PWS - Infrastructure as a Managed Service DRAFT.docx
DOCX document 210 KB Posted
- Attached to
- DA01--Infrastructure as a Managed Service (IaaMS) Federal contract opportunity
- Solicitation number
- 36C10B21R0001
About this file
This is a draft performance work statement for an infrastructure as a managed service. The Department of Veterans Affairs seeks a solution for storage and compute infrastructure across its facilities, to replace existing platforms reaching end of life. Required are project management, solution design and security requirements, capacity and redundancy, and operations and maintenance. The solution will initially deploy a Veterans Health Information Systems and Technology Architecture imaging storage system to 158 facilities. Additional file, block and object storage may be added through optional tasks. Pricing will be monthly per terabyte of storage used. The response deadline is November 4, 2020.
View the file
Other files for this federal contract opportunity
| File | Type | Posted |
|---|---|---|
| 36C10B21R0001_1.docx | DOCX document | |
| 36C10B21R0001_2.docx | DOCX document | |
| Attachment B - IaaMS Solution Infrastructure Requirements DRAFT.docx | DOCX document | |
| Attachment A - Facility-Specific Quantities Capacities and Locations DRAFT.xlsx | XLSX spreadsheet | |
| Price Schedule IaaMS - DRAFT.docx | DOCX document | |
| 36C10B21R0001.docx | DOCX document | |
| Attachment C _ IaaMS Storage Modeling Requirements DRAFT.docx | DOCX document | |
| Attachment 0001 - IaaMS Price Evaluation Spreadsheet DRAFT.xlsx | XLSX spreadsheet | |
| DRAFT 36C10B20R0025 Cover Page - IaaMS.docx | DOCX document |
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
Infrastructure as a Managed Service
VA-20-00031010
PERFORMANCE WORK STATEMENT (PWS)
DEPARTMENT OF VETERANS AFFAIRS
Office of Information & Technology Solution Delivery
Infrastructure as a Managed Service (IaaMS)
Date: October 16, 2020
VA-20-00062767
PWS Version Number: 1.16
Contents
| 1.0 | BACKGROUND | 5 |
| 2.0 | APPLICABLE DOCUMENTS | 5 |
| 3.0 | SCOPE OF WORK | 9 |
| 3.1 | CONTRACT TYPE | 10 |
| 3.2 | RIGHTS IN DOCUMENTATION AND COMPUTER SOFTWARE | 10 |
| 4.0 | PERFORMANCE DETAILS | 10 |
| 4.1 | PERFORMANCE PERIOD | 10 |
| 4.2 | PLACE OF PERFORMANCE | 11 |
| 4.3 | TRAVEL | 11 |
| 5.0 | SPECIFIC TASKS AND DELIVERABLES | 12 |
| 5.1 | PROJECT MANAGEMENT | 12 |
| 5.1.1 | CONTRACTOR PROJECT MANAGEMENT PLAN | 12 |
| 5.1.2 | TECHNICAL KICK-OFF MEETING | 12 |
| 5.1.3 | REPORTING REQUIREMENTS | 13 |
| 5.1.4 | VA MANDATORY TRAINING | 14 |
| 5.1.5 | ONBOARDING | 15 |
| 5.2 | IaaMS SOLUTION REQUIREMENTS | 16 |
| 5.2.1 | STORAGE RESOURCE MANAGEMENT (SRM) | 16 |
| 5.2.2 | IaaMS SOLUTION SECURITY REQUIREMENTS | 17 |
| 5.2.2.1 | ENCRYPTION | 17 |
| 5.2.2.2 | ROLE-BASED ACCESS CONTROL | 17 |
| 5.2.2.3 | MULTIFACTOR AUTHENTICATION | 17 |
| 5.2.2.4 | KEY MANAGEMENT | 17 |
| 5.2.2.5 | STORAGE MEDIA RETENTION | 18 |
| 5.2.2.6 | OPERATING ENVIRONMENT | 18 |
| 5.2.3 | IaaMS CAPACITY REQUIREMENTS | 18 |
| 5.2.3.1 | DATA EFFICIENCY | 18 |
| 5.2.4 | IaaMS DATA STORAGE REDUNDANCY REQUIREMENTS | 19 |
| 5.3 | IaaMS VI SOLUTION REQUIREMENTS | 19 |
| 5.3.1 | VI STORAGE | 21 |
| 5.3.1.1 | SERVER MESSAGE BLOCK | 21 |
| 5.3.1.2 | NAMESPACE | 21 |
| 5.3.1.3 | CAPACITY | 21 |
| 5.3.1.4 | VI DATA EFFICIENCY | 22 |
| 5.3.1.5 | PERFORMANCE | 22 |
| 5.3.1.6 | REDUNDANCY | 22 |
| 5.3.1.7 | DATA INTEGRITY | 22 |
| 5.3.2.1 | DATA MIGRATION | 23 |
| 5.3.3 | VI CLOUD DISASTER RECOVERY REPOSITORY | 24 |
| 5.3.3.1 | CLOUD REPORTING | 26 |
| 5.3.4 | INFORMATION LIFECYCLE MANAGEMENT | 27 |
| 5.3.5 | RECOVERALL | 27 |
| 5.4 | LAB SYSTEM | 28 |
| 5.4.1 | VI - LAB SYSTEM | 29 |
| 5.5 | IaaMS SOLUTION INSTALLATION, IMPLEMENTATION, CONFIGURATION REQUIERMENTS | 29 |
| 5.5.1 | IaaMS SITE READINESS ACTIVITY | 29 |
| 5.5.2 | SHIPPING | 30 |
| 5.5.3 | INSTALLATION | 30 |
| 5.6 | IaaMS OPERATIONS & MAINTENANCE REQUIREMENTS | 31 |
| 5.6.1 | MAINTENANCE SUPPORT | 32 |
| 5.6.1.1 | ORIGINAL EQUIPMENT MANUFACTURER SUPPORT | 32 |
| 5.6.1.2 | SOFTWARE UPGRADES | 32 |
| 5.6.1.3 | PLANNED MAINTENANCE ACTIVITIES | 33 |
| 5.6.1.4 | VI CLOUD DISASTER RECOVERY REPOSITORY MAINTENANCE | 33 |
| 5.6.2 | IAAMS SERVICE LEVEL AGREEMENTS (SLA) | 34 |
| 5.6.2.1 | UPTIME | 34 |
| 5.6.2.2 | STORAGE | 34 |
| 5.6.2.3 | DATA AVAILABILITY | 34 |
| 5.6.2.4 | UNPLANNED OUTAGES | 35 |
| 5.6.2.5 | FAILED HARDWARE | 36 |
| 5.6.2.6 | STORAGE RESOURCE MANAGEMENT PERFORMANCE | 36 |
| 5.6.3 | AUTHORITY TO OPERATE (ATO) | 36 |
| 5.6.4 | CATASTROPHIC FACILITY RECOVERY | 37 |
| 5.7 | TECHNOLOGY REFRESH | 38 |
