GSA / GSA/modernization

Formal Comments for the American Technology Council

Open
#18 0 comments 0 reactions 0 assignees View on GitHub
Public comment
Dominant language
CSS
Stars
59
Forks
8
PR merge metrics
No merged PRs in 30d

Description

Submitted by:
Office of the Chief Records Officer
National Archives and Records Administration
PRMD@nara.gov

Thank you for the opportunity to comment on the draft Report to the President on Federal IT Modernization.

M-17-09 defines High Value Assets as “those assets, Federal information systems, information, and data for which an unauthorized access, use, disclosure, disruption, modification, or destruction could cause a significant impact to the United States' national security interests, foreign relations, economy, or to the public confidence, civil liberties, or public health and safety of the American people.”

Likely much of the information covered under the HVA definition will meet the definition of a record under the Federal Records Act (FRA) at 44 USC 3301. The FRA defines records as:

“all recorded information, regardless of form or characteristics, made or received by a Federal agency under Federal law or in connection with the transaction of public business and preserved or appropriate for preservation by that agency or its legitimate successor as evidence of the organization, functions, policies, decisions, procedures, operations, or other activities of the United States Government or because of the informational value of data in them.”

https://www.archives.gov/files/about/laws/p-l-113-187.pdf

At a high level, our comments relate to key questions 3 and 4 and concern ensuring records management requirements are addressed when agencies work to meet the goals outlined in those sections. We have four specific comments:

**1: Include the Senior Agency Officials for Records Management as a stakeholder group.**

In the Executive Summary, paragraph on Resourcing Federal Network IT Modernization, consider adding the Senior Agency Official for Records Management (SAORM) as a key stakeholder. SAORMs work to ensure their agency/agencies efficiently and appropriately comply with all applicable records management statutes, regulations, NARA policy, and OMB policy. The SAORM promotes effective records management at a senior level by seeing across
program offices in the deployment of individual IT systems and advocates for the records management program ensuring adequate resources are embedded into the agency’s Strategic Information Resources Management (IRM) Plan. The SAORMs are a key agency stakeholder in moving to a fully digital government.

The SAORM position was established by the 2011 Presidential Memorandum on Managing Government Records and was further described in OMB/NARA Memorandum M-12-18 and OMB Circular A-130. While many in the SAORM community are CIOs (roughly one-third), there are SAORMs who should be included in agency discussions about managing IT systems and moving to a digital government. NARA maintains a list of SAORMs on our website: https://www.archives.gov/records-mgmt/agency/sao-list

**2: Include Public Law 113-187, The Presidential and Federal Records Act Amendments of 2014, as an additional legal consideration in Appendix E.**

As we mentioned earlier, there may be significant overlap between HVAs and information that qualifies as a Federal record. The ATC should include a review of legal considerations of managing records as it relates to IT modernization and moving to a shared services infrastructure. The FRA at 44 USC 3101 requires that:

“each Federal agency shall make and preserve records containing adequate and proper documentation of the organization, functions, policies, decisions, procedures, and essential transactions of the agency and designed to furnish the information necessary to protect the legal and financial rights of the Government and of persons directly affected by the agency’s activities.”

This means that Federal records are managed and retained for as long as needed to conduct agency business and that permanent records of historical value are transferred to the National Archives of the United States.

The records stored on legacy IT systems must be reliable, authentic, usable, and maintain their integrity. Metadata must also be maintained to document the content, context, and structure of records (36 CFR 1236.10, https://www.ecfr.gov/cgi-bin/text-idx?SID=cdfab00fef52c315167e41f5bdcec0e8&node=pt36.3.1236&rgn=div5) as they are migrated to new systems. This requirement also applies to records stored in a cloud or shared services environment.

Further, when storing records in the cloud or utilizing shared services, agencies need to ensure records and information remain under government control and they have the ability to export information. As agencies continue to procure commercial solutions, they need to include proper data rights/management clauses to ensure their information can be available and removed and they understand the fees for export at conclusion of the contract.

Ultimately, an agency maintains responsibility for managing its records whether they reside in a contracted environment or under agency physical custody (see 36 CFR Part 1222.32 (b), https://www.ecfr.gov/cgi-bin/text-idx?SID=0b17c2728b73e72f6093e6f2a050638f&mc=true&node=pt36.3.1222&rgn=div5). When procuring tools or services, an agency must include a records management clause in any contract or similar agreement to address records. At a minimum, a records management clause ensures that the Federal agency and the contractor are aware of their statutory records management responsibilities. (NARA Bulletin 2010-05: Guidance on Managing Records in Cloud Computing Environments, https://www.archives.gov/records-mgmt/bulletins/2010/2010-05.html)

Because of these requirements, we ask that ATC review the FRA for legal considerations. More information can be found in the paper “Aging Federal IT Infrastructure Poses Risk to Records Management” provided in NARA’s Presidential Transition 2016-2017 Briefing Book (page 41): https://www.archives.gov/files/foia/presidential-transition-2016-2017.pdf

**3: Include a records management clause in the FAR to help define consistent requirements for security, privacy, and access to data for use in cloud contracts.**

Earlier this year, NARA released updated records management language for use in contracts. NARA has long-provided sample language to use in contracts. This update reflects changes in the way Government creates and manages records and current legal obligations. This is a sample for agencies to modify and fit for their purposes: https://www.archives.gov/records-mgmt/handbook/records-mgmt-language.html

By including records management contract language in the FAR, agencies will know what Federal records management requirements should be included in their contracts. Contracts should provide clear legal obligations describing how Federal records must be managed. The inclusion of a records management clause in the FAR will hopefully ease the procurement process and allow for Federal records to be properly managed.

**4: NARA has self-reported data about agency adoption of cloud email in our annual Records Management Self-Assessment (RMSA).**

NARA anticipates that last FY’s RMSA will be released in the coming weeks: https://www.archives.gov/records-mgmt/resources/self-assessment.html. On last year’s assessment, agencies were asked the following questions:

Q93: Does your agency use cloud services? Y/N/DNK
Q94: For what purpose? (Choose all that apply)
-Email
-Administrative functions such as payroll, purchasing, and financial mgmt
-Mission/program-related functions
-Other, please explain
-DNK

Once the report is available, NARA can provide the information reported by agencies concerning cloud adoption of email.

[Report_to_the_President_on_Federal_IT_Modernization_AC_NARA_Comments.docx](https://github.com/GSA/modernization/files/1315926/Report_to_the_President_on_Federal_IT_Modernization_AC_NARA_Comments.docx)

Contributor guide

No contributing guide indexed for this repository

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.