Draft_PWS_-_NCES_Data_Licensing__Inspection_Support_11-13-2012.doc
DOC document 252 KB Posted
- Attached to
- NCES DATA LICENSING AND INSPECTION SUPPORT Federal contract opportunity
- Solicitation number
- ED-IES-13-R-0004
View the file
Other files for this federal contract opportunity
| File | Type | Posted |
|---|---|---|
| AMENDMENT_001_signed.pdf | ||
| Attachment_A_-_PWS.doc | DOC document | |
| SF1449_-_Solicitation_NCES_DATA_LICENSING_AND_INSPECTION_SUPPORT.pdf | ||
| Attachment_C_Past_Performance_Form.doc | DOC document | |
| Attachment_B_QASP.docx | DOCX document | |
| Draft_PWS_-NCES_Data_Licensing_Inspection_Support_12-10-2012.doc | DOC document | |
| RFI_Capability_Satement_Instructions-_NCES_DATA_LICENSING_and_INSPECTION_SUPPORT.docx | DOCX document |
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
DRAFT - PERFORMANCE WORK STATEMENT
NCES Data Licensing and Inspection Support
ED-IES-13-R-0004
I. Background The National Center for Education Statistics (NCES) of the Institute of Education Science (IES) is the primary federal entity for collecting, analyzing, and reporting data related to education in the United States and other nations. It fulfills a congressional mandate to collect, collate, analyze, and report full and complete statistics on the condition of education in the United States; conduct and publish reports and specialized analyses of the meaning and significance of such statistics; assist state and local education agencies in improving their statistical systems; and review and report on education activities in foreign countries.
II. Purpose
The Statistical Standard Programs (SSP) within the Office of Deputy Commissioner (ODC) of NCES provides state-of-the-art technical and statistical support to the Center and to federal and non-federal organizations and entities that engage in statistical work in support of the mission of IES/NCES. One of SSP’s responsibilities is to devise, administer, and monitor all facets of the preservation of the confidentiality of individually identifiable information in data held and disseminated by IES/NCES as required by law and regulation.
SSP has a need for a contractor to perform periodic, on-site inspections of selected IES/NCES licensee sites where researchers have licensing agreements with IES/NCES to access IES/NCES restricted-use data files, to maintain and update the License Documentation System, to review data security plans submitted by the licensure applicants, and to perform data inspection technical assistance.
III. Enabling Legislation The authority for this project resides in law H.R.3801, an Act to “provide for improvement of Federal education research, statistics, evaluation, information, and dissemination, and for other purposes.” Under Title I, Part C, Sec. 151 of the Act, it states:
(a) ESTABLISHMENT.—There is established in the Institute a National Center for Education Statistics (in this part referred to as the ‘‘Statistics Center’’). (b) MISSION.—The mission of the Statistics Center shall be — (1) to collect and analyze education information and statistics in a manner that meets the highest methodological standards; (2) to report education information and statistics in a timely manner; and (3) to collect, analyze, and report education information and statistics in a manner that — (A) is objective, secular, neutral, and nonideological and is free of partisan political influence and racial, cultural, gender, or regional bias; and (B) is relevant and useful to practitioners, researchers, policymakers, and the public.
Further, the Sec.154 of the Act states NCES’ performance of duties as follows:
(a) GRANTS, CONTRACTS, AND COOPERATIVE AGREEMENTS. — In carrying out the duties under this part, the Statistics Commissioner, may award grants, enter into contracts and cooperative agreements, and provide technical assistance.
(c) DURATION. — Notwithstanding any other provision of law, the grants, contracts, and cooperative agreements under this section may be awarded, on a competitive basis, for a period of not more than 5 years, and may be renewed at the discretion of the Statistics Commissioner for an additional period of not more than 5 years.
