Attachment_L-1_Statement_of_Objectives.pdf

PDF 188 KB Posted

Attached to
JEDI Cloud RFP Federal contract opportunity
Solicitation number
HQ003418R0077_JEDI_CLOUD_RFP
Issued by
DOD Washington Headquarters Service

About this file

Attachment L-1 : JEDI Cloud SOO

View the file

Other files for this federal contract opportunity

Other files attached to JEDI Cloud RFP, newest first.
File Type Posted
Attachment_L-5_Price_Scenario_Price_Build-up_Template_Updated_.xlsx XLSX spreadsheet
HQ0034-18-R-0077_0002.pdf PDF
Amendment_0002_Summary_of_Changes.pdf PDF
Attachment_J-7_DD_Form_254,_DoD_Contract_Security_Classification_Specification_for_ID_IQ_Amendment_0002.pdf PDF
JEDI_Cloud_Industry_and_Gov_QA_Amendment_0001.pdf PDF
Attachment_L-8_PWS-SOO_Crosswalk_Matrix-Amendment_0002.xlsx XLSX spreadsheet
Attachment_L-2_Price_Scenarios_Amendment_0001.pdf PDF
Attachment_J-8_Definitions_Amendment_0001.pdf PDF
Amendment_0001_Summary_of_Changes.pdf PDF
Attachment_L-1_Statement_of_Objectives_Amendment_0001.pdf PDF
JEDI_Cloud_Industry_and_Gov_QA_Final_RFP.pdf PDF
Oracle_Pre-Award_Protest.pdf PDF
Attachment_L-3_Task_Order_001_PWS.pdf PDF
JEDI_CDRL_A006_-_Role-Based_User_Training_Materials.pdf PDF
MIL-STD-810G_CN1.pdf PDF
JEDI_CDRL_A014_-_Portability_Test.pdf PDF
JEDI_CDRL_A004_Technology_Refresh_Plan.pdf PDF
Attachment_L-4_Task_Order_002_PWS.pdf PDF
Attachment_L-9__Company_Non-Disclosure_Agreement_for_JEDI_Cloud.pdf PDF
JEDI_CDRL_A001_-_Contract_Monthly_Progress_Report.pdf PDF
JEDI_CDRL_A002_-_Transition_Out_Plan.pdf PDF
JEDI_Cloud_Comment_Resolution_Matrix_for_Final_RFP.xlsx XLSX spreadsheet
JEDI_Cloud_Industry_and_Gov_QA_dRFP2.pdf PDF
JEDI_CDRL_A008_-_Contract_Ordering_Guide.pdf PDF
180510_Final_Cloud_Combined_Congressional_Report__vg7_PDF_Redacted.pdf PDF
Attachment_L-7_OCI_Analysis_Disclosure_Form.pdf PDF
DoD_CIO_RFP_Release_Letter_26_Jul.pdf PDF
CNSSP15.pdf PDF
Attachment_L-6__Small_Business_Subcontracting_Plan_Template.docx DOCX document
JEDI_CDRL_A011_-_Security_Authorization_Package.pdf PDF
Attachment_L-8_PWS-SOO_Crosswalk_Matrix.xlsx XLSX spreadsheet
Attachment_J-8_Definitions.pdf PDF
JEDI_CDRL_A007_-_Portability_Plan.pdf PDF
Attachment_J-10__Small_Business_Participation_Commitment_Document.pdf PDF
Attachment_J-7_Form_DD254.pdf PDF
Attachment_J-6_JEDI_Cyber_Security_Plan.pdf PDF
JEDI_CDRL_A015_-_Task_Order_Monthly_Progress_Report.pdf PDF
JEDI_CDRL_A013_-_Small_Business_Reporting.pdf PDF
JEDI_CDRL_A016_-_Meeting_Materials.pdf PDF
Attachment_L-2_Price_Scenarios.pdf PDF
JEDI_CDRL_A009_-_Change_Management_Roadmap.pdf PDF
PM_Letter_for_RFP_Release_Letter.pdf PDF
JEDI_CDRL_A005_-_System_Administrator_Training_Material.pdf PDF
JEDI_CDRL_A010_-_Quality_Control_Plan.pdf PDF
JEDI_Single_Award_DF-USD(AS)__17July18.pdf PDF
JEDI_CDRL_A012_-_Technical_Report.pdf PDF
In-Person_Q&A_Session_Information.pdf PDF
JEDI_CDRL_A003_-_Contract_Security_Management_Plan.pdf PDF
HQ0034-18-R-0077.pdf PDF
Attachment_L-5_Price_Scenario_Price_Build-up_Template.xlsx XLSX spreadsheet
Show all 50

JEDI Cloud RFP has more files on GovTribe.

