FCHS2_Section_J_Attachment_6_Day_One_NPS_CLP.pdf

PDF 588 KB Posted

Attached to
DOI Foundation Cloud Hosting Services (FCHS2) Federal contract opportunity
Solicitation number
140D0423R0002
Issued by
Department of the Interior Departmental Offices Interior Business Center

View the file

Other files for this federal contract opportunity

Other files attached to DOI Foundation Cloud Hosting Services (FCHS2), newest first.
File Type Posted
Sol_140D0423R0002_Amd_0008.pdf PDF
FCHS2_Section_J_Attachment_9_Question_and_Answer_Amd_0008_0008.pdf PDF
Sol_140D0423R0002_Amd_0007.pdf PDF
Sol_140D0423R0002_Amd_0006.pdf PDF
140D0423R0002_0006_0006.pdf PDF
Sol_140D0423R0002_Amd_0005.pdf PDF
Sol_140D0423R0002_Amd_0004.pdf PDF
FCHS2_Section_J_Attachment_07a_Usage_Summary_of_June_2023_Cloud_Services_Amd0003_0003.xlsx XLSX spreadsheet
Amendment_0003_Q_A__Consolidation_Sections_0003.pdf PDF
FCHS2_Section_J_Attachment_07b_Example_Invoice_Template_Amd0003_0003.xlsx XLSX spreadsheet
Sol_140D0423R0002_Amd_0003.pdf PDF
FCHS2_Section_J_Attachment_9_Question_and_Answer_Template_Amd0002_0002.xlsx XLSX spreadsheet
FCHS2_Section_J_Attachment_8_IDIQ_Pricing_Template_Amd0002_0002.xlsx XLSX spreadsheet
FCHS2_Section_J_Attachment_07_Day_One_USDA_DISC_Amd0002_0002.pdf PDF
FCHS2_Section_J_Attachment_2_OCIO-PAM_Memo_DOI_IT_Baseline_Compliance_Contract_Guidelines_0002.pdf PDF
FCHS2_Section_J_Attachment_4_Subcontracting_Plan_Template_Amd0002_0002.pdf PDF
RFP_140D0423R0002_Amd0002_0002.pdf PDF
FCHS2_Section_J_Attachment_05_Day_One_BIA_EUMS_Amd0002_0002.pdf PDF
FCHS2_Section_J_Attachment_3_Past_Performance_Questionnaire_Amd0002_0002.pdf PDF
FCHS2_Section_J_Attachment_06_Day_One_OCIO_GeoPlatform_Amd0002_0002.pdf PDF
FCHS2_Section_J_Attachment_01_Security_Objectives_Service_Level_Agreements_Amd0002_0002.docx DOCX document
Sol_140D0423R0002_Amd_0002.pdf PDF
FCHS2_Section_J_Attachment_0-Amd_0001_0001.pdf PDF
FCHS2_Section_J_Attachment_10-Question_and_Answer_Template_0001.xlsx XLSX spreadsheet
Sol_140D0423R0002_Amd_0001.pdf PDF
FCHS2_Section_L_Instructions__Conditions__Notices.pdf PDF
FCHS2_Section_J_Attachment_7_Day_One_NPS_Volunteer.pdf PDF
FCHS2_Section_J_Attachment_3_Past_Performance_Questionnaire.pdf PDF
FCHS2_Section_J_Attachment_0.pdf PDF
FCHS2_Section_I_Contract_Clauses.pdf PDF
FCHS2_Section_G_Contract_Administration_Data.pdf PDF
FCHS2_Section_C_Statement_of_Work.pdf PDF
FCHS2_Section_K_Representations__Certifications__and_Other_Statements_of_Offeror.pdf PDF
FCHS2_Section_M_Evaluation_Factor_for_Award.pdf PDF
FCHS2_Section_J_Attachment_4_Subcontracting_Plan_Template.pdf PDF
FCHS2_Section_E_Inspection_and_Acceptance.pdf PDF
Sol_140D0423R0002.pdf PDF
FCHS2_Section_F_Deliverables_or_Performance.pdf PDF
FCHS2_Section_B_Supplies__Services_and_Costs.pdf PDF
FCHS2_Section_J_Attachment_8_Day_One_OCIO_GeoPlatform.pdf PDF
FCHS2_Section_J_Attachment_5_Day_One_BIA_EUMS.pdf PDF
FCHS2_Section_J_Attachment_9_Day_One_USDA_DISC.pdf PDF
FCHS2_Section_J_Attachment_2_OCIO-PAM_Memo_DOI_IT_Baseline_Compliance_Contract_Guidelines.pdf PDF
FCHS2_Section_J_Attachment_1_Security_Objectives_-_Service_Level_Agreements.pdf PDF
FCHS2_Section_H_Special_Contract_Requirements.pdf PDF
FCHS2_Section_D_Packaging_and_Marketing.pdf PDF
Show all 46

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

Foundation Cloud Hosting Services II (FCHS2) Section J

J06-1

SECTION J – ATTACHMENT 06

SECTION 1. INTRODUCTION DAY ONE USE CASE

NATIONAL PARK SERVICE (NPS)-DISTANCE LEARNING GROUP-NPS COMMON

LEARNING PORTAL SYSTEM (CLP)

The Department of the Interior (DOI) has prepared this Day One Use Case to support the National Park Service, Office of Learning & Development, Washington D.C. Area Support Office (WASO)

The WASO Distance Learning Program is in the process of planning for FCSH2 contract which includes the potential migration to new hosting environment for the NPS Common Learning Portal (CLP) system, which is a web application for all NPS employees to post to and for each other a wide variety of training and learning opportunities. CLP is developed using the WordPress Content Management System (CMS) and currently hosted on a FedRAMP commercial Cloud Service Provider

J06-2

SECTION 2. STATEMENT OF WORK (SOW)

A. Background The WASO Distance Learning Program requires initial services to encompass the potential application migration, providing and provisioning an Infrastructure as a Service (IaaS) platform, and providing training sessions for our internal team and contracted developers on the services, as well as related, processes, security, and service management of the IaaS infrastructure.

