PRIME_Requirements.xlsx
XLSX spreadsheet 60 KB Posted
- Attached to
- Kessel Run PRIME RFI Federal contract opportunity
- Solicitation number
- FA8730_PRIME_KR
About this file
This document is a comprehensive Requirements file for the Kessel Run PRIME contract, detailing technical requirements for Air Force enterprise IT services across multiple focus areas including End User Services, Infrastructure, Platform, CI/CD Capabilities, and Documentation. The requirements span critical domains such as hardware and software provisioning, virtualized storage and compute, network connectivity, cybersecurity, developer tools, and IT service management, with a strong emphasis on secure, compliant, and efficient technology solutions for military operational environments.
Key technical requirements include developing a secure release pipeline supporting classified and unclassified environments, implementing Zero Trust networking, providing comprehensive ServiceNow workflow development, managing hardware and software assets across multiple security classifications (NIPR, SIPR, JWICS), and establishing robust CI/CD capabilities with advanced security controls. The solicitation is a Pre-Solicitation Request for Information (RFI) issued by the Department of the Air Force Materiel Command Lifecycle Management Center, seeking industry collaboration to refine and validate the extensive technical requirements for mission-critical warfighting application development and support.
View the file
Other files for this federal contract opportunity
| File | Type | Posted |
|---|---|---|
| PRIME_RFI_Amendment_1_Response_Template.xlsx | XLSX spreadsheet | |
| PRIME_RFI_Cover_Document_Amendment_1.docx | DOCX document | |
| PRIME_RFI_Cover_Document.pdf | ||
| PRIME_RFI_Response_Template.xlsx | XLSX spreadsheet |
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
End User Sys & Docs
| Focus Area | Requirement Block | ID | Requirement Statement | Rationale | ||
| End User Services | Air Force Enterprise Tools | ADCP-EUS-ET- | 001 | ADCP-EUS-ET-001 | The vendor shall provide support for NIPR (Non-classified Internet Protocol Router Network) accounts and CAC (Common Access Card) provisioning for Kessel Run personnel. | Kessel Run operates within a DoD environment where NIPRNet access and CAC authentication are fundamental for secure network access, data handling, and personnel identification. This ensures compliance with government security protocols and enables personnel to access critical resources and perform their duties effectively. |
| End User Services | Air Force Enterprise Tools | ADCP-EUS-ET- | 002 | ADCP-EUS-ET-002 | The vendor shall provide support for the setup and configuration of designated organizational communication resources (e.g., Orgbox). | Effective communication is crucial for project success. Supporting the setup and configuration of designated communication resources ensures Kessel Run personnel have the necessary tools for seamless collaboration, information sharing, and efficient workflow within the organization and with external stakeholders. |
| End User Services | Air Force Enterprise Tools | ADCP-EUS-ET- | 003 | ADCP-EUS-ET-003 | The vendor shall adhere to clear procedures for identifying, reporting, and responding to Intellectual Property (IP) spillage incidents. | Protecting Intellectual Property is paramount. Adhering to clear IP spillage procedures is critical for preventing unauthorized disclosure of sensitive information, mitigating potential security breaches, and ensuring compliance with data protection regulations. This safeguards Kessel Run's proprietary assets and maintains operational security. |
| End User Services | Software Procurement and Management | ADCP-EUS-ET- | 004 | ADCP-EUS-SW-001 | The vendor shall procure and manage licenses for diagramming software as required for project documentation and design. | Diagramming software is essential for visual communication, system design, and comprehensive project documentation. Providing and managing these licenses ensures Kessel Run teams can effectively plan, illustrate, and document complex architectures, workflows, and processes, leading to clearer understanding and better-engineered solutions. |
| End User Services | Software Procurement and Management | ADCP-EUS-ET- | 005 | ADCP-EUS-SW-002 | The vendor shall procure and manage licenses for UI mockup software for user interface design and prototyping. | UI mockup software is vital for designing user-centric applications. Managing these licenses enables Kessel Run teams to rapidly prototype, visualize, and iterate on user interfaces, gather early feedback, and ensure an optimal user experience before significant development effort is expended, thereby reducing rework and improving product quality. |
| End User Services | Software Procurement and Management | ADCP-EUS-ET- | 006 | ADCP-EUS-SW-003 | The vendor shall procure and manage licenses for necessary development and Continuous Integration (CI) tools. | These tools form the backbone of modern software development. Providing and managing licenses for development and CI tools ensures Kessel Run teams have the essential infrastructure for efficient code creation, automated testing, continuous integration, and streamlined deployment pipelines, leading to faster delivery of high-quality software. |
| End User Services | Software Procurement and Management | ADCP-EUS-ET- | 007 | ADCP-EUS-SW-004 | The vendor shall procure and manage licenses for paired programming tools. | Paired programming enhances code quality, facilitates knowledge transfer, and fosters collaboration among developers. Managing these licenses supports Kessel Run's adoption of best practices in agile software development, leading to more robust code, faster problem-solving, and improved team synergy. |
| End User Services | Software Procurement and Management | ADCP-EUS-ET- | 008 | ADCP-EUS-SW-005 | The vendor shall procure and manage licenses for security tools for code analysis, vulnerability scanning, and other security-related tasks. | Providing and managing licenses for security tools ensures continuous code analysis, early detection of vulnerabilities, and adherence to security best practices throughout the development lifecycle, protecting systems from threats and maintaining compliance with DoD security standards. |
| End User Services | Software Procurement and Management | ADCP-EUS-ET- | 009 | ADCP-EUS-SW-006 | The vendor shall procure and manage licenses for Integrated Development Environments (IDEs). | IDEs are fundamental productivity tools for developers, offering comprehensive features for coding, debugging, and project management. Managing these licenses ensures Kessel Run developers have the powerful and efficient tools necessary to maximize their output, streamline workflows, and maintain a consistent development environment across projects. |
