviewed and have met the technical and interoperability requirements to become catalog items of the Agency-wide Cloud Services Catalog.

Agencies build their approved portfolio of cloud services by vetting them through the application rationalization process. This portfolio aligns with their capital IT system portfolio and details a composite suite of cloud service offerings and service models. As selected cloud services become representative of the Departments pre-approved cloud services catalog, they also serve as the priority to join existing venue instead of starting over and/or buying the same service differently. Establishing the Cloud Services Catalog business objectives are:

• Improve agility while managing the confidentiality, integrity, availability, and performance of compute and storage services;

• Communicate electronically approved offerings and catalogs to the farthest reaches of the Department.

• Reduce Total Cost of Ownership (“TCO”) of delivering shared IT services;

• Promote the use of Green IT, such as offering pre-built accelerators or an embedded carbon emissions automated calculators and conversions dashboard. The Department compares and reports reduced cloud emissions from the overall energy, real estate footprint, and use of toxic components of datacenters, and implementing effective recycling and reuse programs;

• Ensure all applicable federal mandates for information security and privacy regulations are maintained and adhered to;

• Provide tiered functions, service levels, and performance for customers;

• Provide interoperable and portable solutions that enable mobility across hosting models and service providers; and

• Enable scaling of infrastructure and application resources to meet elastic application and user demands.

The deliverable for Contractor(s) is to participate with efficient business systems and strategies.

Provide pre-solicitation coordination in fulfilling gaps for newly introduced services and streamline recurring task orders through high performing business operations.

C-9

The following Table 1 lists the Department’s current, but not all-inclusive lines of business.

These require varying levels of support including discovery, development, onboarding, migration, operations, and decommissioning types of services.

Bolded lines of business are either within a Day One use case or on the existing expiring FCHS IDIQ contract and require more imminent cloud-based service support.

Table 1 – Cloud Services - Lines of Business

1) Application Hosting, Hybrid data lake, storage, virtual desktop, DevTest Sites

2) Archive, repository, Data at rest, Disaster Recovery, Artificial Intelligence Scanning

Imaging Retrieval

3) Aviation Inventory-Safety and Asset Management

4) Building and Real Property Maintenance

5) Business Process management, seamless customer integration, ticketing, helpdesk

6) Case Management Software (CMS), includes claims and litigations tracking

7) Change Management System

8) Chemical and Safety Inspections

9) Cloud Access Security Broker, multi-factor authentication

10) Cloud Security and Workload Balance Management

11) Content Management System Suite (CMSS) or Content Delivery Network (CDN)

12) Customer Experience and Survey Tool Application

13) Customer Relationship Management (CRM)

14) Cyber Security Services (crash test, blockchain, antivirus, breach, and attack)

15) Digital Signature

16) Electronic mail, messaging delivery campaign and communications, encryption/security

17) Emergency notification, weather, mass notification

18) Endpoint detection, response, and protection

19) Event, Facilities and Resource Scheduling and Conference Management Workflow

20) Facility, space, and Computerized Maintenance Management System (CMMS)

21) Federal Human Resources, Position Classification

22) Fleet Maintenance

23) Fuel distribution and management

24) General Computer Business Collaboration Tools, Microsoft Office

25) Geospatial, mapping, GIS, GPS, geo-modelling

26) Government Retirement & Benefits

27) GRC - Cyber Governance, Risk Management, Compliance

28) Image and Video catalog, storage, and on-demand delivery

29) Learning Management System (LMS)

30) Library catalog, OCLC integration, image, audio-video

31) MIS – Management Information System – operational activities and work processes

32) Open-Source Code and Forum sharing, community hub

33) Permitting, licensing, lottery online portal

34) Radio program service management incident tracking

C-10

35) Robotic Process Automation (RPA), Intelligent Optical Character Recognition

(IOCR)

36) Safety Tracking and Monitoring Software

37) Science and Analytics Data System

38) Secure File Transfer (SFT)

39) Supply Chain Mgmt/Tracking

40) Video surveillance, IP security, body worn, footage, storage, retrieval devices

41) Visitor, Volunteer and Public outreach, recruit, schedule, engagement, and management

42) Website Hosting CMS platform, Drupal, civic engagement, info dissemination

43) Warehouse Management

44) Work Order - Automated scheduling and dispatch eWorkOrders

C.3.3 Enterprise-wide Requirements Enterprise-wide requirements are baseline requirements common to all task orders. They are applicable to all cloud service lines, regardless of resources, service levels, security categorization, or characteristics identified to fulfill task orders.

