Attachment J-3 QASP.pdf
PDF 318 KB Posted
- Attached to
- Department of Homeland Security (DHS) Data Center and Cloud Optimization (DCCO) Support Services Federal contract opportunity
- Solicitation number
- 70RTAC21R00000006
About this file
This document contains a Quality Assurance Surveillance Plan (QASP) for the Department of Homeland Security (DHS) Data Center and Cloud Optimization (DCCO) Support Services contract. The QASP outlines 32 performance objectives for the contractor such as service desk response times, incident resolution times, system availability metrics, and security compliance standards. It describes methods for monitoring performance including direct observation, management reports, inspections, and user complaints. The QASP also defines performance ratings, incentive structures, and processes for documenting performance in the Contractor Performance Assessment Reporting System. It is intended to guide the evaluation of the contractor's work under the DCCO Support Services contract number 70RTAC21R00000006.
View the file
Other files for this federal contract opportunity
Show all 19
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
70RTAC21R00000006 Page 1 of 17 Attachment J-3 QASP
ATTACHMENT J-3
QUALITY ASSURANCE SURVEILLANCE PLAN (QASP)
U.S. Department of Homeland Security
Data Center and Cloud Optimization (DCCO) Support Services
Contract Number: TBD Contractor’s name: TBD (hereafter referred to as the Contractor)
70RTAC21R00000006 Page 2 of 17
INTRODUCTION
This Quality Assurance Surveillance Plan (QASP) is pursuant to the requirements listed in the Data Center and Cloud Optimization (DCCO) Performance Work Statement (PWS) (Attachment J-2). This plan sets the procedures and guidelines the Department of Homeland Security (DHS) Office of the Chief Information Officer (OCIO) will use in ensuring the required performance standards or services levels are achieved by the Contractor. Other work required under this contract may be monitored and other contractual remedies taken by the Government as needed.
The subject QASP will be utilized by the Government to monitor performance at the Indefinite Delivery-Indefinite Quantity (IDIQ) contract level and by DHS Components at the Task Order level.
EXECUTIVE SUMMARY
This QASP provides a systematic method to evaluate performance for the stated contract and explains the following:
• What will be monitored?
• How monitoring will take place?
• Who will conduct the monitoring?
• How monitoring efforts and results will be documented?
This QASP does not detail how the Contractor will accomplish the work. Rather, the QASP is created with the premise that the Contractor is responsible for management and quality control actions necessary to meet the terms of the contract. It is the Government’s responsibility to be objective, fair, and consistent in evaluating performance. In addition, the QASP recognizes that unforeseen and uncontrollable situations may occur.
This QASP is a “living document” and the Government may review and revise it on a regular basis. However, the Government will coordinate changes with the Contractor. Updates shall ensure that the QASP remains a valid, useful, and enforceable document. Copies of the original QASP and revisions shall be provided to the Contractor and Government officials implementing surveillance activities.
The following FAR clauses may apply depending on contract type:
37.6 Performance-Based Acquisition
46.4 Government Contract Quality Assurance
52.246-4 Inspection of Services – Fixed-Price, 52.246-6 Inspection of Services – Time-and-Material and Labor-Hour
PURPOSE
This QASP describes the procedures the DHS will use to monitor and evaluate the Contractor’s performance.
The primary concern of DHS is with the determined quality of the services provided by the Contractor.
Therefore, the QASP focuses on the Government’s measure of the Contractor’s performance on service level agreements (SLAs). It is intended that the QASP be a tool to guide the Contracting Officer’s Representative (COR) in assessing Contractor performance. In some cases, specific metrics will be used to measure Contractor performance; in other cases, subjective judgment and evaluation by DHS/OCIO personnel will be the determining criteria. This plan describes the methodology utilized to conduct both quantitative and qualitative evaluation of Contractor performance under the contract.
