Attachment_C.2.4_RMEW_Contingency_Plan.pdf

PDF 303 KB Posted

Attached to
Risk Management Early Warning & eFiling Support Federal contract opportunity
Solicitation number
16PBGC19R0005
Issued by
Pension Benefit Guaranty Corporation

About this file

This solicitation seeks proposals to provide Risk Management Early Warning (RMEW) and eFiling system support services to the Pension Benefit Guaranty Corporation (PBGC). Key details include: the single award IDIQ contract will have a base period of eight months and nine one-year option periods; the solicitation and any amendments will be available at FBO.gov; the question deadline is specified in Section L.5 of the RFP; interested parties should monitor FBO.gov for updates; paper copies will not be distributed; and the anticipated award date is May 2019. Offerors must be registered in SAM.gov to be eligible for award. The services required include support for RMEW and the eFiling system to support PBGC's Office of Information Technology.

Attachment C.2.4 - RMEW Information System Contingency Plan (ISCP)

View the file

Other files for this federal contract opportunity

Other files attached to Risk Management Early Warning & eFiling Support, newest first.
File Type Posted
Attachment_L.2.1_RMEW_Task_Order_1_-_Amd_1.pdf PDF
Amendment_01_Questions_and_Responses_Posting.xlsx XLSX spreadsheet
Amend_01_Solicitation_19R0005_rev_Nov_6.pdf PDF
Attachment_L.2.1.2_Proposed_Staffing_by_Labor_Category_.xlsx XLSX spreadsheet
Attachment_L.2.1_RMEW_Task_Order_1.docx DOCX document
Attachment_C.2.a_TRM_AD_Tools.xlsx XLSX spreadsheet
Attachment_C.6_Performance_Standards.xlsx XLSX spreadsheet
Attachment_C.4.2.a_ITSLCM_Framework_v3.0.pdf PDF
Solicitation_19R0005_rev_Oct_10.pdf PDF
Attachment_B.5_RMEW_IDIQ_Price_Schedule.xlsx XLSX spreadsheet
Attachment_B.5_RMEW_TO_1_Price_Schedule.xlsx XLSX spreadsheet
Attachment_L.3.b_RMEW_Proposed_Labor_Build_Up.xlsx XLSX spreadsheet
Attachment_C_Acronym_List.docx DOCX document
Attachment_C.2_RMEW_Environment_and_Requirements.docx DOCX document
Attachment_L.3.a_RMEW_Labor_Category_Crosswalk.xlsx XLSX spreadsheet
Attachment_L.5_Solicitation_Questions_Template.xlsx XLSX spreadsheet
Attachment_C.1_OIT_Organizational_Chart.pdf PDF
Attachment_C.4.2.b_ITSLCM_Handbook_v3.0.pdf PDF
Show all 18

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

Controlled Unclassified Information (CUI)

Pension Benefit Guaranty Corporation

Office of Negotiations and Restructuring

(ONR)

Risk Management Early Warning (RMEW)

Information System Contingency Plan

(ISCP)

June 2018

Version 2.0

RMEW ISCP 06/06/2018 v2.0 ii

Document Review and Change History

Version Number Date Summary of Changes

Section Number/Pa ragraph Number

Changes Made By

1.0 12/4/2017 Created draft All Benita Okodike

1.1 03/02/2018 Updated based on feedback from the RMEW Support Team

All RMEW Support Team

1.2 04/04/2018 Updated based on feedback from RMEW

COR

All RMEW Support Team

1.3 04/26/2018 Updated based on feedback from RMEW Team

All Benita Okodike

1.4 05/21/2018 Update from COOP Manager Review All Benita Okodike

2.0 06/06/2018 Performed quality assurance review All Wendy Maiello iii

Acronym List Acronym Description

AO Authorizing Official BCP Business Continuity Plan CISO Chief Information Security Officer CMP Configuration Management Plan

COOP Continuity of Operations CSAM Cyber Security Assessment and Management DBA Database Administrator DRP Disaster Recovery Plan DMS Document Management System

ERISA Employee Retirement Security Act FIPS Federal Information Processing Standard GSS General Support System ISCP Information System Contingency Plan ISO Information System Owner

ISSM Information System Security Manager ISSO Information System Security Officer

IT Information Technology ITISGSS Information Technology Infrastructure Services General Support System

IPT Integrated Project Team NIST National Institute of Standards and Technology OEP Occupant Emergency Plan OMB Office of Management and Budget ONR Office of Negotiations and Restructuring O&M Operations and Maintenance PBGC Pension Benefit Guaranty Corporation POC Point of Contact PM Project Manager (PM)

RTO Recovery Time Objective RMEW Risk Management Early Warning

SOP Standard Operating Procedures SA System Administrator

SPM System Program Manager SSP System Security Plan TC TeamConnect iv

Annual Review Record The Information System Owner shall review this plan at least annually, and sign and date the table below.

