Statement_of_Work_for_FCHS_Follow_On_2023-2033_IDIQ_Contract.pdf
PDF 532 KB Posted
- Attached to
- Foundation Cloud Hosting Services (FCHS2) Cloud Co Federal contract opportunity
- Solicitation number
- DOIDFBO220040
View the file
Other files for this federal contract opportunity
| File | Type | Posted |
|---|---|---|
| FCHS2_Department_of_the_Interior_Q_A_from_RFI_and_Industry_Day_-_Final_0003.xlsx | XLSX spreadsheet | |
| Sol_DOIDFBO220040_Amd_0003.pdf | ||
| Sol_DOIDFBO220040_Amd_0002.pdf | ||
| Sol_DOIDFBO220040_Amd_0001.pdf | ||
| Cover_Sheet_for_Request_for_Information_-_draft.docx | DOCX document | |
| _Statement_of_Work_-_FCHS2_Attachment_2_Authorities_and_Prohibitions.docx | DOCX document | |
| _Statement_of_Work_-_FCHS2_Attachment_1_Security_Objectives-Cybersecurity-and-Governance.docx | DOCX document | |
| Sol_DOIDFBO220040.pdf |
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
Section C - Statement of Work Foundation Cloud Hosting Services (FCHS2)
Cloud Contract Services
1. Overview The Department of the Interior (DOI/Department) is initiating a ten-year (10-year) federal wide multi-award, Indefinite Delivery Indefinite Quantity (IDIQ) delivery order contract per the Federal Acquisition Regulation (FAR) section 16.504(a) (48 CFR 16.504). DOI is seeking cloud service contractors to provide licensing and support services by meeting requirements as described in this Statement of Work (SOW) for government wide Infrastructure, Platform, Software, and other as a Service environments. This SOW describes the U.S. Department of the Interior (DOI) next generation contract vehicle requirements from the original 2013-2023 Foundation Cloud Hosting Services (FCHS1). This new contract called FCHS2 will be operational from fiscal year 2023 through 2033.
1.1 Background
Since 2013 DOI has provided assisted acquisition services by technical service lines to federal agencies in accordance with the Government Management and Reform Act (GMRA) of 1994. DOI has been managing these services aligned with the Federal Cloud Computing Strategy. The FCHS2 next generation requirements are similar and require expertise in cloud services based on the objectives below.
1.2 Current Environment
The U.S. Department of the Interior (DOI) is a federal executive department, established in 1849 and responsible for the administration of lands, minerals, and other resources of the United States. DOI’s mission is protecting and managing the nation’s natural resources and cultural heritage for the benefit of the American people; providing scientific information about those resources and natural hazards; and exercising the nation’s trust responsibilities and special commitments to American Indians, Alaska Natives, and island territories under U.S. administration.
DOI oversees 420 million acres of federal lands, nearly 55 million acres of tribal lands, more than 700 million acres of subsurface minerals, and about 2.5 billion acres of the outer continental shelf. To resource this mission, the DOI averages 63,000 employees throughout 11 Bureaus and multiple Offices and Programs.
https://www.doi.gov/cloud/contract https://cloud.cio.gov/strategy/
Figure 1 - Department of the Interior Bureau/Office Organization
1.2.1 Current Cloud Service Offering (CSO) Investments
Over time the Department has increased Cloud Service Offerings (CSO) exponentially. At the beginning of calendar year 2022, DOI was using 75+ different CSO’s supporting hundreds of IT Systems and rapidly expanding these numbers. Behind the expanding cloud smart adoption is a paralleled initiative under the Data Center Optimization Initiation (DCOI) to consolidate, optimize, and close physical data centers.
Going forward, the biggest CSO increase will be in the emerging FedRAMP SaaS and government community collaboration opportunities.
1.2.2 External Agencies
Like FCHS 1, the follow-on FCHS2 will be Federal wide and the requirements within this statement of work extend to other Federal agencies. DOI intends to provide unique cloud solutions not readily available and equally postured on other federal contracts. DOI prioritizes CSO’s and support services aligned with the list of Services below and not duplicative of other Federal sources.
