ML23320A282: Difference between revisions

From kanterella
Jump to navigation Jump to search
(StriderTol Bot insert)
 
(StriderTol Bot change)
 
Line 15: Line 15:


=Text=
=Text=
{{#Wiki_filter:}}
{{#Wiki_filter:U.S. Nuclear Regulatory Commission Privacy Threshold Analysis Lighting System Automated Access Control and Computer Enhanced Security System (ACCESS)
Office of Administration (ADM)
EA Number H0008 Version 1.0 08/24/2023 Instruction Notes:
Please do not enter the PIA document into ADAMS. An ADAMS accession number will be assigned through the e-Concurrence system which will be handled by the Privacy Team Template Version 2.0 (03/2023)
 
ACCESS Lighting System                                                  Version 1.0 Privacy Threshold Analysis                                              08/24/2023 Document Revision History Date        Version      PTA Name/Description          Author 08/24/2023  1.0          Lighting PTA - Initial Release ADM Oasis Systems, LLC 08/04/2023  DRAFT        Lighting PTA - DRAFT Release  ADM Oasis Systems, LLC
 
ACCESS Lighting System                                      Version 1.0 Privacy Threshold Analysis                                  08/24/2023 Table of Contents 1  Description                                                          1 2  Characterization of the Information                                  2 3  Records and Information Management-Retention and Disposal            4 4  Privacy Act Determination                                            7
 
ACCESS Lighting System                                                                Version 1.0 Privacy Threshold Analysis                                                            08/24/2023 System/Project Name: ACCESS Lighting Data Storage Location (i.e., Database Server, SharePoint, Cloud, Other Government Agency, Power Platform)
NRC campus and buildings Date Submitted for review/approval: 11/1/2023 1 Description 1.1 Provide the description of the system/subsystem, technology (i.e., Microsoft Products), program, or other data collections (hereinafter referred to as project).
Explain the reason the project is being created.
The lighting system is used to control lighting in buildings 1 and 2 (intensity and degree).
Please indicate if your project/system will involve the following:
PowerApps                                  Public Website Dashboard                                  Internal Website SharePoint                                  None Other 1.2 Does this privacy threshold analysis (PTA) support a proposed new project, proposed modification to an existing project, or other situation? Mark appropriate response in table below.
Status Options New system/project Modification to an existing system/project.
If modifying or making other updates to an existing system/project, provide the ADAMS ML of the existing PTA and describe the modification.
Annual Review If making minor edits to an existing system/project, briefly describe the changes below.
Other (explain)
ACCESS Lighting PTA is being split from the ACCESS HVAC PTA and updated to new template per NRCs Privacy Officers request.
1 PTA Template (03-2023)
 
ACCESS Lighting System                                                              Version 1.0 Privacy Threshold Analysis                                                          08/24/2023 1.3 Points of
 
==Contact:==
Project Manager        System              ISSO            Executive Owner/Data                            Sponsor Owner/Steward Name      Darryl Quirck    Jennifer Golder    Tamar Katz        Jennifer Golder Office      Office of        Office of          Office of          Office of
    /Division Administration        Administration  Administration      Administration
      /Branch (ADM) / Division          (ADM)        (ADM) / Program          (ADM) of Facilities &                      Management, Security (DFS)                      Announcements,
                      /Security                          & Editing Management and                      (PMAE) / Budget Operations                          & Information Branch (SMOB)                          Technology Team (BITT)
Telephone      301-415-0154      301-287-0741    301-415-2500        301-287-0741 2 Characterization of the Information Does this project collect, process, or retain information on: (Check all that apply)
Category of individual NRC Federal employees Other Federal employees Contractors working on behalf of NRC Members of the Public (non-licensee workers, applicants before they are licenses etc.)
Project/system does not collect any personally identifiable information Other 2.1 Is the project/system collecting information about an individual? If yes, provide a description of the information being collected.
N/A 2
PTA Template (03-2023)
 
