Attachment_C.4.2.b_ITSLCM_Handbook_v3.0.pdf

PDF 2 MB Posted

Attached to
Enterprise Business Technology Services (EBTS) Federal contract opportunity
Solicitation number
16PBGC19R0003
Issued by
Pension Benefit Guaranty Corporation

About this file

This document summarizes a federal solicitation for Enterprise Business Technology Services. The Pension Benefit Guaranty Corporation seeks to award an Indefinite Delivery Indefinite Quantity contract to provide IT support services to the agency's Office of Information Technology. The base period of performance is one year with nine one-year options, for a total of ten years. The anticipated award date is June 2019. Interested parties must register in the System for Awards Management database to be eligible for award. Questions regarding the solicitation must be submitted by the date specified in the request for proposals, available at the Federal Business Opportunities website.

Attachment C.4.2.b ITSLCM Handbook

View the file

Other files for this federal contract opportunity

Other files attached to Enterprise Business Technology Services (EBTS), newest first.
File Type Posted
Amendment_01_19R0003_final.pdf PDF
Amend_001_Questions_EBTS_19R0003_final.xlsx XLSX spreadsheet
Amendment_01_Attachment_C.2_EBTS_Environment_and_Requirements.pdf PDF
Attachment_L.5_Solicitation_Questions_Template.xlsx XLSX spreadsheet
Attachment_C.4.2.a_ITSLCM_Framework_v3.0.pdf PDF
Attachment_B.5_EBTS__IDIQ_Price_Schedule.xlsx XLSX spreadsheet
Attachment_C.1_OIT_Organizational_Chart.pdf PDF
Attachment_C.2.a_TRM_AD_Tools.xlsx XLSX spreadsheet
Attachment_L.2.1_EBTS_Task_Order_1.docx DOCX document
Attachment_C.6_Performance_Standards.xlsx XLSX spreadsheet
Attachment_L.2.1.2_Proposed_Staffing_by_Labor_Category_.xlsx XLSX spreadsheet
Attachment_C_Acronym_List.docx DOCX document
Attachment_L.3.b_EBTS_Proposed_Labor_Build_Up.xlsx XLSX spreadsheet
Attachment_L.3.a_EBTS_Labor_Category_Crosswalk.xlsx XLSX spreadsheet
Attachment_C.2_EBTS_Environment_and_Requirements.docx DOCX document
19R0003.pdf PDF
Attachment_B.5_EBTS_TO_1_Price_Schedule.xlsx XLSX spreadsheet
Show all 17

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

IT Solutions Life Cycle Management Framework (ITSLCM) Handbook

Developed By: Program Management Office (PMO) Document Number: Version 2.0 Date: 06/22/2017

PM-GDE-01-01

ITSCLM Framework Handbook ii

Table of Contents

1.0 INTRODUCTION

1.1 HANDBOOK PURPOSE

1.2 SCOPE

1.3 BACKGROUND

1.4 KEY PARTNERS

2.0 THE ITSLCM FRAMEWORK – HIGH LEVEL CONCEPTS

2.1 PBGC’S IT PORTFOLIO, IT PROGRAMS, AND IT PROJECTS

2.2 ITSLCM FRAMEWORK OVERVIEW

2.3 5 TIERS OF IT GOVERNANCE

2.4 ITSLCM FRAMEWORK COMPONENTS

2.4 ITSLCM ROLES

3.0 ITSLCM FRAMEWORK – DETAILED WALK THROUGH

3.1 NEED/CONCEPT PHASE

3.2 PLANNING PHASE

3.3 EXECUTION PHASE

3.4 OPERATIONS & DISPOSITION PHASE

APPENDIX

APPENDIX A: PBGC IT PORTFOLIO GOVERNANCE – OVERVIEW

APPENDIX B: DELIVERABLES – OVERVIEW

APPENDIX C: STANDARDS & GUIDANCE – OVERVIEW

APPENDIX D: EXTERNAL PROCESSES – OVERVIEW

APPENDIX E: FEDERAL STATUTES & REQUIREMENTS – OVERVIEW

APPENDIX F: SOLUTION DEVELOPMENT APPROACH GUIDANCE

1.0 Introduction

1.1 Handbook Purpose

The Information Technology Solutions Life Cycle Management (ITSLCM) Framework Handbook is a resource to assist the Pension Benefit Guaranty Corporation (PBGC) employees and contractors in navigating PBGC's ITSLCM Framework. This document presents an overview of the ITSLCM Framework phases, streams, gates and reviews, tasks, standards and guidance, deliverables, external processes, and corresponding roles required to properly execute the Framework. The Program Management Office (PMO), within the Office of Information Technology's (OIT) Business Innovation Services Department (BISD), develops and maintains this document. For additional details about the Framework and its components, contact the PMO.

It is important to note that while the ITSLCM Framework and this Handbook do not call out standard project management practices (e.g., scope management, time management, cost management, quality management, human resource management, communications management, risk management, procurement management, stakeholder management), individuals should leverage project management industry best practices (e.g., Project Management Institute (PMI)).

Additionally, project management practitioners may leverage much of the project management documentation directly from the program documentation as well as create and use other artifacts that are not called out (e.g., Project Management Charter), as appropriate.

1.2 Scope

The three sections of this Handbook are: Section 1: Introduction, Section 2: The ITSLCM Framework – High Level Concepts, and Section 3:

ITSLCM Framework Phases – Detailed Information. Section 1: Introduction offers insight into the history and background of the ITSLCM. Section 1 also provides an overview of the key partners that provide input into the ITSLCM and the requirements that govern it. Section 2: The ITSLCM Framework – High Level Concepts describes PBGC’s IT Portfolio, IT Programs, and IT Projects and steps through the ITSLCM Framework components, roles, and phases. Section 3: ITSLCM Framework Phases – Detailed Information describes what happens during each stream of each phase.

