About this file

This document contains a Quality Assurance Surveillance Plan (QASP) for the Department of Homeland Security (DHS) Data Center and Cloud Optimization (DCCO) Support Services contract. The QASP outlines 32 performance objectives for the contractor such as service desk response times, incident resolution times, system availability metrics, and security compliance standards. It describes methods for monitoring performance including direct observation, management reports, inspections, and user complaints. The QASP also defines performance ratings, incentive structures, and processes for documenting performance in the Contractor Performance Assessment Reporting System. It is intended to guide the evaluation of the contractor's work under the DCCO Support Services contract number 70RTAC21R00000006.

View the file

Other files for this federal contract opportunity

Show all 19

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

70RTAC21R00000006 Page 1 of 17 Attachment J-3 QASP

ATTACHMENT J-3

QUALITY ASSURANCE SURVEILLANCE PLAN (QASP)

U.S. Department of Homeland Security

Data Center and Cloud Optimization (DCCO) Support Services

Contract Number: TBD Contractor’s name: TBD (hereafter referred to as the Contractor)

70RTAC21R00000006 Page 2 of 17

INTRODUCTION

This Quality Assurance Surveillance Plan (QASP) is pursuant to the requirements listed in the Data Center and Cloud Optimization (DCCO) Performance Work Statement (PWS) (Attachment J-2). This plan sets the procedures and guidelines the Department of Homeland Security (DHS) Office of the Chief Information Officer (OCIO) will use in ensuring the required performance standards or services levels are achieved by the Contractor. Other work required under this contract may be monitored and other contractual remedies taken by the Government as needed.

The subject QASP will be utilized by the Government to monitor performance at the Indefinite Delivery-Indefinite Quantity (IDIQ) contract level and by DHS Components at the Task Order level.

EXECUTIVE SUMMARY

This QASP provides a systematic method to evaluate performance for the stated contract and explains the following:

• What will be monitored?

• How monitoring will take place?

• Who will conduct the monitoring?

• How monitoring efforts and results will be documented?

This QASP does not detail how the Contractor will accomplish the work. Rather, the QASP is created with the premise that the Contractor is responsible for management and quality control actions necessary to meet the terms of the contract. It is the Government’s responsibility to be objective, fair, and consistent in evaluating performance. In addition, the QASP recognizes that unforeseen and uncontrollable situations may occur.

This QASP is a “living document” and the Government may review and revise it on a regular basis. However, the Government will coordinate changes with the Contractor. Updates shall ensure that the QASP remains a valid, useful, and enforceable document. Copies of the original QASP and revisions shall be provided to the Contractor and Government officials implementing surveillance activities.

The following FAR clauses may apply depending on contract type:

37.6 Performance-Based Acquisition

46.4 Government Contract Quality Assurance

52.246-4 Inspection of Services – Fixed-Price, 52.246-6 Inspection of Services – Time-and-Material and Labor-Hour

PURPOSE

This QASP describes the procedures the DHS will use to monitor and evaluate the Contractor’s performance.

The primary concern of DHS is with the determined quality of the services provided by the Contractor.

Therefore, the QASP focuses on the Government’s measure of the Contractor’s performance on service level agreements (SLAs). It is intended that the QASP be a tool to guide the Contracting Officer’s Representative (COR) in assessing Contractor performance. In some cases, specific metrics will be used to measure Contractor performance; in other cases, subjective judgment and evaluation by DHS/OCIO personnel will be the determining criteria. This plan describes the methodology utilized to conduct both quantitative and qualitative evaluation of Contractor performance under the contract.

70RTAC21R00000006 Page 3 of 17

The QASP provides a means for evaluating whether the Contractor is meeting the performance standards/quality levels identified in the PWS

QUALITY MANAGEMENT STRATEGY

The Contractor is responsible for the quality and consistency of all services provided. The Contractor measures that quality through execution of its own Quality Management Plan. DHS will regularly review quality of delivered services through surveillance of performance of the requirements stated in the DCCO Performance Work Statement, Service Level Agreement (SLA) performance, reviews of deliverables, and reviews of stated operational practices.

