J-35_-_Policy_-_Departmental_Web_Policy.pdf

PDF 246 KB Posted

Attached to
Enterprise IT Shared Services (EITSS) Federal contract opportunity
Solicitation number
693JK419R500005
Issued by
Department of Transportation Immediate Office of the Secretary Transportation

About this file

This document contains a request for proposals for enterprise information technology shared services. The Department of Transportation Office of the Chief Information Officer is seeking proposals to provide infrastructure and standard operations support for the DOT Common Operating Environment. Offerors must submit 20 thumb drives containing their technical and business volume proposals in a sealed envelope to the DOT headquarters lobby between 10:00 am and 3:00 pm Eastern time on January 8, 2019. The requirement has a NAICS code of 541513 with a $27.5 million size standard. Large businesses must include a small business subcontracting plan. The unrestricted solicitation is open to all, while the small business set-aside requires the small business prime to perform 51% of the work.

J-35 - Policy - Departmental Web Policy

View the file

Other files for this federal contract opportunity

Other files attached to Enterprise IT Shared Services (EITSS), newest first.
File Type Posted
Solicitation_693JK419R500005_Amendment_4.pdf PDF
EITSS_Amendment_Schedule_-_Updated_30January2019.xlsx XLSX spreadsheet
J-42_-_Unrestricted_SF-33_-_Solicitation_Offer_and_Award.pdf PDF
EITSS_Amendment_Schedule.pdf PDF
EITSS_Final_Amendment_Cover_Letter_-_11January2019.pdf PDF
J-42_-_Small_Business_SF-33_-_Solicitation_Offer_and_Award.pdf PDF
J-37_-_EITSS_Pricing_Proposal_Template.xlsx XLSX spreadsheet
SMALL_BUSINESS_RFP__FINALVERSION_FINAL.pdf PDF
J-37_-_EITSS_Pricing_Proposal_Template_final.xlsx XLSX spreadsheet
J-42_-_SF_33_-_Solicitation_Offer_and_Award_updated_13December2018.pdf PDF
J-11_-_Critical_Incident_Management_Overview.pdf PDF
J-21_-_Infrastructure_Servers_Inventory_Final.pdf PDF
__EITSS_Cover_Page_with_Key_Deadlines_12-12-2018.pdf PDF
J-1_DOT_EITSS_-_Program_Mgmt_and_Integration_Support_PWS_-_SMALL_BUSINESS-FINAL_12-11-2018.pdf PDF
J-29-_Desktop_Laptop_Hardware_and_Wireless_Catalog.pdf PDF
_Final_RFP_Questions_and_Responses_-_12-12-2018.pdf PDF
J-3_DOT_EITSS_-_Infrastructure_Operations_PWS_-_12-12-2018.pdf PDF
J-8_-_Network_Software_and_Vendor_Support.pdf PDF
J-38_-_OST_Small_Business_Subcontracting_Plan_Template__FINAL.pdf PDF
J-24_-_Core_Image_Software.pdf PDF
J-9_-_Security_Assets_-_Hardware_and_Software.pdf PDF
J-5_-_Historical_Metrics_and_Monthly_Snapshot.pdf PDF
J-30_-_EITSS_Current_Environment_Summary-FINAL.pdf PDF
J-39_-_Disclosure_of_Lobbying_Activities.pdf PDF
J-40_-_Past_Performance.pdf PDF
J-34_-_Policy_-_National_Initiative_for_Cybersecurity_Education_(NICE)Cybersecurity_Workforce_Framework.pdf PDF
J-2_DOT_EITSS_-_End_User_Operations_PWS_FINAL-12-12-2018.pdf PDF
J-22_-_DOT_Remedy_Environment_Overview_-_Final.pdf PDF
J-13_-_Policy_-_Privacy_Policy_for_Information_Sharing_Environment.pdf PDF
J-17_-_Policy_-_Personally_Identifiable_Information.pdf PDF
J-43_-_List_of_EITSS_Required_Transition_Personnel.pdf PDF
J-36_-_Non_Disclosure_Agreement.pdf PDF
J-20_-_Databases_Supported_by_Data_Center.pdf PDF
J-23_-_COE_Approved_Software_List.pdf PDF
J-12_-_Hosting_Software_and_Vendor_Support_v2.pdf PDF
J-10_-_Infrastructure_Hardware_Inventory.pdf PDF
J-32_-_Policy_-_Data_Management_-_1351.34.pdf PDF
J-19_-_Policy_for_508_-_EIT-Accessibility-Order.pdf PDF
J-16_-_Policy_-_Privacy_Risk_Management.pdf PDF
J-33_-_Policy_-_508_Accessibility_Policy.pdf PDF
J-42_-_SF_33_-_Solicitation_Offer_and_Award.pdf PDF
J-7_-_DOT_Service_Locations_-_Final.pdf PDF
J-14_-_Policy_-_IT_Management.pdf PDF
J-28_-_Test_Lab_Volume.pdf PDF
J-27_-_Test_Lab_Inventory_and_Diagrams.pdf PDF
J-4_-_Definition_of_Terms_and_Acronyms_Final.pdf PDF
_SMALL_BUSINESS_RFP__FINALVERSION.pdf PDF
J-37_-_EITSS_Pricing_Proposal_Template_final.xlsx XLSX spreadsheet
J-31_-_Modes_and_Services_Provided.pdf PDF
J-15_-_Policy_-_Records_Management_(1351_28).pdf PDF
Show all 50

Enterprise IT Shared Services (EITSS) has more files on GovTribe.

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

DOT Order 1351.24 Departmental Web Policy

CIOP CHAPTER 24

Departmental Web Policy

TABLE OF CONTENTS

Section 24.1 Purpose

Section 24.2 Background

Section 24.3 Scope and Applicability

Section 24.4 Policy

Section 24.5 Roles and Responsibilities

Section 24.6 Dates

Section 24.7 Cancellations

Section 24.8 Compliance

Section 24.9 Waivers

Section 24.10 Audit Procedures

Section 24.11 Approval

Appendix A – Legal Authorities and Guidance

Appendix B – Glossary of Terms

Appendix C – DOT Linking Policy

Appendix D – DOT Privacy Policy

Appendix E – Adapted Privacy Impact Assessments

Section 24.1 Purpose

24.1.1 This departmental Web policy establishes policies and responsibilities for creating, managing and maintaining the U.S. Department of Transportation’s (DOT) Internet, extranet and intranet Web sites, including Web presences hosted on non “.gov” domains, for audiences both internal and external to DOT.

