RDD_-_FINAL_1.4.pdf
PDF 2 MB Posted
- Attached to
- NASIS for BIE Federal contract opportunity
- Solicitation number
- 140A1619Q0071
About this file
NASIS Requirements Definition Document (RDD)
View the file
Other files for this federal contract opportunity
| File | Type | Posted |
|---|---|---|
| Q&A_FINAL.pdf | ||
| Sol_140A1619Q0071_Amd_0001.pdf | ||
| B08_Solicitation_140A1619Q0071.pdf | ||
| DOI_Cloud_Policy_-_FINAL.pdf | ||
| SOW_-_FINAL_PRESOLICITATION.docx | DOCX document | |
| Sol_140A1619Q0071.pdf | ||
| RDD_Crosswalk.xlsx | XLSX spreadsheet | |
| Federal_Cloud_Policy_-_FINAL.pdf |
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
Native American Student Information System (NASIS) Requirements Definition Document
This Document Contains Controlled Unclassified Information (CUI) Office of Information Management Technology i
Office of Information Management Technology
Native American Student Information System (NASIS)
Requirements Definition Document
Version 1.4 February 27, 2019
U.S. Department of the Interior Indian Affairs
Office of Information Management Technology i
Revision History
Author Version Revision Date Revision Summary
M.B. McGarvey 1.0 05/29/2018 Formatted and proofread.
John Biegler 1.1 07/30/2018 Performed review and comparison of Requirements Definition Document, Requirements Traceability Matrix, and Statement of Work.
Appended to Requirements Traceability Matrix for Alignment with SOW.
John Biegler 1.2 12/13/2018 Performed review and comparison of Requirements Definition Document and Requirements Traceability Matrix
Edited / appended to Requirements Traceability Matrix
John Biegler 1.3 02/05/2019 Edited Appendix B (Requirements Traceability Matrix), R-504 for alignment with SOW.
John Biegler 1.4 02/27/2019 Edited Appendix B (Requirements Traceability Matrix), R-505 (GPRA Reporting) for alignment with SOW.
Office of Information Management Technology ii
Table of Contents
Contents
1.0 Introduction
1.1 Project Description
1.2 Background
2.0 Purpose
3.0 Interfaces to External Systems
4.0 Document References
4.1 Regulatory Documents
4.2 Laws and Regulations
4.3 Executive Orders
4.4 OMB Circulars and Memoranda
4.5 Standards and Guidelines
5.0 Requirements Summary
5.1 Traceable Requirements
5.1.1 Functional Requirements
5.1.2 Data Requirements
5.1.3 Security
5.2 General Requirements
5.2.1 Operational Requirements
5.2.2 Audit Trail
5.2.3 Data Currency
5.2.4 Reliability
5.2.5 Recoverability
5.2.6 System Availability
5.2.7 Fault Tolerance
5.2.8 Performance
5.2.9 Capacity
5.2.10 Data Retention
Appendix A Points of Contact Appendix B Requirements Traceability Matrix
Office of Information Management Technology 1
1.0 Introduction
1.1 Project Description
This Requirements Definition Document (RDD) describes the Native American Student Information System (NASIS) business and functionality requirements. It is prepared in accordance with the Indian Affairs Information Technology Office System Life Cycle requirements.
This document was jointly prepared by the Bureau of Indian Education (BIE) and the Indian Affairs Information Technology Office (IAIT). BIE participants included school and Central Office staff. Changes to the RDD are approved through the BIE Change Control Board.
The RDD supports the following activities:
Procurement of the system
Designing and developing the system
Evaluating the product in all subsequent phases of the life cycle
Enhancement of the product in all subsequent phases of the life cycle
Determining the success criteria of the project
1.2 Background
NASIS is a centralized system supporting teachers, other school staff, students, parents, and Central Office staff. NASIS provides the statistical reports needed for the various funding programs, provides reports required by Federal and State education agencies, and provides the source data to analyze student performance along with the tools needed to perform the analysis.
BIE is different from many other education jurisdictions in that BIE is comprised of 186 schools in 23 states, and is required by statute to report regarding those schools to State and Federal education agencies. This federally mandated requirement will be provided by NASIS.
This requirements, and related requirements, are performed in NASIS by Central Office staff using NASIS reporting and analysis services.
NASIS was deployed during the school year 2006-07 and is fully implemented bureau-wide.
Office of Information Management Technology 2
2.0 Purpose
The purpose of the NASIS investment is to improve student achievement through a student data management system for the BIE. NASIS will deliver services tailored to the BIE Central Office and deliver separate, but related services to the schools.
The requirement for an information system for BIE originated in the Educational Amendments of 1978 to P.L. 95-561 (the basic P.L. 95-561 was enacted in 1965). The "No Child Left Behind (NCLB) Act” is P.L. 107-110; Part D is entitled the "Native American Education Improvement Act". Part D consists primarily of a complete restatement of the Educational Amendments of 1978 to P.L., 95-561 and adds suspense dates tied to specific items.
NASIS will support the fulfillment of these statutes, the maintenance of the Indian School Equalization Program (ISEP), Average Daily Attendance/Average Daily Membership (ADA/ADM) reports, student counts and placements required under P.L. 108-446, Individuals with Disabilities Education Improvement Act of 2004 (IDEA), enrollment information required under NCLB, lunch program needs, and other reports such as those required under Government Performance and Results Act (GPRA).
