06 - FSA NARA Universal Electronic Records Management Requirements v2.03.xlsx
XLSX spreadsheet 84 KB Posted
- Attached to
- Request for Information: Award Eligibility Determination Federal contract opportunity
- Solicitation number
- Not on record
- Issued by
- Department of Education
About this file
This Request for Information from the Department of Education seeks industry input on capabilities to support the Award Eligibility Determination system. The AED system will modernize the Central Processing System, which currently processes Federal Student Aid applications to calculate Expected Family Contribution. The RFI requests information to support a total system redesign that would receive applicant data from the Free Application for Federal Student Aid and other federal systems. Key capabilities of interest include a modernized system to intake applicant data and determine financial aid eligibility. The RFI is issued for planning purposes only and does not represent a commitment to procure any services described. Responses will inform potential future procurement actions related to the Award Eligibility Determination system modernization.
View the file
Other files for this federal contract opportunity
| File | Type | Posted |
|---|---|---|
| 01 - Award Eligibility Determination Requirements_REVISED PER CE.pdf | ||
| 02 - Pricing Template.xlsx | XLSX spreadsheet | |
| 07 - Hosting Environments w Approved ATOs.pdf | ||
| 09 - FSA Current State.pdf | ||
| AED RFI Final.pdf | ||
| 03 - Security Technical Requirements.xlsx | XLSX spreadsheet | |
| 08 - FSA Identity Access Mgt Solution Overview.docx | DOCX document | |
| 10 - AED Draft SLAs.xlsx | XLSX spreadsheet | |
| 12 - CPS 101 with FA impacts 09102020.pdf | ||
| 11 - ED CSF Risk Scorecard Overview_July 2020.pdf | ||
| 05 - Hosting Environments with Approved Agency ATOs.pdf | ||
| 04 - Additional Current State Technical Constraints.xlsx | XLSX spreadsheet |
Show all 12
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
Change Log
| Version | Change Number | Section | Requirement ID | Change Description |
| 1 | Version 1 released by NARA August 4, 2017. | |||
| 2 | Version 2 released by NARA on April 6, 2020. Posted updated versions to fix numbering. | |||
| 2 | 001 | Abstract | Revised Abstract to clarify what the Universal ERM Requirements are and how they should be used. | |
| 2 | 002 | Abstract | Updated Abstract with a link to guidance on classified records. | |
| 2 | 003 | Abstract | Updated GSA schedule language on Consolidated Multiple Award Schedules. | |
| 2 | 004 | Lifecycle Requirements | 0.03; 0.06 | Combined 0.03 and 0.06 into 0.05. Renumbered subsequent requirements. |
| 2 | 005 | Lifecycle Requirements | 1.02 | Updated requirement, "A record is considered reliable if it ensures a full and accurate representation of the transactions or activities." |
| 2 | 006 | Lifecycle Requirements | 1.08 | Removed 1.08 as it was a duplicate requirement. Renumbered subsequent requirements. |
| 2 | 007 | Lifecycle Requirements | 2.02 | Added a new requirement and authoritatives sources to address FOIA. New 2.02: "Records should be managed in a manner that allows the searches to be saved for the purposes of supporting sufficiency of search under FOIA." |
| 2 | 008 | Lifecycle Requirements | 2.07 | Added a new requirement 2.07, "Agencies should have a records sustainability plan to maintain records over time." For more information, see: https://github.com/usnationalarchives/digital-preservation/blob/master/Digital%20Audio%20Formats/NARA_PreservationActionPlan_DigitalAudio_20190801.pdf |
| 2 | 009 | Lifecycle Requirements | 2.19 | Added a new requirement 2.19: "Records must be managed in a manner to support export of records to facilitate access processing under the FOIA or for the purposes of proactive release." |
| 2 | 010 | Lifecycle Requirements | 2.21 | Added a new requirement 2.21: "Agencies should have the ability to configure workflows based on an organization’s business process rules and transactional data, without custom programming." |
| 2 | 011 | Lifecycle Requirements | 2.23 | Added a new requirement 2.23: "The records system must allow agencies to identify and categorize any records considered essential." |
| 2 | 012 | Lifecycle Requirements | 3.05 | Updated language. |
| 2 | 013 | Lifecycle Requirements | 0.06; 1.09; 2.01; 2.18; 2.20; 3.01; 3.02; 3.03; 3.04; 4.04; 5.06 | Updated authorities with "must have" requirements that pointed to "Requirements Working Group" to a regulation citation. |
| 2 | 014 | Lifecycle Requirements | 6.02; 6.03 | Changed requirements from "must have" to "should have". |
| 2 | 015 | Transfer Format Requirements | TF.26 | Added the calendar format to the "Transfer Format Requirements" tab. |
| 2 | 016 | Glossary | Updated definition of Shared Drives in the glossary tab to include SharePoint and Google Drive as examples of shared drives. | |
| 2 | 017 | Glossary | Added digital preservation language into the definition for Maintain & Use into the Glossary. | |
| 2 | 018 | Glossary | Updated terms and definitions to align with those cited in NARA regulations or policy. Added definition sources. |
Abstract Universal Electronic Records Management Requirements, Version 2
The National Archives and Records Administration's (NARA) Requirements Working Group (RWG) created the Universal Electronic Records Management (ERM) Requirements to:
| 1. provide standards for agencies and existing Shared Services functional areas to manage their electronic records; |
| 2. help vendors determine capabilities for their ERM tools; |
| 3. help agencies identify the best tools to procure for their needs. |
The requirements have six sections based on the lifecycle of electronic records management. Please refer to the Glossary tab for their definitions.
| 1. Capture |
| 2. Maintenance and Use |
| 3. Disposal |
| 4. Transfer |
| 5. Metadata |
| 6. Reporting |
These requirements address born digital electronic records. The requirements are either “program” requirements, relating to the design and implementation of an agency’s ERM policies and procedures, or “system” requirements, providing technical guidance to vendors in creating ERM tools and specifications for agencies to consider when procuring them. Users of this document can filter on "program" or "system" requirements as needed. This could be helpful in finding a list of requirements a system needs to manage electronic records.
