Gaming System Monitoring and Analysis Effort
|
|
|
- Lawrence Cameron
- 10 years ago
- Views:
Transcription
1 for the Gaming System Monitoring and Analysis Effort DHS/S&T/PIA-025 October 11, 2012 Contact Point Douglas Maughan DHS S&T Cyber Security Division Reviewing Official Jonathan R. Cantor Acting Chief Privacy Officer Department of Homeland Security (202)
2 Page 2 Abstract The Gaming System Monitoring and Analysis project is a research effort funded by the Department of Homeland Security (DHS) Science and Technology Directorate (S&T) Cyber Security Division (CSD) to design and develop forensic tools for extracting data from gaming systems. S&T is conducting a Privacy Impact Assessment (PIA) because gaming systems used in this research project may contain personally identifiable information (PII). Introduction In 2008, DHS S&T was approached by the law enforcement community for assistance in researching a capability to investigate potential crimes being conducted through the use of modern gaming systems. Today s typical gaming systems have processing, multimedia, and networking capabilities rivaling personal computers. Not only are they used to play video games, wireless capabilities enable users to interact and communicate with other players, browse and purchase items over the internet, and stream videos onto their systems. As a result, these gaming platforms are increasingly being used by criminal pedophiles as a tool for identifying and exploiting children. Because of their use by criminals, some gaming systems are being seized by U.S. law enforcement agencies during court-authorized searches. The research and analysis of gaming systems is a relatively unexplored area of digital forensics. At the present time the U.S. government and U.S. law enforcement agencies capabilities to track, engage, and record criminal activity on these systems is limited by a number of factors, including the fact that each gaming system platform uses its own proprietary architecture, software, and communications protocols. The lack of forensic methods for extracting and analyzing information from game consoles is problematic for law enforcement s efforts to investigate and combat criminal activities. The purpose of this project is to research and examine the types of information that may be present on a gaming console (including chat logs) and accessible by law enforcement during an active criminal investigation. The Naval Postgraduate School (NPS) was selected by DHS S&T to complete this work because of its related expertise in the area specifically the development of the Real Data Corpus (RDC) and its experience in developing open source tools for bulk data analysis. DHS S&T is funding this effort to research and develop forensic tools that can support law enforcements efforts to investigate game consoles and similar electronic devices. The forensic tool will be made available by NPS for law enforcement users. S&T will receive a final report from NPS at the end of this project. The RDC is a set of raw data extracted from hard drives, flash memory cards, cellular telephones, and other data-carrying devices that were purchased on the secondary market outside
3 Page 3 the United States. Raw data may include web browsing history, chat logs, addresses, among other data elements. The RDC is currently housed at NPS. Its use for the development of computer forensic tools has been approved by multiple Institutional Review Boards (IRB). Unlike data that is created in a laboratory environment, the structure and content of data in the RDC is both unpredictable and uncontrollable. The data also have a scale and diversity that approaches the scale and diversity of data recovered during actual law enforcement operations. The RDC is typically used as simulated or test data for developing and testing new computer forensic algorithms. This is vitally important, as forensic tool developers typically cannot obtain access to actual case data due to legal restrictions. As is NPS practice, NPS restricts its purchasing of used gaming consoles to systems that have been sold or disposed of by their previous owners outside the United States. Previous experience has shown that used equipment purchased inside the U.S. is highly likely to contain U.S. Person 1 data, while equipment purchased outside the U.S. is less likely to contain such data. As a second level of protection, NPS researchers and NPS contractors protect the information using access control technologies and generally do not attempt to identify any individuals whose information may reside inside the data carrying devices. For most of the project, data is used in aggregate form where it is processed and analyzed in bulk. On occasion, forensic tools used against the RDC may have the capability to extract personal data elements. In such cases, researchers take due diligence to examine the data, in accordance to NPS policies and standards, and deduce whether it belongs to U.S persons. If they find the data may belong to U.S. person, the data is removed from the Real Data Corpus. Finally, NPS policy prohibits the use of data in the RDC from being used in actual cases or for training purposes; the use of the data is limited only to research purposes. No individuals (U.S. Persons and non U.S. persons) are impacted if their data is extracted from the gaming consoles during this project. The RDC and its data are owned and controlled by NPS. DHS S&T is not provided access to the personal information or data on the gaming consoles purchased for this project. Access to that data is limited to NPS researchers and contractors. Fair Information Practice Principles (FIPPs) The Privacy Act of 1974 articulates concepts of how the federal government should treat individuals and their information and imposes duties upon federal agencies regarding the collection, use, dissemination, and maintenance of personally identifiable information. The Homeland Security Act of 2002, Section 222(2) states that the Chief Privacy Officer shall assure that information is handled in full compliance with the fair information practices as set out in the Privacy Act of U.S. Person refers to United States citizens and lawful permanent residents (LPRs).