The contractor SLA performance will generally be monitored on a monthly basis. The COR and designates will surveille stated monthly performance metrics, the trends, and report any discrepancies in findings.

The Contractor PM shall participate in quarterly “self-assessments “with the COR and associated PM designates. Quarterly performance reviews will be conducted informally and act as a “progress report” on the annual assessment of Contractor performance. Quarterly assessments will detail adherence to the submitted Quality Management Plan (QMP) deliverable and performance in stated Contractor Performance Assessment Reporting System (CPARS) categories.

The COR will enter annual performance assessments in the CPARS system that encompass monthly SLA performance metric analysis, details of Contractor performance and support, and a qualitative review of performance that encompasses quarterly assessments of performance.

The COR will monitor performance and review deliverables furnished by the Contractor to determine how the Contractor is performing against communicated performance objectives of the QMP. The COR will surveille determinations regarding incentives and disincentives based on the QASP and notify the Contractor of findings. The Contractor will be responsible for making adjustments to SLA performance levels, incentives, disincentives and deliverables as necessary, based on COR review. DHS on-site representatives will monitor and report to the COR on Contractor practices, adherence to industry standards, performance, and support.

QASP RELATION TO THE QUALITY MANAGEMENT PLAN

The Contractor’s QMP is a formal contract deliverable. The DHS expects the implementation of the Contractor’s QMP requirements will be sufficient in meeting the performance details of the PWS. While the QMP represents the way the Contractor will pursue quality and timeliness of services, as defined in the PWS, the QASP represents the way the DHS will evaluate the Contractor’s performance. The Contractor’s QMP and the QASP should be complementary and ultimately ensure successful Contractor performance.

REVISIONS TO THE QASP

The QASP will be used in DHS’s administration of the contract and remains subject to revision at any time by the Government throughout the contract performance period. Revisions to this surveillance plan are the responsibility of the Contracting Officer (CO) or designee with support, input, and coordination with the DHS program designees. An initial revision encompassing surveillance details related to the Contractor’s submitted QMP may be made within 60 days of the initial QMP submission. While the Contractor may be engaged, determinations of necessary revisions or changes may be made unilaterally at the discretion of the Government.

70RTAC21R00000006 Page 4 of 17

As the performance period progresses, surveillance may be altered as determined necessary to improve performance in specific areas. DHS may also alter surveillance as key priority changes are made by DHS, OCIO or associated program management offices (PMO)s.

ROLES AND RESPONSIBILITIES

As the purpose of QASP is to ensure that the Government receives satisfactory services and that the Contractor is meeting contractual requirements, the roles and responsibilities of the Contractor and Government involved in the QASP are described below.

CONTRACTOR ROLES AND RESPONSIBILITIES

The Contractor is responsible for delivering acceptable service levels, as detailed in the QASP and per industry standards for any actions and activities not covered in the QASP. The Contractor is responsible for implementing its QMP, which is a contract deliverable. The QMP describes the Contractor’s methods for ensuring all services provided under the contract meet established performance standards. The Contractor is responsible for producing, maintaining, and providing for audit, quality assurance/control records and reports and all records associated with the investigation and resolution of COR-identified performance issues.

Program Manager (PM) – The PM is responsible for all Contractor work performed under the contract and as stated in the PWS. The PM shall meet with the COR and PMO designates regularly. The PM shall participate in quarterly performance reviews and engage Contractor staff as appropriate. The PM is responsible for Quality Management. Quality Management includes providing appropriate visibility as to the quality of work products and the maintenance of standards, processes, and procedures at the program and project level across the HCE Enterprise.

The following employees of the Contractor serve as the Contractor’s representatives for this contract:

a. Program Manager: <upon award, enter name> Telephone: <enter number> Email: <enter address>

b. Other Contractor Personnel: Upon award, enter the following lines for each additional individual.