The Contractor shall coordinate recurring and prospectus cloud services and service lines to meet the following contract-wide requirements, including:

1) Provide accessible browser-based consoles, dashboards, portals, and interfaces to manage cloud services and applications as intended;

2) Restrict access to authorized users, administrators, customers, and personnel;

3) Manage appropriate level of security controls and service level agreements;

4) Define user roles, user authorization, and support levels;

5) Provision, configure, and de-commission resources as needed, both elastically and manually;

6) Monitor, set alerts, and automated notifications for general cloud service health, SLA performance, security, resources, alarms, and alerts;

7) Compile reports to document, system plans, incident processes, architectures, processes, job aids, configuration settings, and other knowledge base aspects of managed cloud services.

C.4 Technical Objectives FCHS2 requires Infrastructure, Platform and Software as a Service (IaaS-PaaS-SaaS) license and support services for hosting major and minor applications, storage, archival/disaster recovery, backup, virtual machine, database hosting, web hosting, development, and test environment, and application hosting services. As needed, cloud service offerings shall provide bundled work-space tools including a combination of operating system, storage, compute, and software resources. Contractor shall provide technical advisory services necessary to fully migrate the Government’s target application(s) and services(s) to the cloud per individual task order requirements.

FCHS2 is not limiting the varieties of software applications and/or brand names of potential SaaS available but identifies current common services in Table 1 – Cloud Services – Lines of

C-11

Business. Technical advisory and discovery services are commonly needed where program personnel are experts at their mission and data management, but not at the vast array of cloud IaaS/PaaS/SaaS layers and compute services. Technical solutions are commonly sought when on-premise IT Systems are near the end of their life expectancy and require cloud adoption as well as modernization going forward.

• Contractor should offer both tested and reliable services among the latest trends as well as innovations for new and existing IT Systems.

• Standard methods for managing the constant state of modernizing and process improvements should be practiced (e.g. such as using Carnegie Mellon University Capability Maturity Model (CMM).

• Contractors should have established partnership(s) with application developers, cyber security continuous monitoring experts, and software engineering solution providers.

Task orders require:

1) Contractors to meet Department technical objectives along with providing status updates and milestones during installation, development, migration, technology refreshes, testing plans, and rollback capabilities and procedures.

2) Contractors to provide technical advisory for pre-installation as well as ongoing post-development and management services as identified in individual task orders.

3) Contractors to provide pre-award plans for a successful track record of migration, use of automated toolsets for discovery, and be prepared to provide environments for production, integration, development, and sandbox purposes, etc. to support the complete systems lifecycle.

C.4.1 FedRAMP Technical Objectives Contractor shall secure cloud services in compliance with the suite of Federal regulations and guidelines, the latest National Institute of Science Technology (NIST) special publications, and especially cloud smart Federal Risk and Authorization Management Program (FedRAMP).

Related to FedRAMP Technical Objectives is Section J Attachment 1 – Security Objectives- Service Level Agreements.

For FedRAMP security package documents not located on Max.Gov, DOI requires Contractors to provide free and easily obtainable access to vendors secure location. Federal clients should not have to purchase additional software to login and collect the monthly security “ConMon” documentation from Contractor’s site.

Contractor shall briefly describe with each new cloud service provider proposal (or new tenant) that providers status or practices listed in Table 2 below.

TABLE 2 – Brief Outline on all New Cloud Service Providers Applies to all New (Original Base Order) Task Orders

1 FedRAMP authorization status, including the full cloud stack, and interest/intentions (if different than current status)

2 If full stack not FedRAMP authorized, whether Cloud Service Provider conducts third-party assessment organization (3PAO) reviews and shares report results with customers

C-12

3 Options available (and additional cost if any) to customer on how Cloud Provider meets Federal standards for record retention, which includes a decommissioning process to export/migrate for electronic archiving purposes appropriate records in a functional format at end of Task Order

4 Any major support role practices required between the Cloud Service Provider versus Agency that are not addressed elsewhere in the requirements or proposal

C.4.2 Open Standards To drive interoperability, scalability, portability of workloads and affordability Agencies prefer systems architected on open-standards technologies whenever possible and practical. Agencies are seeking contractors who offer innovations that stand the test of time and do not lock the Government into today’s technologies.

The technical objective is for portfolios to model solutions based on OpenStand Principles including cooperation, adherence to principles, collective empowerment, availability, and voluntary adoption. Standards selected should drive innovation and borderless commerce. They should also move Agencies forward in DevSecOps, IPv6, Zero-Trust, incident response, end-to-end physical connectivity, and seamless public availability.

