FCHS2_Section_J_Attachment_8_Day_One_OCIO_GeoPlatform.pdf
PDF 669 KB Posted
- Attached to
- DOI Foundation Cloud Hosting Services (FCHS2) Federal contract opportunity
- Solicitation number
- 140D0423R0002
View the file
Other files for this federal contract opportunity
Show all 46
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
Foundation Cloud Hosting Services II (FCHS2) Section J
D-1
SECTION J – ATTACHMENT 08
Introduction Day One Use Case – OCIO-GeoPlatform
OGIO GeoPlatform https://www.geoplatform.gov and OSMRE https://geomine.osmre.gov/
The Department of the Interior (DOI) has prepared this Day One Use Case to support the Office of the Chief Information Officer (OCIO), Office of the Geospatial Information Officer (OGIO) to provide license and support services for DOI’s managed GeoPlatform cloud environment beyond the contract life of the existing Foundation Cloud Hosting Services (FCHS) contract.
Services may include cloud migration, modernization, and improvements in efficiency, agility, innovation, and sustainability.
DOI GIS Priorities covered by this Day One Use Case are listed below in descending order of importance:
1. Cloud Environment and automated maintenance of over 40 accounts.
2. STIG compliant machine images
3. Solution providing both ESRI ArcGIS and Open Source Geospatial Foundation (OSGEO) technology stacks as well as support for MapBox , CKAN , Top Quadrant , CARIS, Bentley, Trimble, Carto (NPS), Rstudio (FWS ECOS), Burp Suite Pro (GP), Voyager (USACE
DISDI), and Esri (USACE)
4. Information Technology Security
5. Program and Project Management
6. Multi-agency collaboration
7. Cloud Migration and migration strategy equivalent to AWS US East / West IaaS and PaaS cloud environment that encompasses licenses and provisioning service for existing
GeoPlatform. During migration, the Department will be required to fund both the existing environment and new environment. With this overlap requirement in mind, what is your approach and practices to shorten the overall migration window while successfully meeting the SOO requirements above.
8. Contractor included VM +
Background
The GeoPlatform at https://www.geoplatform.gov was developed by the agencies of the Federal
Geographic Data Committee (FGDC) through collaboration with partners and stakeholders. The target audience for GeoPlatform includes Federal, State, local, and Tribal governments, private sector, academia and the general public. GeoPlatform offers open geospatial hosting and services on an AWS managed environment. The strategy is to support the Administration’s Open
Government, Open Data and Digital Government strategies to enhance transparency, collaboration, and participation. The cross-agency collaborative effort and shared service operates under the authority of the Geospatial Data Act of 2018. It provides access to 100,000 open geospatial data assets and includes services, applications, and community tools for over 30
Federal agencies.
The OSMRE GeoMine is an interactive web-based mapping application that supports the Surface https://www.geoplatform.gov/ https://www.geoplatform.gov/
D-2
Mining Control and Reclamation Act (SMCRA) by providing public access to surface coal mining and reclamation geospatial data within the United States. It merges data from numerous state and federal sources to create standardized, seamless layers that cross state boundaries.
GeoMine is based on ESRI technology and heavily uses FME to pull data from multiple data sources into the system.
Period and Place of Performance
The base Period of Performance will be two years beginning from the date of award and four two-year option periods. The life expectancy of this project is ten years. Services will be performed remotely.
Current Environment
The current GeoPlatform environment is built on a FedRAMP authorized Amazon US East/West
IaaS/PaaS/SaaS. GeoPlatform is listed as FISMA Moderate and stores some sensitive personally identifiable information (PII) including name, username, and email. See GeoPlatform PIA -https://www.doi.gov/sites/doi.gov/files/geoplatform-pia-06162022.pdf The environment current supports 32 different organizations and has been in service since 2011.
Geoplatform AWS hosting environment is complex and consists generally of the following resources
• AWS VPC – 850 virtual private clouds with 3000 subnets
• AWS EC2 Instances – 400 running linux and windows server
• AWS EBS volumes - 1200 comprising 250 TB storage
• AWS S3 Buckets – 1000 buckets comprising 40m objects and 10TB storage
• AWS RDS Instances – 170 Oracle, PostGres, SQL Server comprising 60 TB storage
• AWS Autoscaling Groups – 60
• AWS Configuration channels – 40
• AWS Certificates managed – 110
• AWS Cloud Formation Stacks – 1200
• AWS Cloud Front Distributions – 50
• AWS Elastic Beanstalk – 25 applications
• AWS Elastic Container Service – 90 clusters with 150 tasks
• AWS IAM – 1400 users, 1000 groups
• AWS Key Management – 600 keys
• AWS Lambda – 550 functions
• AWS Route 53 – 40 zones
Scope
The proposed services will include providing ongoing IaaS, PaaS, and SaaS cloud license and support services for an existing mature multi-agency, multi-tenant cloud environment. DOI does not anticipate significant cloud-to-cloud migration, technology refresh, or tenant enhancements being required, but welcomes proposed solutions.
The Statement of Objectives described below addresses work scope associated with the
D-3 following activities:
• If cloud migration is proposed, contractor shall include migration mapping and architecture of new cloud environment.
• Contractor to provide FedRAMP authorized GIS Hosting Services compatible and/or equivalent to the existing AWS US East/West IaaS and PaaS cloud environment that encompasses licenses and provisioning services for the existing GeoPlatform applications and datasets.