70RTAC21R00000006 Page 3 of 17
The QASP provides a means for evaluating whether the Contractor is meeting the performance standards/quality levels identified in the PWS
QUALITY MANAGEMENT STRATEGY
The Contractor is responsible for the quality and consistency of all services provided. The Contractor measures that quality through execution of its own Quality Management Plan. DHS will regularly review quality of delivered services through surveillance of performance of the requirements stated in the DCCO Performance Work Statement, Service Level Agreement (SLA) performance, reviews of deliverables, and reviews of stated operational practices.
The contractor SLA performance will generally be monitored on a monthly basis. The COR and designates will surveille stated monthly performance metrics, the trends, and report any discrepancies in findings.
The Contractor PM shall participate in quarterly “self-assessments “with the COR and associated PM designates. Quarterly performance reviews will be conducted informally and act as a “progress report” on the annual assessment of Contractor performance. Quarterly assessments will detail adherence to the submitted Quality Management Plan (QMP) deliverable and performance in stated Contractor Performance Assessment Reporting System (CPARS) categories.
The COR will enter annual performance assessments in the CPARS system that encompass monthly SLA performance metric analysis, details of Contractor performance and support, and a qualitative review of performance that encompasses quarterly assessments of performance.
The COR will monitor performance and review deliverables furnished by the Contractor to determine how the Contractor is performing against communicated performance objectives of the QMP. The COR will surveille determinations regarding incentives and disincentives based on the QASP and notify the Contractor of findings. The Contractor will be responsible for making adjustments to SLA performance levels, incentives, disincentives and deliverables as necessary, based on COR review. DHS on-site representatives will monitor and report to the COR on Contractor practices, adherence to industry standards, performance, and support.
QASP RELATION TO THE QUALITY MANAGEMENT PLAN
The Contractor’s QMP is a formal contract deliverable. The DHS expects the implementation of the Contractor’s QMP requirements will be sufficient in meeting the performance details of the PWS. While the QMP represents the way the Contractor will pursue quality and timeliness of services, as defined in the PWS, the QASP represents the way the DHS will evaluate the Contractor’s performance. The Contractor’s QMP and the QASP should be complementary and ultimately ensure successful Contractor performance.
REVISIONS TO THE QASP
The QASP will be used in DHS’s administration of the contract and remains subject to revision at any time by the Government throughout the contract performance period. Revisions to this surveillance plan are the responsibility of the Contracting Officer (CO) or designee with support, input, and coordination with the DHS program designees. An initial revision encompassing surveillance details related to the Contractor’s submitted QMP may be made within 60 days of the initial QMP submission. While the Contractor may be engaged, determinations of necessary revisions or changes may be made unilaterally at the discretion of the Government.
70RTAC21R00000006 Page 4 of 17
As the performance period progresses, surveillance may be altered as determined necessary to improve performance in specific areas. DHS may also alter surveillance as key priority changes are made by DHS, OCIO or associated program management offices (PMO)s.
ROLES AND RESPONSIBILITIES
As the purpose of QASP is to ensure that the Government receives satisfactory services and that the Contractor is meeting contractual requirements, the roles and responsibilities of the Contractor and Government involved in the QASP are described below.
CONTRACTOR ROLES AND RESPONSIBILITIES
The Contractor is responsible for delivering acceptable service levels, as detailed in the QASP and per industry standards for any actions and activities not covered in the QASP. The Contractor is responsible for implementing its QMP, which is a contract deliverable. The QMP describes the Contractor’s methods for ensuring all services provided under the contract meet established performance standards. The Contractor is responsible for producing, maintaining, and providing for audit, quality assurance/control records and reports and all records associated with the investigation and resolution of COR-identified performance issues.
Program Manager (PM) – The PM is responsible for all Contractor work performed under the contract and as stated in the PWS. The PM shall meet with the COR and PMO designates regularly. The PM shall participate in quarterly performance reviews and engage Contractor staff as appropriate. The PM is responsible for Quality Management. Quality Management includes providing appropriate visibility as to the quality of work products and the maintenance of standards, processes, and procedures at the program and project level across the HCE Enterprise.
The following employees of the Contractor serve as the Contractor’s representatives for this contract:
a. Program Manager: <upon award, enter name> Telephone: <enter number> Email: <enter address>
b. Other Contractor Personnel: Upon award, enter the following lines for each additional individual.
