DAU Cloud Acquisition Guidebook
Total Page:16
File Type:pdf, Size:1020Kb
Defense Acquisition University DoD Cloud Computing Acquisition Guidebook November 2019 Version 1.2 This page intentionally left blank DOCUMENT CHANGE HISTORY Version Date Change 1.0 18 December 2018 Initial Version 1.1 20 April 2019 Updated with latest DoD Cloud Strategy (references, executive summary and 4.2.1) Updated Financial Audit Requirements (added paragraph 4.2.3.4) to include Special Organization Considerations (SOC) Added additional strategic contracting considerations in paragraph 4.2.5 Added paragraph (4.2.7) on using Services Contracts (DoD 5000.74) for acquiring Cloud Services 1.2 5 November 2019 Added sections 4.3.4.5 Testing and 4.4.6 Cybersecurity T&E Added additional Testing considerations in applicable areas such as in definitions, references, and Service level agreements (SLAs) Added DoD Digital Modernization Strategy to References Updated status of ISO/IEC 19086-1:2016 Standard (Information technology — Cloud computing — Service level agreement (SLA) framework — Part 1: Overview and concepts) Added (DRAFT) NIST Special Publication 800-171B Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations Enhanced Security Requirements for Critical Programs and High Value Assets Added CIO Cloud Smart Application Rationalization Playbook to references Updated references for DoD Enterprise DevSecOps Added “Reference Design Version 1.0 12 August 2019 (public)” and the DoD A&S and CIO signed memo “Software Development, Security, and Operations for Software Agility” Added Navy Cloud Broker Information and Air Force Cloud One Information to Section 6.0 DoD Cloud Acquisition Guidebook ACKNOWLEDGEMENTS / LEGAL STATEMENT: The following DoD/Federal government personnel (or FFRDC support) provided content to this Guidebook: Author: Ardis B. Hearn, Defense Acquisition University (DAU) CASTLE Team – Scott Stewart (DISA), Jodi Cramer (USAF) for CASTLE guide Mr. Ashley P. Moore, MBCI, CEAP™, CPIC-P™ Director, IT Risk Management Division (T/CR) Office of the Chief Information Officer (CIO) United States Agency for Global Media (USAGM) Kim Kendall, Cybersecurity Department, DAU National Geospatial-Intelligence Agency NGA Cloud Team (2018) George "Lee" Kennedy, Institute for Defense Analyses, Information Technology and Systems Division Susan May, MITRE, Principal Cyber Security Engineer Sarah M. Standard, Cybersecurity/Interoperability Technical Director, OUSD R&E, D-DT&E _____________________________________________________ November 2019 - Version 1.2 4 DoD Cloud Acquisition Guidebook November 2019 - Version 1.2 5 DoD Cloud Acquisition Guidebook Executive Summary DoD agencies are struggling with how to utilize existing acquisition methods to acquire cloud services that use consumption and rate-based business models. Cloud computing presents an enormous paradigm shift from the usual acquisition model for acquiring traditional Information Technology (IT) services. An understanding of how to acquire IT “as-a-service” must be addressed in order to obtain the benefits that these services can provide. The technology is mature and available commercially and therefore a lesser concern than the existing business and contracting models. This Guidebook provides information and best practices that will allow programs to take advantage of the opportunities provided by cloud services. This new paradigm requires agencies to understand how to acquire critical services and re-think not only the way they acquire IT services in the context of deployment, but also how the IT services they consume provide mission and support functions on a shared basis. This Guidebook also includes information on the importance of understanding the commercial cloud environment as well as how solid planning can avoid potential risk areas such as vendor-lock and hidden costs. The December 2018 DoD Cloud Strategy laid out clear objectives required to meet warfighter needs. “DoD will continue to rely on its ability to process and disseminate information for military operations, intelligence collection, and related activities. To ensure this, the Department must address the unique mission requirements through a multi-cloud, multi-vendor strategy that incorporates a General Purpose cloud and Fit For Purpose clouds (reference Appendix A of the DoD Cloud Strategy). To this end, this strategy will design objectives around solving these strategic challenges: • Enable Exponential Growth • Scale for the Episodic Nature of the DoD Mission • Proactively Address Cyber Challenges • Enable AI and Data Transparency • Extend Tactical Support for the Warfighter at the Edge • Take Advantage of Resiliency in the Cloud • Drive IT Reform at DoD “ The DoD Digital Modernization Strategy signed in July 2019 also laid out the DoD