Attachment-G8-ACF_System Categorization_V1.0.docx

DOCX document 99 KB Posted

Attached to
Legal Services for Unaccompanied Alien Children (UAC) Federal contract opportunity
Solicitation number
75P00126R00003
Issued by
Not on record

About this file

This is a system categorization document that serves as a technical reference guide for ACF (Administration for Children and Families) system classification and security control requirements.

The document establishes categorization standards for systems supporting the Unaccompanied Alien Children (UAC) legal services contract, defining how systems should be classified based on impact levels and security requirements. It provides detailed guidance on system categorization methodologies, security control frameworks, and implementation procedures aligned with federal information security standards. The document specifies control selection criteria for systems operating at different impact levels (Low and Moderate), establishes baseline security requirements, and outlines procedures for implementing and maintaining security controls throughout the system lifecycle. This categorization framework is essential for contractor compliance with federal security standards and ensures that all IT systems supporting UAC legal services delivery meet required information security protocols. The document functions as supporting technical documentation for the solicitation and would be referenced by offerors in their technical proposals and system security planning for the contract performance period.

View the file

Other files for this federal contract opportunity

Other files attached to Legal Services for Unaccompanied Alien Children (UAC), newest first.
File Type Posted
Amendment 15 - Attachment J - Section F Deliverables Table June 06 2026.pdf PDF
Amendment 15 - Attachment B - Section C- Performance Work Statement (PWS) UAC Legal Services June 06 2026.pdf PDF
Amendment 15 - Attachment L Questions and Answers June 06 2026.pdf PDF
Amendment 15 - RFP UAC Legal Services.pdf PDF
Attachment-G5-ACF_Incident Response Plan_V1.0.docx DOCX document
Attachment E - Quality Assurance Surveillance Plan (QASP) UAC Legal Services_20260515.docx DOCX document
Attachment-G10-ACF_System Security Plan_V1.0.docx DOCX document
Attachment-G9-ACF_System Registration_V1.0.docx DOCX document
Attachment-G4-ACF_Contingency Plan.docx_V1.0.docx DOCX document
Attachment J - Section F Deliverables Schedules and Performance Requirements Summary Table_20260513.docx DOCX document
Attachment D - ORR Facilities by State_20260513.pdf PDF
Attachment-G6-ACF_Interconnection Security Agreement_V1.0.docx DOCX document
Attachment-G3-ACF_Configuration Management Plan.docx_V1.0.docx DOCX document
Attachment-G2-ACF_Business Impact Analysis.docx_V1.0.docx DOCX document
Attachment-G1-ACF_ E-Authentication Agreement_V1.0.docx DOCX document
Attachment H - Glossary of Abbreviations and Acronyms_20260513.docx DOCX document
Attachment F - ACF External System Control Implementation Policy and Procedures_20251203.docx DOCX document
RFP UAC LEGAL SERVICES 20260515.pdf PDF
Attachment J- Questions and Answers_2026.03.24 (Amd 0010).pdf PDF
Attachment B- Section C- PWS_2026.03.24 (Amd 0010).pdf PDF
Attachment A- Pricing Worksheet_2026.03.24 (Amd 0010).xlsx XLSX spreadsheet
Attachment C- Standard Form (SF)-1449.pdf PDF
Attachment A- Pricing Worksheet UAC Legal Services (Amd. 0007) 2026.02.23.xlsx XLSX spreadsheet
Attachment B- Section C- PWS (Amd 0007) 2026.02.23.pdf PDF
Attachment E- Quality Assurance Surveillance Plan (QASP) (Amd. 0007) 2026.02.23.pdf PDF
Attachment H- Glossary of Abbreviations and Acronyms.pdf PDF
Attachment C- Standard Form (SF)-1449.pdf PDF
Attachment G- ATO Templates-2025.zip ZIP file
75P00126R00003_2026.02.23.pdf PDF
Attachment D - ORR Facilities by State.xlsx XLSX spreadsheet
QA-75P00126R00003(Rev1) (Amd 0004)(12.11.2025)#Q127.pdf PDF
75P00126R00003 (Rev2)(Amd 0004)(12.11.2025).pdf PDF
Attachment B-Pricing Worksheet UAC Legal Services (Rev2) (Amd 0004)(12.11.2025).xlsx XLSX spreadsheet
Attachment A- Performance Work Statement (PWS) (Rev1) (Amd 0003) (12.09.2025).pdf PDF
Attachment F- Quality Assurance Surveillance Plan (QASP)(Rev1)(Amd 0003)(12.09.2025).pdf PDF
Attachment B-Pricing Worksheet UAC Legal Services (Rev1) (Amd 0003)(12.09.2025).xlsx XLSX spreadsheet
Attachment E- ORR Facilities by State (Amd 0003).pdf PDF
Attachment G- ACF External System Control Implementation Policy and Procedures (Amd 0003).pdf PDF
Attachment I- Selected Controls (Moderate) (Amd 0003).xlsx XLSX spreadsheet
Attachment H- ATO Templates_2025 (Amd 0003).zip ZIP file
QA-75P00126R00003(12.09.2025) (Amd 0003).pdf PDF
75P00126R00003 (Rev1)(Amd 0003)(12.09.2025).pdf PDF
Attachment J- Selected Controls (Low) (Amd 0003).xlsx XLSX spreadsheet
Attachment B- Pricing Worksheet UAC Legal Services (11.25.2025).xlsx XLSX spreadsheet
Attachment B- Pricing Worksheet UAC Legal Services.xlsx XLSX spreadsheet
Attachment C- HHS Subcontracting Plan Review Form.doc DOC document
Attachment F- Quality Assurance Surveillance Plan (QASP).pdf PDF
75P00126R00003.pdf PDF
Attachment A - Performance Work Statement (PWS)_2025.11.24.pdf PDF
Attachment D- Standard Form (SF)-1449.pdf PDF
Show all 50