| 5.8 | IaaMS PRICE AND BILLING REQUIREMENTS | 39 |
| 5.9 | TRAINING | 40 |
| 5.10 | OPTIONAL TASKs – STORAGE CAPACITY | 41 |
| 5.10.1 | HIGH PERFORMANCE FILE STORAGE – MINIMALLY MANAGED | 41 |
| 5.10.2 | HIGH PERFORMANCE BLOCK STORAGE – MINIMALLY MANAGED | 41 |
| 5.10.3 | HIGH PERFORMANCE OBJECT STORAGE – MINIMALLY MANAGED | 41 |
| 5.10.4 | MIXED PERFORMANCE/CAPACITY FILE STORAGE – MINIMALLY MANAGED | 42 |
| 5.10.5 | MIXED PERFORMANCE/CAPACITY BLOCK STORAGE – MINIMALLY MANAGED | 42 |
| 5.10.6 | MIXED PERFORMANCE/CAPACITY OBJECT STORAGE – MINIMALLY MANAGED | 42 |
| 5.10.7 | HIGH CAPACITY FILE STORAGE – MINIMALLY MANAGED | 42 |
| 5.10.8 | HIGH CAPACITY BLOCK STORAGE – MINIMALLY MANAGED | 42 |
| 5.10.9 | HIGH CAPACITY OBJECT STORAGE – MINIMALLY MANAGED | 43 |
| 5.10.10 | HIGH PERFORMANCE FILE STORAGE – FULLY MANAGED | 43 |
| 5.10.11 | HIGH PERFORMANCE BLOCK STORAGE – FULLY MANAGED | 43 |
| 5.10.12 | HIGH PERFORMANCE OBJECT STORAGE – FULLY MANAGED | 43 |
| 5.10.13 | MIXED PERFORMANCE/CAPACITY FILE STORAGE – FULLY MANAGED | 43 |
| 5.10.14 | MIXED PERFORMANCE/CAPACITY BLOCK STORAGE – FULLY MANAGED | 44 |
| 5.10.15 | MIXED PERFORMANCE/CAPACITY OBJECT STORAGE – FULLY MANAGED | 44 |
| 5.10.16 | HIGH CAPACITY FILE STORAGE – FULLY MANAGED | 44 |
| 5.10.17 | HIGH CAPACITY BLOCK STORAGE – FULLY MANAGED | 44 |
| 5.10.18 | HIGH CAPACITY OBJECT STORAGE – FULLY MANAGED | 44 |
| 5.10.19 | HIGH PERFORMANCE BACKUP STORAGE – MINIMALLY MANAGED | 45 |
| 5.10.20 | MIXED PERFORMANCE/CAPACITY BACKUP STORAGE – MINIMALLY MANAGED | 45 |
| 5.10.21 | HIGH CAPACITY BACKUP STORAGE – MINIMALLY MANAGED | 45 |
| 5.11 | OPTIONAL TASK – HYPERCONVERGED COMPUTE FOUNDATION | 45 |
| 5.11.1 | Base Compute Requirements | 46 |
| 5.11.2 | Hyperconverged Compute Foundation Workload Requirements | 47 |
| 5.11.3 | Hyperconverged Compute Foundation Interconnectivity Requirements | 48 |
| 5.11.4 | Compute Hosted Storage Workloads | 48 |
| 5.11.5 | Security | 48 |
| 5.11.6 | Management | 48 |
| 5.12 | OPTIONAL TASK – HYPERCONVERGED COMPUTE NODE EXPANSION | 49 |
| 5.13 | OPTIONAL TASK – CONVERGED COMPUTE FOUNDATION | 49 |
| 5.14 | OPTIONAL TASK – CONVERGED COMPUTE NODE EXPANSION | 51 |
| 5.15 | OPTIONAL TASK – AD HOC PROFESSIONAL SERVICES | 51 |
| Contractor is responsible to perform all professional services required to perform PWS tasks set forth in PWS Sections 5.2 through 5.14 and PWS Section 5.16 Transition Support. VA may require additional Professional Services from the Contractor to plan and execute operational changes, including but not limited to site preparation support, network modifications, and system integration. Professional services shall be made available within seven calendar days of exercise of the option. . | 51 | |
| 5.16 | OPTIONAL TASK – CONTRACT TRANSITION | 52 |
| 5.16.1 | TRANSITION-OUT PLAN | 52 |
| 5.16.2 | TRANSITION-OUT SERVICES | 53 |
| 6.0 | General Requirements | 55 |
| 6.1 | Enterprise and IT Framework | 55 |
| 6.2 | Security and Privacy Requirements | 57 |
| 6.2.1 | Position/Task Risk Designation Level(s) | 57 |
| 6.2.1.1 | Contractor Personnel Security Requirements | 58 |
| 6.3 | Method and Distribution of Deliverables | 60 |
| 6.4 | Performance Metrics | 60 |
| 6.5 | Facility/Resource Provisions | 61 |
| 6.6 | GOVERNMENT FURNISHED PROPERTY | 62 |
| 6.7 | Shipment of Hardware or Equipment | 63 |
| 6.8 | POINTS OF CONTACT | 64 |
| ADDENDUM A – ADDITIONAL VA REQUIREMENTS, CONSOLIDATED | 66 | |
| Addendum B – VA Information and Information System Security/Privacy Language | 73 |
BACKGROUND
The mission of the Department of Veterans Affairs (VA), Office of Information & Technology (OIT), IT Operations and Services (ITOPS) is to provide world-class information technology (IT) solutions that enable timely and accurate delivery of healthcare and benefits to the nation’s veterans.
VA seeks an Infrastructure as a Managed Service (IaaMS) solution for storage and compute infrastructure at facilities across the United States and abroad. The IaaMS solution consists of all hardware, software, and services provided in response to this PWS and shall be utilized to replace existing storage and compute platforms as they reach end of life (EOL) status. IaaMS will deploy storage and compute infrastructure when and where it is needed. The contract will be leveraged to move VA toward a standardized service delivery model that eliminates application-specific infrastructure silos, leverages cloud-based storage capabilities, and implements industry best practices for storage in geographically dispersed facilities.