| End User Services | IT Service Management System | ADCP-EUS-ITSM- | 011 | ADCP-EUS-ITSM-001 | The vendor shall develop, implement, and maintain digitized service workflows within the ServiceNow platform. | This establishes the foundational technology platform (ServiceNow) for all subsequent ITSM and workflow development, ensuring a unified, integrated, and scalable solution for optimizing IT service delivery and support. |
| End User Services | IT Service Management System | ADCP-EUS-ITSM- | 012 | ADCP-EUS-ITSM-002 | The vendor shall maintain and enhance a user-friendly, centralized employee service portal. | Designing and developing a user-friendly, centralized portal is essential for promoting self-service, enhancing user experience, encouraging adoption, and reducing the administrative burden on IT staff by empowering users to find information and submit requests independently. |
| End User Services | IT Service Management System | ADCP-EUS-ITSM- | 013 | ADCP-EUS-ITSM-003 | The centralized employee service portal shall facilitate IT service requests. | Providing a centralized capability for IT service requests streamlines the process for users, improves request tracking, ensures consistent fulfillment, and provides valuable data for service improvement, leading to better service delivery and user satisfaction. |
| End User Services | IT Service Management System | ADCP-EUS-ITSM- | 014 | ADCP-EUS-ITSM-004 | The centralized employee service portal shall facilitate incident reporting. | Offering an easy and centralized channel for incident reporting enables rapid detection of issues, reduces service downtime, and improves the overall responsiveness and efficiency of IT support in addressing service interruptions. |
| End User Services | IT Service Management System | ADCP-EUS-ITSM- | 015 | ADCP-EUS-ITSM-005 | The centralized employee service portal shall provide searchability of the knowledge base. | Providing searchability for the knowledge base is critical for employee efficiency and self-service. It enables personnel to quickly and independently find answers to common questions, policies, and procedures, reducing reliance on direct support channels. This minimizes disruptions, improves productivity, and maximizes the value of the knowledge base content by making it easily accessible. |
| End User Services | IT Service Management System | ADCP-EUS-ITSM- | 016 | ADCP-EUS-ITSM-006 | The vendor shall develop and manage digitized workflows for efficient incident reporting. | Efficient incident reporting workflows ensure that all incidents are captured accurately and quickly, providing the necessary information for rapid diagnosis and resolution, which is the critical first step in restoring normal service operations. |
| End User Services | IT Service Management System | ADCP-EUS-ITSM- | 017 | ADCP-EUS-ITSM-007 | The vendor shall develop and manage digitized workflows for efficient incident triage. | Effective incident triage workflows ensure that reported incidents are promptly categorized, prioritized based on impact and urgency, and assigned to the most appropriate support teams or individuals, thereby optimizing resolution time and resource allocation. |
| End User Services | IT Service Management System | ADCP-EUS-ITSM- | 018 | ADCP-EUS-ITSM-008 | The vendor shall develop and manage digitized workflows for efficient incident escalation and resolution. | Standardized and managed resolution workflows promote consistent and effective problem-solving approaches, reduce the likelihood of recurring issues, and improve the overall quality and stability of IT services. |
| End User Services | IT Service Management System | ADCP-EUS-ITSM- | 020 | ADCP-EUS-ITSM-009 | The vendor shall develop and maintain a comprehensive service catalog for request fulfillment. | A comprehensive service catalog provides clear visibility into all available IT services, enabling users to easily find and request services, promoting standardization of service offerings, and streamlining the request fulfillment process. |
| End User Services | IT Service Management System | ADCP-EUS-ITSM- | 021 | ADCP-EUS-ITSM-010 | The vendor shall define and integrate workflows for each service item within the service catalog. | Integrating defined workflows directly with each service item in the catalog automates the fulfillment process, ensuring consistency, efficiency, and accurate tracking of service requests from initiation to completion, reducing manual errors and processing times. |
| End User Services | IT Service Management System | ADCP-EUS-ITSM- | 022 | ADCP-EUS-ITSM-011 | The vendor shall develop and manage digitized workflows for employee onboarding, including IT provisioning, access granting, and training assignments. | Automating IT provisioning during employee onboarding ensures that new employees have immediate access to necessary systems and equipment upon joining, enhancing productivity from their first day and ensuring compliance with asset management policies. |
| End User Services | IT Service Management System | ADCP-EUS-ITSM- | 023 | ADCP-EUS-ITSM-012 | The vendor shall develop and manage digitized workflows for employee offboarding, including IT asset retrieval and account deactivation. | Standardized workflows for IT asset retrieval during offboarding and account deactivation prevent the loss of company property, ensure proper decommissioning, and maintain accurate inventory records, reducing financial loss and operational overhead. |
| End User Services | IT Service Management System | ADCP-EUS-ITSM- | 024 | ADCP-EUS-ITSM-013 | The vendor shall develop and manage digitized workflows for employee transfers, including IT asset relocation and access adjustments. | Streamlined workflows for IT asset relocation and access adjustments during employee transfers ensure continuity of service for employees in their new roles or locations, minimizing productivity disruptions and ensuring proper asset management and access management. |
| End User Services | IT Service Management System | ADCP-EUS-ITSM- | 025 | ADCP-EUS-ITSM-014 | The vendor shall maintain a comprehensive Knowledge Management system accessible via the service portal. | Establishing a comprehensive Knowledge Management (KM) system accessible via the service portal empowers users to find answers independently, reduces the volume of support tickets, and improves overall user satisfaction and efficiency. |