IV. Restricted-use Data Licensing System Restricted-use Data Licensing Procedure
Many individuals, such as staff of IES/NCES, employees of contractors, staff of State and local education agencies, and research staff in other units of the Department of Education, may require the use of complete data sets that contain individual records and information that make the identification and disclosure of individuals possible. These data may be necessary either for the purpose of data collection and verification or for analysis that is consistent with the purpose for which the data were collected. Others, such as scholars, researchers and policy makers, may also need access to this kind of data.
All external users of IES/NCES individually identifiable data must take an oath of non-disclosure, and undertake commitments with respect to security of the data. Files and records of the oaths of non-disclosure are maintained by the IES/NCES as a system of records as defined by the Privacy Act of 1974.
IES/NCES has made a significant effort to make its data more useful to the education community. This has involved either a greater linkage of surveys, more geographic detail, or expansion of data-items. There is often a significant amount of information available to the public about the units or individuals surveyed through external universe files or through other sources. Inclusion of all of the survey information collected on a “public” release data file (or CD-ROM) makes it easy to disclose individual identities. For this reason, IES/NCES conducts disclosure risk analysis and modifies or suppresses data in order to release a “public use” file that meets the confidentiality requirements.
While public use data files meet the needs of a large number of data users, other users require more detail. By law, the Director of IES can authorize outside use of potentially identifiable information for statistical purposes. The Director must be able to protect the identity of individuals in data held and distributed by IES/NCES.
IES/NCES provides sworn individuals access to data in a monitored environment at IES/NCES or through licensing agreements that permit a sworn user to have access at his/her own facility. All persons with access to identifiable information must sign and notarize an affidavit of non-disclosure, be able to justify their planned use of the data, and give reasons why the public-use file is not sufficient for research needs.
Those who desire access to individually identifiable information at their own facility through a licensing agreement must provide security for the data files. The licensing agreement includes guidance on those security procedures. IES/NCES has licensed a number of Federal agencies, State agencies, various research organizations and research universities. The period of time for the license usually depends upon the length of the research project, with renewable licenses available for periods of 1 to 5 years.
Before IES/NCES grants a license, the potential licensees must agree to the terms of the license that address the protection of the identity of individual records. IES/NCES, as required by the Education Sciences Reform Act of 2002, is responsible for the physical security of confidential information and computer security both in-house, for contractor licensees, and any others who have direct access to IES/NCES confidential data. IES/NCES also has a mandate to share information with the education research community in order to maximize the data utility.
A Restricted-Use Data Procedures Manual has been developed that addresses all aspects of the IES/NCES licensing program and the procedures for inspection. The manual can be found at: http://nces.ed.gov/pubs96/96860rev.pdf. All persons having access to IES/NCES restricted data must follow the requirements and restrictions in the method of maintenance and handling of individually identifiable information, as specified in this manual.
The Procedures Manual describes how institutions and individual researchers may apply for access to potentially individually identifiable information, and how organizations enter into licensing agreements for receipt, retention, protection and utilization of databases containing restricted data. Each license only grants access for up to seven (7) users of the approved dataset. If a Principal Project Officer (PPO) wants to add users to an existing license that already contains seven (7) users, he/she needs to apply for another license. In recent years, NCES granted approximately 200 original, first time licenses each year.
License Documentation System (LDS)
According to the licensing process described in the Chapter 2 of the Restricted-Use Data Procedures Manual, institutions and individuals must submit an online formal request through the NCES Electronic Application System to initiate the application process. Once the request is accepted, the applicant must submit the following paper documents to the IES Data Security Office for approval: a signed License Agreement, executed Affidavits of Nondisclosure, and a signed Security Plan.
The LDS is a mechanism that converts the paper license documents using high resolution optical scanning and optical character recognition (OCR) software to produce digitally secure, searchable text, in the form of electronic Acrobat PDF files that simulate the original license document forms. The PDF files have the advantage of being keyword-searchable and fully secure. The system allows for easy exportability and allows for data conversion to alternative file systems according to IES/NCES needs.