In tandem with on-premises hardware, VA intends to use cloud-based storage and compute resources to meet offsite storage requirements. The VA Enterprise Cloud (VAEC) was established by the Enterprise Cloud Solutions Office (ECSO) in 2017, to host cloud computing solutions. In November 2018, VA issued the Cloud First Policy mandating that all new and existing IT solutions be assessed to determine suitability to be offered as an enterprise cloud computing service. The Contractor shall provide on-premises compute and storage hardware for functions the VA determines must remain on-site. The Contractor shall utilize the VAEC for offsite backup and disaster recovery functions.
The IaaMS solution shall initially deploy a Veterans Health Information Systems and Technology Architecture (VistA) Imaging (VI) storage systems solution to 158 VA facilities as detailed in Attachment A – VI Facility-Specific Quantities, Capacities, and Locations. Following the VI initial deployment, it is anticipated that the IaaMS solution for VI shall expand by an additional 220+ petabytes (PB) of capacity over the Period of Performance (POP). Expansion shall be provided via optional tasks for file, block, and object storage using both minimally managed and fully managed services and presented using a variety of storage performance tiers. The IaaMS solution may deploy new compute and storage requirements at up to 300 total VA facilities during the POP.
APPLICABLE DOCUMENTS
In the performance of the tasks associated with this Performance Work Statement (PWS), the Contractor shall comply with the following:
1. 44 U.S.C. § 3541, “Federal Information Security Management Act (FISMA) of 2002”
2. Federal Information Processing Standards (FIPS) Publication 140-2, “Security Requirements for Cryptographic Modules”
3. FIPS Pub 201-2, “Personal Identity Verification of Federal Employees and Contractors,” August 2013
4. 10 U.S.C. § 2224, "Defense Information Assurance Program"
5. Carnegie Mellon Software Engineering Institute, Capability Maturity Model® Integration for Development (CMMI-DEV), Version 1.3 November 2010; and Carnegie Mellon Software Engineering Institute, Capability Maturity Model® Integration for Acquisition (CMMI-ACQ), Version 1.3 November 2010
6. 5 U.S.C. § 552a, as amended, “The Privacy Act of 1974”
7. 42 U.S.C. § 2000d “Title VI of the Civil Rights Act of 1964”
8. VA Directive 0710, “Personnel Suitability and Security Program,” June 4, 2010, http://www.va.gov/vapubs/
9. VA Handbook 0710, Personnel Suitability and Security Program, September 10, 2004, http://www.va.gov/vapubs
10. VA Directive and Handbook 6102, “Internet/Intranet Services,” July 15, 2008
11. 36 C.F.R. Part 1194 “Electronic and Information Technology Accessibility Standards,” July 1, 2003
12. Office of Management and Budget (OMB) Circular A-130, “Management of Federal Information Resources,” November 28, 2000
13. 32 C.F.R. Part 199, “Civilian Health and Medical Program of the Uniformed Services (CHAMPUS)”
14. An Introductory Resource Guide for Implementing the Health Insurance Portability and Accountability Act (HIPAA) Security Rule, October 2008
15. Sections 504 and 508 of the Rehabilitation Act (29 U.S.C. § 794d), as amended by the Workforce Investment Act of 1998 (P.L. 105-220), August 7, 1998
16. Homeland Security Presidential Directive (12) (HSPD-12), August 27, 2004
17. VA Directive 6500, “Managing Information Security Risk: VA Information Security Program,” September 20, 2012
18. VA Handbook 6500, “Risk Management Framework for VA Information Systems – Tier 3: VA Information Security Program,” March 10, 2015
19. VA Handbook 6500.1, “Electronic Media Sanitization,” November 03, 2008
20. VA Handbook 6500.2, “Management of Breaches Involving Sensitive Personal Information (SPI)”, October 28, 2015
21. VA Handbook 6500.3, “Assessment, Authorization, And Continuous Monitoring of VA Information Systems,” February 3, 2014
22. VA Handbook 6500.5, “Incorporating Security and Privacy in System Development Lifecycle”, March 22, 2010
23. VA Handbook 6500.6, “Contract Security,” March 12, 2010
24. VA Handbook 6500.8, “Information System Contingency Planning”, April 6, 2011
25. Project Management Accountability System (PMAS) portal (reference https://www.voa.va.gov/pmas/)
26. OI&T ProPath Process Methodology (reference process maps at http://www.va.gov/PROPATH/Maps.asp and templates at http://www.va.gov/PROPATH/Templates.asp
27. One-VA Technical Reference Model (TRM) (reference at http://www.va.gov/trm/TRMHomePage.asp)
28. National Institute Standards and Technology (NIST) Special Publications (SP)
29. VA Directive 6508, Implementation of Privacy Threshold Analysis and Privacy Impact Assessment, October 15, 2014
30. VA Directive 6300, Records and Information Management, February 26, 2009
31. VA Handbook, 6300.1, Records Management Procedures, March 24, 2010
32. OMB Memorandum, “Transition to IPv6”, September 28, 2010
33. VA Directive 0735, Homeland Security Presidential Directive 12 (HSPD-12) Program, February 17, 2011
34. VA Handbook 0735, Homeland Security Presidential Directive 12 (HSPD-12) Program, March 20, 2014
35. OMB Memorandum M-06-18, Acquisition of Products and Services for Implementation of HSPD-12, June 30, 2006
36. OMB Memorandum 05-24, Implementation of Homeland Security Presidential Directive (HSPD) 12 – Policy for a Common Identification Standard for Federal Employees and Contractors, August 5, 2005
37. OMB memorandum M-11-11, “Continued Implementation of Homeland Security Presidential Directive (HSPD) 12 – Policy for a Common Identification Standard for Federal Employees and Contractors, February 3, 2011
38. OMB Memorandum, Guidance for Homeland Security Presidential Directive (HSPD) 12 Implementation, May 23, 2008
39. Federal Identity, Credential, and Access Management (FICAM) Roadmap and Implementation Guidance, December 2, 2011
40. NIST SP 800-116, A Recommendation for the Use of Personal Identity Verification (PIV) Credentials in Physical Access Control Systems, November 20, 2008
