JEDI_Cloud_Industry_and_Gov_QA_dRFP2.pdf

PDF 233 KB Posted

Attached to
JEDI Cloud RFP Federal contract opportunity
Solicitation number
HQ003418R0077_JEDI_CLOUD_RFP
Issued by
DOD Washington Headquarters Service

About this file

JEDI Cloud Industry and Government Q&A for draft RFP2

View the file

Other files for this federal contract opportunity

Other files attached to JEDI Cloud RFP, newest first.
File Type Posted
Attachment_L-5_Price_Scenario_Price_Build-up_Template_Updated_.xlsx XLSX spreadsheet
HQ0034-18-R-0077_0002.pdf PDF
Amendment_0002_Summary_of_Changes.pdf PDF
Attachment_J-7_DD_Form_254,_DoD_Contract_Security_Classification_Specification_for_ID_IQ_Amendment_0002.pdf PDF
JEDI_Cloud_Industry_and_Gov_QA_Amendment_0001.pdf PDF
Attachment_L-8_PWS-SOO_Crosswalk_Matrix-Amendment_0002.xlsx XLSX spreadsheet
Attachment_L-2_Price_Scenarios_Amendment_0001.pdf PDF
Attachment_J-8_Definitions_Amendment_0001.pdf PDF
Amendment_0001_Summary_of_Changes.pdf PDF
Attachment_L-1_Statement_of_Objectives_Amendment_0001.pdf PDF
JEDI_Cloud_Industry_and_Gov_QA_Final_RFP.pdf PDF
Oracle_Pre-Award_Protest.pdf PDF
Attachment_L-3_Task_Order_001_PWS.pdf PDF
JEDI_CDRL_A006_-_Role-Based_User_Training_Materials.pdf PDF
MIL-STD-810G_CN1.pdf PDF
JEDI_CDRL_A014_-_Portability_Test.pdf PDF
JEDI_CDRL_A004_Technology_Refresh_Plan.pdf PDF
Attachment_L-4_Task_Order_002_PWS.pdf PDF
Attachment_L-9__Company_Non-Disclosure_Agreement_for_JEDI_Cloud.pdf PDF
JEDI_CDRL_A001_-_Contract_Monthly_Progress_Report.pdf PDF
JEDI_CDRL_A002_-_Transition_Out_Plan.pdf PDF
JEDI_Cloud_Comment_Resolution_Matrix_for_Final_RFP.xlsx XLSX spreadsheet
JEDI_CDRL_A008_-_Contract_Ordering_Guide.pdf PDF
180510_Final_Cloud_Combined_Congressional_Report__vg7_PDF_Redacted.pdf PDF
Attachment_L-7_OCI_Analysis_Disclosure_Form.pdf PDF
DoD_CIO_RFP_Release_Letter_26_Jul.pdf PDF
CNSSP15.pdf PDF
Attachment_L-6__Small_Business_Subcontracting_Plan_Template.docx DOCX document
JEDI_CDRL_A011_-_Security_Authorization_Package.pdf PDF
Attachment_L-8_PWS-SOO_Crosswalk_Matrix.xlsx XLSX spreadsheet
Attachment_J-8_Definitions.pdf PDF
JEDI_CDRL_A007_-_Portability_Plan.pdf PDF
Attachment_J-10__Small_Business_Participation_Commitment_Document.pdf PDF
Attachment_J-7_Form_DD254.pdf PDF
Attachment_J-6_JEDI_Cyber_Security_Plan.pdf PDF
JEDI_CDRL_A015_-_Task_Order_Monthly_Progress_Report.pdf PDF
JEDI_CDRL_A013_-_Small_Business_Reporting.pdf PDF
JEDI_CDRL_A016_-_Meeting_Materials.pdf PDF
Attachment_L-2_Price_Scenarios.pdf PDF
JEDI_CDRL_A009_-_Change_Management_Roadmap.pdf PDF
PM_Letter_for_RFP_Release_Letter.pdf PDF
Attachment_L-1_Statement_of_Objectives.pdf PDF
JEDI_CDRL_A005_-_System_Administrator_Training_Material.pdf PDF
JEDI_CDRL_A010_-_Quality_Control_Plan.pdf PDF
JEDI_Single_Award_DF-USD(AS)__17July18.pdf PDF
JEDI_CDRL_A012_-_Technical_Report.pdf PDF
In-Person_Q&A_Session_Information.pdf PDF
JEDI_CDRL_A003_-_Contract_Security_Management_Plan.pdf PDF
HQ0034-18-R-0077.pdf PDF
Attachment_L-5_Price_Scenario_Price_Build-up_Template.xlsx XLSX spreadsheet
Show all 50

JEDI Cloud RFP has more files on GovTribe.

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

JEDI Cloud Questions and Answers (Q&A) Matrix for Draft RFP #2, Draft DD Form 254 and Draft Price Scenario Documentation

ID #

Industry Submitted Information Government Response

Draft RFP #2 Document Section Subsection Page # Line # Information Request (Question)

1336 Draft SOO 2 2.5 3 83 How can Commercial Cloud providers comply with DOD security requirements? Accreditation requirements are outlined in the draft Cyber Security Plan updated in draft RFP #2.

1337 Draft SOO 2 2.7 3 97 "Fortified Security" is not a DOD specification The intended meaning of Fortified Security, for purposes of JEDI Cloud, is defined in section 2.7 in the draft SOO.

1338 Draft SOO 3 3 3 118 DOD Security Requirements cannot be met in the time frames identified. If this requirement stays only AWS and Microsoft can bid, There is no requirement for Offerors to have accredited classified environments at the time of proposal. The SOO requires the proposed solution to be available and meet the requirements as specified in the Cyber Security Plan within 30 days of contract award for unclassified services;

within 6 months of contract award for classified services at the Secret level; and within 9 months of contract award for classified services at the Top Secret/Sensitive Compartmented Information (TS/SCI) and Special Access Program (SAP) levels.