Confidentiality Laws
Among the data that IES/NCES collects, many contain individually identifiable information, which is confidential and protected by federal law. The relevant laws about survey data that contain individual identifiable information are found in the followings:
Privacy Act of 1974, as amended – “The purpose of this Act is to provide certain safeguards for an individual against invasion of personal privacy by requiring Federal agencies … to collect, maintain, use or disseminate any record of identifiable personal information in a manner that assures that such action is for necessary and lawful purposes, that the information is current and accurate for its intended use, and that adequate safeguards are provided to prevent misuse of such information.”
Family Educational Rights and Privacy Act of 1974 – The use of data is vital to ensuring the best education for our children. The benefits of using student data must always be balanced with the need to protect students’ privacy rights. It is essential that everyone who has access to personally identifiable student data understands their roles and responsibilities to protect that information and uphold the student’s privacy and confidentiality. These regulations are designed to both protect privacy and to help us ensure that all State or federally funded education programs are adequately preparing children for success in the next stage of life, whether that is in kindergarten or the workforce. These regulations strengthen enforcement, ensure the safety of students, and ensure our taxpayer funds are invested in effective programs.
Computer Security Act of 1987 – This law requires each Federal agency to identify all Federal computer systems that contain sensitive information and implement security plans to protect these systems. The Computer Security Act defines the term “sensitive information” as any unclassified information, which could adversely affect the:
a.
National interest, b.
Conduct of Federal programs, or c.
Privacy to which individuals are entitled under the Privacy Act of 1974.
USA Patriot Act of 2001 – This law permits the Attorney General to petition a court of competent jurisdiction for an ex parte order requiring the Secretary of the Department of Education to provide data relevant to an authorized investigation or prosecution of an offense concerning national or international terrorism. Any data obtained by the Attorney General for these purposes must be subject to a confidentiality agreement negotiated between the Secretary and the Attorney General. This law was incorporated into the Education Sciences Reform Act of 2002.
Education Sciences Reform Act of 2002 – Under this law all individually identifiable information about students, their families, and their schools shall remain confidential. To this end, this law requires that no person may:
a.
Use any individually identifiable information furnished under the provisions of this section for any purpose other than statistical purposes for which it is supplied, except in the case of terrorism (see discussion of the Patriot Act);
b.
Make any publication whereby the data furnished by any particular person under this section can be identified; or c.
Permit anyone other than the individuals authorized by the Commissioner to examine the individual reports.
E-Government Act of 2002, Title V, Subtitle A, Confidential Information Protection – Under this law all data or information acquired from individuals or organizations by any federal agency under a pledge of confidentiality for exclusively statistical purposes shall not be disclosed by the agency in identifiable form, for any use other than an exclusively statistical purpose.
It has been determined that any person, whether Federal employee, employee of a contractor, employee of a State or local education agency, or any other person who has access to individually identifiable information or the possibility of access to such data, must take an oath not to disclosure individually identifiable data. Any data release from IES/NCES or from its contractors, that will go to parties not sworn to confidentiality (i.e., the general public) must be structured so that the identities of individuals cannot easily be derived from review or analysis of the data.
Thus, IES/NCES must ensure that sufficient precautions are taken when it authorizes outside use of data with individual identifiers to protect such information from disclosure. At the same time, IES/NCES must continue to maximize the utility of its statistical data both within and outside IES/NCES subject to confidentiality constraints.
V. Scope of Work
The contractor shall work with the Government to develop and implement procedures for all tasks in this statement of work, including the performance of licensee inspections at sites located throughout the U.S.
Task 1: IES/NCES Data Security Site Inspection Support Services
The contractor shall perform its services at the contractor’s site, NCES, or by traveling to licensees sites located throughout the U.S. The contractor shall plan for an average site visit of four hours. To preserve the element of surprise in the inspection, while at the same time minimizing the cost of unnecessary travel, the contractor shall call in advance, ideally one day ahead, to the PPO, identifying him or herself as a representative of the federal government who needs to schedule an appointment with the individual.
