SDLCM-v2-4.pdf
PDF 3 MB Posted
- Attached to
- OPA Web Services Federal contract opportunity
- Solicitation number
- DOL-OPS-16-R-00036
About this file
SDLCM-v2-4
View the file
Other files for this federal contract opportunity
| File | Type | Posted |
|---|---|---|
| RFP__-_Cover_Letter_Amendment_000002.pdf | ||
| LOE-Document.pdf | ||
| Compiled_Questions_and_Answers_all_(CO_Edits_6_21_16).pdf | ||
| DOL-OPS-16-R-00036_SF_30_Amend_000002.pdf | ||
| DOL-OPS-16-R-00036_AMENDMENT_000001.pdf | ||
| Atch__-_Past_performance_Form.doc | DOC document | |
| RFP__-_Cover_Letter_June_9_2016_Amendment_000001.docx | DOCX document | |
| labor_categories.xls | XLS spreadsheet | |
| SF_1449_DOL-OPS-16-R-00036.pdf | ||
| RFP_DOL-OPS-16-R-00036_W_SOW_Clauses_Provisions.pdf | ||
| RFP__-_cover_letter_rev_DOL-OPS-16-R-00036.pdf |
Show all 11
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
U.S. DEPARTMENT OF LABOR
Office of the Chief Information Officer
System Development Life Cycle Management (SDLCM)
Manual
Version 2.4 July 2014
U.S. Department of Labor, Office of the Chief Information Officer
200 Constitution Avenue, NW, Washington, DC 20210
U.S. Department of Labor SDLCM Version 2.4
Preface
July 2014 i
PREFACE
This document represents Version 2.4 of the Department of Labor’s (DOL) System Development
Life Cycle Management (SDLCM) Manual. The SDLCM Manual was last updated in May 2012.
This version includes the following updates:
The DOL Information Technology (IT) investment life cycle management framework including the Strategic Business Management (SBM) and Capital Planning and
Investment Control (CPIC), IT security life cycles have been removed from this document. This document describes the SDLC management methodology, phases, deliverables, and associated supporting activities. The SBM, CPIC, and IT Security life cycles are still an integral part of DOL’s IT Investment Life Cycle Management framework and DOL IT investment Project Manager’s (PMs) and Integrated Project
Teams are still required to complete these important life cycle management activities.
(For more information, see DOL’s new IT Investment Management Life Cycle (IMLC)
Guide, v1.0, dated July 2014 for a complete and integrated view of DOL’s IT investment management life cycle processes. A copy of the guide can be found in the OCIO
Resource Library on LaborNet under the Investment Management topic area.)
A figure illustrating the seven SDLCM was added to the introduction section.
The DOL IT Governance Model diagram was updated to reflect the requirements associated with OMB’s Digital Government Strategy published in May 2012.
References to the three IT investment threshold levels (i.e., threshold 1, threshold 2, and threshold 3) were replaced with the terms non-Major or Major to be consistent with the
OCIO CPIC Guide and OMB Circular A-11.
References to the “Life Cycle Cost/Benefit (LCC/B) Management” process were removed from the CBA requirements due to agency and OCIO higher priorities.
Renamed “End of phase review” language to “phase gate reviews” to align with industry standard phase/stage gate terminology. In addition, the phase gate review checklists were incorporated into an appendix, i.e., Appendix VII, for reference.
The figures, tables, and exhibits throughout the document were relabeled accordingly to ensure clarity.
The figures in the document were updated to ensure accessibility and compliance with
Section 508 requirements.
The “Document Revision History” in Section 1.3 includes a complete list of changes that have been made to this document since its inception. This document is considered a living document and as such is subject to change. This document will be updated in time, as necessary, to reflect any changes or new information that becomes known or available.
This updated version of the SDLCM Manual takes precedence over prior versions. DOL IT PMs are required to impl ement this version going forward. DOL IT investments are required to follow the life cycle process presented in this manual as well as the DOL IT Investment Management Life Cycle
(IMLC) Guide.
Preface
July 2014 ii
If you have any questions, please contact the OCIO, Room N1301, 200 Constitution Avenue, NW, Washington, DC 20210 or via email at OCIO@dol.gov.
Executive Summary
July 2014 iii
EXECUTIVE SUMMARY
The United States Department of Labor (DOL) invests hundreds of millions of dollars annually on information technology (IT) systems. These IT systems are vital to day-to-day operations of the Department as well as to the overall success of the Department’s mission programs and in achieving the Secretary’s vision. DOL relies on IT systems and advances in technology to ensure a safe, secure, and a dependable method to provide its mission program services, develop products, administer daily activities, and perform short- and long-term management functions.
DOL must continue to ensure data privacy and security when developing and implementing information systems as well as establish uniform privacy and protection practices.
To efficiently and effectively develop, implement, operation and manage the Department’s IT investments, DOL developed this standardized System Development Life Cycle Management
(SDLCM) Manual. This manual serves as the life cycle mechanism to assure developing, modifying, and/or enhancing DOL systems fulfill identified business needs, established customer requirements, and supports DOLs business mission and critical success factors. It sets forth a standard and logical methodology and associated life cycle processes for managing
IT system development activities and approvals that are controlled, measured, documented, and ultimately improved. At the same time, this manual responds to the following current legislation mandating the use of industry standards in the development and management of IT systems:
National Technology Transfer and Advancement Act of 1995
Information Technology Management Reform Act of 1996 – ITMRA (Clinger Cohen
Act)
OMB Circulars (i.e. A-11, A-130, A-94, A-109)
This DOL SDLCM manual is a key component of DOL’s IT Investment Management Life Cycle
(IMLC) Guide, which describes the IT investment life cycle phases and how they are interrelated with the Strategic Business Management, Capital Planning and Investment Control (CPIC), and
IT Security life cycles. Each of these IT life cycles need to be managed in a coordinated fashion to ensure the successful planning, implementation, and ongoing operations and maintenance of
IT systems at DOL. Other related and important IT management functional areas include, but are not limited to, software management, information management, quality management, performance management, records management, and Section 508 accessibility management.