Throughout the Handbook there are Key Concept Callouts (central concepts that contribute to ITSLCM understanding) and ITSLCM Breadcrumbs (highlights of the section of the ITSLCM Framework that is being discussed).

1.3 Background

The ITSLCM Framework is a governance-based framework designed to manage IT programs and projects through the identification, planning, execution, maintenance, and disposition of IT solutions at PBGC. The ITSLCM, a component of the PMO’s program, integrates the federally mandated requirements of Enterprise Architecture (EA), IT Portfolio Management (ITPfM), Program and Project Management, Infrastructure, and Cybersecurity and Privacy.

The Framework is a streamlined way for PBGC to fulfill IT needs while balancing the challenges of pension regulatory changes, emerging technologies, reducing duplication of technology and having better stewardship of IT costs, and securing data and systems.

There are several benefits to using the Framework:

Communication – Business and IT roles serve as partners who work collaboratively throughout a program’s life cycle.

Simplification – Artifacts are carefully selected to capture outcomes of tasks performed and to bring value.

Where possible, leverage IT Program management artifacts to avoid creation of unnecessary documents.

Flexibility – Enables use of various development methodologies (e.g., Iterative, Agile) and types of solutions

Key Concepts: Identify important concepts

Breadcrumbs: Highlight ITSLCM sections

(e.g., Cloud, COTS, Hosted, new solutions and enhancements to existing ones).

Clarity – “Streams” establish logical groupings of related tasks to be performed by the experts of the respective stream.

Transparency – Clear communication of budget, risk, and schedule from the program level through to individual projects.

Compliance – Facilitates compliance with federal IT laws, regulations, and PBGC standards.

PBGC issued its first Systems Development Life Cycle (SDLC) methodology on March 30, 2001 and it provided guidance for all system development efforts and major enhancements to existing systems. Since that time, PBGC has implemented many updates and enhancements (e.g., name change, key concepts) to ensure that the Framework continues to support the evolving industry best practices, federal mandates, and PBGC IT and business needs.

The current version is a result of the collaborative efforts of the following key partners: EA, ITPfM, Enterprise Cybersecurity, PMO, the Information Technology Infrastructure Operations Department (ITIOD), and the Privacy Office.

The Framework also includes input from members of the ITSLCM Change Control Board (CCB). The current version evolves PBGC’s approach from a process-oriented methodology to a flexible framework of requirements and moves the ITSLCM from project management and solution delivery to a higher level of governance of program management and program planning.

The Framework supports PBGC’s efforts in planning for, acquiring, delivering, and managing information technology— from developing new solutions, to modernizing, enhancing, maintaining, and operating existing solutions, through disposition of the solutions. The table below offers insight into the history and background of the ITSLCM. For more information on federal statutes and requirements see Appendix A.

Date Description

July 1996 The Clinger-Cohen Act streamlines IT acquisitions and emphasizes life cycle management as a capital investment.

March 1999 An audit report from the Office of Inspector General’s Financial Statement finds that the lack of a formal SDLC methodology impacts the consistency of systems development initiatives.

March 2001 The PBGC SDLC methodology is issued to meet the requirements identified in the March 1999 Office of Inspector General's Financial Statement Audit.

March 2002 The Systems Life Cycle Methodology (SLCM) replaces the SDLC and the scope is expanded to include all acquisition, development, and enhancement efforts related to information systems.

July 2003 The SLCM is redefined to align with the Business Planning Framework. The Business Planning Framework, established in late 2002, defined the relationship between Strategic Planning and Corporate Initiatives that meet the agency’s goals and objectives.

FY 2004 The Office of Inspector General’s Fiscal Year 2004 Financial Statement Audit by PricewaterhouseCoopers states: “Approval Process for accepting internally developed software should be improved.”

FY 2005 The SLCM is updated to incorporate standard industry models such as the Software Engineering Institute’s (SEI) Capability Maturity Model Integration (CMMI®), and the Project Management Institute’s Project Management Body of Knowledge (PMBOK®).

October 2005 The Chief Technology Officer (CTO) signs the SLCM Corporate Policy.

March 2006 SLCM v2006.1 is released and training is conducted throughout PBGC. This release includes a detailed Requirements Development (RD) process, Requirements Management (REQM) process, and their supporting sub-processes (Business Process Model process, Peer Review process, Submit Artifacts for Approval process).

Summer 2006 The SLCM is updated in conjunction with the creation of the Project Management Life Cycle (PMLC).

The SLCM was re-designed to separate the project management and solutions delivery processes to create a more flexible and tailorable structure. During the SLCM modernization activity, the SLCM is renamed the Information Technology Solutions Life Cycle Methodology (ITSLCM).

Date Description

February 2007 The ITSLCM 2007.1 is released. This release is the first iteration of an overall IT Investments Framework including Enterprise Architecture, Security, and Capital Planning – designed for managing, developing, maintaining, and decommissioning solutions. It incorporates detailed processes embedded within a Project Management Life Cycle (PMLC) and Solutions Development Life Cycle (SDLC). PBGC’s first ITSLCM Directive (IM-05-7) is published.

April 2007 The Chief Management Officer (CMO) signs the Order (Directive), which requires that all PBGC federal and contract employees adhere to the ITSLCM for delivering and managing the delivery of new and existing IT solutions. This Order replaces the SLCM Corporate Policy, dated October 7, 2005.

March 2010 A PBGC Corrective Action Plan (CAP) is delivered in response to OIG information security audit findings.

This CAP serves as a key driver for modernizing the ITSLCM to ensure continued compliance with the National Institute of Standards and Technology (NIST) 800-53 Rev. 3 (specifically, Controls SA-3 and SA- 5). The CAP's implementation schedule identifies January 2011 to initiate an ITSLCM modernization effort.

