NBIS Onboarding Kick-Off Checklist & Memorandum of Understanding
Prior to the Agency Kick-Off meeting, completion of Agency General Requirements and NBIS System User Requirements is crucial. Tasks include signing the Memorandum of Understanding (MOU), appointing an Onboarding Champion, forming an Agency Deployment Team, ensuring browser compatibility, completing personnel vetting questionnaire, meeting NBIS System minimum investigation requirement, holding necessary smartcards, and completing cybersecurity training. The MOU outlines the relationship between DCSA and the Onboarding Agency for NBIS System access. Detailed steps are provided for MOU review, signing, and submission.
Download Presentation
Please find below an Image/Link to download the presentation.
The content on the website is provided AS IS for your information and personal use only. It may not be sold, licensed, or shared on other websites without obtaining consent from the author. Download presentation by click this link. If you encounter any issues during the download, it is possible that the publisher has removed the file from their server.
E N D
Presentation Transcript
DEFENSE COUNTERINTELLIGENCE AND SECURITY AGENCY NBIS ONBOARDING KICK-OFF CHECKLIST Prior to your Agency s Kick-Off meeting, you must complete the Agency General Requirements listed below. Additionally, individuals that require access to the NBIS System will also need to complete the NBIS System User Requirements listed below. While it is strongly recommended that all members of the Agency Deployment Team (ADT) have access, at least one member of the ADT must have access to the NBIS System. Should you have any questions or run into any issues completing the following, please reach out to your Agency Liaison. Agencies are encouraged to complete these requirements earlier than the recommended timeframes listed below. Failure to complete any of these requirements by the timeframes below may delay onboarding. Agency General Requirement Agency General Requirement Description Description Prior To Kick Prior To Kick- -Off Off Begin the process of reviewing and signing the document codifying the relationship between DCSA as owner of the NBIS System and the Onboarding Agency. An MOU must be signed before NBIS accounts can be provisioned. Memorandum of Understanding (MOU) 3 Months Determine if action is needed regarding a System of Records Notice (SORN) Determine if participation in NBIS obligates the Onboarding Agency to publish, amend, or modify its own SORN. Any new SORNs or updated SORNs must be active in the federal register before operationalizing NBIS. 3 Months Identify Agency Onboarding Champion Identify a Federal employee within the Onboarding Agency to function as the main point of contact and sponsor throughout the Onboarding process. 1 Month Form a team of 2-5 federal employees and/or contractors to represent the Onboarding Agency throughout the Onboarding process. Form ADT 1 Month Confirm the Agency has use of the three most recent versions of at least one of the following internet browsers: Internet Explorer, Mozilla Firefox, Google Chrome, Microsoft Edge, or Apple Safari Confirm Compatibility of Internet Browser(s) 1 Month Personnel Vetting Questionnaire Complete the Personnel Vetting Questionnaire in order for the NBIS onboarding team to prepare for your Onboarding Agency. 1 Month NBIS System User Requirement NBIS System User Requirement Description Description Prior To Kick Prior To Kick- -Off Off Meet the NBIS System Minimum Investigation Requirement Ensure NBIS account holders have at least a favorably adjudicated Tier 1 background investigation. 3 Months Confirm NBIS account holders have the necessary smartcard for identity authentication as NBIS System users must have a DoD Common Access Card (CAC), a Public Key Infrastructure-enabled federally-compliant Personal Identity Verification (PIV) card, or with OMB approval, a federally-compliant soft-certification. Confirm Ability to Meet Common Access Card (CAC) / Personal Identity Verification (PIV) Card Requirement 3 Months Complete DoD-sponsored Cybersecurity Training Complete a DoD-sponsored cybersecurity training within the past 12 months. 1 Month Complete DoD-sponsored Personally Identifiable Information (PII) Training Complete a DoD-sponsored Personally Identifiable Information (PII) training within the past 12 months. 1 Month
