FCHS2_Section_J_Attachment_8_Day_One_OCIO_GeoPlatform.pdf

PDF 669 KB Posted

Attached to
DOI Foundation Cloud Hosting Services (FCHS2) Federal contract opportunity
Solicitation number
140D0423R0002
Issued by
Department of the Interior Departmental Offices Interior Business Center

View the file

Other files for this federal contract opportunity

Other files attached to DOI Foundation Cloud Hosting Services (FCHS2), newest first.
File Type Posted
Sol_140D0423R0002_Amd_0008.pdf PDF
FCHS2_Section_J_Attachment_9_Question_and_Answer_Amd_0008_0008.pdf PDF
Sol_140D0423R0002_Amd_0007.pdf PDF
Sol_140D0423R0002_Amd_0006.pdf PDF
140D0423R0002_0006_0006.pdf PDF
Sol_140D0423R0002_Amd_0005.pdf PDF
Sol_140D0423R0002_Amd_0004.pdf PDF
FCHS2_Section_J_Attachment_07a_Usage_Summary_of_June_2023_Cloud_Services_Amd0003_0003.xlsx XLSX spreadsheet
Amendment_0003_Q_A__Consolidation_Sections_0003.pdf PDF
FCHS2_Section_J_Attachment_07b_Example_Invoice_Template_Amd0003_0003.xlsx XLSX spreadsheet
Sol_140D0423R0002_Amd_0003.pdf PDF
FCHS2_Section_J_Attachment_9_Question_and_Answer_Template_Amd0002_0002.xlsx XLSX spreadsheet
FCHS2_Section_J_Attachment_8_IDIQ_Pricing_Template_Amd0002_0002.xlsx XLSX spreadsheet
FCHS2_Section_J_Attachment_4_Subcontracting_Plan_Template_Amd0002_0002.pdf PDF
RFP_140D0423R0002_Amd0002_0002.pdf PDF
FCHS2_Section_J_Attachment_05_Day_One_BIA_EUMS_Amd0002_0002.pdf PDF
FCHS2_Section_J_Attachment_3_Past_Performance_Questionnaire_Amd0002_0002.pdf PDF
FCHS2_Section_J_Attachment_07_Day_One_USDA_DISC_Amd0002_0002.pdf PDF
FCHS2_Section_J_Attachment_2_OCIO-PAM_Memo_DOI_IT_Baseline_Compliance_Contract_Guidelines_0002.pdf PDF
FCHS2_Section_J_Attachment_06_Day_One_OCIO_GeoPlatform_Amd0002_0002.pdf PDF
FCHS2_Section_J_Attachment_01_Security_Objectives_Service_Level_Agreements_Amd0002_0002.docx DOCX document
Sol_140D0423R0002_Amd_0002.pdf PDF
FCHS2_Section_J_Attachment_0-Amd_0001_0001.pdf PDF
FCHS2_Section_J_Attachment_10-Question_and_Answer_Template_0001.xlsx XLSX spreadsheet
Sol_140D0423R0002_Amd_0001.pdf PDF
FCHS2_Section_L_Instructions__Conditions__Notices.pdf PDF
FCHS2_Section_J_Attachment_7_Day_One_NPS_Volunteer.pdf PDF
FCHS2_Section_J_Attachment_3_Past_Performance_Questionnaire.pdf PDF
FCHS2_Section_J_Attachment_0.pdf PDF
FCHS2_Section_I_Contract_Clauses.pdf PDF
FCHS2_Section_G_Contract_Administration_Data.pdf PDF
FCHS2_Section_C_Statement_of_Work.pdf PDF
FCHS2_Section_K_Representations__Certifications__and_Other_Statements_of_Offeror.pdf PDF
FCHS2_Section_B_Supplies__Services_and_Costs.pdf PDF
FCHS2_Section_J_Attachment_6_Day_One_NPS_CLP.pdf PDF
FCHS2_Section_J_Attachment_5_Day_One_BIA_EUMS.pdf PDF
FCHS2_Section_M_Evaluation_Factor_for_Award.pdf PDF
FCHS2_Section_J_Attachment_4_Subcontracting_Plan_Template.pdf PDF
FCHS2_Section_E_Inspection_and_Acceptance.pdf PDF
Sol_140D0423R0002.pdf PDF
FCHS2_Section_F_Deliverables_or_Performance.pdf PDF
FCHS2_Section_J_Attachment_9_Day_One_USDA_DISC.pdf PDF
FCHS2_Section_J_Attachment_2_OCIO-PAM_Memo_DOI_IT_Baseline_Compliance_Contract_Guidelines.pdf PDF
FCHS2_Section_J_Attachment_1_Security_Objectives_-_Service_Level_Agreements.pdf PDF
FCHS2_Section_H_Special_Contract_Requirements.pdf PDF
FCHS2_Section_D_Packaging_and_Marketing.pdf PDF
Show all 46

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

Foundation Cloud Hosting Services II (FCHS2) Section J

D-1

SECTION J – ATTACHMENT 08

Introduction Day One Use Case – OCIO-GeoPlatform

OGIO GeoPlatform https://www.geoplatform.gov and OSMRE https://geomine.osmre.gov/

The Department of the Interior (DOI) has prepared this Day One Use Case to support the Office of the Chief Information Officer (OCIO), Office of the Geospatial Information Officer (OGIO) to provide license and support services for DOI’s managed GeoPlatform cloud environment beyond the contract life of the existing Foundation Cloud Hosting Services (FCHS) contract.

Services may include cloud migration, modernization, and improvements in efficiency, agility, innovation, and sustainability.