1339 Draft SOO 3 3 4 122 Cloud Solution Providers do not deliver at the tactical edge. The requirement needs to discuss the desired outcome not a "prescriptive" solution

The draft SOO released with draft RFP #2 provides the performance objectives, performance requirements, and performance metrics relevant to the tactical edge requirements.

1340 Draft SOO 3 3.2 4 129 Cloud boundary is a undefined term. The Government needs to clarify what that means to DoD. "Cloud boundary" is defined in Attachment 8 Definitions of draft RFP #2.

1341 Draft SOO 3 3.3 4 135 JEDI cloud regions are undefined. Is the government seeking an Industry solution or prescribing one?

The Government will consider all possible solutions industry has to offer that will meet the requirements of the solicitation and will not be prescriptive by specifying a solution.

1342 Draft SOO 3 3.6 4 144 Please define "CCPO"

The CCPO is the Cloud Computing Program Office. This office works directly for the Chief Management Officer and will manage the JEDI Cloud, as was explained in the JEDI Cloud Q-A Matrix for draft RFP #1. For example, reference ID #54.

1343 Draft SOO 3 3.9 4 156 Will PKI and MFA replace CAC identity management?

The JEDI contractor must provide MFA via DoD PKI (CAC), non-DoD PKI, and other industry standard authentication methods as further detailed in the Cyber Security Plan.

1344 Draft SOO 3 3.1 4 157 DoD needs to define the "specific DOD Organizations" that will be requiring usage reports The usage and billing reporting requirements have been updated to be by account, group of specified accounts, or all accounts associated with JEDI Cloud.

1345 Draft SOO 3 3.1.6 5 3878 Would the Government provide and example of "third party Platform and software service"?

A cloud marketplace is an online storefront, operated by a cloud provider, to which customers may subscribe to PaaS and SaaS offerings that run on the cloud provider's infrastructure. The specific third party PaaS and SaaS marketplace offerings are dependent upon the particular cloud provider. SaaS and PaaS offerings that cannot be deployed on the JEDI Cloud are outside of the scope of this acquisition.

1346 Draft SOO 3 3.2.2 5 199 The requirement is not clear There is no section 3.2.2 in the draft SOO. The Government is unclear as to the meaning of this question.

1347 Draft SOO 4 4.1 6 214 How does the JEDI Cloud Security Plan incorporate the DOD Cloud Security guide?

Accreditation requirements are outlined in the draft Cyber Security Plan as updated in draft RFP #2. The incorporation of the DoD Cloud Computing Security Requirements Guide, and the applicable exceptions, are addressed in the draft Cyber Security Plan.

1348 Draft SOO 4 4.7 6 236 How can the Government dictate a percentage of utilization to a CSP. The nature of the environment is such that this is not practical.

The requirement to maintain a certain level of utilization will be removed for the final RFP, but regular reporting about utilization levels will remain.

1349 Draft SOO 4 4.7 6 236 Does the 50% criteria extend to the tactical edge? Or is it an all encompassing measurement?

The requirement to maintain a certain level of utilization will be removed in the final RFP, but regular reporting about utilization levels will remain. The requirement will be clarified in the final

RFP.

1350 Draft SOO 4 4.8 7 241 How will DoD Measure the evergreen infrastructure of the CSP? How will Security controls be applied? The Government is unclear as to the meaning of this question.

1351 Draft SOO 4 4.14 7 3290 How is "nearline" storage defined. Do you have a use case for it? "Nearline" storage is defined in Attachment 8 Definitions of draft RFP #2.

1352 Draft SOO 4 4.19 8 3920 Can the Government provide a description or example of the "portability" requirement?

The scope of work required for the Portability CLINs are described in Section 4 of the draft SOO with RFP #2.

1353 Draft SOO 4 4.2.9 9 364 How does this requirement map to a CSP model? The CSP is responsible for the Cloud Content. This is prescriptive.

The purpose of this requirement is to ensure that JEDI Cloud maintains ongoing commercial parity with the cloud vendor's publicly-available offerings. There are performance metrics in the SOO that also address commercial parity requirements.

1354 Draft SOO 9 4.2.8 9 331 Is the transition plan for the entire DOD cloud or would it be for "tenants"? The requirement is not clear.

The Transition plan is for the enterprise and the portability plans address the "tenants."

Clarification will be provided in the final RFP.

Draft RFP Section H H H-7 19 345-362 This clause reads a default for a cyber attack. It is too restrictive in the DOD environment.

This clause allows the Government to terminate without cure notice if failure to meet security requirements is due to the Contractor's willful misconduct. It is reasonable for the Government to expect contractors to not engage in willful misconduct.

Draft RFP Section H H H-13 21 457-471

Terms of conflicting License need to be addressed. The Government requested a BYO-License offering in the PWW. How will conflicting terms be handled?

With Bring Your Own License, the Government would have negotiated the terms of the license agreement under a separate contracting vehicle. The Section H clause entitled "Third Party Marketplace Offerings" addresses the fact that the JEDI Cloud contractor is not responsible for BYOL licensing terms.

Draft RFP Section L L L-9 91

Small business requirements are not applicable to this procurement. Imposing them on the CSP's will only drive the Governments cost up.

The small business participation approach, which is now Factor 7 in the final RFP, has been substantially updated to allow for Offeror flexibility in proposing an achievable level of small business participation.

1358 Draft SOO 3 3.2 4 131 Why is this an objective versus a design concept?

The Statement of Objectives is framed in terms of performance objectives, performance requirements, and performance metrics.

