EPLC_UCM321959.pdf
PDF 3 MB Posted
- Attached to
- Genomic Information Management System Federal contract opportunity
- Solicitation number
- FDA-SOL-13-1119904
About this file
IT Approval Process guide (EPLC).
View the file
Other files for this federal contract opportunity
| File | Type | Posted |
|---|---|---|
| RFQ_FDA-SOL-13-1119904_(GIMS)_Mod_2.doc | DOC document | |
| RFQ_FDA-SOL-13-1119904_QandA.doc | DOC document | |
| RFQ_FDA-SOL-13-1119904_(GIMS)_Mod_1.doc | DOC document | |
| RFQ_FDA-SOL-13-1119904_(GIMS)_FINAL.doc | DOC document |
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
From Idea to Implementation A Guide to the IT Approval Process
Revised 9/13/2012
Table of Contents
Introduction
CDER Program Management Office (PMO)
Small Projects
Large Projects
IT Investment Management (ITIM)
Initial Preparation
Review and Recommendation
ITIM Approval
Authority to Operate (ATO)
Initial Preparation
Risk and Compliance Team Assessment
ATO Approval
Enterprise Performance Lifecycle (EPLC)
Stage Gates and Critical Partners
Phases of EPLC
Resources
Acronyms and Abbreviations
Acknowledgements
This user guide was developed with the generous cooperation of many individuals in
CDER and OIM. We would like to thank the many FDA employees, contractors, and IT system users who contributed to our efforts, with particular appreciation for the assistance of CDER's PMO; Scientific Computing Solutions Team; and Office of
Communications; as well as OIM's Security Branch; Architecture Review Team;
Enterprise Architecture Team; and Performance, Accepting, and Testing Team.
Introduction
From Idea to Implementation: A Guide to the IT Approval Process | CDER Computational Science Center | 1
RSR and Critical Path Projects
If you plan to seek funding through CDER’s
Science and Research intramural funding programs (Regulatory Science and Review
Enhancement (RSR) or Critical Path), you may need to obtain CDER PMO approval for your project. If your project includes or requires
Information Technology products or services
(such as the purchase or development of software, hardware, or databases) or data extraction from existing FDA systems, you need to complete the CDER PMO process prior to submitting your application. More information on CDER’s Science and Research intramural funding programs can be found on the CDER
Science and Research intranet page.
We Welcome Your Suggestions
This guide is a work in progress. The IT approval processes may be revised or evolve. If you have suggestions for updates or improvements to this guide, please Contact the CSC.
INTRODUCTION
Welcome to From Idea to Implementation: A Guide to the IT Approval Process. This guide provides direction on the approval processes required to turn an information technology (IT) idea into an operational IT solution at FDA.
IT Approval at FDA Before a new IT solution can be deployed at
FDA, it needs to be reviewed and approved. The path through the approval processes will vary depending on the nature of the IT solution and the data involved, and may involve both CDER and agency-level approval.
What Needs Approval?
IT solutions that require FDA resources
(funding or staff support), use FDA data, or are housed on FDA servers will require some type of Center or Agency approval.
Products or projects that may require approval include commercial off-the-shelf
(COTS) solutions, outside solutions developed for use at FDA, as well as solutions developed in-house.
The Approval Processes Below is a brief overview of the processes covered in this guide. Please note that the
Office of Information Management (OIM) is currently revising and streamlining their IT approval processes to improve efficiency and integration; this guide will be revised periodically to provide the most current information.
http://inside.fda.gov:9003/ProgramsInitiatives/Drugs/ScienceResearch/default.htm http://inside.fda.gov:9003/ProgramsInitiatives/Drugs/ScienceResearch/default.htm mailto:CDERCSC@FDA.HHS.GOV
From Idea to Implementation: A Guide to the IT Approval Process | CDER Computational Science Center | 2
CDER PMO
Regardless of size, scope, and complexity, most IT solutions will require CDER-level approval.
Center-level approval is granted through the CDER Program Management Office (PMO). The purpose of the CDER PMO assessment is to ensure IT investments are aligned with overall business priorities, are not duplicative of other projects, and are appropriately scoped and resourced.
ITIM
Before new IT products can be used on FDA systems, they need approval through FDA’s IT
Investment Management (ITIM) process. Managed by the Office of Information Management
(OIM), the ITIM process standardizes the review, evaluation, prioritization, funding, and implementation of IT products at FDA.
ATO
IT products that use FDA data or are housed on FDA servers require approval through the FDA
Security Authorization Process in order to receive an Authority to Operate. This process, facilitated by the Security Branch of OIM, ensures that applications have adequate security to protect the confidentiality, integrity, and availability of information collected, processed, transmitted, stored, or disseminated by the agency. The ATO process is integrated with the larger EPLC process.
EPLC
As IT technologies are developed, they follow the Enterprise Performance Lifecycle (EPLC) framework. EPLC is made up of ten phases that cover the entire lifecycle of an IT technology, from concept to disposition. Each phase involves the completion of various documents, referred to as artifacts, followed by a review of those artifacts by appropriate OIM representatives.
Introduction Figure 1 – The IT approval processes
From Idea to Implementation: A Guide to the IT Approval Process | CDER Computational Science Center | 3
Getting Started Before beginning the CDER- and FDA-level approval processes, the proposed IT solution will need support and buy-in from within the Office. Begin to develop a case for the IT solution.