• Contractor to provide requirements and optional recommendations (and separated line-item pricing) for the most effective industry/service model to meet a multi-agency tenant, best architecture configuration, automation, and management tools.
• Contractor provided solution must support both the ESRI ArcGIS and Open-Source
Geospatial Foundation (OSGEO) technology stacks.
• Contractor to separate base cost of Moderate Level IaaS license and basic services environment prior to any bundling, development, imaging, and provisioning configurations listed below. Basic environment shall be configured with SLAs only e.g., availability, IPv6, VM operating systems, self-provisioning storage, backup retention 30-days, term storage 3 years.
• Contractor to provide STIG complaint machine images
(1) suited to best support the GIS industry and support ESRI server images,
(2) automatically provision ArcGIS Server/Desktop VMs when on-demand thresholds triggered,
(3) automate installation of ArcGIS Server/Desktop on new machines (<1 hr),
(4) allow for reusable virtual machines (VM) that do not duplicate licensing or data files,
(5) manage and deploy images containing ArcGIS Server
(6) manage and deploy images to be used for ArcGIS Server and Geodatabase administration purposes.
(7) manage and maintain ESRI Kubernetes Cluster
(8) manage and maintain including database administration for SQL Server, Oracle, and PostGRES databases
• Contractor to meet IaaS/PaaS OpenGeo Suite requirements:
(1) Environment to include and automatically provision OpenGeo software suite (< 1 hr)
• Contractor to support configuration, operation, and monitoring of other Commercial Off
The Shelf (COTS) geospatial software including software from the following vendors
(1) ESRI
(2) MapBox
(3) CKAN
(4) Top Quadrant
(5) CARIS
(6) Bentley
i. Trimble
ii. Carto
iii. Rstudio
(7) Burp Suite Pro
(8) Voyager
D-4
• Contractor to include in VM
(1) operating system license with elastic, redundant, dynamic computing capabilities,
(2) built-in AI acceleration to dynamically scale processors
(3) ability to create VM templates, allowing different customers to define their own
VM images and upload them,
(4) ability to remotely load applications and data onto VM from Internet,
(5) support a secure administration interface using the latest TLS/SSH transport security,
(6) capability to dynamically reallocate VM with no service interruption,
(7) capability to copy/clone VM for archiving, troubleshooting, and testing
• Contractor to provide the ability for administrators to provision requirements including
(1) VMs storage, servers, operating systems, bandwidth, compute services, backup/retention cycles,
(2) Setting dynamically and instantaneously provisioned/de-provisioned compute services triggered by on-demand requests.
• Contractor to provide the following network requirements including
(1) Capability to implement and manage network load balancing,
(2) Provide load balancer health checks, such as allowing non-responsive machines to be dropped from group,
(3) Support Internet bandwidth of at least 1 Gb/s,
(4) Allow for dynamic (elastic or multiple per network interface) IP addressing,
(5) Provide option to create isolated virtual private network, allowing customer to assign their own IP address ranges, create subnets and routing tables that can limit connectivity, isolate servers by role,
(6) Provide re-assignable static Ips for virtual machines
• The Contractor shall provide multi-agency collaboration and segment flexibility
(1) Establish naming conventions to individually identify tenant groups and compute services
(2) manage data isolation in a multi-tenant environment
(3) provide on-line usage and billing capability allowing customers to see and track the status of invoices based on their specific usage
(4) provide dashboard for monitoring resource utilization and other events and logs such as failure of service, degradations in service, peak usage, backups, and other environmental health thresholds,
(5) provide point in time backups while in use and database as a service backups to allow for point in time as well as regularly scheduled nightly backups
Objectives
1. Business
The following are Business Objectives:
• If Migration Services are proposed- Migration and Provisioning Objectives:
o Enable strategic decisions by the Department to effectively migrate applications to the cloud, maximizing cost reduction and efficiency of IT environment.
o Provide maximum alignment to FDCCI requirements and cloud migration mandates and requirements, amplifying the Departments ability to achieve management
D-5 objectives.
o Provide cloud migration services that accommodate considerations from an enterprise perspective including impact on the Departments’ business units, contracts, management, and technical components.
o Provide all support operations necessary to fully develop and deliver services for each acquisition phase.
• If Application Mapping and Assessment is proposed - Application Mapping and
Assessment o Provide work products for application mapping that result in the Programs understanding of the benefits and implications of moving individual applications or groups of applications to the cloud.
o Produce “quick win” analysis of applications that are well-suited for accelerated deployment to the cloud and provide recommendations for executing this migration.
• If Migration Services are proposed- Migration Planning
The IT Systems, bureaus, offices, and agencies currently residing within the GeoPlatform environment have a wide span of technical configurations. The list below is an outline of these
IT Systems. The Contractor should propose a migration plan, including timeline, kickoff meeting, activities, and any unique considerations to accommodate a phased approach.
Please document the migration strategy and length of time required beginning with the date of award, until the end of the migration timeline. Migration should begin with GeoPlatform.gov and
OSMRE GeoMine. Once these two projects are successfully migrated and stable the migration of other projects may begin. All migrations must be completed by October 2024.
