5 FAM 630 DATA MANAGEMENT POLICY
|
|
|
- Kelley Cox
- 10 years ago
- Views:
Transcription
1 5 FAM 630 DATA MANAGEMENT POLICY (Office of Origin: IRM/BMP/OCA/GPC) 5 FAM 631 GENERAL POLICIES a. Data management incorporates the full spectrum of activities involved in handling data, including its policy, administration, collection, capture, retention, and use. b. This section provides the general policies of managing data across the Department and key areas where Information Resource Management (IRM) provides support. The general policy is based on the principle that the Department of State considers data to be an asset. c. All systems and business owners while managing data must consider cost, ownership, stewardship, privacy and security, risk management, storage, and security. d. Business owners should also consider how data relates to existing laws and regulations and how to maximize information sharing across the Department, Federal Government, and if applicable, the public. 5 FAM Definitions a. A data steward is one who oversees and maintains consistent reference data and master data definitions, publishes relevant interpretation and proper usage of the data, and ensures the quality of the content and metadata. b. A data architect is one who establishes the data architecture, defines the taxonomy and naming conventions to be used, and supports the alignment of the data models to the business needs for the IT system or investment. c. A data administrator is one who manages access, security, and integrity of the database and monitors the performance of the database system to maintain any established service level agreements. d. A data analyst is one who understands, applies a variety of techniques, and analyzes the data to align, interpret, and communicate the data to support effective decision-making. 5 Fam 630 Page 1 of 12
2 5 FAM 632 SCOPE This policy applies to all programs and projects in the Department that collect and store unclassified data. 5 FAM 633 AUTHORITIES The authorities establishing this policy include: (1) Clinger-Cohen Act Public Law , Section 5125 (40 U.S.C ); (2) OMB Circular A-130, Management of Federal Information Resources, November 30, 2002; (3) Data Quality OMB, "Guidelines for Ensuring and Maximizing the Quality, Objectivity, Utility and Integrity of Information Disseminated by Federal Agencies," issued pursuant to the Treasury and General Government Appropriations Act for Fiscal Year 2001, Public Law , Section 515; (4) Government Performance and Results Act (GPRA), Public Law, ; (5) Government Paperwork Elimination Act (GPEA), Public Law, , Title XVII (44 U.S.C note); (6) E-Government Act of 2002, Title II; (7) OMB Memorandum M-13-13, Open Data Policy Managing Information as an Asset, May 9, 2013; (8) Executive Order, Making Open and Machine-Readable the New Default for Government Information, May 9, 2013; and (9) Application and Data Coordination Working Group Charter, May 18, FAM 634 ROLES AND RESPONSIBILITIES a. On behalf of the Under Secretary for Management, the Office of Management Policy, Rightsizing, and Innovation (M/PRI) and IRM provide strategic direction for the Department's Data Management policies, processes, and procedures. b. The Application and Data Coordination Working Group (ADCWG) provides an executive-level body that assists in providing strategic direction in managing data and in promoting the value of data to the Department so that it is managed accordingly. The mission of the ADCWG is to facilitate data standardization across the Department by engaging both the key stakeholders who maintain enterprise data as well as the users to ensure data standards 5 Fam 630 Page 2 of 12
3 meet all stakeholders' business needs. Composed of authoritative personnel who serve as the governing body for determining data standards, the ADCWG approves master reference data sets and provides subject matter expertise for associated definitions, taxonomies, and business rules. The ADCWG is trichaired and sponsored by the Chief Information Officer (IRM), the Chief Financial Officer (CGFS), and the Director of M/PRI. c. The Office of the Chief Architect (IRM/BMP/OCA) provides support in formulating and maintaining the Data Management policy and an enterprise view of information, how it can be shared, accessed, and managed consistently across the Department. OCA supports the IT Investment process in evaluating and assessing the adherence and compliance of systems to the Data Management policy. d. The Systems Integration Office (IRM/OPS/SIO) supports the implementation of the Data Management policy by managing and maintaining the Master Reference Data (MRD), Enterprise Metadata Repository (EMR) and the Enterprise Service Bus (ESB). SIO supports the Data Standardization Process in identifying, analyzing, implementing, and maintaining the master reference data sets that are to be used as standards across the Department. e. The Strategic Planning Office (IRM/BMP/SPO) supports the adherence and compliance of the Data Management policy by managing and maintaining the Department s portfolio management system (imatrix) as a part of the IT Capital Planning and Investment Control (CPIC) process. SPO supports the long-range planning, budget and acquisition process to facilitate decision making regarding the best use of available funds to achieve strategic business goals and objectives. f. Bureau Executive Directors provide leadership to ensure their data is managed as an asset and ensure IT projects conform to data management policy. g. Business Owners are accountable for the definition, assignment, and restricting access to data. Business Owners plan for and ensure implementation of data management policies and standards. h. System owners are accountable for all control, management, and support aspects of the information system that stores and manages the data. System Owners prepare and maintain updated implementation plans, which outline how the system will incorporate standardized data sets. These implementation plans must be submitted annually to the ADCWG chairs. i. Data stewards are responsible for resolving data quality issues (content and metadata) in accordance with ADCWG standards and making decisions related to specific data sets and/or information integrity, security, delivery, and access within the assigned business area. For master reference data, Data Stewards are identified and designated by the ADCWG. j. Data architects are responsible for reviewing the business need, developing strategy, processes, and models to ensure the data model leverages existing 5 Fam 630 Page 3 of 12
