Attachment 13- System Privacy Baseline Process Requirements.pdf

PDF 355 KB Posted

Attached to
Nationwide Default Management Services (NDMS) Federal contract opportunity
Solicitation number
12SAD222R0001
Issued by
Not on record

View the file

Other files for this federal contract opportunity

Other files attached to Nationwide Default Management Services (NDMS), newest first.
File Type Posted
12SAD122R0001_amendment0008.pdf PDF
Uncontested Foreclosure Cases and Contested Foreclosure Hours_Amendment0008.xlsx XLSX spreadsheet
12SAD122R0001-NDMS RFP_amendment0008.pdf PDF
Attachment G - Offeror Questions Template_amendment0008.pdf PDF
12SAD122R0001-NDMS RFP_amendment0007.pdf PDF
Attachment E - IDIQ TEP Workbook_amendment0007.xlsx XLSX spreadsheet
12SAD122R0001_amendment0007.pdf PDF
Attachment 11- Performance Work Statement_amendment0007.docx DOCX document
12SAD122R0001- NDMS RFP_amendment0006.pdf PDF
12SAD122R0001_amendment0006.pdf PDF
12SAD122R0001_amendment0005.pdf PDF
12SAD122R0001- NDMS RFP_amendment0005.pdf PDF
12SAD122R0001_amendment0004.pdf PDF
12SAD122R0001- NDMS RFP_amendment0004.pdf PDF
12SAD122R0001_amendment0003.pdf PDF
12SAD122R0001 - NDMS RFP_amendment0003.pdf PDF
12SAD122R0001- NDMS RFP_amendment0002.pdf PDF
12SAD122R0001_amendment0002.pdf PDF
Attachment E- IDIQ TEP Workbook_amendment0001.xlsx XLSX spreadsheet
Attachment 11- Performance Work Statement__amendment0001.docx DOCX document
12SAD122R0001_amendment0001.pdf PDF
12SAD122R0001 - NDMS RFP_amendment0001.pdf PDF
Attachment G- Offeror Questions Template_amendment0001.pdf PDF
Attachment 02 - PMO 20.4-1 USDA RD Visual Identity Guidelines.pdf PDF
Attachment F- USDA RD Properties Sold with Average Sale Price by State and UPB.pdf PDF
Attachment 10- AD-3030 Representations Regarding Felony Conviction.pdf PDF
Attachment 08 - NDMS Task Order Procedures.docx DOCX document
Attachment A - Past Performance Cover Letter and Questionnaire.doc DOC document
Attachment 09- NDA Rural Development.pdf PDF
Attachment 01- Network Access Security Policy.pdf PDF
Attachment 05 - Quality Control Plan.docx DOCX document
Attachment 07 - Subcontracting Plan.docx DOCX document
Attachment G- Offeror Questions Template.xlsx XLSX spreadsheet
Attachment 11- Performance Work Statement.docx DOCX document
Attachment D - Oral Presentation Instructions.docx DOCX document
Attachment E - IDIQ TEP Workbook.xlsx XLSX spreadsheet
Attachment C - Cross Reference Matrix.xlsx XLSX spreadsheet
Attachment H- Forclosure Unpaid Principal Balance as of June 2021.xlsx XLSX spreadsheet
12SAD122R0001 - NDMS RFP.pdf PDF
Attachment 12- Background Investigation Requirements.pdf PDF
Attachment 06 - Attorney Approval Request Template.docx DOCX document
Attachment B - Subcontracting_Plan_TEMPLATE.docx DOCX document
Attachment 03 - Program Management Plan.docx DOCX document
Attachment 04 - Vendor Management Plan.docx DOCX document
Show all 44

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

January 29, 2021 Version 2.0

RD Cybersecurity

RD System Privacy Baseline Process and Requirements

Rural Development Business Center

USDA RD

WASHINGTON, D.C.

RD OCIO Privacy Baseline Requirements

Table of Contents Revision History

1. Introduction

1.1 Purpose

1.2 Scope

1.2.1 In Scope Controls

1.3 Authority

2 System Privacy Baseline Implementation Process

2.1 Process Overview

2.2 Assumptions

2.3 Process Details

2.3.2 Identify Project Specific Privacy Requirements

2.3.3 Complete and Submit a Privacy Requirements Matrix

2.3.4 Review and Confirm Project Specific Privacy Requirements

2.3.5 Implement Privacy Requirements through System Development Life Cycle (SDLC)

3 RD Privacy Baseline Requirements Appendix A - Definitions

Privacy Personally Identifiable Information Privacy Act Statement

Appendix B – Privacy Roles and Responsibilities Chief Information Officer (CIO) RD Chief Privacy Officer (CPO) RD Privacy Team Lead RD IT Privacy Team RD Security Team System Owners Project Managers System Designers & Engineers

Appendix C - Privacy Requirements Matrix Template Appendix D: References http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r4.pdf http://csrc.nist.gov/publications/nistpubs/800-122/sp800-122.pdf http://www.justice.gov/opcl/privstat.htm http://csrc.nist.gov/publications/fips/fips199/FIPS-PUB-199-final.pdf

Appendix E: Acronyms

1. Introduction

1.1 Purpose

Due to the usage of personally identifiable information (PII), there are a number of information systems within the United States Department of Agriculture (USDA) Rural Development (RD) that must be compliant with federal mandates that cover privacy. This document is intended to assist the system owners, project managers, project teams, system designers and system engineers with the implementation of privacy controls.

National Institute of Standards and Technology (NIST) Special Publication (SP) 800-37 defines two approaches for the selection of security and privacy controls: a baseline control selection approach and an organization generated control selection approach. The baseline control selection approach uses control baselines, which are predefined sets of controls specifically assembled to meet the protection needs of a group, organization, or community of interest. The control baselines serve as a starting point for the protection of individuals’ privacy, information, and information systems. The focus of this document is the baseline control selection.

NIST SP 800-53 Revision 4 (Rev 4) provided a Privacy Control Catalog, in Appendix J (Appendix), that was intended to address the privacy needs of federal agencies. The Appendix provided a structured set of privacy controls, based on best practices, that help organizations comply with applicable federal laws, Executive Orders, directives, instructions, regulations, policies, standards, guidance, and organization-specific issuances; and established a linkage and relationship between privacy and security controls for purposes of enforcing respective privacy and security requirements which may overlap in concept and in implementation.

NIST SP 800-53 Rev 5 was published in September 2020 to provide changes to make the security and privacy controls more usable by diverse groups and integrated information security and privacy controls into a seamless, consolidated control catalog for information systems and organizations. Control baselines and tailoring guidance was transferred from NIST SP 800-53 Rev 5 to NIST SP 800-53B, also in September 2020. NIST SP 800-53 Rev 5 is superseding NIST SP 800-53 Rev 4, as such Rev 4 will be withdrawn on September 23, 2021. Until further guidance is received from the Department, the privacy controls guidance provided in Rev 4 will be implemented and followed.

NIST SP 800-53B provides that security and privacy control baselines are predefined sets of controls specifically assembled to address the protection needs of groups, organizations, or communities of interest. The control baselines serve as a starting point for the protection of individuals’ privacy, information, and information systems and can be tailored (i.e., customized)—appropriately taking into account organizational missions and business functions, specific and credible threat information, the environment in which the organization operates, and individuals’ privacy interests. The concept of a control baseline is introduced to assist organizations in selecting a set of controls for their systems that is commensurate with security and privacy risk. SP 800-53B—along with other supporting NIST publications—is designed to help organizations identify the security and privacy controls needed to manage risk and to satisfy the security and privacy requirements in FISMA, the Privacy Act of 1974, selected OMB policies (e.g., OMB A-130), and designated Federal Information Processing Standards (FIPS), among others.