The requirements are either mandatory (“Must Have”) or preferred (“Should Have”). These designations help vendors determine what functions their tools must perform, as opposed to those that are ideal. “Must Have” and “Should Have” requirements also help agencies prioritize procurement of these ERM tools according to their needs and financial priorities.
While automation is not required, agencies should make it a goal to automate their processes as much as possible.
If a record type is not listed, review all of the requirements.
The requirements apply to electronic records and not the services used to manipulate records.
The requirements represent cross-cutting perspectives from multiple Federal agencies. Vendors on GSA’s Electronic Records Management Schedule must self-certify they meet these requirements to be added to the procurement offerings. Agencies should consider it an authoritative source when making purchasing decisions.
NARA's Electronic Records Management Federal Integrated Business Framework (ERM-FIBF) is based on these requirements. The Business Lifecycle and Business Capabilities, Use Cases, and Standard Data Items of the FIBF describe the requirements in more detail.
| Note: For classified records, see https://www.archives.gov/files/isoo/policy-documents/isoo-implementing-directive.pdf. | |||
| Version | Date | Change Description | Author of Change |
| 1 | 8/4/17 | First released. | NARA |
| 2 | 4/6/20 | Incorporated feedback from agencies and NARA. Posted on April 6, 2020. | NARA |
| 2.01 | 4/20/20 | Fixed an error in the Version 2 posted on April 6, 2020. | NARA |
| 2.02 | 5/14/20 | Fixed a numbering error in the Version 2.01. | NARA |
&A For Official Use Only Page &P of https://www.archives.gov/records-mgmt/policy/universalermrequirements Lifecycle Requirements
| Req ID | Requirement Text | Lifecycle Phase | Req Type | Priority | Source | Office Management Applications | Electronic Messages | Social Media | Cloud Services | Websites | Digital Media (Photo) | Digital Media (Audio) | Digital Media (Video) | Structured Data | Shared Drives | Engineering Drawings |
| 0.05 | Agencies must have controls to prevent unauthorized use, alteration, concealment, or deletion of records. Examples of controls include audit trails, access lists, monitoring, and agent validation. | Full Lifecycle | System | Must Have | 36 CFR 1236.10 | X | X | X | X | X | X | X | X | X | X | X |
| 1.01 | A record must be able to provide adequate and proper documentation of agency business for as long as the information is needed. | 1. Capture | System | Must Have | 36 CFR 1236.10 | X | X | X | X | X | X | X | X | X | X | X |
| 1.02 | A record is considered reliable if it ensures a full and accurate representation of the transactions or activities. | 1. Capture | System | Must Have | 36 CFR 1236.10 | X | X | X | X | X | X | X | X | X | X | X |
| 1.03 | A record is considered reliable if it can be depended upon in the course of subsequent transactions or activities. | 1. Capture | System | Must Have | 36 CFR 1236.10 | X | X | X | X | X | X | X | X | X | X | X |
| 1.04 | A records is considered to have integrity if it is complete and protected from unauthorized addition, deletion, alteration, use, and concealment. | 1. Capture | System | Must Have | 36 CFR 1236.10 | X | X | X | X | X | X | X | X | X | X | X |
| 1.05 | A record is considered usable of it can be located, retrieved, presented, and interpreted. | 1. Capture | System | Must Have | 36 CFR 1236.10 | X | X | X | X | X | X | X | X | X | X | X |
| 1.06 | An authentic record is considered authoritative evidence of a transaction or event; records are authentic if they are what they claim to be. | 1. Capture | System | Must Have | ISO 15489-1:2016, Section 5.2 Records | X | X | X | X | X | X | X | X | X | X | X |
| 1.07 | A record must be authentic to be considered authoritative evidence of a transaction or event; records are authentic if they are created or sent by the agent claiming to have created or sent it. | 1. Capture | System | Must Have | ISO 15489-1:2016, Section 5.2 Records | X | X | X | X | X | X | X | X | X | X | X |
| 1.08 | Once a record has been captured into a records system, all events and actions related to the record by person entities and non-person entities must be documented on an on-going basis. | 1. Capture | System | Must Have | ISO 15489-1:2016, Section 9.5 Access control | X | X | X | X | X | X | X | X | X | X | X |
| 1.09 | All records must be associated with the approved records schedules that pertain to each record. | 1. Capture | System | Must Have | 36 CFR 1236.20 | X | X | X | X | X | X | X | X | X | X | X |
| 2.01 | Records of current and former employees must be managed in a manner that supports searching in response to information requests, including FOIA and agency business needs. | 2. Maintain & Use | System | Must Have | 5 U.S.C. § 552 (a)(3); Department of Justice Guide to the Freedom of Information Act Procedural Requirements | X | X | X | X | X | X | X | X | X | X | X |
| 2.05 | Any actions changing the level of access, altering the record, or changing the location of the record must be documented and tracked into an audit log. | 2. Maintain & Use | System | Must Have | ISO 15489-1:2016, Section 5.2 Records | X | X | X | X | X | X | X | X | X | X | X |
| 2.23 | The records system must allow agencies to identify and categorize any records considered essential. | 2. Maintain & Use | System | Must Have | 36 CFR 1223.16 | |||||||||||
| 3.01 | Electronic records must be disposed of in a manner that protects any sensitive, proprietary, or national security information. Any recording media previously used for electronic records containing sensitive, proprietary, or national security information must not be reused if the previously recorded information can be compromised in any way by reuse of the media. | 3. Disposal | System | Must Have | 36 CFR 1226.24 | X | X | X | X | X | X | X | X | X | X | X |