The proposed services will support desired outcomes, including:

• The successful and complete migration of the NPS Common Learning Portal system to the new cloud environment

• Service management and monitoring in the cloud to support cost-effective, secure, and agile IT management

The proposed services include providing ongoing IaaS cloud hosting support services aligned with the FCHS Section J – Attachment 1 “Security Objectives” to include cloud environment configuration, continuous monitoring, and user training. Application support includes ensuring the CLP application has appropriate FISMA Moderate level confidentiality, integrity, and availability within the new hosting environment. NPS does not anticipate application development support in the WordPress CMS language.

All cloud services provided will be required to meet vendor-offered Service Level Agreements (SLAs) as well as the performance criteria described later in section 6. Additionally, these services will provide backup, volume snapshots, archiving, performance scaling, and supporting security and updates.

B. Objectives Contractor to provide cloud IaaS environment including migration planning and services, provision new environments, configure for readiness, and training in the environment. To achieve this, these cloud services must meet applicable business, technical, security, management, and administrative objectives.

The outcome of cloud services should be aligned with the Departments’ enterprise service delivery model described below and support the agency’s ability to deliver future sustainable services. Contractor proposal shall include their technical and administrative approach to the following bullets:

1) Provision to allow maximum flexibility to innovatively manage program cost, schedule, performance, risks, warranties, contracts and subcontracts, vendors, and data required to deliver effective migration services

2) Maintain clear government visibility into program cost, schedule, technical performance, and risk, including periodic reporting

3) Provide meaningful reporting and analytics that provide the Program with up-to-date and comprehensive information regarding technical and management performance

4) Provide a brief description on the management of any subcontractor relationships and contracts.

Outline the roles and responsibilities per party involved in the service and where key responsibilities reside

5) Provide a transition plan detailing milestones, activities, and timelines for the migration and provisioning of services

6) Utilize a robust cloud environment for hosting the system that is secure and where the underlying components (OS, security patches, backups) are maintained by the vendor to reduce the required expertise in these areas by the government

Provide a brief description of proposed efficiencies, e.g. cost savings, automating routines, shortening the timeline to production, configurations that decrease egress and other license costs, other - etc.

J06-3

Scope This SOW addresses the broad scope of work to be completed by the Contractor, in coordination with NPS technical staff in the following associated activities.

The Contractor shall:

(a) Provide and provision the cloud environment services to host the applications or services. Provision virtual machines, operating system(s) and required compute and storage services in the IaaS environment.

(b) Coordinate and perform the migration of CLP application from existing to the new Cloud Hosting Provider.

(c) Under the proposed model the scope of this SOW includes providing a scalable (per demand) production environment (WordPress CMS) with (MySQL) database backends.

(d) In addition to the Production environment, build a Staging and Development environment that will allow code promotion, development to staging, and staging to production. Contractor will maximize environment efficiencies (e.g. cost savings) such as establishing a staging and development environments that requires less uptime due to their limited use.

(e) The Production application server will be public facing, with all servers also utilizing a private internal IP address for administration via terminal access.

(f) Provide a migration plan, including developing the milestones and migration roadmap.

(g) Both traditional Backups and VM Volume Snapshots will be required to provide minimal data loss and uptime to the production servers. Snapshots are a point-in-time copy of the Virtual Machine and permit faster roll-back to a previous point-in-time.

(h) Provide the elasticity to increase/decrease resources, as needed, automatically and/or manual to support any periods of unpredictable high/low usage. Scalable resources include Bandwidth, Servers, Storage, Database instances

(i) The proposed production environment should scale to demand automatically without requiring intervention by the vendor or government.

(j) Administration functions such as instance configurations, snapshots, backups, and security updates will be handled by the vendor, documented, and delivered as a CLP Disaster Recovery Plan prior to Production stage

(k) Vendor must provide the ability for a Government System Administrator to perform system administrative functionality within the CLP instances.

(l) The Vendor shall provide information and training describing the method(s) available for performing this functionality (i.e., command line, API, etc.) and the type and scope of system administration functions available.

Vendor shall provide the ability and training to monitor the environments via a web portal and include information such as bandwidth usage, CPU utilization, and rebooting servers. See FCHS2 Section J Attachment 1 Security Objectives for following bullets. These describe environment support requirements, e.g. Incident Response, Service Level Agreement thresholds, Availability and Help Desk support.

a) The Vendor shall provide automated notifications to the Government for any: Critical Incident Alerts, Unplanned traffic spikes, Outages, Custom Alerts based on government defined thresholds.

b) Provide the Government near real-time visibility and 24x7x365 monitoring including, but not limited to, the following: Server utilization (bandwidth, memory, CPU), Cloud services performance, Service status, Key performance indicators of the system against the established SLAs, Custom Monitoring Metrics.

c) The Prime Vendor shall provide monitoring of the system and troubleshooting incidents associated with the hosting environment to ensure SLAs thresholds are met. Managing incidents may include: 24 hours per day, seven days a week, and 365 days per year proactive monitoring

J06-4 and support for resolution of all outages. The NPS requires support services available 8x5 Single (EST) Time Zone: 9am to 5pm Monday through Friday, (Eastern), Troubleshooting services and support during core duty hours.

d) The help desk shall be available 8x5 Single Time Zone: 9am to 5pm Monday through Friday, (Eastern) 24x7x365

e) Mean Time to Acknowledge (MTA) Requirements: Band 2 (Sev 1: From 15 minutes to 2 hours;