DOI GIS Priorities covered by this Day One Use Case are listed below in descending order of importance:

1. Cloud Environment and automated maintenance of over 40 accounts.

2. STIG compliant machine images

3. Solution providing both ESRI ArcGIS and Open Source Geospatial Foundation (OSGEO) technology stacks as well as support for MapBox , CKAN , Top Quadrant , CARIS, Bentley, Trimble, Carto (NPS), Rstudio (FWS ECOS), Burp Suite Pro (GP), Voyager (USACE

DISDI), and Esri (USACE)

4. Information Technology Security

5. Program and Project Management

6. Multi-agency collaboration

7. Cloud Migration and migration strategy equivalent to AWS US East / West IaaS and PaaS cloud environment that encompasses licenses and provisioning service for existing

GeoPlatform. During migration, the Department will be required to fund both the existing environment and new environment. With this overlap requirement in mind, what is your approach and practices to shorten the overall migration window while successfully meeting the SOO requirements above.

8. Contractor included VM +

Background

The GeoPlatform at https://www.geoplatform.gov was developed by the agencies of the Federal

Geographic Data Committee (FGDC) through collaboration with partners and stakeholders. The target audience for GeoPlatform includes Federal, State, local, and Tribal governments, private sector, academia and the general public. GeoPlatform offers open geospatial hosting and services on an AWS managed environment. The strategy is to support the Administration’s Open

Government, Open Data and Digital Government strategies to enhance transparency, collaboration, and participation. The cross-agency collaborative effort and shared service operates under the authority of the Geospatial Data Act of 2018. It provides access to 100,000 open geospatial data assets and includes services, applications, and community tools for over 30

Federal agencies.

The OSMRE GeoMine is an interactive web-based mapping application that supports the Surface https://www.geoplatform.gov/ https://www.geoplatform.gov/

D-2

Mining Control and Reclamation Act (SMCRA) by providing public access to surface coal mining and reclamation geospatial data within the United States. It merges data from numerous state and federal sources to create standardized, seamless layers that cross state boundaries.

GeoMine is based on ESRI technology and heavily uses FME to pull data from multiple data sources into the system.

Period and Place of Performance

The base Period of Performance will be two years beginning from the date of award and four two-year option periods. The life expectancy of this project is ten years. Services will be performed remotely.

Current Environment

The current GeoPlatform environment is built on a FedRAMP authorized Amazon US East/West

IaaS/PaaS/SaaS. GeoPlatform is listed as FISMA Moderate and stores some sensitive personally identifiable information (PII) including name, username, and email. See GeoPlatform PIA -https://www.doi.gov/sites/doi.gov/files/geoplatform-pia-06162022.pdf The environment current supports 32 different organizations and has been in service since 2011.

Geoplatform AWS hosting environment is complex and consists generally of the following resources

• AWS VPC – 850 virtual private clouds with 3000 subnets

• AWS EC2 Instances – 400 running linux and windows server

• AWS EBS volumes - 1200 comprising 250 TB storage

• AWS S3 Buckets – 1000 buckets comprising 40m objects and 10TB storage

• AWS RDS Instances – 170 Oracle, PostGres, SQL Server comprising 60 TB storage

• AWS Autoscaling Groups – 60

• AWS Configuration channels – 40

• AWS Certificates managed – 110

• AWS Cloud Formation Stacks – 1200

• AWS Cloud Front Distributions – 50

• AWS Elastic Beanstalk – 25 applications

• AWS Elastic Container Service – 90 clusters with 150 tasks

• AWS IAM – 1400 users, 1000 groups

• AWS Key Management – 600 keys

• AWS Lambda – 550 functions

• AWS Route 53 – 40 zones

Scope

The proposed services will include providing ongoing IaaS, PaaS, and SaaS cloud license and support services for an existing mature multi-agency, multi-tenant cloud environment. DOI does not anticipate significant cloud-to-cloud migration, technology refresh, or tenant enhancements being required, but welcomes proposed solutions.

The Statement of Objectives described below addresses work scope associated with the

D-3 following activities:

• If cloud migration is proposed, contractor shall include migration mapping and architecture of new cloud environment.

• Contractor to provide FedRAMP authorized GIS Hosting Services compatible and/or equivalent to the existing AWS US East/West IaaS and PaaS cloud environment that encompasses licenses and provisioning services for the existing GeoPlatform applications and datasets.

• Contractor to provide requirements and optional recommendations (and separated line-item pricing) for the most effective industry/service model to meet a multi-agency tenant, best architecture configuration, automation, and management tools.

• Contractor provided solution must support both the ESRI ArcGIS and Open-Source

Geospatial Foundation (OSGEO) technology stacks.

• Contractor to separate base cost of Moderate Level IaaS license and basic services environment prior to any bundling, development, imaging, and provisioning configurations listed below. Basic environment shall be configured with SLAs only e.g., availability, IPv6, VM operating systems, self-provisioning storage, backup retention 30-days, term storage 3 years.

• Contractor to provide STIG complaint machine images

(1) suited to best support the GIS industry and support ESRI server images,

(2) automatically provision ArcGIS Server/Desktop VMs when on-demand thresholds triggered,

(3) automate installation of ArcGIS Server/Desktop on new machines (<1 hr),

(4) allow for reusable virtual machines (VM) that do not duplicate licensing or data files,

(5) manage and deploy images containing ArcGIS Server

(6) manage and deploy images to be used for ArcGIS Server and Geodatabase administration purposes.

(7) manage and maintain ESRI Kubernetes Cluster

(8) manage and maintain including database administration for SQL Server, Oracle, and PostGRES databases

• Contractor to meet IaaS/PaaS OpenGeo Suite requirements:

(1) Environment to include and automatically provision OpenGeo software suite (< 1 hr)

• Contractor to support configuration, operation, and monitoring of other Commercial Off

The Shelf (COTS) geospatial software including software from the following vendors

(1) ESRI

(2) MapBox

(3) CKAN

(4) Top Quadrant

(5) CARIS

(6) Bentley

i. Trimble

ii. Carto

iii. Rstudio

(7) Burp Suite Pro

(8) Voyager

D-4

• Contractor to include in VM

(1) operating system license with elastic, redundant, dynamic computing capabilities,

(2) built-in AI acceleration to dynamically scale processors

(3) ability to create VM templates, allowing different customers to define their own

VM images and upload them,

(4) ability to remotely load applications and data onto VM from Internet,

(5) support a secure administration interface using the latest TLS/SSH transport security,

(6) capability to dynamically reallocate VM with no service interruption,

(7) capability to copy/clone VM for archiving, troubleshooting, and testing

• Contractor to provide the ability for administrators to provision requirements including

(1) VMs storage, servers, operating systems, bandwidth, compute services, backup/retention cycles,

(2) Setting dynamically and instantaneously provisioned/de-provisioned compute services triggered by on-demand requests.