Depending on the nature of the project, this could include a description of the need, who the stakeholders are, a strategic fit that places the project in the context of the agency’s mission, the financial impact (including potential cost savings), and a project plan overview.
Projects begin the approval process with CDER PMO. Once the project has support within the organization, the Requester should see the CDER PMO section of this guide. At the conclusion of the CDER PMO process, the Requester is advised how to proceed. Projects may require approval through the ITIM and EPLC processes. After completing the CDER PMO process, the
Requester typically proceeds to the ITIM process, which overlaps with early phases of the EPLC process. The ATO process, which is integrated with EPLC, begins when the project reaches the appropriate phase of EPLC.
CDER PMO Process
From Idea to Implementation: A Guide to the IT Approval Process | CDER Computational Science Center | 4
Who is Involved?
Requester – The individual or group initiating the approval process for the project
Client – The Office Director; each member of the CDER Executive Committee is a Client
Client Manager – The Office’s representative on the CDER PMO; the Director of the Office of Business Informatics appoints a Client Manager for each CDER Executive Committee member
CDER PMO – The CDER Program Management Office; made up of the OBI Director, Client Managers, OBI Service Line Directors, PMO Lead, and PMO Coordinator
CDER PMO Coordinator – Manages PMO logistics and conducts initial reviews with the
CITL
CITL – The Center IT Liaison; coordinates IT requests between CDER and OIM
CDER Executive Committee – The Clients (CDER Office Directors) collectively make up the Executive Committee and functions as CDER’s Information Technology Investment Review Board (ITIRB)
CDER PMO
Once a need has been identified and an IT solution is developed, the next step is to submit a request to the CDER Program Management Office
(PMO). The CDER PMO resides in CDER’s Office of Business Informatics (OBI), and is responsible for assessing IT requests and maintaining the
CDER Informatics Action Plan, the plan for
CDER’s informatics priorities. The purpose of the
CDER PMO assessment is to ensure IT investments are aligned with overall business priorities, are not duplicative of other projects, and are appropriately scoped and resourced.
More information can be found at MyPMO, the
CDER PMO’s website.
The CDER PMO will review the request, assess its impact and the resources required to implement the idea, and provide valuable feedback on next steps (such as proceeding to the
ITIM and/or EPLC processes). When appropriate, the CDER PMO will include a project on the CDER Informatics Action Plan and provide Center-level support as the project moves through development and into operations and maintenance.
http://inside.fda.gov:9003/CDER/OfficeofBusinessProcessSupport/ucm273002.htm
From Idea to Implementation: A Guide to the IT Approval Process | CDER Computational Science Center | 5
CDER PMO Figure 1 - The CDER PMO assessment process for both Small and Large Projects.
From Idea to Implementation: A Guide to the IT Approval Process | CDER Computational Science Center | 6
Resources:
Master Approved Technologies List Before submitting a project request, check the MAT List for an existing or alternative solution. Items on the MAT list have already been approved through the ITIM (IT
Investment Management) process, and do not require CDER PMO approval. They can be requested with an ERIC ticket. More information is available at the link above.
Small Project Request Tracker
CDER Informatics Action Plan
The Requester can consult the Small Project Request Tracker and the Informatics Action
Plan to see if any projects in the pipeline will meet their needs.
Develop User Request
In developing the request, the Requester should check if there are IT solutions already approved or waiting to be approved that will meet their needs. Three places to find this information are listed in the box below: the FDA Master Approved Technologies (MAT) List, the CDER PMO Small Project Request Tracker, and the CDER Informatics Action Plan.
Keep in mind that the CDER PMO will assess the project based on some or all of the following factors, depending on the project’s size:
Strategic fit – Has the project request been deemed a strategic fit by the Office
Director?
Redundancy – Does the request overlap with or duplicate an existing initiative?
Technical feasibility and compliance –
Is the project practical and in alignment with the FDA’s IT policies and enterprise architecture plans? General information about IT governance and the Enterprise Architecture program is available from the Information
Technology webpage of Inside.FDA.
Is the Project Small or Large?
The path that the request will follow through the CDER PMO assessment depends on its size and scope. Determining whether the project is small or large is the next step in the process.
The request will be classified by the CDER PMO as small or large using the following criteria:
Impact – How many users are impacted and is there potential impact on other IT systems?
Effort – What resources and how much time would be required to implement the proposed project?
Cost – What is the total cost to implement and maintain the proposed project?
When developing the request, the following considerations will help the Requester determine whether the project will ultimately be small or large:
What are the total costs associated with the project?
Total costs include both the costs of initial implementation and the costs of ongoing operations and maintenance. Costs can include software, hardware, licenses, infrastructure, scientific or http://apex.test.fda.gov/pls/apex/f?p=130:1:2131725691707702 http://eroom.fda.gov/eRoomReq/Files/CDER11/myPMO/0_58f6/CDER%20PMO%20Request%20Tracker.pdf http://eroom.fda.gov/eRoom/CDER11/myPMO/0_58fc
From Idea to Implementation: A Guide to the IT Approval Process | CDER Computational Science Center | 7
If the Requester is unsure whether the project request is large or small, they may consult the CDER PMO via
MyPMO. The Requester may also submit a Small Project Request with all of the available information. The
CDER PMO will review the request and offer advice and guidance.
