MCS SOW State Agencies.docx

DOCX document 266 KB Posted

Attached to
STC Managed Cloud Services State and local contract opportunity
Solicitation number
5400028075
Issued by
South Carolina

About this file

This document is a Statement of Work (SOW) for Managed Cloud Services for State Agencies in South Carolina, developed by the South Carolina Department of Administration (Admin). The SOW outlines comprehensive cloud services for state agencies, including base managed cloud services and optional managed cloud services across multiple cloud service providers. The services encompass a wide range of technical capabilities such as cloud center of excellence support, cloud service provisioning, network services, security services, technical support, database management, and transition services. The contract involves detailed service management processes, information security management, and a structured transition plan for implementing cloud services across state agencies.

The SOW is part of Solicitation No. 5400028075 and establishes a framework for cloud service delivery with specific requirements for service levels, financial management, and operational performance. The document indicates that services will be provided through an ITIL-based service management approach, with extensive documentation, reporting, and collaboration requirements. Pricing and financial management will be handled through the Admin-provided systems, with the Service Provider responsible for collecting and reporting cloud service consumption data, supporting chargeback processing, and optimizing cloud financial performance. The contract emphasizes a collaborative approach between the Service Provider, Admin, and state agency customers, with a strong focus on security, continuous improvement, and transparent service delivery.

View the file

Other files for this state and local contract opportunity

Other files attached to STC Managed Cloud Services, newest first.
File Type Posted
Canceled Contracts.docx DOCX document
Financial Resp Matrix.xlsx XLSX spreadsheet
Form of Invoice Data Feed.xlsx XLSX spreadsheet
Form of Parent Guaranty.docx DOCX document
General Provisions.docx DOCX document
MCS SOW OGE.docx DOCX document
NDA.docx DOCX document
Non Disclosure Form.docx DOCX document
Definitions.docx DOCX document
MCS SOL Com Serv.docx DOCX document
Negotiated T&C.docx DOCX document
RFP Offer Qual.docx DOCX document
Service Level & Deliver.xlsx XLSX spreadsheet
Source Code Escrow.docx DOCX document
Business Model.docx DOCX document
Key Personnel.docx DOCX document
MCS Solicitation.pdf PDF
MCS Solution State Agencies.docx DOCX document
Pricing Structure.xlsx XLSX spreadsheet
RFP Offeror Reference.docx DOCX document
Reports.xlsx XLSX spreadsheet
Service Model.docx DOCX document
Form of Work Order.docx DOCX document
Goverance Model.docx DOCX document
InFlight Projects.docx DOCX document
MCS Solution OGE.docx DOCX document
Performance Model.docx DOCX document
RFP Exceptions.xlsx XLSX spreadsheet
RFP Offeror Experience.docx DOCX document
RFP Security Asses Quest.docx DOCX document
Rep, Cert & Other.docx DOCX document
Service Level Definitions.docx DOCX document
Service Management Manual.docx DOCX document
Show all 33

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

Exhibit 2.1.1 (Managed Cloud Services Statement of Work) Solicitation No. 5400028075

Managed Cloud Services

Exhibit 2.1.1 Statement of Work – State Agencies

Solicitation No. 5400028075

Table of Contents

1Introduction3
1.1Overview3
1.2Operating Model4
1.3Cloud Services5
2Base Managed Cloud Services6
2.1Cloud Center of Excellence (CCOE) Support6
2.1.1Technology Standards7
2.2Cloud Service Provisioning and Management7
2.2.1Provisioning Automation9
2.3Network Services10
2.3.1Customer CSP Connection Coordination10
2.3.2Network within the CSPs10
2.4Base Managed Cloud Security Services11
3Optional Managed Cloud Services11
3.1Request for Solution (RFS)11
3.2Customer Virtual CSP Connection12
3.3Customer Direct CSP Connection13
3.4Managed Technical Support13
3.4.1Operations Monitoring17
3.4.2Performance and Capacity Management18
3.4.3Backup and Recovery Services19
3.4.4Disaster Recovery Services20
3.4.5Real-Time Forensics Support Services21
3.5Virtual Machine Middleware Services21
3.6Virtual Machine System Administration22
3.7Cloud Native Middleware Services23
3.8Distributed Denial of Service Protection Services23
3.9Database Management Services24
3.9.1DBMS Administration and Operations24
3.10Technology Roadmap25
4Service Management25
4.1Service Management Systems26
4.2Process Documentation and Execution28
4.3Training and Education29
4.4Portal30
4.5Service Catalog Management30
4.6IT Service Desk31
4.7Incident Management32
4.8Problem Management33
4.9Request Management and Fulfillment34
4.9.1Request Management processes and systems34
4.9.2Service Request Operations35
4.10Change Management37
4.11Service Asset and Configuration Management37
4.12IT Service Continuity Management38
4.13Project Management39
4.14Operational Intelligence39
4.15Customer Satisfaction40
4.16Service Level Management41
4.17IT Financial Management42
4.18Cloud Financial Performance Optimization43
5Information Security Management for Service Provider Services46
5.1Information Security Management General Requirements46
5.2Service Provider Staff47
5.3Integration with Admin SIEM47
5.4Security Event Identification and Alerting Services47
5.5Security Incident Management48
5.6Physical Security Administration48
5.7Customer Facilities49
5.8Security Assessments49
6Transition Services51
6.1Service Commencement51
6.2Transition Overview51
6.3Knowledge Transfer52
6.4Transition Management Requirements53
6.5Transition Project Plan54
6.5.1Transition Project Plan Critical Deliverable55
6.5.2Kickoff56
6.5.3Meeting Attendance and Reporting Requirements57
6.5.4Transition Documentation and Collaboration58
6.5.5Organizational Change Management (OCM)59
6.5.6Operational Readiness60
6.5.7Staffing Plan and Requirements61
6.5.8Determination of Responsibility (Service Provider and Other State Vendors)61
6.6Remedies for Transition Failure62