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

Attachment L-1 1 Joint Enterprise Defense Infrastructure (JEDI) Cloud 2

Statement of Objectives (SOO) 3 As of 26 July 2018 4

0 Introduction 6

The Department of Defense’s (DoD’s) lack of a coordinated enterprise-level approach to 8 cloud infrastructure and platforms prevents warfighters and leaders from making critical data-9 driven decisions at “mission-speed”, negatively affecting outcomes. In the absence of modern 10 services, warfighters and leaders are forced to choose between foregoing capabilities or slogging 11 through a lengthy acquisition, rollout, and provisioning process. A fragmented and largely on-12 premises computing and storage solution forces the warfighter into tedious data and application 13 management processes, compromising their ability to rapidly access, manipulate, and analyze 14 data at the homefront and tactical edge. Most importantly, current environments are not 15 optimized to support large, cross domain analysis using advanced capabilities such as machine 16 learning and artificial intelligence to meet current, and future warfighting needs and 17 requirements. 18

To maintain our military advantage, DoD requires an extensible and secure cloud 20 environment that spans the homeland to the global tactical edge, as well as the ability to rapidly 21 access computing and storage capacity to address warfighting challenges at the speed of 22 relevance. These foundational infrastructure and platform technologies are needed for DoD to 23 capitalize on modern software, keep pace with commercial innovation, and make use of artificial 24 intelligence and machine learning capabilities at scale. 25

This Statement of Objectives (SOO) describes the Joint Enterprise Defense Infrastructure 27 (JEDI) Cloud acquisition of commercial infrastructure as a service (IaaS) and platform as a 28 service (PaaS) offerings to support DoD business and mission operations. JEDI Cloud is an 29 important first step to acquiring a general purpose cloud capable of delivering infrastructure and 30 platform services for the bulk of the Department’s mission. JEDI Cloud will also serve as a 31 pathfinder for DoD to understand how to deploy enterprise cloud at scale while effectively 32 accounting for security, governance, and modern architectures. This SOO is intended to 33 maximize Offeror flexibility in proposing and delivering solutions to meet DoD’s requirements. 34 1 Purpose 36

The purpose of this SOO is to describe the performance objectives, requirements, and 38 metrics for the JEDI Cloud contract. 39

2 Scope 41

JEDI Cloud will provide enterprise-level, commercial IaaS and PaaS to support DoD 43 business and mission operations. This means that JEDI Cloud users will include all of DoD as 44 defined in 10 U.S.C. 111. Other potential users, subject to compliance with all applicable 45 statutes, regulations, and policies, may include the following entities when the order is directly 46 related to DoD business and mission operations: the U.S. Coast Guard; the Intelligence 47 Community (excluding DoD agencies); countries with which the United States (U.S.) has 48 collective defense arrangements as defined by the U.S. Department of State; and Federal 49 government contractors. 50

JEDI Cloud services will be offered at all classification levels, across the homefront to 52 the tactical edge, including disconnected and austere environments, and closed loop networks. 53 JEDI Cloud services are required to meet industry-standard service level agreements (SLAs) and 54 the requirements of this SOO regardless of where services are being delivered. 55

Achieving ongoing commercial parity is a key underpinning of the JEDI Cloud 57 acquisition. To that end, there is no requirement for unclassified data center locations and 58 network infrastructure (including points of presence and the transport layer) to be dedicated or 59 exclusive to DoD as long as the data centers and infrastructure comply with the requirements of 60 the JEDI Cloud Cyber Security Plan. The classified infrastructure must be physically isolated 61 from all other Offeror infrastructure. 62

Unless otherwise annotated, the stated objectives, requirements, and metrics in the SOO 64 apply across all classification levels. Also, unless otherwise stated, all date ranges in the SOO are 65 calendar days. The Government understands that some Cloud Service Providers (CSPs) may 66 propose functionality beyond anything specified in the SOO as part of their commercial cloud 67 offerings. The SOO should not be interpreted as limiting any potential functionality within the 68 proposed solution. 69

At a high level, there are eight primary objectives that the acquired cloud solution must 71 achieve: 72

2.1. Available and Resilient Services: A solution that provides highly 74 available, resilient infrastructure that is reliable, durable, and can continue to operate despite 75 catastrophic failure of pieces of infrastructure. The infrastructure must be capable of supporting 76 geographically dispersed users across the homefront to the tactical edge and at all classification 77 levels, including in closed-loop networks as standalone computing and storage resources which 78 may re-sync with global infrastructure to support warfighter operations. 79

2.2. Globally Accessible: Computing and storage resources that are securely 81 accessible worldwide, regardless of location and connectivity status, at all classification levels. 82 The computing and storage resources must provide assured access and enable interoperability 83 between virtual enclaves containing applications to and data. 84

2.3. Centralized Management and Distributed Control: A solution that 86 enables a central Cloud Computing Program Office (CCPO) to exert appropriate oversight and 87 management of cloud services for the DoD including the ability to apply security policies; 88 monitor security compliance and service usage across the network; and promulgate standardized 89 service configurations; and to automate, to the extent possible, and distribute the account 90 provisioning process, including the management of budgets and expenditures, from the CCPO to 91 users. 92

2.4. Ease of Use: A solution that decreases the technical expertise required to 94 effectively store data and access, deploy, and manage applications using cloud services. The 95 solution must offer efficient self-service and initiation of computing and storage services 96 enabling rapid development and deployment of new applications and advanced capabilities. 97 Additionally, the solution must be capable of hosting and allowing for extraction of modern 98 applications and structured data. 99

