U.S. DEPARTMENT OF COMMERCE UNITED STATES PATENT AND TRADEMARK OFFICE. Privacy Impact Assessment

Similar documents
U.S. DEPARTMENT OF COMMERCE UNITED STATES PATENT AND TRADEMARK OFFICE. Privacy Impact Assessment

U.S. DEPARTMENT OF COMMERCE UNITED STATES PATENT AND TRADEMARK OFFICE. Privacy Impact Assessment

U.S. DEPARTMENT OF COMMERCE UNITED STATES PATENT AND TRADEMARK OFFICE. Privacy Impact Assessment

U.S. DEPARTMENT OF COMMERCE UNITED STATES PATENT AND TRADEMARK OFFICE. Privacy Impact Assessment

U.S. DEPARTMENT OF COMMERCE UNITED STATES PATENT AND TRADEMARK OFFICE. Privacy Impact Assessment

How To Use The Revenue Accounting And Management System (Ram) System

U.S. DEPARTMENT OF COMMERCE UNITED STATES PATENT AND TRADEMARK OFFICE. Privacy Impact Assessment

Privacy Impact Assessment

U.S. DEPARTMENT OF COMMERCE UNITED STATES PATENT AND TRADEMARK OFFICE. Privacy Impact Assessment

Privacy Impact Assessment (PIA) for the. Certification & Accreditation (C&A) Web (SBU)

Privacy Impact Assessment

Privacy Impact Assessment

Privacy Impact Assessment. For Person Authentication Service (PAS) Date: January 9, 2015

Privacy Impact Assessment. For. Non-GFE for Remote Access. Date: May 26, Point of Contact and Author: Michael Gray

Crew Member Self Defense Training (CMSDT) Program

Network Infrastructure - General Support System (NI-GSS) Privacy Impact Assessment (PIA)

Privacy Impact Assessment Forest Service Computer Base Legacy

Federal Trade Commission Privacy Impact Assessment for:

Homeland Security Virtual Assistance Center

Privacy Impact Assessment For Management Information System (MIS) Date: September 4, Point of contact: Hui Yang

Privacy Impact Assessment. For. TeamMate Audit Management System (TeamMate) Date: July 9, Point of Contact: Hui Yang

U.S. DEPARTMENT OF COMMERCE UNITED STATES PATENT AND TRADEMARK OFFICE. Privacy Impact Assessment

General Support System

Federal Trade Commission Privacy Impact Assessment. Conference Room Scheduling PIA

8. Does this system collect, display, store, maintain or disseminate Personally Identifiable Information (PII)? Yes

Domain Management with EMC Unisphere for VNX

I. U.S. Government Privacy Laws

Federal Trade Commission Privacy Impact Assessment

Office of Financial Research Constituent Relationship Management Tool Privacy Impact Assessment ( PIA ) April, 2015

A. SYSTEM DESCRIPTION

Federal Trade Commission Privacy Impact Assessment. for the: Secure File Transfer System

Federal Trade Commission Privacy Impact Assessment. for the: Analytics Consulting LLC Claims Management System and Online Claim Submission Website

Federal Trade Commission Privacy Impact Assessment. for the: Gilardi & Co., LLC Claims Management System and Online Claim Submission Website

A. SYSTEM DESCRIPTION

A. SYSTEM DESCRIPTION

Privacy Impact Assessment for the Volunteer/Contractor Information System

Privacy Impact Assessment for Threat Assessments for Access to Sensitive Security Information for Use in Litigation December 28, 2006

U.S. Department of Transportation. Privacy Impact Assessment (Update) National Registry of Certified Medical Examiners (National Registry)

Were there other system changes not listed above? No 3. Check the current ELC (Enterprise Life Cycle) Milestones (select all that apply)

Central Application Tracking System (CATS) Privacy Impact Assessment (PIA) Version 1.0. April 28, 2013

A. SYSTEM DESCRIPTION

Department of Homeland Security Web Portals

8. Does this system collect, display, store, maintain or disseminate Personally Identifiable Information (PII)? Yes

Privacy Impact Assessment for the. January 19, 2007

Privacy Impact Assessment. For Personnel Development Program Data Collection System (DCS) Date: June 1, 2014

Data Collection Agent for NAS EMC Isilon Edition

Privacy Impact Assessment (PIA)

A. SYSTEM DESCRIPTION

Department of the Interior Privacy Impact Assessment

ERIC - A Guide to an Introduction

Market Research in the Field v.1

Federal Trade Commission Privacy Impact Assessment for:

Privacy Recommendations for the Use of Cloud Computing by Federal Departments and Agencies. Privacy Committee Web 2.0/Cloud Computing Subcommittee

Privacy Impact Assessment. For Rehabilitation Services Administration Management Information System (RSA-MIS) Date: November 19, 2014

Final Audit Report. Report No. 4A-CI-OO

Permit Power of Attorney (PoA) to establish an agreement on behalf of the taxpayer