41. OMB Memorandum M-07-16, Safeguarding Against and Responding to the Breach of Personally Identifiable Information, May 22, 2007
42. NIST SP 800-63-2, Electronic Authentication Guideline, August 2013
43. Draft NIST Special Publication 800-157, Guidelines for Derived PIV Credentials, March 2014
44. NIST Special Publication 800-164, Guidelines on Hardware-Rooted Security in Mobile Devices (Draft), October 2012
45. Draft National Institute of Standards and Technology Interagency Report (NISTIR) 7981 Mobile, PIV, and Authentication, March 2014
46. VA Memorandum, VAIQ #7100147, Continued Implementation of Homeland Security Presidential Directive 12 (HSPD-12), April 29, 2011 (reference https://www.voa.va.gov/documentlistpublic.aspx?NodeID=514)
47. VA Memorandum, VAIQ # 7011145, VA Identity Management Policy, June 28, 2010 (reference Enterprise Architecture Section, PIV/IAM (reference https://www.voa.va.gov/documentlistpublic.aspx?NodeID=514)
48. IAM Identity Management Business Requirements Guidance document, May 2013, (reference Enterprise Architecture Section, PIV/IAM (reference https://www.voa.va.gov/documentlistpublic.aspx?NodeID=514)
49. Trusted Internet Connections (TIC) Reference Architecture Document, Version 2.0, Federal Interagency Technical Reference Architectures, Department of Homeland Security, October 1, 2013, https://www.fedramp.gov/files/2015/04/TIC_Ref_Arch_v2-0_2013.pdf
50. OMB Memorandum M-08-05, “Implementation of Trusted Internet Connections (TIC), November 20, 2007
51. OMB Memorandum M-08-23, Securing the Federal Government’s Domain Name System Infrastructure, August 22, 2008
52. VA Memorandum, VAIQ #7497987, Compliance – Electronic Product Environmental Assessment Tool (EPEAT) – IT Electronic Equipment, August 11, 2014 (reference Document Libraries, EPEAT/Green Purchasing Section, https://www.voa.va.gov/documentlistpublic.aspx?NodeID=552)
53. Sections 524 and 525 of the Energy Independence and Security Act of 2007, (Public Law 110–140), December 19, 2007
54. Section 104 of the Energy Policy Act of 2005, (Public Law 109–58), August 8, 2005
55. Executive Order 13693, “Planning for Federal Sustainability in the Next Decade”, dated March 19, 2015
56. Executive Order 13221, “Energy-Efficient Standby Power Devices,” August 2, 2001
57. VA Directive 0058, “VA Green Purchasing Program”, July 19, 2013
58. VA Handbook 0058, “VA Green Purchasing Program”, July 19, 2013
59. Office of Information Security (OIS) VAIQ #7424808 Memorandum, “Remote Access”, January 15, 2014, https://www.voa.va.gov/DocumentListPublic.aspx?NodeId=28
60. Clinger-Cohen Act of 1996, 40 U.S.C. §11101 and §11103
61. VA Directive 6071, Project Management Accountability System (PMAS), February 20, 2013
62. VA Memorandum, “Implementation of Federal Personal Identity Verification (PIV) Credentials for Federal and Contractor Access to VA IT Systems”, (VAIQ# 7614373) July 9, 2015, https://www.voa.va.gov/DocumentListPublic.aspx?NodeId=28
63. VA Memorandum “Mandatory Use of PIV Multifactor Authentication to VA Information System” (VAIQ# 7613595), June 30, 2015, https://www.voa.va.gov/DocumentListPublic.aspx?NodeId=28
64. VA Memorandum “Mandatory Use of PIV Multifactor Authentication for Users with Elevated Privileges” (VAIQ# 7613597), June 30, 2015; https://www.voa.va.gov/DocumentListPublic.aspx?NodeId=28
65. “Veteran Focused Integration Process Guide 1.0”, December, 2015, https://vaww.oit.va.gov/wp-content/uploads/2016/01/VIP_Guide_1_0_v14.pdf
66. “VIP Release Process Guide”, Version 1.0, December 2015, https://www.voa.va.gov/DocumentView.aspx?DocumentID=4411
67. “POLARIS User Guide”, Version 1.2, February 2016, https://www.voa.va.gov/DocumentView.aspx?DocumentID=4412
68. VA Enterprise Cloud Technical Reference Guide, version 1.3, July 2018, https://www.vendorportal.ecms.va.gov/FBODocumentServer/DocumentServer.aspx?DocumentId=4701399&FileName=36C10B19R0006-001.pdf
69. VA Infrastructure Standard for Telecommunications Spaces, https://www.cfm.va.gov/til/dguide/OIT-InfrastrucStdsTelecommSpaces.pdf
70. VA OIT Design Guide Templates, https://www.cfm.va.gov/til/dGuide/OIT-DGTemplates-CriticalTelecommSpaces.pdf
71. ANSI/TIA-607-C, Generic Telecommunications Bonding and Grounding (Earthing) for Customer Premises
72. NIST 800-34 Rev. 1 – Contingency Planning Guide for Federal Information Systems, https://nvlpubs.nist.gov/nistpubs/Legacy/SP/nistspecialpublication800-34r1.pdf
73. NIST 800-53 Rev. 4 – Security and Privacy Controls for Federal Information Systems and Organizations, https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf
74. Information Technology Standards (INCITS) 359-2012 Role-Based Access Control (RBAC), https://standards.incits.org/apps/group_public/project/details.php?project_id=1658
75. Code of Federal Regulations (CFR), Title 21, Part 820, https://www.accessdata.fda.gov/scripts/cdrh/cfdocs/cfcfr/CFRSearch.cfm?CFRPart=820
76. VA Records Control Schedule 10-1, Page III-6-1 (142), January 2019
77. U.S. Department of Veterans Affairs Seismic Zone Map, November 1, 2016, https://www.cfm.va.gov/til/etc/seismicmap.pdf
78. Oasis Key Management Interoperability Protocol Specification Version 2.0, https://docs.oasis-open.org/kmip/kmip-spec/v2.0/os/kmip-spec-v2.0-os.html
SCOPE OF WORK
The Contractor shall provide an IaaMS solution for storage and compute infrastructure at facilities across the United States and abroad. The IaaMS solution includes all hardware, software, and services to perform the requirements under this PWS and attachments, specifically project management; solution requirements; VI requirements; lab system; installation, implementation, and configuration; Operations & Maintenance (O&M), technology refresh, price and billing services, and training. Contractor through VA exercise of optional tasks shall replace existing storage and compute platforms as they reach end of life (EOL) status in all VA facilities.