4 Page 4 In response to this obligation, the DHS Privacy Office developed a set of Fair Information Practice Principles (FIPP) from the underlying concepts of the Privacy Act to encompass the full breadth and diversity of the information and interactions of DHS. The FIPPs account for the nature and purpose of the information being collected in relation to DHS s mission to preserve, protect, and secure. DHS conducts Privacy Impact Assessments on both programs and information technology systems, pursuant to the E-Government Act of 2002, Section 208 and the Homeland Security Act of 2002, Section 222. Given that the Gaming System Monitoring and Analysis project is a software tool rather than a particular information technology system, this PIA is conducted as it relates to the DHS construct of the Fair Information Principles. This PIA examines the privacy impact of the Gaming Systems Monitoring and Analysis research and development work as it relates to the Fair Information Principles. 1. Principle of Transparency Principle: DHS should be transparent and provide notice to the individual regarding its collection, use, dissemination, and maintenance of PII. Technologies or systems using PII must be described in a SORN and PIA, as appropriate. There should be no system the existence of which is a secret. The gaming consoles that are purchased for use during this research project are intentionally bought from markets outside of the United States to avoid the collection of PII from U.S. Persons. NPS immediately deletes any U.S. Person s PII extracted from devices that it acquires under this project. DHS S&T is not collecting the information extracted from the consoles used in this effort, nor will the information be used for any law enforcement investigation. The forensic tools developed from this effort will be distributed to the public by NPS as open source software. 2. Principle of Individual Participation Principle: DHS should involve the individual in the process of using PII. DHS should, to the extent practical, seek individual consent for the collection, use, dissemination, and maintenance of PII and should provide mechanisms for appropriate access, correction, and redress regarding DHS s use of PII. The gaming consoles being purchased for use during this research project have been sold or disposed of by their previous owners. The gaming consoles are intentionally purchased from markets outside of the United States to avoid the collection of PII from U.S. Persons. NPS deletes any U.S. Persons data found on the devices. DHS S&T does not receive any PII from the purchased gaming consoles.
5 Page 5 3. Principle of Purpose Specification Principle: DHS should specifically articulate the authority that permits the collection of PII and specifically articulate the purpose or purposes for which the PII is intended to be used. Law enforcement agencies require forensic tools that can extract information from gaming consoles seized during investigations. DHS S&T is funding this effort to research and develop forensic tools that can support law enforcements efforts to investigate game consoles and similar electronic devices. DHS S&T will not use any data collected for operational law enforcement purposes. 4. Principle of Data Minimization Principle: DHS should only collect PII that is directly relevant and necessary to accomplish the specified purpose(s) and only retain PII for as long as is necessary to fulfill the specified purpose(s). PII should be disposed of in accordance with DHS records disposition schedules as approved by the National Archives and Records Administration (NARA). DHS S&T is not collecting any PII. Any non-u.s. person PII found in the gaming consoles may be included in the RDC, which is used to research, develop, and test prototype systems. The RDC is owned and controlled by NPS; DHS S&T does not receive any PII from the RDC. NPS uses computer security access controls to protect the PII that resides in the RDC If any PII belonging to U.S. persons is identified, NPS immediately removes the data from the RDC. 5. Principle of Use Limitation Principle: DHS should use PII solely for the purpose(s) specified in the notice. Sharing PII outside the Department should be for a purpose compatible with the purpose for which the PII was collected. The non-u.s. Persons information is extracted from the gaming consoles and added to the RDC for the purpose of developing digital forensics tools. This use of the information has been approved by the NPS Institutional Review Board for research. There are no other uses for this information. Any information belonging to U.S. persons is immediately deleted. 