Attachment_3_-_Requirement_Definition_Document.pdf
PDF 981 KB Posted
- Attached to
- Native American Student Information System Recompe Federal contract opportunity
- Solicitation number
- 140A2325Q0066
About this file
This is a Requirements Definition Document (RDD) that describes the business and functionality requirements for the Native American Student Information System (NASIS) for the Bureau of Indian Education (BIE). The system is BIE's designated student information system which stores and tracks student data including demographics, grades, attendance records, and statistical reports needed for funding various programs and federal/state education agency reporting requirements.
The RDD specifies that NASIS must be delivered as a contractor-owned, contractor-operated (CoCo) web-based system accessible to staff, parents and students. Key requirements include: ability to achieve Authority to Operate within 12 months of award; support for PIV multi-factor authentication; integration with BIE's learning management system through standard APIs; compliance with FERPA and Privacy Act requirements; 99.95% system availability; support for approximately 53,400 students across 183 schools in 23 states; and comprehensive data tracking capabilities for attendance, grades, special education, assessment scores, and other student information. The system must enable reporting for various federal requirements including EDFacts, IDEA, ESSA and GPRA. Security requirements mandate adherence to NIST SP 800-53 Rev 5 Moderate controls and data must be hosted within the continental United States.
View the file
Other files for this federal contract opportunity
| File | Type | Posted |
|---|---|---|
| Sol_140A2325Q0066_Amd_0007.pdf | ||
| Sol_140A2325Q0066_Amd_0006.pdf | ||
| Sol_140A2325Q0066_Amd_0005.pdf | ||
| Sol_140A2325Q0066_Amd_0004.pdf | ||
| Small_Business_Q_A_for_NASIS_0004.pdf | ||
| Sol_140A2325Q0066_Amd_0003.pdf | ||
| Sol_140A2325Q0066_Amd_0002.pdf | ||
| Q_A_for_NASIS_0001.pdf | ||
| Sol_140A2325Q0066_Amd_0001.pdf | ||
| Sol_140A2325Q0066.pdf | ||
| Attachment_4_-_Pricing_Schedule.xlsx | XLSX spreadsheet | |
| Attachment_2_-_Performance_Requirement_Summary.pdf | ||
| Attachment_1_-_Performance_Work_Statement.pdf |
Show all 13
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
This Document Contains Controlled Unclassified Information (CUI)
Native American Student Information System (NASIS)
Requirements Definition Document
Version 2.0 February 07, 2025
U.S. Department of the Interior Indian Affairs
Office of Information Technology
Native American Student Information System (NASIS) Requirements Definition Document
Office of Information Technology 1
Table of Contents
1.0 Introduction
1.1 Project Description
1.2 Background
2.0 Purpose
3.0 Interfaces to External Systems
4.0 Documents References
4.1 Regulatory Document
4.2 Laws and Regulations
4.3 Executive Orders
Improving the Nations Cyber Security
4.4 OMB Circulars and Memoranda
4.5 Standards and Guidelines
5.0 Requirements Summary
5.1 Traceable Requirements
5.1.1 Functional Requirements
5.1.2 Data Requirements
5.1.3 Security
5.2 General Requirements
5.2.1 Operational Requirements
5.2.2 Audit Trail
5.2.3 Data Currency
5.2.4 Reliability
5.2.5 Recoverability
5.2.6 Knowledge System Availability
5.2.7 Fault Tolerance
5.2.8 Performance
5.2.9 Capacity
5.2.10 Data Retention
Points of Contact Requirements Traceability Matrix (RTM)
Office of Information Technology 2
List of Tables Table 1: Interfaces to External Systems Table 2: Regulatory Document Table 3: Laws and Regulations Table 4: Executive Orders Table 5: Standards and Guidelines Table A-1: Points of Contact Table B-1: Requirements Traceability
Office of Information Technology 3
1.0 Introduction
1.1 Project Description
This Requirements Definition Document (RDD) describes the Native American Student Information System (NASIS) business and functionality requirements. It is prepared in accordance with the Indian Affairs Information Technology Office System Life Cycle requirements.
This document was jointly prepared by the Bureau of Indian Education (BIE) and the Indian Affairs Information Technology Office (IAIT). BIE participants include Central Office staff and field staff. Changes to the RDD are approved through the BIE Change Control Board.
The RDD supports the following activities:
• Procurement of the system
• Designing and developing the system
• Evaluating the product in all subsequent phases of the life cycle
• Enhancement of the product in all subsequent phases of the life cycle
• Determining the success criteria of the project
1.2 Background
NASIS is the Bureau of Indian Education’s (BIE’s) designated student information system (SIS) which stores and tracks all student data that school administrators and/or teachers need to manage their classroom and operate their instructional programs.
Information such as student demographics, grades and attendance records are tracked through this platform. NASIS also supports Central Office and provides data and the statistical reports needed for funding various programs, provides reports required by Federal and State education agencies, and provides the source data to analyze student performance along with the tools needed to perform the analysis. NASIS provides students access to the information that pertains to them and parent access that differentiates tools from a higher education SIS. NASIS provides SMS function that allows teachers and parents to communicate directly. This allows a teacher to keep that parent updated with their child’s social and academic progress in the classroom. In light of the pandemic, it is necessary to integrate NASIS with BIE’s education learning management system (eLMS).
