CLOUDSTORE GUIDELINES Version 1.0, 17 Feb 2015 Info-communications Development Authority of Singapore 10 Pasir Panjang Road #10-01 Mapletree Business City Singapore 117438 Copyright of IDA, 2015 This document may be downloaded from the IDA website at http://www.ida.gov.sg and shall not be reproduced, or distributed without written permission from IDA. Page 1 of 13 CloudStore Document #3a
Glossary of Key Terms and Abbreviations The meaning and definition of terms in this document shall be the same as those found in the Glossary of Key Terms and Abbreviations in the CloudStore Terms and Conditions. Version 1.0, 17 Feb 2015 Page 2 of 13 CloudStore Document #3a
Contents 1. Government Cloud Programme... 4 2. CloudStore Overview... 4 3. How Call For Participation Works... 5 4. CloudStore Qualification... 5 5. CloudStore Listing... 6 6. Update Qualified Offering Information... 6 7. Renewal of Qualification... 7 8. Government Agency and Statutory Board Procurement... 8 9. Fee Structure... 8 ANNEX A CLOUDSTORE QUALIFICATION FOR SAAS... 9 1. Qualification Process for SaaS... 9 2. Enhanced Qualification Process for SaaS on G-Cloud... 9 3. Deployment of Qualified SaaS On G-Cloud... 10 ANNEX B GOVERNMENT CLOUD FACTSHEET... 11 1. Introduction... 11 2. Restriction On G-Cloud Access For Administration... 11 3. G-Cloud Services... 11 Version 1.0, 17 Feb 2015 Page 3 of 13 CloudStore Document #3a
1. Government Cloud Programme 1.1 The first phase of the Government Cloud programme, completed in 2013, provides Infrastructure-as-a-Service offerings for Government agencies and statutory boards on the Government Cloud (G-Cloud). 1.2 G-Cloud provides resilient computing resources to meet security and governance requirements across the whole-of-government. Government agencies and statutory boards can currently subscribe to a full range of Infrastructure-as-a-Service for hosting websites and e-services. Services available for subscription include compute, storage, network, security, operating systems, middleware and databases. 1.3 In Phase 2 of the G-Cloud programme, IDA plans to set up a CloudStore to provide a marketplace of qualified cloud offerings from the industry for Government agencies and statutory boards to consider during procurement. 2. CloudStore Overview 2.1 The CloudStore will provide a listing of qualified cloud offerings by categories. Companies interested in participating in the CloudStore shall submit their applications to IDA for qualification via a Call for Participation process. Once IDA has qualified the submitted offering, it will be listed on the CloudStore for Government agencies and statutory boards to consider for their procurement. Government agencies and statutory boards will carry out their own evaluation and procure Qualified Offerings via quotations/tenders. CloudStore Qualified Offerings SaaS on Public Clouds SaaS on G-Cloud Other Categories Analytics Security Testing CRM Qualification Process Call for Participation Industry Evaluation Qualified Offering By Category Ongoing At regular cycles Valid for 24 months Figure 1: CloudStore Overview Version 1.0, 17 Feb 2015 Page 4 of 13 CloudStore Document #3a
2.2 The CloudStore will benefit the industry as it provides a channel for cloud providers to showcase their cloud offerings to Government agencies and statutory boards. Agency Procurement of cloud offerings will be simplified. The increased adoption of cloud offerings for the public sector ICT needs will mean faster turnaround time and improve public service delivery. 3. How Call For Participation Works 3.1 When IDA decides to add a new category on the CloudStore, IDA will issue a CFP to invite industry applications for the category. Once a CFP has been issued for a category, it remains open indefinitely for on-going CloudStore s until IDA declares it closed. The CFP process is illustrated in Figure 2 below. CloudStore Call For Participation (CFP) CFP for Category X CFP stays open. CloudStore applications for Cat X can be submitted at any time. (Cat X) (Cat X) (Cat X) CFP for Category Y CFP stays open. CloudStore applications for Cat Y can be submitted at any time. (Cat Y) (Cat Y) (Cat Y) CFPs will be called to add new Categories Figure 2: Call for Participation Process 3.2 The CloudStore Forms to be submitted for a given category will be spelt out in its CFP. 3.3 Evaluations of CloudStore s will be carried out in regular cycles. 3.4 Once IDA declares a CFP closed, it will stop accepting CloudStore s for the closed category. 4. CloudStore Qualification 4.1 Participants should first ascertain the categories that are open for application. For easy reference, Instruction to Participants (Annex A) at http://www.ida.gov.sg/programmespartnership/sectors/government/initiatives/cloudstore lists all the CloudStore CFPs, the categories opened for application and the CloudStore Forms for each category. 4.2 Participants shall submit CloudStore s for each offering they wish to offer on the CloudStore. Version 1.0, 17 Feb 2015 Page 5 of 13 CloudStore Document #3a
