82_FR_23398 82 FR 23301 - Agency Information Collection Activities; Request for Comments; Revision of the BJS Confidentiality Pledge

82 FR 23301 - Agency Information Collection Activities; Request for Comments; Revision of the BJS Confidentiality Pledge

DEPARTMENT OF JUSTICE

Federal Register Volume 82, Issue 97 (May 22, 2017)

Page Range23301-23303
FR Document2017-10345

The Bureau of Justice Statistics (BJS), a component of the Office of Justice Programs (OJP) in the U.S. Department of Justice (DOJ), is seeking comments on revisions to the confidentiality pledge it provides to its respondents. These revisions are required by the passage and implementation of provisions of the federal Cybersecurity Enhancement Act of 2015, which requires the Secretary of the Department of Homeland Security (DHS) to provide Federal civilian agencies' information technology systems with cybersecurity protection for their Internet traffic. More details on this announcement are presented in the SUPPLEMENTARY INFORMATION section below. The revisions to the confidentiality pledge were previously published in the Federal Register on March 20, 2017, allowing for a 60 day comment period. BJS received and responded to one comment.

Federal Register, Volume 82 Issue 97 (Monday, May 22, 2017)
[Federal Register Volume 82, Number 97 (Monday, May 22, 2017)]
[Notices]
[Pages 23301-23303]
From the Federal Register Online  [www.thefederalregister.org]
[FR Doc No: 2017-10345]


-----------------------------------------------------------------------

DEPARTMENT OF JUSTICE

[OMB Number 1121-NEW]


Agency Information Collection Activities; Request for Comments; 
Revision of the BJS Confidentiality Pledge

AGENCY: Bureau of Justice Statistics, U.S. Department of Justice.

ACTION: Notice.

-----------------------------------------------------------------------

SUMMARY: The Bureau of Justice Statistics (BJS), a component of the 
Office of Justice Programs (OJP) in the U.S. Department of Justice 
(DOJ), is seeking comments on revisions to the confidentiality pledge 
it provides to its respondents. These revisions are required by the 
passage and implementation of provisions of the federal Cybersecurity 
Enhancement Act of 2015, which requires the Secretary of the Department 
of Homeland Security (DHS) to provide Federal civilian agencies' 
information technology systems with cybersecurity protection for their 
Internet traffic. More details on this announcement are presented in 
the SUPPLEMENTARY INFORMATION section below. The revisions to the 
confidentiality pledge were previously published in the Federal 
Register on March 20, 2017, allowing for a 60 day comment period. BJS 
received and responded to one comment.

DATES:  Comments are encouraged and will be accepted for 30 days until 
June 21, 2017.

ADDRESSES: Questions about this notice should be addressed to the 
Bureau of Justice Statistics, Office of Justice Programs, U.S. 
Department of Justice, ATTN: Devon Adams, 810 7th Street NW., 
Washington, D.C. 20531; email: [email protected]; telephone: 202-
307-0765 (this is not a toll-free number).

FOR FURTHER INFORMATION CONTACT: Allina Lee by telephone at 202-305-
0765 (this is not a toll-free number); by email at 
[email protected]; or by mail or courier to the Bureau of Justice 
Statistics, Office of Justice Programs, U.S. Department of Justice, 
ATTN: Allina Lee, 810 7th Street NW., Washington, D.C. 20531. Because 
of delays in the receipt of regular mail related to security screening, 
respondents are encouraged to use electronic communications.

SUPPLEMENTARY INFORMATION: 

I. Abstract

    Federal statistics provide key information that the Nation uses to 
measure its performance and make informed choices about budgets, 
employment, health, investments, taxes, and a host of other significant 
topics. Most federal surveys are completed on a voluntary basis. 
Respondents, ranging from businesses to households to institutions, may 
choose whether or not to provide the requested information. Many of the 
most valuable federal statistics come from surveys that ask for highly 
sensitive information such as proprietary business data from companies 
or particularly personal information or practices from individuals. BJS 
protects all personally identifiable information collected under its 
authority under the confidentiality provisions of 42 U.S.C. Sec.  
3789g. Strong and trusted confidentiality and exclusively statistical 
use pledges under Title 42 U.S.C. Sec.  3789g and similar statutes are 
effective and necessary in honoring the trust that businesses, 
individuals, and institutions, by their responses, place in statistical 
agencies.
    Under statistical confidentiality protection statutes, federal 
statistical agencies make statutory pledges that the information 
respondents provide will be seen only by statistical agency personnel 
or their agents and will be used only for statistical purposes. These 
statutes protect such statistical information from administrative, law