Delete these lines if not applicable:
<enter title>: <upon award, enter name> Telephone: <enter number> Email: <enter address>
GOVERNMENT ROLES AND RESPONSIBILITIES
The Government is responsible for clear communication of established DHS initiatives, standards for performance, and acceptance of deliverables. The Government also shall revise the QASP to surveille in concert with stated QMP practices.
Contracting Officer (CO) - The CO shall ensure performance of all necessary actions for effective contracting, ensure compliance with the contract terms, and shall safeguard the interests of DHS regarding the contractual relationship. The CO shall also assure that the Contractor receives impartial, fair, and equitable treatment under this contract. The CO is ultimately responsible for the final determination of the adequacy of the Contractor’s performance.
70RTAC21R00000006 Page 5 of 17
Contracting Officer’s Representative (COR) - The COR is responsible for technical administration of the contract and shall assure proper Government surveillance of the Contractor’s performance. The COR shall revise the QASP to meet the specifics of the submitted QMP and also keep a quality assurance file including (but not limited to) monthly SLA results, quarterly quality review details and annual CPARS. At the conclusion of the contract or when requested by the CO, the COR shall provide documentation to the CO.
The COR is not empowered to make any contractual commitments or to authorize any contractual changes on the Government’s behalf. The Contractor shall refer any changes they deem may affect contract price, terms, or conditions to the CO for action.
Government Program Manager – The Government Program Manager shall meet regularly with the COR and Contractor PM to keep open communication of customer and executive feedback and keep the Contractor PM abreast of DHS OCIO and PMO initiatives. The Government Program Manager may engage PMO designates and Government Service Owners as necessary to participate in related meetings.
The following Government personnel represent the Government for this contract:
Assigned CO: <enter name> Organization or Agency: <enter Organization or Agency Name> Telephone: <enter telephone number> Email: <enter email address>
Assigned COR: <enter name> Organization or Agency: <enter Organization or Agency Name> Telephone: <enter telephone number> Email: <enter email address>
Assigned Program Manager: <enter name> Organization or Agency: <enter Organization or Agency Name> Telephone: <enter telephone number> Email: <enter email address>
PERFORMANCE STANDARDS
Performance standards define desired services. The Government performs surveillance to determine if the Contractor exceeds, meets or does not meet these standards.
The Performance Work Statement (PWS) (Attachment J-2) and the QASP include performance standards and other applicable contract requirements. The Government shall use these standards to assess Contractor performance and shall compare Contractor performance to the Acceptable Quality Levels (AQL) for each Performance Objective.
INCENTIVES
The Government shall use incentives and disincentives for the Enterprise SLAs. Incentives or disincentives shall be based on exceeding, meeting, or not meeting performance standards. Information about incentives can be found in the QASP.
METHODS OF QUALITY ASSURANCE SURVEILLANCE
Various methods exist to monitor performance. The COR may use the surveillance methods listed below in the administration of this QASP. Final determination of methods of surveillance will be determined upon review of the Contractor’s QMP deliverable.
70RTAC21R00000006 Page 6 of 17
a) Direct Observation – (Can be performed periodically or through 100% surveillance by the COR and or designates.)
- Performance Standard: All performance standards listed in the QASP and other applicable contract requirements.
b) Management Information Systems (MIS). (Evaluate outputs through the use of monthly contract deliverable management information reports and other compliance output from other entities.)
- Performance Standard: All SLAs listed in the QASP and other applicable contract requirements.
c) Periodic Inspection. (Uses a comprehensive evaluation of selected outputs. Inspections may be scheduled [daily, weekly, monthly, quarterly, or annually] or unscheduled, as required.)
d) Validated User/Customer complaints. (Relies on the user of the service to identify deficiencies.