24.1.2 This directive cancels and replaces the Departmental Information Resources Management Manual (DIRMM) Chapter 7,” Departmental Web Policy.”

(Table of Contents)

Section 24.2 Background

24.2.1 This policy is developed in reference to and is consistent with many

DOT Order 1351.24 Page 1 of 33 existing laws and Federal policies that govern DOT information provided via the Web.

The entire list of references can be found in Appendix A, Legal Authorities and Guidance. The policy is issued under authority delegated to the Chief Information Officer (CIO) under DOT Order 1101.16A, the Organization Manual for the Office of the Secretary of Transportation, which assigns responsibility to the CIO for ensuring that DOT’s use of Information Technology (IT) complies with IT external mandates such as Section 508, Office of Management and Budget (OMB) reporting and the Privacy Act and Records Management statutes.

(Table of Contents)

Section 24.3 Scope and Applicability

24.3.1 The provisions of this chapter apply to all DOT Internet, extranet and intranet Web sites.

24.3.2 Departmental organizations may issue additional policies, instructions and/or guidance as necessary, provided they comply with existing laws, regulations and departmental policies and procedures, including this chapter.

24.3.3 Departmental utilization of social media is not addressed in this policy and will be addressed separately in a social media policy.

(Table of Contents)

Section 24.4 Policy

24.4.1 The Internet and intranet are to be used to deliver information and services efficiently and effectively and conduct business electronically. Every effort shall be made to maximize the accessibility, quality, integrity and utility of information, while protecting privacy and security. In general:

24.4.1.1 The DOT Internet homepage (www.dot.gov) is the

Department’s "face to the world." The primary audience includes people outside DOT; the public; DOT’s current and potential business partners, stakeholders and constituents; and other government entities at the Federal, State and local levels.

24.4.1.2 The Department maintains extranet sites for external audiences that require authenticated access to departmental systems.

24.4.1.3 The Department also maintains an intranet site for internal communications. The DOT intranet is a management tool to foster communications on policy and procedural matters, serve as a clearinghouse of job-related information and conduct internal business.

24.4.1.4 Departmental organizations may establish Internet and

DOT Order 1351.24 Page 2 of 33 http:www.dot.gov

DOT Order 1351.24 Page 3 of 33 intranet Web sites consistent with DOT policies. Each new or retired Internet and extranet Web site must be registered with the DOT Office of the Chief Information Officer (OCIO) on a quarterly basis. Departmental organizations with many Web sites may register groups of sites and shall review their registered sites on an annual basis.

24.4.1.5 Web sites for groups or organizations not part of DOT's official organizational structure may not be created and stored in DOT infrastructure using DOT equipment. Examples of such groups may include, but are not limited to, Federal Advisory Committees, national partnerships such as the Safe Routes to School National Partnership and the Interagency Sustainable Communities Partnership. Waivers may be granted through the process outlined in Section 24.9.3 of this policy.

24.4.1.6 Endorsements of specific organizations, products or

services, commercial sponsorships or advertisements may not appear on official DOT Web sites available to the public, including sites hosted by private contractors.

24.4.1.7 All DOT Web sites, including unofficial presences on non “.gov” domains and those using third-party content rendering applications, shall make proper use of the seal or signature, as outlined in DOT Order 1000.14A, Official Seal and Signatures of the Department of Transportation.

24.4.2 All DOT Web sites must abide by DOT’s domain naming convention.

Specifically:

24.4.2.1 In accordance with OMB Memorandum M-05-04, “Policies for Federal Agency Public Web sites,” official DOT Web sites shall use a “.gov” domain unless the departmental organization head determines another domain is necessary for the proper performance of an agency function. Exceptions must be approved per the waiver process outlined in Section 24.9.1 of this policy.

24.4.2.2 DOT may also maintain unofficial presences on non-“.gov” domains, provided that:

24.4.2.2.1 The Terms of Service (TOS) of such third-party presence providers are reviewed, approved and agreed to by appropriate parties and use of this presence is registered with the Office of the CIO.

24.4.2.2.2 Content intended to be official that is posted to the third-party presence is retained on an official “.gov” site and visitors to the third-party presence are properly directed to an official “.gov” site for official content.

Furthermore, if the third-party presence is used to solicit feedback, an official DOT e-mail address that users can also send feedback shall be provided.

DOT Order 1351.24 Page 4 of 33

24.4.2.2.3 Non-“.gov” domains may be aliased to a “.gov” domain provided the waiver process outlined in Section 24.9.4 of this policy is followed.

24.4.2.2.4 Use of such presences is in compliance with the DOT social media policy as well as the privacy and security requirements outlined in 24.4.7.2.

24.4.3 All DOT Web sites, both Internet and intranet shall comply with the technical requirements of Section 508 of the Rehabilitation Act of 1973 (29 U.S.C 794d), which requires that all Federal Web sites be designed to make information and services accessible to individuals with disabilities.

24.4.4 DOT public Web sites shall comply with Executive Order 13166, Improving Access to Services for Persons with Limited English Proficiency, which requires meaningful access to services consistent with, and without unduly burdening, the fundamental mission of DOT.

24.4.5 In accordance with OMB’s Information Quality guidelines, DOT public Web sites shall maintain a basic standard of quality (objectivity, quality and integrity), and appropriate steps shall be taken to ensure information presented on each Web site is accurate and up-to-date. The date of the page’s last update shall be included on each Web page or document.

24.4.6 DOT Web sites shall have security safeguards and management controls, consistent with National Institute of Standards and Technology (NIST) standards for encryption, in place to ensure privacy and security.

24.4.6.1 Information posted and collected on the Web is resistant to tampering–that information does not improperly change from production to consumption or from transmission to receipt.

24.4.6.2 Information collected on the Internet remains confidential, as necessary, including sensitive personal information.

24.4.6.3 Sensitive information is not made available/disclosed to unauthorized individuals, entities, devices or processes unless required by law.

24.4.6.4 DOT Web sites shall provide complete information regarding DOT Privacy Policy including meeting the following requirements:

24.4.6.4.1 Links to official DOT Privacy Policy (Appendix D of this Order), including Personally Identifiable Information (PII) Breach Notification Controls and PII Rules of Conduct and Consequences Policy, that are in Chapter 19 and 20 of the CIO Policy (CIOP) shall be posted on all DOT public Web sites.

http://www.englishfirst.org/13166/eo13166.html�

24.4.6.4.2 DOT Web sites that have a portion of the site designed for or attractive to children, or collect age in a portion designed for the general public shall comply with the Children’s Online Privacy Protection Act of 1998 (COPPA) 15 USC 6501 et seq.