The Contractor shall initially deploy an IaaMS VI solution to 158 VA facilities as detailed in Attachment A – VI Facility-Specific Quantities, Capacities, and Locations. The Contractor shall perform data migration activities for all VI data currently stored on legacy architecture to the on-premises IaaMS solution and off-premises IaaMS VI cloud disaster recovery repository. The Contractor shall provide all licensing and professional services required to implement a VI cloud disaster recovery repository hosted within the VAEC AWS GovCloud or Azure Government environments. The Contractor shall not be responsible for providing or acquiring cloud-based compute or storage capacity for this contract. VA will furnish VAEC capacity as Government Furnished Equipment (GFE).
The Contractor shall provide additional file, block, and object storage using both minimally managed and fully managed services (terms are defined in Attachment XXX) presented using a variety of storage performance tiers through optional tasks. The Contractor shall provision converged and hyperconverged foundation architectures and compute nodes through optional tasks. This effort also includes optional tasks for ad-hoc professional services and contract transition.
CONTRACT TYPE
The effort is a hybrid Firm-Fixed-Price (FFP) and Labor-Hour contract.
RIGHTS IN DOCUMENTATION AND COMPUTER SOFTWARE
The Contractor is required to deliver technical data, configurations, documentation, including but not limited to all training materials or other information first produced or created for VA, during contract performance in accordance with the Deliverables set forth herein. The Government shall receive Unlimited Rights in intellectual property first produced and delivered in the performance of this contract in accordance with FAR 52.227-14, Rights In Data-General (MAY 2014). This includes all rights to any and all documentation created in support thereof. License rights in any Commercial Computer Software shall be governed by FAR 52.227-19, Commercial Computer Software License (DEC 2007).
PERFORMANCE DETAILS
PERFORMANCE PERIOD
The Period of Performance (POP) shall be a 12-month base period and six 12-month option periods.
The IaaMS VI initial deployment delivery, installation, and configuration shall be completed within seven months of award at all 158 sites, as detailed in Attachment A – VI Facility-Specific Quantities, Capacities, and Locations. All data migration of the IaaMS VI initial deployment shall be completed within 12 months from award at all 158 sites, as detailed in Attachment A – VI Facility-Specific Quantities, Capacities, and Locations.
Any IaaMS solution implementation exercised via optional tasks under this contract shall be delivered, installed, and configured within six months of option exercise. These optional tasks may be exercised at any time during the period of performance. However, VA will not exercise any optional task requiring on-site implementation within six months of the end of the final option period.
Scheduling of all installations shall be coordinated by the Contractor with the VA Program Manager (PM) and Contracting Officer's Representative (COR) and site Points of Contact (POCs). VA will identify individual POCs for each facility prior to commencing work at each location.
Any onsite work at the Government site shall not take place on Federal holidays or weekends unless approved by the Contracting Officer (CO). The CO may designate the Contractor to work during holidays and weekends.
There are 10 Federal holidays set by law (USC Title 5 Section 6103) that VA follows:
Under current definitions, four are set by date:
| New Year's Day | January 1 |
| Independence Day | July 4 |
| Veterans Day | November 11 |
| Christmas Day | December 25 |
If any of the above falls on a Saturday, then Friday shall be observed as a holiday. Similarly, if one falls on a Sunday, then Monday shall be observed as a holiday.
The other six are set by a day of the week and month:
| Martin Luther King's Birthday | Third Monday in January | |||
| Washington's Birthday | Third Monday in February | |||
| Memorial Day | Last Monday in May | |||
| Labor Day | First Monday in September | |||
| Columbus Day | Second Monday in October | |||
| Thanksgiving | Fourth Thursday in November |
PLACE OF PERFORMANCE
Tasks under this PWS shall be performed both off-site at Contractor facilities and on-site at VA facilities. The IaaMS solution is expected to be deployed at a maximum of 300 sites across VA, both in the United States and abroad. The initial IaaMS VI deployment shall be implemented at 158 specific facilities specified in Attachment A – VI Facility-Specific Quantities, Capacities, and Locations. Additional VA facilities may be added by VA as needed throughout the PO P by exercising contract optional tasks. Software configuration and data migration work may be performed at remote locations with prior approval of the PM, COR, Principal Architect (PA) or designee.
TRAVEL
The Government anticipates travel to perform the tasks associated with this effort and travel will be required throughout the period of performance. The Contractor shall include all estimated travel costs in its firm-fixed price line items. Travel costs will not be directly reimbursed by the Government.
SPECIFIC TASKS AND DELIVERABLES
All IaaMS solution performance, utility, reliability, and security requirements shall be met simultaneously. None of the features required to meet any specification below may be disabled, suspended, or otherwise altered to meet the performance, reliability, or utility requirements within this PWS.
The Contractor shall perform the following:
PROJECT MANAGEMENT
The Contractor shall oversee all aspects of the execution of this PWS. The Contractor shall provide a single dedicated primary and direct POC to serve as Contractor project manager throughout the POP. VA may provide the Contractor with remote access to the VA network. The Contractor shall coordinate with VA to gain and maintain remote access to the VA network.
CONTRACTOR PROJECT MANAGEMENT PLAN
The Contractor shall deliver within seven (7) business days after award a Contractor Project Management Plan (CPMP) that lays out the Contractor’s approach, timeline and tools to be used in execution of the contract. The CPMP shall take the form of both a narrative and graphic format that displays the schedule, milestones, risks and resource support. The CPMP shall also include how the Contractor shall coordinate and execute planned, routine, and ad hoc data collection reporting requests as identified within the PWS. The initial baseline CPMP shall be concurred upon by VA and updated in accordance with Section B of the contract. The Contractor shall update and maintain the PM approved CPMP monthly throughout the POP. The Contractor shall directly upload the CPMP and any required updates to a VA-provided SharePoint library.
Deliverables:
A. Contractor Project Management Plan
TECHNICAL KICK-OFF MEETING
A technical kickoff meeting shall be held within 10 business days after award. The Contractor shall coordinate the date, time, and location (can be virtual) with the Contracting Officer (CO), as the Post-Award Conference Chairperson, the VA PM, as the Co-Chairperson, the Contract Specialist (CS), and the COR. Key Contractor personnel involved in designing and managing the procured solutions shall be introduced to the VA COR, Principal Architect (PA) and PM at this time. A review of the contract deliverables and timetables shall occur. The Contractor shall provide a draft agenda to the CO and VA PM at least two calendar days prior to the meeting. Upon Government approval of a final agenda, the Contractor shall distribute to all meeting attendees. During the kickoff-meeting, the Contractor shall present for review and approval by the Government, the details of the intended approach, work plan, and project schedule for each effort via a Microsoft Office PowerPoint presentation. At the conclusion of the meeting, the Contractor shall update the presentation with a final slide entitled “Summary Report” which shall include notes on any major issues, agreements, or disagreements discussed during the kickoff meeting and the following statement “As the Post-Award Conference Chairperson, I have reviewed the entirety of this presentation and assert that it is an accurate representation and summary of the discussions held during the Technical Kickoff Meeting for IaaMS.” The Contractor shall submit the final updated presentation to the CO for review and signature within three calendar days after the meeting. The Contractor shall also work with CS to prepare and distribute the meeting minutes of the kickoff meeting to the CO, COR and all attendees within three calendar days after the meeting. The Contractor shall obtain concurrence from the CS on the content of the meeting minutes prior to distribution of the document.