Subtask 1a: Select Inspection Sites Within two weeks after the contract is awarded, work with the Task Leader and Contracting Officer’s Representative (COR) to select two hundred (200) licenses for data security and compliance inspection. The 200 licenses should contain at least 150 different sites/organizations as some organizations/sites may obtain more than one license. The criteria for selecting the site inspection include, but are not limited to, 1) the licensees who have not been previously inspected, 2) new licensees, and 3) the licensees with reported difficulties with security requirements. Of the 200 licenses, at least 40 licenses shall be in each of the Census Bureau’s Regions (i.e., Northeast, Midwest, South, and West). Often, but not always, these sites are visited in clusters of up to 3 sites. Appendix A lists some possible inspection locations by region.
Subtask 1b: Complete a Site Inspection Plan Submit the proposed plan for inspecting the 200 licenses and obtain the approval from the Task Leader and COR within two (2) weeks after the selection of 200 licenses is approved by the Task Leader and COR. The plan shall contain information including, but is not limited to: 1) the list of 200 licenses to be inspected including license number, name of the PPO, location of the organization, etc., and 2) the tentative month for each inspection. The contractor shall plan approximately 50 inspections per 3 months. Among the 200 licenses, up to 40 are subject to change based on programmatic needs or knowledge of recent or suspected security violations.
Subtask 1c: Update the Site Inspection Form Within one month after the contract is awarded, work with the Task Leader and COR to modify and finalize a currently used computer assisted site inspection form for conducting the inspections. The currently used inspection form is shown in Appendix B.
The final site inspection form should, at minimum, collect information on areas generally to be checked during the inspection. These areas can be found in the Restricted-Use Data Procedures Manual (http://nces.ed.gov/statprog/rudman). These site inspection forms shall be marked as “For Office Use Only” to ensure confidentiality within the Department.
Subtask 1d: Conduct Site Inspections
The content of a site inspection includes, but is not limited to:
i. reviewing and determining whether all security procedures, as prescribed in the IES Restricted-Use Data Procedures Manual, the licensee’s approved Security Plan, and License Agreement, have been implemented or honored by the licensee;
ii. working with licensees to correct any minor infractions to facilitate compliance;
iii. reviewing and verifying authorized users, by confirming that all persons having access to restricted-use data have executed and notarized affidavits of non-disclosure, and that any exceptions are noted in the inspection report;
iv. assisting in the retrieval of restricted-use data from licensees and/or from the location originally issued the restricted-use data when poor protection of data warrants it. Prior to retrieval of the data, the contractor shall get permission from the IES Data Security Officer and COR.
v. bearing responsibility for the security of the licensee’s License information and all relevant NCES data to and from the sites.
An inspection form shall be completed and electronically transmitted to the Task Leader and Data Security Officer for review and appropriate action within two (2) weeks after the inspection is conducted. The individual inspection report should include evidence of compliance with or violation of the terms of the licensing and security procedures. In addition to the individual inspection reports, the contractor shall also submit a bi-weekly “Action Required” spreadsheet indicating the concerns during the site inspections and providing suggestions for potential actions. The currently used Action Required spreadsheet includes the following columns: date, license number, organization name, PPO name, notes from the site inspector, comments from NCES, and completion indicator. Minor infractions corrected in c. ii should be included in the Inspection Report.
Task 2: License Documentation System (LDS) Support Services
Subtask 2a: Maintain and Update LDS
The contractor shall maintain and continue to update the License Documentation System (LDS) that converts paper license documents using high resolution optical scanning and optical character recognition (OCR) software to produce digitally secure, searchable text, in the form of electronic Acrobat PDF files that simulate the original license document forms. These PDF files will have the advantage of being keyword-searchable and fully secure. The system will allow for easy exportability and will allow for data conversion to alternative file systems according to IES/NCES needs (see further details below).
The Government owns the LDS software and contents. The contractor shall convert paper license documents using high-resolution optical scanning and optical character recognition (OCR) software to produce digitally secure, searchable text files that are accessible across standard software platforms. The contractor must maintain a system that produces a customized electronic archiving solution by using data imaging to scan the paper files and by converting them into electronic PDF files. The resulting PDF files simulate the original document format, but the contractor shall ensure that they are keyword-searchable, fully secure, and have backwards compatibility with legacy systems while maintaining simple upgradability.
