Scope of Work
The purpose and scope of this task are to procure candidate Infrastructure Operations and Maintenance support for EPA’s Office of Chemical Safety and Pollution Prevention (OCSPP) and ensure the infrastructure and hosted services and systems are running without disruption.
The candidate shall participate in the Change Control Board (CCB) board with other key OCSPP members that are responsible for tracking, identifying, and analyzing issues and potential changes pertaining to the infrastructure. The CCB also serves as the approving authority for changes to the systems within the infrastructure. The Candidate shall serve as the technical advisor to the CCB.
The Candidate shall:
- Facilitate the preferred Change Management process to make sure that the systems are reliable, efficient, effective, secure, and comply with EPA architecture.
- Recommend procedures for maintaining and tracking existing and new systems, subsystems, and equipment deployed to the CBI Infrastructure as well as any hardware or software configuration changes.
- Provide advice on appropriate change status-reporting methods for the controlled configuration artifacts.
- Identify potential points of failure and provide recommendations for mitigating, accepting, and/or transferring risk.
- Provide written reports via email after the CCB meeting
OCSPP Infrastructure Operation and Maintenance Support
The Candidate shall maintain OCSPP infrastructure that includes existing server hardware, associated operating systems, security artifacts, and proprietary applications and tools that are currently in use within the CBI infrastructures. It also includes the operations and maintenance support of the hosted applications that are currently in production or in the process of being deployed in production by other vendors. All activities with associated schedules for system operation, critical support tasks, and activities include the following:
- IT Consulting Assistance
- New software development and new technology platforms
- Maintenance of all software including sub-systems for all software applications and other
- system platform issues.
- Support for project-related issues associated with all OCSPP information systems residing
- on Windows servers, Linux servers, VMware servers, Citrix, NetApp, Oracle
- Database Appliance, and all other platforms as required.
- Support platforms such as Salesforce PaaS, MuleSoft ESB, Oracle, Java/J2EE,
- Documentum, Business Objects, Cold Fusion, Dreamweaver, Adobe, Macromedia, and
- other application development platforms.
- Document Firewall Rules and TIC changes/updates.
- Support to ensure that information systems remain readily available to OCSPP personnel via
- the LAN and OCSPP external customers via the Intranet/Internet and other mechanisms
- (AAA remote access, File Transfer Protocol (FTP) sites, for example).
- Perform software patching and upgrades as required to remediate vulnerabilities and
- secure the infrastructure.
- Develop enhancements to existing applications as required by law changes.
System Security
- The Candidate shall work closely with OCSPP management/staff to monitor system performance and maintenance, and prevent any unauthorized access, threat and security risks, misuse, modification, or denial of Infrastructure accessible resources. The Candidate shall be responsible for reporting any known or discovered areas of vulnerability or concern to OCSPP management and staff. The Candidate shall analyze, respond to, and adequately document the network security threat, generate reports, and assist in accident/violation investigation process.
- The Candidate shall ensure the design and implementation for systems and databases hosted within the infrastructure align to information security rules, agency IT security policies and procedures, and the latest available and cost-effective information security technology. The Candidate shall work closely with OCSPP’s Information Security Officers (ISO’s) to provide continuous monitoring and awareness of the OCSPP information security program, vulnerabilities, and threats to facilitate risk-based decision-making. The Continuous Monitoring Assessment (CMA) will involve an ongoing assessment and analysis of OCSPP’s systems security controls, ongoing reporting on the systems security posture, and support risk management decisions to help maintain OCSPP’s risk tolerance at acceptable levels. The task may include but is not limited to:
- Ensure consistent application of information security standards across all applications on the
- network.
- Ensure all new IT projects meet or integrate security standards.
- Perform internal vulnerability testing and scanning to assess the security posture using current
- tool.
- Prepare a monthly report on scanning results.
- Prepare a monthly report on the analysis of security configuration management.
- Provide recommendations for improvement of the security processes and procedures.
System Administration
- The Candidate shall be responsible for the administration of Windows Active Directory, Linux, VMware, Documentum, Web Logic, NetApp and Citrix. The Candidate shall execute additional systems administration tasks by reviewing logs for errors or warnings and resolving problems when they appear. In addition, the Candidate shall check and update the list of required periodic inspections and preventive maintenance procedures. For data protection of the LAN, the Candidate shall perform backups as per the current process and schedule (full backups will be performed weekly and incremental backups will be performed daily). Perform data restores upon request and periodically test backup system for verification purposes.
- The Candidate shall execute Service Level Agreement (SLA) for Infrastructure Operations & Maintenance