Delete these lines if not applicable:

<enter title>: <upon award, enter name> Telephone: <enter number> Email: <enter address>

GOVERNMENT ROLES AND RESPONSIBILITIES

The Government is responsible for clear communication of established DHS initiatives, standards for performance, and acceptance of deliverables. The Government also shall revise the QASP to surveille in concert with stated QMP practices.

Contracting Officer (CO) - The CO shall ensure performance of all necessary actions for effective contracting, ensure compliance with the contract terms, and shall safeguard the interests of DHS regarding the contractual relationship. The CO shall also assure that the Contractor receives impartial, fair, and equitable treatment under this contract. The CO is ultimately responsible for the final determination of the adequacy of the Contractor’s performance.

70RTAC21R00000006 Page 5 of 17

Contracting Officer’s Representative (COR) - The COR is responsible for technical administration of the contract and shall assure proper Government surveillance of the Contractor’s performance. The COR shall revise the QASP to meet the specifics of the submitted QMP and also keep a quality assurance file including (but not limited to) monthly SLA results, quarterly quality review details and annual CPARS. At the conclusion of the contract or when requested by the CO, the COR shall provide documentation to the CO.

The COR is not empowered to make any contractual commitments or to authorize any contractual changes on the Government’s behalf. The Contractor shall refer any changes they deem may affect contract price, terms, or conditions to the CO for action.

Government Program Manager – The Government Program Manager shall meet regularly with the COR and Contractor PM to keep open communication of customer and executive feedback and keep the Contractor PM abreast of DHS OCIO and PMO initiatives. The Government Program Manager may engage PMO designates and Government Service Owners as necessary to participate in related meetings.

The following Government personnel represent the Government for this contract:

Assigned CO: <enter name> Organization or Agency: <enter Organization or Agency Name> Telephone: <enter telephone number> Email: <enter email address>

Assigned COR: <enter name> Organization or Agency: <enter Organization or Agency Name> Telephone: <enter telephone number> Email: <enter email address>

Assigned Program Manager: <enter name> Organization or Agency: <enter Organization or Agency Name> Telephone: <enter telephone number> Email: <enter email address>

PERFORMANCE STANDARDS

Performance standards define desired services. The Government performs surveillance to determine if the Contractor exceeds, meets or does not meet these standards.

The Performance Work Statement (PWS) (Attachment J-2) and the QASP include performance standards and other applicable contract requirements. The Government shall use these standards to assess Contractor performance and shall compare Contractor performance to the Acceptable Quality Levels (AQL) for each Performance Objective.

INCENTIVES

The Government shall use incentives and disincentives for the Enterprise SLAs. Incentives or disincentives shall be based on exceeding, meeting, or not meeting performance standards. Information about incentives can be found in the QASP.

METHODS OF QUALITY ASSURANCE SURVEILLANCE

Various methods exist to monitor performance. The COR may use the surveillance methods listed below in the administration of this QASP. Final determination of methods of surveillance will be determined upon review of the Contractor’s QMP deliverable.

70RTAC21R00000006 Page 6 of 17

a) Direct Observation – (Can be performed periodically or through 100% surveillance by the COR and or designates.)

- Performance Standard: All performance standards listed in the QASP and other applicable contract requirements.

b) Management Information Systems (MIS). (Evaluate outputs through the use of monthly contract deliverable management information reports and other compliance output from other entities.)

- Performance Standard: All SLAs listed in the QASP and other applicable contract requirements.

c) Periodic Inspection. (Uses a comprehensive evaluation of selected outputs. Inspections may be scheduled [daily, weekly, monthly, quarterly, or annually] or unscheduled, as required.)

d) Validated User/Customer complaints. (Relies on the user of the service to identify deficiencies.