[[Page 23302]]

enforcement, taxation, regulatory, or any other non-statistical use and 
immunize the information submitted to statistical agencies from legal 
process. Moreover, many of these statutes carry monetary fines and/or 
criminal penalties for conviction of a knowing and willful unauthorized 
disclosure of covered information. Any person violating the 
confidentiality provisions of 42 U.S.C. Sec.  3789g may be punished by 
a fine of up to $10,000, in addition to any other penalties imposed by 
law.
    As part of the Consolidated Appropriations Act for Fiscal Year 2016 
(Pub. L. No. 114-113) signed on December 17, 2015, the Congress 
included the Federal Cybersecurity Enhancement Act of 2015 (codified in 
relevant part at 6 U.S.C. Sec.  151). This act, among other provisions, 
permits and requires the Secretary of Homeland Security to provide 
federal civilian agencies' information technology systems with 
cybersecurity protection for their Internet traffic. The technology 
currently used to provide this protection against cyber malware is 
known as Einstein 3A. Einstein 3A electronically searches internet 
traffic in and out of federal civilian agencies in real time for 
malware signatures.
    When such a signature is found, the internet packets that contain 
the malware signature are shunted aside for further inspection by DHS 
personnel. Because it is possible that such packets entering or leaving 
a statistical agency's information technology system may contain a 
small portion of confidential statistical data, statistical agencies 
can no longer promise their respondents that their responses will be 
seen only by statistical agency personnel or their agents. However, 
federal statistical agencies can promise, in accordance with provisions 
of the Federal Cybersecurity Enhancement Act of 2015, that such 
monitoring can be used only to protect information and information 
systems from cybersecurity risks, thereby, in effect, providing 
stronger protection to the integrity of the respondents' submissions.
    Consequently, with the passage of the Federal Cybersecurity 
Enhancement Act of 2015, the federal statistical community has an 
opportunity to welcome the further protection of its confidential data 
offered by DHS' Einstein 3A cybersecurity protection program. The DHS 
cybersecurity program's objective is to protect federal civilian 
information systems from malicious malware attacks. The federal 
statistical system's objective is to endeavor to ensure that the DHS 
Secretary performs those essential duties in a manner that honors the 
statistical agencies' statutory promises to the public to protect their 
confidential data. DHS and the federal statistical system have been 
successfully engaged in finding a way to balance both objectives and 
achieve these mutually reinforcing objectives.
    However, pledges of confidentiality made pursuant to 42 U.S.C. 
Sec.  3789g and similar statutes assure respondents that their data 
will be seen only by statistical agency personnel or their agents. 
Because it is possible that DHS personnel could see some portion of 
those confidential data in the course of examining the suspicious 
Internet packets identified by Einstein 3A sensors, statistical 
agencies are revising their confidentiality pledges to reflect this 
process change. Therefore, BJS is providing this notice to alert the 
public to these confidentiality pledge revisions in an efficient and 
coordinated fashion.

II. Method of Collection

    The following is the revised statistical confidentiality pledge for 
applicable BJS data collections, with the new line added to address the 
new cybersecurity monitoring activities bolded for reference only:

    ``The Bureau of Justice Statistics (BJS) is authorized to 
conduct this data collection under 42 U.S.C. Sec.  3732. BJS is 
dedicated to maintaining the confidentiality of your personally 
identifiable information, and will protect it to the fullest extent 
under federal law. BJS, BJS employees, and BJS data collection 
agents will use the information you provide for statistical or 
research purposes only, and will not disclose your information in 
identifiable form without your consent to anyone outside of the BJS 
project team. All personally identifiable data collected under BJS's 
authority are protected under the confidentiality provisions of 42 
U.S.C. Sec.  3789g, and any person who violates these provisions may 
be punished by a fine up to $10,000, in addition to any other 
penalties imposed by law. Further, per the Cybersecurity Enhancement 
Act of 2015 (codified in relevant part at 6 U.S.C. Sec.  151), 
federal information systems are protected from malicious activities 
through cybersecurity screening of transmitted data. For more 
information on the federal statutes, regulations, and other 
authorities that govern how BJS, BJS employees, and BJS data 
collection agents collect, handle, store, disseminate, and protect 
your information, see the BJS Data Protection Guidelines--(https://www.bjs.gov/content/pub/pdf/BJS_Data_Protection_Guidelines.pdf).''

