PFRDA circular · 15 Jun 2020
2 | P a g e new generation application. High Availability: The application should have 99.5% availability. It should allow online addition, deletion and modification of the software modules without any impact on aforesaid availability. BCP: The system should support a Recovery Point Objective (RPO) of zero and Recovery…
2 | P a g e new generation application. High Availability: The application should have 99.5% availability. It should allow online addition, deletion and modification of the software modules without any impact on aforesaid availability. BCP: The system should support a Recovery Point Objective (RPO) of zero and Recovery Time Objective (RTO) of near zero. Scalability: The system should provide horizontal, vertical and linear scalability without inherent bottle necks and design changes. The solution scalability should be proven by carrying out the benchmark exercise by applicant. Configurability: The system should be highly configurable and parameterized. High Capacity and Throughput: The solution should have high throughput and capacity; a solution capable of achieving a sustained throughput of 1000 Transactions Per Second (TPS) to be provided to start with. Application should be scalable to handle a throughput of 5,000 TPS and above to meet future requirements. Platform Independence: The solution should be Platform independent and should not be constrained to a single Hardware Platform or Operating System or database. Monitoring Capability: The solution must have adequate real-time monitoring of the transactions and application modules with automated alert mechanism through multiple channels. Secured: The CRA System has to be developed from approach of “secure from start” and should have all controls well defined as per regulator, industry standards (Data Security Standards, ISO) requirements and PFRDA Policies. Natively IPv6 Ready and Backward Compatible. Overview of Requirements: The applicant is expected to build necessary infrastructure for providing CRA services to various stakeholders. The services, applications and infrastructure required for this purpose are depicted in the diagram given below. It is proposed that the establishments and operationalization would be undertaken viz. building of infrastructure, operations and maintenance, and termination phase. The broad scope of the activities is described below. 1 Building of Infrastructure This involves building necessary IT infrastructure considering the requirements and Service level (SL) parameters specified. This broadly involves 3 | P a g e i. Application development o SRS preparation o Application development and implementation o User Acceptance Test ii. Application Architecture The application architecture of the solution should be one which not only fulfills the role of providing services to stake holders but also takes into account scalability in terms of growth of users, increase of stakeholders and increase in services offered by National Pension System (NPS). Pension data being financial data of the public and their life’s savings, security and confidentiality forms a crucial consideration. Also, the system is critical and needs accessibility and flexibility in terms of inter-operations with other systems. Hence, it is emphasized that the applicant should develop a technical solution considering these requirements and challenges. The broad architecture in terms of technology is illustrated in the diagram below. In nutshell the architecture should conform to open standards. Considering the diverse functional requirements, the sub architectures can be categorized as under 4 | P a g e • The application sub architecture • The data management sub architecture (a) Application sub Architecture Application sub architecture describes the technology and standards that facilitate communication and functional interface between systems, both at module-to-module level or intra-application level, and at the application- to-application or inter-application level. The application sub architecture domain therefore encompasses the aspects of communication (inter and intra-application) and integration. The scope is to provide a framework under which the CRA application system can be integrated to improve service delivery and business value. These are indicative guidelines, however, the applicant is expected to arrive at an appropriate solution. The diagram below shows the application sub architecture. The suggested components would be as follows: Application Server: This is the main application engine where the core application will be hosted.This will provide the core functionalities and will be connected to the database layer. Web Server: The solution is a web based application, therefore, a web server component is necessary for hosting. 5 | P a g e Directory Server: The system is expected to have a single sign on The directory server is to facilitate this function and allow for Single sign on services. Mail/Messaging Server: This component will take care of the mail and messaging needs of the application. The major chunk of communications will be through e-mails and messages. (b) Data Management sub Architecture This architecture covers the business and technical aspects of managing data and the database environment. The structure of the data management system should reflect a lifecycle approach to data management such as collection from the end users, analysis and planning, acquisition, use, operation and maintenance, archiving and disposal. The data management framework encompasses business rules to ensure the security and consistency of data. The system should: • Provide the NPS with a framework for best practices in data management • Facilitate effective management of NPS data within legislative and regulatory guidelines. • Provide highly secure environment for storing the data iii. Data Management Framework Requirements (Data transfer pertaining to the PRANs opting for CRA) o Preparation of Data Migration (Transfer) strategy o Data Migration (Transfer) for interoperability o System driven co-ordination of data. As data is the most critical component of the entire solution, it is emphasized that a data management framework should be in place for the proper use of data. This should not only consist of the technical infrastructure, but also the proper manpower and security infrastructure. • Data management activities should be planned and governed, based upon business needs with relevance to the highly critical and sensitive nature of the NPS data • Data should be acquired, updated and catalogued in a coordinated manner and in accordance with agreed standards regarding acquisition, access, storage and dissemination. • There should be a policy framework, mechanisms, audit procedures and training in 6 | P a g e the CRA for proper use of the data. At every step, representatives of the PFRDA have the right to check these mechanisms and have their comments incorporated • The database should be established for ensuring data integrity, risk management and availability. • The data should be archived and disposed of in accordance with best practices and security guidelines. • The applicant should have an established data management framework that ensures effective storage, retrieval, access, sharing, privacy and security are maintained for operational processing and analysis. • There should be accountability for data management. • In this context, it should maintain regimes for data integrity, data identification and maintain an inventory of all data holdings. • It should account for the value and expected lifespan of the data assets. • It should have metadata repositories, which provide details of location, content and business purpose. • The CRA should have a coordinated and published plan and means for data capture. • It should be able to implement an integrated data coordination framework to leverage existing systems in data acquisition and holding. • It should provide clear communication and education regarding proper and improper use of data. The applicant should have clear formulated policies regarding the items mentioned below which will form the basis of their data management solution: • Use of data in transactional and analytical processing • Brokerage, duplication and partitioning • Use of data in management support systems and data warehouses • Authoritative source and instances of data records • Database management systems and open standards • Backup and recovery • Access management • Data integration Replication and warehousing Data archival and disposal in accordance with relevant legislation, standards and guidelines • It should ensure that business data access and usage is audited.