US Federal Student Aid Datashare (SBU-PII) Application and Database

A. SYSTEM DESCRIPTION

A. SYSTEM DESCRIPTION

REMEDY Enterprise Services Management System

Web Time and Attendance

A. SYSTEM DESCRIPTION

24x7 Incident Handling and Response Center

PRIVACY IMPACT ASSESSMENT TEMPLATE

Federal Trade Commission Privacy Impact Assessment. for the:

8. Does this system collect, display, store, maintain or disseminate Personally Identifiable Information (PII)? Yes

Privacy Impact Assessment. For EDUCATE. Date October 28, Point of Contact: System Owner: Lisa Mendis Author: Michael Rohde

UNITED STATES PATENT AND TRADEMARK OFFICE. AGENCY ADMINISTRATIVE ORDER Agency Administrative Order Series. Secure Baseline Attachment

Privacy Impact Assessment. For Education s Central Automated Processing System (EDCAPS) Date: October 29, 2014

Online Detainee Locator System

Federal Bureau of Prisons. Privacy Impact Assessment for the HR Automation System. Issued by: Sonya D. Thompson Deputy Assistant Director/CIO

Pacific Life Insurance Company

EMC CLARiiON Secure Remote Support Solutions Technical Notes P/N REV A03 October 5, 2010

United States Patent and Trademark Office

U.S. OFFICE OF PERSONNEL MANAGEMENT OFFICE OF THE INSPECTOR GENERAL OFFICE OF AUDITS. Final Audit Report

PRIVACY IMPACT ASSESSMENT

CLARiiON Performance Monitoring Scripting

Canine Website System (CWS System) DHS/TSA/PIA-036 January 13, 2012

How To Protect Data On Network Attached Storage (Nas) From Disaster

Department of the Interior Privacy Impact Assessment

Department of the Interior Privacy Impact Assessment (PIA) Updated February 2011

AX4 5 Series Software Overview

8. Does this system collect, display, store, maintain or disseminate Personally Identifiable Information (PII)? Yes

A. SYSTEM DESCRIPTION

Department of State SharePoint Server PIA

Physical Access Control System

Department of the Interior Privacy Impact Assessment

Privacy Impact Assessment. Date: April 18, Point of Contact: Jim Hibberd KratosLearning.com

Privacy Impact Assessment for TRUFONE Inmate Telephone System

Authentication and Provisioning Services (APS)

FHFA. Privacy Impact Assessment Template FM: SYSTEMS (SYSTEM NAME)

8. Does this system collect, display, store, maintain or disseminate Personally Identifiable Information (PII)? Yes

U.S. Securities and Exchange Commission. Mailroom Package Tracking System (MPTS) PRIVACY IMPACT ASSESSMENT (PIA)

USDA. Privacy Impact Assessment. APHIS Enterprise Infrastructure General Support System (AEI GSS)

Student Administration and Scheduling System

Stakeholder Engagement Initiative: Customer Relationship Management

8. Does this system collect, display, store, maintain or disseminate Personally Identifiable Information (PII)? Yes

Mapping Information Platform (MIP)

NTP Software File Reporter Analysis Server

Transcription:

U.S. DEPARTMENT OF COMMERCE UNITED STATES PATENT AND TRADEMARK OFFICE Privacy Impact Assessment Storage Infrastructure Managed Services (SIMS) DOC50PAPT0905000 05/29/2015

Privacy Impact Assessment This Privacy Impact Assessment (PIA) is a requirement of the Privacy Act of 1987 and OMB Memorandum 03-22, OMB Guidance for Implementing the Privacy Provisions of the E-Government Act of 2002. A PIA documents the due diligence and oversight placed upon information associated with the project or system in question. Written from the System Owner s perspective for the American public, the PIA discloses what information is being collected, and how that information is protected. The intent is to build confidence that privacy information is secure, processes that utilize this information comply with Federal requirements, and more importantly, inform the privacy expectations of the American public. The Privacy Threshold Analysis (PTA) is a separate artifact that must be completed prior to beginning this PIA. In many cases, the PTA will be the only required artifact to satisfy DOC privacy considerations.

SYSTEM DESCRIPTION The Storage Infrastructure Managed Services (SIMS) is a detailed Storage Infrastructure which is designed for an extremely high level of availability, reliability, and resiliency, for blocks and file data types. The Storage Infrastructure is spread across three (3) different data centers, each providing a specific role; the Alexandria production data center, the Boyers data center, and the Test and Development Lab data center (Alexandria). The SIMS architecture denotes the Boyers component to be an alternate processing site, beyond the current function of a data bunkering site. The SIMS provides disk-based storage and consists of data center storage equipment that includes Storage Area Network (SAN) switches and storage devices consisting of Tier 1, Tier 2, and Network Attached Storage (NAS) devices. The Tier 1 SAN is used to support systems that require high-performance inputs and outputs (I/O) and currently consists of EMC a VMAX-40K storage array running higher performance drives.. The Tier 2 SAN supports systems that have less demanding I/O requirements, but is contained inside of the Tier 1 VMAX-40K storage array, comprised of lower performing disk drives. The NAS consists of EMC Isilon system. Other devices at the Alexandria location include EMC CLARiiON and Symmetrix storage arrays, and NetApp devices. There are currently four main types of devices at the Boyers site: EMC CLARiiON and Symmetrix storage arrays, and NetApp and EMC NAS devices. The SIMS relies on a data bunkering system (DBS) component for data replication between the Alexandria and Boyers sites. EMC RecoverPoint provides the Continuous Remote Replication (CRR) as well as local and remote data protection, enabling reliable replication of data over any distance. The solution consists of enterprise class arrays with virtual storage technology that delivers data mobility and availability across the arrays for all of the defined storage classes at the Production, Boyers, and Lab environments.