Specific standards will be identified in individual task orders, but all should be utilized include:

• Open Virtualization Format (OVF) – applicable only to IaaS virtual machines

• Cloud Data Management Interface (CDMI)

• Open Cloud Computing Interface (OCCI)

• Research (OpenStack.org, Apache CloudStack, and OpenNebula)

C.4.3 Hosting Resources Federal agencies are leveraging this FCHS IDIQ contract to maintain a competitive edge and have transparency across their hybrid cloud services. They are seeking advanced technologies to migrate terabytes of data and manage multiple cloud service providers. Today, federal agencies are seeking contractors who can innovatively build and bridge hybrid and geolocation services into compatible enterprise environments. They require flexible and agile architectural foundations lasting a ten-plus year life-cycle while still compatible with emerging technologies.

Hosting service options shall include

• IaaS virtual server space, IP addresses, network connections, internet connection, firewalls, bandwidth, load balancers, etc.

• PaaS tools to build and deploy cloud-smart software applications in either on-premise, hybrid or public cloud combinations. PaaS shall have capacity to deploy the IaaS infrastructure automatically, operate the software, handle runbook scenarios automatically, and provide navigational dashboard to manage users, developers, testers, and tenants using production applications.

• SaaS services bundled within IaaS/PaaS hosting environments and aligned with the business or technical objective.

https://open-stand.org/

C-13

C.4.4 Provisioning Contractor shall provision resources for elastic bandwidth, storage, software license suites outside (generally above) the amount initially planned. Contractor shall demonstrate a holistic provisioning approach to achieve demand variations throughout the IT Systems lifecycle.

Provisioning should include the use of automation, dashboard tools, performance standards, data protection thresholds, incident response techniques, change management coordination, triggers/reports for customer inclusion, and monitoring real-time usage accounting. Use cases typically include:

• Faster Time to Production – automating manual steps to reduce time to production dramatically (months to hours in some cases)

• Lower Cost – resource setting, monitoring, automation, and sharing applications to save on infrastructure costs and reduces labor (at least 50% reduction from on-premise)

• Lower Capital Commitment – allow new offerings to start with small deployments and grow automatically as demand builds (90% reduction from peak life cycle usage)

• Manage many applications easier – provide common and systematic tools to better manage and reduce duplication for application, tenant, user management, security, and load balancing.

• More Responsive – provide automated deployment to implement faster changes and automated scaling to meet demands faster

• Best Practices – to incorporate application management that systematizes and professionalizes the operation of many applications

• Increase Reuse – facilitates reusing services through various kinds of multi-tenancy, load balancing and resource sharing to reduce cost an innovate faster.

C.4.5 Assessment and Authorization (A&A) and Technical Services Generally, the government will author their Authority to Operate (ATO) through Cloud Service Providers making their A&A documentation portal available. However, some individual task orders may include A&A support services for the Cloud Service Provider and/or IT Systems included within the tenant. Contractors shall provide expertise at varying levels of participation to complete A&A of cloud services. Contractors shall be able to improve the approach through cutting edge, intelligent, and automated processes. Contractor personnel should have a proven track record and capable of providing a holistic strategy of both the entire cloud environment and individual components.

These services shall align to the NIST Special Publication 800-37 and FedRAMP authorization processes and meet the security and privacy thresholds identified in Section J Attachment 01. In the event the full cloud stack is not FedRAMP authorized, Contractor shall provide technical advisory services for FISMA equivalent and their approach to achieving FedRAMP authorization.

Other particulars or details will be identified within specific task orders. For all newly proposed cloud service providers or instances, Contractors shall respond to the elements of Table 2 – Mandatory Statements on all New Task Orders within their price proposal. Individual task orders may include a variety of end-to-end technical support services, such as discovery of current systems (on-premises, legacy, data center), life-cycle cost estimates (migration through decommission), application rationalization, continuous monitoring, training sessions, application

C-14 development, and security and performance management. Discovery should include devising migration plans of heavily customized applications, distinguish tasks with phased approaches, decommissioning initial and onboarding new IT Systems.

Technical objectives shall include the 1) primary hosting storage and file systems and 2) services capacity for multiple geographical locations, support for data storage tiers, backup, recovery and disaster recovery procedures and processes that support the Service Level Agreements.

Individual task orders will identify specifics outside primary and common alternate storage and file system requirements.