Every two (2) weeks, the contractor shall upload the update LDS information to the IES/NCES secure server.
Subtask 2b: Provide Physical Storage for License Documents
The contractor shall provide secure off-site office space for systematic storage of license documents after they have been scanned into the LDS. The office space shall: a) be an office room approximately 20 feet by 20 feet in width and depth; b) have least seven (7) four (4) drawer fire proof cabinets; c) have 24-hour CCTV monitoring (Non-IP access) seven (7) days per week; d) in house DVR recording and monitored by contract cleared personnel only; e) first floor office must be windowless and second and above must have at a minimum 8mm blast proof glass film on all windows; f) steel interior office entrance door; g) interior walls run to ceiling above and do not stop at ceiling tile height; and h) the room and office should have an alarm system installed (including window censors and motion detectors).
The contractor shall include in their technical proposal a drawing that depicts the floor plan of the storage office space. Ideally, the drawing should include a layout of items and where they are placed in the office (i.e. fire proof file cabinets, work station, placement of monitoring devices, windows etc.).
Task 3: Data Inspection Technical Support Services
The contractor shall provide inspection technical support services to the IES/NCES Data Security Program Office. At the request of IES/NCES, the contractor shall answer some security questions from IES/NCES about the security of licensees’ facilities and other questions about safeguarding IES/NCES confidential data.
VI. Special Work Order Requests
Work Order Request VI.A: Data Security Site Inspection Support Services
The contractor shall be prepared to provide additional site inspection technical support services beyond the 200 licenses specified under Task 1. The specifications of this task are the same as listed under Task 1, except the number of licenses for inspection. If needed, ED will increase the number of license inspections in units of 25. The contractor shall provide a fixed price for 25 additional license inspections.
Work Order Request VI.B: Data Security Plan Document Review Services
The contractor shall be prepared to review and approve up to 50 security plan proposals submitted by prospective licensees. The contractor’s review is to ensure that all security requirements in the Restricted-Use Data Procedures Manual are included in the licensee's data security plans. If needed, ED will add review technical support in units of 50 reviews. The contractor shall provide a fixed price for reviewing 50 security plan proposals.
VII. Period of Performance
This PWS will be awarded for a 12 month base period with annual one-year options for years two through five (2-5) of the contract, if exercised. The first year contract starts April 10, 2013 through April 9, 2014. Further, in accordance with PL 107.279, Section 154, the NCES Commissioner has the discretion to renew for an additional period of not more than five years.
VIII. Transition
Over a two-week period in April, 2013, if necessary, the Government may request transition meetings with the current contractor, the new contractor Project Director and Data Security Investigator, the Task Leader, and the COR, aimed at orienting the new contractors to the work to be done. In the transition meetings, the new contractor will have opportunities to review examples of acceptable deliverables, and ask any clarification questions. The number of hours for the transition is a total of 20 hours.
IX. Assumptions
The contractor shall pay for all the travel, per diem and any other costs associated with site visits. This includes travel to and from the licensee sites. No government reimbursements will be made as a result of work conducted under this contract. In order to minimize its own travel cost, the contractor is encouraged to conduct inspections in clusters of multiple sites when in certain regions of the country.
All data, either in paper or electronic form, related to the work of this task are confidential. The paper documents that need to be converted into PDF files and stored in the License Documentation System shall be picked up by the contractor in person. The government also needs to have easy accessibility to the physical data storage for monitoring purpose. For these reasons, the contractor selected to conduct the work described in the PWS must be located within 50 miles from the NCES office.
X. Required Knowledge, Skills, and Abilities
For the first year of work, the Government estimates that this project require a total of 500 hours of a Project Director/Senior Data Security Investigator, 1,240 hours of a Data Security Investigator, and 240 hours of Research Assistant. These estimates do not include the work under Special Work Order Requests.