ACCESS Lighting System                                                          Version 1.0 Privacy Threshold Analysis                                                      08/24/2023 2.2 Please list the data fields/information being collected.
The Lighting system does not collect data.
2.3 Does this project use or collect Social Security Numbers (SSNs)? (This includes truncated SSNs, such as the last four.)
N/A 2.4 Describe how the data is collected for the project. (i.e., NRC Form, survey, questionnaire, existing NRC files/ databases, response to a background check).
N/A 2.5 If using a form to collect the information, provide the form number, title and/or a link.
N/A 2.6 If the project/system shares information with any other NRC systems, identify the system, what information is being shared and the method of sharing.
N/A 2.7 If the project/system connects, receives, or shares information with any external non-NRC partners or systems, identify what is being shared.
N/A Identify what agreements are in place with the external non-NRC partners or systems in the table below.
Agreement Type Contract Provide Contract Number:
License Provide License Information:
Memorandum of Understanding Provide ADAMS ML number for MOU:
Other None 2.8 Describe how the data is accessed (NRC network/remotely) and the access control mechanisms that prevent misuse.
N/A 3
PTA Template (03-2023)
 
ACCESS Lighting System                                                                      Version 1.0 Privacy Threshold Analysis                                                                  08/24/2023 2.9 Define the FISMA boundary this project/system is part of.
Lighting is a part of the ACCESS FISMA boundary.
2.10 Is there an Authority to Operate (ATO) associated with this project/system?
Authorization Status Unknown No If no, please note that the authorization status must be reported to the Chief Information Security Officer (CISO) and Computer Security Organization (CSOs) Point of Contact (POC) via e-mail quarterly to ensure the authorization remains on track.
In Progress provide the estimated date to receive an ATO.
Estimated date:
Yes Indicate the data impact levels (Low, Moderate, High, Undefined) approved by the Chief Information Security Officer (CISO)
Confidentiality-Moderate Integrity-Moderate Availability-Low 2.11 Provide the NRC system Enterprise Architecture (EA)/Inventory number. If unknown, contact EA Service Desk to get the EA/Inventory number.
The EA number is H0008.
3 Records and Information Management-Retention and Disposal The National Archives and Records Administration (NARA), in collaboration with federal agencies, approves whether records are Temporary (eligible at some point for destruction/deletion because they no longer have business value) or Permanent (eligible at some point to be transferred to the National Archives because of historical or evidential significance). Records/data and information with historical value, identified as having a permanent disposition, are transferred to the National Archives of the United States at the end of their retention period. All other records identified as having a temporary disposition are destroyed at the end of their retention period in accordance with the NARA Records Schedule or the General Records Schedule.
These determinations are made through records retention schedules and NARA statutes (44 United States Code (U.S.C.), 36 Code of Federation Regulations (CFR)). Under 36 CFR, agencies are required to establish procedures for addressing Records and Information Management (RIM) requirements. This includes strategies for establishing and managing recordkeeping requirements and disposition instructions before approving new electronic information systems or enhancements to existing systems.
4 PTA Template (03-2023)
 
ACCESS Lighting System                                                            Version 1.0 Privacy Threshold Analysis                                                        08/24/2023 The following questions are intended to determine whether the records/data and information in the system have approved records retention schedules and disposition instructions, whether the system incorporates RIM strategies including support for NARAs Universal Electronic Records Management (ERM) requirements, and if a mitigation strategy is needed to ensure compliance.
If the project/system:
* Does not have an approved records retention schedule and/or
* Does not have an automated RIM functionality
* Involves a cloud solution
* And/or if there are additional questions regarding Records and Information Management
        - Retention and Disposal, please contact the NRC Records staff at ITIMPolicy.Resource@nrc.gov for further guidance.
If the project/system has a record retention schedule or an automated RIM functionality, please complete the questions below.
3.1 Does this project map to an applicable retention schedule in NRCs Comprehensive Records Disposition Schedule (NUREG-0910), or NARAs General Records Schedules?
NUREG-0910, NRC Comprehensive Records Disposition Schedule NARAs General Records Schedules Unscheduled 3.2 If so, cite the schedule number, approved disposition, and describe how this is accomplished.
System Name (include sub-systems, platforms,            Lighting or other locations where the same data resides)
Records Retention Schedule Number(s)                    GRS 5.4 item 010 - Facility, space, vehicle, equipment, stock, and supply administrative and operational records GRS 5.4 item 070 - Facility, space, and equipment inspection, maintenance, and service records GRS 5.2 item 010 - Transitory records 5
PTA Template (03-2023)
 
