_Statement_of_Work_-_FCHS2_Attachment_1_Security_Objectives-Cybersecurity-and-Governance.docx
DOCX document 307 KB Posted
- Attached to
- Foundation Cloud Hosting Services (FCHS2) Cloud Co Federal contract opportunity
- Solicitation number
- DOIDFBO220040
View the file
Other files for this federal contract opportunity
| File | Type | Posted |
|---|---|---|
| FCHS2_Department_of_the_Interior_Q_A_from_RFI_and_Industry_Day_-_Final_0003.xlsx | XLSX spreadsheet | |
| Sol_DOIDFBO220040_Amd_0003.pdf | ||
| Sol_DOIDFBO220040_Amd_0002.pdf | ||
| Sol_DOIDFBO220040_Amd_0001.pdf | ||
| Cover_Sheet_for_Request_for_Information_-_draft.docx | DOCX document | |
| _Statement_of_Work_-_FCHS2_Attachment_2_Authorities_and_Prohibitions.docx | DOCX document | |
| Statement_of_Work_for_FCHS_Follow_On_2023-2033_IDIQ_Contract.pdf | ||
| Sol_DOIDFBO220040.pdf |
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
Section C – Statement of Work Attachment 1 Security Objectives - Cybersecurity and Governance
The Statement of Work (SOW) Attachment 1 identifies security, privacy, and service level agreements related to the products and services offered under the Foundation Cloud Hosting Services or FCHS contract.
1 Security Objectives Security objectives within this statement of work are generally the default threshold. Contractors shall describe how their solutions meet these thresholds within the contract and individual task order proposals where they differ or provide additional, or value-add in specific objectives. Individual task orders will identify variations, reduced or elevated requirements for that specific program, IT System, or service.
1.1 Security Control Compliance
Contractor licensing agreement(s) for each Cloud Service Offering (CSO) shall comply with Department of the Interior (DOI) high level security policy/guidelines, to include:
1) Ensure ongoing Assessment and Authorization (A&A) of the cloud service tenant according to the appropriate level and conform with the Federal Information Security Modernization Act (FISMA), the FIPS 199 Categorization (Low, Moderate, High), and OMB Circular A-130, and FedRAMP standards.
2) Comply and meet thresholds set in the NIST SP 800-53 Risk Management Framework “Security and Privacy Controls for Federal Information Systems and Organizations.”
3) Meet DOI’s service level agreements which are aligned with ISO/IEC 19086-1:2016, 19086-2:2018, 19086-3:2017 standards.
4) Information shall comply with Executive Order 13556 regarding Controlled Unclassified Information (CUI), Personally Identifiable Information (PII) a subset of CUI, and Sensitive PII a subset of PII that requires additional controls and safeguards.
5) Maintain strong physical security controls, managed access to the virtual environment, and maintain strong separation between virtual workloads and environments. Provide clear segregation of data unless otherwise specified, at the application level, and storage level.
6) Adhere to all statutory compliance measures (audit trails, rules-based policy enforcement, etc.).
7) Provide the capability to encrypt all data, including backed up data. Employ appropriate level of encrypt or cryptography protocols to address Data in Transit between user endpoint and the cloud services.
8) Capable to implement Two-Factor Homeland Security Presidential Directive 12 (HSPD-12) PIV Card authentication to provide integration with Federally- operated services and shall accept Two-Factor or HSPD-12 PIV Card for user authentication.
9) All software upgrades and patching shall be coordinated with the IT System customers and shall be compliant with federal and Agency specific IT security patch policies.
10) Provide accessibility through both Internet Protocol Version 6 (IPv6) and IPv4. If not already IPv6 compliant, the Contractor shall provide the Government with a statement regarding its plans and timeframe to implement IPv6. Technical objectives shall meet OMB M-21-07 IPv6 Completing the Transition to Internet Protocol Version 6 (IPv6) service level and NIST Special Publication 500-267 A (most recent versions).
11) The creation and maintenance of websites with content and links, shall comply with Section 508 of the Rehabilitation Act and Web Content Accessibility Guidelines (WCAG).
12) Provide any application and operating system logs associated with an incident, as well as a file system timeline for potentially compromised hosts and any additional files referenced during forensic analysis. Provide system memory dumps and forensic images of any systems that were possibly compromised.
13) Employ appropriate level of encrypt or cryptography protocols to address Data at Rest to ensure ongoing confidentiality and integrity of information storage in the cloud.