Review Date Reviewer 06/05/2018 Alexander Reed v

Contingency Plan Distribution A copy of this RMEW ISCP has been provided to the following personnel:

• Information System Owner (ISO)

• System Program Manager (SPM)

• System Administrator (SA)

• Information System Security Officer (ISSO)

• Information System Security Manager (ISSM) vi

Table of Contents 39T 39T139T39T 39T 39TIntroduction39T39T

39T 39T1.139T39T 39T 39TPurpose39T39T

39T 39T1.239T39T 39T 39TScope39T 39T

39T 39T1.339T39T 39T 39TAssumptions39T39T

39T 39T1.439T39T 39T 39TReferences39T39T

39T 39T239T39T 39T 39TConcept of Operations39T 39T

39T 39T2.139T39T 39T 39TSystem Description39T39T

39T 39T2.239T39T 39T 39TPhysical and Environmental Protection Security Controls39T39T

39T 39T2.339T39T 39T 39TOverview of the Three Phases39T39T

39T 39T2.439T39T 39T 39TRoles and Responsibilities39T39T

39T 39T2.539T39T 39T 39TContingency Training39T 39T

39T 39T339T39T 39T 39TActivation and Notification39T 39T

39T 39T3.139T39T 39T 39TNotification39T39T

39T 39T3.239T39T 39T 39TOutage Assessment39T39T

39T 39T439T39T 39T 39TRecovery39T39T

39T 39T4.139T39T 39T 39TSequence of Recovery Activities39T 39T

39T 39T4.239T39T 39T 39TRecovery Procedures39T 39T

39T 39T539T39T 39T 39TReconstitution39T39T

39T 39T5.139T39T 39T 39TValidation Data Testing39T 39T

39T 39T5.239T39T 39T 39TValidation Functionality Testing39T 39T

39T 39T5.339T39T 39T 39TRecovery Declaration39T 39T

39T 39T5.439T39T 39T 39TNotifications (Users)39T 39T

39T 39T5.539T39T 39T 39TData Backup39T39T

39T 39T5.639T39T 39T 39TEvent Documentation39T 39T

39T 39T5.739T39T 39T 39TDeactivation39T 39T

39T 39T639T39T 39T 39TContingency Plan Testing and Exercises39T39T

39T 39TAppendix A: Contingency Plan Security Requirements39T 39T

39T 39TAppendix B: Contact List39T39T

39T 39TAppendix C: System Validation Test Plan39T39T

39T 39TAppendix D: After-Action Report39T 39T

39T 39TAppendix E: Contingency Training Documentation39T 39T

39T 39TAppendix F: Test and Maintenance Schedule39T 39T vii

39T 39TApproval of RMEW Contingency Plan39T 39T

List of Tables 39T 39T UUTable 1: RMEW CP Roles and ResponsibilitiesUU39T39T

39T 39T UUTable 2: System Validation Test PlanUU39T39T

39T 39T UUTable 3: After-Action Report TemplateUU39T 39T

39T 39T UUTable 4: Test and Maintenance ScheduleUU39T 39T

1 Introduction In accordance with the National Institute of Standards and Technology (NIST) Special Publication (SP) 800-34, Rev. 1, Contingency Planning Guide for Information Systems; and NIST SP 800-53, Rev. 4, Recommended Security Controls for Federal Information Systems and Organizations, PBGC requires that the business areas within the agency develop and implement an Information System Contingency Plan (ISCP) for each IT system. Copies of the ISCP are distributed to key contingency planning personnel.

Information systems are vital to the Office of Negotiations and Restructuring (ONR) business processes. Therefore, it is important that services provided by PBGC operate effectively and without excessive interruption. This ISCP establishes comprehensive procedures to recover the Risk Management Early Warning (RMEW) quickly and effectively following a service disruption (NIST SP 800-34, Rev. 1). The RMEW system is comprised of the TeamConnect (TC) Legal Matter Management System, Document Management System (DMS) and E-Filing Portal applications.