Each of these IT management areas is described in greater detail in the DOL IMLC Guide. The
Department’s IMLC represents a comprehensive integrated approach to IT investment management. A copy of the guide can be found in the OCIO Resource Library on LaborNet under the Investment Management topic area.
This SDLCM manual represents many years of systems development and engineering experience by information systems professionals, including the incorporation of lessons learned from prior implementation versions. The purpose of this manual is to disseminate standardized and proven practices for use throughout DOL. The specific benefits expected include the following:
July 2014 iv
Increased likelihood of system planning, development, implementation, and operational success
Reduced risk of IT system investment failure
Greater IT system monitoring and control integrity, openness, awareness, and management performance accountability
Promotes greater communications between IT system business owners and the technical
Integrated Project Team (IPT) throughout the entire life of the system
Supports enhanced critical business management and IT system management decision making capability
Promotes the early identification and resolution of technical and management issues including avoiding investing in features or functions not benefiting end users or the business owners/stakeholders
Formalizes the IT system planning, acquisition, development, implementation, operation
& maintenance, and the decommissioning processes including the associated incremental management approval process for each milestone and phase
Is consistent with industry standards in the life cycle management of IT systems
Supports disclosure of all life cycle costs to guide business management decision-making
Fosters realistic expectations of what the system will and will not provide, through active user involvement
Provides information enabling consideration of all aspects -- programmatic, technical, management, and cost -- of a proposed system development or modification effort
Provides periodic IT system evaluations to identify systems needing enhancements or are no longer effective and need to be replaced
Measurements of progress and status to enable effective corrective action before proceeding to the next phase
Essential information that supports effective resource management and budget planning.
The Department’s SDLCM divides an IT system's life cycle into seven phases starting with
Conceptual Planning and ending with the Disposition Phase. It describes the inputs, activities and deliverables associated with each phase. Further, it presents guidance on how the approach can be tailored to suit the various types of systems development and maintenance projects that exist within DOL today.
The use of the SDLCM manual applies to all DOL and contractor personnel who are developing, acquiring (i.e. Commercial Off-The-Shelf (COTS)), or managing new systems, including making modifications or enhancements to existing systems. Adherence to the SDLCM by program officials, PMs, IPTs, integrators, system developers, employees, and contractors performing systems work for the Department is crucial to delivering cost effective information systems.
DOL Agencies are responsible for ensuring that the SDLCM methodology and practices described in this SDLCM are implemented accordingly throughout the life cycle of an IT investment. The Chief Information Officer/Office of the Chief Information Officer (CIO/OCIO) is the authority for this SDLCM manual.
On September 27, 2004, the DOL Office of the Assistant Secretary for Administration and
Management (OASAM) issued a memorandum titled “Guidance for the DOL Earned Value
Management System (EVMS) Methodology” which established the requirements and timeline
July 2014 v for submission of earned value data by specific IT investments within the Department of Labor
(DOL), pursuant to directives from the Office of Management and Budget (OMB) and applicable legislation. As a result of this memorandum, Earned Value Management (EVM) has become a mandatory requirement for major DOL IT investments. As such, EVM information and guidance is contained within this SDLCM manual to assist and support IT PM’s in understanding the EVM requirements in the context of the SDLCM. A more detailed explanation of EVM and of the DOL EVM requirements can be found in the DOL EVM Operational Guide which can be found in the DOL OCIO Resource Library on LaborNet under the CPIC subject area. In addition, the DOL OCIO has prepared an EVM Quick Reference Guide which can also be found on LaborNet under the CPIC subject area.
file:///C:/Users/portera-oliver-j/AppData/Local/Microsoft/Windows/Temporary%20Internet%20Files/Content.Outlook/G3H69TZQ/under
U.S. Department of Labor SDLCM Version 2.3.1
July 2014 vi
TABLE OF CONTENTS
PREFACE .................................................................................................................................................................... I
EXECUTIVE SUMMARY ...................................................................................................................................... III