April 2011 Based on the FY2011 PBGC Security CAP, an initiative to modernize the ITSLCM begins. This results in the release of the ITSLCM Framework (v1.0). The Framework incorporates federally mandated requirements of EA, Capital Planning, Cybersecurity, Privacy, and external IT processes, including IT Governance Gates and Reviews, and IT Standards, and it defines key roles and deliverables. The ITSLCM encourages SDLC Agile and no longer endorses the Waterfall approach.

August 2014 ITSLCM Framework (v2.0) was updated to incorporate improvements based on the IT Portfolio Maturity effort; integrate requirements from Office of Management and Budget’s (OMB’s) Architect, Invest, Implement paradigm; incorporate NIST controls, and better achieve agency goals by closing gaps.

August 2015 ITSLCM Framework (v2.1) was updated to include some of process improvements identified in the P3M nine and three day working sessions. This ITSLCM more clearly defines the gates that decide if a project is to continue or stop its course of action versus the gates that just make strong recommendations.

October 2016 ITSLCM Framework (v2.2) was updated to account for the IT Portfolio Review Board (ITPRB) portfolio registration modification, Enterprise Architecture Alternatives Analysis Standard and Methodology, and Enterprise Cybersecurity standards superseded by the Cybersecurity & Privacy Catalog. These updates improve the assessment and delivery of agency IT solutions.

May 2017 ITSLCM Framework (v3.0) incorporates business process improvements derived from a nine-day working session. ITSLCM v3.0 incorporates process improvements in the areas of project and program management, Enterprise Architecture, Change and Release Management, and Cybersecurity and Privacy.

Table 1: ITSLCM History and Background

1.4 Key Partners

As a user navigates the ITSLCM Framework, it is important to leverage available assistance provided by key partners that provide input into the lifecycle process for IT solutions and the requirements that govern it. This assistance is critical to ensuring the successful development and implementation of an IT solution. These key partners are the PMO, Enterprise Architecture Division (EAD), IT Portfolio Division (ITPD), Enterprise Cybersecurity Division (ECD), ITIOD, and the Privacy Office. The following sections provide a brief description of each partner.

In addition to the key partners listed below, there are several primary and supporting roles that help to facilitate and execute the ITSLCM Framework as described in Section 2.4: ITSLCM Roles.

1.4.1 Program Management Office (PMO)

The PMO mission is to establish and manage consistent approaches to managing IT programs/projects and creative implementation approaches to enable business agility.

The PMO is also responsible for the following functions:

1. Establish and tailor a Program Management Office in accordance with federal mandates, best practices in government and industry.

2. Develop, implement and ensure adherence to IT program/project management policies, processes, procedures, standards and guidelines for practitioners and stakeholders to comply with PBGC and federal mandates.

3. Promote the use of best practices and adherence to policies and procedures by establishing an IT Program/Project Management Community of Practice and conduct reviews of IT programs/projects to affect course corrections early for a successful completion of projects.

4. Govern execution of IT programs/projects by providing transparency into performance using dashboard reporting to the CIO and appropriate governance boards.

For more information, please visit the PMO website.

1.4.2 Enterprise Architecture Division (EAD)

The EAD mission is to establish and manage an Enterprise Target Architecture (ETA) for PBGC and govern the application of Information Technology (IT) to achieve cost-effective solutions. EAD establishes the Agency-wide roadmap to achieve PBGC's mission through optimal performance of its core business processes within an efficient IT environment.

EAD fulfills its mission by completing the following functions:

1. Establish and tailor an Enterprise Architecture Program in accordance with federal mandates, best practices in government and industry.

2. Develop, implement and ensure adherence to Enterprise Architecture policies, processes, procedures, standards and guidelines for practitioners and stakeholders to comply with PBGC and federal mandates.

3. Represent the CIO on Federal Enterprise Architecture (FEA) Committees and Working Groups to tailor mandates for PBGC and report effectiveness metrics.

4. Guide the Corporation through business needs analyses (BNAs)/alternative analyses, choices of technology and securing funding for implementation by leveraging shared/managed services, and cloud solutions.

5. Govern technology presence by integrating with other CIO Programs and governance boards.

For more information, please visit the EAD website.

EAD guides PBGC through Business Needs

Analysis and/or Alternatives Analysis, which provide content for concept proposal and business cases to justify funding.

The PMO is responsible for maintaining, updating, and providing training on the

ITSLCM Framework.

https://pbgcgov.sharepoint.com/BISD/PMO/Pages/default.aspx https://pbgcgov.sharepoint.com/EGD/EAD/Pages/Default.aspx

1.4.3 IT Portfolio Division (ITPD)

ITPD’s mission is to establish and manage PBGC’s IT Portfolio of IT Programs that yield the best benefits for PBGC’s business operations.

ITPD’s functions include:

1. Establish and tailor an IT Portfolio Management Program in accordance with federal mandates, best practices in government and industry.

2. Develop, implement and ensure adherence to IT portfolio management policies, processes, procedures, standards and guidelines for practitioners and stakeholders to comply with PBGC and federal mandates.

3. Represent the CIO on Federal IT Portfolio Committees and Working Groups to tailor mandates for PBGC and report effectiveness metrics.

4. Guide the corporation in developing, managing and submitting quality business cases that secure IT funding.

5. Govern selection, management (execution) and evaluation (business value) of IT Programs technology presence by integrating with other CIO Programs and governance boards.

For more information, please visit the ITPD website.

1.4.4 Enterprise Cybersecurity Division (ECD)

ECD’s mission is to coordinate the protection and security of PBGC IT and information resources. In order, to ensure that security policies, standards, processes, and procedures are followed, ECD maintains the IT Security Framework, and Information System Security Officers (ISSO) serve on the Integrated Program Teams (IPgTs) and Integrated Project Teams (IPTs).