| End User Services | IT Service Management System | ADCP-EUS-ITSM- | 026 | ADCP-EUS-ITSM-015 | The Knowledge Management system shall include FAQs (Frequently Asked Questions). | Including FAQs in the KM system proactively addresses common queries, significantly reducing repetitive questions directed to support staff and providing quick, consistent answers for users, thereby improving efficiency for both users and IT. |
| End User Services | IT Service Management System | ADCP-EUS-ITSM- | 027 | ADCP-EUS-ITSM-016 | The Knowledge Management system shall include how-to guides. | Providing how-to guides within the KM system offers step-by-step instructions for common tasks, enabling user self-sufficiency, promoting best practices, and reducing reliance on direct IT support for routine activities. |
| End User Services | IT Service Management System | ADCP-EUS-ITSM- | 028 | ADCP-EUS-ITSM-017 | The Knowledge Management system shall include troubleshooting steps. | Incorporating troubleshooting steps empowers users to resolve minor technical issues independently, decreasing incident volume, reducing MTTR (Mean Time To Resolution) for basic problems, and improving overall system availability. |
| End User Services | IT Service Management System | ADCP-EUS-ITSM- | 030 | ADCP-EUS-ITSM-018 | The vendor shall develop and maintain custom workflows to support specialized business and governance procedures as identified by Kessel Run. | Developing custom workflows to support specialized business and governance procedures ensures compliance with specific internal policies or external regulations relevant to Kessel Run, enhancing control, transparency, and reducing audit risks. |
| End User Services | IT Service Management System | ADCP-EUS-ITSM- | 031 | ADCP-EUS-ITSM-019 | The vendor shall implement and manage a digital Change Management workflow. | Implementing and managing a robust Change Management process is critical for minimizing the risks associated with IT changes, preventing service disruptions, ensuring system stability, and maintaining operational continuity. |
| End User Services | IT Service Management System | ADCP-EUS-ITSM- | 033 | ADCP-EUS-ITSM-020 | The Change Management process shall offer distinct workflows for standard, normal, and emergency change procedures. | Offering distinct workflows for Standard, Normal, and Emergency changes ensures that each type of change is handled with an appropriate level of rigor, speed, and approval. This optimizes both the efficiency for routine, low-risk changes and the control required for complex or urgent, high-impact changes, balancing agility with risk management. |
| End User Services | Tier 1 Support | ADCP-EUS-SUP- | 035 | ADCP-EUS-SUP-001 | The vendor shall provide Tier 1 support for initial diagnosis, classification, and resolution of common, well-documented incidents, leveraging available knowledge bases and troubleshooting guides. | To quickly restore normal service operation for end-users by addressing frequently encountered issues at the first point of contact, minimizing disruption and improving user productivity. |
| End User Services | Tier 1 Support | ADCP-EUS-SUP- | 036 | ADCP-EUS-SUP-002 | The vendor shall perform accurate prioritization and timely escalation of incidents that cannot be resolved at Tier 1 to appropriate higher-tier support teams. | To ensure that complex or unfamiliar incidents are routed efficiently to specialized teams for timely resolution, preventing delays and optimizing the overall incident management process. |
| End User Services | Tier 1 Support | ADCP-EUS-SUP- | 037 | ADCP-EUS-SUP-003 | The vendor shall provide Tier 1 support for fulfilling standard, pre-defined service requests according to established procedures and within agreed-upon service level expectations. | To efficiently deliver common, recurring services (e.g., standard access grants, software provisioning) to users in a standardized and timely manner, enhancing user experience and operational efficiency. |
| End User Services | Tier 1 Support | ADCP-EUS-SUP- | 038 | ADCP-EUS-SUP-004 | The vendor shall perform validation and accurate routing of more complex service requests, requiring specialized resources or approvals, to appropriate higher-tier teams for fulfillment. | To ensure that service requests beyond Tier 1's scope are correctly processed and directed to the relevant teams, maintaining an efficient request fulfillment workflow and reducing processing delays. |
| End User Services | Hardware Asset Provision and Support | ADCP-EUS-HW- | 059 | ADCP-EUS-HW-001 | The vendor shall provision and support all specified hardware assets required for project operations. | Ensures that all necessary physical and virtual infrastructure is available, operational, and maintained to support project activities and personnel productivity. |
| End User Services | Hardware Asset Provision and Support | ADCP-EUS-HW- | 060 | ADCP-EUS-HW-002 | The vendor shall provision and support NIPR (Non-classified Internet Protocol Router Network) connected hardware, including workstations and laptops. | Provides standard, secure access for personnel to unclassified government networks for daily operations, communication, and data processing. |
| End User Services | Hardware Asset Provision and Support | ADCP-EUS-HW- | 061 | ADCP-EUS-HW-003 | The vendor shall provision and support unclassified virtual desktop environments. | Offers flexible, remote-accessible, and managed desktop environments for unclassified work, enhancing productivity, security, and ease of access for users. |
| End User Services | Hardware Asset Provision and Support | ADCP-EUS-HW- | 062 | ADCP-EUS-HW-004 | The vendor shall provision and support standard peripherals (e.g., monitors, keyboards, mice, printers). | Ensures personnel have the essential accessories needed for their workstations to function effectively, supporting their daily tasks. |
| End User Services | Hardware Asset Provision and Support | ADCP-EUS-HW- | 063 | ADCP-EUS-HW-005 | The vendor shall provision and support mobile devices, including cellphones, iPads, and MiFi devices. | Provides mobile connectivity and computing capabilities for personnel, supporting remote work, on-the-go communication, and operational flexibility. |
| End User Services | Hardware Asset Provision and Support | ADCP-EUS-HW- | 064 | ADCP-EUS-HW-006 | The vendor shall provision and support TACLANE encryptors for secure communication within classified spaces. | Provides critical cryptographic protection for network communications handling classified information, adhering to stringent government security standards and preventing unauthorized access. |