Complaints are then investigated and validated.)

e) Random Sampling. (Designed to evaluate the outputs of the award requirement by randomly selecting and inspecting a statistically significant sample, such as sanitization service of level 1 hardware.)

f) Periodic Sampling. (Variation of random sampling. However, sample is only taken when a deficiency is suspected. May be a follow-up to MIS analysis. Sample results are applicable only for the specific work inspected. Since the sample is not entirely random, it cannot be applied to total activity performance.)

g) Progress or Status Meetings. (Status Meetings include at a minimum a Monthly SLA review and daily status briefing/meetings with key contract personnel, support personnel, and onsite federal representatives; regular Progress Meetings; ad hoc meetings directed by the customer and Contractor that may address the execution of a separate Task Order, tech uplift of supporting equipment, security related matters, and any other topics of concern.)

h) Performance reporting. (Evaluates metrics for a specific time period as listed in the QASP.)

- Performance Standard: All SLAs listed in the QASP and other applicable contract requirements

Surveillance results may be used as the basis for revisions to contract deliverables and to substantiate CPARS review ratings. In such cases, the Inspection of Services clause in the Contract becomes the basis for the CO’s actions.

Table 1 lists the DCCO performance objectives and corresponding acceptable quality levels (AQLs)

70RTAC21R00000006 Page 7 of 17

Table 1: Performance Requirements Summary: Performance Objectives and Acceptable Quality Levels

Service Output

Performance Objective Acceptable Quality Level

(AQL)

Method of Inspection Positive Incentive

Negative Incentive

1 Service Desk: Speed to Answer. Speed to answer Service Desk calls in 45 seconds or less.

95% COR review and validation of Contractor SLA outputs derived from daily automated report is issued by

NASA/NCCIPS

CPARS

Rating

CPARS

Rating

2 Service Desk: Speed to Respond to Communications. Speed to respond to contacts through identified communication channels other than telephone (currently email) in 1 elapsed hour or less.

95% COR review and validation of Contractor SLA outputs

CPARS

Rating

CPARS

Rating

3 Customer Satisfaction Rating. Overall measure of the Net Promoter Score (NPS) measured monthly is greater than or equal to 30. Service Satisfaction rated as “Very Satisfied” or “Extremely satisfied” measured quarterly.

NPS≥30 COR review of NPS documentation (50% weight)

CPARS

Rating

CPARS

Rating

94% of responses rating 8.0 or better on a survey scale of 1 to 10.

94% COR review of Contractor provided SLA outputs from an industry-recognized survey tool (Medallia or equivalent) (50% weight)

CPARS

Rating

CPARS

Rating

4 Root cause determination. The percentage of Severity 1 and Severity 2 Incidents for which Root Cause Analysis (RCA) has been completed and submitted within 72 hours of Incident occurrence.

95% COR Review of noted incident start time and RCA submission time

CPARS

Rating

CPARS

Rating

70RTAC21R00000006 Page 8 of 17

5 Incident Management Resolution Time (Severity 1, 2, and 3). Elapsed time to resolve incidents for Severity 1, 2, and 3 incidents occurring during a reporting period measured in continuous elapsed time from the time of incident occurrence - not in business hours.

Severity 1 - 4 Clock Hours (240 Minutes); Severity 2 - 8 Clock Hours (480 minutes); Severity 3 - 12 Clock Hours (720 minutes)

99.5% per Severity Level

COR review of Contractor provided SLA outputs detailing intendent duration

CPARS

Rating

CPARS

Rating

6 Incident Management: Time for DHS System Owner to be notified when non-security incident is found. Target elapsed time for System Owner and designated stakeholder notification for Severity 1 and 2 incidents is 30 minutes or less; notification time for Severity 3 incidents is 8 hours for a reporting period.

95% COR review of Contractor provided SLA outputs detailing total number of incidents and notification times

CPARS

Rating

CPARS

Rating

7 Incident Management: Status Update Frequency.

Incident tickets for Priority Level 1 and Level 2 incidents are to be updated at least hourly. Priority Level 3 incidents are to be updated every 8 hours.

All other incident tickets shall be updated at least daily. Measurement is for all tickets during a reporting period.

