Attachment-G9-ACF_System Registration_V1.0.docx
DOCX document 91 KB Posted
- Attached to
- Legal Services for Unaccompanied Alien Children (UAC) Federal contract opportunity
- Solicitation number
- 75P00126R00003
- Issued by
- Not on record
About this file
This is a system registration template document for the Administration for Children and Families (ACF) within the Department of Health and Human Services. The document serves as a standardized form for registering new information technology systems within ACF's enterprise architecture framework and is version 1.0, dated June 26, 2025.
The template is designed to be completed in two stages: Part 1 at the Project Initiation Review Stage Gate and Part 2 at the Critical Design Review Stage Gate. Part 1 requires system administrators to provide fundamental system information including system name, acronym, type, location, and operational details such as mission criticality, IT investment amounts, and cost-per-year figures. It also mandates identification of system roles including the system operator, business owner, system owner, Information Systems Security Officer (ISSO), and requires ACF Chief Information Officer (CIO) sign-off. Additionally, Part 1 includes a comprehensive privacy review section with five assessment questions designed to determine whether a System of Records Notice (SORN) and Privacy Threshold Analysis/Privacy Impact Assessment (PTA/PIA) are required. These questions assess whether the system contains records about individuals, whether records are retrievable by direct personal identifiers, whether records are public, whether existing SORNs cover the system's records, and whether privacy assessments have been initiated. Part 2, completed at the Critical Design Review stage, requests Enterprise Architecture updates including system UUID, supported user estimates, applicable user groups (executive team, government employees, public users, partner organizations), authentication requirements, system interconnections, contract end dates, and documentation of all technologies and software products in use. The document also includes Appendix A, which provides detailed descriptions of 26 different business segments under which ACF systems may be categorized, ranging from Access to Health Care and Consumer Safety to Research Management, Strategic Planning, and Training and Outreach.
View the file
Other files for this federal contract opportunity
Show all 50
Legal Services for Unaccompanied Alien Children (UAC) has more files on GovTribe.
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
Enter System Name ACF
System Registration Test
Version 1.0 Dated: 6/26/25
Table of Contents
| Test | 0 |
| Part 1: Complete and Provide at the Project Initiation Review Stage Gate | 2 |
| ACF Chief Information Officer (CIO) Sign-Off for System Registration | 4 |
| Privacy Review | 5 |
| 1. Does the system contain records about individuals? | 5 |
| 2. Are records retrieved by a direct personal identifier? | 5 |
| 3. Are records about individuals in the public? | 6 |
| 4. Does an existing SORN(s) cover the types of records maintained by this system? | 6 |
| 5. Has a PTA/PIA been initiated for this system? | 6 |
| ACF Senior Official for Privacy (SOP) Sign-Off for SORN Determination | 7 |
| Part 2: Complete and Provide at the Critical Design Review Stage Gate | 8 |
| Appendix A: Segments | 10 |
Part 1: Complete and Provide at the Project Initiation Review Stage Gate The following fields help to create the Enterprise Architecture record for the system. The creation of this record will assign a Unique ID (UUID) to the system.
Table 1. System Information System Information
| System Name (full) |
| Enter System Name |
| System Acronym |
| Enter acronym |
| System Type |
| Select answer |
| System Location |
| Enter location |
| System State |
| Select answer |
| ATO Date |
| Select date |
| Commercial or Government |
| Select answer |
| Website URL |
| Enter URL |
| Brief Description |
| Enter description |
| Mission Critical |
| Select answer |
| Operational Criticality |
| Select answer |
| Segment[footnoteRef:2] [2: Refer to Appendix A for detailed descriptions of each segment] |
| Select answer |
| IT Investment |
| Enter investment |
| Investment ID (UII per PMT) |
Enter ID
| Does the system contain PII? |
| Select answer |
| Cost per Year |
| Enter cost |
| Average # of Users Expected Per Month |
| Enter # of users |
| User Base |
| Select answer |
| Cloud Enabled? |
| Select answer |
| Cloud Deployment Model? |
| Select answer |
| Cloud Service Model? |
| Select answer |
Table 2. Roles Roles
| System Operator | |
| Enter system operator | |
| Stakeholders | |
| Enter stakeholders | |
| Executive Sponsor | Comment by Rosner, Diana (ACF) (CTR): Business Owner |
| Enter executive sponsor | |
| System Owner | |
| Enter system owner | |
| ISSO | |
| Enter ISSO | |
| Employee FTE | |
| Enter employee FTE | |
| Contractor FTE | |
| Enter contractor FTE | |
| Program Office | |
| Enter program office |
ACF Chief Information Officer (CIO) Sign-Off for System Registration
Enter CIO Name Digital Signature – CIO
Privacy Review The following questions will be used to determine whether a SORN is believed to be required for the system or not. In addition, please indicate if a Privacy Threshold Analysis (PTA)/Privacy Impact Assessment (PIA) has been initiated. Draft System Registration document should be sent to the Privacy Team for review, OCIO.Privacy@acf.hhs.gov