For the work under Special Work Order Requests, the Government estimates approximately a total of 60 hours of a Project Director/Senior Data Security Investigator and 125 hours of a Data Security Investigator for every 25 license inspections specified in the Special Work Order Request VI.A. The Government estimates approximately a total of 100 hours of a Data Security Investigator for every 50 security plan proposal reviews specified in the Special Work Order Request VI.B.
The personnel performing the license inspection shall be experienced working with institutions of higher education, research organizations, state governments, and other categories of users of restricted IES/NCES data and shall have a minimum of six (6) years of law enforcement investigative experience, including four (4) of those years specifically in the area of security plan formulation and sensitive inspections. The personnel shall be acquainted with the NCES “Restricted-Use Procedures Manual” and the provisions of the Privacy Act of 1974, as amended, Family Educational Rights and Privacy Act of 1974, the Computer Security Act of 1987, the National Education Statistics Act of 1994, as amended, the U.S, Patriot Act of 2001, and Confidential Information Protection and Statistical Efficiency Act of 2002.
The personnel performing the licensing inspection shall also pass the required IES/NCES security clearance procedure and the IES/NCES annual security training required of all contractors before conducting any site inspections.
XI. Deliverables
| Task |
| Deliverable |
| Estimated Due Date |
| Subtask 1a: Select Inspection Sites |
| A List of 200 licenses for inspection |
| Within two weeks of contract initiation |
| Subtask 1b: Complete a Site Inspection Plan |
| A inspection plan containing: 1) the list of 200 licenses to be inspected including license number, name of the PPO, location of the organization, etc., and 2) the tentative month for each inspection. |
| Within two weeks after the list of 200 licenses is approved |
| Subtask 1c: Update the Site Inspection Form |
| Computer assisted interview tool and inspection form |
Within one month of contract initiation
| Subtask 1d: Conduct Site Inspections |
| Individual inspection report for each inspection |
| Within two weeks after each site visit; ongoing |
| An “Action Required” spreadsheet listing the concerns during the site inspections and providing suggestions for potential actions. |
| Biweekly |
A monthly report that includes:
1) a cumulative report that includes the list of license inspections in each of the previous months by each license number, PPO name, city, state, and organization’s name;
2) the list of licenses to be inspected in the current month by each license number, PPO name, city, state, and organization’s name; and
3) the list of licenses to be inspected in the remainder of the year, by month;
The 5th of each month.
| Subtask 2a: Maintain and Update LDS |
| A monthly report that includes: |
1) a cumulative report that includes the list of paper license documents scanned into the License Documentation System (LDS) in each of the previous months by each license number, PPO name, city, state, and organization’s name; and;
The 5th of each month.
| Task 3: Data Inspection Technical Support Services |
| A monthly report includes the number of hours contractor provides technical support to IES/NCES about licensees by each license number, PPO name, city, state, and organization’s name. |
| The 5th of each month. |
| Work Order Request VI.A: Data Security Site Inspection Support Services |
| Individual inspection report for each inspection |
| Within two weeks after each site visit; ongoing |
| An “Action Required” spreadsheet listing the concerns during the site inspections and providing suggestions for potential actions. |
| Biweekly |
A monthly report that includes:
4) a cumulative report that includes the list of license inspections in each of the previous months by each license number, PPO name, city, state, and organization’s name;
5) the list of licenses to be inspected in the current month by each license number, PPO name, city, state, and organization’s name; and
6) the list of licenses to be inspected in the remainder of the year, by month;
The 5th of each month when the services are needed.
| Work Order Request VI.B: Data Security Plan Document Review Services |
| A monthly report includes a cumulative report that includes the list of security plans reviewed in each of the previous months by each license number, PPO name, city, state, and organization’s name. |
| The 5th of each month when the services are needed. |
XII. Pricing Schedule
By the 16th of the month, the contractor shall submit to the Government an invoice of the deliverables that were submitted to and accepted by the Government during the previous calendar month.
