Showing posts with label ISE-SAR. Show all posts
Showing posts with label ISE-SAR. Show all posts

Tuesday, December 21, 2010

Suspicious Activity Reporting Final Rule

The Department of Homeland Security published their final rule to amend its regulations to exempt portions of a newly established system of records titled, “Department of Homeland Security/ALL – 031 Information Sharing Environment, in the Federal Register today. This rule goes into effect today.

This follows the submission of an NPRM back in September, upon which I previously reported. DHS received a few comments, mostly supportive, on that NPRM and they address those comments in the preamble to this final rule, clarifying a number of issues.

Justice Department Program

One important area of clarification that DHS makes in this rule document is that the underlying program that this rule supports, the Nationwide Suspicious Activity Reporting Initiative (NSI), is overseen by the Department of Justice (DOJ). Thus DHS is required to adhere “to the requirements established by the NSI requiring participants to apply the ISE-SAR Functional Standard Version 1.5 in determining whether a suspicious activity is an ISE-SAR” (75 FR 79947).

This clarification also has applications to the definition of one of the controversial terms used in the NPRM. The NPRM described the people who might have access to the collected information as “federal departments and agencies, state, local and tribal law enforcement agencies, and the private sector [emphasis added]” (75 FR 55290). In the preamble to this rule DHS explains that it “does not maintain a list of private sector partners or entities who are authorized NSI participants” as that responsibility rests with the DOJ system managers.

FOIA

One commentor wanted DHS to clarify which items of information would be protected under the Freedom of Information Act, requesting blanket exception be described for certain classes of information. DHS responded that this rule does not provide any exceptions to the FOIA disclosure rules. They also note that the “FOIA currently does not provide for a standard “blanket exception” for ISE-SARs data filed by a private-sector entity reporting an information-security related attack” (75 FR 79949).

DHS does note that that if an FOIA request was received asking for disclosure of information about a reported cyber security attack by a private sector organization that the current FOIA rules, for example “Exemption 4 which applies to trade secrets and commercial or financial information obtained from a person that is privileged or confidential may apply in this instance), would be applied when processing that request.

Personally Identifiable Information

A comment was received questioning the protection of personally identifiable information in the DHS ISE-SAR program. Again, DHS reminds the commentor that the use of personally identifiable information in the NSI is not governed by DHS rules. DHS does maintain that the information that it enters into the system will be via the “Summary ISE-SAR Information format, which excludes privacy fields or data elements that contain PII as identified in Section IV of the ISE-SAR Functional Standard”.

Further Questions

DHS notes that anyone with additional general questions about this rule and the associated “Department of Homeland Security/ALL – 031 Information Sharing Environment Suspicious Activity Reporting Initiative System of Records” should contact the DHS Office of Intelligence and Analysis or the DHS Privacy Office.

Friday, September 10, 2010

Information Sharing Environment Notices

Today the Department of Homeland Security published two notices in the Federal Register. The first notice announced the establishment of a new system of records that will be maintained by the Department while the second notice is a required notice of proposed rule making (NPRM) notifying the public that it intends to exempt portions of that new record system from one or more provisions of the Privacy Act because of criminal, civil, and administrative enforcement requirements.

The new record system that will be maintained by DHS is the Information Sharing Environment (ISE) Suspicious Activity Reporting (SAR) Initiative System of Records. This will allow currently collected Suspicious Activity Reports from various agencies within DHS to be collected, analyzed and shared. The information is expected to be shared “with authorized participants in the Nationwide Suspicious Activity Reporting Initiative, including other DHS components, federal departments and agencies, state, local and tribal law enforcement agencies, and the private sector” (75 FR 55335).

The compilation of the SARS will be authorized as long as those reports meet the established ISE Functional Standard for Suspicious Activity Reporting. According to the program notice that standard “defines an ISE-SAR as official documentation of observed behavior determined to have a potential nexus to terrorism (i.e., to be reasonably indicative of criminal activity associated with terrorism)” (75 FR 55336).

The exemption to Privacy Act rules is being claimed because some of the information being collected analyzed and disseminated relates “to official DHS national security, law enforcement, immigration, intelligence activities, and protective services to the President of the U.S. or other individuals pursuant to Section 3056 and 3056A of Title 18” (75 FR 55291). The NPRM notes that the “exemptions proposed here are standard law enforcement and national security exemptions exercised by a large number of federal law enforcement and intelligence agencies” (75 FR 55291).

Public comments on both the establishment of the system of records (Docket DHS-2010-0075) and the claimed law enforcement exemption to provisions of the Privacy Act (Docket DHS-2010-0076) may be filed via the Federal e-Rulemaking Portal. Such comments need to be filed by October 12th, 2010.
 
/* Use this with templates/template-twocol.html */