Figures Figure 1 – MCS State Agency Operating Model 5

Tables

Table 1 – State Agency Cloud Services5
Table 2 - Service Management Capabilities26

Introduction Overview This Exhibit 2.1.1 (Managed Cloud Services SOW - State Agencies) sets forth the Services that Service Provider shall provide as of the Commencement Date unless otherwise specified to support State Agencies that elect Managed Cloud Services (MCS). Further, this Exhibit 2.1.1 (Managed Cloud Services SOW - State Agencies) sets forth the processes and systems that the Service Provider will provide, including the Service Provider's obligations to work with other South Carolina Department of Administration (Admin) Service Providers, and Customer cloud security teams and providers, to deliver integrated end-to-end Services. The Service Provider shall coordinate with Admin, Admin Service Component Providers (SCPs), Customer cloud security teams and providers, and Admin Contractors to effectively provide the Services.

The Service Provider shall provide a solution that supports all the requirements described in this Exhibit 2.1.1 (Managed Cloud Services SOW - State Agencies) and its Exhibits in accordance with Exhibit 4.2 (Financial Responsibility Matrix). All Services are included within the Charges described in Exhibit 4.0 (Business Model). Accordingly, the Service Provider also confirms that Admin will not incur any other Charges for the requirements described in this Exhibit 2.1.1 (Managed Cloud Services SOW - State Agencies).

The Service Provider shall deliver the Services in the best interests of the State. The Service Provider shall be responsive to Admin’s current and future requirements by proactively anticipating needs and adjusting Services accordingly within the Charges. Requirements for New Services will be handled in accordance with Exhibit 1.4 (General Provisions), and the Service Provider shall assess the impact of these requirements on Admin’s and Admin Customers’ operating environments and supported applications in accordance with the terms of the Agreement.

The Service Provider shall be responsible for all activities necessary to ensure Admin’s Services are performed in accordance with all standards and processes contained in the Agreement, the Service Levels in Exhibit 3.1 (Service Level & Deliverables Matrix), and the Service Management Manual (SMM).

Service Provider shall integrate and fully cooperate with Admin and all other SCPs as required for smooth and efficient operation during the development, implementation, and execution of its Service Management Processes to ensure consistency and integration across all Service Providers. Service Provider will work with Admin and other SCPs to deliver integrated Services and share Service Level responsibilities as defined in Exhibit 3.1 (Service Level & Deliverables Matrix).

Operating Model Exhibit 2.1.1 (Managed Cloud Services SOW - State Agencies) contains specific cross-functional requirements that all SCPs must meet to perform the requested Services and responsibilities defined in Exhibit 2.0 (Service Model).

Figure 1 - MCS State Agency Operating Model below depicts the relationships between Customers, SCPs, Admin, and State Fiscal Accountability Authority (SFAA.)

Figure 1 – MCS State Agency Operating Model As the overall service owner for State Agency-consumed shared services, including Managed Cloud Services (MCS), Admin provides functional governance of services and operations functions that provide customer relationship leadership, service catalog and Level 1 service desk, IT service management, and Division of Information Security (DIS). The Admin Sourcing Management function works closely with the Admin-managed SCPs to ensure the provided services individually adhere to the Service Provider's requirements and collectively meet Admin's desired outcomes. The Admin DIS Information Security SCP supports State Agency cloud Customers and the Service Provider for cloud security and incident response.

Cloud Services The State Agency Cloud Service offerings include Base Managed Cloud Services, available to all State Agencies that elect Cloud Services, and Optional Managed Cloud Services, as elected by the Customer. Table 1 State Agency Cloud Services summarizes the high-level services the Service Provider is to design, deploy, and deliver either as base services or optionally.

Table 1 – State Agency Cloud Services

Service Provider Services
Base Managed Cloud Services
Optional Managed Cloud Services
Architectures, standards, and education
Yes, provided by Admin
Cloud Center of Excellence
Yes
Provisioning
Yes, account-level only
Cloud Security & Security Incident Response
Yes, provide support to DIS as requested in support of a security incident only
Ordering CSP Services from Admin Service Catalog
Yes
Service Provider Service Levels
Yes, limited to Service Levels that apply to the subscribed services
Yes, limited to Service Levels that apply to the subscribed services
Customer to CSP Network Connections
Yes, coordination
Optional Connections Available
Networking within CSPs
Yes
Cloud Service Consumption Reporting
Yes

RFS - Cloud Solution Design & Project Mgt.