24.4.6.4.3 A machine-readable version of the privacy policy (Appendix D of this Order) shall be made available on all DOT public Web sites

24.4.7 DOT Internet and extranet Web sites shall comply with information collection standards.

24.4.7.1 Review requirements for conducting a privacy impact

assessment (PIA). A PIA is needed for new or significantly changed technology that collects personally identifiable information (PII), including new collections of PII from Web sites. Departmental organizations that wish to begin collecting additional PII on their Web sites shall comply with the privacy policies outlined in CIOP Chapters 19 and 20. Adapted PIA requirements for non-”.gov” domain presences and third-party content rendering applications are outlined in Appendix E of this order.

24.4.7.2 Before using a non-”.gov” Web presence or third-party content rendering application to engage with the public, examination of the third party’s privacy policy to evaluate the risks and determine whether the Web site or application is appropriate for use shall be performed. In addition, monitoring any changes to the third party’s privacy policy and periodically reassessing the risks shall be performed regularly. To the extent feasible, a privacy notice meeting the requirements of OMB Memorandum M-10-23 “Guidance for Agency Use of Third- Party Websites and Applications” shall be posted on the non-“.gov” presence or third-party content rendering application. If it is not feasible to post a privacy notice in full, a link to a dot.gov site containing the full notice must be provided. If neither requirement can be fulfilled, the Privacy Officer shall be consulted. The privacy notice shall:

24.4.7.2.1 Explain that the Web site or application is not a government Web site or application, that it is controlled or operated by a third party, and that the DOT privacy policy outlined in Appendix D of this order does not apply.

24.4.7.2.2 Indicate whether and how the DOT will maintain, use or share PII that becomes available through the use of the third-party Web site or application, which shall be determined using the PIA outlined in Appendix E of this order.

24.4.7.2.3 Explain that by using the Web site or application to communicate with DOT, individuals may be providing non-government third parties access to PII.

DOT Order 1351.24 Page 5 of 33

DOT Order 1351.24 Page 6 of 33

24.4.7.2.4 Direct individuals to the DOT’s official Web site where they may obtain comparable information and services as an alternative to using the non-“.gov” Web presence or third-party content rendering application and where they may access DOT’s privacy policy which applies to DOT official Web sites.

24.4.7.2.5 In the event that the full privacy notice cannot be provided on the third-party’s presence, a link to a privacy notice hosted on an official DOT Web site shall be provided, to the extent feasible.

24.4.7.3 Web site forms shall comply with the Privacy Act (5 USC 552a) and the Paperwork Reduction Act (44 USC 3501, et seq). Forms that collect personally identifiable information (as defined in OMB Memorandum M-07-16) from 10 or more non-DOT employees shall be approved by OMB and include an OMB control number and burden statement. When using a presence on a non-”.gov” domain Web site or third-party content rendering application to engage with the public, only collect the minimum amount of PII necessary to accomplish a purpose required by statute, regulation or executive order.

24.4.7.4 Web sites may automatically log the type of computer, browser, Web service, as well as the date, time and pages visited. Subject to the limitations outlined below, DOT Web sites may make use of Web measurement technologies for the purpose of improving online services through analysis of usage or customization of the user’s experience. Such technologies shall comply with existing policies regarding privacy and data safeguarding standards. If applicable, the PIA and any System of Record Notice (SORN) shall be posted in accordance with the DOT privacy policy outlined in Appendix D of this order.

Under no circumstances may DOT Web sites use such technologies to:

24.4.7.4.1 Track user individual-level activity on the Internet outside of the Web site or application from which the technology originates.

24.4.7.4.2 Share the data obtained through such technologies, without the user’s explicit consent, with other departments or agencies.

24.4.7.4.3 Cross-reference, without the user’s explicit consent, any data gathered from Web measurement and customization technologies against PII to determine individual-level online activity.

24.4.7.4.4 Collect PII without the user’s explicit consent in any fashion.

24.4.7.4.5 Perform any other similar usages prohibited by OMB or

DOT.

24.4.7.5 Cookies are permitted on DOT intranet Web sites without restriction. For DOT Internet and extranet Web sites, cookies are permitted subject to the following restrictions:

24.4.7.5.1 Single session cookies are permitted, provided that their presence and information they collect is disclosed in accordance with the DOT Privacy Policy (Appendix D of this order).

24.4.7.5.2 DOT Web sites shall provide users an opt-out option for all cookie types and shall provide users with instruction on how to opt-out. The DOT Web sites shall direct users to http://www.usa.gov/optout_instructions.shtml, which contains instructions on how users can opt-out of the most commonly used cookie technologies.

24.4.7.5.3 Persistent (multi-session) cookies that do not collect PII are permitted. These include cookies that are used to record a user’s opt-out decision.

24.4.7.5.4 Persistent (multi-session) cookies that collect PII are permitted, subject to the waiver process outlined in Section 24.9.2 of this policy.

Users must opt-in to such technologies.

24.4.7.5.5 Users that choose to opt-out or do not wish to opt-in to such technologies must be able to access information that is comparable to the information available to users who do opt-in.

24.4.7.6 The data collected from the use of web measurement and cookie technologies shall be retained for only as long as necessary to achieve the specific objective for which was collected. Moreover, only employees who need to have access to the data shall be permitted access.

24.4.7.6.1 Information collected from such technologies shall be evaluated to determine if it is a Federal record; information that is a Federal record can only be disposed of as authorized in a record retention schedule that has been approved by the National Archives and Records Administration

(NARA).

24.4.7.6.2 If not/no longer required by law, policy or a specific need, the retention time for such data shall be scheduled as one year or less.

24.4.7.6.3 To the extent feasible, manual or automated technical enforcement mechanisms shall be put into place to implement stated retention times and limit access to authorized personnel.

24.4.7.7 On an annual basis, DOT shall review its use of Web

DOT Order 1351.24 Page 7 of 33 http://www.usa.gov/optout_instructions.shtml measurement and cookie technologies for compliance with the requirements of this order. The results of this review shall be posted at www.dot.gov/open, with a mechanism for the public to provide feedback on the results.