6. Principle of Data Quality and Integrity Principle: DHS should, to the extent practical, ensure that PII is accurate, relevant, timely, and complete, within the context of each use of the PII. During the course of this research project, non-u.s. person PII extracted from the gaming systems purchased will be utilized by the researcher to develop and test new digital forensics tools. There will not be any exchange of information to DHS and the data will only be housed in
6 Page 6 the RDC. 7. Principle of Security Principle: DHS should protect PII (in all forms) through appropriate security safeguards against risks such as loss, unauthorized access or use, destruction, modification, or unintended or inappropriate disclosure. DHS S&T does not receive any PII collected during this research project; that information remains in the RDC and controlled by NPS. The deliverables that DHS S&T receive for law enforcement customers will be the forensically-sound data extraction tools that are used for investigative purposes, and as admissible in a court of law. 8. Principle of Accountability and Auditing Principle: DHS should be accountable for complying with these principles, providing training to all employees and contractors who use PII, and should audit the actual use of PII to demonstrate compliance with these principles and all applicable privacy protection requirements. All DHS S&T personnel are required to receive privacy awareness training on an annual basis. However, DHS S&T is not receiving or collecting any PII during this research and development project. The PII found on the gaming systems and collected in the RDC during the effort is not U.S. persons data and remains with NPS as part of the RDC. NPS uses computer security access controls to limit access to the Real Data Corpus and retains a list of all researchers that have had access to the data. All proposed research involving the RDC must first be approved by an Institutional Review Board with a DoD assurance.
7 Page 7 Conclusion The goal of the Gaming System Monitoring and Analysis effort is to research and develop a forensic tool that can extract data from gaming consoles for law enforcement and investigative purposes. During this project, NPS collects gaming consoles that have been sold by their previous owners. NPS only purchases gaming systems from outside the U.S. to minimize PII collected on U.S. Persons. Any non-u.s. Persons PII is retained on the RDC and used to test and validate the developed forensic tool. Any operational use of the tool is outside the scope of this PIA; a separate PIA will need to be conducted by any DHS operational component that plans to deploy the tool for operational use. Responsible Officials Douglas Maughan DHS S&T Cyber Security Division Approval Signature Page Original signed and on file with the DHS Privacy Office. Jonathan R. Cantor Acting Chief Privacy Officer Department of Homeland Security
TSA Advanced Imaging Technology
for TSA Advanced Imaging Technology DHS/TSA/PIA-032(d) December 18, 2015 Contact Point Jill Vaughan Assistant Administrator Office of Security Capabilities [email protected] Reviewing Official
DHS SharePoint and Collaboration Sites
for the March 22, 2011 Robert Morningstar Information Systems Security Manager DHS Office of the Chief Information Officer/Enterprise Service Delivery Office (202) 447-0467 Reviewing Official Mary Ellen
Cell All Demonstration
for the Cell All Demonstration March 2, 2011 Contact Point Stephen Dennis HSARPA Technical Director (202) 254-5788 Reviewing Official Mary Ellen Callahan Chief Privacy Officer Department of Homeland Security
Virginia Systems Repository (VSR): Data Repositories DHS/FEMA/PIA 038(a)
for the (VSR): DHS/FEMA/PIA 038(a) May 12, 2014 Contact Point Tammy Rinard Recovery Directorate (540) 686-3754 Reviewing Official Karen L. Neuman Chief Privacy Officer Department of Homeland Security (202)
May 2 1,2009. Re: DHS Data Privacy and Integrity Advisory Committee White Paper on DHS Information Sharing and Access Agreements