    The following listing shows the current BJS Paperwork Reduction Act 
(PRA) OMB numbers and information collection titles whose 
confidentiality pledges will change to reflect the statutory 
implementation of DHS' Einstein 3A monitoring for cybersecurity 
protection purposes.

------------------------------------------------------------------------
           OMB control No.                Information collection title
------------------------------------------------------------------------
1121-0094............................  Deaths in Custody Reporting
                                        Program.
1121-0065............................  National Corrections Reporting
                                        Program.
------------------------------------------------------------------------

    Affected Public: Survey respondents to applicable BJS information 
collections.
    Total Respondents: Unchanged from current collection.
    Frequency: Unchanged from current collection.
    Total Responses: Unchanged from current collection.
    Average Time per Response: Unchanged from current collection.
    Estimated Total Burden Hours: Unchanged from current collection.
    Estimated Total Cost: Unchanged from current collection.
    BJS has also added information about the Cybersecurity Enhancement 
Act and Einstein 3A to the BJS Data Protection Guidelines to provide 
more details to interested respondents about the new cybersecurity 
monitoring requirements. The following text has been added to Section 
V. Information System Security and Privacy Requirements:

    ``The Cybersecurity Enhancement Act of 2015 (codified in 
relevant part at 6 U.S.C. Sec.  151) required the Department of 
Homeland Security (DHS) to provide cybersecurity protection for 
federal civilian agency information technology systems and to 
conduct cybersecurity screening of the Internet traffic going in and 
out of these systems to look for viruses, malware, and other 
cybersecurity threats. DHS has implemented this requirement by 
instituting procedures such that, if a potentially malicious malware 
signature were found, the Internet packets that contain the malware 
signature would be further inspected, pursuant to any required legal 
process, to identify and mitigate the cybersecurity threat. In 
accordance with the Act's provisions, DHS conducts these 
cybersecurity screening activities solely to protect federal 
information and information systems from cybersecurity risks. To 
comply with the Act's requirements and to increase the protection of 
information from cybersecurity threats, OJP facilitates, through the 
DOJ Trusted Internet Connection and DHS's EINSTEIN 3A system, the 
inspection of all information transmitted to and from OJP systems 
including, but not limited to, respondent data collected and 
maintained by BJS.''

    The Census Bureau collects data on behalf of BJS for BJS's National 
Crime Victimization Survey (NCVS) and its supplements. These 
collections are protected under Title 13 U.S.C. Section 9. The Census 
Bureau issued a Federal Register notice (FRN) to revise its 
confidentiality pledge language to address the new cybersecurity 
screening

[[Page 23303]]

requirements (new line bolded for reference only):

    ``The U.S. Census Bureau is required by law to protect your 
information. The Census Bureau is not permitted to publicly release 
your responses in a way that could identify you. Per the Federal 
Cybersecurity Enhancement Act of 2015, your data are protected from 
cybersecurity risks through screening of the systems that transmit 
your data.''

    The following listing includes the BJS information collections that 
are administered by the Census Bureau whose confidentiality pledge will 
be revised.

------------------------------------------------------------------------
           OMB control No.                Information collection title
------------------------------------------------------------------------
1121-0111............................  NCVS.
1121-0184............................  School Crime Supplement to the
                                        NCVS.
1121-0317............................  Identity Theft Supplement to the
                                        NCVS.
1121-0260............................  Police Public Contact Supplement
                                        to the NCVS.
1121-0302............................  Supplemental Victimization Survey
                                        to the NCVS.
------------------------------------------------------------------------

    Affected Public: Survey respondents to applicable BJS information 
collections.
    Total Respondents: Unchanged from current collection.
    Frequency: Unchanged from current collection.
    Total Responses: Unchanged from current collection.
    Average Time per Response: Unchanged from current collection.
    Estimated Total Burden Hours: Unchanged from current collection.
    Estimated Total Cost: Unchanged from current collection.
    The 60-day FRN submitted by the Census Bureau can be accessed at 
https://www.federalregister.gov/documents/2016/12/23/2016-30959/agency-information-collection-activities-request-for-comments-revision-of-the-confidentiality-pledge. The Census Bureau is currently reviewing and 
preparing responses to the comments it received and will publish a 30-
day FRN to solicit additional public comment. Comments on the Census 
Bureau's revised confidentiality pledge should be submitted directly to 
the point-of-contact listed in the notice.

