SAR FAQs
Q: Who is this document for?
A: Agencies within the State of New Jersey who are looking to buy, build or otherwise acquire and/or use any new information technology assets or modify existing assets (including but not limited to: hardware, software, services, SaaS, etc.)
Q: What is the purpose, and value of the System Architecture Review process?
A: The System Architecture Review, or SAR, ensures that technology solutions for the State are conceived, designed, developed and deployed to maximize the benefits and functionality of the technology, while minimizing costs and risks.
Q: What are the key steps of the SAR process?
A: The different System Architecture Reviews (SARs) are checkpoints at specific stages of a project’s normal System Development Life Cycle (SDLC). The agency is responsible for initiating each checkpoint in the SAR process:
- Technology Initiation Proposal (TIP): Starts with Agency submitting their TIP in SimpliGov, which allows the business owner to explain the business need and high-level project details for OIT, OHSP, TRE/DPP review
- Logical SAR (LSAR): After conclusion of the TIP checkpoint, this checkpoint starts with the Agency submitting their LSAR once a solution is identified to discuss the logical design details of the project.
- Validated Design: After the closure of the LSAR checkpoint, the design from LSAR is updated by the Agency with all components, data and control flows, as well as all interfaces. The OIT Solutions Architecture team then vets the diagram with OIT and OHSP security teams.
- Implementation Review (IR): After the conclusion of Validated Design, this final SAR checkpoint starts with the agency submitting their IR document (with mandatory validated design diagram), at least two weeks before project go-live.
Q: Where can I find the appropriate workflows/ documents for each SAR checkpoint?
A: May be found on our website: https://www.nj.gov/it/whatwedo/sar/
For documents that are not in SimpliGov, submissions should go directly to the SAR team shared mailbox: OIT.SARMeeting@tech.nj.gov
Q: When should I start the SAR process for my project?
A: The SAR process should begin as early as possible in the project lifecycle, ideally before any procurement or development activities begin. Submission of a Technology Initiation Proposal (TIP) is the required first step. To ensure a smooth and timely process, please give yourself ample time to navigate all the SAR checkpoints.
Q: Why do I need the SAR process for my project?
A: SAR is mandated per policy by the State CTO. The System Architecture Review (SAR) policy document is located on the SAR website at https://nj.gov/it/whatwedo/sar/
The SAR process ensures compliance with cybersecurity, architecture standards and best practices, as well as providing for the controlled introduction of new technologies and the appropriate reuse of existing technology in order to increase returns on investment.
Per the NJ Statewide Information Security Manual (SISM), all departments and agencies must be aware of, determine classification of, and maintain an inventory of all information assets of which they are either Owners or Stewards according to the Information Asset Classification and Control standard and procedures.
Q: What are the detailed steps for the SAR checkpoints?
A: The System Architecture Review Procedure document provides details for each SAR checkpoint. The SAR procedure document is located on the SAR website at https://nj.gov/it/whatwedo/sar/
Official Site of The State of New Jersey