14) Provide the ability to restrict government access to the cloud service from government specified networks, in accordance with the Office of Management and Budget (OMB) Memorandum M-08-05, “Implementation of Trusted Internet Connections (TIC),” and the Department of Homeland Security’s “Trusted Internet Connections (TIC) Reference Architecture Document Version 2.0 (or 3.0 as available).” If not currently able to provide this ability, the Contractor shall provide the Government with a statement regarding its plans to have such capability, including timeframe.
1.2 Administrative Objectives
Cloud Service Providers shall provide end-to-end monitoring capability and reporting for service level agreements (SLA) requirements and metrics as identified under ISO/IEC 19086-1:2016, 19086-2:2018, 19086-3:2017, (and later as applicable) “Cloud computing – Service level agreement (SLA) framework” (see diagram below). Typical categories of cloud service characteristics of interest include performance, availability, information security, accessibility, cloud service support, termination of service, governance, service changes, service reliability, attestations/certifications, data management, and PII protection.
2 Security and Privacy Controls Contractor shall ensure Cloud Service Providers document and submit a System Security Plan that identifies the risks impact rating for the IT Systems confidentiality, integrity, and availability according to the NIST Special Publication SP 800-37: Guide for Applying the Risk Management Framework to Federal Information Systems: A Security Life Cycle Approach, and NIST SP 800-39, Managing Information Security Risk: Organization, Mission, and Information System View
Upon any security or privacy breach, Cloud Service Provider(s) under these task orders shall immediately report all incidents, whether suspected or confirmed, involving potential risks to the confidentiality, integrity, or availability of the IT System. Contractor shall submit an email to the following incumbents designated at time of task order initiation or when notified of personnel changes.
1) Department of the Interior - Computer Incident Response Center (DOI-CIRC) at doicirc@ios.doi.gov and 703-648-5655. For non-DOI agencies, submit to their equivalent
2) Contracting Officer
3) Contracting Officer Representative
4) Authorizing Official and/or System Owner
5) Information System Security Officer and/or Cloud Service Provider portal within max.gov
2.1 FedRAMP Authorization
Contractor shall provide support and services in compliance and alignment with Federal Risk Authorization Management Program (FedRAMP) standardized security assessment, authorization, and continuous monitoring policies. This shall include cloud-based platforms, subscriptions, models, and products that have demonstrated they meet basic FISMA standards and reporting requirements.
The Contractor shall manage cloud services risk by meeting related National institute of Science Standards (NIST) guidance and FedRAMP authorizations including the following:
· NIST SP 800-145, The NIST Definition of Cloud Computing
· NIST SP 500-322 Evaluation of Cloud Computing Services based on NIST SP 800-145
· NIST SP 800-37 Rev 2 (or later) Risk Management Framework for Information Systems and Organizations: A System Life Cycle Approach for Security and Privacy
· NIST SP 800-53 Rev 5 (or later) Security and Privacy Controls for Information Systems and Organizations
· NIST SP 800-160 v1 Systems Security Engineering: Considerations for Multidisciplinary Approach in the Engineering of Trustworthy Secure Systems
· NIST SP 800-39 Managing Information Security Risk: Organization, Mission, and Information System View For task orders associated with migration services, contractor shall comply with security and privacy that are consistent with the NIST Special Publication 800-144 – “Guidelines on Security and Privacy in Public Cloud Computing” or other applicable standards and guidelines.
2.2 Authentication
Contractor shall provide a security plan that includes proposed authentication types based on security classification (low, moderate, high) for all end-user integration points such as role-based LDAP, two-factor authentication (2FA0, single sign-on (SSO), multi-factor authentication (MFA), and public or customer access on external facing systems. Authentication includes both physical and logical security and certification (e.g. FedRAMP). Proposals shall focus delivery on both (1) a unified comprehensive solution that leverages the entire IT System boundary and (2) reduces end user confusion and management complexity.
2.2.1 Agency Personnel Authentication
Contractor shall provide a trusted security communication channel for cloud environment management to support the Government’s PIV Card authentication (dual factor method) of remote access (OMB M-11-11 HSPD-12 Policy for a Common Identification Standard for Federal Employees and Contractors). The DOI Agency requires all cloud service offerings to be configured with Active Directory Federated Services (ADFS) using SAML 2.0 Single Sign-on Authentication prior to going into production stage. Contractor solutions for DOI IT Systems shall meet this Agency mandate and plan and coordinate with DOI security personnel for configuration compliance.
