Attachment 5 - ITSLCM Framework.pdf

PDF 254 KB Posted

Attached to
LEGACY PIMS ACTUARIAL and IT SUPPORT SERVICES Federal contract opportunity
Solicitation number
16PBGC25R0056
Issued by
Pension Benefit Guaranty Corporation

About this file

The document is an IT Solutions Lifecycle Management (ITSLCM) Framework diagram that details the comprehensive process for managing IT solutions from initial concept through operations and disposition. The framework is organized into four main stages: Need/Concept, Planning, Execution (Development, Modernization, Enhancement and Maintenance), and Operations and Disposition, with specific roles, deliverables, and governance checkpoints for each stage.

Key elements include iterative processes involving multiple stakeholders such as the Business Program Manager, IT Program Manager, Integrated Program Team, Contracting Officer, and various technical and security roles. The framework outlines critical activities like Business Needs Analysis, Alternatives Analysis, IT Program Planning, Requirements Development, Design, Testing, Security and Privacy Compliance (RMF Process), Implementation, and Continuous Monitoring. The diagram includes multiple governance review points like IT Portfolio Registration Review (ITPRB), Change Advisory Board (CAB), and Technology Review Board (TRB) to ensure strategic alignment, risk management, and quality control throughout the IT solution lifecycle.

View the file

Other files for this federal contract opportunity

Show all 15

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

Test Plan, Test Scripts & Test Results [D]

Review & Update

Iteratively

ShareIT

• Execute operations activities (IT Prj Mgr, infrastructure, and application teams)

Business Needs Analysis (S)

Alternatives Analysis (S)

Build/Update IT Program Plan with IPgT:

o Identify IPgT and define Roles and Responsibilities o Identify recommendations from BNA to address business and IT gaps, including system replacements oDetermine strategic alignment oConduct Alternatives Analysis and Cost Benefit Analysis oDevelop Independent Government Cost Estimate (IGCE), including impacts to other programs oDevelop Acquisition Strategy oDevelop Risk, Issue, Quality, Configuration, Communication Plans and Matrices oDefine program reporting/oversight oPrioritize program requirements and program schedule with IPgT stakeholders

• Finalize IT Program Plan Reflect IGCE in departmental budget formulation/request

BUSINESS PROGRAM MANAGER

IT PROGRAM MANAGER

INTEGRATED PROGRAM TEAM (IPgT)

CHIEF ENTERPRISE ARCHITECT (CEA)

RELEASE MANAGER

CONTRACTING OFFICER

INFORMATION SYSTEM SECURITY MANAGER

BUSINESS OWNER/SPONSOR

STEERING/OVERSIGHT COMMITTEE

Need/Concept Planning Execution (Development, Modernization, Enhancement and Maintenance)

Operations and Disposition

Perform monitoring and reporting (i.e., provide updates to IT Program Plan)

ShareIT

• RM/A Submits Disposition RFC

Required RMF Deliverables

Disposition Review

Update IT Program Plan with authority to close out program and/or dispose of IT solution

Close out program

Execute according to the IT Program Plan

Maintain IT Program Plan

Note: Information in IT Program Plan will be used for Semi‐Annual Program Review oPerform program monitoring and reporting including cost and schedule performance using earned value (EV)

Select development approach

Develop Cost Loaded Project Schedule

Conduct Product and Technology Recommendation

Develop high level design from high level requirements, including integration with other systems, and submit for CAB review

Refine IGCE

Develop Business Implementation Strategy Document (Large Projects)

IT Project Manager develops high level project plan (w/Business Project Manager)

COR completes IT Acquisition Checklist

Requirements Document (S) Design (S) Development (S) Enterprise Data (S)

• Requester reviews GetIT, Technical Reference Model (TRM), and mAppIT, or contact CEA at AskEA@pbgc.gov

• CEA reviews enterprise program solutions to determine resolution:

o EXISTING Solution: Requester submits GetIT Request for Existing Solution o ENHANCE EXISTING Solution: Requester takes Modification Requirements to existing solution program manager;

Business Program Manager (BPM) queues for Change Control Boards (CCBs) Prioritization o New Business Need: CEA schedules Business Needs Analysis (BNA) (w/ BPM Sponsor); Sponsor and CEA fund and secure resources necessary to conduct the BNA; conduct BNA.

Cybersecurity and Privacy Catalog (S) RMF Process (G) System of Records Notice (SORN) Guide (G)

Privacy Impact Assessment (PIA) Guide (G) Interconnection Security Agreement (ISA) (G)

Execute selected

Development Approach

Establish Program CCB

Update IT Program Plan with results of product selection and refined IGCE

Portfolio Manager evaluate prioritize IT Portfolio (w/Program Manager)

BPIT Budget Recommendation;

Portfolio Manager submit 53 & 300s

Software Services (S) Implementation & Training Plan (S) Lessons Learned Document (S) Testing Guidance (G)*

Stabilize the solution

Grant access to users

Set up service desk support

Transition to Operations

Execute Implementation Strategy and Training Plan

Document Lessons Learned and Project Closeout

Change Management

Configuration Management

Configuration Management

Configuration ManagementIT Service/Incident/Problem Management

IT Service/Incident/Problem Management

Budget Formulation & ExecutionIT Risk Management

Review Risk Management Framework (RMF) process to determine the list of required security and privacy activities, deliverables, and reviews