Collectively, the Federal Government is seeking and prioritizing FedRAMP authorized (or ready) cloud solutions that align IT strategies with enterprise business objectives. Agency Chief Information Officers require transparent, inclusive, agile, and systematic approaches to IT strategy development to meet ever-changing mission needs. DOI is seeking contractor solutions that
• Reflect all IT and digital efforts across Agency’s enterprises and to be a shared effort for the respective Lines of Business (LOB),
• Lay the groundwork to prepare, develop, and bring together diverse Agency stakeholders,
• Employ a systematic and agile approach to migrate legacy into state-of-the-art and integrated enterprise environments,
• Provide partnership support from start of strategy throughout lifecycle and decommissioning.
1.2.3 Current Operational Constraints
DOI is seeking contractors who can bridge the gap of current cloud adoption barriers. DOI identifies two leading constraints that challenge a larger scale of cloud adoption and migration. Under FCHS2, DOI is prioritizing contractors who consider security, availability, and technical objectives (listed below) equally. FCHS2 seeks contractor insight and participation in overcoming these challenges based upon IT security and IT availability.
1) Security: DOI aligns hybrid cloud integration with federal agency regulations and guidelines such as FISMA Modernization Act, NIST Special Publications, FedRAMP, and the Cybersecurity and Infrastructure Security Agency (CISA) – Trusted Internet Connections 3.0.
• Risks are mitigated by routinely adopting new standards after emerging technologies are fully vetted and tested by governing agencies.
• IT Systems access is limited through modelling zero trust architectures such as instituting an unlimited array of hybrid or integrated cloud solutions.
2) Availability: On-premise data center footprint(s) are sprawling throughout the continental
United States and territories to meet mission, legal, and technical requirements at those geographic locations. Until secured, high-speed, ample bandwidth, as well as federated cloud technical solutions are available, cloud and/or hybrid cloud adoption and migration constraints are intentionally established.
2. Business Objectives The DOI is seeking cloud service offerings for both existing and new cloud-based IT systems. Existing cloud systems periodically require task order renewals, migrations, technology refreshes, or integrations from one service offering to another. New cloud service offerings are required to fulfill anticipated first-time or data center consolidation, cloud adoption transitions, or cloud decommissioning.
The objective is to build a composite suite of cloud service offerings and service models that align with an established and anticipated cloud portfolio and represent in a “Mission-Facing” Agency-Wide IT Services Catalog. All FCHS2 accepted services shall be identified “as-a-Service”, typically, but not limited to Infrastructure as a Service, Platform as a Service, or Software as a Service.
The business objectives for IT Systems and Services are as follows:
• Improve agility while managing the confidentiality, integrity, availability, and performance of compute and storage services;
• Reduce Total Cost of Ownership (“TCO”) of delivering shared IT services;
• Promote the use of Green IT by reducing the overall energy, real estate footprint, and use of toxic components of datacenters, and implementing effective recycling and reuse programs;
• Ensure all applicable federal mandates for information security and privacy regulations are maintained and adhered to;
• Provide tiered functions, service levels, and performance for customers;
• Provide interoperable and portable solutions that enable mobility across hosting models and service providers; and
• Enable scaling of infrastructure and application resources to meet elastic application and user demands.
2.1 Attributes
DOI will measure services based upon the Cloud Service Offerings ability to demonstrate
1) On-demand self-service capacity and automated triggers and thresholds to minimize manual management.
2) Broad network access through the Continental United States, including Alaska, Hawaii, and US territories.
3) Resource Pooling to serve multiple front-end users and back-end administrators or integrated applications, including delivering and supporting multi-tenant and multi-cloud service offering environments.
4) Rapid elasticity to automatically scale up or down compute, network, and storage provisions, as demands dictate and flex on a recurring basis.
5) Measured and metered services to automatically control and optimize resources, incidents, network health, usage, costs, thresholds, triggers, and integration success tracking to name a few.
2.2 Services
The type of service models required are predominantly Infrastructure as a Service (IaaS), Platform as a Service (PaaS) and Software as a Service (SaaS), but other similar or “... as a Service” models can be included within these requirements. Individual task orders will identify the business requirements that include cloud licenses, services, or both. Public SaaS applications are expected to be the fastest growing in numbers, especially among availability within the FedRAMP Marketplace.
Within the scope of objectives, Agency programs may periodically request to sponsor Cloud Service Offerings to achieve their FedRAMP authorization. Sponsorship tasks may be performed independently in the form of license only task orders or include contractor support services to collectively achieve authorization.
