A knowledge base article about Managed System Support Service-Level Agreement (SLA) provided by the UC Berkeley IT Service Hub - Knowledge Portal
General Overview
This document describes what is provided by Berkeley IT (bIT) Platform Infrastructure (PI) as part of managed operating system support packages, including operating system maintenance, costs, communication, security, incident response, Customer and Service Provider responsibilities, and other related details.
Purpose of Agreement
This Service Level Agreement (SLA) defines the services and Support Package service levels provided by bIT Platform Infrastructure Team to its Customers. Eligible Customers are the units, departments, and colleges internal to the University of California, Berkeley, or any UC campus. This SLA is designed to cover service related terms and conditions, costs, roles and responsibilities, and provides a framework for communication, problem escalation, and service resolution.
Length of Agreement
Support Packages are provided on a month-to-month basis and will continue until either party terminates. The agreement begins when the requested service is provisioned and will automatically renew each month. Support Packages may be canceled for the next period with a minimum of two business days advance notice.
Billing Cycle
Customers will be billed monthly at the beginning of each month. Any billing questions should be directed to istbill@berkeley.edu. Credits and Charges cannot exceed sixty (60) days retroactively by University policy.
Service Description
Platform Infrastructure offers standards-based, professionally managed Linux and Windows systems administration for virtual machines in the Platform Infrastructure Virtual Private Server (VPS) environment. Support services include (but are not limited to) server hardening, capacity planning, installation, configuration, security patching and updating, troubleshooting, monitoring, firewall configuration, load balancer configuration, documentation, and assistance with implementation of a data backup strategy that meets the business requirements for the Customer. Any services provided outside the scope of this SLA are subject to an additional fee. Under normal circumstances, the Platform Infrastructure staff is available during business hours.
Rates and Fees
Current recharge rates and fees for any associated service offerings can be located in the System Support & Consultation section of the Information Technology Rates page: https://technology.berkeley.edu/rates
Hours of Coverage
- Business hours are defined as 8:00a - 5:00p, Monday through Friday, excluding University holidays.
- Service Requests will be addressed during business hours only.
- Incident resolution on Standard Support systems will be addressed during business hours.
- Incident resolution on Extended Support systems will be addressed 24 hours a day, 7 days a week.
Key Metrics
Platform Infrastructure (PI) strives for a goal of a 99.99% uptime. Below are defined priorities and expected response times based on Impact and Urgency:
- Initial Response Times for an Incident:
- Priority 1 (Critical) - 1 hour - Phone call required for immediate assistance on critical issues (reference Customer Communications section below)
- Priority 2 (High) - 4 hours (reference Customer Communications section below)
- Initial Response Time for a Service Request is 4 business hours.
- First follow-up after an initial evaluation is 1 business day.
- Responses to priority requests or incidents may delay responses to other requests.
- When it is necessary to escalate a problem to other teams for resolution, PI cannot guarantee the response times of the other teams. PI will act as the lead resolution contact point for cases that require support from other teams.
- Follow-ups to incidents and service requests will be sent as needed.
Priority Assignment
- Impact: Campus loss and potential damage (e.g. financial, student/faculty/staff, regulatory, security, reputation, brand) caused by the incident:
- Low - Impacts a single department or person, no substantial impact
- Medium - Impacts multiple departments / people, some impact
- High - Impacts campus or systemwide service, major impact
- Urgency: The speed at which the business expects the incident to be resolved:
- Low - "As time allows"
- Medium - "Sooner is better than later"
- High - "ASAP"
Matrix of choices aligning priority of issue to impact and urgency
Priority
|
Impact
|
|
1 - High
|
2 - Medium
|
3 - Low
|
Urgency
|
1 - High
|
1 - Critical
|
2 - High
|
3 - Moderate
|
|
2 - Med
|
2 - High
|
3 - Moderate
|
4 - Low
|
|
3 - Low
|
3 - Moderate
|
4 - Low
|
5 - Planning
|
Service Request and Incident Communications
A Service Request is any request made by a Customer to the bIT Platform Infrastructure team for routine operational support.
An Incident refers to an outage or degradation of the normal function of the server or service where it is severely malfunctioning.