• Contractor to provide the following network requirements including

(1) Capability to implement and manage network load balancing,

(2) Provide load balancer health checks, such as allowing non-responsive machines to be dropped from group,

(3) Support Internet bandwidth of at least 1 Gb/s,

(4) Allow for dynamic (elastic or multiple per network interface) IP addressing,

(5) Provide option to create isolated virtual private network, allowing customer to assign their own IP address ranges, create subnets and routing tables that can limit connectivity, isolate servers by role,

(6) Provide re-assignable static Ips for virtual machines

• The Contractor shall provide multi-agency collaboration and segment flexibility

(1) Establish naming conventions to individually identify tenant groups and compute services

(2) manage data isolation in a multi-tenant environment

(3) provide on-line usage and billing capability allowing customers to see and track the status of invoices based on their specific usage

(4) provide dashboard for monitoring resource utilization and other events and logs such as failure of service, degradations in service, peak usage, backups, and other environmental health thresholds,

(5) provide point in time backups while in use and database as a service backups to allow for point in time as well as regularly scheduled nightly backups

Objectives

1. Business

The following are Business Objectives:

• If Migration Services are proposed- Migration and Provisioning Objectives:

o Enable strategic decisions by the Department to effectively migrate applications to the cloud, maximizing cost reduction and efficiency of IT environment.

o Provide maximum alignment to FDCCI requirements and cloud migration mandates and requirements, amplifying the Departments ability to achieve management

D-5 objectives.

o Provide cloud migration services that accommodate considerations from an enterprise perspective including impact on the Departments’ business units, contracts, management, and technical components.

o Provide all support operations necessary to fully develop and deliver services for each acquisition phase.

• If Application Mapping and Assessment is proposed - Application Mapping and

Assessment o Provide work products for application mapping that result in the Programs understanding of the benefits and implications of moving individual applications or groups of applications to the cloud.

o Produce “quick win” analysis of applications that are well-suited for accelerated deployment to the cloud and provide recommendations for executing this migration.

• If Migration Services are proposed- Migration Planning

The IT Systems, bureaus, offices, and agencies currently residing within the GeoPlatform environment have a wide span of technical configurations. The list below is an outline of these

IT Systems. The Contractor should propose a migration plan, including timeline, kickoff meeting, activities, and any unique considerations to accommodate a phased approach.

Please document the migration strategy and length of time required beginning with the date of award, until the end of the migration timeline. Migration should begin with GeoPlatform.gov and

OSMRE GeoMine. Once these two projects are successfully migrated and stable the migration of other projects may begin. All migrations must be completed by October 2024.

To help plan and communicate with IT System personnel, the Contractor shall work with the

GeoPlatform team to identify which of the following IT Systems they recommend for each phase. The Contractor shall identify any preparations required by the government prior to their respective migration phase. Likewise, the Contractor shall identify expectations, disruptions, communications requirements, required by the government during their respective migration phase. The Contractor should submit any additional questions prior to award to assist with migration discovery.

o Produce a roadmap for the Program to effectively plan for cloud migration that maximizes cost reduction and identifies constraints and inhibitors to cloud migration.

o Describe a business case comparison of current expenditures to proposed expenditures, demonstrating ROI of proposed solution.

o Provide a migration plan describing recommendations for service models (SaaS, PaaS, or IaaS), and deployment model (private, public, community, etc.).

o Describe applications’ development lifecycle, business relevance, security impacts, organizational roles, financial aspects of cloud service delivery, and other migration considerations.

o As of February 2, 2023, there are 43 funded GeoPlatform programs that will potentially require migration. At time of contract award there may be more or less

D-6 programs.

All of the following projects utilize technologies identified under the current environment above.

They are:

1. United States Geological Survey () Web Informatics and Mapping (WiM)

a. Multiple VPCs with multiple environments supporting ESRI GIS software.

Includes high visibility / high priority emergency common operating picture applications

2. Trails

a. Consolidated trails across the country along with applications to develop new trails based on elevation, proximity and land data.

3. Bureau of Ocean Energy Management (BOEM) GeoSEAS

a. Data and applications for multiple operational units of BOEM

4. Federal Emergency Management Agency (FEMA) Disasters

a. Multiple applications in support of response and recovery of federally declared disasters.

5. FEMA RMD

a. Primarily ESRI infrastructure for Risk Management data

6. Fish and Wildlife Service (FWS) TRACS

a. ESRI GIS infrastructure in support of USFWS tracking and reporting for conservation species

7. FWS ECOS

a. Multiple applications in support of wildlife and habitat management

8. FWS Sandbox

a. Development environment for USFWS applications

9. FWS IRIS

a. A set four database driven applications supporting the USFWS Integrated Refuge

Information System

10. FWS BGDS

a. ESRI Server environment supporting a wide variety of USFWS geographic data services

