SharePoint RFP Tech - Systems 20Assurance 20Plan.pdf

PDF 992 KB Posted

Attached to
SharePoint Integration and Support Services Federal contract opportunity
Solicitation number
HSCETC-10-R-00015
Issued by
Immigration and Customs Enforcement

About this file

ICE Enterprise Systems Assurance Plan

View the file

Other files for this federal contract opportunity

Other files attached to SharePoint Integration and Support Services, newest first.
File Type Posted
HSCETC-10-R-00015 A0003.pdf PDF
Attachment 3-Pricing Matrix.xls XLS spreadsheet
Attach 7DD254.pdf PDF
Attach 4 OCIO.doc DOC document
A0002 Sol 55-64.pdf PDF
Attach 1 SOW —
A0002 Sol 65-115.pdf PDF
A0002 Sol 5-54.pdf PDF
Attach 2 PPQ.doc DOC document
Attach 6ClassContract.pdf PDF
A0002CoverSheet.pdf PDF
A0002 Sol 116-131.pdf PDF
HSCETC-10-R-00015P0001.pdf PDF
RFPQuestionSharePoint 4 20 20 final.pdf PDF
SharePoint RFP Tech - ICE_MOSS 20Intranet 20Physical 20Production 20Topology_jpg.jpg JPG image
SharePoint RFP - Section B - M.doc DOC document
SharePoint RFP - Section A.pdf PDF
SharePoint RFP Tech - Standards Web Services .doc DOC document
SharePoint RFP - Response to Questions Asked at Pre-Proposal Conference —
SharePoint RFP Tech - IA Program Policy-Handbook FINAL as of 20090127.doc DOC document
SharePoint RFP Tech - SLM 20Tech 20Ref 20guide 20Book.pdf PDF
SharePoint RFP - Attach 3 - Pricing Matrix.pdf PDF
SharePoint RFP - Attach 1- TO SOW.pdf PDF
SharePoint RFP Tech - DHS_Sensitive_Systems_Policy_4300A_v7dot1.doc DOC document
SharePoint RFP Tech - Table of Contents - ICE- OCIO Technical Documents .doc DOC document
SharePoint RFP Tech - DHS 20MD 20140-02.pdf PDF
SharePoint RFP Tech - SLM 20Test 20Evaluation.pdf PDF
SharePoint RFP - Attach 2 -Past Perf Questions.pdf PDF
SharePoint RFP Tech - SLM 20Hand 20Book.pdf PDF
SharePoint RFP - Attach 4 - OCI Disclosure Forms.pdf PDF
SharePoint RFP Tech - 33443 Information Assurance Program Policy FINAL asof 20100309.doc DOC document
SharePoint - Pre-Proposal Conference Presentation —
SharePoint - Pre-Proposal Conference - List of Registrants.xls XLS spreadsheet
SharePoint - Answers to Questions on Draft SOW.doc DOC document
SharePoint - Registration Form.doc DOC document
SharePoint - SOW_Task Order1.doc DOC document
SharePoint - SOW.doc DOC document
Show all 37

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

SMI-0039-IRM-417-JAW-50097A

December 30, 2004 SMI-0039-IRM-417-JAW-60097B

Enterprise Systems Assurance Plan

ENTERPRISE

SYSTEMS ASSURANCE PLAN

Version 1.2

Task Order No.: 02-SM/I-IRM-417 (OPT 2)

FINAL

December 30, 2004

SMI-0039-IRM-417-JAW-60097B

This page has been intentionally left blank.

i

Enterprise Systems Assurance Plan

Contents

CONTENTS

CHAPTER 1—ENTERPRISE SYSTEMS ASSURANCE OVERVIEW

1-1 Introduction ......................................................................................... 1-1 1-2 Enterprise Systems Assurance Goals .................................................... 1-2 1-3 Key Enterprise Systems Assurance Roles............................................. 1-3 1-4 Enterprise Systems Assurance Activities .............................................. 1-3

CHAPTER 2—ENTERPRISE QUALITY ASSURANCE PLAN

2-1 Enterprise Quality Assurance Overview ............................................... 2-1 2-2 Quality Planning Process ..................................................................... 2-7 2-3 Quality Assurance Process ................................................................... 2-8 2-4 Quality Control Process ....................................................................... 2-9

CHAPTER 3—ENTERPRISE CONFIGURATION MANAGEMENT PLAN

3-1 Enterprise Configuration Management Overview ................................. 3-1 3-2 Configuration Management Baselines .................................................. 3-6 3-3 Enterprise Change Management Process .............................................. 3-8 3-4 Configuration Reviews and Audits ..................................................... 3-12 3-5 Software Release Process ................................................................... 3-14 3-6 Platform-Specific Release Activities .................................................. 3-22 3-7 Critical Release Handling................................................................... 3-27 3-8 Client/Server Application Installation Packaging Reference Guide .... 3-31 3-9 Electronic Library Document Delivery Standards............................... 3-33 3-10 Contract Transition Process................................................................ 3-35

CHAPTER 4—ENTERPRISE REQUIREMENTS MANAGEMENT PLAN

4-1 Enterprise Requirements Management Overview ................................. 4-1 4-2 Requirements Definition and Analysis Process..................................... 4-7 4-3 Requirements Control Process.............................................................. 4-9 4-4 Enterprise Requirements Standards Development Process .................. 4-11 4-5 Enterprise Requirements Maintenance Process................................... 4-11

SMI-0039-IRM-417-JAW-60097B December 30, 2004 ii

Enterprise Systems

Contents

CHAPTER 5—ENTERPRISE DATA MANAGEMENT PLAN

5-1 Enterprise Data Management Overview................................................5-1 5-2 Application Data Model Development Process .....................................5-4 5-3 Application Data Model Consistency Checks .......................................5-7 5-4 Technical Data Architecture Development and Maintenance Process..5-12 5-5 Metadata Management Process ...........................................................5-14