Complaints are then investigated and validated.)
e) Random Sampling. (Designed to evaluate the outputs of the award requirement by randomly selecting and inspecting a statistically significant sample, such as sanitization service of level 1 hardware.)
f) Periodic Sampling. (Variation of random sampling. However, sample is only taken when a deficiency is suspected. May be a follow-up to MIS analysis. Sample results are applicable only for the specific work inspected. Since the sample is not entirely random, it cannot be applied to total activity performance.)
g) Progress or Status Meetings. (Status Meetings include at a minimum a Monthly SLA review and daily status briefing/meetings with key contract personnel, support personnel, and onsite federal representatives; regular Progress Meetings; ad hoc meetings directed by the customer and Contractor that may address the execution of a separate Task Order, tech uplift of supporting equipment, security related matters, and any other topics of concern.)
h) Performance reporting. (Evaluates metrics for a specific time period as listed in the QASP.)
- Performance Standard: All SLAs listed in the QASP and other applicable contract requirements
Surveillance results may be used as the basis for revisions to contract deliverables and to substantiate CPARS review ratings. In such cases, the Inspection of Services clause in the Contract becomes the basis for the CO’s actions.
Table 1 lists the DCCO performance objectives and corresponding acceptable quality levels (AQLs)
70RTAC21R00000006 Page 7 of 17
Table 1: Performance Requirements Summary: Performance Objectives and Acceptable Quality Levels
Service Output
Performance Objective Acceptable Quality Level
(AQL)
Method of Inspection Positive Incentive
Negative Incentive
1 Service Desk: Speed to Answer. Speed to answer Service Desk calls in 45 seconds or less.
95% COR review and validation of Contractor SLA outputs derived from daily automated report is issued by
NASA/NCCIPS
CPARS
Rating
CPARS
Rating
2 Service Desk: Speed to Respond to Communications. Speed to respond to contacts through identified communication channels other than telephone (currently email) in 1 elapsed hour or less.
95% COR review and validation of Contractor SLA outputs
CPARS
Rating
CPARS
Rating
3 Customer Satisfaction Rating. Overall measure of the Net Promoter Score (NPS) measured monthly is greater than or equal to 30. Service Satisfaction rated as “Very Satisfied” or “Extremely satisfied” measured quarterly.
NPS≥30 COR review of NPS documentation (50% weight)
CPARS
Rating
CPARS
Rating
94% of responses rating 8.0 or better on a survey scale of 1 to 10.
94% COR review of Contractor provided SLA outputs from an industry-recognized survey tool (Medallia or equivalent) (50% weight)
CPARS
Rating
CPARS
Rating
4 Root cause determination. The percentage of Severity 1 and Severity 2 Incidents for which Root Cause Analysis (RCA) has been completed and submitted within 72 hours of Incident occurrence.
95% COR Review of noted incident start time and RCA submission time
CPARS
Rating
CPARS
Rating
70RTAC21R00000006 Page 8 of 17
5 Incident Management Resolution Time (Severity 1, 2, and 3). Elapsed time to resolve incidents for Severity 1, 2, and 3 incidents occurring during a reporting period measured in continuous elapsed time from the time of incident occurrence - not in business hours.
Severity 1 - 4 Clock Hours (240 Minutes); Severity 2 - 8 Clock Hours (480 minutes); Severity 3 - 12 Clock Hours (720 minutes)
99.5% per Severity Level
COR review of Contractor provided SLA outputs detailing intendent duration
CPARS
Rating
CPARS
Rating
6 Incident Management: Time for DHS System Owner to be notified when non-security incident is found. Target elapsed time for System Owner and designated stakeholder notification for Severity 1 and 2 incidents is 30 minutes or less; notification time for Severity 3 incidents is 8 hours for a reporting period.
95% COR review of Contractor provided SLA outputs detailing total number of incidents and notification times
CPARS
Rating
CPARS
Rating
7 Incident Management: Status Update Frequency.
Incident tickets for Priority Level 1 and Level 2 incidents are to be updated at least hourly. Priority Level 3 incidents are to be updated every 8 hours.
All other incident tickets shall be updated at least daily. Measurement is for all tickets during a reporting period.
