47QFAA24R0004_T10_08d_Attachment 9_BDMS Design Document_2024-06-10.pdf

PDF 1 MB Posted

Attached to
Budget Department Management System (BDMS) Implementation & Support Services for PBGC Federal contract opportunity
Solicitation number
47QFAA24R0004
Issued by
General Services Administration Federal Acquisition Service Assisted Acquisition Services Region 1

About this file

This document is a Design Document for the Budget Department Management System (BDMS) application, which is a cloud-based budget formulation solution built on the OneStream software platform for the Pension Benefit Guaranty Corporation (PBGC).

The BDMS application is intended to automate and streamline PBGC's budget formulation and reporting processes. Key capabilities include operational budgeting, forecasting, reporting, and data analytics. The solution will integrate with PBGC's Consolidated Financial System (CFS) and the Department of Labor's Departmental E-Business Suite (DEBS) system, though these integrations will remain manual data transfers initially. The BDMS will leverage FedRAMP-certified cloud hosting, with access provided via SAML 2.0 authentication through PBGC's ADFS. Ongoing operations and maintenance, including user management, configuration changes, and system upgrades, will be a collaborative effort between PBGC and the OneStream vendor.

View the file

Other files for this federal contract opportunity

Other files attached to Budget Department Management System (BDMS) Implementation & Support Services for PBGC, newest first.
File Type Posted
47QFAA24R0004_T10_08a Solicitation_RFP_2024-07-16 Amendment 3.docx DOCX document
47QFAA24R0004_T10_08d_Attachment 6_Prior Experience Worksheet_2024-07-12.xlsx XLSX spreadsheet
47QFAA24R0004_T10_08d_Attachment 4_Task Order 01 Labor Category Positions and Key Personnel_2024-07-12.xlsx XLSX spreadsheet
47QFAA24R0004_T10_08a Solicitation_RFP_2024-07-12.docx DOCX document
47QFAA24R0004 Questions and Answers 12 July 2024.xlsx XLSX spreadsheet
47QFAA24R0004_T10_08a Solicitation_RFP_2024-07-03.pdf PDF
47QFAA24R0004_T04_02a_BRAND NAME JA_2024-06-04.pdf PDF
47QFAA24R0004_T10_08a Solicitation_RFP_2024-06-05.pdf PDF
47QFAA24R0004_T10_08d_Attachment 14_GSA CUI Guide_2024-06-10.pdf PDF
47QFAA24R0004_T10_08b_Attachment 1_Task Order 01 CLINs 0001 and 0002 PWS_2024-06-10.pdf PDF
47QFAA24R0004_T10_08d_Attachment 12 BISD Operating Model Playbook - The 6 Plays_2024-06-10.pdf PDF
47QFAA24R0004_T10_08b_Attachment 2 Task Order 01 CLIN 0003 Statement of Objectives_2024-06-10.pdf PDF
47QFAA24R0004_T10_08d_Attachment 6_Prior Experience Worksheet_2024-06-10.xlsx XLSX spreadsheet
47QFAA24R0004_T10_08d_Attachment 13 Consent to Purchase (CTP) Form_2024-06-10.xlsx XLSX spreadsheet
47QFAA24R0004_T10_08d_Attachment 4_Task Order 01 Labor Category Positions and Key Personnel_2024-06-10 _.xlsx XLSX spreadsheet
47QFAA24R0004_T10_08d_Attachment 10_ITSLCM Handbook_2024-06-10.pdf PDF
47QFAA24R0004_T10_08d_Attachment 15 Section K Full Text Reps and Certs_2024-06-10.pdf PDF
47QFAA24R0004_T10_08d_Attachment 11_IT Solutions Life Cycle Management (ITSLCM) Framework_2024-06-10.pdf PDF
47QFAA24R0004_T10_08d_Attachment 7_Past Performance Questionnaire and Reference Sheet_2024-06-10.docx DOCX document
47QFAA24R0004_T10_08d_Attachment 3_IDIQ Master Staffing Plan_2024-06-10.xlsx XLSX spreadsheet
47QFAA24R0004_T10_08c_Attachment 8_Task Order 01 QASP_2024-06-07.pdf PDF
47QFAA24R0004_T10_08d_Attachment 5 Task Order 01 Pricing Spreadsheet for Evaluation_2024-06-10.xlsx XLSX spreadsheet
Show all 22

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

Budget Department (BD) and Office of Information Technology (OIT)

Budget Department Management System 2.0 Business and Technical Footprint

Version 2.0 Page 1 11/02/2022

Release Summary

Overview

Design Approach

Design Assumptions

Design Constraints

Design Dependencies

Reference and Justification

Justification

Business Architecture

Core Functional Capabilities

Budget Formulation Process Improvement

Application Architecture

Data Architecture

Data Design

Data Configuration Model

Persistent and Dynamic Data

Data and Information Exchange

Integration/Interfaces

OneStream Cloud to PBGC Connectivity

Data Exchange

Data Migration supporting Initial Launch

Scheduled Import of Budget Actuals

Unscheduled Data Imports

People Planner Data Imports

Infrastructure

FedRAMP Certified Environment

Email Service Account

CyberArk Access Control

XF Marketplace Components

Configuration and Build Management

Technology Stack

Technology Stack Detail

Version 2.0 Page 2 11/02/2022

Information Security and Privacy

User Access & Roles Management

User Interface/User Experience (Scrum Team Session)

Reports and Business Intelligence

Design Patterns

Post-Deployment Management Considerations

Design Governance and Compliance

Glossary of Terms

Figures and Tables

Figure 1 - BDMS High Level Integration Figure 2 – Budget Segment, Target State Architecture Figure 3 – High-Level Technical Infrastructure Figure 4 – Business Process Flow Diagram Figure 5 – Business Process Flow Diagram (cont.)