4 data as applicable. k. Data administrators are responsible for ensuring the database is running efficiently and securely. They monitor the operations of the database in line with the system. l. Data analysts collect, analyze, and interpret data in support of business needs. Data Analysts also support the Data Steward and Data Administrator in identifying quality issues and supporting decisions about data sets related to information integrity, security, delivery, and access. 5 FAM 635 MANAGEMENT OF DATA LIFECYCLE a. Create or acquire: During this phase, all data stakeholders must make sure that all the conceptual details and requirements are addressed whether the data is being created or acquired from other sources. b. Store and maintain: During this phase, the data must be stored using best practices that cover areas such as data integrity and data quality. There needs to be a mechanism in place to perform quality assurance and quality control to ensure data quality. c. Use and share: During this phase, data is shared with the appropriate audiences through secure channels. System owners must consider leveraging technology to interface with other systems so that sharing of data can be automated; where appropriate, authoritative data sources must be used. d. Archive or Dispose: During this phase, data must either be archived or disposed in accordance with policies or guidelines associated with the type of data. System owners must document their standard practices for data storage, archival, or backup. 5 FAM 636 DATA MANAGEMENT COMPONENTS The Data Management policy provides a framework supporting system and business owners for the purpose of improving the accuracy and integrity of data being used. The five components of the data management policy are: (1) Data Governance: Provides strategic oversight and controls to ensure policy and principles are upheld. This component is led by the ADCWG; (2) Information Architecture: Provides an enterprise view of information, business entities, relationships, attributes, definitions and reference values as guidance to share, access, and manage data consistently across the Department. This component is led by IRM/BMP/OCA; 5 Fam 630 Page 4 of 12
5 (3) Implementation: Leverages existing investments (e.g., Master Reference Data) to support operations and maintenance of sound policies, processes, and practices. Provides best practices and standards to manage data as an asset. All business and system owners participate in this component in coordination with IRM/OPS/SIO and IRM/BMP; (4) Information Security Management: Provides the processes and methodologies to protect data. When new technology and infrastructure are introduced, supports the Department by bringing together the processes, tools, and discipline on how information can be accessed, delivered, and protected. All business and system owners participate in this component in coordination with IRM/IA and DS; and (5) Collaboration: Provides tools and processes to enable better collaboration, management of data to facilitate data sharing and compliance with all regulations and policies. 5 FAM 637 DATA MANAGEMENT PRINCIPLES The Data Management policy is guided by the following key principles. These principles provide a foundation to: (1) Build a consensus amongst data stakeholders across the Department (2) Ensure consistency in data management across bureaus and system owners; and (3) Implement and monitor compliance to the policy. 5 FAM Managing Data a. Data is an asset of the Department and must be managed accordingly. It is an invaluable resource for the Department to inform decisions. b. Data must be carefully managed to ensure that the source is credible. c. All data assets must be registered in the Department s portfolio management system (imatrix). d. Roles and responsibilities for those associated with the data must be clearly defined. 5 FAM Data Quality a. The accuracy of data that is used and shared must be verified and validated. 5 Fam 630 Page 5 of 12
6 b. Data quality procedures should be followed throughout the lifecycle. Data users must be able to clearly identify the data quality procedures (e.g. quality assurance, quality control, etc.) that have been followed. 5 FAM Securing Data a. Data residing in any systems (data at rest) or being transmitted (data in motion) must be secured according to the required level of classification. b. Data must be protected from unauthorized use and disclosure. c. Security needs must be identified and managed at the data and information flow level. d. An ongoing and evolving data security approach of tested layered controls must be used for reducing risks to data. 5 FAM Sharing Data a. Data is made available to users as needed to perform their functions. b. Data must be classified and discoverable by users. c. Levels of access to the underlying data must be determined by security principles. d. Common data access policies and guidelines must be adopted and enforced to keep the data current and secure. e. Clear statements of criteria for data access and, when applicable, information on any limitations must be applied to data to enable control of full access that could affect its use. f. Data being shared or published must be consistent with relevant policies, guidelines, and/or initiatives as specified by the Data Policy Framework Working Group s Information Memo dated March FAM Authoritative Data Source a. Authoritative data sources must be registered in the Department's portfolio management system (imatrix), and the associated data sets must be registered in the Enterprise Data Inventory. Generally, authoritative data sources should also be the primary source system, with an appropriate records disposition schedule, for the data, except where the authoritative data source is a combination of disparate sources. 5 Fam 630 Page 6 of 12