The concept of a control baseline is introduced to assist organizations in selecting a set of controls for their systems that is commensurate with security and privacy risk. Privacy programs are responsible for managing the risks to individuals associated with the creation, collection, use, processing, dissemination, storage, maintenance, disclosure, or disposal (collectively referred to as “processing”) of personally identifiable information (PII) and for ensuring compliance with applicable privacy requirements. When a system processes PII, the information security and privacy programs have a shared responsibility to manage the impacts to individuals that arise from security risks and collaborate to determine the security categorization and the selection and tailoring of controls from the security control baselines.

Organizations conduct privacy risk assessments that consider the nature of the PII processing and its impact on individuals to guide the tailoring of the privacy control baseline for their programs and systems. The objective of this document is to generate a set of privacy controls that will apply only at the information system level, so system engineers and designers can use the requirements as a guide when implementing privacy controls.

1.2 Scope

The RD System Privacy Baseline Process and Requirements represent the privacy baseline controls that are consistent with the information types and information systems that align with a scope of coverage governed by NIST SP 800-53 Rev 4, applicable federal laws, Executive Orders, directives, policies, standards, and/or regulations. RD privacy baseline requirements are applicable to all information systems that contain Personally Identifiable Information (PII) at USDA RD. It is important that organizations consider how privacy and security programs collaborate in activities related to these controls, such as categorization, tailoring, implementation, and assessment.

Due to the fact that NIST SP 800-53 Rev 4 has been updated to NIST SP 800-53 Rev 5, and will be withdrawn on September 23, 2021, the RD System Privacy Baseline Process and Requirements will be revised at that time to reflect the most current guidance provided by the Department.

Elements of NIST 800-122 were also used in the creation of the RD System Privacy Baseline Process and Requirements, as were Fair Information Practice Principles (FIPPs): transparency; individual participation; purpose specification; data minimization; use limitation; data quality and integrity; security and accountability; and auditing.

In a few instances, controls will be customized by the RD IT Privacy team if RD systems process data governed by the following legislations:

Gramm-Leach Bliley Act Health Insurance Portability and Accountability Act (HIPAA)

HITECH

other E-Government Act related privacy control translations

Furthermore, the RD system privacy baseline process and requirements will extend the coverage to cloud and mobility-based information systems when they become available or are utilized by RD in the future.

The control baselines can be implemented by any organization that processes, stores, or transmits Information. This document is applicable to information technology system owners, project managers, project teams, system designers and system engineers. In many cases, the Security Team will provide this document to project managers who would then be required to comply with RD system privacy baseline process and requirements.

1.2.1 In Scope Controls

The following table illustrates the privacy controls, contained in Appendix J of NIST SP 800-53 Rev 4, that are currently applicable for all RD information systems that contain PII:

Control

ID

Control Family In Scope Controls

AP Authority and Purpose AP-2

AR Accountability, Audit, Risk Management AR-2(b), AR-7

DI Data Quality and Integration DI-1(a), DI-1(b), DI-1(c), DI-1(d), DI-1(1)

DM Data Minimization and Retention DM-1(a), DM-1(b), DM-1(1), DM-2(a), DM-2(b), DM- 2(c), DM-2(1), DM-3, DM-3(1)

IP Individual Participation and Redress IP-1(a), IP-1(b), IP-1(c), IP-1(d), IP-1(1), IP-2, IP-3

TR Transparency TR-1(a), TR-1(b)

UL Use Limitations UL-1, UL-2(a), UL-2(b), UL-2(d) Table 1: In Scope Controls

Note: NIST SP 800-53, Revision 4, has been superseded by NIST SP 800-53, rev. 5 and will be withdrawn on September 23, 2021. The Privacy Control Baseline guidelines provided in this document are applicable to privacy controls contained in Appendix J of NIST SP 800-53 Rev 4, until revised by Department guidance.

1.3 Authority

Executive Branch Policy

Office of Management and Budget (OMB) Circular A-123, Management’s Responsibility for Enterprise Risk Management and Internal Control, July 15, 2016

OMB Circular A-123, Appendix A, Management of Reporting and Data Integrity Risk (Revised June 6, 2018)

OMB Circular A-130, Managing Information as a Strategic Resource, July 2016 OMB Memorandum M-17-12, Preparing for and Responding to a Breach of Personally

Identifiable Information

Applicable Laws, Guidelines, Regulations, and Guidance Directives

Privacy Act of 1974, 5 U.S.C. § 552a, as amended National Information Infrastructure Protection Act of 1996, Public Law 104-294 E-Government Act of 2002, Public Law (P.L.) 107-347 (44 U.S.C. §3501 note), which includes

Federal Information Security Management Act of 2002 (FISMA), 44 U.S.C. §3541, November 2000, as revised to Federal Information Security Modernization Act of 2014 (also known as FISMA), (44 U.S.C. §3551), December 2014

Presidential Policy Directive 21 (PPD-21), Critical Infrastructure Security and Resilience, February 2013

Computer Matching and Privacy Protection Act of 1988, P.L. 100-503, October 1988 (commonly referred to as the Computer Matching Act)

National Institute of Standards and Technology (NIST) Special Publications (SP) 800-37 Revision 2: Risk Management Framework for Information Systems and Organizations: A

System Life Cycle Approach for Security and Privacy, December 2018 NIST SP 800-53, Revision 4, Security and Privacy Controls for Federal Information Systems and

Organizations, January 2015 (Note: superseded by NIST SP 800-53, rev. 5 and will be withdrawn on September 23, 2021)

NIST SP 800-53, Revision 5, Security and Privacy Controls for Information Systems and Organizations, September 2020

NIST SP 800-53A, Revision 4, Assessing Security and Privacy Controls in Federal Information Systems and Organizations: Building Effective Assessment Plans, December 2014 (Updated 12/18/2014)

NIST SP 800-53B Control Baselines for Information Systems and Organizations, October 2020 NIST SP 800-61, Revision 2: Computer Security Incident Handling Guide, August 2012 NIST SP 800-122 Guide to Protecting the Confidentiality of Personally Identifiable Information

(PII), April 2010

USDA Internal Regulations

Departmental Manuals DM 3440-001, USDA Classified National Security Information Program Manual, June 09, 2016 DM 3510-001, Physical Security Standards for Information Technology (IT) Restricted Space, August 19, 2004 DM 3525-000, USDA Internet and E-mail Security, February 17, 2005 DM 3550-002, Sensitive but Unclassified (SBU) Information Protection, February 17, 2005

Departmental Regulations DR 1700-002, OIG Organization and Procedures, June 17, 1997 DR 3080-001, Records Management, August 16, 2016 DR 3505-005, Cyber Security Incident Management Policy, November 30, 2018 DR 3140-001, USDA Information Systems Security Policy, May 15, 1996 DR 3180-001, Information Technology Standards, May 12, 2015 DR 3300-001, Telecommunications & Internet Services and Use, March 18, 2016 DR 3440-001, USDA Classified National Security Information Program Regulation, June 09, DR 3440-002, Control, and Protection of “Sensitive Security Information”, January 30, 2003 DR 3545-001, Information Security Awareness and Training Policy, October 22, 2013 DR 4070-735-001, Employee Responsibilities and Conduct, October 04, 2007 DR-4080-811-02 Telework Program, January 04, 2018

Rural Development Memorandum

Protecting Personally Identifiable Information (PII), October 11, 2018

2 System Privacy Baseline Implementation Process

2.1 Process Overview

The control baselines address the protection needs of a diverse set of constituencies, including individual users and organizations. Thus, certain working assumptions generally underlie the control baselines. These assumptions consider the environments in which organizational information systems operate, including legislative, regulatory, or policy obligations; the nature of organizational operations; the specific functionality employed within the systems;

the types of threats confronting organizations, mission and business processes, and systems; individuals’ privacy interests; and the types of information processed, stored, or transmitted by systems.