CIO vision which includes four top priorities: Cybersecurity; Artificial Intelligence (AI); Cloud; and Command, Control and Communications (C3) (See Appendix F of this Cloud Guidebook for the full references.) This Guidebook will aid in implementing this strategy by providing a broad overview of Cloud computing terminology and concepts in addition to detailed considerations for DoD Personnel based on their roles and responsibilities in the acquisition of IT capabilities. The Guidebook is aligned with DoD Instruction (DoDI) 5000.02, DoDI 5000.74, DoDI 5000.75, the Defense Acquisition University’s (DAU) Introduction to Cloud Computing (CLE 075), and the Defense Acquisition Guidebook (DAG). Other key references include: November 2019 - Version 1.2 6 DoD Cloud Acquisition Guidebook 15 December 2014 DoD CIO memo regarding Updated Guidance on the Acquisition and Use of Commercial Cloud Computing Services defines The Federal and Department of Defense (DoD) Cloud Computing Strategies The DoD Joint Information Environment (JIE) The DoD Chief Information Officer’s DoD Cloud Way Forward NIST Guidelines on Security and Privacy in Public Cloud Computing The DoD Cloud Computing (CC) Security Requirements Guide (SRG) 7. Financial Statement Audit Requirements for Service Organizations (DoD Cloud Way Forward) 8. DOD Cybersecurity T&E Guidebook v2, Change 1 April 2018; Addendum: Cybersecurity T&E of DoD Systems Hosted on Commercial Cloud Service Offerings. (https://www.dau.edu/cop/test/Pages/Documents.aspx) For a full list of references, refer to Appendix F: References. November 2019 - Version 1.2 7 DoD Cloud Acquisition Guidebook This page intentionally left blank November 2019 - Version 1.2 8 DoD Cloud Acquisition Guidebook Table of Contents DoD Cloud Computing Acquisition Guidebook ................................................................... 1 1 Overview ........................................................................................................ 13 1.1 Audience......................................................................................................... 13 1.2 Applicability ..................................................................................................... 13 1.3 Basic Terminology .......................................................................................... 13 2 Foundations of Cloud Computing ............................................................... 19 2.1 Background .................................................................................................... 19 2.2 DoD Definition of Cloud Computing ................................................................ 20 3 DoD Approach for Acquisition of Commercial Cloud Services ................ 25 3.1 Assessment of “As-Is” State ........................................................................... 25 3.2 DoD Specific Requirements to Acquire Cloud ................................................ 27 4 Information Tailored for Specific Roles and Responsibilities .................. 34 4.1 Program Managers Roles and Responsibilities .............................................. 34 4.2 Contracting Officers/Financial Managers/Attorneys ........................................ 42 4.3 Technical Considerations (Engineers/IT Specialists) ...................................... 54 4.4 Cybersecurity Considerations ......................................................................... 72 5 Service Level Agreements (SLAs) ............................................................... 83 5.1 Background .................................................................................................... 83 5.2 Challenges and Best Practices ....................................................................... 83 5.3 The Exit Strategy ............................................................................................ 85 5.4 Standards 19086 Series -- Service Level Agreements Standards .................. 85 5.5 SLA Fundamental Concepts and Vocabulary ................................................. 85 5.6 SLA Metrics .................................................................................................... 86 6 Existing DoD Contracts and POCs .............................................................. 95 November 2019 - Version 1.2 9 DoD Cloud Acquisition Guidebook Military Sealift Command ........................................................................................ 98 Naval Air Systems Command ................................................................................. 98 Naval Information Warfare Systems Command ...................................................... 99 Appendix A: Representative Example Contract Clauses ............................................ 103 Appendix B: Example Service Level