| End User Services | Hardware Asset Provision and Support | ADCP-EUS-HW- | 065 | ADCP-EUS-HW-007 | The vendor shall provision and support storage solutions for SIPRNet (Secret Internet Protocol Router Network) classified data. | Ensures secure, compliant, and reliable storage for classified information up to the Secret level, meeting government data handling and retention requirements. |
| End User Services | Hardware Asset Provision and Support | ADCP-EUS-HW- | 066 | ADCP-EUS-HW-008 | The vendor shall provision and support SIPRNet-specific hardware and peripherals (e.g., workstations, printers, KVM switches) within classified spaces. | Provides the necessary specialized equipment for personnel to securely access and process classified information on the SIPRNet, maintaining segregation and integrity. |
| End User Services | Hardware Asset Provision and Support | ADCP-EUS-HW- | 067 | ADCP-EUS-HW-009 | The vendor shall provision and support Classified Personal Electronic Devices (CPEDs), such as SIPR laptops, as required for project roles within classified environments. | Equips authorized personnel with specialized devices to securely access and process classified information, adhering to strict government security protocols for handling sensitive data. |
| End User Services | Hardware Asset Provision and Support | ADCP-EUS-HW- | 068 | ADCP-EUS-HW-010 | The vendor shall provision and support conference room equipment (e.g., video conferencing systems, displays, presentation tools) in unclassified spaces. | Facilitates effective collaboration and communication for meetings and presentations within unclassified environments, enhancing team interaction and productivity. |
| End User Services | Hardware Asset Provision and Support | ADCP-EUS-HW- | 069 | ADCP-EUS-HW-011 | The vendor shall provision and support Wi-Fi and network infrastructure in unclassified spaces. | Provides reliable and secure network connectivity for personnel and devices within unclassified operational areas, supporting daily work and system access. |
| End User Services | Documentation - Platform | ADCP-DOC-PLA- | 070 | ADCP-EUS-DOC-001 | The vendor shall develop and maintain documentation for the ADCP platform's underlying infrastructure. | Provides essential reference for understanding, operating, and troubleshooting the foundational components of the ADCP platform for administrators and technical users. |
| End User Services | Documentation - Platform | ADCP-DOC-PLA- | 072 | ADCP-EUS-DOC-002 | The vendor shall develop and maintain documentation detailing the ADCP platform's "Path to Production" process. | Provides clear, step-by-step guidance for deploying applications and services to production environments, ensuring consistency, compliance, and efficiency. |
| End User Services | Documentation - Platform | ADCP-DOC-PLA- | 073 | ADCP-EUS-DOC-003 | The vendor shall develop and maintain documentation for ADCP platform support procedures and resources. | Enables users to efficiently seek and receive assistance, clarifying support channels, expectations, and escalation paths, thus improving resolution times. |
| End User Services | Documentation - Platform | ADCP-DOC-PLA- | 074 | ADCP-EUS-DOC-004 | The vendor shall develop and maintain documentation to enhance the developer experience on the ADCP platform. | Provides developers with guides, tutorials, and best practices to maximize productivity and streamline development on the platform, fostering adoption and efficient use. |
| End User Services | Documentation - Platform | ADCP-EUS-DOC-005 | The platform documentation shall include comprehensive playbooks for all incident response and outage recovery procedures. | Detailed incident/outage playbooks enable rapid and organized response to disruptions, minimizing Mean Time To Recovery (MTTR) and impact on service availability. | ||
| End User Services | Documentation - Platform | ADCP-EUS-DOC-006 | The platform documentation shall include clear and up-to-date architecture diagrams of the platform components including Model-Based Systems Engineering (MBSE) models. | Architecture diagrams provide visual clarity into the platform's structure, aiding customer understanding, troubleshooting, and integration efforts. | ||
| End User Services | Documentation - Platform | ADCP-EUS-DOC-007 | The vendor shall provide comprehensive and up-to-date documentation covering all features, functionalities, and operational procedures. | Comprehensive documentation is essential for customer self-sufficiency, enabling them to effectively use, troubleshoot, and manage their applications and interactions with the platform. | ||
| End User Services | Documentation - Enterprise User Support | ADCP-DOC-EUS- | 075 | ADCP-EUS-DOC-008 | The vendor shall develop and maintain documentation for KR Enterprise business tools and associated processes. | Ensures users understand how to effectively utilize enterprise tools and adhere to established business workflows, promoting operational consistency and efficiency. |
| End User Services | Documentation - Enterprise User Support | ADCP-DOC-EUS- | 076 | ADCP-EUS-DOC-009 | The vendor shall develop and maintain a comprehensive set of Frequently Asked Questions (FAQs) for KR Enterprise user support. | Provides quick answers to common user queries, reducing support load and improving user self-sufficiency for routine issues. |
| End User Services | Documentation - Enterprise User Support | ADCP-DOC-EUS- | 077 | ADCP-EUS-DOC-010 | The vendor shall develop and maintain security documentation for KR Enterprise user support. | Informs users about security policies, best practices, and procedures relevant to KR Enterprise, promoting a secure user environment and reducing security risks. |
| End User Services | Documentation - AOC Playbooks | ADCP-DOC-AOC- | 078 | ADCP-EUS-DOC-011 | The vendor shall develop and maintain comprehensive playbooks for on-site support for each Air Operations Center (AOC). | Provides standardized, actionable guides for support personnel in specific operational environments, ensuring consistent, efficient, and effective incident response and maintenance. |
| End User Services | Documentation - AOC Playbooks | ADCP-DOC-AOC- | 079 | ADCP-EUS-DOC-012 | The vendor shall validate and test all Standard Operating Procedures (SOPs) within the on-site support playbooks. | Ensures the accuracy, effectiveness, and practicality of the procedures under operational conditions, reducing errors and improving reliability. |
| End User Services | Documentation - AOC Playbooks | ADCP-DOC-AOC- | 080 | ADCP-EUS-DOC-013 | The vendor shall develop and maintain Maintenance & Operations Standard Operating Procedures (SOPs) within the on-site support playbooks. | Provides clear, step-by-step instructions for routine maintenance and operational tasks, ensuring consistency, efficiency, and adherence to best practices. |
