06_Attachment 3 - IT Solutions Life Cycle Management Handbook.pdf
PDF 1 MB Posted
- Attached to
- FOIA/Privacy Act System & Services Federal contract opportunity
- Solicitation number
- 16PBGC23Q0004
- Issued by
- Pension Benefit Guaranty Corporation
About this file
This Request for Quotation solicits proposals for a Freedom of Information Act Online System replacement solution and associated services for the Pension Benefit Guaranty Corporation. The solicitation seeks to modernize the agency's FOIA processing system and requests proposals for developing, implementing, and maintaining a new electronic case management platform to facilitate document intake, review, redaction, and production. Offerors should demonstrate experience developing similar FOIA case management systems for federal agencies. Proposals are due by the date specified in the solicitation and the agency intends to award a single fixed-price contract for a one-year base period with four optional one-year extensions.
View the file
Other files for this federal contract opportunity
| File | Type | Posted |
|---|---|---|
| 06_Attachment 2 - IT Solutions Life Cycle Management Framework.pdf | ||
| 06_16PBGC23Q0004_FOIA.pdf | ||
| 06_Attachment 4 - Pricing Breakout.24 Oct 2022.docx | DOCX document | |
| 06_Attachment 1 - Requirements Traceability Matrix.xlsx | XLSX spreadsheet |
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
IT Solutions Life Cycle Management Framework (ITSLCM) Handbook
Developed By: Program Management Office (PMO) Document Number: Version 2.1 Date: 01/18/2019
ITSCLM Framework Handbook i
Revision History
Version Date Change Description Author
1.0 09/22/2014 ITSLCM Framework Handbook PMO
2.0 06/22/2017 Updates to the ITSLCM Framework Handbook based on Framework v3.0
PMO
2.1 6/07/2018 Updates to Handbook based on the creation of the ITSLCM Companion Guide
PMO
2.1 11/14/2018 Update broken links PMO
2.1 01/19/2019 Add PMO manager edits PMO
Owner Signature: David Gleaton Signature Date
Approval Signature (GCB): Velma Briscoe, GCB Chair Signature/Approval Date
01/25/2019
01/29/2019 ii
Table of Contents
1.0 INTRODUCTION
1.1 HANDBOOK PURPOSE
1.2 SCOPE
1.3 BACKGROUND
1.4 KEY PARTNERS
1.5 ITSLCM FRAMEWORK OVERVIEW
2.0 THE ITSLCM FRAMEWORK – HIGH LEVEL CONCEPTS
2.1 PBGC’S IT PORTFOLIO, IT PROGRAMS, AND IT PROJECTS
2.2 5 TIERS OF IT GOVERNANCE
2.3 ITSLCM FRAMEWORK COMPONENTS
2.4 ITSLCM ROLES
3.0 ITSLCM FRAMEWORK – WALK THROUGH
3.1 THE NEED CONCEPT PHASE
3.2 THE PLANNING PHASE
3.3 THE EXECUTION PHASE
3.4 THE OPERATIONS AND DISPOSITION PHASE
1.0 Introduction
1.1 Handbook Purpose
The Information Technology Solutions Life Cycle Management (ITSLCM) Framework Handbook is a resource to assist the Pension Benefit Guaranty Corporation (PBGC) employees and contractors in navigating PBGC's ITSLCM Framework. This document presents an overview of the ITSLCM Framework phases, streams, gates and reviews, tasks, standards and guidance, deliverables, external processes, and corresponding roles required to properly execute the Framework. The Program Management Office (PMO), within the Office of Information Technology's (OIT) Business Innovation Services Department (BISD), develops and maintains this document. For additional details about the Framework and its components, contact the PMO or view the ITSLCM Companion Guide.
It is important to note that while the ITSLCM Framework and this Handbook do not call out standard project management practices (e.g., scope management, time management, cost management, quality management, human resource management, communications management, risk management, procurement management, stakeholder management), individuals should leverage project management industry best practices (e.g., Project Management Institute (PMI)).
Additionally, project management practitioners may leverage much of the project management documentation directly from the program documentation as well as create and use other artifacts that are not called out (e.g., Project Management Charter), as appropriate.
1.2 Scope
The three sections of this Handbook are: Section 1: Introduction, Section 2: The ITSLCM Framework – High Level Concepts, and Section 3: ITSLCM Framework Phases – Detailed Information. Section 1: Introduction offers insight into the history and background of the ITSLCM.
1.3 Background
The ITSLCM Framework is a governance-based framework designed to manage IT programs and projects through the identification, planning, execution, maintenance, and disposition of IT solutions at PBGC. The ITSLCM, a component of the PMO’s program, integrates the federally mandated requirements of Enterprise Architecture (EA), IT Portfolio Management (ITPfM), Program and Project Management, Infrastructure, and Cybersecurity and Privacy.
The Framework is a streamlined way for PBGC to fulfill IT needs while balancing the challenges of pension regulatory changes, emerging technologies, reducing duplication of technology and having better stewardship of IT costs, and securing data and systems.
There are several benefits to using the Framework:
Communication – Business and IT roles serve as partners who work collaboratively throughout a program’s life cycle.
Simplification – Artifacts are carefully selected to capture outcomes of tasks performed and to bring value.
Where possible, leverage IT Program management artifacts to avoid creation of unnecessary documents.
Flexibility – Enables use of various development methodologies (e.g., Iterative, Agile) and types of solutions (e.g., Cloud, COTS, Hosted, new solutions and enhancements to existing ones).
