Attachment_L-1_Statement_of_Objectives_Amendment_0001.pdf

PDF 189 KB Posted

Attached to
JEDI Cloud RFP Federal contract opportunity
Solicitation number
HQ003418R0077_JEDI_CLOUD_RFP
Issued by
DOD Washington Headquarters Service

About this file

Attachment L-1 Statement of Objectives 0001

View the file

Other files for this federal contract opportunity

Other files attached to JEDI Cloud RFP, newest first.
File Type Posted
Attachment_L-5_Price_Scenario_Price_Build-up_Template_Updated_.xlsx XLSX spreadsheet
Attachment_J-7_DD_Form_254,_DoD_Contract_Security_Classification_Specification_for_IDIQ_Amendment_0003_(1).pdf PDF
HQ0034-18-R-0077_0003_Change_Page.pdf PDF
Attachment_L-2_Price_Scenarios_Amendment_0002.pdf PDF
Attachment_J-7_DD_Form_254,_DoD_Contract_Security_Classification_Specification_for_ID_IQ_Amendment_0002.pdf PDF
HQ0034-18-R-0077_0002.pdf PDF
Amendment_0002_Summary_of_Changes.pdf PDF
HQ0034-18-R-0077_0001.pdf PDF
Attachment_J-10_Small_Business_Participation_Commitment_Document_0001.pdf PDF
JEDI_Cloud_Comment_Resolution_Matrix_for_Amendment_0001.xlsx XLSX spreadsheet
JEDI_Cloud_Industry_and_Gov_QA_Final_RFP.pdf PDF
Attachment_L-2_Price_Scenarios_Amendment_0001.pdf PDF
Attachment_J-8_Definitions_Amendment_0001.pdf PDF
Amendment_0001_Summary_of_Changes.pdf PDF
Oracle_Protest_Exhibits.pdf PDF
JEDI_CDRL_A005_-_System_Administrator_Training_Material.pdf PDF
JEDI_CDRL_A010_-_Quality_Control_Plan.pdf PDF
JEDI_Single_Award_DF-USD(AS)__17July18.pdf PDF
JEDI_CDRL_A012_-_Technical_Report.pdf PDF
In-Person_Q&A_Session_Information.pdf PDF
JEDI_CDRL_A003_-_Contract_Security_Management_Plan.pdf PDF
HQ0034-18-R-0077.pdf PDF
Attachment_L-5_Price_Scenario_Price_Build-up_Template.xlsx XLSX spreadsheet
JEDI_CDRL_A001_-_Contract_Monthly_Progress_Report.pdf PDF
JEDI_CDRL_A002_-_Transition_Out_Plan.pdf PDF
JEDI_Cloud_Comment_Resolution_Matrix_for_Final_RFP.xlsx XLSX spreadsheet
JEDI_Cloud_Industry_and_Gov_QA_dRFP2.pdf PDF
JEDI_CDRL_A008_-_Contract_Ordering_Guide.pdf PDF
180510_Final_Cloud_Combined_Congressional_Report__vg7_PDF_Redacted.pdf PDF
Attachment_L-7_OCI_Analysis_Disclosure_Form.pdf PDF
DoD_CIO_RFP_Release_Letter_26_Jul.pdf PDF
CNSSP15.pdf PDF
Attachment_L-6__Small_Business_Subcontracting_Plan_Template.docx DOCX document
JEDI_CDRL_A011_-_Security_Authorization_Package.pdf PDF
Attachment_L-8_PWS-SOO_Crosswalk_Matrix.xlsx XLSX spreadsheet
Attachment_L-3_Task_Order_001_PWS.pdf PDF
JEDI_CDRL_A006_-_Role-Based_User_Training_Materials.pdf PDF
MIL-STD-810G_CN1.pdf PDF
JEDI_CDRL_A014_-_Portability_Test.pdf PDF
JEDI_CDRL_A004_Technology_Refresh_Plan.pdf PDF
Attachment_L-4_Task_Order_002_PWS.pdf PDF
Attachment_L-9__Company_Non-Disclosure_Agreement_for_JEDI_Cloud.pdf PDF
Attachment_J-8_Definitions.pdf PDF
JEDI_CDRL_A007_-_Portability_Plan.pdf PDF
Attachment_J-10__Small_Business_Participation_Commitment_Document.pdf PDF
Attachment_J-7_Form_DD254.pdf PDF
Attachment_J-6_JEDI_Cyber_Security_Plan.pdf PDF
JEDI_CDRL_A015_-_Task_Order_Monthly_Progress_Report.pdf PDF
JEDI_CDRL_A013_-_Small_Business_Reporting.pdf PDF
JEDI_CDRL_A016_-_Meeting_Materials.pdf PDF
Show all 50

JEDI Cloud RFP has more files on GovTribe.

