20240215_TCODE RFI FINAL to increase the page number-.pdf

PDF 221 KB Posted

Attached to
TRANSCOM CLOUD OPTIMAL DEVSECOPS ECOSYSTEM (TCODE) REQUEST FOR INFORMATION (RFI) Federal contract opportunity
Solicitation number
TRANSCOM24D003TCODE
Issued by
Department of Defense United States Transportation Command

About this file

This Request for Information (RFI) from the United States Transportation Command (USTRANSCOM) seeks information from industry regarding the TRANSCOM CLOUD OPTIMAL DEVSECOPS ECOSYSTEM (TCODE) requirement. Interested parties are requested to provide details on their experience and capabilities in areas such as DevSecOps platforms, cloud migration, vulnerability management, key management, and compliance with DoD security standards. Responses are due by March 11, 2024 and should not exceed 10 pages. The anticipated award date for the follow-on TCODE contract is October 18, 2024 with a period of performance beginning January 1, 2025. USTRANSCOM is considering a small business set-aside and encourages responses from all business sizes and socioeconomic categories. Interested parties should describe their technical approach, past performance on similar requirements, and provide a rough order of magnitude for cost.

View the file

Other files for this federal contract opportunity

Other files attached to TRANSCOM CLOUD OPTIMAL DEVSECOPS ECOSYSTEM (TCODE) REQUEST FOR INFORMATION (RFI), newest first.
File Type Posted
2024.03.04 Combined Q & A.xlsx XLSX spreadsheet
2024.02.23_ TCODE PWS AMD 02.pdf PDF
20240301_TCODE RFI AMD 02.pdf PDF
20240215_TCODE PWS Draft-Track Change Add to Section 1.3 Scope.pdf PDF
20240212_TCODE RFI FINAL.pdf PDF
20240123_TCODE PWS Draft.docx DOCX document

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

REQUEST FOR INFORMATION (RFI)

FOR

UNITED STATES TRANSPORTATION COMMAND (USTRANSCOM)

TRANSCOM CLOUD OPTIMAL DEVSECOPS ECOSYSTEM (TCODE)

RFI NUMBER TRANSCOM24D003

1. RFI Overview

In 2024, USTRANSCOM plans to have a contract in place for maintenance and modification (where applicable) to the existing software factory services for USTRANSCOM software developers, as well as establish and maintain target platforms for software delivery across Impact Levels 2, 4, 5 and 6 (SIPRNET) as applicable to the tenant application requirements. USTRANSCOM seeks a solution that supports developments and security teams as well as providing continuous security testing.

USTRANSCOM is seeking information about what solutions currently exist in the market and is interested in learning about what information industry may need to scope a logical roadmap to succeed.

This announcement constitutes an RFI for informational and planning purposes only.

THIS IS NOT A REQUEST FOR PROPOSAL (RFP), nor is it to be construed as a commitment by the Government. No contract will be awarded as a result. Industry’s response to the RFI—or lack thereof—will have no impact on the evaluation of responses to any subsequent RFP or Request for Quote (RFQ) released. The information requested will be used within USTRANSCOM as market research to facilitate decision making (e.g., determining acquisition strategy, small business concerns) and will not be disclosed outside the Government.

Proprietary information submitted shall be appropriately marked. Do not submit confidential information in your response.

**Note** USTRANSCOM will NOT be responsible for any costs incurred by interested parties responding to this RFI.

1.1. RFI Contact(s)

We have designated the following individual(s) to serve as the official point(s) of contact (POCs) for this RFI. These individuals are the only authorized contact(s) permitted to communicate on behalf of USTRANSCOM about this RFI.

Contact information for RFI POC(s):

NAME TITLE OFFICE EMAIL

Ms. Amy Miller Contracting Officer TCAQ-D Amy.m.miller50.civ@mail.mil

Mr. Matthew Wessel Contract Specialist TCAQ-D Matthew.c.wessel.civ@mail.mil

Ms. Jenna Varel Contract Specialist TCAQ-D Jenna.m.varel.civ@mail.mil

Ms. Georgia Wilde Contract Specialsist TCAQ-D Georgia.l.wilde.civ@mail.mil

1.2. Submission Details

Please submit your response to this RFI via email to the RFI POC(s) identified in Section 1.1. and ensure it is received prior to the due date identified in Section 1.3. If you have any questions about this RFI, please direct them to the RFI POC(s) listed in Section 1.1.

Physical (paper) copies of RFI responses will not be accepted.

