About this file

This document provides a Quality Assurance Surveillance Plan (QASP) for a Datacenter and Cloud Optimization procurement to be conducted by the Department of Homeland Security. The QASP outlines 36 key performance standards across areas such as incident management, availability, backup success rates, and security. It describes methods for monitoring contractor performance against service level agreements on metrics including speed of response, customer satisfaction ratings, and system uptime percentages. The QASP also establishes procedures for documenting performance through the Contractor Performance Assessment Reporting System, including the use of ratings defined as exceptional, very good, satisfactory, marginal, and unsatisfactory. Roles and responsibilities are designated for the contractor, contracting officer, contracting officer's representative, and government program manager to implement the quality assurance surveillance activities defined in this plan.

View the file

Other files for this federal contract opportunity

Other files attached to Department of Homeland Security (DHS) Data Center and Cloud Optimization (DCCO) Support Services, newest first.
File Type Posted
FINAL DRAFT Request for Proposal Feedback Template.xlsx XLSX spreadsheet
Attachment Draft J-1 Pricing Schedule.xlsx XLSX spreadsheet
Attachment J-4 Draft DD254.pdf PDF
Attachment J-2 Draft PWS.pdf PDF
DCCO Draft Final Request for Proposal.pdf PDF
DCCO Industry Day II Audio.mp4 MP4 file
DHS_DCCO_Industry_Day_II_Presentation_September 10 2020 FINAL .pdf PDF
Draft CLIN Structure.pdf PDF
Attachment II - DRAFT Solicitation Feedback Template.xlsx XLSX spreadsheet
Draft Evaluation Factors .pdf PDF
DRAFT Section B - Supplies or Service and Price.pdf PDF
Draft - Performance Work Statement .pdf PDF
DHS DCCO Industry Day Presentation March 2020.pdf PDF
DCCO Industry Day Recording.mp4 MP4 file
DCCO Industry Day Presentation - Question and Answers .pdf PDF
Attachment I - Questions and Topics of Discussion Template.xlsx XLSX spreadsheet
DHS DCCO Support Services - Executive Summary - Objectives and Scope.pdf PDF
Show all 17

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

SECTION X – ATTACHMENT X-Y

QUALITY ASSURANCE SURVEILLANCE PLAN (QASP)

Datacenter and Cloud Optimization procurement (DCCO)

Contract Number: TBD Contractor’s name: TBD (hereafter referred to as the contractor)

TABLE OF CONTENTS

INTRODUCTION

This quality assurance surveillance plan (QASP) is pursuant to the requirements listed in the Performance Work Statement (PWS) This plan sets the procedures and guidelines the Department of Homeland Security (DHS) Office of the Chief Information Officer (OCIO) will use in ensuring the required performance standards or services levels are achieved by the contractor. Other work required under this contract may be monitored and other contractual remedies taken by the Government as needed.

Executive Summary

This Quality Assurance Surveillance Plan (QASP) provides a systematic method to evaluate performance for the stated contract. This QASP explains the following:

What will be monitored.

How monitoring will take place.

Who will conduct the monitoring.

How monitoring efforts and results will be documented.

This QASP does not detail how the contractor accomplishes the work. Rather, the QASP is created with the premise that the contractor is responsible for management and quality control actions to meet the terms of the contract. It is the Government’s responsibility to be objective, fair, and consistent in evaluating performance.

In addition, the QASP should recognize that unforeseen and uncontrollable situations may occur.

This QASP is a “living document” and the Government may review and revise it on a regular basis. However, the Government shall coordinate changes with the contractor. Updates shall ensure that the QASP remains a valid, useful, and enforceable document. Copies of the original QASP and revisions shall be provided to the contractor and Government officials implementing surveillance activities.