11. FWS South Atlantic Simple Viewer (SA)

a. Fish and Wildlife refuge and project mapping and tracking

12. Office of Service Mining and Reclamation Enforcement (OSMRE) GeoMine

a. Data for surface and subsurface coal mine operations

13. Federal Geographic Data Committee (FGDC) GeoPlatform

a. Shared service metadata catalog and applications, GeoPlatform.gov

14. FGDC GeoPlatform Imagery Data Management (IDM)

a. Open source software for processing and management of UAS data

15. Bureau of Reclamation (BOR)

a. GIS for infrastructure and water management

16. BOR BORGIS

a. ESRI GIS Server environment in support of California great basin restoration

California Great Basin Restoration

17. United States Army Corps of Engineers (USACE) CWBI / IL4

a. A set of one dozen or more VPCs with both 50+ endpoints and PIV controlled

D-7 systems

b. Security and compliance are at DoD Cloud Impact Level 4

c. Oracle databases as EC2 and RDS

d. Multiple platforms including oracle APEX, REACT, cold fusion,

18. USACE DISDI/IL4

a. Defense Installation Spatial Data Infrastructure

b. ESRI and other applications in multiple VPCs

c. Requires DISA Cloud Access Point

d. Requires STIG compliance for DoD impact level 4

19. USACE Dam and Levee Safety

a. Applications and services consisting of mainly cloud native code

20. USACE Data Catalogue

a. Kubernetes deployment of bespoke code for managing metadata using similar software to DOI IDM

21. USACE IENC CARIS

a. Oracle database, vendor server software and appstream envrionment for maintaining inland electronic navigation charts

22. USACE ArcGIS

a. Multiple instances of full ESRI server stack with multiple data stores and appstream desktops

23. Office of Natural Resources Revenue (ONRR) TopBraid

a. Wildfire ontology and multi-agency coordination

24. National Park Service (NPS)

a. GIS for web applications and physical map production

25. NPS Unstable Slope Management Program (USMP)

a. Application to analyze slope stability for road maintenance

26. Office of Aviation Services (OAS) Safecom

a. Application to manage manned and UAS operations in support of DOI and the fire community

b. Relatively small environment consisting of cloud native code and postgres rds

27. US Dept of Agriculture (USDA)/ Interdepartmental Imagery Publication Platform (IIPP)

a. Kubernetes deployment to manage and serve NAIP imagery

28. US Environmental Protection Agency (EPA) National Hydrograhic Dataset Plus

(NHD+), part of the GeoPlatform program

a. National hydro dataset and applications

29. Bureau of Trust Fund Administration (BTFA)

a. Applications in support of Tribal financial data and management

30. Office of Emergency Management (OEM) SHIRA

a. Department of the Interior Common Operating Picture for situational awareness and emergency operations.

31. Office of Wildland Fire (OWF) TopBraid

a. Graph database managing wildfire operations

32. National Geospatial-Intelligence Agency (NGA)

a. Used to transfer and make unclassified data available to the federal govt.

33. Bureau of Indian Affairs (BIA) Bureau of Geospatial Support (BOGS)

a. Multiple applications and GIS data supporting BIA operations

D-8

34. BIA SmartSheets

a. Acquire and support SmartSheets Software As A Service (SAAS) for Bureau of

Indian Affairs

35. Office of the Chief Information Officer (OCIO) Controlled Unclassified Information

(CUI)

a. DOI metadata catalog

36. Office of Management and Budget (OMB) Economic Justice Screen Tool

a. New environment for Explore the map - Climate & Economic Justice Screening

Tool (geoplatform.gov)

37. OSMRE Abandon Mine Land Inventory System (e-AMILS)

a. GIS and financial data for abandoned mine reclamation activities

38. USFS Imagery Data Manager (IDM)

a. Same environment as number 15 but billed separately

2. Management / Key Personnel

The following are Management objectives:

• Provide a Senior project manager that is the primary point of contact for the government.

Senior PM may need to supervise multiple Project Managers and technical experts as well as subcontractors as needed.

• Provide a financial specialist to work directly with the Government Contracting Officer and Contracting Officer Representatives. Ideally the financial specialist has experience with Federal contracting.

• Provide senior cloud architect with documented certifications and extensive experience in design and implementation of secure cloud computing architecture.

• Provide senior geospatial solution architect and or geospatial systems administrator with extensive experience implementing full suite of ESRI software in cloud hosted environment for large data programs.

• Provide senior database administrator with deep understanding and experience with database design, database security, database monitoring and database tuning with one or more of the following RDBMS systems: SQL Server, Oracle RDBMS, PostGres

• Provide a Cybersecurity Analyst who is the primary point of contact for cloud system security. The cybersecurity analyst will work with the GeoPlatform Executive

Management Team.

• Provision to allow maximum flexibility to innovatively manage program cost, schedule, performance, risks, warranties, contracts and subcontracts, vendors, and data required to deliver effective migration services.

• Maintain clear government visibility into program cost, schedule, technical performance, and risk, including periodic reporting.

• Provide meaningful reporting and analytics that provide the Program with up-to-date and comprehensive information regarding technical and management performance.

Reporting includes weekly program meetings and quarterly project meetings with the projects in the GeoPlatform environment.

• Provide a brief description on the management of any subcontractor relationships and contracts. Outline the roles and responsibilities per party involved in the service and where key responsibilities reside.

• Provide a transition plan detailing milestones, activities, and timelines for the migration https://screeningtool.geoplatform.gov/en/#3/33.47/-97.5 https://screeningtool.geoplatform.gov/en/#3/33.47/-97.5

D-9 and provisioning of services.

• Maintenance of architecture diagrams for the GeoPlatform and projects in the

GeoPlatform cloud environment.

3. Administrative

The following are Administrative objectives:

• Quality Assurance: Provide a draft Quality Assurance Surveillance Plan (QASP) and/or

Quality Control Plan (QCP) that shall include details for measuring performance and deliverables with metrics that may include data availability, storage capacity, uptime, etc.

These documents are to be correlated with the “as-is” and “to-be” environments provided in Sections 5.1 and 5.2 above.

• Invoicing: Provide accurate monthly invoices on a timely basis, as well as monitor each program’s CLIN fund use giving a 4 month warning time for any projects in danger of running out of funding.

4. Technical

The following are Technical objectives:

• Provide cloud environments (e.g., IaaS, PaaS, etc.) for production purposes to support the complete systems lifecycle. Cloud environments should be standardized as much as possible to allow interoperability. Environments should be the equivalent of AWS Band

2-4 with most at a Band 3.

