10 - AED Draft SLAs.xlsx

XLSX spreadsheet 32 KB Posted

Attached to
Request for Information: Award Eligibility Determination Federal contract opportunity
Solicitation number
Not on record
Issued by
Department of Education

About this file

This document contains proposed Service Level Agreements (SLAs) for the Award Eligibility Determination (AED) system. Key details include specific performance metrics for system availability, incident response times, imaging and printing turnaround times, calculation processing timeframes, and defect identification and remediation. It also outlines cybersecurity requirements such as two-factor authentication, hardware and software asset inventory and configuration management, vulnerability and patch management, and cybersecurity framework scorecard standards. Additional terms address contractor personnel security screening timelines for submitting security clearance forms and monitoring expiration dates. The SLAs establish financial penalties for failures to meet designated targets.

View the file

Other files for this federal contract opportunity

Other files attached to Request for Information: Award Eligibility Determination, newest first.
File Type Posted
01 - Award Eligibility Determination Requirements_REVISED PER CE.pdf PDF
02 - Pricing Template.xlsx XLSX spreadsheet
07 - Hosting Environments w Approved ATOs.pdf PDF
06 - FSA NARA Universal Electronic Records Management Requirements v2.03.xlsx XLSX spreadsheet
05 - Hosting Environments with Approved Agency ATOs.pdf PDF
04 - Additional Current State Technical Constraints.xlsx XLSX spreadsheet
12 - CPS 101 with FA impacts 09102020.pdf PDF
11 - ED CSF Risk Scorecard Overview_July 2020.pdf PDF
09 - FSA Current State.pdf PDF
AED RFI Final.pdf PDF
03 - Security Technical Requirements.xlsx XLSX spreadsheet
08 - FSA Identity Access Mgt Solution Overview.docx DOCX document
Show all 12

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

AED SLAs

DRAFT Service Level Agreements (SLAs) for AED
FSA GoalNext Gen GoalAED GoalAED ObjectivesSLA CategorySLA Sub Category
(If Applicable)SLA TitleSLA DescriptionDefinitionUnit of MeasurePerformance MeasureTargetIssuePenaltyRemidiationComments
Empower a high performing organizationExecute efficient business operationsMaintain and continually enhance the student aid information processing system-Eliminating defects in the overall calculation flow

-Increasing the interoperability of data

-Promoting fast, available processing of data

-Quickly and accurately image, scan, print, and mail documents for customers System Performance N/A System Availability System is available for > 99.9% of the time not including scheduled system maintenance Total amount of system up time divided by (the total amount of time in the reporting period less any scheduled maintenance time) Percentage up-time > 99.9% up-time between 98% - 99.9% up-time between 95% - 98% up-time less than 95% Funding reduction by 0.5% Funding reduction by 1.0% Penalty is incurred by the root-cause of the outage or degradation (application, platform, infrastructure, etc.)

Incident Notification TimelinessFSA requirement for notification from contractor for incident identificationFSA requires notification of Critical incidents within 30 minutes of the incident 24/7, High incidents with one (1) hour 24/7, and Medium incidents reported daily on business daysTicket ReportingSee Definition
Imaging, Printing, and ScanningFSA requirement for the contractor to image applications, scan them into the database, print and mail SAR and SAR acknowledgementsTotal amount of time for imaging, printing, and scanningTurnaround Time4 business days>4 business days

>5 business days >6 business days Funding reduction by 0.5% Funding reduction by 1.0%� Printing and Distributing FSA requirement for contractor to print and mail SAR, SAR acknowledgements forms, subsequent application letters, and any other documents that are required for this process Total amount of time for printing and mailing items Turnaround Time 4 business days 1. SAR: 100% mailed in 4 business days

2. SAR Acknowledgements: 100% mailed in 4 business days

3. Letters: 100% mailed in 4 business days Funding reduction by 0.5% Funding reduction by 1.0%�

Compute ProcessingCalculation of results within the systemTotal amount of time for imaging, printing, and scanningTurnaround Time72 hours / real timeCompute processing with external matches: 100% in 72 hours
Without external matches, in real timeFunding reduction by 0.5%