To help plan and communicate with IT System personnel, the Contractor shall work with the
GeoPlatform team to identify which of the following IT Systems they recommend for each phase. The Contractor shall identify any preparations required by the government prior to their respective migration phase. Likewise, the Contractor shall identify expectations, disruptions, communications requirements, required by the government during their respective migration phase. The Contractor should submit any additional questions prior to award to assist with migration discovery.
o Produce a roadmap for the Program to effectively plan for cloud migration that maximizes cost reduction and identifies constraints and inhibitors to cloud migration.
o Describe a business case comparison of current expenditures to proposed expenditures, demonstrating ROI of proposed solution.
o Provide a migration plan describing recommendations for service models (SaaS, PaaS, or IaaS), and deployment model (private, public, community, etc.).
o Describe applications’ development lifecycle, business relevance, security impacts, organizational roles, financial aspects of cloud service delivery, and other migration considerations.
o As of February 2, 2023, there are 43 funded GeoPlatform programs that will potentially require migration. At time of contract award there may be more or less
D-6 programs.
All of the following projects utilize technologies identified under the current environment above.
They are:
1. United States Geological Survey () Web Informatics and Mapping (WiM)
a. Multiple VPCs with multiple environments supporting ESRI GIS software.
Includes high visibility / high priority emergency common operating picture applications
2. Trails
a. Consolidated trails across the country along with applications to develop new trails based on elevation, proximity and land data.
3. Bureau of Ocean Energy Management (BOEM) GeoSEAS
a. Data and applications for multiple operational units of BOEM
4. Federal Emergency Management Agency (FEMA) Disasters
a. Multiple applications in support of response and recovery of federally declared disasters.
5. FEMA RMD
a. Primarily ESRI infrastructure for Risk Management data
6. Fish and Wildlife Service (FWS) TRACS
a. ESRI GIS infrastructure in support of USFWS tracking and reporting for conservation species
7. FWS ECOS
a. Multiple applications in support of wildlife and habitat management
8. FWS Sandbox
a. Development environment for USFWS applications
9. FWS IRIS
a. A set four database driven applications supporting the USFWS Integrated Refuge
Information System
10. FWS BGDS
a. ESRI Server environment supporting a wide variety of USFWS geographic data services
11. FWS South Atlantic Simple Viewer (SA)
a. Fish and Wildlife refuge and project mapping and tracking
12. Office of Service Mining and Reclamation Enforcement (OSMRE) GeoMine
a. Data for surface and subsurface coal mine operations
13. Federal Geographic Data Committee (FGDC) GeoPlatform
a. Shared service metadata catalog and applications, GeoPlatform.gov
14. FGDC GeoPlatform Imagery Data Management (IDM)
a. Open source software for processing and management of UAS data
15. Bureau of Reclamation (BOR)
a. GIS for infrastructure and water management
16. BOR BORGIS
a. ESRI GIS Server environment in support of California great basin restoration
California Great Basin Restoration
17. United States Army Corps of Engineers (USACE) CWBI / IL4
a. A set of one dozen or more VPCs with both 50+ endpoints and PIV controlled
D-7 systems
b. Security and compliance are at DoD Cloud Impact Level 4
c. Oracle databases as EC2 and RDS
d. Multiple platforms including oracle APEX, REACT, cold fusion,
18. USACE DISDI/IL4
a. Defense Installation Spatial Data Infrastructure
b. ESRI and other applications in multiple VPCs
c. Requires DISA Cloud Access Point
d. Requires STIG compliance for DoD impact level 4
19. USACE Dam and Levee Safety
a. Applications and services consisting of mainly cloud native code
20. USACE Data Catalogue
a. Kubernetes deployment of bespoke code for managing metadata using similar software to DOI IDM
21. USACE IENC CARIS
a. Oracle database, vendor server software and appstream envrionment for maintaining inland electronic navigation charts
22. USACE ArcGIS
a. Multiple instances of full ESRI server stack with multiple data stores and appstream desktops
23. Office of Natural Resources Revenue (ONRR) TopBraid
a. Wildfire ontology and multi-agency coordination
24. National Park Service (NPS)
a. GIS for web applications and physical map production
25. NPS Unstable Slope Management Program (USMP)
a. Application to analyze slope stability for road maintenance
26. Office of Aviation Services (OAS) Safecom
a. Application to manage manned and UAS operations in support of DOI and the fire community
b. Relatively small environment consisting of cloud native code and postgres rds
27. US Dept of Agriculture (USDA)/ Interdepartmental Imagery Publication Platform (IIPP)
a. Kubernetes deployment to manage and serve NAIP imagery
28. US Environmental Protection Agency (EPA) National Hydrograhic Dataset Plus
(NHD+), part of the GeoPlatform program
a. National hydro dataset and applications
29. Bureau of Trust Fund Administration (BTFA)
a. Applications in support of Tribal financial data and management
30. Office of Emergency Management (OEM) SHIRA
a. Department of the Interior Common Operating Picture for situational awareness and emergency operations.
31. Office of Wildland Fire (OWF) TopBraid
a. Graph database managing wildfire operations
32. National Geospatial-Intelligence Agency (NGA)
a. Used to transfer and make unclassified data available to the federal govt.