BIE is different from many other education jurisdictions in that BIE is comprised of 183 Federally operated and Tribally Controlled schools in 23 states, is required by Federal statute and the degree granting States to report regarding those schools to State and Federal education agencies. This federal and state mandated requirements will be provided by NASIS. This federal requirement, and state related requirements, are performed in NASIS by Central Office staff using NASIS reporting and analysis services tools.
NASIS was deployed during the school year 2006-07 and is fully implemented bureau wide.
Office of Information Technology 4
2.0 Purpose
The primary purpose of the NASIS investment is to manage, store and track student data in a secured environment that allows school staff to store and access students’ academic records in one place and ensure that only authorized persons can access the information. Student data collected and stored in NASIS are used to improve student achievement and to ensure statutorily and regulatory reporting compliance. NASIS will deliver services tailored to the BIE Central Office and deliver separate, but related services to the schools.
The requirement for an information system for BIE originated in the Educational Amendments of 1978 to P.L. 95-561 (the basic P.L. 95-561 was enacted in 1965). The "No Child Left Behind (NCLB) Act” is P.L. 107-110; Part D is entitled the "Native American Education Improvement Act". Part D consists primarily of a complete restatement of the Educational Amendments of 1978 to P.L., 95-561 and adds suspense dates tied to specific items.
NASIS will support the fulfillment of these statutes, the maintenance of the Indian School Equalization Program (ISEP), Average Daily Attendance/Average Daily Membership (ADA/ADM) reports, student counts, and placements required under P.L.
108-446, Individuals with Disabilities Education Act of 2004 (IDEA), enrollment and reporting required under ESSA, lunch program needs, and other reports such as those required under Government Performance and Results Act (GPRA).
Office of Information Technology 5
3.0 Interfaces to External Systems
The SIS must be able to support the following objectives when integrating with external systems, particularly the BIE’s eLMS platform.
• Student Data Sync: The SIS must be able to synchronize student data using an industry-standard Application Programming Interface (API), such as OneRoster v1.2 to update student enrollment data (admissions and discharges), course scheduled, grades, and attendance.
• User Provisioning: The integration must support automatically provisioning user accounts in the BIE’s eLMS based on information stored in the SIS, such as student and staff information.
• SSO: Must support full Single Sign On through either SAML 2.0 or OAuth/OAuth2, the level of integration required, multi-factor authentication or complex password.
• Grade Pass back: The integration must allow for the automatic transfer of grades from Schoology to the SIS, eliminating the need for manual grade entry.
• Attendance Tracking: The integration must allow attendance data to be automatically synced between the SIS and Schoology, reducing the need for manual entry and ensuring accurate attendance records.
• Scheduling Integration: The SIS must support the syncing of class schedules between the SIS and Schoology, allowing for seamless integration between the two systems. The integration must allow for the automatic syncing of course data, including course names, descriptions, and schedules.
• Data Security: The integration must provide robust data security measures to ensure that student data is continually protected at the NIST SP 800-53 Rev 5 Moderate AIC controls.
Table 1: API Interface standards to External Systems
Name of Application Owner Interface Details One Roster 1.2 (or successor (s))
REST API standard for general Learning Management Systems interface, such as Schoology.
Export / Import of the following
• Class Rosters - the set of people enrolled on a class at a site and for a set period
• Resources - to identify the set of resources that are required for a class and/or a course
• Gradebooks - the data is broken into results, line items (a set of results) and categories (a set of line Items).
Learning Tools Interoperability Advantage (or successor(s))
LTI Advantage Standard for Learning Management Systems Interface
Support the following standard services:
• Deep Linking
• Names and Role Provisioning
• Class and Rostering
Office of Information Technology 6
4.0 Documents References
4.1 Regulatory Document
Table 2: Regulatory Document
Regulatory and Statutory Reporting Requirements Consolidated State Performance Reports: Parts I and II Report of Children with Special Disabilities Receiving Special Education Under Part B of the Individuals with Disabilities Education Act, As Amended Personnel (In Full-Time Equivalency of Assignment) Employed to Provide Special Education and Related Services for Children with Disabilities Part B, Individuals with Disabilities Education Act Implementation of FAPE Requirements Report of Children with Disabilities Exiting Special Education Report of Children with Disabilities Subject to Disciplinary Removal by Disability Category Report of the Participation and Performance of Students with Disabilities on State Assessments Report of Students Who Receive Early Intervention Services funded by P.L. 108-446 Part B
(IDEIA 2004)
Behavior Reports: Reports that will be filtered by positive or negative behaviors for various intervals of time (Example: No behaviors for one date to the next).
4.2 Laws and Regulations
Table 3: Laws and Regulations
Document Identifier Title Description 15 U.S.C. 1681a(f) Disclosure to Consumer
Reporting Agencies; Fair Credit Reporting Act
The term “consumer reporting agency” means any person which, for monetary fees, dues, or on a cooperative nonprofit basis, regularly engages in whole or in part in the practice of assembling or evaluating consumer credit information or other information on consumers for the purpose of furnishing consumer reports to third parties, and which uses any means or facility of interstate commerce for the purpose of preparing or furnishing consumer reports.