Sev 2: From 30 min to 4 hr; Sev 3: From 45 min to 6hr; Sev 4: From 60 min to 8 hr.) Production environment 15 minutes to 2 hours maximum time to acknowledge for Priority 1 severity, and for mean time to resolve.

f) Mean Time to Resolve (MTR) Requirements: Band 2 (Sev 1: From 15 minutes to 2 hours; Sev 2:

From 30 min to 4 hr; Sev 3: From 45 min to 6 hr; Sev 4: 60 min to 8 hr)

g) Planned Downtime: Band 3 (From 1 hr to 2 hr)

h) The Prime Vendor shall provide a trouble ticket submission process for submitting support requests and questions from users. The trouble ticket requests will include real-time case status and history.

i) The Prime Vendor shall provide a Project Manager or other single point of contact for submitting inquiries and conducting bi-weekly meetings with the System.

j) There are requirements for potentially migrating existing data or systems. If required, the Vendor will provide a location for uploading the data, which can then be moved to the server environment. The initial site upload, from the developer, will be loaded to the development environment where the developer will test functionality, then promote the code to staging, where the developer will test functionality, then finally promote the code to production where the developer will perform testing.

k) System relies on the DOI Active Directory Federated Services (ADFS) / Security Assertion Markup Language (SAML) for authenticating employees via PIV (smartcard) cards to the web application.

l) For IaaS, the Prime Vendor responsibilities include:

• Non-Government network services, including but not limited to:

Routers, Switches, Firewalls, Load balancing

• Server management and hardware administration (physical and virtual)

• Storage management (NAS and SAN)

• Providing hardware, communications, hosting, storage, software

• Backups and volume snapshots for IaaS hosting

C. Period and Place of Performance

The base Period of Performance will be two years beginning from the date of award and four two-year option periods. The life expectancy of this project is ten years. Services will be performed remotely.

D. Current Environment The Common Learning Portal (CLP) increases the visibility and availability training resources to the entire NPS workforce, including Seasonal employees, Volunteers, and Partners. The CLP provides training resources to the entire NPS workforce, including those without a PIV card.

Using the CLP, Training and Program Managers can create content available to the entire NPS Workforce, and help employees find and register for training in the Learning Management System. The CLP is built upon a highly customized version of WordPress.

Our Program has a contracted web development team and internal team which support the system.

Production web server will be public facing to serve the public and is available globally, while other

J06-5 servers will have a private server address for administration via VPN and terminal.

System data is FISMA Moderate and will require a VPN connection for administration via terminal access to the server’s private IP address.

The following environments are specified for hosting considerations:

• Development

• Test/ QA (we are referring to this as Staging)

• Production

Current WordPress CMS environment is hosted on:

• Red Hat Linux 64-bit version 6.1

• Apache2 version 2.4.34

• MySQL 5.5.52

• PHP 7.0.27

Table 1 Current Environment Configuration

# of VM Type VM Type CPU Cores # RAM

(GB)

Storage (GB) Operating System

1 HaProxy Web Balancer 4 64 300 Red Hat Linux 64 bit Load Balances Word Press app servers, public -> private interface

2 Web Servers (Production) 4 64 2000 Red Hat Linux 64 bit Apache 2, PHP, Gluster FS - synced storage

2 Database Servers (Production) 6 64 2000 Red Hat Linux 64 bit MySQL, master/slave setup

1 Staging Server 4 64 2000 Red Hat Linux 64 bit Apache 2, PHP, MySQL

1 Development Server 4 64 2000 Red Hat Linux 64 bit Apache 2, PHP, MySQL

Table 2 Currently (August 2022) the Production server supports

Current Anticipated Future Need (FY23) Number of Users: Peak Time 5,000 Sessions week 10,000 Sessions week Number of Users: Average Time 7,000 Sessions per week 15,000 Sessions per week Amount of Bandwidth: Peak Time 100 GiB per month 120 Gib per month Amount of Bandwidth: Average Time 65 Gib per month 80 Gib per month

J06-6

Number of Transactions: Peak Time 25,000 Pageviews 35,000 Pageviews Number of Transactions: Average Time 16,000 Pageviews 20,000 Pageviews

E. Detailed Requirements

Overall Requirements: Establish a new IaaS cloud tenant from the best suited major cloud service provider in FedRAMP space for the Government.

(a) Provision cloud tenant at the Moderate FISMA Level with instances and environment including network, operating system, compute services, monitoring and other management tools, and disaster recovery (backup) provisions according to the Security and Constraints below

(b) Coordinating with DOI technical staff, migrate existing Application and Data

(c) Configure access and authentication for DOI Administrators who will access the systems via Vendor provided VPN and terminal access

(d) Provide coordination configuration for DOI users to authenticate using Microsoft Federated SAML

2.0.

(e) Provide FedRAMP or equivalent access to system security plan, system assessment report, system assessment plan, disaster recovery plan, Monthly ConMon Reports, Plan of Action and Milestones, Control Implementation Sheet Workbook, and other related documents for the Government to achieve a NIST SP-800-37, SP-800-53 level Authority to Operate.

(f) Provision tenant to meet all the Security Requirements listed below under 7.0

(g) Train Government team on the tenant environment

(h) Provide maximum alignment to Federal CIO Cloud Smart migration and requirements, amplifying the Departments ability to achieve management objectives.

(i) Provide all support operations necessary to fully plan, develop, deliver, and operate services for each life-cycle phase.

Planning Requirements: Utilize industry best practices to conduct an inventory of the Programs IT assets and provide a comprehensive view of the boundary and environment, including but not limited to applications, infrastructure, and security delivered into a full architectural rendering.

(j) Architectural Diagram - The Prime Vendor shall provide an architecture diagram of the proposed solution.

(k) Produce a migration planning roadmap for the Program to effectively plan for cloud migration that maximizes cost reduction and identifies constraints and inhibitors to cloud migration.