2.2.2 Public / Customer Authentication
DOI requires a phishing-resistant “Identity Authentication” single sign-on credentialling option configured for external facing customer services that meet the M-22-09 “Moving the U.S. Government Toward Zero Trust Cybersecurity Principles” (e.g. id.me, login.gov, okta login). Contractor shall propose option(s) in task orders to establish effective customer authentication including license and startup configuration support services.
For existing systems with technical or operational challenges preventing implementation of this requirement, contractor will coordinate with system owners on migration plans that meet appropriate identity requirements.
2.2.3 Contractor Personnel
Contractors authenticating into Agency cloud services shall also comply with Homeland Security Presidential Directive (HSPD-12) that require all federal entities and associated contractors have security background investigations equivalent to federal employees. Background investigations will be performed by the Office of Personnel Management (OPM). Three levels of background clearances exist
1) Standard –Low risk positions require a National Agency Check with Written Inquiries (NACI) or equivalent investigation
2) Moderate risk positions will be identified within individual task orders. These require either a Limited Background Investigation (LBI) or a Minimum Background Investigation (MBI) based on case-by-case determination
3) High risk positions require a full Background Investigation (BI)
If level of background is not specified, Contractor shall provide support personnel cleared at the minimum (Low) background investigation level. Minimum background investigations seek information about support personnel employment, criminal, and personal history in an effort to investigate behavioral reliability, integrity, and personal adjustment. Individual task orders will identify elevated security credentials if needed.
IT Systems within the Department that process Sensitive Compartmented Information (SCI) must meet the same security standards as systems that process controlled unclassified information. Department programs and contractors shall comply with NIST Special Publication 800-59, Guideline for Identifying an Information System as a National Security System.
1) Systems processing collateral (non-SCI) national security information must comply with security policy established by the Committee on National Security Systems (CNSS).
2) Systems processing SCI must comply with security policy established by the Director of National Intelligence (DNI) in Intelligence Community Directive (ICD) 503, Intelligence Community Information Technology Systems Security Risk Management, Certification and Accreditation.
2.4 Data Management - IT System Data Security
Data security and availability requirement levels are identified in each IT Systems categorization as low, moderate, or high. The contractor shall provide a full description with each task order identifying their role and responsibilities and the customers role and responsibilities of securing and protecting data. Information shall be provided in the form of a Control Implementation Summary (CIS) worksheet and Customer Responsibility Matrix (CRM) or equivalent.
Hosting environments provisioned by service providers must demonstrate an appropriate level of security by meeting the requirements of the Federal Information Security and Management Act (FISMA) for moderate-impact systems, and related agency-specific policies. This includes a formal agency security authorization review covering security controls, continuous monitoring, and identification of risks. The agency must consider and accept the risks before Authority to Operate (ATO) will be granted.
As a standard, the DOI requires the service provider environment qualify for ATO no later than 180 calendar days from the date of award. Moreover, the service provider must become compliant with Federal Risk and Authorization Management Program (FedRAMP) requirements within 180 calendar days of the date it becomes available and must maintain compliance throughout the period of performance. The continuous monitoring provided must comply with the NIST Special Publication 800-137 framework and Department of Homeland Security (DHS) guidance.
Contractor shall provide security for non-standard data transfers both in transit and at rest resulting from the migration of the applications or services to the cloud.
Contractor shall provide support for specified auditable events related to the applications or services.
Contractor shall provide at time of initiating individual task orders, the cloud service provider and customer responsibility requirements for when decommissioning occurs including timelines and limits of preservation, removal, snapshots, deletion, sanitizing and other associated requirements of government customized application, configured hosting services, compute instances, and government data storage on the last day (and timeline beyond) task order period of performance.
The Contractor shall ensure the protection of government intellectual property (IP) and data ownership rights and those of any licensors. They shall identify and provide visibility of IP owned and managed components by them or the cloud service provider. Unless otherwise noted by contractor and government all data is owned by government.