ACCESS Lighting System                                                            Version 1.0 Privacy Threshold Analysis                                                        08/24/2023 Approved Disposition Instructions                    GRS 5.4 item 010: Temporary.
Destroy when 3 years old or 3 years after superseded, as appropriate, but longer retention is authorized if required for business use.
GRS 5.4 item 070: Temporary.
Destroy when 3 years old, but longer retention is authorized if required for business use.
GRS 5.2 item 010: Temporary.
Destroy when no longer needed for business use, or according to an agency predetermined time period or business rule.
Is there a current automated functionality or a      Yes.
manual process to support RIM requirements? This includes the ability to apply records retention and disposition policies in the system(s) to support records accessibility, reliability, integrity, and disposition.
Disposition of Temporary Records                      Yes, the records are automatically deleted at the Will the records/data or a composite be automatically end of the retention period.
or manually deleted once they reach their approved retention?
Disposition of Permanent Records                      No permanent records are created.
Will the records be exported to an approved format and transferred to the National Archives based on approved retention and disposition instructions?
If so, what formats will be used?
NRC Transfer Guidance (Information and Records Management Guideline
- IRMG) 6 PTA Template (03-2023)
 
ACCESS Lighting System                                                          Version 1.0 Privacy Threshold Analysis                                                      08/24/2023 4 Privacy Act Determination Review Results                              Action Items This project/system does not contain PII.        No further action is necessary for Privacy.
This project/system does contain PII            A privacy impact assessment is required Comments:
Reviewers Name                                Title Signed by Hardy, Sally on 01/16/24                      Privacy Officer I concur with this analysis.
Signed by Feibus, Jonathan on 01/16/24 Jonathan Feibus Director Cyber & Infrastructure Security Division Office of the Chief Information Officer 7
PTA Template (03-2023)}}

Latest revision as of 01:52, 21 February 2024

Access Lighting - Privacy Threshold Analysis v1.0 08/24/2023
ML23320A282
Person / Time
Issue date: 01/19/2024
From: Tamar Katz
NRC/OCIO/CISD
To:
Katz T
References
Download: ML23320A282 (1)


Text

U.S. Nuclear Regulatory Commission Privacy Threshold Analysis Lighting System Automated Access Control and Computer Enhanced Security System (ACCESS)

Office of Administration (ADM)

EA Number H0008 Version 1.0 08/24/2023 Instruction Notes:

Please do not enter the PIA document into ADAMS. An ADAMS accession number will be assigned through the e-Concurrence system which will be handled by the Privacy Team Template Version 2.0 (03/2023)

ACCESS Lighting System Version 1.0 Privacy Threshold Analysis 08/24/2023 Document Revision History Date Version PTA Name/Description Author 08/24/2023 1.0 Lighting PTA - Initial Release ADM Oasis Systems, LLC 08/04/2023 DRAFT Lighting PTA - DRAFT Release ADM Oasis Systems, LLC

ACCESS Lighting System Version 1.0 Privacy Threshold Analysis 08/24/2023 Table of Contents 1 Description 1 2 Characterization of the Information 2 3 Records and Information Management-Retention and Disposal 4 4 Privacy Act Determination 7

ACCESS Lighting System Version 1.0 Privacy Threshold Analysis 08/24/2023 System/Project Name: ACCESS Lighting Data Storage Location (i.e., Database Server, SharePoint, Cloud, Other Government Agency, Power Platform)

NRC campus and buildings Date Submitted for review/approval: 11/1/2023 1 Description 1.1 Provide the description of the system/subsystem, technology (i.e., Microsoft Products), program, or other data collections (hereinafter referred to as project).

Explain the reason the project is being created.