2.5. Commercial Parity: An environment that delivers parity with 101 commercially available cloud service offerings where the services available to JEDI Cloud 102 users keep pace with advancements in industry and new features are rapidly made available to 103 JEDI Cloud users as they become commercially available. This also includes ongoing parity 104 with public commercial prices for the cloud service offerings available to JEDI Cloud users. 105

2.6. Modern and Elastic Computing, Storage and Network Infrastructure: 107

A solution that enables provisioning of modern computing, storage and network infrastructure 108 that is updated and maintained regularly -- including processing architectures, servers, storage 109 options, and platform software -- and with scale to meet consumption to enable rapid 110 development and deployment in support of mission needs. 111

2.7. Fortified Security: Security that enables enhanced cyber defenses from 113 the root level of systems through the application layer and down to the data layer with improved 114 capabilities including continuous monitoring and auditing, automated threat identification, 115 resiliency against persistent adversary threat, encryption at rest and in transit, and an operating 116 environment that meets or exceeds DoD information security requirements. 117

2.8. Advanced Data Analytics: An environment that securely enables data-119 driven and timely decision making at the tactical level (within a single data domain) and strategic 120 level (across data domains) and supports advanced data analytics capabilities such as machine 121 learning and artificial intelligence. 122

3 Performance Requirements 124

The requirements in this section are a minimum capability, condition, or attribute of JEDI 126 Cloud. All time-based requirements apply to all cloud offerings, including tactical edge. 127

3.0 The proposed solution must be available and meet security requirements as specified in the 129 Cyber Security Plan within 30 days of contract award for unclassified services. Classified 130 infrastructure capable of supporting Secret services and meeting Secret-level security 131 requirements must be provided by the Contractor within 180 days of contract award. Classified 132 infrastructure capable of supporting all classified services (including Top Secret, SCI, and SAP) 133 and meeting all security requirements outlined in the JEDI Form DD 254 must be provided 134 within 270 days of contract award. 135

3.1 Provide computing, networking, and storage IaaS and PaaS offerings. 137

3.1.1 Provide a user interface for provisioning and deploying of cloud-based computing, 138 networking, and storage services, including provisioning of pre-configured machine images, and 139 a simple mechanism to deprovision any deployed service. 140

3.1.2 Provisioning a new account, user, or service offering, or deploying said offerings 141 within JEDI Cloud, must not take any longer than the level of service that is provided in the 142 Offeror’s publicly-available Commercial Cloud assuming that the offerings have been authorized 143 for use in JEDI Cloud. 144

3.1.3 The DoD must have a mechanism for activating and deactivating any cloud service 145 offering for particular accounts or all accounts under the JEDI Cloud contract. 146

3.1.4 Provide a mechanism to deploy cloud-based computing and storage services based 147 on standardized, pre-made configurations and security policies, where appropriate, and a simple 148 mechanism to deprovision any service. 149

3.1.5 When an authorized user requests a cloud resource within the Offeror’s portal, or 150 via an API, the response time for when the portal confirms that resource deployment has begun 151 must be on the order of seconds. 152

3.1.6 The time required to go from power off to receiving and processing user 153 instructions (less any operating system boot time) for an individual IaaS compute instance must 154 be on the order of seconds. 155

3.1.7 Provide processing unit architectures, system memory, storage capabilities, and 156 networking options that are optimized for specific compute-based IaaS activities. 157

3.1.8 Provide an API Gateway service that allows JEDI Cloud users the ability to 158 develop, deploy, secure and scale their APIs as needed. 159

3.1.9 Provide the ability to remotely connect to a virtual desktop environment that has 160 access to persistent storage. 161

3.2 Provide the ability for JEDI Cloud to scale globally. Scalability improves computing and 163 storage capacity, in an efficient and rapid manner, to meet mission requirements. 164

3.2.1 Infrastructure and networks supporting at the classified services must be physically 165 separate from the infrastructure and networks supporting unclassified services. 166

3.2.2 The Offeror shall provide redundant and globally distributed points of presence 167 available on all continents (except Antarctica) through two or more connections providing a total 168 bandwidth capacity of at least 40 Gigabits per second. 169

3.3 Meet all requirements outlined in the JEDI Cloud Cyber Security Plan. 171

3.4 The Offeror must provide encryption and logical isolation for the unclassified and classified 173 offerings. 174

3.4.1 The Offeror must provide the ability to encrypt data at rest and data in transit, such 175 that users can choose to require the implementation of up to two layers of NSA-approved 176 encryption using algorithms and procedures specified in Committee on National Security 177 Systems Policy (CNSSP) 15. Users must be able to specify encryption at rest and in transit as a 178 default configuration. 179

3.4.2 The Offeror must provide logical separation with cryptographic certainty of 180 processing between tenants within the virtualized environment to include the implementation and 181 configuration of the hypervisor. 182

