SOW.pdf

PDF 103 KB Posted

Attached to
IHS1471354 - IT System Backup Solution - PAO Federal contract opportunity
Solicitation number
SS-23-PHX-021
Issued by
Department of Health and Human Services Indian Health Service

View the file

Other files for this federal contract opportunity

Other files attached to IHS1471354 - IT System Backup Solution - PAO, newest first.
File Type Posted
BIA Sources Sought.pdf PDF

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

Phoenix Area Indian Health Service IT System Backup Solution

SCOPE OF WORK

I. OBJECTIVE:

The objective of this project is to provide a centralized and standardized backup solution for the Phoenix Area Indian Health Service. Local Backups are to be performed onsite to the new local appliances, then replicated out to a central Repository hosted by IHS in Albuquerque, NM. Locations of the sites span Arizona, Nevada, Utah, and New Mexico.

II. DELIVERABLES:

A. Hardware/Software/licensing

The following sites will receive an onsite backup appliance(s), software to run and integrate with IHS systems (Windows, VMware, SQL, Oracle), and licensing to operate:

PAO – Appliance with 60TB Usable storage for backups, with SFP+ connections;

PIMC - Appliance with 60TB Usable storage for backups, with SFP+ connections;

Whiteriver - Appliance with 60TB Usable storage for backups, with SFP+ connections;

Parker - Appliance with 30TB Usable storage for backups, with SFP+ connections;

Ft. Yuma - Appliance with 30TB Usable storage for backups, with SFP+ connections;

Hopi - Appliance with 30TB Usable storage for backups, with SFP+ connections;

Ft. Duchesne - Appliance with 30TB Usable storage for backups, with SFP+ connections;

Elko - Appliance with 30TB Usable storage for backups, with SFP+ connections.

The following site will be the DR site for the above locations. This site will host a backup appliance and be the target for replication:

Albuquerque, NM – Appliance with 240TB usable storage for replication, with SFP+ connections.

B. Backup Solution technical requirements:

Data ingested by the backup solution should be encrypted in flight and at rest at all phases of the backup lifecycle such as replication and archive. Backups should not be stored in a native format to the source data as this allows for potential access of the data.

Online backups should not be exposed via open protocols such as SMB and NFS. A logical air gap solves for rapid speed of recovery while keeping the backups vaulted offline from the network and behind a zero-trust configuration.

The backup solution should make use of CRC to ensure that the data committed to the backup repository is the same data that was backed up at the time of the backup, through the life cycle of the data, and when the data is called for restore to ensure the backups have not been modified. If any data is modified the solution should be self-healing to correct the data.

Retention Lock, not to be confused with immutable backups, Retention Lock protects against insider threats or compromised identities by providing a compliant method of locking data to not expire until a predetermined time has expired. This requires at a minimum Two-Person-Integrity via a support-drive process, otherwise an individual, even a security admin role, can go rogue and disable retention lock.

Your data protection system should be able to identify anomalous filesystem activities and encryption events at the file level. Ransomware events are ‘unknown recovery events’ and are different than the traditional IT Restore request.

Your data protection system should be able to identify IOC’s, such as file hashes, a file matching a hex value, file extensions etc, via YARA rules. This needs to apply across all of the backups to discover and report where IOCs are present and when they were introduced.

Includes storage and compute in a single hardware appliance.

Must natively support multiple hypervisors to include but not limited to Hyper-V, Acropolis HV, and Vmware ESXi. Any proposed solution is capable of supporting a variety of hypervisors such that user is not prevented from changing hypervisors in the future should they choose to do so without the use of third-party hardware or software.

The solution’s software defined storage features Includes the following data management features:

o Compression (Either Inline or Post Process).

o Deduplication (Deduplication must span all storage tiers to include but not limited to RAM, flash and HDD, and scale as the storage cluster grows.

o Data redundancy policies that provide options for single host failure and simultaneous host failure with no impact to data availability.

The solution has no single point of failure;

Storage platform is a closed architecture that cannot be written to by 3 party applications;

Solution does not allow for 3rd party applications to be installed on it;

Provides a master-less clustered architecture;

Is scalable backing up into the petabyte range of data;

Is FIPS 140-2 compliant;

Supports vLan Tagging (IEEE 802.1Q standard);

Must have IP-based connectivity;

Is TAA Compliant;

Verified free from Foreign Ownership, Control or Influence (FOCI).

C. Services:

Onsite Installation for each appliance to include:

Project Planning -o Confirmation of site readiness - space, power, switch and port availability;

o Review network configuration requirements;

o Review firewall, NTP and DNS requirements;

o Confirmation and documentation of IP addressing;

o Confirmation of workload account permissions;

o Security Checklist Review and Confirmation.

Physical Installation -o Confirm Delivery Contents;

o Rack equipment;

o Cable equipment;

o Power and validate network accessibility.

