1.93k likes | 1.95k Views
Get updates on the latest developments and improvements in Federal Student Aid software systems, including improved alignment with business processes, enhanced data management, streamlined processes, and increased security.
E N D
Federal Student Aid Software Developers Conference August 16, 2007
WELCOME Katie Blot
Outcomes • Improved alignment of systems with Federal Student Aid business processes, and reduced redundancy and complexity of interfaces among systems • Improved consistency and quality of Person and Organization data through implementation of master data management • Reduced redundancy and duplication of effort through use of shared assets (e.g., Security Architecture, Enterprise Portal, etc.) • Improved security and streamlined processes for gaining access to Federal Student Aid systems and services • Improved timeliness and accuracy of data through reengineered process flows and implementation of data standards
Progress to Date • Three Key Areas • Infrastructure • Application Development • Supporting Processes
Infrastructure • Enterprise Portal • Technical Proof of Concept Complete • Infrastructure Deployment in Process • Will Support Integrated Partner Management User Interface • Next Step: Internal “Employee View” • Enterprise Services Bus • Evolution of EAI • Technical Proof of Concept Complete • Infrastructure Deployment in Process • Will Support Integrated Partner Management Data Interfaces • Security Architecture • Deployed, Currently Supporting Nine Applications • Will Support New Participation Management Process • On the Horizon • Gateway
Application Development • Integrated Partner Management (IPM) • Requirements underway (near completion) • Infrastructure deployment in process • Operations and Maintenance contract awarded • On the Horizon • Person Data Management, Integrated Student View, Aid History Management, Application Processing, Collections
Key Supporting Processes • Requirements Standards • Development Standards • Technical Standards • Enterprise Data Management
Need for Change in How We Deliver Development Services Federal Student Aid has: • Grown its technical and process knowledge • Made significant progress in establishing integrated processes for development projects • Recognized a need for changes in the management of development projects that help achieve better results
Agenda Welcome 08:30 am – 09:00 am Security 09:00 am – 10:00 am Break 10:00 am – 10:15 am Integrated Partner Management 10:15am – 11:15 am NSLDS Update 11:15 am – 11:45 am Lunch on your own 11:45 am – 01:30 pm Common Origination Disbursement Update 01:30 pm – 02:30 pm Central Processing System Update 02:30 pm – 03:30 pm Break 03:30 pm – 03:45 pm Federal Update 03:45 pm – 04:45 pm Round Table 04:45 pm – 05:00 pm Closing 05:00 pm – 05:15 pm
Contact Information Katie Blot Chief Information Officer Phone: 202-377-3528 Email: Katie.Blot@ed.gov
SECURITY Bob Ingwalson
Defense in Depth • Policy • Personnel Security • Physical Security • Network Security • Host based Security • Application Security
Application Development Security • The Bad • The Ugly • The Good
The Bad -- Malicious Threat Application Development Security • Know the Threat • OWASP (http://www.owasp.org) • SANS Top 20 (www.sans.org/top20) • National Vulnerability Database (http://nvd.nist.gov) • cgisecurity (http//www.cgisecurity.com)
The Bad -- Malicious Threat Application Development Security Know the Threat – Hmmm?
The Bad -- Malicious Threat Application Development Security • Cross Site Scripting • What is Cross Site Scripting and how is it used? • Prevention
The Bad -- Malicious Threat Application Development Security • SQL Injection • What is SQL Injection and how is it used? • Prevention
The Bad -- Malicious Threat Application Development Security • Cookie Poisoning • What is Cookie Poisoning and how is it used? • Prevention
The Ugly – The Innocent User Application Development Security • Code Mistakes • Federal Student Aid has had them • Results • Prevention
The Ugly – The Innocent User Application Development Security • Untrained Users • Examples and outcomes • Provide the training • Rules of Behavior • Annual refresher training
The Ugly – The Innocent User Application Development Security • Keyloggers • What is it and how does it exploit a Web Application? • It doesn’t affect you right? – think again! • Some things to do about Keylogger activity
The Good – Good Development Application Development Security • Implement Prevention in Code • Train Users • Thorough Testing • Use of Tools
The Good – Good Development Application Development Security
Contact Information Name: Robert Ingwalson Chief Security Officer Chief Information Office Phone: 202-377-3563 Email: Robert.Ingwalson@ed.gov
INTEGRATED PARTNER MANAGEMENT (IPM) Susan Stallard Joseph Policella, Perot Systems
Agenda • IPM Overview • Implementation Schedule • Where We Are: Requirements • What This Means to Our Partners • Workbench Demonstration
IPM: Overview • New system that consolidates business functions currently being provided by multiple systems: • Lender Application Process (LAP) • Electronic Application (eAPP) • eZ-Audit • Participation Management portion of SAIG • Post Secondary Education Participant System (PEPS) • Electronic Records Management (ERM) • Technology modernization with associated benefits: • Single sign-on • Consistent user experience • Ease of use and navigation • Increased Security • Implemented in three releases with increasing functionality to reduce and/or eliminate risks
Implementation Timeline Release 1:April – June 2008 • Implement Partner Eligibility & Enrollment • Legacy systems retired: • eAPP • Participation Management • Lender Application (LAP) • Electronic Records Management (ERM) Release 2:July – September 2008 • Implement Financial Statements and Compliance Audits submission • Legacy system retired: • eZ-Audit Release 3: January – March 2009 • Implement Partner Oversight functions • Legacy system retired: • Post Secondary Education Participant System (PEPS)
Where We Are: Requirements Requirements Conducted (January – July 2007) • Series of three Joint Application Design (JAD) sessions held with Federal Student Aid staff to gather requirements (January to April 2007) • Extensive use of prototypes to assist in identifying and capturing requirements • Additional breakout JAD sessions and meetings held with Federal Student Aid Subject Matter Experts to capture requirements for specialized areas such as foreign schools and financial partners • Data Requirements (Data Management & Migration) • Technical Requirements
What This Means to Our Partners • Provides a single entry point to sign up for services and maintain eligibility for the Title IV program • Streamlines and simplifies through automation the process for communicating required notifications (paperless environment) to/from Federal Student Aid • Provides Partners with on-line access to school status and eligibility information and proactive notifications • Provides the capability for e-Signature on required applications and forms to establish enrollment and maintain eligibility • Increases usage of the paperless environment in the processing of compliance audit and financial statement submissions
Key Workbench Concepts • IPM Workbench will provide the foundation for single sign-on to Federal Student Aid systems • Participation Management Services are consolidated with User Management • Complex structures allow corporate entities to manage their subsidiaries with a single user experience • Affiliations provide a mechanism to manage the data and features granted to servicing partners
Partner Workbench Homepage Header Right Navigation Left Navigation Footer
IPM User/Partner Management User Profile Management – for user contact information
IPM User/Partner Management Security Architecture – debarment check, default loan check, password management and system access. • Participation Management – allocation of services • Concept of Affiliation: • Partner Users added via Partner Management • Schools and Lenders add Servicer affiliations • Servicers gain IPM identity and access • Servicers’ DPA manages their own pool of users
CPS UPDATE Ginger Klock
CPS Update Agenda • Application Processing Statistics • 2008-2009 FAFSA Changes • 2008-2009 Central Processing System Changes • Edits • EDE Applications and Corrections • 2008-2009 Institutional Student Information Record (ISIR) Changes • 2008-2009 Participation Management (PM) System • 2008-2009 CPS Test System
CPS Update Application Processing StatisticsPaper vs. Web filers through Week 29 Since 2005-2006: • Number of Web filers has increased 13.44% • Number of paper filers has decreased 64.16%