With this request for participation, the Tax Administration (later also the Customer) requests applications for participation.
The target of the acquisition is the Tax Administration's management, maintenance and development service for a cloud platform based on the Microsoft Azure public cloud. Together with the Tax Administration, the Finnish Tax Administration is looking for a partner to be responsible for the areas of management, maintenance and development of the cloud platform in strategic, tactical and operational level functions in the target area.
The content of the service covers the architecture of the Tax Administration's cloud platform, server management, telecommunications, monitoring, incident management, information security, data protection, support for application development, development and measurement of internal operations, and production and maintenance of documentation for the cloud platform.
The acquisition covers the management, maintenance and development services of the cloud platform as well as the implementation project.
More detailed descriptions of the services to be procured are attached to the participation request. The procurement will be carried out through a negotiated procedure in accordance with the Act on Public Procurement and Concession Contracts.
The Finnish Tax Administration's cloud environment is essentially a hybrid environment. A special feature is that the environment is both technically and partly technically part of the state's shared telecommunications and IT environments. Valtori's partner in these joint solutions is Valtori. The Finnish Tax Administration's own onprem data center is produced as a service by another partner.
The cloud environment is broadly IaaS-based. Microservice architecture and serverless solutions are considered on a case-by-case basis, considering the costs and benefits.
The Finnish Tax Administration's cloud strategy is the "cloud first" policy, in which the possibility of using cloud services is primarily investigated for new development targets and only onprem solutions secondarily. The Microsoft cloud adoption framework and Azure well architected framework have been used as the basis for environmental management. Cloud operations primarily aim at infrastructure as a code (IaC)-based implementation.
In the Tax Administration's operations, cloud manageability and reliability are the number one priorities. For this reason, only general availability type Azure services are used in the cloud. Third-party products are used judiciously, through separate explanations and exceptions.
Taking into account the Tax Administration's operating environment, special attention is paid to information security and data protection. The least priviledge principle is an integral part of the cloud operating model. Changes to information security/technical architecture are carefully planned and implemented and implemented through the Tax Administration's change management process. The Tax Administration's environments are not operated from anywhere other than computers owned by the Tax Administration, the policies of the Tax Administration, the Tax Administration's networks and with minimum access rights. Zero-trust operations are under development. The cyber and information security of the Tax Administration's environment is monitored by the SecurityOperationCenter (SOC) led by the Tax Administration.
The Finnish Tax Administration's cloud environment includes an extensive analytics environment built with Azure native components, applications built with Azure native components, and virtual server-based application entities transferred from the data center.
The cloud platform produces and maintains the Finnish Tax Administration's Azure cloud platform for use in other products and applications. The cloud platform is responsible for the common operating models of the Tax Administration's Azure environment and is responsible for ensuring that the cloud platform is used in accordance with the architecture and information security practices agreed upon by the Tax Administration. The cloud platform is also responsible for ensuring that applications have uniform practices for application development in the cloud environment (incl. DevSecOps). In addition, the cloud platform is responsible for the centrally provided functionalities of the Tax Administration's cloud environment (e.g. server management).
The Finnish Tax Administration currently employs a team of about 20 people to develop and maintain the cloud platform. There are 7 own persons who will remain to work together with the Supplier in accordance with Appendix 1e Organization Description. Application development for cloud applications is not part of making a cloud platform, nor is it part of this tendering.
The Cloud Partnership includes:
-Cloud platform management, maintenance and development service takeover project
-basic fixed-price service
-Services
-separate development projects and small-scale development