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

Attachment L-1 1 Joint Enterprise Defense Infrastructure (JEDI) Cloud 2

Statement of Objectives (SOO) 3 As of 22 August 2018 4

0 Introduction 6

The Department of Defense’s (DoD’s) lack of a coordinated enterprise-level approach to 8 cloud infrastructure and platforms prevents warfighters and leaders from making critical data-9 driven decisions at “mission-speed”, negatively affecting outcomes. In the absence of modern 10 services, warfighters and leaders are forced to choose between foregoing capabilities or slogging 11 through a lengthy acquisition, rollout, and provisioning process. A fragmented and largely on-12 premises computing and storage solution forces the warfighter into tedious data and application 13 management processes, compromising their ability to rapidly access, manipulate, and analyze 14 data at the homefront and tactical edge. Most importantly, current environments are not 15 optimized to support large, cross domain analysis using advanced capabilities such as machine 16 learning and artificial intelligence to meet current, and future warfighting needs and 17 requirements. 18

To maintain our military advantage, DoD requires an extensible and secure cloud 20 environment that spans the homeland to the global tactical edge, as well as the ability to rapidly 21 access computing and storage capacity to address warfighting challenges at the speed of 22 relevance. These foundational infrastructure and platform technologies are needed for DoD to 23 capitalize on modern software, keep pace with commercial innovation, and make use of artificial 24 intelligence and machine learning capabilities at scale. 25

This Statement of Objectives (SOO) describes the Joint Enterprise Defense Infrastructure 27 (JEDI) Cloud acquisition of commercial infrastructure as a service (IaaS) and platform as a 28 service (PaaS) offerings to support DoD business and mission operations. JEDI Cloud is an 29 important first step to acquiring a general purpose cloud capable of delivering infrastructure and 30 platform services for the bulk of the Department’s mission. JEDI Cloud will also serve as a 31 pathfinder for DoD to understand how to deploy enterprise cloud at scale while effectively 32 accounting for security, governance, and modern architectures. This SOO is intended to 33 maximize Offeror flexibility in proposing and delivering solutions to meet DoD’s requirements. 34 1 Purpose 36

The purpose of this SOO is to describe the performance objectives, requirements, and 38 metrics for the JEDI Cloud contract. 39

2 Scope 41

JEDI Cloud will provide enterprise-level, commercial IaaS and PaaS to support DoD 43 business and mission operations. This means that JEDI Cloud users will include all of DoD as 44 defined in 10 U.S.C. 111. Other potential users, subject to compliance with all applicable 45 statutes, regulations, and policies, may include the following entities when the order is directly 46 related to DoD business and mission operations: the U.S. Coast Guard; the Intelligence 47 Community (excluding DoD agencies); countries with which the United States (U.S.) has 48 collective defense arrangements as defined by the U.S. Department of State; and Federal 49 government contractors. 50

JEDI Cloud services will be offered at all classification levels, across the homefront to 52 the tactical edge, including disconnected and austere environments, and closed loop networks. 53 JEDI Cloud services are required to meet industry-standard service level agreements (SLAs) and 54 the requirements of this SOO regardless of where services are being delivered. 55

Achieving ongoing commercial parity is a key underpinning of the JEDI Cloud 57 acquisition. To that end, there is no requirement for unclassified data center locations and 58 network infrastructure (including points of presence and the transport layer) to be dedicated or 59 exclusive to DoD as long as the data centers and infrastructure comply with the requirements of 60 the JEDI Cloud Cyber Security Plan. The classified infrastructure must be physically isolated 61 from all other Offeror infrastructure. 62

Unless otherwise annotated, the stated objectives, requirements, and metrics in the SOO 64 apply across all classification levels. Also, unless otherwise stated, all date ranges in the SOO are 65 calendar days. The Government understands that some Cloud Service Providers (CSPs) may 66 propose functionality beyond anything specified in the SOO as part of their commercial cloud 67 offerings. The SOO should not be interpreted as limiting any potential functionality within the 68 proposed solution. 69

At a high level, there are eight primary objectives that the acquired cloud solution must 71 achieve: 72

2.1. Available and Resilient Services: A solution that provides highly 74 available, resilient infrastructure that is reliable, durable, and can continue to operate despite 75 catastrophic failure of pieces of infrastructure. The infrastructure must be capable of supporting 76 geographically dispersed users across the homefront to the tactical edge and at all classification 77 levels, including in closed-loop networks as standalone computing and storage resources which 78 may re-sync with global infrastructure to support warfighter operations. 79

2.2. Globally Accessible: Computing and storage resources that are securely 81 accessible worldwide, regardless of location and connectivity status, at all classification levels. 82 The computing and storage resources must provide assured access and enable interoperability 83 between virtual enclaves containing applications to and data. 84

2.3. Centralized Management and Distributed Control: A solution that 86 enables a central Cloud Computing Program Office (CCPO) to exert appropriate oversight and 87 management of cloud services for the DoD including the ability to apply security policies; 88 monitor security compliance and service usage across the network; and promulgate standardized 89 service configurations; and to automate, to the extent possible, and distribute the account 90 provisioning process, including the management of budgets and expenditures, from the CCPO to 91 users. 92

2.4. Ease of Use: A solution that decreases the technical expertise required to 94 effectively store data and access, deploy, and manage applications using cloud services. The 95 solution must offer efficient self-service and initiation of computing and storage services 96 enabling rapid development and deployment of new applications and advanced capabilities. 97 Additionally, the solution must be capable of hosting and allowing for extraction of modern 98 applications and structured data. 99