The following FAR clauses may apply depending on contract type:

37.6 Performance-Based Acquisition

46.4 Government Contract Quality Assurance

52.246-4 Inspection of Services – Fixed-Price, 52.246-6 Inspection of Services – Time-and-Material and Labor-Hour

Purpose

This QASP describes the procedures the DHS will use to monitor and evaluate the Contractor’s performance.

The primary concern of the DHS is with the determined quality of the services provided by the Contractor.

Therefore, the QASP focuses on the Governments measure of the Contractor’s performance on service level agreements. It is intended that the QASP be a tool to guide the contracting officer’s representative (COR) in assessing Contractor performance. In some cases, specific metrics are used to measure Contractor performance; in other cases, subjective judgment and evaluation by DHS/OCIO personnel will be the determining criteria. This plan describes the methodology utilized to conduct both quantitative and qualitative evaluation of Contractor performance under the contract.

The QASP provides a means for evaluating whether the contractor is meeting the performance standards/quality levels identified in the PWS

Quality Management Strategy

The contractor is responsible for the quality and consistency of all services provided. The contractor measures that quality through execution of its own Quality Management Plan. Through surveillance of the DCCO PRS, SLA performance, Deliverables and review of stated operational practices, the DHS will regularly review quality of delivered services.

The contractor SLA performance will generally be monitored on a monthly basis. The COR and designates will surveille stated monthly performance metrics, the trends, and report any discrepancies in findings

The Contractor PM shall participate in quarterly “self-assessments “with the COR and associated PM designates. Quarterly performance review will be conducted informally and act as a “progress report” on the annual assessment of Contractor performance. Quarterly assessment will detail adherence to the submitted QMP deliverable and performance in stated Contractor performance assessment reporting system (CPARS) categories.

The COR will conduct annual performance assessments in the CPARS system that encompass monthly SLA performance metric analysis, detail of contractor performance and support, and qualitative review of performance that encompasses quarterly assessments of performance.

The COR will monitor performance and review deliverables furnished by the contractor to determine how the contractor is performing against communicated performance objectives of the QMP. The COR will surveille determinations regarding incentives and disincentives based on the QASP and notify the contractor of findings. The contractor will be responsible for making adjustments to SLA performance levels, incentives, disincentives and deliverables as necessary, based on COR review. DHS on-site representatives will monitor and report to the COR on contractor practices, adherence to industry standards, performance, and support.

QASP Relation to the Quality Management Plan

The Contractor’s QMP is a formal contract deliverable. The DHS expects the implementation of the Contractor’s QMP requirements will be sufficient in meeting the performance details of the PWS. While the QMP represents the way the Contractor will pursue quality and timeliness of services, as defined in the PWS, the QASP represents the way the DHS will evaluate the Contractor’s performance. The Contractor’s QMP and the QASP should be complementary and ultimately ensure successful Contractor performance.

Revisions to the QASP

The QASP will be used in DHS’s administration of the contract and remains subject to revision at any time by the Government throughout the contract performance period. Revisions to this surveillance plan are the responsibility of the Contracting Officer (CO) or designee with support, input, and coordination with the DHS program designees. An initial revision, encompassing surveillance details related to the Contractors submitted QMP may be made within 60 days of the initial QMP submission. While the Contractor may be engaged determinations of necessary revisions, changes may be made unilaterally at the discretion of the Government.

As the performance period progresses, surveillance may be altered as determined necessary in service areas where performance is either consistently excellent or consistently unsatisfactory. The DHS may also alter surveillance as key priorities are determined by DHS, OCIO or associated program management offices (PMO)s.

Roles and responsibilities

As the purpose of QASP is to ensure that the Government receives satisfactory services and that the Contractor is meeting contractual requirements, the roles and responsibilities of the Contractor and Government involved in the QASP are described below.