Funding reduction by 1.0%� Testing N/A Defects Found in UAT FSA requires the contractor to deliver a system for UAT with minimal defects If it has to go through 508 compliance then Zero (0) Critical defects , Zero (0) High defects, Less than ten (10) Medium defects found during UAT

If it has to be 508- compliant, then five (5) or less defects found during UAT Count See Definition If it has to go through 508 compliance then Zero (0) Critical defects , Zero (0) High defects, Less than ten (10) Medium defects found during UAT

If it has to be 508- compliant, then five (5) or less defects found during UATFunding reduction by 0.5%
Funding reduction by 1.0%�Define the word defects and include the vehicle to be used to monitor. Currently we receive a Production Defect Density report from GDOS which has been useful to monitor trends is defects across releases.
Defect Closure - UATTimely closure of defects found in UATAny defects found in UAT that are not resolved before the first release must be resolved by the second releaseCountAll UAT defects resolved by second AED releaseAll UAT defects not resolved by second AED releaseFunding reduction by 1%
Defect Closure - ProductionTimely closure of defects found in ProductionAny defects found in production must be resolved in the next two releasesCountAll production defects resolved within two releasesAll production defects not resolved within two releasesFunding reduction by 1%
Strengthen data protection and cybersecurityContinuously evolve data protection and cybersecurityUpdate and evolve data protection and cybersecurity continuously-Develop and maintain a secure environment for processing of users (i.e. customers, students, and other stakeholders) financial aid data that can quickly identify, notify, and remediate security incidentsSecurityAccess ControlMandatory Use of Two Factor Authentication (TFA)Privileged users that access or monitor systems or applications, must use a Privileged Access Management capability with TFA unless other arrangements have been made with FSA.Number of users not using TFA0See Cybersecurity Framework Scorecard
Configuration ManagementAsset InventoryHardware and Software Asset inventory is accurate and up-to-date daily with weekly notifications of assets additions, modifications/changes or deletions.Number of assets reported as accurate and timely99.90%See Cybersecurity Framework Scorecard
Configuration ManagementSecure Configurations for Hardware & SoftwareInfrastructure components in use by the vendor shall be hardened and use FSA approved hardening guides.Percent of the Number of Conforming Components99.90%See Cybersecurity Framework Scorecard
AuditAudit and Audit SupportFailure to provide audit support to FSA or FSA auditors through failure of timely delivery of requested audit artifacts or impediment of unfettered access to FSA network attached devices.Requested Artifacts Provided On-Time0.999See Cybersecurity Framework Scorecard
AuditAudit Findings and Repeat Audit FindingsNo repeat audit findings, and AARTS (OIG and GAO) findings will be closed within 1 yearPercent of Audit Findings Corrected On-time0.999See Cybersecurity Framework Scorecard
Incident ResponseMean Time to Security Event Discovery (MTED)All security events, as defined by OCIO-14 Incident Categories 1, 2, 3 and Category 4, will be communicated to the EDCIRC within 2 hours of event trigger or discovery. After Contract Award: The specific OCIO-14 Department CAT 4 reportable events will be defined in the Systems Incident Response Plan and approved by the FSA CISO.Not done in the times identified per the guidance2 hoursSee Cybersecurity Framework Scorecard
Incident ResponseEvidence Collection and Protection (ECP)Evidence for any security incident must be maintained in a tamper proof manner and should be made available for legal and regulatory purposes, as required by federal and DoED/FSA policy. All Request for Information, i.e. log requests, incident evidence will be acknowledged and fulfilled within 72 hours unless other arrangements have been made with the FSA SOC.Percent of On-Time Incident Security Requests Fulfilled72 hoursSee Cybersecurity Framework Scorecard
Incident ResponseTime to Security Incident NotificationSuspicious Event Report (SER) must be created for all suspicious activity that may indicate the potential of data breach, violation or policy, intrusion attempt, etc. delivered within 1 hour and must be updated before close of business (per Department policy OCIO-14) unless other arrangements have been made with the FSA SOCPercent of On-time Security Event Reports1 hourSee Cybersecurity Framework Scorecard
Vulnerability ManagementCybersecurity Framework ScorecardThe Cybersecurity Framework Scorecard is a risk-based determination of a systems compliance and cybersecurity posture produced by the Department on a monthly basis.Scorecard produces a range of scores from 0.0 to 3.03Funding reduction by:

