SOW.pdf
PDF 124 KB Posted
- Attached to
- IHS1471354 - IT System Backup Solution - PAO Federal contract opportunity
- Solicitation number
- RFQ-23-PHX-065
About this file
This scope of work document outlines requirements for an IT system backup solution for the Phoenix Area Indian Health Service. Key deliverables include hardware appliances with backup storage capacities ranging from 30TB to 160TB to be installed onsite at eight specified locations, along with a centralized 240TB appliance in Albuquerque, NM for disaster recovery. The solution must provide encrypted backups with data integrity checks and retention lock capabilities. Onsite installation, configuration, training and support services are also required. The related federal contract opportunity is a request for quote issued by the Department of Health and Human Services Indian Health Service to procure these services with a 60-day period of performance.
View the file
Other files for this federal contract opportunity
| File | Type | Posted |
|---|---|---|
| QUESTIONS ANSWERS.pdf | ||
| Manual_Exhibit_5-5_1A_IEERepresentationForm.pdf | ||
| Pricing Schedule.xlsx | XLSX spreadsheet | |
| Combined Synopsis - Final.pdf |
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
SCOPE OF WORK
I. OBJECTIVE:
The objective of this project is to provide a centralized and standardized backup solution for the Phoenix Area Indian
Health Service. Local Backups are to be performed onsite to the new local appliances; and, replicated out to a central
Repository hosted by IHS in Albuquerque, NM or FedRamp approved cloud storage service. Locations of the sites span
Arizona, Nevada, Utah, and New Mexico.
II. DELIVERABLES:
A. Hardware/Software/licensing
The following sites will receive an onsite backup appliance(s), software to run and integrate with IHS systems
(Windows, VMware, SQL, Oracle), and licensing to operate:
PAO – Appliance with 60TB Usable storage for backups, with SFP+ connections;
PIMC - Appliance with 160TB Usable storage for backups, with SFP+ connections;
Whiteriver - Appliance with 60TB Usable storage for backups, with SFP+ connections;
Parker - Appliance with 30TB Usable storage for backups, with SFP+ connections;
Ft. Yuma - Appliance with 30TB Usable storage for backups, with SFP+ connections;
Hopi - Appliance with 30TB Usable storage for backups, with SFP+ connections;
Ft. Duchesne - Appliance with 30TB Usable storage for backups, with SFP+ connections;
Elko - Appliance with 30TB Usable storage for backups, with SFP+ connections.
The following site will be the DR site for the above locations. This site will host a backup appliance and be the target for replication:
Albuquerque, NM – Appliance with 240TB usable storage for replication, with SFP+ connections or FedRamp approved cloud storage service
Vendor may propose options for additional cloud storage at sites listed above.
B. Backup Solution technical requirements:
Data ingested by the backup solution should be encrypted in flight and at rest at all phases of the backup lifecycle such as replication and archive. Backups should not be stored in a native format to the source data as this allows for potential access of the data.
Online backups should not be exposed via open protocols such as SMB and NFS. A logical air gap solves for rapid speed of recovery while keeping the backups vaulted offline from the network and behind a zero-trust configuration.
The backup solution should make use of CRC to ensure that the data committed to the backup repository is the same data that was backed up at the time of the backup, through the life cycle of the data, and when the data is called for restore to ensure the backups have not been modified. If any data is modified the solution should be self-healing to correct the data.
Retention Lock, not to be confused with immutable backups, Retention Lock protects against insider threats or compromised identities by providing a compliant method of locking data to not expire until a predetermined time has expired. This requires at a minimum Two-Person-Integrity via a support-drive process, otherwise an individual, even a security admin role, can go rogue and disable retention lock.
Your data protection system should be able to identify anomalous filesystem activities and encryption events at the file level. Ransomware events are ‘unknown recovery events’ and are different than the traditional IT Restore request.
Your data protection system should be able to identify IOC’s, such as file hashes, a file matching a hex value, file extensions etc, via YARA rules. This needs to apply across all of the backups to discover and report where IOCs are present and when they were introduced.
Includes storage and compute in a single hardware appliance.
Must natively support multiple hypervisors to include but not limited to Hyper-V, Acropolis HV, and Vmware
ESXi. Any proposed solution is capable of supporting a variety of hypervisors such that user is not prevented from changing hypervisors in the future should they choose to do so without the use of third-party hardware or software.
The solution’s software defined storage features Includes the following data management features:
o Compression (Either Inline or Post Process).
o Deduplication (Deduplication must span all storage tiers to include but not limited to RAM, flash and HDD, and scale as the storage cluster grows.
o Data redundancy policies that provide options for single host failure and simultaneous host failure with no impact to data availability.
The solution has no single point of failure;
Storage platform is a closed architecture that cannot be written to by 3 party applications;
Solution does not allow for 3rd party applications to be installed on it;
Provides a master-less clustered architecture;
Is scalable backing up into the petabyte range of data;
Is FIPS 140-2 compliant;
Supports vLan Tagging (IEEE 802.1Q standard);
Must have IP-based connectivity;
Is TAA Compliant;
Verified free from Foreign Ownership, Control or Influence (FOCI).
