11.07.2015 Views

HSIN-Intelligence Portal - Center for Investigative Reporting

HSIN-Intelligence Portal - Center for Investigative Reporting

HSIN-Intelligence Portal - Center for Investigative Reporting

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

FOROFFICIALUSEONLYPrivacy Impact Assessment<strong>Intelligence</strong>&Analysis,<strong>HSIN</strong><strong>Intelligence</strong>Page269.2 Describe how data integrity, privacy, and security were analyzed aspart of the decisions made <strong>for</strong> your system.System developers of <strong>HSIN</strong>-<strong>Intelligence</strong> recognized from the beginning the need to ensure theintegrity, privacy, and security of the sensitive in<strong>for</strong>mation to be collected, used, and disseminated on thesystem. All decisions about system design were based on the need to ensure data integrity, embed strongprivacy controls, and implement robust security features.(b)(2) High9.3 What design choices were made to enhance privacy?(b)(2) High, in order to bolsterprivacy protections, <strong>HSIN</strong>-<strong>Intelligence</strong> requires that a “minimization” process be employed whereby allreports, analyses, assessments, and other products, prior to dissemination by I&A (i.e., posted onto the HSSLIC compartment), are reviewed to assess and determine whether the specific U.S. person identityin<strong>for</strong>mation is necessary <strong>for</strong> the use of or understanding of the product by the intended recipients. Thus,<strong>for</strong> documents disseminated by I&A within the HS SLIC where the U.S. Person in<strong>for</strong>mation or identity isnot necessary to understand the product, the identity in<strong>for</strong>mation will be “masked” by removing andreplacing it with “a U.S. Person,” “USPER,” or some similar marking, as appropriate. Where an I&Aproduct on the HS SLIC will include U.S. person identifying in<strong>for</strong>mation, the product itself will carry awarning stating that “This product contains U.S. Person In<strong>for</strong>mation” or words to that effect. This is donein accordance with I&A’s <strong>Intelligence</strong> Oversight obligations and policies, and the I&A In<strong>for</strong>mation HandlingGuidelines.As discussed above, (b)(2) High technology was selected because it provides the programmanagement staff the tools necessary <strong>for</strong> I&A to comply, not only with the <strong>Intelligence</strong> Community’soversight responsibilities uniquely applicable within <strong>HSIN</strong> <strong>Intelligence</strong> to I&A, but to facilitate compliancewith the Privacy framework (e.g., 28 CFR Part 23) <strong>for</strong> any other organization with access to, including thecapability to post and exchange its own in<strong>for</strong>mation within, certain portions of the portal. This was aspecific design choice made to enhance accountability surrounding the possible use of personallyidentifiable in<strong>for</strong>mation in the HS SLIC portion of <strong>HSIN</strong>-<strong>Intelligence</strong>.Conclusion<strong>HSIN</strong>-<strong>Intelligence</strong> was deployed as an Internet-based plat<strong>for</strong>m to ensure compatibility andinteroperability among interrelated communities of users securely exchanging critical sensitive in<strong>for</strong>mationrelevant to their official domestic security missions while also ensuring that the integrity and privacy ofindividuals’ data was maintained consistent with their own applicable standards, laws, policies, andprocedures. For the HS SLIC compartment of the portal, U.S. person identifying in<strong>for</strong>mation is routinelyminimized unless the in<strong>for</strong>mation is required <strong>for</strong> understanding the specific intelligence report, analysis,assessment or other product. This significantly mitigates the privacy risks <strong>for</strong> in<strong>for</strong>mation accessiblethrough <strong>HSIN</strong> <strong>Intelligence</strong>. For those documents that do contain personally identifiable in<strong>for</strong>mation, anumber of safeguards are in place to protect the privacy and integrity of the in<strong>for</strong>mation. The registrationFOROFFICIALUSEONLY

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!