99.5% per Priority Level
COR review of Contractor provided SLA outputs detailing update frequency and COR observed update percentages for Severity 1,2&3 incidents
CPARS
Rating
CPARS
Rating
8 Service Asset and Configuration Management:
Percentage of CMDB Inventoried Annually - Accuracy of Level 1 and 2 Systems. Percentage of Level 1 and 2 Systems found to have accurate information in the CMDB measured annually with an error rate less than or equal to 2%.
98% Annual COR review of monthly Contractor generated, Fed validated SLA outputs detailing CMDB accuracy
CPARS
Rating
CPARS
Rating
9 Service Asset and Configuration Management:
Percentage of CMDB Accuracy of Level 1 and 2 Systems. Percentage of Level 1 and 2 systems found to have accurate information in the CMDB in a reporting period. Validation is based on a 25% minimum progressive sample of the baseline inventory measured monthly to ensure a 100%
98% Monthly COR review of Contractor generated, Fed (on site when possible) validated SLA outputs detailing CMDB accuracy
CPARS
Rating
70RTAC21R00000006 Page 9 of 17 audit over four months with less than 2% error rate.
10 Service Asset and Configuration Management:
Percentage of Contractor provided and/or managed physical and virtual assets and cloud services inventoried. Validation that at least 10.00% of baseline inventory of physical and virtual assets and cloud services within the HCE was progressively audited during a monthly reporting period to ensure a 100% validation over 10 months with an error rate not to exceed 0.5%.
99.5% Monthly COR review of Contractor generated, Fed (on site when possible) validated SLA outputs detailing HCE inventory
CPARS
Rating
CPARS
Rating
11 Change Management: Percentage of Successfully Implemented Changes - Level 1 and 2. Percentage of Changes authored and primarily executed by the Contractor for Level 1 and 2 supported systems in data centers, colocation facilities, and cloud environments that did not result in an incident or fault and with no negative impacts to operational stability.
99.5% COR review and validation of Contractor SLA outputs detailing percentage of closed change tickets
CPARS
Rating
CPARS
Rating
12 Change Management: Percentage of Changes Resulting in an Incident. Percentage of Incidents per reporting period that were the result of Changes authored and/or primarily executed by the Contractor.
≤3% COR review and validation of Contractor SLA outputs detailing incidents causes by changes
CPARS
Rating
CPARS
Rating
13 Change Management: Percentage of Emergency Changes. Percentage of Contractor initiated non-security changes that were flagged as “Emergency” compared to all other rendered changes.
≤10% COR review and validation of Contractor SLA outputs detailing percentage of emergency changes
CPARS
Rating
CPARS
Rating
14 Capacity Management: DHS CPU Utilization.
Percentage of CPU Utilization for Contractor provided and/or managed Level 2 systems or applications. (average [mean] percentage for each system and application).
≤70% COR review and validation of Contractor SLA outputs detailing CPU utilization
CPARS
Rating
70RTAC21R00000006 Page 10 of 17
15 Capacity Management: DHS Disk Utilization.
Percentage of System Disk Utilization - Level 2 systems. Average (mean) Percentage of disk Utilization for Contractor-provided and/or Level 2 systems.
≤70% COR review and validation of Contractor SLA outputs detailing disk utilization
CPARS
Rating
CPARS
Rating
16 Capacity Management: DHS SAN Utilization.
Percentage of SAN Utilization - Level 2 Systems.
Average (Mean) Percentage of SAN Utilization of Contractor-provided and/or managed Level 2 Systems.
≤70% COR review and validation of Contractor SLA outputs detailing SAN utilization
CPARS
Rating
CPARS
Rating
17 Capacity Management: DHS Network Bandwidth Utilization. Percentage of LAN bandwidth utilization of Contractor provided and/or managed DHS HCE Network Infrastructure. - Reporting Period Average (Mean) Percentage of Network Utilization of Contractor provided and/or managed DHS HCE infrastructure (enterprise).