If the CDER PMO has additional questions about the request, the
Requester may be asked to complete an Additional Information
Form. This form is used by the CDER
PMO to collect additional information about the project, allowing them to better determine its size and scope.
other equipment, and personnel. Small Projects are those that typically cost less than $25,000;
Large Projects typically cost more than $25,000.
Will the project have information security issues?
What data is involved? Where is it stored and how/where/to whom is it transmitted? Projects with information security issues may be classified as large to address these issues.
Are OBI (Office of Business Informatics) or OIM (Office of Information Management) resources required to complete the project?
Small Projects typically require only minimal resources from OBI or OIM; e.g., an ERIC (Employee Resource & Information Center) request for loading software on one or two laptops. Large Projects typically require more resources; e.g., Business and IT Project Managers (PMs) or a Business Analyst.
Will the project be housed on the FDA network? Will it access the FDA network?
Solutions and systems that are housed on the FDA network are typically large due to the resources required for implementation.
Will the project integrate with other applications?
Systems and solutions that integrate with other systems or applications are classified as large due to the level of effort required for implementation and the potential impact to other systems.
Will the project be a shared application?
How will the solution/system be accessed; e.g., from the web, the FDA network, an individual server, a shared drive, a laptop? How many users will have access? Shared applications may be classified as large because of their impact on multiple users or systems and security issues.
Will the project require customization of existing software?
Projects that require tailoring or customization of software are classified as large due to the effort needed for requirements gathering, project management, development, testing, training, and implementation.
CDER PMO Table 1, below, lists very simplified classification criteria to help in determining if the project is large or small. Every project, however, is different, and the CDER PMO considers many aspects in characterizing the project’s size and scope. The Requester can contact the
CDER PMO via MyPMO if there are questions on whether the project is small or large.
From Idea to Implementation: A Guide to the IT Approval Process | CDER Computational Science Center | 8
Criteria Small Project Large Project
Budget $25,000 or less Over $25,000
Security Impact Non-sensitive data Sensitive data (e.g., personally identifiable information)
OBI or OIM Resources Only ERIC resources needed for loading software
Resources are needed to implement the project
Housed on the Network? No Yes
Integrate with Other
Applications?
No Yes
Shared Application? No Yes
Customization or Tailoring of
Existing Software?
No Yes
If it is determined that the project is a Small Project, continue on the next page.
If it is determined that the project is a Large Project, follow the Large Project guide, beginning on page 12.
CDER PMO Table 1 – CDER PMO classification criteria for small vs. large projects.
From Idea to Implementation: A Guide to the IT Approval Process | CDER Computational Science Center | 9
Resources:
Small Project Request Form Complete the form and click the “Submit” button to initiate the request.
Small Project Request Tracker
The status of Small Projects can be tracked using the CDER PMO Small Project Request
Tracker.
Small Projects
Submit a Small Project Request Form To initiate the Small Project assessment process, the Requester completes and submits a Small
Project Request Form, available on the MyPMO website. The form collects information about the project, including the business need, the primary user(s), the IT and business resources required, the total estimated cost, and the amount and source of funding. The form can be completed and submitted electronically.
PMO Figure 2 - The Small Project assessment process http://inside.fda.gov:9003/CDER/OfficeofBusinessProcessSupport/ucm273043.htm http://eroom.fda.gov/eRoomReq/Files/CDER11/myPMO/0_58f6/CDER%20PMO%20Request%20Tracker.pdf
From Idea to Implementation: A Guide to the IT Approval Process | CDER Computational Science Center | 10
Small requests that lack funding, are not supportive of CDER’s long term strategic goals, are not in compliance with FDA
OIM standards (e.g., technical and security policies), or are highly redundant with other efforts will be denied. Denied requests will be returned to the Requester with recommendations for next steps.
Requests with incomplete cost estimates or resource requirements may need to go through the ITIM process before being approved by the CDER PMO.
Requesters may be asked to submit the project for approval through the ITIM process in order to obtain further cost and resource assessment. The request would then return to the CDER PMO after the ITIM review.
The CDER PMO Assessment Small Project Requests are reviewed initially by the CDER PMO Coordinator and the CITL. As mentioned above, the following criteria will be used to assess a Small Project Request:
Redundancy
Technical feasibility and compliance
(Strategic fit is not evaluated for Small Projects. The CDER
PMO bases the evaluation on the assumption that if funding is approved for the project, supervisory approval has been obtained.)
If the CDER PMO Coordinator and CITL have questions about the level of resources or funding required for the project, a full CDER PMO assessment may be necessary. Full CDER PMO assessments are performed during weekly CDER PMO meetings, attended by the Client Managers and the
CDER PMO Coordinator.
Does This Qualify as a Small Project Request?
After reviewing the Small Project Request, the CDER PMO Coordinator or the CDER PMO will determine if the project is small or large. As detailed above, project requests are classified as small or large using the following criteria:
Impact – How many users are impacted and is there potential impact on other IT systems?
Effort – What resources and how much time would be required to implement the proposed project?
Cost – What is the total cost to implement and maintain the proposed project?