Contractor Roles and Responsibilities - The Contractor is responsible for delivering acceptable service levels, as detailed in the QASP and per industry standards for any actions and activities not covered in the QASP. The Contractor is responsible for implementing its QMP, which is a contract deliverable. The QMP describes the Contractor’s methods for ensuring all services provided under the contract meet established performance standards. The Contractor is responsible for producing, maintaining, and providing for audit, quality assurance/control records and reports and all records associated with the investigation and resolution of COR identified performance issues.

The Quality Manager (QM) is a Key Personnel position. The QM is responsible for providing appropriate visibility as to the quality of work products and the maintenance of standards, processes and procedures at the program and project level across the HCE Enterprise. The QM ensures compliance with stated quality assurance standards, guidelines, and procedures.

The Program Manager (PM) is responsible for all Contractor work performed under the contract and as stated in the PWS. The PM shall meet with the COR and PMO designates regularly. The PM shall participate in quarterly performance reviews and engage Contractor staff, including the QM, as appropriate.

The following employees of the contractor serve as the contractor’s representatives for this contract:

Program Manager - <upon award, enter name> Telephone: <enter number> Email: <enter address>

b. Task Manager - <upon award, enter name> Telephone: <enter number> Email: <enter address>

c. Other Contractor Personnel - <upon award, enter name or delete these lines if not applicable> Title: <enter title> Telephone: <enter number> Email: <enter address>

Government Roles and responsibilities – The government is responsible for clear communication of established DHS initiatives, standards for performance and acceptance of deliverables. The Government also shall revise the QASP to surveille in concert with stated QMP practices.

Contracting Officer (CO) - The CO shall ensure performance of all necessary actions for effective contracting, ensure compliance with the contract terms, and shall safeguard the interests of the DHS regarding the contractual relationship. The CO shall also assure that the contractor receives impartial, fair, and equitable treatment under this contract. The CO is ultimately responsible for the final determination of the adequacy of the contractor’s performance.

Contracting Officer’s Representative (COR) - The COR is responsible for technical administration of the contract and shall assure proper Government surveillance of the contractor’s performance. The COR shall revise the QASP to meet the specifics of the submitted QMP and also keep a quality assurance file including (but not limited to) monthly SLA results, quarterly quality review details and annual CPARS. At the conclusion of the contract or when requested by the CO, the COR shall provide documentation to the CO.

The COR is not empowered to make any contractual commitments or to authorize any contractual changes on the Government’s behalf. The contractor shall refer any changes they deem may affect contract price, terms, or conditions to the CO for action.

Government PM – the Government PM shall meet regularly with the COR and Contractor PM to keep open communication of customer and executive feedback and keep the Contractor PM abreast of DHS OCIO and PMO initiatives. The PM may engage PMO designates and Government Service Owners as necessary to participate in related meetings.

Assigned CO: TBD Organization or Agency:

Telephone:

Email:

Assigned COR: TBD Organization or Agency:

Telephone:

Email:

Assigned PM: TBD Organization or Agency:

Telephone:

Email:

Performance Standards.

Performance standards define desired services. The Government performs surveillance to determine if the contractor exceeds, meets or does not meet these standards.

The Performance Work Statement (PWS) (Attachement J3) and the QASP includes performance standards and other applicable contract requirements. The Government shall use these standards to determine contractor performance and shall compare contractor performance to the Acceptable Quality Levels (AQL).

Incentives.

The Government shall use incentives and disincentives for the Enterprise SLAs. Incentives or disincentive shall be based on exceeding, meeting, or not meeting performance standards. Information about incentives can be found in the QASP.

Methods of Quality Assurance Surveillance.

Various methods exist to monitor performance. The COR may use the surveillance methods listed below in the administration of this QASP. Final determination of methods of surveillance will be determined upon review of the Contractor’s QMP deliverable.

a) Direct Observation - Can be performed periodically or through 100% surveillance by the COR and or designates.)

- Performance Standard; All performance standards listed in the QASP and other applicable contract requirements

b) Management Information Systems (MIS). (Evaluates outputs through the use of monthly contract deliverable management information reports and other compliance output from other entities.)