| 4.04 | During records migration, all records and associated metadata in the originating system must be retained until the migration is complete and the destination system has been deemed reliable and secure. | 4. Transfer | System | Must Have | ISO 15489-1:2016, Section 9.8 Migrating and converting records | X | X | X | X | X | X | X | X | X | X | X |
| 5.01 | Metadata for a record must consist of information recording (1) the description of the content of the record; (2) the structure of the record (form, format, and relationships between record components); (3) the business context in which the record was created; (4) relationships with other records and metadata; (5) identifiers and other information needed to retrieve the record; (6) the business actions and events involving the record throughout its existence. | 5. Metadata | System | Must Have | ISO 15489-1:2016, Section 5.2 Records | X | X | X | X | X | X | X | X | X | X | X |
| 5.02 | Records systems must define metadata to (1) enable the identification and retrieval of records; (2) associate records with changing business rules, policies, and mandates; (3) associate records with agents, and their authorizations and rights with regards to the records; (4) associate records with their business activities; (5) track processes carried out on records. | 5. Metadata | System | Must Have | ISO 15489-1:2016, Section 8.2 Metadata schemas for records | X | X | X | X | X | X | X | X | X | X | X |
| 5.03 | Metadata to manage records must be in one of six categories: (1) Identity - information identifying the record; (2) Description - information determining the nature of the record; (3) Use - information facilitating immediate and longer-term record use; (4) Event plan - information used to manage the record, such as disposition information; (5) Event history - information recording past events on the record and its metadata; (6) Relation - information describing the relationship between the record and other records. | 5. Metadata | System | Must Have | ISO 15489-1:2016, Section 8.2 Metadata schemas for records | X | X | X | X | X | X | X | X | X | X | X |
| 5.05 | Once the record has been captured, the associated metadata must be fixed and kept as transactional evidence. The metadata includes a unique identifier, author, date of creation, and relationships with other records. | 5. Metadata | System | Must Have | ISO 15489-1:2016, Section 9.3 Capturing records | X | X | X | X | X | X | X | X | X | X | X |
| 5.06 | When migrating records, all metadata must be preserved and accompanied with the transfer. | 5. Metadata | System | Must Have | 36 CFR 1236.12 | X | X | X | X | X | X | X | X | X | X | X |
| 5.07 | Permanent records transfers to NARA must include the following metadata elements: File Name, Record ID, Title, Description, Creator, Creation Date, Rights. Metadata elements such as Coverage and Relation must also be provided if they apply to the records being transferred. | 5. Metadata | System | Must Have | NARA Bulletin 2015-04: Metadata Guidance | X | X | X | X | X | X | X | X | X | X | X |
| 5.08 | When transferring permanent records to NARA, agencies must provide the metadata elements as an index in a machine-readable CSV file. Agencies must notify NARA if there are additional metadata provided with the transferred permanent records. | 5. Metadata | System | Must Have | NARA Bulletin 2015-04: Metadata Guidance | X | X | X | X | X | X | X | X | X | X | X |
| 6.01 | Agencies must have the ability to generate reports demonstrating effective controls and compliance. | 6. Reporting | System | Must Have | 36 CFR 1220.18 | X | X | X | X | X | X | X | X | X | X | X |
| 2.02 | Records should be managed in a manner that allows the searches to be saved for the purposes of supporting sufficiency of search under FOIA. | 2. Maintain & Use | System | Should Have | 5 U.S.C. § 552 (a)(3); Department of Justice Guide to the Freedom of Information Act Procedural Requirements | X | X | X | X | X | X | X | X | X | X | X |
| 2.03 | Access rights and permission rules for records should be adjusted to coincide with changes to the legal/regulatory environment, to business activities, or to the structure of the organization. | 2. Maintain & Use | System | Should Have | ISO 15489-1:2016, Section 9.5 Access control | X | X | X | X | X | X | X | X | X | X | X |
| 2.04 | Access rights and permission rules for records should be based on the function, activity, or business process related to the records. This allows for changes to be made to the organization without affecting the access and permission rules. | 2. Maintain & Use | System | Should Have | ISO 15489-1:2016, Section 8.4 Access and permission rules | X | X | X | X | X | X | X | X | X | X | X |
| 2.21 | Agencies should have the ability to configure workflows based on an organization’s business process rules and transactional data, without custom programming. | 2. Maintain & Use | System | Should Have | ISO 15489-1:2016, Section 5.3 Records Systems | X | X | X | X | X | X | X | X | X | X | X |
| 2.22 | The records system should allow users to perform a full-text search of a record’s content. | 2. Maintain & Use | System | Should Have | 36 CFR 1236.20 | X | X | X | X | X | X | X | X | X | X | X |
| 6.02 | The records system should provide the ability to design and generate customized reports. | 6. Reporting | System | Should Have | ISO 15489-1:2016, Section 6.4 Monitoring and evaluation | X | X | X | X | X | X | X | X | X | X | X |
| 6.03 | The records system should provide the ability to print reports that are legible, professional in appearance, and usable for an agency's official business purposes. | 6. Reporting | System | Should Have | ISO 15489-1:2016, Section 6.4 Monitoring and evaluation | X | X | X | X | X | X | X | X | X | X | X |