Initial review of the Small Project Request Form will be completed and feedback will be provided by the CDER
PMO Coordinator within 30 calendar days. If the project is confirmed as small and approved, the Requester may proceed.
If the CDER PMO determines the project is actually large, it will be returned to the Requester with instructions to resubmit the project as a Large Project through their Office Director. See the
Large Project section beginning on page 12 for more information.
From Idea to Implementation: A Guide to the IT Approval Process | CDER Computational Science Center | 11
As an auxiliary member of the CDER
PMO and the Center’s liaison with
OIM, the CITL will be able to offer guidance during the ITIM process.
Begin ITIM Process If the CDER PMO approves the project, the Requester will be contacted via email with the approval and associated recommendations. The email will also include any conditions associated with the approval. The Requester should be sure to follow all instructions provided by the CDER PMO.
Some projects may require ITIM approval if required hardware or software is not already approved (i.e., on the
MAT list). The ITIM process provides review and approval of IT requests for FDA. For more information, see the ITIM section in this document.
From Idea to Implementation: A Guide to the IT Approval Process | CDER Computational Science Center | 12
Business Analysts and/or Business
Project Managers may be assigned at various times during the project depending on the nature of the project, initial understanding of the requirements, and availability of resources.
Large Projects
Submit to and Prioritize Within Requesting Organization To initiate a large project, the Requester should discuss their needs and proposed solution with their supervisor. The project will need to be approved within the Requester’s organization and presented to the Office Director (the Client) for prioritization across the Office. If the Director deems the solution to be a priority, he or she will present it to the CDER PMO Client Manager for the Office during a quarterly Joint Business Planning meeting.
Conduct Joint Business Planning Office informatics needs are assessed and prioritized during Joint Business Planning meetings.
The Client (the Requester’s Office Director) will determine the priority for the proposal and discuss it with the CDER PMO Client Manager for the Office. The request will be prioritized relative to existing projects on the CDER Informatics Action Plan. The CDER Informatics Action
Plan tracks the status and assigned resources for CDER’s large IT projects. The CDER PMO
Client Manager will take the request to the CDER PMO for further evaluation.
If needed, the CDER PMO will assign a Business Analyst to work with the Client’s designated point of contact to clarify high-level requirements. A Business Analyst may be needed to determine:
Are OIM resources required?
What are the objectives of the project?
What capabilities are provided by the proposed solution?
How much development or customization will be required?
What are the estimated total costs?
Is a solution already available?
CDER PMO Figure 3 - The Large Project assessment process
From Idea to Implementation: A Guide to the IT Approval Process | CDER Computational Science Center | 13
The Requester’s supervisor should be the point of contact for information about the project’s assessment.
The Director of the Office of Business
Informatics conducts quarterly reviews of the CDER Informatics
Action Plan with the CDER Executive
Committee.
Requests with incomplete estimates of cost or resource requirements may need to go through the ITIM process before being approved by the CDER PMO.
Requesters may be asked to submit the project for approval through the ITIM process in order to obtain further cost and resource assessment. The request is returned to the CDER PMO after the ITIM review.
During Joint Business Planning, requests not supportive of CDER’s long-term strategic goals, not in compliance with FDA OIM standards (e.g., technical and security policies), or highly redundant with other efforts will be denied. If the request is denied, the Requester will be contacted via email with recommended next steps.
The CDER PMO Assessment The CDER PMO performs the CDER PMO assessment. CDER PMO assessments are completed during weekly CDER PMO meetings, attended by the Client Managers and the CDER PMO
Coordinator.
As mentioned above, the following criteria will be used to assess Large Project requests:
Strategic fit – Has the project request been deemed a strategic fit by the Office Director?
Redundancy – Does the request overlap with or duplicate an existing initiative?
Technical feasibility and compliance – Is the project practical and in alignment with the
FDA’s IT policies and enterprise architecture plans? General information about IT governance and the Enterprise Architecture program is available from the Information
Technology webpage of Inside.FDA.
Update the CDER Informatics Action Plan Large Project requests that meet the assessment criteria, have been deemed a priority by the
Office Director, and have been reviewed and accepted by the CDER PMO will be added to the
CDER Informatics Action Plan.
The Informatics Action Plan is reviewed and approved by the Executive Committee. The CDER Executive
Committee serves as the Information Technology
Investment Review Board (ITIRB) and meets on a quarterly basis to resolve Center-wide priority or resource conflicts, as well as to review and approve the CDER
Informatics Action Plan. The Executive Committee has final approval over projects placed on the Informatics
Action Plan by the CDER PMO.
From Idea to Implementation: A Guide to the IT Approval Process | CDER Computational Science Center | 14
PMO Assigns Resources Once a project is added to the Informatics Action Plan, initial project planning will begin. Scope, cost, and resource estimates will be further refined, and timelines will be negotiated in Joint
Business Planning based on these estimates. Resource needs will vary depending on the nature of the project. The CDER PMO will work with the appropriate Offices to obtain the necessary project support. Projects are typically assigned a Business Project Manager (PM) from OBI and an IT PM from OIM as part of the project team. The Office of Planning and Informatics
(OPI)/OBI will request and obligate all necessary funds to support and implement projects added to the CDER Informatics Action Plan after approval by the CDER Executive Committee.