| End User Services | Documentation - AOC Playbooks | ADCP-DOC-AOC- | 081 | ADCP-EUS-DOC-014 | The vendor shall develop and maintain Troubleshooting Standard Operating Procedures (SOPs) within the on-site support playbooks. | Equips support personnel with structured approaches to diagnosing and resolving common and complex issues, reducing Mean Time To Repair (MTTR). |
| End User Services | Documentation - AOC Playbooks | ADCP-DOC-AOC- | 082 | ADCP-EUS-DOC-015 | The vendor shall develop and maintain Crisis Standard Operating Procedures (SOPs) within the on-site support playbooks. | Provides critical guidance for responding to severe incidents and emergencies, ensuring organized, effective, and compliant crisis management. |
| End User Services | Documentation - AOC Playbooks | ADCP-DOC-AOC- | 083 | ADCP-EUS-DOC-016 | The vendor shall develop and maintain comprehensive checklists to support all relevant operational and maintenance tasks within the on-site support playbooks. | Provides concise, verifiable steps to ensure critical procedures are followed correctly and completely, enhancing reliability and reducing human error. |
Infrastructure
| Focus Area | Requirement Block | ID | Requirement Statement | Rationale |
| Infrastructure | Virtualized Storage and Compute | ADCP-INFRA-VIRT-001 | The cloud infrastructure shall automatically apply security‑hardening procedures to every image before the image is made available for deployment, and the hardening shall be performed in accordance with the DoD STIG. | Automated hardening of images guarantees a baseline security posture for all cloud workloads, reduces the risk of human error during manual hardening, and satisfies the organization’s regulatory and mission‑critical compliance obligations. |
| Infrastructure | Virtualized Storage and Compute | ADCP-INFRA-VIRT-002 | The cloud infrastructure shall be managed as code, using a version‑controlled, automated Infrastructure‑as‑Code (IaC) process that provisions, configures, and updates all cloud resources. | Managing the infrastructure as code enables repeatable, auditable, and reversible deployments, reduces configuration drift, and supports continuous delivery pipelines. |
| Infrastructure | Virtualized Storage and Compute | ADCP-INFRA-VIRT-003 | The cloud infrastructure shall provision virtual machines using hardened base images from the common repository. | Hardened images reduce the attack surface of VMs, ensuring that known vulnerabilities are mitigated before deployment and that a single, controlled source of images supports traceability and repeatability. |
| Infrastructure | Virtualized Storage and Compute | ADCP-INFRA-VIRT-004 | The cloud infrastructure common image repository shall support self-service. | Providing self‑service reduces support overhead, accelerates development cycles, and improves the agility of teams that rely on standardized baseline images. |
| Infrastructure | Virtualized Storage and Compute | ADCP-INFRA-VIRT-005 | The cloud infrastructure shall use version controlled images for virtual machines. | Using hardened base images from a common repository ensures that virtual machines are consistently deployed with secure, pre-approved configurations, reducing vulnerabilities and aligning with organizational security policies. Version control enables traceability, supports rollback in case of issues, and ensures that updates to images are managed systematically to maintain compliance and operational stability. |
| Infrastructure | Virtualized Storage and Compute | ADCP-INFRA-VIRT-006 | The cloud infrastructure shall employ role based access control (RBAC) that supports self-service role creation. | |
| Infrastructure | Virtualized Storage and Compute | ADCP-INFRA-VIRT-007 | The cloud infrastructure shall employ role based access control (RBAC) that supports auditing of access. | Role-Based Access Control (RBAC) enforces the principle of least privilege, ensuring users and systems have only the permissions necessary to perform their tasks, thereby reducing the attack surface and limiting the impact of potential breaches. Supporting self-service role creation and access auditing enhances operational efficiency, ensures accountability, and enables continuous monitoring to maintain compliance with security policies. |
| Infrastructure | Virtualized Storage and Compute | ADCP-INFRA-VIRT-008 | The cloud infrastructure shall employ role based access control (RBAC) that enforces the policy of least privilege. | Applying RBAC with a least‑privilege policy reduces the attack surface, limits the impact of compromised credentials, and satisfies the organization’s security governance requirements. |
| Infrastructure | Virtualized Storage and Compute | ADCP-INFRA-VIRT-009 | The cloud infrastructure shall provide cloud storage services that are self-service. | Enabling customers to provision, manage, and delete storage resources on‑demand reduces operational overhead, and shortens time‑to‑value. |
| Infrastructure | Virtualized Storage and Compute | ADCP-INFRA-VIRT-010 | The cloud infrastructure shall provide cloud storage services that allow for customer-defined encryption. | Providing customer‑defined encryption enables customers to satisfy their internal security policies and external regulatory mandates for data confidentiality, thereby preserving trust and compliance in a multi‑tenant environment. |
| Infrastructure | Virtualized Storage and Compute | ADCP-INFRA-VIRT-011 | The cloud infrastructure shall provide resiliency through the use of a multiple region cloud. | To satisfy the stakeholder need for continuous service availability, deploying the cloud across multiple regions provides geographic redundancy and fault isolation, thereby enhancing overall system resiliency. This design directly supports the system’s reliability performance objectives and ensures continuity of critical mission functions in the event of localized failures. |
| Infrastructure | Virtualized Storage and Compute | ADCP-INFRA-VIRT-012 | The cloud infrastructure shall provide resiliency through the use of multiple availability zones within each region. | Using multiple availability zones distributes workloads across physically separated data centers, and satisfying the stakeholder requirement for high availability and continuity of service. This approach aligns with the system’s reliability and risk‑mitigation objectives. |