JEDI Cloud Questions and Answers (Q&A) Matrix for Draft RFP #2, Draft DD Form 254 and Draft Price Scenario Documentation

ID #

Industry Submitted Information Government Response

Draft RFP #2 Document Section Subsection Page # Line # Information Request (Question)

1359 Draft SOO 4 22 8 309-324

CLIN 4 talks about the portability plan for data, yet with the emphasis on AI and Machine Learning, how is the government going to address moving those AI and ML-based services and associated capabilities? For example, if I use AI/ML services in CSP #1, and then want to move to CSP #2, I can transfer all my data over using CLIN 4 procedures, but all the specifics of the AI/ML services can be proprietary to the CSP…so how does the government intend to move those services over?

The Government recognizes that not all features of a specific Offeror's cloud environment will be portable should the Government decide to move to a different hosting environment for a particular application and/or data.

1360 Draft SOO 3 1 4 125

For OCONUS non-tactical support, will the government be providing data center space to the CSPs, or is the CSP expected to leverage OCONUS contractor-owned facilities via foreign subsidiaries?

There are two types of OCONUS requirements. The first is OCONUS tactical edge capabilities, and the static, modular, rapidly deployable data centers are required to be on military controlled locations. The second is the points of presence requirements. Per the Cyber Security Plan, all infrastructure, excluding networking equipment and points of presence, must be within US customs territory or on US military installations.

1361 General Factor 1 1.7 87

Aside from the timed demos, how will the government evaluate/score the requirement for an on-line marketplace? Is there a minimum number of 3rd party offerings? Minimum # of native CSP-to-3rd party integrations? Any other criteria aside from what is listed? The Government's evaluation criteria are provided in Section L and M.

1362 Draft SOO 2 2.4 2 78

It is clear that the government realizes apps need to be either modern or re-engineered to move into the JEDI cloud. How does the government intend to determine which legacy apps will be re-engineered, and for those that can’t/won’t be re-engineered, what is the government’s intent for those apps?

The Government is aware that some applications may require modernization. System owners are responsible for architecting and optimizing applications and data that they migrate to the JEDI Cloud.

1363 Draft SOO 3 3.4 4 132

Scalability and resiliency as currently deployed and enabled in cloud providers does not follow an industry standard paradigm, i.e.,. the APIs and services for resiliency that CSP #1 provides are not transferable to CSP #2 without re-architecting each application being moved. All CSPs implement these services in a proprietary nature unique to their specific platform. Has the government considered including off-boarding/re-architecting services for these services in CLIN 4? As it reads now, CLIN 4 is dedicated solely to data transfer, but has not considered application and/or service/API re-platforming issues. Transition and migration services are outside the scope of this contract.

1364 Draft SOO 3 3.21 5 195

(Also related to draft pricing scenario #2-ERP). The proposed scenario focuses on the size of the ERP system’s database, and lists requests per minute for performance. A) Would the government consider pricing these database services at the single server level, i.e., provision a database server and pay for actual consumption of compute (CPU/Memory) resources over time as traffic varies, instead of on a reserved basis? This would be a combination of the usage-based and reservation-based pricing models. b) If so, how would the government compare this methodology to the two methods listed in SOO 3.21. c) Has the government considered requiring performance-based SLAs for these databases? Typically, ERP systems must have a dedicated database instance, and need guaranteed levels of performance to meet application response time requirements.

The Government will consider all possible solutions industry has to offer that will meet the requirements of the solicitation and will not be prescriptive by specifying a solution.

1365 General 98

Will the government provide guidance on the mandated use of existing DoD security architecture (i.e. .JRSS, Service component gateways, base level TLA stacks, Cloud Access Points, etc.)….if alternative security solutions are acceptable, what cyber security data/reporting is required? Will the government provide additional guidance on the required use of existing Cyber Security Service Providers and the relationship and reporting to service component (Army/Navy/AF/USMC) Cyber Component Headquarters The Cyber Security Plan sets forward the security requirements that must be met.

1366 Draft SOO 3 3 118

What specific changes to the existing C&A process (i.e.. DISA’s review & oversight) are proposed to allow CSPs to meet these delivery timelines? The current, mandated processes will not allow anyone to meet these objectives.

Department policy decisions are outside of the scope of the draft solicitiation. The Cyber Security Plan sets forward the security requirements that must be met.

1367 Draft SOO 3 3.2 4 131

Will the government require the use of existing DISN infrastructure to include Cloud Access Points to connect customers to this new cloud service? If not, will connection criteria be provided to identify authorized connection solutions and will certification/Authority to Connect procedures be required for these new DoD network connections?

The Draft Cyber Security Plan in draft RFP #2 states that the Contractor is required to establish direct fiber links to DoD Meet-Me-Points for unclassified connections.

1368 Draft SOO 147

Will the government mandate the use of existing (CAC based) authentication methods and infrastructure (i.e., PKI) to access new cloud services? If no, how will new multi-factor authentication solutions be evaluated by security officials?

The JEDI contractor must provide MFA via DoD PKI (CAC), non-DoD PKI, and other industry standard authentication methods.

1369 Draft SOO 235 Can the government explain the intent of the requirement that the CSP provider not exceed 50% of public capacity?

The requirement to maintain a certain level of utilization will be removed in the final RFP, but regular reporting about utilization levels will remain. The requirement will be clarified in the final

RFP.

1370 Draft SOO 4 4.27 356 Will the government be prepared to identify and deliver existing/owned licensing to be leveraged within the marketplace?

The responsibilities for licensing terms and conditions for third party offerings in the marketplace are clarified in clause H-15 in draft RFP #2.

Draft CyberSec Plan 4 4.1.4 4 135

Will facilities (floor space, power, cooling, etc.) and base/facility access be provided to the CSP for overseas locations to adequately support the tactical warfighter environment from US controlled bases/installations? If so, how will the government manage/charge for this facility use/access?

The Government, not the JEDI Cloud contractor, is responsible for establishing the appropriate facilities to support tactical edge capabilities.

Draft CyberSec Plan 4 4.4.5 6 173

Will the governments ‘meet me points’ mirror or requirement include existing DISN Cloud Access Points (CAPS)? If so, what bandwidth/real throughput to customers will be guaranteed to the existing base level networks?