7 b. An authoritative data source has to be identified for any data that is being shared. c. An authoritative data set is a data asset recognized by the ADCWG as the official data for use by the Department. The Master Reference Data platform is the authoritative data source for standardized data. d. Published data that is available and useable to users must be clearly documented with consistent delivery procedures. 5 FAM Common Taxonomy a. Data must be defined consistently throughout the Department. b. Taxonomy is the science of classification, wherein objects are structured in relation to one another. It is a conceptual framework for organizing information within a defined scope and context. Taxonomy is also a component of Information Architecture. c. Taxonomies can be applied to any electronic resource system to improve information access. Taxonomies structure information and are integral to effective data management. d. Terms in common taxonomies should be defined in a way that is unambiguous, in order to be understandable and available to all stakeholders. e. Applications or systems using common data sets must use a common vocabulary to facilitate communication. 5 FAM 638 DATA MANAGEMENT PRACTICES The following Data Management practices must be followed by all business and system owners: (1) Business owners at all levels (executive directors, program managers, project managers, etc.) must plan for and enforce data management policies and standards; (2) Information resource (data) project managers must refer to the Department s Information Architecture Blueprint that contains conventions, reference models, practices, and guidelines to ensure architectural alignment; (3) System owners must apply effective Data Quality Management procedures that include quality assurance and quality control processes at all stages of the data lifecycle; (4) System owners must leverage standardized data sets identified in the 5 Fam 630 Page 7 of 12
8 Master Reference Data that have been approved by the ADCWG. Bureaus must prepare and maintain updated implementation plans, which outline how the bureau s systems will incorporate standardized data sets. These implementation plans should be submitted annually to the ADCWG chairs; (5) All system owners must have a mechanism to produce metadata of their key data sets using Metadata Management. The metadata of the data sets being shared must be provided to the Enterprise Metadata Repository; and (6) To ensure effective and secure use of data throughout the lifecycle, some of the key documentation must include: o Data/Information flows o Logical Data Model o Database specifications o Data storage, backup, and recovery methods o Archival or disposition plan 5 FAM 639 IMPLEMENTING DATA MANAGEMENT 5 FAM Enterprise Data Inventory a. imatrix maintains the inventory of the Department's data assets as a part of the Enterprise Data Inventory (EDI). b. System or business owners must register their data assets in imatrix and update the entries on a regular basis. c. The EDI contains data elements as required by OMB and other additional data elements so that valuable insights into the data assets can be obtained. d. The authoritative data sources for the data assets must be identified and entered in imatrix. e. The data assets must be categorized in accordance with the Information Reference Model specified in the Information Architecture Blueprint. 5 FAM Master Reference Data a. Master Reference Data (MRD) is a set of stable reference data sets sharable by all business teams and applications across the Department. b. Incorporating Master Reference Data into all Department systems where applicable improves the accuracy and integrity of data being used, while also 5 Fam 630 Page 8 of 12
9 facilitating information exchange and cross-system reporting. c. The MRD application is the central source for the Department s authoritative data sets approved by the ADCWG. d. The MRD application improves the accuracy, consistency, and timeliness of reference data, while reducing maintenance requirements. e. Master Reference Data is available to application developers in various formats, including as a web service. f. Master Reference Data is maintained by the data steward established and appointed during the data standardization process chartered by the ADCWG. g. System and business owners must incorporate or have a plan of incorporating the Master Reference Data into their system and process where the data is applicable. Adherence to this policy will be evaluated as a part of the CPIC process. h. The owners of information resource programs and projects must apply data sharing and use of Master Reference Data (MRD), as approved by the ADCWG, as explicit business requirements for all Department systems and must integrate these data management principles into the data lifecycle. 5 FAM Security Guidelines and Checklists a. IT access controls must be implemented pursuant to 12 FAM 652 and 12 FAM 653; b. IT security awareness and training must be implemented pursuant to 5 FAM 845 and 12 FAM 632; c. IT auditing and accountability must be implemented pursuant to 12 FAH-10 and 12 FAM 623; d. IT security and authorization assessments must be conducted pursuant to 1 FAM 262, 12 FAH-10, 5 FAH-6, 5 FAH-11, and 12 FAM 629; e. IT configuration management must be implemented pursuant to 5 FAM 650; f. IT contingency planning must be implemented pursuant to 5 FAM 1060 and 12 FAM 622; g. User and system identification and authentication measures must be implemented pursuant to 12 FAM 623, 12 FAM 632, 12 FAM 653, and 12 FAH- 10; h. Computer security incident response must be implemented pursuant to 12 FAM 590, 12 FAM 622, 12 FAM 680 and 1 FAM 262; i. IT system maintenance must be implemented pursuant to 5 FAH-5, 5 FAH-11, and 12 FAH-10; 5 Fam 630 Page 9 of 12
10 j. Document and media protection must be implemented pursuant to 5 FAH-11, 7 FAH-2, 12 FAM 620, and 12 FAM 630; k. Physical and environmental protection must be implemented pursuant to 12 FAH-5, 12 FAM 390, 12 FAM 530, and 12 FAM 575; l. Security planning must be conducted pursuant to 12 FAH-5, 12 FAH-10 and 11; m. Information security program plans must be developed and disseminated pursuant to 12 FAM 500, and 5 FAH-11; n. Personnel security must be implemented pursuant to 5 FAM 100, 5 FAM 900, 5 FAH-11 and 12 FAH-10; o. IT risk assessments must be conducted pursuant to 5 FAH-5, and 5 FAH-11; p. System and service acquisition must be managed pursuant to 5 FAH-5 and 5 FAH-11; q. Systems and communication protections must be implemented pursuant to 5 FAH-11 and 12 FAH-10; and r. System and information integrity must be maintained pursuant to 12 FAM 600 and 12 FAH FAM Enterprise Metadata Repository a. Metadata is the definition or description of data. In data processing, metadata provides information about, or documentation of, other data managed within an application or environment. For example, metadata would include name, size, data type, and definition for a data element or attribute, as well as data about records or data structures (length, fields, columns, etc.) and information about data (e.g., where it is located, how it is associated, who owns it, what other data it may be related to, etc.). b. The Enterprise Metadata Repository (EMR) contains enterprise metadata elements from various sources in a centralized system. c. IRM/OPS/SIO provides user access and accounts and administers the application, as follows: (1) Provides data to both technical and business users; (2) Provides repeatable data transformation processes; (3) Supports data standardization; (4) Provides data traceability across systems; and (5) Provides a capability to produce impact analysis for changes to Department systems. d. IT project managers must provide metadata to the EMR based on the 5 Fam 630 Page 10 of 12