To make a Service Request or report an Incident, the Customer must create a ticket in the ServiceNow ticketing system and provide information that the request is for a Managed Server Support customer, and include the server name (if known). Any of the following methods are appropriate for submitting a Service Request or reporting an Incident:
- Create a ticket by sending an email:
- Create a ticket by submitting through the ServiceNow portal:
- Go to https://berkeley.service-now.com/itservicehub
- Select “Report an Issue”
- Fill out the form, selecting "Server System Administration (xx)" for "Affected Service" where xx is the style of server you need support for.
- Submit form.
- Create a ticket by contacting the IT Service Desk by phone:
- Call 510-664-9000
- Ask to assign this request to “bIT Unix” or “bIT Windows” as appropriate, or follow prompts for after-hours support.
- NOTE: It is advised to call the Service Desk directly when creating "Priority 1" or "Priority 2" incidents, as this will provide the quickest response.
If an extended system support package has been purchased, the Service Desk can be contacted outside of regular business hours for Incidents only. Be sure to provide the customer name, department, specification that this is for a Managed Server Support customer, and include the server name (if known). This information will allow the operators to properly escalate the call to the appropriate support team.
During normal business hours, Service Requests will be responded to within four (4) hours after initial notification to the Service Provider. Service Request changes will be performed during normal business hours. Requests placed after normal business hours may not be responded to until the following business day. If an Incident or Service Request is not responded to with the response times outlined above, the Customer may escalate by directly contacting their assigned Platform Infrastructure technical/functional contact, Platform Infrastructure account manager or the ITCS Help Desk. Please refer to the ticket number when escalating.
Incidents reported after normal business hours may not be addressed until the following business day. After-hours requests for support and emergency support will be fulfilled on a best-effort basis.
Should there be a dispute about services rendered, escalations can be requested by the Customer directly to the management of Platform Infrastructure Services.
Customer Communications
Depending on the request, one or more of the following methods may be used for communication:
- Distribution Lists for Unix/Linux and Windows service announcements
- Change Advisory Board announcements
- E-Mail
- ServiceNow tickets
- Phone
- Slack messaging
- System Status Dashboard
Customers are responsible for providing updated contact information when technical or functional owners change. Failure to do so may cause delays in service.
Routine Maintenance
Because the central IT environment is regularly upgraded to allow for growth and change in the use of information technology, the Customer should expect routine maintenance to be scheduled periodically in order to comply with new standards and upgrades. bIT will notify the Customer when such work is needed. Growth or change initiated by the Customer may warrant a Service Review of their current environment. Please make note that maintenance work may cause service disruptions. Service outages are published to the bIT system status page at Status Dashboard.
Data Backups
By default, systems are enrolled in the UCBackup service and are backed up daily. Customers may request specific inclusions/exclusions of their data in these backups.
Business Continuity and Disaster Recovery
By default, Platform Infrastructure does not provide a solution for Business Continuity or Disaster Recovery solutions. Platform Infrastructure can work with customers on an application-by-application basis to develop a plan specific to the needs of the customer if required. For further clarification, please refer to the IS-12 requirements associated with the specific application in question.
Security Standards
Platform Infrastructure refers to the Minimum Security Standards for Electronic Information (MSSEI) when assigning Security Controls on Managed Systems. Please see the bIT Policy website for more information on minimum security standards (Information Security Office).
As defined in the Roles and Responsibilities Policy, each Customer is the IT Resource Proprietor, and is expected to use their professional judgment in managing risks to the information and systems they use and/or support in partnership with the relevant Institutional Information Proprietor(s). As a Service Provider for the systems, bIT Platform Infrastructure will make recommendations based on the customer-identified data classification and risk assessment. Platform Infrastructure will work with the Information Security Office to implement Customer approved solutions to protect the data.
Responsibilities and Expectations
bIT Platform Infrastructure:
- Includes one hour of consultation to gather requirements and provide a cost estimate for the initial service engagement.
- Offers server provisioning and operating system management.
- Operating system patches are reviewed for their criticality as they are released.
- Routine patches are applied on a consistent basis in order to minimize server outages.