J. Howard Beales Chair, DHS Data Privacy and Integrity Advisory Committee Via Hand Delivery Secretary Janet Napolitano Department of Homeland Security Washington, DC 20528 Ms. Mary Ellen Callahan Chief
Recommendations for the PIA. Process for Enterprise Services Bus. Development
Recommendations for the PIA Process for Enterprise Services Bus Development A Report by the Data Privacy and Integrity Advisory Committee This report reflects the consensus recommendations provided by
Physical Access Control System
for the Physical Access Control System DHS/ALL 039 June 9, 2011 Contact Point David S. Coven Chief, Access Control Branch (202) 282-8742 Reviewing Official Mary Ellen Callahan Chief Privacy Officer (703)
Stakeholder Engagement Initiative: Customer Relationship Management
for the Stakeholder Engagement Initiative: December 10, 2009 Contact Point Christine Campigotto Private Sector Office Policy 202-612-1623 Reviewing Official Mary Ellen Callahan Chief Privacy Officer Department
Privacy Impact Assessment
AUGUST 16, 2013 Privacy Impact Assessment CIVIL PENALTY FUND AND BUREAU-ADMINISTERED REDRESS PROGRAM Contact Point: Claire Stapleton Chief Privacy Officer 1700 G Street, NW Washington, DC 20552 202-435-7220
Department of Homeland Security Web Portals
for the Department of Homeland Security Web Portals June 15, 2009 Contact Point Mary Ellen Callahan Chief Privacy Officer Department of Homeland Security (703) 235-0780 Page 2 Abstract Many Department
9/11 Heroes Stamp Act of 2001 File System
for the 9/11 Heroes Stamp Act of 2001 File System Contact Point Elizabeth Edge US Fire Administration Federal Emergency Management Agency (202) 646-3675 Reviewing Official Nuala O Connor Kelly Chief Privacy
Immigration and Customs Enforcement Forensic Analysis of Electronic Media
for the Immigration and Customs Enforcement Forensic Analysis of Electronic Media DHS/ICE/PIA-042 May 11, 2015 Contact Point Peter T. Edge Executive Assistant Director Homeland Security Investigations
I. U.S. Government Privacy Laws
I. U.S. Government Privacy Laws A. Privacy Definitions and Principles a. Privacy Definitions i. Privacy and personally identifiable information (PII) b. Privacy Basics Definition of PII 1. Office of Management
Clearances, Logistics, Employees, Applicants, and Recruitment (CLEAR)
for Clearances, Logistics, Employees, Applicants, and Recruitment (CLEAR) DHS/USSS/PIA-013 January 3, 2013 Contact Point Latita M. Payne, Privacy Officer United States Secret Service (202) 406-5838 Reviewing
Privacy Impact Assessment. For. Non-GFE for Remote Access. Date: May 26, 2015. Point of Contact and Author: Michael Gray michael.gray@ed.
For Non-GFE for Remote Access Date: May 26, 2015 Point of Contact and Author: Michael Gray [email protected] System Owner: Allen Hill [email protected] Office of the Chief Information Officer (OCIO)
Online Detainee Locator System
for the Online Detainee Locator System April 9, 2010 Contact Point James Chaparro Director, Office of Detention and Removal Operations U.S. Immigration and Customs Enforcement (202) 732-3100 Reviewing
Federal Bureau of Prisons
Federal Bureau of Prisons Privacy Impact Assessment for the Forensic Laboratory Issued by: Sonya D. Thompson, Senior Component Official for Privacy, Sr. Deputy Assistant Director/CIO Approved by: Erika
E-Mail Secure Gateway (EMSG)
for the E-Mail Secure Gateway (EMSG) DHS/MGMT/PIA-006 March 22, 2012 Contact Point David Jones MGMT/OCIO/ITSO/ESDO DHS HQ (202) 447-0167 Reviewing Official Mary Ellen Callahan Chief Privacy Officer Department
Best Practices for. Protecting Privacy, Civil Rights & Civil Liberties. Unmanned Aircraft Systems Programs
U.S. Department of Homeland Security Best Practices for Protecting Privacy, Civil Rights & Civil Liberties In Unmanned Aircraft Systems Programs U.S. Department of Homeland Security Privacy, Civil Rights
Privacy Impact Assessment
Technology, Planning, Architecture, & E-Government Version: 1.1 Date: April 14, 2011 Prepared for: USDA OCIO TPA&E Privacy Impact Assessment for the April 14, 2011 Contact Point Charles McClam Deputy Chief
Port Authority of New York/New Jersey Secure Worker Access Consortium Vetting Services
for the Port Authority of New York/New Jersey Secure Worker Access Consortium Vetting Services DHS/TSA/PIA-040 November 14, 2012 Contact Point Joseph Salvator Office of Intelligence & Analysis [email protected]
Privacy Impact Assessment