Deliverables:
A. Technical Kick-Off Agenda B. Technical Kick-Off Meeting Minutes
REPORTING REQUIREMENTS
The Contractor shall conduct recurring calls every week with the VA PA, COR, and PM beginning one week after the Kickoff Meeting and continuing throughout the POP. Regularly scheduled calls may be cancelled at VA’s discretion in the event there are no IaaMS deployments taking place. Additionally, ad hoc meetings may be requested by VA on an as-needed basis. The Contractor shall provide Recurring Meeting Minutes within three business days after each meeting to the PA, COR, and PM.
The Contractor shall provide the PA, COR, and PM with Weekly Progress Reports in electronic form in Microsoft Word or Project format delivered via electronic mail during any equipment procurement, installation, configuration, and testing periods. The Contractor shall directly upload a copy of the Weekly Progress Reports to a VA-provided SharePoint library. The Reports shall include detailed explanations for each topic the Contractor includes in the Weekly Progress Report or that is requested by the PA, COR, or PM to be included in the Report, to ensure that Weekly Progress Report is an accurate reflection of the current state of the Contract. These reports shall reflect data as of the last day of the preceding week. VA may provide, at its sole discretion, a template that shall be used by the Contractor for the Weekly Progress Report.
The Weekly Progress Reports shall cover all work completed during the reporting period and work planned for the subsequent two reporting periods. The Report shall also identify any problems that arose and a description of how the problems were resolved. If problems have not been completely resolved, the Contractor shall provide an explanation including its plan and timeframe for resolving the issue. The Contractor shall monitor performance against the CPMP and report any deviations. The Contractor shall establish and maintain open communication with VA to prevent escalation of outstanding issues.
The Weekly Progress Report shall include at a minimum the following:
1. List of sites completed.
2. Network addresses, subnet masks, and gateways for any network interfaces configured.
3. List of outstanding issues for in-progress sites, including the estimated date of resolution for each issue.
4. Estimated installation dates for sites that have not been completed.
The Weekly Progress Report shall be delivered no later than 12:00pm ET each Friday.
The Contractor shall prepare a Monthly Program Management Review (PMR), to be distributed on the last weekly status meeting of the month that documents the activities and achievements in the prior month and the planned activities, milestones, and deliverables due for the following month. The PMR report shall document any problems or unresolved issues that may impact schedule.
The Contractor shall prepare a PMR Report format for Government review, and upon Government concurrence, deliver the PMR Report. The PMR Report shall outline primary activities conducted by the contractor for each reporting period. The PMR Report shall measure the Contractor's schedule performance using a format mutually agreed upon by the Government and the Contractor.
Deliverables:
A. Recurring Meeting Minutes B. Weekly Progress Report C. Project Management Review Report
VA MANDATORY TRAINING
The Contractor and VA Project Manager (PM) shall determine which team members require access to the VA network and Rational Tool Set (Rational). All Contractor personnel that require access to the VA network and Rational Tool Set shall complete all the required VA Talent Management System (TMS) training courses within fourteen (14) calendar days of the identification of the access need. The Contractor shall work with its respective point of contact to obtain access to TMS to complete the mandatory training courses.
As an action under the Continuous Readiness in Information Security Program (CRISP), VA's Assistant Secretary for Information and Technology issued a memorandum requiring all VA government and contract staff to complete information security awareness and applicable role-based training. The Contractor shall submit Talent Management System (TMS) Training Certificates of completion for VA Privacy and Information Security Awareness (PISA), Rules of Behavior (ROB), Health Insurance Portability and Accountability Act (HIPAA), and Role-Based trainings. The Contractor shall provide signed copies of the Contractor Rules of Behavior in accordance with Section 9, Training, from Appendix C of the VA Handbook 6500.6, “Contract Security”.
The Contractor shall complete the following VA TMS training courses for all contractors with required access to Rational:
1. TMS ID 3878248 - IBM Rational Team Concert - Agile Sprint, Configuration/Change Management Level 1
2. TMS ID 3878249 - IBM Rational Team Concert - Agile Sprint, Configuration /Change Management Level 2
3. TMS ID 3878250 - IBM Rational DOORS Next Generation - Requirements Management Level 1
4. TMS ID 3897036 - IBM Rational DOORS Next Generation - Requirements Management Level 2
5. TMS ID 3897034 - IBM Rational Quality Manager - Quality Management Level 1
6. TMS ID 3897035 - IBM Rational Quality Manager - Quality Management Level 2
Contractors who have completed these VA training courses within the past 12 or 24 months, depending on the training requirements, and have furnished training certificates to VA, will not be required to re-take the training courses.
Deliverables:
A. TMS Training Certificates for all mandatory training courses B. Signed Contractor Rules of Behavior
ONBOARDING
In addition to the requirements set forth in 6.2.1.1, the Contractor shall manage the onboarding of its staff. Onboarding includes steps to obtain a VA Personal Identity Verification (PIV) card, network and email account, complete training, initiate background investigations, and gain physical and logical access. Note that, where required by VA, background investigations are expected to take between one and three months to complete. In addition, the Contractor shall identify individuals which may require elevated privileges to the necessary development and test environments for the various systems to be enhanced. After review between the Contractor and VA COR, a decision will be made as to the necessity of obtaining GFE for the onboarding staff. If approved, Contractor shall follow the appropriate steps to obtain the equipment.
A single Contractor Onboarding POC shall be designated by the Contractor that tracks the onboarding status of all Contractor personnel. The Contractor Onboarding POC shall be responsible for accurate and timely submission of all required VA onboarding paperwork to the VA COR. The Contractor shall be responsible for tracking the status of all its staff’s onboarding activities to include the names of all personnel engaged on the task, their initial training date for VA Privacy and Information Security training, and their next required training date. The Contractor Onboarding POC shall also report the status at the staff level during onboarding status meetings. The Contractor shall provide an Onboarding Status Report weekly for any staff with outstanding onboarding requests for review by the COR and PM.