18 U.S.C. § 1030 Computer Fraud and Abuse Act of 1986
This law provides for the punishment of individuals who access Federal computer resources without authorization, attempt to exceed access privileges, abuse government resources, and/or conduct fraud on government computers.
Office of Information Technology 7
Document Identifier Title Description 18 U.S.C. § 1030 National Information
Infrastructure Protection Act of 1996
This law provides for the protection of computer resources.
20 USC § 6301 Strengthening and Improvement of Elementary and Secondary Schools.
The purpose of this subchapter is to provide all children significant opportunity to receive a fair high-quality education, and to close educational achievement gaps.
25 CFR 31 Federal Schools for Indians Code of Federal Regulations for Native American Schools
25 CFR 36 Minimum Academic Standards for the Basic Education of Indian Children and National Criteria for Dormitory Situations.
Sets minimum standards in the following areas: General Provisions, Educational Management, Minimum Program of Instruction, Student Instructional Evaluation, Instructional Support, Evaluation of Educational Standards and Homeliving Programs
25 CFR 39 The Indian School Equalization Program.
This part provides for the uniform direct funding of Bureau-operated and tribally operated day schools, boarding schools, and dormitories. This part applies to all schools, dormitories, and administrative units that are funded through the Indian School Equalization Program of the Bureau of Indian Affairs.
25 U.S.C. 1 Commissioner of Indian Affairs [and] agreement between the Secretary and the Tribal Government.
Establishment of the Bureau of Indian Affairs and the government-government relationships between Tribes and the US Government.
25 U.S.C. 13 The Snyder Act.
Expenditure of Appropriations by Bureau
BIA Appropriations Law
20 U.S.C. § 1400 Education of Individuals with Disabilities
This law means specifically designed instruction, at no cost to parents, to meet the unique needs of a child with a disability.
25 U.S.C. 1a Delegation of powers and duties by Secretary of the Interior and Commissioner of Indian Affairs
For the purpose of facilitating and simplifying the administration of the laws governing Indian affairs
Office of Information Technology 8
Document Identifier Title Description 25 U.S.C. 2001 Accreditation for the basic education of Indian children in Bureau of Indian Affairs schools
The purpose of the accreditation required under this section shall be to ensure that Indian students being served by a school funded by the Bureau of Indian Affairs are provided with educational opportunities that equal or exceed those for all other students in the United States.
25 U.S.C. 2501 Declaration of policy.
Tribally Controlled School Grants.
Congress declares its commitment to the maintenance of the Federal Government’s unique and continuing trust relationship with and responsibility to the Indian people for the education of Indian children through the establishment of a meaningful Indian self-determination policy for education that will deter further perpetuation of Federal bureaucratic domination of programs.
25 U.S.C. 452 Contracts for education, medical attention, relief and social welfare of Indians
The Secretary of the Interior is authorized, in his discretion, to enter into a contract or contracts with any State or Territory, or political subdivision thereof, or with any State university, college, or school, or with any appropriate State or private corporation, agency, or institution, for the education, medical attention, agricultural assistance, and social welfare, including relief of distress, of Indians in such State or Territory, through the agencies of the State or Territory or of the corporations and organizations hereinbefore named, and to expend under such contract or contracts, moneys appropriated by Congress for the education, medical attention, agricultural assistance, and social welfare, including relief of distress, of Indians in such State or Territory.
Office of Information Technology 9
Document Identifier Title Description 25 U.S.C. 5301 Indian Self-Determination and Education Assistance
(a) Findings respecting historical and special legal relationship, and resultant responsibilities The Congress, after careful review of the Federal Government's historical and special legal relationship with, and resulting responsibilities to, American Indian people, finds that—
(1) the prolonged Federal domination of Indian service programs has served to retard rather than enhance the progress of Indian people and their communities by depriving Indians of the full opportunity to develop leadership skills crucial to the realization of self-government, and has denied to the Indian people an effective voice in the planning and implementation of programs for the benefit of Indians which are responsive to the true needs of Indian communities; and
(2) the Indian people will never surrender their desire to control their relationships both among themselves and with non- Indian governments, organizations, and persons.
(b) Further findings The Congress further finds that—
(1) true self-determination in any society of people is dependent upon an educational process which will ensure the development of qualified people to fulfill meaningful leadership roles;
(2) the Federal responsibility for and assistance to education of Indian children has not [a]effected the desired level of educational achievement or created the diverse opportunities and personal satisfaction which education can and should provide; and
(3) parental and community control of the educational process is of crucial importance to the Indian people.
(Pub. L. 93–638, §2, Jan. 4, 1975, 88 Stat.
2203.)
Office of Information Technology 10
Document Identifier Title Description 31 U.S.C. § 1101 Government
Performance and Results Act (GPRA) of 1993
This law establishes policies for managing agency performance of mission, including performance of its practices.
34 CFR 300.300 Individuals with Disabilities Education Act of 2004
This law that makes available a free appropriate public education to eligible children with disabilities throughout the nation and ensure special education and related service to those children. Parental Consent for Initial evaluation for determining eligibility for special education.