All task orders shall meet the following minimal Federal mandates of cloud security and boundary thresholds:
1) Cryptographic modules are consistently validated to FIPS 140-2 requirements;
2) Systems fully support user authentication via Agency Common Access Card (CAC) or Personal Identity Verification (PIV) credentials as identified in OMB Memorandum M-11-11;
3) Systems operate at Digital Identity Level 2 or higher;
4) Cloud Service Provider has ability to remediate High vulnerabilities with 30-days, Moderate vulnerabilities within 90 days, and Low vulnerabilities within 180 days;
5) Cloud Service Provider meets Federal Records Management Requirements, including ability to support record holds, National Archives and Records Administration (NARA) requirements, and Freedom of Information Act (FOIA) requirements;
6) Cloud Service Provider’s external DNS security (NDSSEC) provides origin authentication and integrity verification.
All Cloud Service Provider solutions shall meet FIPS 140-2 certification. Environments shall encrypt in-transit and at-rest sensitive data according to Federal Information Processing Standard Publication (FIPS) 140-2 a mandatory standard for the protection of sensitive or valuable data within Federal IT systems. Additionally, FIPS 140-3 shall be used as an incremental advancement for compliant and validated cryptographic modules, algorithms, and conditional algorithm self-tests.
CONUS: Access, transmit, process, house, and store all sensitive agency information, including information subject to the Privacy Act and Personally Identifiable Information (PII), only within the sole jurisdiction of the United States Federal Government (i.e., within the continental United States, Hawaii, Alaska, Puerto Rico, Guam, and the Virgin Islands).
IaaS/PaaS Cloud Service Providers shall have capacity to implement cloud service infrastructure and data storage redundancy in at least two facilities located within the sole jurisdiction of the United States Federal Government (i.e., within the continental United States, Hawaii, Alaska, Puerto Rico, Guam, and the Virgin Islands) with adequate geographical separation of at least 250 miles with one serving as the primary site and the other as an alternate backup Disaster Recovery (DR) site capable of restoration and resumption of IT services and complete preservation and reconstitution of all DOI data/information within 24 hours of failure of the services normally provided by the primary site.
2.5 Privacy
The Contractor shall adhere to and comply with applicable Laws, Executive Orders and Executive Branch Policy regarding privacy during design, build, testing, operations and maintenance of the information system and the security controls designed to safeguard agency information. Privacy requirements are applicable when DOI information is generated, accessed, stored, processed, or exchanged with DOI or on behalf of DOI by a service provider or subcontracted service provider, regardless of whether the information resides on a DOI information system or a service provider/subcontracted service provider’s information system. The service provider shall protect the confidentiality, integrity, and availability of DOI electronic information and IT resources and protect DOI electronic information from unauthorized disclosure.
Cloud Service Providers shall comply with security and privacy requirements identified in the NIST Special Publication 800-53 rev 5 (or later) - Guide for Assessing the Security Controls in Federal Information Systems and Organizations.
2.6 Continuous Monitoring
For all initial IaaS/PaaS task orders, DOI requires the cloud service provider submit a Security Assessment Plan (SAP) and initially assess all applicable security controls, using an agreed upon independent third-party assessor, and provide security assessment results in the Security Assessment Report (SAR) according to NIST Special Publication 800-53 rev 5 (or later).
DOI requires all cloud service providers to perform continuous monitoring and provide a Continuous Monitoring Plan (CMP) consistent with NIST standards, including NIST SP 800-137, Information Security Continuous Monitoring (ISCM) for Federal Information Systems and Organizations. The continuous monitoring program must address, at a minimum
1) the effectiveness of deployed security controls
2) changes to information systems and the environments in which the system operates
3) compliance to federal legislation, directives, policies, standards, and guidance with regard to information security and risk management.
In documenting the continuous monitoring program for the IT System, the Contractor shall identify and obtain approval by the Authorizing Official for the security controls to be monitored, the frequency of monitoring, and the control assessment approach. The program must define how changes to the IT System will be monitored, how security impact analyses will be conducted, and the security status reporting requirements including recipients of the status reports.
Within the CMP, the Contractor shall develop and maintain a Plan of Action and Milestones (POA&M) report that includes all known IT security vulnerabilities and weaknesses and associated risk mitigation timelines for remediation. All corrective actions and related information shall be included in a monthly POA&M report and submitted according to SO/ISSO personnel according to FedRAMP or equivalent authorization requirements.