Clarity – “Streams” establish logical groupings of related tasks to be performed by the experts of the respective stream.
Transparency – Clear communication of budget, risk, and schedule from the program level through to individual projects.
Compliance – Facilitates compliance with federal IT laws, regulations, and PBGC standards.
PBGC issued its first Systems Development Life Cycle (SDLC) methodology on March 30, 2001 and it provided guidance for all system development efforts and major enhancements to existing systems. Since that time, PBGC has implemented many updates and enhancements (e.g., name change, key concepts) to ensure that the Framework continues to support the evolving industry best practices, federal mandates, and PBGC IT and business needs.
The current version is a result of the collaborative efforts of the following key partners: EA, ITPfM, Enterprise Cybersecurity, PMO, the Information Technology Infrastructure Operations Department (ITIOD), and the Privacy Office.
The Framework also includes input from members of the ITSLCM Change Control Board (CCB). The current version evolves PBGC’s approach from a process-oriented methodology to a flexible framework of requirements and moves the ITSLCM from project management and solution delivery to a higher level of governance of program management and program planning.
The Framework supports PBGC’s efforts in planning for, acquiring, delivering, and managing information technology— from developing new solutions, to modernizing, enhancing, maintaining, and operating existing solutions, through disposition of the solutions. The table below offers insight into the history and background of the ITSLCM.
Date Description July 1996 The Clinger-Cohen Act streamlines IT acquisitions and emphasizes life cycle management as a capital investment.
March 1999 An audit report from the Office of Inspector General’s Financial Statement finds that the lack of a formal SDLC methodology impacts the consistency of systems development initiatives.
March 2001 The PBGC SDLC methodology is issued to meet the requirements identified in the March 1999 Office of
Inspector General's Financial Statement Audit.
March 2002 The Systems Life Cycle Methodology (SLCM) replaces the SDLC and the scope is expanded to include all acquisition, development, and enhancement efforts related to information systems.
July 2003 The SLCM is redefined to align with the Business Planning Framework. The Business Planning
Framework, established in late 2002, defined the relationship between Strategic Planning and Corporate Initiatives that meet the agency’s goals and objectives.
FY 2004 The Office of Inspector General’s Fiscal Year 2004 Financial Statement Audit by PricewaterhouseCoopers states: “Approval Process for accepting internally developed software should be improved.”
FY 2005 The SLCM is updated to incorporate standard industry models such as the Software Engineering Institute’s (SEI) Capability Maturity Model Integration (CMMI®), and the Project Management Institute’s Project Management Body of Knowledge (PMBOK®).
October 2005 The Chief Technology Officer (CTO) signs the SLCM Corporate Policy.
March 2006 SLCM v2006.1 is released and training is conducted throughout PBGC. This release includes a detailed Requirements Development (RD) process, Requirements Management (REQM) process, and their supporting sub-processes (Business Process Model process, Peer Review process, Submit Artifacts for Approval process).
Summer 2006 The SLCM is updated in conjunction with the creation of the Project Management Life Cycle (PMLC).
The SLCM was re-designed to separate the project management and solutions delivery processes to create a more flexible and tailorable structure. During the SLCM modernization activity, the SLCM is renamed the Information Technology Solutions Life Cycle Methodology (ITSLCM).
February 2007 The ITSLCM 2007.1 is released. This release is the first iteration of an overall IT Investments Framework including Enterprise Architecture, Security, and Capital Planning – designed for managing, developing, maintaining, and decommissioning solutions. It incorporates detailed processes embedded within a Project Management Life Cycle (PMLC) and Solutions Development Life Cycle (SDLC). PBGC’s first ITSLCM Directive (IM-05-7) is published.
April 2007 The Chief Management Officer (CMO) signs the Order (Directive), which requires that all PBGC federal and contract employees adhere to the ITSLCM for delivering and managing the delivery of new and existing IT solutions. This Order replaces the SLCM Corporate Policy, dated October 7, 2005.
Date Description March 2010 A PBGC Corrective Action Plan (CAP) is delivered in response to OIG information security audit findings.
This CAP serves as a key driver for modernizing the ITSLCM to ensure continued compliance with the National Institute of Standards and Technology (NIST) 800-53 Rev. 3 (specifically, Controls SA-3 and SA- 5). The CAP's implementation schedule identifies January 2011 to initiate an ITSLCM modernization effort.
April 2011 Based on the FY2011 PBGC Security CAP, an initiative to modernize the ITSLCM begins. This results in the release of the ITSLCM Framework (v1.0). The Framework incorporates federally mandated requirements of EA, Capital Planning, Cybersecurity, Privacy, and external IT processes, including IT Governance Gates and Reviews, and IT Standards, and it defines key roles and deliverables. The ITSLCM encourages SDLC Agile and no longer endorses the Waterfall approach.
August 2014 ITSLCM Framework (v2.0) was updated to incorporate improvements based on the IT Portfolio Maturity effort; integrate requirements from Office of Management and Budget’s (OMB’s) Architect, Invest, Implement paradigm; incorporate NIST controls, and better achieve agency goals by closing gaps.
August 2015 ITSLCM Framework (v2.1) was updated to include some of process improvements identified in the P3M nine and three day working sessions. This ITSLCM more clearly defines the gates that decide if a project is to continue or stop its course of action versus the gates that just make strong recommendations.
October 2016 ITSLCM Framework (v2.2) was updated to account for the IT Portfolio Review Board (ITPRB) portfolio registration modification, Enterprise Architecture Alternatives Analysis Standard and Methodology, and Enterprise Cybersecurity standards superseded by the Cybersecurity & Privacy Catalog. These updates improve the assessment and delivery of agency IT solutions.