Figure 6 – Unfunded Reallocation Workflow Figure 7 – OneStream-PBGC Connectivity Figure 8 – OneStream Relational Architecture Figure 9 – OneStream N-tier Architecture Stack

Table 1 – Target State (from BNA) Table 2 – OneStream Technology Stack Table 3 – Glossary

Version 2.0 Page 3 11/02/2022

Release Summary Overview

BDMS is a OneStream cloud application hosted in a FedRAMP-certified environment, providing full-scope support for all requirements identified in the AA. It provides a unified financial planning software solution that supports financial and operational budgeting, planning, forecasting, and reporting for maximum agility. This modern CPM platform can support top-down, bottom-up, driver based planning, rolling forecast, predictive analytics, and other advanced planning techniques.

Figure 1 - BDMS High Level Integration

The OneStream XF solution meets many of PBGC’s Budget Formulation business requirements.

OneStream XF supports a rich Internet Application (RIA) that utilizes a Service-Oriented Architecture. It is designed to be highly scalable to support thousands of users. Engineered from the ground up as a native 64-bit application, OneStream XF allows users to take advantage of true 64-bit technology, including performance benefits, broader scalability, and a lower cost of ownership. It supports fault tolerance and unlimited scalability with its inherent ability to support multiple web servers and application servers using a stateless 64-bit architecture.

On the functional side, BDMS starts with the core OneStream framework, and extends functionality by adding additional modules from the OneStream Marketplace. Each new module extends the core OneStream data model, but does not overwrite or replace it, which simplifies future expansions. The following BDMS version releases outline these module deployments:

• v1.0 – Budget Formulation (using core OneStream framework and Task Manager (UTM pv 630 sv 100)) (deployed)

Version 2.0 Page 4 11/02/2022

• v2.0 – People Planner (PLP pv 620 sv101)

• v3.0 – Master Staffing List (PLP1 second instance of PLP) and Transaction Matching

(TXM pv 530 sv 201) (future state)

• v4.0 – Budget Execution (core OneStream framework) (future state)

On the infrastructure side, OneStream is maintained in baseline version releases. These are independent from OneStream Marketplace module releases and are also independent of PBGC’s BDMS release schedule (above). OneStream regularly releases updates to the core framework.

Customers are required to upgrade annual at minimum. PBGC maintains the connectivity to OneStream, and all updates/patching for that connection is separate from OneStream and BDMS versioning.

OneStream is built on a .NET / SQL Server technology stack. This is not directly relevant to PBGC, however, because all elements of OneStream infrastructure have been abstracted or obscured as a matter of security and of FedRAMP-high policy. At no point will PBGC have direct access to OneStream servers, service accounts, databases, cloud components, or scheduled processes.

The underlying database is available for inspection, but it can only be queried, manipulated, or changed through the OneStream front-end. There is no access via SQL Server Management Studio. PBGC cannot initiate an IIS reset or alter/inspect the .NET webconfig file. Even the OneStream Marketplace (which hosts modules to expand OneStream functionality) is inaccessible to customers such as PBGC.

OneStream is updated via version releases. The versions of the OneStream cloud environment and the local windows desktop client must match exactly. The current version of OneStream deployed at PBGC is documented in the Solution Environment Plan (SEP). With each new version release, the windows desktop client must first be installed on a PBGC test VDI for security scanning and testing before it may be approved for deployment to end-user machines.

Deployments must be closely coordinated to ensure cloud and desktop components are deployed at the same time to minimize user disruption.

Security is maintained by complying with FedRAMP-High standards. End user access is handled through a SAML authentication via secure standard HTTPS traffic, leveraging SSO, so that end-users typically just ensure their PIV card is inserted when logging into BDMS. The granting of access and role assignments is handled by PBGC and is done via CyberArk encapsulated service account sessions. All changes to infrastructure or environment settings performed by OneStream staff must be approved by PBGC through a checkbox on each relevant service ticket. These approaches are all part of the FedRAMP-High security posture supporting BDMS.

1. In addition, OneStream provides: Enhanced narrative and reporting capabilities (baseline functionality)

2. Enhanced ability to track and manage unfunded requests (UFRs) (Task Manager module)

3. Integrated Personnel Compensation and Benefits (PC&B) management (People Planning module)

Version 2.0 Page 5 11/02/2022

Overall, BDMS is set to achieve the following goals:

1. Automate budget formulation

2. Improve data availability

3. Generate operating efficiencies

The target state for BDMS will provide:

• A purpose-built budget formulation solution that enables and automates the formulation and adjustment functions of budget management.

• An automated budget formulation and approval process.

• A role-based central repository that stores all budget data and adhere to the least privilege principle.

• A budget prioritization tool used during budget formulation for all budget submissions.

• Budget reports that are not labor intensive to produce. A simplified means of producing budget reports that use real-time data, enabling the inclusion of up-to-the-minute information.

• An automated means of prioritizing adjustments to approved budgets.

• A comprehensive budget formulation solution for the PBGC that eliminates the need for costly and time-consuming file management, version control, error checking and data consolidation tasks required with the use of Excel spreadsheets.

• Workflow automation for all budgeting processes and workflows. Real-time budget status is also available via dashboard to all users.