Office of Information Management Technology 3
3.0 Interfaces to External Systems
Name of Application Owner Interface Details
Michigan School Data System (MSDS)
Michigan Center of Educational Performance and Information
(CEPI)
Michigan Student Data System, managed by the Michigan CEPI, aligns individual data collections with state and federal program requirements.
Comprehensive Education Data and Research System
(CEDARS)
Washington State Office of Superintendent of Public Instruction (OSPI)
Washington State data system, managed by the Office of Superintendent of Public Instruction, to collect, store and report data related to students, courses, and teachers in order to meet state and federal reporting requirements, and to help educators and policy makers to make data driven decisions.
Student Teacher Accountability Reporting System (STARS)
New Mexico Public Education Department (NMPED)
New Mexico’s STARS system is a comprehensive student, staff, and course information system that provides a standard data set for each student served by New Mexico’s 3Y/4Y – Grade 12 public education system.
Student Accountability Information System (SAIS)
Arizona State Department of Education
Arizona’s SAIS system reduces the reporting burden from Local Education Agencies (LEA), while improving the accuracy and timeliness of student counts required for state and federal funding and reporting.
Infinite Campus South Dakota Department of Education
Export / import capability of student information enrollment data from NASIS to Infinite Campus may alleviate need for duplicate data entry for the purposes of accreditation.
Office of Information Management Technology 4
4.0 Document References
4.1 Regulatory Documents
Regulatory Documents
Consolidated State Performance Reports: Parts I and II
Report of Children with Special Disabilities Receiving Special Education Under Part B of the Individuals with Disabilities Education Act, As Amended
Personnel (In Full-Time Equivalency of Assignment) Employed to Provide Special Education and Related Services for Children with Disabilities
Part B, Individuals with Disabilities Education Act Implementation of FAPE Requirements
Report of Children with Disabilities Exiting Special Education
Report of Children with Disabilities Subject to Disciplinary Removal by Disability Category
Report of the Participation and Performance of Students with Disabilities on State Assessments
Office of Indian Education Programs, Bureau-Wide Annual Report Card
Report of Students Who Receive Early Intervention Services funded by P.L. 108-446 Part B (IDEIA 2004)
Consolidated State Performance Reports: Parts I and II
Behavior Reports: Reports that will be filtered by positive or negative behaviors for various intervals of time (Example: No behaviors for one date to the next).
4.2 Laws and Regulations
Document Identifier Title Description
15 U.S.C. 1681a(f) Disclosure to Consumer Reporting Agencies; Fair Credit Reporting Act
18 U.S.C. § 1030 Computer Fraud and Abuse Act of 1986
This law provides for the punishment of individuals who access Federal computer resources without authorization, attempt to exceed access privileges, abuse government resources, and/or conduct fraud on government computers.
Office of Information Management Technology 5
18 U.S.C. § 1030 National Information Infrastructure Protection Act of
This law provides for the protection of computer resources.
20 USC § 6301 Strengthening and Improvement of Elementary and Secondary Schools.
25 CFR 31: Federal Schools for Indians
25 CFR 36 Minimum Academic Standards for the Basic Education of Indian Children and National Criteria for Dormitory Situations.
25 CFR 39 The Indian School Equalization Program.
25 U.S.C. 480 Indians Eligible for Loans.
25 U.S.C. 1 Commissioner of Indian Affairs [and] agreement between the Secretary and the Tribal Government.
25 U.S.C. 13 The Snyder Act. Expenditure of Appropriations by Bureau
20 U.S.C. § 1400 Education of Individuals with Disabilities
This law means specifically designed instruction, at no cost to parents, to meet the unique needs of a child with a disability.
25 U.S.C. 1a Delegation of powers and duties by Secretary of the Interior and Commissioner of Indian Affairs
25 U.S.C. 2001 Accreditation for the basic education of Indian children in Bureau of Indian Affairs schools
25 U.S.C. 2501 Declaration of policy. Tribally Controlled School Grants.
25 U.S.C. 452 Contracts for education, medical attention, relief and social welfare of Indians
25 U.S.C. 5301 Indian Self-Determination and Education Assistance
Office of Information Management Technology 6
31 U.S.C. § 1101 Government Performance and Results Act (GPRA) of 1993
This law establishes policies for managing agency performance of mission, including performance of its practices.
34 CFR 300.300 Individuals with Disabilities Education Act of 2004
This law that makes available a free appropriate public education to eligible children with disabilities throughout the nation and ensure special education and related service to those children
31 U.S.C. § 3111 Federal Financial Management Improvement Act (FFMIA) of
This law mandates Federal agencies to implement and maintain financial management systems that comply substantially with Federal systems requirements, Federal accounting standards, and the U.S. Government Standard General Ledger (SGL). FFMIA also requires GAO to report annually on the implementation of the act.
31 U.S.C. § 3512 Federal Managers Financial Integrity Act of 1982 (FMFIA), This law mandates that Federal agencies establish and maintain an internal control program to safeguard data processing resources, assure their accuracy and reliability, and protect the integrity of information resident on such systems.
31 U.S.C. 3701(a)(3) Disclosure to Consumer Reporting Agencies; Federal Claims Collection Act of 1966
34 CFR 300.226 Early intervening services An LEA may not use more than 15% of the amount the LEA receives under Part B of the Act for any fiscal year, less any amount reduced by the LEA pursuant to § 300.205, if any, in combination with other amounts (which may include amounts other than education funds), to develop and implement coordinated, early intervening services, which may include interagency financing structures, for students in kindergarten through grade 12 (with a particular emphasis on students in kindergarten through grade three) who are not currently identified as needing special education or related services, but who need additional academic and behavioral support to succeed in a general education environment.