ECD manages this through the six steps outlined in the Information Security Risk Management Framework (RMF) to integrate with the PBGC ITSLCM Framework.

These six steps are:

Step 1 – Categorize Information – categorize the information system consistent with the organization's overall risk management strategy to identify the potential impact to mission/business functions resulting from the loss of confidentiality, integrity, and/or availability of the agency’s data.

Step 2 – Select – complete the implementation of the security and privacy baseline controls, tailor-out non-applicable controls, and/or tailor-in supplemental controls that reduce the risk to the data processed, stored, or transmitted by the system.

Step 3 – Implement – apply the security and privacy controls in accordance with the stated implementation strategies defined in the SSP A system-level Information System Continuous Monitoring (ISCM) plan shall be created.

Step 4 – Assess – assessment of the security and privacy controls for the system.

Step 5 – Authorize – authorization of the information system based on a determination of the risk to PBGC operations, assets, individuals, and other organizations resulting from the operation of the information systems.

Step 6 – Monitor – monitoring the security and privacy controls in the information system and day-to-day operational security measures on a continuous basis.

For more information related to cybersecurity, please contact your ISSO or visit the ECD website.

ISSOs are available to help navigate through security policies, standards, processes, and procedures.

ITPfM supports an effective IT Portfolio analysis, selection, and decision-making environment at PBGC.

https://pbgcgov.sharepoint.com/EGD/ITPD/Pages/ITPfM_Overview.aspx https://pbgcgov.sharepoint.com/CIO/ECD/pages/Default.aspx

1.4.5 1.4.5 Privacy Office The Privacy Office’s mission is to develop and maintain privacy policies and guidance for PBGC in compliance with Federal mandates and regulations. The Privacy Office is committed to protecting PBGC’s clients, employees, and the Agency’s privacy.

The Privacy Office partners with ECD to utilize the six steps outlined in the RMF to integrate with the PBGC ITSLCM Framework.

For more information, please visit the PBGC Privacy Office website.

1.4.6 Information Technology Infrastructure Operations Department (ITIOD)

ITIOD’s mission is to manage the delivery of the infrastructure systems and services, measure capabilities to ensure services levels are met, and ensure the delivery of a secure, cost effective, and sustained level of availability and support overall business continuity.

ITIOD is responsible for the change and release management policies and procedures that impact the ITSLCM Framework. ITIOD manages operations activities and support for IT solutions at PBGC.

For more information, please visit the ITIOD website.

The Privacy Office is committed to protecting PBGC’s clients’ privacy’ employees’ privacy, and the Agency’s privacy.

ITIOD provides the infrastructure and operations support necessary for IT solutions at PBGC.

https://pbgcgov.sharepoint.com/OGC/Privacy/Pages/Default.aspx https://pbgcgov.sharepoint.com/ITIOD/pages/default.aspx

2.0 The ITSLCM Framework – High Level Concepts

2.1 PBGC’s IT Portfolio, IT Programs, and IT Projects

In order to comprehend how programs and projects relate to each other throughout a solution’s lifecycle, it is first important to understand the ITPfM process and how the IT Programs are organized within the process.

The purpose of PBGC’s ITPfM program is to establish, maintain, and support an effective IT Portfolio analysis, selection, and decision-making environment at PBGC. The ITPfM program works in conjunction with EA and PMO to facilitate the Architect, Invest, and Implement paradigm. PBGC’s ITPfM program embodies OMB’s Capital Planning and Investment Control (CPIC) guidance to achieve the aforementioned goals. The CPIC Cycle includes the Prioritize, Control, and Evaluate reviews and is intended to ensure the success and overall health of the PBGC IT Portfolio. The Appendix includes an overview of IT portfolio governance at PBGC.

The Prioritize Review assesses the IT programs and projects and validates the budget, scope, and schedule to recommend prioritization for budgetary decision-making. Prioritization criteria includes alignment with Corporate and IT Strategic goals and objectives, alignment with the EA Roadmap, and implementation readiness.

The Control Review assesses program and project performance resulting in recommendations on continued funding and ensuring that the project is continuing to fulfill the Corporation’s strategic IT needs in a timely and cost-efficient manner.

Program control criteria includes cost performance index (CPI), schedule performance index (SPI), and progress against program measures. Project control criteria includes project manager (PM) qualifications and certifications; CPI; SPI; and an assessment of reliability, sustainability, and executability.

The Evaluate Review assesses the steady state or managed service performance. It also notes changes in the business or technology drivers that may result in recommendations to continue funding or initiate a new planning phase. Evaluate criteria includes program performance measures, business drivers, technology drivers, and operations and maintenance (O&M) costs.

PBGC’s Strategic Plan and IT Strategic Plan communicate PBGC’s goals and objectives. IT Programs use information technology resources to achieve efficient and effective business operations to meet PBGC’s strategic goals, performance goals and priorities, and strategies. IT Programs include the planning, development, modernization, enhancements, operations, and maintenance of IT projects and managed services. IT Projects are temporary endeavors, with a defined start and end date, to develop, modernize, and/or enhance an IT solution that contributes to the IT Program’s measurable benefits. An IT Project may be delivered in one or more releases using various development approaches (see Appendix for more information) enabling modular development. The collection of IT Programs managed as a group to achieve PBGC strategic goals and objectives comprises the PBGC IT Portfolio. Below is a representation of the PBGC IT Program structure.