24.4.8 DOT public Web sites shall abide by the DOT linking policy, as outlined below and discussed in Appendix C.

24.4.8.1 To ensure information available on all DOT sites is

consistent and fosters DOT’s mission, each Internet homepage shall link to the DOT homepage. Similarly, each intranet homepage shall link to DOT’s intranet.

24.4.8.2 Links to any government Web site that is publicly available are permitted. Federal government-owned or sponsored Web sites will generally have “.gov,” “.mil” or “.fed.us” domains. However, some may occasionally end in “.com,” “.org” or “.net.”

24.4.8.3 Links to public or private sector partnerships with the Federal Government, State and local government Web sites are permitted.

24.4.8.4 Links must provide content that is relevant, useful and authoritative for citizens, businesses and government officials. Links shall support the service the Web site provides to the public and the DOT’s overall mission and must not:

24.4.8.4.1 Duplicate existing content on an authoritative “.gov” site.

24.4.8.4.2 Exhibit hate, bias, discrimination or other inappropriate content or facilitate access to such content.

24.4.8.4.3 Contain misleading information, unsubstantiated claims, imply endorsements or be in conflict with DOT’s mission or policies.

24.4.8.5 Measures shall be taken to reasonably ensure the

information on the linked site is accurate and useful, including regularly reviewing links on a quarterly basis to ensure they:

24.4.8.5.1 Contain information that is accurate and current.

24.4.8.5.2 Continue to function.

24.4.8.5.3 Remain pertinent to the site’s purpose.

24.4.8.5.4 Are used as intended by Web visitors.

24.4.8.5.5 Continue to add value to the Web site.

DOT Order 1351.24 Page 8 of 33 http://www.dot.gov/open�

24.4.8.6 When using a link to a non-government Web site (anything other than a Federal, State or local government Web site), users need to click and confirm on the following exit disclaimer:

You are about to access a non-government link outside of the U.S.

Department of Transportation (DOT). Our Web sites have many links to other organizations, including educational institutions and non-profit associations. Please note: While links to Web sites outside of DOT are offered for your convenience in accessing transportation-related information, please be aware that when you exit DOT Web sites, the privacy policy, including tracking technology, computer security, intellectual property protection and Section 508 of the Rehabilitation Act (accessibility requirements) no longer apply. In addition, DOT cannot attest to the accuracy, relevancy, timeliness or completeness of information provided by linked sites. Linking to a Web site does not constitute an endorsement by DOT or any of its employees of the sponsors of the site or the products presented on the site. For more information, please view DOT's Web site linking policy. To get back to the page you were previously viewing, click your browser's "Back" button.

24.4.8.7 In accordance with OMB Policy, Section 3: Establish and Enforce Agency wide Linking Policies, Section(F), agency linking policies must identify mandatory links and post (or link to) the information as appropriate.

24.4.8.7.1 The links shall be displayed as footer links on their home page and all other known major entry points to the Department’s sites.

24.4.8.7.2 Provide a link to the inventory of important information on the Web site’s home page and other major entry points.

24.4.8.7.2.1 As required by the E-Government Act of 2002 and

OMB Circular A-130, each Operating Administration (OA) shall post an inventory of information currently published on the Web site and a schedule of information that will be made available in the future.

24.4.8.7.2.2 Inventories and prioritized schedules of information distributed to the public shall be included as part of DOT’s annual E-Government Act of 2002 report submitted to OMB.

24.4.8.7.2.3 Changes to the schedule shall be posted to the Web site immediately and included in DOT’s annual E-Government report submitted to OMB.

24.4.8.7.2.4 All DOT Web sites will comply with and post, in their

DOT Order 1351.24 Page 9 of 33 http://www.usa.gov/webcontent/reqs_bestpractices/omb_policies/linking.shtml� http://www.usa.gov/webcontent/reqs_bestpractices/omb_policies/linking.shtml� required place, the required links found on WebContent.gov.

24.4.9 DOT Web sites shall provide a search feature and shall be discoverable by non-DOT search engines.

24.4.9.1 The home page and other entry points to the Web site shall provide a search function that:

24.4.9.1.1 Permits searching of and within all files intended for public use on the Web site.

24.4.9.1.2 Displays search results in order of relevancy to the search criteria.

24.4.9.1.3 Provides response times consistent with industry best practices.

24.4.9.1.4 Provides search results in an industry standard format that allows users to aggregate, disaggregate or otherwise manipulate and analyze the data for their needs.

24.4.9.1.5 Provides a DOT-approved search application, implemented by OAs, for Web site search functions.

24.4.9.2 In limited circumstances, such as for small Web sites, site maps or subject indexes may be used if they are more effective in lieu of a search function in locating the correct information quickly.

24.4.9.3 To the extent practicable and applicable, DOT Web sites will make use of search engine optimization techniques including, but not limited to, the use of meta elements and Uniform Resource Identifier (URI) schemes

24.4.9.4 DOT Web sites shall use such search engine optimization techniques in conformance with World Wide Web Consortium and Internet Engineering Task Force standards

24.4.10 DOT Web sites may make use of technology that is not resident on the official “.gov” domain to display Web content. Such technology is referred to as a “third party content rendering application,” which may be implemented provided that:

24.4.10.1 The use of third-party content rendering applications complies with the other provisions of this policy, especially the privacy and security requirements outlined in Section 24.4.7.2.

24.4.10.2 The acquisition of a third-party content rendering application DOT Order 1351.24 Page 10 of 33 http://www.usa.gov/webcontent/managing_content/organizing/links/required_links.shtml� is subject to the procedures outlined in the Transportation Acquisition Manual (TAM) (DOT Order 4200.18B) and the DOT Certification, Accreditation and Security Assessment Policy (DOT Order 1351.6)

24.4.10.3 The TOS for a third-party content rendering application is reviewed and approved by the Office of General Counsel or Chief Counsel, who shall issue a written opinion documenting approval or disapproval.

24.4.10.4 A representative from the DOT program office acting as the sponsor of the third-party content rendering application reads and certifies that they will abide by the TOS.

24.4.10.5 Use of the third-party content rendering application is registered with the DOT OCIO.

24.4.11 DOT Web sites may provide content using open standards, provided that:

24.4.11.1 To the extent practicable and appropriate, open standards for the display, streaming and subscription to content on any Internet or intranet site is used.