Cluster Initialization/Bootstrapping -o Confirm software version;

o Confirm Hardware Health Status;

o Perform Node discovery;

o Confirm all Management and IPMI IPs available;

o Initiate bootstrap process;

o Enable support tunnel;

o Support Portal Registration.

One-time setup items -o Upgrade software Version (if applicable);

o Network settings;

o Users settings;

o Notification settings;

o Review Support Tunnel;

o Security Hardening Best Practices;

Enablement and Workload Integration -o Dashboard Overview;

o SLA Domain Configuration of up to 5 SLAs;

o Integrate (1) One Hypervisor (VMware);

o Configure up to 5 VMs for protection and demonstrate supported recovery options;

o Configure up to 5 SQL databases and demonstrate basic supported recovery options (Live Mount, Export, Restore, Instant Recovery, Download);

o Configure up to 5 (each) Windows and Linux hosts and demonstrate supported recovery options of Fileset + Volume Groups;

o Configure up to 5 NAS fileshares using filesets and demonstrate supported recovery options of File Recovery;

o Addition of a single Archival and single Replication Target;

o Demonstrate reporting capabilities;

Central Device Management Integration -o Register Appliance with Central Device Management;

o Users and Roles;

o Initiated Upgrades;

o Initiated Support Tunnel;

o Security Hardening Best Practices.

QuickStart Review Session -o Question & Answer - Recap Session.

Project Closeout -o Provide completed Implementation Summary including Workbook;

o Review Support Engagement Process.

D. Training: Onsite Training at the Phoenix Area office for up to 12 people.

In-person instructor-led training course at customer site, local offices, or virtual. Maximum of 12 individuals per course.

III. GENERAL CONDITIONS:

A. Proof of qualifications. Provide qualification packet which shall include business capability, list of similar projects completed, licenses held, list of representative agreements, certification held and a list of qualified technicians who will perform the work.

B. Codes and Standards. The Contractor shall adhere to the following code requirements for work performed, including testing and inspection:

1. NFPA 70 National Electric Code

2. IEEE Standards

3. BICSI International Standards

4. International Building Code

5. Occupational Safety and Health Act – CFR1926

C. Project Safety:

1. All work will comply with Occupational Safety and Health Act – CFR1926.

2. Contractor shall supply all required worksite safety equipment.

3. Contractors will be required to submit and adhere to the following items including but not limited to:

a. MSDS construction binder for all products used onsite.

b. Project specific site safety plan.

4. Contractor shall be responsible for complete and strict compliance with all Fort Yuma Service Unit facility policies, including the safety policy.

D. Submittals: Furnish submittals for all building materials, fixtures and appliances. Provide in scanned PDF format for formal approval.

1. Product Cutsheets.

2. MSDS Sheets for all products.

E. Quality Assurance/Quality Control:

1. All materials shall be approved by owner.

2. All materials shall be installed per manufacturer’s instructions and all applicable codes, and good work practices.

3. Housekeeping will be accomplished on a daily basis. All debris and trash generated by this project will be disposed of properly in accordance with governing national, state and local environmental regulations.

4. Qualifications: All electrical, plumbing and HVAC work shall be performed by an appropriately licensed contractor specializing in the specific trade required.

F. Execution:

1. Construction activities shall be coordinated with Indian Health Service Facility Management Staff to ensure that there are no detrimental impacts on the day to day operations of the Hospital or on local residents’ safety.

2. The Contractor shall be responsible for obtaining all required construction permits and licensing, and paying all applicable fees as required.

3. The Contractor shall verify all existing field conditions and measurements prior to foundation and building construction/installation.

G. Inspection:

1. The Government reserves the right to inspect all aspects of work performed, including hiring a third party inspector to verify proper installation and operation.

2. Contractor is required to demonstrate full and complete operation of all work performed.

3. Final acceptance will be based on an acceptable final inspection, including final verification testing of all material and workmanship.

H. Project Schedule:

1. The contactor shall provide a detailed schedule indicating the date that each phase of construction will be completed.

2. Facility day time hours of operation are 7:00 AM – 5:00 PM, Monday through Friday (excluding Federal holidays). Work outside of these hours must be submitted in writing to the Facility Manager for approval.

3. Schedule shall be in Microsoft Project format or approved equal.

I. Performance Period: 60 days following issuance of a written Notice to Proceed from the Contracting Officer.

J. Final Payment:

1. Final Payment will not be authorized until all work is complete (including punch list), the final inspection has been made and Warranty Documents for the appurtenances have been received.

K. Warranty:

1. Contractor shall warrant all work for one year from date of acceptance.

2. All Hardware shall come with a 5 year warranty.

3. All Software shall come with a 5 year warranty.

Scope of Work

File details come from the government source that posted it. Updated .