1.1 Purpose

This RMEW ISCP establishes procedures to recover RMEW following a disruption. The following recovery plan objectives have been established:

• Maximize the effectiveness of contingency operations through an established plan that consists of the following phases:

o Activation and Notification Phase – To activate the plan and determine the extent of damage;

o Recovery Phase – To restore RMEW operations; and o Reconstitution Phase – To ensure that RMEW is validated through testing and that normal operations are resumed.

• Identify the activities, resources and procedures to carry out RMEW processing requirements during prolonged interruptions to normal operations.

• Assign responsibilities to designated Office of Negotiations and Restructuring (ONR) personnel and provide guidance for recovering RMEW during prolonged periods of interruption to normal operations.

• Coordinate contingency planning activities with incident handling activities.

• Ensure coordination with other personnel responsible for ONR contingency planning strategies.

• Ensure coordination with external points of contact and/or vendors associated with RMEW and execution of this plan.

1.2 Scope

The ISCP complies with National Institute of Standards and Technology (NIST) 800-34 Contingency Planning Guide for Federal Information Systems requirements.

This ISCP has been developed for RMEW, which is classified as a Moderate-Impact system, in accordance with the Federal Information Processing Standard (FIPS) 199, Standards for Security Categorization of Federal Information and Information Systems. Procedures in this ISCP is for Moderate-Impact systems.

This plan does not address replacement or purchase of new equipment, short-term disruptions lasting less than 48 hours, or loss of data at the onsite facility or at the user-desktop levels.

The RMEW ISCP does not apply to the following situations:

• Overall recovery and continuity of business operations. The Business Continuity Plan (BCP) and Continuity of Operations Plan (COOP) address continuity of business operations.

• Emergency evacuation of personnel. The Occupant Emergency Plan (OEP) addresses employee evacuation.

1.3 Assumptions

The following assumptions were used when developing this ISCP:

• RMEW has been established as a Moderate-Impact system in accordance with Federal Information Processing Standard (FIPS) 199.

• Alternate processing sites and offsite storage are not and have not been established for this system.

• Current backups of the system software and data may not be available.

• RMEW does not participate in PBGC Continuity of Operations Plan

(COOP).

• RMEW Recovery Time o TeamConnect (TC) has a recovery time objective of 10 days o DMS (Document Management System) has a recovery time objective of 30 days o E-Filing Portal has a recovery time objective of 30 days

• If RMEW is inoperable at the PBGC data center and cannot be recovered after 30 days, the ISCP will be activated.

• RMEW personnel have been identified and trained in their emergency response and recovery roles; they are available to activate the RMEW Contingency Plan.

1.4 References

The following references were also used in preparation of this document:

• Office of Management and Budget (OMB) Circular No. A-130, Transmittal Memorandum #4, Management of Federal Information Resources, Appendix III, Security of Federal Automated Information Resources, November 2000.

• FIPS Publication 199, Standards for Security Categorization of Federal Information and Information Systems, February 2004.

• NIST SP 800-34, Rev. 1, Contingency Planning Guide for Federal Information Systems, May 2010.

• NIST SP 800-53, Rev. 4, Recommended Security Controls for Federal Information Systems and Organizations, April 2013.

• NIST SP 800-53A, Assessing Security and Privacy Controls in Federal Information Systems and Organizations, December 2014.

2 Concept of Operations The Concept of Operations section provides details about RMEW, an overview of the three phases of the ISCP (Activation and Notification, Recovery, and Reconstitution), a description of roles and responsibilities of ONR personnel during a contingency activation, a description of training activities, and schedule.