2.5. Commercial Parity: An environment that delivers parity with 101 commercially available cloud service offerings where the services available to JEDI Cloud 102 users keep pace with advancements in industry and new features are rapidly made available to 103 JEDI Cloud users as they become commercially available. This also includes ongoing parity 104 with public commercial prices for the cloud service offerings available to JEDI Cloud users. 105

2.6. Modern and Elastic Computing, Storage and Network Infrastructure: 107

A solution that enables provisioning of modern computing, storage and network infrastructure 108 that is updated and maintained regularly -- including processing architectures, servers, storage 109 options, and platform software -- and with scale to meet consumption to enable rapid 110 development and deployment in support of mission needs. 111

2.7. Fortified Security: Security that enables enhanced cyber defenses from 113 the root level of systems through the application layer and down to the data layer with improved 114 capabilities including continuous monitoring and auditing, automated threat identification, 115 resiliency against persistent adversary threat, encryption at rest and in transit, and an operating 116 environment that meets or exceeds DoD information security requirements. 117

2.8. Advanced Data Analytics: An environment that securely enables data-119 driven and timely decision making at the tactical level (within a single data domain) and strategic 120 level (across data domains) and supports advanced data analytics capabilities such as machine 121 learning and artificial intelligence. 122

3 Performance Requirements 124

The requirements in this section are a minimum capability, condition, or attribute of JEDI 126 Cloud. All time-based requirements apply to all cloud offerings, including tactical edge. 127

3.0 The proposed solution must be available and meet security requirements as specified in the 129 Cyber Security Plan within 30 days of the conclusion of the post award kickoff event for 130 unclassified services. Classified infrastructure capable of supporting Secret services and meeting 131 Secret-level security requirements must be provided by the Contractor within 180 days of the 132 conclusion of the post award kickoff event. Classified infrastructure capable of supporting all 133 classified services (including Top Secret, SCI, and SAP) and meeting all security requirements 134 outlined in the JEDI Form DD 254 must be provided within 270 days of the conclusion of the 135 post award kickoff event. 136

3.1 Provide computing, networking, and storage IaaS and PaaS offerings. 138

3.1.1 Provide a user interface for provisioning and deploying of cloud-based computing, 139 networking, and storage services, including provisioning of pre-configured machine images, and 140 a simple mechanism to deprovision any deployed service. 141

3.1.2 Provisioning a new workspace, user, or service offering, or deploying said offerings 142 within JEDI Cloud, must not take any longer than the level of service that is provided in the 143 Offeror’s publicly-available Commercial Cloud assuming that the offerings have been authorized 144 for use in JEDI Cloud. 145

3.1.3 The DoD must have a mechanism for activating and deactivating any cloud service 146 offering for particular workspaces or all workspaces under the JEDI Cloud contract. 147

3.1.4 Provide a mechanism to deploy cloud-based computing and storage services based 148 on standardized, pre-made configurations and security policies, where appropriate, and a simple 149 mechanism to deprovision any service. 150

3.1.5 When an authorized user requests a cloud resource within the Offeror’s portal, or 151 via an API, the response time for when the portal confirms that resource deployment has begun 152 must be on the order of seconds. 153

3.1.6 The time required to go from power off to receiving and processing user 154 instructions (less any operating system boot time) for an individual IaaS compute instance must 155 be on the order of seconds. 156

3.1.7 Provide processing unit architectures, system memory, storage capabilities, and 157 networking options that are optimized for specific compute-based IaaS activities. 158

3.1.8 Provide an API Gateway service that allows JEDI Cloud users the ability to 159 develop, deploy, secure and scale their APIs as needed. 160

3.1.9 Provide the ability to remotely connect to a virtual desktop environment that has 161 access to persistent storage. 162

3.2 Provide the ability for JEDI Cloud to scale globally. Scalability improves computing and 164 storage capacity, in an efficient and rapid manner, to meet mission requirements. 165

3.2.1 Infrastructure and networks supporting at the classified services must be physically 166 separate from the infrastructure and networks supporting unclassified services. 167

3.2.2 The Offeror shall provide redundant and globally distributed points of presence 168 ultimately available on all continents (except Antarctica) through two or more connections 169 providing a total bandwidth capacity of at least 40 Gigabits per second. 170

3.2.2.1 Compliant points of presence must be active and available for use on all 171 continents except Africa and Antarctica at the time of proposal submission. 172

3.2.2.2 One or more compliant points of presence must be located in Africa, 173 active, and available for use within 30 days of the conclusion of the post award kickoff 174 event. 175

3.3 Meet all requirements outlined in the JEDI Cloud Cyber Security Plan. 177

3.4 The Offeror must provide encryption and logical isolation for the unclassified and classified 179 offerings. 180

3.4.1 The Offeror must provide the ability to encrypt data at rest and data in transit, such 181 that users can choose to require the implementation of up to two layers of NSA-approved 182 encryption using algorithms and procedures specified in Committee on National Security 183 Systems Policy (CNSSP) 15. Users must be able to specify encryption at rest and in transit as a 184 default configuration. 185

3.4.2 The Offeror must provide logical separation with cryptographic certainty of 186 processing between tenants within the virtualized environment to include the implementation and 187 configuration of the hypervisor. 188