24.4.11.2 The acquisition of tools for generating content in an open format are subject to acquisition procedures outlined in the TAM (DOT Order 4200.18B) and DOT Certification, Accreditation and Security Assessment Policy (DOT Order 1351.6).

24.4.11.3 The TOS for a third-party tool for providing content in an open standard format application is reviewed and approved by the Office of General Counsel or Chief Counsel.

24.4.11.4 A representative from the DOT program office acting as the sponsor of the third-party tool for providing content in an open standard format reads and certifies that they will abide by the TOS.

24.4.11.5 Use of tools for generating content in an open format application is registered with the DOT OCIO.

24.4.12 Each Web page or document or Web site’s frame must include an e-mail address and/or a Web form to a designated point of contact that can provide additional information on the page’s topic.

24.4.12.1 E-mail received from DOT Web visitors shall be answered promptly and accurately, using e-mail whenever possible. Although it is not necessary to establish formal control systems to monitor Web-generated mail, content owners and Web managers will be held accountable via performance

DOT Order 1351.24 Page 11 of 33

DOT Order 1351.24 Page 12 of 33 standards for responding in a timely and accurate manner.

24.4.12.2 Responses are not required for e-mails that can reasonably be determined to be SPAM or other solicitations.

24.4.12.3 Employees receiving e-mails requesting information that could be helpful to terrorists, criminal enterprises, organized crime, foreign agents of hostile nations or considered a security threat shall advise their supervisors, who shall decide whether to inform the OA’s security coordinator (who in turn may decide to alert the Office of the Secretary of Transportation’s (OST) Office of Intelligence, Security and Emergency Response (S-60)).

(Table of Contents)

Section 24.5 Roles and Responsibilities

24.5.1 The Departmental CIO is the Office of Primary Responsibility for this policy and shall:

24.5.1.1 Provide policy and procedural guidance with respect to establishing, managing and maintaining Internet and intranet Web sites.

24.5.1.2 Advise other DOT organizations on the proper and/or

effective use of the Internet consistent with established policy, information technology architectures and capital investments.

24.5.1.3 Maintain a registry of web-related activities:

24.5.1.3.1 All Internet and intranet Web sites for the entire Department.

24.5.1.3.2 Web sites for groups or organizations that are not part of DOT's official organizational structure and that use DOT equipment.

24.5.1.3.3 Third-party Web presences on a non-”.gov” domain.

24.5.1.3.4 The use of third-party content rendering applications.

24.5.1.3.5 All Web measurement and cookie technologies across all DOT Web sites and post as part of the DOT privacy policy.

24.5.1.4 Review and approve the waiver for aliasing a third-party presence on a non-”.gov” domain to a “.gov” domain.

24.5.1.5 Review OA CIO reports on Web measurement and cookie

technologies. On an annual basis, compile these results into a report that will be

DOT Order 1351.24 Page 13 of 33 posted at www.dot.gov/open.

24.5.2 Heads of Operating Administrations shall:

24.5.2.1 Designate a single, high-level point of contact to serve as

Web Manager of their respective organization. The designated Web Manager shall be at a level in the organization high enough to manage Web initiatives throughout the organization.

24.5.2.2 Establish policies and procedures to implement all applicable policies, laws, regulations and guidance.

24.5.2.3 Provide adequate management oversight of the Web sites created by their respective organizations.

24.5.2.4 Establish procedures to provide for an annual certification to the respective departmental organization’s CIO that all Web sites comply with DOT Privacy Policy (referenced in Appendix A and detailed in Appendix D).

24.5.3 Operating Administration CIOs shall:

24.5.3.1 Approve new Web sites within their Operating

Administration.

24.5.3.2 Approve Web sites for groups or organizations that are not part of DOT’s official organizational structure and that use DOT equipment.

24.5.3.3 Maintain a registry of OA Web-related activities and report changes in the use of such technologies to the DOT CIO on a quarterly basis:

24.5.3.3.1 All Internet and intranet Web sites for the entire OA.

24.5.3.3.2 Web sites for groups or organizations that are not part of DOT's official organizational structure and that use DOT equipment.

24.5.3.3.3 Third-party Web presences on a non-”.gov” domain.

24.5.3.3.4 The use of third-party content rendering applications.

24.5.3.3.5 All Web measurement and cookie technologies used by OA Web sites

24.5.3.4 Review and approve the use of a third-party Web presence on a non-”.gov” domain and a third-party content rendering application, ensuring that such Web presences and applications are registered with the DOT OCIO.

24.5.3.5 Review and approve the waiver for aliasing a third-party presence on a non-”.gov” domain to a “.gov” domain

24.5.3.6 Review annually the results of OA Privacy Officer audits of the use of Web measurement and cookie technologies on OA Websites and take corrective action, if applicable, to maintain compliance with DOT privacy policy.

Report these results and corrective actions to the DOT CIO.

24.5.3.7 Report changes in the use of such technologies to the DOT CIO on a quarterly basis.

24.5.3.8 Review annually, the results of OA Privacy Officer audits of PII collected on non-“.gov” Web presences or third-party content rendering applications and, where necessary, take corrective action. Report these results and corrective actions to the DOT CIO.

24.5.4 Web Managers shall:

24.5.4.1 Establish procedures to implement DOT and OA Web

policies.

24.5.4.2 Make day-to-day decisions about creating Internet sites and maintenance, content, consistency, linkage with other DOT Internet sites and technical operations.

24.5.4.3 Register new Web sites or groups of sites at the same time with the DOT OCIO on a quarterly basis.

24.5.4.4 Ensure that DOT Web sites use a “.gov” domain and that the approvals from the Secretary of Transportation are in place when exceptions for domain name arise.

24.5.4.5 Initiate a review of and monitor changes to the TOS and privacy policy for a third-party Web presence on a non-”.gov” domain or third-party content rendering application.

24.5.4.6 Periodically review the TOS for a third-party Web presence on a non-”.gov” domain for changes and, if necessary, refer them for review.

24.5.4.7 Initiate the waiver process for aliasing a third-party non ”.gov” domain to a “.gov” domain.

24.5.4.8 Ensure that Web sites provide the privacy policy.

24.5.4.9 Submit written approval requests for using persistent cookies DOT Order 1351.24 Page 14 of 33 that collect PII to the Secretary of Transportation through the OA CIO’s office.

24.5.4.10 Adhere to the departmental Web policy when developing, maintaining and operating DOT internal and external Web sites. This includes providing opt-in functionality for the use of persistent cookies that collect PII and registering the Web sites that use cookies of any type with the OA CIO.