C.4.6 Hosting Major Applications The government requires cloud services to implement and host their major and High Value Assets (HVA) applications including both support services and licenses. Additionally, major applications frequently require integration to on-premise wide area networks and/or other cloud tenants and require advanced data center to device traffic routing technologies. Typical task order requirements are requested for three to five years, but some may be the length of this contract.

1) Contractor shall have experience and capacity to provide multi-federal agency hosting platforms.

2) Contractor shall have experience and capacity to host federally classified High Value Assets and mission critical major applications. These require special attention to security due to the risk and magnitude of the harm resulting from the loss, misuse, or unauthorized access.

3) Contractor shall have the capacity for a robust disaster recovery plan, providing redundancy capacity at least 250 Continental United States (CONUS) miles apart.

4) Cloud service providers shall ensure confidentiality, integrity, and availability requirements while balancing a cost-effective solution for generally “moderate” levels of objectives.

5) Contractor shall be capable of providing end-to-end monitoring capability and reporting for service level agreement (SLA) requirements and metrics (as identified in Attachment

1) for each cloud service provider.

6) Contractor shall be capable of performing application assessments, rationalization, or modernization and provide value-added licensing and expertise on the best approach such as (1) new development, (2) migration, or (3) replatform techniques.

7) Contractor shall provide startup and ongoing configuration management forums, processes, and step-by step client guidance for each cloud virtual environment that integrates with the task order.

8) Contractor shall provide a Quality Assurance Surveillance Plan (QASP) and/or Quality Control Plan (QCP) that shall include details for Contractor/client roles, inspections, measuring performance and assessment deliverables for each cloud service provider with metrics that may include data availability, storage capacity, uptime, etc.

C.4.7 Licensing Without this contract venue, individual orders would have to start from scratch. The licensing intent of this contract is to promote expediency and consistency in Department data priorities across the board. Therefore, when individual task orders are initiated, that data and system join a https://www.cisa.gov/sites/default/files/publications/Securing%20High%20Value%20Assets_Version%201.1_July%202018_508c.pdf https://www.cisa.gov/sites/default/files/publications/Securing%20High%20Value%20Assets_Version%201.1_July%202018_508c.pdf https://www.cisa.gov/sites/default/files/publications/Securing%20High%20Value%20Assets_Version%201.1_July%202018_508c.pdf https://www.cisa.gov/sites/default/files/publications/Securing%20High%20Value%20Assets_Version%201.1_July%202018_508c.pdf

C-15 collective ten-year out life cycle plan. To meet this, Contractors should provide clear evidence on how to expand Department use of the cloud in multiples of task orders, phased approaches to the whole, adding parcels to existing hybrid-clouds, and provide efficient licensing plans that support quick turn-around response times in meeting ongoing and recurring license renewals.

Contractor shall provide licenses based on the appropriate X-as-a-service cloud computing service models, products, and/or subscriptions. The Department requires the ability to set multi-year subscriptions with simple annual true ups. Proposed environments should offer the best data storage, retrievability, and egress longevity patterns. Whether storage spend is on structure or unstructured data or allowing for a combination and shift over time. The latest in data encryption standards should be implemented by default and aligned with the systems security categorization.

Upon award, decommissioning may be several years away. However, Contractors shall identify in all new task order proposals, their process, options, and any additional costs the Government should expect at end-of-life, decommissioning, and/or repurchasing.

Licenses for each computing cloud model shall meet the National Institute of Standards and Technology (NIST) Special Publication 800-145 definition of Cloud Computing; a cloud based solution provides an ubiquitous, convenient, on-demand network access to a shared pool of configurable computing resources, allows for rapid elasticity to provision and release computing capabilities as required, and is delivered as a measured service to identify for only the services which the agency actively utilizes (Example: networks, servers, storage, applications, and services).

1) Provide flexibility to assign a per user license for use across all respective platform modules, services, products, and/or subscriptions.

2) Provide full suite of services on PaaS and SaaS for the availability for users to access a tools and services catalog within the application instance in order to add to their portfolio of services without reissuing a new task order.

3) Provide licensing and professional services cost separation along with full description each includes.

4) Provide the availability of licenses, by download or media, for each Task Order issued.

5) Provide flexibility to allow no-cost transfers of unused licenses amongst bureaus and offices. Licenses shall be transferable between bureaus and offices that utilize or subscribe to the same platform or service.

6) Provide licensing models and pricing strategies that are in line with the department and bureau licensing goals.