3.4.3 Encryption keys will be managed by either the JEDI Cloud user or Offeror at the 189 discretion of the user. 190

3.5 The Offeror must provide secure data transfer capability with the attributes described below. 192

3.5.1 Secure and highly deterministic one-way data transfer capability between logical 193 enclaves and tenants within the cloud offering, to external destinations, including multi-tenant 194 peering gateways, and across classification levels, while limiting any additional threats. 195

3.5.2 Protect enclaves from cyber threats, including malware and virus transfer, and 196 prevent penetration by external sources. 197

3.5.3 Allow specific role-based accounts to overrule automated security measures to 198 securely transfer information that may be flagged as malicious. 199

3.5.4 Mitigate the risk of the transfer capability as a covert channel. 200

3.5.5 Enforce technical policies controlling how data transfer capabilities can be used 201 including gaining the appropriate role-based approval for use. 202

3.5.6 The ability to configure secure network fabrics as needed for their applications to 203 work and interact with each other and services outside of JEDI Cloud. 204

3.6 The Offeror must provide automated information security and access control tools with the 206 attributes described below. 207

3.6.1 Auditability of both the physical location and logical isolation of any hosted service 208 to ensure compliance with security policy. 209

3.6.2 Automated breach identification. 210

3.6.3 Self-service and automated tools for handling data spills of classified or other 211 controlled information. 212

3.6.4 Ability to erase data in both unclassified and classified environments. 213

3.6.5 Ability to purge data in classified environments. 214

3.6.6 Self-service tools to access data and analysis generated by threat detection systems. 215

3.6.7 The ability to provide notifications and findings of threats to system owners. 216

3.6.8 The ability to enable and disable services and restrict parameters within service 217 configurations, in a manner that is easy to use by the majority of users. 218

3.6.9 Object and resource access control management, including data and resource 219 tagging for billing tracking, access control, and technical policy management. 220

3.7 With respect to authentication, authorization, and identity and access management the 222 Offeror must provide mechanisms for each of the below. 223

3.7.1 Highly granular role-based access control (RBAC) configuration within a 224 workspace to include workspace administration, provisioning of new cloud services, and 225 management of existing services and the ability to assign permissions to roles in accordance with 226 technical policies. 227

3.7.2 Securely verify user identity using modern authentication protocols, including 228 multi-factor authentication (MFA) and public key infrastructure (PKI) that work in all JEDI 229 Cloud environments. 230

3.7.3 Federated identity support wherever the Offeror’s identity management systems are 231 in use (including across all classification levels and at the tactical edge). The Offeror must 232 provide the ability to generate and issue time-limited, role-based authentication tokens that allow 233 a user to assume a set of permissions within a specific workspace within the cloud environment. 234

3.8 Provide cloud-service usage and billing reports for all workspaces under the JEDI Cloud 236 contract and by specified workspace(s). 237

3.8.1 Provide a user interface to track budgets, including spend reports, cost planning and 238 projections, and setting limits based on cloud service usage both for individual workspaces and 239 all workspaces under the JEDI Cloud contract, including notifications and alerts where 240 appropriate. Provide usage reports that contain service usage for all billable aspects offered by 241 the Offeror. This information must be produced at the workspace level and for all workspaces 242 under the JEDI Cloud contract. 243

3.8.2 Provide an application program interface (API) with access to service usage, actual 244 user costs, and the ability to set billing limits with notifications for individual workspaces and for 245 all workspaces under the JEDI Cloud contract. 246

3.8.3 All billing reports and invoices must identify major categories of actual user cost 247 drivers so that users can determine what variables are impacting consumption of the provisioned 248 offerings and corresponding price consequences. Users must be able to set a threshold such that 249 when spending in the specified workspace reaches the threshold automated notifications are sent 250 to the user, CCPO, and Task Order Contracting Officer. 251

3.9 The Offeror shall provide an API for the IaaS and PaaS offerings that is capable of creating, 253 reading, updating, and deleting resources as identified below. All areas of the API must be 254 accessible to all JEDI Cloud users provided they have the proper access control authorization. 255

3.9.1 The API must provide, at a minimum, the following: 256

3.9.1.1 Identity and access management, including account creation and 257 management within the JEDI Cloud contract, token-based and time-limited federated 258 authentication, role-based access control configuration; 259

3.9.1.2 Provisioning and management of network configuration, compute 260 instances, data and object storage including database management systems, and tools for 261 scaling systems such as application server load balancing; 262

3.9.1.3 Storage object lifecycle management; 263

3.9.1.4 Reading usage data and alerts for compute, storage, and network 264 utilization; 265

3.9.1.5 Reading billing data and pricing data, including by service, by specified 266 workspace, and under the entire JEDI Cloud contract; and 267

3.9.1.6 Setting billing and usage thresholds and adding automated notifications to 268 workspace owners and the CCPO. 269

3.9.2 The Offeror’s API must be actively maintained, properly versioned, documented, 270 and adhere to modern standards and protocols. Any changes which break backward compatibility 271 must be announced, and JEDI Cloud users notified, at least 30 days prior to the change being put 272 into production. 273