(l) Provide a migration plan describing recommendations for service models (SaaS, PaaS, or IaaS), and deployment model (private, public, community, etc.).

(m) During planning stage, provide an overall project Requirements Traceability Matrix (RTM table) illustrating the degree to which their proposed solution will meet the requirements of the hosted environment specified in this statement of work. It should include task line items within each planning, migration, development, and production stage. It should include the project’s scope, requirements, milestones, and deliverables.

(n) Deliverables and Reviews - The Vendor and Government teams (via the Government point of contact) shall review the scope of the system requested by the Government team. The Vendor and Government teams shall elaborate on the high-level requirements for the system, including the overall capabilities of the web system and the integrations with any external systems that the web system will interface with.

(o) Deliverable Review - All deliverables shall be submitted to the Contracting Officer’s Representative (COR) and Government Task Lead(s) for review, unless otherwise agreed upon.

(p) Review Process - The COR/GTL will review for completeness the preliminary or draft documentation that the Vendor submits and may return it to the Vendor for correction. Absence of any comments by the COR will not relieve the Vendor of the responsibility for complying with the

J06-7 requirements of this statement of work. Final approval and acceptance of documentation required herein shall be by letter of approval and acceptance by COR. The Prime Vendor shall not construe any letter of acknowledgement of receipt material as a waiver of review, or as an acknowledgement that the material is in conformance with the work statement. Any approval given during preparation of the documentation, or approval for shipment shall not guarantee the final acceptance of the completed documentation.

(q) Quality Measures - General quality measures, as set forth below, are applied to each deliverable received from the Prime Vendor under this effort.

(r) Accuracy – Deliverables will be accurate in presentation, technical content, and adherence to accepted elements of style.

(s) Clarity – Deliverables will be clear and concise. All diagrams will be easy to understand and be relevant to the supporting narrative.

(t) Consistency to Requirements – All deliverables must satisfy the requirements of this SOW.

(u) File Editing – All text and diagrammatic files will be editable by the Government.\

(v) Format – Deliverables will be submitted in hard copy where applicable and in media mutually agreed upon prior to submission. Hard copy formats will follow any specified directives or manuals.

(w) Timelines – Deliverables and work products will be submitted on or before the due date specified herein or submitted in accordance with a later scheduled date determined by the Government.

(x) Development Requirements: The Prime Vendor shall prepare and submit a weekly status report in accordance with the requirements of this task order. The weekly status report shall include but is not limited to the following:

(y) Progress for the period: a detailed progress report of findings, key relevant activities, and accomplishments during the reporting period, including any partner activities.

(z) Progress report shall be aligned with the activities identified under the Requirements Traceability Matrix.

(aa) Activities planned, to include any partner activities, for the next reporting period: planned activities, as well as the status of all deliverables, including planned delivery date(s).

(bb) Production Performance Reports: - The Prime Vendor shall provide reporting and analytics that provides the Government with up-to-date and comprehensive information regarding technical and management performance (summarizing projected vs. actual measures), pricing and other related issues by bureau and office.

(cc) The Prime Vendor shall prepare and submit an itemized list of proposed costs for this contract to permit the government the opportunity to adjust quantities in accordance with the Program’s available budget prior to award.

Security In addition to the itemized list below, all Security and Privacy requirements under this task order shall comply with the FCHS2 base contract. Proposals should include either acceptance or alternate metrics as appropriate for cloud compute services under this task order.

• Provide all technical advisory services necessary to fully plan and migrate the Programs target

Application to the cloud.

• Provide cloud environments (e.g., IaaS, PaaS, etc.) for [production, integration, development, and sandbox] purposes to support the complete systems lifecycle.

• Provide post-deployment cloud support and/or governance services, including the completion of all task assignments including creating and authorization of individual instances as required.

• Provide open-standards based technologies whenever possible to provide interoperability. Specific standards considered include:

1. Open Virtualization Format (OVF) – applicable only to IaaS virtual machines

2. Cloud Data Management Interface (CDMI)

J06-8

3. Open Cloud Computing Interface (OCCI)

• Provide capability to elastically provision resources for bandwidth, storage, memory, compute services, within-tenant software licenses, etc. as required to support the migration beyond the amount normally planned for operations.

• Provide migration status in the RTM including milestones and support or implement specified migration testing plans and related rollback capabilities.

• Provide Disaster Recovery backup and recovery procedures and processes in the cloud environment for the target applications and services that support the following objectives:

• Configure automated nightly and on-demand as needed backup routines.

• Recovery Time Objective (RTO) – ability to recover files within < 24 hours of request.

• Recovery Point Objective (RPO) - ability to recover files no older than 24 hours old for any specific day within a rolling two (2) month period.

• Mean Time to Repair (MTTR) – the elapsed recovery average time required to complete a restore request is set for four (8) hours. Depending on the size of individual restore requests the calculated “Average” is based on the aggregate of all restore requests over a month.

• Data Backup Location – Data backups maintained or replicated at a site geographically 250-miles disparate from the production site such that the loss of one data center does not prohibit recovery of data within the prescribed RTO.

• Provide support for data storage tiers between live, at-rest, archive, etc.

• Provide complete support for IPv6 within the cloud environments provided. If can’t provide IPv6, then must provide IPv4 with detailed plans and timeline to achieve IPv6.

• Provide support and services in compliance and alignment with Federal Risk and Authorization

Management Program (FedRAMP) standardized security assessment, authorization, and continuous monitoring policies as required by the scope of the project. Assessment and Authorization (A&A) activities will be included as part of the migration.

• Provide migration services regarding security and privacy that are consistent with the NIST Special Publication 800-144 – “Guidelines on Security and Privacy in Public Cloud Computing”

• Provision services to manage FISMA MODERATE security and privacy risk for the IT Systems life-cycle that are consistent with NIST Special Publication 800-37 and NIST Special Publication 800-53.