May 2017 ITSLCM Framework (v3.0) incorporates business process improvements derived from a nine-day working session. ITSLCM v3.0 incorporates process improvements in the areas of project and program management, Enterprise Architecture, Change and Release Management, and Cybersecurity and Privacy.
Table 1: ITSLCM History and Background
1.4 Key Partners
As a user navigates the ITSLCM Framework, it is important to leverage available assistance provided by key partners that provide input into the lifecycle process for IT solutions and the requirements that govern it. This assistance is critical to ensuring the successful development and implementation of an IT solution. These key partners are the PMO, Enterprise Architecture Division (EAD), IT Portfolio Division (ITPD), Enterprise Cybersecurity Division (ECD), ITIOD, and the Privacy Office.
In addition to the key partners listed below, there are several primary and supporting roles that help to facilitate and execute the ITSLCM Framework as described in Section 2.4: ITSLCM Roles.
1.5 ITSLCM Framework Overview
The ITSLCM Framework is a cradle-to-grave IT management framework that provides for the identification, planning, implementation, maintenance, and disposition of IT solutions throughout their lifecycle. It provides governance and direction by highlighting governance gates and reviews; standards and deliverables; roles and responsibilities (defined in the IT Management Directive 05-07); external IT processes; and required tasks across four phases: Need/Concept, Planning, Execution (Development, Modernization, Enhancement, and Maintenance), and Operations and Disposition.
The ITSLCM Framework is designed to align with the OMB Performance Improvement Life Cycle (PILC), which establishes a framework for aligning goals to results. The OMB’s PILC is a business-outcome-driven approach used to analyze and determine the necessary improvements to business processes and IT assets; then to determine where to invest to ensure every dollar invested in implementing changes to processes and/or IT assets provides the best possible return on investment in terms of business outcomes.
OMB’s PILC is comprised of three phases:
• The “Architect” phase focuses on the identification of both enterprise performance gaps and the capabilities needed to fill the gaps.
• The “Invest” phase focuses on defining the implementation and funding strategy for individual gaps identified during the “Architect” phase and ensures the alignment of project selections to the goals and objectives set forth.
• The “Implement” phase focuses on ensuring the design for the solution is executed to close the performance gaps and that the initiatives are executed and operating according to plan.
Figure 3 below depicts how the CIO’s Program components map to the ITSLCM framework phases and align with OMB’s PILC.
Figure 1: Mapping to OMB’s Performance Improvement Life Cycle
By leveraging the PILC as a basis for the ITSLCM, PBGC is enabling the IT solution management infrastructure to effectively select, implement, manage, and monitor IT initiatives. When the ITSLCM is executed properly and consistently, IT Programs address capability gaps and deliver the performance improvements that are being sought. Further, the ITSLCM Framework is structured in a way that easily demonstrates the tasks and responsibilities from the perspective of program management, project management, and information security and privacy. The ITSLCM balances governance with an appropriate amount of flexibility to allow program and project managers to complete and implement tasks in the order that aligns to their individual needs within each phase. The Framework also streamlines documentation requirements by reducing duplicative artifacts at the program and project level.
PBGC’s IT Management Directive (IM 05-07) applies to all PBGC Information Technology, throughout its lifecycle, regardless of the source of funding or resources owned and operated on behalf of PBGC.
2.0 The ITSLCM Framework – High Level Concepts
2.1 PBGC’s IT Portfolio, IT Programs, and IT Projects
In order to comprehend how programs and projects relate to each other throughout a solution’s lifecycle, it is first important to understand the ITPfM process and how the IT Programs are organized within the process.
The purpose of PBGC’s ITPfM program is to establish, maintain, and support an effective IT Portfolio analysis, selection, and decision-making environment at PBGC. The ITPfM program works in conjunction with EA and PMO to facilitate the Architect, Invest, and Implement paradigm. PBGC’s ITPfM program embodies OMB’s Capital Planning and Investment Control (CPIC) guidance to achieve the aforementioned goals. The CPIC Cycle includes the Prioritize, Control, and Evaluate reviews and is intended to ensure the success and overall health of the PBGC IT Portfolio. The Appendix includes an overview of IT portfolio governance at PBGC.
The Prioritize Review assesses the IT programs and projects and validates the budget, scope, and schedule to recommend prioritization for budgetary decision-making. Prioritization criteria includes alignment with Corporate and IT Strategic goals and objectives, alignment with the EA Roadmap, and implementation readiness.
The Control Review assesses program and project performance resulting in recommendations on continued funding and ensuring that the project is continuing to fulfill the Corporation’s strategic IT needs in a timely and cost-efficient manner.
Program control criteria includes cost performance index (CPI), schedule performance index (SPI), and progress against program measures. Project control criteria includes project manager (PM) qualifications and certifications; CPI; SPI; and an assessment of reliability, sustainability, and executability.
The Evaluate Review assesses the steady state or managed service performance. It also notes changes in the business or technology drivers that may result in recommendations to continue funding or initiate a new planning phase. Evaluate criteria includes program performance measures, business drivers, technology drivers, and operations and maintenance (O&M) costs.