Office of Information Management Technology 7
34 CFR 300.320 Definition of individualized education program.
Child Find
The term individualized education program (IEP) means a written statement for each child with a disability that is developed, reviewed, and revised in a meeting in accordance with §§ 300.320 through 300.324.
All children with disabilities residing in the State including children with disabilities who are homeless children or are ward of the State, and attending private schools, regardless of severity of their disability, and who are in need of special education and related services are identified, located and evaluated.
34 CFR 300.321 IEP Team For the child, the IEP Team includes the parents; at least one regular education teacher; one special education teacher; a school representative who is qualified to provide or supervise the provision of specially designed instruction to meet the unique needs of children with disabilities, and is knowledgeable about the general education curriculum, and availability of resources of the school. An individual who can interpret the instructional implications of evaluation results; At the discretion of the parent or the agency, other individuals who have knowledge or special expertise regarding the child, including related services personnel as appropriate; and whenever appropriate, the child with a disability; and to the extent appropriate, with the consent of the parents or a child who has reached the age of majority, a representative of any participating agency that has special expertise and likely to be responsible for providing or paying for transition services.
34 CFR 300.323 When IEPs must be in effect. At the beginning of each school year, each public agency must have in effect, for each child with a disability within its jurisdiction, an IEP, as defined in § 300.320.
Office of Information Management Technology 8
34 CFR 300.324 Development, review, and revision of IEP
In the development, review, and revision of IEP, in general when developing a child's IEP, the IEP Team must consider, the strengths of the child; the concerns of the parents for enhancing the education of their child; the results of the initial or most recent evaluation of the child; and the academic, developmental, and functional needs of the child. In addition, consideration of special factors the IEP Team must include items found in (2), (3), (4), (5) and (6). The Review and revision of IEPs must include (b), (1), (2) and (3). And, Failure to meet transition objectives must include (c), (1) and (2).
34 CFR 300.34(a) General. Related services Related services means transportation and such developmental, corrective, and other supportive services as are required to assist a child with a disability to benefit from special education, and includes speech-language pathology and audiology services, interpreting services, psychological services, physical and occupational therapy, recreation, including therapeutic recreation, early identification and assessment of disabilities in children, counseling services, including rehabilitation counseling, orientation and mobility services, and medical services for diagnostic or evaluation purposes.
Related services also include school health services and school nurse services, social work services in schools, and parent counseling and training.
34 CFR § 300.322 Parent participation Each public agency must take steps to ensure that one or both of the parents of a child with a disability are present at each IEP Team meeting or are afforded the opportunity to participate, including
(b) (c) (d) (e) and (f).
40 U.S.C. § 11101 Clinger-Cohen Act – Information Technology Management Reform Act of
This law improves the acquisition, use, and disposal of Information Technology (IT) by the Federal government.
43 CFR 2.60: Freedom of Information Act.
Records and Testimony.
Appeals
Office of Information Management Technology 9
43 CFR 2.63 Freedom of Information Act.
Records and Testimony.
Expedited Processing of Appeals
44 U.S.C. § 101 E-Government Act of 2002 This law enhances the management and promotion of electronic government services and processes by establishing a broad framework of measures requiring technology to enhance citizen access to government information services.
44 U.S.C. § 3504 Government Paperwork Elimination Act (GPEA) of
This law provides for Federal agencies, by October 21, 2003, to give persons who are required to maintain, submit, or disclose information, the option of doing so electronically when practicable as a substitute for paper and to use electronic authentication methods to verify the identity of the sender and the integrity of electronic content.
44 U.S.C. § 3541 Federal Information Security Management Act of 2002
(FISMA)
FISMA requires Federal agencies to establish agency-wide risk-based information security programs that include periodic risk assessments, use of controls and techniques to comply with information security standards, training requirements, periodic testing and evaluation, reporting, and plans for remedial action, security incident response, and continuity of operations.
44 U.S.C. §§ 3501-3520 Paperwork Reduction Act of 1995, Revised
This law provides for the administration and management of computer resources.
44 U.S.C. §21, 29, 31 and 33
Federal Records Act of 1950 Establishes the framework used by Federal agencies for their Records Management programs.
5 U.S.C. § 552 The Freedom of Information Act (FOIA) of 1966
This law requires that Federal information be made available to the public except under certain specified conditions.
5 U.S.C. § 552a The Privacy Act of 1974 This law imposes collection, maintenance, use, safeguard, and disposal requirements for Executive Branch offices maintaining information on individuals in a “system of records.”
Office of Information Management Technology 10
5 U.S.C. 552a(b)(12) Disclosure to Consumer Reporting Agencies; Public information; agency rules, opinions, orders, records, and proceedings
Public Law 94-142 as amended by P.L. 105-17
Individuals with Disabilities Act This law that makes available a free appropriate public education to eligible children with disabilities throughout the nation and ensure special education and related service to those children.
Public Law 95-561 Education Amendments of 1978: An Act to Extend and Amend Expiring Elementary and Secondary Education Programs, and for Other Purposes
Public Law 103-382 Improving America's Schools Act of 2004
This law that makes available a free appropriate public education to eligible children with disabilities throughout the nation and ensure special education and related service to those children.