- Performance Standard; All SLAs listed in the QASP and other applicable contract requirements

c) Periodic Inspection. (Uses a comprehensive evaluation of selected outputs. Inspections may be scheduled [Daily, Weekly, Monthly, Quarterly, or annually] or unscheduled, as required.)

d) Validated user/Customer complaints. (Relies on the user of the service to identify deficiencies.

Complaints are then investigated and validated.)

e) Random Sampling. (Designed to evaluate the outputs of the award requirement by randomly selecting and inspecting a statistically significant sample, such as sanitization service of level 1 hardware.)

f) Periodic Sampling. (Variation of random sampling. However, sample is only taken when a deficiency is suspected. Good follow-up to MIS analysis. Sample results are applicable only for the specific work inspected. Since sample is not entirely random, it cannot be applied to total activity performance.)

g) Progress or Status Meetings. (Status Meetings; at a minimum Monthly SLA review and daily status briefing/meetings with key contract personnel, support personnel, and onsite federal representation.

Progress Meetings; ADOHC meetings directed by the customer and contractor that can include but are not limited to, the execution of a separate Task Order, tech uplift of supporting equipment and security related matters.

h) Performance reporting. (Evaluate metrics for a specific time period as listed in the QASP.)

Surveillance results may be used as the basis for revisions to Deliverables and to substantiate CPARS review ratings. In such cases, the Inspection of Services clause in the Contract becomes the basis for the CO’s actions.

Quality Assurance Surveillance Plan Table

Table 1: DCCO PWS Section 12; Performance Requirements Summary Service Output

Performance Objective Acceptable Quality Level

(AQL)

Method of Inspection Positive Incentive

Negative Incentive

1 Service Desk: Speed to Answer. Speed to answer Service Desk calls in 45 seconds or less.

95% COR review and validation of vendor SLA outputs derived from daily automated report is issued by NASA/NCCIPS

CPARS

Rating

CPARS

Rating

2 Service Desk: Speed to Respond to Communications. Speed to respond to contacts through identified communication channels other than telephone (currently email) in 1 elapsed hour or less.

95% COR review and validation of vendor SLA outputs

CPARS

Rating

CPARS

Rating

3 Customer Satisfaction Rating. Overall measure of the Net Promoter Score (NPS) measured monthly is greater than or equal to 30. Service Satisfaction rated as “Very Satisfied” or “Extremely satisfied” measured quarterly.

NPS≥30 COR review of NPS documentation (50% weight)

CPARS

Rating

CPARS

Rating

94% of responses rating 8.0 or better on a survey scale of 1 to 10.

94% COR review of vendor provided SLA outputs from an industry-recognized survey tool (Medallia or equivalent) (50% weight)

CPARS

Rating

CPARS

Rating

4 Root cause determination. The percentage of Severity 1 and Severity 2 Incidents for which Root Cause Analysis (RCA) has been completed and submitted within 72 hours of Incident occurrence.

95% COR Review of noted incident start time and RCA submission time

CPARS

Rating

CPARS

Rating

5 Incident Management Resolution Time (Severity 1, 2, and 3). Elapsed time to resolve incidents for Severity 1, 2, and 3 incidents occurring during a reporting period measured in continuous elapsed time from the time of incident occurrence – not in business hours.

99.5% per Severity Level

COR review of vendor provided SLA outputs detailing intendent duration

CPARS

Rating

CPARS

Rating

Severity 1 – 4 Clock Hours (240 Minutes);

Severity 2 – 8 Clock Hours (480 minutes);

Severity 3 – 12 Clock Hours (720 minutes)

6 Incident Management: Time for DHS System Owner to be notified when non-security incident is found. Target elapsed time for System Owner and designated stakeholder notification for Severity 1 and 2 incidents is 30 minutes or less; notification time for Severity 3 incidents is 8 hours for a reporting period.