3.4.3 Encryption keys will be managed by either the JEDI Cloud user or Offeror at the 183 discretion of the user. 184

3.5 The Offeror must provide secure data transfer capability with the attributes described below. 186

3.5.1 Secure and highly deterministic one-way data transfer capability between logical 187 enclaves and tenants within the cloud offering, to external destinations, including multi-tenant 188 peering gateways, and across classification levels, while limiting any additional threats. 189

3.5.2 Protect enclaves from cyber threats, including malware and virus transfer, and 190 prevent penetration by external sources. 191

3.5.3 Allow specific role-based accounts to overrule automated security measures to 192 securely transfer information that may be flagged as malicious. 193

3.5.4 Mitigate the risk of the transfer capability as a covert channel. 194

3.5.5 Enforce technical policies controlling how data transfer capabilities can be used 195 including gaining the appropriate role-based approval for use. 196

3.5.6 The ability to configure secure network fabrics as needed for their applications to 197 work and interact with each other and services outside of JEDI Cloud. 198

3.6 The Offeror must provide automated information security and access control tools with the 200 attributes described below. 201

3.6.1 Auditability of both the physical location and logical isolation of any hosted service 202 to ensure compliance with security policy. 203

3.6.2 Automated breach identification. 204

3.6.3 Self-service and automated tools for handling data spills of classified or other 205 controlled information. 206

3.6.4 Ability to erase data in both unclassified and classified environments. 207

3.6.5 Ability to purge data in classified environments. 208

3.6.6 Self-service tools to access data and analysis generated by threat detection systems. 209

3.6.7 The ability to provide notifications and findings of threats to system owners. 210

3.6.8 The ability to enable and disable services and restrict parameters within service 211 configurations, in a manner that is easy to use by the majority of users. 212

3.6.9 Object and resource access control management, including data and resource 213 tagging for billing tracking, access control, and technical policy management. 214

3.7 With respect to authentication, authorization, and identity and access management the 216 Offeror must provide mechanisms for each of the below. 217

3.7.1 Highly granular role-based access control (RBAC) configuration within an account 218 to include account administration, provisioning of new cloud services, and management of 219 existing services and the ability to assign permissions to roles in accordance with technical 220 policies. 221

3.7.2 Securely verify user identity using modern authentication protocols, including 222 multi-factor authentication (MFA) and public key infrastructure (PKI) that work in all JEDI 223 Cloud environments. 224

3.7.3 Federated identity support wherever the Offeror’s identity management systems are 225 in use (including across all classification levels and at the tactical edge). The Offeror must 226 provide the ability to generate and issue time-limited, role-based authentication tokens that allow 227 a user to assume a set of permissions within a specific account within the cloud environment. 228

3.8 Provide cloud-service usage and billing reports for all accounts under the JEDI Cloud 230 contract and by specified account(s). 231

3.8.1 Provide a user interface to track budgets, including spend reports, cost planning and 232 projections, and setting limits based on cloud service usage both for individual accounts and all 233 accounts under the JEDI Cloud contract, including notifications and alerts where appropriate. 234 Provide usage reports that contain service usage for all billable aspects offered by the Offeror. 235 This information must be produced at the account level and for all accounts under the JEDI 236 Cloud contract. 237

3.8.2 Provide an application program interface (API) with access to service usage, actual 238 user costs, and the ability to set billing limits with notifications for individual accounts and for 239 all accounts under the JEDI Cloud contract. 240

3.8.3 All billing reports and invoices must identify major categories of actual user cost 241 drivers so that users can determine what variables are impacting consumption of the provisioned 242 offerings and corresponding price consequences. Users must be able to set a threshold such that 243 when spending in the specified account reaches the threshold automated notifications are sent to 244 the user, CCPO, and Task Order Contracting Officer. 245

3.9 The Offeror shall provide an API for the IaaS and PaaS offerings that is capable of creating, 247 reading, updating, and deleting resources as identified below. All areas of the API must be 248 accessible to all JEDI Cloud users provided they have the proper access control authorization. 249

3.9.1 The API must provide, at a minimum, the following: 250

3.9.1.1 Identity and access management, including account creation and 251 management within the JEDI Cloud contract, token-based and time-limited federated 252 authentication, role-based access control configuration; 253

3.9.1.2 Provisioning and management of network configuration, compute 254 instances, data and object storage including database management systems, and tools for 255 scaling systems such as application server load balancing; 256

3.9.1.3 Storage object lifecycle management; 257

3.9.1.4 Reading usage data and alerts for compute, storage, and network 258 utilization; 259

3.9.1.5 Reading billing data and pricing data, including by service, by specified 260 account, and under the entire JEDI Cloud contract; and 261

3.9.1.6 Setting billing and usage thresholds and adding automated notifications to 262 account owners and the CCPO. 263

3.9.2 The Offeror’s API must be actively maintained, properly versioned, documented, 264 and adhere to modern standards and protocols. Any changes which break backward compatibility 265 must be announced, and JEDI Cloud users notified, at least 30 days prior to the change being put 266 into production. 267

3.10 The Offeror must not bundle any offerings for storage, compute, and network IaaS, with 269 any particular PaaS or SaaS product. For purposes of this requirement, any PaaS that uses the 270 Offeror’s infrastructure, but which is not invoiced separately and not deployed to user 271 provisioned cloud resources, is not considered “bundled”. 272