| 6.04 | The records system should provide the ability to filter and sort report data based on the values contained in any field or column. | 6. Reporting | System | Should Have | ISO 15489-1:2016, Section 6.4 Monitoring and evaluation | X | X | X | X | X | X | X | X | X | X | X |
| 6.05 | The records system should provide the ability to schedule the delivery of reports, and to distribute them to a specified list of recipients. | 6. Reporting | System | Should Have | ISO 15489-1:2016, Section 6.4 Monitoring and evaluation | X | X | X | X | X | X | X | X | X | X | X |
| 6.06 | The records system should provide users the ability to design and run ad hoc reports using any information for which they have been granted access. | 6. Reporting | System | Should Have | ISO 15489-1:2016, Section 6.4 Monitoring and evaluation | X | X | X | X | X | X | X | X | X | X | X |
| The records system should provide the ability to save the configurations of ad hoc reports for reuse. | 6. Reporting | System | Should Have | ISO 15489-1:2016, Section 6.4 Monitoring and evaluation | X | X | X | X | X | X | X | X | X | X | X | |
| 0.01 | Agencies must manage all electronic records including all recorded information, regardless of form or characteristics, made or received by a Federal agency as evidence of the organization, functions, policies, decisions, procedures, operations, or other activities of the US Government. | Full Lifecycle | Program | Must Have | 44 USC 3301 | X | X | X | X | X | X | X | X | X | X | X |
| 0.04 | Agencies retain responsibility for managing their electronic records, regardless of whether they reside in a public, private, or community cloud; a contracted environment; or under the agency's physical control. | Full Lifecycle | Program | Must Have | NARA Bulletin 2010-05: Cloud Computing | X | ||||||||||
| 0.06 | Agencies must be responsible for monitoring changes to third-party terms of service that may affect the management of records. | Full Lifecycle | Program | Must Have | ISO 15489-1:2016, Section 6.4 Monitoring and evaluation | X | X | X | X | X | X | X | X | X | X | X |
| 1.10 | Agencies are responsible for identifying what kind of social media output constitutes a federal record, and capturing those records appropriately. | 1. Capture | Program | Must Have | NARA Bulletin 2014-02: Social Media | X | ||||||||||
| 1.12 | Agencies must analyze existing records schedules to determine if social media records are covered, and if not, develop an appropriate schedule. | 1. Capture | Program | Must Have | NARA Bulletin 2014-02: Social Media | X | ||||||||||
| 1.13 | Any agency business conducted through electronic messaging accounts are considered Federal records and must be captured within 20 days. | 1. Capture | Program | Must Have | NARA Bulletin 2015-02: Electronic Messages | X | ||||||||||
| 2.06 | Records must be usable for as long as needed to conduct agency business. | 2. Maintain & Use | Program | Must Have | 36 CFR 1236.14 | X | X | X | X | X | X | X | X | X | X | X |
| 2.08 | Ensuring usability of records means determining if the retention period for any records is longer than the life of the system where they are currently stored. | 2. Maintain & Use | Program | Must Have | 36 CFR 1236.14 | X | X | X | X | X | X | X | X | X | X | X |
| 2.09 | Ensuring usability of records includes converting records to usable formats and maintaining the link between the records and their metadata through the conversion process. | 2. Maintain & Use | Program | Must Have | 36 CFR 1236.14 | X | X | X | X | X | X | X | X | X | X | X |
| 2.10 | Ensuring usability of records includes planning for the migration of records to a new system before the current system is retired. | 2. Maintain & Use | Program | Must Have | 36 CFR 1236.14 | X | X | X | X | X | X | X | X | X | X | X |
| 2.11 | Ensuring usability of records includes ensuring that migration of records addresses non-active electronic records stored off-line. | 2. Maintain & Use | Program | Must Have | 36 CFR 1236.14 | X | X | X | X | X | X | X | X | X | X | X |
| 2.12 | Ensuring usability of records includes carrying out system upgrades of hardware and software while maintaining the functionality and integrity of the electronic records created in them. | 2. Maintain & Use | Program | Must Have | 36 CFR 1236.14 | X | X | X | X | X | X | X | X | X | X | X |
| 2.13 | If their cloud provider discontinues services, agencies must continue to meet their records management responsibilities by migrating the records to another system or repository. | 2. Maintain & Use | Program | Must Have | NARA Bulletin 2010-05: Cloud Computing | X | ||||||||||
| 2.14 | The system receiving the migrated records must have appropriate security and records management controls in place to manage the records throughout the entire lifecycle, including preventing the unauthorized access or disposal of records. | 2. Maintain & Use | Program | Must Have | NARA Bulletin 2010-05: Cloud Computing | X | ||||||||||
| 2.15 | Agency personnel must have proper authorization before removing Federal records from government custody. | 2. Maintain & Use | Program | Must Have | NARA Bulletin 2013-03: Protecting Records | X | X | X | X | X | X | X | X | X | X | X |
| 2.16 | Agency personnel must obtain approval from a designated official of the agency, such as the Agency Records Officer or General Counsel, before removing extra copies of records or other non-record materials from government custody. | 2. Maintain & Use | Program | Must Have | 36 CFR 1222.18 | X | X | X | X | X | X | X | X | X | X | X |
| 2.17 | Agencies must contact NARA of any actual, impending, or threatened unlawful removal, defacing, alteration, corruption, deletion, erasure, or other destruction of records in the custody of the agency. | 2. Maintain & Use | Program | Must Have | 44 USC 3106 (a) | X | X | X | X | X | X | X | X | X | X | X |