Figure 1: IT Portfolio Management http://www.pbgc.gov/Documents/PBGC-Strategic-Plan-2014-2018.pdf https://pbgcgov.sharepoint.com/CIO/Shared%20Documents/PBGC-IT-Strategic-Plan-FY14-FY18.pdf#search=IT%20strategic%20plan

Figure 2: PBGC IT Program Structure

The IT Programs are grouped logically by functionality and service affinity to ensure ease of organization and understanding. Additionally, the IT Program structure ensures an optimal amount of alignment and compliance with reporting requirements. This optimization enables greater integration throughout the enterprise and an increased capacity to leverage common resources, documentation, and lessons learned. This increased capacity is important as federal requirements increasingly encourage IT integration, data sharing, and cloud-based solutions. For these efficiencies to be fully realized it requires open and continuous communication between projects and their sponsoring programs and then among the programs within the portfolio.1 IT Programs are reported at the OMB Agency IT Portfolio Summary level and are tracked by lifecycle phase to support consistency, transparency, and ease.

1 For more information on the PBGC IT Portfolio, please visit the ITPD website.

https://pbgcgov.sharepoint.com/EGD/ITPD/Pages/ITPfM_Overview.aspx

2.2 ITSLCM Framework Overview

The ITSLCM Framework is a cradle-to-grave IT management framework that provides for the identification, planning, implementation, maintenance, and disposition of IT solutions throughout their lifecycle. It provides governance and direction by highlighting governance gates and reviews; standards and deliverables; roles and responsibilities (defined in the IT Management Directive 05-07); external IT processes; and required tasks across four phases: Need/Concept, Planning, Execution (Development, Modernization, Enhancement, and Maintenance), and Operations and Disposition.

The ITSLCM Framework is designed to align with the OMB Performance Improvement Life Cycle (PILC), which establishes a framework for aligning goals to results. The OMB’s PILC is a business-outcome-driven approach used to analyze and determine the necessary improvements to business processes and IT assets; then to determine where to invest to ensure every dollar invested in implementing changes to processes and/or IT assets provides the best possible return on investment in terms of business outcomes.

OMB’s PILC is comprised of three phases:

The “Architect” phase focuses on the identification of both enterprise performance gaps and the capabilities needed to fill the gaps.

The “Invest” phase focuses on defining the implementation and funding strategy for individual gaps identified during the “Architect” phase and ensures the alignment of project selections to the goals and objectives set forth.

The “Implement” phase focuses on ensuring the design for the solution is executed to close the performance gaps and that the initiatives are executed and operating according to plan.

Figure 3 below depicts how the CIO’s Program components map to the ITSLCM framework phases, and align with OMB’s

PILC.

Figure 3: Mapping to OMB’s Performance Improvement Life Cycle

By leveraging the PILC as a basis for the ITSLCM, PBGC is enabling the IT solution management infrastructure to effectively select, implement, manage, and monitor IT initiatives. When the ITSLCM is executed properly and consistently, IT Programs address capability gaps and deliver the performance improvements that are being sought. Further, the ITSLCM Framework is structured in a way that easily demonstrates the tasks and responsibilities from the perspective of program management, project management, and information security and privacy. The ITSLCM balances governance with an appropriate amount of flexibility to allow program and project managers to complete and implement tasks in the order that aligns to their individual needs within each phase. The Framework also streamlines documentation requirements by reducing duplicative artifacts at the program and project level.

PBGC’s IT Management Directive (IM 05-07) applies to all PBGC Information Technology, throughout its lifecycle, regardless of the source of funding or resources owned and operated on behalf of PBGC.

The ITSLCM Framework is designed to provide programs with the information needed for the successful implementation of IT solutions that meet business needs and close performance gaps.

2.3 5 Tiers of IT Governance

PBGC’s IT Management Directive (IM 05-07) outlines 5 Tiers of Governance for managing scope, cost, schedule, risks, and issues. These tiers are labeled as follows:

Tier 1- Project Management (IT and Business) Tier 2- Program Management (IT and Business) Tier 3- Steering/Oversight Committees (CIO and associated Chief Officer, also commonly referred to as the CXO) Tier 4- PBGC Governance Boards Tier 5- OMB

All IT Programs and Projects follow this 5 Tier Governance model. Tiers 1 and 2 form the foundation of IT governance at PBGC. In these tiers practitioners, meaning the IT and Business Project and Program Managers, closest to the activities actively manage all aspects of IT Projects and Programs. In Tier 3, Steering/Oversight Committees led by the CIO and CXO review the status of IT Projects, IT Programs, risks, issues, etc. In Tier 4, oversight is provided by corporate-level governance boards such as the ITPRB, the Executive Management Committee (EMC), and Budget Planning and Integration Team (BPIT).

Tier 5 involves external oversight from OMB, which is above and beyond the solid internal oversight provided by Tiers 1 through 4.

Each of the groups outlined within the 5 tiers are supported by the PMO but are governed by different entities. Tiers 1 through 3 are governed by the ITPRB, Tier 4 is governed by the CIO, and Tier 5 is governed by OMB.

The ITSLCM Framework aligns with PBGC’s 5 Tier Governance model. The Framework provides guidance on the tasks, standards, deliverables and reviews needed within each phase to align with the 5 Tier Governance, including who is responsible for completing each activity based on their role.

2.4 ITSLCM Framework Components

The ITSLCM is comprised of four phases which incorporate tasks that satisfy requirements of applicable federal mandates and regulations related to EA, ITPfM, IT security, privacy, program and project management, infrastructure, and federal acquisition:

1. Need/Concept: New business needs are identified and requests for new solutions are submitted and guided through a structured IT Program Authorization Review to determine if it should be classified as IT and if so, how it might impact PBGC’s IT Portfolio. The ETA for current and planned systems and technologies in comparison to planned projects is reviewed.