APPENDICES

APPENDIX A—SERENA TRACKER STANDARD FIELDS

APPENDIX B—REFERENCES

APPENDIX C—ACRONYMS AND ABBREVIATIONS

EXHIBITS

CHAPTER 1—ENTERPRISE SYSTEMS ASSURANCE OVERVIEW

Exhibit 1-1: Key Enterprise Systems Assurance Roles ..................................1-3

CHAPTER 2—ENTERPRISE QUALITY ASSURANCE PLAN

Exhibit 2-1: Enterprise Quality Assurance Stakeholder Responsibilities........2-1 Exhibit 2-2: Quality Standards ......................................................................2-5 Exhibit 2-3: Quality Criteria..........................................................................2-6 Exhibit 2-4: Quality Ratings..........................................................................2-7 Exhibit 2-5: Quality Tools.............................................................................2-7 Exhibit 2-6: Quality Planning Process ...........................................................2-8 Exhibit 2-7: Quality Assurance Process.........................................................2-8 Exhibit 2-8: Quality Control Process ...........................................................2-10 Exhibit 2-9: Product Assessment Tasks .......................................................2-12 Exhibit 2-10: Quality Control Reviews..........................................................2-13 Exhibit 2-11: SLM Review Tasks..................................................................2-14 Exhibit 2-12: Enterprise Quality Assurance Audits .......................................2-15 Exhibit 2-13: Audit Tasks .............................................................................2-16 iii

Enterprise Systems Assurance Plan

Contents

CHAPTER 3—ENTERPRISE CONFIGURATION MANAGEMENT PLAN

Exhibit 3-1: Enterprise Configuration Management Stakeholder

Responsibilities ......................................................................... 3-2 Exhibit 3-2: Configuration Management Boards ........................................... 3-3 Exhibit 3-3: Enterprise Configuration Management Documentation.............. 3-4 Exhibit 3-4: Enterprise Configuration Management Tools and Repositories.. 3-6 Exhibit 3-5: Configuration Management Baselines ....................................... 3-6 Exhibit 3-6: Standard System Change Request Lifecycle ............................ 3-10 Exhibit 3-7: TPR Resolution Options.......................................................... 3-12 Exhibit 3-8: Software Release Identification Scheme.................................. 3-15 Exhibit 3-9: Serena Version Manager Scope ............................................... 3-17 Exhibit 3-10: Release Process Flow .............................................................. 3-20 Exhibit 3-11: Release Activities.................................................................... 3-21 Exhibit 3-12: Mainframe Migration Approval Flow...................................... 3-25 Exhibit 3-13: .Information to Include in the Request for Deviation ................ 3-29 Exhibit 3-14: Client/Server Application Installation Packaging Guidelines... 3-31 Exhibit 3-15: Document Delivery Information .............................................. 3-34 Exhibit 3-16: Transition Process ................................................................... 3-37 Exhibit 3-17: Transition Process Responsible Parties.................................... 3-37

CHAPTER 4—REQUIREMENTS MANAGEMENT PLAN

Exhibit 4-1: ICE OCIO Requirements Management Overview ...................... 4-2 Exhibit 4-2: Enterprise Requirements Management ...................................... 4-4 Exhibit 4-3: Enterprise Requirements Management Stakeholder

Responsibilities ......................................................................... 4-5 Exhibit 4-4: Enterprise Requirements Management Standards ...................... 4-6 Exhibit 4-5: Enterprise Requirements Management Tools............................. 4-7 Exhibit 4-6: User Group Charter Process ...................................................... 4-7 Exhibit 4-7: System Concept Development Process ...................................... 4-8 Exhibit 4-8: Requirements Definition Process............................................... 4-9 Exhibit 4-9: Requirements Control Process................................................. 4-10 Exhibit 4-10: Enterprise Requirement Standards Development Process ........ 4-11 Exhibit 4-11: Enterprise Requirements Maintenance Process ........................ 4-12

CHAPTER 5—ENTERPRISE DATA MANAGEMENT PLAN

Exhibit 5-1: Enterprise Data Management..................................................... 5-2 Exhibit 5-2: Enterprise Data Management Stakeholder Responsibilities ....... 5-3 Exhibit 5-3: Technical Data Architecture Standards...................................... 5-4 iv

Enterprise Systems Assurance Plan

Contents

Exhibit 5-4: Enterprise Data Management Tools ...........................................5-4 Exhibit 5-5: Application Logical Data Model Development Process..............5-5 Exhibit 5-6: Application Physical Data Model Development Process ............5-7 Exhibit 5-7: Application Logical Data Model Consistency Check Process.....5-8 Exhibit 5-8: Application Logical Data Model Development and Consistency

Check ........................................................................................5-9 Exhibit 5-9: Application Physical Data Model Consistency Check Process .5-10 Exhibit 5-10: Application Physical Data Model Development and

Consistency Check ..................................................................5-11 Exhibit 5-11: Technical Data Architecture Development and Maintenance

Process ....................................................................................5-12 Exhibit 5-12: ICE Data Model Development .................................................5-13 Exhibit 5-13: Metadata Management Process ................................................5-14

APPENDIX A—SERENA TRACKER STANDARD FIELDS

Exhibit A-1: ICE Standard Fields for Serena Tracker ....................................A-1

Assurance Plan

Chapter 1

CHAPTER 1

ENTERPRISE SYSTEMS ASSURANCE

OVERVIEW

Assurance Plan

Chapter 1

1-1

Enterprise Systems Assurance Plan

Chapter 1

1 ENTERPRISE SYSTEMS ASSURANCE

OVERVIEW

1.1 Introduction

The Enterprise Systems Assurance Plan documents Enterprise Quality Assurance, Enterprise Configuration Management, Enterprise Requirements Management, and Enterprise Data Management policies and procedures so project teams understand how the Immigration and Customs Enforcement (ICE) Office of the Chief Information Officer (OCIO) Technical Architecture Program verifies IT project conformance to the Technical Architecture and adherence to the Technical Architecture standards.