The Government intends to access the Contractor's cloud services via both the meet-me-points and the Internet. The Government is responsible for providing adequate access and throughput from the DISN to the meet-me-points and Internet.

JEDI Cloud Questions and Answers (Q&A) Matrix for Draft RFP #2, Draft DD Form 254 and Draft Price Scenario Documentation

ID #

Industry Submitted Information Government Response

Draft RFP #2 Document Section Subsection Page # Line # Information Request (Question)

1373 Draft SOO Cost table

Cloud Support Package 6 58

Migration services are key to the success of JEDI and need to be available to the Government.

Affixed price or hourly rates should be included and mapped to the SOW requirements Transition and migration services are outside the scope of this contract.

Draft RFP Section C C1

Performanc e works statement 14 132

Migration services will be key to the success of JEDI. The Government should describe the "migration vision" in the PWS. Transition and migration services are outside the scope of this contract.

Draft PWS Template C2 c-3, b, vi 14 154

The Government is seeking accreditation without a commitment to Industry. If Industry accredits the solutions how will the Government guarantee usage? Usage is not guaranteed beyond the stated ID/IQ contract minimum.

Draft RFP Section C C4 b 15 183 This reads as the Government will be entering into "an oral contract"

Depending on the urgency, the initial direction may be made orally, but the final RFP will clarify that the direction will be reduced to writing as soon as practicable.

Draft RFP Section C F3 n/a 16 225

The Government must identify locations for service as to ensure response, availability, and support. Your comment has been noted.

Draft RFP Section C H4 SOFA 17 277 Non-Federal entities do not know what SOFA is or how to comply. The Status of Forces Agreement clause has been removed from Section H in the final RFP.

Draft RFP Section C H5

a. - New services 18 288

How can New Services be proposed with the limitations stipulated by the Government in the

SOW.

There is nothing in the SOO that prohibits incorporation of new services so long as it complies with all contract requirements.

Draft RFP Section C H5 c- Price Premium 18 303 Too prescriptive (i.e. percentage of increase for new services).

The Section H clause for new serices has been updated to balance the requirement for commercial parity with Offeror pricing flexibility.

Draft RFP Section C H-13

License Agreement or terms of use 21 455 Not clear as to who is responsible for the agreements

The Offeror is responsible for all agreement with the exception of Bring Your Own License offerings.

Draft RFP Section C H-13

Assignment by Licensor 25 n/a The government must accept license terms to have consistency in SLA's and terms. The Government is prohibited from accepting terms that are inconsistent with Federal laws.

Draft RFP Section C H-14 third party market place offerings 27 529 Will the Government define the scope of "bring your own license"? Vague at best.

Based on market research, Bring Your Own License is a common offering for cloud provider marketplaces.

Draft RFP Section C I

Availability of funds 29 561 Funding must cover the period of performance and not started and stopped each Fiscal Year. Your comment has been noted.

Draft RFP Section L Tab C

Tactical Edge 85 n/a

The 19 page total is confusing. With 10 and 3 per scenario. What does the Government want to see? Is pricing or a narrative required or both?

For the tactical edge evaluation criteria, the Offeror is allocated 10 pages to address the elements outside of the Pricing Scenarios. For the invoked Pricing Scenarios, the Offeror is required to provide a technical approach to each invoked Pricing Scenario; the Offeror is limited to 3 pages per Pricing Scenario.

Draft RFP Section J

Attachme nt 4

5c Multiple data uplink options to include fiber optic, low and high bandwidth Ethernet, and compatibilit y with standard sitcom systems Do the uplink options need to be routed through the Container?

The Government is unclear as to the meaning of this question. However, any tactical edge device must be able to accept connections through a Government provided uplink.

JEDI Cloud Questions and Answers (Q&A) Matrix for Draft RFP #2, Draft DD Form 254 and Draft Price Scenario Documentation

ID #

Industry Submitted Information Government Response

Draft RFP #2 Document Section Subsection Page # Line # Information Request (Question)

Draft RFP Section J

Attachme nt 4

5c Multiple data uplink options to include fiber optic, low and high bandwidth Ethernet, and compatibilit y with standard sitcom systems Will the sitcom systems reside in the Container

The Government is unclear as to the meaning of this question. However, any tactical edge device must be able to accept connections through a Government provided satellite uplink.

Draft RFP Section J

Attachme nt 4

5c Multiple data uplink options to include fiber optic, low and high bandwidth Ethernet, and compatibilit y with standard sitcom systems will there be a requirement for the sitcom antenna’s or any other antenna’s require mounting on the Container?

The Government will consider all possible solutions industry has to offer that will meet the requirements of the solicitation and will not be prescriptive by specifying a solution.

Draft RFP Section C

How is the Government evaluating the “Tactical Edge” support plan? There does not seem to be any mention of it in sections L or M. How will the Prime provide support. Will the requirement be on-site?

The manner in which DoD intends to evaluate tactical edge is described in Sections L and M.

The requirements for support to the tactical edge are described in the SOO.

1394 Draft SOO 2 2.7 3 107-111

To enable root level system security, it is imperative that the DoD maintain ownership and separation of the data keys, while encrypting the data prior to entering the cloud environment.

Does the JEDI program require DoD agencies to maintain a root level of trust through key ownership and separation as well as data encryption?

Encryption keys will be managed by either the government or Offeror at the discretion of the user.

The requirements for cryptographic certainty have been been clarified in the Cyber Security Plan with the final RFP.

1395 Draft SOO 3 3.5 4 139 Monitoring and auditing service security should be made possible through an additional layer of security, outside of the cloud environment, prior to entering the cloud. Your comment has been noted.

Draft CyberSec Plan 1 1.1.2 1 27

In the interest of data protection, security and privacy, we highly recommend the DoD require all JEDI CSP personnel and contractors to be US Citizens. Your comment has been noted.