If resources are not immediately available to support the project, the project may be placed on the CDER Informatics Action Plan with resources marked as TBD (To Be Determined). Once resources for the project are available, an OBI Business PM will be assigned.
Begin EPLC/ITIM Process The ITIM process provides review and approval of IT requests for FDA. The EPLC process provides a standard structure for planning, managing, and overseeing IT projects over their entire life cycle. For more information, see the ITIM and EPLC sections in this document.
The Business PM, in coordination with the CITL, will submit the ITIM request at the appropriate time and work with the Client’s designee to complete the ITIM process.
EPLC requirements will be managed by either the OBI Business PM or the OIM PM— depending on the project—in coordination with the requesting Office.
ITIM Process
From Idea to Implementation: A Guide to the IT Approval Process | CDER Computational Science Center | 15
Who is Involved?
Requester – The individual or group designated to manage the approval process for the project
CITL– CDER Center IT Liaison; offers guidance and support while completing the ITIM request
ART Analyst – OIM Architecture Review Team Analyst; the ART Analyst works with the Requester to guide the project through the process
TAST – OIM Technology Architecture Support Team; supplies comments and a recommendation for each IT request
ART Chair – OIM Architecture Review Team Chair; confirms the impact of requests and determines the categorization and recommendation
SRB – OIM Strategic Review Board; gives final approval authority for ITIM requests
Resources:
IT Standards (ITIM) website More information on the ITIM process can be found here
FDA Master Approved Technologies (MAT) List Before submitting a request, check the MAT List for an existing or alternative solution. Items on the MAT list have already been approved through ITIM.
They can be requested with an ERIC ticket. More information is available at the link above.
IT INVESTMENT MANAGEMENT (ITIM)
The objective of the IT Investment Management
(ITIM) process is to standardize the review, evaluation, prioritization, funding, and implementation of information technology products and services across the FDA. Requests should be assessed by the CDER PMO (Program
Management Office) before initiating the ITIM process.
The ITIM process evaluates technology requests requiring Office of Information Management
(OIM) involvement. These requests can be for technologies that are scientific or non-scientific in nature, including Statements of Work and IT projects, as well as new software and software upgrades, hardware, new server infrastructure, and new scientific devices. ITIM ultimately grants approval for technologies to be used at the
FDA.
OIM is currently revising and streamlining their
IT approval processes to improve efficiency and integration. This guide will be revised in order to provide the most current information. Please check our site regularly for updates, and
Contact the CSC if you have suggestions for updates or improvements.
Depending on the project’s requirements, it may be supported by a number of individuals, including Project Managers
(PMs) and Analysts assigned during the
CDER PMO approval process, subject matter experts (SMEs), and additional project staff assigned by the requesting
Office. A member or members of this project team will act on behalf of the team to navigate the approval processes. This person or these persons are referred to here as the Requester.
http://inside.fda.gov/it/ITGovernance/ITStandards/default.htm http://apex.test.fda.gov/pls/apex/f?p=130:1:2131725691707702
From Idea to Implementation: A Guide to the IT Approval Process | CDER Computational Science Center | 16
Before submitting an ITIM request, the Requester should have a well-developed idea, including a detailed business need and well-defined goals and objectives. In addition, the Requester should work with their Center IT Liaison (CITL) to explore other options to meet the business need. This should include a review of the FDA Master Approved Technologies (MAT) List. The
MAT List contains approved technologies, including software applications, hardware infrastructure and peripherals, and scientific software and devices. If the technology is on the
MAT List, it may not require further ITIM approval.
For more information about the ITIM process, as well as how to request IT products on the
MAT List, visit the ITIM web site on Inside.FDA.
http://apex.test.fda.gov/pls/apex/f?p=130:1:2131725691707702
From Idea to Implementation: A Guide to the IT Approval Process | CDER Computational Science Center | 17
ITIM Figure 1 – The ITIM approval process
From Idea to Implementation: A Guide to the IT Approval Process | CDER Computational Science Center | 18
Instructions for Completing the IT Request Form:
1. Save the IT Request Form as a Word document to your desktop with the Name of your
Center and Product Name (e.g., CDER_ProductName).
2. Ensure there are no spaces in the document name.
3. Answer the questions on the form with as much detail as possible. Clearly state and explain the business need for the product.
4. Work with the vendor and/or IT specialist to answer specific software/hardware questions.
For an example of the necessary level of detail, consult the Sample IT Request Form available on the ITIM site.
Initial Preparation
Requester Submits IT Request Form To begin the ITIM approval process, the
Requester completes and submits an IT
Request Form (please see instructions below). The CITL can provide the
Requester assistance with the IT Request
Form.
Once the form is complete, the Requester submits the form via an ERIC ticket. See the call-out box on the next page for detailed instructions for completing the
ERIC ticket.
Once submitted, the IT Request Form first goes to the IT Call Center. The IT Call
Center will respond via email with a ticket number. (The Requester may also call
ERIC to obtain this number.) The IT Call
Center forwards the request to the CITL, who reviews the request and places it in the
ITIM queue.