2.2 Assumptions

The following assumptions described are used for determining privacy requirements, and the selection of relevant privacy controls process:

1) The RD Privacy Baseline Requirements will provide guidance to the project team from an engineering perspective based on privacy requirements.

2) The information system contains PII data.

3) The hosting environment has successfully completed an Assessment and Authorization (A&A) process and has valid USDA Authorization to Operate (ATO) as the system being deployed (or higher) FIPS-199 classification level. Additionally, the hosting environment Privacy Impact Assessment (PIA) and Privacy Threshold Analysis (PTA) identifies that hosting environment as containing PII.

4) The RD Privacy Baseline Requirements will impact the entire system accreditation boundary.

5) The privacy baseline requirements table provides system level implementation requirements identified in

NIST SP 800-53 Rev 4, Appendix J.

2.3 Process Details

2.3.1 Complete Privacy Threshold Analysis

A PTA will be conducted for each RD information system to determine if the information system contains PII.

2.3.2 Identify Project Specific Privacy Requirements

If the PTA indicates that information system contains PII, the project managers will review the RD Privacy Baseline Requirements and identify the relevant privacy controls that must be implemented for the specific information system.

2.3.3 Complete and Submit a Privacy Requirements Matrix

All proposed privacy baseline requirements must be documented by the project managers using a privacy requirements matrix (Appendix C). If the RD Privacy Baseline Requirements cannot be implemented, the project managers shall fill out the justification section in the privacy requirements matrix.

The privacy requirements matrix will contain at least the information listed in the bulleted list below and will address all controls shown in Section 3 of this document.

Information System Name – Provided by Project Manager Control ID – Included in the Privacy Requirements Matrix Template Control Title - Included in the Privacy Requirements Matrix Template Control Description - Included in the Privacy Requirements Matrix Template Can the control be implemented (Yes/No) – Provided by Project Manager Detail description of justification for why not – Provided by Project Manager

Alternatives for the controls that cannot be implemented – Provided by Project Manager

The privacy requirements matrix template will be provided as a separate document by the RD Cybersecurity Team.

This matrix will be prefilled with the information for Control ID, Control Title, and Control Description. Project manager is responsible for providing information regarding the system name, whether the control can be implemented and if the control cannot be implemented, the justification for why not. Furthermore, project managers must provide alternatives for the privacy controls that cannot be implemented.

The privacy requirements matrix will be submitted to the RD Cybersecurity Team for approval by the RD CISO or alternative designated official.

2.3.4 Review and Confirm Project Specific Privacy Requirements The RD Cybersecurity and Privacy Team reviews the privacy requirements matrix provided by the project manager to ensure that the privacy controls meet the intended requirements, confidentiality, integrity and availability of information. If the proposed privacy controls do not meet the intended requirements, the project manager shall update the privacy requirements matrix per RD Cybersecurity Team guidance. If there is no consent the privacy team will follow the risk assessment process to document the associated privacy risk.

2.3.5 Implement Privacy Requirements through System Development Life Cycle (SDLC) If the RD Cybersecurity Team approves the proposed privacy controls, then the project managers will follow the SDLC phases for design, implementation and test of privacy requirements. The project managers will be required to follow the RD SDLC requirements.

R D

O C

IO

P riv ac y B as el in e

R eq ui re m en ts V er si on

.0

Pa ge

RD

P riv ac y

Ba se lin e

Re qu ire m en ts

Th e

RD

P riv ac y

Ba se lin e

Re qu ire m en ts a re il lu st ra te d be lo w . T he d es cr ip tio ns o f e ac h co nt ro l d et ai l c an b e fo un d in N

IS

T

0-

R ev

, A pp en di x J . T he p riv ac y co nt ro l n um be r a nd fa m ily id en tif ie rs a re li st ed in th e

“C on tr ol an d “T itl e” c ol um n in R

D pr iv ac y ba se lin e re qu ire m en ts ta bl e.

C on tr ol e nh an ce m en ts , w he n us ed to su pp le m en t p riv ac y co nt ro ls, a re in di ca te d by th e co nt ro l e nh an ce m en t n um be r s pe cif ie d in N

IS

T

0-

R ev

, A pp en di x J.

Fu rt he rm or e, s ub se ct io ns in a s pe cif ic co nt ro l a re in di ca te d by th e as so cia te d pr iv ac y co nt ro l n um be r a nd th e sim pl e ca se le tt er a ss oc ia te d to th at sp ec ifi c p riv ac y co nt ro l.

Th e m at rix b el ow co nt ai ns b ot h m an ag em en t a nd te ch ni ca l c on tr ol

. M an ag em en t c on tr ol s a re th e se cu rit y co nt ro ls (i.

e.

, s af eg ua rd s o r c ou nt er m ea su re s) fo r a n in fo rm at io n sy st em th at fo cu s on th e m an ag em en t o f r isk a nd th e m an ag em en t o f i nf or m at io n sy st em s ec ur ity a nd c an b e im pl em en te d by th e sy st em o w ne r.

Te ch ni ca l c on tr ol s ar e th e se cu rit y co nt ro ls

(i.

e.

, s af eg ua rd s o r c ou nt er m ea su re

s) fo r a n in fo rm at io n sy st em th at a re p rim ar ily im pl em en te d an d ex ec ut ed b y th e in fo rm at io n sy st em th ro ug h m ec ha ni sm s c on ta ed e ha rd w ar e, so ftw ar e, o r f irm w ar e co m po ne nt s o f t he sy st em

, a nd sh ou ld th er ef or e be d es ig ne d in to th e sy st em a t t he a pp ro pr ia te le ve l.

Co nt ro l

Ti tle ro l D es cr ip tio n

Co nt ro l

Ty pe

Re fe re nc e

Co m m en t

Au th or ity a nd

P ur po se

AP

-2

Pu rp os e Sp ec ifi ca tio n Th e sy st em o w ne rs s ha ll de sc rib e th e pu rp os e( s) f or w hi ch p er so na lly i de nt ifi ab le fo rm at io n (P

II)

i s co lle ct ed us ed m ai nt ai ne d an d sh ar ed i n its P riv ac y Im pa ct

As ss m en ts (P

IA

s)

M an ag em en t

NI

ST

S P

0-ev

Ap pe nd ix

J os e Sp ec ifi ca tio n Th e sy st em sh al l p ro vi de a P riv ac y Ac t S ta te m en t t o th e pu bl ic at th e tim e of

P

II

co lle ct io n.

Te ch ni ca l

NI

ST

S

P ev

Ap pe nd ix J

Ac co un ta bi lit y, A ud it an d

Ri sk

M an ag em en t

AR

Pr iv ac y Im pa ct a nd

R isk

A ss es sm en t

Th e sy st em o w ne rs sh al l c on du ct a

P riv ac y

Th re sh ol d As se ss m en t (

PT

A) fo r a ll in fo rm at io n sy st em s.

M an ag em en t

NI

ST

S P ev

Ap pe nd ix

J ac y

Im pa ct a nd R isk A ss es sm en t Th e sy st em o w ne rs sh al l c on du ct a P riv ac y Im pa ct

A ss es sm en t (

PI

As

) f or in fo rm at io n sy st em s w he re re qu ire d by th e

PT

A.

M an ag em en t

NI

ST

S P ev

Ap pe nd ix

J

-7 ac y- En ha nc ed S ys te m D es ig n an d De ve lo pm en t Th e sy st em sh al l i m pl em en t a ut om at ed m ec ha ni sm s t o sa fe gu ar d pe rs on al ly id tif ia bl e in fo rm at io n

(P

II)

d ur in g its co lle ct io n pr oc es s.