• Provide a security plan focused on end-to-end integration points, including data in transit and at rest.

• Provide support for specified auditable events related to the applications or services.

• Properly secure connections between co-located systems and integrations consistent with Trusted

Internet Connection 3.0 and similar mandates.

• Provide end-to-end monitoring capability and reporting for service level agreement (SLA) requirements and metrics.

• Accessibility: Applications and services that fall under the Information and Communication

Technology (ICT) services shall comply with Section 508 of the Rehabilitation Act and Web Content Accessibility Guidelines (WCAG).

• Availability: Provide cloud services compliant with the Secure Software Development Framework (SSDF) – Supply Chain Security.

• Cloud services should be fully operational 99.90% and scheduled maintenance, downtime, patching, and other implementations potentially affecting availability will be pre-coordinated and transparent to the Program.

• Performance: Provision services to permit visibility to monitor and manage variations in performance metrics, e.g., on-demand services available, adaptation to demand fluctuations, role filtered tools to support billing and service functions, peak usage and historical average reports, alarms and logging dashboards, automated reporting metrics/failures, etc.

https://nvlpubs.nist.gov/nistpubs/Legacy/SP/nistspecialpublication800-144.pdf https://nvlpubs.nist.gov/nistpubs/Legacy/SP/nistspecialpublication800-144.pdf https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-37r2.pdf https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r5.pdf https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r5.pdf

J06-9

• Continuous Monitoring: Provide Security Assessment Plan and Security Assessment Report according to NIST SP 800-53. Provide Continuous Monitoring Plan (CMP), with included Plan of Actions and Milestones (POAMs) consistent with NIST SP 800-137.

• Service Center: Provide default available tiers and types of Service Centers including trouble ticketing and business operations. Provide contact links and phone numbers for initiating contact with Online Support Site “reading room”, 800 number, Help Desk, chat, task order support, etc.

Provide days, hours, and time zones available. Provide “mean time to” response services between

(1) routine, (2) Mission Priority, and (3) Emergency (health and safety)

• Additional Services: At vendors discretion, provide optional additional support services available and/or recommended not included in standard licensing. Provide description, line items, and cost separately and clearly labelled as optional on task order proposal.

• Service Reliability: Deliver a Disaster Recovery Plan for each CSP that includes (at a minimum) service resilience, fault tolerant, customer data backup and restore, and disaster recovery reliability. Describe Network Configuration Manager features to meet reliability standards; e.g., change management, login attempt log, idle timeout, syslog events, routine backups, etc.

• Backup and Restore: Describe backup routines, frequency, and types available according to the Disaster Recovery objectives above. Describe the length of times and states for retention.

Describe FIPS 140-3 encryption and other measures implemented for the protection of sensitive and valuable data. Backup solutions must be agentless architecture solution, meet 100TB backup capacity in under 8 hours, scalable into petabyte range, test and verify without having to restore, ability to launch VM directly from de-duplicated compressed backup, provide end-to-end AES encryption.

• Data Management: Provide Control Implementation Summary (CIS) and Customer Responsibility Matrix (CRM) of all security controls at the Moderate environment level according to NIST SP 800-53 rev 5. CIS should describe CSP versus customer responsibilities.

Provide security for both data in transit and at rest. Select CSP regions/zones within the Continental United States, Hawaii, Alaska, Puerto Rico, Guam, and Virgin Islands with geographical separation of at least 250- miles. Provide support for auditable events to the applications and/or services.

• Incident Response: Follow IR procedures for all privacy breaches and take immediate action (within 1 hour when identified) to contain and mitigate the impact of breach and cooperate with Government officials. Contractor shall document: programs/platforms, location of breach, date/time, nature of event/loss/unauthorized access, summary description, whether personally identifiable information involved, number of users/customers impacted, estimated records, data sets affected. Submit email regardless of time or day to:

• Department of the Interior - Computer Incident Response Center (DOI-CIRC) at doicirc@ios.doi.gov and 703-648-5655.

• Contracting Officer

• Authorizing Official and/or System Owner

• Information System Security Officer and/or Cloud Service Provider portal within max.gov

• Quality Assurance: Provide a draft Quality Assurance Surveillance Plan (QASP) and/or Quality

Control Plan (QCP) that shall include details for measuring performance and deliverables with metrics that may include data availability, storage capacity, uptime, etc. These documents are to be correlated with the “as-is” and “to-be” environments provided in Sections 5.1 and 5.2 above.

Constraints

• Access Control: Cloud Service Provider has capacity to meet Federal Records Management

Requirements, including ability to support record holds, National Archives and Records Administration (NARA) requirements, and Freedom of Information Act (FOIA) requirements;

• Contractor shall not remove PII or Privacy Act material from Government facilities or systems, or mailto:doicirc@ios.doi.gov

J06-10 facilities or systems operated or maintained on the Government’s behalf, without the express written permission of the Head of the Contracting Activity.

• Contractor may be required to provide necessary support to assist the Government in meeting the requirements of the Privacy Act and related laws and shall cooperate to provide supporting documentation and access to information upon request by authorized agency officials.

• Provision services to protect Federal records appropriately and protect them from unauthorized removal from the Departments custody, including the handling of records containing information exempt from disclosure under the Freedom of Information Act (FOIA) (5 U.S.C. 552), the Privacy Act (5 U.S.C. 522a)

• Intellectual Property: Ensure the protection of government intellectual property (IP) and data ownership rights and those of any licensors. They shall identify and provide visibility of IP owned and managed components by them or the cloud service provider. Unless otherwise noted by contractor and government all data is owned by government.

• Origin of DNS: Cloud Service Provider’s external DNS security (NDSSEC) provides origin authentication and integrity verification.