11 requirements previously stated in 5 FAM 638(e). 5 FAM Authoritative Data Sets a. All authoritative data sets must be identified as a part of the Enterprise Data Inventory. b. A comprehensive list of reference data sets and their authoritative data sources can be found in the Master Reference Data tables. c. Uses of authoritative data sets require all naming, classification, and standardization conventions to be in compliance with the determination made by the ADCWG. d. The data must be maintained and updated by the appropriate data steward, to be selected by the ADCWG. e. Data consumers and/or application owners must request changes to data sets through the ADCWG change request (CR) process. f. Manipulating data 'downstream' for alternative functions is permissible (such as appending data points that require a security classification), provided the MRD is still the source of the data and the manipulated data is not exchanged across bureaus. g. The core attributes identified with each data set must be stored in each system that is required to use the reference data sets from the MRD. Storing the core attributes ensures that common elements are stored in each system to facilitate data exchange and to make downstream aggregation of data possible. h. Data up to the SBU-level should be exchanged with the MRD through IRM s SBU Enterprise Service Bus (ESB). Any exceptions should be documented in the Capital Planning and Investment Control process. 5 FAM Naming Conventions a. Department systems must adhere to object naming conventions as governed by the ADCWG and be compatible with the Federal Information Processing Standards (FIPS) 156 Information Resource Dictionary System (IRDS) standard and the National Institute of Standards and Technology (NIST) data design guidelines. b. Object definition and naming conventions are critical in facilitating object sharing and consistency across the Department s organizations. c. The Department s naming conventions describe how objects should be defined, including what metadata should be documented. In addition, naming conventions are defined to: 5 Fam 630 Page 11 of 12
12 (1) Facilitate object sharing, object consistency, and communication among the Department s organizations; (2) Increase reliability of information stored, shared, and managed by the repository tool set; (3) Promote accessibility and understandability of information across systems; (4) Improve the quality of data and application documentation; (5) Eliminate data redundancy and inconsistency; (6) Facilitate user access to object names and related documentation as used throughout the Department. (7) Assist analysts in selecting names that are clear and represent rules of good grammar; and (8) Simplify recognition of synonyms. 5 Fam 630 Page 12 of 12
UNITED STATES DEPARTMENT OF THE INTERIOR BUREAU OF LAND MANAGEMENT MANUAL TRANSMITTAL SHEET. 1283 Data Administration and Management (Public)
Form 1221-2 (June 1969) Subject UNITED STATES DEPARTMENT OF THE INTERIOR BUREAU OF LAND MANAGEMENT MANUAL TRANSMITTAL SHEET 1283 Data Administration and Management (Public) Release 1-1742 Date 7/10/2012
5 FAM 620 INFORMATION TECHNOLOGY (IT) PROJECT MANAGEMENT
5 FAM 620 INFORMATION TECHNOLOGY (IT) PROJECT MANAGEMENT 5 FAM 621 GENERAL (Office of Origin: IRM/BMP/SPO/PMD) a. The strategic importance of Information Technology (IT) to the mission of the State Department
5 FAH-11 H-500 PERFORMANCE MEASURES FOR INFORMATION ASSURANCE
5 FAH-11 H-500 PERFORMANCE MEASURES FOR INFORMATION ASSURANCE 5 FAH-11 H-510 GENERAL (Office of Origin: IRM/IA) 5 FAH-11 H-511 INTRODUCTION 5 FAH-11 H-511.1 Purpose a. This subchapter implements the policy
City of Minneapolis Policy for Enterprise Information Management
City of Minneapolis Policy for Enterprise Information Management Origin: Developed by the City Clerk s Office and Business Information Services. Based on requirements set forth in Federal and State regulations
US Department of Education Federal Student Aid Integration Leadership Support Contractor June 1, 2007
US Department of Education Federal Student Aid Integration Leadership Support Contractor June 1, 2007 Draft Enterprise Data Management Data Policies Final i Executive Summary This document defines data
Guidelines for Best Practices in Data Management Roles and Responsibilities
Guidelines for Best Practices in Data Management Roles and Responsibilities September 2010 Data Architecture Advisory Committee A subcommittee of Information Architecture & Standards Branch Table of Contents
5 FAH-8 H-351 CLOUD COMPUTING
5 FAH-8 H-350 CLOUD COMPUTING (Office of Origin: IRM/BMP) 5 FAH-8 H-351 CLOUD COMPUTING GOVERNANCE BOARD a. The Cloud Computing Governance Board (CCGB) exists to provide advice to the Authorizing Official
UNITED STATES DEPARTMENT OF THE INTERIOR BUREAU OF LAND MANAGEMENT MANUAL TRANSMITTAL SHEET
Form 1221-2 (June 1969) UNITED STATES DEPARTMENT OF THE INTERIOR BUREAU OF LAND MANAGEMENT Release: 1-1718 Date: MANUAL TRANSMITTAL SHEET Subject 1265 Information Technology Investment Management (ITIM)
Rowan University Data Governance Policy
Rowan University Data Governance Policy Effective: January 2014 Table of Contents 1. Introduction... 3 2. Regulations, Statutes, and Policies... 4 3. Policy Scope... 4 4. Governance Roles... 6 4.1. Data
Audit of the Department of State Information Security Program
UNITED STATES DEPARTMENT OF STATE AND THE BROADCASTING BOARD OF GOVERNORS OFFICE OF INSPECTOR GENERAL AUD-IT-15-17 Office of Audits October 2014 Audit of the Department of State Information Security Program
U.S. Department of Education. Office of the Chief Information Officer
U.S. Department of Education Office of the Chief Information Officer Investment Review Board (IRB) CHARTER January 23, 2013 I. ESTABLISHMENT The Investment Review Board (IRB) is the highest level IT investment
Institutional Data Governance Policy
Institutional Data Governance Policy Policy Statement Institutional Data is a strategic asset of the University. As such, it is important that it be managed according to sound data governance procedures.