Legal Services for Unaccompanied Alien Children (UAC) has more files on GovTribe.

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

Enter System Name ACF

System Categorization Enter System Name Select System Category

Version 1.0 Dated: 6/26/25

Table of Contents

1. Introduction and Purpose2
2. System Overview2
2.1 Operational Overview2
2.2 Mission Relevance2
2.3 Integrated Product Team Members3
3. Risk & Impact Analysis4
3.1 Impacts of Data Loss4
3.2 Additional Considerations4
4. Information Types & Impact Ratings5
5. Final Security Categorization6
6. Approval and Authorization7
System Owner7
ACF Senior Agency Official for Privacy7
Document Revision History8

1. Introduction and Purpose This document establishes the impact of confidentiality, integrity, and availability (CIA) on the overall security categorization of the system. The scope of this categorization is limited to this system and excludes information processed or stored by external systems. It is based solely on the information necessary to support the system’s routine business operations within the Administration of Children and Families (ACF).

2. System Overview

2.1 Operational Overview

Clearly describe the system’s primary operational purpose and the types of users it serves (e.g., internal staff, contractors, or public users). Explain any time-sensitive functions, constraints, or dependencies (e.g., reliance on other systems). Identify factors that could increase the risk of data compromise, disruption, or loss, as this will help justify impact level adjustments in later sections.

Enter system’s primary operational purpose

2.2 Mission Relevance

Describe how the system supports the mission of the Administration for Children and Families (ACF). Include a summary of the system’s primary function, its role in delivering services or supporting agency operations, and why maintaining its confidentiality, integrity, and availability is essential to mission success.

Enter mission relevance

2.3 Integrated Product Team Members

List the key individuals involved in the system’s development, operation, and security oversight. Include names, roles, and contact information for each team member responsible for contributing to or approving the system categorization. Add additional rows as needed

Table 1. System Stakeholders

Role
Name
Phone
Email

3. Risk & Impact Analysis

3.1 Impacts of Data Loss

Identify the potential impacts if the system’s data were lost, compromised, or unavailable. Include an assessment of how many users would be affected, the potential harm to ACF’s reputation or operations, and any risks to individuals, organizational assets, or mission-critical services. This information should justify the impact levels assigned in later sections.

Impacts of data loss:

Enter potential impacts of data loss

Number of users affected:

Enter number of users affected

Impacts on reputation, organizational operations, assets, individuals, etc.:

Enter other impacts

3.2 Additional Considerations

Table 2. Classification of System

Classification of System
Type of Classification
What is the Classification of Information?
Select answer
Any Interconnected Systems/External Services that could elevate the impact level?
Select answer
Do any executive orders or overarching policies define the impact of data loss or breach?
Select answer
Does a Clearance or Need to Know requirement for data vary by role or personnel?
Select answer
Does the loss or breach of multiple data sources cause an aggregation condition that heightens impact value?
Select answer
Is the system a joint authorization?
Select answer

4. Information Types & Impact Ratings Using NIST SP 800-60 and system documentation, identify each information type processed, stored, or transmitted by the system. For each type, record the source, its use within the system, and the provisional impact levels for confidentiality, integrity, and availability. Do not include information types handled solely by external or interconnected systems unless their data directly influences this system’s categorization.

Table 3. Information Type and Description

Information Type
Information Source
Description of How Information Type is Contained in a System

Table 4. Impact Levels

Information Type
Provisional Confidentiality Impact
Provisional Integrity Impact
Provisional Availability Impact

After assigning provisional impact values, assess whether adjustments are needed based on the system’s operational context, data sensitivity, system dependencies, or other factors. Provide a brief justification for any adjustments.

5. Final Security Categorization Determine the final impact level for confidentiality, integrity, and availability by identifying the highest impact value assigned across all information types and applicable operational considerations.

These impact levels will represent the system’s overall security categorization and will be used to select the initial baselines of security controls in accordance with FIPS 199 and NIST guidance.

Document the three impact levels that accurately represent the system’s risk profile.

Table 5. System Categorization

Security Objective
Impact Level
Confidentiality Rating
Select answer
Integrity Rating
Select answer
Availability Rating
Select answer

6. Approval and Authorization This System Categorization has been reviewed and approved by the System Owner.

System Owner Enter System Owner name Digital Signature - Date

ACF Senior Agency Official for Privacy Enter Official name Digital Signature - Date

Document Revision History

Date
Version
Comments

Version 1.0 Security Categorization 1 image1.png image2.png

File details come from the government source that posted it. Updated .