2.7 Secure Software Development Framework (SSCF) - Supply Chain Security National Institute of Standards and Technology (NIST) has issued a Secure Software Development Framework (SSDF) and related guidance. Contractor is expected to integrate the NIST Software Supply Chain Security Guidance under Executive Order 14028 Section 4e into their existing software lifecycle management practices to ensure only secure and trustworthy products. Following SSDF practices should help software producers reduce the number of vulnerabilities in released software, reduce the potential impact of the exploitation of undetected or unaddressed vulnerabilities, and address the root causes of vulnerabilities to prevent recurrence.
3 Service Level Agreements The following sections identify the defaults, thresholds, and requirements under the twelve principal Service Level Agreements.
3.1 Accessibility SLA
Cloud Service Provider solutions shall provide and protect millions of people who have disabilities that impede their ability to use Information and Communications Technology (ICT). IT solutions shall provide assistive technologies such as magnifiers, screen readers, braille readers and alternative input devices are available on client computing platforms to make the use of ICT, including cloud services, easier for people with disabilities. The following standards and guidelines for Information and Communication Technology (ICT) services is available and shall be used to provide cloud services to persons with disabilities including:
· W3C Web Content Accessibility Guidelines (WCAG) 2.0, Level A and AA Guidelines, also published as ISO/IEC 40500:2012,
· ISO/IEC TR 29138 (all parts) — Accessibility considerations for people with disabilities,
· ISO/IEC Guide 71 — Guide for addressing accessibility in standards,
· Section 508 of the Rehabilitation Act of 1973, as amended (29 U.S.C. 794d) in the United States of America
· Applicable ICT Accessibility Provisions from Information and Communication Technology (ICT) Standards and Guidelines (36 CFR Part 1194)
3.2 Availability SLA
The Contractor shall provide several tiers of on-demand services for the scale of basic resources that must be always readily provisional. Contractor shall provision defaults of pre-approved tiers within the Cloud Service Offering instance/dashboard/portal. Authorized users shall be able to establish the resource scaling sequence most appropriate to their application when configuring automatic scaling. Contractor may propose alternative methods for meeting the automated, scalable objectives to streamline incremental provisioning for common, cost-effective configurations.
3.2.1 Adapt to Demand Fluctuations
Contractor shall ensure system infrastructure is able to accommodate fluctuations in demand with minimal impact on system performance. Anticipated seasonality, minimum, peak, and average demand rates will be provided in individual task orders to facilitate resource planning.
Latency shall be managed, by the Contractor, so as to optimize IT System responsiveness to end users and ensure functionality of the hosted application. Contractor shall deploy Virtual Application Hosting as applicable to improve user experience.
Several Availability SLAs have set minimums for Acceptable Performance of Cloud Services. These shall be available and usable on demand by authorized entities. Individual task orders will identify different elevated or minimized bands of services as required. In the absence of individual task order specifics, Contractor shall meet the minimums identified in the description or tables below.
3.2.2 Uptime - Downtime
The Contractor shall guarantee several tiers of uptime of all Contractor controlled resources in terms of percentage of minutes/hours a month that the Contractor controlled resources shall be fully operational and available. Planned scheduled downtime and meet mean-time-to-restore are counted as the system being fully operational.
| Uptime Service Band |
| Minimum (<=) |
| Maximum (<) |
| Maximum Planned Downtime |
| Band 1 |
| 99.99% |
| 100.0% |
| <4 minutes/month |
| Band 2 |
| 99.90% |
| 99.99% |
| <43 minutes/month |
| Band 3 |
| 99.% |
| 99.90% |
| <7.2 hours/month |
| Band 4 (default) |
| 95% |
| 99% |
| <36 hours/month |
The Contractor shall provide support services that accommodate several maintenance window maximums. Planned downtime must occur at times specified in the individual task order or agreed upon by application system owner. The Contractor shall notify system administrators through email of specific associated patching and version control services 48 hours in advance.
| Downtime Service Band |
| Minimum (<=) |
| Maximum (<) |
| Notes |
Band 1 (high availability)
0.1 min
| Band 2 |
| 0.1 min |
| 1 hr |
| Band 3 |
| 1 hr |
| 2 hr |
| Band 4 |
| 2 hr |
| 4 hr |
| Band 5 (default) |
| 4 hr |
| 8 hr |
| During non-peak times |
3.2.3 Disaster Recovery Plan
The Contractor shall identify the Cloud Service Offerings minimal service objectives identified as their Disaster Recovery Plan metrics within their task order proposals for the Recovery Time Objective (RTO) and Recovery Point Objective (RPO) and Meet Mean-Time-To-Restore (MMTR). Combinations of compute services, storage, file systems, applications, programming interfaces, and data are defined as the minimum availability requirements. The Contractor shall meet at least the minimum performance requirement and may propose one or more alternative service bands to provide either a more robust service level for mission critical applications or less stringent service level to save on test/sandbox services.