33. Bureau of Indian Affairs (BIA) Bureau of Geospatial Support (BOGS)
a. Multiple applications and GIS data supporting BIA operations
D-8
34. BIA SmartSheets
a. Acquire and support SmartSheets Software As A Service (SAAS) for Bureau of
Indian Affairs
35. Office of the Chief Information Officer (OCIO) Controlled Unclassified Information
(CUI)
a. DOI metadata catalog
36. Office of Management and Budget (OMB) Economic Justice Screen Tool
a. New environment for Explore the map - Climate & Economic Justice Screening
Tool (geoplatform.gov)
37. OSMRE Abandon Mine Land Inventory System (e-AMILS)
a. GIS and financial data for abandoned mine reclamation activities
38. USFS Imagery Data Manager (IDM)
a. Same environment as number 15 but billed separately
2. Management / Key Personnel
The following are Management objectives:
• Provide a Senior project manager that is the primary point of contact for the government.
Senior PM may need to supervise multiple Project Managers and technical experts as well as subcontractors as needed.
• Provide a financial specialist to work directly with the Government Contracting Officer and Contracting Officer Representatives. Ideally the financial specialist has experience with Federal contracting.
• Provide senior cloud architect with documented certifications and extensive experience in design and implementation of secure cloud computing architecture.
• Provide senior geospatial solution architect and or geospatial systems administrator with extensive experience implementing full suite of ESRI software in cloud hosted environment for large data programs.
• Provide senior database administrator with deep understanding and experience with database design, database security, database monitoring and database tuning with one or more of the following RDBMS systems: SQL Server, Oracle RDBMS, PostGres
• Provide a Cybersecurity Analyst who is the primary point of contact for cloud system security. The cybersecurity analyst will work with the GeoPlatform Executive
Management Team.
• Provision to allow maximum flexibility to innovatively manage program cost, schedule, performance, risks, warranties, contracts and subcontracts, vendors, and data required to deliver effective migration services.
• Maintain clear government visibility into program cost, schedule, technical performance, and risk, including periodic reporting.
• Provide meaningful reporting and analytics that provide the Program with up-to-date and comprehensive information regarding technical and management performance.
Reporting includes weekly program meetings and quarterly project meetings with the projects in the GeoPlatform environment.
• Provide a brief description on the management of any subcontractor relationships and contracts. Outline the roles and responsibilities per party involved in the service and where key responsibilities reside.
• Provide a transition plan detailing milestones, activities, and timelines for the migration https://screeningtool.geoplatform.gov/en/#3/33.47/-97.5 https://screeningtool.geoplatform.gov/en/#3/33.47/-97.5
D-9 and provisioning of services.
• Maintenance of architecture diagrams for the GeoPlatform and projects in the
GeoPlatform cloud environment.
3. Administrative
The following are Administrative objectives:
• Quality Assurance: Provide a draft Quality Assurance Surveillance Plan (QASP) and/or
Quality Control Plan (QCP) that shall include details for measuring performance and deliverables with metrics that may include data availability, storage capacity, uptime, etc.
These documents are to be correlated with the “as-is” and “to-be” environments provided in Sections 5.1 and 5.2 above.
• Invoicing: Provide accurate monthly invoices on a timely basis, as well as monitor each program’s CLIN fund use giving a 4 month warning time for any projects in danger of running out of funding.
4. Technical
The following are Technical objectives:
• Provide cloud environments (e.g., IaaS, PaaS, etc.) for production purposes to support the complete systems lifecycle. Cloud environments should be standardized as much as possible to allow interoperability. Environments should be the equivalent of AWS Band
2-4 with most at a Band 3.
• Provide cloud support and/or governance services, including assigning responsibility for authorizing individual instances for provisioning.
• Provide open-standards based technologies whenever possible to provide interoperability.
Specific standards considered include:
o Open Virtualization Format (OVF) – applicable only to IaaS virtual machines o Cloud Data Management Interface (CDMI) o Open Cloud Computing Interface (OCCI)
• Provide backup, recovery and disaster recovery procedures and processes in the cloud environment for the target applications and services that support the following objectives:
o Recovery Time Objective (RTO) – ability to recover files within < 24 hours of request.
o Recovery Point Objective (RPO) - ability to recover files for any specific day within a rolling two (2) month period.
o Mean Time to Repair (MTTR) – the elapsed recovery average time required to complete a restore request is set for < 24 hours.
o Data Backup Location – Data backups maintained or replicated at a site geographically 250-miles disparate from the production site such that the loss of one data center does not prohibit recovery of data within the prescribed RTO.
• Provide support for data storage tiers between live, at-rest, archive, etc.
• Provide complete support for IPv6 within the cloud environments provided.
• Contractor will provide continuous monitoring and reporting to demonstrate effective cloud cost control. The contractor must demonstrate that they avoid over provisioning of server resources, idle instances, and abandoned resources that resulting in unnecessary expense to the government. Contractor will report monthly
D-10 on all resources across all accounts demonstrating that resources are optimally provisioned, or configured to meet specific customer requirement, and identifying opportunities to further reduce costs.
• While support is generally required during business hours, the contractor should be prepared in unusual / emergent cases to work evenings and weekends when requested. Cases would be presidentially declared disaster requires unplanned support. CISA indicates urgent cyber security threat requires immediate remediation.
Other customer emergency when validated through contract officer representative
• All software, scripts, playbooks, notes, guidance, briefings, diagrams, or reports whether in prototype, draft or final form, when prepared for any activity under this task order must be managed in government specified code and document repositories.
All items in the repositories are explicitly government property and may be immediately shared by the government across projects, with other vendors, or with the public at government discretion. The vendor may make no claim of intellectual property for any work conducted under this task order
Security
In addition to the itemized list below, all Security and Privacy requirements under this task order shall comply with the FCHS2 base contract. Proposals should include either acceptance or alternate metrics as appropriate for cloud compute services under this task order.