24.5.4.11 Submit the information collected through Web measurement or cookie technologies to the appropriate Records Management Officer for review and disposition of Federal records status. Maintain records in accordance with the disposition. If not required by law, ensure that this information is held for less than one year, as required by OMB Memorandum M-10-22.

24.5.4.12 Review content for compliance to Executive Order 13166, Improving Access to Services for Persons with Limited English Proficiency.

24.5.4.13 Review content and Web site functionality for compliance with Section 508 of the Rehabilitation Act of 1973 (29 U.S.C. 794d) technical standards and all applicable privacy and security laws, regulations and OMB requirements.

24.5.4.14 Implement the linking policy.

24.5.4.15 Request approval of the Web sites for groups or

organizations that are not part of DOT's official organizational structure and that use DOT equipment.

24.5.4.16 Provide a machine-readable version of the privacy policy on all DOT public Web sites.

24.5.4.17 Provide for search functions and search engine

discoverability, as outlined in section 24.4.9 of this policy.

24.5.4.18 Select and initiate a review of third-party content rendering applications.

24.5.4.19 Select, initiate a review of and implement tools for providing content using open standards, as outlined in section 24.4.11 of this policy.

24.5.5 The Department Office of General Counsel shall:

24.5.5.1 Review, negotiate and approve the TOS and outline

appropriate guidelines for use of a third-party presence on a non-”.gov” domain.

24.5.5.2 Review, negotiate and approve the TOS and outline

DOT Order 1351.24 Page 15 of 33 appropriate guidelines for the use of third-party content rendering applications on DOT Web sites.

24.5.5.3 Review, negotiate and approve the TOS and outline

appropriate guidelines for the use of tools for generating content on DOT Web sites using open standards.

24.5.6 OA Privacy Officers shall:

24.5.6.1 Review public Web pages for compliance with Section 208 of the E-Government Act of 2002 (44 USC 5301 et seq).

24.5.6.2 Review all Web sites that collect personally identifiable information for compliance with the Privacy Act of 1974 and, if appropriate, COPPA.

24.5.6.3 Review all non-“.gov” domain Web presences and third-party content rendering application privacy policies for risks and determine whether the Web site or application is appropriate for use.

24.5.6.4 Inform Departmental Privacy Officer of new public Web pages that collect personal information.

24.5.6.5 Ensure that a PIA is completed for new or significantly changed technology that collects personally identifiable information, including new collections of data from Web sites. In addition, complete an adapted PIA (see Appendix E) for non-“.gov” domain Web presences and third-party content rendering applications as outlined in OMB Memorandum M-10-23 “Guidance for Agency Use of Third-Party Websites and Applications,” .

24.5.6.6 Audit the use of Web measurement and cookie technologies to ensure that such use is in compliance with the DOT Privacy Policy. Report the results of these audits to the OA CIO.

24.5.6.7 Audit the use of non-“.gov” domain Web presences and third-party content rendering applications to ensure that they only collect the minimum amount of PII necessary to accomplish a purpose required by statute, regulation or Executive Order. Furthermore, ensure that these third-party sites post the privacy notice prescribed at 24.4.7.2, or link to it, to the extent feasible.

Report the results of these audits to the OA CIO.

24.5.6.8 Advise the departmental organizations whether a PIA needs to be developed if the organizations wish to begin collecting additional information on their Web sites.

DOT Order 1351.24 Page 16 of 33

24.5.7 Information Systems Security Officers shall:

24.5.7.1 Ensure that information posted or collected on DOT Web sites is resistant to tampering.

24.5.7.2 Ensure that information collected on DOT Web sites remains confidential, including sensitive personal information.

24.5.7.3 Ensure that sensitive information is not made

available/disclosed to unauthorized individuals, entities, devices or processes.

24.5.8 Records Management Officers shall:

24.5.8.1 Advise content owners of the appropriate records

management requirements and disposition authority (records schedules) for Web records.

24.5.8.2 Monitor content owner compliance with appropriate records management requirements and records schedules.

24.5.8.3 Advise Web managers of the Federal record status of

information collected by Web measurement or cookie technologies.

24.5.9 Content Owners shall:

24.5.9.1 Ensure that DOT Web sites do not endorse specific products or services, commercial sponsorships or advertisements.

24.5.9.2 Comply with the TOS and guidelines for use of a third party presence on a non-”.gov” domain.

24.5.9.2.1 Retain content intended to be official on an official “.gov” site.

24.5.9.2.2 Ensure that visitors to a third-party non-”.gov” presence are properly directed to an official “.gov” site for official content and, if said third-party presence is used to solicit feedback, that an official DOT e-mail address where users can also send feedback is provided.

24.5.9.3 Provide content that complies with Section 508 of the Rehabilitation Act of 1973 (29 U.S.C. 794d).

24.5.9.4 Provide content that complies with Executive Order 13166, “Improving Access to Services for Persons with Limited English Proficiency.”

DOT Order 1351.24 Page 17 of 33

24.5.9.5 Provide content that complies with OMB Information Quality Guidelines.

24.5.9.6 Ensure that any required Web site forms comply with the Privacy Act of 1974 (5 USC 552a) and the Paperwork Reduction Act (44 USC 3501 et seq).

24.5.9.7 Post the required privacy notice prescribed at 24.4.7.2 on all non-“.gov” Web presences and third-party content rendering applications, or link to it, to the extent feasible.

24.5.9.8 Take measures to ensure that links remain current, continue to work, are being used as intended by Web visitors and continue to add value to the Web site.

24.5.9.9 Respond to e-mails received from DOT Web visitors

promptly and accurately, using e-mail whenever possible.

24.5.9.10 Provide content that may take advantage of open standards.

24.5.9.11 Comply with National Archives and Records Administration (NARA) guidance for managing Web records.

24.5.9.12 Handle records in accordance with schedules prescribed by the appropriate Records Management Officer.

(Table of Contents)

Section 24.6 Dates

24.6.1 This directive is effective as of the date signed.

(Table of Contents)

Section 24.7 Cancellations

24.7.1 This directive cancels and replaces the DIRMM Chapter 7, “Departmental Web Policy” (Table of Contents)

Section 24.8 Compliance

24.8.1 If any DOT Web site is found to be using Web measurement and cookie technologies outside of the process or parameters specified in this order, the DOT Web site must immediately cease use of such technologies and inform the OA CIO of the

DOT Order 1351.24 Page 18 of 33 extent of such unauthorized use. The OA CIO and DOT CIO will respond as necessary and appropriate.

