Shows & Panels
- The 2014 Big Picture on Cyber Security
- AFCEA Answers
- Ask the CIO
- Building the Hybrid Cloud
- Connected Government: How to Build and Procure Network Services for the Future
- Continuing Diagnostics and Mitigation: Discussion of Progress and Next Steps
- Federal Executive Forum
- Federal Tech Talk
- The Intersection: Where Technology Meets Transformation
- Maximizing ROI Through Data Center Consolidation
- Moving to the Cloud. What's the best approach for me
- Navigating Tough Choices in Government Cloud Computing
- The New Generation of Database
- Satellite Communications: Acquiring SATCOM in Tight Times
- Targeting Advanced Threats: Proven Methods from Detection through Remediation
- Transformative Technology: Desktop Virtualization in Government
- Value of Health IT
Shows & Panels
OIRA outlines privacy assessments for using 3rd party websites
Thursday - 1/5/2012, 3:02pm EST
Kevin Nyland, the deputy administrator in OMB's Office of Information and Regulatory Policy, sent agency chief information officers a memo Dec. 29 outlining how agencies should prepare an adapted Privacy Impact Assessment (PIA). The PIA should address specific functions of a third-party website or application that the agency is using.
Agencies must complete the PIA before using a third-party website, which could include commercial offerings such as YouTube, Facebook or survey sites.
"To facilitate agency use of third-party websites and applications, OMB has worked with the CIO Council's Privacy Committee to develop a model PIA reflecting the requirements for an adapted PIA," the memo stated.
The PIA memo calls on agencies to develop a PIA with eight sections:
- Specific purpose of how the agency is using the third-party site or application.
- Any personal identifiable information (PII) likely to become available to the agency through the use of the site or app.
- How the agency will use the PII.
- How the agency will share or disclose the personal information.
- How the agency will maintain and retain the personal information.
- How will the PII be secured.
- How the agency will identify and mitigate other privacy risks.
- How the agency will create or modify a system of records.
"An agency may prepare one PIA to cover multiple websites or applications that are functionally comparable, as long as the agency's practices are substantially similar across each website and application," the memo stated.
"For example, one PIA may be sufficient to cover an agency's use of multiple social media websites where limited PII is made available to the agency, but none is collected, shared or maintained. However, if an agency's use of a website or application raises distinct privacy risks, the agency should prepare a PIA that is exclusive to that website or application."