DEPARTMENT OF TRANSPORTATION
Office of the Secretary of Transportation (OST)
PRIVACY IMPACT ASSESSMENT
November 1, 2007
TABLE OF CONTENTS
Overview of Privacy Management Process
Personally Identifiable Information (PII) & Enterprise Support Systems (ESS)
Why Enterprise Support Systems (ESS) Collects Information
How Enterprise Support Systems (ESS) Uses Information
How Enterprise Support Systems (ESS) Shares Information
How Enterprise Support Systems (ESS) Provides Notice and Consent
How Enterprise Support Systems (ESS) Ensures Data Accuracy
How Enterprise Support Systems (ESS) Provides Redress
How Enterprise Support Systems (ESS) Secures Information
How Long Enterprise Support Systems (ESS) Retains Information
System of Records
Enterprise Support Systems (ESS) consists of B-30 functionality that is utilized by other B-30 Systems, such as Delphi & CASTLE. Three sub-systems have been identified as the following:
Privacy management is an integral part of the Enterprise Support Systems (ESS). AME has retained the services of privacy experts to help assess its privacy management program, utilizing proven technology, sound policies and procedures, and established methodologies.
The privacy management process is built upon a methodology that has been developed and implemented in leading companies around the country and globally. The methodology is designed to help ensure that DOT and AME will have the information, tools and technology necessary to manage privacy effectively and employ the highest level of fair information practices while allowing AME to achieve its mission of protecting and enhancing the U.S. transportation system. The methodology is based upon the following steps:
ESS is hosted and supported by the Enterprise Service Center (ESC) located at the Federal Aviation Administration (FAA), Mike Monroney Aeronautical Center (MMAC), in Oklahoma City. ESS hardware physically resides in the System Management Facility (SMF), which are a consolidated data processing and support facility for small and large scale, general and special purpose data processing and telecommunications systems at the MMAC.
Per DOT, all agency data is considered sensitive data and it may or may not contain PII. The Enterprise Support System consists of functionality that is being used by all B-30 systems.
The Enterprise Support System collects information that will be utilized by both B-30 systems.
Kintana is utilized by ESS as a means of tracking & mitigating System Change Request (SCR). In mitigating SCR’s, test results are sometimes attached to provide proof documentation that the enhancement was tested. If the attachment contains PII, it is encrypted. If encryption is not used, all PII/SPII fields are masked out with a comment in the notes field dictating as such. All other sub-systems of ESS do not display data to the users.
Kintana is utilized by ESS as a means of tracking & mitigating System Change Request (SCR). In mitigating SCR’s, test results are sometimes attached to provide proof documentation that the enhancement was tested. If the attachment contains PII, it is encrypted. If encryption is not used, all PII/SPII fields are masked out with a comment in the notes field dictating as such. All other sub-systems of ESS do not display data to the users.
All ESS users (Kintana users) are required to sign a Rules of Behavior (RoB).
The ESS sub-systems receive their data from Delphi & CASTLE. That data is presumed to be accurate. Kintana information is entered via the users.
Corrections would not be made to the ESS system unless it was a problem with the data being displayed in error. There will be a "help desk" number for the users to call.
Enterprise Support Systems (ESS) takes appropriate security measures to safeguard PII and other sensitive data. Enterprise Support Systems (ESS) applies DOT security standards, including but not limited to routine scans and monitoring, back-up activities, and background security checks of AME employees and contractors.
ROLE |
ACCESS |
SAFEGUARDS |
---|---|---|
User (Level 3) |
|
|
User (Level 2) |
|
|
Site Administrator |
|
|
Kintana information is retained for 7 years and is currently backed up under the Delphi Tape Backup.
Enterprise Support Systems (ESS) contains information that is part of existing System of Records subject to the Privacy Act. In some cases, such as DOT/OST 101, the Department of Transportation controls the data and maintains System of Records responsibilities. In other cases, other government entities providing Enterprise Support Systems (ESS) source data control the data and retain Privacy Act responsibilities.
Enterprise Support Systems (ESS) was certified and accredited in September 2007 in accordance with DOT information technology security standard requirements.