The Enterprise Systems Assurance Plan serves as a “how-to” guide for implementing the System Lifecycle Management (SLM) process.1 The Enterprise Systems Assurance Plan provides instructions for carrying out specific quality assurance (QA), configuration management (CM), requirements management (RM), and data management activities and delineates the responsibilities of these activities for Enterprise Systems Assurance teams and project teams.

This document contains five chapters:

Chapter 1: Enterprise Systems Assurance Overview

Chapter 2: Enterprise Quality Assurance Plan

Chapter 3: Enterprise Configuration Management Plan

Chapter 4: Enterprise Requirements Management Plan

Chapter 5: Enterprise Data Management Plan

As an introduction to Enterprise Systems Assurance, this chapter:

Identifies Enterprise Systems Assurance goals

Defines key Enterprise Systems Assurance roles

Describes Enterprise Systems Assurance activities

The remaining four chapters correspond to the main functional areas within Enterprise Systems Assurance.

1 The ICE System Lifecycle Management Handbook specifies SLM process requirements to which project teams must adhere.

1-2

Enterprise Systems Assurance Plan

Chapter 1

Chapter 2 presents the Enterprise Quality Assurance Plan, which describes how QA is performed within ICE. This plan identifies quality standards; defines quality criteria and quality ratings; describes product assessments and audits; and specifies data to be collected, aggregated, analyzed, and reported. The Enterprise Quality Assurance Plan serves as the QA Plan for IT projects.

Chapter 3 presents the Enterprise Configuration Management Plan, which describes how CM is performed within ICE. This plan specifies CM baselines and configuration items, documents the change control process through which system change requests (SCR) and test problem reports (TPR) are tracked and controlled, and describes CM audits. It also explains the system release process, release numbering scheme, release activities, and critical release handling. The Enterprise Configuration Management Plan serves as the CM Plan for IT projects.

Chapter 4 presents the Enterprise Requirements Management Plan, which describes how requirements management is performed within ICE. This plan identifies Enterprise Requirements Management standards and tools, outlines high-level activities to be performed in defining and analyzing requirements, documents the process followed by ICE OCIO IT Systems to verify adherence of requirements-related documentation to Enterprise Requirements Management standards, and describes how ICE OCIO IT Systems manages enterprise requirements.

Chapter 5 presents the Enterprise Data Management Plan, which describes how data management is performed within ICE OCIO IT Systems. This plan identifies Technical Data Architecture (TDA) standards and tools; outlines activities to be performed by development teams when developing application logical and physical data models, documents the process followed by ICE to verify the consistency of application and physical data models with TDA standards; and describes how ICE manages enterprise logical and physical metadata assets.

1.2 Enterprise Systems Assurance Goals

Enterprise Systems Assurance reduces risks associated with IT projects so that management is confident that they:

Adhere to approved Technical Architecture standards

Adhere to established architecture-related processes and documentation requirements

Conform to the Technical Architecture

1-3

Enterprise Systems Assurance Plan

Chapter 1

1.3 Key Enterprise Systems Assurance

Roles

Exhibit 1-1 delineates the key roles performed by ICE OCIO IT Systems, project teams, and Enterprise Systems Assurance in fulfilling SLM responsibilities.

Exhibit 1-1: Key Enterprise Systems Assurance Roles

Organization Role

ICE OCIO IT Systems Provides technical oversight of IT projects

Project Team Defines, plans, designs, builds, implements, and maintains systems and infrastructure

Enterprise Systems Assurance

Assists and monitors project teams in completing SLM activities and in adhering to SLM process requirements

1.4 Enterprise Systems Assurance

Activities

In support of the ICE OCIO Technical Architecture Program, Enterprise Systems Assurance oversees the implementation and execution of the SLM process in order to verify adherence to the Technical Architecture standards. Enterprise Systems Assurance aligns and integrates with the Architecture Consulting and Engineering (ACE), Architecture Test and Evaluation (T&E), and Application Integration Services (AIS) components in the ICE OCIO Technical Architecture Program and with additional ICE organizations to ensure that the SLM process requirements are applied consistently and impartially.

Enterprise Systems Assurance coordinates and directs the Enterprise Quality Assurance, Configuration Management, Requirements Management, and Data Management activities to ensure that its component activities integrate seamlessly and communicate cohesively with project teams, ICE OCIO IT Systems, and other stakeholders throughout the SLM process. It also supports the ICE OCIO Technical Architecture Program by:

Working with project teams to determine an acceptable work pattern

Interpreting the intent of the SLM process and resolving process ambiguities and questions

Tracking and reporting the status of IT project adherence to Technical Architecture standards

1-4

Enterprise Systems Assurance Plan

Chapter 1

Processing and adjudicating requests for deviation (RFD)

Formulating SLM process improvement initiatives to clarify process ambiguities, rectify process deficiencies, and improve process efficiency

Assurance Plan

Chapter 2

CHAPTER 2

ENTERPRISE QUALITY ASSURANCE

PLAN

Assurance Plan

Chapter 2

2-1 December 30, 2004

Enterprise Systems Assurance Plan

Chapter 2

2 ENTERPRISE QUALITY ASSURANCE PLAN

This chapter presents the Enterprise Quality Assurance Plan, which describes how quality assurance (QA) is performed within ICE. The Enterprise Quality Assurance Plan serves as the QA Plan for IT projects.