In response to this statement of work, the Contractor shall provide a list and very brief description of the different CSO’s they provide either directly or through partnership they believe will contribute to services listed below. Additionally, include support services performed in alignment with CSO’s achieving their FedRAMP authorization.
2.3 Business Management
DOI will prioritize contractors who can demonstrate a past performance of tightly managing deadlines, expedient invoicing/payment processing, quality task order quote preparedness, and conducting recurring customer change management or similar forums.
DOI will prioritize contractors who demonstrate their capacity to manage a high functioning sales and support team, including hiring, training, and retaining initiatives.
DOI is most interested in contractors who have a broader catalog selection of license and support services along with reseller partnerships that would be available to federal agencies through FCHS2.
The following table lists DOI’s current, but not all-inclusive lines of business that may request varying levels of support including discovery, development, onboarding, migration, operations, and decommissioning types of services.
TABLE 1 – Department of the Interior Identified Lines of Business Aviation Inventory-Safety Management
Building and Real Property Maintenance Business Process management, seamless customer integration, ticketing, helpdesk
Case Management Software (CMS), includes claims and litigations tracking
Chemical and Safety Inspections and Monitoring Software
Change Management System
Cloud Access Security Broker, multi-factor authentication
Cloud Security and Workload Balance Management
Cloud container and continuous monitoring analysis
Communications, video, chat, eRadio Content Management System Suite
(CMSS)
Cyber Governance, Risk Management, and Compliance (GRC)
Cyber Security Services crashtest, blockchain, antivirus, breach, and attack
Data Lake file-print, storage, virtual desktop, hybrid cloud integration
Digital Signature eArchive, repository, DAR, DR, AI Scanning Imaging Retrieval
Electronic mail, messaging delivery campaign and communications, encryption/security
Emergency notification, weather, mass notification
Endpoint detection, response, and protection
Facility and Space Computerized Maintenance Management System
(CMMS)
Fleet Maintenance
Fuel distribution and management General Computer Business Collaboration and Tools, Microsoft Office
Geospacial, mapping, storage/retrieval application, GPS, location intelligence
Image and Video catalog, storage, and on-demand delivery
Learning Management System Library catalog, OCLC integration, image, audio-video
Major Application Hosting MIS – Management Information System – operational activities and work processes
Open-Source Code and Forum sharing, community hub
Permitting and licensing online portal Robotic Process Automation (RPA) Safety tracking and management system
Scheduling, Event and Conference
Science and Analytics Data System Secure File Transport (SFT)
Space Management
Supply Chain Management
Survey Tool and Customer Experience Application
Video surveillance, IP enabled security, body worn, footage feed, storage and retrieval application and devices
Visitor, Volunteer and Public outreach, recruit, schedule, engagement, and management
Warehouse Management WorkOrder - Automated scheduling and dispatch eWorkOrders
Waste, scrap and recycle transaction management
Website CMS platform e.g. Drupal, civic engagement, information dissemination
Website supporting applications, social media, governance, compliance, access/crowd control
2.4 Computing Models
Business objectives within this Contract shall target OMB M-16-19 Data Center Optimization Initiative (DCOI) “cloud smart” objectives and the National Institute of Science Technology definition of cloud computing Specialist Publication 800-145. Public Cloud is the most common deployment model, but others could include Private, Community, and Hybrid configurations.
Cloud computing models shall enable ubiquitous, convenient, on-demand network access to a shared pool of configurable computing resources (e.g., networks, servers, storage, applications, and services) https://nvlpubs.nist.gov/nistpubs/Legacy/SP/nistspecialpublication800-145.pdf that can be rapidly provisioned and released with minimal management effort or service provider interaction. They shall represent the “Cloud Smart” five essential characteristics, three service models, and four deployment models.
Figure 2 NIST Working Definition of Cloud Computing
2.5 Management Objectives
DOI is seeking vendor participation in the overall strategies and best value to DOI investments.
Management objectives should satisfy each task order while maintaining the posture of DOI wide enterprise objectives. Above and beyond task order specifics, contractor should seek and provide levels or phases of options that promote innovation to costs, schedule, performance, risks, warranties, contracts and subcontracts, 3rd party vendors, and data required to deliver effective migration services.