2. Planning: Detailed program and project planning tasks are conducted and documented. Planning elements, such as the establishment of the Program Management Plan (PgMP), IT Program Release Plan, Project Management Plan (PMP) (if needed), product selection, and selection of development methodology, are all completed in this phase. The tasks and deliverables in this phase are produced to ensure that a budget, scope, and schedule are in place so the solution meets the intended business need, as well as to ensure that IT resources are being planned and managed in accordance with all applicable federal policies and mandates and internal PBGC policies and directives.

3. Execution (Development, Modernization, Enhancement, and Maintenance): The IT solution is designed, developed, implemented, tested, and deployed with an Authority to Operate (ATO). Programs and projects are monitored and reported on. Maintenance activities (patching, vendor-supported versions, and defect correction) needed to sustain the IT solution at the current capability and performance levels. It includes corrective hardware and software maintenance, voice and data communications maintenance and service, and replacement of broken or obsolete IT equipment. The ITPRB conducts quarterly project control reviews to assess PM qualifications and certifications, CPI, SPI, and to assess reliability/sustainability/executability.

4. Operations and Disposition: During this phase, the operations support is provided to the IT solution in the agency’s production environment per the last set of approved requirements. Tasks associated with solution operations in the production environment include service desk support, backups, disaster recovery/Continuity of Operations Plan [COOP]. Once it is determined an IT solution or program is at the end of its useful life cycle, disposition activities include destroying, recycling, or repurposing IT solutions.

Each phase incorporates tasks that satisfy requirements of applicable federal mandates and regulations related to enterprise architecture, ITPfM, IT cybersecurity and privacy, program and project management, along with external-related processes (e.g., infrastructure, IT risk management, federal acquisition, etc.). The tasks, across the four phases, are separated into three streams:

1. Program Management: Identifies tasks associated with providing centralized, coordinated management of an IT program (which may consist of multiple IT Projects or IT-related initiatives) to achieve business goals and objectives. Program planning also includes all tasks associated with both the IT Portfolio Process (Prioritize, Control, and Evaluate reviews) and EA requirements. It focuses on achieving defined benefits (closing performance gaps), aligning to the corporate and IT Strategic Plans, and managing program resources. This objective is achieved by promoting these goals along with best practices and guidance on IT program management to business and IT program managers.

2. Project & Technology Management: Identifies tasks associated with applying knowledge, skills, tools, and techniques to project tasks in order to plan, execute, monitor, and control IT projects effectively by achieving cost, schedule, and/or performance goals. Focuses on planning and implementing solutions. This objective is achieved by leveraging project management best practices.

3. Cybersecurity & Privacy: Identifies information security and privacy related tasks that emphasizes managing risk at three different tiers within PBGC: (1) agency-wide security and privacy risks; (2) business/mission function security and privacy risks, and (3) information system security and privacy risks. This includes tasks associated with the information and instructions necessary for determining, documenting, tracking, and reporting: an information system's mission areas, and the overall agency's security and privacy risks, thereby improving information security and privacy risk management within PBGC. ECD and the Privacy Office have their own process, the PBGC Information Security RMF Process. ITSLCM users should reference the RMF for required security and privacy tasks.

Each stream reflects the following:

1. Go/No-go governance gate reviews: Go/No-go governance gates (represented by the red and green diamond) are meant to ensure that the solution conforms to IT standards and federal and agency requirements. Non-compliance with the applicable policies and standards found during these reviews might prohibit a project from proceeding past the governance gate.

2. Governance Gate Reviews: Governance gate reviews (represented by a solid green diamond) indicate a review by a governance board. Governance gate reviews produce strong recommendations for your project, however, work will not necessarily be stopped based on the review’s outcome.

3. IPT Reviews: IPT reviews (represented by a yellow oval) are designed to ensure that project components have been reviewed by the relevant stakeholders. IPT reviews represent the internal assessment of deliverables by responsible business and IT organizations or divisions.

4. Streams: Streams are visual elements that distinguish tasks by program management, project and technology management, and cybersecurity and privacy.

5. Roles: Roles are individuals or groups responsible for performing the tasks identified.

6. Tasks: Tasks required to satisfy federal mandates and regulations, resulting in an outcome or deliverable, are identified by phase and stream.

7. Deliverables: Deliverables are identified by phase and stream.

8. Standards and Guidance: Applicable IT Standards and Guidance to be addressed in phase deliverables are identified by phase and stream. Standards (S) provide the minimum technical or non-technical requirements or criteria for ITSLCM deliverables, reviews, and gates. Supporting guidance (G) documents and processes are also identified on the Framework.

9. External processes: Critical applicable external processes are identified by phase to achieve successful development and implementation.

10. Circular Arrow: Recurring task are identified by circular arrows. Recurring tasks should be repeated, reviewed, updated, or continually monitored as directed.

The following page provides a snapshot of the ITSLCM Framework with the aforementioned components highlighted and the remainder of Section 2 explains each of these components.

Process

Text

Figure 4: ITSLCM Framework

2.4 ITSLCM Roles

Before describing the ITSLCM phases, it is important to understand the other roles that play a part in the ITLSCM. The graphic below provides an overview of the roles and how they relate to others – more detailed descriptions of the roles is included in the IT Management Directive (IM 05-07). The next section provides the phases and corresponding roles.2

Figure 5: ITSLCM Roles

2 In addition to those shown in the graphic, there are a number of roles that support and/or influence ITSLCM activities. Such roles may include Subject Matter Experts (SMEs) from organizations such as: Procurement Department (PD), Budget Department (BD), Workplace Solutions Department (WSD), Human Resources Department (HRD), and technical/infrastructure SMEs. These SMEs may participate in an as needed and consultative manner, depending upon the nature of the IT program/project and its maturity in the ITSLCM Framework.