| Infrastructure | Virtualized Storage and Compute | ADCP-INFRA-VIRT-013 | The cloud infrastructure shall provide cloud account management resource insights for cost optimization. | Providing detailed cloud‑account resource insights enables stakeholders to monitor utilization, detect potential inefficiencies, and make data‑driven decisions that keep operating costs within budgetary constraints, thereby fulfilling the stakeholder’s need for financial stewardship. |
| Infrastructure | Virtualized Storage and Compute | ADCP-INFRA-VIRT-014 | The cloud infrastructure shall provide cloud account management resource tagging for cost optimization. | Providing a mechanism for resource‑level tagging in the cloud account enables precise cost attribution and usage visibility, which directly supports the stakeholder need for financial stewardship and the system objective of cost‑effective operation. |
| Infrastructure | Virtualized Storage and Compute | ADCP-INFRA-VIRT-015 | The cloud infrastructure shall provide cloud account management utilization reporting for cost optimization. | Because stakeholders must maintain financial accountability and ensure the solution remains affordable, providing cloud‑account utilization reports supplies the actionable data needed to identify under‑used resources and drive cost‑optimization decisions, directly supporting the system’s performance, affordability, and sustainability objectives. |
| Infrastructure | Virtualized Storage and Compute | ADCP-INFRA-VIRT-016 | The vendor shall fulfill user request for user account access provisioning. | Fulfilling user‑requested account provisioning promptly enables personnel to access required system functions when needed, thereby supporting mission‑critical operations, maintaining system availability, and complying with organizational security and access‑control policies. |
| Infrastructure | Virtualized Storage and Compute | ADCP-INFRA-VIRT-017 | The vendor shall fulfill user requests for cloud account provisioning. | Timely fulfillment of user requests for cloud account provisioning enables users to obtain the necessary access to mission‑critical services, thereby maintaining operational readiness and compliance with security and governance policies. |
| Infrastructure | Virtualized Storage and Compute | ADCP-INFRA-VIRT-018 | The vendor shall fulfill requests for deprovisioning of user accounts. | Timely deprovisioning of user accounts mitigates the security risk of unauthorized access and ensures compliance with the organization’s access‑control policies and applicable regulatory requirements. |
| Infrastructure | Local Storage and Compute | ADCP-INFRA-LOCAL-001 | The local infrastructure shall provide cloud-compatible local block storage for mission data hosting. | Providing cloud‑compatible block storage locally satisfies the stakeholder need for low‑latency, on‑premise access to mission‑critical data while preserving the ability to migrate or off‑load data to a cloud environment |
| Infrastructure | Local Storage and Compute | ADCP-INFRA-LOCAL-002 | The local infrastructure shall provide cloud-compatible local block storage that supports disaster recovery. | Enabling disaster‑recovery replication ensures rapid restoration of mission‑critical data after a failure, directly supporting the system availability and resilience objectives. |
| Infrastructure | Local Storage and Compute | ADCP-INFRA-LOCAL-003 | The local infrastructure shall provide cloud-compatible local block storage that supports replication to the cloud. | Cloud replication provides an off‑site backup and facilitates rapid data restoration or analytics in the cloud, meeting the stakeholder‑driven need for data durability and resiliency. |
| Infrastructure | Local Storage and Compute | ADCP-INFRA-LOCAL-004 | The local infrastructure shall provide cloud-compatible local block storage that supports cross-region replication. | Cross‑region replication mitigates the risk of regional outages |
| Infrastructure | Local Storage and Compute | ADCP-INFRA-LOCAL-005 | The local infrastructure virtualization and orchestration layer shall run containerized application and service workloads. | |
| Infrastructure | Local Storage and Compute | ADCP-INFRA-LOCAL-006 | The local infrastructure virtualization and orchestration layer shall be Elastic Kubernetes Service Distro (EKS-D) compatible. | Compatibility with Elastic Kubernetes Service Distro (EKS-D) ensures interoperability of the platform with the cloud and local environments. |
| Infrastructure | Local Storage and Compute | ADCP-INFRA-LOCAL-007 | The local infrastructure virtualization and orchestration layer shall host the High Assurance Platform (HAP). | Compatibility with the High Assurance Platform (HAP) ensures parity of the platform between the cloud and local environments. |
| Infrastructure | Local Storage and Compute | ADCP-INFRA-LOCAL-008 | The configuration for the virtualization and orchestration layer shall be managed exclusively via a version-controlled repository. | To ensure all infrastructure changes are traceable, repeatable, and reversible, and to prevent unauthorized, manual configuration drift. |
| Infrastructure | Local Storage and Compute | ADCP-INFRA-LOCAL-009 | The local infrastructure virtualization / orchestration layer shall be regularly patched for lifecycle management. | Regular patching maintains a hardened security posture, compliance with applicable standards, and reduces vulnerability exposure throughout the system’s operational life. |
| Infrastructure | Local Storage and Compute | ADCP-INFRA-LOCAL-010 | The local infrastructure compute resources shall be highly available with 3 availability zones per edge node. | Distributing compute across three Availability Zones provides tolerance to zone‑level failures and supports the defined availability targets for mission‑essential processing. |
| Infrastructure | Local Storage and Compute | ADCP-INFRA-LOCAL-011 | The local infrastructure compute resources shall be highly available supporting zero downtime upgrade capability. | Enabling zero‑downtime upgrades preserves uninterrupted service delivery during maintenance windows, directly addressing the stakeholder need for continuous mission support. |
| Infrastructure | Hybrid Networking Connectivity | ADCP-INFRA-NET-001 | The hybrid networking infrastructure shall use Zero Trust (ZT) for ingress management. | Zero Trust enforces continuous verification of every connection, reducing the attack surface and satisfying the stakeholder requirement for high‑assurance security of inbound traffic. |
| Infrastructure | Hybrid Networking Connectivity | ADCP-INFRA-NET-002 | The hybrid networking infrastructure shall use a next generation firewall (NGFW) for ingress management. | An NGFW provides deep‑packet inspection, application‑aware controls, and integrated threat intelligence, ensuring compliance with the organization’s policy of proactive intrusion prevention for inbound traffic. |