1.3. RFI Timeline

The RFI timeline is outlined below. Dates may be modified by USTRANSCOM and posted as an amendment to this RFI.

RFI Released: 12-FEB-24 RFI One-on-Ones 13-MAR-24 Deadline for Questions: 4:00 (CT) on 23-FEB-24 Responses Due: 08:30 (CT) on 11-MAR-24

1.4. RFI One-on-One Information

SAVE THE DATE: Week of 13 Mar 23 (estimated) - Industry One-on-One Sessions via MS TEAMS.

Please follow the instructions below to request a one-on-one session.

• Submit your RFI response, including a request for a one-on-one, no later than the response due date identified in Section 1.3.

• The RFI responses received (that include a request for a one-on-one) will be allocated a 20-minute session with the requirements team.

2. Background Information

USTRANSCOM conducts globally integrated mobility operations, leads the broader Joint Deployment and Distribution Enterprise, and provides enabling capabilities in order to project and sustain the Joint Force in support of national objectives.

2.1. Scope of the Requirement

Wilde, Georgia L CIV TRANSCOM TCAQ (USA) Added Georgia Wilde as Contract Specialist

The TCODE ecosystem is a service capability which has adopted the DoD Enterprise DevSecOps Platform initiative (DSOP) in USTRANSCOM by leveraging lessons learned by the Platform One program, industry best practices, open-source software such as Kubernetes, and commercial solutions to instantiate DevSecOps continuous integration, delivery, and deployment pipelines at various classification levels. TCODE is currently hosted in CloudOne’s AWS GovCloud and implementing PlatformOne’s services such as Big Bang, Iron Bank, and Cloud Native Access Point as a Service (CNAPaaS).

The draft Performance Work Statement (PWS) has been attached for your reference and includes additional details. The Government seeks comments from industry, regarding the draft PWS to clarify any ambiguities. These comments will be addressed when the final PWS and RFP are issued. Individual responses will not be provided to comments submitted outside of the virtual meetings.

The Government is requesting a Rough Order of Magnitude (ROM) or estimated price range for what you determine it may cost to support the full requirement. This is strictly a market research request to gauge interest and estimated costs.

The majority of the daily work associated with this PWS is at the unclassified level, but contractor personnel will be required to access SECRET information and/or classified areas, during performance of this task order.

2.2. Place of Performance

Tasks shall be performed at the Contractor’s facility and/or alternate locations for Classified Systems.

2.3. Anticipated Award Timeline

The current contract expires 31 December 2024. A follow-on contract is anticipated to be awarded on or about 18 October 2024 with Transition period to being 1 November and Performance to begin 1 January 2025.

3. Information Requested

Parties interested in assisting USTRANSCOM with this market research are requested to submit the following information in the format outlined below. The response should be detailed (but no more than 10 pages). Title pages and cover letter will not count against the page limit. Respondents are highly encouraged to submit a tailored response rather than a generic capability statement to ensure the requested information is provided.

The Government will not extend invitations for virtual one-on-ones to respondents merely submitting a generic capability statement which does not address the specific requests for information outlined herein.

Wilde, Georgia L CIV TRANSCOM TCAQ (USA) Increased number of page from 7 to no more than 10 pages

3.1. Company Information

• Company Name

• Unique Entity ID

• CAGE Code

• POCs, to include name, title, phone number, and email address

3.2. Business Size

The anticipated North American Industry Classification System (NAICS) for this effort is 541511, Custom Computer Programming Services. The Small Business Administration’s small business size standard for this NAICS is $34Million. Based on this NAICS, identify your business size as a LARGE or SMALL business. If a small business, identify any of the following socio-economic categories that apply to your business under this NAICS: Historically Under-utilized Business Zones (known as “HUBZone”), Service-Disabled Veteran-Owned, Veteran-Owned, Small Disadvantaged Business, 8(a), Women-Owned, or Economically Disadvantaged Women-Owned.

3.3. Who We’re Looking For

USTRANSCOM highly encourages responses from capable businesses of all sizes, including large and small business concerns and all socioeconomic categories. However, it should be noted that small business set-aside opportunities are being considered for the NAICS identified in Section 3.2.

3.4. What We’re Looking For

Interested Parties are invited to provide information on the following subjects of interest, specifically describing your capabilities in successfully executing the following:

Generally, describe your company’s abilities and interest in fulfilling TCODE requirement. Include supporting information which demonstrates your company’s knowledge to meet the requirements of the PWS tasks. If no direct performance or experience with the above, please explain how you will perform tasks utilizing experienced subcontractors, through a proposed teaming arrangement or hiring qualified personnel. Supporting information shall not reiterate the language of the tasks provided in the Draft PWS; rather it shall provide details regarding your company’s knowledge to execute these tasks. USTRANSCOM is not asking for disclosure of specific or detailed innovative solutions; however, specific examples would assist the Government with this

RFI.

