10 - AED Draft SLAs.xlsx
XLSX spreadsheet 32 KB Posted
- Attached to
- Request for Information: Award Eligibility Determination Federal contract opportunity
- Solicitation number
- Not on record
- Issued by
- Department of Education
About this file
This document contains proposed Service Level Agreements (SLAs) for the Award Eligibility Determination (AED) system. Key details include specific performance metrics for system availability, incident response times, imaging and printing turnaround times, calculation processing timeframes, and defect identification and remediation. It also outlines cybersecurity requirements such as two-factor authentication, hardware and software asset inventory and configuration management, vulnerability and patch management, and cybersecurity framework scorecard standards. Additional terms address contractor personnel security screening timelines for submitting security clearance forms and monitoring expiration dates. The SLAs establish financial penalties for failures to meet designated targets.
View the file
Other files for this federal contract opportunity
| File | Type | Posted |
|---|---|---|
| 01 - Award Eligibility Determination Requirements_REVISED PER CE.pdf | ||
| 02 - Pricing Template.xlsx | XLSX spreadsheet | |
| 07 - Hosting Environments w Approved ATOs.pdf | ||
| 06 - FSA NARA Universal Electronic Records Management Requirements v2.03.xlsx | XLSX spreadsheet | |
| 05 - Hosting Environments with Approved Agency ATOs.pdf | ||
| 04 - Additional Current State Technical Constraints.xlsx | XLSX spreadsheet | |
| 12 - CPS 101 with FA impacts 09102020.pdf | ||
| 11 - ED CSF Risk Scorecard Overview_July 2020.pdf | ||
| 09 - FSA Current State.pdf | ||
| AED RFI Final.pdf | ||
| 03 - Security Technical Requirements.xlsx | XLSX spreadsheet | |
| 08 - FSA Identity Access Mgt Solution Overview.docx | DOCX document |
Show all 12
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
AED SLAs
| DRAFT Service Level Agreements (SLAs) for AED | ||||||||||
| FSA Goal | Next Gen Goal | AED Goal | AED Objectives | SLA Category | SLA Sub Category | |||||
| (If Applicable) | SLA Title | SLA Description | Definition | Unit of Measure | Performance Measure | Target | Issue | Penalty | Remidiation | Comments |
| Empower a high performing organization | Execute efficient business operations | Maintain and continually enhance the student aid information processing system | -Eliminating defects in the overall calculation flow |
-Increasing the interoperability of data
-Promoting fast, available processing of data
-Quickly and accurately image, scan, print, and mail documents for customers System Performance N/A System Availability System is available for > 99.9% of the time not including scheduled system maintenance Total amount of system up time divided by (the total amount of time in the reporting period less any scheduled maintenance time) Percentage up-time > 99.9% up-time between 98% - 99.9% up-time between 95% - 98% up-time less than 95% Funding reduction by 0.5% Funding reduction by 1.0% Penalty is incurred by the root-cause of the outage or degradation (application, platform, infrastructure, etc.)