| Infrastructure | Hybrid Networking Connectivity | ADCP-INFRA-NET-003 | The hybrid networking infrastructure shall use a network firewall for egress management. | A dedicated egress firewall enforces data‑exfiltration controls and outbound traffic policies, helping address the data‑loss‑prevention (DLP) concerns. |
| Infrastructure | Hybrid Networking Connectivity | ADCP-INFRA-NET-004 | The hybrid networking infrastructure shall use a next generation firewall (NGFW) for egress management. | Deploying an next generation firewall (NGFW) at egress enables granular, application‑level filtering and real‑time threat detection on outbound flows, supporting the risk‑management objective of preventing compromised hosts from communicating. |
| Infrastructure | Hybrid Networking Connectivity | ADCP-INFRA-NET-005 | The hybrid networking infrastructure transit gateway shall use Identity and Access Management (IAM). | Identity and Access Management (IAM) centralizes authentication and authorization for routing decisions, satisfying the stakeholder requirement for auditable, least‑privilege access to inter‑region connectivity. |
| Infrastructure | Hybrid Networking Connectivity | ADCP-INFRA-NET-006 | The hybrid networking infrastructure transit gateway shall use routing tables. | Explicit routing tables provide deterministic path selection and enable traceability of traffic flows, meeting the performance‑predictability and troubleshooting needs. |
| Infrastructure | Hybrid Networking Connectivity | ADCP-INFRA-NET-007 | The hybrid networking infrastructure shall employ Break and Inspect (B&I) on network traffic. | B&I forces traffic out of the data path for deep inspection, a proven control for detecting sophisticated malware and other nefarious exfil that aligns with the organization’s security‑assurance mandate. |
| Infrastructure | Hybrid Networking Connectivity | ADCP-INFRA-NET-008 | The hybrid networking infrastructure B&I shall use an internally managed certificate authority (CA) server. | An internally managed Certificate Authority (CA) ensures full control over certificate issuance and revocation |
| Infrastructure | Hybrid Networking Connectivity | ADCP-INFRA-NET-009 | The hybrid networking infrastructure B&I shall perform lateral (east-west) traffic inspection. | Inspecting lateral (east‑west) traffic mitigates intra‑environment propagation of threats |
| Infrastructure | Hybrid Networking Connectivity | ADCP-INFRA-NET-010 | The hybrid networking infrastructure B&I shall forward logs to the security information and event management (SIEM) solution. | Centralized log forwarding enables correlation, alerting, and forensic analysis, supporting the compliance stakeholder’s requirement for continuous security monitoring and auditability. |
| Infrastructure | Hybrid Networking Connectivity | ADCP-INFRA-NET-011 | The hybrid networking infrastructure shall have parity of ingress / egress across cloud and edge. | Consistent ingress/egress controls across cloud and edge eliminate policy gaps, ensuring uniform security posture. |
| Infrastructure | Hybrid Networking Connectivity | ADCP-INFRA-NET-012 | The hybrid networking infrastructure shall use a single pane of glass for management. | A unified management interface reduces operational complexity and human error, increasing efficiency and usability. |
| Infrastructure | Hybrid Networking Connectivity | ADCP-INFRA-NET-013 | The hybrid networking infrastructure shall use a single pane of glass for monitoring. | Consolidated monitoring provides real‑time situational awareness and faster incident response. |
| Infrastructure | Hybrid Networking Connectivity | ADCP-INFRA-NET-014 | The hybrid networking infrastructure firewall behavior shall be consistent across environments from the perspective of (platform and application) developers. | Consistent firewall behavior across environments enables developers to have common expectations across the broader system. |
| Infrastructure | Cyber Security | ADCP-INFRA-CYBSERSEC-001 | The infrastructure at-large shall adhere to Authority to Operate (ATO) lifecycle management. | Maintaining an Authority to Operate (ATO) lifecycle ensures that the infrastructure continuously satisfies the security, policy, and compliance criteria defined by the authorizing official, thereby reducing the risk of unauthorized operation and supporting traceability of certification evidence. |
| Infrastructure | Cyber Security | ADCP-INFRA-CYBSERSEC-002 | The infrastructure at-large shall employ audit logging. | Implementing comprehensive audit logging provides verifiable records of system activities that support accountability, forensic analysis, and compliance with security standards, directly addressing the need for traceability of actions and detection of anomalous behavior. |
| Infrastructure | Cyber Security | ADCP-INFRA-CYBSERSEC-003 | The infrastructure at-large shall employ real-time security monitoring. | Real‑time security monitoring enables immediate detection and response to threats, fulfilling the operational need for continuous protection of critical assets and minimizing exposure time to potential attacks. |
| Infrastructure | Developer Services | ADCP-INFRA-DEVSVC-001 | DevOps pipeline execution shall be lightweight to gain permission to. | |
| Infrastructure | Developer Services | ADCP-INFRA-DEVSVC-002 | DevOps pipeline execution shall be self-service. | Enabling self‑service pipeline execution empowers development teams to provision and run builds without intermediary bottlenecks, supporting rapid iteration and continuous delivery. |
| Infrastructure | Developer Services | ADCP-INFRA-DEVSVC-003 | DevOps pipeline execution shall be least privilege principle compliant. | Implementing least‑privilege controls limits each pipeline’s access to only the resources it requires, mitigating the risk of privilege escalation and data leakage in accordance with the organization’s security policy. |
| Infrastructure | Developer Services | ADCP-INFRA-DEVSVC-004 | Virtual desktop infrastructure shall support Microsoft Windows. | Supporting Microsoft Windows ensures compatibility with necessary tools unique to that operating system. |
| Infrastructure | Developer Services | ADCP-INFRA-DEVSVC-005 | Virtual desktop infrastructure shall support Linux. | Supporting Linux ensures compatibility with necessary tools unique to that operating system. |