| 2.18 | Agencies must continuously review their records schedules to determine if changes to their use of technology affects the value of the records in question. | 2. Maintain & Use | Program | Must Have | 36 CFR 1225.22 | X | X | X | X | X | X | X | X | X | X | X |
| 2.19 | Records must be managed in a manner to support export of records to facilitate access processing under the FOIA or for the purposes of proactive release. | 2. Maintain & Use | Program | Must Have | 5 U.S.C. § 552 (a)(2) | X | X | X | X | X | X | X | X | X | X | X |
| 2.20 | Agencies must continuously review their records schedules to determine if changes to their business processes affects the value of the records in question. | 2. Maintain & Use | Program | Must Have | 36 CFR 1225.22 | X | X | X | X | X | X | X | X | X | X | X |
| 3.02 | Agencies must control any proposed deletion of records pursuant to existing records schedules. | 3. Disposal | Program | Must Have | 36 CFR 1226.10 | X | X | X | X | X | X | X | X | X | X | X |
| 3.03 | All records must be covered by a NARA-approved disposition authority. This includes using existing records schedules, creating new schedules, or using an applicable GRS. | 3. Disposal | Program | Must Have | 36 CFR 1226.10 | X | X | X | X | X | X | X | X | X | X | X |
| 3.04 | If a suspend-disposition authority or legal hold is issued, the disposition of approved records must cease immediately. The approved records will remain suspended until a revocation order lifts the authority. Once the authority is lifted, the disposition of approved records can continue. | 3. Disposal | Program | Must Have | 36 CFR 1226.18 | X | X | X | X | X | X | X | X | X | X | X |
| 3.06 | Once the circumstances pertaining to the extended retention of records are no longer applicable, agencies must destroy the records in accordance with the records schedule. | 3. Disposal | Program | Must Have | 36 CFR 1226.18 | X | X | X | X | X | X | X | X | X | X | X |
| 4.01 | Agencies must transfer documentation adequate to identify, service, and interpret the permanent electronic records. | 4. Transfer | Program | Must Have | 36 CFR 1235.48 | X | X | X | X | X | X | X | X | X | X | X |
| 4.02 | Agencies must transfer electronic records in a format that is independent of specific hardware or software. | 4. Transfer | Program | Must Have | 36 CFR 1235.50 | X | X | X | X | X | X | X | X | X | X | X |
| 4.03 | Agencies using an email system that identifies users by codes or nicknames, or identifies addressees only by the name of a distribution list, must include information with the transfer-level documentation to ensure identification of the sender and addressee(s). | 4. Transfer | Program | Must Have | Email Management Success Criteria | X | ||||||||||
| 4.05 | Agencies must be able to identify and preserve permanent records regardless of format or location for transfer to NARA, when appropriate. | 4. Transfer | Program | Must Have | 36 CFR 1236.14 | X | X | X | X | X | X | X | X | X | X | X |
| 4.06 | Agencies must disable passwords or other forms of file-level encryption that prevent access to records before transferring permanent records to NARA. | 4. Transfer | Program | Must Have | NARA Bulletin 2014-04: Format Guidance | X | X | X | X | X | X | X | X | X | X | X |
| 4.07 | Agencies must retain a copy of all permanent electronic records transferred to NARA until receiving official notification that NARA has accepted legal custody of the records. | 4. Transfer | Program | Must Have | 36 CFR 1235.44(a) | X | X | X | X | X | X | X | X | X | X | X |
| 4.08 | Agencies must transfer permanent records to NARA in accordance with their records retention schedules. Generally, permanent records are transferred between 15 and 30 years after their creation or receipt. | 4. Transfer | Program | Must Have | NARA Bulletin 2015-01: Age of Records | X | X | X | X | X | X | X | X | X | X | X |
| 4.09 | Agencies must transfer permanent records to NARA in accordance with the preferred and acceptable file formats outlined in the "Transfer Formats" section of the ERM LoB Requirements Collection. The "Transfer Formats" section is current as of 3/21/2017. | 4. Transfer | Program | Must Have | NARA Bulletin 2014-04, Appendix A: Table of File Formats | X | X | X | X | X | X | X | X | X | X | X |
| 5.04 | The metadata for a record must be protected from unauthorized deletion, and must be retained or destroyed in accordance with the record's retention schedule. | 5. Metadata | Program | Must Have | ISO 15489-1:2016, Section 5.2 Records | X | X | X | X | X | X | X | X | X | X | X |
| 0.02 | Agencies should monitor and review access rights and permission rules for electronic records regularly; these access rights and permission rules should be updated on a regular basis. | Full Lifecycle | Program | Should Have | ISO 15489-1:2016, Section 8.4 Access and permission rules | X | X | X | X | X | X | X | X | X | X | X |
| 0.03 | Agencies should regularly monitor and evaluate their records controls. | Full Lifecycle | Program | Should Have | ISO 15489-1:2016, Section 6.4 Monitoring and evaluation | X | X | X | X | X | X | X | X | X | X | X |
| 1.11 | Agencies should establish a Social Media Working Group to handle the special demands of managing federal records created through social media. | 1. Capture | Program | Should Have | NARA Bulletin 2014-02: Social Media | X | ||||||||||
| 2.07 | Agencies should have a records sustainability plan to maintain records over time. | 2. Maintain & Use | Program | Should Have | 36 CFR 1236.14; 36 CFR 1236.20 | X | X | X | X | X | X | X | X | X | X | X |
| 3.05 | Agencies may retain records approved for destruction beyond the period outlined in the records schedule if the records in question pertain to a court order, executive order, law, or approved business justification. | 3. Disposal | Program | Should Have | 36 CFR 1226.18 | X | X | X | X | X | X | X | X | X | X | X |