- Security patches deemed critical may be applied outside the predefined maintenance window or patching schedule.
- bIT Platform Infrastructure will not be responsible for any application failure, downtime or issues resulting from these mandatory updates.
- Provides operating system technical support and problem resolution.
- Provides patch management only for software installed by the systems support teams. bIT Platform Infrastructure will install, support, and patch the operating system of each server under this SLA.
- Maintains server security in accordance with the policies governing UC Berkeley Information Technology resources.
- Assists with server lifecycle management. The deployment platform for all new servers is a virtual machine running on the bIT Private Cloud Service. The virtual machine specifications will be established based upon recommendations from the application vendor and bIT server administrators.
- Implements a data backup strategy that meets the business requirements for the Customer.
- Provides basic system performance monitoring, network monitoring, and troubleshooting. Operational monitoring is provided for all managed systems.
- Standard Support monitoring is configured to alert during standard business hours.
- Extended Support monitoring is configured to alert 24x7.
- Maintains bSecure network firewall configuration (for VMs located behind managed firewalls.)
- Maintains network Load Balancer configuration, if applicable, (for VMs located behind PI-managed load balancers.)
- Coordinates with other bIT Departments and 3rd party vendors as needed.
- Provides best effort application deployment. Platform Infrastructure will provide initial assistance in setting up applications to the point of proper functioning. Platform Infrastructure does not provide ongoing application support or development.
- Log changes to any server configuration.
- Perform planned maintenance on a scheduled basis during the maintenance window agreed upon by Platform Infrastructure and the Customer.
- Provide the Customer contact with notification of any service disruptions and emergency maintenance as soon as feasible.
- OS user accounts are only provided to individuals with active UC Berkeley Affiliations and CalNet accounts.
In order to protect the interests and assets of the University of California Berkeley, bIT may be required to render services beyond those described in this document. Such additional support is provided at the discretion of University senior management with Customer consultation. This work may result in additional charges.
The Customer:
- Acts as the IT Resource Proprietor of their data, and must categorize that data according to University requirements while working with the Institutional Information Proprietor(s).
- Is responsible for the installation, configuration, maintenance, patching, upgrades, licensing, and security of their installed applications. Any assistance from bIT required to meet these obligations may involve a Time and Materials (hourly) charge.
- Is required to perform application testing for all patches, upgrades, and database changes in a timely manner.
- Is responsible for notifying their own application users and/or Service Desk of any service interruptions or outages, as appropriate.
- Is required to provide up to date contact information. 24x7 support requires 24x7 contacts.
- Is responsible for approving access to the system resources and application data.
- Is responsible for promptly notifying PI when OS user account access or permissions should be changed due to UC Berkeley Affiliation expiration or changes.
- Is responsible for providing a Technical/Functional Contact to assist in troubleshooting issues.
- Is responsible for providing an Information Security Contact and responding to ISO alerts with regard to their application.
- Is responsible for providing a designated Billing Contact.
- The customer is responsible for specifying the IS-3 Protection, IS-3 Availability, and IS-12 Recovery levels (or N/A) of their applications, and notifying PI immediately if this changes.
- The Customer must register applications hosting restricted data in the Socreg Asset Registration Portal.
- Is responsible for complying with all campus computer use and security policies. bIT reserves the right to shut down or isolate any server that is found to be out of date, vulnerable, or compromised.
- Will provide prompt payment and provisioning of appropriate chartstring (please note: chartstrings or “COAs” are required to request provisioning of services.)
- Will respond to Platform Infrastructure staff inquiries in a timely manner.
- Will consult with Platform Infrastructure before making hardware or software purchases related to supported systems.
- Should anticipate Operating System re-platforming every 3-5 years.
- Will work with the Information Security Office to submit and maintain accurate System Security Plan(s) and allow PI to review the SSP(s) for technical accuracy.
- Is solely responsible for submitting security exceptions to ISO if PI staff makes the customer aware of vulnerabilities during routine support efforts.
- Will work with the bIT Business Continuity team to meet IS-12 requirements, if applicable, and will allow PI to review the IS-12 plans for technical accuracy.