Shows & Panels
- The 2014 Big Picture on Cyber Security
- AFCEA Answers
- Ask the CIO
- Connected Government
- Consolidating Mission-critical Systems
- Constituent Servicing
- Continuous Monitoring: Tools and Techniques for Trustworthy Government IT
- The Data Privacy Imperative: Safeguarding Sensitive Data
- Eliminating the Pitfalls: Steps to Virtualization in Government
- Federal Executive Forum
- Federal Tech Talk
- Government Cloud Brokerage: Who, What, When, Where, Why?
- Government Mobility
- Mission-critical Apps in the Cloud
- Mobile Device Management
- The Modern Federal Threat Landscape
- The Path from Legacy Systems
- Understanding the Intersection of Customer Service and Security in the Cloud
Shows & Panels
OIRA outlines privacy assessments for using 3rd party websites
Thursday - 1/5/2012, 3:02pm EST
Kevin Nyland, the deputy administrator in OMB's Office of Information and Regulatory Policy, sent agency chief information officers a memo Dec. 29 outlining how agencies should prepare an adapted Privacy Impact Assessment (PIA). The PIA should address specific functions of a third-party website or application that the agency is using.
Agencies must complete the PIA before using a third-party website, which could include commercial offerings such as YouTube, Facebook or survey sites.
"To facilitate agency use of third-party websites and applications, OMB has worked with the CIO Council's Privacy Committee to develop a model PIA reflecting the requirements for an adapted PIA," the memo stated.
The PIA memo calls on agencies to develop a PIA with eight sections:
- Specific purpose of how the agency is using the third-party site or application.
- Any personal identifiable information (PII) likely to become available to the agency through the use of the site or app.
- How the agency will use the PII.
- How the agency will share or disclose the personal information.
- How the agency will maintain and retain the personal information.
- How will the PII be secured.
- How the agency will identify and mitigate other privacy risks.
- How the agency will create or modify a system of records.
"An agency may prepare one PIA to cover multiple websites or applications that are functionally comparable, as long as the agency's practices are substantially similar across each website and application," the memo stated.
"For example, one PIA may be sufficient to cover an agency's use of multiple social media websites where limited PII is made available to the agency, but none is collected, shared or maintained. However, if an agency's use of a website or application raises distinct privacy risks, the agency should prepare a PIA that is exclusive to that website or application."