(Table of Contents)

Section 24.9 Waivers

24.9.1 Domain Name Waiver. Written approval to use a non-”.gov” domain is granted by the Secretary of Transportation, through the Departmental CIO’s office. The request shall come from the head of the Operating Administration and include:

24.9.1.1 Written justification of the compelling need to establish presence on a non-”.gov” domain

24.9.1.2 A discussion of whether a non-”.gov” presence will be considered official or unofficial. If the presence will be official, justification of why a non-”.gov” domain is appropriate

24.9.1.3 A description of the plan for conducting records

management, protecting privacy and/or confidentiality and maintaining security on the non-”.gov” presence

24.9.2 Cookie Waiver. Written approval to use persistent cookies that collect PII is granted by the Secretary of Transportation, through the Department CIO’s office. The request shall come from the head of the OA and include:

24.9.2.1 Written justification that there is a compelling need to gather the data on the site (including citation of applicable statutory and regulatory mandates), a discussion of plans for expiration of a cookie, if applicable, and a plan to review persistent cookie requirements on a periodic basis

24.9.2.2 Demonstration that appropriate and publicly disclosed privacy safeguards for handling of information derived from cookies exist;

including a description of how clear and conspicuous notice will be provided for persistent cookies

24.9.2.3 Notice of intent to use such cookies provided at

www.dot.gov/open for a minimum of 30 days. This notice and comment must be reviewed by the OA Privacy Officer, who will ensure that substantive comments have been sufficiently addressed prior to enabling such technologies. The notice must include DOT’s proposal to use such technologies and a description of how they will be used, addressing the:

24.9.2.3.1 Nature of the information collected

24.9.2.3.2 Purpose and use of the information

DOT Order 1351.24 Page 19 of 33

DOT Order 1351.24 Page 20 of 33

24.9.2.3.3 Whether and to whom the information will be disclosed

24.9.2.3.4 Privacy safeguards applied to the information

24.9.2.3.5 Data retention policy for the information

24.9.2.3.6 Identities of all third-party vendors involved in such technologies

24.9.3 Written approval for Web sites for groups or organizations not part of DOT’s official organizational structure is granted through the designated Web Manager or, for OST offices, the Departmental CIO.

24.9.4 Aliasing non-“.gov” domains to “.gov” domains. Written approval for aliasing presences hosted on “non-“.gov” domains to an official “.gov” domain is granted by the Secretary of Transportation, through the CIO’s office. The request shall come from the head of the Operating Administration and include:

24.9.4.1 Written justification that there is a compelling need to use a non-“.gov” presence

24.9.4.2 Business case for selecting a non-“.gov” presence rather than acquiring a tool to be used inside the “.gov” domain

24.9.4.3 Description of the plan for conducting records management, protecting privacy and/or confidentiality and maintaining security on the non ”.gov” presence

(Table of Contents)

Section 24.10 Audit Procedures

24.10.1 The DOT CIO, OA CIOs, OA Privacy Officers and Records Management Officers shall develop audit procedures as required to ensure that all Web sites, including non-“.gov” Web presences, are in compliance with this policy.

24.10.2 The DOT CIO, OA CIOs, OA Privacy Officers and Records Management Officers shall develop audit procedures as required to ensure that all Web measurement and cookie technologies are operating in compliance with this policy.

24.10.3 The DOT CIO, OA CIOs, Office of General Counsel and OA Privacy Officers shall develop audit procedures as required to ensure that all non-“.gov” Web presences and third-party content rendering applications in use across DOT are in compliance with this policy.

(Table of Contents)

Appendix A – Legal Authorities and Guidance DOT Orders and Guidance

DOT Order 1000.14A – Official Seal and Signatures of the Department of Transportation

DOT Order 1351.6 – Certification, Accreditation, and Security Assessments

DOT Order 1351.20 – U.S. Department of Transportation Rules of Conduct and Consequences Policy Relative to Safeguarding Personally Identifiable Information

DOT Order 1351.29 – Paperwork Reduction Act (PRA) and Information Collection Request (ICR)

DOT Order 4200.18B – Transportation Acquisition Manual

Departmental Information Resources Management Manual, Chapter 2 “Electronics and Information Technology”

Departmental Information Resources Management Manual, Chapter 9 “Departmental Records Management Program”

Statutory Considerations Children’s Online Privacy Protection Act of 1998

Computer Fraud and Abuse Act of 1986

Computer Security Act of 1987

E-Government Act of 2002

Electronic Communications Privacy Act of 1986

Electronic Signatures in Global and National Commerce Act

Federal Advisory Committee Act

Federal Records Act of 1950

Freedom of Information Act 1991 and amendments

Government Paperwork Elimination Act of 1999 DOT Order 1351.24 Page 22 of 33 http://www.ftc.gov/ogc/coppa1.htm� http://www.law.cornell.edu/uscode/18/1030.html� http://csrc.nist.gov/groups/SMA/ispab/documents/csa_87.txt� http://www.gpo.gov/fdsys/pkg/PLAW-107publ347/content-detail.html� http://www.law.cornell.edu/uscode/18/usc_sup_01_18_10_I_20_119.html� http://www.ftc.gov/os/2001/06/esign7.htm� http://www.archives.gov/federal-register/laws/fed-advisory-committee/� http://www.law.cornell.edu/uscode/html/uscode44/usc_sup_01_44_10_31.html� http://www.justice.gov/oip/amended-foia-redlined-2010.pdf� http://frwebgate.access.gpo.gov/cgi-bin/getdoc.cgi?dbname=105_cong_public_laws&docid=f:publ277.105.pdf�

DOT Order 1351.24 Page 23 of 33

Paperwork Reduction Act of 1995

Privacy Act of 1974, as Amended

The 1998 Amendments to the Rehabilitation Act of 1973 (Section 508)

5 CFR Part 2635, Standards of Ethical Conduct for Employees of the Executive Branch

5 CFR Chapter L and 49 CFR Part 99, Supplemental Standards of Ethical Conduct for Employees of the Department of Transportation

Executive Orders Executive Order 13166, Improving Access to Services for Persons with Limited English Proficiency

Executive Order 13103, Computer Software Piracy

Executive Orders 12674 and 12731 Principles of Ethical Conduct of Government Officers and Employees