XIII. Invoicing and Monthly Reports
Invoicing
The invoice for the prior month’s work much be received by 16th of each month. The invoice shall be submitted to OCFOCAMInvoicing@ed.gov with a carbon copy to the Contract Specialist, COR, and appointed Task Leader.
Monthly Report
The contractor shall submit monthly reports on or before the 5th of each month. The monthly reports are to be submitted via paper and electronic transmission. The monthly report shall be submitted to the COR, appointed Task Leader, and Contract Specialist.
XIV. Place of Performance
The contractor shall perform its services either at the contractor’s site, or at the office of IES/NCES, or by traveling to other licensee sites located throughout the United States and performing its services, as requested by the Government.
XV. Other Requirements
Confidentiality Requirements
The contractor shall implement such confidentiality and security provisions as NCES may require.
Deliverables
The contractor shall provide all deliverables in electronic formats.
XVI. Government Furnished Property
None.
XVII. Contact Information
The contractor shall send all deliverables to the following:
Chen-Su Chen, COR
1990 K Street, NW
Room 9059
Washington DC, 20006
Phone: (202) 502-7393
Chen-Su.Chen@ed.gov Shelley Burns, Task Leader
1990 K Street, NW
Washington DC, 20006
Phone: (202) 502-7319
Shelley.Burns@ed.gov Appendix A
Potential Locations of License Inspection
The possible locations of license inspection may include, but is not limited to, the cities in the table below. The locations are subject to change due to constant addition and deletion of the licenses.
Region 1: Northeast
| New England |
| Middle Atlantic |
CT: New Haven, Storrs
MA: Amherst, Boston, Cambridge, Chestnut Hill, Medford, Northampton, Roxbury, Shrewsbury, Somerville, Waltham, Wellesley, Woburn
ME: Lewiston
NH: Durham
RI: Kingston, Providence
VT: Burlington NJ: Glassboro, Joint Base McGuire Dix Lakehurst, Mahwah, Montclair, New Brunswick, Piscataway, Princeton, Teaneck, Wayne
NY: Albany, Alfred, Binghamton, Bronx, Buffalo, Canton, Cortland, Flushing, Hamilton, New York, Queens, Rochester, Saratoga Springs, Stony Brook, Syracuse
PA: Bethlehem, Haverford, Middletown, Newtown, Philadelphia, Pittsburgh, University Park, Villanova
Region 2: Midwest
| East North Central |
| West North Central |
IL: Champaign, Chicago, DeKalb, Normal, Springfield
IN: Bloomington, Notre Dame, West Lafayette
MI: Ann Arbor, Detroit, East Lansing, Kalamazoo, Mt. Pleasant, University Center
OH: Cincinnati, Cleveland, Columbus, Dayton, Kent, University Heights
WI: La Crosse, Madison, River Falls IA: Iowa City
KS: Lawrence, Manhattan, Topeka
MN: Minneapolis, St. Cloud, St. Paul
MO: Springfield, St. Louis
ND: Fargo
NE: Lincoln, Omaha
Appendix A
Region 3: South
| South Atlantic |
| East South Central |
| West South Central |
DC: Washington
FL: Boca Raton, Coral Gables, Ft. Myers, Gainesville, Orlando, Tallahassee
GA: Athens, Atlanta, Kennesaw
MD: Baltimore, Bethesda, Bowie, College Park, Rockville
NC: Chapel Hill, Charlotte, Davidson, Durham, Elon, Raleigh, Winston-Salem
SC: Columbia, Rock Hill
VA: Alexandria, Arlington, Blacksburg, Charlottesville, Fairfax, Lexington, Norfolk, Richmond, Williamsburg AL: Auburn, Tuscaloosa
KY: Lexington, Louisville
MS: Mississippi State University
TN: Knoxville, Nashville AR: Fayetteville, Little Rock
LA: Lafayette
OK: Norman, Stillwater, Tulsa
TX: Austin, Denton, Houston, Huntsville, Odessa, Richardson
Region 4: West
| Mountain |
| Pacific |
CO: Boulder, Colorado Springs, Denver, Fort Collins, Greeley
MT: Bozeman, Missoula
NV: Las Vegas
