Supporting Statement 0584-0532 (OIRA Passback) NO track changes5-18-18

Supporting Statement 0584-0532 (OIRA Passback) NO track changes5-18-18.docx

FNS Computer System Access Request

OMB: 0584-0532

Document [docx]
Download: docx | pdf





Supporting Statement for

The FNS User Access Request Form Data Collection”

(OMB Control Number 0584-0532)


Joseph Binns

Chief Information Security Officer (CISO)

Office of Information Technology (OIT)

Food, Nutrition and Consumer Services, USDA

3101 Park Center Drive

Alexandria, Virginia 22302

Office: 703-605-1181

Email: [email protected]

TABLE OF CONTENTS


A. Justification 3

1. Explain the circumstances that make the collection of information necessary. 3

2. How the information will be used, by whom and for what purpose 4

3. use of improved information technology to reduce burden 6

4. Efforts to identify and avoid duplication…………………………………………………….7

5. eFFORTS TO MINIMIZE BURDEN ON SMALL BUSINESSES OR OTHER ENTITIES. 7

6. consequences of less frequent data collection. 7

7. Special circumstances requiring collection of information 8

8. federal register comments and efforts to consult with persons outside the agency. 9

9. Payments to respondents. 10

10. assurance of confidentiality . 10

11. questions of a sensitive nature . 11

12. estimates of respondent burden. 11

13. estimates of other annual costs to respondents 13

14. estimates of annualized government costs. 14

15. changes in burden hours. 15

16. time schedule, publication and analysis plans . 15

17. display of expiration date for omb approval. 15

18. exceptions to the certification statement 15


APPENDICES:

  • Appendix A: Legal Authority Public Law 107-347

  • Appendix B: USDA Information System Security Program Directive

  • Appendix C: OMB Circular No A-130

  • Appendix D: FNS-674

  • Appendix E: User Guide for Completing the 674

  • Appendix F: FNCS 702 Handbook

  • Appendix G: Outside Consultations Comments on Form FNS-674

Appendix G1: Outside Consultation Comment - Luebeck

Appendix G2: Outside Consultation Comment - Gordon

Appendix G3: Outside Consultation Comment - Kuo

Appendix G4: Outside Consultation Comment – Young

Appendix G5: Comment to 60dayFRN – Unknown





A. Justification

  1. Explain the circumstances that make the collection of information necessary. Identify any legal or administrative requirements that necessitate the collection. Attach a copy of the appropriate section of each statute and regulation mandating or authorizing the collection of information.

This is an extension of a currently approved collection. Section 301 of the E-Government Act 2002, (P.L. 107-347) and Office of Management and Budget (OMB) Circular A-130, Appendix III (see Appendix C), Security of Federal Automated Information Resources, revised November 28, 2000, establishes a minimum set of controls to be included in Federal automated information security programs. Establishing personnel controls to screen users to allow access to authorized system is directed in OMB Circular A-130. The FNS User Access Request Form, FNS-674 (see Appendix D) , is designed for this purpose and will be used in all situations where access to an FNS computer system is required or where current access is required to be modified and can be used where access is no longer required and must be deleted.

  1. Indicate how, by whom and for what purpose the information is to be used. Except for a new collection, indicate the actual use the Agency has made of the information received from the current collection.

FNCS employees, contractors, state agencies and partners, e.g. Food Banks, etc. have requested access to FNCS systems via the User Access Request form. FNCS has used the information collected to grant access to FNCS Systems. Only specific systems require PII in order to grant access. Information that is collected includes: Name, e-Authentication ID (if exists), telephone number, home zip code, email address, contract expiration date, temporary employee expiration date, office address, State/locality codes, system name, form type, type of access, action requested, comments and special instructions.

From whom will the information be collected?

The User Access Request Form collects information from:

  • new FNCS Employees (in line with their duties; as a result, not accounted for in the burden hours)

  • new FNCS Contract Staff

  • new State Agencies to FNCS

  • new Partners to FNCS or

  • Existing employees, Contract Staff, State Agencies or Partners to FNCS requesting updates to current access to FNCS Information Systems.

How will the information be collected (e.g., forms, non-forms, electronically, face-to-face, over the phone, over the internet)?

The information is collected via a paper form FNS-674 available online and emailed to FNS to the Security Officers’ Mailbox at [email protected] from System Helpdesks.

How frequently will the information be collected?