Draft CyberSec Plan 4 4.4.1 3 111

Requiring crytographic certainty of encryption is important, however this addresses only half of the data security equation. The keys to encrypt and decrypt the data must be owned by the DoD and must reside outside of the Cloud in a key management system. A key management system is available as hardware or a software solution and provide a root of trust, owned by the DoD. The final Cyber Security Plan has been updated to clarify the Government's requirements.

1398 Draft SOO 3 3.8 4 151

Does DoD expect the PKI mechanism used to address this requirement to be the same an existing PKI infrastructures used in DoD (CAC cards, SIPR cards, etc) or are you looking for new PKI infrastructure for identities assigned to system administrator, as other agencies are doing. If new identities, must these share space on existing tokens and cards (ie. use of multi-identity cards or multi-purpose tokens) or will new cards or tokens be required?

The JEDI contractor must provide MFA via DoD PKI (CAC), non-DoD PKI, and other industry standard authentication methods.

1399 Draft SOO 3 3.9 4 154 Does the government see the possibility of Out-of-Band identify solutions, such as one time passwords, as a viable mechanism to meet this federated identity requirement?

Any federated identity solution must include time-limited, role-based authentication tokens. While one time passwords may be part of that solution, it does not alone meet the requirement.

1400 Draft SOO 2 2.7 3 110

Can the government provide any specific information security requirements that would be required for the encryption of data at rest and in transit? For example, would NIST SP 800-53 govern the data at rest and the data in transit operating environment?

The Offeror must encrypt data at rest and data in transit to include the ability for users to require the implementation of up to two layers of commercial grade encryption utilizing algorithms and procedures specified in Committee on National Security Systems Policy (CNSSP) 15.

1401 Draft SOO 4 4.32 10 376-382

Given the requirement for an abiliytn to operate at the tactical endge in disconnected mode with all containerized applications, one implicit assumption is that all keys necessary for application usage at the tactical edge must be resident on the edge device. Does the government requirements a specific FIPS 140-2 key protection level for keys resident on the tactical edge.

Is a FIPS 140-2 level 2 or 3 requirement to be imposed, or will software only key protection (FIPS 140-2 level 1) be allowed for storage of highly sensitive keys?

The final SOO has been clarified to state that tactical edge capabilities must support key management both on and off the device at the discretion of the user. The classification level involved and expected connection status will likley drive this decision.

JEDI Cloud Questions and Answers (Q&A) Matrix for Draft RFP #2, Draft DD Form 254 and Draft Price Scenario Documentation

ID #

Industry Submitted Information Government Response

Draft RFP #2 Document Section Subsection Page # Line # Information Request (Question)

1402 Draft SOO 4 4.34 10 394

Must encryption and logical isolation of classified and unclassified data be provided within a single edge computing environment, or is it acceptable to meet this objective with a separate set of tactical endge computing environments?

The tactical edge devices must comply with the physical and logical isolation requirements for classified information. The Government will consider all possible solutions industry has to offer that will meet the requirements of the solicitation and will not be prescriptive by specifying a solution.

1403 Draft SOO 4 4.34.1 10 396-399 If two layers of commercial encryption are required, it is also a requirement that those solutions be provided by separate encryption vendors?

The Government will consider all possible solutions industry has to offer that will meet the requirements of the solicitation and will not be prescriptive by specifying a solution.

1404 Draft SOO 4 4.35.1 11 408

Per existing DoD policy, transfer of data across isolated enclaves and especially across classification levels requires a UCSDMO approved cross-domain solution (CDS), which typically requires being run on a dedicated hardware platform with a hardened OS. Is the JEDI team proposing virtualized CDS solutions now be deployed on a virtualized cloud infrastructure, with or without approval from UCDSMO, or is the JEDI team expecting offerers to provide UCDSMO approved CDS hardware devices in the data centers hosting these cloud services (and potentially comingled with commercial cloud offerings)?

The secure data transfer requirements have been clarified in the evaluation criteria and Cyber Security Plan. The Government does not intend to provide the Contractor a particular cross domain solution; the Contractor is required to provide a secure data transfer capability in accordance with the Cyber Security Plan and SOO. The Government will consider all possible solutions industry has to offer that will meet the requirements of the solicitation and will not be prescriptive by specifying a solution.

1405 Draft SOO 4 4.35.2 11 411

Will the data transfer capability described here provide the government with the ability to create newDoD policies that govern the data transfer between enclaves based on such characteristics as file type, data volume, QoS and others? How does content checking play into this paradigm?

The draft SOO provided with draft RFP #2 included a requirement that the data transfer capability be able to enforce technical policies controlling how data transfer capabilities can be used.

1406 Draft SOO 4 4.35.7 11 421

An orchestrated multi-tenant peering gateway is not an industry standard term with a known set of requirements. How does the JEDI team see this component being evaluated for completeness and efficacy. Must it meet all requirements of a cross domain solution, a subset of those requirements, or a new set of requirements. If the latter, do any of those requirements address content inspection, which is not directly addressed in this DRFP, and if so, is it incumbent upon the offerer to specifiy what rerquirements its orchestrated multi-tenant peering gateway will meet, or will the govenrment provide more specific requirements in future iteratrions

The SOO with the final RFP has been updated to clarify these requirements. The term orchestrated multi-tenant peering gateway is no longer used.

1407 Draft SOO 4 4.34.1 10 396 Will there be a requirement to encrypt data traversing commercial carriers' circuits.

The Offeror must encrypt data at rest and data in transit to include the ability for users to require the implementation of up to two layers of commercial grade encryption utilizing algorithms and procedures specified in Committee on National Security Systems Policy (CNSSP) 15.

Draft CyberSec Plan 1 1.1 3 71-72

All references to Impact Levels have been removed from this draft. However, Section 1.1 of this document states: "1.1 The Contractor is responsible for following the DoD Cloud Computing Security Requirement Guidelines,". By including this requirement to meet the DoD Cloud Computing Security Requirement Guidelines, bidders will be required to achieve IL5 and IL6 certification to be in compliance. If the goal is to remove Impact Level certifications, clear exceptions should be added to this section. If impact level certifications are required, please add explicit requirements directly back within this document to clearly outline the impact levels and deadlines required.