99.5% per Priority Level

COR review of Contractor provided SLA outputs detailing update frequency and COR observed update percentages for Severity 1,2&3 incidents

CPARS

Rating

CPARS

Rating

8 Service Asset and Configuration Management:

Percentage of CMDB Inventoried Annually - Accuracy of Level 1 and 2 Systems. Percentage of Level 1 and 2 Systems found to have accurate information in the CMDB measured annually with an error rate less than or equal to 2%.

98% Annual COR review of monthly Contractor generated, Fed validated SLA outputs detailing CMDB accuracy

CPARS

Rating

CPARS

Rating

9 Service Asset and Configuration Management:

Percentage of CMDB Accuracy of Level 1 and 2 Systems. Percentage of Level 1 and 2 systems found to have accurate information in the CMDB in a reporting period. Validation is based on a 25% minimum progressive sample of the baseline inventory measured monthly to ensure a 100%

98% Monthly COR review of Contractor generated, Fed (on site when possible) validated SLA outputs detailing CMDB accuracy

CPARS

Rating

70RTAC21R00000006 Page 9 of 17 audit over four months with less than 2% error rate.

10 Service Asset and Configuration Management:

Percentage of Contractor provided and/or managed physical and virtual assets and cloud services inventoried. Validation that at least 10.00% of baseline inventory of physical and virtual assets and cloud services within the HCE was progressively audited during a monthly reporting period to ensure a 100% validation over 10 months with an error rate not to exceed 0.5%.

99.5% Monthly COR review of Contractor generated, Fed (on site when possible) validated SLA outputs detailing HCE inventory

CPARS

Rating

CPARS

Rating

11 Change Management: Percentage of Successfully Implemented Changes - Level 1 and 2. Percentage of Changes authored and primarily executed by the Contractor for Level 1 and 2 supported systems in data centers, colocation facilities, and cloud environments that did not result in an incident or fault and with no negative impacts to operational stability.

99.5% COR review and validation of Contractor SLA outputs detailing percentage of closed change tickets

CPARS

Rating

CPARS

Rating

12 Change Management: Percentage of Changes Resulting in an Incident. Percentage of Incidents per reporting period that were the result of Changes authored and/or primarily executed by the Contractor.

≤3% COR review and validation of Contractor SLA outputs detailing incidents causes by changes

CPARS

Rating

CPARS

Rating

13 Change Management: Percentage of Emergency Changes. Percentage of Contractor initiated non-security changes that were flagged as “Emergency” compared to all other rendered changes.

≤10% COR review and validation of Contractor SLA outputs detailing percentage of emergency changes

CPARS

Rating

CPARS

Rating

14 Capacity Management: DHS CPU Utilization.

Percentage of CPU Utilization for Contractor provided and/or managed Level 2 systems or applications. (average [mean] percentage for each system and application).

≤70% COR review and validation of Contractor SLA outputs detailing CPU utilization

CPARS

Rating

70RTAC21R00000006 Page 10 of 17

15 Capacity Management: DHS Disk Utilization.

Percentage of System Disk Utilization - Level 2 systems. Average (mean) Percentage of disk Utilization for Contractor-provided and/or Level 2 systems.

≤70% COR review and validation of Contractor SLA outputs detailing disk utilization

CPARS

Rating

CPARS

Rating

16 Capacity Management: DHS SAN Utilization.

Percentage of SAN Utilization - Level 2 Systems.

Average (Mean) Percentage of SAN Utilization of Contractor-provided and/or managed Level 2 Systems.

≤70% COR review and validation of Contractor SLA outputs detailing SAN utilization

CPARS

Rating

CPARS

Rating

17 Capacity Management: DHS Network Bandwidth Utilization. Percentage of LAN bandwidth utilization of Contractor provided and/or managed DHS HCE Network Infrastructure. - Reporting Period Average (Mean) Percentage of Network Utilization of Contractor provided and/or managed DHS HCE infrastructure (enterprise).

≤70% COR review and validation of Contractor SLA outputs detailing HCE network bandwidth utilization

CPARS

Rating

CPARS

Rating

18 Capacity Management: HCE CSP Compute Resource Utilization. Average Percentage Utilization of CSP-Resources provided by the Contractor during the reporting period (average (mean) percentage) does not exceed the AQL.