Te ch ni ca l

NI

ST

S

P ev

Ap pe nd ix J

Th e sy st em sh al l i m pl em en t a ut om at ed m ec ha ni sm s t o sa fe gu ar d pe rs on tif ia bl e in fo rm at io n (P

II)

d ur in g its u se p ro ce ss

Te ch ni ca l

NI

ST

S P ev

Ap pe nd ix

J Th e sy st em sh al l i m pl em en t a ut om at ed m ec ha ni sm s t o sa fe gu ar d pe rs on tif ia bl e in fo rm at io n

(P

II)

d ur in g its re te nt io n pr oc es s.

Te ch ni ca l

NI

ST

S

P ev

Ap pe nd ix J

O C

IO

P riv ac y B as el in e

R eq ui re m en ts V er si on ro l I

D ro l D es cr ip tio n Co nt ro l re nc e

Co m m t sy st em sh al l i m pl em en t a ut om at ed m ec ha ni sm s t o sa fe gu ar d pe rs on tif ia bl e in fo rm at io n (P

II)

d ur in g its d isc lo su re p ro ce ss

Te ch ni ca l

NI

ST

S

P ev

Ap pe nd ix J

Da ta

Q ua lit y an d

In te gr ity

DI

-1

(a

Da ta

Q ua lit y

Th e sy st em sh al l i m pl em en t m ea su re s t ha t c on fir m th e ac cu ra cy

, r el ev an ce , t im el in es s, an d co m pl et en es s o f P

II

up on co lle ct io n or cr ea tio ni ca l

NI

ST

S P ev

Ap pe nd ix

J

DI

-1

(b

Da ta

Q ua lit y

Th e sy st em sh al l i m pl em en t m ea su re s t o co lle ct P

II

di re ct ly fr om th e in di vi du al to th e gr ea te st e xt en t p ra ct ica bl e.

ni ca l

NI

ST

S P ev

Ap pe nd ix

J

DI

-1 (c

Da ta Q ua lit y Th e sy st em sh al l i m pl em en t a ut om at ed m ea su re s t o ch ec k an d co rr ec t a ny in ac cu ra te or o ut da te d

PI

I w ith in a p re de fin ed fr eq ue nc y [b us in es s t o de fin e fre qu en cy

Te ch ni ca l

NI

ST

S P ev

Ap pe nd ix

J

DI

-1

(d

Da ta

Q ua lit y

Th e sy st em sh al l i m pl em en t m ec ha ni sm s t o en su re th e qu al ity , a nd in te gr ity o f di ss em in at ed in fo rm at io n.

(e

.g . I np ut v al id at io n, g ui da nc e to th e us er fo r i np ut

Te ch ni ca l

NI

ST

S P ev

Ap pe nd ix

J Th e sy st em o w ne r s ha ll en su re th e ut ili ty a nd o bj ec tiv ity o f d iss em in at ed in fo rm at ag em en t

NI

ST

S

P ev

Ap pe nd ix J

DI

-1

(1

Va lid at e

PI

I

Th e sy st em sh al l r eq ue st th at th e in di vi du al o r i nd iv id ua ls' a ut ho riz ed re pr es en ta tiv e va lid at e

PI

I d ur in g th e co lle ct io n pr oc es s.

Te ch ni ca l

NI

ST

S P ev

Ap pe nd ix

J Da ta M in im iza tio n an d Re te nt io n

DM

-1

(a

M in im iza tio n of P

II

Th e sy st em o w ne rs s ha ll ut ili ze

P riv ac y

Im pa ct A ss es sm en ts

PI

As to i de nt ify he im um p er so na lly i de nt ifi ab le i nf or m at io n (P

II)

e le m en ts t ha t ar e re le va nt ne ce ss ar y to a cc om pl ish th e le ga lly a ut ho riz ed p ur po se o f c ol le ct ag em en t

NI

ST

S P ev

Ap pe nd ix

J

DM

-1

(b

M in im iza tio n of P

II

Th e sy st em sh al l l im it th e co lle ct io n an d re te nt io n of

P

II

to th e m in im um e le m tif ie d fo r t he p ur po se d es cr ib ed in P

IA

a nd th e Pr iv ac y Ac t S ta te m en t.

Te ch ni ca l

NI

ST

S

P ev

Ap pe nd ix J

DM

-1

(1

Lo ca te /R em ov e/ Re da ct

/A no ny ize

PI

I

Th e sy st em s ha ll, lo ca te , r em ov e, r ed ac t, an on ym ize a nd /o r de

-id en tif ie d

PI

I t o pe rm it us e of t he r et ai ne d in fo rm at io n w hi le r ed uc in g its s en sit iv ity a nd r ed uc in g th e ris k re su lti ng fr om d isc lo su re

Te ch ni ca l

NI

ST

S

P ev

Ap pe nd

O C

IO

P riv ac y B as el in e

R eq ui re m en ts V er si on

DM

(a

Da ta

R et en tio n an d Di sp os sy st em s ha ll re ta in p er so na lly id en tif ia bl e in fo rm at io n

(P

II)

f or a p re de fin ed t im e pe rio d to fu lfi ll th e pu rp os e(

s) id en tif ie d in th e sy st em p riv ac y no tic e or a s re qu ire d by la w

Po pu la te th e tim e pe rio d ba se d on th e

Sy st em s R ec or ds R et en tio n

Sc he du le

Te ch ni ca l

NI

ST

S

P ev

Ap pe nd ix J

DM

2( b)

Da ta R et en tio n an d

Di sp sy st em sh al l a pp ro pr ia te ly d isp os e of

P

II,

in a cc or da nc e w ith a

N

AR

A Ap pr ov ed re co rd nt io n sc he du le a nd in a m an ne r th at p re ve nt s lo ss , t he ft, m isu se , o r un au th or ize d ac ce ss

Te ch ni ca l

NI

ST

S

P ev

Ap pe nd ix J

DM

-2

(b

Da ta

R et en tio n an d Di sp sy st em s ha ll sy st em at ica lly d es tr oy

, e ra se , a nd /o r a no ny m ize s th e

PI

I, re ga rd le ss o f th e m et ho d of st or ag e

(e .g el ec tr on ic, o pt ica l m ed ia

, o r p ap er

-b as ed ) i n ac co rd an ce ith

NA

RA

-a pp ro ve d re co rd r et en tio n sc he du le a nd in a m an ne r th at p re ve nt s lo ss

, t ft, ni ca l

NI

ST

S

P ev

Ap pe nd ix J

DM

-2

(c

Da ta

R et en tio n an d Di sp sy st em s ha ll us e in du st ry b es t pr ac tic es a nd f ed er al m an da te d te ch ni qu es et ho ds to e ns ur e se cu re d el et io n or d es tr uc tio n of P

II

(in clu di ng o rig in al s, co pi es , a ar iv ed re co rd s)

Te ch ni ca l

NI

ST

S

P ev

Ap pe nd ix J

DM

-2

(1

Sy st em C on fig ur at io n

Th e sy st em s ha ll co nf ig ur e its in fo rm at io n sy st em s to r ec or d th e da te P

II

is co lle ct ed cr ea te d, o r u pd at ed

Te ch ni ca l

NI

ST

S P ev

Ap pe nd ix

J

DM

-2 (1

Sy st em

C on fig ur at io n Th e sy st em sh al l c on fig ur e its in fo rm at io n sy st em s t o re co rd w he n

PI

I i s t o be d el et ed o r ar ch iv ed u nd er a n ap pr ov ed re co rd re te nt io n sc he du le