2.75 to 3.00 – 0%

2.00 to 2.74 - 0.5%

0.00 to 1.99 – 5%

Vulnerability ManagementRisk Management and Flaw RemediationFlaw remediation will be accomplished within 10 (ten) calendar days for all Critical/Serious/Very High vulnerabilities discovered, within 30 calendar days for High vulnerabilities discovered, within 90 calendar days for Moderate vulnerabilities, and 120 days for Low vulnerabilities, unless agreed to by FSA.No critical security findings and all non-remediated findings have a risk acceptanceNot done in the timely manner expected per the guidanceSee Cybersecurity Framework Scorecard
Vulnerability ManagementPatching ProgramInfrastructure components, hardware, and software shall be patched following the OCIO 3-112, OCIO STND-01, and FSA patch remediation guidelines as follows unless other arrangements have been made with FSA CISO.Percent of Completed Patches within the Department/FSA policy99.90%See Cybersecurity Framework Scorecard
Empower a high performing organizationExecute efficient business operationsEnsure the system has sufficient resources to securely conduct operations at all times-Streamlining internal security clearance processing times

-Guarantee prompt response to COR and ISSO requests from the vendor e-Qip N/A Timely submission of e-Qip Submit e-Qip form to the COR/ISSO within 10 business days of a contractor employee’s assignment to a Department contract and ensure that the forms are accurate and complete (reference EDARS 3452.239-72 Department Security Requirement). (Time frame may change based upon Departmental policy) Send a confirmation email to the FSA CO/COR/ISSO and Program Management by 5:00PM of the due date that certifies the success of complete, accurate, and timely clearance submission. Business Days See Definition $5,000 per 6C, $2,500 per 5C, and $500 per 1C over the standard in the reporting period.

95% complete and timely submissions over monthly period

Period – Monthly Metric

Disincentive - $5,000 per 6C, $2,500 per 5C, and $500 per 1C over the standard in the reporting period.

NOTE: Example: For a contractor employee reporting for duty Monday, August 17, 2015, e-Qip initiation form must be received by 5:00PM of Tuesday, August 18, 2015.
Timely resolution of e-Qip information deficienciesIf any information on forms required by e-Qip are not complete or the submission is returned for any reason, the contractor must resubmit the forms to the COR/ISSO within 7 (reference OM: 5-101 Contractor Employee Personnel Security Screenings) business days or the contractor employee must be removed from the contractSend a confirmation email to the FSA CO/COR/ISSO and Program Management by 5:00PM of the due date that certifies the success of timely clearance form re-submission or the removal of the contract employee from the contract.Business DaysSee Definition$5,000 per 6C, $2,500 per 5C, and $500 per 1C over the standard in the reporting period

99% complete, accurate, and timely re-submission over monthly period

Period – Monthly Metric

Disincentive - $5,000 per 6C, $2,500 per 5C, and $500 per 1C over the standard in the reporting period
ClearanceN/AClearance MonitoringWhen clearance information is returned with clearance type and date issued, monitor contractor employee clearance and employment status under the contract to ensure clearances renewals are submitted 30 calendar days prior to expiration, departed employees are identified and removed, and any clearance changes are annotated.A consolidated report of all employees in the format shown below will be submitted to the COR and ISSO (copy to the CO) within 5 business days following each three-month period of performance for identification of changes over the last quarter (new employees, employees with clearance in process (and status), change in clearance type, and resubmittals for employees 30 calendar days prior to clearance expiration and departed employees).Business DaysSee DefinitionDisincentive - $1,000 per error over the standard in the reporting period.

