Appendix_I_-_PPA_Best_Practices_by_Release.pdf
PDF 21 KB Posted
- Attached to
- FDA Nonclinical Information Management System (NIMS) Federal contract opportunity
- Solicitation number
- FDA-SOL-13-1116203
About this file
Appendix I
View the file
Other files for this federal contract opportunity
Show all 21
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
EPLC ARTIFACT AUTHOR9 INITIAL
RELEASE
MAJOR RELEASE
(upgrade version)
MINOR RELEASE
(config changes)
EMERGENCY RELEASE
(change config or upgrade for security) 1 (I01) Boundary Document Business with IT Support Create Review5 Waive Waive 2 (C01) Business Case Business Combine with I01 Review5 Waive Waive 3 (C06) Project Charter IT PM and Business PM Create Waive Waive Waive 4 (C07) Business Requirements Document Business Create Review5 Waive Waive 5 (P01) Project Management Plan IT PM and Business PM Create (High, Med) Review5 Waive Waive 6 (R03) CONOPS IPT with Business Combine with C07 Review5 Waive Waive 7 (T01) Master Test Plan IPT w/Business input for UAT Create Review Waive Waive 8 (IM03) Service Level Agreement(s) and/or Memorandum(s) of
Understanding
TBD
(depends on content) Create1 Review5 Waive Waive
9 (I02) Project Process Agreement (PPA) IT Project Manager (IT PM) with Business PM
Create Create Create Create
10 (P02) Project Schedule IT PM and Business PM Create Update Update Update 11 (R01) Logical Data Model and Data Dictionary (ERWIN) IPT Waive (Vendor) Waive (Vendor) Waive Waive 12 (R02) System Requirements Specifications IPT Create8 Review5 Review5 Waive 13 (DS01) System Design Document IPT Combine with R02 Review5 Review5 Waive 14 (DS02) Physical Data Model and Data Dictionary (ERWIN) IPT Waive Waive Waive Waive 15 (DS03) Interface Control Document (ICD) IPT Combine with R02 Review5 Review5 Waive 16 (DS04) Systems Security Plan IPT Create Review5 Review5 Waive 17 (DV01) System Architecture Document IPT Combine with R02 Review5 Review5 Waive 18 (DV02) Version Description Document (VDD) Developer Create Update Update Update 19 (DV03) Software Unit Test Report Developer Waive Waive Waive Waive 20 (T03) Release Test Plan IPT Waive Create6 Create6 Waive 21 (T04) Test Cases Specifications Testers Create Update Review5 Waive 22 (T06) Requirements Traceability Matrix (RTM) IPT Create Update Review5 Waive 23 (T07) System Test Report Test Manager Create Create Create Create 24 (T08) Section 508 Test Report Test Manager Waive (VPAT) Waive (VPAT) Waive (VPAT) Waive 25 (T09) Performance Test Report Test Manager Combine with T07 Combine with T07 Waive Waive 26 (T11) User Acceptance Test (UAT) Report Test Manager w/ Business Create2 Create7 Waive Waive 27 (T12) Operation and Maintenance Manual IPT with Developer Create3 Update Update Waive 28 (T13) Project Implementation Plan IPT with Business Create (High, Med) Update (High, Med) Waive Waive 29 (T14) Training Plan Business with IT Support Create Review5 Review5 Waive 30 (T15) Training Materials Business with IT Support Create4 Review5 Review5 Waive 31 (T16) User Manual IPT with Business Create4 Review5 Review5 Waive
32 (C02) Security Categorization Form (SCF) Security SME with IPT Create 33 (C03) Privacy Impact Analysis (PIA) Security Create 34 (C04) System of Records Notice (SORN) Freedom of Information
(OA/OM/OS/OPILS)
Create
35 (C05) E-Authentication Security Create 36 (T02) Security Assessment Plan Business Owner with support from
Security Create
37 (T05) Risk Assessment Security Create 38 (T10) Security Assessment Report (SAR) (Security Test Report) Security Create 39 (IM04) Security Authorization Executive Summary (SAES)
Security Create
40 (IM01) Contingency and Disaster Recovery Plan Security with Business and IT
Create
41 (IM02) Plan of Action and Milestones Security 42 (IM05) Annual Operational Analysis Business 43 (OM01) Disposition Plan Business with IPT
ARTIFACTS TO CREATE 32 4 3 2
ARTIFACTS TO UPDATE 0 6 3 2
ARTIFACTS TO REVIEW and/or UPDATE5 0 15 10 0
ARTIFACTS WAIVED 5 5 15 27
1 Create if an SLA or MOU is needed 6 If testing for this release is different from what is documented in the Master Test Plan (T01) 2 Create only if business owner wants a UAT 7 Only if significant changes warrant a UAT 3 This would consist of mostly the vendor's documentation with the configurations used at FDA. 8 4 Could be waived if Vendor documentation is sufficient 5 Update if upgrade provides significant changes in functionality 9
(High, Med) Create or update only if project is determined to be high or medium complexity
Create - Create a new artifact Initial The first rlease of a system (release 1.0) Update - Update the existing artifiact Major Review - Review the existing artifiact, update if necessary Combine - Combine with another EPLC artifact Waive - Artifact will not be created for the project or release. Justification required. Minor
Emergency
FDA EPLC PROJECT PROCESS AGREEMENT
SUMMARY OF BEST PRACTICES BY RELEASE TYPE
FOR PROJECTS INVOLVING COTS PRODUCTS WITH NO CUSTOMIZATION OTHER THAN CONFIGURATION
EPLC PROJECT LEVEL ARTIFACTS
A planned release comprised of enhancements or changes to an existing production system (including data migrations). It can include new features, functions, capabilities, or corrections to problems that cause the system to function incorrectly/inadequately.