3.0 ITSLCM Framework – Detailed Walk Through

The four phases of the ITSLCM each have a distinct purpose. These phases encompass the full lifecycle of an IT solution from its origination as a business need to its final disposition. The phases and related tasks may happen in a linear order and some may occur simultaneously in a mixed lifecycle program. The following is an overview of each of these four phases.

3.1 Need/Concept Phase

The Need/Concept Phase is the first phase of the ITSLCM and occurs only in the Program Management Stream. During this phase, new business needs are analyzed within individual program areas and across the enterprise to determine if the business need can be met using an existing IT solution, through enhancing an existing IT solution, or through establishment of a new IT solution or program.

3.1.1 Program Management Stream

3.1.1.1 Gates & Reviews

There are two gates in the Need/Concept Phase:

IT Program Authorization: The Business Owner/Sponsor reviews the program charter to ensure completeness, accuracy, validate documented need, and finalize sponsorship.

ITPRB IT Portfolio Registration Review: The ITPRB decides whether to classify a request as IT/non-IT and helps determine potential impact to PBGC’s IT Portfolio. Additional input may be provided by select SMEs for the review.

3.1.1.2 Roles

The most critical participants include:

Requester: Identifies a business need

EAD: Provides perspective and insight

ECD: Provides perspective and insight

Infrastructure: Provides perspective and insight

ITPD: Facilitates the ITPRB processes

ITPRB: Determines whether request is IT and its impact to IT portfolio

3.1.1 Tasks

During the Need/Concept Phase, requests are submitted and guided through a structured IT Portfolio Registration Review to determine if it should be classified as IT and, if so, how it might impact PBGC’s IT Portfolio. The IT Portfolio Registration Presentation supports ITPRB decisions about whether to classify a budget request as IT/non-IT and helps determine potential impact to PBGC’s IT Portfolio. The Presentation is divided into 2 parts:

• Part 1: ITPRB reviews and determines whether a request is IT and, if so, how it might impact the IT Portfolio.

• Part 2: ITPRB records its decision about whether the request is IT/not IT and placement within the IT Portfolio.

The Need/Concept Phase is the point of entry to the ITSLCM Framework.

The following table provides an overview of the steps associated with this process.

Step Description

1. Requester identifies a business need and reviews GetIT, the Technical Reference Model (TRM), and mAppIT, or contacts the CEA at AskEA@pbgc.gov to determine if a solution exists.

2. The CEA reviews enterprise program solutions to determine if the business need can be accommodated by an IT Solution (e.g., Does the current architecture include an existing/planned solution to meet this need?).

a) If not, the CEA schedules a BNA with the Business Program Manager/Sponsor. The Sponsor and CEA secure the resources necessary and conduct the BNA. Proceed to step 3.

b) If there is an existing solution, the requestor submits a GetIT request.

c) If the existing solution needs to be enhanced, the requester takes modification requirements to existing solution Program Manager. The Business Program Manager queues the modifications for Change Control Board (CCB) prioritization.

3. The Business Program Manager submits the IT Portfolio Registration Presentation and supporting materials, as needed, to ITPD. ITPD adds an agenda item for an upcoming ITPRB meeting to review the presentation and distributes read-ahead materials to ITPRB.

4. The ITPRB reviews the presentation and materials to determine whether a request is IT and, if so, how it might impact the IT Portfolio. The ITPRB then records its decision about whether the request is IT/not IT and placement within the IT Portfolio. If the ITPRB is unsure, they have the option to engage the CIO, SAISO, ITIOD Director, EAD, ITPD, PMO, information owner, the proposing sponsor/entity, Department Director of that sponsor, and others, as necessary.

5. ITPRB notifies the BPIT of the outcome from the IT Portfolio Registration Process and provides recommendations for funding of the proposed solution, as applicable.

Table 2: IT Portfolio Registration Review

The results of the above process will establish the applicability of proceeding through the ITSLCM:

If the business need can be met using an existing IT solution: Where an IT solution already exists that will fulfill the business need, a GetIT request to obtain access to the IT solution is submitted. No subsequent ITSLCM tasks are required.

If the business need can be met through enhancing an existing IT solution: Where an IT solution exists, but needs to be modified or enhanced, the business requirements will be identified and preliminary analysis and market research conducted on the resources required. Cost, schedule, and scope changes are submitted to the program area’s designated CCB for review and approval. When a budget request is being made, the changes are than submitted with the ITPRB to update PBGC's IT Portfolio to reflect the appropriate changes.

The IT Program Plan for that respective program will also then be updated.

If the business need requires establishing a new IT solution: Where no IT solution exists within the organization, and a new solution or program is needed to fulfill the business need, sponsorship for the new program will be finalized and a new IT Program Plan will need to be created and the new program added to PBGC’s IT Portfolio.

If a new IT Program is established, the Sponsor assumes responsibility for the program and a new IT Program Plan is developed. The IT Program Plan includes the following components:

IT Program Charter/Authority – This includes general information about the program (e.g., program name, unique investment identifier, program size, establishment data, end date, approximate annual cost range, current program state, program scope, relationships/dependencies, legislative authority, and Business Owner/Sponsor names) and is completed with sign-off by the Sponsor or IT Program Authorization.

IPgT – This includes information on the IPgT and the full-time equivalent (FTE) calculations.

mailto:AskEA@pbgc.gov

IT Program Measures (Monitoring & Reporting) – This includes information on performance measures (e.g., EA alignment and status, accomplishments by fiscal year, program oversight, program change and communications management, quality management, configuration management, and return on investment (ROI) on development, modernization, and enhancement (DME) projects).

Total Cost of Ownership (TCO)/Summary of Spending – This provides TCO information for planning, DME, O&M, and Managed Services.

Acquisition Strategy – This includes information on acquisition/contract strategy.

Program Risks – This includes information for the IT Risk Register.

