Attachment_C.4.2.a_ITSLCM_Framework_v3.0.pdf
PDF 656 KB Posted
- Attached to
- Enterprise Business Technology Services (EBTS) Federal contract opportunity
- Solicitation number
- 16PBGC19R0003
- Issued by
- Pension Benefit Guaranty Corporation
About this file
This document provides an IT Service Lifecycle Management (ITSLCM) framework for federal agencies. The framework outlines a process for IT program and project management including planning, development, operations, and disposition. It defines roles and responsibilities for program managers, project managers, integrated program teams, contracting officers, and other stakeholders. Key governance and review points are identified including requirements reviews, design reviews, deployment reviews, ongoing authorization reviews and disposition reviews. Guidance and standards are referenced to inform activities in areas like cybersecurity, privacy, acquisition, and configuration management. Templates and documents noted include business needs analyses, alternatives analyses, program plans, implementation plans, and lessons learned reports.
The related federal contract opportunity is a solicitation from the Pension Benefit Guaranty Corporation seeking proposals for an Enterprise Business Technology Services contract to support the agency's Office of Information Technology. The single Indefinite Delivery Indefinite Quantity award would have a one-year base period and nine one-year options. The anticipated award date is June 2019. Interested parties must register in the System for Award Management to be eligible. The solicitation and amendments will be available electronically on FBO.gov; paper copies will not be distributed. Questions must be submitted by the date specified in the RFP Section L.5.
Attachment C.4.2.a ITSLCM Framework
View the file
Other files for this federal contract opportunity
Show all 17
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
Test Plan, Test Scripts & Test Results [D]
Review & Update
Iteratively
ShareIT
• Execute operations activities (IT Prj Mgr, infrastructure, and application teams)
Business Needs Analysis (S)
Alternatives Analysis (S)
Build/Update IT Program Plan with IPgT:
o Identify IPgT and define Roles and Responsibilities o Identify recommendations from BNA to address business and IT gaps, including system replacements oDetermine strategic alignment oConduct Alternatives Analysis and Cost Benefit Analysis oDevelop Independent Government Cost Estimate (IGCE), including impacts to other programs oDevelop Acquisition Strategy oDevelop Risk, Issue, Quality, Configuration, Communication Plans and Matrices oDefine program reporting/oversight oPrioritize program requirements and program schedule with IPgT stakeholders
• Finalize IT Program Plan
Reflect IGCE in departmental budget formulation/request
BUSINESS PROGRAM MANAGER
IT PROGRAM MANAGER
INTEGRATED PROGRAM TEAM (IPgT)
CHIEF ENTERPRISE ARCHITECT (CEA)
RELEASE MANAGER
CONTRACTING OFFICER
INFORMATION SYSTEM SECURITY MANAGER
BUSINESS OWNER/SPONSOR
STEERING/OVERSIGHT COMMITTEE
Need/Concept Planning Execution
(Development, Modernization, Enhancement and Maintenance) Operations and Disposition
Perform monitoring and reporting (i.e., provide updates to IT Program Plan)
ShareIT
• RM/A Submits Disposition RFC
Required RMF Deliverables
Disposition Review
Update IT Program Plan with authority to close out program and/or dispose of IT solution
Close out program
Execute according to the IT Program Plan
Maintain IT Program Plan
Note: Information in IT Program Plan will be used for Semi-Annual Program Review oPerform program monitoring and reporting including cost and schedule performance using earned value (EV)
Select development approach
Develop Cost Loaded Project Schedule
Conduct Product and Technology
Recommendation
Develop high level design from high level requirements, including integration with other systems, and submit for CAB review
Refine IGCE
Develop Business Implementation Strategy
Document (Large Projects)
IT Project Manager develops high level project plan (w/Business Program
Manager)
COR completes IT Acquisition Checklist
Requirements Document (S)
Design (S)
Development (S)
Enterprise Data (S)
• Requester reviews GetIT, Technical
Reference Model (TRM), and mAppIT, or contact CEA at AskEA@pbgc.gov
• CEA reviews enterprise program solutions to determine resolution:
o EXISTING Solution: Requester submits
GetIT Request for Existing Solution o ENHANCE EXISTING Solution: Requester takes Modification Requirements to existing solution program manager;
Business Program Manager (BPM) queues for Change Control Boards
(CCBs) Prioritization o New Business Need: CEA schedules
Business Needs Analysis (BNA) (w/ BPM
Sponsor); Sponsor and CEA fund and secure resources necessary to conduct the BNA; conduct BNA.