2.1 Enterprise Quality Assurance Overview

Enterprise Quality Assurance comprises three key processes: Quality Planning, Quality Assurance, and Quality Control. These processes ensure that IT projects incorporate quality as a key element of project activities.

2.1.1 Enterprise Quality Assurance Stakeholders

Exhibit 2-1 identifies the Enterprise Quality Assurance stakeholders and their responsibilities in performing Enterprise Quality Assurance activities.

Exhibit 2-1: Enterprise Quality Assurance Stakeholder Responsibilities

Enterprise Quality Assurance Stakeholders Responsibilities

ICE OCIO IT Systems Provides management and technical oversight of IT projects

Monitors conformance to Technical Architecture Conducts SLM reviews

Project Team Conforms to Technical Architecture and established quality standards

Conducts peer reviews and walkthroughs Ensures defects and deficiencies are appropriately identified, reported, and resolved Participates in and delivers presentation at SLM reviews

Chapter 2

SMI-0039-IRM-417-JAW-60097B

2-2 December 30, 2004

Exhibit 2-1: Enterprise Quality Assurance Stakeholder Responsibilities (continued)

Enterprise Quality Assurance Stakeholders Responsibilities

Enterprise Quality Assurance Team Assists project teams in navigating and resolving questions about the SLM process

Evaluates, monitors, and measures adherence to SLM process

Coordinates documentation reviews by subject matter experts (SME)

Performs product assessments and documents assessment findings

Performs process and documentation audits and documents audit findings

Schedules, coordinates, and participates in SLM reviews

Prepares and distributes SLM review summary reports Collects, aggregates, analyzes, and reports metrics Formulates process improvement recommendations to rectify process deficiencies identified during audits Maintains quality records

SLM Liaison Facilitates SLM reviews

Architecture Consulting and Engineering Team Evaluates adherence to Technical Architecture Performs design consistency checks and code reviews Participates in SLM reviews

Enterprise Configuration Management Team Monitors adherence to versioning standards and product release standards

Participates in SLM reviews Serves as SME in reviewing Version Description

Document (VDD) and other configuration-related documentation

Prepares client/server application release packages

2-3 December 30, 2004

Enterprise Systems Assurance Plan

Chapter 2

Exhibit 2-1: Enterprise Quality Assurance Stakeholder Responsibilities (continued)

Enterprise Quality Assurance Stakeholders Responsibilities

Requirements and Data Services Evaluates adherence to Enterprise Requirements Management standards and Technical Data Architecture (TDA) standards, including:

► Enterprise Data Naming, Structure, and

Business Rules standards as documented in ICE Data Model

► Requirements Definition Guide ► ICE Modeling Standards ► ICE XML Data Schema Standards

Performs requirements, application logical data model and application physical data model consistency checks

Assists in system and interface requirement and data definition

Participates in SLM reviews Serves as SME in reviewing System Concept of

Operations (ConOps), System Requirements Document (SRD), Requirements Traceability Matrix (RTM), Interface Agreement, Data Management Plan (DMP), Design Document, and other requirements and data-related documentation

Architecture Test and Evaluation (T&E) Ensures defects and deficiencies are appropriately identified and reported

Participates in SLM reviews Serves as SME in reviewing SRD, RTM, System

Workload Analysis Document (SWAD), Design Document, VDD, Development Test Plan, Development Test Analysis Report (TAR), User Manual, Training Plan, and other test-related documentation

Application Integration Services (AIS) Team Evaluates adherence to Web standards Participates in SLM reviews Serves as SME in reviewing SWAD, SDD or DDD, and

Web-related documentation

Security Engineer Evaluates adherence to Office of Information Systems Security Management (OISSM) standards and Certification and Accreditation (C&A) policies and documentation requirements

Assists project teams in preparing and submitting C&A package

Participates in SLM reviews Serves as SME in reviewing security-related documentation and security requirements documented in SRD

Chapter 2

SMI-0039-IRM-417-JAW-60097B

2-4

Exhibit 2-1: Enterprise Quality Assurance Stakeholder Responsibilities

(continued)

Enterprise Quality Assurance Stakeholders Responsibilities

Telecommunications Engineering Evaluates adherence to Telecommunications Engineering standards, including cabling, local area network (LAN), and domain name standards

Serves as SME in reviewing data communication requirements documented in the SRD, SWAD, Design Document, and other design-related documentation

Production Database Team Evaluates adherence to Oracle-based application development standards and IDMS-based application development standards

Participates in SLM reviews Serves as SME in reviewing SWAD, Design Document, Data Conversion Plan, and System Administration and Operations Manual

Reviews all scripts to be executed in production Assists project teams with query tuning

IT Service Delivery Evaluates adherence to Technical Support and Help Desk policies and documentation requirements

Serves as SME in reviewing Design Document, other design-related documentation, VDD, and System Administration and Operations Manual

Training Services Evaluates adherence to training policies and documentation requirements

Serves as SME in reviewing Training Plan and User Manual

2-5 December 30, 2004

Enterprise Systems Assurance Plan

Chapter 2

2.1.2 Quality Standards

Exhibit 2-2 identifies key quality standards; however, this list of quality standards is not exhaustive. The Quality Standards listed in Exhibit 2-2 are available in the Electronic Library at http://documents.ice.dhs.gov/worksite, under Systems Development Governance Documents. Follow the Electronic Library login process to access these documents.