| 5.09 | Records can represent more than one business activity and therefore can be assigned to more than one record category. | 5. Metadata | Program | Should Have | RMSC Functional Requirements | X | X | X | X | X | X | X | X | X | X | X |
NARA Universal Electronic Records Management Requirements Page &P
Transfer Format Requirements
| Req ID | Requirement Text | Lifecycle Phase | Req Type | Priority | Source | Office Management Applications | Electronic Messages | Social Media | Cloud Services | Websites | Digital Media (Photo) | Digital Media (Audio) | Digital Media (Video) | Structured Data | Shared Drives | Engineering Drawings |
| TF.01 | Agencies must transfer CAD records to NARA in the following file formats: preferred file formats are (1) X3D, and (2) STEP; acceptable file formats are (1) PDF/E, (2) U3D, and (3) PRC. | 4. Transfer | System | Must Have | NARA Bulletin 2014-04, Appendix A: Table of File Formats | X | ||||||||||
| TF.02 | Agencies must transfer Digital Audio records to NARA in the following file formats: preferred file formats are (1) BWF, and (2) FLAC; acceptable file formats are (1) AIFF, (2) MP3, and (3) Wave. | 4. Transfer | System | Must Have | NARA Bulletin 2014-04, Appendix A: Table of File Formats | X | ||||||||||
| TF.03 | Digital Audio records must be transferred at a minimum of 16 bits per sample, but 24 bits per sample is preferred. Digital Audio records should also be transferred at a sample rate of at least 44.1 KHz, but a sample rate of 96 KHz is preferred. | 4. Transfer | System | Must Have | NARA Bulletin 2014-04, Appendix A: Table of File Formats | X | ||||||||||
| TF.04 | Agencies must transfer Digital Cinema records to NARA in the following file formats: preferred file formats are (1) DPX. | 4. Transfer | System | Must Have | NARA Bulletin 2014-04, Appendix A: Table of File Formats | X | ||||||||||
| TF.05 | Agencies must transfer Digital Video records to NARA in the following file formats: acceptable file formats are (1) AVI, (2) MOV, (3) WMV, (4) MPEG 4, (5) MPEG2, and (6) MXF. | 4. Transfer | System | Must Have | NARA Bulletin 2014-04, Appendix A: Table of File Formats | X | ||||||||||
| TF.06 | Agencies must transfer Digital Photograph records to NARA in the following file formats: preferred file formats are (1) TIFF; acceptable file formats are (1) JFIF with JPEG compression, (2) DNG, (3) PNG, and (4) JP2. | 4. Transfer | System | Must Have | NARA Bulletin 2014-04, Appendix A: Table of File Formats | X | ||||||||||
| TF.07 | Agencies must transfer Scanned Text records to NARA in the following file formats: preferred file formats are (1) TIFF, (2) JP2, (3) PNG, and (4) PDF/A; acceptable file formats are (1) JFIF with JPEG compression, (2) GIF, and (3) PDF/A-2. | 4. Transfer | System | Must Have | NARA Bulletin 2014-04, Appendix A: Table of File Formats | X | ||||||||||
| TF.08 | For Scanned Text records, Bitonal images must be transferred at 300-600 ppi, with 600 ppi preferred; Gray scale must be scanned at 300-400 ppi, with 400 ppi preferred; Color must be scanned at 300-400 ppi, with 400 ppi preferred. | 4. Transfer | System | Must Have | NARA Bulletin 2014-04, Appendix A: Table of File Formats | X | ||||||||||
| TF.09 | Agencies must transfer Digital Poster records to NARA in the following file formats: preferred file formats are (1) TIFF, (2) JP2, (3) PNG, and (4) PDF/A; acceptable file formats are (1) JFIF with JPEG compression, and (2) GIF. | 4. Transfer | System | Must Have | NARA Bulletin 2014-04, Appendix A: Table of File Formats | X | ||||||||||
| TF.10 | For Digital Poster records, Bitonal images must be transferred at 300-600 ppi, with 600 ppi preferred; Gray scale must be scanned at 300-400 ppi, with 400 ppi preferred; Color must be scanned at 300-400 ppi, with 400 ppi preferred. | 4. Transfer | System | Must Have | NARA Bulletin 2014-04, Appendix A: Table of File Formats | X | ||||||||||
| TF.11 | Agencies must transfer Geospatial records to NARA in the following file formats: preferred file formats are (1) Geo TIFF, (2) GML, (3) TIGER, and (4) KML; acceptable file formats are (1) VPF, (2) ESRI ARC/INFO, TerraGo Geospatial PDF, (3) ESRI Shapefile, and (4) SDTS (imminent transfer format). | 4. Transfer | System | Must Have | NARA Bulletin 2014-04, Appendix A: Table of File Formats | |||||||||||
| TF.12 | Agencies must transfer Presentation records to NARA in the following file formats: preferred file formats are (1) ODP, and (2) PDF/A-1; acceptable file formats are (1) PPT, (2) PPTX, and (3) PDF/A-2. | 4. Transfer | System | Must Have | NARA Bulletin 2014-04, Appendix A: Table of File Formats | X | ||||||||||
| TF.13 | Agencies must transfer Textual Data records to NARA in the following file formats: preferred file formats are (1) ASCII Text, (2) Unicode Text, (3) ODF, (4) PDF/A-1, and (5) PDF/A-2; acceptable file formats are (1) PDF, (2) DOCX, and (3) DOC. | 4. Transfer | System | Must Have | NARA Bulletin 2014-04, Appendix A: Table of File Formats | X | ||||||||||
| TF.14 | Agencies must transfer Structured Data records to NARA in the following file formats: preferred file formats are (1) CSV, (2) ODS, (3) ASCII Text, (4) JSON, and (5) XML; acceptable file formats are (1) MS Excel Office Open XML, (2) XLS, and (3) EBCDIC (imminent transfer format). | 4. Transfer | System | Must Have | NARA Bulletin 2014-04, Appendix A: Table of File Formats | X | ||||||||||
| TF.15 | Data files or databases must be transferred as flat files or rectangular tables. All records in a database, or rows in a relational database, must have the same logical format. Each data element within a record must contain only one data value, and each record must not contain nested repeating groups of data items. | 4. Transfer | System | Must Have | NARA Bulletin 2014-04, Appendix A: Table of File Formats | X | ||||||||||