A. Title 5, United States Code (U.S.C.), Section 552a, Records Maintained On Individuals (The Privacy Act of 1974)
Department of Homeland Security DHS Directives System Directive Number: 103-01 Revision Number: 01 Issue Date: 8/25/2014 ENTERPRISE DATA MANAGEMENT POLICY I. Purpose This Directive establishes the Department
United States Department of Health & Human Services Enterprise Architecture Program Management Office. HHS Enterprise Architecture Governance Plan
United States Department of Health & Human Services Enterprise Architecture Program Management Office HHS Enterprise Architecture Governance Plan Version 3.0 February 2007 Approvals The Health and Human
DIRECTIVE TRANSMITTAL
U.S. NUCLEAR REGULATORY COMMISSION DIRECTIVE TRANSMITTAL TN: DT-07-08 To: Subject: Purpose: Office and Division of Origin: NRC Management Directives Custodians Transmittal of Management Directive 2.8,
IT SECURITY EDUCATION AWARENESS TRAINING POLICY OCIO-6009-09 TABLE OF CONTENTS
OFFICE OF THE CHIEF INFORMATION OFFICER Date of Issuance: May 22, 2009 Effective Date: May 22, 2009 Review Date: Section I. PURPOSE II. AUTHORITY III. SCOPE IV. DEFINITIONS V. POLICY VI. RESPONSIBILITIES
5 FAM 670 INFORMATION TECHNOLOGY (IT) PERFORMANCE MEASURES FOR PROJECT MANAGEMENT
5 FAM 670 INFORMATION TECHNOLOGY (IT) PERFORMANCE MEASURES FOR PROJECT MANAGEMENT (CT:IM-92; 08-01-2007) (Office of Origin: IRM/BPC/PRG) 5 FAM 671 WHAT ARE IT PERFORMANCE MEASURES AND WHY ARE THEY REQUIRED?
U.S. Department of Energy Washington, D.C.
U.S. Department of Energy Washington, D.C. ORDER DOE O 200.1A Approved: SUBJECT: INFORMATION TECHNOLOGY MANAGEMENT 1. OBJECTIVES. The Department of Energy s (DOE) overarching mission, to advance the national,
AUDIT REPORT. The Energy Information Administration s Information Technology Program
U.S. Department of Energy Office of Inspector General Office of Audits and Inspections AUDIT REPORT The Energy Information Administration s Information Technology Program DOE-OIG-16-04 November 2015 Department
EPA Classification No.: CIO 2123.0-P-01.1 CIO Approval Date: 06/10/2013 CIO Transmittal No.: 13-003 Review Date: 06/10/2016
Issued by the EPA Chief Information Officer, Pursuant to Delegation 1-84, dated June 7, 2005 CONFIGURATION MANAGEMENT PROCEDURE 1 PURPOSE The purpose of this procedure is to describe the process EPA Program
COMDTINST 5200.7 11 JUL 2013 COAST GUARD C4I DATA MANAGEMENT (DM) POLICY
Commandant 2100 2 nd St SW Stop 7101 United States Coast Guard Washington, DC 20593-7101 Staff Symbol: CG-6 Phone: (202) 475-3469 Fax: (202)475-3930 Email: [email protected] COMMANDANT INSTRUCTION 5200.7 COMDTINST
PREFACE TO SELECTED INFORMATION DIRECTIVES CHIEF INFORMATION OFFICER MEMORANDUM
PREFACE TO SELECTED INFORMATION DIRECTIVES CIO Transmittal No.: 15-010 CIO Approval Date: 06/12/2015 Issued by the EPA Chief Information Officer, Pursuant to Delegation 1-19, dated 07/07/2005 CHIEF INFORMATION
Data Governance Policy. Version 2.0 19 October 2015
Version 2.0 19 October 2015 Document Title: Summary: Date of Issue: Status: Contact Officer: Applies To: References: This policy provides the Cancer Institute NSW with an instrument to formally manage
Interagency Science Working Group. National Archives and Records Administration
Interagency Science Working Group 1 National Archives and Records Administration Establishing Trustworthy Digital Repositories: A Discussion Guide Based on the ISO Open Archival Information System (OAIS)
Management and Use of Information & Information Technology (I&IT) Directive. Management Board of Cabinet
Management and Use of Information & Information Technology (I&IT) Directive Management Board of Cabinet February 28, 2014 TABLE OF CONTENTS PURPOSE... 1 APPLICATION AND SCOPE... 1 PRINCIPLES... 1 ENABLE
Data Governance Policy. Staff Only Students Only Staff and Students. Vice-Chancellor
Name of Policy Description of Policy Policy applies to Data Governance Policy To establish proper standards to assure the quality and integrity of University data. This policy also defines the roles and
DATA STANDARDS POLICY
EPA Classification No: CIO 2133.0 (formerly 2128.0) CIO Approval Date: 06/28/07 Issued by the EPA Chief Information Officer, Pursuant to Delegation 1-19, dated 07/07/2005 DATA STANDARDS POLICY 1. PURPOSE
National Geospatial Data Policy Procedure for Geospatial Metadata Management
Issued by the EPA Chief Information Officer, Pursuant to Delegation 1-19, dated 07/07/2005 National Geospatial Data Policy Procedure for Geospatial Metadata Management 1. PURPOSE The purpose of the Procedure
U.S. Department of Education Federal Student Aid
U.S. Department of Education Federal Student Aid Lifecycle Management Methodology Stage Gate Review Process Description Version 1.3 06/30/2015 Final DOCUMENT NUMBER: FSA_TOQA_PROC_STGRW.NA_001 Lifecycle
Corporate Property Automated Information System CPAIS. Privacy Impact Assessment
Corporate Property Automated Information System CPAIS Privacy Impact Assessment May 2003 CONTENTS Background...3 Access to the Data...5 Maintenance of Administrative Controls...9 1 Introduction The Office
Part A OVERVIEW...1. 1. Introduction...1. 2. Applicability...2. 3. Legal Provision...2. Part B SOUND DATA MANAGEMENT AND MIS PRACTICES...