• A budget formulation solution with reporting capabilities to help with budget report requirements. Integration with Consolidated Financial Systems (CFS) will help reduce manual processing, enabling faster review and decision making.

• A forecasting and reporting capability for Personnel Compensation & Benefits (PC&B), mirroring (but not replacing) relevant HR data sources.

• Additional requirements for Master Staffing List (MSL) and budget execution are desired, but may not be fully reflected yet in this document.

Version 2.0 Page 6 11/02/2022

Figure 2 – Budget Segment, Target State Architecture

Version 2.0 Page 7 11/02/2022

Design Approach BDMS leverages the COTS applications delivered by OneStream and integrates with other dependent systems downstream.

• OneStream XF: This is a cloud-based COTS application, hosted in a FedRAMP certified Azure platform, that forms the core of BDMS. It supports real-time budget formulation tasks and updates in a secure collaborative environment. The current project implements OneStream XF as a stand-alone application, with a future state goal of integrating it with other PBGC financial systems in future unplanned releases.

• DEBS: Integration with the federal DEBS platform, hosted by the Department of Labor (DOL) for DOL, OMB, and CBJ review, relies on a manual process of exporting office document files. The data comprising these export/import files was defined once requirements were confirmed and mirror the documents BD currently assembles manually (for reporting budget formulation data to DEBS.) See section 9.1.4 for more information on DEBS submission.

• CFS: Integration with PBGC’s internal financial system (CFS) relies on a manual process of exporting and importing spreadsheet files. The OneStream XF tool provides for spreadsheet export and import of all reports. The data comprising these export/import files was defined once key requirements were confirmed and they mirror the spreadsheets (BD) currently assembles manually (for exchanging budget formulation data with CFS.

See section 9.1.5 for more information on how budget formulation data is passed to CFS.

Figure 3 – High-Level Technical Infrastructure

Design Assumptions

• COTS project – there will be no customizations – only configuration changes made. The priority is on maintaining a simple architecture that is easily patched and upgraded by the vendor.

• ADFS integration (for authentication) will leverage PBGC’s existing SAML 2.0 framework.

• ICAM reporting requirements and controls must be adhered to from the start of the project.

Version 2.0 Page 8 11/02/2022

• All FedRAMP hosting and data standards will apply.

• Data masking is not supported by OneStream XF out of the box.

• OneStream will host one single “environment”, with multiple “applications/instances” to host DEV, TEST, and PROD instances.

• Ongoing upgrades/patching/monitoring will be shared between PBGC and OneStream, subject to a notification and review cycle with PBGC business owners.

Design Constraints No automated integration outside of ADFS is planned.

Only DEV, TEST, and PROD instances will be created.

Design Dependencies The ADFS / SAML 2.0 framework must be available for authentication.

The DEBS, CFS, and HR systems must support import and export of tabular data in standardized form (CSV and/or Excel files).

An SMTP email service must be available for outgoing automated email notifications and reporting. This email service (and an email service account) must be maintained independently by PBGC. It is external to OneStream, and OneStream must be permitted to issue SMTP service calls to it.

Version 2.0 Page 9 11/02/2022

Reference and Justification Justification

ADFS AUTOMATION

OneStream supports basic authentication through ADFS integration but does not support automating updates through that integration. Users will request access and have this recorded in Active Directory, but this will not automatically be transmitted to OneStream for activation.

Users will open a service ticket, and an OneStream system administrator will perform user activations manually. Similarly, when a user has access removed, a ticket will be opened to remove them from OneStream.

Strategy and Performance

Table 1 – Target State (from BNA)

BUDGET SEGMENT TARGET STATE BY BDMS DESIGN MEETS

TARGET

A purpose-built Budget Formulation Solution that enables and automates the formulation and adjustment functions of budget management.

YES

Budget formulation and approval process is automated. YES All budget data is stored in a central repository with role-based access controls, following the principle of least privilege.

YES

Budget prioritization tool is used during budget formulation for all budget submissions.

YES

Budget reports are not labor intensive to produce. Budget reports use real-time data, so business decisions are based on up-to-the-minute information.

YES

Adjustments to approved budget are considered on a priority basis and supported with automation.

YES

A comprehensive Budget Formulation Solution for the Agency eliminates costly and time-consuming file management, version control, error checking and data consolidation which is required today when Excel spreadsheets are used to support budget formulation.

YES

Workflow automation is available for all budgeting processes and workflows. Real-time budget status is also available via dashboard to all users.

YES

The Budget Formulation Solution will have reporting capabilities to help with budget report requirements.

YES

Integration with Consolidated Financial Systems (CFS) will help reduce manual processing, enabling faster review and decision making.

Yes (CFS integration is still manual in current release)

Version 2.0 Page 10 11/02/2022

Business Architecture The scope of this BDMS project includes the current business and operational functions provided by the Budget Department, including budget formulation, reporting, and the budget review process with OMB and Congressional oversight.

Core Functional Capabilities Below are the anticipated core capabilities to be implemented in the solution.

Front-end User Interface:

• Implement a modern, practitioner-facing front end that is intuitive and user-friendly.

• Provide online and intuitive help screens.

• Provide dashboard to access self-service features.

• Integrate communications with the front end.

Budget Formulation Process:

• Operational budgeting

• End-to-end planning

• Forecasting

• Reporting

• Data analytics

Infrastructure and Performance Monitoring:

• Ensure scalability and maintainability (including production and development environments).

• Ensure 24x7availability of BDMS for all users.

• Implement a proactive, real-time application performance monitoring and reporting framework, including real-time alerts and notifications.