31 U.S.C. § 3111 Federal Financial Management Improvement Act (FFMIA) of 1996
This law mandates Federal agencies to implement and maintain financial management systems that comply substantially with Federal systems requirements, Federal accounting standards, and the U.S. Government Standard General Ledger (SGL). FFMIA also requires GAO to report annually on the implementation of the act.
31 U.S.C. § 3512 Federal Managers Financial Integrity Act of
1982 (FMFIA)
This law mandates that Federal agencies establish and maintain an internal control program to safeguard data processing resources, assure their accuracy and reliability, and protect the integrity of information resident on such systems.
31 U.S.C. 3701(a)(3) Disclosure to Consumer Reporting Agencies;
Federal Claims Collection Act of 1966
Defines Consumer Reporting Agencies
34 CFR 300.226 Early intervening services An LEA may not use more than 15% of the amount the LEA receives under Part B of the Act for any fiscal year, less any amount reduced by the LEA pursuant to § 300.205, if any, in combination with other amounts (which may include amounts other than education funds), to develop and implement coordinated, early intervening services, which may include interagency financing structures, for students in kindergarten through grade 12 (with a particular emphasis on students in kindergarten through grade three) who are not currently identified as needing special education or related services, but who need additional academic and behavioral support to succeed in a general education environment.
Office of Information Technology 11
Document Identifier Title Description
34 CFR 300.320
Definition of individualized education program.
The term individualized education program (IEP) means a written statement for each child with a disability that is developed, reviewed, and revised in a meeting in accordance with §§ 300.320 through 300.324.
Section 300.111 IDEA Child Find All children with disabilities residing in the State including children with disabilities who are homeless children or are ward of the State, and attending private schools, regardless of severity of their disability, and who are in need of special education and related services are identified, located and evaluated.
34 CFR 300.323 When IEPs must be in effect.
At the beginning of each school year, each public agency must have in effect, for each child with a disability within its jurisdiction, an IEP, as defined in § 300.320.
34 CFR 300.324 Development, review, and revision of IEP
In the development, review, and revision of IEP, in general when developing a child's IEP, the IEP Team must consider, the strengths of the child; the concerns of the parents for enhancing the education of their child; the results of the initial or most recent evaluation of the child; and the academic, developmental, and functional needs of the child. In addition, consideration of special factors the IEP Team must include items found in (2), (3), (4), (5) and (6). The Review and revision of IEPs must include (b), (1), (2) and (3).
Failure to meet transition objectives must include (c), (1) and (2).
Office of Information Technology 12
Document Identifier Title Description 34 CFR 300.34(a) General. Related services Related services means transportation and such developmental, corrective, and other supportive services as are required to assist a child with a disability to benefit from special education, and includes speech-language pathology and audiology services, interpreting services, psychological services, physical and occupational therapy, recreation, including therapeutic recreation, early identification and assessment of disabilities in children, counseling services, including rehabilitation counseling, orientation and mobility services, and medical services for diagnostic or evaluation purposes.
Related services also include school health services and school nurse services, social work services in schools, and parent counseling and training.
34 CFR § 300.322 Parent participation Each public agency must take steps to ensure that one or both of the parents of a child with a disability are present at each IEP Team meeting or are afforded the opportunity to participate, including (b) (c)
(d) (e) and (f).
40 U.S.C. § 11101 Clinger-Cohen Act – Information Technology Management Reform Act of 1996
This law improves the acquisition, use, and disposal of Information Technology (IT) by the Federal government.
43 CFR 2.60: Freedom of Information Act. Records and Testimony.
Appeals
Defines who makes decisions on FOIA Appeals
43 CFR 2.63 Freedom of Information Act. Records and Testimony.
Expedited Processing of Appeals
Requests to access (federal) records
44 U.S.C. § 101 E-Government Act of
This law enhances the management and promotion of electronic government services and processes by establishing a broad framework of measures requiring technology to enhance citizen access to government information services.
Office of Information Technology 13
Document Identifier Title Description 44 U.S.C. § 3504 Government Paperwork
Elimination Act (GPEA) of
This law provides for Federal agencies, by October 21, 2003, to give persons who are required to maintain, submit, or disclose information, the option of doing so electronically when practicable as a substitute for paper and to use electronic authentication methods to verify the identity of the sender and the integrity of electronic content.
44 U.S.C. § 3541 Federal Information Security Management Act of 2002 (FISMA)
FISMA requires Federal agencies to establish agency-wide risk-based information security programs that include periodic risk assessments, use of controls and techniques to comply with information security standards, training requirements, periodic testing and evaluation, reporting, and plans for remedial action, security incident response, and continuity of operations.
44 U.S.C. §§ 3501-
Paperwork Reduction Act of 1995, Revised
This law provides for the administration and management of computer resources.
44 U.S.C. §21, 29, 31 and 33
Federal Records Act of
Establishes the framework used by Federal agencies for their Records Management programs.
5 U.S.C. § 552 The Freedom of Information Act (FOIA) of
This law requires that Federal information be made available to the public except under certain specified conditions.