The information is requested as often as needed based on the user requests for new access or updated access requests to systems. In State agencies, the State Coordinators provide a liaison between the State agency and the Information Systems Security Officers (ISSO) in FNCS Regional Offices and the Information Security Office (ISO) in the FNCS National Office. The State Coordinator is responsible for ensuring that State users and entities comply with the FNCS Information Systems Security Guidelines and Procedures Handbook 702 (see Appendix E). The ISSOs act on behalf of the National Office ISO to ensure that Regional, Field and Compliance Office users comply with the FNCS 702 Handbook (see Appendix F).

Will the information be shared with any other organizations inside or outside USDA or the government?

This information will be stored in the Information System Security Office (ISO), the Financial Management Division (FMD) where the information is stored and maintained for users requesting access to Financial Management Systems, the National Finance Center (NFC), and the National Information Technology Center (NITC) where information from this form is shared to grant access to NFC and NITC Systems.

If this is an ongoing collection, how have the collection requirements changed over time?

The information collected on this form and instructions has changed to include additional required fields used to identify a user when changes are requested to their access or when password resets are needed. Also, information is now collected to validate the completion of Information Security Awareness (ISA) and Privacy Act Training, prior to processing the form. No changes have been made to include other training.

  1. Describe whether, and to what extent, the collection of information involves the use of automated, electronic, mechanical, or other technological collection techniques or other forms of information technology, e.g. permitting electronic submission of responses, and the basis for the decision for adopting this means of collection. Also, describe any consideration of using information technology to reduce burden.

FNS has reached out to the FNS workgroup to collect requirements in order to automate the FNS- 674 for applications that have available funding to support the automation. Therefore, this collection is in compliance with E-Government 2002. The automation has not been implemented. Information on the FNS-674 will be displayed and captured using Microsoft ASP.Net and HTML, via a web-based system on the FNCS web site. The information will be stored in Microsoft SharePoint Server. The information will be transmitted over a secured HTTP protocol. The foundation of this technical architecture is Microsoft, which is consistent with current FNCS standards. The FNS-674 forms are currently submitted via email sent to [email protected] and are stored electronically at http://fncs/apps/isodoc/Pages/Default.aspx. The form is a fillable electronic Adobe pdf, available on the FNCS intranet e-forms library at http://fncs/ondemand/elibrary/EForms/FNS-674.pdf and also on the internet on various public sites for systems. Currently, FNS does not have an electronic submission web-based system to receive these requests.

  1. Describe efforts to identify duplication. Show specifically why any similar information already available cannot be used or modified for use for the purpose described in item 2 above.

There is no similar information available. FNS solely monitors issuance of FNS computer access to ensure integrity. The information required for FNS-674 is not currently reported to any other entity outside of FNS. Every effort has been made to avoid duplication. FNS has reviewed USDA reporting requirements.

  1. If the collection of information impacts small businesses or other small entities, describe any methods used to minimize burden.

There will be no impact to small businesses or entities that work with FNCS. FNS anticipates that out of the 180 respondents, 75 percent or 130 are considered respondents of small businesses.

  1. Describe the consequences to Federal program or policy activities if the collection is not conducted or is conducted less frequently, as well as any technical or legal obstacles to reducing burden.

This is a mandatory and on-going data collection. If this form were not submitted, FNCS could not ensure integrity of our systems and the computer users would be denied access to systems needed to effectively deliver or monitor FNCS programs benefits. Users provide name, e-Authentication ID (if exists), telephone number, email address, contract expiration date, temporary employee expiration date, office address, State/locality codes, system name, form type, type of access, action requested, comments and special instructions to gain initial access to FNCS Information Systems and may require subsequent submissions if access requires changes. This form can also be used if an individual should be removed as a user from a specific system.

  1. Explain any special circumstances that would cause an information collection to be con­ducted in a manner:

  • requiring respondents to report information to the agency more often than quarterly;

  • requiring respondents to prepare a written response to a collection of information in fewer than 30 days after receipt of it;

  • requiring respondents to submit more than an original and two copies of any docu­ment;

  • requiring respondents to retain records, other than health, medical, government contract, grant-in-aid, or tax records for more than three years;

  • in connection with a statistical survey, that is not designed to produce valid and reli­able results that can be generalized to the universe of study;

  • requiring the use of a statistical data classification that has not been reviewed and approved by OMB;

  • that includes a pledge of confidentiality that is not supported by authority established in statute or regulation, that is not supported by disclosure and data security policies that are consistent with the pledge, or which unnecessarily impedes sharing of data with other agencies for compatible confidential use; or

  • requiring respondents to submit proprietary trade secret, or other confidential information unless the agency can demonstrate that it has instituted procedures to protect the information's confidentiality to the extent permitted by law.