Public Law 107-110 No Child Left Behind Act of
2001 (NCLBA)
Part D: Native American Education Improvement Act
15 U.S.C. 1681a(f) Disclosure to Consumer Reporting Agencies; Fair Credit Reporting Act
18 U.S.C. § 1030 Computer Fraud and Abuse Act of 1986
This law provides for the punishment of individuals who access Federal computer resources without authorization, attempt to exceed access privileges, abuse government resources, and/or conduct fraud on government computers.
18 U.S.C. § 1030 National Information Infrastructure Protection Act of
This law provides for the protection of computer resources.
4.3 Executive Orders
Document Identifier Title Description
Executive Order 10450 Security Requirements for Government Employees, April
This order establishes that the interests of national security require all government employees be trustworthy, of
Office of Information Management Technology 11 good character, and loyal to the United States.
Executive Order 13011, Federal Information Technology, July 1996
This order establishes policy for the head of each agency to effectively use information technology to improve mission performance and service to the public.
Executive Order 13103 Computer Software Piracy, September 1998
This order establishes policy that each executive agency shall work diligently to prevent and combat software piracy in order to give effect to copyrights associated with computer software.
Executive Order 13231 Critical Infrastructure Protection in the Information Age, October 2001
This order establishes policy that ensures protection of information systems for critical infrastructure, including emergency preparedness communications, and the physical assets that support such information systems.
Presidential Decision Directive 63
Critical Infrastructure Protection, May 1998
This directive requires that the United States take all necessary measures to swiftly eliminate any significant vulnerability to both physical and cyber-attacks on critical infrastructures, including our cyber systems.
4.4 OMB Circulars and Memoranda
Document Identifier Title Description
A-11, Section 53 Information Technology and E- Government
This directive specifies the identification of security and privacy safeguards for managing sensitive information.
A-123 Management Accountability and Control, as revised December 21, 2004
This directive specifies the policies and standards for establishing, assessing, correcting, and reporting on management controls in Federal agencies.
A-127 Financial Management Systems, as revised by Transmittal Memorandum Number 3, December 1, 2004
This directive prescribes policies and standards for executive departments and agencies to follow in developing, operating, evaluating, and reporting on financial management systems.
A-130, Appendix I Federal Agency Responsibilities for Maintaining Records About Individuals
This directive prescribes policy to agencies for the implementation of the Privacy Act and reporting requirements related to the management of personally identifiable information (PII).
Office of Information Management Technology 12
A-130, Appendix III Security of Federal Automated Information Resources, as revised by Transmittal Memorandum Number 4, November 28, 2000
This directive stipulates that each agency shall implement a comprehensive automated information security program.
The appendix establishes basic managerial and procedural controls that shall be included in Federal automated information systems.
Memorandum M-05-24 Implementation of Homeland Security Presidential (HSPD) 12
– Policy for a Common Identification Standard for Federal Employees and Contractors.
Memorandum M-06-16, Protection of Sensitive Agency Information
Establish requirements for the use of two-factor authentication for remote system access and requirements for responding to breaches or possible breaches of PII.
Memorandum M-07-16 Safeguarding Against and Responding to the Breach of Personally Identifiable Information
Establish requirements for the use of two-factor authentication for remote system access and requirements for responding to breaches or possible breaches of PII.
Memorandum M-08-05 Implementation of Trusted Internet Connections, Establishes the requirement for the Department of the Interior (DOI) to comply with the Trusted Internet Connection (TIC) initiative and the architectural requirements defined by the Department of Homeland Security (DHS) in the TIC Reference Architecture (current version 2.0 dated 2011).
Memorandum M-08-16 Guidance for Trusted Internet Connection Statement of Capability Form (April 04, 2008)
Memorandum M-08-27 Guidance for Trusted Internet Connection Compliance (Sep 30, 2008).
Memorandum M-11-11 Continued Implementation of Homeland Security Presidential Directive (HSPD) 12– Policy for a Common Identification Standard for Federal Employees and Contractors (02 Feb, 2011)
Memorandum M-11-33, Reporting Instructions for the Federal Information Security Management Act and Agency Privacy Management (14 Sep 2011)
Office of Information Management Technology 13
4.5 Standards and Guidelines
FIPS Pub 140-2 Security Requirements for Cryptographic Modules
FIPS Pub 199 Standards for Security Categorization of Federal Information and Information Systems
FIPS Pub 200 Minimum Security Requirements for Federal Information and Information Systems
NIST SP 800-137 Information Security Continuous Monitoring for Federal Information Systems and Organizations
NIST SP 800-18 Guide for Developing Security Plans for Federal Information Systems
NIST SP 800-30 Guide for Conducting Risk Assessments
NIST SP 800-34 Contingency Planning Guide for Federal Information Systems
NIST SP 800-37 Guide for Applying the Risk Management Framework to Federal Information Systems: A Security Life Cycle Approach
NIST SP 800-39 Managing Information Security Risk: Organization, Mission, and Information System View
NIST SP 800-53 Recommended Security Controls for Federal Information Systems and Organizations
NIST SP 800-53A Guide for Assessing the Security Controls in Federal Information Systems and Organizations, Building Effective Security Assessment Plans
NIST SP 800-60 Guide for Mapping Types of Information and Information Systems to Security Categories:
(2 Volumes) - Volume 1: Guide Volume 2: Appendices
Office of Information Management Technology 14
NIST Security Technical Implementation Guides
STIGs – also referred to as security configuration checklists
National Security Presidential Directive and Homeland Security Presidential Directive
(NSPD-54/HSPD-23
Department of Homeland Security (DHS) Trusted Internet Connection (TIC), Version 2.0
Federal Identity, Credential and Access Management (FICAM) Roadmap and Implementation Guidance
Family Educational Rights Privacy Act (FERPA)
Health Insurance Portability and Accountability Act (HIPAA).