≤70% COR review and validation of Contractor SLA outputs detailing HCE network bandwidth utilization
CPARS
Rating
CPARS
Rating
18 Capacity Management: HCE CSP Compute Resource Utilization. Average Percentage Utilization of CSP-Resources provided by the Contractor during the reporting period (average (mean) percentage) does not exceed the AQL.
≤85% COR review and validation of Contractor SLA outputs detailing CSP compute resource utilization
CPARS
Rating
CPARS
Rating
19 Capacity Management: HCE CSP Storage Resource Utilization. Average Percentage of Storage Resource Utilization for CSP storage resources provided by the Contractor during the reporting period does not exceed the stated AQL.
≤85% COR review and validation of Contractor SLA outputs detailing CSP storage resource utilization
CPARS
Rating
CPARS
Rating
20 Capacity Management: HCE CSP Database Resource Utilization. Percentage of Database Resource Utilization - Level 2 Systems. Average (Mean) Percentage of Database Resource Utilization of Contractor- provided and/or managed Level 2 Systems.
≤85% COR review and validation of Contractor SLA outputs detailing CSP database resource utilization
CPARS
Rating
70RTAC21R00000006 Page 11 of 17
21 Availability Management. Percentage of System Availability. Percentage of availability per reporting period for Contractor-provided and/or managed Level 1 and 2 systems, including cloud services. Reporting Period Average (mean) percentage of System availability for Contractor-provided Level 1 and 2 Systems, including cloud services.
99.9% COR review and validation of Contractor SLA outputs detailing System Availability
CPARS
Rating
CPARS
Rating
22 Availability Management: Percentage of LAN Availability. Percentage of availability per reporting period for Contractor-provided and/or managed LAN services. Reporting period average (mean) percentage of LAN availability.
99.9% COR review and validation of Contractor SLA outputs detailing percentage of LAN availability
CPARS
Rating
CPARS
Rating
23 Backup Success Rate. Reporting Period Backup Success Rate Average (mean).
99.5% COR review and validation of Contractor SLA outputs detailing backup success rate
CPARS
Rating
CPARS
Rating
24 Disaster Recovery Planning, Testing, and Auditing. Percentage of completed Disaster Recovery documentation (e.g., Security Authorization artifacts) and/or support for stakeholders that have the following: 1) a complete documented DR plan updated annually, 2) initial and annual successful system recovery tests performed.
100% COR review and validation of Contractor SLA outputs detailing DR documentation for related Task Orders
CPARS
Rating
CPARS
Rating
25 Security Management: Security Intrusion Detection. Percentage of Contractor managed Intrusion Detection System (IDS) sensors that successfully generate an alert for events during the reporting period.
100% COR review and validation of Contractor SLA outputs detailing Intrusion Detection System (IDS) sensor data
CPARS
Rating
CPARS
Rating
26 Security Management: Intrusion Reporting and Compliance. Percentage of “significant” Level 1 and Level 2 Security Incidents reported immediately (i.e., within 30 minutes) to System Owner and organizational stakeholders for the measured reporting period.
100% COR review and validation of Contractor SLA outputs detailing incident reporting
CPARS
Rating
70RTAC21R00000006 Page 12 of 17
27 Security Management: Access Termination. All physical/logical access removal administrative actions and notifications shall be submitted within 6 business days of employee termination. However, if employee is terminated within 3 business days of closing month, Contractor security management personnel have until the 3rd day of following month to meet the SLA.
100% COR review and validation of 11000-25 submittals and Contractor SLA outputs detailing access termination
CPARS
Rating
CPARS
Rating
28 Security Management: Vulnerability Scan Compliance. Percentage of Level 2 systems having no “moderate or above” vulnerabilities or are within the published “Comply Date” (if no Comply Date provided, default is 30 days), or have approved DHS mitigation.
99.00% COR review and validation of Contractor SLA outputs detailing vulnerability scan compliance
CPARS
Rating
CPARS
Rating
29 Security Management: Security Authorization Compliance: Percentage of systems, applications and services for which the Contractor provides Security Authorization (SA) artifacts to ensure the SA package is up to date (i.e., ATO has not expired). Percentage of current, up-to-date SA packages for systems where the supplier is responsible for the SA packages and artifacts.