3.10 The Offeror must not bundle any offerings for storage, compute, and network IaaS, with 275 any particular PaaS or SaaS product. For purposes of this requirement, any PaaS that uses the 276 Offeror’s infrastructure, but which is not invoiced separately and not deployed to user 277 provisioned cloud resources, is not considered “bundled”. 278

3.11 Generational replacement and upgrading of all hardware (compute, memory, storage, and 280 networking) must have parity with the Offeror’s publicly-available Commercial Cloud. When 281 upgrading hardware, the new generation must have parity with the publicly-available 282 Commercial Cloud in all cases. 283

3.12 Provide online, nearline, and offline storage options, as well as managed database and 285 noSQL services at the scale and speed to meet mission requirements, including both object 286 storage options and managed databases. 287

3.12.1 The Offeror must have more than one online database storage offering that can 288 support data on the order of hundreds of Terabytes and can be queried in under one second. The 289 offering must perform create, read, update, and delete functions on data on the order of hundreds 290 of Terabytes within seconds, excluding network latency between the compute instance issuing 291 the query and the database management system (DBMS). 292

3.12.2 The Offeror must have at least one online object storage offering that can support 293 data on the order of Petabytes. 294

3.12.3 The Offeror must offer data storage solutions that include both traditional 295 relational databases and recent alternatives in noSQL approaches such as: Key value, Graph, 296 Document and Tuple. Versions of such database management systems must stay current with all 297 major releases of those DBMSs. 298

3.12.4 There must be options for “nearline” (versus online/offline) storage solutions. 299 Such options must provide read and write access on the order of minutes. 300

3.12.5 There must be options for “offline” storage solutions. Such options must provide 301 read and write access within 24 hours. 302

3.13 The Offeror must have processes and rule-sets where required by the Freedom of 304 Information Act, Federal Records Act, Disposal of Records, Executive Order (EO) 12333, EO 305 13587, the Privacy Act, and the Health Insurance Portability and Accountability Act, and any 306 federal regulations implementing those policies. 307

3.14 Provide robust network infrastructure, suitable for handling a high volume of traffic 309 globally, in and out of the Offeror’s cloud boundary. 310

3.14.1 The Offeror’s networking hardware, including links, network points-of-presence, 311 and pass-throughs, must keep pace with commercially available networking hardware. 312

3.14.2 Network capacity, as measured by throughput and latency, must keep pace with 313 the Offeror’s publicly-available Commercial Cloud. 314

3.15 Provide dynamic scalability and resiliency through industry standard mechanisms. 316

3.15.1 The ability for users to create system configurations, either manually or through 317 APIs, to provide automated redundancy of storage, networking and computing systems in the 318 case of catastrophic data center loss. 319

3.15.2 There must be no fewer than three physical data center locations providing 320 unclassified JEDI Cloud services and no fewer than three physical data center locations 321 providing classified JEDI Cloud services within the Customs Territory of the United 322 States, as defined in FAR 2.101. Each classification level requires its infrastructure to be 323 hosted in at least three data centers, so if an Offeror proposes physically separate 324 classified data centers at different classification levels, each classification level requires 325 at least three data centers. 326

3.15.2.1 Each data center must be capable of automated failover of computing, 327 network and storage services to one another within a classification level. 328

3.15.2.2 Geographic dispersion of all data centers within a classification level is 329 such that at least three physical data centers are at least 150 miles from each other. 330 Unclassified and classified (both Secret and Top Secret) data centers may be co-331 located so long as the classified data center meets the DD Form 254 requirements. 332

3.15.3 Provide automatic monitoring of resource utilization and events (to include 333 failures and degradation of service) via web interface and documented APIs that are intuitive and 334 easy to use. These APIs must have online documentation that is readily discoverable, including 335 example code. 336

3.16 Portability. 338

3.16.1 A portability plan must be provided in accordance with the Portability Plan CDRL. 339 (CLIN x005). The portability plan must specifically identify, in the form of user instructions, the 340 complete set of processes and procedures that are necessary to extract all online, nearline, and 341 offline data, including, but not limited to, databases, object and file storage, system 342 configurations, cloud activity logs, source code hosted in a JEDI Cloud code repository, and 343 network configurations such that any JEDI Cloud user can use these instructions to migrate from 344 JEDI Cloud to another environment. Such procedures should be part of a consolidated, single 345 effort versus individual export actions across separate data storage mechanisms, servers, 346 networks, etc. within a cloud workspace. The portability plan must also include an explanation 347 evidencing the ability to demonstrate successful erasing, purging or destruction of all system 348 components, as appropriate, and an ability to prevent re-instantiation of any removed or 349 destroyed system, capability (software or process), data, or information instances once removed 350 from JEDI Cloud. 351

3.16.2 Upon notification of the Contracting Officer, the Offeror must demonstrate 352 portability under the Portability Test line items. (CLIN x006). The Offeror must demonstrate 353 migration of an application and data (provided by the Government for this purpose) from JEDI 354 Cloud to a different hosting environment. The demonstration shall validate the Portability Plan 355 and evidence a reasonable ability to successfully migrate off of JEDI Cloud. 356

3.17 Provide data analytics service offerings, for example streaming analytics, predictive 358 analytics, machine learning, and/or eventually artificial intelligence (if not currently available), 359 available in all environments, including classified regions and disconnected environments. Such 360 offerings must be able to operate across multiple datasets in disparate workspaces across the 361 JEDI Cloud contract. 362