MAY 24, 2012 Privacy Impact Assessment matters management system Contact Point: Claire Stapleton Chief Privacy Officer 1700 G Street, NW Washington, DC 20552 202-435-7220 [email protected] DOCUMENT
Canine Website System (CWS System) DHS/TSA/PIA-036 January 13, 2012
for the (CWS System) DHS/TSA/PIA-036 January 13, 2012 Contact Point Carolyn Y. Dorgham Program Manager, National Explosives Detection Canine Team Program [email protected] Reviewing Official Mary
General Support System
PRIVACY IMPACT ASSESSMENT JUNE 30, 2015 General Support System Does the CFPB use the information to benefit or make a determination about an individual? No. What is the purpose? Store and Transmit all
E-Mail Secure Gateway (EMSG)
for the E-Mail Secure Gateway (EMSG) DHS/ALL/PIA-012(b) February 25, 2013 Contact Point David Jones MGMT/OCIO/ITSO/ESDO DHS HQ (202) 447-0167 Reviewing Official Jonathan R. Cantor Acting Chief Privacy
Privacy Impact Assessment
M AY 2, 2013 Privacy Impact Assessment CFPB BUSINESS INTELLIGENCE TOOL Contact Point: Claire Stapleton Chief Privacy Officer 1700 G Street, NW Washington, DC 20552 202-435-7220 [email protected]
Privacy Impact Assessment for the. E-Verify Self Check. DHS/USCIS/PIA-030(b) September 06, 2013
for the E-Verify Self Check DHS/USCIS/PIA-030(b) September 06, 2013 Contact Point Donald K. Hawkins Privacy Officer United States Citizenship and Immigration Services (202) 272-8030 Reviewing Official
CASE MATTER MANAGEMENT TRACKING SYSTEM
for the CASE MATTER MANAGEMENT TRACKING SYSTEM September 25, 2009 Contact Point Mr. Donald A. Pedersen Commandant (CG-0948) (202) 372-3818 Reviewing Official Mary Ellen Callahan Chief Privacy Officer Department
United States Citizenship and Immigration Services (USCIS) Enterprise Service Bus (ESB)
for the United States Citizenship and Immigration Services (USCIS) June 22, 2007 Contact Point Harry Hopkins Office of Information Technology (OIT) (202) 272-8953 Reviewing Official Hugo Teufel III Chief
Student Administration and Scheduling System
for the Student Administration and Scheduling System DHS/FLETC/PIA-002 February 12, 2013 Contact Point William H. Dooley Chief, Office of IT Budget, Policy, & Plans (912) 261-4524 Reviewing Official Jonathan
REMEDY Enterprise Services Management System
for the Enterprise Services Management System April 28, 2016 Contact Point Marshall Nolan Border Enforcement and Management Systems Division Office of Information Technology U.S. Customs & Border Protection
Federal Trade Commission Privacy Impact Assessment
Federal Trade Commission Privacy Impact Assessment for the: W120023 ONLINE FAX SERVICE December 2012 1 System Overview The Federal Trade Commission (FTC, Commission or the agency) is an independent federal
Automated Threat Prioritization Web Service
for the Automated Threat Prioritization Web Service DHS/ICE/PIA-028 June 6, 2011 Contact Point Luke McCormack Chief Information Officer U.S. Immigration and Customs Enforcement (202) 732-3100 Reviewing
FHFA. Privacy Impact Assessment Template FM: SYSTEMS (SYSTEM NAME)
FHFA Privacy Impact Assessment Template FM: SYSTEMS (SYSTEM NAME) This template is used when the Chief Privacy Officer determines that the system contains Personally Identifiable Information and a more
Cyberprivacy and Cybersecurity for Health Data
Experience the commitment Cyberprivacy and Cybersecurity for Health Data Building confidence in health systems Providing better health care quality at lower cost will be the key aim of all health economies
Office of Financial Research Constituent Relationship Management Tool Privacy Impact Assessment ( PIA ) April, 2015
Office of Financial Research Constituent Relationship Management Tool Privacy Impact Assessment ( PIA ) April, 2015 A. Identification System Name: OMB Unique Identifier: System Owner: Constituent Relationship
Homeland Security Virtual Assistance Center
for the Homeland Security Virtual Assistance Center November 3, 2008 Contact Point Donald M. Lumpkins National Preparedness Directorate (FEMA) (202) 786-9754 Reviewing Official Hugo Teufel III Chief Privacy
Computer Linked Application Information Management System
for the Computer Linked Application Information Management System DHS/USCIS/PIA-015(a) August 31, 2011 Contact Point Donald Hawkins Privacy Officer United States Citizenship and Immigration Services (202)
This Instruction implements Department of Homeland Security (DHS) Directive 110-01, Privacy Policy for Operational Use of Social Media.