While the Cyber Security Plan invokes the DoD Cloud Computing Security Requirements Guide, the Cyber Security Plan also established certain deviations from the CC SRG. The Cyber Security Plan does not require prior accreditation.

Draft CyberSec Plan C

C.3 and C.

4 10 270-272

All references to Impact Levels have been removed from this draft. However, Section 1.1 of this document states: "1.1 The Contractor is responsible for following the DoD Cloud Computing Security Requirement Guidelines,". By including this requirement to meet the DoD Cloud Computing Security Requirement Guidelines, bidders will be required to achieve IL5 and IL6 certification to be in compliance. If the goal is to remove Impact Level certifications, clear exceptions should be added to this section. If impact level certifications are required, please add explicit requirements directly back within this document to clearly outline the impact levels and deadlines required.

While the Cyber Security Plan invokes the DoD Cloud Computing Security Requirements Guide, the Cyber Security Plan also established certain deviations from the CC SRG. The Cyber Security Plan does not require prior accreditation or certification.

1410 Draft SOO 5 Table 5.1 14 Row 13

This requirement states that: "Classified software (DBMS, OS, Hypervisor, Hosted Services) parity" [must be achieved in] "Less than 24 hours from unclassified deployment".

This 24 hour requirement will effectively require that bidding CSPs install and configure software for all new services within the classified environment and harden them to be ready for FedRAMP High Certification days to weeks or even months ahead of deployment in the unclassified/commercial environment. This requirement will force the awarded CSP to deploy all new services into the classified environment first regardless of its applicability to the DoD mission. It will also delay a CSP from being able to deploy services to its commercial/unclassified marketplace which will limit its ability to capture return on development investments.

This requirement should be extended to allow time for services to be deployed, configured and hardened within the classified environment only after they have been successfully deployed and adopted by customers in the commercial/unclassified domain.

Adequate time should also be provided for these services to be fully installed, configured, and hardened within the classified environment. Depending on the scale and scope of these future services the time to do so could be significant.

The requirement has been clarified to state "Within 24 hours of unclassified deployment (ready for IV&V testing)."

JEDI Cloud Questions and Answers (Q&A) Matrix for Draft RFP #2, Draft DD Form 254 and Draft Price Scenario Documentation

ID #

Industry Submitted Information Government Response

Draft RFP #2 Document Section Subsection Page # Line # Information Request (Question)

1411 Draft SOO 5 Table 5.1 16 Row 25

The requirement to make marketplace offerings available in the classified environment within 30 days cannot be enforced by most or all CSPs. The business decision of whether to invest the CapEx and OpEx needed to offer a service in the JEDI classified environment's marketplace ultimately lies with the 3rd party marketplace vendors. Similarly the deployment time cannot be controlled by the hosting CSP. Recommend removing this requirement as it cannot be practically met by any bidders. The requirement has been clarified to state "Within 30 days (ready for IV&V testing)."

1412 Draft SOO 4 4 6 206-210

In the latest draft, the timeline still states that unclassified workloads must be "available and meet accreditation and authorization requirements within 30 days of contract award for unclassified services." The cyber security plan indicates that the requirement for unclassified workloads is FedRAMP moderate.

Question: Given that FedRAMP certification timelines are highly dependent on the work of the FedRAMP assessment team (JAB, etc.). Will the DoD allow bids that include services that are deemed FedRAMP ready within 30 days of award, with the understanding that they cannot be sold within the JEDI cloud until FedRAMP moderate accreditation is met?

We sincerely hope that you will consider this requirements enhancement, as doing so will help bidders to maximize the breadth and depth of their JEDI catalog of services, and will ensure that new services are available as soon as possible after award. We believe that allowing this change is in the spirit of the cloud acceleration goals of their contract.

While the Cyber Security Plan invokes the DoD Cloud Computing Security Requirements Guide, the Cyber Security Plan also established certain deviations from the CC SRG. The Cyber Security Plan does not require prior accreditation or certification. The Gate Criteria for Sub-factor

1.2 - High Availability and Failover has also clarified the applicable FedRAMP requirements.

1413 Draft SOO 4 4 6 206-210

In the latest draft, the timeline still states that classified workloads must be available and meet accreditation and authorization requirements within 6 months of contract award for classified services at the secret level. The cyber security plan indicates that the requirement for classified workloads is FedRAMP High.

Question: Given that FedRAMP High certification timelines are highly dependent on the work of the FedRAMP assessment team (JAB, etc.). Will the DoD allow bids that include classified secret services that are deemed FedRAMP ready within 30 days of award, with the understanding that they cannot be sold within the classified secret environment within the JEDI cloud until FedRAMP High accreditation is met?

We sincerely hope that you will consider this requirements enhancement, as doing so will help bidders to maximize the breadth and depth of their JEDI catalog of services, and will ensure that new services are available as soon as possible after award. We believe that allowing this change is in the spirit of the cloud acceleration goals of their contract.

While the Cyber Security Plan invokes the DoD Cloud Computing Security Requirements Guide, the Cyber Security Plan also established certain deviations from the CC SRG. The Cyber Security Plan does not require prior accreditation or certification. The Gate Criteria for Sub-factor

1.2 - High Availability and Failover has also clarified the applicable FedRAMP requirements. The Cyber Security Plan has clarified the federal and DoD policies applicable classified infrastructure.

1414 Draft SOO 4 4 6 206-210

In the latest draft, the timeline still states that classified workloads must be available and meet accreditation and authorization requirements within 9 months of contract award for classified services at the top secret level. The cyber security plan does not explicitly provide requirements for classified workloads at the Top Secret level, but indicates generally that the requirement for classified workloads is FedRAMP High. Question: Can you confirm that there are no additional accreditation requirements beyond FedRAMP High for Top Secret workloads or update the RFP to include those requirements.