| Incident Notification Timeliness | FSA requirement for notification from contractor for incident identification | FSA requires notification of Critical incidents within 30 minutes of the incident 24/7, High incidents with one (1) hour 24/7, and Medium incidents reported daily on business days | Ticket Reporting | See Definition | |
| Imaging, Printing, and Scanning | FSA requirement for the contractor to image applications, scan them into the database, print and mail SAR and SAR acknowledgements | Total amount of time for imaging, printing, and scanning | Turnaround Time | 4 business days | >4 business days |
>5 business days >6 business days Funding reduction by 0.5% Funding reduction by 1.0%� Printing and Distributing FSA requirement for contractor to print and mail SAR, SAR acknowledgements forms, subsequent application letters, and any other documents that are required for this process Total amount of time for printing and mailing items Turnaround Time 4 business days 1. SAR: 100% mailed in 4 business days
2. SAR Acknowledgements: 100% mailed in 4 business days
3. Letters: 100% mailed in 4 business days Funding reduction by 0.5% Funding reduction by 1.0%�
| Compute Processing | Calculation of results within the system | Total amount of time for imaging, printing, and scanning | Turnaround Time | 72 hours / real time | Compute processing with external matches: 100% in 72 hours | ||
| Without external matches, in real time | Funding reduction by 0.5% |
Funding reduction by 1.0%� Testing N/A Defects Found in UAT FSA requires the contractor to deliver a system for UAT with minimal defects If it has to go through 508 compliance then Zero (0) Critical defects , Zero (0) High defects, Less than ten (10) Medium defects found during UAT
If it has to be 508- compliant, then five (5) or less defects found during UAT Count See Definition If it has to go through 508 compliance then Zero (0) Critical defects , Zero (0) High defects, Less than ten (10) Medium defects found during UAT
| If it has to be 508- compliant, then five (5) or less defects found during UAT | Funding reduction by 0.5% | ||||||||||||
| Funding reduction by 1.0%� | Define the word defects and include the vehicle to be used to monitor. Currently we receive a Production Defect Density report from GDOS which has been useful to monitor trends is defects across releases. | ||||||||||||
| Defect Closure - UAT | Timely closure of defects found in UAT | Any defects found in UAT that are not resolved before the first release must be resolved by the second release | Count | All UAT defects resolved by second AED release | All UAT defects not resolved by second AED release | Funding reduction by 1% | |||||||
| Defect Closure - Production | Timely closure of defects found in Production | Any defects found in production must be resolved in the next two releases | Count | All production defects resolved within two releases | All production defects not resolved within two releases | Funding reduction by 1% | |||||||
| Strengthen data protection and cybersecurity | Continuously evolve data protection and cybersecurity | Update and evolve data protection and cybersecurity continuously | -Develop and maintain a secure environment for processing of users (i.e. customers, students, and other stakeholders) financial aid data that can quickly identify, notify, and remediate security incidents | Security | Access Control | Mandatory Use of Two Factor Authentication (TFA) | Privileged users that access or monitor systems or applications, must use a Privileged Access Management capability with TFA unless other arrangements have been made with FSA. | Number of users not using TFA | 0 | See Cybersecurity Framework Scorecard | |||
| Configuration Management | Asset Inventory | Hardware and Software Asset inventory is accurate and up-to-date daily with weekly notifications of assets additions, modifications/changes or deletions. | Number of assets reported as accurate and timely | 99.90% | See Cybersecurity Framework Scorecard | ||||||||
| Configuration Management | Secure Configurations for Hardware & Software | Infrastructure components in use by the vendor shall be hardened and use FSA approved hardening guides. | Percent of the Number of Conforming Components | 99.90% | See Cybersecurity Framework Scorecard | ||||||||
| Audit | Audit and Audit Support | Failure to provide audit support to FSA or FSA auditors through failure of timely delivery of requested audit artifacts or impediment of unfettered access to FSA network attached devices. | Requested Artifacts Provided On-Time | 0.999 | See Cybersecurity Framework Scorecard | ||||||||
| Audit | Audit Findings and Repeat Audit Findings | No repeat audit findings, and AARTS (OIG and GAO) findings will be closed within 1 year | Percent of Audit Findings Corrected On-time | 0.999 | See Cybersecurity Framework Scorecard | ||||||||
| Incident Response | Mean Time to Security Event Discovery (MTED) | All security events, as defined by OCIO-14 Incident Categories 1, 2, 3 and Category 4, will be communicated to the EDCIRC within 2 hours of event trigger or discovery. After Contract Award: The specific OCIO-14 Department CAT 4 reportable events will be defined in the Systems Incident Response Plan and approved by the FSA CISO. | Not done in the times identified per the guidance | 2 hours | See Cybersecurity Framework Scorecard | ||||||||