4.3 Evaluation of CloudStore s will be carried out periodically at regular cycles. While CloudStore s for a category can be submitted at any time during its CFP period, evaluation of the CloudStore s by IDA will only be carried out at the next evaluation cycle. 4.4 Any CloudStore received when an evaluation cycle is in progress shall be processed during the next evaluation cycle. 4.5 Participants shall note that if there is a re-submission of a CloudStore when an evaluation cycle has commenced, IDA will suspend the evaluation of the CloudStore and process the re-submission in the next evaluation cycle. 4.6 Participants shall provide clear information about their offerings to enable evaluation to be carried out. 4.7 CloudStore s which IDA have evaluated to have met the qualification criteria will be awarded the Qualification by IDA. 4.8 The Qualification shall be valid for 24 months. 4.9 Participants shall be notified about the result of their application as outlined in the CloudStore Terms and Conditions. 4.10 The Qualification is only applicable to the specific version of the Qualified Offering that had undergone the evaluation. It shall not be transferrable or be applicable to other portfolio or versions of product(s) under the Qualified Provider. 4.11 The CloudStore Qualification process for SaaS is further set out in CloudStore Guidelines (Annex A). 5. CloudStore Listing 5.1 Upon Qualification, the Qualified Offering shall be listed on the CloudStore. 5.2 Participants shall note that all information about the Qualified Offering submitted for evaluation (including technical, service catalogue and pricing information) will be made available on the CloudStore. The CloudStore website will be available on the Government intranet with unrestricted access. 5.3 The availability of the CloudStore website on the internet shall be at IDA s sole discretion. 6. Update Qualified Offering Information 6.1 Qualified Providers can submit requests to update the Qualified Offering by using the appropriate form provided by CloudStore. 6.2 The process for the update of Qualified Offering information is illustrated in Figure 3 below. Version 1.0, 17 Feb 2015 Page 6 of 13 CloudStore Document #3a
Update Qualified Offering Information Process Submit Update Request Evaluation Updates Approved Publish Updated Information By Qualified Provider By IDA at regular cycles By IDA By IDA Figure 3: Update Qualified Offering Information Process 6.3 Update requests shall only be processed during an evaluation cycle. Once processed, IDA will notify the Qualified Provider about the outcome of the update request via email. IDA shall not be obliged to provide any reasons for rejecting the update request. 6.4 When the update request is approved, the updated listings shall be published as described in clause 5. 7. Renewal of Qualification 7.1 Qualified Providers shall submit the qualification renewal form provided by CloudStore in order to renew any Qualification before it expires. The renewal application shall be made to IDA no later than four (4) months before the expiry of the Qualification. Renewal of Qualification Process Submit Renewal 4 months before expiry Evaluation At regular cycles Notify Outcome To Qualified Provider Qualification Renewed Qualification Not Renewed Publish Updated Information Remove CloudStore Listing Figure 4: Renewal of Qualification Process 7.2 When the qualification renewal is approved, the renewed listing shall be published as described in clause 5. 7.3 If the qualification renewal is not approved, the relevant CloudStore listing will be removed accordingly. 7.4 If no Qualification renewal application is received by IDA, the CloudStore listing will be removed when the Qualification expires. In such cases, IDA reserves the right to remove the listing without notification to the company. Version 1.0, 17 Feb 2015 Page 7 of 13 CloudStore Document #3a