III. Data

    OMB Control Number: 1121-0358.
    Legal Authority: 44 U.S.C. 3506(e) and 42 U.S.C. 3789g.
    Form Number(s): None.

IV. Request for Comments

    Comments are invited on the efficacy of BJS's revised 
confidentiality pledge above. Comments submitted in response to this 
notice will become a matter of public record. BJS received one comment 
during the 60-day notice period. The commenter questioned why BJS chose 
not to specifically reference who (cybersecurity personnel, or DHS 
personnel) would conduct the cybersecurity screening activities 
authorized by the Cybersecurity Act of 2015. BJS responded with 
information about the process it followed to revise the confidentiality 
pledge, including using the results of pretesting that other 
statistical agencies conducted on different versions of revised 
language and coordinating with OJP's Office of General Counsel to 
ensure that the new pledge language fulfills BJS's statutory obligation 
to inform respondents that their data may be accessed by others for 
non-statistical purposes. BJS also directed the commenter to the 
information added to the BJS Data Protection guidelines (Section V. 
Information System Security and Privacy Requirements) that provides 
more details about the Act and the associated monitoring activities. 
BJS is not proposing edits to its confidentiality pledge, though it 
will consider conducting pretesting activities on its various 
respondent populations and developing more detailed guidance for staff 
and contractors on how to answer respondents' questions about the Act.
    If additional information is required contact: Melody Braswell, 
Department Clearance Officer, United States Department of Justice, 
Justice Management Division, Policy and Planning Staff, Two 
Constitution Square, 145 N Street NE., 3E.405A, Washington, DC 20530.

    Dated: May 17, 2017.
Melody Braswell,
Department Clearance Officer for PRA, U.S. Department of Justice.
[FR Doc. 2017-10345 Filed 5-19-17; 8:45 am]
 BILLING CODE 4410-18-P



                                                                                  Federal Register / Vol. 82, No. 97 / Monday, May 22, 2017 / Notices                                               23301