There are no special circumstances. The collection of information is conducted in a manner consistent with the guidelines in 5 CFR 1320.5.

8. If applicable, provide a copy and identify the date and page number of publication in the Federal Register of the agency's notice, soliciting comments on the information collection prior to submission to OMB. Summarize public comments received in response to that notice and describe actions taken by the agency in response to these comments.

A 60-day notice requesting public comment on this collection was published in the Federal Register at Vol. 82, No. 215, Pages 51801 - 51802, Wednesday, November 8, 2017. The comment period closed on January 8, 2018. One comment was received that was not relevant to the collection.

Describe efforts to consult with persons outside the agency to obtain their views on the availability of data, frequency of collection, the clarity of instructions and record keeping, disclosure, or reporting form, and on the data elements to be recorded, disclosed, or reported.

State agencies interact daily with Regional staff and sometimes provide their views on the aspects of this collection if necessary. During recent discussions, State agencies’ provided valid concerns about the routine use of this form and submitted suggestions to FNCS National Office Information Systems Security Office. We considered all valid suggestions when redesigning this form to its users.

During 2017 and 2018 outside consultations with State users, comments were collected about the FNS-674 specifically on the availability of data, frequency of collection, the clarity of instructions and record keeping responsibilities, disclosure or reporting form, and the data elements to be recorded, disclosed, or reported. An employee working group compiled and considered all suggestions received for changes. Comments were received from four State Users of the FNS-674 including Patricia Gordon, Birgit Luebeck, Chung Kuo, and Max Young (Appendix G1-G4). Changes agreed upon by the group, including updating the required Privacy Act and Public Burden Statements, the Office and System drop down lists, removing fields no longer needed on the form, and making updates that addressed all State User comments were incorporated into the version of the FNS-674 to be used after OMB has approved. We also received one comment in response to the 60dayFRN which was not relevant to this information collection burden (Appendix G5).

9. Explain any decision to provide any payment or gift to respondents, other than re-enumeration of contractors or grantees.

Payments or gifts are not provided to respondents.

10. Describe any assurance of confidentiality provided to respondents and the basis for the assurance in statute, regulation, or agency policy.

The FNS-674 will contain a Privacy Act Statement and the data will be stored in a secured database. The applications for authorization contain personal identifying information on individuals doing business with Food and Nutrition Service. Therefore, the Food and Nutrition Service published such a Privacy Act notice (system of records), USDA/FNS-10, entitled “Persons Doing Business with the Food and Nutrition Service” on March 31, 2000 in the Federal Register Volume 65 pages 17251-52 to specify the uses to be made of the information in this collection. Access to records is limited to those persons who process the records for the specific uses stated in this Privacy Act notice. Records are kept in physically secured rooms and/or cabinets. Various methods of computer security limit access to records in automated databases.

11. Provide additional justification for any questions of a sensitive nature, such as sexual behavior or attitudes, religious beliefs, and other matters that are commonly considered private. This justification should include the reasons why the agency considers the questions necessary, the specific uses to be made of the information, the explanation to be given to persons from whom the information is requested, and any steps to be taken to obtain their consent.

This information collection includes no questions of a sensitive nature.

12. Provide estimates of the hour burden of the collection of information. The statement should:

  • Indicate the number of respondents, frequency of response, annual hour burden, and an explanation of how the burden was estimated. If this request for approval covers more than one form, provide separate hour burden estimates for each form and aggregate the hour burdens in Item 13 of OMB Form 83-I.

  • Provide estimates of annualized cost to respondents for the hour burdens for collections of information, identifying and using appropriate wage rate categories.


Estimate of Burden

The respondents are State agencies, who are located in the 50 states and Trust Territories, staff contractors and Federal employees. Respondents who require access to the FNS systems are estimated at 3,600 annually (includes Federal, State and private) however, only 2,700 will account for the total public burden, excluding Federal employees. Based on the actual number of FNS 674 submitted via email, FNS estimates that it will receive an average of 300 requests per month (15 per day). Of the 300, 70 percent (or 210) of the responses are State Agency users, 5 percent (or 15) are staff contractors and 25 percent (or 75) are Federal employees which is not included in the total number of responses. Annually, that results in 2,700 respondents (210 State Agency users per month + 15 staff contractors per month × 12 months).