• Provide support and services in compliance and alignment with Federal Risk and
Authorization Management Program (FedRAMP) standardized security assessment, authorization, and continuous monitoring policies as required by the scope of the project.
• Provide migration services regarding security and privacy that are consistent with the
NIST Special Publication 800-144 – “Guidelines on Security and Privacy in Public Cloud
Computing”
• Provision services to manage FISMA MODERATE security and privacy risk for the IT
Systems life-cycle that are consistent with NIST Special Publication 800-37 and NIST
Special Publication 800-53.
• Provide a security plan focused on end-to-end integration points, including data in transit and at rest.
• Provide support for specified auditable events related to the applications or services.
• Properly secure connections between co-located systems and integrations consistent with
Trusted Internet Connection 3.0 or DISA BCAP as needed
• Provide role-based access controls through identity and access mechanisms for rights and privileges to Cloud services for the customer environment.
• Support DOI and other federal agency Enterprise Active Directory Authentication utilizing SAML (see Section 2.7.8) as well as external SAML authentication providers, including login.gov
• Provide multi-factor authentication to the configuration interfaces of Cloud services for the customer environment using login.gov or other source
• Provide logging, monitoring, auditing, and reporting for Cloud service offerings as specified in section 2.7 https://nvlpubs.nist.gov/nistpubs/Legacy/SP/nistspecialpublication800-144.pdf https://nvlpubs.nist.gov/nistpubs/Legacy/SP/nistspecialpublication800-144.pdf https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-37r2.pdf https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r5.pdf https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r5.pdf
D-11
• Monthly scanning and reporting for all environments
Service Level Agreements
Provide end-to-end monitoring capability and reporting for service level agreement (SLA) requirements and metrics.
• Accessibility: Applications and services that fall under the Information and
Communication Technology (ICT) services shall comply with Section 508 of the
Rehabilitation Act and Web Content Accessibility Guidelines (WCAG).
• Availability: Provide cloud services compliant with the Secure Software Development
Framework (SSDF) – Supply Chain Security.
• Cloud services should be fully operational 99.90% and scheduled maintenance, downtime, patching, and other implementations potentially affecting availability will be pre-coordinated and transparent to the Program.
• Performance: Provision services to permit visibility to monitor and manage variations in performance metrics, e.g., on-demand services available, adaptation to demand fluctuations, role filtered tools to support billing and service functions, peak usage and historical average reports, alarms and logging dashboards, automated reporting metrics/failures, etc.
• Continuous Monitoring: Provide Security Assessment Plan and Security Assessment
Report according to NIST SP 800-53. Provide Continuous Monitoring Plan (CMP), with included Plan of Actions and Milestones (POAMs) consistent with NIST SP 800-137.
• Service Center: Provide default available tiers and types of Service Centers including trouble ticketing and business operations. Provide contact links and phone numbers for initiating contact with Online Support Site “reading room”, 800 number, Help Desk, chat, task order support, etc. Provide days, hours, and time zones available. Provide “mean time to” response services between (1) routine, (2) Mission Priority, and (3) Emergency
(health and safety)
• Additional Services: At vendors discretion, provide optional additional support services available and/or recommended not included in standard licensing. Provide description, line items, and cost separately and clearly labelled as optional on task order proposal.
• Service Reliability: Deliver a Disaster Recovery Plan for each CSP that includes (at a minimum) service resilience, fault tolerance, customer data backup and restore, and disaster recovery reliability. Describe Network Configuration Management features to meet reliability standards; e.g., change management, login attempt log, idle timeout, syslog events, routine backups, etc.
• Backup and Restore: Describe backup routines, frequency, and types available. Describe the length of times and states for retention. Describe FIPS 140-3 encryption and other measures implemented for the protection of sensitive and valuable data. Backup solutions must be agentless architecture solution, meet 100TB backup capacity in under 8 hours, scalable into petabyte range, test and verify without having to restore, ability to launch
VM directly from de-duplicated compressed backup, provide end-to-end AES encryption.
• Data Management: Provide Control Implementation Summary (CIS) and Customer
Responsibility Matrix (CRM) of all security controls at the appropriate Low, Moderate, High environment level according to NIST SP 800-53 rev 5. Describe CSP versus customer responsibilities. Provide security for both data in transit and at rest. Select CSP within the Continental United States, Hawaii, Alaska, Puerto Rico, Guam, and Virgin
D-12
Islands with geographical separation of at least 250- miles. Provide support for auditable events to the applications and/or services.
• Incident Response: Follow IR procedures for all privacy breaches and take immediate action (within 1 hour when identified) to contain and mitigate the impact of breach and cooperate with Government officials. Contractor shall document 1) programs/platforms,
2) location of breach, 3) date/time, 4) nature of event/loss/unauthorized access, 5) summary description, 6) number of users impacted, 7) estimated records, 8) data sets affected.