Complete required security and privacy deliverables

Review RMF process to determine the list of required security and privacy activities, deliverables, and reviews

Complete required security and privacy deliverables

Continuous Monitoring Continuous Monitoring

ATO

(Go Live)

IT Risk Management

IT Risk Management

IT Risk Management

Cybersecurity and Privacy Catalog (S)

RMF Process (G)

PIA Guide (G)

Change Management

Release and Deployment Management

Requirements Document [D]

Design [D]

Lessons Learned Document [D]

Acquisition

Acquisition

IT Portfolio Registration Presentation [D] Business Need Analysis Document [D]

Alternatives Analysis [D]

IT Program Plan [D]

Business Need Analysis Document [D]

Alternatives Analysis [D]

IT Program Plan [D]

Program Performance Reports [D]

Cost Loaded Project Schedule [D]

Alternatives Analysis [D]

Security and Privacy Authorization Package [D]

Pr og ra m M an ag em en t

Pr oj ec t &

T ec hn ol og y M an ag em en t

Cy be rs ec ur ity a nd

P riv ac y

BUSINESS PROJECT MANAGER

IT PROJECT MANAGER

INTEGRATED PROJECT TEAM (IPT)

CONTRACTING OFFICER’S REPRESENTATIVE

(COR)

ENTERPRISE ARCHITECT REPRESENTATIVE

IMPACTED PROJECT MANAGERS

RELEASE MANAGER/ANALYST (RM/A)

INFORMATION SYSTEM SECURITY OFFICER

Alternatives Analysis (S)

Cybersecurity and Privacy Catalog (S)

RMF Process (G)

User Manual [D]

Implementation & Training Plan [D]

Release and Deployment Management Ex te rn al

Pr oc es se s

Update & Maintain Iteratively

• Bus Program Manager performs Operational Analysis (OA) on System Posture

Review & Update

Iteratively

Review RMF process to determine the list of required security and privacy activities, deliverables, and reviews

Complete required security and privacy deliverables

• COR executes Acquisition Plan

• Bus Prj Mgr develops

Implementation & Training Plan

• IT Prj Mgr Execute Plan

• Analyze & Document Requirements

• Develop & Refine (if needed)

Design Specifications

• Manage/Monitor/Report Project

Scope, Cost, Schedule, Risks, Quality, etc.

• ShareIT (SharePoint Site):

• Dev environment needs, i.e., Service Request (Dev Team)

• Dev and Test environment set up

(RM/A Team)

• Start Deployment/Installation

Guide (Dev Team)

• RM/A 1st CAB (if needed)

ITPRB

(IT Portfolio

Registration Review)

IT Program (Authorization)

ITPRB

(Prioritize Review)

ITPRB

(Semi‐Annual Program Review)

ITPRB

(Annual OA)

ITPRB

(Disposition Review)

Requirements (Technology

Solution Review)

CAB

(Production/COOP Deployment Review)

TRB

(Design Review)

TRB

(Product Review)

1st CAB ITPRB (Quarterly Project

Review)

Production Readiness Validation

Design (Technology

Solution Review)

ITSLCM Framework v3.0 – Updated January 2019

INFORMATION SYSTEM OWNER/INFORMATION OWNER

INFORMATION SYSTEM SECURITY OFFICER/

INFORMATION SYSTEM SECURITY MANAGER

AUTHORIZING OFFICIAL

CHIEF INFORMATION SECURITY OFFICER (CISO)

SENIOR AGENCY OFFICIAL FOR PRIVACY (SAOP)

CHIEF PRIVACY OFFICER (CPO)

INDEPENDENT ASSESSOR

Business Needs Analysis (S)

Alternatives Analysis (S)

Deployment/Installation Guidance (G)* Solution Environment Guidance (G)*

Go/No‐Go Governance Gate Review Gov. Review

IPT Review Roles Deliverables [D]

IT Standards (S) & Guidance (G) Le ge nd

IT Program Plan [D]

Post‐Assessment Controls Review

Ongoing Authorization Review

Disposition Process Review

Required RMF Deliverables Required RMF Deliverables

Deployment/Installation Guide [D]

Solution Environment Plan [D]

Operations Guide [D]

• IT Prj Mgr

• Decide if Design Review is needed o Yes – Go to TRB Design Review Gate o No – Execute Plan (Pre‐Deployment)

• Develop/Configure Solution

• Conduct Testing

• ShareIT

• Document Production Ops/Maintenance Needs in

Operations Guide

• Complete Deployment/Installation Guide

• RM/A Submit RFC (For Deployment)

• Deploy Solution

• Bus Prj Mgr Execute Implementation & Training Plan

• IT Prj Mgr Execute Plan (Post‐Deployment)

Enterprise Continuous Monitoring (ECM) Plan (G)

Information System Continuous Monitoring (ISCM) Plan (G)

*Found in the OIT ITSLCM Supplemental Guide

Acquisition

File details come from the government source that posted it. Updated .