Exhibit 2-2: Quality Standards

Quality Standard Description

Cabling Standards Standards for material, infrastructure, design, installation, and certification of structured cabling systems in support of LANs and voice connectivity

Domain Name System (DNS) Standards

Standards for ICE DNS, including structured naming convention for ICE and an efficient name resolution for intranet or Web applications

Enterprise Data Naming, Structure, and Business Rules Standards

Enterprise standards for data naming, structures, and specifications for the enterprise data requirements, which are documented in the ICE Data Model

ICE Modeling Standards Standards for developing application logical and physical data models in order to provide a consistent level of readability, quality, and documentation across all data models

ICE Standards Profile Set of profiles defining Technical Architecture standards that support services and processes articulated in the Technical Reference Manual (TRM)

ICE XML Data Schema Standards

Standards for developing application XML data schema

IDMS-based Application Development Standards

Standards for developing an IDMS-based application

Local Area Network (LAN) Standards

Standards for LAN materials, infrastructure, design, and installation

Office of Information Systems Security Management (OISSM)

Standards for certifying and accrediting systems and infrastructure are conceived, designed, and implemented with adequate security measures and adhere to established security policies

Oracle-based Application Development Standards

Standards for developing an efficient Oracle-based application to be hosted on the ICE Enterprise Oracle Relational Database Management System

(RDBMS)

Product Release Standards Standards for releasing enterprise client/server, Web, and mainframe applications; infrastructure commercial off-the-shelf (COTS) applications; and baseline desktop and server images into the production environment

Product Release Standards documented in Chapter 3 of the Enterprise Systems Assurance Plan

Chapter 2

SMI-0039-IRM-417-JAW-60097B

2-6

Exhibit 2-2: Quality Standards (continued)

Quality Standard Description

Requirements Definition Guide Standard for defining, documenting, tracing, and managing requirements and for producing requisite requirements documentation

SLM Process Process that IT projects follow when planning, designing, building, testing, implementing, and maintaining systems

Versioning Standards Standards for identifying and controlling lifecycle products Versioning standards and tools documented in Chapter 3 of the Enterprise

Systems Assurance Plan

Web Standards Standards for creating and maintaining Web pages; policies for Web content, management, and graphics; and standards for publishing online content

2.1.3 Quality Criteria

Exhibit 2-3 defines the criteria against which the quality of products and process results are evaluated during assessments and audits to determine product or process result acceptability.

Exhibit 2-3: Quality Criteria

Quality Criteria Description

Complete Product is complete and includes the appropriate level of detail. Process tasks are completed.

Compliant Product and process tasks meet applicable standards and requirements.

Consistent Product maintains consistency within itself and with related external products.

Traceable Product fulfills its allocated requirements.

Timeliness Process activities and tasks are performed as scheduled and project team is ready.

Expectedness Expected process outputs and results are achieved.

Integrity Process inputs are defined and are correct versions.

2.1.4 Quality Ratings

Exhibit 2-4 defines the quality ratings applied to assessment and audit results. The quality ratings are based on the significance of the deficiency within the context of the particular item, the product, and the project as a whole.

2-7 December 30, 2004

Enterprise Systems Assurance Plan

Chapter 2

Exhibit 2-4: Quality Ratings

Quality Rating Definition

Low Applies to content and formatting issues that do not have a direct impact on the reader’s ability to understand the item. This rating may apply to non-conformance to SLM templates or pertinent content applied in an inappropriate document section. Minor issues can be resolved in a timeframe convenient to the project team, usually during the next planned release or revision of a document.

Medium Applies to content that detracts from the reader’s ability to comprehend the item and how the project will address it. Medium issues typically do not prevent formal acceptance of a deliverable; however, resolving medium severity deficiencies improves product quality and clarity while increasing deliverable value and reducing project risk.

High Applies to content that impacts the scope of the project. Failure to revise and address appropriately may introduce significant risk to the project that negatively impacts the ability of the project to meet cost, schedule and/or quality objectives. High severity deficiencies must be resolved for the deliverable to fulfill its intent, achieve acceptance and meet documentation standards.

2.1.5 Quality Tools

Exhibit 2-5 identifies quality records associated with product assessments and SLM reviews.

Exhibit 2-5: Quality Tools

Quality Tool Description

Product Assessment Schedule Schedule used to track progress and state of product assessment

Product Assessment Checklist Tool used to guide product assessment of material submitted

Enterprise Quality Assurance Assessment Log

Contains deficiency data identified during product assessments, including defect identifier, defect description, affected deliverable, date initiated, date closed, status (open, withdrawn, or closed), and product criteria affected (completeness, adherence, consistency, or traceability)

Product Assessment Report Report provided to project team upon completion of product assessment

Product Assessment Correspondence

Includes sent and received e-mail messages related to product assessment

2.2 Quality Planning Process

Quality Planning lays out how quality is to be implemented in a system or infrastructure project. Within Enterprise Quality Assurance, the Quality Planning Process ensures that quality is addressed at the beginning of and throughout the project, rather than as an afterthought when formal reviews and audits take place.

Exhibit 2-6 identifies Quality Planning inputs, activities, and outputs.

Chapter 2

SMI-0039-IRM-417-JAW-60097B

2-8 December 30, 2004

Exhibit 2-6: Quality Planning Process

Quality Planning Inputs Quality Planning Activities Quality Planning Outputs

Quality standards

Statement of Work

System Lifecycle Management Handbook

Enterprise Systems Assurance Plan

Architecture Test and Evaluation Plan

Technical Architecture Guidebook

Tailor work pattern1

Determine relevant quality standards2

Determine project QA activities to ensure that IT project conforms to quality standards3

Document relevant quality standards and QA activities in the PMP3

Tailored Work Pattern4

Notes:

1 The project team coordinates with the Enterprise Quality Assurance team in tailoring a work pattern.

2 Enterprise Quality Assurance team determines quality standards that are relevant for the IT project.

3 The project team performs this activity.

4 The Tailored Work Pattern must be approved by the ICE OCIO Systems Assurance Manager.

2.3 Quality Assurance Process

The Quality Assurance Process comprises quality activities performed by the project team. These activities include peer reviews, walkthroughs, product assessments, process audits, and defect identification, reporting, and resolution.