                                                  Substances Act (CSA), ‘‘upon a finding                  medicine in the state of Wyoming.’’ GX                  March 20, 2017, allowing for a 60 day
                                                  that the registrant . . . has had his State             3, at 18. I therefore find that Registrant              comment period. BJS received and
                                                  license . . . suspended [or] revoked                    lacks authority to dispense controlled                  responded to one comment.
                                                  . . . by competent State authority and is               substances in Wyoming, the State in                     DATES: Comments are encouraged and
                                                  no longer authorized by State law to                    which he is registered with the Agency                  will be accepted for 30 days until June
                                                  engage in the . . . dispensing of                       and that he is not entitled to maintain                 21, 2017.
                                                  controlled substances.’’ Also, DEA has                  his registration. See Hooper, 76 FR at                  ADDRESSES: Questions about this notice
                                                  long held that the possession of                        71371; Blanton, 43 FR 27616.                            should be addressed to the Bureau of
                                                  authority to dispense controlled                        Accordingly, I will order that his                      Justice Statistics, Office of Justice
                                                  substances under the laws of the State                  registration be revoked. 21 U.S.C.                      Programs, U.S. Department of Justice,
                                                  in which a practitioner engages in                      824(a)(3).                                              ATTN: Devon Adams, 810 7th Street
                                                  professional practice is a fundamental                                                                          NW., Washington, D.C. 20531; email:
                                                  condition for obtaining and maintaining                 Order
                                                                                                                                                                  Devon.Adams@usdoj.gov; telephone:
                                                  a practitioner’s registration. See, e.g.,                  Pursuant to the authority vested in me               202–307–0765 (this is not a toll-free
                                                  James L. Hooper, 76 FR 71371 (2011),                    by 21 U.S.C. 824(a), as well as 28 CFR                  number).
                                                  pet. for rev. denied, 481 Fed. Appx. 826                0.100(b), I order that DEA Certificate of
                                                                                                                                                                  FOR FURTHER INFORMATION CONTACT:
                                                  (4th Cir. 2012); see also Frederick Marsh               Registration No. FK5578464 issued to
                                                  Blanton, 43 FR 27616 (1978) (‘‘State                    Shakeel A. Kahn, M.D., be, and it hereby                Allina Lee by telephone at 202–305–
                                                  authorization to dispense or otherwise                  is, revoked. I further order that any                   0765 (this is not a toll-free number); by
                                                  handle controlled substances is a                       application of Shakeel A. Khan, M.D., to                email at Allina.Lee@usdoj.gov; or by
                                                  prerequisite to the issuance and                                                                                mail or courier to the Bureau of Justice
                                                                                                          renew or modify this registration be,
                                                  maintenance of a Federal controlled                                                                             Statistics, Office of Justice Programs,
                                                                                                          and it hereby is, denied. This Order is
                                                  substances registration.’’).                                                                                    U.S. Department of Justice, ATTN:
                                                                                                          effective immediately.1
                                                     This rule derives from the text of two                                                                       Allina Lee, 810 7th Street NW.,
                                                                                                            Dated: May 15, 2017.                                  Washington, D.C. 20531. Because of
                                                  provisions of the Controlled Substances
                                                                                                          Chuck Rosenberg,                                        delays in the receipt of regular mail
                                                  Act (CSA). First, Congress defined ‘‘the
                                                  term ‘practitioner’ [to] mean[ ] a . . .                Acting Administrator.                                   related to security screening,
                                                  physician . . . or other person licensed,               [FR Doc. 2017–10386 Filed 5–19–17; 8:45 am]             respondents are encouraged to use
                                                  registered or otherwise permitted, by                   BILLING CODE 4410–09–P                                  electronic communications.
                                                  . . . the jurisdiction in which he                                                                              SUPPLEMENTARY INFORMATION:
                                                  practices . . . to distribute, dispense,                                                                        I. Abstract
                                                  [or] administer . . . a controlled                      DEPARTMENT OF JUSTICE
                                                  substance in the course of professional                                                                            Federal statistics provide key
                                                                                                          [OMB Number 1121–NEW]
                                                  practice.’’ 21 U.S.C. 802(21). Second, in                                                                       information that the Nation uses to
                                                  setting the requirements for obtaining a                Agency Information Collection                           measure its performance and make
                                                  practitioner’s registration, Congress                   Activities; Request for Comments;                       informed choices about budgets,
                                                  directed that ‘‘[t]he Attorney General                  Revision of the BJS Confidentiality                     employment, health, investments, taxes,
                                                  shall register practitioners . . . if the               Pledge                                                  and a host of other significant topics.
                                                  applicant is authorized to dispense . . .                                                                       Most federal surveys are completed on
                                                  controlled substances under the laws of                 AGENCY: Bureau of Justice Statistics,                   a voluntary basis. Respondents, ranging
                                                  the State in which he practices.’’ 21                   U.S. Department of Justice.                             from businesses to households to
                                                  U.S.C. 823(f).                                          ACTION: Notice.                                         institutions, may choose whether or not
                                                     Moreover, because ‘‘the controlling                                                                          to provide the requested information.
                                                  question’’ in a proceeding brought                      SUMMARY:    The Bureau of Justice                       Many of the most valuable federal
                                                  under 21 U.S.C. 824(a)(3) is whether the                Statistics (BJS), a component of the                    statistics come from surveys that ask for
                                                  holder of a DEA registration ‘‘is                       Office of Justice Programs (OJP) in the                 highly sensitive information such as
                                                  currently authorized to handle                          U.S. Department of Justice (DOJ), is                    proprietary business data from
                                                  controlled substances in the [S]tate,’’                 seeking comments on revisions to the                    companies or particularly personal
                                                  Hooper, 76 FR at 71371 (quoting Anne                    confidentiality pledge it provides to its               information or practices from
                                                  Lazar Thorn, 62 FR 12847, 12848                         respondents. These revisions are                        individuals. BJS protects all personally
                                                  (1997)), the Agency has also long held                  required by the passage and                             identifiable information collected under
                                                  that revocation is warranted even where                 implementation of provisions of the                     its authority under the confidentiality
                                                  a practitioner has lost his state authority             federal Cybersecurity Enhancement Act                   provisions of 42 U.S.C. § 3789g. Strong
                                                  by virtue of the State’s use of summary                 of 2015, which requires the Secretary of                and trusted confidentiality and
                                                  process and the State has yet to provide                the Department of Homeland Security                     exclusively statistical use pledges under
                                                  a hearing to challenge the suspension.                  (DHS) to provide Federal civilian                       Title 42 U.S.C. § 3789g and similar
                                                  Bourne Pharmacy, 72 FR 18273, 18274                     agencies’ information technology                        statutes are effective and necessary in
                                                  (2007); Wingfield Drugs, 52 FR 27070,                   systems with cybersecurity protection                   honoring the trust that businesses,
                                                  27071 (1987). Thus, for the purposes of                 for their Internet traffic. More details on             individuals, and institutions, by their
                                                  the CSA, it is of no consequence that the               this announcement are presented in the                  responses, place in statistical agencies.
                                                  Wyoming Medical Board has employed                      SUPPLEMENTARY INFORMATION section                          Under statistical confidentiality
                                                  summary process in suspending                           below. The revisions to the                             protection statutes, federal statistical
mstockstill on DSK30JT082PROD with NOTICES