7) Provide flexible pricing to allow bureaus and offices to choose only the modules, products, services, or subscriptions required with options to “right-size” based on actual or projected license use. Points or discounts shall meet or exceed similar Government-wide Catalog pricing structures/schedules.

8) Provide for annual “True-Up” period with the ability to regulate licenses usage (e.g., add, subtract, transfer and/or renew existing licenses) by scaling up or down throughout the contract period. This includes the ability to scale up and down resources and licenses as needed to support seasonal workloads.

C-16

9) Provide the ability to allow bureaus and offices to add, subtract, transfer and/or renew existing licenses to support existing or new modules, products, services, and/or subscriptions.

10) Provide access to automatic software upgrades to capabilities and features without reconfiguration or licensing costs.

11) Pricing for licenses shall also include all third-party tools, add-ons, and applications to be integrated, purchased, or licensed.

12) Provide scalability and flexibility to allow “no cost” transfers of production environment licenses and snapshots to a non-production environment (e.g., sandbox, DEV, or training) and back. In other words, the intent is to allow the option to leverage licenses procured for use in the production environment and extending those licenses for use in a non-production environment without incurring additional cost.

13) Provide the ability to dynamically assign licenses during the standing-up of new sandboxes and/or development environments within 24 hours or less.

14) Provide the option for bureaus and offices to participate in initial BETA testing of new features, subscription, services, or products, to include roadmap technologies in advance of releasing for global use.

15) Provide licenses to support the transition and integration with other applications and third-party tools via Application Programming Interfaces (API) (e.g., capability for integration with digital Interactive Voice Response (IVR) telephonic systems) or web services for functions such as geocoding and address/location verification.

16) Provide the ability to track user login activity and licenses, to include the ability to deactivate or suspend inactive accounts or licenses.

17) Provide the ability to support agile, rapid implementation of new modules, services, products, and/or subscription upgrades and licenses.

18) Provide training via a “Training Credit” model to allow licensed users to conduct on-demand, user initiated, and/or group training on current and future CRM modules, services, products, and/or subscription-based services.

C.5 Security Objectives – Service Level Agreements Agencies require their risk assessments based upon the collective mission, business, and information system perspective. Much of the assessment is based upon iterative processes among a shrinking resource environment. Therefore, agencies are seeking the latest assistive technologies to streamline and gain economy of efficiencies, e.g., artificial intelligence, machine learning platforms, cross-platform digital services.

Agencies prioritize vendors who demonstrate a framework of the Service Delivery principles, standards, policies, and constraints of IT Systems from design to retirement. Additionally, federal cybersecurity laws and regulations must be embedded as a matter of standards.

For Service Level Agreements, see Section J Attachment 01 - C.5 Security Objectives – Service Level Agreements. The attachment outlines the IT security compliance, administrative objectives, security controls, privacy, and service level agreement requirements.

https://doimspp.sharepoint.com/:w:/r/sites/OCIO-PMD/Shared%20Documents/FCHS2/SOW/FCHS2%20Section%20J%20Attachment%2001%20Security%20Objectives%20-%20Service%20Level%20Agreements.docx?d=w174ffb889ddb4ae5a30e77255a1b4f0f&csf=1&web=1&e=gQXK2B https://doimspp.sharepoint.com/:w:/r/sites/OCIO-PMD/Shared%20Documents/FCHS2/SOW/FCHS2%20Section%20J%20Attachment%2001%20Security%20Objectives%20-%20Service%20Level%20Agreements.docx?d=w174ffb889ddb4ae5a30e77255a1b4f0f&csf=1&web=1&e=gQXK2B

SECTION C – STATEMENT OF WORK REQUIREMENTS
C.1 Overview
C.1.1 Background
C.1.2 Current Cloud Service Offering (CSO) Investments
C.1.3 Current Environment
C.1.4 Government Wide
C.1.5 Current Operational Constraints – Adoption Barriers
C.2 Business Objectives
C.2.1 Achieving Net-Zero
C.2.2 Attributes
C.2.3 Services
C.2.4 Application and Data Management Services
C.3 Management Objectives
C.3.1 Business Management
C.3.2 Establishing Cloud Services Catalogs
C.3.3 Enterprise-wide Requirements
C.4 Technical Objectives
C.4.1 FedRAMP Technical Objectives
C.4.2 Open Standards
C.4.3 Hosting Resources
C.4.4 Provisioning
C.4.5 Assessment and Authorization (A&A) and Technical Services
C.4.6 Hosting Major Applications
C.4.7 Licensing

C.5 Security Objectives – Service Level Agreements

File details come from the government source that posted it. Updated .