1. The RTO identifies downtime and how long it takes to restore the incident until normal operations area available to both administrators and users. The Contractor shall guarantee that, following any outage attributable to failure of the infrastructure support, systems will be made operational within a specified maximum time (48 hours).
| Recovery Time Objective (RTO) |
| From |
| To |
| Band 1 |
| 0 minutes |
| 5 minutes |
| Band 2 |
| 5 minutes |
| 4 hours |
| Band 3 |
| 4 hours |
| 24 hours |
| Band 4 (default) |
| 24 hours |
| 48 hours |
| Band 5 |
| 48 hours |
| 7 days |
2. The RPO limits how far to roll back in time and defines the maximum allowable amount of lost data measured in time from a failure occurrence to the last valid backup. The Contractor shall guarantee that, following a triggering event, systems will be reverted to a prior state no older than the specified maximum duration (24 hours).
| Recovery Point Objective (RPO) |
| From |
| To |
| Band 1 |
| 0 minutes |
| 5 minutes |
| Band 2 |
| 5 minutes |
| 4 hours |
| Band 3 (default) |
| 4 hours |
| 24 hours |
| Band 4 |
| 24 hours |
| 48 hours |
| Band 5 |
| 48 hours |
| 7 days |
3. Meet Mean Time to Restore Requirements is the average time required to complete a restore request. Depending on the size of a restore request the following service levers are calculated as the “Average” of all restore requests over a month. Specific Mean Time to Restore requirements are identified in the individual task orders. The default minimum Mean-Time-to-Restore is Band 3 (24 hours). Contractor shall meet this minimum and may propose an alternate with explanation.
| Mean-Time-to-Restore Bands |
| Time to Restore |
| Band 1 |
| 15 minutes |
| Band 2 |
| 4 hours |
| Band 3 (default) |
| 24 hours |
| Band 4 |
| 72 hours |
3.3 Performance SLA
Contractors shall provide their defaults, suggestions and tiered options of provisional performance services including the speed the hosted system can respond to changes in demand. Specified times shall be identified in the proposal and selected in the individual task order.
In all cases resources shall be brought online and available for use within time. After a request has been made (either manually or automatically in response to configurable triggers), resources (e.g., storage, virtual machines) shall be available within time.
Contractor shall Implement Transparent and Effective Performance Management services as follows:
1) Provide clear access and visibility to ongoing performance and resources usage.
2) Provide role filtered self-management tools to support billing, monitoring, and reporting on service management function.
3) Provide visibility into usage metering using metrics and granularity appropriate to the type of service.
4) Provide a suite of reports, dashboards, and alarms to monitor and track operational and infrastructure performance (e.g., incidents, service usage, capacity, SLA adherence).
5) Provide automatic monitoring of resource utilization and other events such as failure of service, degraded service, etc. via service dashboard or other electronic mean.
6) Provide the ability to filter and view usage and invoicing by: Technical Service Line, bureau (and sub-bureau), program, IT System, IT System type, IT System Life-Cycle, Security Level, and other elements which may be identified in individual Task Orders.
7) Provide access to all log files generated by the hosted application, associated middleware, operating system, and underlying virtual and physical infrastructure.
8) Provide online reporting metrics interface for all resource utilization including metrics such as: current utilization, historical average and peak for a user defined window of time.
3.3.1 Service Center
Contractor shall provide several tiers of support services including trouble ticket, systems service management, business operations, and other similarly related support services. Contractor shall describe their core (default) and may provide optional support services 1) availability and 2) Time to Respond (acknowledge) requests. In addition, they may provide a variety of means in reaching their support teams including toll free numbers, Tier 0 support websites, support email boxes, chat operators, on-demand videos, etc.
Contractor shall identify their support services by Severity Levels including:
Severity 1: Emergency (Health and Safety)
Severity 2: Mission Priority (Bureau Director)
Severity 3: Program Priority
Severity 4: Routine
Upon contacting support services (helpdesk), the Contractor shall acknowledge request within the following minimum times based upon Severity:
Severity 1: 15 minutes – 2 hours
Severity 2: 30 minutes – 4 hours
Severity 3: 45 minutes – 6 hours
Severity 4: 60 minutes – 8 hours
Contractor shall commitment on the mean time to acknowledge within the timeframes of the Severity Level as well as complete a restore request within MMRT time. Time is calculated on monthly average against the initial response time until satisfactory resolution or escalation occurs.