Part A OVERVIEW...1 1. Introduction...1 2. Applicability...2 3. Legal Provision...2 Part B SOUND DATA MANAGEMENT AND MIS PRACTICES...3 4. Guiding Principles...3 Part C IMPLEMENTATION...13 5. Implementation
US Department of Education Federal Student Aid Integration Leadership Support Contractor January 25, 2007
US Department of Education Federal Student Aid Integration Leadership Support Contractor January 25, 2007 Task 18 - Enterprise Data Management 18.002 Enterprise Data Management Concept of Operations i
CIOP CHAPTER 1351.40 Common Operating Environment (COE) Services Management Policy TABLE OF CONTENTS. Section 40.1. Purpose
CIOP CHAPTER 1351.40 Common Operating Environment (COE) Services Management Policy TABLE OF CONTENTS Section 40.1. Purpose... 1 Section 40.2. Background... 2 Section 40.3. Scope and Applicability... 3
FSIS DIRECTIVE 1306.3
UNITED STATES DEPARTMENT OF AGRICULTURE FOOD SAFETY AND INSPECTION SERVICE WASHINGTON, DC FSIS DIRECTIVE 1306.3 REVISION 1 12/13/12 CONFIGURATION MANAGEMENT (CM) OF SECURITY CONTROLS FOR INFORMATION SYSTEMS
University of Michigan Medical School Data Governance Council Charter
University of Michigan Medical School Data Governance Council Charter 1 Table of Contents 1.0 SIGNATURE PAGE 2.0 REVISION HISTORY 3.0 PURPOSE OF DOCUMENT 4.0 DATA GOVERNANCE PROGRAM FOUNDATIONAL ELEMENTS
2.0 ROLES AND RESPONSIBILITIES
2.0 ROLES AND RESPONSIBILITIES This handout describes applicable roles and responsibilities for the Capital Planning and Investment Process (CPIC) as presented in the NIST Integrating IT Security into
THE STATUS OF ENTERPRISE ARCHITECTURE AND INFORMATION TECHNOLOGY INVESTMENT MANAGEMENT IN THE DEPARTMENT OF JUSTICE
THE STATUS OF ENTERPRISE ARCHITECTURE AND INFORMATION TECHNOLOGY INVESTMENT MANAGEMENT IN THE DEPARTMENT OF JUSTICE U.S. Department of Justice Office of the Inspector General Audit Division Audit Report
TREASURY INSPECTOR GENERAL FOR TAX ADMINISTRATION
TREASURY INSPECTOR GENERAL FOR TAX ADMINISTRATION The Customer Account Data Engine 2 Systems Development Guidelines; However, Process Improvements Are Needed to Address Inconsistencies September 30, Year
UNCLASSIFIED (U) U.S. Department of State Foreign Affairs Manual Volume 5 Information Management 5 FAM 870 NETWORKS
5 FAM 870 NETWORKS (Office of Origin: IRM/BMP/GRP/GP) 5 FAM 871 ENTERPRISE NETWORKS (CT:IM-138; 01-18-2013) The Department currently has two enterprise networks: ClassNet and OpenNet. Only Department-issued
U.S. Department of the Treasury. Treasury IT Performance Measures Guide
U.S. Department of the Treasury Treasury IT Performance Measures Guide Office of the Chief Information Officer (OCIO) Enterprise Architecture Program June 2007 Revision History June 13, 2007 (Version 1.1)
Information Security Program Management Standard
State of California California Information Security Office Information Security Program Management Standard SIMM 5305-A September 2013 REVISION HISTORY REVISION DATE OF RELEASE OWNER SUMMARY OF CHANGES
CMS Policy for Information Technology (IT) Investment Management & Governance
Chief Information Officer Office of Information Services Centers for Medicare & Medicaid Services CMS Policy for Information Technology (IT) Investment Management & Governance May 17, 2007 Document Number:
BPA Policy 434-1 Cyber Security Program
B O N N E V I L L E P O W E R A D M I N I S T R A T I O N BPA Policy Table of Contents.1 Purpose & Background...2.2 Policy Owner... 2.3 Applicability... 2.4 Terms & Definitions... 2.5 Policy... 5.6 Policy
Privacy Impact Assessment (PIA) for the. Certification & Accreditation (C&A) Web (SBU)
Privacy Impact Assessment (PIA) for the Cyber Security Assessment and Management (CSAM) Certification & Accreditation (C&A) Web (SBU) Department of Justice Information Technology Security Staff (ITSS)
Embarcadero DataU Conference. Data Governance. Francis McWilliams. Solutions Architect. Master Your Data
Data Governance Francis McWilliams Solutions Architect Master Your Data A Level Set Data Governance Some definitions... Business and IT leaders making strategic decisions regarding an enterprise s data
Department of the Interior Privacy Impact Assessment
Department of the Interior August 15, 2014 Name of Project: email Enterprise Records and Document Management System (eerdms) Bureau: Office of the Secretary Project s Unique ID: Not Applicable A. CONTACT
Scope The data management framework must support industry best practice processes and provide as a minimum the following functional capability:
Data Management Policy Version Information A. Introduction Purpose 1. Outline and articulate the strategy for data management across Redland City Council (RCC). This document will provide direction and
FISH AND WILDLIFE SERVICE INFORMATION RESOURCES MANAGEMENT. Chapter 7 Information Technology (IT) Security Program 270 FW 7 TABLE OF CONTENTS
TABLE OF CONTENTS General Topics Purpose and Authorities Roles and Responsibilities Policy and Program Waiver Process Contact Abbreviated Sections/Questions 7.1 What is the purpose of this chapter? 7.2
VOLUME 1, CHAPTER 3: FEDERAL FINANCIAL MANAGEMENT IMPROVEMENT ACT OF 1996 COMPLIANCE, EVALUATION, AND REPORTING SUMMARY OF MAJOR CHANGES
VOLUME 1, CHAPTER 3: FEDERAL FINANCIAL MANAGEMENT IMPROVEMENT ACT OF 1996 COMPLIANCE, EVALUATION, AND REPORTING SUMMARY OF MAJOR CHANGES All changes are denoted by blue font. Substantive revisions are
Master Data Management
Master Data Management Managing Data as an Asset By Bandish Gupta Consultant CIBER Global Enterprise Integration Practice Abstract: Organizations used to depend on business practices to differentiate them
ClOP CHAPTER 1351.39. Departmental Information Technology Governance Policy TABLE OF CONTENTS. Section 39.1
ClOP CHAPTER 1351.39 Departmental Information Technology Governance Policy TABLE OF CONTENTS Section 39.1 Purpose... 1 Section 39.2 Section 39.3 Section 39.4 Section 39.5 Section 39.6 Section 39.7 Section