ITIM Figure 2 – The process for preparing and submitting the IT Request http://inside.fda.gov:9003/downloads/it/ITGovernance/ITStandards/UCM113952.doc http://inside.fda.gov:9003/downloads/it/ITGovernance/ITStandards/UCM127095.doc
From Idea to Implementation: A Guide to the IT Approval Process | CDER Computational Science Center | 19
Instructions for Submitting the IT Request Form:
1. Sign on to the ERIC Request website and create an ERIC ticket
2. Title the ERIC ticket – Standards Approval for ‘Product Name’
3. Attach the IT Request Form to the ticket
4. Submit the ticket according to the instructions on the ERIC Request website
The weekly deadline for ITIM requests to be received in the ITIM queue is 4:00pm on Thursday.
The Requester should plan to submit the request in advance of the Thursday deadline to allow the CITL time to review and forward the request to the ITIM queue by this deadline. The
Requester may assist in this step by notifying the
CITL that the request has been submitted and providing the CITL with the ERIC ticket number.
Once submitted to the ITIM queue, requests take a minimum of two weeks to review. (Please see
ITIM Figure 3 – Timeline for straight-forward
ITIM requests.) Note that this timeline applies to requests that encounter few questions or issues during the approval process. More complicated requests may require more time. Requests can be tracked using the IT Request Tracker.
ITIM Figure 3 – Timeline for straight-forward ITIM requests http://fdswv03811:8080/sc/ess.do http://apex.test.fda.gov/pls/apex/f?p=900:1
From Idea to Implementation: A Guide to the IT Approval Process | CDER Computational Science Center | 20
Levels of Impact
Requests are categorized by level of impact:
Low Impact: No impact to the infrastructure (e.g., install desktop software)
Medium Impact: Incremental impact to the existing technology and infrastructure (small to medium projects)
High Impact: Significant impact to existing technology and infrastructure (large projects or new strategic investments)
ART Administrator Ensures Request is Complete and Assigns an ART
Analyst Once an IT Request is received, the Architecture
Review Team (ART) Administrator reviews the request and ensures that it is complete. The ART
Administrator then confirms the impact category of the request and assigns an ART
Analyst. Analysts are assigned based on the nature of the request (i.e., scientific vs. non-scientific, hardware vs. software, and center-developed vs. COTS products). The ART
Administrator notifies the Requester with the name of the assigned ART Analyst.
If the request is incomplete, the ART
Administrator will contact the Requester or the CITL for additional information.
ART Analyst Reviews Project Request and Gathers Information Once assigned, the ART Analyst will move the request through the approval process and work with the Requester to answer questions and concerns. The ART Analyst reviews the request and gathers necessary information from the Requester or from other sources, as needed.
ART Analyst Submits Request to TAST for Review The ART Analyst submits the request to the Technology Architecture Support Team (TAST) for review. The Requester should anticipate receiving questions from the TAST via the ART
Analyst.
From Idea to Implementation: A Guide to the IT Approval Process | CDER Computational Science Center | 21
The TAST is composed of OIM representatives from the following disciplines:
Infrastructure
Systems
Security
508 Compliance
Scientific Computing
Review and Recommendation
TAST Reviews the Request
The TAST reviews the request. Their review looks specifically at the following:
Security issues
Technology concerns
Implementation requirements for new technologies
Supportability of new technologies
If the TAST needs any questions answered as a part of their review, they will send the questions to the ART Analyst, who will work with the Requester to answer them. The ART Analyst returns the answers to the TAST.
TAST Votes to Approve
When the TAST is prepared to vote on a recommendation, the Requester is invited to attend the
TAST meeting. During the TAST meeting, the Requester is given the opportunity to address any questions previously received from the TAST (see above) as well as additional questions that may arise as a result of the discussion.
ITIM Figure 4 – The process for review and recommendation
From Idea to Implementation: A Guide to the IT Approval Process | CDER Computational Science Center | 22
The ART recommendations are based on the following:
Architecture
Redundancy
Mission
Risk
Lifecycle
Strategy
Following the Q&A, the TAST votes on their recommendation:
Pass: The TAST did not find any issues/concerns with the request; no other FDA standard technology meets the needs of the requester
Fail: The TAST found an issue/concern with the request; another approved FDA standard technology would better fit the needs of the requester
On-Hold: The TAST needs more information from the requester to clarify an issue/concern; more time is necessary to research the request
The ART and the Strategic Review Board (SRB) will use the TAST recommendation while considering final approval of the request.
ART Analyst Conducts Peer Review and Formulates Recommendation
Following the TAST voting, the ART Analyst conducts a peer review in coordination with other ART Analysts. Requests are analyzed to determine the most appropriate system impact categorization and approval recommendation.
Once the peer review is complete, the ART
Analyst formulates the recommendation for presentation to the ART.
ART Analyst Submits Recommendation to ART
The ART Analyst brings the request and the recommendation to the ART meeting for review and approval. The ART meets each Wednesday. The Requester and the CITL are invited to attend the meeting.
From Idea to Implementation: A Guide to the IT Approval Process | CDER Computational Science Center | 23
Depending on the level of impact of the request, different sets of documents are developed and reviewed by the ART Chair and SRB for approval.
Low Impact:
Evaluate business need, costs, and alternative solutions, and provide recommendations
(Qualified, Contain, Pilot, Not Recommend)
Medium Impact:
Develop Enterprise Information Management (EIM) Workbook (containing an evaluation of the request’s mission, EIM capabilities, gaps, and dependencies)
High Impact:
Develop an EIM Workbook and Business Case (providing the total projected costs and benefits of the investment)
ITIM Approval
ART Chair Recommends Approval, Denial, or Asks Questions
Once the ART recommendation is formulated, it is reviewed by the ART
Chair to assess business need, alternatives, value, cost, architectural impact, and required OIM support.