While the Cyber Security Plan invokes the DoD Cloud Computing Security Requirements Guide, the Cyber Security Plan also established certain deviations from the CC SRG. The Cyber Security Plan does not require prior accreditation or certification. The Gate Criteria for Sub-factor

1.2 - High Availability and Failover has also clarified the applicable FedRAMP requirements. The Cyber Security Plan has clarified the federal and DoD policies applicable classified infrastructure.

1415 Draft SOO 4 4 6 206-210

In the latest draft, the timeline still states that classified workloads must be available and meet accreditation and authorization requirements within 9 months of contract award for classified services at the top secret level. The cyber security plan does not explicitly provide requirements for classified workloads at the Top Secret level, but indicates generally that the requirement for classified workloads is FedRAMP High.

Question: Given that FedRAMP High certification timelines are highly dependent on the work of the FedRAMP assessment team (JAB, etc.) and that Top Secret accreditation requirements have not yet been provided, will the DoD allow bids that include classified top secret services that are deemed FedRAMP ready within 30 days of award with the understanding that they cannot be sold within the classified secret environment within the JEDI cloud until FedRAMP High accreditation and to-be-defined Top Secret accreditation are granted?

We sincerely hope that you will consider this requirements enhancement, as doing so will help bidders to maximize the breadth and depth of their JEDI catalog of services, and will ensure that new services are available as soon as possible after award. We believe that allowing this change is in the spirit of the cloud acceleration goals of their contract.

While the Cyber Security Plan invokes the DoD Cloud Computing Security Requirements Guide, the Cyber Security Plan also established certain deviations from the CC SRG. The Cyber Security Plan does not require prior accreditation or certification. The Gate Criteria for Sub-factor

1.2 - High Availability and Failover has also clarified the applicable FedRAMP requirements. The Cyber Security Plan has clarified the federal and DoD policies applicable classified infrastructure.

1416 General 0 0 0 0

There were numerous questions submitted in response to the first draft RFP asking whether the Government requirement is for one cloud service provider providing one cloud or open to multi-cloud teaming arrangements. In response to those questions, the Government has repeated over and over the same answer stating, “Offerors may propose any kind of teaming/partnering arrangement so long as the proposed solution meets the requirements of the solicitation.” But what is the “requirement”? That is the question.

Offerors may propose any kind of teaming/partnering arrangement so long as the proposed solution meets the requirements of the solicitation. The requirement is everything in the RFP package.

1417 General 0 0 0 0 Please state – yes or no – is the Government’s JEDI requirement for one cloud?

JEDI Cloud is a single award ID/IQ contract for commercial IaaS and PaaS at all classification levels.

1418 General 0 0 0 0 Is a multi-cloud solution – 2 or more CSPs working together – acceptable assuming it otherwise meets the SOO of the RFP?

Offerors may propose any kind of teaming/partnering arrangement so long as the proposed solution meets the requirements of the solictiation.

JEDI Cloud Questions and Answers (Q&A) Matrix for Draft RFP #2, Draft DD Form 254 and Draft Price Scenario Documentation

ID #

Industry Submitted Information Government Response

Draft RFP #2 Document Section Subsection Page # Line # Information Request (Question)

1419 General 0 0 0 0

Leading industry analyst IDC states in its worldwide cloud predictions for 2017 that by 2018, “[o] ver 85% of enterprises will commit to multicloud architectures encompassing a mix of public cloud services, private clouds, community clouds, and hosted clouds” and that “[b]y the end of 2018, more than 50% of enterprise-class businesses will subscribe to more than five different public cloud services and will continually add, expand, contract, and drop subscriptions based on business needs.” It further explains that “Dispersed ‘hybrid cloud’ and ‘multicloud’ IT environments will be the rule” and that businesses as a result should “[m]aster the integration and management of hybrid cloud and multicloud environments,” which will be “a fundamental requirement for operating.” The various reasons for this trend include the importance of tailoring particular workloads to the cloud solution for which they are best adapted, the ability to take advantage of new and innovative services from all providers (not just a single provider), and the ability to secure the best price and take advantage of new pricing and service models.

What is DOD’s assessment of this report in the context of the JEDI cloud initiative? DoD is not going to use the solicitation process to provide feedback on a third-party report.

1420 General 0 0 0 0

For indefinite-delivery, indefinite-quantity contracts with broadly defined scopes of work, the law strongly favors awarding multiple contracts so that the government can benefit from competition as specific task orders are articulated in the future. The more ill-defined the scope of work, the greater the need for competition at the task order level. How will DOD meet this requirement given the broadly defined JEDI scope of work? Your comment has been noted.

1421 General 0 0 0 0

If the government intends to migrate applications, how will the government assess the various IaaS and PaaS offerors’ ability to enable the performance of existing or newly built applications in their clouds? Transition and migration services are outside the scope of this contract.

1422 General 0 0 0 0 If this RFP is meant to be complementary to other cloud service contracts, even within DoD, what is the government’s justification for making a single award in this procurement?

While not required by acquisition law, the DoD's rationale for single award has been published with the final RFP.

1423 General 0 0 0 0 Is there a requirement for any of the services at the higher classification level to be delivered inclusive of support solely from a government controlled environment? The cloud support package requirements have been clarified in the SOO with the final RFP.

1424 General 0 0 0 0

The government did not specifiy the number of ICD705 compliant datacenters to meet the Top Secret, SCI, and SAP requirements in the RFP. Will two ICD 705 compliant datacenters separated by the same distances as the unclassified datacenters be acceptable? The SOO has been updated to require at least 3 classified data centers.

Draft CyberSec Plan 1 1.1.0 3 74

Please give more details on logical separation requirements for and between Commercial, IL2, IL4, IL5, does this allow separate Virtual Machine on Same Server?