Exhibit 2-7 identifies QA inputs, activities, and outputs.

Exhibit 2-7: Quality Assurance Process

Quality Assurance Inputs Quality Assurance Activities Quality Assurance Outputs

Tailored work pattern SLM Checklist Design Assessment Guidelines Quality standards

Conduct peer reviews and walkthroughs

Perform product assessments and process audits to ensure conformance to quality standards

Identify, report, and resolve defects and deficiencies

Participate in SLM reviews Process activities such as submitting to the library

Peer review, assessment, and audit findings

Corrective action recommendations

SCR

Test Problem Reports (TPR)

2-9 December 30, 2004

Enterprise Systems Assurance Plan

Chapter 2

2.4 Quality Control Process

Quality Control monitors and measures the quality of process activities and results.

Within Enterprise Quality Assurance, the Quality Control Process ensures that IT projects adhere to quality standards. This process comprises quality activities performed by the Enterprise Quality Assurance team. These activities include product assessments; process audits; process performance monitoring; metrics collection, aggregation, analysis, and reporting; process improvement recommendations; quality records maintenance; and coordination with other teams. The Enterprise Quality Assurance team is supported by SMEs who provide required technical expertise during product assessments and quality control document reviews.

Exhibit 2-8 identifies Quality Control inputs, activities, and outputs.

Chapter 2

SMI-0039-IRM-417-JAW-60097B

2-10 December 30, 2004

Exhibit 2-8: Quality Control Process

Quality Control Inputs Quality Control Activities Quality Control Outputs

Project documentation

Project checklists

Assessment checklists

Audit checklists

Design assessment review guidelines

SLM review agendas and guidelines

Quality standards

Coordinate documentation reviews1

Perform documentation reviews2

Document review findings1

Perform requirements verification checks and document findings3

Perform application logical and physical data model consistency checks and document findings3

Perform design consistency checks and document findings4

Perform code reviews and document findings5

Assess products2

Participate in SLM reviews

Prepare and distribute SLM review summary reports1

Perform process and documentation audits1

Monitor status of IT projects and their adherence to SLM process1

Collect, aggregate, analyze, and report metrics1

Identify process deficiencies and recommend process improvements

Maintain quality records1

Documentation review reports

Product assessment reports

Review summary reports

Audit reports

Metrics reports

IT project status report

Assessment and audit trends

Notes:

1 Enterprise Quality Assurance performs this activity.

2 Enterprise Quality Assurance and appropriate subject matter experts (SME) perform this activity.

3 Requirements and Data Services performs this activity.

4 Architecture Consulting and Engineering (ACE) and Requirements and Data Services perform this activity.

5 ACE, Requirements and Data Services, and Application Integration Services (AIS) perform these activities.

2-11 December 30, 2004

Enterprise Systems Assurance Plan

Chapter 2

2.4.1 Product Assessments

The Enterprise Quality Assurance team inspects SLM products identified as entry criteria for a particular SLM review before the review takes place. The ICE OCIO Systems Assurance Manager relies on product assessments to ensure that products are complete and conform to established standards and specifications.

During product assessments, the Enterprise Quality Assurance team and SMEs use pre-defined, product-specific checklists to determine product acceptability. Products are assessed for completeness, adherence, consistency, and traceability.2 The product assessment checklists include two categories:

Yes–product meets defined criteria

No–product does not adhere to defined criteria

Identified deficiencies are assigned a quality rating of low, medium, or high3 based on the significance of the deficiency within the context of the particular item, the product, and the project as a whole. Failure of project teams to resolve product deficiencies might delay the project from proceeding to the subsequent SLM phase.

The Enterprise Quality Assurance team maintains product assessment schedules, product assessment reports, deficiency data, and assessment-related correspondence as quality records.

Exhibit 2-9 identifies the tasks performed by the Enterprise Quality Assurance team, SMEs, the ICE OCIO Systems Assurance Manager, and project team during product assessments.

2 Complete, compliant, consistent, and traceable are the four product-related quality criteria defined in Exhibit 2-3.

3 Exhibit 2-4 defined the three quality ratings (low, medium, high) assigned to deficiencies identified during product assessments.

Chapter 2

SMI-0039-IRM-417-JAW-60097B

2-12 December 30, 2004

Exhibit 2-9: Product Assessment Tasks

Key Stakeholder Product Assessment Tasks

Enterprise Quality Assurance Analyst

Identifies products for assessment Coordinates product assessment schedule with project team and SMEs to ensure that Electronic Library has received product and to negotiate lead time needed to inspect product based on project type, size, complexity, and schedule

Inspects product Prepares product assessment report based on review of SMEs Delivers product assessment report

Subject Matter Expert (SME) Inspects product and rates identified deficiencies Documents assessment findings Submits product assessment findings to Enterprise Quality Assurance analyst

ICE OCIO Systems Assurance Manager

Reviews product assessment report as appropriate Forwards product assessment report as appropriate

Project Team Corrects identified product deficiencies before the SLM review is held Submits updated products to Electronic Library Notifies Enterprise Quality Assurance Analyst that updated products have been submitted to Electronic Library

2.4.2 Quality Control Reviews

Quality Control reviews occur within the framework of the SLM process. These reviews provide technical and management oversight of IT projects to ensure adherence to quality standards.

Exhibit 2-10 identifies the types of Quality Control reviews.

2-13 December 30, 2004

Enterprise Systems Assurance Plan

Chapter 2

Exhibit 2-10: Quality Control Reviews

Quality Control Reviews Description

Documentation Reviews Performed by subject matter experts (SME), documentation reviews evaluate project documentation for adherence to Technical Architecture standards and adherence to document template content specifications.

Documentation reviews differ from product assessments in that the Enterprise Quality Assurance team does not coordinate these reviews.