A planned release comprised of defect fixes, minor enhancements, related to previous initial or major release that does not impact infrastructure, scope/boundary, interfaces, security, and/or data structure.
An unplanned production release to correct a defect (code, data, or infrastructure) which causes severe issues in functionality, performance, or data resulting in work stoppage with no immediate workaround. Also includes a release of a mandated, time-critical security patch.
EPLC RELEASE LEVEL ARTIFACTS
EPLC ARTIFACTS SUMMARY
NOTES
KEY
TIME OR EVENT DRIVEN EPLC ARTIFACTS
Artifacts created for initial release and reviewed/updated when there are significant changes and during annual security assessments
Artifacts created for initial release and reviewed during annual security assessments. Re-signed every 3 years.
Artifact created for initial release and reviewed/updated when there are significant changes and during annual security assessments
Created when deficiencies are found. Updated when new deficiencies are found Artifact created annually during annual operation analysis
Artifact created when the annual operation analysis determines system is ready for disposition
If there is no IT PM assigned, the business PM or designee (as documented in Project Charter) performs all IT PM functions.
Based primarily on the vendor documentation of functionality with additional non-functional and configuration based requirements.
In iti at io n
C on ce pt
Pl an ni ng
R eq ui re m en ts
D es ig n
D ev el op m en t
Te st in g
Im pl em en ta tio n
In iti at io n
C on ce pt
Pl an ni ng
R eq ui re m en ts
D es ig n
D ev el op m en t
Te st in g
Im pl em en ta tio n
In iti at io n
C on ce pt
Pl an ni ng
R eq ui re m en ts
D es ig n
D ev el op m en t
Te st in g
Im pl em en ta tio n
In iti at io n
C on ce pt
Pl an ni ng
R eq ui re m en ts
D es ig n
D ev el op m en t
Te st in g
Im pl em en ta tio n
P P
P P P P N P P P P P P P P
P P P P P C2
P P P P P P
P P P P P P
1 For combined stage gates, artifacts from all included stages should be reviewed 2 Infrastructure may not need to participate if there is no change to infrastructure or interfaces 3 508 may not need to participate if there is no change to GUI or outputs
P Participate Hold Hold stage gate N Notify only, will not participate in review Waive Stage gate not necessary for project and release type C Conditional
NOTES
KEY
P N P
P P
P PSecurity Testing
P P P
Freedom of Information Office
CRITICAL PARTNER
FDA EPLC PROJECT PROCESS AGREEMENT
SUMMARY OF BEST PRACTICES BY RELEASE TYPE
FOR PROJECTS INVOLVING COTS PRODUCTS WITH NO CUSTOMIZATION OTHER THAN CONFIGURATION
Acquisitions Budget Business Configuration Management
CPIC
Data Standards and Integration
EMERGENCY RELEASE
(change config or upgrade for security)
Waive Waive Waive
Hold1
STAGE GATE REVIEWS
Waive Waive Waive
Waive Waive
MINOR RELEASE
(config changes)
Initiation
STAGE GATE MAJOR RELEASE
(upgrade version)
P P
Waive
C3
P P N
Hold1
Waive
STAGE GATE REVIEW SUMMARY
Waive
Waive WaiveDisposition
Hold1
Waive Waive
Hold1
Hold
P
INITIAL
RELEASE
Hold Hold Hold
Hold1
Hold1
Waive
Waive Waive
P P P P
P
Hold1
Waive Waive
P P
Waive
P
C3
P P N
C2
P
P P
Implementation
Infrastructure Records Management
C2
Data Standards Council
P
P
Enterprise Architecture N
Concept Planning Requirements
Operations and Maintenance
Design Development Test
N
P
File details come from the government source that posted it. Updated .