INFORMATION MANAGEMENT
United States Government Accountability Office Report to the Committee on Homeland Security and Governmental Affairs, U.S. Senate May 2015 INFORMATION MANAGEMENT Additional Actions Are Needed to Meet Requirements
Subject: 1268-1 Information Technology Configuration Management Manual
Form 1221-2 (June 1969) UNITED STATES DEPARTMENT OF THE INTERIOR BUREAU OF LAND MANAGEMENT Release 1-1741 Date MANUAL TRANSMITTAL SHEET 06/19/2012 Subject: 1268-1 Information Technology Configuration Management
Integrated Financial Management Information System (IFMIS) Merger
for the Information System (IFMIS) Merger DHS/FEMA/PIA-020 December 16, 2011 Contact Point Michael Thaggard Office of Chief Financial Officer (202) 212-8192 Reviewing Official Mary Ellen Callahan Chief
The Data Reference Model. Volume I, Version 1.0 DRM
The Data Reference Model Volume I, Version 1.0 DRM September 2004 Document Organization Document Organization 2 Executive Summary 3 Overview of the DRM 9 DRM Foundation 12 Use of the DRM 17 DRM Roadmap
NATIONAL CREDIT UNION ADMINISTRATION OFFICE OF INSPECTOR GENERAL
NATIONAL CREDIT UNION ADMINISTRATION OFFICE OF INSPECTOR GENERAL INDEPENDENT EVALUATION OF THE NATIONAL CREDIT UNION ADMINISTRATION S COMPLIANCE WITH THE FEDERAL INFORMATION SECURITY MANAGEMENT ACT (FISMA)
Information Security for Managers
Fiscal Year 2015 Information Security for Managers Introduction Information Security Overview Enterprise Performance Life Cycle Enterprise Performance Life Cycle and the Risk Management Framework Categorize
Bureau of Land Management. Information System Decommissioning Guide
Department Bureau of the Land Interior Management Bureau of Land Management Information System Decommissioning Guide Version Control Log Date Version # Author Description January 11, 2011 0.1 WO-550 Original
POLICY AND PROCEDURES OFFICE OF STRATEGIC PROGRAMS. CDER Informatics Governance Process. Table of Contents
CENTER FOR DRUG EVALUATION AND RESEARCH MAPP 7600.8 Rev. 1 POLICY AND PROCEDURES OFFICE OF STRATEGIC PROGRAMS CDER Informatics Governance Process Table of Contents PURPOSE...1 BACKGROUND...1 POLICY...2
5 FAM 1060 INFORMATION ASSURANCE MANAGEMENT
5 FAM 1060 INFORMATION ASSURANCE MANAGEMENT 5 FAM 1061 GENERAL (CT:IM-141; 06-07-2013) (Office of Origin: IRM/IA) a. The Chief Information Security Officer (CISO) operates under the direction and supervision
Information Security Guide For Government Executives. Pauline Bowen Elizabeth Chew Joan Hash
Information Security Guide For Government Executives Pauline Bowen Elizabeth Chew Joan Hash Introduction Table of Contents Introduction 1 Why do I need to invest in information security? 2 Where do I need
Seeing Though the Clouds
Seeing Though the Clouds A PM Primer on Cloud Computing and Security NIH Project Management Community Meeting Mark L Silverman Are You Smarter Than a 5 Year Old? 1 Cloud First Policy Cloud First When evaluating
CMS Policy for Configuration Management
Chief Information Officer Centers for Medicare & Medicaid Services CMS Policy for Configuration April 2012 Document Number: CMS-CIO-POL-MGT01-01 TABLE OF CONTENTS 1. PURPOSE...1 2. BACKGROUND...1 3. CONFIGURATION
An Overview of Data Management
An Overview of Data Management Recognition of Contribution The AICPA gratefully recognizes the invaluable contribution and involvement from the AICPA s IMTA Executive Committee Data Management Task Force
USAID Management Operations Council Charter
USAID Management Operations Council Charter Version 1.0 Date: August 1, 2011 TABLE OF CONTENTS 1. INTRODUCTION... 1 1.1 PURPOSE... 1 1.2 OBJECTIVE... 1 1.3 SCOPE... 1 2. OVERVIEW OF THE MOC... 1 2.1 MOC
Washington State s Use of the IBM Data Governance Unified Process Best Practices
STATS-DC 2012 Data Conference July 12, 2012 Washington State s Use of the IBM Data Governance Unified Process Best Practices Bill Huennekens Washington State Office of Superintendent of Public Instruction,
TITLE III INFORMATION SECURITY
H. R. 2458 48 (1) maximize the degree to which unclassified geographic information from various sources can be made electronically compatible and accessible; and (2) promote the development of interoperable
STATEMENT OF. Dr. David McClure Associate Administrator Office of Citizen Services and Innovative Technologies General Services Administration
STATEMENT OF Dr. David McClure Associate Administrator Office of Citizen Services and Innovative Technologies General Services Administration BEFORE THE HOUSE COMMITTEE ON OVERSIGHT AND GOVERNMENT REFORM
Department of Defense INSTRUCTION
Department of Defense INSTRUCTION NUMBER 7750.07 October 10, 2014 DoD CIO SUBJECT: DoD Forms Management Program References: See Enclosure 1 1. PURPOSE. This instruction: a. Reissues DoD Instruction (DoDI)
EXPLORING THE CAVERN OF DATA GOVERNANCE
EXPLORING THE CAVERN OF DATA GOVERNANCE AUGUST 2013 Darren Dadley Business Intelligence, Program Director Planning and Information Office SIBI Overview SIBI Program Methodology 2 Definitions: & Governance
5 FAM 140 ACCEPTABILITY AND USE OF ELECTRONIC SIGNATURES
5 FAM 140 ACCEPTABILITY AND USE OF ELECTRONIC SIGNATURES 5 FAM 141 PURPOSE (CT-IM-112; 07-30-2010) (Office of Origin: IRM/OPS/ITI/SI/IIB) The purpose of this FAM chapter is to enable the Department to
SLCM Framework (Version 2003.1) Roles and Responsibilities As of January 21, 2005
SLCM Framework (Version 2003.1) Roles and Responsibilities As of January 21, 2005 ROLE RESPONSIBILITY REVIEW SIGN- OFF CTO Manage IT assets to meet corporate goals Establish and chair the Information Technology
Significant Revisions to OMB Circular A-127. Section Revision to A-127 Purpose of Revision Section 1. Purpose
Significant Revisions to OMB Circular A-127 Section Revision to A-127 Purpose of Revision Section 1. Purpose Section 5. Definitions Section 6. Policy Section 7. Service Provider Requirements Section 8.