I. Purpose Department of Homeland Security DHS Directives System Instruction Number: 110-01-001 Revision Number: 00 Issue Date: 6/8/2012 PRIVACY POLICY FOR OPERATIONAL USE OF SOCIAL MEDIA This Instruction
Privacy Impact Assessment for the. E-Verify Self Check. March 4, 2011
for the E-Verify Self Check March 4, 2011 Contact Point Janice M. Jackson Privacy Branch, Verification Division United States Citizenship and Immigration Services 202-443-0109 Reviewing Official Mary Ellen
HSIN R3 User Accounts: Manual Identity Proofing Process
for the HSIN R3 User Accounts: Manual Identity Proofing Process DHS/OPS/PIA-008(a) January 15, 2013 Contact Point James Lanoue DHS Operations HSIN Program Management Office (202) 282-9580 Reviewing Official
NOC Patriot Report Database
for the NOC Patriot Report Database December 7, 2010 Contact Point Ashley Tyler Department of Homeland Security Office of Operations and Coordination and Planning Reviewing Official Mary Ellen Callahan
Privacy Impact Assessment. For Person Authentication Service (PAS) Date: January 9, 2015
For Person Authentication Service (PAS) Date: January 9, 2015 Point of Contact and Author: Hanan Abu Lebdeh [email protected] System Owner: Ganesh Reddy [email protected] Office of Federal Student
Privacy Impact Assessment (PIA) Waiver Review System (WRS) Version 03.06.01.01. Last Updated: December 2, 2013
United States Department of State (PIA) Waiver Review System (WRS) Version 03.06.01.01 Last Updated: December 2, 2013 Bureau of Administration 1. Contact Information Department of State Privacy Coordinator
Crew Member Self Defense Training (CMSDT) Program
for the Crew Member Self Defense Training (CMSDT) Program February 6, 2008 Contact Point Michael Rigney Federal Air Marshal Service Flight Programs Division [email protected] Reviewing Officials Peter
Bonds Online System (ebonds) - Phase One
for the Bonds Online System (ebonds) - Phase One July 14, 2009 Contact Point James T. Hayes, Jr. Director, Office of Detention and Removal U.S. Immigration and Customs Enforcement (202) 732-3100 Reviewing
Introduction to The Privacy Act
Introduction to The Privacy Act Defense Privacy and Civil Liberties Office dpclo.defense.gov 1 Introduction The Privacy Act (5 U.S.C. 552a, as amended) can generally be characterized as an omnibus Code
United States Visitor and Immigrant Status Indicator Technology Program (US-VISIT)
for the Conversion to 10-Fingerprint Collection for the United States Visitor and Immigrant Status Indicator Technology Program (US-VISIT) November 15, 2007 Contact Point Barbara M. Harrison, Acting Privacy
Corporate Leadership Council Metrics
for the Corporate Leadership Council Metrics Contact Point Chris Cejka Director, Strategic Planning and Evaluation Division Human Capital Innovation Office of the Chief Human Capital Officer Department
Department of State SharePoint Server PIA
1. Contact Information A/GIS/IPS Director Department of State SharePoint Server PIA Bureau of Administration Global Information Services Office of Information Programs and Services 2. System Information
Preservation of longstanding, roles and missions of civilian and intelligence agencies
Safeguards for privacy and civil liberties Preservation of longstanding, respective roles and missions of civilian and sharing with targeted liability Why it matters The White House has pledged to veto
Digital Mail Pilot Program
for the Digital Mail Pilot Program June 18, 2010 Contact Point Ronald Boatwright Program Manager, Mail Management (202) 343-4220 Reviewing Official Mary Ellen Callahan Chief Privacy Officer Department
The Bureau of the Fiscal Service. Privacy Impact Assessment
The Bureau of the Fiscal Service Privacy Impact Assessment The mission of the Bureau of the Fiscal Service (Fiscal Service) is to promote the financial integrity and operational efficiency of the federal
Android Developer Applications
Android Developer Applications January 31, 2013 Contact Departmental Privacy Office U.S. Department of the Interior 1849 C Street NW Mail Stop MIB-7456 Washington, DC 20240 202-208-1605 [email protected]
Privacy Impact Assessment
DECEMBER 20, 2013 Privacy Impact Assessment MARKET ANALYSIS OF ADMINISTRATIVE DATA UNDER RESEARCH AUTHORITIES Contact Point: Claire Stapleton Chief Privacy Officer 1700 G Street, NW Washington, DC 20552
Federal Trade Commission Privacy Impact Assessment
Federal Trade Commission Privacy Impact Assessment for the: StenTrack Database System September, 2011 1 System Overview The Federal Trade Commission (FTC) protects America s consumers. As part of its work
Department of the Interior Privacy Impact Assessment
Department of the Interior August 15, 2014 Name of Project: email Enterprise Records and Document Management System (eerdms) Bureau: Office of the Secretary Project s Unique ID: Not Applicable A. CONTACT
Hiring Information Tracking System (HITS)
for the Hiring Information Tracking System (HITS) May 13, 2010 Contact Point Robert Parsons Director, Office of Human Capital U.S. Immigration and Customs Enforcement (202) 732-7770 Reviewing Official
Privacy Act of 1974; Department of Homeland Security <Component Name> - <SORN. AGENCY: Department of Homeland Security, Privacy Office.