• Leverage all future releases of core OneStream XF product.

Intuitive and User-Friendly Front End for Admin Staff:

• Maintain simple site/system administration.

• Leverage OneStream solution to perform site/system administrations.

Budget Formulation Process Improvement

Version 2.0 Page 11 11/02/2022

The current Budget Formulation business process flow, which must be supported by the BDMS, is shown below in Figures 4 and 5.

Figure 4 – Business Process Flow Diagram

Figure 5 – Business Process Flow Diagram (cont.)

Version 2.0 Page 12 11/02/2022

Below is a more detailed overview of the Unfunded Reallocation workflow.

Figure 6 – Unfunded Reallocation Workflow

Version 2.0 Page 13 11/02/2022

Application Architecture The application architecture sections describe the components and modules that compose the solution and their interactions within the solution and with other key components of the design.

This section is primarily about the software design (COTS or custom) with detailed descriptions of data interaction and infrastructure components are reserved for other sections of the design document. This section includes an application architecture that provides a visual description of how the modules work together.

The process for moving data between OneStream and the DEBS and CFS systems will closely mirror the current practice of assembling reports for export and import using Excel. There will be no material changes on the DEBS or CFS ends. OneStream will be used to build the spreadsheets, but the action to move the data itself will remain manual and remain subject to existing review and approval cycles.

Version 2.0 Page 14 11/02/2022

OneStream Cloud and PBGC Connectivity

PBGC User

ADFS

Identity Provider

OneStream Boundary [load balancer] [IIS web servers]

OneStream Windows Client App

Security Cert

SAML

Trusted

Relationship

SAML

Authentication

Session

BDMS Connectivity Firewall / ACL

HTTPS / SSL

No VPN

Connection URL Select App dev/test/prod

CFS HR

Internal DB

CFS Actuals Manual export OneStream import

DOL OMB CBJ

External DB

DOL Reporting Manual Submission

Figure 7 – OneStream-PBGC Connectivity

Version 2.0 Page 15 11/02/2022

Data Architecture The BDMS and database is hosted within the OneStream Cloud. OneStream XF is a unified Smart CPM platform solution that can be expanded upon, extended, and blended to meet the needs of a data consumer. The OneStream application is built entirely inside of a single MS SQL Server database that contains tables for metadata, tables for fact data, and application artifacts (forms, workflow profiles, etc.). Some of those tables represent the Stage (relational, pre-cube data), others represent OneStream XF Marketplace solutions, and others represent the cube(s).

A description of the data and the interactions between them is contained in the Logical Data Model below.

Figure 8 – OneStream Relational Architecture

XF Financial Model – Is the Cube (one to many Cubes) for the Consolidation, Planning, and Analytic engine.

XF Framework – Is the backbone of the application and supports security, reporting interfaces, auditing, metadata management, etc...

OneStream XF Workflow - manages review and approval processes with fully customizable user tasks and steps to ensure data quality, accuracy, traceability, and auditing capabilities.

OneStream XF combines Analytic, Stage, Relational, and Source transactional data in One Model. It provides a simple end-user experience to collect, and update detailed relational data.

There is full auditability with all relational data naturally connected to analytic data and which is drillable. This permits the data to live where it belongs, not all data belongs in the cube.

OneStream XF balances the right mix of where analytical and operational data resides for the best performance and analysis.

https://www.onestreamsoftware.com/solutions

Version 2.0 Page 16 11/02/2022

Data Design The specifics of the current OneStream solution are proprietary to the OneStream vendor; hence our review is limited to the documentation shared by OneStream. Below is a diagram showing their high-level data model. Subject to future revisions as data becomes available.

Since it is a stand-alone application, we can focus on its points of interface with other PBGC systems.

OneStream will host this data in an array of data cubes, which will present new opportunities for analytics, forecasting, and reporting.

Data Configuration Model

A formal data dictionary is proprietary to OneStream. While OneStream is built on a SQL Server relational database, most configuration actions are done by applying changes at the dimension level, and the OneStream framework then updates the relational database according to this dimensional metadata. In only a few administrative areas are flat SQL tables referenced in a traditional way.

This OneStream deployment has been “configured”, not “customized”. This is to say that all customization work has been done “inside the box”, and has not involved external components, plugins, services, or independent data pipelines. There are bits of Visual Basic code embedded in some Business Rule objects, and SQL queries built into various reports, but these are not deployable outside the OneStream framework. They are not being versioned or archived externally. And there is no case in which they could be migrated or redeployed outside the OneStream hosting platform. So, these code elements are like the way visual basic can be used within Microsoft Access to enhance functionality. These enhancements are a form of configuration of the baseline tool and are not an external modification that can be maintained and extended outside the OneStream framework.

Dimensions are a way of depicting a hierarchical mapping of baseline objects, such that they can be created, viewed, and manipulated from multiple contexts and business use cases. These use cases, along with the OneStream security model, are all applied at the dimension level, and the engine propagates updates at the relational table level. So, while it is possible to catalog the tables in the database, it is more helpful to document dimensions, which is where configuration and customization work is commonly done.

The dimensions below are all part of the baseline OneStream deployment, while metadata within is configured by the deployment team.

Persistent and Dynamic Data

Persistent Data:

Framework Database – how the application/configuration is stored

Version 2.0 Page 17 11/02/2022

Framework can be thought of as the system database. This database contains system level information and servers as a controlling database or gateway to accessing application data.

OneStream XF always connects to just one Framework database which is specified during the application server configuration process. The Framework database maintains the list of application databases that are associated with the OneStream XF instance.