1 INTRODUCTION
1.1 PURPOSE
1.2 DOCUMENT OVERVIEW
1.3 DOCUMENT REVISION HISTORY
1.4 FREQUENTLY ASKED QUESTIONS (FAQ) ABOUT THE SDLCM
1.5 IT SYSTEM ROLES AND RESPONSIBILITIES
1.6 SDLCM WORK PATTERNS AND ASSOCIATED DELIVERABLES
1.7 DELIVERABLE DESCRIPTION BY LIFE CYCLE PHASE
1.8 CAPITAL PLANNING AND INVESTMENT CONTROL (CPIC)
1.9 IT SECURITY
1.10 STRATEGIC BUSINESS MANAGEMENT
1.11 PERFORMANCE MANAGEMENT
1.12 QUALITY ASSURANCE
1.13 INFORMATION QUALITY GUIDELINES
1.14 SOFTWARE LIFE CYCLE MODELS
1.15 WAIVER/EXCEPTION PROCESS
2 CONCEPTUAL PLANNING PHASE
2.1 PHASE 1 OVERVIEW
2.2 PHASE INPUTS
2.3 PHASE ACTIVITIES AND DELIVERABLES
2.4 PHASE CONSIDERATIONS
3 PLANNING & REQUIREMENTS DEFINITION PHASE
3.1 PHASE 2 OVERVIEW
3.2 PHASE INPUTS
3.3 PHASE ACTIVITIES AND DELIVERABLES
3.4 PHASE CONSIDERATIONS
4 DESIGN PHASE
4.1 PHASE 3 OVERVIEW
4.2 PHASE INPUTS
4.3 PHASE ACTIVITIES AND DELIVERABLES
4.4 PHASE CONSIDERATIONS
5 DEVELOPMENT AND TEST PHASE
5.1 PHASE 4 OVERVIEW
5.2 PHASE INPUTS
5.3 PHASE ACTIVITIES AND DELIVERABLES
5.4 PHASE CONSIDERATIONS
6 IMPLEMENTATION PHASE
6.1 PHASE 5 OVERVIEW
6.2 PHASE INPUTS
6.3 PHASE ACTIVITIES AND DELIVERABLES
6.4 PHASE CONSIDERATIONS
7 OPERATIONS AND MAINTENANCE PHASE
7.1 PHASE 6 OVERVIEW
July 2014 vii
7.2 PHASE INPUTS
7.3 PHASE ACTIVITIES AND DELIVERABLES
7.4 PHASE CONSIDERATIONS
8 DISPOSITION PHASE
8.1 PHASE 7 OVERVIEW
8.2 PHASE INPUTS
8.3 PHASE ACTIVITIES AND DELIVERABLES
8.4 PHASE CONSIDERATIONS
APPENDIX I – SOFTWARE LIFE CYCLE MODELS
APPENDIX II – INFORMATION REFERENCES
APPENDIX III – SLDCM DELIVERABLE SUPPORTING DOCUMENTATION
APPENDIX IV – EXCEPTION REQUEST FORM
APPENDIX V – SDLCM DELIVERABLE TEMPLATES
PROJECT CHARTER
COST BENEFIT ANALYSIS (CBA)
PROJECT MANAGEMENT PLAN (PMP)
WORK BREAKDOWN STRUCTURE (WBS)
RISK MANAGEMENT PLAN (RMP) AND RISK REGISTER (RR)
INVESTMENT TARGET ARCHITECTURE
INVESTMENT TRANSITION STRATEGY AND SEQUENCING PLAN
FIPS 199 SYSTEM CATEGORIZATION REPORT
PRIVACY IMPACT ASSESSMENT
ACQUISITION PLAN (AP)
STATEMENT OF WORK (SOW)
FUNCTIONAL REQUIREMENTS DOCUMENT (FRD)
SECURITY RISK ASSESSMENT
SYSTEM SECURITY PLAN
SECURITY PLAN OF ACTION & MILESTONES (POA&M)
TEST PLAN (TP)
CONFIGURATION MANAGEMENT PLAN (CMP)
LEGACY DATA PLAN
DETAILED DESIGN DOCUMENT (DDD)
CONTINGENCY PLAN
IMPLEMENTATION PLAN (IP)
ACCEPTANCE TEST PLAN
SECURITY CONTROL ASSESSMENT AID (SCAA) / SECURITY TEST & EVALUATION (ST&E) REPORT
ACCEPTANCE TEST REPORT (ATR) AND APPROVAL
TRAINING PLAN (TP)
SYSTEMS ADMINISTRATION MANUAL (SAM)
USER MANUAL (UM)
SECURITY CERTIFICATION AND ACCREDITATION PACKAGE
CONTINGENCY PLAN TEST REPORT
SECURITY ACCREDITATION LETTER
SYSTEM ACCEPTANCE LETTER
SECURITY CONTROLS TEST REPORT / CONTINUOUS MONITORING ANNUAL REPORT
SECURITY RECERTIFICATION AND ACCREDITATION PACKAGE
SECURITY SELF-ASSESSMENT (ANNUAL)
DISPOSITION PLAN (DP)
ADDITIONAL DELIVERABLES
July 2014 viii
APPENDIX VI – STRATEGIC PLANNING DISCUSSION
STRATEGIC MANAGEMENT PROCESS
BUSINESS PROCESS REENGINEERING
APPENDIX VII – SDLCM PHASE GATE REVIEW CHECKLISTS
APPENDIX VIII – LIST OF ACRONYMS
LIST OF FIGURES
Figure 1: DOL’s Seven SDLCM Phases Figure 2: DOL’s IT Governance Structure (as of May 15, 2013) Figure 3: Types of Questions Answered by Earned Value Management (EVM)
Figure 4: Conceptual Planning Phase Activities Figure 5: Planning & Requirements Phase Activities Figure 6: Design Phase Activities
Figure 7: Development and Test Phase Activities Figure 8: Implementation Phase Activities Figure 9: Operations and Maintenance Phase Activities
Figure 10: Disposition Phase Activities Figure 11: Iterative/Incremental SW Development Model Integrated with DOL SDLCM and
CPIC Life Cycles
LIST OF TABLES
Table 1: Major IT Investment Work Pattern
Table 2: Non-Major IT Investment Work Pattern Table 3: SDCLM Deliverable Description By Phase
LIST OF EXHIBITS
Exhibit 1: Sample Functional Requirements Document Outline
Exhibit 2: Sample Test Plan Outline Exhibit 3: Sample Configuration Management Plan Outline Exhibit 4: Sample Detailed Design Document Outline Exhibit 5: Sample Implementation Plan Outline
Exhibit 6: Sample Acceptance Test Report and Approval Outline
Exhibit 7: Sample Training Plan Outline
Exhibit 8: Sample Systems Administration Manual Outline Exhibit 9: Sample User Manual Outline Exhibit 10: Sample System Acceptance Letter Exhibit 11: Sample Disposition Plan Outline Exhibit 12: Sample Requirements Traceability Matrix
Exhibit 13: Sample Test Problem Report Outline Exhibit 14: Sample Maintenance Manual Outline Exhibit 15: Sample Operations Manual Outline
July 2014 1
1 INTRODUCTION
1.1 Purpose
This manual describes the U.S. Department of Labor’s (DOL’s) System Development Life Cycle
Management (SDLCM) methodology including the procedures, practices, and guidelines for engineering and managing DOL IT investments (e.g., an IT project, system, application, service, program, or initiative) through the seven SDLCM life cycle phases. As illustrated in Figure 1, the seven DOL SDLCM phases include the Conceptual Planning, Requirements Definition, Design, Development & Test, Implementation, Operations & Maintenance, and Disposition phase.