Submit email regardless of time or day to:
▪ Department of the Interior - Computer Incident Response Center (DOI-CIRC) at doicirc@ios.doi.gov and 703-648-5655. For non-DOI agencies, submit to their equivalent
▪ Contracting Officer
▪ Authorizing Official and/or System Owner
▪ Information System Security Officer and/or Cloud Service Provider portal within max.gov
Constraints
• Access Control: Cloud Service Provider has capacity to meet Federal Records
Management Requirements, including ability to support record holds, National
Archives and Records Administration (NARA) requirements, and Freedom of
Information Act (FOIA) requirements;
o Contractor shall not remove PII or Privacy Act material from Government facilities or systems, or facilities or systems operated or maintained on the
Government’s behalf, without the express written permission of the Head of the
Contracting Activity.
o Contractor may be required to provide necessary support to assist the Government in meeting the requirements of the Privacy Act and related laws and shall cooperate to provide supporting documentation and access to information upon request by authorized agency officials.
o Provision services to protect Federal records appropriately and protect them from unauthorized removal from the Department’s custody, including the handling of records containing information exempt from disclosure under the Freedom of
Information Act (FOIA) (5 U.S.C. 552), the Privacy Act (5 U.S.C. 522a)
• Intellectual Property: Ensure the protection of government intellectual property (IP) and data ownership rights and those of any licensors. They shall identify and provide visibility of IP owned and managed components by them or the cloud service provider.
Unless otherwise noted by contractor and government all data is owned by government.
• Origin of DNS: Cloud Service Provider’s external DNS security (DNSSec) provides origin authentication and integrity verification.
• Authentication: Seamlessly integrate with the Agency Identity, Authorization and Access
Management (IdAAM) solution that consists of the Microsoft Active Directory (AD) and
Public Key Infrastructure (PKI) architecture and associated Certificate Authority and
DOI HSPD-12 PIV SmartCard-based credentials.
o Provide dual-factor communication channel for cloud environment management to support Federated SAML 2.0 Government’s PIV Card authentication consistent mailto:doicirc@ios.doi.gov
D-13 with OMB M-11-11 “Continued Implementation of HSPD-12 for Common
Identification Standard for Federal Employees and Contractors” o Provide phishing-resistant “Identify Authentication” single sign-on credentialing options for external facing customer services consistent with M-22-09 “Moving the U.S. Government Toward Zero Trust Cybersecurity Principles” o Contractor Personnel: Contractors authenticating into Agency cloud services shall also comply with Homeland Security Presidential Directive (HSPD-12) that require all federal entities and associated contractors have security background investigations equivalent to federal employees. Background investigations will be performed by the Office of Personnel Management (OPM).
Prohibitions:
• Adware: DOI requests contractors to refrain from and to actively prevent adware, spam, and remarketing of information. The Contractor shall not engage in nor permit its agents to push adware, software, or marketing not explicitly authorized by the Agency. The
Contractor and/or their agents shall not resell nor otherwise redistribute information gained from its access to contract users.
• Non-Disclosure Agreements: Contractors shall require each of their administrative employees that interfaces with the cloud services customized applications and government data to sign non-disclosure agreements at onset of project implementation.
Non-disclosure agreements will be supplied by the Contracting Officer, or the Contractor may elect equivalent and approved alternative.
• Government Banners: A government approved logon banner must be displayed on the first page of any public access web pages. Logon warning banners must be automatically incorporated into IT Systems initial logon process and require periodic credentialed acceptance for all (federal and contractor) personnel accessing the federal IT System.
SECTION 3. CLAUSES.
1. FAR 52.252-2, CLAUSES INCORPORATED BY REFERENCE (FEB 1998)
The following clauses are hereby incorporated by reference. The full text version can be found at https://acquisition.gov/far/index.html.
• FAR 52.203-17 CONTRACTOR EMPLOYEE WHISTLEBLOWER RIGHTS AND
REQUIREMENT TO INFORM EMPLOYEES OF WHISTLEBLOWER RIGHTS (JUN
2020)
• FAR 52.212-4 CONTRACT TERMS AND CONDITIONS – COMMERCIAL PRODUCTS
AND COMMERCIAL SERVICES (DEC 2022) and it’s ALTERNATE I (NOV 2021).
• FAR 52.232-18 AVAILABILITY OF FUNDS (APR 1984)
• FAR 52.232-39 UNENFORCEABILITY OF UNAUTHORIZED OBLIGATIONS (JUN
2013)
2. CLAUSES AND PROVISIONS IN FULL TEXT
1. FAR 52.203-18 Prohibition on Contracting with Entities That Require Certain Internal
Confidentiality Agreements or Statements-Representation (JAN 2017)
(a) Definition. As used in this provision-
D-14
Internal confidentiality agreement or statement, subcontract, and subcontractor , are defined in the clause at 52.203-19, Prohibition on Requiring Certain Internal Confidentiality Agreements or
Statements.
(b) In accordance with section 743 of Division E, Title VII, of the Consolidated and Further
Continuing Appropriations Act, 2015 (Pub. L. 113-235) and its successor provisions in subsequent appropriations acts (and as extended in continuing resolutions), Government agencies are not permitted to use funds appropriated (or otherwise made available) for contracts with an entity that requires employees or subcontractors of such entity seeking to report waste, fraud, or abuse to sign internal confidentiality agreements or statements prohibiting or otherwise restricting such employees or subcontractors from lawfully reporting such waste, fraud, or abuse to a designated investigative or law enforcement representative of a Federal department or agency authorized to receive such information.
(c) The prohibition in paragraph (b) of this provision does not contravene requirements applicable to Standard Form 312, (Classified Information Nondisclosure Agreement), Form 4414 (Sensitive
Compartmented Information Nondisclosure Agreement), or any other form issued by a Federal department or agency governing the nondisclosure of classified information.