| TF.16 | Structured data must be transferred together with any associated files necessary to verify the validity of the data, such as DTDs, schemas, or data dictionaries. | 4. Transfer | System | Must Have | NARA Bulletin 2014-04, Appendix A: Table of File Formats | X | ||||||||||
| TF.17 | Agencies must transfer Email records to NARA in the following file formats: preferred file formats are (1) EML, and (2) MBOX; acceptable file formats are (1) XML, and (2) MSG. | 4. Transfer | System | Must Have | NARA Bulletin 2014-04, Appendix A: Table of File Formats | X | ||||||||||
| TF.18 | Agencies must transfer aggregations of Email records to NARA in the following file formats: preferred file formats are (1) PST, and (2) MBOX. | 4. Transfer | System | Must Have | NARA Bulletin 2014-04, Appendix A: Table of File Formats | X | ||||||||||
| TF.19 | Agencies must transfer Web records to NARA in the following file formats: acceptable file formats are (1) WARC, and (2) ARC. | 4. Transfer | System | Must Have | NARA Bulletin 2014-04, Appendix A: Table of File Formats | X | ||||||||||
| TF.20 | Web records must be accessible via HTTP from a server to a client browser when a URL has been activated. | 4. Transfer | System | Must Have | NARA Bulletin 2014-04, Appendix A: Table of File Formats | X | ||||||||||
| TF.21 | Web content records that share a domain name including content managed under format agreement and residing on another site must be transferred together. | 4. Transfer | System | Must Have | NARA Bulletin 2014-04, Appendix A: Table of File Formats | X | ||||||||||
| TF.22 | All component parts of web content records that have been appraised as permanent including image, audio, video, and all other proprietary formats, must be transferred in a manner that maintains all of the original links, functionality, and data integrity. | 4. Transfer | System | Must Have | NARA Bulletin 2014-04, Appendix A: Table of File Formats | X | ||||||||||
| TF.23 | Web records with dynamic content such as calendars or databases must be transferred in an acceptable format, or be made accessible as static content. | 4. Transfer | System | Must Have | NARA Bulletin 2014-04, Appendix A: Table of File Formats | X | ||||||||||
| TF.24 | Web records must include all internally referenced URLs when transferred to NARA. | 4. Transfer | System | Must Have | NARA Bulletin 2014-04, Appendix A: Table of File Formats | X | ||||||||||
| TF.25 | Web records must maintain all control information from the harvesting protocol. | 4. Transfer | System | Must Have | NARA Bulletin 2014-04, Appendix A: Table of File Formats | X | ||||||||||
| TF.26 | Agencies must transfer calendar records to NARA in iCalendar / iCal (ICS). | 4. Transfer | System | Must Have | NARA Bulletin 2014-04, Appendix A: Table of File Formats | X | X |
&A For Official Use Only Page &P of
Glossary
| Lifecycle Phase | Definition | Source |
| Capture | The process of placing an object under records management control for disposition and access purposes. Objects are not necessarily moved from the system they reside in when they are captured. Records can be imported from other sources, manually entered into the system, or linked to other systems. | 36 CFR 1236.20 |
| Maintain & Use | The process of managing records through their most active stage. This includes ensuring records are migrated and transformed as systems change, so the records remain usable. Digital preservation is particularly important for permanent records that will eventually be transferred to NARA. | 36 CFR 1222.26 |
| Disposal | The process of disposing of records scheduled for destruction. Records that meet these conditions are destroyed in accordance with their records retention schedule according to 36 CFR 1226.24 and methods such as those outlined in NIST Special Publication 800-88. Electronic records scheduled for destruction must be disposed of in a manner that ensures protection of any sensitive, proprietary, or national security information. | 36 CFR 1226.24 |
| Transfer | The process of transferring records that have been scheduled as permanent to the National Archives of the United States. This includes records that have been scheduled as permanent, records that are designated as permanent in a GRS; and, when appropriate, records that are accretions to holdings (continuations of series already accessioned.) | 36 CFR 1235.10 |
| Metadata | Metadata are elements of information that answer the questions ‘who, what, where, when, and why’ regarding electronic records. Metadata elements provide administrative, descriptive, and technical information that describe the structure and content of electronic records. Metadata elements also provide contextual information that explains how electronic records were created, used, managed, and maintained prior to their transfer to NARA, and how they are related to other records. This information enables NARA to appropriately manage, preserve, and provide access to electronic records for as long as they are needed. Examples include identifier, creator, title, creation date, rights, etc. | NARA Bulletin 2015-04: Metadata Guidance for the Transfer of Permanent Electronic Records |
| Reporting | Generating reports to allow for further analysis and to demonstrate effective controls and compliance. Reports may include search results, records eligible for disposition, audit logs, and other customized or ad hoc reports. | 36 CFR 1220.10 |
| Requirement Type | Definition | Source |
| Program | Program requirements describe controls over the creation, maintenance, and use of records in the conduct of current business in an Agency's Records Management Program implemented by an agency records officer. These requirements help create the proper environment for the successful implementation of an Electronic Records Management System or Solution. | 36 CFR 1220.30 |