2.1 System Description

RMEW functions as a major application within the direct management control and oversight of the Office of Negotiations and Restructuring (ONR). Within this system are components or subsystems functioning individually or in conjunction with other systems to complete their processing objectives. RMEW’s components generally reside within the PBGC Information Technology Infrastructure Services General Support System (ITISGSS), but the content and administration of the system/component is the responsibility of ONR. As such, most security controls are inherited from the general support system. RMEW is composed of three software applications that are hosted within PBGC’s ITISGSS.

o TeamConnect is a legal matter and case management system that gives RMEW the ability to share common information and coordinate more closely on a wide range of cases and legal matters, including plan termination actions, bankruptcy matters, and reportable event filings. It’s comprised of three components: TC Enterprise, TC Data Warehouse, and the TC Reports components. The TC Enterprise is accessed via a web interface utilizing Microsoft Internet Explorer and Google Chrome. The TC Data Warehouse provides defined and ad-hoc reporting from data sources linked to the TC database.

o DMS, RMEW’s document management system, is used for the capture, storage and retrieval of documents from historical records in the archives, to current reports, evidence, and legal testimony. DMS adds to RMEW the mechanism to store the documents in a variety of file types (MS Word, txt, MS Outlook, Excel, PDFs, etc.). It also includes searchable .pdf file format which is produced after having been scanned into the system by the Adlib Express Server OCR software.

o e-Filing Portal is the web-based application and database that interfaces with the RMEW system to push subsets of e-4010 tax filing data into RMEW. e-Filing Portal allows pension plan practitioners to file annual financial and actuarial information and create and submit 4010 tax filings per Section 4010 of the Employee Retirement Security Act (ERISA) which requires certain under-funded plans to report identifying financial, and actuarial information to the Pension Benefit Guaranty Corporation (PBGC).

2.2 Physical and Environmental Protection Security Controls

The physical and environmental protection security controls are in the System Security Plan (SSP) located in Cyber Security Assessment and Management (CSAM).

2.3 Overview of the Three Phases

This ISCP has been developed to recover RMEW using a three-phase approach. This approach ensures that system recovery efforts are performed in a methodical sequence to maximize the effectiveness of the recovery effort and minimize system outage time due to errors and omissions.

The system recovery phases are the following:

• Activation and Notification Phase – Activation of the ISCP occurs after a disruption or outage that may reasonably extend beyond the Recovery Time Objective (RTO) established for a system. The outage event may result in severe damage to the facility that houses the system, severe damage or loss of equipment, or other damage that typically results in long-term loss.

Once the ISCP is activated, information system owners and users are notified of a possible long-term outage, and a thorough outage assessment is performed for the system.

Information from the outage assessment is presented to information system owners and may be used to modify recovery procedures specific to the cause of the outage.

• Recovery Phase – This recovery phase details the activities and procedures for recovery of the affected system. Activities and procedures are written at a level that would allow an appropriately skilled technician to recover the system without intimate system knowledge. This phase includes notification and awareness escalation procedures for communication of recovery status to system owners and users.

• Reconstitution Phase – This reconstitution phase defines the actions taken to test and validate system capability and functionality. Reconstitution consists of two major activities: (1) validation of successful recovery and (2) deactivation of the plan.

During validation, the system is tested and validated as operational prior to returning operation to its normal state. Validation procedures may include functionality or regression testing, concurrent processing, and data validation. The system is declared recovered and operational by system owners upon successful completion of validation testing.

Deactivation includes activities to notify users of system operational status. This phase also addresses recovery effort documentation, activity log finalization, incorporation of lessons learned into plan updates, and readying resources for any future recovery events.

2.4 Roles and Responsibilities

This ISCP establishes several roles for RMEW recovery and recovery support, which are defined in Appendix B. Personnel or teams assigned an ISCP role are trained to respond to a contingency event affecting RMEW.

2.5 Contingency Training

Training for personnel with ISCP responsibilities should focus on familiarizing them with ISCP roles and teaching skills necessary to fulfill those roles. This approach helps ensure that staff are prepared to participate in tests, exercises, and actual outage events (47T47TNIST SP 800-34, Rev. 1).

Training may be conducted in conjunction with annual testing. The testing exercises may serve as training exercises. ISCP testing results also may be incorporated into refresher training.

Training records are maintained to document that the training covers the procedures and activities necessary to fulfill identified organizational contingency roles and responsibilities, and to document that training is provided according to established schedules. See Appendix E for RMEW training records.

3 Activation and Notification The Activation and Notification Phase defines initial actions taken once a RMEW disruption has been detected or appears to be imminent. This phase includes activities to notify recovery personnel, conduct an outage assessment, and activate the ISCP. At the completion of the Activation and Notification Phase, RMEW ISCP staff will be prepared to perform recovery measures to restore system functions. Activation Criteria and Procedure

The ISCP may be activated if one or more of the following criteria are met:

o The type of outage indicates RMEW (TeamConnect, DMS and e-filling) will be down for more than 30 days o The facility housing RMEW (TeamConnect, DMS and e-filling) is damaged and may not be available within 30 days

The following persons or roles may activate the ISCP if one or more of these criteria are met: Please reference Appendix B for key personnel’s contact information.