REPORTING BURDEN

Affected Public

Form Number

Number of Respondents

Number of responses annually per Respondent

Total Annual Responses

Estimate of Burden Hours per response

Total Annual Burden Hours

Contractors

FNS-674

180

1

180

0.16667

(10 minutes)

30

State Agency Users

FNS-674

2,520

2

5,040

0.16667

(10 minutes)

840

Annualized Totals


2,700

1.9

5,220

10 minutes

870

RECORDKEEPING BURDEN

There is no recordkeeping burden imposed on the public. All requests from respondents are archived on FNCS National Office systems.

Annualized Cost to Respondent

It is estimated that each respondent take 10 minutes to read the instruction and complete the on-line form. Using the hourly rate reported in the National Sector NAICS Industry-Specific estimates of US Occupational Employment and Wages in the U.S., May 2016; Department of Labor, Bureau of Labor Statistics at http://www.bls.gov/oes/current/oes_stru.htm. Occupational codes (OC) used for States and Contractors include NAICS 999200 - 13-0000 Business and Financial Operations Occupations (at $36.09 hourly wage rate) and 15-1122 Information Security Analysts (at $52.36 hourly wage rate).

Affected Public

Type of Instrument

Average time per response

Number of Respondents

Frequency of Response

Hourly Wage Rate

Cost to Respondent

State Agencies

FNS-674

0.16667

2,520

2

$36.09

$30,316.21

Contractors

FNS-674

0.16667

180

1

$52.36

$1570.83

Total



2,700

3


$31,887.04

13. Provide estimates of the total annual cost burden to respondents or record keepers resulting from the collection of information, (do not include the cost of any hour burden shown in items 12 and 14). The cost estimates should be split into two components: (a) a total capital and start-up cost component annualized over its expected useful life; and (b) a total operation and maintenance and purchase of services component.

There are no capital/startups or ongoing/annualized maintenance costs to the respondents.

14. Provide estimates of annualized cost to the Federal Government. Also, provide a description of the method used to estimate cost and any other expense that would not have been incurred without this collection of information.


Description of Activities

HQ Staff

(2 – GS-13 @

($46.46 per hour)

Regional Staff

(14 – GS-12 @

$39.07 per hour)

Contractor

($52.36 per hour)

Total

Updating on-line form to support the collection

2 hours = $92.92



$92.92

Testing of computer system



10 hours = $523.60

$523.60

Reviewing, approving and issuing password 1

36 hours =$1,672.56

108 hours = $4,219.56


$5,892.12

Labor for analyzing, evaluating, summarizing, and reporting on the collected information 2

16 hours =$743.36



$743.36

Total Cost to the Federal Government

$7252.00

National Office: Two (2) GS-13 Information Security Officers spend 2 minutes (0.04 of an hour) reviewing, approving, and issuing passwords for each of the National Office applications received. (3,600 applications/25% = 900 x 0.04 = 36 hours. 36 hours @$46.46 per hour = $1,672.56.)

Regions: Fourteen (14) GS-12 Information Security Officers spend 2 minutes (or 0.04 of an hour) reviewing, approving, and issuing passwords for users in State agencies. (3,600 applications/75% = 2,700 x 0.04 = 108 hours. 108 hours @ $39.07 per hour = $4,219.56)

2 Two (2) GS-13 HQ Security Officers spend 2 hours per quarter, each, on the analyzing and running reports of security users and authorized systems. (16 hours @ $46.46 per hour = $743.36)

Annualized costs are determined by tasks as described in the chart above. The FNCS National Office’ staff salary was determined by the January 2018 Salary and Wage tables available from the Office of Personnel Management (OPM). The staff contractors’ salary was determined by using the national average available from the Department of Labor.

15. Explain the reasons for any program changes or adjustments reported in items 13 or 14 of the OMB Form 83-I.

This is an extension without functional change to a currently approved collection; the current estimated annual burden inventory for this information collection is 5,220 total annual responses and 870 burden hours and we are requesting the same for this renewal. Everything remains unchanged.

16. For collection of information whose results are planned to be published, outline plans for tabulation and publication.

There are no plans for publication.

  1. If seeking approval to not display the expiration date for OMB approval of the information collection, explain the reasons that display would be inappropriate.

We will display the OMB control number and expiration date on this form.

  1. Explain each exception to the certification statement identified in Item 19 “Certification for Paperwork Reduction Act.”

There are no exceptions to the certification statement.

1


2

8

OMB #0584-0532

May 2018

File Typeapplication/vnd.openxmlformats-officedocument.wordprocessingml.document
File TitleDate
AuthorAuthorized Gateway Customer
File Modified0000-00-00
File Created2021-01-21

© 2024 OMB.report | Privacy Policy