Provide the following project or contract information for requirements deemed similar to this effort:

• A brief description of the project

• Contract number

• Period of performance

• Was your company a prime or subcontractor?

• Dollar value of the project

• Scope of the portion of the effort your company supported

If your company is a large business, specify whether you partnered or subcontracted with small business concerns to provide the same or similar services as this requirement.

If your company has no direct performance or experience with the above, explain how you will perform tasks utilizing experienced subcontractors through a proposed teaming arrangement or the hiring of qualified personnel.

3.5. Commercial Availability

Commercial Practices. Request responses to the following questions as they pertain to providing TCODE support.

A. Contractor personnel will be required to access SECRET information during the performance of this contract. Do you have this ability?

B. Knowledge and experience in any Cloud Native DevSecOps Ecosystem. Specific capabilities:

i. Do you have experience with architecting DoD-standard Zero Trust capabilities?

1. If so, how were they designed/implemented?

2. If not, how would you leverage DoD-standard Zero Trust capabilities to defend TCODE?

ii. Describe your strategy for addressing multi-tier support across the multiple

Impact Level environments for this contract?

iii. Describe how you would support a 24/7 uptime requirement for high availability systems?

iv. Identify and describe any elements in the PWS that may represent risk or require further details to ensure success.

v. Have you migrated tenant applications into a software factory while collaborating with another Prime Developer Contractor? If so, describe the planning and collaboration process.

vi. Have you performed a Migration as a Service? If so, describe the modernization and migration process. Describe the collaboration process with Prime Developer Contractor - training and handoff process.

vii. Section 7, Specialized Skills Required: Are the labor categories and specialized skills identified adequate to satisfy this contract in accordance with DoDM

8140.03 qualification?

viii. Describe how many FTEs would be needed to satisfy the terms of this contract?

1. Describe the teaming breakout concept (Product Manager, platform developers, cyber security personnel, helpdesk support, etc.)

ix. Describe your software development methodology and your release cadence.

x. Describe your comprehensive approach to vulnerability management for a

Software Factory / PaaS platform.

1. Detection: Describe how you would identify vulnerabilities within the Software Factory / PaaS platform. Describe where in the SDLC you detect vulnerabilities. Describe what tools, techniques, and business processes are used. Describe best practices for Continuous Monitoring of cloud hosting environment and your experience performing continuous monitoring.

2. Triage: Once a vulnerability is detected, describe how you prioritize and assess its severity. What criteria do you use to determine the level of risk posed by each vulnerability? Describe your strategy to address critical vulnerabilities promptly.

3. Tracking: Describe how you track and manage vulnerabilities within the Software Factory / PaaS platform? What centralized vulnerability tracking system or dedicated vulnerability management tool is used?

Describe how you ensure vulnerabilities are properly documented and assigned for remediation.

4. Remediation: Describe your process for remediating vulnerabilities. How do you ensure that patches, updates, or configuration changes are applied in a timely manner?

5. Mitigation: Describe your process for mitigating the risk of unpatched vulnerabilities and/or applying compensating controls for vulnerabilities that cannot be patched within recommended timelines.

6. Reporting: Describe your experience meeting DoD-required vulnerability reporting requirements such as compliance with CTO’s and IAVMs issued by the DoD. How do you provide visibility and reporting on vulnerabilities within the Software Factory / PaaS platform? We would like to gain a comprehensive understanding of your capabilities in the following areas:

7. Reporting Process: Describe your established process for receiving, reviewing, and responding to CTOs and IAVMs issued by the DOD.

How do you ensure timely and accurate reporting of vulnerabilities identified in DOD information systems? What mechanisms do you have in place to track and document compliance with CTOs and IAVMs?

a. Compliance Management: Detail your methods for ensuring compliance with CTOs and IAVMs. How do you track and document the implementation of required actions? How do you verify and demonstrate compliance to DOD stakeholders?