Indian Affairs System Delivery Lifecycle (SDLC)
Office of Information Management Technology 15
5.0 Requirements Summary
The Requirements Summary is in two parts. The traceable requirements are further detailed in the Requirements Traceability Matrix (RTM). The General Requirements are overall solution requirements. If any section of these requirements is not applicable, then enter Not Applicable for the section.
5.1 Traceable Requirements
5.1.1 Functional Requirements
NASIS will allow BIE to store, access, and analyze data to reformulate academic and residential strategies, align curriculum to standards; including the standards of 23 different states, analyze standardized test trends in student performance to identify weakness and successes, create new visions and ideas to increase academic performance, provide data to make accountability determination and the related state assessments and benchmark data.
NASIS allows access to student achievement information, making possible the distillation of data into reports at school, Education Resource Center (ERC)/Education Program Administrator (EPA), Regional Director, BIE Central Office, and state levels. EPAs will be able to run reports covering their jurisdictions and BIE will run bureau-wide aggregate reports as well as all other reports.
The other primary NASIS requirement is the delivery of NASIS Student and School Services.
Student and School Services are similar to those that would be anticipated in most schools systems.
NASIS will provide schools with as complete a feature set as possible to support and satisfy day to day and planning needs. This would include data input, collection and reporting for a variety of functions such as, but not limited to, scheduling, attendance, grade reporting, behavior tracking, test and assessment histories, program enrollments, and other areas of need. There are some unique BIE requirements related to, for example, tribal documentation, early childhood programs, transportation and residential/dormitory operations.
To reduce overall life cycle costs and simplify system support, and to take advantage of proven technology, NASIS must be a centralized, web-based system.
5.1.2 Data Requirements
Data requirements include the ability to;
Migrate Systems Interoperability Framework (SIF) and Open Database Connectivity (ODBC) compliant data to the procured solution, while providing the continued capability for a centralized system supporting teachers, other school staff, students, parents, and Central Office staff.
Synchronize data elements entered at the District level of the system, to the State level of the system.
Office of Information Management Technology 16
NASIS will employ XML compliant data structures.
The data storage facility must ensure that the data is not visible for anyone outside of the BIE. This requires the following:
NASIS will have the capability to institute role-based rights to data and functions.
No other interface can be added to the system without prior approval and/or notification of BIE.
NASIS will comply with the requirements of the Privacy Act and the Family Educational Rights Privacy Act (FERPA).
NASIS will comply with the requirements of the Health Insurance Portability and Accountability Act (HIPAA).
5.1.3 Security
As with all Federal government agencies, BIE is subject to numerous requirements stemming from a variety of laws, rules, regulations, directives, and standards aimed at ensuring the protection of sensitive agency information and information systems. These requirements include providing information security protections commensurate with the risk and magnitude of the potential harm resulting from unauthorized access, use, disclosure, disruption, modification, or destruction of (i) information collected or maintained by or on behalf of the agency; and (ii) information systems used or operated by the agency or by a contractor on behalf of the agency.
Consequently, the Contractor shall also adhere to and comply with applicable Laws, Executive Orders and Executive Branch Policy regarding the design, build, testing, operations and maintenance of the information system and the security controls designed to safeguard agency information. This document outlines and references the information technology (IT) security and privacy requirements in which the service provider must comply.
These requirements are applicable when BIE information is generated, accessed, stored, processed, or exchanged with BIE or on behalf of BIE by a service provider or subcontracted service provider, regardless of whether the information resides on a BIE information system or a service provider/subcontracted service provider’s information system. The service provider shall protect the confidentiality, integrity, and availability of BIE electronic information and IT resources and protect BIE electronic information from unauthorized disclosure.
If NASIS is in a BIE facility, the government will provide network perimeter security. If in an Application Service Provider (ASP) facility, the vendor will provide network perimeter security.
The system will generate alerts for selected significant events, including;
Adverse Events: An event with a negative consequence, such as system crash, network packet flood, unauthorized use of system privileges, defacement of a Web page, and execution of malicious code that destroys data. Adverse events are reportable incidents that are computer security-related, which are not caused by sources such as natural disasters and power failure.
Office of Information Management Technology 17
Anomalies: Any detected, or reported, security event that requires further analysis by the IA Computer Incident Response Team (CIRT).
Denial of Service (DoS): An attack that prevents or impairs the authorized use of networks, systems, or applications by exhausting resources.
Events: Any observable occurrence in a system or network, such as a firewall blocking a connection attempt.
Incidents: NIST Special Publication 800-61 defines a reportable computer incident within the federal government as a violation or imminent threat of violation of computer security policies, acceptable use policies, or standard computer security practices.
If NASIS must be delivered via an ASP, the system and the supporting infrastructure will be subjected to periodic tests by the government. The vendor will be required to provide certifications or test data demonstrating its compliance with applicable Federal and State Information Technology and Privacy security requirements.