95% COR review of vendor provided SLA outputs detailing total number of incidents and notification times

CPARS

Rating

CPARS

Rating

7 Incident Management: Status Update Frequency.

Incident tickets for Priority Level 1 and Level 2 incidents are to be updated at least hourly. Priority Level 3 incidents are to be updated every 8 hours.

All other incident tickets shall be updated at least daily. Measurement is for all tickets during a reporting period.

99.5% per Priority Level

COR review of vendor provided SLA outputs detailing update frequency and COR observed update percentages for Sev 1,2&3 incidents

CPARS

Rating

CPARS

Rating

8 Service Asset and Configuration Management:

Percentage of CMDB Inventoried Annually - Accuracy of Level 1 and 2 Systems. Percentage of Level 1 and 2 Systems found to have accurate information in the CMDB measured annually with an error rate less than or equal to 2%.

98% Annual COR review of monthly vendor generated, Fed validated SLA outputs detailing CMDB accuracy

CPARS

Rating

CPARS

Rating

9 Service Asset and Configuration Management:

Percentage of CMDB Accuracy of Level 1 and 2 Systems. Percentage of Level 1 and 2 systems found to have accurate information in the CMDB in a reporting period. Validation is based on a 25% minimum progressive sample of the baseline inventory measured monthly to ensure a 100% audit over four months, with less than a 2% error rate.

98% Monthly COR review of vendor generated, Fed (on site when possible) validated SLA outputs detailing CMDB accuracy

CPARS

Rating

10 Service Asset and Configuration Management: Percentage of Contractor provided and/or managed physical and virtual assets and cloud services inventoried. Validation that at least 10.00% of baseline inventory of physical and virtual assets and cloud services within the HCE was progressively audited during a monthly reporting period to ensure a 100% validation over 10 months with an error rate not to exceed 0.5%.

99.5% Monthly COR review of vendor generated, Fed (on site when possible) validated SLA outputs detailing HCE inventory

CPARS

Rating

CPARS

Rating

11 Change Management: Percentage of Successfully Implemented Changes – Level 1 and 2. Percentage of Changes authored and primarily executed by the Contractor for Contractor Level 1 and 2 supported systems in data centers, colocation facilities, and cloud environments that did not result in an incident or fault and with no negative impacts to operational stability.

99.5% COR review and validation of vendor SLA outputs detailing percentage of closed change tickets

CPARS

Rating

CPARS

Rating

12 Change Management: Percentage of Changes Resulting in an Incident. Percentage of Incidents per reporting period that were the result of Changes authored and primarily executed by the Contractor.

≤3% COR review and validation of vendor SLA outputs detailing incidents causes by changes

CPARS

Rating

CPARS

Rating

13 Change Management: Percentage of Emergency Changes. Percentage of Contractor initiated non-security changes that were flagged as “Emergency” compared to all other rendered changes.

≤10% COR review and validation of vendor SLA outputs detailing percentage of emergency changes

CPARS

Rating

CPARS

Rating

14 Capacity Management: DHS CPU Utilization.

Percentage of CPU Utilization for Contractor provided and/or managed Level 2 systems or application systems – reporting period average (mean) percentage.

≤70% COR review and validation of vendor SLA outputs detailing CPU utilization

CPARS

Rating

CPARS

Rating

15 Capacity Management: DHS Disk Utilization.

Percentage of System Disk Utilization – Level 2 systems. Average (mean) Percentage of disk Utilization for Contractor-provided and/or Level 2 systems.

≤70% COR review and validation of vendor SLA outputs detailing disk utilization

CPARS

Rating

16 Capacity Management: DHS SAN Utilization.

Percentage of SAN Utilization – Level 2 Systems.

Average (Mean) Percentage of SAN Utilization of Contractor-provided and/or managed Level 2 Systems.

