The Executive Office for U. S. Attorneys (EOUSA) and United States Attorneys’ offices (USAOs) must insure the integrity, security and efficiency of all information technology (IT) systems procured, developed, and deployed in its offices. Toward that end, the Director, EOUSA shall lead a corporate senior management team chartered to assure all new and major enhanced IT systems are developed, maintained and continuously evaluated in an integrated manner as follows:
- 1. Enterprise Architecture (EA) Management: The institutional blueprint which defines both the business and the supporting technology for the EOUSA and USAOs’ current mission, strategic plans, and target operating environments. The EA also defines the roadmap to achieve mission and strategic plan support within the target environment. This blueprint and the acquisition roadmap are to be updated on at least an annual basis.
- 2. IT Investment Management: Using an established, structured process, the selection of new/enhanced IT projects, assuring that each supports mission and user needs. The resulting portfolio of investments shall be evaluated at least semiannually within the context of the USAO enterprise architecture, and reviewed in terms of progress in meeting cost and schedule milestones.
- 3. IT Security Management: The protection of the integrity, confidentiality, and availability of the USAOs’ IT assets, resulting in the reduction of the risks of tampering, unauthorized intrusions and disclosures, and disruption of operations. IT security policies and controls shall be established centrally, with the performance of continuous business risk analyses and the implementation, maintenance, monitoring and evaluation of the effectiveness of policies and controls. A comprehensive report shall be delivered at least annually on the state of IT security management.
- 4. System Acquisition Management: The management of major system investments (major system projects) in a manner that increases the probability of promised system capabilities being delivered on time and within budget. Acquisition of major systems shall be done in a rigorous and disciplined manner to reduce the risk of fielding systems that do not perform as intended, are delivered late, or cost more than planned. All major system contracts shall be planned, tracked, and required deliverables monitored for timeliness and quality by the acquisition organization as well as by the technical project manager.
- 5. Electronic Records System Management. Pursuant to the requirements of the e-Government Act of 2002, EOUSA shall implement processes and procedures to manage electronic records in all existing EOUSA and USAO electronic records systems; identify and schedule electronic records in these systems; transfer to NARA permanent electronic records from existing or legacy systems according to National Archives and Records Administration (NARA) approved records schedules and using NARA-approved electronic formats; and implement procedures to assure the timely destruction of temporary records according to NARA-approved records schedules. Likewise, EOUSA shall assure the inclusion of records management capabilities into all newly developed systems generating Federal records, specifically including functionalities to identify and transfer to NARA records of permanent or potentially permanent value.
EOUSA shall document and execute systems acquisitions consistent with industry-standard capability maturity model best practices and procedures and in compliance with all legal and regulatory requirements.
[updated February 2018]