3.11 Generational replacement and upgrading of all hardware (compute, memory, storage, and 274 networking) must have parity with the Offeror’s publicly-available Commercial Cloud. When 275 upgrading hardware, the new generation must have parity with the publicly-available 276 Commercial Cloud in all cases. 277

3.12 Provide online, nearline, and offline storage options, as well as managed database and 279 noSQL services at the scale and speed to meet mission requirements, including both object 280 storage options and managed databases. 281

3.12.1 The Offeror must have more than one online database storage offering that can 282 support data on the order of hundreds of Terabytes and can be queried in under one second. The 283 offering must perform create, read, update, and delete functions on data on the order of hundreds 284 of Terabytes within seconds, excluding network latency between the compute instance issuing 285 the query and the database management system (DBMS). 286

3.12.2 The Offeror must have at least one online object storage offering that can support 287 data on the order of Petabytes. 288

3.12.3 The Offeror must offer data storage solutions that include both traditional 289 relational databases and recent alternatives in noSQL approaches such as: Key value, Graph, 290 Document and Tuple. Versions of such database management systems must stay current with all 291 major releases of those DBMSs. 292

3.12.4 There must be options for “nearline” (versus online/offline) storage solutions. 293 Such options must provide read and write access on the order of minutes. 294

3.12.5 There must be options for “offline” storage solutions. Such options must provide 295 read and write access within 24 hours. 296

3.13 The Offeror must have processes and rule-sets where required by the Freedom of 298 Information Act, Federal Records Act, Disposal of Records, Executive Order (EO) 12333, EO 299 13587, the Privacy Act, and the Health Insurance Portability and Accountability Act, and any 300 federal regulations implementing those policies. 301

3.14 Provide robust network infrastructure, suitable for handling a high volume of traffic 303 globally, in and out of the Offeror’s cloud boundary. 304

3.14.1 The Offeror’s networking hardware, including links, network points-of-presence, 305 and pass-throughs, must keep pace with commercially available networking hardware. 306

3.14.2 Network capacity, as measured by throughput and latency, must keep pace with 307 the Offeror’s publicly-available Commercial Cloud. 308

3.15 Provide dynamic scalability and resiliency through industry standard mechanisms. 310

3.15.1 The ability for users to create system configurations, either manually or through 311 APIs, to provide automated redundancy of storage, networking and computing systems in the 312 case of catastrophic data center loss. 313

3.15.2 There must be no fewer than three physical unclassified data center locations and 314 no fewer than three physical classified data center locations within the Customs Territory of the 315 United States, as defined in FAR 2.101. Each classification level requires at least three data 316 centers, so if an Offeror proposes physically separate classified data centers at different 317 classification levels, each classification level requires at least three data centers. Each data center 318 must be capable of automated failover of computing, network and storage services to one another 319 within a classification level. Geographic dispersion of all data centers within a classification 320 level is such that at least three physical data centers are at least 150 miles from each other. 321 Unclassified and classified data centers may be co-located so long as the classified data center 322 meets the DD Form 254 requirements. 323

3.15.3 Provide automatic monitoring of resource utilization and events (to include 324 failures and degradation of service) via web interface and documented APIs that are intuitive and 325 easy to use. These APIs must have online documentation that is readily discoverable, including 326 example code. 327

3.16 Portability. 329

3.16.1 A portability plan must be provided in accordance with the Portability Plan CDRL. 330 (CLIN x005). The portability plan must specifically identify, in the form of user instructions, the 331 complete set of processes and procedures that are necessary to extract all online, nearline, and 332 offline data, including, but not limited to, databases, object and file storage, system 333 configurations, cloud activity logs, source code hosted in a JEDI Cloud code repository, and 334 network configurations such that any JEDI Cloud user can use these instructions to migrate from 335 JEDI Cloud to another environment. Such procedures should be part of a consolidated, single 336 effort versus individual export actions across separate data storage mechanisms, servers, 337 networks, etc. within a cloud account. The portability plan must also include an explanation 338 evidencing the ability to demonstrate successful erasing, purging or destruction of all system 339 components, as appropriate, and an ability to prevent re-instantiation of any removed or 340 destroyed system, capability (software or process), data, or information instances once removed 341 from JEDI Cloud. 342

3.16.2 Upon notification of the Contracting Officer, the Offeror must demonstrate 343 portability under the Portability Test line items. (CLIN x006). The Offeror must demonstrate 344 migration of an application and data (provided by the Government for this purpose) from JEDI 345 Cloud to a different hosting environment. The demonstration shall validate the Portability Plan 346 and evidence a reasonable ability to successfully migrate off of JEDI Cloud. 347

3.17 Provide data analytics service offerings, for example streaming analytics, predictive 349 analytics, machine learning, and/or eventually artificial intelligence (if not currently available), 350 available in all environments, including classified regions and disconnected environments. Such 351 offerings must be able to operate across multiple datasets in disparate accounts across the JEDI 352 Cloud contract. 353