Contractor should work with DOI key personnel to maintain clear visibility into short and long term expected program costs, schedules, technical performance, risks, and periodic reports throughout the life cycle of IT Systems.
Contractor should provide meaningful reporting and analytics that provide Agency with up-to-date and comprehensive information regarding technical and management performance.
All task orders and particularly public cloud services shall define an agreement between the Cloud Service Provider and customer regarding ownership and management of Covered Service responsibilities.
3 Technical Objectives FCHS2 requires Infrastructure, Platform and Software as a Service (IaaS-PaaS-SaaS) license and support services for hosting major and minor applications, storage, archival/disaster recovery, backup, virtual machine, database hosting, web hosting, development, and test environment, and SAP application hosting services. Cloud service offerings shall provide bundled work-space tools including a combination of operating system, storage, compute, and software resources.
Contractor shall provide technical advisory services necessary to fully migrate the Agencies target application(s) and Services(s) to the cloud per individual task order requirements.
DOI is seeking industry partners that have relationships with multiple cloud service providers and optionally offer a catalog suite of available SaaS.
FCHS2 is not limiting the varieties of software applications and/or brand names of potential SaaS available, but predominantly focused on services aligned with Table 1 – DOI The Department of the Interior Identified Lines of Business. To meet ten years of evolving technical objectives, DOI will revise and increase provider and reseller capacity throughout the life of FCHS2 and based on added requirements of emerging task orders.
Contractors shall offer tested and reliable services among the latest trends and offer delivery innovations for new and existing IT Systems. DOI will prioritize contractors based upon their verified and established partnerships levels with various solution and cloud service providers.
Contractors shall meet agency technical objectives by providing status updates and milestones during installation, development, migration, technology refreshes, testing plans, and rollback capabilities and procedures.
Contractors shall provide technical advisory for pre-installation as well as ongoing post-development and management services as identified in individual task orders.
Contractor(s) shall be prepared to provide environments for production, integration, development, and sandbox purposes to support the complete systems lifecycle. Technical advisory and discovery services are commonly needed where program personnel are experts at their mission and data management, but not at the vast array of cloud IaaS/PaaS/SaaS layers. Technical solutions may be sought when IT Systems are at or after their life expectancy and migrating from on-premise legacy solutions.
3.1 FedRAMP Technical Objectives
Contractor shall secure cloud services in compliance with the suite of Federal regulations and guidelines, the latest National Institute of Science Technology (NIST) special publications, and the Federal Risk and Authorization Management Program (FedRAMP).
DOI requires contractors to offer access to FedRAMP packages that are not stored on Max.Gov.
Additionally, alternate access mechanism should not require installation of any specialized tools at DOI’s expense.
• DOI Detailed technical service level agreements, security, and privacy requirements are covered under Attachment 1 – Security Objectives-Cybersecurity and Governance.
• DOI Detailed Authorities, Laws, Regulations, Policies, Guidance and Prohibitions are covered under and Attachment 2 – Authorities and Prohibitions
Each Contractor task order proposal shall cover the following Service Level Agreements.
TABLE 2 – Mandatory Statements on all New Task Orders Applies to all New (Original Base Order) Task Orders
1 FedRAMP authorization status, and interest/intentions (if different than status) 2 Service Level Agreement on retention length and destruction standards after Task Order expiration, including Cloud Service Providers decommission within or beyond the life of order
3 Guarantee of System Availability based upon systems level (Low, Moderate, High) 4 Cloud Service Provider versus Agency roles 5 Service Level Agreement identifying who will measure, track, and report performance 6 List of performance measures received from Cloud Service Provider 7 Service Level Agreement for not meeting service levels 8 Service Level Agreement on e-discovery practices, including litigation and general 9 Service Level Agreement on privacy (based upon sensitivity level)
10 How will Cloud Service Provider perform incident detection and third-party reviews
3.2 Open Standards
To drive interoperability, scalability, and affordability DOI requires contractors to offer open-standards technologies whenever possible. The technical objective is for portfolios to model solutions based on OpenStand Principles including cooperation, adherence to principles, collective empowerment, availability, and voluntary adoption. Specific standards will be identified in individual task orders, but all should/must be utilized include:
• Open Virtualization Format (OVF) – applicable only to IaaS virtual machines
• Cloud Data Management Interface (CDMI)
• Open Cloud Computing Interface (OCCI)
• Research (OpenStack.org, Apache CloudStack, and OpenNebula)
DOI requests contractor provide their opinion on open standards as related to individual performance work statements.