DEPARTMENT OF HOMELAND SECURITY Office of the Secretary [Docket No. DHS-2014-] Privacy Act of 1974; Department of Homeland Security -
IAPE STANDARDS SECTION 16 DIGITAL EVIDENCE
IAPE STANDARDS SECTION 16 DIGITAL EVIDENCE IAPE STANDARD SECTION 16.1 DIGITAL EVIDENCE Standard: Digital evidence is a critical element of modern criminal investigation that should be maintained in strict
Privacy Impact Assessment. For. TeamMate Audit Management System (TeamMate) Date: July 9, 2014. Point of Contact: Hui Yang Hui.Yang@ed.
For TeamMate Audit Management System (TeamMate) Date: July 9, 2014 Point of Contact: Hui Yang [email protected] System Owner: Wanda Scott [email protected] Author: Mike Burgenger Office of the Inspector
US-VISIT Program, Increment 1 Privacy Impact Assessment
US-VISIT Program, Increment 1 Privacy Impact Assessment December 18, 2003 Contact Point Steve Yonkers US-VISIT Privacy Officer Department of Homeland Security (202) 298-5200 Reviewing Official Nuala O
DEPARTMENT OF THE INTERIOR. Privacy Impact Assessment Guide. Departmental Privacy Office Office of the Chief Information Officer
DEPARTMENT OF THE INTERIOR Privacy Impact Assessment Guide Departmental Privacy Office Office of the Chief Information Officer September 30, 2014 Table of Contents INTRODUCTION... 1 Section 1.0 - What
How To Ensure Health Information Is Protected
pic pic CIHI Submission: 2011 Prescribed Entity Review October 2011 Who We Are Established in 1994, CIHI is an independent, not-for-profit corporation that provides essential information on Canada s health
Reward TM System Privacy Impact Assessment
Reward TM System Privacy Impact Assessment February 11, 2005 Contact Point John Allen Human Capital Business Systems Department of Homeland Security (202) 357-8285 Reviewing Official Nuala O Connor Kelly
Privacy Impact Assessment. For. Institute of Education Sciences Peer Review Information Management Online (PRIMO) Date: May 4, 2015
For Institute of Education Sciences Peer Review Information Management Online (PRIMO) Date: May 4, 2015 Point of Contact and System Owner: Dr. Anne Ricciuti [email protected] Author: Ellie Pelaez [email protected]
US-VISIT Five Country Joint Enrollment and Information-Sharing Project (FCC)
for the Five Country Joint Enrollment and Information-Sharing Project (FCC) November 2, 2009 Contact Point Paul Hasson, Privacy Officer Program National Protection & Programs Directorate (202) 298-5200
ACCESS, PRODUCTION AND RETENTION OF CITY RECORDS
1.05-3 1 of 6 I. PURPOSE This directive prescribes the rules regarding access, production, and retention of City records. II. POLICY A. All records and other matters in City offices are presumed to be
Bank Secrecy Act E-Filing. Privacy Impact Assessment (PIA) Bank Secrecy Act E-Filing. Version 1.5
Bank Secrecy Act E-Filing Privacy Impact Assessment (PIA) Bank Secrecy Act E-Filing Version 1.5 August13, 2014 E-Filing Privacy Impact Assessment Revision Number Change Effective Date Revision History
Appendix A: Rules of Behavior for VA Employees
Appendix A: Rules of Behavior for VA Employees Department of Veterans Affairs (VA) National Rules of Behavior 1 Background a) Section 5723(b)(12) of title 38, United States Code, requires the Assistant
SECURITY and MANAGEMENT CONTROL OUTSOURCING STANDARD For NON-CHANNELERS
SHP-570A 1/14 SECURITY and MANAGEMENT CONTROL OUTSOURCING STANDARD For NON-CHANNELERS The goal of this document is to provide adequate security and integrity for criminal history record information (CHRI)