If there are no questions or concerns the ART Chair will approve the request, moving it forward for SRB approval. If there are questions or concerns not answered in the meeting, the ART Analyst will coordinate with the Requester to address them. Once questions and concerns are addressed, the request can be reviewed at the next meeting of the ART.
ITIM Figure 5 – The process for ART and SRB review and approval
From Idea to Implementation: A Guide to the IT Approval Process | CDER Computational Science Center | 24
The Strategic Review Board membership is composed of Senior Leadership to include the following individuals:
ART Chair
OIM Division Directors
Chief Information Officer (CIO)
Deputy CIO, as needed
SRB Approves, Denies or Asks Questions
The Strategic Review Board (SRB) reviews ITIM requests at their weekly meeting (each
Thursday). This is the final approval required.
The SRB could decide one of three ways on IT project requests. The options are as follows:
Approve: The IT project request is approved
Deny: The IT project request is denied
On-Hold: The SRB needs additional information from the ART
If the SRB does not have any questions or concerns, the request is approved. If there are unanswered questions or concerns, they will be brought to the Requester by the ART
Analyst. Once questions and concerns are answered, the request can be reviewed at the next meeting of the SRB. If a request is denied, the Requester will be notified.
ITIM Request is Approved
Approvals are sent out every Friday, following the SRB meeting. An email with the request’s ticket number and the project name will be sent to the Requester and the CITL. The email will also include any conditions associated with the approval. The Requestor should comply with all conditions outlined in the email.
ATO Process
From Idea to Implementation: A Guide to the IT Approval Process | CDER Computational Science Center | 25
Who is Involved?
Requester – The individual or group designated to manage the approval process for the project
PM – The Project Manager, responsible for managing the development and the operation and maintenance of the application
Business Owner – The Executive Sponsor for the project
System Owner – An IT manager responsible for the technical development of the project
ISSO– The OIM Information Systems Security Officer for CDER
Risk and Compliance Team – The OIM team responsible for independently assessing security controls
CISO – FDA’s Chief Information Security Officer; reviews and approves the Security Authorization Executive Summary (SAES)
CIO – FDA’s Chief Information Officer; serves as the ultimate approval authority
The ATO Process consists of three phases:
Preparation – the system is categorized;
security controls are selected, implemented, and assessed
Execution – the system is authorized
Continuous Monitoring – security controls are monitored on an ongoing basis
This document describes the Preparation and
Execution phases.
AUTHORITY TO OPERATE (ATO)
Information technology projects that store, process, or transmit FDA information, or are housed on an FDA server, ultimately must complete the FDA Security Authorization process in order to obtain the Authority to
Operate (ATO) within the FDA information technology environment. This process is referred to here as the ATO process.
The ATO process is facilitated by the Security
Branch in the Office of Information Management
(OIM), and fulfills requirements to ensure that information resources have adequate security to protect the confidentiality, integrity, and availability of information. Projects begin the
ATO process once they reach the appropriate phase of the Enterprise Performance Life Cycle
(EPLC). The ATO process is part of the EPLC process, and should be completed as a component of that larger process.
OIM is currently revising and streamlining their
IT approval processes to improve efficiency and integration. This guide will be revised in order to provide the most current information. Please check our site regularly for updates, and Contact the CSC if you have suggestions for updates or improvements.
Depending on the project’s requirements, it may be supported by a number of individuals, including Project Managers
(PMs) and Analysts assigned during the
CDER PMO approval process, subject matter experts (SMEs), and additional project staff assigned by the requesting Office. A member or members of this project team will act on behalf of the team to navigate the approval processes. This person or these persons are referred to here as the Requester.
From Idea to Implementation: A Guide to the IT Approval Process | CDER Computational Science Center | 26
Resources:
FDA Security Authorization Toolkit
FDA Risk and Compliance Homepage
Additional information and resources are available at the links above, including relevant
Federal guidelines and requirements.
The Security Team needs to know the project schedule and the desired date on which the application will go into production; however, the Requester should plan to be flexible in order to provide the required information and allow for the proper testing and review. The ATO process typically takes four to six months, and may run concurrently with other pre-production project activities.
Once ATO is granted, an annual security assessment will be required.
For more information about the Security Authorization process or ATO, consult the Security
Authorization Toolkit on Inside.FDA, or contact FDASecurityAuthorization@fda.hhs.gov.
http://inside.fda.gov:9003/it/ITSecurity/SecurityOverview/ucm226603.htm#rc_mainMenu http://inside.fda.gov:9003/it/ITSecurity/SecurityOverview/ucm220709.htm http://inside.fda.gov:9003/it/ITSecurity/SecurityOverview/ucm220709.htm http://inside.fda.gov:9003/it/ITSecurity/SecurityOverview/ucm226603.htm#rc_mainMenu mailto:FDASecurityAuthorization@fda.hhs.gov
From Idea to Implementation: A Guide to the IT Approval Process | CDER Computational Science Center | 27
ATO Figure 1 – The ATO process
From Idea to Implementation: A Guide to the IT Approval Process | CDER Computational Science Center | 28
Resources:
Templates are available online for the following Security documents:
Security Categorization Form (SCF) e-Authentication (e-Auth)
Initial Preparation
Requester Prepares Initial System Security Documents Projects will begin the ATO process once they reach the appropriate phases of the Enterprise
Performance Life Cycle (EPLC). When the project is ready to begin the ATO process, the
Requester contacts the CDER Information Systems Security Officer (ISSO), who will then provide the Requester with the initial security templates:
Security Categorization Form (SCF) e-Authentication (e-Auth)
Privacy Impact Assessment (PIA)
These initial documents are used to understand the data involved, the security risks associated with the data, how the data is stored and protected, and how it is transmitted. The SCF outlines the confidentiality, integrity, and availability of application data, and assigns a security categorization to each: Low, moderate, or high. The e-Auth determines if a system is available outside of FDA, if it requires user authentication, and if it contains confidential or proprietary information. The PIA determines if the system includes data that must be protected under the Privacy Act and what data requires this protection. The system is assessed to determine if it contains Personally Identifiable
Information (PII). The Privacy Office signs the PIA.
The Requester completes each of the forms and returns them to the ISSO.
ATO Figure 2 – The process for preparing and submitting security documents http://inside.fda.gov:9003/downloads/it/ITSecurity/SecurityOverview/ucm239988.xls http://inside.fda.gov:9003/downloads/it/ITSecurity/SecurityOverview/ucm239989.xls
From Idea to Implementation: A Guide to the IT Approval Process | CDER Computational Science Center | 29
Applications joining an existing ATO application group will follow the same ATO process;
however, the level of effort in each step is lessened due to the pre-existing security documents. Typically, the application group’s security documents are updated to reflect the addition of the new application. Updated documents are reviewed and signed.
Requester Reviews Initial Security Documents with the ISSO Once the forms are received and reviewed, the ISSO will contact the Requester to schedule a series of meetings. The ISSO uses these meetings with the Requester to discuss and clarify the information provided in the security documents.
ISSO Completes Risk Analysis Based on the SCF, e-Auth, and PIA, as well as the information from the series of meetings discussed above, the ISSO conducts the Risk Analysis. The Risk Analysis considers both security and business risks.
During the Risk Analysis, the ISSO determines if the SCF appropriately identifies the application information types and if the associated risk categorizations are correct. Security categorizations determine which security controls the application will need to incorporate.
Security controls are safeguards and countermeasures that the application will need to incorporate to protect itself and its data.
If the ISSO determines that the initial security documents do not adequately assess the risks, he will work with the Requester to revise the documents as necessary.
Can Application be Folded into an Existing Group?
Because many applications may have common characteristics and levels of impact, they may also have common security controls, and therefore they can share ATO as an application group, also known as an ATO application roll-up.
After completing the Risk Analysis, the ISSO determines if the application can be folded into an existing ATO application group. Applications with similar risk categorizations can receive an
ATO as a part of a group—for example; a new low-impact application would be grouped with other similar low-impact applications. Applications are also grouped by type of data (e.g., clinical data) and application functionality. In order to determine if a project can join an existing application group, the ISSO will need to understand the data used by the application and how that data is used, stored, processed, and transmitted.
Once an ATO application group is established, new applications may be added. When an application joins a group, it inherits the group’s original approval and authorization date, and follows the group’s maintenance and reauthorization schedule.
Applications within an ATO application group
From Idea to Implementation: A Guide to the IT Approval Process | CDER Computational Science Center | 30
Does the application require a System of
Records Notice (SORN)?
The Privacy Office will review the PIA and provide feedback to the ISSO. Ultimately, the
Privacy Office will determine if the application requires a SORN, and if it can be associated with an existing SORN. If a SORN is required, the Requester is not involved in the process.
share common security documents. When an application joins the group, the security documents are updated by the ISSO to include application-specific information, as required.
The application will be required to meet all security controls established for the existing application group.
ISSO Provides System Security Plan Template The ISSO provides the template for the System Security Plan (SSP); if the application will be joining an existing group, the ISSO provides the application group’s SSP. The SSP provides an overview of the security requirements for the application and describes the security controls in place or planned for meeting those requirements.
The risk categorizations established during the Risk Analysis will determine the security controls that are included in the SSP. Many security controls are inherited—meaning that they are addressed by FDA systems and do not need to be accounted for on the application level.
The inherited controls may vary depending on the server or data center where the application is hosted, as well as the application’s specific requirements. The SSP provided by the ISSO will only include security controls the Requester needs to address.
Requester and ISSO Complete Additional Security Documentation The Requester works with the ISSO to complete the Risk Assessment (RA) and Contingency
Plan (CP), as well as the SSP.
The RA evaluates the SSP and assesses the risk to agency operations (including mission, functions, image, or reputation), agency assets, or individuals by determining the probability of occurrence, the resulting impact, and additional security controls that would mitigate the impact. The CP provides a detailed description of the contingency activities for the application in the event of loss, degraded operation, or security breech.
In addition to specific information about how security controls are addressed, the SSP requires a general description of the…
This is the start of the file's text. The full file is on GovTribe.
File details come from the government source that posted it. Updated .