Optional

Managed Technical Support (bundle)

Optional Bundle

Operations Monitoring & Reporting

Optional Bundle

Performance and Capacity Management

Optional Bundle

Backup and Recovery Services

Optional Bundle

Disaster Recovery Services

Optional Bundle

Real-Time Forensics Support Services

Optional Bundle

Virtual Machine Middleware Services

Optional

Virtual Machine Administration

Optional

Cloud Native Middleware Services

Optional

Distributed Denial of Service Protection Services

Optional

Database Management Services

Optional

Technology Roadmap

Optional

In the above Table 1 - State Agency Cloud Services, the following meaning is intended:

1. Scope flag:

a. Yes - In-scope Services provided by Service Provider.

b. Yes, qualification - In-scope Services the Service Provider delivers only applies to specific criteria.

c. Optional – Services provided by the Service Provider that are optional as elected by a Customer.

Base Managed Cloud Services Cloud Center of Excellence (CCOE) Support The Admin-led public Cloud Center of Excellence (CCOE) program charter aims to align the Service Providers to ensure success with public cloud adoption. Through the CCOE program, Admin provides public cloud strategy and governance through policies, standards, and best practices to State Agencies.

The Service Provider shall support Admin in the creation of best practices, including, at a minimum:

1. Collaborate with Admin and other SCPs and utilize industry and other best practices to support Admin’s public Cloud Center of Excellence.

1. Develop consistent approaches to ensure solutions are consistently implemented across Cloud Service Providers (CSPs).

1. Document solutions to identify products used across CSPs to ensure similar functions and workflows for the State and Customers, regardless of hosting location.

1. Develop and maintain a solution accelerator library with frameworks, templates, tools, and methodologies to streamline and accelerate solution documentation and implementation.

1. Develop and maintain documented solutions for frequently used activities (e.g., user provisioning, resource deployment).

1. Promote consistency through automation of service operations by examining the frequency of requests, commonalities between products and services, and streamlining processes.

1. Support Admin with optimization of the cloud service catalog through leveraging public cloud best practices, particularly around automation and orchestration.

1. Support Admin in continually maintaining the currency of public cloud-approved services as Services are made available by the CSP and with the State's agreement.

Technology Standards The Service Provider shall research and recommend standard products to the Admin CCOE for adoption into the program, including, at a minimum:

1. Provide and make available the description of Services and offerings by Service Provider that are in use on a quarterly basis.

1. Provide and make available the description of standard products to Authorized Users as requested by the State.

1. Provide standards for supporting open-source software.

1. Describe approved Services and offerings.

1. Provide feedback on the approved Services and offerings list with respect to the State’s strategic direction and technical architecture.

Cloud Service Provisioning and Management One of the goals of public cloud is to allow Customers to provision and consume services in the public cloud as natively as possible with technical, delivery, and security assurances. In accordance with the Services provided for Base Managed Cloud Services, the Service Provider shall, at a minimum:

1. Manage and administer initial access to the cloud services, systems, networks, operating software, system files, and Admin and Customer’s data, including:

a. Enable role-based access to public cloud services and functions for Customer and enterprise user roles.

b. Assign initial and, as requested, reset existing privileged account passwords per established procedures.

c. Provide Customer access to create user IDs, suspend and delete inactive logon IDs, research system security problems, and maintain network access authority.

2. Provide cloud service provisioning with State-approved CSPs in accordance with the Services provided for Base Managed Cloud Services to support service provisioning and billing for each approved CSP, including, but not limited to:

a. Accounts, subscriptions/organizations, organizational units, resources/services, etc.

i. State Agencies’ services will be deployed in the Admin tenant and may have certain restrictions.

ii. As approved by Admin, exceptions may be granted to allow a State Agency to be deployed into a Customer tenant.

iii. Service Provider will support potential variations in onboarding differences between provisioning in the Admin and Customer tenants and processes.

b. Communicate the approved information electronically with the requesting Customer, enabling the Customer to access and use the provisioned service.

c. Support the Customer with questions regarding how to gain access to the provisioned service.

d. Provide Customers with the ability to provision and support services aligned with public cloud capabilities by leveraging native interfaces.

3. Develop and maintain, within the SMM, Customer-facing and internal operational documentation on the steps to request, provision, and support the provisioning of cloud services for Customers.

4. Implement access controls to services and operational functions based on defined Customer and Service Provider support responsibilities.

5. Integrate Service Provider Services with CSP native console and/or service catalogs, including:

a. Provisioning access to allow fulfillment of Customer provision requests based on templates aligned with State standards and policies, and/or application tools available from CSPs.

b. Enable deployment of the templatized cloud infrastructure with role-based security and automated fulfillment, leveraging public cloud best practices delivered with the Admin service catalog integration.

i. Role-based security shall be delivered based upon Customer requirements and Cloud Services, within defined State policies, and governed by the principle of “least privilege” as defined by The State, required to balance Customer requirements with program goals effectively.

6. Provide the ability to integrate provisioning and management through automated orchestration and integration of CSP service catalogs (e.g., custom catalogs).

7. Provisioning infrastructure components based on Admin-defined reference architecture standards, including compute, network, storage, and security resources.

8. Extend cloud service capabilities by integrating with cloud native, cloud-agnostic, and third-party tools.

9. Ensure that security and certificates meet State program requirements.

10. Assist Admin in implementing IT Financial Management (ITFM) billing and chargeback of cloud services consumed, including integrated tagging of services, products, and components for tracking chargeback.

11. Develop cloud service tagging automation and orchestration to inform service management, billing processes, and capabilities.

12. Perform necessary service integration within State program service catalog to ensure necessary brokering and orchestration can occur in an automated fashion to provision service requests successfully.