Operational Analysis (OA) – This includes information related to the operational analysis (e.g., program performance measures, cost assessments, business drivers, technology drivers, and overall program recommendation).

Artifacts – This provides additional artifacts such as IT Program Oversight Briefings, BNA documentation, and Alternatives Analysis information.

3.1.1.4 Deliverables

The following table provides the minimum deliverables required as well as a recommended approach to assigning roles and responsibilities using a Responsible-Accountable-Consulted-Informed (RACI) matrix. It also notes organizations that, while not required on the Framework, may add value to the process. It is important to note that program and project managers have the authority to negotiate roles and responsibilities as well as create roles and responsibilities as they deem necessary and appropriate. Responsible roles own the deliverable in that they are responsible for completing it. Accountable roles must sign off or approve of the deliverable. Consulted roles have information that may be necessary to complete the deliverable. Informed roles must be notified of results, but need not be consulted.

Deliverable Description Repository Responsible Accountable Consulted Informed

IT Portfolio Registration Presentation

Supports ITPRB decisions about whether to classify a budget request as IT/non-IT and helps determine potential impact to PBGC’s IT Portfolio. Completed by the Program Managers and submitted to the ITPRB.

N/A Business Program Manager

ITPRB PMO

ITPD

CEA

ECD & Privacy Office

Infrastructure

IT & Business Program Managers

BPIT

Business Needs Analysis Document

The BNA helps PBGC fulfill requirements from the Clinger Cohen Act;

eGovernment Act, and OMB Circulars A-130 and A-11. The BNA deliverable is the result of a collaborative analysis process that assesses a business domain’s current state and results in a design for the target state as well as recommendations and a transition roadmap to achieve that future state that are funding through the capital planning and prioritization process.

N/A

Note: BNA Recommend-ations are stored in P3M.

Business Program Manager/ Sponsor

CEA

Business Sponsor

CEA

Business Sponsor

IT & Business Program Managers

ECD & Privacy Office

Infrastructure

Deliverable Description Repository Responsible Accountable Consulted Informed

Alternatives Analysis

The Alternatives Analysis deliverable is used to identify, compare, and assess viable information technology alternatives to address a given business need or performance gap, determine and recommend the best alternative, and document the associated rationale. A sound Alternatives Analysis may incorporate a cost benefit analysis and facilitates and documents a sound decision-making process.

An Alternatives Analysis also helps the agency perform acquisition planning and market research during procurements.

N/A Business Program Manager/ Sponsor

CEA

Business Sponsor

CEA

Business Sponsor

IT & Business Program Managers

ECD & Privacy

Table 3: Deliverables RACI

3.1.1.5 IT Standards & Guidance

Business Needs Analysis Standard: Defines the architectural approach for conducting a BNA to support the prioritization, investment and planning decisions as well as to establish or confirm the alignment of these decisions to PBGC business plans and strategic goals.

Alternatives Analysis Standard: Defines the approved process for identifying and recommending an IT product(s) or solution(s) that is the best overall fit for PBGC use. This standard and process helps to properly prepare for the PBGC acquisition process.

3.1.2 Project and Technology Management Stream

There are no gates/reviews, tasks, deliverables, or standards in this phase/stream.

3.1.3 Cybersecurity and Privacy Stream

There are no gates/reviews, tasks, deliverables, or standards in this phase/stream.

3.1.4 External Processes

There is one external process:

IT Risk Management: Focuses on identifying and evaluating the threats and opportunities pertinent to the proposed IT program/project and identifying risk management and mitigation strategies. For more information, visit the IT Risk Management Strategy and Procedures in the OIT Process & Procedures Library (PPL).

https://pbgcgov.sharepoint.com/EGD/PCD/PPL/PBGC%20Business%20Needs%20Analysis%20Standard%20and%20Methodology%20(Apr%202017).pdf https://pbgcgov.sharepoint.com/EGD/PCD/PPL/PBGC%20Alternatives%20Analysis%20Standard%20and%20Methodology%20(May%202016).pdf https://pbgcgov.sharepoint.com/EGD/PCD/PPL/IT%20Risk%20Management%20Strategy%20And%20Process%20(April%202017).pdf#search=IT%20risk%20management%20process%20and%20procedures

3.2 Planning Phase

During the Planning Phase, ITSLCM users conduct and document detailed program and project planning tasks. As part of planning, all IT Programs and Projects are required to establish a baseline for performance, scope, cost, and schedule.

3.2.1 Program Management Stream

3.2.1.1 Gates & Reviews

There is one gate in the Planning Phase:

ITPRB Prioritize Review: The ITPRB reviews the IT Program Plans for all IT Programs, assesses them for alignment and implementation readiness, and sends resulting prioritization recommendations to the BPIT.

Additional input may be requested from select SMEs to assist the ITPRB in its recommendations.

3.2.1.2 Roles

The most critical participants include:

IT & Business Program Managers: Update and maintain the IT Program Plan

ITPRB: Reviews the IT Program Plans for all IT programs, assesses them for alignment and implementation readiness, and sends resulting prioritization recommendations to the BPIT

3.2.1.3 Tasks

In the Program Management Stream, the IT and Business Program Managers are the key roles, and their primary responsibility is building, updating, and maintaining the IT Program Plan. This means planning the tasks for the program and consists of, at minimum, annually reviewing and updating the IT Program Plan. The IT and Business Program Managers are responsible for:

Identifying IPgT roles and responsibilities to ensure appropriate engagement.

Identifying recommendations from the BNA to address business and IT gaps, including system replacements.

Determining strategic alignment by analyzing the PBGC Strategic Plan and the IT Strategic Plan.

This is the start of the file's text. The full file is on GovTribe.

File details come from the government source that posted it. Updated .