Cybersecurity and Privacy Catalog (S)
RMF Process (G)
System of Records Notice (SORN) Guide (G)
Privacy Impact Assessment (PIA) Guide (G)
Interconnection Security Agreement (ISA) (G)
Execute selected
Development Approach
Establish Program CCB
Update IT Program Plan with results of product selection and refined IGCE
Portfolio Manager evaluate prioritize IT
Portfolio (w/Program Manager)
BPIT Budget Recommendation;
Portfolio Manager submit 53 & 300s
Software Services (S)
Implementation & Training Plan (S)
Lessons Learned Document (S)
Testing Guidance (G)*
Stabilize the solution
Grant access to users
Set up service desk support
Transition to Operations
Execute Implementation Strategy and
Training Plan
Document Lessons Learned and
Project Closeout
Change Management
Configuration Management
Configuration Management
Configuration ManagementIT Service/Incident/Problem Management
IT Service/Incident/Problem Management
Budget Formulation & ExecutionIT Risk Management
Review Risk Management Framework
(RMF) process to determine the list of required security and privacy activities, deliverables, and reviews
Complete required security and privacy deliverables
Review RMF process to determine the list of required security and privacy activities, deliverables, and reviews
Complete required security and privacy deliverables Continuous Monitoring
ATO
(Go Live)
IT Risk Management
IT Risk Management
IT Risk Management
Cybersecurity and Privacy Catalog (S)
RMF Process (G)
PIA Guide (G)
Change Management
Release and Deployment Management
Requirements Document [D]
Design [D]
Lessons Learned Document [D]
Acquisition
Acquisition
IT Portfolio Registration Presentation [D]
Business Need Analysis Document [D]
Alternatives Analysis [D]
IT Program Plan [D]
Business Need Analysis Document [D]
Alternatives Analysis [D]
IT Program Plan [D]
Program Performance Reports [D]
Cost Loaded Project Schedule [D]
Alternatives Analysis [D]
Security and Privacy Authorization
Package [D]
P ro gr am
M an ag e m e n t
P ro je ct
T e ch n o lo gy
M an ag e m e n t
C yb e rs e cu ri ty a n d P ri va cy
BUSINESS PROJECT MANAGER
IT PROJECT MANAGER
INTEGRATED PROJECT TEAM (IPT)
CONTRACTING OFFICER’S REPRESENTATIVE
(COR)
ENTERPRISE ARCHITECT REPRESENTATIVE
IMPACTED PROJECT MANAGERS
RELEASE MANAGER/ANALYST (RM/A)
INFORMATION SYSTEM SECURITY OFFICER
Alternatives Analysis (S)
Cybersecurity and Privacy Catalog (S)
RMF Process (G)
User Manual [D]
Implementation & Training Plan [D]
Release and Deployment Management
Ex te rn al
P ro ce ss e s
Update & Maintain
Iteratively
• Bus Program Manager performs Operational Analysis
(OA) on System Posture
Review & Update
Iteratively
Review RMF process to determine the list of required security and privacy activities, deliverables, and reviews
Complete required security and privacy deliverables
• COR executes Acquisition Plan
• Bus Prj Mgr develops
Implementation & Training Plan
• IT Prj Mgr Execute Plan
• Analyze & Document Requirements
• Develop & Refine (if needed)
Design Specifications
• Manage/Monitor/Report Project
Scope, Cost, Schedule, Risks, Quality, etc.
• ShareIT (SharePoint Site):
• Dev environment needs, i.e., Service Request (Dev Team)
• Dev and Test environment set up
(RM/A Team)
• Start Deployment/Installation
Guide (Dev Team)
• RM/A 1st CAB (if needed)
ITPRB
(IT Portfolio
Registration Review)
IT Program (Authorization)
ITPRB
(Prioritize Review)
ITPRB
(Semi-Annual Program Review)
ITPRB
(Annual OA)
ITPRB
(Disposition Review)
Requirements (Technology
Solution Review)
CAB
(Production/COOP
Deployment Review)
TRB
(Design Review)
TRB
(Product Review)
1st CAB ITPRB (Quarterly Project
Review)
Production Readiness Validation
Design (Technology
Solution Review)
ITSLCM Framework v3.0 – Updated June 2017
INFORMATION SYSTEM OWNER/INFORMATION OWNER
INFORMATION SYSTEM SECURITY OFFICER/
INFORMATION SYSTEM SECURITY MANAGER
AUTHORIZING OFFICIAL
CHIEF INFORMATION SECURITY OFFICER (CISO)
SENIOR AGENCY OFFICIAL FOR PRIVACY (SAOP)
CHIEF PRIVACY OFFICER (CPO)
INDEPENDENT ASSESSOR
Business Needs Analysis (S)
Alternatives Analysis (S)
Deployment/Installation Guidance (G)*
Solution Environment Guidance (G)*
Go/No-Go Governance Gate Review Gov. Review
IPT Review Roles Deliverables [D]
IT Standards (S) & Guidance (G) Le ge n d
IT Program Plan [D]
Post-Assessment Controls Review
Ongoing Authorization Review
Disposition Process Review
Required RMF Deliverables Required RMF Deliverables
Deployment/Installation Guide [D]
Solution Environment Plan [D]
Operations Guide [D]
• IT Prj Mgr
• Decide if Design Review is needed o Yes – Go to TRB Design Review Gate o No – Execute Plan (Pre-Deployment)
• Develop/Configure Solution
• Conduct Testing
• ShareIT
• Document Production Ops/Maintenance Needs in
Operations Guide
• Complete Deployment/Installation Guide
• RM/A Submit RFC (For Deployment)
• Deploy Solution
• Bus Prj Mgr Execute Implementation & Training Plan
• IT Prj Mgr Execute Plan (Post-Deployment)
Enterprise Continuous Monitoring (ECM) Plan (G)
Information System Continuous Monitoring (ISCM) Plan (G)
*Found in the OIT ITSLCM Supplemental Guide
Acquisition mailto:AskEA@pbgc.gov
File details come from the government source that posted it. Updated .