≤70% COR review and validation of vendor SLA outputs detailing SAN utilization

CPARS

Rating

CPARS

Rating

17 Capacity Management: DHS Network Bandwidth Utilization. Percentage of LAN bandwidth utilization of Contractor provided and/or managed DHS HCE Network Infrastructure. – Reporting Period Average (Mean) Percentage of Network Utilization of Contractor provided and/or managed DHS HCE infrastructure (enterprise).

≤70% COR review and validation of vendor SLA outputs detailing HCE network bandwidth utilization

CPARS

Rating

CPARS

Rating

18 Capacity Management: HCE CSP Compute Resource Utilization. Average Percentage Utilization of CSP-Resources provided by the Contractor during the reporting period (average (mean) percentage) does not exceed the AQL.

≤85% COR review and validation of vendor SLA outputs detailing CSP compute resource utilization

CPARS

Rating

CPARS

Rating

19 Capacity Management: HCE CSP Storage Resource Utilization. Average Percentage of Storage Resource Utilization for CSP storage resources provided by the Contractor during the reporting period does not exceed the stated AQL.

≤85% COR review and validation of vendor SLA outputs detailing CSP storage resource utilization

CPARS

Rating

CPARS

Rating

20 Capacity Management: HCE CSP Database Resource Utilization. Percentage of Database Resource Utilization – Level 2 Systems. Average (Mean) Percentage of Database Resource Utilization of Contractor-provided and/or managed Level 2 Systems.

≤85% COR review and validation of vendor SLA outputs detailing CSP database resource utilization

CPARS

Rating

CPARS

Rating

21 Availability Management. Percentage of System Availability. Percentage of availability per reporting period for Contractor-provided and/or managed Level 1 and 2 systems, including cloud services. Reporting Period Average (Mean) percentage of System availability for Contractor-provided Level 1 and 2 Systems, including cloud services.

99.9% COR review and validation of vendor SLA outputs detailing System Availability

CPARS

Rating

22 Availability Management: Percentage of LAN Availability. Percentage of availability per reporting period for Contractor-provided and/or managed LAN services. Reporting period average (Mean) percentage of LAN availability.

99.9% COR review and validation of vendor SLA outputs detailing percentage of LAN availability

CPARS

Rating

CPARS

Rating

23 Backup Success Rate. Reporting Period Backup Success Rate Average (Mean).

99.5% COR review and validation of vendor SLA outputs detailing backup success rate

CPARS

Rating

CPARS

Rating

24 Disaster Recovery Planning, Testing, and Auditing. Percentage of stakeholders requiring Disaster Recovery documentation (e.g., Security Authorization artifacts) that have the following: 1) a complete documented DR plan updated annually, 2) initial and annual successful system recovery tests performed.

100% COR review and validation of vendor SLA outputs detailing DR documentation for related Task Orders

CPARS

Rating

CPARS

Rating

25 Security Management: Security Intrusion Detection. Percentage of Contractor managed Intrusion Detection System (IDS) sensors that successfully generate an alert during the reporting period.

100% COR review and validation of vendor SLA outputs detailing Intrusion Detection System (IDS) sensor data

CPARS

Rating

CPARS

Rating

26 Security Management: Intrusion Reporting and Compliance. Percentage of “significant”, Level 1 and Level 2, Security Incidents reported immediately (i.e. within 30 minutes) to System Owner and organizational stakeholders for the measured reporting period.

100% COR review and validation of vendor SLA outputs detailing incident reporting

CPARS

Rating

CPARS

Rating

27 Security Management: Access Termination.

All physical/logical access removal administrative actions and notifications shall be submitted within 6 business days of employee termination.

However, if employee is terminated within 3 business days of closing month, Contractor security management personnel have until the 3rd day of following month to meet the SLA.

100% COR review and validation of 11000-25 submittals and vendor SLA outputs detailing access termination

CPARS

Rating

28 Security Management: Vulnerability Scan Compliance. Percentage of Level 2 systems having no “moderate or above” vulnerabilities or are within the published “Comply Date” (if no Comply Date provided, default is 30 days).