100% COR review and validation of Contractor SLA outputs detailing Security Authorization Compliance
CPARS
Rating
CPARS
Rating
30 Security Management: Virus Protection Management Compliance. Percentage of Contractor supported systems or applications with current anti-virus signatures.
100% COR review and validation of Contractor SLA outputs detailing antivirus signatures and virus protection compliance
CPARS
Rating
CPARS
Rating
31 Security Management: Information Security Awareness Training Compliance. Percentage of Contractor employees having received DHS Security Authorization Training for the measured reporting period. Percentage of Contractor employees supporting the HCE Task Order having documentation demonstrating completion of
100% COR review and validation of Contractor SLA outputs detailing employee security training
CPARS
Rating
70RTAC21R00000006 Page 13 of 17
Information Security Awareness Training for the measured reporting period.
32 IaaS: Service Availability. Percentage of IaaS availability in the reporting period.
99.9% COR review and validation of Contractor SLA outputs detailing IaaS availability
CPARS
Rating
CPARS
Rating
33 IaaS: Service Provisioning Time. Elapsed time taken to provision each virtual machine with the basic operating system.
8.0 Hours COR review and validation of
Contractor SLA outputs detailing IaaS VM provisioning time
CPARS
Rating
CPARS
Rating
34 IaaS: Service De-Provisioning and De- Commissioning Time. Elapsed time required to de-provision or de-commission each instance
(VM).
8.0 hours COR review and validation of Contractor SLA outputs detailing IaaS VM de-commissioning time
CPARS
Rating
CPARS
Rating
35 Security Integrity - Successful System Scans Compliance.
Assesses the ability of the Contractor to conduct successful system Vulnerability and Antivirus scans.
Measures the number of successful system Antivirus and Authenticated and non-authenticated Vulnerability scans conducted during the reporting period compared to the total number of appliances, applications, devices, environments, solutions, or servers subject to each scan.
99.9% COR review and validation of Contractor SLA outputs detailing vulnerability and antivirus scan compliance
CPARS
Rating
CPARS
Rating
36 Remediation - Vulnerabilities mitigated or remediated within 30 days.
99.5% COR review and validation of Contractor SLA outputs detailing vulnerability mitigation
CPARS
Rating
CPARS
Rating
37 Network Services: Availability of the HCE Network Infrastructure - The aggregated availability of HCE network infrastructure during the reporting period.
99.9% COR review and validation of Contractor SLA outputs detailing HCE network infrastructure availability
CPARS
Rating
70RTAC21R00000006 Page 14 of 17
RATINGS
The Contractor’s SLA measurement outputs will be used to determine if performance exceeds, meets, or does not meet the expectations of the DHS. The Contractor’s overall success rate in meeting the determined AQLs will have significance in completion of the Contractor’s annual CPARS rating.
DOCUMENTING PERFORMANCE
The Government shall document performance using CPARS.
When exemplary or unacceptable performance occurs, the COR shall inform the Contractor, verbally and or in writing. The COR may document the discussion and place it in the COR file.
When unacceptable performance occurs, conflicting with requirements of the contract, the COR will prepare a Contract Discrepancy Report (CDR) and present it to the Contractor's program manager and or on-site representative. A CDR template is attached to this QASP. The CDR and any other documentation (including but not limited to letters to the file) will document deficient Contractor performance and specify any determined need for corrective actions.
The Contractor shall acknowledge receipt in writing. If the Contractor is required to prepare a corrective action plan to document how the Contractor shall correct the unacceptable performance and avoid a recurrence, the COR will specify how long after receipt the Contractor has to present this corrective action plan to the COR. The Government shall review the Contractor's corrective action plan to determine acceptability.
CDRs and any other related documentation detailing exemplary or unacceptable performance may become a part of the supporting documentation for contract quarterly incentive/disincentive allocations, or other contractual actions deemed necessary by the CO.