• Authentication: Seamlessly integrate with the Agency Identity, Authorization and Access Management (IdAAM) solution that consists of the Microsoft Active Directory (AD) and Public Key Infrastructure (PKI) architecture and associated Certificate Authority and DOI HSPD-12 PIV SmartCard-based credentials.

• Provide multi-factor-authentication communication channel for cloud environment management to support Microsoft Federated SAML 2.0 Government’s PIV Card authentication consistent with OMB M-11-11 “Continued Implementation of HSPD-12 for Common Identification Standard for Federal Employees and Contractors”

• Provide Login.gov type phishing-resistant “Identify Authentication” single sign-on credentialing options for external facing customer services consistent with M-22-09 “Moving the U.S.

Government Toward Zero Trust Cybersecurity Principles”

• Contractor Personnel: Offeror’s personnel and other Contractors authenticating into Agency cloud services shall also comply with Homeland Security Presidential Directive (HSPD-12) that require all federal entities and associated contractors have security background investigations equivalent to federal employees. Background investigations will be performed by the Office of Personnel Management (OPM).

• Prohibitions:

• Adware: DOI requests contractors to refrain from and to actively prevent adware, spam, and remarketing of information. The Contractor shall not engage in nor permit its agents to push adware, software, or marketing not explicitly authorized by the Agency. The Contractor and/or their agents shall not resell nor otherwise redistribute information gained from its access to contract users.

• Non-Disclosure Agreements: Contractors shall require each of their administrative employees that interfaces with the cloud services customized applications and government data to sign non-disclosure agreements at onset of project implementation. Non-disclosure agreements will be supplied by the Contracting Officer, or the Contractor may elect equivalent and approved alternative.

• Government Banners: A government approved logon banner must be displayed on the first page of any public access web pages. Logon warning banners must be automatically incorporated into IT Systems initial logon process and require periodic credentialed acceptance for all (federal and contractor) personnel accessing the federal IT System.

(END of SOW)

J06-11

SECTION 3. CLAUSES.

3.1 FAR 52.252-2, CLAUSES INCORPORATED BY REFERENCE (FEB 1998)

The following clauses are hereby incorporated by reference. The full text version can be found at https://acquisition.gov/far/index.html.

• FAR 52.203-17 CONTRACTOR EMPLOYEE WHISTLEBLOWER RIGHTS AND

REQUIREMENT TO INFORM EMPLOYEES OF WHISTLEBLOWER RIGHTS (JUN 2020)

• FAR 52.212-4 CONTRACT TERMS AND CONDITIONS – COMMERCIAL PRODUCTS AND

COMMERCIAL SERVICES (DEC 2022) and it’s ALTERNATE I (NOV 2021).

• FAR 52.232-18 AVAILABILITY OF FUNDS (APR 1984)

• FAR 52.232-39 UNENFORCEABILITY OF UNAUTHORIZED OBLIGATIONS (JUN 2013)

3.2 CLAUSES AND PROVISIONS IN FULL TEXT

3.2.1 FAR 52.203-18 Prohibition on Contracting with Entities That Require Certain Internal Confidentiality Agreements or Statements-Representation (JAN 2017)

(a) Definition. As used in this provision-

Internal confidentiality agreement or statement, subcontract, and subcontractor , are defined in the clause at 52.203-19, Prohibition on Requiring Certain Internal Confidentiality Agreements or Statements.

(b) In accordance with section 743 of Division E, Title VII, of the Consolidated and Further Continuing Appropriations Act, 2015 (Pub. L. 113-235) and its successor provisions in subsequent appropriations acts (and as extended in continuing resolutions), Government agencies are not permitted to use funds appropriated (or otherwise made available) for contracts with an entity that requires employees or subcontractors of such entity seeking to report waste, fraud, or abuse to sign internal confidentiality agreements or statements prohibiting or otherwise restricting such employees or subcontractors from lawfully reporting such waste, fraud, or abuse to a designated investigative or law enforcement representative of a Federal department or agency authorized to receive such information.

(c) The prohibition in paragraph (b) of this provision does not contravene requirements applicable to Standard Form 312, (Classified Information Nondisclosure Agreement), Form 4414 (Sensitive Compartmented Information Nondisclosure Agreement), or any other form issued by a Federal department or agency governing the nondisclosure of classified information.

(d) Representation. By submission of its offer, the Offeror represents that it will not require its employees or subcontractors to sign or comply with internal confidentiality agreements or statements prohibiting or otherwise restricting such employees or subcontractors from lawfully reporting waste, fraud, or abuse related to the performance of a Government contract to a https://www.acquisition.gov/far/part-52#FAR_52_203_19

J06-12 designated investigative or law enforcement representative of a Federal department or agency authorized to receive such information (e.g., agency Office of the Inspector General).

(End of provision)

3.2.2 FAR 52.204-21 Basic Safeguarding of Covered Contractor Information Systems (NOV 2021)

(a) Definitions. As used in this clause—

Covered contractor information system means an information system that is owned or operated by a contractor that processes, stores, or transmits Federal contract information.

Federal contract information means information, not intended for public release, that is provided by or generated for the Government under a contract to develop or deliver a product or service to the Government, but not including information provided by the Government to the public (such as on public websites) or simple transactional information, such as necessary to process payments.

Information means any communication or representation of knowledge such as facts, data, or opinions, in any medium or form, including textual, numerical, graphic, cartographic, narrative, or audiovisual (Committee on National Security Systems Instruction (CNSSI) 4009).

Information system means a discrete set of information resources organized for the collection, processing, maintenance, use, sharing, dissemination, or disposition of information ( 44 U.S.C. 3502).

Safeguarding means measures or controls that are prescribed to protect information systems.

(b) Safeguarding requirements and procedures.

(1) The Contractor shall apply the following basic safeguarding requirements and procedures to protect covered contractor information systems. Requirements and procedures for basic safeguarding of covered contractor information systems shall include, at a minimum, the following security controls:

(i) Limit information system access to authorized users, processes acting on behalf of authorized users, or devices (including other information systems).