8. Government Agency and Statutory Board Procurement 8.1 Government agencies and statutory boards will be able to view a listing of Qualified Offerings and access information for each Qualified Offering on CloudStore. 8.2 When a Government agency or a statutory board decides to procure from the CloudStore, all procurement shall be carried out via GeBIZ. 8.3 The Government and statutory boards are not bound to procure from the CloudStore and have the option to procure via other procurement methods. 8.4 Qualified Service Providers shall be required to provide regular reporting, on the spend by Government agencies and statutory boards on its Qualified Offering/Qualified Offerings, to the CloudStore. 9. Fee Structure 9.1 Currently, IDA does not collect any fees for CloudStore qualification and participation. IDA reserves the right to impose fees in the future. Version 1.0, 17 Feb 2015 Page 8 of 13 CloudStore Document #3a
Annex A ANNEX A CLOUDSTORE QUALIFICATION FOR SAAS 1. Qualification Process for SaaS 1.1 IDA will consider CloudStore s for SaaS hosted on public clouds and/or G- Cloud. 1.2 The basic qualification criteria for SaaS is primarily based on assessed capability with focus on strength and track record, technical and operations which include service features, service delivery and service support criteria. 1.3 The qualification process for SaaS is shown in Figure 5. CloudStore s for SaaS on G-Cloud will undergo an enhanced qualification process. After evaluation, shortlisted CloudStore s shall be required to undergo a SaaS on G-Cloud Hosting Assessment process before award of Qualification. Qualification Process For SaaS CFP Opens Company submits CloudStore IDA evaluates CloudStore If SaaS on G-Cloud SaaS on G-Cloud Hosting Assessment Qualification Outcome By category of offering At regular cycles Walk-through with shortlisted applications Qualification valid for 2 years Figure 5: Qualification Process For SaaS 1.4 General information about G-Cloud is provided in Annex B G-Cloud Factsheet to allow the Participant to have a general understanding about G-Cloud and G-Cloud services. More detailed information about G-Cloud will only be provided to CloudStore s shortlisted to undergo the SaaS on G-Cloud Hosting Assessment. 2. Enhanced Qualification Process for SaaS on G-Cloud 2.1 The enhanced qualification process for SaaS offerings to be hosted on G-Cloud is shown in Figure 6. Enhanced Qualification for SaaS on G-Cloud Evaluation SaaS on G-Cloud Hosting Assessment Meet G-Cloud pre-requisite Criteria Meet Basic Qualification Criteria Walk-through SaaS on G-Cloud hosting model Complete SaaS on G-Cloud Information Similar evaluation as SaaS on Public Cloud To ascertain SaaS deployment model on G-Cloud Update offering info with G-Cloud specifics Figure 6: Enhanced Qualification for SaaS on G-Cloud Version 1.0, 17 Feb 2015 Page 9 of 13 CloudStore Document #3b
Annex A 2.2 The G-Cloud pre-requisite criteria are specified in the CloudStore Form. Information about SaaS on G-Cloud Hosting Assessment shall only be provided to Participants with shortlisted CloudStore s that have passed G-Cloud prerequisite criteria and basic qualification criteria. The Participant shall be required to sign a non-disclosure agreement (in a form as prescribed by IDA) before the additional G-Cloud information will be released to the Participant. 2.3 The SaaS on G-Cloud Hosting Assessment involves a walkthrough with the Participant to ascertain the SaaS deployment model on G-Cloud. It involves a detailed exchange of information between the Participant and the G-Cloud team on areas such as SaaS architecture deployment, network bandwidth requirements, firewall requirements and G-Cloud Infrastructure-as-a-Service required. 2.4 Upon successful completion of the G-Cloud Qualification, the Participant shall complete all required Qualified Offering information for its SaaS on G-Cloud for submission to IDA. 3. Deployment of Qualified SaaS On G-Cloud 3.1 There is no prescribed timeline for the Qualified Provider to set up its Qualified SaaS on G-Cloud. 3.2 The Qualified Provider shall note that security audits and reviews for its Qualified SaaS on G-Cloud must be carried out before the Qualified SaaS on G-Cloud can be used by any Government agency or statutory board customer. The Qualified Provider shall engage an independent and competent third-party auditor to conduct security audit and reviews and to document the security findings and recommendations in a report for IDA s consideration. The scope of the security review shall include application security assessment and penetration testing. 3.3 It is the Qualified Provider s responsibility to determine when it wishes to fulfil the requirements of clause 3.2 above. The Qualified Provider should factor this into the schedule during Agency Procurement. 3.4 The Qualified Provider shall notify IDA at least one month in advance of the planned deployment of the Qualified SaaS on G-Cloud. Version 1.0, 17 Feb 2015 Page 10 of 13 CloudStore Document #3b