(d) Representation. By submission of its offer, the Offeror represents that it will not require its employees or subcontractors to sign or comply with internal confidentiality agreements or statements prohibiting or otherwise restricting such employees or subcontractors from lawfully reporting waste, fraud, or abuse related to the performance of a Government contract to a designated investigative or law enforcement representative of a Federal department or agency authorized to receive such information (e.g., agency Office of the Inspector General).
(End of provision)
2. FAR 52.204-21 Basic Safeguarding of Covered Contractor Information Systems (NOV 2021)
(a) Definitions. As used in this clause—
Covered contractor information system means an information system that is owned or operated by a contractor that processes, stores, or transmits Federal contract information.
Federal contract information means information, not intended for public release, that is provided by or generated for the Government under a contract to develop or deliver a product or service to the Government, but not including information provided by the Government to the public
(such as on public websites) or simple transactional information, such as necessary to process payments.
Information means any communication or representation of knowledge such as facts, data, or opinions, in any medium or form, including textual, numerical, graphic, cartographic, narrative, or audiovisual (Committee on National Security Systems Instruction (CNSSI) 4009).
Information system means a discrete set of information resources organized for the collection, processing, maintenance, use, sharing, dissemination, or disposition of information ( 44 U.S.C. 3502).
Safeguarding means measures or controls that are prescribed to protect information systems.
(b) Safeguarding requirements and procedures.
(1) The Contractor shall apply the following basic safeguarding requirements and procedures to protect covered contractor information systems. Requirements and procedures for basic safeguarding of covered contractor information systems shall include, at a minimum, the following security controls:
(i) Limit information system access to authorized users, processes acting on behalf of authorized users, or devices (including other information systems).
(ii) Limit information system access to the types of transactions and functions that authorized users are permitted to execute.
(iii) Verify and control/limit connections to and use of external information systems.
(iv) Control information posted or processed on publicly accessible information systems.
(v) Identify information system users, processes acting on behalf of users, or devices.
https://www.acquisition.gov/far/part-52#FAR_52_203_19 http://uscode.house.gov/browse.xhtml;jsessionid=114A3287C7B3359E597506A31FC855B3
D-15
(vi) Authenticate (or verify) the identities of those users, processes, or devices, as a prerequisite to allowing access to organizational information systems.
(vii) Sanitize or destroy information system media containing Federal Contract
Information before disposal or release for reuse.
(viii) Limit physical access to organizational information systems, equipment, and the respective operating environments to authorized individuals.
(ix) Escort visitors and monitor visitor activity; maintain audit logs of physical access; and control and manage physical access devices.
(x) Monitor, control, and protect organizational communications
(i.e., information transmitted or received by organizational information systems) at the external boundaries and key internal boundaries of the information systems.
(xi) Implement subnetworks for publicly accessible system components that are physically or logically separated from internal networks.
(xii) Identify, report, and correct information and information system flaws in a timely manner.
(xiii) Provide protection from malicious code at appropriate locations within organizational information systems.
(xiv) Update malicious code protection mechanisms when new releases are available.
(xv) Perform periodic scans of the information system and real-time scans of files from external sources as files are downloaded, opened, or executed.
(2) Other requirements. This clause does not relieve the Contractor of any other specific safeguarding requirements specified by Federal agencies and departments relating to covered contractor information systems generally or other Federal safeguarding requirements for controlled unclassified information (CUI) as established by Executive Order 13556.
(c) Subcontracts. The Contractor shall include the substance of this clause, including this paragraph
(c), in subcontracts under this contract (including subcontracts for the acquisition of commercial products or commercial services, other than commercially available off-the-shelf items), in which the subcontractor may have Federal contract information residing in or transiting through its information system.
(End of clause)
3. FAR 52.204-24 Representation Regarding Certain Telecommunications and Video Surveillance
Services or Equipment (NOV 2021)
The Offeror shall not complete the representation at paragraph (d)(1) of this provision if the Offeror has represented that it "does not provide covered telecommunications equipment or services as a part of its offered products or services to the Government in the performance of any contract, subcontract, or other contractual instrument" in paragraph (c)(1) in the provision at 52.204-26, Covered Telecommunications
Equipment or Services—Representation, or in paragraph (v)(2)(i) of the provision at 52.212-
3, Offeror Representations and Certifications-Commercial Products or Commercial Services.
The Offeror shall not complete the representation in paragraph (d)(2) of this provision if the Offeror has represented that it "does not use covered telecommunications equipment or services, or any equipment, system, or service that uses covered telecommunications equipment or services" in paragraph (c)(2) of the provision at 52.204-26, or in paragraph (v)(2)(ii) of the provision at 52.212-3.
(a) Definitions. As used in this provision—
Backhaul, covered telecommunications equipment or services, critical technology, interconnection arrangements, reasonable inquiry, roaming, and substantial or essential component have the meanings provided in the clause 52.204-25, Prohibition on Contracting for Certain Telecommunications and Video
Surveillance Services or Equipment.