(ii) Limit information system access to the types of transactions and functions that authorized users are permitted to execute.

(iii) Verify and control/limit connections to and use of external information systems.

(iv) Control information posted or processed on publicly accessible information systems.

(v) Identify information system users, processes acting on behalf of users, or devices.

http://uscode.house.gov/browse.xhtml;jsessionid=114A3287C7B3359E597506A31FC855B3

J06-13

(vi) Authenticate (or verify) the identities of those users, processes, or devices, as a prerequisite to allowing access to organizational information systems.

(vii) Sanitize or destroy information system media containing Federal Contract Information before disposal or release for reuse.

(viii) Limit physical access to organizational information systems, equipment, and the respective operating environments to authorized individuals.

(ix) Escort visitors and monitor visitor activity; maintain audit logs of physical access; and control and manage physical access devices.

(x) Monitor, control, and protect organizational communications (i.e., information transmitted or received by organizational information systems) at the external boundaries and key internal boundaries of the information systems.

(xi) Implement subnetworks for publicly accessible system components that are physically or logically separated from internal networks.

(xii) Identify, report, and correct information and information system flaws in a timely manner.

(xiii) Provide protection from malicious code at appropriate locations within organizational information systems.

(xiv) Update malicious code protection mechanisms when new releases are available.

(xv) Perform periodic scans of the information system and real-time scans of files from external sources as files are downloaded, opened, or executed.

(2) Other requirements. This clause does not relieve the Contractor of any other specific safeguarding requirements specified by Federal agencies and departments relating to covered contractor information systems generally or other Federal safeguarding requirements for controlled unclassified information (CUI) as established by Executive Order 13556.

(c) Subcontracts. The Contractor shall include the substance of this clause, including this paragraph (c), in subcontracts under this contract (including subcontracts for the acquisition of commercial products or commercial services, other than commercially available off-the-shelf items), in which the subcontractor may have Federal contract information residing in or transiting through its information system.

(End of clause)

3.2.3 FAR 52.204-24 Representation Regarding Certain Telecommunications and Video Surveillance Services or Equipment (NOV 2021)

The Offeror shall not complete the representation at paragraph (d)(1) of this provision if the Offeror has represented that it "does not provide covered telecommunications equipment or services as a part of its offered products or services to the Government in the performance of any contract, J06-14 subcontract, or other contractual instrument" in paragraph (c)(1) in the provision at 52.204-26, Covered Telecommunications Equipment or Services—Representation, or in paragraph (v)(2)(i) of the provision at 52.212-3, Offeror Representations and Certifications-Commercial Products or Commercial Services.

The Offeror shall not complete the representation in paragraph (d)(2) of this provision if the Offeror has represented that it "does not use covered telecommunications equipment or services, or any equipment, system, or service that uses covered telecommunications equipment or services" in paragraph (c)(2) of the provision at 52.204-26, or in paragraph (v)(2)(ii) of the provision at 52.212-3.

(a) Definitions. As used in this provision—

Backhaul, covered telecommunications equipment or services, critical technology, interconnection arrangements, reasonable inquiry, roaming, and substantial or essential component have the meanings provided in the clause 52.204-25, Prohibition on Contracting for Certain Telecommunications and Video Surveillance Services or Equipment.

(b) Prohibition. (1) Section 889(a)(1)(A) of the John S. McCain National Defense Authorization Act for Fiscal Year 2019 (Pub. L. 115-232) prohibits the head of an executive agency on or after August 13, 2019, from procuring or obtaining, or extending or renewing a contract to procure or obtain, any equipment, system, or service that uses covered telecommunications equipment or services as a substantial or essential component of any system, or as critical technology as part of any system. Nothing in the prohibition shall be construed to—

(i) Prohibit the head of an executive agency from procuring with an entity to provide a service that connects to the facilities of a third-party, such as backhaul, roaming, or interconnection arrangements; or

(ii) Cover telecommunications equipment that cannot route or redirect user data traffic or cannot permit visibility into any user data or packets that such equipment transmits or otherwise handles.

(2) Section 889(a)(1)(B) of the John S. McCain National Defense Authorization Act for Fiscal Year 2019 (Pub. L. 115-232) prohibits the head of an executive agency on or after August 13, 2020, from entering into a contract or extending or renewing a contract with an entity that uses any equipment, system, or service that uses covered telecommunications equipment or services as a substantial or essential component of any system, or as critical technology as part of any system. This prohibition applies to the use of covered telecommunications equipment or services, regardless of whether that use is in performance of work under a Federal contract. Nothing in the prohibition shall be construed to—

(i) Prohibit the head of an executive agency from procuring with an entity to provide a service that connects to the facilities of a third-party, such as backhaul, roaming, or interconnection arrangements; or

(ii) Cover telecommunications equipment that cannot route or redirect user data traffic or cannot permit visibility into any user data or packets that such equipment transmits or otherwise handles.

(c) Procedures. The Offeror shall review the list of excluded parties in the System for Award Management (SAM) ( https://www.sam.gov) for entities excluded from receiving federal awards for "covered telecommunications equipment or services".

(d) Representation. The Offeror represents that— https://www.acquisition.gov/far/part-52#FAR_52_204_26 https://www.acquisition.gov/far/part-52#FAR_52_212_3 https://www.acquisition.gov/far/part-52#FAR_52_204_26 https://www.acquisition.gov/far/part-52#FAR_52_212_3 https://www.acquisition.gov/far/part-52#FAR_52_204_25 https://www.sam.gov/

J06-15

(1) It □ will, □ will not provide covered telecommunications equipment or services to the Government in the performance of any contract, subcontract or other contractual instrument resulting from this solicitation. The Offeror shall provide the additional disclosure information required at paragraph (e)(1) of this section if the Offeror responds "will" in paragraph (d)(1) of this section; and

(2) After conducting a reasonable inquiry, for purposes of this representation, the Offeror represents that—

It □ does, □ does not use covered telecommunications equipment or services, or use any equipment, system, or service that uses covered telecommunications equipment or services.