This SDLCM Manual has been created to assist and support DOL Agencies in successfully managing their IT investments throughout the entire life cycle of the investment. This manual applies to all new or existing IT investments including, for example, IT hardware and/or software solutions, software development systems, COTS/GOTS software deployments, existing system development, modernization, and/or enhancement and integration activities, interface development activities, infrastructure changes or enhancements, as well as new IT services, and/or projects. This SDLCM manual sets forth a proven, standard, repeatable, reliable, flexible, and adaptable life cycle management methodology applicable to all DOL IT investments. When followed and implemented correctly by IT PMs and IPTs the life cycle methodology will lead to sound and consistent IT investment management practices across the Department and result in higher quality and successfully managed IT investments – delivered on budget, schedule, and with promised functionality.
The SDLCM concepts presented in this manual are a part of DOL’s IT life cycle management framework to improve the quality of Departmental IT investments. See the DOL IT Investment
Management Life Cycle (IMLC) Guide for more details on the complete and integrated life cycle management framework. A copy of the guide can be found in the OCIO Resource Library on
LaborNet under the Investment Management topic area.
Conceptual Planning
System Development Life Cycle Management (SDLCM) Phases
Design Development
& Test Implement Operations &
Maintenance Disposition
Planning & Reqts Definition
Legend: Phase Gate Reviews
Phase 1 Phase 2 Phase 3 Phase 4 Phase 5 Phase 6 Phase 7
Figure 1: DOL’s Seven SDLCM Phases
1.2 Document Overview
This chapter provides an overview of the general concepts that are relevant to the SDLCM, including project management roles and responsibilities, and quality assurance. Subsequent chapters present details regarding the Department’s seven defined phases of the SDLCM.
July 2014 2
Finally, the appendices provide additional information on several of the areas highlighted in the main document as well as detailed descriptions and templates for the SDLCM deliverables.
Appendix II, in particular, contains hyperlinks and relevant references for Departmental, Federal and legislative guidance that relates to and/or impacts SDLCM activities.
1.3 Document Revision History
The following table describes the revision history of this document including the version number, the version date, the person who made the modification(s), and a description of the changes.
Version
No.
Version
Date
Modified
By
Description of Changes
1.0 01/2000 Initial draft developed
2.0 06/2000
2.1 12/2002 DOL OCIO Administrative update including the following changes:
Addition of Frequently Asked Questions (FAQs)
Addition of a business process, integrating the
SDLCM with Capital Planning, Security and
Privacy, and other functional areas under CIO oversight
Update of security requirements
Addition of enterprise architecture material
Addition of quality assurance material
Addition of information quality material
Addition of software life cycle models
Addition of a Waiver/Exception process
Legislative update for the E-Government Act of
2002, Public Law 107-347
2.2 08/2006 DOL OCIO Replaced/updated I-TIPS references and information with eCPIC information throughout the entire document since I-TIPS is no longer used by the
Department.
Added section “1.14 Document Revision History”.
Updated the FAQ section to clarify answers to previous questions and to add several new questions and answers.
Combined the Figure 3 and 4 Large and Medium
System Work Patterns
Updated the deliverables in the Large/Medium and small work patterns (and the associated text in
Chapters 2 through 8 supporting these Figures), Eliminated the threshold 3i investment category in
Section 1.4.1 and removed Figure 5 the Maintenance and Enhancement Effort Work Pattern
Updated the threshold 1, 2, and 3 descriptions to be consistent with the OCIO Capital Planning Guide and increased the minimum annual investment cost from $100K to $250K for threshold 1 and 2 investments. Also, added the text “with annual investment costs of $500K or above” to the financial management system bullet in the threshold 3 section
July 2014 3 and language clarifying whether the threshold level was considered an Major or Non-Major investment as defined by Circular A-11.
Deleted References to OMB Director’s Policy
Memorandum M-97-02 (Raines Rules)
Replaced the word “project” with “investment” accept when referencing the Project Manager or
Project Management Plan (PMP).
Updated Figure 1 the DOL IT Investment
Management Framework
Deleted References to the following six deliverables:
Data Sensitivity Assessment
Acceptance Test Approval
Delivered System
System Fielding Authorization
Trained Personnel
Implemented System
Added six new deliverables including a description of each in Figure 7
Investment Target Architecture
Investment Transition Strategy
FIPS 199 System Categorization
Contingency Plan Test Report
Security Controls Testing/ Continuous
Monitoring
Re-certification and Accreditation
The following changes were made to the list of existing deliverables in the Figure 3 work pattern:
“Security “Security Test & Evaluation” was changed to “Security Control Assessment
Aid (SCAA) / Security Test & Evaluation
(ST&E)”
“Acceptance Test Report” was combined with “Acceptance Test Approval” to form
“Acceptance Test Report and Approval”
“Implementation Certification Statement” was changed to “System Acceptance Letter”
“Archived System” is now integrated into the “Disposition Plan”
Updates to the CBA are now indicated for
Phase 4 and 5, and 6. Updates in Phase 6 are driven by the results of the Operational
Analysis (OA).
The PMP and RMP are required to be updated in Phase 6
The WBS is a core requirement in Phase 1 and is updated for each of the remaining phases.
