12.11.2014 Views

(NASIS) Requirements Definition Document - Bureau of Indian ...

(NASIS) Requirements Definition Document - Bureau of Indian ...

(NASIS) Requirements Definition Document - Bureau of Indian ...

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

<strong>NASIS</strong> <strong>Requirements</strong> <strong>Definition</strong> <strong>Document</strong> (RDD)<br />

Version 1.0<br />

17 February 2006<br />

• <strong>NASIS</strong> will undergo the DOI OMB Circular A-130, Appendix 3 certification and accreditation<br />

process.<br />

• <strong>NASIS</strong> will be subject to the annual security review required by OMB Circular A-130, Appendix<br />

3. (http://www.whitehouse.gov/omb/circulars/a130/a130trans4.html)<br />

• <strong>NASIS</strong> will comply with the requirements <strong>of</strong> the Privacy Act and the Family Educational Rights<br />

Privacy Act (FERPA)<br />

• <strong>NASIS</strong> will comply with the requirements <strong>of</strong> the Health Insurance Portability and Accountability<br />

Act (HIPAA).<br />

• <strong>NASIS</strong> will provide security controls as described in National Institute <strong>of</strong> Standards and<br />

Technology (NIST) Standards Publication (SP) 800-26, Security Self-Assessment Guide for<br />

Information Technology Systems.<br />

• A contingency plan will exist, be updated annually, and be tested annually.<br />

2.4.2 Identification and Authentication<br />

Use <strong>of</strong> the system will be controlled through a log-on process requiring a user ID and a password. The<br />

password parameters will be configurable, including length <strong>of</strong> password, use <strong>of</strong> alphabetic and numeric<br />

characters, password re-use, password expiration, and account lockout due to failed log-on attempts.<br />

<strong>NASIS</strong> will have a user-administered password reset capability.<br />

Parental access to student data over the Web may use a simplified access capability if the student<br />

identifying information is limited to a student ID number.<br />

2.4.3 Audit Trail<br />

The system will have the ability log events and transactions. Logging parameters will be customizable.<br />

If <strong>NASIS</strong> is delivered by ASP, then BIA will have online access to audit facilities or be provided audit<br />

log reports on a daily basis. The system shall record logon failures and successes.<br />

2.4.4 Alerts<br />

The system will generate alerts for selected significant events.<br />

2.4.5 Network Perimeter Security<br />

If <strong>NASIS</strong> is in an OIEP facility, the government will provide network perimeter security. If in an ASP<br />

facility, the vendor will provide network perimeter security.<br />

2.4.6 ASP Security<br />

If <strong>NASIS</strong> is delivered via an ASP, the system and the supporting infrastructure will be subjected to<br />

periodic tests by the government. The vendor will be required to provide certifications or test data<br />

demonstrating its compliance with applicable Federal and State statutes.<br />

12

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!