95% complete and accurate over quarterly period

Period – Quarterly Metric

Submittal of quarterly report does not replace timely requests for e-Qip for new employees, monitoring status of clearance/clearance renewal requests, requesting clearance renewals 30 days before expiration, or notification that an employee has departed. COR will spot check quarterly and submit annually to the Security Office for a 100% validation when requested.

Timely Submittal of Clearance RenewalsEDARS 3452.239-72 Department Security Requirement requires contractor employees in High Risk 6 (C) positions to submit clearance packages for re-investigation every five years. Once a contractor employee receives their clearance, an issuance and expiration date will be provided back to the contractor for tracking. Contractors must submit re-investigation packages to e-Qip 30 calendar days prior to clearance expiration.A confirmation email to the FSA CO/COR/ISSO and Program Management 30 calendar days prior to the Clearance expiration date that certifies the success of complete, accurate, and timely clearance re-submissions.Calendar DaysSee Definition$1,000 per error over the standard in the reporting period.
Tier II Help DeskN/ASolution AccuracyMinimal amount of calls to Tier II Help Desk require follow-uptotal number of calls where there was no follow-up required divided by the total number of callsPercentageFollow-up Percentage < 98%Follow-up Percentage between 98%-99%
Follow-up Percentage > 99%Funding reduction by 1%

Contractual changes?

FSA Tech Response TimeSpeed of Response required within one (1) business day to FSA Tech List Serve Postingstotal number of responses to FSA Tech List Serve provided within one (1) business day divided by the total number of FSA Tech List Serve requestsPercentage100.00%Speed of response between 99% - 100%
Speed of response < 99%Funding reduction by 1%

Contractual changes?

Forecast AccuracyVariance between forecast work effort and actual work effort based on baselined average handle time for each channelForecasted effort for each channel less the actual work effortHoursTBDVariance > 5%Funding reduction by 1% per sprint affectedShould story points be used?
Prompt AnswersHow quickly incoming phone calls are answered% of calls answered in 20 secondsPercentage80%<80%Funding reduction by 1%
Increase parner engagements and oversight effectivenessStreamline partnerships with institutionsDevelop and solidify partnerships with stakeholders-Interview and meet with schools and software developers to understand how AED could empower their work
-Implement feedback into AED development and finalizationN/A

AED Goals

FSA GoalsNext Gen GoalsAED GoalsAED Objectives
Empower a high performing organizationExecute efficient business operationsMaintain and continually enhance the student aid information processing systemEliminating defects in the overall calculation flow

Increasing the interoperability of data Promoting fast, available processing of data Quickly and accurately image, scan, print, and mail documents for customers Ensure the system has sufficient resources to securely conduct operations at all times Streamlining internal security clearance processing times Guaranteeing the prompt responding to COR and ISSO requests

Provide a world class customer experienceOptimize the customer experienceOptimize the user (i.e. customers, internal users, students) experienceSatisfy student aid recipients by promptly and fully addressing all questions and issues related to their EFC and other financial aid instruments
Strengthen data protection and cybersecurityContinuously evolve data protection and cybersecurityUpdate and evolve data protection and cybersecurity continuouslyDevelop and maintain a secure environment for processing of users (i.e. customers, students, and other stakeholders) financial aid data that can quickly identify, notify, and remediate security incidents
Increase partner engagement and oversight effectivenessStreamline partnerships with institutionsDevelop and solidify partnerships with stakeholdersInterview and meet with schools and software developers to understand how AED could empower their work

Implement feedback into AED development and finalization Enhance portfolio management and transparency Drive improved outcomes for taxpayers Increase communication and transparency with other Next Gen projects and the FUTURE Act TBD

File details come from the government source that posted it. Updated .