DEFENSE COUNTERINTELLIGENCE AND SECURITY AGENCY NBIS ONBOARDING KICK-OFF CHECKLIST MEMORANDUM OF UNDERSTANDING (MOU) The Memorandum of Understanding (MOU) outlines the relationship between DCSA, as owner of the NBIS System, and the Onboarding Agency. The MOU is designed to ensure each Onboarding Agency understands and agrees to the requirements and responsibilities concerning NBIS System access and use. In addition, any agency who performs vetting work for or on-behalf of another federal agency should forward copies of any such agreements to their agency liaison for review and consideration by DCSA during the onboarding process. WHAT MUST BE DONE WHAT MUST BE DONE Identify necessary reviewers Obtain the most recent MOU version with the Onboarding Agency s DCSA routing number, from the Agency Liaison Review MOU Frequently Asked Questions Route / coordinate MOU through appropriate authorities for review Notify Agency Liaison if the Onboarding Agency is requesting any changes to the MOU so that they can be adjudicated by DCSA After MOU is signed by the Onboarding Agency, the Onboarding Agency should forward to the Agency Liaison Agency Liaison will have the MOU countersigned by DCSA and then return the fully executed MOU to the Onboarding Agency In addition, if your agency performs vetting work for, or on-behalf of another federal agency then forward copies of any agreements to the Agency Liaison SYSTEM OF RECORDS NOTICE (SORN) The SORN allows the Onboarding Agency to maintain a system that contains information on individuals and retrieves that information through a personal identifier. DCSA published its own SORN for the NBIS System ( Personnel Vetting Records System DUSDI 02-DoD SORN) in October 2018 (Federal Register Vol 83, Number 201). It covers personnel for whom DoD conducts or adjudicates background investigations The Onboarding Agency must make its own determination if participation in NBIS obligates it to publish, amend, or modify its own SORN. For your awareness, complete publication, amendment, or modification of an Onboarding Agency SORN is not required for Kick-Off but should be completed prior to entering subject data into NBIS. WHAT MUST BE DONE WHAT MUST BE DONE Determine if participation in NBIS obligates the Onboarding Agency to publish, amend, or modify its own SORN If necessary, take action to publish, amend, or modify a SORN AGENCY ONBOARDING CHAMPION The Onboarding Agency will identify an Agency Onboarding Champion to serve as the Onboarding Agency s designated point of contact for all matters pertaining to the NBIS System Onboarding process. The Agency Onboarding Champion will identify SMEs from the Onboarding Agency with expertise in project management, metrics and reporting, configuration management, investigation initiation workflow, training, and human resources and will select appropriate members of the ADT. The Agency Onboarding Champion will also attend all DCSA onboarding coordination meetings with the Onboarding Agency and oversee the actions of the ADT. WHAT MUST BE DONE WHAT MUST BE DONE Identify the Agency Onboarding Champion Provide name and contact information to respective Agency Liaison Align expectations internally on level of effort required of Agency Onboarding Champion
DEFENSE COUNTERINTELLIGENCE AND SECURITY AGENCY NBIS ONBOARDING KICK-OFF CHECKLIST AGENCY DEPLOYMENT TEAM (ADT) The Agency Onboarding Champion, with authorization from the Onboarding Agency, will form an ADT. The ADT, with training, guidance, and support from DCSA, will establish the Onboarding Agency s hierarchy and workflow in the NBIS System as well as provision the initial set of Onboarding Agency users. Ideally, the ADT will consist of members with expertise in the following areas: Configuration Management, Performance Management, Project Management, Operations Management, Training, and Human Resources. WHAT MUST BE DONE WHAT MUST BE DONE Identify ADT members Complete ADT form and send to respective Agency Liaison Align expectations internally on level of effort required of ADT members BROWSER REQUIREMENT The NBIS System is accessed through a web-based application that requires a supported internet browser. The NBIS System must be accessed using the three most recent versions of either Internet Explorer, Mozilla Firefox, Google Chrome, Microsoft Edge, or Apple Safari. Onboarding Agencies must have use of at least one of the above listed browsers. WHAT MUST BE DONE WHAT MUST BE DONE Verify with the Onboarding Agency s Chief Information Officer (CIO), or appropriate designee, that all information systems which the Onboarding Agency will use to access NBIS have at least one of the above listed compatible browsers Obtain access to one of the above listed compatible browsers, if necessary Email your respective Agency Liaison to confirm compatibility of internet browsers PERSONNEL VETTING QUESTIONNAIRE NBIS includes support for background investigation form submission, background investigation completion, background investigation adjudication, clearance management, continuous vetting, and related personnel vetting functions. As such, agencies will need to determine which functions of NBIS they would like to adopt for their operations. Subsequently, agencies will account for the offices that will be conducting those functions within the personnel