PBGC’s Strategic Plan and IT Strategic Plan communicate PBGC’s goals and objectives. IT Programs use information technology resources to achieve efficient and effective business operations to meet PBGC’s strategic goals, performance goals and priorities, and strategies. IT Programs include the planning, development, modernization, enhancements, operations, and maintenance of IT projects and managed services. IT Projects are temporary endeavors, with a defined start and end date, to develop, modernize, and/or enhance an IT solution that contributes to the IT Program’s measurable benefits. An IT Project may be delivered in one or more releases using various development approaches (see Appendix for more information) enabling modular development. The collection of IT Programs managed as a group to achieve PBGC strategic goals and objectives comprises the PBGC IT Portfolio. Below is a representation of the PBGC IT Program structure.
Figure 2: IT Portfolio Management https://www.pbgc.gov/sites/default/files/pbgc-strategic-plan-2018-2022.pdf https://www.pbgc.gov/sites/default/files/pbgc-it-strategic-plan-2018-2022.pdf
Figure 3: PBGC IT Program Structure
The IT Programs are grouped logically by functionality and service affinity to ensure ease of organization and understanding. Additionally, the IT Program structure ensures an optimal amount of alignment and compliance with reporting requirements. This optimization enables greater integration throughout the enterprise and an increased capacity to leverage common resources, documentation, and lessons learned. This increased capacity is important as federal requirements increasingly encourage IT integration, data sharing, and cloud-based solutions. For these efficiencies to be fully realized it requires open and continuous communication between projects and their sponsoring programs and then among the programs within the portfolio.0F
1 IT Programs are reported at the OMB Agency IT Portfolio Summary level and are tracked by lifecycle phase to support consistency, transparency, and ease.
1 For more information on the PBGC IT Portfolio, please visit the ITPD website.
https://pbgcgov.sharepoint.com/EGD/ITPD/Pages/ITPfM_Overview.aspx
2.2 5 Tiers of IT Governance PBGC’s IT Management Directive (IM 05-07) outlines 5 Tiers of Governance for managing scope, cost, schedule, risks, and issues. These tiers are labeled as follows:
Tier 1- Project Management (IT and Business) Tier 2- Program Management (IT and Business) Tier 3- Steering/Oversight Committees (CIO and associated Chief Officer, also commonly referred to as the CXO) Tier 4- PBGC Governance Boards Tier 5- OMB
All IT Programs and Projects follow this 5 Tier Governance model. Tiers 1 and 2 form the foundation of IT governance at PBGC. In these tiers practitioners, meaning the IT and Business Project and Program Managers, closest to the activities actively manage all aspects of IT Projects and Programs. In Tier 3, Steering/Oversight Committees led by the CIO and CXO review the status of IT Projects, IT Programs, risks, issues, etc. In Tier 4, oversight is provided by corporate-level governance boards such as the ITPRB, the Executive Management Committee (EMC), and Budget Planning and Integration Team (BPIT).
Tier 5 involves external oversight from OMB, which is above and beyond the solid internal oversight provided by Tiers 1 through 4.
Each of the groups outlined within the 5 tiers are supported by the PMO but are governed by different entities. Tiers 1 through 3 are governed by the ITPRB, Tier 4 is governed by the CIO, and Tier 5 is governed by OMB.
The ITSLCM Framework aligns with PBGC’s 5 Tier Governance model. The Framework provides guidance on the tasks, standards, deliverables and reviews needed within each phase to align with the 5 Tier Governance, including who is responsible for completing each activity based on their role.
2.3 ITSLCM Framework Components
The ITSLCM is comprised of four phases which incorporate tasks that satisfy requirements of applicable federal mandates and regulations related to EA, ITPfM, IT security, privacy, program and project management, infrastructure, and federal acquisition:
1. Need/Concept: New business needs are identified and requests for new solutions are submitted and guided through a structured IT Program Authorization Review to determine if it should be classified as IT and if so, how it might impact PBGC’s IT Portfolio. The ETA for current and planned systems and technologies in comparison to planned projects is reviewed.
2. Planning: Detailed program and project planning tasks are conducted and documented. Planning elements, such as the establishment of the Program Management Plan (PgMP), IT Program Release Plan, Project Management Plan (PMP) (if needed), product selection, and selection of development methodology, are all completed in this phase. The tasks and deliverables in this phase are produced to ensure that a budget, scope, and schedule are in place, so the solution meets the intended business need, as well as to ensure that IT resources are being planned and managed in accordance with all applicable federal policies and mandates and internal PBGC policies and directives.
3. Execution (Development, Modernization, Enhancement, and Maintenance): The IT solution is designed, developed, implemented, tested, and deployed with an Authority to Operate (ATO). Programs and projects are monitored and reported on. Maintenance activities (patching, vendor-supported versions, and defect correction) needed to sustain the IT solution at the current capability and performance levels. It includes corrective hardware and software maintenance, voice and data communications maintenance and service, and replacement of broken or obsolete IT equipment. The ITPRB conducts quarterly project control reviews to assess PM qualifications and certifications, CPI, SPI, and to assess reliability/sustainability/executability.
4. Operations and Disposition: During this phase, the operations support is provided to the IT solution in the agency’s production environment per the last set of approved requirements. Tasks associated with solution operations in the production environment include service desk support, backups, disaster recovery/Continuity of Operations Plan [COOP]. Once it is determined an IT solution or program is at the end of its useful life cycle, disposition activities include destroying, recycling, or repurposing IT solutions.