The Acquisition Plan is a core requirement in Phase 2
Deleted Implemented System, Acceptance
Test Approval, Delivered System, System
Fielding Authorization, and Trained
Personnel
A Records Management Plan has been
July 2014 4 added to the Project Management Plan
(PMP) – a description of what is expected by implementing a Records Management is also described in the document.
Deleted Section 1.8 entitled “Certificate Based
Services” which described the Departments intention to create a PKI certificate based service since the
Department is no longer pursuing this service.
Added text throughout the document describing
EVM and Operational Analysis requirements including for example an FAQ question/answer and
Section 1.12 Performance Management
Added text to Section 2.1, Step 1 indicating an
Agency should use its EA to identify the need for new or modified IT investments as well as consolidation, business optimization, and collaboration opportunities.
Replaced text in Section 2.1, Step 2, in the EA section of the table that states “the Departments enterprise target architecture and standards” with
“the Departments enterprise architecture and IT standards.”
Added a “Note” to Figure 5 in Section 1.9 to the definition of the Investment Target Architecture and
Investment Transition Strategy to clarify that these
EA deliverables are required to be incorporated into the Agency Target Architecture and Transition
Strategy, respectively. Otherwise, an IT Investment
PM may choose to create and maintain an IT
Investment Target Architecture and Transition
Strategy document that is separate from the Agency
Target Architecture document.
The Cost Benefit Analysis (CBA) outline in
Appendix V has been updated and well as the CBA text in Chapter 2 and 3.
A description of the OCIO Cost Model has been incorporated in the CBA sections.
The Project Management Plan (PMP) text has been updated to clarify the WBS and several other existing requirements.
The Risk Management sections have been updated to reflect the new OCIO Risk Management Plan template and associated Risk Register (RR).
The References section has been updated including the URLs.
The Acronyms List has been updated to reflect current acronyms
2.3 05/2012 DOL OCIO An updated description of the OCIO Cost Model has been incorporated in the CBA sections.
The Risk Management sections have been updated to reflect the latest updates to the OCIO Risk
Management Plan template and associated Risk
Register.
A description of the end of phase review process was
July 2014 5 added to the document.
A description of the Performance Measurement
Baseline (PMB) and the Integrated Baseline Review
(IBR) was added to document.
A description of Release Management and the associated Release Management process that is to be implemented by IT investments was added to the document.
A description of the relationship between the
SDLCM and the PMBOK Guide was added to the
Q&A section of this document.
A description of how the Federal Acquisition
Certification for Program and Project Managers
(FAC P/PM) requirements relate to the SDLCM was added to the Q&A section of this document.
A description of how the Cyber Security Assessment and Management (CSAM) Internet-based tool relates to the SDLCM was added to the Security section of this document.
A description of the Initial Investment Post
Implementation Review (PIR) was added as an activity in the beginning of Phase 6.
A description of the Independent Verification and
Validation (IV&V) activities that will need to be performed by an IT investment has been added to the
Quality Assurance (QA) section of the document.
References have been incorporated in applicable sections throughout the manual to the following
OCIO templates: CBA template, Acquisition Plan template, Project Charter, IT Rebaseline Guide, Initial Investment PIR template, EVM Operational
Guide, and the EVM Quick Reference Guide.
The word “initiative” was replaced with the words
“IT investment” throughout the document to be consistent with Office of Management and Budget
(OMB) A-11, Part 7 terminology.
References to the OCIO FAQ website on LaborNet have been removed.
The URLs throughout the document have been tested, updated or removed as necessary, and/or verified as being active.
The Acronyms List has been updated to reflect current acronyms.
The IT Investment Management Framework diagram in Figure 1 was updated to reflect changes (i.e., SDLCM end of phase reviews, CPIC Control phase starting during the SDLCM phase 2, EA shift to
Strategic Business Management and the associated phases being updates, and updates to the Security life cycle phases.
The DOL IT Governance Model was updated to reflect the changes made and announced by the DOL
Assistant Secretary for Administration and
Management in the memo dated July 26, 2011.
Deleted Appendix I – Enterprise Architecture as the
July 2014 6 information was duplicative and dated
Deleted Appendix II – Security Roles, Activities, and
Deliverables as the information is duplicative to the
DOL Computer Security Handbook.
2.3.1 09/2013 DOL OCIO The DOL IT Governance Model was updated to comply with the requirements of the OMB Digital
Government Strategy published in May 2012.
Relabeled the Figures, Tables, and Exhibits accordingly.
Added alternative text to each of the figures to make them Section 508 compliant.
2.4 01/2014 DOL OCIO See the “Preface” for a summary of changes made to this document.
1.4 Frequently Asked Questions (FAQ) about the SDLCM
What is the SDLCM Manual?
This DOL System Development Life Cycle Management (SDLCM) Manual establishes and describes the standard methodology including principles, practices, and guidelines for governing the conceptual planning, requirements definition, design, development & test, implementation, operations & maintenance, and disposition of IT investments within the DOL. This manual has been created to assist and support DOL Agencies in successfully managing their IT investments throughout the entire life cycle of the investment. It applies to all IT investments including for example custom software application development, COTS application implementation, integration, IT infrastructure changes, as well as IT services (i.e., fully outsourced services, cloud computing solutions, etc.). This manual provides a proven, structured, and standardized life cycle management approach to all DOL IT investments.
Why do I have to use the SDLCM methodology?
The DOL SDLCM methodology is based on standard SDLC principles and practices that are time-tested and have been proven successful for managing IT investments in the private sector as well as in the Federal Government including civilian agencies and the Department of Defense.