3.1 Notification

The first step upon activation of the RMEW ISCP is notification of appropriate business and system support personnel. Contact information for appropriate Points of Contact (POCs) is included in Appendix B.

3.2 Outage Assessment

Following notification, a thorough outage assessment is necessary to determine the extent of the disruption, any damage, and expected recovery time. This outage assessment is conducted by the

Production Support Team. Assessment results are provided to the ISCP Coordinator to assist in the coordination of the recovery of RMEW.

The ISO notifies users RMEW is unavailable and informs them of the expected recovery time assessed by the Production Support Team. The ISO collects input from users to determine if RMEW deliverables can be delayed pending recovery or if manual data processing methods should be adopted until service is restored.

If necessary, the ISO coordinates manual production of RMEW deliverables until service is restored.

4 Recovery The Recovery Phase provides formal recovery operations that begin after the ISCP has been activated, outage assessments have been completed (if possible), personnel have been notified, and appropriate teams have been mobilized. Recovery Phase activities focus on implementing recovery strategies to restore system capabilities, repair damage, and resume operational capabilities at the original or new permanent location. After the completion of the Recovery Phase, RMEW will perform the functions identified in this plan.

4.1 Sequence of Recovery Activities

The following activities shall apply during recovery of RMEW:

• The Production Support Team monitors the recovery of primary systems and informs the ISO when they have recovered RMEW.

• The Production Support Team checks RMEW data to ensure that all data have been recovered and RMEW is up to date. Upon notification from the Production Support Team that all data has been recovered, the ISO produces a test reports to confirm the system is fully operational.

• If RMEW is operating normally, the ISO notifies users, and no further action is required.

If primary systems are available and refreshed but RMEW is not, the ISO checks with the RMEW Operations and Maintenance (O&M) System Administrator and Federal IT Project Manager (PM) to determine the sequence and timing of checking links to sources and running off-cycle data refreshes if required.

• The ISO will inform system users of recovery progress and reporting readiness.

4.2 Recovery Procedures

The following procedures are provided for recovery of RMEW at the original or established alternate location. Recovery procedures are outlined and should be executed in the sequence presented to maintain an efficient recovery effort.

Each business unit will have to enact its business continuity plan. Concurrently, General Support System (GSS) will activate their contingency plan.

A. If multiple users report inability to access RMEW, the PBGC service desk will report the outage to the Production Support Team, which will:

1. Contact O&M Team to determine the scope of the issue

2. Initiate root cause analysis

3. Estimate downtime and proceed as follows:

a. If brief (1 day – 2 weeks):

I. Monitor remediation

II. Report progress to Integrated Project Team (IPT), and users until systems are fully functional

III. Test links

IV. Communicate readiness to reestablish normal operations to DBA and appropriate source system administrators

V. Run refresh scripts as applicable to catch up on data

VI. Inform RMEW AO, ISO, ISSO, and system users of progress and reporting readiness.

b. If longer period of downtime (more than 2 weeks or near deadline)

I. The Production Support Team Will Perform Steps B.1 through B.3

II. Simultaneously, initiate source system queries for performance measures

III. The ISO will coordinate manual production of RMEW deliverables

5 Reconstitution Reconstitution is the process by which a recovered system is tested to validate system capability and functionality. During the Reconstitution Phase, recovery activities are completed, and normal system operations are resumed. If the original facility is unrecoverable, the activities in this phase can also be applied to preparing a new permanent location to support system processing requirements. This phase consists of two major activities: (1) validation of successful recovery and (2) deactivation of the plan.

5.1 Validation Data Testing

Validation data testing is the process of testing and validating recovered data to ensure that data files or databases have been recovered completely. To validate the data recovered, a complete check of the recovered data shall be verified against the last available backup by the RMEW Development/Support Team. Detailed data test procedures are provided in Appendix C, System Validation Test Plan.

5.2 Validation Functionality Testing

Validation functionality testing is the process of verifying that recovered system functionality has been tested and the system is ready to return to normal operations. This will be completed by the RMEW Development/Support Team in collaboration with ONR Business Representatives.

Detailed data test procedures are provided in Appendix C: System Validation Test Plan.