• Provide cloud support and/or governance services, including assigning responsibility for authorizing individual instances for provisioning.

• Provide open-standards based technologies whenever possible to provide interoperability.

Specific standards considered include:

o Open Virtualization Format (OVF) – applicable only to IaaS virtual machines o Cloud Data Management Interface (CDMI) o Open Cloud Computing Interface (OCCI)

• Provide backup, recovery and disaster recovery procedures and processes in the cloud environment for the target applications and services that support the following objectives:

o Recovery Time Objective (RTO) – ability to recover files within < 24 hours of request.

o Recovery Point Objective (RPO) - ability to recover files for any specific day within a rolling two (2) month period.

o Mean Time to Repair (MTTR) – the elapsed recovery average time required to complete a restore request is set for < 24 hours.

o Data Backup Location – Data backups maintained or replicated at a site geographically 250-miles disparate from the production site such that the loss of one data center does not prohibit recovery of data within the prescribed RTO.

• Provide support for data storage tiers between live, at-rest, archive, etc.

• Provide complete support for IPv6 within the cloud environments provided.

• Contractor will provide continuous monitoring and reporting to demonstrate effective cloud cost control. The contractor must demonstrate that they avoid over provisioning of server resources, idle instances, and abandoned resources that resulting in unnecessary expense to the government. Contractor will report monthly

D-10 on all resources across all accounts demonstrating that resources are optimally provisioned, or configured to meet specific customer requirement, and identifying opportunities to further reduce costs.

• While support is generally required during business hours, the contractor should be prepared in unusual / emergent cases to work evenings and weekends when requested. Cases would be presidentially declared disaster requires unplanned support. CISA indicates urgent cyber security threat requires immediate remediation.

Other customer emergency when validated through contract officer representative

• All software, scripts, playbooks, notes, guidance, briefings, diagrams, or reports whether in prototype, draft or final form, when prepared for any activity under this task order must be managed in government specified code and document repositories.

All items in the repositories are explicitly government property and may be immediately shared by the government across projects, with other vendors, or with the public at government discretion. The vendor may make no claim of intellectual property for any work conducted under this task order

Security

In addition to the itemized list below, all Security and Privacy requirements under this task order shall comply with the FCHS2 base contract. Proposals should include either acceptance or alternate metrics as appropriate for cloud compute services under this task order.

• Provide support and services in compliance and alignment with Federal Risk and

Authorization Management Program (FedRAMP) standardized security assessment, authorization, and continuous monitoring policies as required by the scope of the project.

• Provide migration services regarding security and privacy that are consistent with the

NIST Special Publication 800-144 – “Guidelines on Security and Privacy in Public Cloud

Computing”

• Provision services to manage FISMA MODERATE security and privacy risk for the IT

Systems life-cycle that are consistent with NIST Special Publication 800-37 and NIST

Special Publication 800-53.

• Provide a security plan focused on end-to-end integration points, including data in transit and at rest.

• Provide support for specified auditable events related to the applications or services.

• Properly secure connections between co-located systems and integrations consistent with

Trusted Internet Connection 3.0 or DISA BCAP as needed

• Provide role-based access controls through identity and access mechanisms for rights and privileges to Cloud services for the customer environment.

• Support DOI and other federal agency Enterprise Active Directory Authentication utilizing SAML (see Section 2.7.8) as well as external SAML authentication providers, including login.gov

• Provide multi-factor authentication to the configuration interfaces of Cloud services for the customer environment using login.gov or other source

• Provide logging, monitoring, auditing, and reporting for Cloud service offerings as specified in section 2.7 https://nvlpubs.nist.gov/nistpubs/Legacy/SP/nistspecialpublication800-144.pdf https://nvlpubs.nist.gov/nistpubs/Legacy/SP/nistspecialpublication800-144.pdf https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-37r2.pdf https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r5.pdf https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r5.pdf

D-11

• Monthly scanning and reporting for all environments

Service Level Agreements

Provide end-to-end monitoring capability and reporting for service level agreement (SLA) requirements and metrics.

• Accessibility: Applications and services that fall under the Information and

Communication Technology (ICT) services shall comply with Section 508 of the

Rehabilitation Act and Web Content Accessibility Guidelines (WCAG).

• Availability: Provide cloud services compliant with the Secure Software Development

Framework (SSDF) – Supply Chain Security.

• Cloud services should be fully operational 99.90% and scheduled maintenance, downtime, patching, and other implementations potentially affecting availability will be pre-coordinated and transparent to the Program.

• Performance: Provision services to permit visibility to monitor and manage variations in performance metrics, e.g., on-demand services available, adaptation to demand fluctuations, role filtered tools to support billing and service functions, peak usage and historical average reports, alarms and logging dashboards, automated reporting metrics/failures, etc.

• Continuous Monitoring: Provide Security Assessment Plan and Security Assessment

Report according to NIST SP 800-53. Provide Continuous Monitoring Plan (CMP), with included Plan of Actions and Milestones (POAMs) consistent with NIST SP 800-137.

• Service Center: Provide default available tiers and types of Service Centers including trouble ticketing and business operations. Provide contact links and phone numbers for initiating contact with Online Support Site “reading room”, 800 number, Help Desk, chat, task order support, etc. Provide days, hours, and time zones available. Provide “mean time to” response services between (1) routine, (2) Mission Priority, and (3) Emergency

(health and safety)

• Additional Services: At vendors discretion, provide optional additional support services available and/or recommended not included in standard licensing. Provide description, line items, and cost separately and clearly labelled as optional on task order proposal.

• Service Reliability: Deliver a Disaster Recovery Plan for each CSP that includes (at a minimum) service resilience, fault tolerance, customer data backup and restore, and disaster recovery reliability. Describe Network Configuration Management features to meet reliability standards; e.g., change management, login attempt log, idle timeout, syslog events, routine backups, etc.