DOI remains responsible and accountable for all risk incurred by use of services provided by external service providers. This risk is addressed by requiring a minimum set of security and privacy controls that must be implemented and monitored to provide assurance that DOI information remains accurate, secure and available. The requirements outlined herein are intended to provide DOI with an acceptable level of trust and controls that must be maintained throughout the lifecycle of the acquisition. This level of trust and controls are maintained by:
1. Reciprocity through a centralized, Federal acquisition vehicle in accordance with the Federal Risk and Authorization Management Program (FedRAMP). In accordance with the OMB memorandum entitled, Security Authorization of Information Systems in Cloud Computing Environments, issued on December 8, 2011, the DOI Authorizing Official (AO) anticipates leveraging and accepting provisional authorizations granted by the FedRAMP Joint Authorization Board (JAB), comprised of the Department of Defense (DOD), Department of Homeland Security (DHS) and the General Services Administration (GSA), in granting security authorizations and an accompanying authority to operate (ATO) for DOI use of the FCHS, to the extent allowable. DOI does not necessarily anticipate leveraging authorizations granted independently by other individual agencies, but may opt to do so at its discretion;
2. The Provider acquiring the services of an agreed upon independent third-party assessor to test and evaluate the effectiveness of the applicable security controls;
and
3. Meeting the IT security and privacy requirements set forth within this document, including satisfying the ongoing requirements identified within the IT Security and Privacy Checklist (Appendix A) and eighteen DOI Security Control Standards that correspond to the National Institute of Standards and Technology (NIST) Special Publication (SP) 80-53, Recommended Security Controls for Federal Information Systems, which identify additional required control enhancements.
Office of Information Management Technology 18
5.2 General Requirements
5.2.1 Operational Requirements
In order to: 1) minimize system support needs and system cost, 2) enhance security and the user experience, and 3) position the system for future technological developments, NASIS must embody the following characteristics:
Centralized, Web-based system, accessible to staff, parents, and students Web browser-based user interface utilizing Microsoft Internet Explorer and Mozilla
Firefox, at a minimum.
Windows-based user interface NASIS shall be capable of evolving with technological developments.
NASIS shall employ open standards and open source technology.
Online analytical processing (OLAP) tools Data warehouse for student and school information Data analysis tools for multi-dimensional data analyses and reports Messaging for staff, students, and parents NASIS must be delivered as either a government-owned and operated system or as a service from an application service provider (ASP).
Core NASIS Platform. The NASIS processing environment shall be consistent with
(FIPS, NIST) standards set by the BIE and the Department of the Interior.
Network Service. Users will communicate with the core NASIS platform over TCP/IP based networks. Schools have access to the Internet.
Federal and State Reporting. The foremost requirement of NASIS is to support the reporting requirements levied on BIE by the US Department of Education and the State education agencies. BIE is distinct from many other school systems in that it operates in 23 states and must exchange and associate data with the states and their standards, including the required reports. Federal reporting requirements may also include, but are not limited to, indicators for State Annual Performance Report, Civil Rights Report and Census Reports. Many of these operational requirements are related to risks associated with noncompliance.
Office of Information Management Technology 19
5.2.2 Audit Trail
The system will have the ability to log events and transactions. Logging parameters will be customizable. If NASIS is delivered by ASP, then BIE will have online access to audit facilities or be provided audit log reports on a daily basis. The system shall record logon failures and successes.
In the event NASIS is operated outside of BIE facilities, BIE shall have the ability to monitor the status of the system via reports or dashboards. Data required by BIE includes:
Operational status Number of active users Number of sessions/users per day Number of open trouble tickets (cumulative and by category) General trouble ticket statistics
5.2.3 Data Currency
Once data is entered, the data shall be available immediately.
5.2.4 Reliability
The minimum acceptable level of availability is 99.97%.
5.2.5 Recoverability
In the event the system is unavailable to users because of a major system failure, the maximum time period required for restoring function and data is 4 hours. The system must be capable of being restored to the condition that existed just prior to system failure.
In the event of destruction of the processing site, the backup site must be available within 8 hours of failure.
A Disaster Recovery Plan is required, and must be approved by BIE. It must be updated and tested annually by the anniversary date plan was approved by BIE.
5.2.6 System Availability
The system must be available to users 24 hours a day, 365 days a year. Additionally, a separate Service Level Agreement (SLA) must be established that will clarify the System Availability, Recoverability, and Performance. This will be developed in coordination with the provider and BIE.
Routine system maintenance and upgrades must be scheduled in advance and proper notice must be given before a scheduled system outage. Proper notice is defined as 1 week.
Office of Information Management Technology 20
To ensure system available the ‘warm site’ servers will be in a clustered configuration.
5.2.7 Fault Tolerance
The Native American Student Information System has been identified as mission critical for the Bureau of Indian Education. Fault Tolerance requirements include;
Total failover capabilities with 100% replacement and restoration of data and functionality of two ‘hot sites’ and one ‘warm site’. If a ‘hot site’ does fail the transition of the ‘warm site’ to ‘hot site’ will be expedited.
Low network latency will be required to maintain ‘hot site to hot site’ and ‘warm site’ data synchronization.
Servers will have redundant hardware and be hot swappable to reduce potential down time.
The operation procedures, training, and continuous improvement will be a part of the operational environment.