13. Support Admin in service integration in service catalog orchestration to ensure automated provisioning of requests.

Provisioning Automation The Service Provider shall enable continuous integration and automated testing of cloud service provisioning deployments using Infrastructure as Code (IaC), including but not limited to:

1. Provide, deploy, and manage IaC using State-approved tools to support cloud services' deployment, provisioning, scaling, networking, and security.

2. Automate service deployment, operational monitoring, and security monitoring using IaC concepts or policies to ensure resources remain compliant with requirements.

3. Comply with established reference architecture standards and standard products for IaC deployments.

a. Where these standards may not exist or contain a complete view of best practices, the Service Provider shall recommend updates to the documentation owner.

4. Document all IaC processes, procedures, and Source Code documentation, aligning with the SMM.

5. Implement a data protection solution to ensure the backup and recoverability of IaC configurations in an Admin-approved Source Code library.

6. Develop rollback procedures as applicable for restoration to previous configurations.

7. Perform quality assurance testing for IaC deployments.

8. Utilize best practices relating to IaC, including but not limited to:

a. Develop and deploy IaC using templates, images, and stacks that define the resources and interconnections.

b. Maintain detailed documentation to ensure resources and properties, metadata, parameters, mappings, conditions, and outputs are defined.

c. Provide transferable solutions and approaches to IaC that minimize vendor lock-in and protect the State program against an over-reliance on a single vendor solution.

Network Services The Service Provider shall provide networking services management for all in-scope service elements, including but not limited to:

Customer CSP Connection Coordination For all Customers, solution, coordinate, and project manage network connections that enable Customers to connect to CSP services.

Service Provider shall, at a minimum:

1. Coordinate public cloud connectivity in support of Admin operations and the Admin network team.

2. Assist the responsible Admin SCP in the design and management of direct public cloud network connections for the delivery of Services.

Network within the CSPs For all Customers, solution, deploy, and manage networking within CSPs to enable Customers to connect to CSP services securely.

Service Provider shall, at a minimum:

1. Architect virtual network reference architecture standards to define best practices, design principles, and security guidelines for setting up networking within CSPs that support Customer segregation, billing, audit, reporting, security, and operations management.

2. Create and manage Customer cloud environments using virtual network reference architecture standards as recommended by the State, aligning with and supporting customer segregation, billing, audit, reporting, security, and operations management.

3. Provide installation, testing, operating, troubleshooting, and maintenance of cloud virtual network solutions (e.g., Virtual Private Clouds (VPCs), virtual cloud network), compute resources, operating system(s), configuration items, software, services, and other elements that comprise the Service.

4. Implement zone-based network security (e.g., VPCs, Virtual Networks, Subnets) with stateful firewall filtering between isolated networks, utilizing stateful packet inspection to manage packet flows. This ensures that only packets from known active connections can pass.

5. Provide cloud virtual network reporting (e.g., subnet in use, port mapping, internet usage).

6. Provide a solution to control network access to cloud services and associated functions based on State-approved policies and customer requirements. (i.e., ability to restrict/grant appropriate services access based on Admin-approved services, support models, and reference architectures using features like cloud-native firewall and network security groups).

a. The solution shall be auditable and reportable, enabling identification of levels of Service Provider support services.

7. Provide and support standardized virtual network (or comparable) build automation and the ability to support utilization of existing VPCs when required for new compute build requests.

8. Provide and support the ability to deploy custom virtual network solutions (e.g., support VNet/Subnet counts and sizes).

9. Request available IP address ranges from Admin and allocate and manage IP addresses in accordance with Admin IPAM strategies, processes, and standards to support public cloud services.

10. As requested by Admin, where needed to resolve Customer overlapping IP address issues, develop and deploy a Network Address Translation (NAT) solution as needed within CSPs.

Base Managed Cloud Security Services State Agency Customers are required to adhere to the Admin SCDIS-210 publication security framework and guidelines. In support of Customers, the Service Provider shall, at a minimum:

1. Provide configurations and support in adherence to the SCDIS-210 Information Security Technology Coverage Measurement Standards published by Admin.

2. As requested by Admin, evaluate the security controls and data protection standards implemented in public cloud services and report on performance and compliance requirements adherence to SCDIS-200 Information Security and Privacy Standards as published by Admin, and CIS Benchmarks as approved by Admin.

Optional Managed Cloud Services As requested by Customers and approved by Admin, the Service Provider will offer optional services.

Request for Solution (RFS) Requests for Solution (RFS) are Customer requests where requirements are captured, and the Service Provider develops solutions and cost estimates for Customer review and approval. These solutions typically assume the Service Provider builds and implements the solution. For Customer Requests that require the Service Provider to propose a solution, the Service Provider shall, at a minimum:

1. Support the State in developing and maintaining RFS processes in the SMM, including supporting systems and appropriate mechanisms for fulfilling complex requests that require design, pricing, solutions, and proposals. This includes clear and effective communication to set expectations and promote excellent customer service.

2. Support the State in developing and maintaining RFS ROM processes in the SMM, including appropriate mechanisms to support rapid proposal development that provides accuracy for budgetary information without requiring a complete solution (e.g., rough order magnitude (ROM) pricing and high-level architecture).