If the Offeror is able to ensure logical separation with cryptographic certainty at the processor and storage levels between VMs on the same server, this would be allowed. Physical separation at the processor level along with cryptographic certainty to address storage isolation is also acceptable.

Draft CyberSec Plan 1 1.1.0 3 74

Please give more details as to where the Cryptographic Certainty should be applied in logical separation?

Cryptographic certainly should be applied such that there is no inadvertant communication or traffic transferred between logically separated workloads. The Department is looking for vendors to provide innovative products and services while following industry standards and best practices.

Draft CyberSec Plan 1 1.1.0 3 74

Can a Commercial Non-DoD Virtual Machine be on the same Server as IL5 DoD virtual as long as it is logically separated with cryptographic certainty?

If the Offeror is able to ensure logical separation with cryptographic certainty at the processor and storage levels between VMs on the same server, this would be allowed. Physical separation at the processor level along with cryptographic certainty to address storage isolation is also acceptable.

Draft CyberSec Plan 3 0 4 108

This states that the offeror must meet requirements at or beyond commercial capabilities.

Since the CSP Offeror is based on a commercial capability, and the CSP Offeror already does R&D to advance new technology for their commercial cloud offerings, will the government fund the CSP to invent this technology that goes beyond what is currently being developed and also provide the requirements for such unforseen new inventions? DoD will not separately fund the vendor's R&D activities under the JEDI Cloud contract.

Draft CyberSec Plan 4 1 4 118

This specifies at least 3 data centers. How will the government provide survivability of DoD's IT enterprise if easy to identify and disable data center facilities were taken out by foreign or domestic bad actors, and wouldn't the government want multiple clouds providers with a vast number of data centers to avoid a risk of national defense survivability? Your comment has been noted.

Draft CyberSec Plan 4 3 5 155

Can the government specify the list of future hardware vulnerabilities that will arise so the offeror can meet this requirement? If not available, suggest rewriting requirement to hardware that is hardened but upgradeable if vulnerabilites arise. This requirement has been clarified in the Cyber Security Plan with the final RFP.

Draft CyberSec Plan 4 4 4 113

How much of a goegraphic distance is required for the data centers for Secret, Top Secret Top Secret/Sensitive Compartmented Information (TS/SCI), Special Access Program (SAP) levels?

The SOO has been clarified to require at least 150 miles apart for data centers at different classification levels.

Draft CyberSec Plan 4 4.01 4 118 Are 3 Data Centers for HA needed for Unclassified workloads(IL2, IL4, IL5)? The approved Cyber Security Plan has been updated to clarify the Government's requirements.

Draft CyberSec Plan 4 4.01 4 118

Are 3 Data Centers for HA needed for Secret, Top Secret Top Secret/Sensitive Compartmented Information (TS/SCI) and Special Access Program (SAP) levels? The approved Cyber Security Plan has been updated to clarify the Government's requirements.

JEDI Cloud Questions and Answers (Q&A) Matrix for Draft RFP #2, Draft DD Form 254 and Draft Price Scenario Documentation

ID #

Industry Submitted Information Government Response

Draft RFP #2 Document Section Subsection Page # Line # Information Request (Question)

Draft CyberSec Plan 4 4.4 5 161

What are the networking separation requirements for the data center in separating internet traffic coming into data center for (Commercial or IL2 systems) and for NIPR NET Coming in Via DoD CAP to IL4/IL5 systems?

The Department would like the ability for applications within logical enclaves to be accessible from the internet, from NIPRNet, or from both at the discretion of the appropriate Authorizing Official. Traffic should be separated by the Offeror so that systems not authorized for internet access do not have internet traffic. The DoD is looking for vendors to provide innovative products and services while following industry standards and best practices.

Draft RFP Section C C 1 14 132

If migration services are outside the scope of the procurement, how will DoD assess the total cost of moving to a single cloud service provider?

Transition and migration services are outside the scope of this contract. The Department is not going to comment on other contracts outside the scope of JEDI Cloud as part of this RFP process.

Draft RFP Section F 2 2 16 221

Section F2 states that orders with 5 option years can be awarded and option years can be exercised after the expiration of the JEDI contract. Can the term of the marketplace be extended by a task order with option years extending beyond the expiration of the JEDI contract?

This language has been clarified in the final RFP. Task order option years cannot be exercised after the expiration of the JEDI Cloud contract.

Draft RFP Section H 2 0 17 257

DoD should prohibit the JEDI contractor from using Government data, aggregating Government data or data mining for its commercial purposes. Your comment has been noted.

Draft RFP Section H 3 C 17 275

With this statement will the conntractor be responsible for all cryptographic devices being supplied to support connectivity for the program?

The government will utilize multiple mechanisms for cryptographic certainty, including those provided by the Offeror.

Draft RFP Section H 14 c 27 540 How will a dispute between a Third Party Offeror and the IaaS provider be resolved? The specific circumstances and facts would drive the path to resolution.

Draft RFP Section H 14 c 27 540

DoD should ensure there is no requirement imposed by the JEDI contractor for vendors to list or sell products through the JEDI contractor’s commercial marketplace as a condition for selling through the JEDI marketplace. The marketplace requirements are addressed in the SOO and Section H of the RFP.

Draft RFP Section M 3 Factor 3 102 3923 What is the rationale for the RFP’s preference of “existing solutions” at the Tactical Edge? Unclassified tactical edge offerings must be available within 30 days of contract award.

Draft RFP Section M 4 Factor 10 106 4079 How will price reasonableness be evaluated for sales through the marketplace?

The online marketplace requirements have been updated to restrict the types of offerings that are required. Price reasonableness for online marketplace will be evaluated in accordance with Section M, which has been updated for clarity.

1443 Draft SOO 0 0 1 11

The SOO states that…

This is the start of the file's text. The full file is on GovTribe.

File details come from the government source that posted it.