5.2.8 Performance
Assuming negligible network delays, screens, when selected, will display with minimal delay and will not be an encumbrance to performing functions. Reports will be sent to the chosen printer within a timeframe that is measured in seconds as opposed to minutes. Response time for queries and updates should be almost immediate. The system should be able to meet user needs for handling transactions.
5.2.9 Capacity
The current student population is approximately 53,400 students. The number of students is not expected to change significantly. Access to NASIS by parents will increase the user population accordingly.
5.2.10 Data Retention
All data for BIE schools must be retained permanently. Therefore, copies of the data must be furnished to BIE at monthly intervals for data storage purposes if NASIS is delivered via an ASP. All data furnished and turned over to BIE will be in a mutually agreed format which is, at minimum, SIF and ODBC compliant such that BIE will be able to store and access the data at a later time.
Office of Information Management Technology 21
Appendix A Points of Contact Dept Name Phone Date Notes
Director, BIE Tony Dearman System Owner / Business Owner
Office of the Director, BIE
Dr. Joe Herrin Financial Systems Specialist Joe.Herrin@bie.edu
202-208-
04/17/2018 ISEP Base Program and NASIS
COTR, BIE
Marlene Walker
COR
Marlene.Walker@bie.edu
505-563-
CAO
Accountability and Assessment, BIE
Susan McCabe NASIS Specialist Susan.McCabe@bie.edu
NASIS
System Administrator and EDFacts reporting
CAO
Accountability and Assessment, BIE
Rebecca Izzo NASIS Specialist Rebecca.Izzo@bie.edu
State Assessment and School Level Assessment Data
ADD Bureau Operated – Flandreau Indian School, BIE
Katherine Renville Registrar Katherine.Renville@bie.edu
04/16/2018 NASIS – School Level Power User
ADD Navajo
ERC/ELO
Representative, BIE
Elrisa Sells Education Specialist (School Improvement) Elrisa.Naljahihsell@bie.edu
NASIS (Certified User) and Native Star User
ADD Tribally Controlled Schools, BIE
Klarissa Jensen Education Research Analyst Klarissa.Jensen@bie.edu
04/20/2018
Creating Data Systems for educators to inform instruction
Division of Performance and Accountability – ESSA Programs, BIE
Cheryl Quimayousie Education Program Specialist –
ESSA
Cheryl.Quimayousie@bie.edu
505-414-
EDFacts NASIS for ESSA reporting
Division of Performance and Accountability – IDEA Programs, BIE
Connie Albert Education Program Specialist –
IDEA
Connie.Albert@bie.edu
04/20/2018 NASIS user for IEP development and IDEA reporting
Division of Performance and Accountability – IDEA Programs, BIE
Jennifer Davis Education Program Specialist –
IDEA
Jennifer.Davis.bie.edu
NASIS user for IEP development and IDEA reporting
Office of Information Management Technology 22
Dept Name Phone Date Notes
IA OIMT / DPMBS
Peter Sullivan Division Chief, Program Management and Business Services Peter.Sullivan@bia.gov
703-390-
Dyna Wilson Project Manager Dyna.Wilson@bia.gov
Edward ‘Ned’ Connor Team Member Edward.Connor@bia.gov
Vivian Deliz IA IT CP / AC Representative Vivian.Deliz@bia.gov
John Biegler Business Analyst John.Biegler@bia.gov
IA OIMT /
Operations
Theodore McGlohn IT Specialist / Systems Admin Theodore.McGlohn@bia.gov
Security
Richard Gibbs Privacy Officer Richard.Gibbs@bia.gov
Security
Albert Rice
ISSO
Albert.Rice@bia.gov
Office of Information Management Technology 23
Appendix B Requirements Traceability Matrix These requirements have been assembled based on originally identified data elements.
Additional requirements may be specified based on regulatory or business requirements.
Requirements are applicable to the NASIS District-level system unless otherwise noted.
Req. ID Type Function Description Business Objective
Priority
R-001 Student Enrollment and People
State System
Adding new student, staff, people to the system
Auto generate unique student and staff ID across all schools & districts
Unique Identifiers for students and staff
Critical
R-002 Student Enrollment and People
State System
Locating students who may have an enrollment in another school
The ability to locate across all schools & districts when a student enrolls into a new school
Prevent duplicate student entry
Critical
R-003 Student Enrollment
State System
When a student transfers from one school to another school
The ability for transfer of data for a student who withdraws from one school to attend another school in the BIE system
Attendance, Behavior, Assessment, Health, Special Needs, Transcripts, Grades, Schedule, LEP, G&T data to transfer from school to school with the student.
Critical
R-004 Data Quality
State System
System must be capable of validating and certifying state level reporting from the district to the state
The ability to manage validating and certifying process for state reporting
Includes all state reporting
Critical
Office of Information Management Technology 24
Objective
Priority
R-005 Accountability
State System
System must include capability to accept multiple multi-tier assessment setup and scores to accommodate 23 states' assessments.
Once created at state level, then allow to push(publish down to select appropriate schools)
Set up system to accept/import 23 states' (MI, SD, MD, OK, MT, WY, MN, WI, IA, AZ, CA, NV, NM, UT, ID, OR, WA, FL, ME, MS, NC, LA, KS, ND) assessment data for all required grades and subjects tested (mathematics, English Language Arts, Science, etc.), to include the overall test score and result as well as the subtests that are aligned to each states' standards.