Te ch ni ca l

NI

ST

S

P ev

Ap pe nd ix J

-3 im iza tio n of

P

II

Us ed in T es tin g, Tr ai ni ng

, a nd

R es ea rc h Th e sy st em sh al l im pl em en t c on tr ol s t o pr ot ec t P

II

us ed fo r t es tin g, tr ai ni ng

, a nd re se ar ch

Te ch ni ca l

NI

ST

S P ev

Ap pe nd ix

J

DM

-3 (1

Ri sk M in im iza tio n Te ch ni qu es sy st em sh al l i m pl em en t a no ny m iza tio n an d de -id en tif ic at io n te ch ni qu es to m in im ris k to p riv ac y of u sin g

PI

I f or te st in g, tr ai ni ng , a nd re se ar ch

Te ch ni ca l

NI

ST

S

P ev

Ap pe nd ix J

In di vi du al P ar tic ip at io n an d

Re dr es s

IP

-1

(a

Co ns en t

Th e sy st em s ha ll ob ta in c on se nt f ro m i nd iv id ua ls to a ut ho riz e th e co lle ct io n, u se m ai nt ai ni ng

, a nd sh ar in g of P

II

pr io r t o its co lle ct ni ca l

NI

ST

S

P ev

Ap pe nd ix J

IP

-1

(b

Co ns en t

Th e sy sh l di sp la y pr iv ac y ac t no tic r in di vi du al s to un de rs co ns eq ue nc es o f d ec isi on s t o ap pr ov e or d ec lin e th e au th or iza tio n of th e co lle ct io n, u se di ss em in at io n an d re te nt io n of P

II.

ni ca l

NI

ST

S

P ev

Ap pe nd ix J

IP

-1

(c

Co ns en t

Th e sy st em s ha ll ob ta in c on se nt , f ro m in di vi du al s pr io r t o an y ne w u se s or d isc lo su re o f pr ev io us ly co lle ct ed ni ca l

NI

ST

S P ev

A p pe nd

O C

IO

P riv ac y B as el in e

R eq ui re m en ts V er si on ro l I

D ro l D es cr ip tio n Co nt ro l re nc e

Co m m en t

IP

-1

(d

Co ns en t

Th e sy st em sh al l u pd at e pr iv ac y ac t n ot ice s t o en su re th at th e in di vi du al s a re a w ar e of a ll us es o f P

II

no t i ni tia lly d es cr ib ed in th e pu bl ic no tic e th at w as in e ffe ct a t t he ti m e th e or ga ni za tio n co lle ct s t he ni ca l

NI

ST

S

P ev

Ap pe nd ix J

IP

-1

(d

Co ns en t

Th e sy st em sh al l o bt ai n co ns en t t o al l u se s o f P

II

no t i ni tia lly d es cr ib ed in th e pr iv ac y no tic e th at w as in e ffe ct a t t he ti m e th e or ga ni za tio n co lle ct s t he ni ca l

NI

ST

S

P ev

Ap pe nd ix J

IP

-1

(1

M ec ha ni sm s

Su pp or tin g

Ite ize d

Co ns en t

Th e sy st em sh al l i m pl em en t m ec ha ni sm s t o su pp or t i te m ize d co ns en t f or sp ec ifi c u se s of d at a.

(e .g

. I nd iv id ua ls’ it em ize d ch oi ce s a s t o w he th er th ey w ish to b e co nt ac te d fo r an y of a v ar ie ty o f p ur po se s.

In th is sit ua tio n, o rg an iza tio ns co ns tr uc t c on h i t th t i ti l ti l ith i di id l h i

Te ch ni ca l

NI

ST

S

P ev

Ap pe nd ix J

IP

In vi du al

A cc es s

Th e sy st em sh al l i m pl em en t m ec ha ni sm s t o en ab le s i nd iv id ua ls to a cc es s t he ir

PI

I m ai nt ai ne d in sy st em (s

) o f r ec or ds

Te ch ni ca l

NI

ST

S

P ev

Ap pe nd ix J dr es s Th e sy st em sh al l i m pl em en t r ed re ss ca pa bi lit ie s f or in di vi du al s t o ha ve in ac cu ra te

P

II

m ai nt ai ne d by R

D co rr ec te d or a m en de d, a s a pp ro pr ia te

Te ch ni ca l

NI

ST

S

P ev

Ap pe nd ix J

Tr an sp ar cy

TR

(a

Pr iv ac y

No tic e Th e sy st em sh al l p ro vi de p riv ac y ac t n ot ice to th e pu bl ic an d to in di vi du al s r eg ar ng sy st em s a ct iv iti es th at im pa ct p riv ac y in clu di ng co lle ct io n, u se

, s ha rin sa gu ar di ng , m ai nt en an ce , a nd d isp os al o f p er so na lly id en tif ia bl e in fo rm at io n (P

II)

Te ch ni ca l

NI

ST

S

P ev

Ap pe nd ix J

TR

-1

(a

Pr iv ac y

No tic e Th e sy st em sh al l p ro vi de p riv ac y ac t n ot ice to th e pu bl ic an d to in di vi du al s r eg ar sy st em s a ut ho rit y fo r c ol le ct in g

PI

I.

Te ch ni ca l

NI

ST

S P ev

Ap pe nd ix

J

TR

-1

(a

Pr iv ac y

No tic e Th e sy st em sh al l d isp la y pr iv ac y ac t n ot ice to th e pu bl ic an d to in di vi du al s r eg ar di ng th e ch oi ce s, if an y, in di vi du al s m ay h av e re ga rd in g ho w th e or ga ni za tio n us es ni ca l

NI

ST

S

P ev

Ap pe nd ix J

TR

-1

(a

Pr iv ac y

No tic e Th e sy st em sh al l p ro vi de p riv ac y ac t n ot ice to th e pu bl ic an d to in di vi du al s r eg ar co ns eq ue nc es o f e xe rc isi ng o r n ot e xe rc isi ng th os e ch oi ce s.

Te ch ni ca l

NI

ST

S P ev

Ap pe nd ix

J

TR

-1

(a

Pr iv ac y

No tic e Th e sy st em sh al l p ro vi de p riv ac y ac t n ot ice to th e pu bl ic an d to in di vi du al s r eg ar ei r a bi lit y to a cc es s a nd h av e

PI

I a m en de d or co rr ec te d if n ec es sa ry

Te ch ni ca l

NI

ST

S P ev

Ap pe nd

O C

IO

P riv ac y B as el in e

R eq ui re m en ts V er si on ro ro l D es cr ip tio n

Co nt ro l re nc e

Co m m en t

TR

-1

(b

Pr iv ac y

No tic e Th e sy st em sh al l p ro vi de p riv ac y ac t n ot ice to d es cr ib e th e

PI

I c ol le ct ed b y th e sy st em

Te ch ni ca l

NI

ST

S

P ev

Ap pe nd ix J

TR

-1

(b

Pr iv ac y

No tic e Th e sy st em sh al l p ro vi de p riv ac y ac t n ot ice to d es cr ib e th e pu rp os e fo r w hi ch

R D co lle ct s P

II

Te ch ni ca l

NI

ST

S P ev

Ap pe nd ix

J

TR

-1 (b

Pr iv ac y No tic e

Th e sy st em sh al l p ro vi de p riv ac y ac t n ot ice to d es cr ib e, h ow R

D us es P

II

co lle ct ed b y th e sy st em in te rn al ly

Te ch ni ca l

NI

ST

S

P ev

Ap pe nd ix J

TR

-1

(b

Pr iv ac y

No tic e Th e sy st em sh al l p ro vi de p riv ac y ac t n ot ice w hi ch d es cr ib es a ny e xt er na l e nt iti es ho m

P

II

is sh ar ed a nd th e pu rp os e fo r s uc h sh ar g.