3.18 Provide the ability to rapidly and securely deploy CSP and third-party platform and 355 software service offerings from an online marketplace with baseline template configurations 356 where appropriate onto JEDI Cloud infrastructure. Software or platform offerings that cannot be 357 deployed on JEDI Cloud infrastructure are outside the scope of this contract. 358

3.18.1 The online marketplace within the JEDI Cloud environment must support the 359 ability for JEDI Cloud users to deploy CSP and third-party service offerings. 360

3.18.2 For third-party service offerings, the Offeror is only required to make available 361 ones that are free, excluding the cost of IaaS resources, or where the DoD already possesses a 362 license using the bring your own license (BYOL) approach. All free platform and software 363 service offerings that are available in the CSP’s publicly-available commercial cloud 364 environment must also be available in the unclassified JEDI Cloud environment. 365

3.18.3 For BYOL, DoD will be responsible for negotiating the terms and conditions of 366 the licenses under a separate contracting vehicle. A BYOL deployment must include integrated 367 billing with the JEDI Cloud user’s account. 368

3.18.4 The Offeror’s marketplace must support security scanning of new and existing 369 services being offered and also include a rapid method to notify customers using any 370 marketplace service that a vulnerability has been discovered. 371

3.18.5 Deployed third-party platform and software services must include integrated 372 billing. 373

3.18.6 The CCPO must be able to disable ordering of any marketplace offering for users 374 of the JEDI Cloud contract. 375

3.19 Provide Tactical Edge Devices that are suitable for the full range of military operations. 377

3.19.1 The tactical edge computing and storage capabilities must be able to function in 378 totally disconnected or closed loop mode, including provisioning IaaS and PaaS services, locally 379 running containerized applications, data analytics, and processing data. 380

3.19.2 These capabilities must provide for automated bidirectional synchronization of 381 data storage with the cloud environment when connection is re-established. These capabilities 382 must also provide the ability to control synchronization order and throttle synchronization 383 bandwidth. 384

3.19.3 These capabilities must also allow users to quantify and control magnitude of 385 electromagnetic emanations. 386

3.19.4 The proposed solution must provide an ability to replace any tactical edge device 387 in a manner that is suitable for the range of military operations and with minimal mission impact. 388

3.19.5 Upon Government request, the proposed tactical edge device shall be certified as 389 meeting the MIL-STD-810G. The certification process is at no additional cost to the 390 Government. 391

3.19.6 Tactical edge devices must include, but are not limited to, a) durable, ruggedized, 392 and portable compute and storage, and b) static, modular, rapidly deployable data centers. To re-393 emphasize, the tactical edge capabilities should enable JEDI Cloud users to use cloud computing 394 and storage resources across the range of military operations. 395

3.19.7 Tactical edge capabilities must follow the Cyber Security Plan, including physical 396 and logical separation requirements, except when explicitly stated otherwise in the contract. 397

3.19.8 All tactical edge capabilities must be remotely configurable and maintainable to 398 the greatest extent possible. 399

3.19.9 Tactical edge capabilities must support key management both on and off the 400 device at the discretion of the user. 401

3.19.10 Offeror is responsible for the delivery of tactical edge devices to CONUS 402 locations. Any services and fees associated shall be identified and priced in the relevant catalog. 403

3.19.11 At a minimum the operating and transporting temperature thresholds for the 404 tactical edge devices are the “Basic Hot” and “Basic Cold” daily cycles identified in Table 1, 405 Part Three of MIL-STD-810G (page: PART THREE-10). 406

3.20 The Offeror must provide prompt notification and follow up reporting on any service 408 incidents and problems. 409

3.21 The Offeror must provide standard and easy-to-interpret logs, for both humans and 411 machines, for tracking provisioning of services, configuration changes, service access and errors, 412 and any relevant audit trail events. 413

3.21.1 All actions in the system, whether by a human or a machine, must be loggable to 414 an external, non-overwritable destination also within the cloud offering. Such logs must be 415 sufficient to provide an audit trail of activities and actions as required in accordance with DoD 416 CIO Memorandum, Department of Defense Cybersecurity Activities Performed for Cloud 417 Service Offerings, dated November 15, 2017. 418

3.22 The Offeror must provide a pricing calculator with realistic, contractually accurate, and easy 420 to perform price modeling and projection. The calculator must be able to make projections to 421 support users’ long-term (in excess of 12 months) planning needs. 422

3.22.1 Provide a range of service pricing structures that incorporate both usage-based 423 pricing to incentivize efficient utilization of cloud computing resources and subscription models 424 for reserved resources. 425

3.23 The Offeror must provide easy to understand training materials and documentation using a 427 variety of training modalities that helps users understand how to successfully provision services 428 and provides best practices for using services under the JEDI Cloud contract. (CDRLs A005 and 429 A006). Separate training materials and documentation are required for tactical edge capabilities. 430