Each phase incorporates tasks that satisfy requirements of applicable federal mandates and regulations related to enterprise architecture, ITPfM, IT cybersecurity and privacy, program and project management, along with external-related processes (e.g., infrastructure, IT risk management, federal acquisition, etc.). The tasks, across the four phases, are separated into three streams:
1. Program Management: Identifies tasks associated with providing centralized, coordinated management of an IT program (which may consist of multiple IT Projects or IT-related initiatives) to achieve business goals and objectives. Program planning also includes all tasks associated with both the IT Portfolio Process (Prioritize, Control, and Evaluate reviews) and EA requirements. It focuses on achieving defined benefits (closing performance gaps), aligning to the corporate and IT Strategic Plans, and managing program resources. This objective is achieved by promoting these goals along with best practices and guidance on IT program management to business and IT program managers.
2. Project & Technology Management: Identifies tasks associated with applying knowledge, skills, tools, and techniques to project tasks in order to plan, execute, monitor, and control IT projects effectively by achieving cost, schedule, and/or performance goals. Focuses on planning and implementing solutions. This objective is achieved by leveraging project management best practices.
3. Cybersecurity & Privacy: Identifies information security and privacy related tasks that emphasizes managing risk at three different tiers within PBGC: (1) agency-wide security and privacy risks; (2) business/mission function security and privacy risks, and (3) information system security and privacy risks. This includes tasks associated with the information and instructions necessary for determining, documenting, tracking, and reporting: an information system's mission areas, and the overall agency's security and privacy risks, thereby improving information security and privacy risk management within PBGC. ECD and the Privacy Office have their own process, the PBGC Information Security Risk Management Framework (RMF) Process. ITSLCM users should reference the RMF for required security and privacy tasks.
The following page provides a snapshot of the ITSLCM Framework with the aforementioned components highlighted and the remainder of Section 2 explains each of these components.
Figure 4: ITSLCM Framework
2.4 ITSLCM Roles
Before describing the ITSLCM phases, it is important to understand the other roles that play a part in the ITLSCM. The graphic below provides an overview of the roles and how they relate to others – more detailed descriptions of the roles is included in the IT Management Directive (IM 05-07). The next section provides the phases and corresponding roles.1F
Figure 5: ITSLCM Roles
2 In addition to those shown in the graphic, there are a number of roles that support and/or influence ITSLCM activities. Such roles may include Subject Matter Experts (SMEs) from organizations such as: Procurement Department (PD), Budget Department (BD), Workplace Solutions Department (WSD), Human Resources Department (HRD), and technical/infrastructure SMEs. These SMEs may participate in an as needed and consultative manner, depending upon the nature of the IT program/project and its maturity in the ITSLCM Framework.
3.0 ITSLCM Framework – Walk Through
3.1 The Need Concept Phase
3.1.1 Program Management Stream
There are two gates in the Need/Concept Phase:
• IT Program Authorization
• ITPRB IT Portfolio Registration Review
The most critical participants include:
• Requester
• EAD
• ECD
• Infrastructure
• ITPD
• ITPRB
Tasks: During the Need/Concept Phase, requests are submitted and guided through a structured IT Portfolio Registration Review to determine if it should be classified as IT and, if so, how it might impact PBGC's IT Portfolio.
The IT Portfolio Registration Presentation supports ITPRB decisions about whether to classify a budget request as IT/non-IT and helps determine potential impact to PBGC's IT Portfolio.
The results of the above process will establish the applicability of proceeding through the ITSLCM:
• If the business need can be met using an existing IT solution: Where an IT solution already exists that will fulfill the business need, a GetIT request to obtain access to the IT solution is submitted. No subsequent ITSLCM tasks are required.
• If the business need can be met through enhancing an existing IT solution: Where an IT solution exists, but needs to be modified or enhanced, the business requirements will be identified, and preliminary analysis and market research conducted on the resources required. Cost, schedule, and scope changes are submitted to the program area's designated CCB for review and approval. When a budget request is being made, the changes are than submitted with the ITPRB to update PBGC's IT Portfolio to reflect the appropriate changes. The IT Program Plan for that respective program will also then be updated.
• If the business need requires establishing a new IT solution: Where no IT solution exists within the organization, and a new solution or program is needed to fulfill the business need, sponsorship for the new program will be finalized and a new IT Program Plan will need to be created and the new program added to PBGC's IT Portfolio.
If a new IT Program is established, the Sponsor assumes responsibility for the program and a new IT Program Plan is developed.
There are three deliverables associated with this phase/stream:
1. IT Portfolio Registration Presentation
2. Business Needs Analysis Document
3. Alternatives Analysis
There are two standards associated with this phase/stream:
• Business Needs Analysis Standard
• Alternatives Analysis Standard
3.1.2 The Project and Technology Management Stream
The Need/Concept Phase is the first phase in the ITSLCM Framework. There are no gates/reviews, tasks, deliverables, or standards in this phase/stream.
3.1.3 The Cybersecurity and Privacy Stream
There are no gates/reviews, tasks, deliverables, or standards in this phase/stream.
3.1.4 External Processes
There is one external process:
• IT Risk Management
3.2 The Planning Phase
3.2.1 The Program Management Stream
There is one gate in the Planning Phase:
• ITPRB Prioritization
The most critical participants include:
• IT & Business Program Managers
• ITPRB
In the Program Management Stream, the IT and Business Program Managers are the key roles, and their primary responsibility is building, updating, and maintaining the IT Program Plan. This means planning the tasks for the program and consists of, at minimum, annually reviewing and updating the IT Program Plan.
The expectation is that the projects will then leverage the plans established at the program level. The documentation of this activity should be included within the IT Program Plan which contains the following, though not limited to, program information:
• Component Projects
• Scope
• Dependencies to other IT programs
• Program/Project Team Members
• EA Alignment
• TCO
• Acquisition Strategy
• Risk Register
• Quality Management
• Performance Measures https://pbgcgov.sharepoint.com/EGD/EAD/Pages/EAStandards.aspx https://pbgcgov.sharepoint.com/EGD/EAD/Pages/EAStandards.aspx https://pbgcgov.sharepoint.com/EGD/EAD/Pages/EAStandards.aspx https://pbgcgov.sharepoint.com/EGD/EAD/Pages/EAStandards.aspx https://www.pbgc.gov/sites/default/files/itslcm-framework.pdf https://pbgcgov.sharepoint.com/EGD/ITPD/Pages/ITPRB_Overview.aspx https://pbgcgov.sharepoint.com/EGD/PCD/PPL/PBGC%20Business%20Needs%20Analysis%20Standard%20and%20Methodology%20(Apr%202017).pdf https://pbgcgov.sharepoint.com/EGD/PCD/PPL/PBGC%20Alternatives%20Analysis%20Standard%20and%20Methodology%20(May%202016).pdf
All IT Programs undergo an annual ITPRB Prioritization Review where they are assessed for alignment and implementation readiness. The results of this review are then submitted as prioritization recommendations to the BPIT. The Prioritization Review assesses the IT programs and projects and validates the budget, scope, and schedule to recommend prioritization for budgetary decision-making. Prioritization criteria includes alignment with Corporate and IT Strategic goals and objectives, alignment with the EA Roadmap, and implementation readiness.
Program baselining occurs during the ITPRB Prioritization Review.
There are two deliverables associated with this phase/stream:
• IT Program Plan
• Alternatives Analysis
3.2.2 The Project and Technology Management Stream
There is one gate in the Planning Phase:
• TRB Product Review
The most critical roles include:
• IT & Business Project Managers
• TRB
• PMO
There are four tasks associated with this phase/stream:
• In this phase, plans established at the program level are implemented. Select development approach
• Developing a Cost Loaded Project Schedule
• Select the product or technology to fulfill the business need identified and documenting the high-level requirements and design
• Completion of the planning phase usually requires a Product Review by the TRB.
Project baselining (cost, schedule, and scope) occurs during the Planning Phase.
There is one standard in the Planning Phase:
• Alternatives Analysis Standard
3.2.3 The Cybersecurity and Privacy Stream
Since ECD and the Privacy Office have their own process, ITSLCM users should refer to the RMF and consult the ISSO for assistance.
The most critical participants include:
• ISSO
• Information System Owner (ISO) and/or Information Owner (IO)
• ECD and the Privacy Office
Deliverables associated with the Cybersecurity and Privacy stream of the Planning Phase are outlined in the PBGC Information Security RMF, which is located in the PPL.
There are five standards and guidance in the Planning Phase:
• Cybersecurity and Privacy Catalog https://pbgcgov.sharepoint.com/EGD/EAD/Pages/TRB_Home.aspx https://pbgcgov.sharepoint.com/EGD/EAD/Pages/EAStandards.aspx https://pbgcgov.sharepoint.com/EGD/EAD/Pages/EAStandards.aspx https://pbgcgov.sharepoint.com/EGD/PCD/PPL/PBGC%20Cybersecurity%20and%20Privacy%20Catalog%20v.1.3.pdf#search=cybersecurity
• RMF Process
• System of Records Notice (SORN) Guide
• Privacy Impact Assessment (PIA) Guide
• Interconnection Security Agreement (ISA) Guide
3.2.4 External Processes
There are five external processes:
• IT Risk Management
• The Acquisitions Process
• Budget Formulation and Execution
• Configuration Management
• Release Management
3.3 The Execution Phase
3.3.1 The Program Management Stream
There is one gate in the Execution Phase.
• ITPRB Semi-Annual Program Review
The most critical participants include:
The IT and Business Programs Managers’ primary responsibility is making regular updates to the IT Program Plan.
Program managers also conduct IT performance monitoring. As part of ongoing monitoring, all IT Programs must also comply with PBGC’s Performance Management approach identified in the Performance Management Brochure.
Preparation is made for program-level reviews with the ITPRB. Program managers are responsible for monitoring the project-level review outcomes for any of their component projects in the execution phase and for engaging IPgTs and/or IPTs for assistance in preparing for reviews.
There are two deliverables in this phase/stream:
• IT Program Plan
• Program Performance Reports
There are no applicable standards or guidance in this phase/stream.
3.3.2 The Project and Technology Management Stream
There are four gates in the Project and Technology Management Stream of the Execution Phase including the
1st CAB ITPRB (Quarterly Project Review) TRB (Design Review) https://pbgcgov.sharepoint.com/EGD/PCD/PPL/PBGC%20Information%20Security%20Risk%20Management%20Framework%20(RMF)%20Process.pdf#search=RMF%20process https://pbgcgov.sharepoint.com/OGC/Privacy/PRL/SORN%20Guide%20v.3%20with%20Appendices.pdf#search=sorn%20guide https://pbgcgov.sharepoint.com/Directives/Shared%20Documents/PIA%20Guide-w.-Appendices.pdf#search=privacy%20impact%20assessment https://pbgcgov.sharepoint.com/OGC/Privacy/PRL/SORN%20Guide%20v.3%20with%20Appendices.pdf#search=sorn%20guide https://pbgcgov.sharepoint.com/EGD/ITPD/Pages/ITPRB_Overview.aspx https://pbgcgov.sharepoint.com/BISD/PMO/Shared%20Documents/IT-Performance-Management-Brochure-Final.pdf https://pbgcgov.sharepoint.com/BISD/PMO/Shared%20Documents/IT-Performance-Management-Brochure-Final.pdf https://pbgcgov.sharepoint.com/ITIOD/Pages/ITBCMChangeAdvisoryBoard.aspx https://pbgcgov.sharepoint.com/EGD/ITPD/Pages/ITPRB_Overview.aspx https://pbgcgov.sharepoint.com/EGD/EAD/Pages/TRB_Home.aspx
CAB (Production/COOP Deployment Review)
There are four standards in the Execution Phase:
Design Document Standard:
Development Standard Enterprise Data Standard Software Service Standard
There are three IPT reviews in this stream of the Execution Phase.
The most critical participants in this stream and phase include: IT & Business Project Managers, IPT, ITPRB, CAB, TRB.
Additional requirements documentation is developed to elaborate on the high-level requirements defined during the Planning Phase. Execution of the selected development approach occurs as part of Technology Solution Management within this stream. This phase includes solution development lifecycle tasks (requirements, design, build, test, and deploy). The IPT engages the release and change management processes to move the solution through the Execution phase and into production. ShareIT (requires access) is a SharePoint Site that facilitates collaboration between the development and operations teams by providing access to the most up-to-date versions of relevant system/application documents.
ShareIT will be used to create living documents and facilitate real-time communication and updates between teams on IT systems and solutions. The IT and Business Project Managers are required to monitor and report CPI, SPI, CV, SV, and EV for individual IT Projects, including relationship and dependencies between other projects to the IT/Business Program Managers. Careful consideration must be given when analyzing IT Performance Management data. Budget and schedule variances must be evaluated to identify and resolve underlying problems. Project managers report on their project's performance at the ITPRB Quarterly Project Review. After the solution has been deployed into production, the IT Project Manager works with the ISSO as well as ECD and the Privacy Office to establish the ATO from the AO/CIO/SAISO if appropriate. Upon receiving ATO, the IPT may commence stabilizing the solution, granting access to users, establishing service desk support, and transitioning the system into operations. It is important to note that not every project/release will require an ATO. The ATO is only updated und There are ten standards and guidance for the Project and Technology Management Stream in the Execution Phase.
3.3.3 The Cybersecurity and Privacy Stream
Since ECD and the Privacy Office have their own process, ITSLCM users should refer to the RMF and consult the ISSO for assistance.
There are two gates in the Execution Phase:
• Post-Assessment Controls Review
• ATO
The most critical participants include:
• ISSO
• ISO and/or IO
• ECD and the Privacy Office
• AO
• Chief Information Security Officer (CISO)
• Senior Agency Official for Privacy (SAOP) https://pbgcgov.sharepoint.com/ITIOD/Pages/ITBCMChangeAdvisoryBoard.aspx https://pbgcgov.sharepoint.com/EGD/PCD/PPL/PBGC%20Design%20Document%20Standard%20and%20Methodology.pdf https://pbgcgov.sharepoint.com/EGD/PCD/PPL/PBGC%20Development%20Standard%20and%20Methodology.pdf https://pbgcgov.sharepoint.com/EGD/PCD/PPL/PBGC%20OIT%20Enterprise%20Data%20Standard%20and%20Methodology.pdf https://pbgcgov.sharepoint.com/EGD/PCD/PPL/PBGC%20OIT%20Software%20Services%20Standard%20and%20Methodology.pdf https://pbgcgov.sharepoint.com/sites/p-ShareIT
• Chief Privacy Officer (CPO)
• Independent Assessor
Deliverables associated with the Cybersecurity and Privacy stream of the Execution Phase are outlined in the PBGC Information Security RMF, which is located in the PPL.
There are four standards and guidance in the Execution Phase:
• RMF Process
• Enterprise Continuous Monitoring (ECM) Plan
• Information System Continuous Monitoring (ISCM) Plan
3.3.4 External Processes
There are six external processes in the Execution Phase:
• Configuration Management
• Release and Deployment Management
• Acquisitions
• Change Management
• IT Risk Management
• IT Service/Incident/Problem Management
3.4 The Operations and Disposition Phase
3.4.1 The Program Management Phase
There are two gates in the Operations & Disposition Phase:
• ITPRB (Annual OA)
• ITPRB Disposition Review
In the Program Management Stream, the IT and Business Programs Managers' primary responsibility is monitoring and reporting solutions to ensure they are being effectively managed and maintained in the agency's production environment.
Program managers continue to maintain updates to the IT Program Plan with annual maintenance/steady state tasks including results of their operational analysis. Preparation also occurs for annual program-level reviews with the ITPRB. The ITPRB evaluate reviews assess programs against performance measures, O&M/managed service cost analysis, business/technology driver changes, and overall health of the program.
IT and Business Program Managers may discover, through monitoring and reporting, the need to consider re-baselining the overall IT program.
The following are acceptable reasons for making a request to re-baseline:
https://pbgcgov.sharepoint.com/EGD/PCD/PPL/PBGC%20Cybersecurity%20and%20Privacy%20Catalog%20v.1.3.pdf#search=cybersecurity https://pbgcgov.sharepoint.com/EGD/PCD/PPL/PBGC%20Cybersecurity%20and%20Privacy%20Catalog%20v.1.3.pdf#search=cybersecurity https://pbgcgov.sharepoint.com/EGD/PCD/PPL/PBGC%20Information%20Security%20Risk%20Management%20Framework%20(RMF)%20Process.pdf#search=RMF%20process https://pbgcgov.sharepoint.com/EGD/PCD/PPL/Enterprise%20Continuous%20Monitoring%20(ECM)%20Strategy%20and%20Plan%20v2.0.pdf#search=continuous https://pbgcgov.sharepoint.com/EGD/PCD/PPL/Enterprise%20Continuous%20Monitoring%20(ECM)%20Strategy%20and%20Plan%20v2.0.pdf#search=continuous https://pbgcgov.sharepoint.com/EGD/PCD/PPL/Enterprise%20Continuous%20Monitoring%20(ECM)%20Strategy%20and%20Plan%20v2.0.pdf#search=continuous
• Significant change in goals
• Implementation approach is iterative or incremental
• Current baseline is no longer useful
If it is determined that an IT program or solution is no longer meeting a business or IT need, program managers write justifications which demonstrate that the program is no longer needed or has been overcome by legislative mandate or technological advances.
The IT Program Plan is the only deliverable associated with this phase/stream.
There are no applicable standards or guidance in this phase/stream
3.4.2 The Project and Technology Management Phase
There is one applicable IPT Review:
• Disposition Review
The most critical participants include:
• IT & Business Project Managers
• IPT
Tasks
• Monitoring and reporting on solutions to ensure they are effectively managed in the production environment
• Provide production support to the solution
• Monitor and report project performance
• Disposition Review (if applicable)
Although there are standard annual maintenance tasks that must occur in operations, it is important to note that maintenance projects can require completing some or all of the Planning and Execution Phase tasks depending on the size and scope of the project. There may be instances when some maintenance tasks must be completed out of cycle to accommodate a system change, organizational change, or new business requirement. Because of the cyclical nature of the phases, when new business requirements are identified to enhance an IT solution in production, an IT project is initiated, and project managers will follow the tasks outlined in earlier phases of the ITSLCM Framework.
There are no deliverables in this phase/stream.
There are no applicable standards or guidance in this phase/stream
3.4.3 The Cybersecurity and Privacy Stream
Since ECD and the Privacy Office have their own process, ITSLCM users should refer to the RMF and consult the ISSO for assistance.
There are two gates in the Operations & Disposition Phase:
• Ongoing Authorization Review
• Disposition Process Review
• ISSO
• ISO and/or IO
• AO
• ECD and the Privacy Office
Deliverables associated with the Cybersecurity and Privacy stream of the Operations and Disposition Phase are outlined in the PBGC Information Security RMF, which is located in the PPL.
There are three standards and guidance in the Operations & Disposition Phase:
• RMF Process
• PIA Guide
3.4.4 External Processes
There are five external processes in the Operations and Disposition Phase:
• Configuration Management
• IT Risk Management
• The Acquisitions process
• Change Management
• IT Service/Incident/Problem Management https://pbgcgov.sharepoint.com/EGD/PCD/PPL/PBGC%20Cybersecurity%20and%20Privacy%20Catalog%20v.1.3.pdf https://pbgcgov.sharepoint.com/EGD/PCD/PPL/PBGC%20Cybersecurity%20and%20Privacy%20Catalog%20v.1.3.pdf https://pbgcgov.sharepoint.com/EGD/PCD/PPL/PBGC%20Information%20Security%20Risk%20Management%20Framework%20(RMF)%20Process.pdf#search=RMF%20process https://pbgcgov.sharepoint.com/Directives/Shared%20Documents/PIA%20Guide-w.-Appendices.pdf#search=privacy%20impact%20assessment
| 1.0 Introduction |
| 1.1 Handbook Purpose |
| 1.2 Scope |
| 1.3 Background |
| 1.4 Key Partners |
| 1.5 ITSLCM Framework Overview |
| 2.0 The ITSLCM Framework – High Level Concepts |
| 2.1 PBGC’s IT Portfolio, IT Programs, and IT Projects |
| 2.2 5 Tiers of IT Governance |
| 2.3 ITSLCM Framework Components |
| 2.4 ITSLCM Roles |
| 3.0 ITSLCM Framework – Walk Through |
| 3.1 The Need Concept Phase |
| 3.1.1 Program Management Stream |
| If the business need can be met using an existing IT solution: Where an IT solution already exists that will fulfill the business need, a GetIT request to obtain access to the IT solution is submitted. No subsequent ITSLCM tasks are required. |
| If the business need can be met through enhancing an existing IT solution: Where an IT solution exists, but needs to be modified or enhanced, the business requirements will be identified, and preliminary analysis and market research conducted on the... |
| If the business need requires establishing a new IT solution: Where no IT solution exists within the organization, and a new solution or program is needed to fulfill the business need, sponsorship for the new program will be finalized and a new IT P... |
| 3.1.2 The Project and Technology Management Stream |
| 3.1.3 The Cybersecurity and Privacy Stream |
| 3.1.4 External Processes |
| 3.2 The Planning Phase |
| 3.2.1 The Program Management Stream |
| There are two deliverables associated with this phase/stream: |
| 3.2.2 The Project and Technology Management Stream |
| 3.2.3 The Cybersecurity and Privacy Stream |
| 3.2.4 External Processes |
| 3.3 The Execution Phase |
| 3.3.1 The Program Management Stream |
| 3.3.2 The Project and Technology Management Stream |
| 3.3.3 The Cybersecurity and Privacy Stream |
| 3.3.4 External Processes |
| 3.4 The Operations and Disposition Phase |
| 3.4.1 The Program Management Phase |
| 3.4.2 The Project and Technology Management Phase |
| Tasks |
| 3.4.3 The Cybersecurity and Privacy Stream |
| 3.4.4 External Processes |
File details come from the government source that posted it. Updated .