5 U.S.C. § 552a The Privacy Act of 1974 This law imposes collection, maintenance, use, safeguard, and disposal requirements for Executive Branch offices maintaining information on individuals in a “system of records.”
34 CFR Part 99 Family Educational Rights and Privacy Act of
1974 (FERPA)
requirements for the protection of privacy of parents and students under section 444 of the General Education Provisions Act, as amended.
5 U.S.C. 552a(b)(12) Disclosure to Consumer Reporting Agencies;
Public information;
agency rules, opinions, orders, records, and proceedings
Information on appropriate disclosure of information to a consumer reporting agency in accordance with section 3711(e) of title 31.
Public Law 94-142 as amended by P.L. 105-
Individuals with Disabilities Act
This law that makes available a free appropriate public education to eligible children with disabilities throughout the nation and ensure special education and related service to those children.
Office of Information Technology 14
Document Identifier Title Description Public Law 95-561 Education Amendments of 1978: An Act to Extend and Amend Expiring Elementary and Secondary Education Programs, and for Other Purposes
An Act to Extend and Amend Expiring Elementary and Secondary Education Programs, and for Other Purposes.
Public Law 103-382 Improving America's Schools Act of 2004
This law that makes available a free appropriate public education to eligible children with disabilities throughout the nation and ensure special education and related service to those children.
Public Law 107-110 Every Student Succeeds Act No Child Left Behind Act of 2001 (NCLBA)
Part D: Native American Education Improvement Act
Every Student Succeeds Act (ESSA) is the law that replaced the NCLB in 2015. Its purpose is to provide high-quality education to all students. The ESSA reauthorizes Elementary and Secondary Education Act (ESEA), the nation’s national education law and longstanding commitment to equal opportunity for all students.
No Child Left Behind is a comprehensive plan to reform schools, change school culture, empower parents, and improve education for all children. The law promises to raise standards for all children and to help all children meet these standards.
Public Law 94-142
Individuals with Disabilities Education Act
(IDEA)
A law that makes available a free appropriate public education to eligible children with disabilities throughout the nation and ensures special education and related services to those children.
Office of Information Technology 15
4.3 Executive Orders
Table 4: Executive Orders
Document Identifier
Title Description
Executive Order 10450
Security Requirements for Government Employees, April 1953
This order establishes that the interests of national security require all government employees be trustworthy, of good character, and loyal to the United States.
Executive Order 13011, Federal Information Technology, July 1996
This order establishes policy for the head of each agency to effectively use information technology to improve mission performance and service to the public.
Executive Order 13103
Computer Software Piracy, September 1998
This order establishes policy that each executive agency shall work diligently to prevent and combat software piracy in order to give effect to copyrights associated with computer software.
Executive Order 13231
Critical Infrastructure Protection in the Information Age, October
This order establishes policy that ensures protection of information systems for critical infrastructure, including emergency preparedness communications, and the physical assets that support such information systems.
Presidential Decision Directive 63
Critical Infrastructure Protection, May 1998
This directive requires that the United States take all necessary measures to swiftly eliminate any significant vulnerability to both physical and cyber-attacks on critical infrastructures, including our cyber systems.
Office of Information Technology 16
Document Identifier
Title Description
Executive Order 14028 Improving the Nations
Cyber Security
The United States faces persistent and increasingly sophisticated malicious cyber campaigns that threaten the public sector, the private sector, and ultimately the American people’s security and privacy. The Federal Government must improve its efforts to identify, deter, protect against, detect, and respond to these actions and actors. The Federal Government must also carefully examine what occurred during any major cyber incident and apply lessons learned. But cybersecurity requires more than government action. Protecting our Nation from malicious cyber actors requires the Federal Government to partner with the private sector.
Presidential Decision Directive 12
Policy for a Common Identification Standard for Federal Employees and Contractors
There are wide variations in the quality and security of identification used to gain access to secure facilities where there is potential for terrorist attacks. In order to eliminate these variations, U.S. policy is to enhance security, increase Government efficiency, reduce identity fraud, and protect personal privacy by establishing a mandatory, Government-wide standard for secure and reliable forms of identification issued by the Federal Government to its employees and contractors (including contractor employees). This directive mandates a federal standard for secure and reliable forms of identification.
Office of Information Technology 17
4.4 OMB Circulars and Memoranda
Document Identifier Title Description
A-11, Section 53 Information Technology and E- Government
This directive specifies the identification of security and privacy safeguards for managing sensitive information.
A-123 Management Accountability and Control, as revised December 21, 2004
This directive specifies the policies and standards for establishing, assessing, correcting, and reporting on management controls in Federal agencies.
A-127 Financial Management Systems, as revised by Transmittal Memorandum Number 3, December 1, 2004
This directive prescribes policies and standards for executive departments and agencies to follow in developing, operating, evaluating, and reporting on financial management systems.
A-130, Appendix I Responsibilities for Protecting and Managing Federal Information Resources
This Appendix establishes minimum requirements for Federal information security programs, assigns Federal agency responsibilities for the security of information and information systems, and links agency information security programs and agency management control systems established in accordance with OMB Circular A-123, Management’s Responsibility for Enterprise Risk Management and Internal Controls. This Appendix also establishes requirements for Federal agency privacy programs, assigns responsibilities for privacy program management, and describes how agencies should take a coordinated approach to implementing information security and privacy controls.