| System | System requirements describe the desired features and / or functions of an Electronic Records Management System. These requirements help Agencies select a system or solution that meets the functionalities necessary for electronic recordkeeping. | 36 CFR 1236.20 |
| Key Terms | Definition | Source |
| Agency Personnel | Agency personnel refers to federal employees, contractors, volunteers and others that create, receive, access or use federal records on behalf of the agency. | 36 CFR 1220.18; 36 CFR 1222.32 |
| Record Type | Definition | Source |
| Office Management Applications | Office Management Applications refers to documents created with desktop and cloud applications, such as Microsoft Office, Adobe, or other Office Management software. These documents include word processing documents and presentation formats. | NARA Bulletin 2014-04: Format Guidance for the Transfer of Permanent Electronic Records, Appendix A: Tables of File Formats |
| Electronic Messages | Electronic Messages refers to email messages, instant messages, chat messages, text messages, and voicemail messages that meet the definition of Federal records. | NARA Bulletin 2015-02: Guidance on Managing Electronic Messages |
| Social Media | Social Media refers to messages generated through a social media application that meet the definition of Federal records. Examples of social media applications include Facebook, Twitter, Slack, Pinterest, Google Plus, and Skype, among others. | NARA Bulletin 2014-02: Guidance on managing social media records |
| Cloud Services | Cloud Services refers to technology that allows users to access and use shared data and computing services via the Internet or a Virtual Private Network. It gives users access to resources without having to build infrastructure to support these resources within their own environments or networks. Federal records can reside in a cloud environment hosted by a 3rd party service provider. | NARA Bulletin 2010-05: Guidance on Managing Records in Cloud Computing Environments |
| Websites | Websites refers to (1) web content records, which represent information presented on a website, and (2) website administrative records, which provide evidence of the management and operations of the website. Examples of website records include the following: web page content, dynamic content, scripts, list of URLs referenced by hyperlinks, website design records, etc. | NARA Guidance on Managing Web Records |
| Digital Media (Photo) | Digital Media (Photo) include still photographs of natural, real-world scenes or subjects produced by digital cameras, and scanned images of photographic prints, slides, and negatives that meet the definition of Federal records. These records must also be in the correct file formats according to NARA's transfer guidance. | NARA Bulletin 2014-04: Format Guidance for the Transfer of Permanent Electronic Records, Appendix A: Tables of File Formats |
| Digital Media (Audio) | Digital Media (Audio) encompass formats used to encode recorded sound as machine readable files by converting acoustic sound waves into digital signals that meet the definition of Federal records. Digital audio formats are generally composed of both a wrapper format, usually the common name associated with the file extension, and an encoding method or codec. These records must also be in the correct file formats according to NARA's transfer guidance. | NARA Bulletin 2014-04: Format Guidance for the Transfer of Permanent Electronic Records |
| Digital Media (Video) | Digital Media (Video) refers to digital moving images consist of bitmap digital images or “frames” displayed in rapid succession at a constant rate, giving the appearance of movement. Includes both video digitized from analogue sources and born digital video) that meet the definition of Federal records. These records must also be in the correct file formats according to NARA's transfer guidance. | NARA Bulletin 2014-04: Format Guidance for the Transfer of Permanent Electronic Records |
| Structured Data | Structured data refers to data that is stored in defined fields. Categories for structured data include database formats, spreadsheets, statistical data that is the result of quantitative research and analysis, and scientific data collected by instrumentation tools during the scientific process. | NARA Bulletin 2014-04: Format Guidance for the Transfer of Permanent Electronic Records, Appendix A: Tables of File Formats |
| Shared Drives | Shared Drives, also known as network drives, refer to managed shared servers which provide electronic storage space for authorized users to house Federal records in supported file formats. Shared Drives can be manage on premises or in the cloud. Examples include SharePoint, OneDrive, and Google Drive. The use of shared drives poses recordkeeping challenges because agencies may store content that includes Federal records and non-record materials. | NARA Bulletin 2012-02: Guidance on Managing Content on Shared Drives |
| Engineering Drawings | Engineering Drawings refer to technical drawings used to convey all the required information to allow a manufacturer to produce that component. Engineering drawings include computer aided design (CAD) formats, vector graphics files that rely on mathematical expressions to create multi-dimensional computer graphics intended for use in engineering and manufacturing design. CAD programs can generate representations and animations of two and three-dimensional surface projections of objects. Engineering Drawing records must meet the definition of a Federal record, and must be in the correct file formats according to NARA's transfer guidance. | NARA Bulletin 2014-04: Format Guidance for the Transfer of Permanent Electronic Records |
&A For Official Use Only Page &P of
File details come from the government source that posted it. Updated .