C. Services:
Onsite Installation for each appliance to include:
Project Planning -o Confirmation of site readiness - space, power, switch and port availability;
o Review network configuration requirements;
o Review firewall, NTP and DNS requirements;
o Confirmation and documentation of IP addressing;
o Confirmation of workload account permissions;
o Security Checklist Review and Confirmation.
Physical Installation -o Confirm Delivery Contents;
o Rack equipment;
o Cable equipment;
o Power and validate network accessibility.
Cluster Initialization/Bootstrapping -o Confirm software version;
o Confirm Hardware Health Status;
o Perform Node discovery;
o Confirm all Management and IPMI IPs available;
o Initiate bootstrap process;
o Enable support tunnel;
o Support Portal Registration.
One-time setup items -o Upgrade software Version (if applicable);
o Network settings;
o Users settings;
o Notification settings;
o Review Support Tunnel;
o Security Hardening Best Practices;
Enablement and Workload Integration -o Dashboard Overview;
o SLA Domain Configuration of up to 5 SLAs;
o Integrate (1) One Hypervisor (VMware);
o Configure up to 5 VMs for protection and demonstrate supported recovery options;
o Configure up to 5 SQL databases and demonstrate basic supported recovery options (Live Mount, Export, Restore, Instant Recovery, Download);
o Configure up to 5 (each) Windows and Linux hosts and demonstrate supported recovery options of Fileset
+ Volume Groups;
o Configure up to 5 NAS fileshares using filesets and demonstrate supported recovery options of File
Recovery;
o Addition of a single Archival and single Replication Target;
o Demonstrate reporting capabilities;
Central Device Management Integration -o Register Appliance with Central Device Management;
o Users and Roles;
o Initiated Upgrades;
o Initiated Support Tunnel;
o Security Hardening Best Practices.
QuickStart Review Session -o Question & Answer - Recap Session.
Project Closeout -o Provide completed Implementation Summary including Workbook;
o Review Support Engagement Process.
D. Training: Onsite Training at the Phoenix Area office for up to 12 people.
In-person instructor-led training course at customer site, local offices, or virtual. Maximum of 12 individuals per course.
III. GENERAL CONDITIONS:
A. Proof of qualifications. Provide qualification packet which shall include business capability, list of similar projects completed, licenses held, list of representative agreements, certification held and a list of qualified technicians who will perform the work.
B. Codes and Standards. The Contractor shall adhere to the following code requirements for work performed, including testing and inspection:
1. NFPA 70 National Electric Code
2. IEEE Standards
3. BICSI International Standards
4. International Building Code
5. Occupational Safety and Health Act – CFR1926
C. Project Safety:
1. All work will comply with Occupational Safety and Health Act – CFR1926.
2. Contractor shall supply all required worksite safety equipment.
3. Contractors will be required to submit and adhere to the following items including but not limited to:
a. MSDS construction binder for all products used onsite.
b. Project specific site safety plan.
4. Contractor shall be responsible for complete and strict compliance with all Fort Yuma Service Unit facility policies, including the safety policy.
D. Submittals: Furnish submittals for all building materials, fixtures and appliances. Provide in scanned PDF format for formal approval.
1. Product Cutsheets.
2. MSDS Sheets for all products.
E. Quality Assurance/Quality Control:
1. All materials shall be approved by owner.
2. All materials shall be installed per manufacturer’s instructions and all applicable codes, and good work practices.
3. Housekeeping will be accomplished on a daily basis. All debris and trash generated by this project will be disposed of properly in accordance with governing national, state and local environmental regulations.
4. Qualifications: All electrical, plumbing and HVAC work shall be performed by an appropriately licensed contractor specializing in the specific trade required.
F. Execution:
1. Construction activities shall be coordinated with Indian Health Service Facility Management Staff to ensure that there are no detrimental impacts on the day to day operations of the Hospital or on local residents’ safety.
2. The Contractor shall be responsible for obtaining all required construction permits and licensing, and paying all applicable fees as required.
3. The Contractor shall verify all existing field conditions and measurements prior to foundation and building construction/installation.
G. Inspection:
1. The Government reserves the right to inspect all aspects of work performed, including hiring a third party inspector to verify proper installation and operation.
2. Contractor is required to demonstrate full and complete operation of all work performed.
3. Final acceptance will be based on an acceptable final inspection, including final verification testing of all material and workmanship.
H. Project Schedule:
1. The contactor shall provide a detailed schedule indicating the date that each phase of construction will be completed.
2. Facility day time hours of operation are 7:00 AM – 5:00 PM, Monday through Friday (excluding Federal holidays). Work outside of these hours must be submitted in writing to the Facility Manager for approval.
3. Schedule shall be in Microsoft Project format or approved equal.
I. Performance Period: 60 days following issuance of a written Notice to Proceed from the Contracting Officer.
J. Final Payment:
1. Final Payment will not be authorized until all work is complete (including punch list), the final inspection has been made and Warranty Documents for the appurtenances have been received.
K. Warranty:
1. Contractor shall warrant all work for one year from date of acceptance.
2. All Hardware shall come with a 5-year warranty.
3. All Software shall come with a 5-year warranty.
File details come from the government source that posted it. Updated .