3. For all RFSs requested by the Customer:

a. Review RFS to validate for completeness.

b. Coordinate and lead meetings to review requests, gather requirements, solution, and develop the proposal.

c. Coordinate the attendance of all necessary subject matter experts in solution and requirement gathering sessions.

d. Once requirements are complete, provide a timeframe for delivering the solution proposal, including cost estimates.

e. Develop the solution, including the technical solution, effort, acceptance criteria, solution design document, and pricing.

f. Develop the solution to conform to the State-approved architecture, standards, and pricing.

g. Develop the solution in conformance with the State Security Policies, procedures, and guidelines of the Customer and the State.

h. Develop the solution in conformance with State-approved security baselines.

i. Develop the solution in conformance with the boundaries of the State technical guidelines.

j. Coordinate and facilitate solution reviews across the Service Provider as required to review and gain approval for the solution and pricing.

k. Track all Project Change requests in accordance with established procedures in the SMM.

l. Provide a single proposal to the requesting Customer as required.

m. Iterate and adjust the solution and cost estimating template to adhere to the requesting Customer’s feedback and requirements.

n. Document Customer approvals in accordance with established processes as per the SMM.

o. Gather and validate that the proposal acceptance comes from an appropriately authorized user.

p. Provide status to Customers for all outstanding requests.

q. Initiate Project Management as appropriate upon acceptance of the proposal by the Customer to implement approved proposals.

Customer Virtual CSP Connection As an optional service, as requested by Customers who do not have Admin-provided connectivity to CSPs, solution and provide a service that offers Customer virtual connectivity from the Customers network to the CSP services.

Service Provider shall, at a minimum:

1. Design, implement, monitor, and manage cloud access using VPN to enable connections to CSPs.

Customer Direct CSP Connection As an optional service, as requested by Customers that do not have Admin-provided connectivity to CSPs, solution and provide a service that offers Customer direct network connectivity from the Customers network to the CSP services.

Service Provider shall, at a minimum:

1. Design, implement, monitor, and manage cloud access using a Virtual Cross Connect (VXC) direct connect solution to enable Customers to connect securely to CSPs.

2. Provide an optional service to establish and maintain a VPN connection, based on approved Admin use cases, within the VXC direct connect solution.

Managed Technical Support Managed steady-state services include responsibilities and activities to support public cloud products and corresponding workloads, services, processes, systems management roles, virtual networks, microservices, container technologies, serverless architectures, and other public cloud services. Responsibilities for the Admin environment include integration with other Admin Service Providers to ensure the availability of Services. The Service Provider shall, at a minimum:

1. Through ongoing support and maintenance control processes, support the current implementation and solutions developed by the Service Provider during the Agreement term.

2. Manage the implementation of public cloud products, services, and related technologies to support required business applications.

3. Install tools and processes to enable delivery of all in-scope cloud services, operations, monitoring, systems management, event response, and service restoration for the in-scope environment.

4. Perform 24x7 operations monitoring, systems management, event response, and service restoration for the in-scope cloud services.

5. Interface with Admin Incident and Problem Management processes and teams supporting Resolution and service restoration.

6. Resolve all events, warnings, and alarm messages and notify Customers as appropriate.

7. Support cloud-native, cloud-agnostic, and third-party tools and products to support defined Services.

8. Define and provide technical support for cloud services, in accordance with the SMM for operations, including:

a. OS administration.

b. Patch management.

c. Virtualization of resources.

d. Storage management.

e. Backup and recovery.

f. Disaster Recovery.

g. Virtual server support.

h. Install/Move/Add/Change (IMAC).

i. Capacity planning and reporting.

j. Performance tuning.

k. Problem resolution and Root Cause Analysis.

9. Verify that deployed cloud services are compliant with Admin baseline standards.

10. Provide cloud service performance optimization, capacity management, and auditing of configurations to ensure alignment with Admin-defined standards. The Service Provider shall notify Admin where deviations exist.

11. Perform all measurements and reporting for public cloud-hosted platforms as required to support Services as defined in Exhibit 3.0 (Performance Model).

12. Comply with established reference architecture standards and standard products, including deployed software and Services within the managed service.

13. Ensure an auto-scaling design for the following:

a. Tools integration.

b. Host uniqueness.

c. Backup reporting.

d. Billing.

e. Tagging.

f. Compliance implications.

g. Naming standards.

h. Auditability of these Instances.

14. Provide technical advice and support to Projects, applications, application development, and service operations teams as required.

15. Enable and manage native public cloud services for dynamic scaling to meet overall capacity needs, including auto-scaling groups where necessary.

16. Design and implement user and system security measures in alignment with defined security policies.

17. Comply with the requirements of the State program and Customers for Configuration Management items in the Service.

18. Follow Admin-defined Incident Management processes, leveraging the Admin-provided environment.

19. Design, implement, and manage capabilities to enable cross-cloud migration techniques to ease system migration and re-platforming.

20. Implement and manage an automated software deployment and patching set of procedures and tooling, leveraging cloud best practices.

21. Identify and implement required service or configuration changes to address solution defects.

22. Maintain service documentation (technical specifications and testing documentation) as well as common problems, root causes, and remedies to aid in identifying and remedying underlying system incidents.

23. Participate in applicable acceptance testing or review of any changes arising from break/fix or patch/release performed by Service Provider.

24. Verify and ensure compliance with any Admin security-mandated patches, configuration settings, or system levels required, given the nature of the security mandate, and report to Admin, in writing, any risks or issues that the Service Provider becomes aware of in providing the Service to Admin.

25. Assist Admin and Customers by referring incidents to the appropriate third-party entity for resolution and coordinating with the third-party service to help minimize the Customer's role in problem management.