99.00% COR review and validation of vendor SLA outputs detailing vulnerability scan compliance

CPARS

Rating

CPARS

Rating

29 Security Management: Security Authorization Compliance: Percentage of systems, applications and services for which the Contractor provides Security Authorization (SA) artifacts to ensure the SA package is up-to-date (i.e. ATO has not expired).

Percentage of current, up-to-date SA packages for systems where the supplier is responsible for the SA packages and artifacts.

100% COR review and validation of vendor SLA outputs detailing Security Authorization Compliance

CPARS

Rating

CPARS

Rating

30 Security Management: Virus Protection Management Compliance. Percentage of Contractor supported devices with current anti-virus signatures.

100% COR review and validation of vendor SLA outputs detailing antivirus signatures and virus protection compliance

CPARS

Rating

CPARS

Rating

31 Security Management: Information Security Awareness Training Compliance. Percentage of Contractor employees having received DHS Security Authorization Training for the measured reporting period. Percentage of Contractor employees supporting the HCE Task Order having documentation demonstrating completion of Information Security Awareness Training for the measured reporting period.

100% COR review and validation of vendor SLA outputs detailing employee security training

CPARS

Rating

CPARS

Rating

32 IaaS: Service Availability. Percentage of IaaS availability in the reporting period.

99.9% COR review and validation of vendor SLA outputs detailing IaaS availability

CPARS

Rating

CPARS

Rating

33 IaaS: Service Provisioning Time. Elapsed time taken to provision each virtual machine with the basic operating system.

8.0 Hours COR review and validation of

vendor SLA outputs detailing IaaS VM provisioning time

CPARS

Rating

CPARS

Rating

34 IaaS: Service De-Provisioning and De- Commissioning Time. Elapsed time required to de-provision or de-commission each server.

8.0 hours COR review and validation of vendor SLA outputs detailing IaaS VM de-commissioning time

CPARS

Rating

35 Security Integrity – Successful System Scans Compliance.

Assesses the ability of the vendor to conduct successful system Vulnerability and Antivirus scans.

Measures the number of successful system Antivirus and Authenticated and non-authenticated Vulnerability scans conducted during the reporting period compared to the total number of appliances, applications, devices, environments, solutions, or servers subject to each scan.

99.9% COR review and validation of vendor SLA outputs detailing vulnerability and antivirus scan compliance

CPARS

Rating

CPARS

Rating

36 Remediation – Vulnerabilities mitigated or remediated within 30 days.

99.5% COR review and validation of vendor SLA outputs detailing vulnerability mitigation

CPARS

Rating

CPARS

Rating

37 Network Services: Availability of the HCE Network Infrastructure – The aggregated availability of HCE network infrastructure during the reporting period.

99.9% COR review and validation of vendor SLA outputs detailing HCE network infrastructure availability

CPARS

Rating

Ratings

The Vendor’s SLA measurement outputs will be used to determine if performance exceeds, meets, or does not meet the expectations of the DHS. The Vendor’s overall success rate in meeting the determined AQLs will have significance in completion of the Vendor’s annual CPARS rating.

Documenting Performance

The Government shall document performance using the CPARS.

When exemplary or unacceptable performance occurs, the COR shall inform the contractor, verbally and or in writing. The COR may document the discussion and place it in the COR file.

When performance unacceptable, conflicting with requirements of the contract, the COR will prepare a Contract Discrepancy Report (CDR) and present it to the contractor's program manager and or on-site representative. A CDR template is attached to this QASP. The CDR and any other documentation (including but not limited to letters to the file) will document deficient Contractor performance and specify any determined need for corrective actions.

The contractor shall acknowledge receipt in writing. If the Contractor is required to prepare a corrective action plan to document how the contractor shall correct the unacceptable performance and avoid a recurrence, the COR will specify how long after receipt the contractor has to present this corrective action plan to the COR.