The Offeror shall provide the additional disclosure information required at paragraph (e)(2) of this section if the Offeror responds "does" in paragraph (d)(2) of this section.

(e) Disclosures.

(1) Disclosure for the representation in paragraph (d)(1) of this provision. If the Offeror has responded "will" in the representation in paragraph (d)(1) of this provision, the Offeror shall provide the following information as part of the offer:

(i) For covered equipment—

(A) The entity that produced the covered telecommunications equipment (include entity name, unique entity identifier, CAGE code, and whether the entity was the original equipment manufacturer (OEM) or a distributor, if known);

(B) A description of all covered telecommunications equipment offered (include brand;

model number, such as OEM number, manufacturer part number, or wholesaler number; and item description, as applicable); and

(C) Explanation of the proposed use of covered telecommunications equipment and any factors relevant to determining if such use would be permissible under the prohibition in paragraph (b)(1) of this provision.

(ii) For covered services—

(A) If the service is related to item maintenance: A description of all covered telecommunications services offered (include on the item being maintained: Brand; model number, such as OEM number, manufacturer part number, or wholesaler number; and item description, as applicable);

or

(B) If not associated with maintenance, the Product Service Code (PSC) of the service being provided; and explanation of the proposed use of covered telecommunications services and any factors relevant to determining if such use would be permissible under the prohibition in paragraph (b)(1) of this provision.

(2) Disclosure for the representation in paragraph (d)(2) of this provision. If the Offeror has responded "does" in the representation in paragraph (d)(2) of this provision, the Offeror shall provide the following information as part of the offer:

J06-16

(i) For covered equipment—

(A) The entity that produced the covered telecommunications equipment (include entity name, unique entity identifier, CAGE code, and whether the entity was the OEM or a distributor, if known);

(B) A description of all covered telecommunications equipment offered (include brand;

model number, such as OEM number, manufacturer part number, or wholesaler number; and item description, as applicable); and

(C) Explanation of the proposed use of covered telecommunications equipment and any factors relevant to determining if such use would be permissible under the prohibition in paragraph (b)(2) of this provision.

(ii) For covered services—

(A) If the service is related to item maintenance: A description of all covered telecommunications services offered (include on the item being maintained: Brand; model number, such as OEM number, manufacturer part number, or wholesaler number; and item description, as applicable);

or

(B) If not associated with maintenance, the PSC of the service being provided; and explanation of the proposed use of covered telecommunications services and any factors relevant to determining if such use would be permissible under the prohibition in paragraph (b)(2) of this provision.

(End of provision)

3.2.4 FAR 52.204-26 Covered Telecommunications Equipment or Services-Representation (OCT 2020)

(a) Definitions. As used in this provision, "covered telecommunications equipment or services" and "reasonable inquiry" have the meaning provided in the clause 52.204-25, Prohibition on Contracting for Certain Telecommunications and Video Surveillance Services or Equipment.

(b) Procedures. The Offeror shall review the list of excluded parties in the System for Award Management (SAM) ( https://www.sam.gov) for entities excluded from receiving federal awards for "covered telecommunications equipment or services".

(c) (1) Representation. The Offeror represents that it □ does, □ does not provide covered telecommunications equipment or services as a part of its offered products or services to the Government in the performance of any contract, subcontract, or other contractual instrument.

(2) After conducting a reasonable inquiry for purposes of this representation, the offeror represents that it □ does, □ does not use covered telecommunications equipment or services, or any equipment, system, or service that uses covered telecommunications equipment or services.

https://www.acquisition.gov/far/part-52#FAR_52_204_25 https://www.sam.gov/

J06-17

3.2.5 FAR 52.212-5 Contract Terms and Conditions Required to Implement Statutes or Executive Orders-Commercial Products and Commercial Services (MAR 2023)

(a) The Contractor shall comply with the following Federal Acquisition Regulation (FAR) clauses, which are incorporated in this contract by reference, to implement provisions of law or Executive orders applicable to acquisitions of commercial products and commercial services:

(1) 52.203-19, Prohibition on Requiring Certain Internal Confidentiality Agreements or Statements (JAN 2017) (section 743 of Division E, Title VII, of the Consolidated and Further Continuing Appropriations Act, 2015 (Pub. L. 113-235) and its successor provisions in subsequent appropriations acts (and as extended in continuing resolutions)).

(2) 52.204-23, Prohibition on Contracting for Hardware, Software, and Services Developed or Provided by Kaspersky Lab and Other Covered Entities (NOV 2021) (Section 1634 of Pub. L. 115-91).

(3) 52.204-25, Prohibition on Contracting for Certain Telecommunications and Video Surveillance Services or Equipment. (NOV 2021) (Section 889(a)(1)(A) of Pub. L. 115-232).

(4) 52.209-10, Prohibition on Contracting with Inverted Domestic Corporations (NOV 2015).

(5) 52.232-40, Providing Accelerated Payments to Small Business Subcontractors (MAR 2023) ( 31 U.S.C. 3903 and 10 U.S.C. 3801).

(6) 52.233-3, Protest After Award (AUG 1996) ( 31 U.S.C. 3553).

(7) 52.233-4, Applicable Law for Breach of Contract Claim (OCT 2004) (Public Laws 108-77 and 108-78 ( 19 U.S.C. 3805 note)).

(b) The Contractor shall comply with the FAR clauses in this paragraph (b) that the Contracting Officer has…

This is the start of the file's text. The full file is on GovTribe.

File details come from the government source that posted it. Updated .