26. Notify Admin and Customer of Service Provider’s planned and reactive maintenance activities, including service-impacting and non-service-impacting operations, as appropriate.

27. Assess the utilization of all MCS assets (e.g., public cloud products, platforms, storage, network interface points) within the defined lifecycle services within the State program, emerging products, and capabilities to deliver Services more effectively. Drive the overall consistency and reliability of the Service through:

a. Simplification of service offerings and support tiers to move the Service to a support model that is highly repeatable and reliable.

b. Implement repeatable templates, automation, and programmatic orchestration to drive initial quality in service implementations (i.e., “right first time”) and reduce Incident, Problem, and Change Management service requests wherever possible.

c. Review all Customer-facing (and Admin-supporting) help channels and service reports to eliminate extraneous and conflicting elements. This includes removing manual steps by automating Incident, Problem, and Change Management communications and processes.

d. Automate data collection to drive better and more timely data collection to facilitate Service decision-making, cross-functional coordination, and long-term planning.

28. Actively support the demand management process by developing technical solutions, including intra-tower solution development, as initiated through Request for Solution procedures.

29. Perform analysis of and vetting of services and products across CSPs and, in conjunction with Admin, develop Services that align with State program business assurance standards.

30. Develop and maintain support for cross-platform cloud support solutions (e.g., Pivotal, OpenShift, etc.)

31. Upon request, perform multi-homing of installed tooling alerts to include Customers' systems where feasible.

32. Assess CSP services in the public cloud environment to ensure alignment with financial and service optimization activities.

33. Validate that all Admin-approved tools are installed and configured on all deployed systems within the program, including instances deployed via self-service.

a. If systems are identified without Admin-required tooling, Service Provider shall perform necessary remediation.

34. Leverage the approved Admin mechanism to enable the tracking, management, and implementation of security certificates used to secure confidential sessions (e.g., SSL) for Internet and Intranet transactions and communications, including:

a. Establish processes and procedures for renewals, as required by Admin or Customers.

b. Schedule, apply, and support security certificates as Admin or Customer requires.

c. Coordinate and advise Customers regarding certificates that are embedded in Applications.

d. Notify and advise Customers of certificate renewals.

35. Service Provider shall provide system administration assistance with Customer Software installations, upgrades, and patches. Service Provider shall, upon request, assist in the installation, patching, and upgrades of Customer Software. In these instances where Customer requests support, Customer shall provide work instructions for requested activities per the SMM.

36. Maintain MCS-approved service listing as instructed in the SMM, including developing automations for improved service and data quality management.

37. Monitor services for deprecation notices and proactively provide upgrade planning and implementation support to ensure services remain at supported levels and API versions.

38. The Service Provider shall provide storage management for all in-scope service elements, including but not limited to:

a. Configure, monitor, and manage a robust and highly available cloud native storage solution to satisfy the overall needs of Admin and Customers.

b. Perform storage, backup, and restore service testing, and maintain the backup system and service documentation.

c. Implement cloud native platform level encryption on all Admin storage in accordance with Admin standards and security baselines. Due to data classification and compliance requirements, implement and support customer-managed keys for encryption where necessary.

Operations Monitoring The Service Provider shall provide operations monitoring services and support for Customer-elected environments and Services such as virtual networks, microservices, serverless architectures, and native middleware services, with responsibilities including, but not limited to:

1. Install, configure, and provide ongoing CSP services monitoring and reporting tools and services. Where appropriate, Service Provider shall utilize Admin-provided tools and monitoring systems.

2. Perform operational monitoring, including real-time mechanisms for monitoring systems, including but not limited to availability, auto-scaling, performance, capacity, and overall environment health as defined in the SMM and required to support Service Levels as defined in Exhibit 3.0 (Performance Model).

3. Integrate operational monitoring with the Admin ITSM platforms to allow electronic event and Incident Management integration and provide real-time systematic notification of performance issues and events.

4. Conduct 7x24x365 operational monitoring using CSP native health monitoring tools (e.g., Azure Monitor, Azure Resource Health, Azure Application Insights, Amazon Cloud Watch, AWS Service Health Dashboard) and third-party monitoring tools (e.g., Datadog, Splunk) as directed by Admin.

a. Perform service restoration activities of public cloud platforms, including real-time monitoring and reporting of capacity, stability, and performance of Services and platforms.

b. Establish and monitor proactive alarms in accordance with thresholds defined in the SMM.

c. Provide end-to-end visibility to Admin and Admin-approved Users or Customers to view performance statistics (real-time and historical) on public cloud platforms.

5. Provide full monitoring integration with Admin and SCP operational support processes (e.g., SIEM, Incident Management, Change Management, asset, and inventory management, etc.).

6. Provide status and trending reports as required, including:

a. Reports listed in Exhibit 3.3 (Reports).

b. Other Reports as required in this Exhibit 2.1.1 (Managed Cloud Services SOW - State Agencies), Exhibit 4 (Business Model), and related attachments.

Performance and Capacity Management To ensure that Services achieve the desired business and service-based outcomes, the Service Provider shall, at a minimum:

1. Develop performance and capacity management processes.

2. Actively participate in the exchange of data and information amongst other Admin Service Providers, Admin, and Customers to ensure successful delivery of Services, including the ability to validate capacity planning.

3. Integrate performance and capacity management tooling and process outputs with Admin capacity management and other Service Management processes and systems.