DOI requests contractor provide proposals of Cloud Service Provider choices based upon the technical merits of the task orders performance work statement at the time of submittal. DOI also requests contractor provide their opinion of any perceived future interoperability, hybrid or expansion phases.
3.3 Hosting Resources
Hosting service options shall include
• IaaS virtual server space, IP addresses, network connections, internet connection, firewalls, bandwidth, load balancers, etc.
• PaaS tools to build and deploy cloud-smart software applications in either on-premise, hybrid or public cloud combinations. PaaS shall have capacity to deploy the IaaS infrastructure automatically, operate the software, handle runbook scenarios automatically, and provide navigational dashboard to manage users, developers, testers, and tenants using production applications.
• SaaS services bundled within IaaS/PaaS hosting environments and aligned with the business or technical objective.
3.4 Provisioning
Contractor shall provision resources for elastic bandwidth, storage, software license suites outside (generally above) the amount initially planned. Priority shall be given to cloud services who provide and align with Use Cases as follows:
• Faster Time to Production – automating manual steps to reduce time to production dramatically (months to hours in some cases)
• Lower Cost – resource setting, monitoring, automation, and sharing applications to save on infrastructure costs and reduces labor (at least 50% reduction from on-premise)
• Lower Capital Commitment – allow new offerings to start with small deployments and grow automatically as demand builds (90% reduction from peak life cycle usage)
• Manage many applications easier – provide common and systematic tools to better manage and reduce duplication for application, tenant, user management, security, and load balancing.
• More Responsive – provide automated deployment to implement faster changes and automated scaling to meet demands faster
• Best Practices – to incorporate application management that systematizes and professionalizes the operation of many applications
• Increase Reuse – facilitates reusing services through various kinds of multi-tenancy, load balancing and resource sharing to reduce cost an innovate faster.
3.5 Assessment and Authorization (A&A) and Technical Services Individual task orders may include A&A support services for the Cloud Service Provider and/or IT Systems included within the tenant. These services shall align to the NIST Special Publication 800-37 and FedRAMP authorization processes and meet the security and privacy thresholds identified in Attachment 1 and Attachment 2. Details of requirements shall be identified within specific task orders.
Contractors shall respond to the elements of Table 2 – Mandatory Statements on all New Task Orders within their price proposal.
Individual task orders may include a variety of other technical support services, including, but not limited to discovery of current systems (on-premise, legacy, data center), life cycle cost estimates (migration through decommission), application rationalization, continuous monitoring, training sessions, application development, and security and performance management. Discovery should include devising migration plans of heavily customized applications, phased approach, decommissioning initial and onboarding new IT Systems.
In the event the full cloud stack is not FedRAMP authorized, contractor shall provide technical advisory services for FISMA equivalent and achieving FedRAMP authorization.
Technical objectives shall include the 1) primary hosting storage and file systems and 2) services capacity for multiple geographical locations, support for data storage tiers, backup, recovery and disaster recovery procedures and processes that support the Service Level Agreements listed below. Individual task orders will identify specifics outside primary and common alternate storage and file system requirements.
3.6 Hosting Major Applications
DOI requires authorized cloud service providers and authorized cloud service resellers to implement and host DOI’s major application initiatives, including both support services and licenses. Typical task order requirements are requested and quoted for three to five years.
Contractor shall provide end-to-end monitoring capability and reporting for service level agreement (SLA) requirements and metrics (as identified in Attachment 1) for each cloud service provider.
Contractor shall provide configuration management information for each cloud virtual environment that will integrate with the task order configuration management system.
Contractor shall provide a Quality Assurance Surveillance Plan (QASP) and/or Quality Control Plan (QCP) that shall include details for measuring performance and deliverables for each cloud service provider with metrics that may include data availability, storage capacity, uptime, etc. identified in Attachment 1.
3.7 Licensing
Contractor shall provide licenses based on the appropriate X-as-a-service cloud computing service models, products, and/or subscriptions. DOI requires the ability to set multi-year subscriptions with simple annual true-ups.