Presidential Memoranda Electronic Commerce (July 1, 1997)

Successes and Further Work on Electronic Commerce (November 30, 1998)

Electronic Government (December 17, 1999)

Privacy and Personal Information (May 14, 1998)

Office of Management and Budget (OMB) Circular A-130, Management of Federal Information Resources

OMB Information Quality Guidelines

OMB Memoranda Implementation of the Government Paperwork Elimination Act

Guidance on Implementing the Electronic Signatures in Global and National Commerce Act

Guidelines for Implementing the Executive Order on Computer Software http://www.archives.gov/federal-register/laws/paperwork-reduction/� http://www.justice.gov/opcl/privstat.htm� http://www.access-board.gov/about/laws/rehab-508.htm� http://www.access.gpo.gov/nara/cfr/waisidx_01/5cfr2635_01.html� http://www.access.gpo.gov/nara/cfr/waisidx_01/5cfr2635_01.html� http://www.access.gpo.gov/nara/cfr/waisidx_00/49cfr99_00.html� http://www.access.gpo.gov/nara/cfr/waisidx_00/49cfr99_00.html� http://www.justice.gov/crt/cor/Pubs/eolep.php� http://www.justice.gov/crt/cor/Pubs/eolep.php� http://frwebgate.access.gpo.gov/cgi-bin/getdoc.cgi?dbname=1998_register&docid=fr05oc98-130.pdf� http://www.usoge.gov/laws_regs/exec_orders/eo12674.pdf� http://www.usoge.gov/laws_regs/exec_orders/eo12731.pdf� http://www.estrategy.gov/documents/ecpress.cfm� http://govinfo.library.unt.edu/npr/library/direct/memos/elecgovrnmnt.html� http://govinfo.library.unt.edu/npr/library/direct/memos/elecgovrnmnt.html� http://www.whitehouse.gov/omb/memoranda/m00-10.html� http://www.whitehouse.gov/omb/memoranda_m99-05-a/� http://www.whitehouse.gov/sites/default/files/omb/assets/omb/circulars/a130/a130trans4.pdfhttp:/www.whitehouse.gov/omb/circulars/a130/a130trans4.html� http://www.whitehouse.gov/sites/default/files/omb/assets/omb/circulars/a130/a130trans4.pdfhttp:/www.whitehouse.gov/omb/circulars/a130/a130trans4.html� http://www.whitehouse.gov/omb/fedreg_final_information_quality_guidelines/� http://www.whitehouse.gov/omb/fedreg/gpea2.html� http://www.whitehouse.gov/omb/memoranda/m00-15.html� http://www.whitehouse.gov/omb/memoranda/m00-15.html� http://www.cio.gov/Documents/guideline_eo_13103_nov_1999.html�

Piracy

Security of Federal Information Systems

Securing Electronic Government

Guidance for Implementing the Privacy Provisions of the E-Government Act of 2002

Policies for Federal Agency Public Web sites

Reporting Instructions for the Federal Information Security Management Act and Agency Privacy Management

Guidance for Online Use of Web Measurement and Customization Technologies

Guidance for Agency Use of Third-Party Websites and Applications

Other Guidance NARA Guidance on Managing Web Records

NARA Regulations for Records Management (2 CFR Parts 1200-1210)

NIST Special Publication 800-44, Guidelines on Securing Public Web Servers

(Table of Contents)

DOT Order 1351.24 Page 24 of 33 http://www.whitehouse.gov/omb/memoranda/m99-20.html� http://www.cio.gov/Documents/secure_elec_govt_Jan_2001.html� http://www.whitehouse.gov/omb/memoranda/m03-22.html� http://www.whitehouse.gov/omb/memoranda/m03-22.html� http://www.whitehouse.gov/omb/memoranda/fy2005/m05-04.pdf� http://www.whitehouse.gov/sites/default/files/omb/assets/memoranda_2010/m10-15.pdf� http://www.whitehouse.gov/sites/default/files/omb/assets/memoranda_2010/m10-15.pdf� http://www.whitehouse.gov/omb/assets/memoranda_2010/m10-22.pdf� http://www.whitehouse.gov/omb/assets/memoranda_2010/m10-22.pdf� http://www.whitehouse.gov/omb/assets/memoranda_2010/m10-23.pdf� http://www.archives.gov/records-mgmt/policy/managing-web-records-index.html� http://www.archives.gov/about/regulations/subchapter/b.html� http://csrc.nist.gov/publications/nistpubs/800-44-ver2/SP800-44v2.pdf� http://csrc.nist.gov/publications/nistpubs/800-44-ver2/SP800-44v2.pdf�

Appendix B – Glossary of Terms Term Definition

Departmental Organization

An office within the Office of the Secretary, an Operating Administration or other comparable element of the Department.

Dissemination The government-initiated distribution of information to the public.

Dissemination Product Any book, paper, map, machine-readable material, audiovisual production or other documentary material, regardless of physical form or characteristic, disseminated by an agency to the public.

Embedded Object An object created with one application and embedded into a document created by another application. Embedded object may include an object, of a media type, including graphics. Embedding the object, rather than simply inserting or pasting it, ensures that the object retains its original format.

Exit Disclaimer A disclaimer is generally any statement intended to specify or delimit the scope of rights and obligations that may be exercised and enforced by parties in a legally-recognized relationship.

Also referred to as “Exit Page”, “Redirect”, ”Pop-Up” extranet A public-private Website or portal, secured or password-protected, specifically designed for selected workers in an organization and selected external partners to conduct internal business.

Home Page The top-level or main page for an organization, business, subject, person, etc. It is commonly the first page displayed when connecting to a Web site, but may also refer to the introductory page for a collection of Web pages.

Machine-Readable It is a format that a computer can accept. Machine readable-data includes files stored on disk or tape or data that comes from a device connected to a computer.

Official DOT Web site A Web site or a collection of Web pages that contains the official source of information about DOT i.e., a “.gov” page that is maintained by the government. (i.e., a Federal, state or local government) Web site.

Open Standard An Open file format is a published specification for storing digital data, usually maintained by a standards organization, which therefore can be used and implemented by anyone. Open formats are also called free file formats, if they are not encumbered by any copyrights, patents, trademarks, or other restrictions so that anyone may use it at no monetary cost for any desired purposes.

DOT Order 1351.24 Page 25 of 33…

This is the start of the file's text. The full file is on GovTribe.

File details come from the government source that posted it. Updated .