3.18 Provide the ability to rapidly and securely deploy CSP and third-party platform and 364 software service offerings from an online marketplace with baseline template configurations 365 where appropriate onto JEDI Cloud infrastructure. Software or platform offerings that cannot be 366 deployed on JEDI Cloud infrastructure are outside the scope of this contract. 367

3.18.1 The online marketplace within the JEDI Cloud environment must support the 368 ability for JEDI Cloud users to deploy CSP and third-party service offerings. 369

3.18.2 For third-party service offerings, the Offeror is only required to make available 370 ones that are price-free, excluding the cost of IaaS resources, or where the DoD already 371 possesses a license using the bring your own license (BYOL) approach. At least 90% of all 372 price-free platform and software service offerings that are available in the CSP’s publicly-373 available commercial cloud environment must also be available in the unclassified JEDI Cloud 374 environment. 375

3.18.3 For BYOL, DoD will be responsible for negotiating the terms and conditions of 376 the licenses under a separate contracting vehicle. A BYOL deployment must include integrated 377 billing with the JEDI Cloud user’s workspace. 378

3.18.4 The Offeror’s marketplace must support security scanning of new and existing 379 services being offered and also include a rapid method to notify customers using any 380 marketplace service that a vulnerability has been discovered. 381

3.18.5 Deployed third-party platform and software services must include integrated 382 billing. 383

3.18.6 The CCPO must be able to disable ordering of any marketplace offering for users 384 of the JEDI Cloud contract. 385

3.19 Provide Tactical Edge Devices that are suitable for the full range of military operations. 387

3.19.1 The tactical edge computing and storage capabilities must be able to function in 388 totally disconnected or closed loop mode, including provisioning IaaS and PaaS services, locally 389 running containerized applications, data analytics, and processing data. 390

3.19.2 These capabilities must provide for automated bidirectional synchronization of 391 data storage with the cloud environment when connection is re-established. These capabilities 392 must also provide the ability to control synchronization order and throttle synchronization 393 bandwidth. 394

3.19.3 Include the capability to control the magnitude of electromagnetic emanations. 395

3.19.4 The proposed solution must provide an ability to replace any tactical edge device 396 in a manner that is suitable for the range of military operations and with minimal mission impact. 397

3.19.5 Upon Government request, the proposed tactical edge device shall be certified as 398 meeting the MIL-STD-810G. The certification process is at no additional cost to the 399 Government. 400

3.19.6 Tactical edge devices must include, but are not limited to, a) durable, ruggedized, 401 and portable compute and storage, and b) static, modular, rapidly deployable data centers. To re-402 emphasize, the tactical edge capabilities should enable JEDI Cloud users to use cloud computing 403 and storage resources across the range of military operations. 404

3.19.7 Tactical edge capabilities must follow the Cyber Security Plan, including physical 405 and logical separation requirements, except when explicitly stated otherwise in the contract. 406

3.19.8 All tactical edge capabilities must be remotely configurable and maintainable to 407 the greatest extent possible. 408

3.19.9 Tactical edge capabilities must support key management both on and off the 409 device at the discretion of the user. 410

3.19.10 Offeror is responsible for the delivery of tactical edge devices to CONUS 411 locations. Any services and fees associated shall be identified and priced in the relevant catalog. 412

3.19.11 At a minimum the operating and transporting temperature thresholds for the 413 tactical edge devices are the “Basic Hot” and “Basic Cold” daily cycles identified in Table 1, 414 Part Three of MIL-STD-810G (page: PART THREE-10). 415

3.19.12 The Government will not order any tactical edge devices (including both static, 416 modular, rapidly deployable data centers and portable devices) until the first unit is assessed and 417 authorized within each classification level. 418

3.20 The Offeror must provide prompt notification and follow up reporting on any service 420 incidents and problems. 421

3.21 The Offeror must provide standard and easy-to-interpret logs, for both humans and 423 machines, for tracking provisioning of services, configuration changes, service access and errors, 424 and any relevant audit trail events. 425

3.21.1 All actions in the system, whether by a human or a machine, must be loggable to 426 an external, non-overwritable destination also within the cloud offering. Such logs must be 427 sufficient to provide an audit trail of activities and actions as required in accordance with DoD 428 CIO Memorandum, Department of Defense Cybersecurity Activities Performed for Cloud 429 Service Offerings, dated November 15, 2017. 430

3.22 The Offeror must provide a pricing calculator with realistic, contractually accurate, and easy 432 to perform price modeling and projection. The calculator must be able to make projections to 433 support users’ long-term (in excess of 12 months) planning needs. 434

3.22.1 Provide a range of service pricing structures that incorporate both usage-based 435 pricing to incentivize efficient utilization of cloud computing resources and subscription models 436 for reserved resources. 437

3.23 The Offeror must provide easy to understand training materials and documentation using a 439 variety of training modalities that helps users understand how to successfully provision services 440 and provides best practices for using services under the JEDI Cloud contract. (CDRLs A005 and 441 A006). Separate training materials and documentation are required for tactical edge capabilities. 442