The configuration data stored here is what goes into moving customized configurations from one application/environment to the next, and is what gets exported, stored, and version-controlled in the PBGC DevOps code repository (in the form of exported XML files). This is also what the vendor will move when supporting builds that include third-party components such as Task Manager, Parcel Service, and People Planner.

Dynamic Data:

Application Database(s) – how BDMS data is stored Application can be thought of as a data content database. Each OneStream XF instance can access many application databases. An application database contains information specific to a set of Financial Models and the Workflows used to manage the models. Information about PBGC users is static.

This “business data” is never moved automatically from one application/environment to the next.

If business records must be moved, it will be done as a data export-import migration, conducted manually.

Transformation of Data:

State Database – how user sessions are maintained State can be thought of as a temporary database. OneStream XF uses the State database to store temporary report state information. This schema can be deleted and recreated at any point because the information contained in the database is only relevant to a user’s current session.

Version 2.0 Page 18 11/02/2022

Data and Information Exchange Integration/Interfaces

There are just two points of interface for BDMS. Information exchange between PBGC and OneStream is through transfer of large file sets between both systems using SFTP and protected by SSL encryption when in transit. Data can be freely downloaded, manipulated locally in excel and uploaded back into OneStream application. Documentation of the web services consumed, and data elements are described below:

Microsoft Active Directory OneStream supports SAML 2.0 authentication and ADFS Integration. These are the two methods that will be used for access and authentication to OneStream. Both the SAML Configuration and Azure AD configuration guides are embedded below for reference. Note that AD integration will only support Authentication, not Access. (Access will be managed and controlled manually – access requests and approvals will be tracked in AD, and changes will create tickets to implement updates manually in OneStream, by the System Administrator.) No metadata will be used or stored in AD, other than approved user roles.

External Security Providers and Single Sign-On (SSO) OneStream XF Web Server uses Secure Sockets Layer (SSL) encryption for access to XF application (https). OneStream supports single sign-on (SSO) logins through SAML 2.0 with

ADFS.

ADFS will be setup as Identity Provider and OneStream Applications as Service Provider.

Federated Single Sign-On enables applications to redirect to Azure AD (“Pass-Through Authentication") or SAML 2.0 provider for user authentication.

OneStream XF for external authentication with Transport Layer Security (TLS) encryption.

ADFS allows secure sharing of identity information between trusted entities.

PBGC Firewall PBGC maintains a firewall, which must be configured to allow outbound traffic to the OneStream infrastructure. This is done by ensuring that the IP address (and port) specified by OneStream is included in the firewall Access Control List (ACL).

Configure SAML 2.0 SSO with ADFS and OneStream as Service Provider OneStream supports single sign-on (SSO) logins through SAML 2.0 with ADFS. ADFS will be setup as Identity Provider and OneStream Applications as Service Provider. ADFS setup to log in to your OneStream instance will require:

• An Active Directory instance where all users have an email address attribute.

• The ADFS signing SSL certificate and its public fingerprint.

Version 2.0 Page 19 11/02/2022

• A private certificate installed in the web server to sign the logout requests to ADFS and its public fingerprint.

• If using OneStream Windows App: A trusted certificate issued to localhost installed on all client machines for hosted SSL and its thumbprint.

DEBS

The process for moving data between OneStream and the DEBS will closely mirror the current practice of assembling reports for export and import using Excel. There will be no material changes on the DEBS end. OneStream will be used to build the documents, but the action to move the data itself will remain manual and remain subject to existing review and approval cycles.

The Budget Department provided a template for PBGC’s standard DEBS submissions (DOL, OMB, CBJ), in the form of a Word document. BDMS uses Task Manager to assemble a Word document that complies with this template. Task Schedule uses fields containing narrative content to paste into this template. This narrative content is drafted and approved within BDMS, subject to version control, check-out/check-ins, and collaborative contributions from multiple people.

No tabular financial data is gathered in any automated way from BDMS budget formulation data.

The data that exists and that gets published in this Word document is drafted “manually” by BD administrators and inserted in narrative fields. None of the financial data is “live” data – it is subject to this manual process of compilation, insertion, and review.

Similarly, the DEBS document, once exported and saved as a Word document, is submitted to DEBS in a manual process. There is no automated submission process, and there is no automated validation or error-handling process when a DEBS submission is received. There is also no designated single point of contact at DOL for document submission – it is an administrative process, not an automated electronic process requiring tech support.

CFS and HR The process for moving data between OneStream and the CFS and HR will closely mirror the current practice of assembling reports for export and import using Excel. There will be no material changes on the CFS or HR end. OneStream will be used to build the spreadsheets, but the action to move the data itself will remain manual and remain subject to existing review and approval cycles.

CFS “actuals” data was loaded into BDMS in a one-time data load process prior to launch. Data at launch spanned four fiscal years of data prior to implementation. Post-launch, actuals data will be pulled from CFS and loaded into BDMS annually, complying with the report template sample (to be linked to here.)

Version 2.0 Page 20 11/02/2022

By a similar process, budget formulation data that is approved by the full DEBS submission cycle (DOL, OMB, CBJ) is provided to CFS from those documents directly. There is no automated import of BDMS data into CFS. Approved budget execution data, including formulation and spend-plan, is handled outside of BDMS. The method of loading this external data from BD spreadsheets into CFS is outside the scope of this document.

OneStream Cloud to PBGC Connectivity

OneStream –There will be no special VPN tunnel. All connections run through the firewall via HTTPS/SSL service calls. All OneStream application environments are accessed through the same process and subject to the same security protocols. The firewall must be configured to allow outbound traffic to OneStream.