4. Conduct performance and capacity planning and management activities for all supported products, platforms, and applications.

5. Participate in scheduled capacity planning meetings.

6. Create, update, and report a Capacity Plan that includes:

a. Developing an agreed-upon formula for measuring capacity.

b. Services, components, and resources measured.

c. Current, trending, and forecasted capacity based on technical planning and demand management.

d. Detailed performance and consumption characteristics.

e. Identify workload landscape (Prod, Test, etc.).

f. Risk areas (including over- and under-capacity or approaching quota limits).

g. Actual consumption compared to plan.

7. As required, provide performance and capacity technical advice and support to projects, applications, application development, and database teams.

Backup and Recovery Services Service Provider shall be responsible for backup and recovery of enrolled Customer Services. In establishing, monitoring, and managing backup/restore operations, the Service Provider shall, at a minimum:

1. Design, install, monitor, and manage backup policies and services to satisfy the overall needs of Admin and its Customers within the public cloud, including support for virtual machines, storage, snapshots, virtual grids, virtual tape libraries (VTL), volumes, databases, tables, files, and filesystems.

2. Design and manage storage, file, and volume gateway solutions.

3. Develop backup and recovery-related management processes and automation.

4. Assess, develop, and formally recommend opportunities to reduce (or avoid) costs associated with a backup environment.

5. Perform environment/supported backup tuning, job, and environment restructuring, and provide tools and other efforts to help improve the efficiency and reliability of storage and backup operations and to help reduce ongoing maintenance requirements.

6. Maintain backup environments in accordance with Admin strategies and standards relating to technical, data, and applications architectures as agreed upon in this Exhibit, and as required by Customer projects, environments, the SMM, or other supporting documents.

7. Establish, publish, and maintain a production backup calendar, including daily and periodic backup and service maintenance activities.

8. Generate and provide access to monthly summary reports that track the progress of the CSP and Service Provider’s backup and service maintenance work performance.

9. Perform ad hoc backup/restore operations reporting as agreed by the parties.

10. Meet with Customers at least once a year to review existing backup schedules for suitability and identify any required updates to existing backup schedules and retention policies.

11. Monitor and remediate backup failures on the Service Provider's standard backup service.

12. Perform backup restoration testing.

13. Install, configure, and manage file-level backup agents and services where appropriate.

14. Backup all databases deployed within the State program using database-aware technologies.

15. Encrypt all backups, regardless of media and location, to ensure compliance with the SC DIS 200 security framework or subsequent versions.

16. Implement and monitor backup and restore services operations for all regions and availability zones.

17. Update the backup platforms and services as new tools and technology are available to improve Admin’s or Customer’s business processes and performance.

18. Verify backup outcomes correctly achieve service delivery requirements for Service Provider responsible data (i.e., operating system recoverability).

19. Provide an auditable solution for Customer to view the schedule, retention, and target information as configured in the backup systems, with the ability for Customer to correlate to Customer’s requested requirements.

20. Provide reporting on backups and backup infrastructure (e.g., success/failure, schedules, retention, targets, archive, capacity, performance, storage media types, and storage location).

21. Perform backup administration and monitoring, including:

a. Verify backup jobs start as scheduled.

b. Monitor scheduled production backup jobs.

c. Perform job restart, as necessary, in accordance with resolution and restart procedures.

d. Resolve backup scheduling conflicts.

e. Ensure that failed backup jobs are restarted once the failure condition is identified and resolved.

22. Monitor scheduler-related incidents and develop and recommend changes to the scheduler database.

23. Schedule backup jobs, as requested by the Customer, that require expedited or ad hoc execution.

Disaster Recovery Services Customers will be solely responsible for overall business continuity and application recovery plans. The Service Provider retains responsibility for business continuity plans for Service Provider Services and, if requested by the Customer, supports Customers with the recovery of cloud services. Service Provider Disaster Recovery (DR) does not apply to non-native cloud middleware and application software configurations, application presentation, or customizations, and is limited to in-scope cloud services unless otherwise agreed to with Admin or Customers.

The Service Provider shall, at a minimum:

1. Design and deploy solutions, via the RFS process, that align with the defined DR class requirements as required by Customers, and complement Customer activities in support of Customer and business continuity plan(s), including:

a. Leverage region failover and availability zones.

b. Document procedures to restore primary operations.

2. Monitor and manage recoverable cloud services within the public cloud to satisfy the Customers' needs.

3. Upon Customer request, participate in Admin or Customer DR planning sessions, DR testing sessions, or actual DR recovery efforts for in-scope service elements.

Real-Time Forensics Support Services Upon Customer or Admin’s request, Service Provider shall secure, acquire, and preserve evidence data within the public cloud, and allow third-party forensic teams to perform analysis without potentially losing critical data. If requested, the Service Provider shall, at a minimum:

1. Implement and manage a forensics capability and support within any defined public cloud hosting environment.

2. Support Admin, SCP, or a third-party at Customer or Admin’s direction, in securing, acquiring, and preserving evidence data within the public cloud hosting environment.

3. Provide a mechanism for a third-party forensics team to access collected data for analysis.

Virtual Machine Middleware Services As an optional service, requested and approved by the Customer, the Service Provider is responsible for monitoring and supporting Middleware (e.g., Microsoft .NET Framework, Apache Kafka, IBM WebSphere, etc.). The Service Provider shall, at a minimum:

1. Perform monitoring of defined Middleware environments.

2. Provide administrative support for enrolled Middleware services.

3. Provide effective technical support (e.g., patching, event resolution, advice, Third-Party Vendor coordination).

4. As appropriate for state entities, integrate with Admin security monitoring and access control management standards (e.g., SIEM, Identity and Access Management (IAM)) as Admin requires.

5. Support Application developers in supporting Middleware runtime environments.

6. Assist the Customer in managing the lifecycle of provisioned Middleware environments, including specification, installation, implementation, monitoring, management, backup/restore, and disaster recovery of Customer Middleware environments.

7. Monitor and manage the Middleware systems components on a 24/7 basis to ensure environments meet performance standards.

8. Alert defined resources if process, application, system events, or thresholds have been exceeded. This notification will occur based on defined SMM procedures and the agreed escalation matrix.

9. Monitor capacity and proactively provide performance and capacity planning.

10. Monitor services for deprecation notices and proactively provide upgrade planning and implementation support to ensure services remain at supported software levels.

Virtual Machine System Administration This optional service is only available for Customers who do not have access to the Admin DTO state data center compute services or as approved by Admin.

The Service Provider shall, at a minimum:

1. Provide systems management and administration services for all in-scope Services.

2. Perform installation, patching, and upgrades of Customer software upon request.

3. Install productivity tools/utilities and perform all required operational modifications for the efficient and proper delivery of the Services.

4. Execute the Operating System’s maintenance, patching, and support, including shared libraries, print, .NET, FTP, mail services, etc.

5. Identify, test, coordinate patching, and provide other updates associated with the supported operating system(s), configuration items, software, and other elements that comprise the Service.

6. Implement additional security-related fixes associated with the operating system(s), configuration items, software, and other elements that comprise the Service.

7. Release upgrades for packaged infrastructure software initiated through scheduled releases, including, but not limited to, operating systems, patches, virus scanners, etc.

8. Work with Customers to identify required access for system administration activities within Customer environments.

9. Enable console access for Customers to have visibility into available and consumed Services for effective resource management. This aligns with the shared responsibility model between CSP, Service Provider, Admin, and Customer, consistent with the defined SMM.

a. This includes API and command line interface account access.

b. These accounts should be governed by the “least privilege” principle required to support requirements to perform work responsibility effectively.

10. Assist in analyzing and correcting endpoint and/or network Incidents and Problems associated with cloud Service processing.

11. Provide technical support for virtual machines, storage, and networking environments in the delivery of Services.

12. Ensure that all solution delivery elements are maintained at currency levels within vendor standard support levels.

13. Support Instance Schedulers in configuring custom start and stop times within public cloud services to assist Customers in reducing operational costs.

14. Provide public cloud tagging enablement for Service Provider-managed tags based on predetermined rules and Customer-managed tags.

15. Actively work with Admin to ensure that tagging includes relevant CI details as defined by the SMM.

16. Ensure all public cloud-hosted instances are tagged with necessary details to support billing, audit, reporting, security, and operations management to meet Admin and Customer requirements.

17. Ensure secure public cloud-hosted instance tagging governance policies are in place to prevent unauthorized modification of tags.

Cloud Native Middleware Services Service Provider monitors and supports CSP-offered cloud-native Middleware (e.g., Azure Integration Services, Azure Event Grid, AWS SQS). The Service Provider shall, at a minimum:

1. Provide administrative support for enrolled Middleware services.

2. Provide adequate technical support (e.g., patching, event resolution, advice, Third-Party Vendor coordination).

3. Integrate with Admin security monitoring and access control management standards (e.g., SIEM, Identity and Access Management (IAM)) as Admin requires.

4. Support Customer application developers in supporting Middleware runtime environments.

5. Assist the Customer in managing the lifecycle of provisioned Middleware environments, including specification, installation, implementation, monitoring, management, backup/restore, and disaster recovery of Customer Middleware environments.

6. Monitor and manage the Middleware systems components on a 24/7 basis to ensure environments meet performance standards.

7. Alert defined resources if process, application, system events, or thresholds have been exceeded. This notification will occur based on defined SMM procedures and the agreed escalation matrix.

8. Monitor capacity and proactively provide performance and capacity planning.

Distributed Denial of Service Protection Services If requested by the Customer, as an optional service, the Service Provider shall, at a minimum:

1. Provide intrusion prevention system (IPS) and intrusion detection system (IDS) services.

2. Manage intrusion detection, prevention, and distributed denial of service (DDOS), including prompt Customer notification of such events, reporting, monitoring, and assessing security events.

3. Work with Admin or Customer to support the denial of communications to and from known malicious IP addresses.

4. Ensure the public cloud network architecture separates internal systems from DMZ and extranet systems.

5. Require remote login access to use two-factor authentication.

6. Support Admin or Customer’s monitoring and managing devices remotely, logging into the internal network.

7. Support Admin or Customer in configuring firewall session tracking mechanisms for addresses that access the public cloud.

Database Management Services The Service Provider manages and operates Admin’s optional public cloud database management services, including all database management systems across all CSPs available to Customers. Database management is an optional service that customers may request. The Service Provider shall, at a minimum:

1. Design and deploy database components and services with appropriate high availability and resilience configurations to meet the requirements.

2. Complete management of the lifecycle of provisioned database environments,…

This is the start of the file's text. The full file is on GovTribe.

File details come from the government source that posted it. Updated .