Additionally, this Appendix incorporates requirements of statute, such as FISMA (44 U.S.C. Chapter 35), the E- Government Act of 2002 (44 U.S.C.
Chapters 35 and 36), the Paperwork Reduction Act (44 U.S.C. Chapter 35), and the Privacy Act of 1974, and responsibilities assigned in executive orders and Presidential directives.
Office of Information Technology 18
Document Identifier Title Description A-130, Appendix II Responsibilities for
Managing Personally Identifiable Information
This Appendix outlines some of the general responsibilities for Federal agencies managing information resources that involve personally identifiable information (PII) and summarizes the key privacy requirements included in other sections of Circular A-130. The requirements included in this Appendix apply to PII in any form or medium, including paper and electronic media.
Memorandum M-05-
Implementation of Homeland Security Presidential (HSPD) 12
– Policy for a Common Identification Standard for Federal Employees and Contractors.
The Directive requires the development and agency implementation of a mandatory, government-wide standard for secure and reliable forms of identification for Federal employees and contractors.
Memorandum M-11-
Continued Implementation of Homeland Security Presidential Directive (HSPD) 12– Policy for a Common Identification Standard for Federal Employees and Contractors (02 Feb, 2011)
HSPD-12 requires agencies to follow specific technical standards and business processes for the issuance and routine use of Federal Personal Identity Verification (PIV) smartcard credentials including a standardized background investigation to verify employees’ and contractors’ identities.
Memorandum M-11-
Reporting Instructions for the Federal Information Security Management Act and Agency Privacy Management (14 Sep 2011)
Monthly reporting of key metrics through CyberScope
Memorandum M-17-
Preparing for and Responding to a Breach of Personally Identifiable Information
This Memorandum sets forth the policy for Federal agencies to prepare for and respond to a breach of personally identifiable information (PII). It includes a framework for assessing and mitigating the risk of harm to individuals potentially affected by a breach, as well as guidance on whether and how to provide notification and services to those individuals.
Office of Information Technology 19
4.5 Standards and Guidelines
Table 5: Standards and Guidelines
Document Identifier Title Description FIPS Pub 140-2 Security Requirements for Cryptographic Modules
This Federal Information Processing Standard (140-2) specifies the security requirements that will be satisfied by a cryptographic module, providing four increasing, qualitative levels intended to cover a wide range of potential applications and environments. The areas covered, related to the secure design and implementation of a cryptographic module, include specification; ports and interfaces; roles, services, and authentication; finite state model; physical security; operational environment; cryptographic key management; electromagnetic interference/electromagnetic compatibility (EMI/EMC); self-tests;
design assurance; and mitigation of other attacks.
FIPS Pub 199 Standards for Security Categorization of Federal Information and Information Systems
The purpose of this document is to provide a standard for categorizing federal information and information systems according to an agency's level of concern for confidentiality, integrity, and availability and the potential impact on agency assets and operations should their information and information systems be compromised through unauthorized access, use, disclosure, disruption, modification, or destruction.
Office of Information Technology 20
Document Identifier Title Description FIPS Pub 200 Minimum Security
Requirements for Federal Information and Information Systems
FIPS 200 is the second standard that was specified by the Information Technology Management Reform Act of 1996 (FISMA). It is an integral part of the risk management framework that the National Institute of Standards and Technology (NIST) has developed to assist federal agencies in providing levels of information security based on levels of risk. FIPS 200 specifies minimum security requirements for federal information and information systems and a risk-based process for selecting the security controls necessary to satisfy the minimum requirements.
NIST SP 800-137 Information Security Continuous Monitoring for Federal Information Systems and Organizations
The purpose of this guideline is to assist organizations in the development of a continuous monitoring strategy and the implementation of a continuous monitoring program providing visibility into organizational assets, awareness of threats and vulnerabilities, and visibility into the effectiveness of deployed security controls. It provides ongoing assurance that planned and implemented security controls are aligned with organizational risk tolerance as well as the information needed to respond to risk in a timely manner should observations indicate that the security controls are inadequate.
Office of Information Technology 21
Document Identifier Title Description NIST SP 800-18 Guide for Developing
Security Plans for Federal Information Systems
The objective of system security planning is to improve protection of information system resources. All federal systems have some level of sensitivity and require protection as part of good management practice. The protection of a system must be documented in a system security plan. The completion of system security plans is a requirement of the Office of Management and Budget (OMB) Circular A-130, "Management of Federal Information Resources," Appendix III, "Security of Federal Automated Information Resources," and Title III of the E-Government Act, entitled the Federal Information Security Management Act (FISMA), The purpose of the system security plan is to provide an overview of the security requirements of the system and describe the controls in place or planned for meeting those requirements. The system security plan also delineates responsibilities and expected behavior of all individuals who access the system. The system security plan should be viewed as documentation of the structured process of planning adequate, cost-effective security protection for a system. It should reflect input from various managers with responsibilities concerning the system, including information owners, the system owner, and the senior agency information security officer (SAISO).