                                                  Registrant’s state license.                             confidentiality pledge were previously                  agencies make statutory pledges that the
                                                     As found above, on November 29,                      published in the Federal Register on                    information respondents provide will be
                                                  2016, the Wyoming Board of Medicine                                                                             seen only by statistical agency
                                                                                                             1 For the same reasons that led the Wyoming
                                                  ordered the summary suspension of                                                                               personnel or their agents and will be
                                                                                                          Board to summarily suspend Registrant’s medical
                                                  Registrant’s Physician License effective                license, I find that the public interest necessitates
                                                                                                                                                                  used only for statistical purposes. These
                                                  the same day, thereby suspending ‘‘his                  that this order be effective immediately. 21 CFR        statutes protect such statistical
                                                  authority and ability to practice                       1316.67.                                                information from administrative, law


                                             VerDate Sep<11>2014   23:17 May 19, 2017   Jkt 241001   PO 00000   Frm 00132   Fmt 4703    Sfmt 4703   E:\FR\FM\22MYN1.SGM   22MYN1


                                                  23302                           Federal Register / Vol. 82, No. 97 / Monday, May 22, 2017 / Notices

                                                  enforcement, taxation, regulatory, or any               statistical agencies’ statutory promises               OMB control        Information collection title
                                                  other non-statistical use and immunize                  to the public to protect their                            No.
                                                  the information submitted to statistical                confidential data. DHS and the federal
                                                  agencies from legal process. Moreover,                  statistical system have been successfully             1121–0094 .....   Deaths in Custody Reporting
                                                  many of these statutes carry monetary                   engaged in finding a way to balance                                       Program.
                                                                                                                                                                1121–0065 .....   National Corrections Report-
                                                  fines and/or criminal penalties for                     both objectives and achieve these                                         ing Program.
                                                  conviction of a knowing and willful                     mutually reinforcing objectives.
                                                  unauthorized disclosure of covered                        However, pledges of confidentiality
                                                                                                                                                                   Affected Public: Survey respondents
                                                  information. Any person violating the                   made pursuant to 42 U.S.C. § 3789g and
                                                                                                                                                                to applicable BJS information
                                                  confidentiality provisions of 42 U.S.C.                 similar statutes assure respondents that
                                                                                                                                                                collections.
                                                  § 3789g may be punished by a fine of up                 their data will be seen only by statistical              Total Respondents: Unchanged from
                                                  to $10,000, in addition to any other                    agency personnel or their agents.                     current collection.
                                                  penalties imposed by law.                               Because it is possible that DHS
                                                     As part of the Consolidated                                                                                   Frequency: Unchanged from current
                                                                                                          personnel could see some portion of                   collection.
                                                  Appropriations Act for Fiscal Year 2016                 those confidential data in the course of
                                                  (Pub. L. No. 114–113) signed on                                                                                  Total Responses: Unchanged from
                                                                                                          examining the suspicious Internet                     current collection.
                                                  December 17, 2015, the Congress                         packets identified by Einstein 3A
                                                  included the Federal Cybersecurity                                                                               Average Time per Response:
                                                                                                          sensors, statistical agencies are revising            Unchanged from current collection.
                                                  Enhancement Act of 2015 (codified in                    their confidentiality pledges to reflect
                                                  relevant part at 6 U.S.C. § 151). This act,                                                                      Estimated Total Burden Hours:
                                                                                                          this process change. Therefore, BJS is                Unchanged from current collection.
                                                  among other provisions, permits and                     providing this notice to alert the public
                                                  requires the Secretary of Homeland                                                                               Estimated Total Cost: Unchanged
                                                                                                          to these confidentiality pledge revisions             from current collection.
                                                  Security to provide federal civilian                    in an efficient and coordinated fashion.
                                                  agencies’ information technology                                                                                 BJS has also added information about
                                                  systems with cybersecurity protection                   II. Method of Collection                              the Cybersecurity Enhancement Act and
                                                  for their Internet traffic. The technology                 The following is the revised statistical           Einstein 3A to the BJS Data Protection