Instead, the relevant Technical team coordinates the documentation review schedule with the project team, provides the project team with documented review findings, and meets with the project team to resolve any issues identified during the documentation review. Product assessments typically occur before an SLM review to determine acceptability of review entry criteria, whereas documentation reviews occur within the framework of technical guidance provided by SMEs when assisting project teams with completing required SLM activities and adhering to Technical Architecture standards.

Requirements Verification Performed by Requirements and Data Services, requirements verification verifies that requirement-related documentation conforms to Enterprise Requirements Management standards.

Enterprise Requirements Management Plan (Chapter 4) explains how requirements verification is conducted and clarifies project team and Requirements and Data Services responsibilities during requirements verification.

Application Logical Data Model Consistency Checks

Performed by Requirements and Data Services, application logical data model consistency checks verify that the application logical data model is consistent with the ICE Data Model and ICE Modeling Standards.

Enterprise Data Management Plan (Chapter 5) explains how application logical data model consistency checks are conducted and clarifies project team and Requirements and Data Services responsibilities during these consistency checks.

Application Physical Data Model Consistency Checks

Performed by Requirements and Data Services, application physical data model consistency checks verify that the application physical data model is consistent with the application logical data model and standards.

Enterprise Data Management Plan (Chapter 5) explains how application physical data model consistency checks are conducted and clarifies project team and Requirements and Data Services responsibilities during these consistency checks.

Code Reviews Code reviews verify that the application code complies with the Technical Architecture standards and that applications will operate effectively and efficiently within the existing infrastructure.

Code reviews evaluate XML data schema and application code for adherence to Technical Architecture standards.

SLM Reviews SLM reviews serve as key checkpoints to ensure that the technical results of phase activities are formally reviewed, that all SLM phase exit criteria have been satisfied, that required products have been determined to be acceptable, that any remaining non-critical open issues are identified and documented, and that formal approval is documented for project to successfully conclude review and enter subsequent phase.

SLM reviews are not held until all required deliverables identified as exit criteria have been delivered to the Electronic Library and have been found acceptable.

Exhibit 2-11 identifies the SLM review tasks performed by key review stakeholders.

Chapter 2

SMI-0039-IRM-417-JAW-60097B

2-14 December 30, 2004

Exhibit 2-11: SLM Review Tasks

Key Stakeholder SLM Review Tasks

Project Team Submits project deliverables identified as review entry criteria to Electronic Library

Notifies Enterprise Quality Assurance Analyst that required project deliverables have been submitted to Electronic Library

Corrects identified product deficiencies before SLM review is held Submits updated products to Electronic Library Notifies Enterprise Quality Assurance Analyst that updated products have been submitted to Electronic Library Prepares presentation to be delivered during SLM review Participates in SLM reviews

Enterprise Quality Assurance Analyst

Coordinates the assessment of each required project deliverable and performs product assessment tasks as specified in Exhibit 2-9

Attends SLM reviews Prepares SLM review summary reports and forwards reports to the ICE

OCIO Systems Assurance Manager Submits SLM review summary reports to Electronic Library

Subject Matter Expert (SME) Performs product assessment tasks as specified in Exhibit 2-9

ICE OCIO Systems Assurance Manager

Performs product assessment tasks as specified in Exhibit 2-9 Reviews documented summary findings and approves SLM review summary report before delivery to Electronic Library

Enterprise Quality Assurance Project Coordinator

Schedules SLM reviews Prepares and distributes review agendas

SLM Liaison Facilitates SLM reviews

Concurrers Concurs that all review exit criteria have been satisfied

Approval Authority Signs review approval certification certifying that review exit criteria have been satisfied

2-15

Enterprise Systems Assurance Plan

Chapter 2

2.4.3 Audits

The Enterprise Quality Assurance team performs audits of process activities and documentation to evaluate the timely completion of process activities and tasks, the achieved results against expected results, and the integrity of process inputs. The Enterprise Quality Assurance team usually coordinates audits in advance with the project team; however, process audits may occasionally occur at unscheduled intervals when requested by the ICE OCIO Systems Assurance Manager. One business day notification will precede an unscheduled process audit. The ICE OCIO Systems Assurance Manager relies on audits to ensure that project teams are adhering to process requirements and are performing process activities and developing required documentation according to process specifications.

During audits, the Enterprise Quality Assurance team uses pre-defined, process-specific checklists to audit process activities and tasks for timeliness, realized process outputs and results against projected outputs and results, and process inputs for integrity.3 The audit checklists include two categories:

Yes—task or product meets defined criteria

No—task or product does not adhere to defined criteria

Identified deficiencies are assigned a quality rating of low, medium, or high based on the significance of the deficiency within the context of the particular item, the activity or product, and the project as a whole.5 Failure of project teams to resolve identified deficiencies might delay the project from proceeding to the subsequent SLM phase.

The Enterprise Quality Assurance team maintains completed audit checklists, audit reports, deficiency data, and audit-related correspondence as quality records.

Exhibit 2-12 defines the types of Quality Control audits performed by the Enterprise Quality Assurance team.

Exhibit 2-12: Enterprise Quality Assurance Audits

Quality Control Audits Description

Process Audit Evaluates project adherence to SLM process activities

Documentation Audit Evaluates adherence to SLM documentation

4 Timeliness, Expectedness, and Integrity are the three process-related quality criteria defined in Exhibit 2-3.

5 Exhibit 2-4 defines the three quality ratings (low, medium, high) assigned to deficiencies identified during audits.

2-16 December 30, 2004

Enterprise Systems Assurance Plan

Chapter 2

Exhibit 2-13 identifies the audit tasks performed by the Enterprise Quality Assurance team, the ICE OCIO Systems Assurance Manager, and project team during audits.