The lighting system is used to control lighting in buildings 1 and 2 (intensity and degree).

Please indicate if your project/system will involve the following:

PowerApps Public Website Dashboard Internal Website SharePoint None Other 1.2 Does this privacy threshold analysis (PTA) support a proposed new project, proposed modification to an existing project, or other situation? Mark appropriate response in table below.

Status Options New system/project Modification to an existing system/project.

If modifying or making other updates to an existing system/project, provide the ADAMS ML of the existing PTA and describe the modification.

Annual Review If making minor edits to an existing system/project, briefly describe the changes below.

Other (explain)

ACCESS Lighting PTA is being split from the ACCESS HVAC PTA and updated to new template per NRCs Privacy Officers request.

1 PTA Template (03-2023)

ACCESS Lighting System Version 1.0 Privacy Threshold Analysis 08/24/2023 1.3 Points of

Contact:

Project Manager System ISSO Executive Owner/Data Sponsor Owner/Steward Name Darryl Quirck Jennifer Golder Tamar Katz Jennifer Golder Office Office of Office of Office of Office of

/Division Administration Administration Administration Administration

/Branch (ADM) / Division (ADM) (ADM) / Program (ADM) of Facilities & Management, Security (DFS) Announcements,

/Security & Editing Management and (PMAE) / Budget Operations & Information Branch (SMOB) Technology Team (BITT)

Telephone 301-415-0154 301-287-0741 301-415-2500 301-287-0741 2 Characterization of the Information Does this project collect, process, or retain information on: (Check all that apply)

Category of individual NRC Federal employees Other Federal employees Contractors working on behalf of NRC Members of the Public (non-licensee workers, applicants before they are licenses etc.)

Project/system does not collect any personally identifiable information Other 2.1 Is the project/system collecting information about an individual? If yes, provide a description of the information being collected.

N/A 2

PTA Template (03-2023)

ACCESS Lighting System Version 1.0 Privacy Threshold Analysis 08/24/2023 2.2 Please list the data fields/information being collected.

The Lighting system does not collect data.

2.3 Does this project use or collect Social Security Numbers (SSNs)? (This includes truncated SSNs, such as the last four.)

N/A 2.4 Describe how the data is collected for the project. (i.e., NRC Form, survey, questionnaire, existing NRC files/ databases, response to a background check).

N/A 2.5 If using a form to collect the information, provide the form number, title and/or a link.

N/A 2.6 If the project/system shares information with any other NRC systems, identify the system, what information is being shared and the method of sharing.

N/A 2.7 If the project/system connects, receives, or shares information with any external non-NRC partners or systems, identify what is being shared.

N/A Identify what agreements are in place with the external non-NRC partners or systems in the table below.

Agreement Type Contract Provide Contract Number:

License Provide License Information:

Memorandum of Understanding Provide ADAMS ML number for MOU:

Other None 2.8 Describe how the data is accessed (NRC network/remotely) and the access control mechanisms that prevent misuse.

N/A 3

PTA Template (03-2023)

ACCESS Lighting System Version 1.0 Privacy Threshold Analysis 08/24/2023 2.9 Define the FISMA boundary this project/system is part of.

Lighting is a part of the ACCESS FISMA boundary.

2.10 Is there an Authority to Operate (ATO) associated with this project/system?

Authorization Status Unknown No If no, please note that the authorization status must be reported to the Chief Information Security Officer (CISO) and Computer Security Organization (CSOs) Point of Contact (POC) via e-mail quarterly to ensure the authorization remains on track.

In Progress provide the estimated date to receive an ATO.

Estimated date:

Yes Indicate the data impact levels (Low, Moderate, High, Undefined) approved by the Chief Information Security Officer (CISO)

Confidentiality-Moderate Integrity-Moderate Availability-Low 2.11 Provide the NRC system Enterprise Architecture (EA)/Inventory number. If unknown, contact EA Service Desk to get the EA/Inventory number.

The EA number is H0008.