70RTAC21R00000006 Page 15 of 17
Table 2. CPARS Ratings
Rating Definition Notes
(a) Exceptional
Performance meets contractual requirements and exceeds many to the Government’s benefit. The contractual performance of the element or sub-element being evaluated was accomplished with few minor problems for which corrective actions taken by the Contractor were highly effective.
To justify an Exceptional rating, identify multiple significant events and state how they were of benefit to the Government. A singular benefit, however, could be of such magnitude that it alone constitutes an Exceptional rating. Also, there should have been NO significant weaknesses identified.
(b) Very Good Performance meets contractual requirements and exceeds some to the Government’s benefit. The contractual performance of the element or sub-element being evaluated was accomplished with some minor problems for which corrective actions taken by the Contractor were effective.
To justify a Very Good rating, identify a significant event and state how it was a benefit to the Government. There should have been no significant weaknesses identified.
(c) Satisfactory
Performance meets contractual requirements. The contractual performance of the element or sub-element contains some minor problems for which corrective actions taken by the Contractor appear or were satisfactory.
To justify a Satisfactory rating, there should have been only minor problems, or major problems the Contractor recovered from without impact to the contract/order. There should have been NO significant weaknesses identified. A fundamental principle of assigning ratings is that contractors will not be evaluated with a rating lower than Satisfactory solely for not performing beyond the requirements of the contract/order.
(d) Marginal Performance does not meet some contractual requirements. The contractual performance of the element or sub-element being evaluated reflects a serious problem for which the Contractor has not yet identified corrective actions. The Contractor’s proposed actions appear only marginally effective or were not fully implemented.
To justify Marginal performance, identify a significant event in each category that the Contractor had trouble overcoming and state how it impacted the Government. A Marginal rating should be supported by referencing the management tool that notified the Contractor of the contractual deficiency (e.g., management, quality, safety, or environmental deficiency report or letter).
70RTAC21R00000006 Page 16 of 17
Rating Definition Notes
(e) Unsatisfactory
Performance does not meet most contractual requirements and recovery is not likely in a timely manner. The contractual performance of the element or sub-element contains a serious problem(s) for which the Contractor’s corrective actions appear or were ineffective.
To justify an Unsatisfactory rating, identify multiple significant events in each category that the Contractor had trouble overcoming and state how it impacted the Government. A singular problem, however, could be of such serious magnitude that it alone constitutes an unsatisfactory rating. An Unsatisfactory rating should be supported by referencing the management tools used to notify the Contractor of the contractual deficiencies (e.g., management, quality, safety, or environmental deficiency reports, or letters).
70RTAC21R00000006 Page 17 of 17
CONTRACT DISCREPANCY REPORT (CDR)
1. Contract Number: <insert number>
2. TO: (Contractor Program Manager, Task Manager or on-site representative) <insert name>
3. FROM: COR <insert name of COR>
4. DATE AND TIME DISCREPANCY OBSERVED: <insert date and time>
5. DISCREPANCY OR PROBLEM:
<Describe in detail. Identify any attachments.>
6. Corrective action plan:
A written corrective action plan < is / is not > required.
< If a written corrective action plan is required include the following. > The written Corrective Action Plan will be provided to the undersigned not later than < # days after receipt of this
CDR. >
Prepared by: <Enter COR’s name>
Contracting Officer’s Representative Date
Received by:
Contractor Program Manager, Task Manager or Date on-site representative
< The COR may initiate a CDR at any time, including whenever the number of monthly recorded defects for a performance standard exceeds the allowable number of defects;
anytime unacceptable performance is determined critical in nature and requires formal corrective action; and whenever an unfavorable trend is detected in Contractor performance.>
FOR OFFICIAL USE ONLY
| Introduction |
| Executive Summary |
| Purpose |
| Quality Management Strategy |
| QASP Relation to the Quality Management Plan |
| Revisions to the QASP |
| Roles and Responsibilities |
| Contractor Roles and Responsibilities |
| Government Roles and Responsibilities |
| Performance Standards |
| Incentives |
| Methods of Quality Assurance Surveillance |
| Ratings |
| Documenting Performance |
File details come from the government source that posted it. Updated .