11.07.2015 Views

Independent Auditor's Report on Applying Agreed-Upon Procedures ...

Independent Auditor's Report on Applying Agreed-Upon Procedures ...

Independent Auditor's Report on Applying Agreed-Upon Procedures ...

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

<str<strong>on</strong>g>Independent</str<strong>on</strong>g> Assessment of U.S. Agency for Internati<strong>on</strong>al Development’sCompliance with §522 of the C<strong>on</strong>solidated Appropriati<strong>on</strong>s Act of 2005BackgroundThe United States Agency for Internati<strong>on</strong>al Development (USAID) is an independentFederal Agency resp<strong>on</strong>sible for c<strong>on</strong>ducting foreign assistance and humanitarian aid,advancing the political and ec<strong>on</strong>omic interests of the United States. USAID, based inWashingt<strong>on</strong>, DC, operates in about 100 developing countries and provides assistance tothese countries by supporting:• Ec<strong>on</strong>omic growth, agriculture, and trade;• Global health; and• Democracy, c<strong>on</strong>flict preventi<strong>on</strong>, and humanitarian assistance.The C<strong>on</strong>solidated Appropriati<strong>on</strong>s Act of 2005 (Public Law 108-447), Divisi<strong>on</strong> HTransportati<strong>on</strong>/Treasury, Title V, §522 (hereafter referred to as §522), requires that eachAgency designate a Chief Privacy Officer to assume primary resp<strong>on</strong>sibility for privacyand data protecti<strong>on</strong> policy. The act also requires each agency to:1. Establish and implement comprehensive privacy and data protecti<strong>on</strong> proceduresgoverning the agency’s collecti<strong>on</strong>, use, sharing, disclosure, transfer, storage andsecurity of informati<strong>on</strong> in an identifiable form relating to the agency employeesand the public;2. Prepare a written report of its use of informati<strong>on</strong> in an identifiable form, al<strong>on</strong>g withits privacy and data protecti<strong>on</strong> policies and procedures and record it with theInspector General of the agency to serve as a benchmark for the agency. Eachreport shall be signed by the agency privacy officer to verify that the agencyintends to comply with the procedures in the report; and3. Have an independent third party review performed at least every two years <strong>on</strong>the agency’s use of informati<strong>on</strong> in an identifiable form.ObjectiveUrbach Kahn & Werlin (UKW) was engaged by USAID’s Office of Inspector General(OIG), Informati<strong>on</strong> Technology and Special Audits Divisi<strong>on</strong>, to c<strong>on</strong>duct an independentassessment to determine USAID’s compliance with §522 of the C<strong>on</strong>solidatedAppropriati<strong>on</strong>s Act of 2005. As a result, the objective of this review was to answer thefollowing questi<strong>on</strong>:Did USAID develop and implement comprehensive privacy and dataprotecti<strong>on</strong> procedures as required by the C<strong>on</strong>solidated Appropriati<strong>on</strong>s Act of2005, §522?2

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!