The Contractor’s project manager shall obtain remote access to the VA network. During the technical kickoff meeting, the Contractor shall provide the name of the Contractor’s project manager and begin the process of obtaining Homeland Security Presidential Directive 12 (HSPD-12) PIV credentials. All Contractor staff that are required to obtain an HSPD-12 PIV credential shall submit an application to VA within 10 calendar days of award.
Deliverables:
A. Weekly Onboarding Status Report B. HSPD-12 PIV Application
IaaMS SOLUTION REQUIREMENTS The IaaMS solution consists of all hardware, software, and services delivered in accordance with (IAW) this PWS. The Contractor shall deliver all infrastructure including but not limited to, hardware, software, tools, cables, and materials, required for a fully functional implementation of the IaaMS solution to all VA facilities. The Contractor shall support VA certification testing of the IaaMS solution to ensure the solution meets all requirements and specifications for all infrastructure throughout the POP.
The IaaMS solution shall meet all infrastructure requirements as stated in Attachment B – IaaMS Infrastructure Requirements.
STORAGE RESOURCE MANAGEMENT (SRM)
The Contractor shall install, configure, deploy, operate, and maintain a single Storage Resource Management (SRM) platform for the IaaMS solution. The SRM platform shall provide a single interface that covers all capacity from all storage systems provided as part of this contract. The SRM platform shall meet the following requirements:
1. Update data from all storage devices at least once per hour.
2. Provide the capability to uniquely tag data volumes to identify the owning application and the level of service management (i.e. fully managed or minimally managed).
3. Provide global capacity dashboards for all deployed storage.
4. Monitor data replication activities to ensure replication is completing successfully within user-configurable thresholds. Provide configurable e-mail alerts for replication jobs that have failed or fallen behind.
5. Provide centralized alerting and health reports for all storage capacity maintained by the solution.
6. Provide a published API permitting the automated extraction of SRM data.
7. Provide flexible and customizable wizard-based reporting.
8. Maintain a minimum of one year of historical workload and response time data.
9. Provide monitoring and reporting for storage consumed by the IaaMS solution and the growth rate of storage utilization, for both on-premises and in the IaaMS VI cloud disaster recovery repository.
10. Provide protocol-specific Input/Output (IO) utilization and growth trending.
11. Identify future storage needs based on capacity and IO growth trends.
12. Provide a chargeback function that permits calculation of storage costs based on storage tier, consumer, and location.
13. Track underutilized storage resources based on IO and capacity.
The SRM platform shall provide the following data:
1. Current total capacity per application tag, per performance tier, per facility, and across the enterprise
2. Current used capacity per application tag, per performance tier, per facility, and across the enterprise
3. Current growth rate per application tag, per performance tier, per facility, and across the enterprise
4. Projected capacity exhaustion date per application tag, per performance tier and per facility
IaaMS SOLUTION SECURITY REQUIREMENTS
ENCRYPTION
The IaaMS solution shall encrypt all data at all times both at rest and in transit. All data written to any storage medium shall be encrypted upon initial write and remain encrypted throughout the entirety of the data lifecycle. Encryption shall be performed with an Advanced Encryption Standard (AES) with a block size of 256 bits and shall be enciphered using a FIPS 140-2 level 1 validated cryptographic library. The solution shall meet all performance, reliability, and utility requirements of this PWS while configured to meet these encryption requirements. The IaaMS solution shall be implemented in a manner that allows all encryption requirements to be met without interfering with deduplication, thin provisioning, compression, compaction, or other data efficiency mechanisms offered by the solution.
ROLE-BASED ACCESS CONTROL
The IaaMS solution shall implement International Committee for Information Technology Standards (INCITS) 359-2012 Role-Based Access Control (RBAC) for all management interfaces both on-premises and in the cloud, permitting granular control over access to all components including compute, storage, and network infrastructure. The IaaMS solution shall implement RBAC for all production storage, including file, block, and object delivery. All RBAC shall be integrated with VA’s Active Directory infrastructure. The solution shall support cross-domain authentication within the VA.gov forest, permitting authentication, authorization, and accounting from both local and remote domains within the forest.
MULTIFACTOR AUTHENTICATION
The IaaMS solution shall conform with VA Directive 6500 administrative authentication requirements for all administrative access.
KEY MANAGEMENT
The Contractor shall deliver and manage an IaaMS solution with a key management system that shall manage all encryption key management activities for the overall solution, including key creation, storage, and logging. The solution shall automatically export keys upon creation to a VA-provided key management infrastructure. The Contractor-provided key management system shall be sized to maintain all encryption keys throughout the POP. The key management system shall maintain a local copy of each encryption key in the same location as each copy of encrypted data. A minimum of two copies shall always be maintained in geographically disparate locations determined by VA. The key management infrastructure shall implement a key distribution function that is capable of enciphering keys with another key. The key management infrastructure shall implement modification detection functionality that can detect both inadvertent and malicious changes to individual keys or the key database. The key management infrastructure shall implement replay detection and avoidance functionality. The key management infrastructure shall implement key replacement functionality to permit keys to be replaced upon compromise or expiration.
STORAGE MEDIA RETENTION
The Contractor shall deliver and manage an IaaMS solution with all storage media devices to include, at a minimum, rotating hard disk drives, solid state disk drives, PCIe flash media, Universal Serial Bus (USB) memory devices, and 3D XPoint media. All storage media devices delivered to VA shall be retained by VA. The Contractor shall not remove storage media from VA facilities without the prior written approval of the CO.
OPERATING ENVIRONMENT
The Contractor shall configure all operating systems and software utilized by the IaaMS solution in a manner that meets VA software security and deployment baselines, including the configuration of group policies, access control, antivirus software, host-based intrusion prevent systems (HIPS), log management software, and forensic analysis software. The solution shall meet all applicable Defense Information Systems Agency (DISA) Security Technical Implementation Guides (STIGs) and Security Requirements Guides (SRGs).
IaaMS CAPACITY REQUIREMENTS The IaaMS solution minimum usable capacity shall be calculated as the amount of capacity available for end-user utilization when the device is configured to meet all other requirements of this PWS.
The Contractor shall maintain an unused and available capacity equal to or greater than 25% of currently used capacity for the IaaMS VI solution and each IaaMS solution storage performance tier.
VA shall notify the Contractor of any one-time data ingestion that exceeds 20% of the current capacity in use at a given facility. The Contractor shall implement additional out-of-band capacity within 60 calendar days of request by VA. The IaaMS VI solution initial deployment is excluded from this calculation until completion of data migration.