Additional information may be included in the basic plan and the structure and format organized according to agency needs, so long as the major sections described in this document are adequately covered and readily identifiable.
Office of Information Technology 22
Document Identifier Title Description NIST SP 800-30 Guide for Conducting
Risk Assessments The purpose of Special Publication 800- 30 is to provide guidance for conducting risk assessments of federal information systems and organizations, amplifying the guidance in Special Publication 800-
39. Risk assessments, carried out at all three tiers in the risk management hierarchy, are part of an overall risk management process—providing senior leaders/executives with the information needed to determine appropriate courses of action in response to identified risks.
NIST SP 800-34 Contingency Planning Guide for Federal Information Systems
This publication assists organizations in understanding the purpose, process, and format of information system contingency planning development through practical, real-world guidelines. This guidance document provides background information on interrelationships between information system contingency planning and other types of security and emergency management-related contingency plans, organizational resiliency, and the system development life cycle. This document provides guidance to help personnel evaluate information systems and operations to determine contingency planning requirements and priorities.
Office of Information Technology 23
Document Identifier Title Description NIST SP 800-37 Guide for Applying the
Risk Management Framework to Federal Information Systems: A Security Life Cycle Approach
This publication describes the Risk Management Framework (RMF) and provides guidelines for applying the RMF to information systems and organizations. The RMF provides a disciplined, structured, and flexible process for managing security and privacy risk that includes information security categorization; control selection, implementation, and assessment;
system and common control authorizations; and continuous monitoring. The RMF includes activities to prepare organizations to execute the framework at appropriate risk management levels. The RMF also promotes near real-time risk management and ongoing information system and common control authorization through the implementation of continuous monitoring processes;
provides senior leaders and executives with the necessary information to make efficient, cost-effective, risk management decisions about the systems supporting their missions and business functions;
and incorporates security and privacy into the system development life cycle.
Executing the RMF tasks links essential risk management processes at the system level to risk management processes at the organization level. In addition, it establishes responsibility and accountability for the controls implemented within an organization’s information systems and inherited by those systems.
Office of Information Technology 24
Document Identifier Title Description NIST SP 800-39 Managing Information
Security Risk:
Organization, Mission, and Information System View
The purpose of Special Publication 800- 39 is to provide guidance for an integrated, organization-wide program for managing information security risk to organizational operations (i.e., mission, functions, image, and reputation), organizational assets, individuals, other organizations, and the Nation resulting from the operation and use of federal information systems. Special Publication 800-39 provides a structured, yet flexible approach for managing information security risk that is intentionally broad-based, with the specific details of assessing, responding to, and monitoring risk on an ongoing basis provided by other supporting NIST security standards and guidelines. The guidance provided in this publication is not intended to replace or subsume other risk-related activities, programs, processes, or approaches that organizations have implemented or intend to implement addressing areas of risk management covered by other legislation, directives, policies, programmatic initiatives, or mission/business requirements. Rather, the information security risk management guidance described herein is complementary to and can be used as part of a more comprehensive Enterprise Risk Management (ERM) program.
NIST SP 800-47 Managing the Security of Information Exchanges
This publication focuses on managing the protection of the information being exchanged or accessed before, during, and after the exchange and provides guidance on identifying information exchanges, considerations for protecting exchanged information, and the agreement(s) needed to help manage the risk associated with exchanging information.
Office of Information Technology 25
Document Identifier Title Description NIST SP 800-53 Recommended Security
Controls for Federal Information Systems and Organizations
This publication provides a catalog of security and privacy controls for information systems and organizations to protect organizational operations and assets, individuals, other organizations, and the Nation from a diverse set of threats and risks, including hostile attacks, human errors, natural disasters, structural failures, foreign intelligence entities, and privacy risks. The controls are flexible and customizable and implemented as part of an organization-wide process to manage risk. The controls address diverse requirements derived from mission and business needs, laws, executive orders, directives, regulations, policies, standards, and guidelines. Finally, the consolidated control catalog addresses security and privacy from a functionality perspective (i.e., the strength of functions and mechanisms provided by the controls) and from an assurance perspective (i.e., the measure of confidence in the security or privacy capability provided by the controls). Addressing functionality and assurance helps to ensure that information technology products and the systems that rely on those products are sufficiently trustworthy.
Office of Information Technology 26
Document Identifier Title Description NIST SP 800-53A Guide for Assessing the
Security Controls in Federal Information Systems and Organizations, Building Effective Security Assessment Plans
This publication provides a methodology and set of procedures for conducting assessments of security and privacy controls employed within systems and organizations within an effective risk management framework. The assessment procedures, executed at various phases of the system development life cycle, are consistent with the security and privacy controls in NIST Special Publication 800-53, Revision 5. The procedures are customizable and can be easily tailored to provide organizations with the needed flexibility to conduct security and privacy control assessments that support organizational risk management processes and are aligned with the stated risk tolerance of the organization.
Information on building effective security and privacy assessment plans is also provided with guidance on analyzing assessment results.
NIST SP 800-60 Guide for Mapping Types of Information and Information Systems to Security Categories: (2 Volumes) - Volume 1:
Guide Volume 2: Appendices
Categorize information and information systems collected or maintained by or on behalf of each agency based on the objectives of providing appropriate levels of information security according to a range of risk levels; and guidelines recommending the types of information and information systems to be included in each such category.