                                                  currently used to provide this protection               confidentiality pledge for applicable BJS             Guidelines to provide more details to
                                                  against cyber malware is known as                       data collections, with the new line                   interested respondents about the new
                                                  Einstein 3A. Einstein 3A electronically                 added to address the new cybersecurity                cybersecurity monitoring requirements.
                                                  searches internet traffic in and out of                 monitoring activities bolded for                      The following text has been added to
                                                  federal civilian agencies in real time for              reference only:                                       Section V. Information System Security
                                                  malware signatures.                                                                                           and Privacy Requirements:
                                                                                                            ‘‘The Bureau of Justice Statistics (BJS) is
                                                     When such a signature is found, the                  authorized to conduct this data collection               ‘‘The Cybersecurity Enhancement Act of
                                                  internet packets that contain the                       under 42 U.S.C. § 3732. BJS is dedicated to           2015 (codified in relevant part at 6 U.S.C.
                                                  malware signature are shunted aside for                 maintaining the confidentiality of your               § 151) required the Department of Homeland
                                                  further inspection by DHS personnel.                    personally identifiable information, and will         Security (DHS) to provide cybersecurity
                                                  Because it is possible that such packets                protect it to the fullest extent under federal        protection for federal civilian agency
                                                  entering or leaving a statistical agency’s              law. BJS, BJS employees, and BJS data                 information technology systems and to
                                                                                                          collection agents will use the information            conduct cybersecurity screening of the
                                                  information technology system may
                                                                                                          you provide for statistical or research               Internet traffic going in and out of these
                                                  contain a small portion of confidential                                                                       systems to look for viruses, malware, and
                                                  statistical data, statistical agencies can              purposes only, and will not disclose your
                                                                                                          information in identifiable form without your         other cybersecurity threats. DHS has
                                                  no longer promise their respondents                     consent to anyone outside of the BJS project          implemented this requirement by instituting
                                                  that their responses will be seen only by               team. All personally identifiable data                procedures such that, if a potentially
                                                  statistical agency personnel or their                   collected under BJS’s authority are protected         malicious malware signature were found, the
                                                  agents. However, federal statistical                    under the confidentiality provisions of 42            Internet packets that contain the malware
                                                  agencies can promise, in accordance                     U.S.C. § 3789g, and any person who violates           signature would be further inspected,
                                                  with provisions of the Federal                          these provisions may be punished by a fine            pursuant to any required legal process, to
                                                  Cybersecurity Enhancement Act of                        up to $10,000, in addition to any other               identify and mitigate the cybersecurity threat.
                                                                                                          penalties imposed by law. Further, per the            In accordance with the Act’s provisions, DHS
                                                  2015, that such monitoring can be used
                                                                                                          Cybersecurity Enhancement Act of 2015                 conducts these cybersecurity screening
                                                  only to protect information and                                                                               activities solely to protect federal information
                                                  information systems from cybersecurity                  (codified in relevant part at 6 U.S.C. § 151),
                                                                                                          federal information systems are protected             and information systems from cybersecurity
                                                  risks, thereby, in effect, providing                    from malicious activities through                     risks. To comply with the Act’s requirements
                                                  stronger protection to the integrity of the             cybersecurity screening of transmitted data.          and to increase the protection of information
                                                  respondents’ submissions.                               For more information on the federal statutes,         from cybersecurity threats, OJP facilitates,
                                                     Consequently, with the passage of the                regulations, and other authorities that govern        through the DOJ Trusted Internet Connection
                                                  Federal Cybersecurity Enhancement Act                   how BJS, BJS employees, and BJS data                  and DHS’s EINSTEIN 3A system, the
                                                  of 2015, the federal statistical                        collection agents collect, handle, store,             inspection of all information transmitted to
                                                  community has an opportunity to                         disseminate, and protect your information,            and from OJP systems including, but not
                                                  welcome the further protection of its                   see the BJS Data Protection Guidelines—               limited to, respondent data collected and
                                                                                                          (https://www.bjs.gov/content/pub/pdf/BJS_             maintained by BJS.’’
                                                  confidential data offered by DHS’
                                                  Einstein 3A cybersecurity protection                    Data_Protection_Guidelines.pdf).’’                       The Census Bureau collects data on
                                                  program. The DHS cybersecurity                            The following listing shows the                     behalf of BJS for BJS’s National Crime
mstockstill on DSK30JT082PROD with NOTICES