UT: Provo, Salt Lake City CA: Aliso Viejo, Bakersfield, Berkeley, Chico, Davis, Fullerton, Long Beach, Los Angeles, Menlo Park, Merced, Northridge, Oakland, Orange, Palo Alto, Riverside, Sacramento, San Diego, San Francisco, San Luis Obispo, Santa Barbara, Santa Monica, Stanford
HI: Honolulu
OR: Eugene
WA: Seattle
Appendix B
Site Inspection Form
Restricted-Use Data Security Assessment
□ COMPLIANT □ NONCOMPLIANT
| Inspection Date: |
| _______________________________ |
| Data Holder: |
| _______________________________________ |
| License Number: |
| _______________________________ |
| Organization: |
| _______________________________________ |
| Person Interviewed: |
| _______________________________ |
| City & state: |
| _________________ |
| Phone: _____________ |
THIS AREA TO BE COMPLETED BY NCES REPRESENTATIVE DOING ONSITE INSPECTION:
Is the location consistent with the License Agreement Security Plan? _____________________________________ □ YES □ NO
Is the Data Holder currently using the restricted-use data? (IF NO, advise Data Holder to contact Client Program office to close license) _______________________________________________________________________________________ □ YES □ NO
Minor Infractions
| □ |
| Data Holder not available at the time of the inspection |
| □ |
| No computer warning signs |
| □ |
| Office door unlocked |
| □ |
| License files not located with data |
| □ |
| Window(s) open |
| □ |
| Unauthorized users have access to the project office |
| □ |
| Computer viewable by non-employees |
| □ |
| Use of weak passwords |
| □ |
| Unlocked data storage cabinet |
| □ |
| Other: |
| □ |
| Data Holder lost key to data storage cabinet |
Major Infractions
| □ |
| Data Holder lost data |
| □ |
| Computer connected to internet |
| □ |
| Data Holder relocated |
| □ |
| Data Holder not in control of data |
| □ |
| Use of laptop computer |
| □ |
| Unauthorized users have access to data |
| □ |
| Data use at home residence |
| □ |
| Computer is not password protected |
| □ |
| NCES representative denied access to data |
| □ |
| Lack of adequate firewall protection |
| □ |
| Data loaded on server or network |
| □ |
| Lack of antivirus software |
| □ |
| Use of external hard drive/USB flash drive |
| □ |
| Other: |
Facility Security
| □ |
| Open access building |
| □ |
| Swipe card access required for office suites |
| □ |
| Building doors locked after normal business hours |
| □ |
| Receptionist present at main entrance |
| □ |
| External door is accessible after business hours only with a swipe card |
| □ |
| There is evidence of suspicious activity (see comments sheet) |
| □ |
| No security guard/police force in place |
| □ |
| Other: |
NCES Representative Action Taken
| □ |
| Follow up with Data Holder |
| □ |
| Forwarded to Data Security Officer |
| □ |
| Data Holder does not respond to NCES representative’s attempts to contact |
| □ |
| Other: |
Photos
Photo 1 Description: _________________________________ Photo 2 Description: _________________________________
Photo 3 Description: _________________________________ Photo 4 Description: _________________________________
NCES Representative: _______________________ Signature: ________________ Date: __________
Photos
Photo 5 Description: _________________________________ Photo 6 Description: _________________________________
Comments
Inspection Interview Notes
| Inspection Date: |
| _______________________________ |
| Data Holder: |
| _______________________________________ |
| License Number: |
| _______________________________ |
| Organization: |
| _______________________________________ |
| Person Interviewed: |
| _______________________________ |
| City & state: |
| _________________ |
| Phone: _____________ |
THIS AREA TO BE COMPLETED BY NCES REPRESENTATIVE DOING ONSITE INSPECTION:
- 1 -
File details come from the government source that posted it. Updated .