Privacy Impact Assessment. For Personnel Development Program Data Collection System (DCS) Date: June 1, 2014
For Personnel Development Program Data Collection System (DCS) Date: June 1, 2014 Point of Contact: Marlene Simon-Burroughs [email protected] System Owner: Bonnie Jones [email protected]
Scotland s Commissioner for Children and Young People Records Management Policy
Scotland s Commissioner for Children and Young People Records Management Policy 1 RECORDS MANAGEMENT POLICY OVERVIEW 2 Policy Statement 2 Scope 2 Relevant Legislation and Regulations 2 Policy Objectives
Recruit Analysis and Tracking System
for the November 30, 2009 Contact Point Tom DeGeorge Mission Support United States Coast Guard Recruiting Command (703) 235-1715 Reviewing Official Mary Ellen Callahan Chief Privacy Officer Department
Council Policy. Records & Information Management
Council Policy Records & Information Management COUNCIL POLICY RECORDS AND INFORMATION MANAGEMENT Policy Number: GOV-13 Responsible Department(s): Information Systems Relevant Delegations: None Other Relevant
Data Management Policies. Sage ERP Online
Sage ERP Online Sage ERP Online Table of Contents 1.0 Server Backup and Restore Policy... 3 1.1 Objectives... 3 1.2 Scope... 3 1.3 Responsibilities... 3 1.4 Policy... 4 1.5 Policy Violation... 5 1.6 Communication...
Personal Information Collection and the Privacy Impact Assessment (PIA)
SEPTEMBER 27, 2012 Privacy Impact Assessment NATIONWIDE MORTGAGE LICENSING SYSTEM AND REGISTRY Contact Point: Claire Stapleton Chief Privacy Officer 1700 G Street, NW Washington, DC 20552 202-435-7220
Screening of Passengers by Observation Techniques (SPOT) Program
for the Screening of Passengers by Observation Techniques (SPOT) Program August 5, 2008 Contact Point Michael Kimlick, Branch Chief, Behavior Detection and Travel Document Validation Branch, Screening
Were there other system changes not listed above? No 3. Check the current ELC (Enterprise Life Cycle) Milestones (select all that apply)
Date of Approval: October 9, 2015 PIA ID Number: 1448 A. SYSTEM DESCRIPTION 1. Enter the full name and acronym for the system, project, application and/or database. AIMS Centralized Information System,
Customer Scheduling and Services
for the Customer Scheduling and Services DHS/USCIS/PIA-046 March 25, 2014 Contact Point Donald K. Hawkins Privacy Officer U.S. Citizenship and Immigration Services (202) 272-8000 Reviewing Official Karen
Authentication and Provisioning Services (APS)
for the (APS) DHS/FEMA/PIA-031 August 6, 2013 Contact Point Tina Wallace-Fincher Information Technology Security Branch FEMA Information Technology (202) 646-4605 Reviewing Official Jonathan R. Cantor
United States Department of State Privacy Impact Assessment Risk Analysis and Management
United States Department of State Privacy Impact Assessment Risk Analysis and Management Bureau of Administration 1. Contact Information Risk Analysis and Management (RAM) PIA Department of State Privacy
DHS / UKvisas Project
for the DHS / UKvisas Project November 14, 2007 Contact Point Elizabeth Gaffin Associate Counsel United States Citizenship and Immigration Services 202-272-1400 Reviewing Official Hugo Teufel III Chief
Integrated Digitization Document Management Program (IDDMP)
for the Integrated Digitization Document Management Program January 5, 2007 Contact Point Elizabeth Gaffin Privacy Officer U.S. Citizenship and Immigration Services (USCIS) (202) 272-1400 Reviewing Official