Privileged account access (for the purpose of conducting administrative tasks such as exporting/loading configuration or enabling users as part of Fulfillment) runs through service accounts contained and controlled by CyberArk.

Version 2.0 Page 21 11/02/2022

Data Exchange Data Migration supporting Initial Launch

Data was migrated into BDMS from Budget Formulation records (in the form of Excel files) and Budget Actuals (in the form of data files from CFS) as part of the 1.0 launch of BDMS. This was a set of manual imports, with several rounds of editing and review (in Excel) before it was brought into BDMS. Below is a mapping from CFS Budget Actuals data to BDMS data dimensions.

Scheduled Import of Budget Actuals

Budget Actuals will be exported from CFS through an automated process in a future release of BDMS. This will take place on an annual schedule, after this new BDMS release has been deployed. The BDMS support team will assist BD in creating and testing an automated data extract process. Note that the import of Budget Actuals data into BDMS will always be a manual process, to accommodate BD’s internal review and quality controls.

Unscheduled Data Imports

The BDMS team will managed ad-hoc data imports as needed, in coordination with BD requirements. These imports may come from federal data sources like CBJ, from PBGC data sources like CFS (through standard and ad-hoc reporting), and from BD data files (though these data sources have likely all been included in the initial deployment of BDMS already.)

Ad-hoc data imports will be managed either as a business workflow task (in the case of data sources which have been used before, as part of routine data management), or as encapsulated in an RFC (in the case of large data sources that require updates to the BDMS dimensional data model to accommodate).

People Planner Data Imports

There is a scheduled import of the data:

An initial load will occur during the beginning of the formulation period Periodic loads will occur throughout the formulation period to reflect updated employee status Data will always need to be imported into BDMS manually This data is subject to privacy controls, and will be masked in lower environments

– ultimately it will consist of synthetic data in lower environments

Version 2.0 Page 22 11/02/2022

Infrastructure BDMS is hosted within the OneStream Government Cloud and the infrastructure will not be documented here. This infrastructure is controlled by OneStream, and they reserve the right to change infrastructure components based on the ability to support Service Level agreements with

PBGC.

FedRAMP Certified Environment

In addition to BDMS high-level requirements, all FedRAMP requirements for a cloud service provider are also in effect. For example, all servers and storage capacity within the solution are scalable and the business continuity Recovery Time Objective (RTO) target is 24 hours.

FedRAMP certification is integral to the security posture of BDMS. The system will leverage the existing FedRAMP Authorization to Operate (ATO) to inherit applicable security controls provided by OneStream. The system owner is responsible for identification, tailoring, implementation, and monitoring of system-specific controls based on the system categorization and assessed information security risk. The implementation statements for both inherited and system specific security controls will be documented in the System Security Plan (SSP). This plan will be developed and maintained in Cyber Security Assessment and Management (CSAM) tool.

In addition to what is documented in the SSP, Access/Audit Controls on the PBGC side are governed by an ICAM reporting loop, in which two reports are transmitted daily to the Security team’s Splunk processing group. The Users and Roles report contains all active users and the roles assigned to them, to be matched against their corresponding records in the PBGC Service Catalog. The Security Events report contains applicable events such as dates of last login, error messages, etc. It does NOT contain failed login attempts since authentication is handled on the PBGC side using SSO.

Email Service Account

OneStream does not send or receive emails directly. Email notifications and scheduled report deliveries are handled by sending SMTP service calls to a PBGC-controlled cloud-only email service account. This account is configured for sending emails to internal PBGC recipients only.

It is not intended to receive email, and there is no provision for monitoring this account.

This is a cloud-only account hosted in Office 365. While it is a trusted account by PBGC email systems, it is logically isolated and hosted externally. This is being done to boost security, given that the credentials for this account must be shared with the vendor. The vendor is maintaining these credentials in a privileged account vault, similar to CyberArk, and subject to the same access controls and audit requirements that our CyberArk users are subject to.

CyberArk Access Control

Privileged actions will be managed from access-controlled service accounts, run by designated members of the Fulfillment Team and the Incident Response Team.

Version 2.0 Page 23 11/02/2022

“Privileged Actions” include account/role changes (such as adding new users, disabling existing users, and reassigning Roles to users) and configuration management tasks (specifically, moving configuration-builds from DEV to TEST to PROD as assigned in RFC tasks).

These service accounts are accessible only through CyberArk, connecting through to OneStream per CyberArk’s standard process of instantiating Remote Desktop connections. In this case, they connect to two physical jump servers set up specifically for BDMS, both having the OneStream windows client installed and configured.

XF Marketplace Components

Parcel Service Parcel Service allows you to create document packages or groups of packages that can be delivered based on predefined distribution settings. These documents may be in the form of certain exportable file formats (such as PDF) or as document files, depending on how they are created. Parcel Service can be configured to send packages to email lists, single email addresses, or file locations on the OneStream file system. BDMS is using Parcel Service to deliver standard reports to designated users, as configured in Task Manager (see below.)

Parcel Service is a plugin for OneStream, accessible through the OneStream Marketplace, and installable only through certified OneStream partners.

Task Manager Task Manager provides the ability to schedule data management sequences that execute a data management step within the application. Data management sequences are an embedded capability within OneStream, and Task Manager provides for automating these as Tasks in a calendar interface. Task Manager drives certain processes such as special report creation (as with automated assembly of Budget Department deliverable documents to be submitted to DEBS and OMB, and with scheduled delivery of standard reports via Parcel Service.)