• Backup and Restore: Describe backup routines, frequency, and types available. Describe the length of times and states for retention. Describe FIPS 140-3 encryption and other measures implemented for the protection of sensitive and valuable data. Backup solutions must be agentless architecture solution, meet 100TB backup capacity in under 8 hours, scalable into petabyte range, test and verify without having to restore, ability to launch

VM directly from de-duplicated compressed backup, provide end-to-end AES encryption.

• Data Management: Provide Control Implementation Summary (CIS) and Customer

Responsibility Matrix (CRM) of all security controls at the appropriate Low, Moderate, High environment level according to NIST SP 800-53 rev 5. Describe CSP versus customer responsibilities. Provide security for both data in transit and at rest. Select CSP within the Continental United States, Hawaii, Alaska, Puerto Rico, Guam, and Virgin

D-12

Islands with geographical separation of at least 250- miles. Provide support for auditable events to the applications and/or services.

• Incident Response: Follow IR procedures for all privacy breaches and take immediate action (within 1 hour when identified) to contain and mitigate the impact of breach and cooperate with Government officials. Contractor shall document 1) programs/platforms,

2) location of breach, 3) date/time, 4) nature of event/loss/unauthorized access, 5) summary description, 6) number of users impacted, 7) estimated records, 8) data sets affected.

Submit email regardless of time or day to:

▪ Department of the Interior - Computer Incident Response Center (DOI-CIRC) at doicirc@ios.doi.gov and 703-648-5655. For non-DOI agencies, submit to their equivalent

▪ Contracting Officer

▪ Authorizing Official and/or System Owner

▪ Information System Security Officer and/or Cloud Service Provider portal within max.gov

Constraints

• Access Control: Cloud Service Provider has capacity to meet Federal Records

Management Requirements, including ability to support record holds, National

Archives and Records Administration (NARA) requirements, and Freedom of

Information Act (FOIA) requirements;

o Contractor shall not remove PII or Privacy Act material from Government facilities or systems, or facilities or systems operated or maintained on the

Government’s behalf, without the express written permission of the Head of the

Contracting Activity.

o Contractor may be required to provide necessary support to assist the Government in meeting the requirements of the Privacy Act and related laws and shall cooperate to provide supporting documentation and access to information upon request by authorized agency officials.

o Provision services to protect Federal records appropriately and protect them from unauthorized removal from the Department’s custody, including the handling of records containing information exempt from disclosure under the Freedom of

Information Act (FOIA) (5 U.S.C. 552), the Privacy Act (5 U.S.C. 522a)

• Intellectual Property: Ensure the protection of government intellectual property (IP) and data ownership rights and those of any licensors. They shall identify and provide visibility of IP owned and managed components by them or the cloud service provider.

Unless otherwise noted by contractor and government all data is owned by government.

• Origin of DNS: Cloud Service Provider’s external DNS security (DNSSec) provides origin authentication and integrity verification.

• Authentication: Seamlessly integrate with the Agency Identity, Authorization and Access

Management (IdAAM) solution that consists of the Microsoft Active Directory (AD) and

Public Key Infrastructure (PKI) architecture and associated Certificate Authority and

DOI HSPD-12 PIV SmartCard-based credentials.

o Provide dual-factor communication channel for cloud environment management to support Federated SAML 2.0 Government’s PIV Card authentication consistent mailto:doicirc@ios.doi.gov

D-13 with OMB M-11-11 “Continued Implementation of HSPD-12 for Common

Identification Standard for Federal Employees and Contractors” o Provide phishing-resistant “Identify Authentication” single sign-on credentialing options for external facing customer services consistent with M-22-09 “Moving the U.S. Government Toward Zero Trust Cybersecurity Principles” o Contractor Personnel: Contractors authenticating into Agency cloud services shall also comply with Homeland Security Presidential Directive (HSPD-12) that require all federal entities and associated contractors have security background investigations equivalent to federal employees. Background investigations will be performed by the Office of Personnel Management (OPM).

Prohibitions:

• Adware: DOI requests contractors to refrain from and to actively prevent adware, spam, and remarketing of information. The Contractor shall not engage in nor permit its agents to push adware, software, or marketing not explicitly authorized by the Agency. The

Contractor and/or their agents shall not resell nor otherwise redistribute information gained from its access to contract users.

• Non-Disclosure Agreements: Contractors shall require each of their administrative employees that interfaces with the cloud services customized applications and government data to sign non-disclosure agreements at onset of project implementation.

Non-disclosure agreements will be supplied by the Contracting Officer, or the Contractor may elect equivalent and approved alternative.

• Government Banners: A government approved logon banner must be displayed on the first page of any public access web pages. Logon warning banners must be automatically incorporated into IT Systems initial logon process and require periodic credentialed acceptance for all (federal and contractor) personnel accessing the federal IT System.

SECTION 3. CLAUSES.

1. FAR 52.252-2, CLAUSES INCORPORATED BY REFERENCE (FEB 1998)

The following clauses are hereby incorporated by reference. The full text version can be found at https://acquisition.gov/far/index.html.

• FAR 52.203-17 CONTRACTOR EMPLOYEE WHISTLEBLOWER RIGHTS AND

REQUIREMENT TO INFORM EMPLOYEES OF WHISTLEBLOWER RIGHTS (JUN

2020)

• FAR 52.212-4 CONTRACT TERMS AND CONDITIONS – COMMERCIAL PRODUCTS

AND COMMERCIAL SERVICES (DEC 2022) and it’s ALTERNATE I (NOV 2021).

• FAR 52.232-18 AVAILABILITY OF FUNDS (APR 1984)

• FAR 52.232-39 UNENFORCEABILITY OF UNAUTHORIZED OBLIGATIONS (JUN

2013)

2. CLAUSES AND PROVISIONS IN FULL TEXT

1. FAR 52.203-18 Prohibition on Contracting with Entities That Require Certain Internal

Confidentiality Agreements or Statements-Representation (JAN 2017)

(a) Definition. As used in this provision-

D-14

Internal confidentiality agreement or statement, subcontract, and subcontractor , are defined in the clause at 52.203-19, Prohibition on Requiring Certain Internal Confidentiality Agreements or

Statements.