3.24 Provide a catalog of support under the Cloud Support Package line items in the contract to 444 advise and assist with architecture, usage, provisioning, configuration of unclassified and 445 classified IaaS and PaaS offerings, to include homefront to the tactical edge; and advise and 446 assist users on optimizing the use of cloud services under the JEDI Cloud contract. Package 447 services shall also include training on, advising on, and assisting with integration, aggregation, 448 orchestration, and troubleshooting of cloud services. (CDRLs A005 and A006). 449

3.24.1 If a Cloud Support Package offering is constrained by the number of hours 450 available to users, then the Offeror must provide a mechanism for users to inquiry how many 451 hours have been consumed (without that request consuming additional hours) within 24 hours of 452 submitting a request. 453

3.25 Provide overarching program management capabilities under the Cloud Computing 455 Program Office (CCPO) Program Management Support line items to oversee all contract 456 activities for the ID/IQ during the entire period of performance of the ID/IQ. One of the purposes 457 of CCPO Program Management Support is to align with the CCPO and provide feedback to 458 ensure the JEDI Cloud contract is being used efficiently and in line with commercial practices. 459 The requirements listed below are in addition to any requirements identified in any CCPO TO 460 for CCPO PM Support. 461

3.25.1 Conducting any activities necessary to authorize the unclassified and classified 462 IaaS and PaaS infrastructure and offerings. 463

3.25.2 Conducting continuous audit assessments and, as needed, management reviews as 464 requested by the CCPO. 465

3.25.3 Providing reports for all workspaces under the JEDI Cloud contract, as needed, on 466 infrastructure hosting JEDI Cloud users’ systems, including specific server hardware, network 467 systems, power infrastructure, cooling systems, etc. and software running on those systems 468 below the virtualization layer. 469

3.25.4 Delivering to the CCPO and executing the Transition Out Plan IAW Section C3: 470 Transition Out. (CDRL A002). 471

3.25.5 Advising on CCPO program artifacts including acquisition life cycle 472 documentation in an effort to maintain commercial parity. 473

4 Desired Capabilities 474 The desired capabilities are “nice to have” capabilities that are above and beyond the required 476 performance requirements of JEDI Cloud. 477

4.1 Tactical Edge 479

4.1.1 Tactical edge capabilities that enhance warfighting advantage. For example, devices that 481 require minimal or no external power and are capable of running for extended periods of time 482 without battery swap or recharging. Other examples include smaller form-factor devices that are 483 human-portable for extended periods of time; or capabilities that are deployable into air or space. 484

4.1.2 Innovative solutions for overcoming logistics challenges in delivering, maintaining, and/or 485 return shipping tactical edge capabilities. 486

4.2 Security 488

4.2.1 Advanced automated security capabilities, for example, the ability to detect and respond to 490 adversaries through artificial intelligence. 491

4.3 Cloud Support Package 493

4.3.1 Smaller, more incremental levels of support beyond the Offeror’s standard Cloud Support 495 Package offerings. 496

4.3.2 Includes specialized training support in various modalities, including, but not limited to, 497 classroom, train-the-trainer, certifications, and advising on the development of training packages. 498

5 Performance Metrics: The metrics defined below identify the performance requirements for 501 JEDI Cloud. These metrics will be reviewed at least annually and may change as technological 502 advances occur. 503

Table 5.1*

Item Objectives Standard Acceptable Quality Limit (must occur within time indicated within x%)

Monitoring Method

1 Time to provision new VM (excludes boot time)

Under 2 minutes 95% Activity log analysis

2 Time to spin up object storage

Under 2 minutes 98% Activity log analysis

3 Time to spin up a 100GB block storage container and attach it to a running VM

Under 1 minute 98% Activity log analysis

4 Response time for confirmation of job submission

Under 2 seconds 99% Activity log analysis

5 Time required to go from power off to receiving and processing user instructions for a VM

Under 15 seconds

95% Activity log analysis

6 Patch application and updates to underlying infrastructure and cloud services

Within 8 Hours of notification

95% of patches and updates must be completed within required time frame.

Security audit by CCPO and reporting by vendor

7 Infrastructure vulnerability disclosure to CCPO

Within 60 minutes of identification

100%.

Disclosures must be identified within required time.

Security audit by CCPO and reporting by vendor

8 Alerts and Sent within 10 99% Vendor log notifications for budgeting and usage based thresholds minutes of crossing threshold analysis

9 Usage metrics available in vendor

API

No more than 15 minutes lag between usage and API reporting

99% Activity log and API access

10 Actual user cost (billing) available in vendor API

No more than 24 hours lag between usage and API reporting

99% Activity log, API access, and invoices

11 All API systems up-time

99.999 % Uptime must be met 100% of the time.