Task Manager is a plugin for OneStream, accessible through the OneStream Marketplace, and installable only through certified OneStream partners. It is different and distinct from Task Scheduler, which is built-in to OneStream and is available out of the box.

Snippets Code Library The Snippets code library is an installable module of Visual Basic utility classes and methods, designed to extend OneStream functionality and provide for fine control of data manipulation and reporting tasks. It may be used to save standard “book” reports out to a CSV data file in the OneStream file system, for example, and then email that data file without the limitations of Parcel Service.

Snippets is a code library for OneStream, accessible through the OneStream Marketplace, and installable only through certified OneStream partners. It serves as a coding reference and source of templates for common coding patterns used in OneStream business rules. It is not a registered resource library that developers can incorporate as a class or inherit from. This “sample code” is also available outside of Snippets but is more useful to developers when installed as a component because it can leverage the development UI and be more easily searched while working on code.

Version 2.0 Page 24 11/02/2022

People Planning People Planning (PLP) provides the ability to budget and project costs at an employee detail level within the application. This solution allows detailed planning with the ability to incorporate into a dimensional cube providing data transparency from the dimensional model to the individual detailed records. Note that “People Planner” is the BDMS-branded name we are using within PBGC to refer to the “People Planning” module from OneStream.

People Planning is an OneStream MarketPlace solution which is included in the FedRAMP authorization and is installable only through certified OneStream partners.

Configuration and Build Management

Configuration Management for the BDMS / OneStream solution is the process by which updates are developed, tested, and deployed to the production environment, and how they are tracked, archived, and made auditable.

The common ways that configurations and/or data may be passed from one application to the next are documented in the sub-sections below.

Full Application Copy PBGC may request that OneStream copy an entire application from one instance to another, or to a brand-new instance, by filing a simple service request in the OneStream portal. Such requests are usually fulfilled either the same day or by the next day. This copies everything:

• Configuration

• Data

• OneStream XF Marketplace components and their underlying data

This method is useful for synchronizing the Production application down to lower applications (Development, Test), but is not appropriate or usable for moving configuration/updates from lower applications up to Production, because all Production data would be overwritten by what is in those lower applications.

It is also useful for creating temporary application backups or workspaces, where developers can test out updates without disrupting the workflow for other developers/testers, or where an application snapshot is needed to preserve a point in time for BDMS.

Since this method is handled by service ticket, there is no need for an access-controlled connection via privileged service account (CyberArk.)

Export/Load of Configuration OneStream includes an Export/Load tool out of the box, which allows administrators to export configurations as XML files (or zip files containing XML files). These exported files may also

Version 2.0 Page 25 11/02/2022 be imported into the same or other applications. They include only configuration data, not record-based business data. They may be scoped to individual configuration elements, or they may include ALL configuration elements at once. They may contain any and all OneStream-native custom configurations, and do NOT include all aspects of OneStream XF Marketplace components. Dashboard related components and Business Rules for MarketPlace solutions are migrated, but not the individual register configuration

This method may be used to copy specific pieces of customized configuration from one application to another. These copies are “additive”, in that while they may overwrite existing configuration elements, they do not delete any. So, if a piece of configuration must be deleted in another environment, this will have to be performed manually.

This method is appropriate for moving in-the-box configurations up from lower applications to higher ones, given appropriate testing and auditing controls, and given the limitations outlined above.

It may also be used to extract a full local copy of an applications configuration for storage, versioning, and archival. This local copy presents a snapshot of all in-the-box configurations of a OneStream deployment but contains no business data and nothing regarding OneStream XF Marketplace components. This local copy may be archived in PBGC’s code repository in Azure DevOps, and tracked for purposes of snapshotting, versioning, and audit controls.

It is not, by itself, sufficient to rebuild the BDMS deployment configuration, so this is not a way to “backup and restore” a working BDMS application in terms of disaster recovery, because it does not include business data or Marketplace components. All “backup and restore” requirements are being handled by OneStream, as per its FedRAMP certification requirements.

Export/Load actions should be performed only using access controlled privileged service accounts, via CyberArk. Access to this functionality will be restricted to these privileged service accounts in the Production application but will be accessible to administrative roles in the lower applications.

OneStream XF Marketplace Components These components include Task Manager, Parcel Service, Snippets, and People Planning. They are distributed to OneStream customers through the OneStream XF Marketplace. They are not included in OneStream out of the box. Portions of their deployment/configuration are managed through the built-in Export/Load function, but most of their configuration is performed using templates (if available) or by manual configuration.

The initial migration of a MarketPlace solution from Dev to Test or Test to Dev can be addressed with a OneStream support ticket. OneStream will migrate the backend database tables and corresponding data and the BDMS dev team will manage the setup and configuration. Future updates and enhancements require the use of templates (if available) or manual configuration.

Similarly, version updates of Marketplace components must be closely coordinated with OneStream tech support. OneStream is responsible for testing each Marketplace component

Version 2.0 Page 26 11/02/2022 against each version of OneStream, and must explicitly support such upgrades, in a close handshake with PBGC and with those Marketplace component developers.

Since this method is handled by service ticket, there is no need for an access-controlled connection via privileged service account (CyberArk.)

Data-Only Moves Data, meaning actual business-level records and not application-level configuration metadata, may be moved from one application to the next by export and import tools. These migrations are handled manually – there is no support for an automated migration or synch-over-time without manual oversight. Data management sequences (a function within OneStream) may be used to support, perform, and schedule the export side of such moves, but the import side must be performed manually.