vetting questionnaire. The questionnaire will be used by the NBIS onboarding team to help your agency construct your NBIS Organization, Sub-Organizations, and overall NBIS Hierarchy. An NBIS Organization and Sub-Organizations are distinct groups within NBIS where NBIS users are assigned to perform a specific task or set of tasks in the personnel vetting process (e.g. designation, pre-screening, initiate/review/authorize, render interim decisions, investigate, adjudicate). A Hierarchy is the technical reporting structure within NBIS comprised of a central Organization and its Sub-Organizations. An NBIS Hierarchy is similar to an agency s organization chart but only focuses on offices involved in the personnel vetting process and is organized based off of the process-flow and work silos rather than an organization chart s authority structure. Hierarchies are present in the NBIS system to show reporting and workflow structure. WHAT MUST BE DONE WHAT MUST BE DONE Complete the applicable portions of the Personnel Vetting Questionnaire in order for the NBIS onboarding team to prepare for your Onboarding Agency. These questionnaires will provide background information that will guide the creation of your hierarchy in NBIS. At a minimum, agencies must complete the Initiate, Review, Authorize portions of the questionnaire prior to moving forward with the onboarding process. NBIS SYSTEM MINIMUM INVESTIGATION REQUIREMENT A minimum of a favorably adjudicated T1 background investigation is required for access to the NBIS System. Prior to onboarding, the Agency Onboarding Champion and all members of the ADT that need access to the system must have a favorably adjudicated T1 background investigation. Note that future NBIS System capabilities may require a higher Tier background investigation. 4
DEFENSE COUNTERINTELLIGENCE AND SECURITY AGENCY NBIS ONBOARDING KICK-OFF CHECKLIST WHAT MUST BE DONE WHAT MUST BE DONE Email your respective Agency Liaison to validate that Agency Onboarding Champion and all members of the ADT that need access to the system have a minimum favorably adjudicated T1 background investigation CAC / PIV REQUIREMENT NBIS account holders must have a DoD CAC, a Public Key Infrastructure-enabled federally-compliant PIV card, OR approval, a federally-compliant soft-certification in order to authenticate to the NBIS System. OR with OMB WHAT MUST BE DONE WHAT MUST BE DONE Determine which authentication requirement will be used by your Onboarding Agency Obtain authentication methodology as necessary Provide the credentialing authority and/or root certificate information for your agency s CAC/PIV to the Agency Liaison -OR provide a technical POC with knowledge of the PKI certificates used in your CAC/PIV cards Email your respective Agency Liaison to confirm that the Agency Onboarding Champion and all members of the ADT that need access to the system meet the CAC / PIV card requirement CYBERSECURITY TRAINING OR- Prior to being provisioned with an NBIS account, ADT members must have completed a DoD-approved cybersecurity training within the last 12 months and must provide the training certificate to the Agency Liaison. ADT members and the Agency Onboarding Champion that will need access to the system must complete the DoD Cyber Awareness Challenge Training and certify completion. Once agencies begin to internally provision agency users, agencies may require users to complete either the DoD Cyber Awareness Challenge Training or other agency-approved cybersecurity training. DoD Cyber Awareness Challenge Training is available here for non-CAC users: https://public.cyber.mil. DoD Cyber Awareness Challenge Training is available here for CAC users: https://cyber.mil. Both can be found under the Course Catalog. WHAT MUST BE DONE WHAT MUST BE DONE Complete DoD Cyber Awareness Challenge Training found in the course catalog at https://public.cyber.mil (Non-CAC users) or https://cyber.mil (CAC users) Provide training certificates to your Agency Liaison PERSONALLY IDENTIFIABLE INFORMATION (PII TRAINING) Prior to being provisioned with an NBIS account, ADT members must have completed a DoD-approved Personally Identifiable Information (PII) training within the last 12 months and must provide the training certificate to the Agency Liaison. ADT members and the Agency Onboarding Champion that will need access to the system must complete the DoD PII training and certify completion. Once agencies begin to internally provision agency users, agencies may require users to complete either the DoD PII Training or other agency-approved PII training. DoD PII Training is available here: https://securityawareness.usalearning.gov/piiv2/index.htm. WHAT MUST BE DONE WHAT MUST BE DONE Complete DoD PII Training at https://securityawareness.usalearning.gov/piiv2/index.htm Provide training certificates to your Agency Liaison 5