NIST Security Technical Implementation Guides
STIGs – also referred to as security configuration checklists
The use of STIGs enables a methodology for securing protocols within networks, servers, computers, and logical designs to enhance overall security. These guides, when implemented, enhance security for software, hardware, physical and logical architectures to further reduce vulnerabilities.
Office of Information Technology 27
5.0 Requirements Summary
The Requirements Summary is in two parts. The traceable requirements are further detailed in the Requirements Traceability Matrix (RTM). The General Requirements are overall solution requirements. If any section of these requirements is not applicable, then enter Not Applicable for the section.
5.1 Traceable Requirements
5.1.1 Functional Requirements
NASIS will allow BIE to store, access, and analyze student demographic data, student assessment and achievement data to reformulate academic and residential strategies, align curriculum to BIE standards including the standards of states where tribes have approved waivers (potentially 23 different states), analyze standardized assessment trends and student performance to identify weakness and successes, create new visions and ideas to increase academic outcomes, and provide data to make accountability determinations as outlined in the BIE’s Agency Plan, and the submit related data.
NASIS allows access to aforementioned student data making possible the distillation of data into reports at the Central Office, Associate Deputy Director, Education Resource Centers (including the Education Program Administrators), and the schools. At each level, users must be able to run bureau-wide aggregate reports as well as on demand ad-hoc reports.
The other primary NASIS requirement is the delivery of NASIS Student and School Services. Student and School Services are similar to those that would be anticipated in most schools' systems.
NASIS will provide schools with as complete a feature set as possible to support and satisfy day-to-day and planning needs. This would include data input, collection and reporting for a variety of functions such as, but not limited to, scheduling, attendance, grade reporting, behavior tracking, test and assessment histories, program enrollments, and other areas of need. There are some unique BIE requirements related to, for example, tribal documentation, early childhood programs, transportation and residential/dormitory operations.
The contractor shall deliver the student Information System as a contractor-owned, contractor-operated environment (CoCo), this is akin to the contractor performing as an Application Service Provider (ASP) specifically for the BIE.
The contractor is responsible for both the ownership and the day-to-day operations, including staffing, managing, and maintaining the assets or services. The government specifies the scope, performance requirements, and compensation for services provided as described in this document.
The contractor will provide the Student Information System as a single environment from their data center / premise. BIE will access this environment remotely, securely and using PIV multi-factor authentication.
Office of Information Technology 28
The system must also be:
• Be able to achieve an Authority to Operate (ATO) certification within twelve (12) months of award.
• Be able to be minimally modified as necessary to achieve ATO (such as implementing pre-login warning banners)
• Be assessed by a third-party assessment organization (3PAO), either federal or commercial.
5.1.2 Data Requirements
Data requirements include the ability to:
• Migrate Systems Interoperability Framework (SIF) and Open Database Connectivity (ODBC) compliant data to the procured solution, while providing the continued capability for a centralized system supporting teachers, other school staff, students, parents, and BIE staff.
• Synchronize data elements entered at the school level of the system, to the State level of the system, for example chronic absenteeism reporting on a daily basis
• Ability to capture electronic signatures at the point of origination
• Ability to upload documentation, e.g., PDFs at the point of origination.
NASIS will employ XML and JSON compliant data structures.
The platform and its data hosting must ensure that the data is not visible for anyone outside of the BIE, nor hosted outside the Continental US boundaries.
This requires the following:
NASIS will have the capability to institute role-based rights to data and functions.
• No other interface can be added to the system without prior approval and/or notification of BIE.
• NASIS will comply with the requirements of the Privacy Act and the Family Educational Rights Privacy Act (FERPA).
5.1.3 Security
As with all Federal government agencies, BIE is subject to numerous requirements stemming from a variety of laws, rules, regulations, directives, and standards aimed at ensuring the protection of sensitive agency information and information systems. These requirements include providing information security protections commensurate with the risk and magnitude of the potential harm resulting from unauthorized access, use, disclosure, disruption, modification, or destruction of (i) information collected or maintained by or on behalf of the agency; and (ii) information systems used or operated by the agency or by a contractor on behalf of the agency.
Office of Information Technology 29
Consequently, the Contractor shall also adhere to and comply with applicable Laws, Executive Orders and Executive Branch Policy regarding the design, build, testing, operations and maintenance of the information system and the security controls designed to safeguard agency information. This document outlines and references the information technology (IT) security and privacy requirements in which the service provider must comply. These requirements are applicable when BIE information is generated, accessed, stored, processed, or exchanged with BIE or on behalf of BIE by a service provider or subcontracted service provider, regardless of whether the information resides on a BIE information system or a service provider/subcontracted service provider’s information system. The service provider shall protect the confidentiality, integrity, and availability of BIE electronic information and IT resources and protect BIE electronic information from unauthorized disclosure.
The system will generate alerts for selected significant events, including:
• Adverse Events: An event with a negative consequence, such as…
This is the start of the file's text. The full file is on GovTribe.
File details come from the government source that posted it. Updated .