ni ca l

NI

ST

S P ev

Ap pe nd ix

J

TR

-1 (b

Pr iv ac y No tic e

Th e sy st em sh al l p ro vi de p riv ac y ac t n ot ice w hi ch d es cr ib es w he th er in di vi du al s h av e th e ab ili ty to co ns en t t o sp ec ifi c u se s o r s ha rin g of ni ca l

NI

ST

S

P ev

Ap pe nd ix J

TR

-1

(b

Pr iv ac y

No tic e Th e sy st em sh al l p ro vi de p riv ac y ac t n ot ice w hi ch d es cr ib es h ow in di vi du al s m ay ns en t t o sp ec ifi c u se s o r s ha rin g of ni ca l

NI

ST

S P ev

A p pe nd ix

J

TR

-1 (b

Pr iv ac y No tic e

Th e sy st em sh al l p ro vi de p riv ac y ac t n ot ice w hi ch d es cr ib es h ow in di vi du al s m ay o bt ai n ac ce ss to ni ca l

NI

ST

S P ev

Ap pe nd ix

J

TR

-1 (b

Pr iv ac y No tic e

Th e sy st em sh al l p ro vi de p riv ac y ac t n ot ice w hi ch d es cr ib es h ow P

II

w ill b e pr ot ec d.

ni ca l

NI

ST

S P ev

Ap pe nd ix

J Us e Li m ita tio n

UL

rn al U sy st em sh al l b e de sig ne d to u se p er so na lly id en tif ia bl e in fo rm at io n (P

II)

in te rn on fo r t he a ut ho riz ed p ur po se (s

) i de nt ifi ed in th e

PI

A an d/ or in sy st em p riv ac y no tic es

Te ch ni ca l

NI

ST

S

P ev

A p pe nd ix J

UL

-2

(a

In fo rm at io n

Sh ar in g w ith

T hi rd P ar tie s Th e sy st em sh al l b e de sig ne d to sh ar e pe rs on al ly id en tif ia bl e in fo rm at io n (P

II)

ex rn al ly , o nl y fo r t he a ut ho riz ed p ur po se s i de nt ifi ed in th e

PI

A an d/ or d es cr ib sy em p riv ac y no tic e(

s) o r f or a p ur po se th at is co m pa tib le w ith th os e pu rp os es

Te ch ni ca l

NI

ST

S

P ev

Ap pe nd ix J

UL

-2

(b

In fo rm at io n

Sh ar in g w ith

T hi rd P ar tie s If

PI

I i s s ha re d w ith th ird p ar tie s t he sy st em o w ne rs sh al l e nt er in to M

O U, M O

A, IS

A, o r sim ila r a gr ee m en ts w ith th ird p ar tie s.

M an ag em en t

NI

ST

S

P ev

Ap pe nd

O C

IO

P riv ac y B as el in e

R eq ui re m en ts V er si on ro ro l D es cr ip tio n

Co nt ro l re nc e

Co m m en t

UL

-2

(b

In fo rm at io n

Sh ar in g w ith

T hi rd P ar tie s If

PI

I is sh ar ed w ith t hi rd p ar tie s, th e M

O U, M O

A, I

SA

o r sim ila r ag re em en ts s ha ll sp ec ifi ca lly d es cr ib e th e

PI

I s ha re d w ith th e th ird p ar ty a nd e nu m er at e th e pu rp os es fo r w hi ch th e

PI

I m ay b e us ed b y th e th ird p ar ty

M an ag em en t

NI

ST

S P ev

Ap pe nd ix

J

UL

-2 (b

In fo rm at io n Sh ar in g w ith T hi rd

P ar tie s

If

PI

I i s s ha re d w ith th ird p ar tie s, th e sy st em o w ne r s ha ll en su re th at th e M

O U, M O

A, IS

A or si m ila r a gr ee m en ts a re co ns ist en t w ith ag em en t

NI

ST

S

P ev

Ap pe nd ix J

UL

-2

(d

In fo rm at io n

Sh ar in g w ith

T hi rd P ar tie s Th e sy st em s ow ne rs s ha ll ev al ua te a ny p ro po se d ne w in st an ce s of s ha rin g

PI

I w ith ird rt ie s t o as se ss w he th er th e sh ar in g is au th or ize d an d w he th er a dd iti on al o r n ew p ub lic no e is re qu ire ag em en t

NI

ST

S P ev

Ap pe nd ix

J

UL

-2

(d

In fo rm at io n

Sh ar in g w ith

T hi rd P ar tie s Th e sy st em s ow ne rs s ha ll ev al ua te a ny p ro po se d ne w in st an ce s of s ha rin g

PI

I w ith ie s t o as se ss w he th er th e sh ar in g is au th or ize d an d w he th er a dd iti on al o r n ew

P

IA

is ag em en t

NI

ST

S P ev

Ap pe nd ix

J

UL

-2

(d

In fo rm at io n

Sh ar in g w ith

T hi rd P ar tie s Th e sy st em s ow ne rs s ha ll ev al ua te a ny p ro po se d ne w in st an ce s of s ha rin g

PI

I w ith ie s t o as se ss w he th er th e sh ar in g is au th or ize d an d w he th er a dd iti on al o r n ew

M

U, A, IS

A or si m ila r a gr ee m en ts a re re qu ag em en t

NI

ST

S P ev

Ap pe nd

Appendix A - Definitions Privacy Privacy in the information security context refers to the expectations and rights of individuals to privacy of their personal information and adequate, secure handling of this information by its users. Organizations should take necessary precautions to protect the confidentiality and integrity of personal information they collect, store, and process. In particular, organizations’ information security policies should define how personal information is to be collected and processed.

Personally Identifiable Information Any information about an individual maintained by an agency, including (1) any information that can be used to distinguish or trace an individual‘s identity, such as name, social security number, date and place of birth, mother‘s maiden name, or biometric records; and (2) any other information that is linked or linkable to an individual, such as medical, educational, financial, and employment information. 1

Examples of PII include, but are not limited to:

Name, such as full name, maiden name, mother’s maiden name, or alias;

Personal identification number, such as social security number (SSN), passport number, driver‘s license number, taxpayer identification number, or financial account or credit card number;

Address information, such as street address or email address;

Personal characteristics, including photographic image (especially of face or other identifying characteristic), fingerprints, handwriting, or other biometric data (e.g., retina scan, voice signature, facial geometry);

Information about an individual that is linked or linkable to one of the above (e.g., date of birth, place of birth, race, religion, weight, activities, geographical indicators, employment information, medical information, education information, financial information).

Privacy Act Statement A disclosure statement required by Section (e)(3) of the Privacy Act of 1974, as amended, to appear on documents used by organizations to collect PII from individuals to be maintained in a Privacy Act System of Records (SORN).

1 NIST SP 800-122: Guide to Protecting the Confidentiality of Personally Identifiable Information (PII)

Appendix B – Privacy Roles and Responsibilities Chief Information Officer (CIO)

Overall agency-wide responsibility for IT Privacy issues Overall responsibility and accountability for ensuring the RD’ implementation of IT privacy protections, including the agency’s full compliance with federal laws, regulations, and policies relating to information privacy, such as the Privacy Act

Oversee, coordinate, and facilitate RD’ compliance efforts Ensure RD employees and contractors receive appropriate training and education programs regarding the information privacy laws, regulations, policies, and procedures governing the agency’s handling of personal information

Overall authority in decision-making in RD’ development and evaluation of legislative, regulatory and other policy proposals which implicate IT privacy issues, including those relating to the agency’s collection, use, sharing, and disclosure of personal information.