5.3 Recovery Declaration

Upon successfully completing testing and validation, the ISO will formally declare that recovery efforts are complete and RMEW is in normal operations. RMEW business and technical POCs will be notified of the declaration via email communications from the ISO.

5.4 Notifications (Users)

Upon return to normal system operations, RMEW users will be notified by the RMEW ISO via email.

5.5 Data Backup

As soon as reasonable following recovery, the system should be fully backed up and a new copy of the current operational system stored for future recovery efforts. This full backup is then kept with other system backups by PBGC IT Operations Backup Managers. The procedures for conducting a full system backup are:

Daily backups are taken during off-hours, with full backups occurring each weekend, and incremental backups between full backups using Veritas NetBackup Enterprise.

5.6 Event Documentation

It is important that all recovery events be well documented, including actions taken and problems encountered during the recovery effort and lessons learned for inclusion in updates to this ISCP.

It is the responsibility of all recovery teams or personnel to document their actions during the recovery effort and to provide that documentation to the ISO who will coordinate and update with the ISSO.

Types of documentation that should be generated and collected after a contingency activation include:

• Activity logs (including recovery steps performed and by whom, the time the steps were initiated and completed, and any problems or concerns encountered while executing activities);

• Functionality and data testing results;

• Lessons learned documentation; and

• After Action Report.

5.7 Deactivation

Once all activities have been completed and documentation has been updated, the ISO will formally deactivate the ISCP recovery effort. Notification of this declaration will be provided to all business and technical POCs.

6 Contingency Plan Testing and Exercises ISCP testing is an essential element of a viable contingency capability — it enables plan deficiencies to be identified and addressed prior to implementation during an actual disruption or disaster. Testing confirms the accuracy of individual recovery procedures and the overall effectiveness of the plan and helps evaluate the ability of the recovery staff to implement the plan quickly and effectively.

Refer to Appendix E and Appendix F for contingency training documentation and a test and maintenance schedule. Test results are reviewed, corrective actions are initiated, and the ISCP is updated accordingly.

Appendix A: Contingency Plan Security Requirements

The ISCP security controls are in the SSP.

Appendix B: Contact List

Table 1: RMEW CP Roles and Responsibilities

Title Name Phone Email Responsibilities

Information System

Owner (ISO)

Alexander Reed

202- 326- 4000, ext.6600

Reed.Alexander@pbgc.gov Monitors performance, initiates and coordinates plan actions, and informs system users and other CP team members of operating status.

Business Program Manager

Karen Turner

202- 326- 4000, ext.3476

Turner.Karen@pbgc.gov Monitors recovery with ISO and informs leadership as required.

Federal IT Project

Manager

Donna Carraway

202- 326- 4000, ext.

Carraway.Donna@pbgc.gov Monitor performance and keep the ISO informed. Coordinate the test results, support documentation completion including the after-action report and lessons learned

Contractor IT Project

Manager

Heather Birch

202- 326- 4000, ext.

Birch.Heather@pbgc.gov Monitor performance and keep the ISO informed. Coordinate the test results, support documentation completion including the after-action report and lessons learned

RMEW

Technical

Lead

Rose Aquilino

202- 326- 4000, ext.5522

Aquilino.Rose@pbgc.gov Assesses operability of RMEW, executes queries, tests connectivity, and executes data refreshes as required.

Title Name Phone Email Responsibilities

RMEW

System

Administrator

Tiffany Yim

202- 326- 4000, ext.5574

Yim.Tiffany@pbgc.gov Assists in troubleshooting or reestablishing current databases as required.

Information System Security Officer

(ISSO)

Benita Okodike

202- 326- 4000, ext.3805

Okodike.Benita@pbgc.gov Monitors recovery and informs IT security of steps and status.