The Contractor shall meet Mean-Time-To Resolve times based upon severity and identified within individual task orders as follows:
| Mean-Time-to-Restore Bands |
| Severity 1 |
| Severity 2 |
| Severity 3 |
| Severity 4 |
| Band 1 |
| 0 min to 15 min |
| 0 min to 30 min |
| 0 min to 45 min |
| 0 min to 60 min |
| Band 2 |
| 15 min to 2 hr |
| 30 min to 4 hr |
| 45 min to 6 hr |
| 60 min to 8 hr |
| Band 3 (default) |
| 2 hr to 8 hr |
| 4 hr to 16 hr |
| 6 hr to 24 hr |
| 8 hr to 36 hr |
| Band 4 |
| 8 hr to 24 hr |
| 16 hr to 48 hr |
| 24 hr to 72 hr |
| 36 hr to 96 hr |
Within thirty (30) days of any major outage occurrence resulting in greater than 1-hour of unscheduled downtime, the Contractor shall describe the outage including description of root-cause and fix. If cause is related to an associated Cybersecurity & Infrastructure Security Agency (CISA) vulnerability, Contractor shall report and fully comply with requirements as identified within the respective Emergency Directive (ED) YY-###.
Contractors shall provide hours of availability the customer can expect to reach a support or service person able to take down a request for service or log a trouble ticket. Specific Service Center Availability Service Levels will be selected from the available time zone, Continental United States (CONUS) tiers in the individual task orders. If no specified support service times are identified in the individual task order, Contractor shall meet the 8x5 Single Time Zone default and stipulate which Time Zone they meet.
| Availability Type |
| Time |
| Days |
| Notes |
| 8x5 Single Time Zone |
| 9am to 5pm |
| Monday - Friday |
| (Default) single time zone which is default or may be identified in individual task orders |
| 8x5 CONUS |
| 9am to 5pm |
| Monday - Friday |
| in each of the four (4) CONUS Time zones (Eastern, Central, Mountain, and Pacific) |
| 8x5 CONUS + Alaska |
| 9am to 5pm |
| Monday - Friday |
| in each of the four (4) CONUS Time zones (Eastern, Central, Mountain, and Pacific) PLUS Alaska |
| 24 x 7 x 365 / 366 |
| 24 hours a day |
| 7 days a week |
Custom identified in individual task orders
Seasonal or Emergency/Incident identified in individual task orders
3.3.2 Service Desk
The Contractor shall provide licensing and training that meets the following service desk requirements:
· Support integration with service desk application(s) designed for call centers. Licensing shall also support multiple interactions simultaneously via a customer care hub.
· Support integration of an Interactive Voice Response System (IVRS) to enable input and responses using voice recognition, translating text into spoken output for callers (text-to-speech), and transferring IVR calls to available call center agents.
· Include self-help, how-to information, troubleshooting guidelines, and other technical resources to resolve problems locally.
· Provide Tier 1, Tier 2 and Tier 3 help desk services.
3.4 Service Reliability SLA
The Contractor shall provide automated on-demand ability for IT System to back up at current instance or alternate geographical location up to at least 250 miles away. The Contractor may offer software and alternate backup process solutions within their proposals.