(b) In accordance with section 743 of Division E, Title VII, of the Consolidated and Further

Continuing Appropriations Act, 2015 (Pub. L. 113-235) and its successor provisions in subsequent appropriations acts (and as extended in continuing resolutions), Government agencies are not permitted to use funds appropriated (or otherwise made available) for contracts with an entity that requires employees or subcontractors of such entity seeking to report waste, fraud, or abuse to sign internal confidentiality agreements or statements prohibiting or otherwise restricting such employees or subcontractors from lawfully reporting such waste, fraud, or abuse to a designated investigative or law enforcement representative of a Federal department or agency authorized to receive such information.

(c) The prohibition in paragraph (b) of this provision does not contravene requirements applicable to Standard Form 312, (Classified Information Nondisclosure Agreement), Form 4414 (Sensitive

Compartmented Information Nondisclosure Agreement), or any other form issued by a Federal department or agency governing the nondisclosure of classified information.

(d) Representation. By submission of its offer, the Offeror represents that it will not require its employees or subcontractors to sign or comply with internal confidentiality agreements or statements prohibiting or otherwise restricting such employees or subcontractors from lawfully reporting waste, fraud, or abuse related to the performance of a Government contract to a designated investigative or law enforcement representative of a Federal department or agency authorized to receive such information (e.g., agency Office of the Inspector General).

(End of provision)

2. FAR 52.204-21 Basic Safeguarding of Covered Contractor Information Systems (NOV 2021)

(a) Definitions. As used in this clause—

Covered contractor information system means an information system that is owned or operated by a contractor that processes, stores, or transmits Federal contract information.

Federal contract information means information, not intended for public release, that is provided by or generated for the Government under a contract to develop or deliver a product or service to the Government, but not including information provided by the Government to the public

(such as on public websites) or simple transactional information, such as necessary to process payments.

Information means any communication or representation of knowledge such as facts, data, or opinions, in any medium or form, including textual, numerical, graphic, cartographic, narrative, or audiovisual (Committee on National Security Systems Instruction (CNSSI) 4009).

Information system means a discrete set of information resources organized for the collection, processing, maintenance, use, sharing, dissemination, or disposition of information ( 44 U.S.C. 3502).

Safeguarding means measures or controls that are prescribed to protect information systems.

(b) Safeguarding requirements and procedures.

(1) The Contractor shall apply the following basic safeguarding requirements and procedures to protect covered contractor information systems. Requirements and procedures for basic safeguarding of covered contractor information systems shall include, at a minimum, the following security controls:

(i) Limit information system access to authorized users, processes acting on behalf of authorized users, or devices (including other information systems).

(ii) Limit information system access to the types of transactions and functions that authorized users are permitted to execute.

(iii) Verify and control/limit connections to and use of external information systems.

(iv) Control information posted or processed on publicly accessible information systems.

(v) Identify information system users, processes acting on behalf of users, or devices.

https://www.acquisition.gov/far/part-52#FAR_52_203_19 http://uscode.house.gov/browse.xhtml;jsessionid=114A3287C7B3359E597506A31FC855B3

D-15

(vi) Authenticate (or verify) the identities of those users, processes, or devices, as a prerequisite to allowing access to organizational information systems.

(vii) Sanitize or destroy information system media containing Federal Contract

Information before disposal or release for reuse.

(viii) Limit physical access to organizational information systems, equipment, and the respective operating environments to authorized individuals.

(ix) Escort visitors and monitor visitor activity; maintain audit logs of physical access; and control and manage physical access devices.

(x) Monitor, control, and protect organizational communications

(i.e., information transmitted or received by organizational information systems) at the external boundaries and key internal boundaries of the information systems.

(xi) Implement subnetworks for publicly accessible system components that are physically or logically separated from internal networks.

(xii) Identify, report, and correct information and information system flaws in a timely manner.

(xiii) Provide protection from malicious code at appropriate locations within organizational information systems.

(xiv) Update malicious code protection mechanisms when new releases are available.

(xv) Perform periodic scans of the information system and real-time scans of files from external sources as files are downloaded, opened, or executed.

(2) Other requirements. This clause does not relieve the Contractor of any other specific safeguarding requirements specified by Federal agencies and departments relating to covered contractor information systems generally or other Federal safeguarding requirements for controlled unclassified information (CUI) as established by Executive Order 13556.

(c) Subcontracts. The Contractor shall include the substance of this clause, including this paragraph

(c), in subcontracts under this contract (including subcontracts for the acquisition of commercial products or commercial services, other than commercially available off-the-shelf items), in which the subcontractor may have Federal contract information residing in or transiting through its information system.

(End of clause)

3. FAR 52.204-24 Representation Regarding Certain Telecommunications and Video Surveillance

Services or Equipment (NOV 2021)

The Offeror shall not complete the representation at paragraph (d)(1) of this provision if the Offeror has represented that it "does not provide covered telecommunications equipment or services as a part of its offered products or services to the Government in the performance of any contract, subcontract, or other contractual instrument" in paragraph (c)(1) in the provision at 52.204-26, Covered Telecommunications

Equipment or Services—Representation, or in paragraph (v)(2)(i) of the provision at 52.212-

3, Offeror Representations and Certifications-Commercial Products or Commercial Services.

The Offeror shall not complete the representation in paragraph (d)(2) of this provision if the Offeror has represented that it "does not use covered telecommunications equipment or services, or any equipment, system, or service that uses covered telecommunications equipment or services" in paragraph (c)(2) of the provision at 52.204-26, or in paragraph (v)(2)(ii) of the provision at 52.212-3.