DATA EFFICIENCY
The IaaMS solution shall deduplicate redundant data stored within any given storage tier at any given facility. Deduplication efficiency shall not be inhibited by the use of data encryption within the IaaMS solution. The Contractor shall not calculate data efficiency gains toward the minimum usable capacity.
All file and block capacity shall include thin provisioning capability, permitting storage capacity to be assigned on disk only as it is actively used by VA. This requirement does not apply to backup storage tiers.
IaaMS DATA STORAGE REDUNDANCY REQUIREMENTS
1. The IaaMS solution shall withstand the loss of any single component at any given facility, including any single node, without loss of data.
2. The solution shall be capable of booting from a complete power-down status and fully functioning following the loss of a node.
3. The solution shall continue meeting the performance requirements within this PWS following the loss of any single component, including any single node.
4. All data shall be protected using one of the following three methodologies:
a. Redundant Array of Independent Disks (RAID) 6, or equivalent, providing a minimum of two parity bits per stripe
b. Replication Factor 2 (RF2)
c. 2:1 Erasure Coding
IaaMS VI SOLUTION REQUIREMENTS The Contractor shall provide a complete IaaMS storage solution for VI that consolidates the existing Tier 1 and Tier 2 image storage platforms. Tier 1 is a high-performance caching tier used for short-term storage, typically retaining images for 1-3 years. Tier 2 is used for permanent archival storage. The VI storage solution shall meet all requirements set forth in PWS section 5.2, IaaMS Solution Requirements, but the requirements specific to the VI Solution set forth in this section 5.3 shall take precedence. All on-premises elements of the VI solution shall be provided as a minimally managed service as defined in Attachment C – IaaMS Storage Modeling Requirements, in which the Contractor provides professional services necessary for installation, initial configuration, data migration, ongoing capacity expansions, and top-tier technical support. Following the successful completion of data migration, VA will take and maintain responsibility for day-to-day administrative work including patch management, access control, and ongoing configuration maintenance. The Contractor shall remain responsible for all Operations & Maintenance as defined in PWS Section 5.6 and ensuring Capacity Requirements as defined in PWS Section 5.2.3.
The U.S. Department of Health and Human Services Food and Drug Administration (FDA) has classified the VI application as a Class I exempt medical device, and the use of VI in a clinical setting is subject to the Quality System Regulation of the US Food and Drug Administration under Code of Federal Regulations (CFR) Title 21 Part 820 and other federal legislation. VI systems store medical images which are part of Veteran’s electronic health record (EHR) and are protected by the Federal Privacy Act of 1974 and the Health Insurance Portability and Accountability Act of 1996 (HIPAA). The Food and Drug Administration (FDA) requires that a minimum of two copies of each patient image file be stored in geographically separated locations. Current requirements for the system require that a patient’s images be retained for seventy-five (75) years after the last episode of patient care as referenced in VA Records Control Schedule 10-1, Page III-6-1 (142), January 2019.
The IaaMS VI solution shall store one copy of all data on-premises at each facility and shall store the second copy within the IaaMS VI cloud disaster recovery repository on the VAEC. Upon receiving a new medical image, VI stores two copies of the image (and associated files) on-premises via separate Tier 1 and Tier 2 Server Message Block (SMB) shares. The first, Tier 1, is a high-performance caching tier used for short-term storage, typically retaining images for 1-3 years. The second, Tier 2, is used for permanent archival storage. The IaaMS solution shall deduplicate Tier 1 and Tier 2 copies and store a single image to disk on-premise.
Current State The current VI application stack is hosted on Hewlett Packard (HP) servers running Windows Server 2012 R2. Those hosts run the Hyper-V virtualization hypervisor with resident Windows-based virtual machine guests that, in turn, run the individual VI applications. An HP 3PAR storage system stores the virtual machine disks and associated VM files, as well as the Tier 1 medical images. The retention time for those images range from 90 calendar days to 5 calendar years depending upon the facility. The VistA Imaging application stack writes image data to Tier 1 via SMB. SMB presentation for Tier 1 is managed by Windows Server 2012 R2 virtual machines.
Tier 2 medical images are stored on a hybrid storage system consisting of NetApp E2600 and E2700 block storage. Cisco UCS M3 servers running the VMware ESXi hypervisor hosting multiple SUSE Linux guest virtual machines that run the NetApp StorageGRID 9.x application. StorageGRID consumes block storage from the NetApp E-Series appliances and stores data in a shared object namespace that spans a Veteran’s Integrated Service Network (VISN). StorageGRID provides a Server Message Block (SMB) gateway that allows the VI stack to access objects via SMB presentation. The VistA Imaging application stack writes directly to Tier 2 via SMB.
The existing StorageGRID system allows seamless shifting of incoming data writes between facilities within a VISN. If one site within a VISN reaches capacity, future incoming writes are sent to a neighboring site seamlessly without any change to the SMB presentation. StorageGRID is configured with a hub-and-spoke replication model, in which all sites within a VISN replicate to a single hub site. That hub site replicates its own local data to one of the neighboring sites within the VISN.
Future State – Initial Deployment Contractor shall deliver an IaaMS VI solution that shall consolidate the medical images and associated files from the existing HP 3PAR tier 1 solution and the medical images and associated files from the existing NetApp StorageGRID/E-Series tier 2 solution onto a single replacement IaaMS solution. The 3PAR would remain intact to continue providing VM storage for the existing HP virtualization hosts and VI application stack.
The IaaMS VI Solution shall meet the following requirements:
VI STORAGE
SERVER MESSAGE BLOCK
1. VI requires a SMB presentation to the application that presents facility-specific data, backed by a truly global namespace that incorporates all 40 billion files into a single addressable architecture.
2. The solution shall support both SMB v2.0 and SMB v3.0 presentation.
3. The solution shall support, but shall not require, SMB signing and encryption.
4. The solution shall present data to the VI application using SMB v2.0.
5. SMB services shall fully support the use of Windows Common Security Identifiers (SIDs) for built-in local accounts and groups for Administrators, Backup Operators, Power Users, Users, and Guests. The solution shall allow Active Directory-based user and group objects to be added the built-in common SID groups.
6. SMB services shall fully support inter-domain trust to authenticate users for file access from any Active Directory domain under va.gov after joining the system to any domain within the va.gov forest.
7. Only data generated at a given facility shall be presented at that…
This is the start of the file's text. The full file is on GovTribe.
File details come from the government source that posted it. Updated .