3.24 Provide a catalog of support under the Cloud Support Package line items in the contract to 432 advise and assist with architecture, usage, provisioning, configuration of unclassified and 433 classified IaaS and PaaS offerings, to include homefront to the tactical edge; and advise and 434 assist users on optimizing the use of cloud services under the JEDI Cloud contract. Package 435 services shall also include training on, advising on, and assisting with integration, aggregation, 436 orchestration, and troubleshooting of cloud services. (CDRLs A005 and A006). 437

3.24.1 If a Cloud Support Package offering is constrained by the number of hours 438 available to users, then the Offeror must provide a mechanism for users to inquiry how many 439 hours have been consumed (without that request consuming additional hours) within 24 hours of 440 submitting a request. 441

3.25 Provide overarching program management capabilities under the Cloud Computing 443 Program Office (CCPO) Program Management Support line items to oversee all contract 444 activities for the ID/IQ during the entire period of performance of the ID/IQ. One of the purposes 445 of CCPO Program Management Support is to align with the CCPO and provide feedback to 446 ensure the JEDI Cloud contract is being used efficiently and in line with commercial practices. 447 The requirements listed below are in addition to any requirements identified in any CCPO TO 448 for CCPO PM Support. 449

3.25.1 Conducting any activities necessary to authorize the unclassified and classified 450 IaaS and PaaS infrastructure and offerings. 451

3.25.2 Conducting continuous audit assessments and, as needed, management reviews as 452 requested by the CCPO. 453

3.25.3 Providing reports for all accounts under the JEDI Cloud contract, as needed, on 454 infrastructure hosting JEDI Cloud users’ systems, including specific server hardware, network 455 systems, power infrastructure, cooling systems, etc. and software running on those systems 456 below the virtualization layer. 457

3.25.4 Delivering to the CCPO and executing the Transition Out Plan IAW Section C3: 458 Transition Out. (CDRL A002). 459

3.25.5 Advising on CCPO program artifacts including acquisition life cycle 460 documentation in an effort to maintain commercial parity. 461

4 Desired Capabilities 462 The desired capabilities are “nice to have” capabilities that are above and beyond the required 464 performance requirements of JEDI Cloud. 465

4.1 Tactical Edge 467

4.1.1 Tactical edge capabilities that enhance warfighting advantage. For example, devices that 469 require minimal or no external power and are capable of running for extended periods of time 470 without battery swap or recharging. Other examples include smaller form-factor devices that are 471 human-portable for extended periods of time; or capabilities that are deployable into air or space. 472

4.1.2 Innovative solutions for overcoming logistics challenges in delivering, maintaining, and/or 473 return shipping tactical edge capabilities. 474

4.2 Security 476

4.2.1 Advanced automated security capabilities, for example, the ability to detect and respond to 478 adversaries through artificial intelligence. 479

4.3 Cloud Support Package 481

4.3.1 Smaller, more incremental levels of support beyond the Offeror’s standard Cloud Support 483 Package offerings. 484

4.3.2 Includes specialized training support in various modalities, including, but not limited to, 485 classroom, train-the-trainer, certifications, and advising on the development of training packages. 486

5 Performance Metrics: The metrics defined below identify the performance requirements for 489 JEDI Cloud. These metrics will be reviewed at least annually and may change as technological 490 advances occur. 491

Table 5.1*

Item Objectives Standard Acceptable Quality Limit

(must occur within time indicated within x%)

Monitoring Method

1 Time to provision new VM (excludes boot time)

Under 2 minutes 95% Activity log analysis

2 Time to spin up object storage

Under 2 minutes 98% Activity log analysis

3 Time to spin up a 100GB block storage container and attach it to a running VM

Under 1 minute 98% Activity log analysis

4 Response time for confirmation of job submission

Under 2 seconds 99% Activity log analysis

5 Time required to go from power off to receiving and processing user instructions for a VM

Under 15 seconds

95% Activity log analysis

6 Patch application and updates to underlying infrastructure and cloud services

Within 8 Hours of notification

95% of patches and updates must be completed within required time frame.

Security audit by CCPO and reporting by vendor

7 Infrastructure vulnerability disclosure to CCPO

Within 60 minutes of identification

100%. Disclosures must be identified within required time.

Security audit by CCPO and reporting by vendor

8 Alerts and notifications for budgeting and usage based thresholds

Sent within 10 minutes of crossing threshold

99% Vendor log analysis

9 Usage metrics available in vendor API

No more than 15 minutes lag between usage and API reporting

99% Activity log and API access

10 Actual user cost (billing) available in vendor API

No more than 24 hours lag between usage and API reporting

99% Activity log, API access, and invoices

11 All API systems up-time 99.999 % Uptime must be met 100% of the time.

Vendor status log analysis

12 All API response time Less than 500 ms of added latency

98% API and network traffic log analysis

13 Achieve classified hardware and networking commercial parity

Within 30 days from unclassified deployment (ready for IV&V testing)

100% Report to CCPO and/or independent audit

14 Achieve classified software (DBMS, OS, Hypervisor, Hosted Services) commercial parity

Within 24 hours of unclassified deployment (ready for IV&V testing)