1. Does the system contain records about individuals?
Select answer Supplemental Guidance:
A record, as defined by the Privacy Act, is any item, collection, or grouping of information (electronic or paper) about an individual that includes, but is not limited to, at least one of the following items:
· Name
· Identifying Number (e.g., SSN, Date of Birth [DOB])
· Any other identifying information assigned to the individual, such as a finger or voice print, or a photograph
Note that “PII” and “records about individuals” are not synonymous.
If yes, continue to question 2.
If no, please identify the types of records the system does contain:
Enter answer
2. Are records retrieved by a direct personal identifier?
Select answer Supplemental Guidance:
· A retrieval must occur for SORN to be required. Merely having the capacity to retrieve will not trigger the Privacy Act.
· A direct personal identifier may include Name, Email, SSN, or DOB.
If yes, a SORN is most likely required. Please go to question 3. Please contact ACF Privacy at OCIO.Privacy@acf.hhs.gov to confirm if a SORN is needed.
If no, please identify the ways that a record can be retrieved:
Enter answer
3. Are records about individuals in the public?
Select answer If no, a SORN is not needed. Skip question 4.
4. Does an existing SORN(s) cover the types of records maintained by this system?
Select answer Supplemental Guidance:
· All ACF and government wide SORNs can be readily located on the HHS Website.
· Please contact ACF Privacy at OCIO.Privacy@acf.hhs.gov for identifying applicable SORN.
If a SORN may already exist, please cite the name and number for review and confirmation: Direct personal identifiers include Name and Email. SORN is not needed, only PIA is needed.
Enter answer
5. Has a PTA/PIA been initiated for this system?
Select answer If no, please contact the privacy office to initiate and create a POAM.
Prior to submission to ACF SOP, send completed form to ACF Privacy to confirm the SORN Determination information is correct and if a new SORN is needed we will create a Plan of Action and Milestone (POAM) to track the SORN completion.
ACF Senior Official for Privacy (SOP) Sign-Off for SORN Determination
Enter SOP Name Digital Signature – SOP
Part 2: Complete and Provide at the Critical Design Review Stage Gate The following fields help to complete the Enterprise Architecture record for the system.
| Field |
| Response |
| System UUID |
| Enter answer |
| Does a NARA-approved records schedule exist? |
| Select answer |
| Estimate the number of supported users per month |
(number of users supported by the system per month; represents the average, not the peak or high-water mark)
| Enter answer |
| Select all applicable groups |
| ☐ Executive Team (ACF senior leadership/political appointees) |
☐ Government employees (federal staff or direct contractors of HHS, ACF, and/or other OpDivs
☐ Public Users (public citizens [i.e., grantees] with access to the system without needing to authenticate)
☐ Partner Organizations (other federal departments or entities or non-direct contractors that are provided access to the system)
Does the system require authentication to gain access?
(users of the IT system must have an account and must authenticate with the IT system prior to getting system access) Select an answer
If yes, specify: Enter answer
| Does the system connect with other IT systems? |
| Select an answer |
If yes, specify: Enter answer
| When does the current contract, for personnel supporting the system, end? |
| Enter answer |
| Identify the technologies in use by the system, including version when applicable |
| Enter answer |
| Identify all software products in use by the system, including version when applicable |
| Enter answer |
Appendix A: Segments
| Segment Name |
| Description |
| Access to Health Care |
| The Access to Health Care focuses on access to appropriate care. The outcome for the completion of this segment is a successful implementation of the segment target architecture that will result in the population’s timely receipt of the right guidance to the right care at the right location. |
| Consumer Safety |
| Consumer Safety includes evaluation of consumer products, drug, and foods to assess the potential risks and |
dangers; education of the consumer and the general population; and facilitation of health promotion and disease and injury prevention.