Exhibit 2-13: Audit Tasks

Key Stakeholder Audit Tasks

Enterprise Quality Assurance Analyst

Identifies process activities or documentation products to be audited Coordinates audit with project team Performs audit and rates identified deficiencies Documents audit findings in audit checklist Records deficiencies identified during audit in Enterprise Quality

Assurance Audit Log Prepares audit report Submits audit report to the ICE OCIO Systems Assurance Manager Updates Enterprise Quality Assurance Status Log Tracks resolution of identified deficiencies and updates Enterprise Quality

Assurance Audit Log to reflect deficiency resolution Maintains records resulting from audits as quality records

ICE OCIO Systems Assurance Manager

Reviews audit report and forwards report to project team to resolve identified deficiencies

Project Team Corrects identified deficiencies and submits any updated products to Electronic Library

Notifies Enterprise Quality Assurance Analyst that updated products have been submitted to Electronic Library

2.4.4 Process Performance Monitoring

The Enterprise Quality Assurance team tracks the status of system projects in the SLM process and compiles data in an IT Project Status Report.

Chapter 3

December 30, 2004 SMI-0039-IRM-417-JAW-60097B

CHAPTER 3

ENTERPRISE CONFIGURATION

MANAGEMENT PLAN

Chapter 3

3-1

Enterprise Systems Assurance Plan

Chapter 3

3 ENTERPRISE CONFIGURATION

MANAGEMENT PLAN

This chapter presents the Enterprise Configuration Management Plan, which describes how configuration management (CM) is performed within ICE. The Enterprise Configuration Management Plan specifies CM baselines and configuration items, documents the change control process through which system change requests (SCR) and test problem reports (TPR) are tracked and controlled, and describes CM audits. This plan also explains the system release process, release numbering scheme, release activities, and critical release handling. The Enterprise Configuration Management Plan serves as the CM Plan for IT projects.

3.1 Enterprise Configuration Management

Overview

CM governs the integrity and control of system products throughout the SLM process.

It involves identifying the configuration items at the appropriate lifecycle phase, systematically controlling changes to these items, and maintaining the integrity and traceability of these items throughout the project lifecycle.

3.1.1 Enterprise Configuration Management Stakeholders

Exhibit 3-1 identifies the Enterprise Configuration Management stakeholders and delineates their responsibilities in performing CM-related activities.

3-2

Enterprise Systems Assurance Plan

Chapter 3

Exhibit 3-1: Enterprise Configuration Management Stakeholder Responsibilities

Enterprise Configuration Management Stakeholders Responsibilities

ICE OCIO IT Systems Provides management and technical oversight of systems and IT projects

Monitors conformance to Technical Architecture

Development Team Assigns unique identifiers to configuration items Identifies and labels all system configuration items Maintains list of all configuration items Maintains accurate lists of the required CM baselines Documents and tracks all SCRs Uses OCIO-provided standard CM tools in the manner for which they are approved Places all system code (source, executable, database scripts, configuration files, and so forth) in the OCIO code repository

Delivers all formal documentation deliverables to the Electronic Library

Enterprise Configuration Management Team Establishes Enterprise Configuration Management Standards

Administers Enterprise Configuration Management Tools

Administers the Electronic Library Develops and delivers training on using CM tools and

Enterprise Configuration Management standards Validates what is placed in CM Delivers application code to production teams Supports the operation of the Technical Architecture

Program Change Control Board (CCB)

Production Support Team Installs and maintains systems, system updates, and operational environment

Maintains lists of baseline configurations in the server environments

Uses CM tools and repositories approved as enterprise standards in the manner for which they have been approved

3-3

Enterprise Systems Assurance Plan

Chapter 3

3.1.2 Configuration Management Boards

Formal review boards shall be established at the development project level to support configuration management activities on a task order. There are three review boards for each system: the Customer Review Board (CRB), the Project Internal Review Board (PIRB), and the Change Control Board (CCB). Each of these boards shall be chartered and minutes shall be generated for each meeting and placed into the Electronic Library.

This process ensures that all changes are properly identified, documented, and approved before implementation. Project CM staff is responsible for ensuring that this process is followed. Exhibit 3-2 identifies the CM boards and delineates their responsibilities and membership.

Exhibit 3-2: Configuration Management Boards

Board Responsibilities Membership

Customer Review Board

Reviews all SCRs Screens all proposed changes and eliminates from consideration any requests that have little or no chance of ever being approved

Ensures that the Government maintains control over all work, investigative or otherwise, that the development team may consider

Approves the requirements of the request

Screens all new SCRs for clarity and completeness of requirements

Approves all SCRs which merit investigation by the PIRB

Disapproves all SCRs which do not merit future consideration by the PIRB

Chaired by the IT project manager

May also consist of just the system owner or IT project manager, or may consist of a more formal structure, depending upon the system

Smaller systems may handle this step in ways that better suit their particular systems. A simple review of proposed changes by an IT project manager, before the development team evaluates them, is sufficient.

Project Internal Review Board

Investigates and evaluates all proposed SCRs, assesses their feasibility, and provides a recommendation and estimated cost (expressed in terms of hours necessary to code, test, and implement the changes)

Possesses no authority to approve or disapprove SCRs.

The PIRB makes a recommendation, either positive or negative, for each SCR. This is forwarded, with commentary, to the CCB.

Screens all new SCRs for clarity and completeness

Develops a cost associated with proposed changes

Updates Serena Tracker with all information discovered during development team research

Makes a recommendation to the project CCB as to whether the change should be approved or disapproved

Chaired and staffed by members of the development team

3-4

Enterprise Systems Assurance Plan

Chapter 3

Exhibit 3-2: Configuration Management Boards (continued)

Board Responsibilities Membership

Change Control Board

This is the start of the file's text. The full file is on GovTribe.

File details come from the government source that posted it. Updated .