Attachment-G8-ACF_System Categorization_V1.0.docx
DOCX document 99 KB Posted
- Attached to
- Legal Services for Unaccompanied Alien Children (UAC) Federal contract opportunity
- Solicitation number
- 75P00126R00003
- Issued by
- Not on record
About this file
This is a system categorization document that serves as a technical reference guide for ACF (Administration for Children and Families) system classification and security control requirements.
The document establishes categorization standards for systems supporting the Unaccompanied Alien Children (UAC) legal services contract, defining how systems should be classified based on impact levels and security requirements. It provides detailed guidance on system categorization methodologies, security control frameworks, and implementation procedures aligned with federal information security standards. The document specifies control selection criteria for systems operating at different impact levels (Low and Moderate), establishes baseline security requirements, and outlines procedures for implementing and maintaining security controls throughout the system lifecycle. This categorization framework is essential for contractor compliance with federal security standards and ensures that all IT systems supporting UAC legal services delivery meet required information security protocols. The document functions as supporting technical documentation for the solicitation and would be referenced by offerors in their technical proposals and system security planning for the contract performance period.
View the file
Other files for this federal contract opportunity
Show all 50
Legal Services for Unaccompanied Alien Children (UAC) has more files on GovTribe.
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
Enter System Name ACF
System Categorization Enter System Name Select System Category
Version 1.0 Dated: 6/26/25
Table of Contents
| 1. Introduction and Purpose | 2 |
| 2. System Overview | 2 |
| 2.1 Operational Overview | 2 |
| 2.2 Mission Relevance | 2 |
| 2.3 Integrated Product Team Members | 3 |
| 3. Risk & Impact Analysis | 4 |
| 3.1 Impacts of Data Loss | 4 |
| 3.2 Additional Considerations | 4 |
| 4. Information Types & Impact Ratings | 5 |
| 5. Final Security Categorization | 6 |
| 6. Approval and Authorization | 7 |
| System Owner | 7 |
| ACF Senior Agency Official for Privacy | 7 |
| Document Revision History | 8 |
1. Introduction and Purpose This document establishes the impact of confidentiality, integrity, and availability (CIA) on the overall security categorization of the system. The scope of this categorization is limited to this system and excludes information processed or stored by external systems. It is based solely on the information necessary to support the system’s routine business operations within the Administration of Children and Families (ACF).
2. System Overview
2.1 Operational Overview
Clearly describe the system’s primary operational purpose and the types of users it serves (e.g., internal staff, contractors, or public users). Explain any time-sensitive functions, constraints, or dependencies (e.g., reliance on other systems). Identify factors that could increase the risk of data compromise, disruption, or loss, as this will help justify impact level adjustments in later sections.
Enter system’s primary operational purpose
2.2 Mission Relevance
Describe how the system supports the mission of the Administration for Children and Families (ACF). Include a summary of the system’s primary function, its role in delivering services or supporting agency operations, and why maintaining its confidentiality, integrity, and availability is essential to mission success.
Enter mission relevance
2.3 Integrated Product Team Members
List the key individuals involved in the system’s development, operation, and security oversight. Include names, roles, and contact information for each team member responsible for contributing to or approving the system categorization. Add additional rows as needed
Table 1. System Stakeholders
| Role |
| Name |
| Phone |
3. Risk & Impact Analysis
3.1 Impacts of Data Loss
Identify the potential impacts if the system’s data were lost, compromised, or unavailable. Include an assessment of how many users would be affected, the potential harm to ACF’s reputation or operations, and any risks to individuals, organizational assets, or mission-critical services. This information should justify the impact levels assigned in later sections.
Impacts of data loss:
Enter potential impacts of data loss
Number of users affected:
Enter number of users affected
Impacts on reputation, organizational operations, assets, individuals, etc.:
Enter other impacts
3.2 Additional Considerations
Table 2. Classification of System
| Classification of System |
| Type of Classification |
| What is the Classification of Information? |
| Select answer |
| Any Interconnected Systems/External Services that could elevate the impact level? |
| Select answer |
| Do any executive orders or overarching policies define the impact of data loss or breach? |
| Select answer |
| Does a Clearance or Need to Know requirement for data vary by role or personnel? |
| Select answer |
| Does the loss or breach of multiple data sources cause an aggregation condition that heightens impact value? |
| Select answer |
| Is the system a joint authorization? |
| Select answer |
4. Information Types & Impact Ratings Using NIST SP 800-60 and system documentation, identify each information type processed, stored, or transmitted by the system. For each type, record the source, its use within the system, and the provisional impact levels for confidentiality, integrity, and availability. Do not include information types handled solely by external or interconnected systems unless their data directly influences this system’s categorization.
Table 3. Information Type and Description
| Information Type |
| Information Source |
| Description of How Information Type is Contained in a System |
Table 4. Impact Levels
| Information Type |
| Provisional Confidentiality Impact |
| Provisional Integrity Impact |
| Provisional Availability Impact |
After assigning provisional impact values, assess whether adjustments are needed based on the system’s operational context, data sensitivity, system dependencies, or other factors. Provide a brief justification for any adjustments.
5. Final Security Categorization Determine the final impact level for confidentiality, integrity, and availability by identifying the highest impact value assigned across all information types and applicable operational considerations.
These impact levels will represent the system’s overall security categorization and will be used to select the initial baselines of security controls in accordance with FIPS 199 and NIST guidance.
Document the three impact levels that accurately represent the system’s risk profile.
Table 5. System Categorization
| Security Objective |
| Impact Level |
| Confidentiality Rating |
| Select answer |
| Integrity Rating |
| Select answer |
| Availability Rating |
| Select answer |
6. Approval and Authorization This System Categorization has been reviewed and approved by the System Owner.
System Owner Enter System Owner name Digital Signature - Date
ACF Senior Agency Official for Privacy Enter Official name Digital Signature - Date
Document Revision History
| Date |
| Version |
| Comments |
Version 1.0 Security Categorization 1 image1.png image2.png
File details come from the government source that posted it. Updated .