Attachment-G1-ACF_ E-Authentication Agreement_V1.0.docx
DOCX document 102 KB Posted
- Attached to
- Legal Services for Unaccompanied Alien Children (UAC) Federal contract opportunity
- Solicitation number
- 75P00126R00003
- Issued by
- Not on record
About this file
This is an e-Authentication Agreement template document that provides guidance for determining authentication requirements for information systems within the Administration for Children and Families (ACF). The document outlines a threshold analysis and risk assessment process to establish appropriate authentication assurance levels for browser-based, external-facing systems that require user authentication. Organizations complete a three-question threshold analysis to determine if a full e-Authentication Risk Assessment (ERA) is necessary. If all threshold questions are answered affirmatively, the system owner must complete a comprehensive risk assessment evaluating six categories of potential impact from authentication failures: inconvenience or reputational damage, financial loss, harm to agency programs or public interests, unauthorized release of sensitive information, personal safety risks, and civil or criminal violations. Each impact category is rated as low, moderate, or high based on specific criteria. The assessment results are mapped to one of four assurance levels, with assurance level 4 representing the highest security requirements for systems with the greatest potential for harm. The document requires approval signatures from both the system owner and the ACF Chief Information Security Officer (CISO) or delegate. This is a template document establishing the procedural framework and assessment methodology rather than a completed assessment specific to any particular system.
View the file
Other files for this federal contract opportunity
Show all 50
Legal Services for Unaccompanied Alien Children (UAC) has more files on GovTribe.
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
Enter System Name ACF e-Authentication Enter System Name
Version 1.0 Dated: 6/26/25
Table of Contents
| 1. Introduction and Purpose | 2 |
| 2. Threshold Analysis | 2 |
| 3. E-Authentication Risk Assessment (ERA) | 3 |
| 3.1 Step 2: Potential Impact of Authentication Errors | 3 |
| 3.1.1 Potential impact of inconvenience, distress, or damage to standing or reputation: | 3 |
| 3.1.2 Potential impact of financial loss: | 3 |
| 3.1.3 Potential impact of harm to agency programs or public interests: | 4 |
| 3.1.4 Potential impact of unauthorized release of sensitive information: | 4 |
| 3.1.5 Potential impact on personal safety: | 4 |
| 3.1.6 The potential impact of civil or criminal violations is: | 5 |
| 3.2 Step 3: Authentication Assurance Level | 5 |
| 3.3 Final Assurance Level | 6 |
| 4. Approval and Authorization | 6 |
| Document Revision History | 7 |
1. Introduction and Purpose This document guides the System Owner through the e-Authentication Threshold Analysis (ETA) to determine if the full E-Authentication Risk Assessment (ERA) process is necessary for the system, per OMB M-04-04, NIST SP 800-63, and HHS security and privacy policies.
2. Threshold Analysis If the answer to any of the following questions is “No,” please proceed to section 4 and sign the document.
If the answer to all three questions is “Yes,” please complete the ERA in section 3 before signing the document.
Table 1. ERA Threshold Analysis
| Question |
| Y/N |
| Does the information system require user authentication to access its data/functionality? |
| Select answer |
| Is the system browser-based? |
| Select answer |
| Is the system external-facing? (e.g., is this an information system with users connected only to the public Internet?) |
| Select answer |
3. E-Authentication Risk Assessment (ERA) This section helps quantify the risk of authentication failure based on potential harm to users, the agency, or the public.
3.1 Step 2: Potential Impact of Authentication Errors
Indicate the potential impact of an authentication error from the system based on the explanations provided for low, moderate, and high impact.
Please note that if the system has multiple types of transactions (e.g., create, update, delete, read), a separate analysis is required for each type's potential impact. The impact level must reflect the maximum possible impact for each transaction type.
3.1.1 Potential impact of inconvenience, distress, or damage to standing or reputation:
Potential Impact Categories for Authentication Errors
☐ Not Applicable
☐ Low: At worst, limited or short-term inconvenience, distress, or embarrassment to any party.
☐ Moderate: At worst, serious short-term or limited long-term inconvenience, distress, or damage to the standing or reputation of any party.
☐ High: Severe long-term inconvenience, distress, or damage to the standing or reputation of any party (ordinarily reserved for situations with particularly severe effects or which affect many individuals).
3.1.2 Potential impact of financial loss:
Potential Impact Categories for Authentication Errors
☐ Not Applicable
☐ Low: At worst, an insignificant or inconsequential unrecoverable financial loss to any party, or at worst, a trivial or inconsequential agency liability.