≤85% COR review and validation of Contractor SLA outputs detailing CSP compute resource utilization

CPARS

Rating

CPARS

Rating

19 Capacity Management: HCE CSP Storage Resource Utilization. Average Percentage of Storage Resource Utilization for CSP storage resources provided by the Contractor during the reporting period does not exceed the stated AQL.

≤85% COR review and validation of Contractor SLA outputs detailing CSP storage resource utilization

CPARS

Rating

CPARS

Rating

20 Capacity Management: HCE CSP Database Resource Utilization. Percentage of Database Resource Utilization - Level 2 Systems. Average (Mean) Percentage of Database Resource Utilization of Contractor- provided and/or managed Level 2 Systems.

≤85% COR review and validation of Contractor SLA outputs detailing CSP database resource utilization

CPARS

Rating

70RTAC21R00000006 Page 11 of 17

21 Availability Management. Percentage of System Availability. Percentage of availability per reporting period for Contractor-provided and/or managed Level 1 and 2 systems, including cloud services. Reporting Period Average (mean) percentage of System availability for Contractor-provided Level 1 and 2 Systems, including cloud services.

99.9% COR review and validation of Contractor SLA outputs detailing System Availability

CPARS

Rating

CPARS

Rating

22 Availability Management: Percentage of LAN Availability. Percentage of availability per reporting period for Contractor-provided and/or managed LAN services. Reporting period average (mean) percentage of LAN availability.

99.9% COR review and validation of Contractor SLA outputs detailing percentage of LAN availability

CPARS

Rating

CPARS

Rating

23 Backup Success Rate. Reporting Period Backup Success Rate Average (mean).

99.5% COR review and validation of Contractor SLA outputs detailing backup success rate

CPARS

Rating

CPARS

Rating

24 Disaster Recovery Planning, Testing, and Auditing. Percentage of completed Disaster Recovery documentation (e.g., Security Authorization artifacts) and/or support for stakeholders that have the following: 1) a complete documented DR plan updated annually, 2) initial and annual successful system recovery tests performed.

100% COR review and validation of Contractor SLA outputs detailing DR documentation for related Task Orders

CPARS

Rating

CPARS

Rating

25 Security Management: Security Intrusion Detection. Percentage of Contractor managed Intrusion Detection System (IDS) sensors that successfully generate an alert for events during the reporting period.

100% COR review and validation of Contractor SLA outputs detailing Intrusion Detection System (IDS) sensor data

CPARS

Rating

CPARS

Rating

26 Security Management: Intrusion Reporting and Compliance. Percentage of “significant” Level 1 and Level 2 Security Incidents reported immediately (i.e., within 30 minutes) to System Owner and organizational stakeholders for the measured reporting period.

100% COR review and validation of Contractor SLA outputs detailing incident reporting

CPARS

Rating

70RTAC21R00000006 Page 12 of 17

27 Security Management: Access Termination. All physical/logical access removal administrative actions and notifications shall be submitted within 6 business days of employee termination. However, if employee is terminated within 3 business days of closing month, Contractor security management personnel have until the 3rd day of following month to meet the SLA.

100% COR review and validation of 11000-25 submittals and Contractor SLA outputs detailing access termination

CPARS

Rating

CPARS

Rating

28 Security Management: Vulnerability Scan Compliance. Percentage of Level 2 systems having no “moderate or above” vulnerabilities or are within the published “Comply Date” (if no Comply Date provided, default is 30 days), or have approved DHS mitigation.

99.00% COR review and validation of Contractor SLA outputs detailing vulnerability scan compliance

CPARS

Rating

CPARS

Rating

29 Security Management: Security Authorization Compliance: Percentage of systems, applications and services for which the Contractor provides Security Authorization (SA) artifacts to ensure the SA package is up to date (i.e., ATO has not expired). Percentage of current, up-to-date SA packages for systems where the supplier is responsible for the SA packages and artifacts.