Authorize RD IT privacy policies, and baseline requirements

RD Chief Privacy Officer (CPO)

Oversee the IT privacy program Ensure the privacy requirements are consistent with federal laws, regulations, policies; federal guidelines, USDA policies, and RD mission and business objectives Ensure RD coordination with USDA Privacy Team Guide the development and management of IT privacy policies and practices Guide the development and management of privacy processes, procedures, minimum standards, and requirements Provide executive level support and sponsorship for all IT privacy baseline activities

RD Privacy Team Lead

Manage IT privacy program Assure that the privacy requirements sustain, and do not erode, privacy protections relating to the use, collection, and disclosure of personal information Lead the development and management of privacy policies and services Lead the development and management of privacy processes, procedures, minimum standards, and requirements Review IT Privacy Team recommendation and approve or disapprove privacy controls requirements matrix submitted by project managers Review and/or prepare and update Privacy Threshold Analysis (PTA) and Privacy Impact

Assessment (PIA)

RD IT Privacy Team

Track all privacy related laws, regulations, guidelines that are relevant to the information systems Review new laws, guidelines, standards, and regulations for privacy impact Generate privacy requirements for the information systems Provide privacy requirement subject matter expert support to project managers Update the RD Privacy Baseline Requirements as required to ensure compliance to new and existing laws, guidelines, standards, and regulations for privacy Generate and update a privacy requirements matrix template for use by project teams Review and recommend approval or disapproval for privacy controls requirement matrix submitted by project managers Coordinate with the security team to assess, test and evaluate the secure implementation of privacy controls Prepare and/or update Privacy Threshold Analysis (PTA) and Privacy Impact Assessment (PIA)

RD Security Team Coordinate with the Privacy Team with A&A activities related to privacy Assess, test, and evaluate the secure implementation of privacy controls

System Owners

Provide funding to project team Review A&A package, including any residual security and privacy risks Make a risk-based decision if necessary Collaborate with the IT Privacy Team to identify data elements that may contain PII

Project Managers

Review and identify privacy controls that are applicable to information systems Document applicable privacy controls using a privacy requirements matrix Provide justifications for privacy controls that are not applicable for information systems Ensure that system engineers and designers comply with the privacy requirements Identify the resources necessary to complete the privacy requirement tasks Ensure successful implementation of all privacy controls including management, operational and technical controls

System Designers & Engineers

Apply technical privacy requirements that are listed in Section 3 into system design Ensure the privacy controls are implemented correctly Ensure the privacy controls are operating as intended Ensure the privacy controls are producing the desired outcome

O C

IO

P riv ac y B as el in e

R eq ui re m en ts V er si on

Ap nd ix

C

Pr iv ac y

Re qu ire m en ts

M at rix T em pl rm at io n

Sy st em N am e:

ro ro l D es cr ip n ro l

Ca th e

Co nt ro l b e Im pl em en te d (Y es /N o)

De il De sc rip tio n of Ju st ifi ca tio n fo r C on tr ol s t ha t C an no t b e Im pl em en te d

Al te rn at iv es fo r t he C on tr ol s t ha t

Ca nn ot b e Im pl em en te d

Au th or ity a nd

P ur po os e Sp ec ifi ca tio n Th e sy st em o w ne rs sh al l d es cr ib e th e pu rp os e( s) w hi rs on tif ia bl e in fo rm at io n lle ct ed us ed m ai nt ai ne d an d sh its ac y Im

As ss m en ts (P

IA

s)

M an ag em os e Sp ec ifi ca tio n Th e sy st em sh al l p ro vi de a P riv ac y A

St em en t t o th e pu bl ic at th e tim of

I c ol le ct ni ca

Ac un ta bi lit y, A ud it an d

Ri sk

M an ag em en t ac y Im

Ri sk sy st em o w ne rs s ha ll co nd uc t a Pr iv ac y Th re sh ol d

As se ss m en t

(P

TA

fo r a ll in fo rm at io n sy st s.

ag em ac y Im sy st em o w ne rs s ha ll co nd uc t a Pr iv ac y Im pa ct

A ss es sm en t (

PI

As

) f rm at io n sy st em s w he re r eq ui re d by th e

PT

ag em

-7 ac y-

En ha nc

Sy sig n

Th e sy l im pl em en t au to m at ed m ec ha ni sm s t o sa fe gu ar d pe rs on tif ia bl e in fo rm at io n (P

II)

d ur in g its co lle ct io n pr oc es s.

Te ch ni

O C

IO

P riv ac y B as el in e

R eq ui re m en ts V er si on rm at io n

Sy st em N ro ro l D es cr ip ro l th e

Co nt ro l b e Im pl em en te d (Y es il De sc rip tio n of Ju st ifi ca tio n fo r C on tr ol s t ha t C an no t b e Im pl em en te d

Al te rn at iv es fo r t he C on tr ol s t ha t

Ca nn ot b e Im pl em en lo pm en t Th e sy l im pl em en t au to m at ed m ec ha ni sm s t o sa fe gu ar d pe rs on tif ia bl e in fo rm at io n

(P

II)

d ur in g its u se p ro ce ss

Te ch ni sy l im pl em en t au to m at ed m ec ha ni sm s t o sa fe gu ar d pe rs on tif ia bl e in fo rm at io n (P

II)

d ur in g its re te nt io n pr oc es s.

Te ch ni sy l im pl em en t au to m at ed m ec ha ni sm s t o sa fe gu ar d pe rs on tif ia bl e in fo rm at io n (P

II)

d ur in g its d isc lo su re p ro ce ss

Te ch ni

Q ua lit y an d

In te

(a

Da ta

Q ua lit y

Th e sy l im pl em en t m ea su re s th at c on fir m th e ac cu ra cy re le va e, tim el in es s, an d co m pl et en es s of P

II

up on c ol le ct io n i

Te ch ni

(b

Da ta

Q ua lit y

Th e sy l im pl em en t m ea su re s to c ol le ct

P

II

di re ct ly fr om in di vi du al t o th e gr ea te st e xt en t pr ac tic ab le

Te ch ni

(c

Da ta

Q ua lit y

Th e sy l im pl em en t au to m at ed m ea su re s to c he ck rr ec t a ny in ac cu ra te o r o ut da te d

PI

I w pr ed ef fr eq ue nc y [b us in es s t o de fin e fre qu en cy

Te ch ni

O C

IO

P riv ac y B as el in e

R eq ui re m en ts V er si on rm at io n

Sy st em N am e

Co nt ro ro l D es cr ip ro l th e

Co nt ro l b e Im pl em en te d (Y es il De sc rip tio n of Ju st ifi ca tio n fo r C on tr ol s t ha t C an no t b e Im pl em en te d

Al te rn at iv es fo r t he C on tr ol s t ha t

Ca nn ot b e Im pl em en te d

DI

-1

(d

Da ta

Q ua lit y

Th e sy l im pl em en t m ec ha ni sm s to e ns ur e th e qu al ity an d in te ss em in rm at io n.

e.

g.

I np ut v al id at n, gu an ce to th e us er fo r i np ut

Te ch ni sy st em o w ne r sh al l en su re ut ili ty a nd o bj ec tiv ity o f d iss em in rm at ag em

(1

Va lid at e

PI

I

Th e sy st em s ha ll re qu es t th at vi du al o r in di vi du al s' au th or ize d re pr es en ta tiv e va lid at e

PI

I d ur in g th e co lle ct io n pr oc es s.

Te ch ni

M in im iza tio n an d

Re te nt io n

DM

1( a) im iza tio n of

P

II

Th e sy ow l ut ili ze ac y Im pa ct

A ss es sm en ts

(P

IA

tif y th e m in um on tif ia bl e in fo rm at io n re le va ne ce ss ar y to a cc om pl ish t he l eg au or ize d pu rp os e of co lle ct ag em im iza tio n of

P

II

Th e sy st em s ha ll lim it th e co lle ct io n an d re te nt io n of P

II

to th e m in um en ts id en tif ie d fo r th e pu rp os e de sc rib ed in P

IA

a nd t he P riv ac y Ac t St at em en t.