Provide examples of successful compliance management with CTOs and IAVMs in previous engagements.

b. Documentation and Auditing: Describe your documentation practices for vulnerability reporting. How do you maintain comprehensive records of vulnerabilities, actions taken, and compliance status? How do you facilitate auditing and provide evidence of compliance with CTOs, IAVMs, and other vulnerability reporting requirements?

c. Collaboration with DOD Entities: Explain how you collaborate with DOD entities, such as the Defense Information Systems Agency (DISA), Cyber Operations Centers, Cyber Security Service Providers, Component Audit and compliance branches, and other DOD stakeholders to ensure effective vulnerability reporting. How do you align your reporting processes with DOD guidelines and reporting frameworks? Provide examples of successful collaboration with DOD entities in the past.

xi. Have you designed and implemented information systems that have been designated National Security Systems (NSS) comply with Committee on National Security Systems Instruction (CNSSI) 1253 standards? If so, can you provide examples of such systems and describe the specific NSS baselines they adhere to?

1. How do you ensure that the systems you build meet the security requirements outlined in the applicable NSS baselines? Can you describe your approach to security architecture and design?

2. What processes and methodologies do you follow to conduct security assessments and evaluations to ensure compliance with NSS baselines?

How do you address any identified vulnerabilities or non-compliance issues?

3. How do you stay up-to-date with changes and updates to NSS baselines?

How do you ensure that the systems you build remain compliant with the latest requirements?

xii. Do you have experience with the certification and accreditation (C&A) process for DoD information systems and/or NSS systems? How do you navigate the C&A process and work with the appropriate authorities to obtain system authorization? Explain your expectation of participation in the C&A process.

1. How do you handle the documentation and evidence requirements associated with an RMF ATO? Can you provide examples of the documentation you typically prepare to support system authorization and accreditation?

2. Explain your approach to implementing the continuous ATO guidance in support of obtaining a continuous ATO for a Software Factory/PaaS provider. Do you have experience interpreting and deconstructing requirements into technical implementation supporting continuous monitoring and CATO?

xiii. Describe your experience in implementing cryptographic controls and key management practices in accordance with FIPS/NSS and RMF standards? How do you ensure the confidentiality, integrity, and availability of sensitive information? How do you ensure that cryptographic controls are implemented to the minimum standards outlined in DOD guidance?

1. Describe your approach to ensuring the DoD information system uses cryptographic modules that are FIPS 140-2 or FIPS 140-3 validated?

2. Provide evidence or examples of any FIPS compliance assessments or audits conducted for a system? How do you address any identified non-compliance issues?

xiv. Describe your experience (provide examples) with cloud computing and building or maintaining DevSecOps platforms in CloudOne.

xv. Describe your experience (provide examples) with managing cloud computing costs in CloudOne.

xvi. Describe your strategy to capture platform cloud hosting costs separately from Tenant Applications’ costs. How would you capture costs for the Tenant Applications for their individual cloud expenditures?

xvii. Access to SIPR terminals is required. Describe how will you fulfill this requirement?

xviii. Describe how you will meet the required qualification requirements listed in Appendix C.

xix. Describe your experience with implementing the DoD DevSecOps Reference Design.

xx. In the last 24 months, how many new DoD clients has your company gained?

xxi. In the last 24 months, how many DoD clients has your company lost?

xxii. In the last 24 months, how many DoD Platform as a Service software factories has your company developed and brought into production?

C. Provide the following project or contract information for requirements deemed similar to this effort or capabilities described above:

• A brief description of the project

• Contract number

• Period of performance

• Contract type (Firm Fixed Price, Labor Hour, Cost Plus Fixed Fee, etc.).

• Commercial or Non-Commercial Requirement?

• Was your company a prime or subcontractor?

• Dollar value of the project

• Scope of the portion of the effort your company supported

D. Provide Rough Order of Magnitude or estimated price range for what you determine it may cost to support the full requirement. This is strictly a market research request to gauge interest and estimated costs. This is not included in the above page count.

4. Other Important Information

Please list existing contract vehicles available for use in procuring this effort to include Federal Supply Schedules, GSA Governmentwide Acquisition Contracts, DoD Indefinite Delivery Indefinite Quantity contracts (known as “IDIQs”), or any other Government Agency contract vehicles. (This information on available contract vehicles is for market research only and does not preclude your company from responding to this notice.)

Please list any existing contracts you have which could be used to procure this effort.

Provide any other suggestions or considerations to improve this procurement. Are there software advancements, industry developments, or innovative solutions to be considered?

Please feel free to provide questions and/or comments on the draft Performance Work Statement (attached), citing any information you feel may improve/innovate this requirement.

5. Conclusion

USTRANSCOM would like to thank you for taking the time to review this important RFI, and we look forward to reviewing your response.

AMY M. MILLER

Contracting Officer

Attachment:

1. DRAFT Performance Work Statement

File details come from the government source that posted it. Updated .