Vendor status log analysis

12 All API response time

Less than 500 ms of added latency

98% API and network traffic log analysis

13 Achieve classified hardware and networking commercial parity

Within 30 days from unclassified deployment (ready for IV&V testing)

100% Report to CCPO and/or independent audit

14 Achieve classified software (DBMS, OS, Hypervisor, Hosted Services) commercial parity

Within 24 hours of unclassified deployment (ready for IV&V testing)

99% Report to CCPO and/or independent audit

15 Time for DBMS to receive request and respond with data within single availability zone

Under 200 ms, excluding query processing time

99% Database and network log analysis

16 Time for DBMS to receive request and respond with data across availability

Under 1 second, excluding query processing time

99% Database and network log analysis zones 17 Offering of latest

DBMS software offered as IaaS and PaaS offerings (excluding online marketplace offerings)

Less than 24 hours of public release

95% Analysis of catalog changes over time

18 “Nearline” storage read / write the first byte

Under 30 seconds

95% Data storage log analysis

19 “Offline” storage read / write accessible

Under 24 hours 95% Data storage log analysis

20 Time necessary to execute plan identified in CLIN x005 is less than 12 hours

Upon notification from CO, within 12 hours to execute the demonstration

99% Activity log analysis and/or

CCPO

monitoring

21 System activity logging

Less than 1 second after activity execution

99% Activity log analysis

22 Online marketplace offering deploy time starting from authentication in the online portal

Within 5 minutes, excluding time spent waiting for actions being taken by 3rd parties and the time required for any required infrastructure to start up.

95% Analysis of marketplace catalog changes over time

23 Network request and response time between two VMs within the same availability zone

Under 50 ms 99% Network traffic log analysis

24 Network request and response time between two VMs in different availability zones

Under 200 ms 99% Network traffic log analysis

25 Make new cloud service offerings and updates and modifications to existing service offerings available in classified JEDI Cloud environment

Within 30 days (ready for IV&V testing)

99% Report to CCPO and/or independent audit

26 Make new publicly-available commercial marketplace offerings available in classified JEDI Cloud environment (excluding any third party marketplace offerings the contract does not require to be made available to JEDI Cloud users)

Within 30 days (ready for IV&V testing)

99% Catalog availability

27 Notification and nature of service incident impacting JEDI Cloud users

Under 10 minutes

99% Analysis of incident reports and notifications

28 Detailed report on any service incident impacting DoD customers

Within 7 days 95% Analysis of service incident report

29 Recovery Point Objective / Recovery Time Objective

10TB (RPO)

within 5 minutes

(RTO)

98% Random Sampling

30 Delivery of portable tactical edge device in CONUS to the designated address

10 calendar days from date of order placement

80% Random sampling

31 Delivery of modular data center in CONUS to the designated address

14 calendar days from date of order placement

80% Random sampling

* All performance metrics apply to tactical edge capabilities unless explicitly stated otherwise. 506 For unclassified and classified tactical edge devices that are deployed, accepting any 507 modifications to the services and offerings are at the discretion of the JEDI Cloud user. If a JEDI 508 Cloud user does not accept a modification, the Offeror is not responsible for meeting 509 Performance Metrics that are directly affected by the JEDI Cloud user’s decision. 510 Constraints 512 Any constraints are provided elsewhere in the SOO or listed in the Cyber Security Plan. 514 Deliverables 516

Table 5.2

CDRL Deliverable Frequency / Date of First Submission

Medium/Forma t/# of Copies

Submit To

A001 Contract Monthly Progress Report

Monthly Electronic copy in Offeror’s preferred format

CCPO

A002 Transition Out Plan

As required Electronic copy in Offeror’s preferred format

CCPO

A003 Contract Security Management Plan

Within 30 days of contract award and then annually thereafter;

updated annually or as required to reflect necessary changes.

Electronic copy in Offeror’s preferred format

CCPO

A004 Technology Refresh Plan

Within 30 days after contract award and then semi-annually

Electronic copy in Offeror’s preferred format

CCPO

thereafter

A005 System Administrator Training Materials

Within 30 days after award;

updated annually or as required

Various CCPO and Ordering Activity

A006 Role-Based User Training Materials

Within 30 days after award;

updated as required

Various CCPO and Ordering Activity

A007 Portability Plan Within 60 days of contract award

Electronic copy in Offeror’s preferred format

CCPO

A008 Contract Ordering Guide

Within 15 days after Government developed sections provided;

updated annually or as required to reflect necessary changes.

Electronic copy in Offeror’s preferred format

CCPO

A009 Change Management Roadmap

Within 90 days of contract award, then annually thereafter

Electronic copy in Offeror’s preferred format

CCPO

A010 Quality Control Plan

Within 30 days of contract award, then annually thereafter

Electronic copy in Offeror’s preferred format

CCPO

A011 Security Authorization Package

Various depending classification level

Electronic copy in format acceptable to the FedRAMP process

CCPO

A012 Technical Report

As required Electronic copy in Offeror’s preferred format

CCPO

A013 Small Business Reporting

Annually after date of contract award

Electronic copy in Offeror’s preferred format

CCPO

A014 Portability Test As required In accordance with the Portability Plan

CCPO

A015 Task Order Monthly Progress Report

As required Electronic copy in Offeror’s preferred format

CCPO and/or Ordering Activity

A016 Meeting Materials

Quarterly Electronic copy in Offeror’s preferred format

CCPO

Unless otherwise specified, the Government shall have fifteen calendar days to review and 519 provide comments to all deliverables. Any deliverables that are not commented upon within that 520 time frame are deemed approved. Offeror shall have five calendar days to revise and resubmit 521 any deliverables that the Government provides comments upon. 522

File details come from the government source that posted it.