99% Report to CCPO and/or independent audit

15 Time for DBMS to receive request and respond with data within single availability zone

Under 200 ms, excluding query processing time

99% Database and network log analysis

16 Time for DBMS to receive request and respond with data across availability zones

Under 1 second, excluding query processing time

99% Database and network log analysis

17 Offering of latest DBMS software offered as IaaS and PaaS offerings (excluding online marketplace offerings)

Less than 24 hours of public release

95% Analysis of catalog changes over time

18 “Nearline” storage read / write the first byte

Under 30 seconds

95% Data storage log analysis

19 “Offline” storage read / write accessible

Under 24 hours 95% Data storage log analysis

20 Time necessary to execute plan identified in CLIN x005 is less than 12 hours

Upon notification from CO, within 12 hours to execute the demonstration

99% Activity log analysis and/or CCPO monitoring

21 System activity logging Less than 1 second after activity execution

99% Activity log analysis

22 Online marketplace offering deploy time starting from authentication in the online portal

Under 5 minutes excluding time to start any infrastructure necessary to host the offering

95% Analysis of marketplace catalog changes over time

23 Network request and response time between two VMs within the same availability zone

Under 50 ms 99% Network traffic log analysis

24 Network request and response time between two VMs in different availability zones

Under 200 ms 99% Network traffic log analysis

25 Make new cloud service offerings and updates and modifications to existing service offerings available in classified JEDI Cloud environment

Within 30 days (ready for IV&V testing)

99% Report to CCPO and/or independent audit

26 Make new publicly-available commercial marketplace offerings available in classified JEDI Cloud environment (excluding any third party marketplace offerings the contract does not require to be made available to JEDI Cloud users)

Within 30 days (ready for IV&V testing)

99% Catalog availability

27 Notification and nature of service incident impacting JEDI Cloud users

Under 10 minutes

99% Analysis of incident reports and notifications

28 Detailed report on any service incident impacting DoD customers

Within 7 days 95% Analysis of service incident report

29 Recovery Point Objective / Recovery Time Objective

10TB (RPO)

within 5 minutes

(RTO)

98% Random Sampling

30 Delivery of portable tactical edge device in CONUS to the designated address

10 calendar days from date of order placement

80% Random sampling

31 Delivery of modular data center in CONUS to the designated address

14 calendar days from date of order placement

80% Random sampling

* All performance metrics apply to tactical edge capabilities unless explicitly stated otherwise. 494 For unclassified and classified tactical edge devices that are deployed, accepting any 495 modifications to the services and offerings are at the discretion of the JEDI Cloud user. If a JEDI 496 Cloud user does not accept a modification, the Offeror is not responsible for meeting 497 Performance Metrics that are directly affected by the JEDI Cloud user’s decision. 498 Constraints 500 Any constraints are provided elsewhere in the SOO or listed in the Cyber Security Plan. 502 Deliverables 504

Table 5.2

CDRL Deliverable Frequency / Date of First Submission

Medium/Forma t/# of Copies

Submit To

A001 Contract Monthly Progress Report

Monthly Electronic copy in Offeror’s preferred format

CCPO

A002 Transition Out Plan

As required Electronic copy in Offeror’s preferred format

CCPO

A003 Contract Security Management Plan

Within 30 days of contract award and then annually thereafter;

updated annually or as required to reflect necessary changes.

Electronic copy preferred format

CCPO

A004 Technology Refresh Plan

Within 30 days after contract award and then semi-annually thereafter

Electronic copy preferred format

CCPO

A005 System Administrator Training Materials

Within 30 days after award;

updated annually or as required

Various CCPO and Ordering Activity

A006 Role-Based User Training Materials

Within 30 days after award;

updated as required

Various CCPO and Ordering Activity

A007 Portability Plan Within 60 days of contract award

Electronic copy in Offeror’s preferred format

CCPO

A008 Contract Ordering Guide

Within 15 days after Government developed sections provided;

updated annually or as required to reflect necessary changes.

Electronic copy in Offeror’s preferred format

CCPO

A009 Change Management Roadmap

Within 90 days of contract award, then annually thereafter

Electronic copy in Offeror’s preferred format

CCPO

A010 Quality Control Plan

Within 30 days of contract award, then annually thereafter

Electronic copy in Offeror’s preferred format

CCPO

A011 Security Authorization Package

Various depending classification level

Electronic copy in format acceptable to the FedRAMP process

CCPO

A012 Technical Report As required Electronic copy in Offeror’s preferred format

CCPO

A013 Small Business Reporting

Annually after date of contract award

Electronic copy in Offeror’s preferred format

CCPO

A014 Portability Test As required In accordance with the Portability Plan

CCPO

A015 Task Order Monthly Progress Report

As required Electronic copy in Offeror’s preferred format

CCPO and/or Ordering Activity

A016 Meeting Materials

Quarterly Electronic copy in Offeror’s preferred format

CCPO

Unless otherwise specified, the Government shall have fifteen calendar days to review and 507 provide comments to all deliverables. Any deliverables that are not commented upon within that 508 time frame are deemed approved. Offeror shall have five calendar days to revise and resubmit 509 any deliverables that the Government provides comments upon. 510

File details come from the government source that posted it.