QUESTIONNAIRE 1. What information is collected (e.g., nature and source)? Patent products include patent grants and patent application publications in image, text, text and image, and bibliographic forms; and additional information such as patent assignments, maintenance fee events, etc. Design Patents, Plant Patents, Reexamination Certificates (available only in Patent Grant Image files), Reissue Patents, Statutory Invention Registration (SIR) documents, Utility Patents. Trademark products include registration images, application text, assignment text, and Trademark Trial and Appeal Board (TTAB) text. Applicant names and addresses are collected as well. 2. Why is this information being collected (e.g., to determine eligibility)? The Patent organization examines patent applications to compare the scope of claimed subject matter to a large body of technological information to determine whether the claimed invention is new, useful, and non-obvious. Patent examiners also provide answers on applications appealed to the Board of Patent Appeals and Interferences (BPAI), prepare initial memoranda for interference proceedings to determine priority of invention, and prepare search reports and international preliminary examination reports for international applications filed under the Patent Cooperation Treaty (PCT). The Trademark organization registers marks (trademarks, service marks, certification marks, and collective membership marks) that meet the requirements of the Trademark Act of 1946, as amended, and provides notice to the public and businesses of the trademark rights claimed in the pending applications and existing registrations of others 3. What is the intended use of information (e.g., to verify existing data)? To determine whether the claimed invention is new, useful, and non-obvious and define trademarks, etc., to ensure infringements rights are protected. 4. With whom will the information be shared (e.g., another agency for a specified programmatic purpose)? USPTO provides notice to the public and businesses of the trademark rights claimed in the pending applications and existing registrations. Information may be shared with other NIST or Department of Commerce systems, in accordance with the Privacy Act. 5. What opportunities do individuals have to decline to provide information (i.e., where providing information is voluntary) or to consent to particular uses of the information (other than required or authorized uses), and how can individuals grant consent? Users are notified of the USPTO privacy policy which states: we collect no personal information about you when you visit our website unless you choose to provide that information to us. Submitting personal information is voluntary. When you voluntarily submit information, it constitutes your consent to the use of the information for the purpose(s) stated at the time of collection. See the Privacy Act of 1974 (P.L. 93-579) for more information on your rights under the Privacy Act. Users who provide information to facilitate patent applications and trademarking are informed of the use of the information when it is requested and may decline to provide personal information. Businesses which contract with USPTO to perform patent applications and trademarking give their consent as part of the arrangements needed to complete these transactions.

6. How will the information be secured (e.g., administrative and technological controls)? As required by FIPS 199, the SIMS and its components were reviewed for the sensitivity of the information in them, and were determined to require protection appropriate for Moderate Impact systems. All relevant policies, procedures and guidelines, including NIST Special Publication 800-53, have been followed to ensure the security of the systems and the information in them. The System Security Plan on file with the SIMS Security Officer contains additional details. All users are authenticated via the domain and have password-sensitive screen savers enabled. All systems are running Antivirus software, desktop management software, and spy-ware elimination software. SIMS will also utilize PKI (Public Key Infrastructure) technologies and methods to secure information and transactions. Without proper identification (Customer Numbers and Digital Certificates) users are restricted to services such as pending application statuses or financial transactions. SIMS will also be accredited in accordance with Federal and Agency policies and guidelines. 7. How will the data extract log and verify requirement be met? Audit information for EMC storage systems is contained within the event log on each Storage Processor (SP). The log contains hardware and software debug information as well as audit information. It contains a time-stamped record for each event, and each record contains the following information: Event code Description of event Name of the storage system Name of the corresponding SP Hostname associated with the SP The Storage Management Server adds audit records to the event log. An audit record is created each time a user logs in, enters a request through Unisphere, or executes a Secure CLI command. Each audit record is time-stamped, and identifies the following additional information for each request: Requestor (Unisphere username) Type of request Target of request Success or failure of request The Storage Management Server also restricts the ability to clear the audit log to administrators and security administrators only. Whenever the log is cleared by an authorized user, an event is logged to the beginning of the new log. This prevents users from removing evidence of their actions. 8. Is a system of records being created under the Privacy Act, 5 U.S.C. 552a? Yes, these records constitute a system of records within the meaning of the Privacy Act, and a system of records notice (SORN) is required 9. Are these records covered by a record control schedule approved by the National Archives and Records Administration (NARA)? Records created by individual areas using SIMS are scheduled under National Archives and Records Administration (NARA) approved record retention schedules: