MCS SOW State Agencies.docx
DOCX document 266 KB Posted
- Attached to
- STC Managed Cloud Services State and local contract opportunity
- Solicitation number
- 5400028075
- Issued by
- South Carolina
About this file
This document is a Statement of Work (SOW) for Managed Cloud Services for State Agencies in South Carolina, developed by the South Carolina Department of Administration (Admin). The SOW outlines comprehensive cloud services for state agencies, including base managed cloud services and optional managed cloud services across multiple cloud service providers. The services encompass a wide range of technical capabilities such as cloud center of excellence support, cloud service provisioning, network services, security services, technical support, database management, and transition services. The contract involves detailed service management processes, information security management, and a structured transition plan for implementing cloud services across state agencies.
The SOW is part of Solicitation No. 5400028075 and establishes a framework for cloud service delivery with specific requirements for service levels, financial management, and operational performance. The document indicates that services will be provided through an ITIL-based service management approach, with extensive documentation, reporting, and collaboration requirements. Pricing and financial management will be handled through the Admin-provided systems, with the Service Provider responsible for collecting and reporting cloud service consumption data, supporting chargeback processing, and optimizing cloud financial performance. The contract emphasizes a collaborative approach between the Service Provider, Admin, and state agency customers, with a strong focus on security, continuous improvement, and transparent service delivery.
View the file
Other files for this state and local contract opportunity
Show all 33
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
Exhibit 2.1.1 (Managed Cloud Services Statement of Work) Solicitation No. 5400028075
Managed Cloud Services
Exhibit 2.1.1 Statement of Work – State Agencies
Solicitation No. 5400028075
Table of Contents
| 1 | Introduction | 3 |
| 1.1 | Overview | 3 |
| 1.2 | Operating Model | 4 |
| 1.3 | Cloud Services | 5 |
| 2 | Base Managed Cloud Services | 6 |
| 2.1 | Cloud Center of Excellence (CCOE) Support | 6 |
| 2.1.1 | Technology Standards | 7 |
| 2.2 | Cloud Service Provisioning and Management | 7 |
| 2.2.1 | Provisioning Automation | 9 |
| 2.3 | Network Services | 10 |
| 2.3.1 | Customer CSP Connection Coordination | 10 |
| 2.3.2 | Network within the CSPs | 10 |
| 2.4 | Base Managed Cloud Security Services | 11 |
| 3 | Optional Managed Cloud Services | 11 |
| 3.1 | Request for Solution (RFS) | 11 |
| 3.2 | Customer Virtual CSP Connection | 12 |
| 3.3 | Customer Direct CSP Connection | 13 |
| 3.4 | Managed Technical Support | 13 |
| 3.4.1 | Operations Monitoring | 17 |
| 3.4.2 | Performance and Capacity Management | 18 |
| 3.4.3 | Backup and Recovery Services | 19 |
| 3.4.4 | Disaster Recovery Services | 20 |
| 3.4.5 | Real-Time Forensics Support Services | 21 |
| 3.5 | Virtual Machine Middleware Services | 21 |
| 3.6 | Virtual Machine System Administration | 22 |
| 3.7 | Cloud Native Middleware Services | 23 |
| 3.8 | Distributed Denial of Service Protection Services | 23 |
| 3.9 | Database Management Services | 24 |
| 3.9.1 | DBMS Administration and Operations | 24 |
| 3.10 | Technology Roadmap | 25 |
| 4 | Service Management | 25 |
| 4.1 | Service Management Systems | 26 |
| 4.2 | Process Documentation and Execution | 28 |
| 4.3 | Training and Education | 29 |
| 4.4 | Portal | 30 |
| 4.5 | Service Catalog Management | 30 |
| 4.6 | IT Service Desk | 31 |
| 4.7 | Incident Management | 32 |
| 4.8 | Problem Management | 33 |
| 4.9 | Request Management and Fulfillment | 34 |
| 4.9.1 | Request Management processes and systems | 34 |
| 4.9.2 | Service Request Operations | 35 |
| 4.10 | Change Management | 37 |
| 4.11 | Service Asset and Configuration Management | 37 |
| 4.12 | IT Service Continuity Management | 38 |
| 4.13 | Project Management | 39 |
| 4.14 | Operational Intelligence | 39 |
| 4.15 | Customer Satisfaction | 40 |
| 4.16 | Service Level Management | 41 |
| 4.17 | IT Financial Management | 42 |
| 4.18 | Cloud Financial Performance Optimization | 43 |
| 5 | Information Security Management for Service Provider Services | 46 |
| 5.1 | Information Security Management General Requirements | 46 |
| 5.2 | Service Provider Staff | 47 |
| 5.3 | Integration with Admin SIEM | 47 |
| 5.4 | Security Event Identification and Alerting Services | 47 |
| 5.5 | Security Incident Management | 48 |
| 5.6 | Physical Security Administration | 48 |
| 5.7 | Customer Facilities | 49 |
| 5.8 | Security Assessments | 49 |
| 6 | Transition Services | 51 |
| 6.1 | Service Commencement | 51 |
| 6.2 | Transition Overview | 51 |
| 6.3 | Knowledge Transfer | 52 |
| 6.4 | Transition Management Requirements | 53 |
| 6.5 | Transition Project Plan | 54 |
| 6.5.1 | Transition Project Plan Critical Deliverable | 55 |
| 6.5.2 | Kickoff | 56 |
| 6.5.3 | Meeting Attendance and Reporting Requirements | 57 |
| 6.5.4 | Transition Documentation and Collaboration | 58 |
| 6.5.5 | Organizational Change Management (OCM) | 59 |
| 6.5.6 | Operational Readiness | 60 |
| 6.5.7 | Staffing Plan and Requirements | 61 |
| 6.5.8 | Determination of Responsibility (Service Provider and Other State Vendors) | 61 |
| 6.6 | Remedies for Transition Failure | 62 |
Figures Figure 1 – MCS State Agency Operating Model 5
Tables
| Table 1 – State Agency Cloud Services | 5 |
| Table 2 - Service Management Capabilities | 26 |
Introduction Overview This Exhibit 2.1.1 (Managed Cloud Services SOW - State Agencies) sets forth the Services that Service Provider shall provide as of the Commencement Date unless otherwise specified to support State Agencies that elect Managed Cloud Services (MCS). Further, this Exhibit 2.1.1 (Managed Cloud Services SOW - State Agencies) sets forth the processes and systems that the Service Provider will provide, including the Service Provider's obligations to work with other South Carolina Department of Administration (Admin) Service Providers, and Customer cloud security teams and providers, to deliver integrated end-to-end Services. The Service Provider shall coordinate with Admin, Admin Service Component Providers (SCPs), Customer cloud security teams and providers, and Admin Contractors to effectively provide the Services.
The Service Provider shall provide a solution that supports all the requirements described in this Exhibit 2.1.1 (Managed Cloud Services SOW - State Agencies) and its Exhibits in accordance with Exhibit 4.2 (Financial Responsibility Matrix). All Services are included within the Charges described in Exhibit 4.0 (Business Model). Accordingly, the Service Provider also confirms that Admin will not incur any other Charges for the requirements described in this Exhibit 2.1.1 (Managed Cloud Services SOW - State Agencies).
The Service Provider shall deliver the Services in the best interests of the State. The Service Provider shall be responsive to Admin’s current and future requirements by proactively anticipating needs and adjusting Services accordingly within the Charges. Requirements for New Services will be handled in accordance with Exhibit 1.4 (General Provisions), and the Service Provider shall assess the impact of these requirements on Admin’s and Admin Customers’ operating environments and supported applications in accordance with the terms of the Agreement.
The Service Provider shall be responsible for all activities necessary to ensure Admin’s Services are performed in accordance with all standards and processes contained in the Agreement, the Service Levels in Exhibit 3.1 (Service Level & Deliverables Matrix), and the Service Management Manual (SMM).
Service Provider shall integrate and fully cooperate with Admin and all other SCPs as required for smooth and efficient operation during the development, implementation, and execution of its Service Management Processes to ensure consistency and integration across all Service Providers. Service Provider will work with Admin and other SCPs to deliver integrated Services and share Service Level responsibilities as defined in Exhibit 3.1 (Service Level & Deliverables Matrix).
Operating Model Exhibit 2.1.1 (Managed Cloud Services SOW - State Agencies) contains specific cross-functional requirements that all SCPs must meet to perform the requested Services and responsibilities defined in Exhibit 2.0 (Service Model).
Figure 1 - MCS State Agency Operating Model below depicts the relationships between Customers, SCPs, Admin, and State Fiscal Accountability Authority (SFAA.)
Figure 1 – MCS State Agency Operating Model As the overall service owner for State Agency-consumed shared services, including Managed Cloud Services (MCS), Admin provides functional governance of services and operations functions that provide customer relationship leadership, service catalog and Level 1 service desk, IT service management, and Division of Information Security (DIS). The Admin Sourcing Management function works closely with the Admin-managed SCPs to ensure the provided services individually adhere to the Service Provider's requirements and collectively meet Admin's desired outcomes. The Admin DIS Information Security SCP supports State Agency cloud Customers and the Service Provider for cloud security and incident response.
Cloud Services The State Agency Cloud Service offerings include Base Managed Cloud Services, available to all State Agencies that elect Cloud Services, and Optional Managed Cloud Services, as elected by the Customer. Table 1 State Agency Cloud Services summarizes the high-level services the Service Provider is to design, deploy, and deliver either as base services or optionally.
Table 1 – State Agency Cloud Services
| Service Provider Services |
| Base Managed Cloud Services |
| Optional Managed Cloud Services |
| Architectures, standards, and education |
| Yes, provided by Admin |
| Cloud Center of Excellence |
| Yes |
| Provisioning |
| Yes, account-level only |
| Cloud Security & Security Incident Response |
| Yes, provide support to DIS as requested in support of a security incident only |
| Ordering CSP Services from Admin Service Catalog |
| Yes |
| Service Provider Service Levels |
| Yes, limited to Service Levels that apply to the subscribed services |
| Yes, limited to Service Levels that apply to the subscribed services |
| Customer to CSP Network Connections |
| Yes, coordination |
| Optional Connections Available |
| Networking within CSPs |
| Yes |
| Cloud Service Consumption Reporting |
| Yes |
RFS - Cloud Solution Design & Project Mgt.
Optional
Managed Technical Support (bundle)
Optional Bundle
Operations Monitoring & Reporting
Optional Bundle
Performance and Capacity Management
Optional Bundle
Backup and Recovery Services
Optional Bundle
Disaster Recovery Services
Optional Bundle
Real-Time Forensics Support Services
Optional Bundle
Virtual Machine Middleware Services
Optional
Virtual Machine Administration
Optional
Cloud Native Middleware Services
Optional
Distributed Denial of Service Protection Services
Optional
Database Management Services
Optional
Technology Roadmap
Optional
In the above Table 1 - State Agency Cloud Services, the following meaning is intended:
1. Scope flag:
a. Yes - In-scope Services provided by Service Provider.
b. Yes, qualification - In-scope Services the Service Provider delivers only applies to specific criteria.
c. Optional – Services provided by the Service Provider that are optional as elected by a Customer.
Base Managed Cloud Services Cloud Center of Excellence (CCOE) Support The Admin-led public Cloud Center of Excellence (CCOE) program charter aims to align the Service Providers to ensure success with public cloud adoption. Through the CCOE program, Admin provides public cloud strategy and governance through policies, standards, and best practices to State Agencies.
The Service Provider shall support Admin in the creation of best practices, including, at a minimum:
1. Collaborate with Admin and other SCPs and utilize industry and other best practices to support Admin’s public Cloud Center of Excellence.
1. Develop consistent approaches to ensure solutions are consistently implemented across Cloud Service Providers (CSPs).
1. Document solutions to identify products used across CSPs to ensure similar functions and workflows for the State and Customers, regardless of hosting location.
1. Develop and maintain a solution accelerator library with frameworks, templates, tools, and methodologies to streamline and accelerate solution documentation and implementation.
1. Develop and maintain documented solutions for frequently used activities (e.g., user provisioning, resource deployment).
1. Promote consistency through automation of service operations by examining the frequency of requests, commonalities between products and services, and streamlining processes.
1. Support Admin with optimization of the cloud service catalog through leveraging public cloud best practices, particularly around automation and orchestration.
1. Support Admin in continually maintaining the currency of public cloud-approved services as Services are made available by the CSP and with the State's agreement.
Technology Standards The Service Provider shall research and recommend standard products to the Admin CCOE for adoption into the program, including, at a minimum:
1. Provide and make available the description of Services and offerings by Service Provider that are in use on a quarterly basis.
1. Provide and make available the description of standard products to Authorized Users as requested by the State.
1. Provide standards for supporting open-source software.
1. Describe approved Services and offerings.
1. Provide feedback on the approved Services and offerings list with respect to the State’s strategic direction and technical architecture.
Cloud Service Provisioning and Management One of the goals of public cloud is to allow Customers to provision and consume services in the public cloud as natively as possible with technical, delivery, and security assurances. In accordance with the Services provided for Base Managed Cloud Services, the Service Provider shall, at a minimum:
1. Manage and administer initial access to the cloud services, systems, networks, operating software, system files, and Admin and Customer’s data, including:
a. Enable role-based access to public cloud services and functions for Customer and enterprise user roles.
b. Assign initial and, as requested, reset existing privileged account passwords per established procedures.
c. Provide Customer access to create user IDs, suspend and delete inactive logon IDs, research system security problems, and maintain network access authority.
2. Provide cloud service provisioning with State-approved CSPs in accordance with the Services provided for Base Managed Cloud Services to support service provisioning and billing for each approved CSP, including, but not limited to:
a. Accounts, subscriptions/organizations, organizational units, resources/services, etc.
i. State Agencies’ services will be deployed in the Admin tenant and may have certain restrictions.
ii. As approved by Admin, exceptions may be granted to allow a State Agency to be deployed into a Customer tenant.
iii. Service Provider will support potential variations in onboarding differences between provisioning in the Admin and Customer tenants and processes.
b. Communicate the approved information electronically with the requesting Customer, enabling the Customer to access and use the provisioned service.
c. Support the Customer with questions regarding how to gain access to the provisioned service.
d. Provide Customers with the ability to provision and support services aligned with public cloud capabilities by leveraging native interfaces.
3. Develop and maintain, within the SMM, Customer-facing and internal operational documentation on the steps to request, provision, and support the provisioning of cloud services for Customers.
4. Implement access controls to services and operational functions based on defined Customer and Service Provider support responsibilities.
5. Integrate Service Provider Services with CSP native console and/or service catalogs, including:
a. Provisioning access to allow fulfillment of Customer provision requests based on templates aligned with State standards and policies, and/or application tools available from CSPs.
b. Enable deployment of the templatized cloud infrastructure with role-based security and automated fulfillment, leveraging public cloud best practices delivered with the Admin service catalog integration.
i. Role-based security shall be delivered based upon Customer requirements and Cloud Services, within defined State policies, and governed by the principle of “least privilege” as defined by The State, required to balance Customer requirements with program goals effectively.
6. Provide the ability to integrate provisioning and management through automated orchestration and integration of CSP service catalogs (e.g., custom catalogs).
7. Provisioning infrastructure components based on Admin-defined reference architecture standards, including compute, network, storage, and security resources.
8. Extend cloud service capabilities by integrating with cloud native, cloud-agnostic, and third-party tools.
9. Ensure that security and certificates meet State program requirements.
10. Assist Admin in implementing IT Financial Management (ITFM) billing and chargeback of cloud services consumed, including integrated tagging of services, products, and components for tracking chargeback.
11. Develop cloud service tagging automation and orchestration to inform service management, billing processes, and capabilities.
12. Perform necessary service integration within State program service catalog to ensure necessary brokering and orchestration can occur in an automated fashion to provision service requests successfully.
13. Support Admin in service integration in service catalog orchestration to ensure automated provisioning of requests.
Provisioning Automation The Service Provider shall enable continuous integration and automated testing of cloud service provisioning deployments using Infrastructure as Code (IaC), including but not limited to:
1. Provide, deploy, and manage IaC using State-approved tools to support cloud services' deployment, provisioning, scaling, networking, and security.
2. Automate service deployment, operational monitoring, and security monitoring using IaC concepts or policies to ensure resources remain compliant with requirements.
3. Comply with established reference architecture standards and standard products for IaC deployments.
a. Where these standards may not exist or contain a complete view of best practices, the Service Provider shall recommend updates to the documentation owner.
4. Document all IaC processes, procedures, and Source Code documentation, aligning with the SMM.
5. Implement a data protection solution to ensure the backup and recoverability of IaC configurations in an Admin-approved Source Code library.
6. Develop rollback procedures as applicable for restoration to previous configurations.
7. Perform quality assurance testing for IaC deployments.
8. Utilize best practices relating to IaC, including but not limited to:
a. Develop and deploy IaC using templates, images, and stacks that define the resources and interconnections.
b. Maintain detailed documentation to ensure resources and properties, metadata, parameters, mappings, conditions, and outputs are defined.
c. Provide transferable solutions and approaches to IaC that minimize vendor lock-in and protect the State program against an over-reliance on a single vendor solution.
Network Services The Service Provider shall provide networking services management for all in-scope service elements, including but not limited to:
Customer CSP Connection Coordination For all Customers, solution, coordinate, and project manage network connections that enable Customers to connect to CSP services.
Service Provider shall, at a minimum:
1. Coordinate public cloud connectivity in support of Admin operations and the Admin network team.
2. Assist the responsible Admin SCP in the design and management of direct public cloud network connections for the delivery of Services.
Network within the CSPs For all Customers, solution, deploy, and manage networking within CSPs to enable Customers to connect to CSP services securely.
Service Provider shall, at a minimum:
1. Architect virtual network reference architecture standards to define best practices, design principles, and security guidelines for setting up networking within CSPs that support Customer segregation, billing, audit, reporting, security, and operations management.
2. Create and manage Customer cloud environments using virtual network reference architecture standards as recommended by the State, aligning with and supporting customer segregation, billing, audit, reporting, security, and operations management.
3. Provide installation, testing, operating, troubleshooting, and maintenance of cloud virtual network solutions (e.g., Virtual Private Clouds (VPCs), virtual cloud network), compute resources, operating system(s), configuration items, software, services, and other elements that comprise the Service.
4. Implement zone-based network security (e.g., VPCs, Virtual Networks, Subnets) with stateful firewall filtering between isolated networks, utilizing stateful packet inspection to manage packet flows. This ensures that only packets from known active connections can pass.
5. Provide cloud virtual network reporting (e.g., subnet in use, port mapping, internet usage).
6. Provide a solution to control network access to cloud services and associated functions based on State-approved policies and customer requirements. (i.e., ability to restrict/grant appropriate services access based on Admin-approved services, support models, and reference architectures using features like cloud-native firewall and network security groups).
a. The solution shall be auditable and reportable, enabling identification of levels of Service Provider support services.
7. Provide and support standardized virtual network (or comparable) build automation and the ability to support utilization of existing VPCs when required for new compute build requests.
8. Provide and support the ability to deploy custom virtual network solutions (e.g., support VNet/Subnet counts and sizes).
9. Request available IP address ranges from Admin and allocate and manage IP addresses in accordance with Admin IPAM strategies, processes, and standards to support public cloud services.
10. As requested by Admin, where needed to resolve Customer overlapping IP address issues, develop and deploy a Network Address Translation (NAT) solution as needed within CSPs.
Base Managed Cloud Security Services State Agency Customers are required to adhere to the Admin SCDIS-210 publication security framework and guidelines. In support of Customers, the Service Provider shall, at a minimum:
1. Provide configurations and support in adherence to the SCDIS-210 Information Security Technology Coverage Measurement Standards published by Admin.
2. As requested by Admin, evaluate the security controls and data protection standards implemented in public cloud services and report on performance and compliance requirements adherence to SCDIS-200 Information Security and Privacy Standards as published by Admin, and CIS Benchmarks as approved by Admin.
Optional Managed Cloud Services As requested by Customers and approved by Admin, the Service Provider will offer optional services.
Request for Solution (RFS) Requests for Solution (RFS) are Customer requests where requirements are captured, and the Service Provider develops solutions and cost estimates for Customer review and approval. These solutions typically assume the Service Provider builds and implements the solution. For Customer Requests that require the Service Provider to propose a solution, the Service Provider shall, at a minimum:
1. Support the State in developing and maintaining RFS processes in the SMM, including supporting systems and appropriate mechanisms for fulfilling complex requests that require design, pricing, solutions, and proposals. This includes clear and effective communication to set expectations and promote excellent customer service.
2. Support the State in developing and maintaining RFS ROM processes in the SMM, including appropriate mechanisms to support rapid proposal development that provides accuracy for budgetary information without requiring a complete solution (e.g., rough order magnitude (ROM) pricing and high-level architecture).
3. For all RFSs requested by the Customer:
a. Review RFS to validate for completeness.
b. Coordinate and lead meetings to review requests, gather requirements, solution, and develop the proposal.
c. Coordinate the attendance of all necessary subject matter experts in solution and requirement gathering sessions.
d. Once requirements are complete, provide a timeframe for delivering the solution proposal, including cost estimates.
e. Develop the solution, including the technical solution, effort, acceptance criteria, solution design document, and pricing.
f. Develop the solution to conform to the State-approved architecture, standards, and pricing.
g. Develop the solution in conformance with the State Security Policies, procedures, and guidelines of the Customer and the State.
h. Develop the solution in conformance with State-approved security baselines.
i. Develop the solution in conformance with the boundaries of the State technical guidelines.
j. Coordinate and facilitate solution reviews across the Service Provider as required to review and gain approval for the solution and pricing.
k. Track all Project Change requests in accordance with established procedures in the SMM.
l. Provide a single proposal to the requesting Customer as required.
m. Iterate and adjust the solution and cost estimating template to adhere to the requesting Customer’s feedback and requirements.
n. Document Customer approvals in accordance with established processes as per the SMM.
o. Gather and validate that the proposal acceptance comes from an appropriately authorized user.
p. Provide status to Customers for all outstanding requests.
q. Initiate Project Management as appropriate upon acceptance of the proposal by the Customer to implement approved proposals.
Customer Virtual CSP Connection As an optional service, as requested by Customers who do not have Admin-provided connectivity to CSPs, solution and provide a service that offers Customer virtual connectivity from the Customers network to the CSP services.
Service Provider shall, at a minimum:
1. Design, implement, monitor, and manage cloud access using VPN to enable connections to CSPs.
Customer Direct CSP Connection As an optional service, as requested by Customers that do not have Admin-provided connectivity to CSPs, solution and provide a service that offers Customer direct network connectivity from the Customers network to the CSP services.
Service Provider shall, at a minimum:
1. Design, implement, monitor, and manage cloud access using a Virtual Cross Connect (VXC) direct connect solution to enable Customers to connect securely to CSPs.
2. Provide an optional service to establish and maintain a VPN connection, based on approved Admin use cases, within the VXC direct connect solution.
Managed Technical Support Managed steady-state services include responsibilities and activities to support public cloud products and corresponding workloads, services, processes, systems management roles, virtual networks, microservices, container technologies, serverless architectures, and other public cloud services. Responsibilities for the Admin environment include integration with other Admin Service Providers to ensure the availability of Services. The Service Provider shall, at a minimum:
1. Through ongoing support and maintenance control processes, support the current implementation and solutions developed by the Service Provider during the Agreement term.
2. Manage the implementation of public cloud products, services, and related technologies to support required business applications.
3. Install tools and processes to enable delivery of all in-scope cloud services, operations, monitoring, systems management, event response, and service restoration for the in-scope environment.
4. Perform 24x7 operations monitoring, systems management, event response, and service restoration for the in-scope cloud services.
5. Interface with Admin Incident and Problem Management processes and teams supporting Resolution and service restoration.
6. Resolve all events, warnings, and alarm messages and notify Customers as appropriate.
7. Support cloud-native, cloud-agnostic, and third-party tools and products to support defined Services.
8. Define and provide technical support for cloud services, in accordance with the SMM for operations, including:
a. OS administration.
b. Patch management.
c. Virtualization of resources.
d. Storage management.
e. Backup and recovery.
f. Disaster Recovery.
g. Virtual server support.
h. Install/Move/Add/Change (IMAC).
i. Capacity planning and reporting.
j. Performance tuning.
k. Problem resolution and Root Cause Analysis.
9. Verify that deployed cloud services are compliant with Admin baseline standards.
10. Provide cloud service performance optimization, capacity management, and auditing of configurations to ensure alignment with Admin-defined standards. The Service Provider shall notify Admin where deviations exist.
11. Perform all measurements and reporting for public cloud-hosted platforms as required to support Services as defined in Exhibit 3.0 (Performance Model).
12. Comply with established reference architecture standards and standard products, including deployed software and Services within the managed service.
13. Ensure an auto-scaling design for the following:
a. Tools integration.
b. Host uniqueness.
c. Backup reporting.
d. Billing.
e. Tagging.
f. Compliance implications.
g. Naming standards.
h. Auditability of these Instances.
14. Provide technical advice and support to Projects, applications, application development, and service operations teams as required.
15. Enable and manage native public cloud services for dynamic scaling to meet overall capacity needs, including auto-scaling groups where necessary.
16. Design and implement user and system security measures in alignment with defined security policies.
17. Comply with the requirements of the State program and Customers for Configuration Management items in the Service.
18. Follow Admin-defined Incident Management processes, leveraging the Admin-provided environment.
19. Design, implement, and manage capabilities to enable cross-cloud migration techniques to ease system migration and re-platforming.
20. Implement and manage an automated software deployment and patching set of procedures and tooling, leveraging cloud best practices.
21. Identify and implement required service or configuration changes to address solution defects.
22. Maintain service documentation (technical specifications and testing documentation) as well as common problems, root causes, and remedies to aid in identifying and remedying underlying system incidents.
23. Participate in applicable acceptance testing or review of any changes arising from break/fix or patch/release performed by Service Provider.
24. Verify and ensure compliance with any Admin security-mandated patches, configuration settings, or system levels required, given the nature of the security mandate, and report to Admin, in writing, any risks or issues that the Service Provider becomes aware of in providing the Service to Admin.
25. Assist Admin and Customers by referring incidents to the appropriate third-party entity for resolution and coordinating with the third-party service to help minimize the Customer's role in problem management.
26. Notify Admin and Customer of Service Provider’s planned and reactive maintenance activities, including service-impacting and non-service-impacting operations, as appropriate.
27. Assess the utilization of all MCS assets (e.g., public cloud products, platforms, storage, network interface points) within the defined lifecycle services within the State program, emerging products, and capabilities to deliver Services more effectively. Drive the overall consistency and reliability of the Service through:
a. Simplification of service offerings and support tiers to move the Service to a support model that is highly repeatable and reliable.
b. Implement repeatable templates, automation, and programmatic orchestration to drive initial quality in service implementations (i.e., “right first time”) and reduce Incident, Problem, and Change Management service requests wherever possible.
c. Review all Customer-facing (and Admin-supporting) help channels and service reports to eliminate extraneous and conflicting elements. This includes removing manual steps by automating Incident, Problem, and Change Management communications and processes.
d. Automate data collection to drive better and more timely data collection to facilitate Service decision-making, cross-functional coordination, and long-term planning.
28. Actively support the demand management process by developing technical solutions, including intra-tower solution development, as initiated through Request for Solution procedures.
29. Perform analysis of and vetting of services and products across CSPs and, in conjunction with Admin, develop Services that align with State program business assurance standards.
30. Develop and maintain support for cross-platform cloud support solutions (e.g., Pivotal, OpenShift, etc.)
31. Upon request, perform multi-homing of installed tooling alerts to include Customers' systems where feasible.
32. Assess CSP services in the public cloud environment to ensure alignment with financial and service optimization activities.
33. Validate that all Admin-approved tools are installed and configured on all deployed systems within the program, including instances deployed via self-service.
a. If systems are identified without Admin-required tooling, Service Provider shall perform necessary remediation.
34. Leverage the approved Admin mechanism to enable the tracking, management, and implementation of security certificates used to secure confidential sessions (e.g., SSL) for Internet and Intranet transactions and communications, including:
a. Establish processes and procedures for renewals, as required by Admin or Customers.
b. Schedule, apply, and support security certificates as Admin or Customer requires.
c. Coordinate and advise Customers regarding certificates that are embedded in Applications.
d. Notify and advise Customers of certificate renewals.
35. Service Provider shall provide system administration assistance with Customer Software installations, upgrades, and patches. Service Provider shall, upon request, assist in the installation, patching, and upgrades of Customer Software. In these instances where Customer requests support, Customer shall provide work instructions for requested activities per the SMM.
36. Maintain MCS-approved service listing as instructed in the SMM, including developing automations for improved service and data quality management.
37. Monitor services for deprecation notices and proactively provide upgrade planning and implementation support to ensure services remain at supported levels and API versions.
38. The Service Provider shall provide storage management for all in-scope service elements, including but not limited to:
a. Configure, monitor, and manage a robust and highly available cloud native storage solution to satisfy the overall needs of Admin and Customers.
b. Perform storage, backup, and restore service testing, and maintain the backup system and service documentation.
c. Implement cloud native platform level encryption on all Admin storage in accordance with Admin standards and security baselines. Due to data classification and compliance requirements, implement and support customer-managed keys for encryption where necessary.
Operations Monitoring The Service Provider shall provide operations monitoring services and support for Customer-elected environments and Services such as virtual networks, microservices, serverless architectures, and native middleware services, with responsibilities including, but not limited to:
1. Install, configure, and provide ongoing CSP services monitoring and reporting tools and services. Where appropriate, Service Provider shall utilize Admin-provided tools and monitoring systems.
2. Perform operational monitoring, including real-time mechanisms for monitoring systems, including but not limited to availability, auto-scaling, performance, capacity, and overall environment health as defined in the SMM and required to support Service Levels as defined in Exhibit 3.0 (Performance Model).
3. Integrate operational monitoring with the Admin ITSM platforms to allow electronic event and Incident Management integration and provide real-time systematic notification of performance issues and events.
4. Conduct 7x24x365 operational monitoring using CSP native health monitoring tools (e.g., Azure Monitor, Azure Resource Health, Azure Application Insights, Amazon Cloud Watch, AWS Service Health Dashboard) and third-party monitoring tools (e.g., Datadog, Splunk) as directed by Admin.
a. Perform service restoration activities of public cloud platforms, including real-time monitoring and reporting of capacity, stability, and performance of Services and platforms.
b. Establish and monitor proactive alarms in accordance with thresholds defined in the SMM.
c. Provide end-to-end visibility to Admin and Admin-approved Users or Customers to view performance statistics (real-time and historical) on public cloud platforms.
5. Provide full monitoring integration with Admin and SCP operational support processes (e.g., SIEM, Incident Management, Change Management, asset, and inventory management, etc.).
6. Provide status and trending reports as required, including:
a. Reports listed in Exhibit 3.3 (Reports).
b. Other Reports as required in this Exhibit 2.1.1 (Managed Cloud Services SOW - State Agencies), Exhibit 4 (Business Model), and related attachments.
Performance and Capacity Management To ensure that Services achieve the desired business and service-based outcomes, the Service Provider shall, at a minimum:
1. Develop performance and capacity management processes.
2. Actively participate in the exchange of data and information amongst other Admin Service Providers, Admin, and Customers to ensure successful delivery of Services, including the ability to validate capacity planning.
3. Integrate performance and capacity management tooling and process outputs with Admin capacity management and other Service Management processes and systems.
4. Conduct performance and capacity planning and management activities for all supported products, platforms, and applications.
5. Participate in scheduled capacity planning meetings.
6. Create, update, and report a Capacity Plan that includes:
a. Developing an agreed-upon formula for measuring capacity.
b. Services, components, and resources measured.
c. Current, trending, and forecasted capacity based on technical planning and demand management.
d. Detailed performance and consumption characteristics.
e. Identify workload landscape (Prod, Test, etc.).
f. Risk areas (including over- and under-capacity or approaching quota limits).
g. Actual consumption compared to plan.
7. As required, provide performance and capacity technical advice and support to projects, applications, application development, and database teams.
Backup and Recovery Services Service Provider shall be responsible for backup and recovery of enrolled Customer Services. In establishing, monitoring, and managing backup/restore operations, the Service Provider shall, at a minimum:
1. Design, install, monitor, and manage backup policies and services to satisfy the overall needs of Admin and its Customers within the public cloud, including support for virtual machines, storage, snapshots, virtual grids, virtual tape libraries (VTL), volumes, databases, tables, files, and filesystems.
2. Design and manage storage, file, and volume gateway solutions.
3. Develop backup and recovery-related management processes and automation.
4. Assess, develop, and formally recommend opportunities to reduce (or avoid) costs associated with a backup environment.
5. Perform environment/supported backup tuning, job, and environment restructuring, and provide tools and other efforts to help improve the efficiency and reliability of storage and backup operations and to help reduce ongoing maintenance requirements.
6. Maintain backup environments in accordance with Admin strategies and standards relating to technical, data, and applications architectures as agreed upon in this Exhibit, and as required by Customer projects, environments, the SMM, or other supporting documents.
7. Establish, publish, and maintain a production backup calendar, including daily and periodic backup and service maintenance activities.
8. Generate and provide access to monthly summary reports that track the progress of the CSP and Service Provider’s backup and service maintenance work performance.
9. Perform ad hoc backup/restore operations reporting as agreed by the parties.
10. Meet with Customers at least once a year to review existing backup schedules for suitability and identify any required updates to existing backup schedules and retention policies.
11. Monitor and remediate backup failures on the Service Provider's standard backup service.
12. Perform backup restoration testing.
13. Install, configure, and manage file-level backup agents and services where appropriate.
14. Backup all databases deployed within the State program using database-aware technologies.
15. Encrypt all backups, regardless of media and location, to ensure compliance with the SC DIS 200 security framework or subsequent versions.
16. Implement and monitor backup and restore services operations for all regions and availability zones.
17. Update the backup platforms and services as new tools and technology are available to improve Admin’s or Customer’s business processes and performance.
18. Verify backup outcomes correctly achieve service delivery requirements for Service Provider responsible data (i.e., operating system recoverability).
19. Provide an auditable solution for Customer to view the schedule, retention, and target information as configured in the backup systems, with the ability for Customer to correlate to Customer’s requested requirements.
20. Provide reporting on backups and backup infrastructure (e.g., success/failure, schedules, retention, targets, archive, capacity, performance, storage media types, and storage location).
21. Perform backup administration and monitoring, including:
a. Verify backup jobs start as scheduled.
b. Monitor scheduled production backup jobs.
c. Perform job restart, as necessary, in accordance with resolution and restart procedures.
d. Resolve backup scheduling conflicts.
e. Ensure that failed backup jobs are restarted once the failure condition is identified and resolved.
22. Monitor scheduler-related incidents and develop and recommend changes to the scheduler database.
23. Schedule backup jobs, as requested by the Customer, that require expedited or ad hoc execution.
Disaster Recovery Services Customers will be solely responsible for overall business continuity and application recovery plans. The Service Provider retains responsibility for business continuity plans for Service Provider Services and, if requested by the Customer, supports Customers with the recovery of cloud services. Service Provider Disaster Recovery (DR) does not apply to non-native cloud middleware and application software configurations, application presentation, or customizations, and is limited to in-scope cloud services unless otherwise agreed to with Admin or Customers.
The Service Provider shall, at a minimum:
1. Design and deploy solutions, via the RFS process, that align with the defined DR class requirements as required by Customers, and complement Customer activities in support of Customer and business continuity plan(s), including:
a. Leverage region failover and availability zones.
b. Document procedures to restore primary operations.
2. Monitor and manage recoverable cloud services within the public cloud to satisfy the Customers' needs.
3. Upon Customer request, participate in Admin or Customer DR planning sessions, DR testing sessions, or actual DR recovery efforts for in-scope service elements.
Real-Time Forensics Support Services Upon Customer or Admin’s request, Service Provider shall secure, acquire, and preserve evidence data within the public cloud, and allow third-party forensic teams to perform analysis without potentially losing critical data. If requested, the Service Provider shall, at a minimum:
1. Implement and manage a forensics capability and support within any defined public cloud hosting environment.
2. Support Admin, SCP, or a third-party at Customer or Admin’s direction, in securing, acquiring, and preserving evidence data within the public cloud hosting environment.
3. Provide a mechanism for a third-party forensics team to access collected data for analysis.
Virtual Machine Middleware Services As an optional service, requested and approved by the Customer, the Service Provider is responsible for monitoring and supporting Middleware (e.g., Microsoft .NET Framework, Apache Kafka, IBM WebSphere, etc.). The Service Provider shall, at a minimum:
1. Perform monitoring of defined Middleware environments.
2. Provide administrative support for enrolled Middleware services.
3. Provide effective technical support (e.g., patching, event resolution, advice, Third-Party Vendor coordination).
4. As appropriate for state entities, integrate with Admin security monitoring and access control management standards (e.g., SIEM, Identity and Access Management (IAM)) as Admin requires.
5. Support Application developers in supporting Middleware runtime environments.
6. Assist the Customer in managing the lifecycle of provisioned Middleware environments, including specification, installation, implementation, monitoring, management, backup/restore, and disaster recovery of Customer Middleware environments.
7. Monitor and manage the Middleware systems components on a 24/7 basis to ensure environments meet performance standards.
8. Alert defined resources if process, application, system events, or thresholds have been exceeded. This notification will occur based on defined SMM procedures and the agreed escalation matrix.
9. Monitor capacity and proactively provide performance and capacity planning.
10. Monitor services for deprecation notices and proactively provide upgrade planning and implementation support to ensure services remain at supported software levels.
Virtual Machine System Administration This optional service is only available for Customers who do not have access to the Admin DTO state data center compute services or as approved by Admin.
The Service Provider shall, at a minimum:
1. Provide systems management and administration services for all in-scope Services.
2. Perform installation, patching, and upgrades of Customer software upon request.
3. Install productivity tools/utilities and perform all required operational modifications for the efficient and proper delivery of the Services.
4. Execute the Operating System’s maintenance, patching, and support, including shared libraries, print, .NET, FTP, mail services, etc.
5. Identify, test, coordinate patching, and provide other updates associated with the supported operating system(s), configuration items, software, and other elements that comprise the Service.
6. Implement additional security-related fixes associated with the operating system(s), configuration items, software, and other elements that comprise the Service.
7. Release upgrades for packaged infrastructure software initiated through scheduled releases, including, but not limited to, operating systems, patches, virus scanners, etc.
8. Work with Customers to identify required access for system administration activities within Customer environments.
9. Enable console access for Customers to have visibility into available and consumed Services for effective resource management. This aligns with the shared responsibility model between CSP, Service Provider, Admin, and Customer, consistent with the defined SMM.
a. This includes API and command line interface account access.
b. These accounts should be governed by the “least privilege” principle required to support requirements to perform work responsibility effectively.
10. Assist in analyzing and correcting endpoint and/or network Incidents and Problems associated with cloud Service processing.
11. Provide technical support for virtual machines, storage, and networking environments in the delivery of Services.
12. Ensure that all solution delivery elements are maintained at currency levels within vendor standard support levels.
13. Support Instance Schedulers in configuring custom start and stop times within public cloud services to assist Customers in reducing operational costs.
14. Provide public cloud tagging enablement for Service Provider-managed tags based on predetermined rules and Customer-managed tags.
15. Actively work with Admin to ensure that tagging includes relevant CI details as defined by the SMM.
16. Ensure all public cloud-hosted instances are tagged with necessary details to support billing, audit, reporting, security, and operations management to meet Admin and Customer requirements.
17. Ensure secure public cloud-hosted instance tagging governance policies are in place to prevent unauthorized modification of tags.
Cloud Native Middleware Services Service Provider monitors and supports CSP-offered cloud-native Middleware (e.g., Azure Integration Services, Azure Event Grid, AWS SQS). The Service Provider shall, at a minimum:
1. Provide administrative support for enrolled Middleware services.
2. Provide adequate technical support (e.g., patching, event resolution, advice, Third-Party Vendor coordination).
3. Integrate with Admin security monitoring and access control management standards (e.g., SIEM, Identity and Access Management (IAM)) as Admin requires.
4. Support Customer application developers in supporting Middleware runtime environments.
5. Assist the Customer in managing the lifecycle of provisioned Middleware environments, including specification, installation, implementation, monitoring, management, backup/restore, and disaster recovery of Customer Middleware environments.
6. Monitor and manage the Middleware systems components on a 24/7 basis to ensure environments meet performance standards.
7. Alert defined resources if process, application, system events, or thresholds have been exceeded. This notification will occur based on defined SMM procedures and the agreed escalation matrix.
8. Monitor capacity and proactively provide performance and capacity planning.
Distributed Denial of Service Protection Services If requested by the Customer, as an optional service, the Service Provider shall, at a minimum:
1. Provide intrusion prevention system (IPS) and intrusion detection system (IDS) services.
2. Manage intrusion detection, prevention, and distributed denial of service (DDOS), including prompt Customer notification of such events, reporting, monitoring, and assessing security events.
3. Work with Admin or Customer to support the denial of communications to and from known malicious IP addresses.
4. Ensure the public cloud network architecture separates internal systems from DMZ and extranet systems.
5. Require remote login access to use two-factor authentication.
6. Support Admin or Customer’s monitoring and managing devices remotely, logging into the internal network.
7. Support Admin or Customer in configuring firewall session tracking mechanisms for addresses that access the public cloud.
Database Management Services The Service Provider manages and operates Admin’s optional public cloud database management services, including all database management systems across all CSPs available to Customers. Database management is an optional service that customers may request. The Service Provider shall, at a minimum:
1. Design and deploy database components and services with appropriate high availability and resilience configurations to meet the requirements.
2. Complete management of the lifecycle of provisioned database environments,…
This is the start of the file's text. The full file is on GovTribe.
File details come from the government source that posted it. Updated .