The SDLCM methodology serves as the structured mechanism to ensure that DOL IT investments are developed, modified, enhanced, as well as operated and maintained efficiently and effectively. Following the SDLCM methodology ensures DOL IT Investments are managed properly and are delivered on budget, schedule, and with the promised functionality. It also assists and supports IT investment managers in achieving the intended or planned investment mission, goals, financial benefits as well as applicable DOL IT strategic goals and critical success factors. It sets forth a standard, repeatable, and reliable process for managing IT investment development, acquisition, implementation, and operating activities. The life cycle process ensures IT investment are monitored, controlled, measured, documented, and managed efficiently and effectively in accordance and compliance with DOL IT policy and legislation
(e.g., the Clinger Cohen Act). The SDLCM adds value to DOL IT investments by establishing a uniform and standardized approach to IT investment management. The methodology supports as
July 2014 7 well as guides IT investment PMs and IPT members through many required activities and challenging issues throughout the life cycle of an IT investment.
The SDLCM methodology presented in this manual is flexible and adaptable as DOL IT PMs and IPTs are able to choose the best approach to implementing the life cycle phases for their IT
Investment. For example, IT PMs and IPTs are able to choose between phased, sequential, modular, iterative and/or incremental development approaches depending on the nature (e.g., size, scope, complexity, criticality, and/or timing) of the IT investment being developed.
For large and/or complex IT investments, the DOL OCIO and OMB are requiring modular, iterative, and/or incremental development approaches. See OMB’s “Contracting Guidance to
Support Modular Development”, June 14, 2012, for details regarding module development as well as guidance with contracting and implementing a modular development approach for IT investments.
When do I use the SDLCM?
Agency PMs and IPTs will need to follow the SDLCM for applicable IT investments throughout the entire life cycle of the investment from conceptual planning to disposition. The SDLCM should be utilized as a reference and guide throughout the life cycle of an IT investment. The
SDLCM should be used in conjunction with other existing DOL IT investment management framework processes including the Capital Planning and Investment Control (CPIC), Security, and Strategic Business Management (SBM) life cycle processes. (See the DOL IT Investment
Management Life Cycle (IMLC) Guide for further details on DOL’s integrated IT investment management life cycle processes. A copy of the guide can be found in the OCIO Resource
Library on LaborNet under the Investment Management topic area.)
What is a work pattern and how do I know which one to use?
A “work pattern” refers to the activities performed and products or deliverables produced as part of the life cycle phases associated with the development and life cycle of a system. There are two work patterns associated with this SDLCM Manual: one for major IT investments and one for non-major IT investments. See the DOL CPIC Guide for information on determining whether a system is considered a major or non-major IT investment. PMs will need to work with the OCIO CPIC team during the early conceptual planning phase to determine whether a system is consider major or non-major and ensure the determination is clearly identified and included within the IT investment Project Charter document. In general, the more costly, technically complex, or risky an IT investment is, the more likely it’s considered a major system and as such will require completing the major system work pattern. All major systems are required to follow the major work pattern. Please refer to the major and non-major work patterns in Section 1.6 of this manual for a list of required deliverables to be completed, for each pattern, throughout the system’s life cycle. DOL PMs and/or IPTs are highly encouraged to work with the OCIO CPIC team in determining the correct work pattern for an IT investment as soon as possible during the early conceptual planning phase. Ideally, PMs and/or IPT members should seek OCIO CPIC team review and approval of the correct work pattern prior to signature approval of the Project
Charter. For more information on the DOL CPIC process, see the latest DOL Capital Planning and Investment Control (CPIC) Guide. A copy of the CPIC Guide can be found in the OCIO
Resource Library on the DOL LaborNet under the CPIC topic area.
http://www.whitehouse.gov/sites/default/files/omb/procurement/guidance/modular-approaches-for-information-technology.pdf http://www.whitehouse.gov/sites/default/files/omb/procurement/guidance/modular-approaches-for-information-technology.pdf
July 2014 8
How do I know what the security requirements for my system will be?
Security requirements should be discussed with Departmental security staff during the beginning of the conceptual planning phase. Sponsoring Agency security authorities should, if possible, review the requirements referenced in the Computer Security Handbook prior to these discussions. While this SDLCM describes security requirements in each phase of the life cycle, there are numerous other regulations and guidelines that drive security requirements into the
SDLCM. Thus, Project Managers (PMs) and Integrated Project Team (IPT) members are encourage to review the DOL OCIO Computer Security Handbook (CSH) for all the
Department-wide IT security policies, procedures, standards, requirements, and templates. A copy of the DOL CSH can be found in the OCIO Resource Library on LaborNet under the
Security subject area.
Where do I go to get help when I have questions?
The OCIO IT capital planning and system development personnel are the primary resources for providing SDLCM assistance. If you have questions about the SDLCM, please contact Peter
Sullivan in the OCIO at 202-693-4211 or sullivan-peter@dol.gov. Additional SDLCM information can be found in the OCIO Resource Library on the DOL LaborNet under the System
Development Life Cycle Management (SDLCM) topic area.
What if the DOL SDLCM process does not suit the needs of my IT investment?
PMs and IPTs are required to follow the SDLCM for applicable IT investments throughout the entire life cycle of the investment from conceptual planning to disposition. The OCIO requires any deviations or exceptions to implementing and/or utilizing this standard SDLCM methodology to be justified and submitted in writing and approved by OCIO leadership prior to the initiation or funding of an IT investment. Exception requests will be handled on a case-by-case basis, taking into consideration the complexity of the investment and the applicability/reason for the specific request. Please refer to the Waiver/Exception Process section of this manual, and direct exception requests to the OCIO’s IT Governance staff. In addition, please refer to Appendix I for more information on Software Life Cycle Models.
What if my IT investment is considered Software Development or an Application?