| Infrastructure | Developer Services | ADCP-INFRA-DEVSVC-006 | Virtual desktop infrastructure shall be available in the Unclassified environment. | Providing VDI in the Unclassified environment satisfies the requirement to support unclassified operations and development work. |
| Infrastructure | Developer Services | ADCP-INFRA-DEVSVC-007 | Virtual desktop infrastructure shall be available in the Secret Classified environment. | Providing VDI in the Secret environment satisfies the requirement to support operations and development work at the Secret classification level. |
| Infrastructure | SCCRM | ADCP-INFRA-SCCRM-001 | The vendor shall employ technology and practices to ensure a secure software supply chain. | Ensuring a secure software supply chain manages the risk of malicious code insertion, tampering, and supply‑chain attacks that could jeopardize system integrity, safety, and mission success. Employing proven technologies and best‑practice processes aligns with risk management, lifecycle assurance, and maintaining stakeholder confidence throughout the system’s development and operation. |
| Infrastructure | Configuration Management | ADCP-INFRA-CM-001 | The infrastructure at-large shall conform to C3C/C3BM standard practices. | Conforming to C3C/C3BM practices ensures the infrastructure aligns with higher organization standards and decisions. |
| Infrastructure | Configuration Management | ADCP-INFRA-CM-002 | The infrastructure at-large shall adhere to current NIST 800-53 federal standard. | Alignment with NIST 800‑53 provides a comprehensive set of security and privacy controls that satisfy federal mandates, enabling the system to achieve the required assurance level and mitigate identified threats. |
| Infrastructure | Configuration Management | ADCP-INFRA-CM-003 | The infrastructure at-large shall be in compliance with the DOD Risk Management Framework (RMF). | Implementing the DOD RMF establishes a repeatable process for categorizing, securing, and continuously monitoring the system, thereby ensuring that residual risk is acceptable to the mission owner and that the solution remains compliant with DoD acquisition and operational policy. |
Platform
| Focus Area | Requirement Block | ID | Requirement Statement | Rationale | |
| Application Platform | Customer Enablement | ADCP-PLAT-CE-001 | The platform shall provide on-demand sandbox clusters. | This enables customers to independently test, develop, and experiment with applications and configurations in an isolated environment without impacting production systems. | |
| Application Platform | Customer Enablement | ADCP-PLAT-CE-002 | The on-demand sandbox clusters shall include the application stack required for development and testing. | This ensures that sandbox environments are immediately usable and representative of production, reducing setup time and configuration discrepancies for developers. | |
| Application Platform | Customer Enablement | ADCP-PLAT-CE-003 | The platform documentation shall include comprehensive playbooks for all standard operational procedures. | Clear, documented playbooks ensure consistent, efficient, and reproducible execution of routine tasks by operations teams, reducing errors and reliance on individual knowledge. | |
| Application Platform | Customer Enablement | ADCP-PLAT-CE-005 | The platform's operational processes and support structure shall be designed to enable rapid incident response and minimize Mean Time To Recovery (MTTR). | A focus on rapid incident response and low MTTR is critical for maintaining high service availability and ensuring business continuity for customers. | |
| Application Platform | Customer Enablement | ADCP-PLAT-CE-006 | The platform's operational processes and documentation shall clearly define security incident response procedures. | A well-defined security incident response plan is crucial for protecting customer data and applications, ensuring compliance, and maintaining trust in the platform's security posture. | |
| Application Platform | Customer Enablement | ADCP-PLAT-CE-008 | The platform shall provide self-service capabilities for application development teams. | Self-service development empowers application teams to manage their resources and workflows independently, increasing agility and reducing reliance on manual intervention from the platform team. | |
| Application Platform | Customer Enablement | ADCP-PLAT-CE-009 | The platform shall provide self-service capabilities for application operations teams. | Self-service operations enable application teams to manage and monitor their applications efficiently, enhancing operational independence and reducing bottlenecks. | |
| Application Platform | Customer Enablement | ADCP-PLAT-CE-010 | The platform shall provide integrated observability tooling for monitoring platform components. | Integrated observability for the platform itself ensures proactive identification of issues, performance bottlenecks, and health status, enabling effective platform maintenance and stability. | |
| Application Platform | Customer Enablement | ADCP-PLAT-CE-011 | The platform shall provide integrated observability tooling for tenant applications. | Providing observability for tenant applications allows customers to monitor the health, performance, and usage of their own applications deployed on the platform. | |
| Application Platform | Customer Enablement | ADCP-PLAT-CE-012 | The platform's observability system shall be designed for multi-tenancy. | A multi-tenant observability system ensures that each customer's data is isolated and accessible only to them, while efficiently sharing underlying infrastructure. | |
| Application Platform | Customer Enablement | ADCP-PLAT-CE-013 | The platform's observability system shall scale to support monitoring of at least 1000 application nodes. | Scalability of the observability system is critical to support large-scale deployments and accommodate growth in customer applications and infrastructure without performance degradation. | |
| Application Platform | Customer Enablement | ADCP-PLAT-CE-014 | The platform shall provide enablement resources to facilitate application onboarding. | Onboarding enablement resources simplify and accelerate the process for customers to deploy new applications onto the platform, reducing time-to-market and easing adoption. | |
| Application Platform | Customer Enablement | ADCP-PLAT-CE-016 | The platform shall support continuous data synchronization and replication for databases. | Continuous synchronization and replication for databases ensure data consistency, high availability, and disaster recovery capabilities for critical application data. |
This is the start of the file's text. The full file is on GovTribe.
File details come from the government source that posted it. Updated .