| Incident Response | Evidence Collection and Protection (ECP) | Evidence for any security incident must be maintained in a tamper proof manner and should be made available for legal and regulatory purposes, as required by federal and DoED/FSA policy. All Request for Information, i.e. log requests, incident evidence will be acknowledged and fulfilled within 72 hours unless other arrangements have been made with the FSA SOC. | Percent of On-Time Incident Security Requests Fulfilled | 72 hours | See Cybersecurity Framework Scorecard | ||||||||
| Incident Response | Time to Security Incident Notification | Suspicious Event Report (SER) must be created for all suspicious activity that may indicate the potential of data breach, violation or policy, intrusion attempt, etc. delivered within 1 hour and must be updated before close of business (per Department policy OCIO-14) unless other arrangements have been made with the FSA SOC | Percent of On-time Security Event Reports | 1 hour | See Cybersecurity Framework Scorecard | ||||||||
| Vulnerability Management | Cybersecurity Framework Scorecard | The Cybersecurity Framework Scorecard is a risk-based determination of a systems compliance and cybersecurity posture produced by the Department on a monthly basis. | Scorecard produces a range of scores from 0.0 to 3.0 | 3 | Funding reduction by: |
2.75 to 3.00 – 0%
2.00 to 2.74 - 0.5%
0.00 to 1.99 – 5%
| Vulnerability Management | Risk Management and Flaw Remediation | Flaw remediation will be accomplished within 10 (ten) calendar days for all Critical/Serious/Very High vulnerabilities discovered, within 30 calendar days for High vulnerabilities discovered, within 90 calendar days for Moderate vulnerabilities, and 120 days for Low vulnerabilities, unless agreed to by FSA. | No critical security findings and all non-remediated findings have a risk acceptance | Not done in the timely manner expected per the guidance | See Cybersecurity Framework Scorecard | ||||
| Vulnerability Management | Patching Program | Infrastructure components, hardware, and software shall be patched following the OCIO 3-112, OCIO STND-01, and FSA patch remediation guidelines as follows unless other arrangements have been made with FSA CISO. | Percent of Completed Patches within the Department/FSA policy | 99.90% | See Cybersecurity Framework Scorecard | ||||
| Empower a high performing organization | Execute efficient business operations | Ensure the system has sufficient resources to securely conduct operations at all times | -Streamlining internal security clearance processing times |
-Guarantee prompt response to COR and ISSO requests from the vendor e-Qip N/A Timely submission of e-Qip Submit e-Qip form to the COR/ISSO within 10 business days of a contractor employee’s assignment to a Department contract and ensure that the forms are accurate and complete (reference EDARS 3452.239-72 Department Security Requirement). (Time frame may change based upon Departmental policy) Send a confirmation email to the FSA CO/COR/ISSO and Program Management by 5:00PM of the due date that certifies the success of complete, accurate, and timely clearance submission. Business Days See Definition $5,000 per 6C, $2,500 per 5C, and $500 per 1C over the standard in the reporting period.
95% complete and timely submissions over monthly period
Period – Monthly Metric
Disincentive - $5,000 per 6C, $2,500 per 5C, and $500 per 1C over the standard in the reporting period.
| NOTE: Example: For a contractor employee reporting for duty Monday, August 17, 2015, e-Qip initiation form must be received by 5:00PM of Tuesday, August 18, 2015. | |||||
| Timely resolution of e-Qip information deficiencies | If any information on forms required by e-Qip are not complete or the submission is returned for any reason, the contractor must resubmit the forms to the COR/ISSO within 7 (reference OM: 5-101 Contractor Employee Personnel Security Screenings) business days or the contractor employee must be removed from the contract | Send a confirmation email to the FSA CO/COR/ISSO and Program Management by 5:00PM of the due date that certifies the success of timely clearance form re-submission or the removal of the contract employee from the contract. | Business Days | See Definition | $5,000 per 6C, $2,500 per 5C, and $500 per 1C over the standard in the reporting period |
99% complete, accurate, and timely re-submission over monthly period
Period – Monthly Metric
| Disincentive - $5,000 per 6C, $2,500 per 5C, and $500 per 1C over the standard in the reporting period | |||||||
| Clearance | N/A | Clearance Monitoring | When clearance information is returned with clearance type and date issued, monitor contractor employee clearance and employment status under the contract to ensure clearances renewals are submitted 30 calendar days prior to expiration, departed employees are identified and removed, and any clearance changes are annotated. | A consolidated report of all employees in the format shown below will be submitted to the COR and ISSO (copy to the CO) within 5 business days following each three-month period of performance for identification of changes over the last quarter (new employees, employees with clearance in process (and status), change in clearance type, and resubmittals for employees 30 calendar days prior to clearance expiration and departed employees). | Business Days | See Definition | Disincentive - $1,000 per error over the standard in the reporting period. |
95% complete and accurate over quarterly period
Period – Quarterly Metric
Submittal of quarterly report does not replace timely requests for e-Qip for new employees, monitoring status of clearance/clearance renewal requests, requesting clearance renewals 30 days before expiration, or notification that an employee has departed. COR will spot check quarterly and submit annually to the Security Office for a 100% validation when requested.