| Emergency Preparedness & Response |
| Emergency Preparedness and planning involves the development of response programs to be used in case of a disaster as well as pre-disaster mitigation efforts to |
minimize the potential for loss of life and property. This involves the development of emergency management programs and activities as well as staffing and equipping regional response centers, and mitigation focused construction and preparation.
| Financial Management |
| Financial Management involves the use of financial information to measure, operate and predict the effectiveness and efficiency of an entity's activities in relation to its objectives. This includes accounting, funds control, payments, collections and receivables, asset and liability management, reporting, and cost accounting and performance measurement. |
| Health Care Administration |
| Health Care Administration assures that federal health care resources are expended effectively to ensure quality, safety, and efficiency. This includes managing health care quality, cost, workload, utilization, and fraud/abuse efforts. |
| Health Monitoring |
| Health Monitoring involves the observation and status monitoring of health conditions at local, regional, and national levels, including detecting biological, product-related, environmental, or other events and making |
notifications to internal or external stakeholders.
| Human Resource Management |
| Human Resource Management involves all activities associated with the recruitment and management of personnel. These include HR strategy, staff acquisition, organization and position management, compensation |
management, benefits management, employee performance management, employee relations, labor relations, separation management, and human resources development.
| Human Services |
| The Human Services provides public assistance, child, and family welfare services. HHS directs the operations of public assistance and service programs around the |
country. The outcome for the completion of this segment is a successful implementation of the segment target architecture that will support federal assistance efforts and increase collaboration among various federal human services programs.
| Information Management |
| Information Management involves the coordination of information collection, storage, and dissemination, and destruction as well as managing the policies, guidelines, |
and standards regarding information management.
| Information Security |
| Information Security involves all functions pertaining to the protection of federal information and information systems from unauthorized access, use, disclosure, disruptions, modification, or destruction, as well as the creation and implementation of security policies, procedures, and controls. |
| Inspections, Auditing, and Investigations |
| Inspections and Auditing involves the methodical examination and review of regulated activities to ensure compliance with standards for regulated activity. |
| IT Infrastructure |
| IT Infrastructure Maintenance involves the planning, design, and maintenance of an IT Infrastructure to effectively support automated needs. |
| Operations Management |
| Operations Management involves the design, oversight, and control of the management processes to produce goods and/or services. It includes the responsibility of ensuring that business operations are efficient in terms of |
using as few resources as needed, and effective in terms of meeting customer requirements.
| Physical Security Management |
| Physical Security Management involves the physical protection of an organization's personnel, assets, and facilities (including security clearance management). |
| Policy, Rule, and Regulations Management |
| Policy Development involves the creation and |
dissemination of guidelines to assist in the interpretation and implementation of regulations.
| Population Health Management |
| Population Health Management includes monitoring of health, health planning, and health management of humans, animals, animal products, and plants, as well as |
tracking the spread of diseases and pests.
| Product Review and Approval |
| Product Review and Approval includes all activities related to the submission, evaluation, and approval decisions for |
products under regulatory supervision proposed for introduction to the market.
| Program Management |
| Program Management involves the activities related to identifying, assessing, providing funding, or otherwise supporting programs that provide health and human |
services promotion, advocacy, education, awareness, research, or other services. It also involves the implementation, monitoring, evaluation, and corrective action associated with controlling programs or projects operated under the supervision of the organization.
| Public Affairs |
| Public Affairs involve the exchange of information and communication between the federal government, citizens, and stakeholders in direct support of citizen services, public policy, and/or national interest. |
Public Health Laboratory Science and Services All work pertaining to internal or external laboratory research/investigations, workforce development, support services, and partner laboratory support.
| Public Health System Report |
| The provision of resources and technical assistance to state, local and territorial health departments, nations, non-profit organizations, and others to implement public |
health programs and interventions to improve the environment, communities and the health and well-being of individuals.
| Research Management and Operations |
| Research Management and Operations includes activities associated with management, oversight, and execution of |
research activities conducted by internal and external organizations.
| Strategic Planning |
| Strategic Planning entails the determination of annual and long-term goals and the identification of the best approach for achieving those goals and focuses on critical agency strategic activities that advance the overall HHS mission. |
| Training and Outreach |
| Training and outreach involve the activities associated with development and delivery of self-directed or instructor led training sessions. |
| Other |
| The information system does not fit into any of the above categories. |
Version 1.0 System Registration 1 image1.png
File details come from the government source that posted it. Updated .