University of Hawai i Executive Policy on Data Governance (Draft 2/1/12)
University of Hawai i Executive Policy on Data Governance (Draft 2/1/12) I. Definition Data governance is the exercise of authority and control (planning, monitoring, and enforcement) over the management
BPA Policy 236-1 Information Governance & Lifecycle Management
B O N N E V I L L E P O W E R A D M I N I S T R A T I O N BPA Policy 236-1 Table of Contents 236-1.1 Purpose & Background... 2 236-1.2 Policy Owner... 2 236-1.3 Applicability... 2 236-1.4 Terms & Definitions...
Knowledgent White Paper Series. Developing an MDM Strategy WHITE PAPER. Key Components for Success
Developing an MDM Strategy Key Components for Success WHITE PAPER Table of Contents Introduction... 2 Process Considerations... 3 Architecture Considerations... 5 Conclusion... 9 About Knowledgent... 10
PROCEDURE. The permission rights assigned to allow data custodians to view, copy, enter, download, update or query data.
Section: Subject: Administration (AD) Data Governance AD.3.3.1 DATA GOVERNANCE PROCEDURE Legislation: Alberta Evidence Act, RSA 2000, c.a-18; Electronic Transactions Act, SA 2001, c.e- 5.5; Freedom of
Standards for Security Categorization of Federal Information and Information Systems
FIPS PUB 199 FEDERAL INFORMATION PROCESSING STANDARDS PUBLICATION Standards for Security Categorization of Federal Information and Information Systems Computer Security Division Information Technology
Architecture Principles
Architecture Principles Table of Contents 1 GENERAL INFORMATION...2 2 INTENT...2 3 OWNERSHIP...2 4 APPLYING THE PRINCIPLES...2 5 ARCHITECTURAL OBJECTIVES...2 6 ARCHITECTURE PRINCIPLES...3 6.1 General...
Data Governance Baseline Deployment
Service Offering Data Governance Baseline Deployment Overview Benefits Increase the value of data by enabling top business imperatives. Reduce IT costs of maintaining data. Transform Informatica Platform
Evaluation Report. Weaknesses Identified During the FY 2013 Federal Information Security Management Act Review. April 30, 2014 Report Number 14-12
Evaluation Report Weaknesses Identified During the FY 2013 Federal Information Security Management Act Review April 30, 2014 Report Number 14-12 U.S. Small Business Administration Office of Inspector General
Manag. Roles. Novemb. ber 20122
Information Technology Manag gement Framework Roles and Respo onsibilities Version 1.2 Novemb ber 20122 ITM Roles and Version History Version ed By Revision Date Approved By Approval Date Description of
Human Resources Management. Portfolio Management Concept of Operations
Human Resources Management Portfolio Management Concept of Operations September 30, 2012 Table of Contents 1.0 Overview... 2 1.1 Background... 2 1.2 Purpose... 2 1.3 Organization of This Document... 2
Minimum Security Requirements for Federal Information and Information Systems
FIPS PUB 200 FEDERAL INFORMATION PROCESSING STANDARDS PUBLICATION Minimum Security Requirements for Federal Information and Information Systems Computer Security Division Information Technology Laboratory
Department of Veterans Affairs VA Directive 6004 CONFIGURATION, CHANGE, AND RELEASE MANAGEMENT PROGRAMS
Department of Veterans Affairs VA Directive 6004 Washington, DC 20420 Transmittal Sheet September 28, 2009 CONFIGURATION, CHANGE, AND RELEASE MANAGEMENT PROGRAMS 1. REASON FOR ISSUE: This Directive establishes
BC Geographic Warehouse. A Guide for Data Custodians & Data Managers
BC Geographic Warehouse A Guide for Data Custodians & Data Managers Last updated November, 2013 TABLE OF CONTENTS INTRODUCTION... 1 Purpose... 1 Audience... 1 Contents... 1 It's All About Information...
Data Governance Data & Metadata Standards. Antonio Amorin
Data Governance Data & Metadata Standards Antonio Amorin Abstract This data governance presentation focuses on data and metadata standards. The intention of the presentation is to identify new standards
POSTAL REGULATORY COMMISSION
POSTAL REGULATORY COMMISSION OFFICE OF INSPECTOR GENERAL FINAL REPORT INFORMATION SECURITY MANAGEMENT AND ACCESS CONTROL POLICIES Audit Report December 17, 2010 Table of Contents INTRODUCTION... 1 Background...1