Appendix C: System Validation Test Plan

Once the system has been recovered, the following steps will be performed to validate the system data and functionality:

Table 2: System Validation Test Plan

Procedure Expected Results

Actual Results Successful? Performed By

Log into 39T39TRMEW TeamConnect39T

Initial

RMEW

TeamConnect screen appears

Search for a Corporate Parent

Corporate Parent screen displays

Select a link (Actuarial Work Requests, Events, Pension Plans, Cases, Matters, Assignees/Involved Parties, etc.) on the left navigation bar

Selected screen displays and data is accurate

Select ‘History’ link from the left navigation bar

History

Select ‘Documents’ link from the left navigation bar

Documents

Select ‘View’ from the Documents screen

Document opens and is available for review

Select ‘Upload Documents’ from the left navigation bar

Document screen appears with Document Metadata http://teamconnect.ent.pbgc.gov/ http://teamconnect.ent.pbgc.gov/

Procedure Expected Results

Actual Results Successful? Performed By section

Upload document to testing Corporate Parent – 57777

Document successfully uploads to testing Corporate Parent

Select the ‘Reports’ tab

Report screen

Select any report from the report screen and launch it

Report launches successfully

OGC Only: Search for a Matter

Matter screen

OGC Only: Select a link (Plans, Claims, Facts, Assignees/Involved Parties, etc.) from the left navigation bar

Selected screen displays and

Documents, Core Bankruptcy Documents or Related Documents from the left navigation bar

Selected screen displays with documents

‘View’ from the Documents screen

Document opens and is

MEPD Only:

Search for a Financial

Financial Assistance

Procedure Expected Results

Actual Results Successful? Performed By

Assistance displays

MEPD Only:

Select a link (Involved Parties, Filer Comments, Cost per Participant, etc.)

Selected screen displays and

MEPD Only:

Select ‘View’ from the Documents block

Document opens and is

Click on the Documents tab and search for any document

DMS

Documents screen displays with search results

Appendix D: After-Action Report

Table 3: After-Action Report Template

AFTER-ACTION REPORT

Team Name: Date of Report:

Team Leader:

Situation Being Reported:

Objectives Not Met (List the objectives not met during this situation per the ISCP):

Problems (Define problems encountered while performing ISCP activities and describe actions taken to resolve each):

Areas of Weakness (In view of the objectives not met and the problems encountered, specify support functions that were not performed effectively or efficiently; functional areas to consider include management and control, communications, logistics support, administrative support, user response, and operational support from in-house resources/backup facility):

Recommendations (For each area of weakness, recommend improvements; consider the training program, administrative procedures, operational procedures, communications, maintenance procedures (for backup capabilities), and written instructions pertaining to the above):

Supporting Documentation (Attach a copy of completed checklists used during contingency activities, showing the date and time that the ISCP tasks were completed, and the names of the team members who were assigned those tasks):

Appendix E: Contingency Training Documentation

Prior to the contingency training tabletop exercise, documentation will be sent out to all participants for review.

Appendix F: Test and Maintenance Schedule

Table 4: Test and Maintenance Schedule

Step Date Due Responsible Party

Date Scheduled Date Held

Identify tabletop facilitator 09/01/2018 ISSO

Develop tabletop test plan 09/15/2018 ISSO

Invite participants 09/16/2018 ISSO

Conduct tabletop test 09/30/2018 ISSO

Finalize results documentation (After Action Report) and lessons learned

10/15/2018 ISSO

Update ISCP based on lessons learned

10/20/2018 ISSO

Approve and distribute updated version of ISCP

10/30/2018 ISO & ISSO

Approval of RMEW Contingency Plan

Information System Owner Signature

Alexander Reed Date Information System Owner Office of Negotiations and Restructuring

Information System Security Officer Signature

Benita Okodike Date Information System Security Officer

1 Introduction
1.1 Purpose
1.2 Scope
1.3 Assumptions
1.4 References
2 Concept of Operations
2.1 System Description
2.2 Physical and Environmental Protection Security Controls
2.3 Overview of the Three Phases
2.4 Roles and Responsibilities
2.5 Contingency Training
3 Activation and Notification
3.1 Notification
3.2 Outage Assessment
4 Recovery
4.1 Sequence of Recovery Activities
4.2 Recovery Procedures
5 Reconstitution
5.1 Validation Data Testing
5.2 Validation Functionality Testing
5.3 Recovery Declaration
5.4 Notifications (Users)
5.5 Data Backup
5.6 Event Documentation
5.7 Deactivation
6 Contingency Plan Testing and Exercises
Appendix A: Contingency Plan Security Requirements
Appendix B: Contact List
Appendix C: System Validation Test Plan
Appendix D: After-Action Report
Appendix E: Contingency Training Documentation
Appendix F: Test and Maintenance Schedule
Approval of RMEW Contingency Plan
2018-06-08T15:47:55-0400
ALEXANDER REED

File details come from the government source that posted it. Updated .