(b) Prohibition. (1) Section 889(a)(1)(A) of the John S. McCain National Defense Authorization Act for Fiscal Year 2019 (Pub. L. 115-232) prohibits the head of an executive agency on or after August 13, 2019, from procuring or obtaining, or extending or renewing a contract to procure or obtain, any https://www.acquisition.gov/far/part-52#FAR_52_204_26 https://www.acquisition.gov/far/part-52#FAR_52_212_3 https://www.acquisition.gov/far/part-52#FAR_52_212_3 https://www.acquisition.gov/far/part-52#FAR_52_204_26 https://www.acquisition.gov/far/part-52#FAR_52_212_3 https://www.acquisition.gov/far/part-52#FAR_52_204_25
D-16 equipment, system, or service that uses covered telecommunications equipment or services as a substantial or essential component of any system, or as critical technology as part of any system. Nothing in the prohibition shall be construed to—
(i) Prohibit the head of an executive agency from procuring with an entity to provide a service that connects to the facilities of a third-party, such as backhaul, roaming, or interconnection arrangements; or
(ii) Cover telecommunications equipment that cannot route or redirect user data traffic or cannot permit visibility into any user data or packets that such equipment transmits or otherwise handles.
(2) Section 889(a)(1)(B) of the John S. McCain National Defense Authorization Act for Fiscal
Year 2019 (Pub. L. 115-232) prohibits the head of an executive agency on or after August 13, 2020, from entering into a contract or extending or renewing a contract with an entity that uses any equipment, system, or service that uses covered telecommunications equipment or services as a substantial or essential component of any system, or as critical technology as part of any system. This prohibition applies to the use of covered telecommunications equipment or services, regardless of whether that use is in performance of work under a Federal contract. Nothing in the prohibition shall be construed to—
(i) Prohibit the head of an executive agency from procuring with an entity to provide a service that connects to the facilities of a third-party, such as backhaul, roaming, or interconnection arrangements; or
(ii) Cover telecommunications equipment that cannot route or redirect user data traffic or cannot permit visibility into any user data or packets that such equipment transmits or otherwise handles.
(c) Procedures. The Offeror shall review the list of excluded parties in the System for Award
Management (SAM) ( https://www.sam.gov) for entities excluded from receiving federal awards for
"covered telecommunications equipment or services".
(d) Representation. The Offeror represents that—
(1) It □ will, □ will not provide covered telecommunications equipment or services to the
Government in the performance of any contract, subcontract or other contractual instrument resulting from this solicitation. The Offeror shall provide the additional disclosure information required at paragraph (e)(1) of this section if the Offeror responds "will" in paragraph (d)(1) of this section; and
(2) After conducting a reasonable inquiry, for purposes of this representation, the Offeror represents that—
It □ does, □ does not use covered telecommunications equipment or services, or use any equipment, system, or service that uses covered telecommunications equipment or services.
The Offeror shall provide the additional disclosure information required at paragraph (e)(2) of this section if the Offeror responds "does" in paragraph (d)(2) of this section.
(e) Disclosures.
(1) Disclosure for the representation in paragraph (d)(1) of this provision. If the Offeror has responded "will" in the representation in paragraph (d)(1) of this provision, the Offeror shall provide the following information as part of the offer:
(i) For covered equipment—
(A) The entity that produced the covered telecommunications equipment (include entity name, unique entity identifier, CAGE code, and whether the entity was the original equipment manufacturer (OEM) or a distributor, if known);
(B) A description of all covered telecommunications equipment offered (include brand;
model number, such as OEM number, manufacturer part number, or wholesaler number; and item description, as applicable); and
(C) Explanation of the proposed use of covered telecommunications equipment and any factors relevant to determining if such use would be permissible under the prohibition in paragraph (b)(1) of this provision.
(ii) For covered services—
(A) If the service is related to item maintenance: A description of all covered telecommunications services offered (include on the item being maintained: Brand; model number, such https://www.sam.gov/
D-17 as OEM number, manufacturer part number, or wholesaler number; and item description, as applicable);
or
(B) If not associated with maintenance, the Product Service Code (PSC) of the service being provided; and explanation of the proposed use of covered telecommunications services and any factors relevant to determining if such use would be permissible under the prohibition in paragraph (b)(1) of this provision.
(2) Disclosure for the representation in paragraph (d)(2) of this provision. If the Offeror has responded "does" in the representation in paragraph (d)(2) of this provision, the Offeror shall provide the following information as part of the offer:
(i) For covered equipment—
(A) The entity that produced the covered telecommunications equipment (include entity name, unique entity identifier, CAGE code, and whether the entity was the OEM or a distributor, if known);
(B) A description of all covered telecommunications equipment offered (include brand;
model number, such as OEM number, manufacturer part number, or wholesaler number; and item description, as applicable); and
(C) Explanation of the proposed use of covered telecommunications equipment and any factors relevant to determining if such use would be permissible under the prohibition in paragraph (b)(2) of this provision.
(ii) For covered services—
(A) If the service is related to item maintenance: A description of all covered telecommunications services offered (include on the item being maintained: Brand; model number, such as OEM number, manufacturer part number, or wholesaler number; and item description, as applicable);
or
(B) If not associated with maintenance, the PSC of the service being provided; and explanation of the proposed use of covered telecommunications services and any factors relevant to determining if such use would be permissible under the prohibition in paragraph (b)(2) of this provision.
(End of provision)
4. FAR 52.204-26 Covered Telecommunications Equipment or Services-Representation (OCT
2020)
(a) Definitions. As used in this provision, "covered…
This is the start of the file's text. The full file is on GovTribe.
File details come from the government source that posted it. Updated .