(a) Definitions. As used in this provision—

Backhaul, covered telecommunications equipment or services, critical technology, interconnection arrangements, reasonable inquiry, roaming, and substantial or essential component have the meanings provided in the clause 52.204-25, Prohibition on Contracting for Certain Telecommunications and Video

Surveillance Services or Equipment.

(b) Prohibition. (1) Section 889(a)(1)(A) of the John S. McCain National Defense Authorization Act for Fiscal Year 2019 (Pub. L. 115-232) prohibits the head of an executive agency on or after August 13, 2019, from procuring or obtaining, or extending or renewing a contract to procure or obtain, any https://www.acquisition.gov/far/part-52#FAR_52_204_26 https://www.acquisition.gov/far/part-52#FAR_52_212_3 https://www.acquisition.gov/far/part-52#FAR_52_212_3 https://www.acquisition.gov/far/part-52#FAR_52_204_26 https://www.acquisition.gov/far/part-52#FAR_52_212_3 https://www.acquisition.gov/far/part-52#FAR_52_204_25

D-16 equipment, system, or service that uses covered telecommunications equipment or services as a substantial or essential component of any system, or as critical technology as part of any system. Nothing in the prohibition shall be construed to—

(i) Prohibit the head of an executive agency from procuring with an entity to provide a service that connects to the facilities of a third-party, such as backhaul, roaming, or interconnection arrangements; or

(ii) Cover telecommunications equipment that cannot route or redirect user data traffic or cannot permit visibility into any user data or packets that such equipment transmits or otherwise handles.

(2) Section 889(a)(1)(B) of the John S. McCain National Defense Authorization Act for Fiscal

Year 2019 (Pub. L. 115-232) prohibits the head of an executive agency on or after August 13, 2020, from entering into a contract or extending or renewing a contract with an entity that uses any equipment, system, or service that uses covered telecommunications equipment or services as a substantial or essential component of any system, or as critical technology as part of any system. This prohibition applies to the use of covered telecommunications equipment or services, regardless of whether that use is in performance of work under a Federal contract. Nothing in the prohibition shall be construed to—

(i) Prohibit the head of an executive agency from procuring with an entity to provide a service that connects to the facilities of a third-party, such as backhaul, roaming, or interconnection arrangements; or

(ii) Cover telecommunications equipment that cannot route or redirect user data traffic or cannot permit visibility into any user data or packets that such equipment transmits or otherwise handles.

(c) Procedures. The Offeror shall review the list of excluded parties in the System for Award

Management (SAM) ( https://www.sam.gov) for entities excluded from receiving federal awards for

"covered telecommunications equipment or services".

(d) Representation. The Offeror represents that—

(1) It □ will, □ will not provide covered telecommunications equipment or services to the

Government in the performance of any contract, subcontract or other contractual instrument resulting from this solicitation. The Offeror shall provide the additional disclosure information required at paragraph (e)(1) of this section if the Offeror responds "will" in paragraph (d)(1) of this section; and

(2) After conducting a reasonable inquiry, for purposes of this representation, the Offeror represents that—

It □ does, □ does not use covered telecommunications equipment or services, or use any equipment, system, or service that uses covered telecommunications equipment or services.

The Offeror shall provide the additional disclosure information required at paragraph (e)(2) of this section if the Offeror responds "does" in paragraph (d)(2) of this section.

(e) Disclosures.

(1) Disclosure for the representation in paragraph (d)(1) of this provision. If the Offeror has responded "will" in the representation in paragraph (d)(1) of this provision, the Offeror shall provide the following information as part of the offer:

(i) For covered equipment—

(A) The entity that produced the covered telecommunications equipment (include entity name, unique entity identifier, CAGE code, and whether the entity was the original equipment manufacturer (OEM) or a distributor, if known);

(B) A description of all covered telecommunications equipment offered (include brand;

model number, such as OEM number, manufacturer part number, or wholesaler number; and item description, as applicable); and

(C) Explanation of the proposed use of covered telecommunications equipment and any factors relevant to determining if such use would be permissible under the prohibition in paragraph (b)(1) of this provision.

(ii) For covered services—

(A) If the service is related to item maintenance: A description of all covered telecommunications services offered (include on the item being maintained: Brand; model number, such https://www.sam.gov/

D-17 as OEM number, manufacturer part number, or wholesaler number; and item description, as applicable);

or

(B) If not associated with maintenance, the Product Service Code (PSC) of the service being provided; and explanation of the proposed use of covered telecommunications services and any factors relevant to determining if such use would be permissible under the prohibition in paragraph (b)(1) of this provision.

(2) Disclosure for the representation in paragraph (d)(2) of this provision. If the Offeror has responded "does" in the representation in paragraph (d)(2) of this provision, the Offeror shall provide the following information as part of the offer:

(i) For covered equipment—

(A) The entity that produced the covered telecommunications equipment (include entity name, unique entity identifier, CAGE code, and whether the entity was the OEM or a distributor, if known);

(B) A description of all covered telecommunications equipment offered (include brand;

model number, such as OEM number, manufacturer part number, or wholesaler number; and item description, as applicable); and

(C) Explanation of the proposed use of covered telecommunications equipment and any factors relevant to determining if such use would be permissible under the prohibition in paragraph (b)(2) of this provision.

(ii) For covered services—

(A) If the service is related to item maintenance: A description of all covered telecommunications services offered (include on the item being maintained: Brand; model number, such as OEM number, manufacturer part number, or wholesaler number; and item description, as applicable);

or

(B) If not associated with maintenance, the PSC of the service being provided; and explanation of the proposed use of covered telecommunications services and any factors relevant to determining if such use would be permissible under the prohibition in paragraph (b)(2) of this provision.

(End of provision)

4. FAR 52.204-26 Covered Telecommunications Equipment or Services-Representation (OCT

2020)

(a) Definitions. As used in this provision, "covered…

This is the start of the file's text. The full file is on GovTribe.

File details come from the government source that posted it. Updated .