Administrators must be allowed to establish several backup solutions including:
1) Backup routines can be set through web-management console or file interface scripts
2) Backup frequency including hourly, nightly, weekly based on automated schedule or on-demand
3) Backup components such as new, updated data only or full operating environment
4) Backup type including Full, Incremental, Differential, Mirror
5) Backup state including live readily available for automated recovery, data at rest, blob or cold archive storage
6) Backup key word searchability and filetype retention including documents, photos, videos, and associated metadata
7) Backup Length of Time and State that backup will be retained (how long to keep backups and the state they reside within that timeline); example 30 days readily available online and then convert to long term storage for up to 3 years
8) Backup method and tenancy including single or multi tenancy of public cloud-to-cloud (C2C), hybrid/private-to-cloud (P2C), mobile-to-cloud (M2C)
9) Backup encryption meets 256-bit AES encryption standards using a user-defined key that is not stored anywhere on servers
10) Backup meets FIPS 140-2 compliance and industry standards (e.g. HIPAA, PCI, Sarbanes-Oxley (SOX), CiscoIOS, Gramm-Leach-Bliley, and SEC / FINRA). Compliance shall be monitored through the Network Configuration Manager and include Change management, Login attempt log, Enable secret password, Idle timeout, Routine (syslog/events trigger) backup
3.4.1 Retention
Contractor shall meet a variety of retention and restore settings including:
1) Daily frequency with 2 weeks retention, 15 minutes to restore
2) Weekly frequency with 1 month retention, 4 hours to restore
3) Monthly frequency with 1 year retention, 25 hours to restore
4) Yearly frequency with 48 hours retention, 72 hours to restore
5) Ability to set a custom time period
3.4.2 Backup and Restore
Contractor shall meet backup and restore service levels including the average time required to complete a restore request. Given that the size of a restore request will influence time required to restore it, these service levels are calculated as the average of all restore requests (both big and small) over a month. Unless otherwise noted in individual statements of work, backup solutions must
1) Be an agentless architecture solution
2) Meet 100TB backup capacity in under 8 hours
3) Be scalable into the petabyte range of data
4) Must be able to test and verify without restoring to production
5) Ability to launch VM directly from de-duplicated compressed backup file located on backup repository
6) Provide end-to-end 256 AES Encryption
3.4 Information Assurance
The Contractor services and associated solutions shall also implement the following requirements:
1) Encryption of all sensitive data in transit (motion) and at rest (storage) using only NIST Validated FIPS 140-2 compliant and validated cryptographic modules and algorithms.
2) Access, transmit, process, house, and store all sensitive agency information, including information subject to the Privacy Act and Personally Identifiable Information (PII), only within the sole jurisdiction of the United States Federal Government (i.e., within the continental United States, Hawaii, Alaska, Puerto Rico, Guam, and the Virgin Islands).
3) Conduct annual penetration testing using a qualified and competent independent third-party assessor/evaluator subject to approval by the DOI AO.
4) For Infrastructure as a Service (moderate or higher) implementations provide storage redundancy in at least two facilities located at least 250 miles with one serving as the primary site and the other as an alternate backup Disaster Recovery (DR) site capable of restoration and resumption of services and complete preservation and reconstitution of all DOI data/information within 24 hours of failure of the services normally provided by the primary site.
5) Provide a Data Loss Prevention (DLP) capability for the contract to detect and prevent the potential loss, exposure, or confidentiality risks to DOI’s sensitive agency information, including information subject to the Privacy Act and Personally Identifiable Information (PII), resulting from intentional or unintentional disclosure to external entities.
6) Provide E-Discovery capabilities that enable compliance with legal mandates and requests capabilities to support legal hold requests.
Seamlessly integrate with the DOI Identity, Authorization and Access Management (IdAAM) solution that consists of the Microsoft Active Directory (AD) and Public Key Infrastructure (PKI) architecture and associated Certificate Authority and DOI HSPD-12 PIV SmartCard-based credentials and enable logical authentication utilizing those credentials without requiring additional Contractor solution credentials; digital and electronic signing and signatures of emails and documents/content within the collaboration suite; and encryption of emails and documents/content using those capabilities.
Provide solutions that conform to the Federal Desktop Core Configuration (FDCC) and United States Government Configuration Baseline (USGCB) security configuration requirements; and that are compatible with end-user client computing devices, operating systems, and client software/interfaces (e.g., workstations, laptops, mobile/portable devices) that are configured in accordance with those specifications; and that do not alter, or require alteration of, those baseline standard security configurations Contractor shall identify Service Level Agreement Penalties for not meeting minimum and default thresholds. There are a variety of penalties that may be incurred from service level violations. The three most common are:
· Financial penalties. With these, the vendor will be required to pay back to the customer the amount of damages that was agreed upon in the contract. This may not amount to a full reimbursement of the service fee paid by the customer for the job.
· Service credits. With these, the vendor will reimburse the customer for the cost of the work that was done or offer credit for future work to be done. In either event, funds are not being transferred.
· License extension or support. With this, the vendor will be required to extend the license’s term or offer further support to the customer without charge, which may include development and maintenance.
image3.png image2.jpg image3.png
File details come from the government source that posted it. Updated .