Licenses for each computing cloud model shall meet the National Institute of Standards and Technology (NIST) Special Publication 800-145 definition of Cloud Computing; a cloud based solution provides an ubiquitous, convenient, on-demand network access to a shared pool of configurable computing resources, allows for rapid elasticity to provision and release computing capabilities as required, and is delivered as a measured service to identify for only the services which the agency actively utilizes (Example: networks, servers, storage, applications, and services).
1. Provide flexibility to assign a per user license for use across all respective platform modules, services, products, and/or subscriptions.
2. Provide full suite of services on PaaS and SaaS for the availability for users to access a tools and services catalog within the application instance in order to add to their portfolio of services without reissuing a new task order.
3. Provide licensing and professional services cost separation along with full description each includes.
4. Provide the availability of licenses, by download or media, for each Task Order issued.
5. Provide flexibility to allow no-cost transfers of unused licenses amongst bureaus and offices.
Licenses shall be transferable between bureaus and offices that utilize or subscribe to the same platform or service.
6. Provide licensing models and pricing strategies that are in line with the department and bureau licensing goals.
7. Provide flexible pricing to allow bureaus and offices to choose only the modules, products, services, or subscriptions required with options to “right-size” based on actual or projected license use. Points or discounts shall meet or exceed similar government-wide Catalog pricing structures/schedules.
8. Provide for annual “True-Up” period with the ability to regulate licenses usage (e.g., add, subtract, transfer and/or renew existing licenses) by scaling up or down throughout the contract period. This includes the ability to scale up and down resources and licenses as needed to support seasonal workloads.
9. Provide the ability to allow bureaus and offices to add, subtract, transfer and/or renew existing licenses to support existing or new modules, products, services, and/or subscriptions.
10. Provide co-termination of existing and future licenses.
11. Provide access to automatic software upgrades to capabilities and features without reconfiguration or licensing costs.
12. Pricing for licenses shall also include all third-party tools, add-ons, and applications to be integrated, purchased, or licensed.
13. Provide scalability and flexibility to allow “no cost” transfers of production environment licenses and snapshots to a non-production environment (e.g. sandbox, DEV, or training) and back. In other words, the intent is to allow the option to leverage licenses procured for use in the production environment and extending those licenses for use in a non-production environment without incurring additional cost.
14. Provide the ability to dynamically assign licenses during the standing-up of new sandboxes and/or development environments within 24 hours or less.
15. Provide the option for bureaus and offices to participate in initial BETA testing of new features, subscription, services, or products, to include roadmap technologies in advance of releasing for global use.
16. Provide bureaus the flexibility to switch licenses from one cloud model or service to another, and back again, without disruption to business operations.
17. Provide licenses to support the transition and integration with other applications and third-party tools via Application Programming Interfaces (API) (e.g., capability for integration with digital Interactive Voice Response (IVR) telephonic systems) or web services for functions such as geocoding and address/location verification.
18. Provide the ability to track user login activity and licenses, to include the ability to deactivate or suspend inactive accounts or licenses.
19. Provide the ability to support agile, rapid implementation of new modules, services, products, and/or subscription upgrades and licenses.
20. Provide training via a “Training Credit” model to allow licensed users to conduct on-demand, user initiated, and/or group training on current and future CRM modules, services, products, and/or subscription-based services
4 Attachments
See Attachment 1 - Security Objectives – Cybersecurity and Governance
See Attachment 2 – Authorities and Prohibitions
| 1. Overview |
| 1.1 Background |
| 1.2 Current Environment |
| 1.2.1 Current Cloud Service Offering (CSO) Investments |
| 1.2.2 External Agencies |
| 1.2.3 Current Operational Constraints |
| 2. Business Objectives |
| 2.1 Attributes |
| 2.2 Services |
| 2.3 Business Management |
| 2.4 Computing Models |
| 2.5 Management Objectives |
| 3 Technical Objectives |
| 3.1 FedRAMP Technical Objectives |
| 3.2 Open Standards |
| 3.3 Hosting Resources |
| 3.4 Provisioning |
| 3.5 Assessment and Authorization (A&A) and Technical Services |
| 3.6 Hosting Major Applications |
4 Attachments
File details come from the government source that posted it. Updated .