The Government shall review the contractor's corrective action plan to determine acceptability.

CDRs and any other related documentation detailing exemplary or unacceptable performance may become a part of the supporting documentation for contract quarterly incentive/disincentive allocations, or other contractual actions deemed necessary by the CO.

CPARS Ratings

Rating Definition Note

(a) Exceptional

Performance meets contractual requirements and exceeds many to the Government’s benefit. The contractual performance of the element or sub-element being evaluated was accomplished with few minor problems for which corrective actions taken by the contractor were highly effective.

To justify an Exceptional rating, identify multiple significant events and state how they were of benefit to the Government. A singular benefit, however, could be of such magnitude that it alone constitutes an Exceptional rating. Also, there should have been NO significant weaknesses identified.

(b) Very Good Performance meets contractual requirements and exceeds some to the Government’s benefit. The contractual performance of the element or sub-element being evaluated was accomplished with some minor problems for which corrective actions taken by the contractor were effective.

To justify a Very Good rating, identify a significant event and state how it was a benefit to the Government. There should have been no significant weaknesses identified.

(c) Satisfactory

Performance meets contractual requirements. The contractual performance of the element or sub-element contains some minor problems for which corrective actions taken by the contractor appear or were satisfactory.

To justify a Satisfactory rating, there should have been only minor problems, or major problems the contractor recovered from without impact to the contract/order. There should have been NO significant weaknesses identified. A fundamental principle of assigning ratings is that contractors will not be evaluated with a rating lower than Satisfactory solely for not performing beyond the requirements of the contract/order.

(d) Marginal Performance does not meet some contractual requirements. The contractual performance of the element or sub-element being evaluated reflects a serious problem for which the contractor has not yet identified corrective actions. The contractor’s proposed actions appear only

To justify Marginal performance, identify a significant event in each category that the contractor had trouble overcoming and state how it impacted the Government. A Marginal rating should be supported by referencing the management tool that notified the contractor of the contractual deficiency (e.g., Rating Definition Note marginally effective or were not fully implemented.

management, quality, safety, or environmental deficiency report or letter).

(e) Unsatisfactory

Performance does not meet most contractual requirements and recovery is not likely in a timely manner. The contractual performance of the element or sub-element contains a serious problem(s) for which the contractor’s corrective actions appear or were ineffective.

To justify an Unsatisfactory rating, identify multiple significant events in each category that the contractor had trouble overcoming and state how it impacted the Government. A singular problem, however, could be of such serious magnitude that it alone constitutes an unsatisfactory rating. An Unsatisfactory rating should be supported by referencing the management tools used to notify the contractor of the contractual deficiencies (e.g., management, quality, safety, or environmental deficiency reports, or letters).

CONTRACT DISCREPANCY REPORT (CDR)

1. Contract Number: <insert number>

2. TO: (Contractor Program Manager, Task Manager or on-site representative) <insert name>

3. FROM: (Name of COR) <insert name>

4. Date and time observed discrepancy:

5. DISCREPANCY OR PROBLEM:

<Describe in detail. Identify any attachments.>

6. Corrective action plan:

A written corrective action plan < is / is not > required.

< If a written corrective action plan is required include the following. > The written Corrective Action Plan will be provided to the undersigned not later than < # days after receipt of this

CDR. >

Prepared by: <Enter COR’s name>

Contracting Officer’s Representative Date

Received by:

Contractor Program Manager, Task Manager or Date on-site representative

< The COR may initiate a CDR at any time, including whenever the number of monthly recorded defects for a performance standard exceeds the allowable number of defects;

anytime unacceptable performance is determined critical in nature and requires formal corrective action; and whenever an unfavorable trend is detected in contractor performance.>

FOR OFFICIAL USE ONLY

File details come from the government source that posted it. Updated .