3 Records and Information Management-Retention and Disposal The National Archives and Records Administration (NARA), in collaboration with federal agencies, approves whether records are Temporary (eligible at some point for destruction/deletion because they no longer have business value) or Permanent (eligible at some point to be transferred to the National Archives because of historical or evidential significance). Records/data and information with historical value, identified as having a permanent disposition, are transferred to the National Archives of the United States at the end of their retention period. All other records identified as having a temporary disposition are destroyed at the end of their retention period in accordance with the NARA Records Schedule or the General Records Schedule.

These determinations are made through records retention schedules and NARA statutes (44 United States Code (U.S.C.), 36 Code of Federation Regulations (CFR)). Under 36 CFR, agencies are required to establish procedures for addressing Records and Information Management (RIM) requirements. This includes strategies for establishing and managing recordkeeping requirements and disposition instructions before approving new electronic information systems or enhancements to existing systems.

4 PTA Template (03-2023)

ACCESS Lighting System Version 1.0 Privacy Threshold Analysis 08/24/2023 The following questions are intended to determine whether the records/data and information in the system have approved records retention schedules and disposition instructions, whether the system incorporates RIM strategies including support for NARAs Universal Electronic Records Management (ERM) requirements, and if a mitigation strategy is needed to ensure compliance.

If the project/system:

  • Does not have an approved records retention schedule and/or
  • Does not have an automated RIM functionality
  • Involves a cloud solution
  • And/or if there are additional questions regarding Records and Information Management

- Retention and Disposal, please contact the NRC Records staff at ITIMPolicy.Resource@nrc.gov for further guidance.

If the project/system has a record retention schedule or an automated RIM functionality, please complete the questions below.

3.1 Does this project map to an applicable retention schedule in NRCs Comprehensive Records Disposition Schedule (NUREG-0910), or NARAs General Records Schedules?

NUREG-0910, NRC Comprehensive Records Disposition Schedule NARAs General Records Schedules Unscheduled 3.2 If so, cite the schedule number, approved disposition, and describe how this is accomplished.

System Name (include sub-systems, platforms, Lighting or other locations where the same data resides)

Records Retention Schedule Number(s) GRS 5.4 item 010 - Facility, space, vehicle, equipment, stock, and supply administrative and operational records GRS 5.4 item 070 - Facility, space, and equipment inspection, maintenance, and service records GRS 5.2 item 010 - Transitory records 5

PTA Template (03-2023)

ACCESS Lighting System Version 1.0 Privacy Threshold Analysis 08/24/2023 Approved Disposition Instructions GRS 5.4 item 010: Temporary.

Destroy when 3 years old or 3 years after superseded, as appropriate, but longer retention is authorized if required for business use.

GRS 5.4 item 070: Temporary.

Destroy when 3 years old, but longer retention is authorized if required for business use.

GRS 5.2 item 010: Temporary.

Destroy when no longer needed for business use, or according to an agency predetermined time period or business rule.

Is there a current automated functionality or a Yes.

manual process to support RIM requirements? This includes the ability to apply records retention and disposition policies in the system(s) to support records accessibility, reliability, integrity, and disposition.

Disposition of Temporary Records Yes, the records are automatically deleted at the Will the records/data or a composite be automatically end of the retention period.

or manually deleted once they reach their approved retention?

Disposition of Permanent Records No permanent records are created.

Will the records be exported to an approved format and transferred to the National Archives based on approved retention and disposition instructions?

If so, what formats will be used?

NRC Transfer Guidance (Information and Records Management Guideline

- IRMG) 6 PTA Template (03-2023)

ACCESS Lighting System Version 1.0 Privacy Threshold Analysis 08/24/2023 4 Privacy Act Determination Review Results Action Items This project/system does not contain PII. No further action is necessary for Privacy.

This project/system does contain PII A privacy impact assessment is required Comments:

Reviewers Name Title Signed by Hardy, Sally on 01/16/24 Privacy Officer I concur with this analysis.

Signed by Feibus, Jonathan on 01/16/24 Jonathan Feibus Director Cyber & Infrastructure Security Division Office of the Chief Information Officer 7

PTA Template (03-2023)