| Timely Submittal of Clearance Renewals | EDARS 3452.239-72 Department Security Requirement requires contractor employees in High Risk 6 (C) positions to submit clearance packages for re-investigation every five years. Once a contractor employee receives their clearance, an issuance and expiration date will be provided back to the contractor for tracking. Contractors must submit re-investigation packages to e-Qip 30 calendar days prior to clearance expiration. | A confirmation email to the FSA CO/COR/ISSO and Program Management 30 calendar days prior to the Clearance expiration date that certifies the success of complete, accurate, and timely clearance re-submissions. | Calendar Days | See Definition | $1,000 per error over the standard in the reporting period. | |||||
| Tier II Help Desk | N/A | Solution Accuracy | Minimal amount of calls to Tier II Help Desk require follow-up | total number of calls where there was no follow-up required divided by the total number of calls | Percentage | Follow-up Percentage < 98% | Follow-up Percentage between 98%-99% | |||
| Follow-up Percentage > 99% | Funding reduction by 1% |
Contractual changes?
| FSA Tech Response Time | Speed of Response required within one (1) business day to FSA Tech List Serve Postings | total number of responses to FSA Tech List Serve provided within one (1) business day divided by the total number of FSA Tech List Serve requests | Percentage | 100.00% | Speed of response between 99% - 100% | ||
| Speed of response < 99% | Funding reduction by 1% |
Contractual changes?
| Forecast Accuracy | Variance between forecast work effort and actual work effort based on baselined average handle time for each channel | Forecasted effort for each channel less the actual work effort | Hours | TBD | Variance > 5% | Funding reduction by 1% per sprint affected | Should story points be used? | |||||
| Prompt Answers | How quickly incoming phone calls are answered | % of calls answered in 20 seconds | Percentage | 80% | <80% | Funding reduction by 1% | ||||||
| Increase parner engagements and oversight effectiveness | Streamline partnerships with institutions | Develop and solidify partnerships with stakeholders | -Interview and meet with schools and software developers to understand how AED could empower their work | |||||||||
| -Implement feedback into AED development and finalization | N/A |
AED Goals
| FSA Goals | Next Gen Goals | AED Goals | AED Objectives |
| Empower a high performing organization | Execute efficient business operations | Maintain and continually enhance the student aid information processing system | Eliminating defects in the overall calculation flow |
Increasing the interoperability of data Promoting fast, available processing of data Quickly and accurately image, scan, print, and mail documents for customers Ensure the system has sufficient resources to securely conduct operations at all times Streamlining internal security clearance processing times Guaranteeing the prompt responding to COR and ISSO requests
| Provide a world class customer experience | Optimize the customer experience | Optimize the user (i.e. customers, internal users, students) experience | Satisfy student aid recipients by promptly and fully addressing all questions and issues related to their EFC and other financial aid instruments |
| Strengthen data protection and cybersecurity | Continuously evolve data protection and cybersecurity | Update and evolve data protection and cybersecurity continuously | Develop and maintain a secure environment for processing of users (i.e. customers, students, and other stakeholders) financial aid data that can quickly identify, notify, and remediate security incidents |
| Increase partner engagement and oversight effectiveness | Streamline partnerships with institutions | Develop and solidify partnerships with stakeholders | Interview and meet with schools and software developers to understand how AED could empower their work |
Implement feedback into AED development and finalization Enhance portfolio management and transparency Drive improved outcomes for taxpayers Increase communication and transparency with other Next Gen projects and the FUTURE Act TBD
File details come from the government source that posted it. Updated .