This SDLCM manual allows PMs and IPT to choose the software development model and/or deployment approach that works best for the system solution – whether the solution includes one or more software applications and/or interfaces, custom software, Commercial-of the-Shelf
(COTS), and/or Government-of-the-shelf (GOTS) software that needs to be developed or configured and/or integrated into a system solution. This manual provides a proven, structured, and standardized life cycle management approach applicable to most if not all DOL IT investments – whether considered a software system, application, or interface.
The SDLCM methodology presented in this manual is flexible and adaptable as the life cycle phases can be implemented using a phased, sequential, modular, iterative and/or incremental development approach depending on the nature (e.g., size, scope, complexity, criticality, and/or timing) of the system being developed. The life cycle principles and practices presented in this mailto:sullivan-peter@dol.gov
July 2014 9 manual apply regardless of the development approach. Likewise, PMBOK principles, processes, and the associated knowledge areas apply regardless of the size, scope, complexity, criticality, and/or timing of projects – whether a software or system development project or investment.
See Appendix I for more information on various Software Life Cycle Models that may be implemented. Figure 11 in the appendix illustrates, as an example, an iterative/incremental software development approach implemented utilizing the SDLCM life cycle phases.
This DOL SDLCM manual can and should be used throughout the entire life cycle of a software-based IT investment - from conceptual planning to disposition. The software development model and deployment approach is to be defined by DOL PMs and/or IPTs and approved by the OCIO during the conceptual planning phase or as part of the integrated baseline review process. For more information on the DOL IT investment baseline review process see the DOL IT Baseline
Management Policy and the associated IT Baseline Management Guide, both can be found in the
OCIO Resource Library on the DOL LaborNet under the Baseline Management topic area.
How does the SDLCM relate to other OCIO requirements for IT investments?
The SDLCM is one component of DOL’s IT Investment Management Framework. This
Framework is described as the activities necessary to ensure that an IT investment progresses toward the achievement of its objectives in accordance with planned or revised cost, schedule and technical baselines, as well as performance outcomes. The other components of the framework include the Capital Planning and Investment Control (CPIC) process, the Security
Life Cycle phases, and the Strategic Business Management life cycle phases. Other related functional areas within the OCIO include Information Quality, Quality Assurance, Performance
Measurement, E-Government and Records Management. All of these components must work together in an integrated manner to ensure compliance with statutory and regulatory requirements and to lead to successful investment outcomes. In formulating a lifecycle development process, it is essential that requirements documentation, work efforts and system specifications reflect the Department’s guidance on these topics. Reference materials on these topics are listed in the appendices.
How does the SDLCM manual relate to Office of Management and Budget (OMB) requirements for IT investments?
The DOL SDLCM manual is a DOL IT Investment life cycle management process that is implemented by Project Managers and/or Program Managers and associated Integrated Project
Teams (IPTs). DOL IT investments (e.g., an IT projects, systems, or services,) are implemented in accordance and compliance with DOL policies, orders, memorandum, procedures, standards, and guidelines, as well as in accordance and compliance with applicable Federal laws, legislation, policies, standards, regulations, rules, procedures and processes. This includes
OMB requirements as documented in OMB circulars, memorandum, guidance, and presidential directives and orders. As such, DOL Project Managers, Program Managers, and IPTs are expected to manage, implement, and/or operate and maintain IT investments using the SDLCM manual processes to achieve Department, Agency, as well as OMB goals and objectives as is applicable to the specific IT investment. Project Manager, Program Managers, and IPT members are encouraged to monitor, review, implement, and/or abide by OMB circulars, memorandum, directives, and guidance as applicable to DOL IT investments in order to achieve
July 2014 10
OMB goals including, for example, but not limited to, Transparency and Open Government, IT
Cloud-Computing, Shared Services, Consolidation, Virtualization, Standardization, and other
Federal IT modernization and cost cutting initiatives. DOL agencies are encouraged to contact and work with the DOL OCIO Capital Planning and Investment Control (CPIC) group to understand OMBs requirements and how to plan and implement OMBs requirements.
How does DOL’s and OMB’s Baseline Management policy requirements for IT investments relate to the DOL SDLCM manual?
On September 9, 2010, the DOL OCIO CPIC Program Office published DOL specific Baseline
Management policy in accordance and compliance with OMB Memorandum M-10-27, “Information Technology Investment Baseline Management Policy,” issued to Federal Agencies on June 28, 2010. In addition, the OCIO Program Office created the “IT Baseline Management
Guide” to assist and support DOL agencies, IT Project Manager, Program Managers, and IPT member in understanding DOL’s IT baseline management policy, processes and requirements.
In order to comply with DOL and OMB Baseline Management policy, DOL Agency IT Project
Managers, Program Managers, and IPT members are required to establish, manage, and report on (OCIO approved) IT investment baselines for all new and current IT investments to ensure that the investments meet their specified cost, schedule and performance goals and achieve intended results. In order to achieve IT investment baseline approval from the OCIO, Agency IT
Project Managers, Program Managers, and IPT members will need to complete and acquire
OCIO approval of fundamental SDLCM deliverables described in this manual including for example, the Project Charter, Cost Benefit Analysis (CBA), Project Management Plan (PMP), Work Breakdown Structure (WBS), Functional Requirements document, etc. Thus, this SDCLM manual and the DOL IT Baseline Management Guide are critical resources to help Agencies be successful and comply with DOL’s IT baseline management policy and the associated Federal laws and OMB requirements. A copy of the DOL IT Baseline Management Guide can be found in the OCIO Resource Library on the DOL LaborNet under the Baseline Management topic area.
For further information about the Guide or DOL’s baseline management policy or processes, please contact the DOL OCIO via email at OCIOCapitalPlanning@dol.gov.
How does the Project Management Body of Knowledge (PMBOK) Guide relate to the
SDLCM?