☐ Moderate: At worst, a serious unrecoverable financial loss to any party, or a serious agency liability.
☐ High: Severe or catastrophic unrecoverable financial loss to any party, or severe or catastrophic agency liability.
3.1.3 Potential impact of harm to agency programs or public interests:
Potential Impact Categories for Authentication Errors
☐ Not Applicable
☐ Low: At worst, a limited adverse effect on organizational operations, assets, or public interests. Examples of limited adverse effects are (i) mission capability degradation to the extent and duration that the organization can perform its primary functions with noticeably reduced effectiveness, or (ii) minor damage to organizational assets or public interests.
☐ Moderate: At worst, a serious adverse effect on organizational operations, assets, or public interests. Examples of serious adverse effects are (i) significant mission capability degradation to the extent and duration that the organization can perform its primary functions with significantly reduced effectiveness, or (ii) significant damage to organizational assets or public interests.
☐ High: A severe or catastrophic adverse effect on organizational operations, assets, or public interests. Examples of severe or catastrophic effects are (i) severe mission capability degradation or loss to the extent and duration that the organization cannot perform one or more of its primary functions, or (ii) significant damage to organizational assets or public interests.
3.1.4 Potential impact of unauthorized release of sensitive information:
Potential Impact Categories for Authentication Errors
☐ Not Applicable
☐ Low: At worst, a limited release of personal, U.S. government sensitive, or commercially sensitive information to unauthorized parties resulting in a loss of confidentiality with a low impact as defined in FIPS 199.
☐ Moderate: At worst, a release of personal, U.S. government sensitive, or commercially sensitive information to unauthorized parties resulting in loss of confidentiality with a moderate impact as defined in FIPS 199.
☐ High: A release of personal, U.S. Government Sensitive, or commercially sensitive information to unauthorized parties resulting in loss of confidentiality with a high impact as defined in FIPS 199.
3.1.5 Potential impact on personal safety:
Potential Impact Categories for Authentication Errors
☐ Not Applicable
☐ Low: At worst, minor injury not requiring medical treatment.
☐ Moderate: At worst, moderate risk of minor injury or limited risk of injury requiring medical treatment.
☐ High: A risk of serious injury or death.
3.1.6 The potential impact of civil or criminal violations is:
Potential Impact Categories for Authentication Errors
☐ Not Applicable
☐ Low: At worst, a risk of civil or criminal violations that would not ordinarily be subject to enforcement efforts.
☐ Moderate: At worst, a risk of civil or criminal violations that may be subject to enforcement efforts.
☐ High: A risk of civil or criminal violations that are especially important to enforcement programs.
3.2 Step 3: Authentication Assurance Level
Compare the values in tables in Section 3.1 with those in Table 3 below.
Choose the Assurance Level Impact Profile value (1, 2, 3, or 4) that best matches the potential impacts in Table 2. Sometimes, a potential impact may fit more than one assurance level. Use the context to decide which assurance level is most appropriate.
Table 2. Assurance Levels
| Maximum Potential Impacts for Each Assurance Level |
| 1 |
| 2 |
| 3 |
| 4 |
| Potential impact of inconvenience, distress, or damage to standing or reputation |
| Low |
| Moderate |
| Moderate |
| High |
| Potential impact of financial loss |
| Low |
| Moderate |
| Moderate |
| High |
| Potential impact of harm to agency programs or public interests |
| N/A |
| Low |
| Moderate |
| High |
| Potential impact of unauthorized release of sensitive information |
| N/A |
| Low |
| Moderate |
| High |
| Potential impact on personal safety |
| N/A |
| N/A |
| Low |
| Moderate High |
| Potential impact of civil or criminal violations |
| N/A |
| Low |
| Moderate |
| High |
3.3 Final Assurance Level
Identify the dominant, recurring assurance level for each maximum potential impact. This is the system's final assurance level requirement.
Enter assurance level number Enter assurance level
4. Approval and Authorization This eAuthentication has been reviewed and approved by the System Owner.
Enter System Owner name Digital Signature – Date
This eAuthentication has been reviewed and approved by the ACF OCIO CISO (or their delegate).
Enter CISO name Digital Signature – Date
☐ If using a delegate, enter their name and select this box Enter delegate name
Document Revision History
| Date |
| Version |
| Comments |
Version 1.0 e-Authentication 1 image1.png image2.png
File details come from the government source that posted it. Updated .