Annex B ANNEX B GOVERNMENT CLOUD FACTSHEET 1. Introduction 1.1 Government Cloud (G-Cloud) is the next generation whole-of-government infrastructure, leveraging on the benefits of cloud computing. It provides efficient, scalable and resilient cloud computing resources and is designed to meet different levels of security and governance requirements: a. Intranet Zone for hosting of corporate applications used by Government agencies and/or statutory boards; and provides connectivity to the Singapore Government network; and b. Internet Zone for hosting of applications to serve the public; and provides connectivity to the internet. 1.2 G-Cloud is a virtualized hosting environment based on the x86 architecture - using VMware vsphere version 5 (as of 1 Sep 2012). More information on virtual machines (VMs) and virtualisation can be found at VMware s website (http://www.vmware.com/virtualization/virtual-machine.html). 2. Restriction On G-Cloud Access For Administration 2.1 Administration of any G-Cloud VM or any G-Cloud component can only be carried out via the Singapore Government Network. No remote administration via the internet is allowed. In addition, personnel shall be security cleared by the Singapore Government before participation in the project. 3. G-Cloud Services 3.1 A summary of G-Cloud services available in the internet zone and intranet zone are shown in the table below: Services Internet Zone Intranet Zone Service Availability options for Hosting VMs 95%, 99%, 99.5%, 99.9% and 99.95% 95%, 99%, 99.5%, 99.9% and 99.95% Compute Services Software Services Internet Access Services 1 vcpu 2GB RAM, 2 vcpu 4GB RAM, 4 vcpu 8GB RAM, 8 vcpu 16GB RAM (up to max 12 vcpus, 32 RAM) per VM All software on catalogue available for subscription 1Mbps shared bandwidth provided per customer. Additional bandwidth can be subscribed. 1 vcpu 2GB RAM, 2 vcpu 4GB RAM, 4 vcpu 8GB RAM, 8 vcpu 16GB RAM (up to max 12 vcpus, 32 RAM) per VM All software on catalogue available for subscription 1Mbps shared bandwidth provided per customer. Additional bandwidth can be subscribed. Version 1.0, 17 Feb 2015 Page 11 of 13 CloudStore Document #3c
Annex B Services Internet Zone Intranet Zone Backup & Offsite Archival Services Subscription options: Disk-to-disk Disk-to-disk-to-tape Subscription options: Disk-to-disk Disk-to-disk-to-tape SMTP Services Available for e-services Available for e-services (Intranet Systems must use SG-Mail) SFTP Services Subscription by diskspace required Subscription by diskspace required Administration Services Optional subscription Optional subscription 3.2 Additional information for some of the G-Cloud services are as follows: a. Compute & Storage Service Service Item Pricing Model Compute Service Compute Scaling 1 vcpu, 2 GB 2 vcpu, 4 GB 4 vcpu, 8 GB 8 vcpu, 16 GB Per vcpu Scaling (up to 12 vcpu) Per GB RAM Scaling (up to 32GB RAM) Per month Per day Per hour Per month Per day The following standard services are bundled with Compute & Storage Service Baseline and adhoc client virtual machine (VM) snapshot Activation and changes to frequency of online backup and restoration of VM and storage Configuration of network, load balancer, firewall, and system monitoring components De-provisioning of virtual resources Any scaling must be carried out via the self-service portal provided by G-Cloud. Scaling through application programming interfaces (API) is currently not supported by G-Cloud. b. Internet Access Service Service Items Pricing Internet Access Bandwidth Shared Internet Free bundled 1Mbps SLA of Internet Access Service at 99.9% Version 1.0, 17 Feb 2015 Page 12 of 13 CloudStore Document #3c
Annex B c. Software Services Service Operating Systems Service Web Server Software Service Server Software Service Database Software Service Item MS Windows Server (Std/Ent) Linux Redhat Enterprise Solaris on x86 Suse Linux Microsoft IIS Server Oracle Web Tier (prev k.a. iplanet) Microsoft IIS Server Oracle Weblogic Server (Std/Ent) Oracle Glassfish Server (prev k.a. Sun Java) IBM Websphere App Server (Express/Std/Network) Microsoft SQL Server (Std/Ent) Oracle Database Server (Std/Ent) IBM DB2 Server (Express/Ent/Workgrp)* For other software licenses not provided on G-Cloud, the Qualified Provider shall ensure that software terms of use allows for deployment in a virtualised / cloud environment; ensure that software is kept up to date and patched, especially for security patches; and provide its own software upgrades. Version 1.0, 17 Feb 2015 Page 13 of 13 CloudStore Document #3c