100% COR review and validation of Contractor SLA outputs detailing Security Authorization Compliance

CPARS

Rating

CPARS

Rating

30 Security Management: Virus Protection Management Compliance. Percentage of Contractor supported systems or applications with current anti-virus signatures.

100% COR review and validation of Contractor SLA outputs detailing antivirus signatures and virus protection compliance

CPARS

Rating

CPARS

Rating

31 Security Management: Information Security Awareness Training Compliance. Percentage of Contractor employees having received DHS Security Authorization Training for the measured reporting period. Percentage of Contractor employees supporting the HCE Task Order having documentation demonstrating completion of

100% COR review and validation of Contractor SLA outputs detailing employee security training

CPARS

Rating

70RTAC21R00000006 Page 13 of 17

Information Security Awareness Training for the measured reporting period.

32 IaaS: Service Availability. Percentage of IaaS availability in the reporting period.

99.9% COR review and validation of Contractor SLA outputs detailing IaaS availability

CPARS

Rating

CPARS

Rating

33 IaaS: Service Provisioning Time. Elapsed time taken to provision each virtual machine with the basic operating system.

8.0 Hours COR review and validation of

Contractor SLA outputs detailing IaaS VM provisioning time

CPARS

Rating

CPARS

Rating

34 IaaS: Service De-Provisioning and De- Commissioning Time. Elapsed time required to de-provision or de-commission each instance

(VM).

8.0 hours COR review and validation of Contractor SLA outputs detailing IaaS VM de-commissioning time

CPARS

Rating

CPARS

Rating

35 Security Integrity - Successful System Scans Compliance.

Assesses the ability of the Contractor to conduct successful system Vulnerability and Antivirus scans.

Measures the number of successful system Antivirus and Authenticated and non-authenticated Vulnerability scans conducted during the reporting period compared to the total number of appliances, applications, devices, environments, solutions, or servers subject to each scan.

99.9% COR review and validation of Contractor SLA outputs detailing vulnerability and antivirus scan compliance

CPARS

Rating

CPARS

Rating

36 Remediation - Vulnerabilities mitigated or remediated within 30 days.

99.5% COR review and validation of Contractor SLA outputs detailing vulnerability mitigation

CPARS

Rating

CPARS

Rating

37 Network Services: Availability of the HCE Network Infrastructure - The aggregated availability of HCE network infrastructure during the reporting period.

99.9% COR review and validation of Contractor SLA outputs detailing HCE network infrastructure availability

CPARS

Rating

70RTAC21R00000006 Page 14 of 17

RATINGS

The Contractor’s SLA measurement outputs will be used to determine if performance exceeds, meets, or does not meet the expectations of the DHS. The Contractor’s overall success rate in meeting the determined AQLs will have significance in completion of the Contractor’s annual CPARS rating.

DOCUMENTING PERFORMANCE

The Government shall document performance using CPARS.

When exemplary or unacceptable performance occurs, the COR shall inform the Contractor, verbally and or in writing. The COR may document the discussion and place it in the COR file.

When unacceptable performance occurs, conflicting with requirements of the contract, the COR will prepare a Contract Discrepancy Report (CDR) and present it to the Contractor's program manager and or on-site representative. A CDR template is attached to this QASP. The CDR and any other documentation (including but not limited to letters to the file) will document deficient Contractor performance and specify any determined need for corrective actions.

The Contractor shall acknowledge receipt in writing. If the Contractor is required to prepare a corrective action plan to document how the Contractor shall correct the unacceptable performance and avoid a recurrence, the COR will specify how long after receipt the Contractor has to present this corrective action plan to the COR. The Government shall review the Contractor's corrective action plan to determine acceptability.

CDRs and any other related documentation detailing exemplary or unacceptable performance may become a part of the supporting documentation for contract quarterly incentive/disincentive allocations, or other contractual actions deemed necessary by the CO.