The PMBOK Guide is an internationally recognized project management methodology established by the Project Management Institute (PMI). The PMBOK Guide is an important reference document as it describes a comprehensive set of interrelated project management processes that are generally recognized as good practices for managing all types of projects – across various industries. The SDLCM, on the other hand, is a specialized and proven information technology life cycle management methodology. It is flexible, adaptable, and scalable methodology, which has been successfully implemented and utilized to plan, develop, test, integrate, deploy, operate, and manage a wide variety of IT investments (i.e., applications, systems, services, programs, initiatives) at DOL; and similar SDLC methodologies have been successfully used throughout the Federal Government and in private industry for decades.
mailto:OCIOCapitalPlanning@dol.gov
July 2014 11
Since the SDLCM is IT focused, DOL IT investments are managed using the SDLCM methodology as represented in this document. DOL IT PMs and IPTs are highly encourage to apply PMBOK principles, processes, and practices as applicable, while implementing and executing the life cycle phases in this SDLCM Manual. One of the benefits of the good practices established by the PMBOK principles and processes is that they can be applied at various levels and to various degrees throughout the SDLCM methodology. For example, work activities and individual SDLCM deliverables within each of the phases of the SDLCM can be managed using
PMBOK principles and processes. In addition, each of the seven phases of the SDLCM can also be managed using the PMBOK principles, processes, and practices.
An IT investment may have one or more vendors and/or contractor teams including for instance an IV&V team supporting the investment. Each of these entities should manage their individual contracts and associated tasks as independent projects using PMBOK principles. Thus, the DOL
OCIO encourages all IT investment PMs and IPTs to apply PMBOK principles and processes, as applicable and appropriate, to ensure the success of individual IT investment tasks and deliverables as well as individual phases and the IT investment as a whole.
The PMBOK Guide should be used as a reference to support IT Investment PMs/IPTs in implementing and executing the SDLCM methodology. In the unlikely event that the SDLCM and PMBOK principles and practices should conflict or if there is a perception of conflict, then the principles and practices described in this DOL specific manual outweigh the general practices in the PMBOK Guide. This version of the SDLCM continues to include/adopt PMBOK
Guide terminology were applicable and appropriate and as long as it does not conflict with standard SDCLM terminology.
How does the Federal Acquisition Certification for Program and Project Managers (FAC
P/PM) requirements relate to the SDLCM?
DOL Program and Project Managers of Major IT investments must be certified at the FAC-
P/PM Level 3 – Senior/Expert level. This requirement will ensure that DOL Program and
Project Managers (P/PMs) are experienced in managing IT investments, including managing them through the SDLCM phases. To maintain FAC-P/PM Level 3 certification, P/PMs are required to earn 80 continuous learning points (CLPs) every two years. Thus, P/PMs will need to review and follow DOL FAC-P/PM Program and policy requirements in order to be certified and maintain compliance going forward.
The FAC P/PM requirements were established on April 25, 2007 when OMB issued a
Memorandum for Chief Acquisition Officers entitled “The Federal Acquisition Certification for
Program and Project Managers (FAC P/PM)”. The FAC P/PM requirements were based on the recommendations from a Federal Acquisition Institute working group.
As a result of OMBs memo, the DOL established a FAC-P/PM Program within the Department and published DOL specific FAC-P/PM policy. In accordance with the OMB memo, the DOL
FAC-P/PM Program and requirements represent general training and experience requirements
July 2014 12 for certifying DOL program and project managers. As stated in DOL’s FAC-P/PM policy document, the DOL FAC-P/PM Program and requirements focus on defining and establishing essential competencies needed for program and project managers. The DOL FAC-P/PM requirements describe three levels of certification based on the number of years of experience.
The three levels include:
1. Entry or Apprentice level – This level requires at least one year of on the job training defining and assisting a program/project manager. A baccalaureate degree in
Engineering, Systems Management, or Business Admin is desirable at this level.
2. Mid-level/Journeyman level – This level requires at least two years of on the job training.
A Masters degree in Engineering, Systems Management, or Business Admin is desirable at this level.
3. Senior or Expert level – This level requires at least four years of on the job training -
Manage and Evaluate. Senior/Expert-Level FAC-P/PM required for all investments defined as “Major Investments” by OMB. A Masters degree in Engineering, Systems
Management, or Business Admin is desirable at this level.
No additional information regarding the DOL FAC-P/PM Program is included in this SDLCM manual. For additional information, please see the Department of Labor’s Federal Acquisition
Certification in Project/Program Management (FAC-P/PM) Program policy document.
What is Earned Value Management (EVM) and do I have to implement it for my IT investment?
EVM is a Department of Labor and OMB mandated IT investment performance based management process that integrates cost, schedule, and technical performance, to provide decision makers timely and accurate information on the overall performance or health of an IT investment. The EVM process measures the cost and schedule performance of an IT investment by comparing planned, budgeted, and scheduled work activities (which are laid-out in a time-phased manner) against actual work accomplished. As work is accomplished on an IT investment, IT investment value is “earned.” The EVM process is also used as a predictive tool that, when used effectively, can highlight investment risks, identify opportunities to manage or control the performance of the IT investment, and estimate the future (near-term) cost and schedule performance of the investment.
EVM is applicable to Major IT investments and Mixed Lifecycle investments when the annual cost of Development, Modernization, and Enhancement (DME) exceeds $1,000,000. These exemptions are not applicable to an investment that warrants special attention because of other factors as delineated in OMB Circular A-11, such as significant importance to an agency’s mission, high management visibility, or high risk.
IT investments that are required to perform EVM are required to develop a Performance
Measurement Baseline (PMB), which is an integrated scope-schedule-cost plan for the work that
July 2014 13 will be performed. It will be used to measure and manage the actual work performed, i.e., to measure work performance.
This is the start of the file's text. The full file is on GovTribe.
File details come from the government source that posted it. Updated .