System must allow set up at state wide level, push down to appropriate schools at the school level and not allow changes to scores or assessment structure once at the school level.
Critical
R-006 Accountability
State System
System must include capability to accept multiple multi-tier assessment setup and scores to accommodate 23 states' assessments.
Once created at state level, then allow to push(publish down to select appropriate schools)
Set up system to accept/import assessment data of 23 states (MI, SD, MD, OK, MT, WY, MN, WI, IA, AZ, CA, NV, NM, UT, ID, OR, WA, FL, ME, MS, NC, LA, KS, ND) for English Language Proficiency to include the overall assessment scores for identified EL students.
System must allow set up at state wide level, push down to appropriate schools at the school level and not allow changes to scores or assessment structure once at the school level.
Critical
R-007 Data Quality
State System
Ability to create on the fly ad hoc/ query reports as needed and published to the district editions.
Ability to create on the fly ad hoc/ query reports as needed and published to the district editions
Ability to create on the fly ad hoc/ query reports as needed and published to the district editions
Critical
Office of Information Management Technology 25
Objective
Priority
R-008 Ability to publish BIE defined data elements
State System
Ability to publish new fields as defined by BIE
Create and push new BIE or Department of Education defined data elements, like common core course codes to the district/school systems
Create and push new BIE defined data elements to all schools
Critical
R-009 Ability to sync data elements entered at the district level to the state level of the system
State System
Ability to rely on synchronization between district and state or between state and district
Ability to review synchronization accuracy between the systems
Reports, dashboards, logs must be available to review reliability of synchronization
Critical
R-010 Manage student enrollment overlapping
State System
Identify when a student is enrolled in more than one school or more than one enrollment where days overlap within the enrollment
Identify when a student is enrolled in more than one school or more than one enrollment where days overlap within the enrollment
Identify when a student is enrolled in more than one school or more than one enrollment where days overlap within the enrollment
Critical
R-011 Student Enrollment
Summons Automated call slips and messages
Locate Individual Students
High
R-012 Relevant Reports
Attendance Rosters
The ability to print Attendance Rosters
Access Attendance History
Medium
R-013 Relevant Reports
Daily Call Report The ability to provide an Absent List with selection options that include parent/guardian contact information.
Access Attendance History
High
R-014 Relevant Reports
Teacher's Summary of Attendance
The ability to provide a Class Attendance List with selection options of Start Date, Weeks, Access Attendance History
High
Office of Information Management Technology 26
Objective
Priority
Section ID, and indicators for whether or not to include the Signature Line.
R-015 Relevant Reports
Attendance Collection Status
The ability to provide a list of teachers who have/have not submitted attendance for the current day.
Access Attendance History
High
R-016 Relevant Reports
Student Attendance Detail
The ability to provide an Attendance Profile report with selection options that include Daily Attendance History, Period Attendance History, Absence Reasons, Start and End Dates.
Access Attendance History
High
R-017 Relevant Reports
Master Absence List
The ability to provide a list of all students’ absences with selection options that include Date Range, a choice of Absence Reasons, Grade Range.
Access Attendance History
High
R-018 Relevant Reports
Excessive Absence Report
The ability to provide a list of all students’ absences with selection options that include number of occurrences, choice of Absence Reasons and a date range.
Access Attendance History
High
R-019 Relevant Reports
Attendance Phone contact List
The ability to provide a list of students absent with option to include parent/guardian contact information.
Access Attendance History
Office of Information Management Technology 27
Objective
Priority
R-020 Relevant Reports
Monthly Attendance Hours Report
The ability to provide a list of students with summary of attendance hours attended/absent by month
Access Attendance History
High
R-021 Relevant Reports
School ADA, ADM Reports
The ability to provide a summary of students attendance by Date, Minute, Student, etc.
Access Attendance History
High
R-022 Relevant Reports
Student Attendance Summary
The ability to provide a by student summarizing total number of days absent, attended for a given date range.
Access Attendance History
High
R-023 Relevant Reports
Ability to filter reports for various intervals of time (10 days, etc.) as needed
The ability to provide a list of students who have met a certain number of absences by Date, Minute, Student, etc. as needed
Access Attendance History
High
R-024 Relevant Reports
Absentee Report The ability to provide list of students absent with option to include date range, absence reason code
Access Attendance History
High
R-025 Relevant Reports
Attendance Count Report
The ability to provide list counting students absent and attendance
Access Attendance History
High
R-026 Relevant Reports
Consecutive Absences Reports
The ability to provide list of students absent for X number of consecutive school days.
Access Attendance History
High
R-027 Relevant Reports
Perfect Attendance
The ability to provide list of students with
Access Attendance
Office of Information Management Technology 28
Objective
Priority
Report perfect attendance with selection options that include grade range and date range.
History
R-028 Relevant Reports
Student Daily Attendance Report
The ability to provide list of students’ daily attendance with selection options that include absence reasons.
Access Attendance History
High
R-029 Relevant Reports
Weekly Attendance Summary Report
The ability to provide list of students' attendance, absence by week with option for signature line, date range.
Access Attendance History
High
R-030 Relevant Reports
Period Attendance Verification Report
The ability to provide list of students’ attendance by period with option for signature line, date range.
Access Attendance History
High
R-031 Relevant Reports
Student ADM and ADA Reports
By Date, Minute, Student, etc.
Funding…
This is the start of the file's text. The full file is on GovTribe.
File details come from the government source that posted it.