70RTAC21R00000006 Page 15 of 17

Table 2. CPARS Ratings

Rating Definition Notes

(a) Exceptional

Performance meets contractual requirements and exceeds many to the Government’s benefit. The contractual performance of the element or sub-element being evaluated was accomplished with few minor problems for which corrective actions taken by the Contractor were highly effective.

To justify an Exceptional rating, identify multiple significant events and state how they were of benefit to the Government. A singular benefit, however, could be of such magnitude that it alone constitutes an Exceptional rating. Also, there should have been NO significant weaknesses identified.

(b) Very Good Performance meets contractual requirements and exceeds some to the Government’s benefit. The contractual performance of the element or sub-element being evaluated was accomplished with some minor problems for which corrective actions taken by the Contractor were effective.

To justify a Very Good rating, identify a significant event and state how it was a benefit to the Government. There should have been no significant weaknesses identified.

(c) Satisfactory

Performance meets contractual requirements. The contractual performance of the element or sub-element contains some minor problems for which corrective actions taken by the Contractor appear or were satisfactory.

To justify a Satisfactory rating, there should have been only minor problems, or major problems the Contractor recovered from without impact to the contract/order. There should have been NO significant weaknesses identified. A fundamental principle of assigning ratings is that contractors will not be evaluated with a rating lower than Satisfactory solely for not performing beyond the requirements of the contract/order.

(d) Marginal Performance does not meet some contractual requirements. The contractual performance of the element or sub-element being evaluated reflects a serious problem for which the Contractor has not yet identified corrective actions. The Contractor’s proposed actions appear only marginally effective or were not fully implemented.

To justify Marginal performance, identify a significant event in each category that the Contractor had trouble overcoming and state how it impacted the Government. A Marginal rating should be supported by referencing the management tool that notified the Contractor of the contractual deficiency (e.g., management, quality, safety, or environmental deficiency report or letter).

70RTAC21R00000006 Page 16 of 17

Rating Definition Notes

(e) Unsatisfactory

Performance does not meet most contractual requirements and recovery is not likely in a timely manner. The contractual performance of the element or sub-element contains a serious problem(s) for which the Contractor’s corrective actions appear or were ineffective.

To justify an Unsatisfactory rating, identify multiple significant events in each category that the Contractor had trouble overcoming and state how it impacted the Government. A singular problem, however, could be of such serious magnitude that it alone constitutes an unsatisfactory rating. An Unsatisfactory rating should be supported by referencing the management tools used to notify the Contractor of the contractual deficiencies (e.g., management, quality, safety, or environmental deficiency reports, or letters).

70RTAC21R00000006 Page 17 of 17

CONTRACT DISCREPANCY REPORT (CDR)

1. Contract Number: <insert number>

2. TO: (Contractor Program Manager, Task Manager or on-site representative) <insert name>

3. FROM: COR <insert name of COR>

4. DATE AND TIME DISCREPANCY OBSERVED: <insert date and time>

5. DISCREPANCY OR PROBLEM:

<Describe in detail. Identify any attachments.>

6. Corrective action plan:

A written corrective action plan < is / is not > required.

< If a written corrective action plan is required include the following. > The written Corrective Action Plan will be provided to the undersigned not later than < # days after receipt of this

CDR. >

Prepared by: <Enter COR’s name>

Contracting Officer’s Representative Date

Received by:

Contractor Program Manager, Task Manager or Date on-site representative

< The COR may initiate a CDR at any time, including whenever the number of monthly recorded defects for a performance standard exceeds the allowable number of defects;

anytime unacceptable performance is determined critical in nature and requires formal corrective action; and whenever an unfavorable trend is detected in Contractor performance.>

FOR OFFICIAL USE ONLY

Introduction
Executive Summary
Purpose
Quality Management Strategy
QASP Relation to the Quality Management Plan
Revisions to the QASP
Roles and Responsibilities
Contractor Roles and Responsibilities
Government Roles and Responsibilities
Performance Standards
Incentives
Methods of Quality Assurance Surveillance
Ratings
Documenting Performance

File details come from the government source that posted it. Updated .