This method is appropriate for synching targeted data down from Production to lower applications, or for transferring data between lower applications. If data must be moved into the Production application, it must be treated as a formal data migration, and must be tested and approved before being implemented. In this case, an application copy of Production can be made available temporarily, for testing the migration prior to execution.

These data-only moves may be used to store snapshots of data sets for local archival, but this can be done most efficiently by simply saving reports locally. They do not include any application metadata or anything involving Marketplace components.

While reporting may be done by any OneStream role (subject to the security matrix), data exports and imports which use the Export/Load functionality in OneStream should be performed only using access controlled privileged service accounts, via CyberArk. Access to this functionality will be restricted to these privileged service accounts in the Production application but will be accessible to administrative roles in the lower applications.

Version 2.0 Page 27 11/02/2022

Technology Stack Web Client, Web Server, Application Server, and Database Server Overview

Table 2 – OneStream Technology Stack

OneStream XF Component Technology Microsoft Office OneStream Excel (optional add-in not being implemented for

PBGC)

Windows Client OneStream Windows App (including Spreadsheet and Text Editor features) OneStream Studio for report authoring (optional) ClickOnce application installer

Administration OneStream Server Configuration Utility for initial product configuration OneStream Database Configuration Utility for initial product configuration

Web Server Microsoft Internet Information Services (IIS), Windows Process Activation Service (WAS) and .NET Framework using Windows Communication Foundation (WCF) OneStream Web Server software installation

Application Server

Microsoft Internet Information Services (IIS), Windows Process Activation Service (WAS) and .NET Framework using Windows Communication Foundation (WCF) OneStream Application Server software installation

Database Server Microsoft SQL Server Transaction logs and data at a minimum should be stored on separate drives to spread I/O across drives.

Mail Server Microsoft Office 365 online (email service account) SMTP Service

Technology Stack Detail

OneStream utilizes a combination of browser client, windows app, application servers and database servers to render the rich UI, process user requests, compute, analyze, and report budget data. A high-level illustration of the technology stack is shown below.

Version 2.0 Page 28 11/02/2022

Figure 9 – OneStream N-tier Architecture Stack

BDMS is running on the “Level 2” tier of OneStream infrastructure offerings

Microsoft ClickOnce technology is an option for OneStream deployments, to install and maintain version integrity for the OneStream Windows client, but PBGC is NOT using ClickOnce. OneStream has provided the Windows client independently of ClickOnce, and PBGC will maintain installation and version upgrades down to the desktop through a combination of manual planning and automated deployment through Software Center.

The only time the Windows client will ever be updated is when the OneStream cloud application gets updated – there is a one-to-one match that must be maintained between client version number and cloud version number. Any attempts to connect from a Windows client to a mismatched cloud version will result in an error message and a request to install the correct Windows client version.

Version upgrades are installed on-demand when they are available, at PBGC’s planning and discretion. Each version upgrade will be accompanied by a new Windows client installer, which will be set up in Software Center for automated distribution. BDMS currently uses version 6.6 of OneStream.

In addition, version upgrades require 4 hours of down-time. They will be scheduled during non-busy periods, set for Friday afternoons (1pm-5pm EST), and coordinated with the Windows team for simultaneous client upgrading. If users are offline when the OneStream cloud version has been upgraded, they will be able to upgrade their Windows client by simply clicking the new version in Software Center to trigger installation.

It is important to be very specific with OneStream about which version they need to upgrade to, and that they rebuild the security configuration after each upgrade.

Web-based End User Deployment is also an option with OneStream, but PBGC is NOT using the web client. The web client requires the Silverlight browser plugin, which has been deemed a security risk, and has been removed from the TRM.

Version 2.0 Page 29 11/02/2022

OneStream XF provides a Studio Client Package, for creating special report layouts.

This capability is currently out of scope for BDMS, and there is no provision for installing the OneStream XF Studio package at PBGC.

OneStream XF provides for an Excel plugin that would allow some workflow and data management processes to be conducted directly in Excel. PBGC is not implementing this functionality, for a variety of security reasons.

To be very clear, the only way for users to connect to OneStream at PBGC is through the Windows client, as hosted in Software Center.

Version 2.0 Page 30 11/02/2022

Information Security and Privacy

The Data Quality Engine is responsible for controlling data confirmation and certification processes. This Confirmation Engine is used to define and control the sequence of data value checks required to assert the information submitted from a source system is correct. The Certification Engine is responsible for managing user certifications and determining the Workflow dependents’ completion status.

The preferred access and authorization mechanism will be SAML 2.0 with ADFS integration.

PIV cards will be required, as with any SSO application. There will be no separate password required. The Business Information Owner has approved this solution.

As part of the FedRAMP process, OneStream keeps an updated System Security Plan (SSP) document which details all the processes and methods used to meet control specifications mandated by FedRAMP. Refer to the latest accepted SSP (available on request to the ISSO) for details.

User Access & Roles Management BDMS requires access by internal PBGC users, who will use standard PBGC Single Sign-on authentication to gain access. All authorization for users will be controlled by the OneStream security model.

User Management

Internal user roles are designed to allow PBGC personnel to execute and manage all Budget Formulation functionality. Roles are for system-wide users, and Groups are for department-level access-controlled user groups.

Application Security XF uses a four-prong approach to manage security which consists of Workflow Security, Entity Security, Account Security, and Security Roles. OneStream XF’s security is determined through Users and Groups.

This is the start of the file's text. The full file is on GovTribe.

File details come from the government source that posted it. Updated .