Te ch ni

O C

IO

P riv ac y B as el in e

R eq ui re m en ts V er si on rm at io n

Sy st em N ro ro l D es cr ip ro l th e

Co nt ro l b e Im pl em en te d (Y es il De sc rip tio n of Ju st ifi ca tio n fo r C on tr ol s t ha t C an no t b e Im pl em en te d

Al te rn at iv es fo r t he C on tr ol s t ha t

Ca nn ot b e Im pl em en te d

DM

1)

Lo te

Th e s ys l, lo ca te

, r em ov ni e/ da ct

An on ym re da ct a no ny d/ e-tif ie d

PI

I to p er m it us e of in ed in fo rm at io n w hi le r ed uc in g its s en sit iv ity a nd r ed uc in g th e ris k re su lti ng fr om d isc lo su a) nt io n an d Di sp sy st em s ha ll re ta in p er so na lly tif ia bl e in fo rm at io n (P

II)

f ef in ed t im e pe rio d to f ul fil l t pu os e( s) i de nt ifi ed i n th e sy ac y no tic e or a s re qu ire d by la w

[P op ul at e th e tim e pe rio d ba se

Sy st em s

Re co rd s

Re te nt io n Sc he du le

Te ch ni sy l ap pr op ria ni nt io n an d di sp os e of

P

II,

in a cc or da nc e

Di sp

RA

Ap rd re te nt sc du ne r t ev lo

, t he ft, m isu se th or ize d ac ce sy l sy st em at ica ni nt io n an d de st ro y, e ra se

, a nd

/o r a no ny m

Di sp

I, re ga rd m et ho ag e (e

.g el ec tr ic, op ia

, o r p ap er

-b as ed ) i n ac co rd

RA

-a pp ro ve d re nt io n sc he du le a nd in a m an p re ve nt s l os s, th ef t, m isu se

, o th or ize d ac ce

O C

IO

P riv ac y B as el in e

R eq ui re m en ts V er si on rm at io n

Sy st em N am e

Co nt ro ro l D es cr ip ro l th e

Co nt ro l b e Im pl em en te d (Y es il De sc rip tio n of Ju st ifi ca tio n fo r C on tr ol s t ha t C an no t b e Im pl em en te d

Al te rn at iv es fo r t he C on tr ol s t ha t

Ca nn ot b e Im pl em en te d

DM

c) nt io n an d Di sp sy st em s ha ll us e in du st ry b es t pr ac fe de ra l m an da te d te ch ni qu es a nd m et ho ds t o en su cu re d el et io n or d es tr uc tio n of

P

II

(in clu ig in al s, co pi es an d ar ch iv ed re co rd s)

Te ch ni nf ig ur at io n

Th e sy l co nf ig ur rm at io n sy st em s to r ec or d th e is co lle ct ed cr ea d, up ni nf ig ur at io n

Th e sy l co nf ig ur rm at io n sy st em s to r ec or d w he n

PI

I i s t o be d el et ed o r a rc hi ve d un de ap nt io n sc he du le

Te ch ni im iza tio n of

P

II

Us ni ng , a sy st em s ha ll im pl em en t c on tr ol ot ec t

PI

I us te st tr ni ng , a nd re se ar ch

Te ch ni

3( im iza tio n

Te ch ni sy l im pl em en t an on ym iza tio n an d de -id en tif ica tio n te ch ni qu es t o m in im ize t he r isk t o pr iv ac y g

PI

I fo r te st tr ni ng

, a nd re se ar ch

Te ch ni vi du al P ar tic ip at io n an d

Re dr es s

IP

-1

(a

Co ns en t

Th e sy st em sh al l o bt ai n co ns en t f ro vi du al co lle ct nt ai ni ng an d sh ar in g of

P

II

pr io r t o its co lle ct ni

O C

IO

P riv ac y B as el in e

R eq ui re m en ts V er si on rm at io n

Sy st em N am e

Co nt ro ro l D es cr ip ro l th e

Co nt ro l b e Im pl em en te d (Y es il De sc rip tio n of Ju st ifi ca tio n fo r C on tr ol s t ha t C an no t b e Im pl em en te d

Al te rn at iv es fo r t he C on tr ol s t ha t

Ca nn ot b e Im pl em en te d

IP

-1

(b

Co ns en t

Th e sy st em s ha ll di sp la y pr iv ac y ac t no tic es fo r i nd iv id ua ls to u nd er st an d th e co ns eq ue nc es o f de cis io ns t o ap pr ov e or d ec lin e th e au th or iza tio n of t he c ol le ct io n, u se , d iss em in at io n an d re te nt io n of ni

(c

Co ns en t

Th e sy l ob en t, fro m i nd iv id ua ls pr io r to a ny ew lo ev io lle ct ed ni

(d

Co ns en t

Th e sy st em s ha ll up da te p riv ac y ac t no tic es to e ns ur e th at th e in di vi du al s ar e aw ar e of a ll u se s o f P

II

no t i ni tia rib ed i n th e pu bl ic no tic e as ef tim e th e or ga ni za tio n co lle ct s t he ni

(d

Co ns en t

Th e sy st em sh al l o bt ai n co ns en t t o al l us es o f

PI

I no t in iti al ly d es cr ib pr iv ac y no tic e th at w as in e ffe he t im e th e or ga ni za tio n co lle ct s th e

PI

I.

Te ch ni

O C

IO

P riv ac y B as el in e

R eq ui re m en ts V er si on rm at io n

Sy st em N am e

Co nt ro ro l D es cr ip ro l th e

Co nt ro l b e Im pl em en te d (Y es il De sc rip tio n of Ju st ifi ca tio n fo r C on tr ol s t ha t C an no t b e Im pl em en te d

Al te rn at iv es fo r t he C on tr ol s t ha t

Ca nn ot b e Im pl em en te d

IP

-1

(1

M ec ha ni sm s

Su pp or tin g Ite m ize d Co ns en t

Th e sy l im pl em en t m ec ha ni sm pp or t ite m ize d co ns en t f or sp ec ifi c u se s o f d at a.

(e .g

In di vi du al s’ ite m ize d ch oi ce s as t o w he th er t he y w ish t o be c on ta an y of a v ar ie ty o f pu rp os es sit ua tio n, o rg an iza tio ns co ns tr uc t co ns en t m ec ha ni sm s to e ns ur e ga ni za tio na l op er at pl y w ith in di vi du al ch oi s.)

ni vi du

Ac sy l im pl em en t m ec ha ni sm s t o en ab le s i nd iv id ua ls ac ei r

PI

I m ai nt ai ne em (s

) o f r ec or ds

Te ch ni dr es s Th e sy st em s ha ll im pl em en t re dr es s ca pa bi lit ie s fo r in di vi du al s to h av e in ac cu ra m ai nt ai ne by

RD

rr ec te d, ap op ria te

Te ch ni sp ar cy

(a

Pr iv ac y

No tic e Th e sy st em s ha ll pr ov id e pr iv ac y ac t no tic e to th e pu bl ic an d to in di vi du al s re ga rd in g th e sy st em s ac tiv iti es t ha t im pa ct p riv ac y in clu di ng c ol le ct sa gu ar di ng m ai nt en an ce an d di sp on tif ia bl e in fo rm at io n

(P

II)

Te ch ni

O C

IO

P riv ac y B as el in e

R eq ui re m en ts V er si on rm at io n

Sy st em N ro ro l D es cr ip ro l th e

Co nt ro l b e Im pl em en te d (Y es il De sc rip tio n of Ju st ifi ca tio n fo r C on tr ol s t ha t C an no t b e Im pl em en te d

Al…

This is the start of the file's text. The full file is on GovTribe.

File details come from the government source that posted it. Updated .