                                                  program’s objective is to protect federal               current BJS Paperwork Reduction Act                   Victimization Survey (NCVS) and its
                                                  civilian information systems from                       (PRA) OMB numbers and information                     supplements. These collections are
                                                  malicious malware attacks. The federal                  collection titles whose confidentiality               protected under Title 13 U.S.C. Section
                                                  statistical system’s objective is to                    pledges will change to reflect the                    9. The Census Bureau issued a Federal
                                                  endeavor to ensure that the DHS                         statutory implementation of DHS’                      Register notice (FRN) to revise its
                                                  Secretary performs those essential                      Einstein 3A monitoring for                            confidentiality pledge language to
                                                  duties in a manner that honors the                      cybersecurity protection purposes.                    address the new cybersecurity screening


                                             VerDate Sep<11>2014   23:17 May 19, 2017   Jkt 241001   PO 00000   Frm 00133   Fmt 4703   Sfmt 4703   E:\FR\FM\22MYN1.SGM   22MYN1


                                                                                   Federal Register / Vol. 82, No. 97 / Monday, May 22, 2017 / Notices                                             23303

                                                  requirements (new line bolded for                        above. Comments submitted in response                 Federal agencies with an opportunity to
                                                  reference only):                                         to this notice will become a matter of                comment on proposed and continuing
                                                    ‘‘The U.S. Census Bureau is required by                public record. BJS received one                       collections of information. This helps
                                                  law to protect your information. The Census              comment during the 60-day notice                      the Department assess the impact of its
                                                  Bureau is not permitted to publicly release              period. The commenter questioned why                  information collection requirements and
                                                  your responses in a way that could identify              BJS chose not to specifically reference               minimize the public’s reporting burden.
                                                  you. Per the Federal Cybersecurity                       who (cybersecurity personnel, or DHS                  It also helps the public understand the
                                                  Enhancement Act of 2015, your data are                   personnel) would conduct the                          Department’s information collection
                                                  protected from cybersecurity risks through               cybersecurity screening activities                    requirements and provide the requested
                                                  screening of the systems that transmit your              authorized by the Cybersecurity Act of                data in the desired format. The
                                                  data.’’                                                  2015. BJS responded with information                  Employee Benefits Security
                                                    The following listing includes the BJS                 about the process it followed to revise               Administration (EBSA) is soliciting
                                                  information collections that are                         the confidentiality pledge, including                 comments on the proposed extension of
                                                  administered by the Census Bureau                        using the results of pretesting that other            the information collection requests
                                                  whose confidentiality pledge will be                     statistical agencies conducted on                     (ICRs) contained in the documents
                                                  revised.                                                 different versions of revised language                described below. A copy of the ICRs
                                                                                                           and coordinating with OJP’s Office of                 may be obtained by contacting the office
                                                    OMB control         Information collection title       General Counsel to ensure that the new                listed in the ADDRESSES section of this
                                                       No.                                                 pledge language fulfills BJS’s statutory              notice. ICRs also are available at
                                                                                                           obligation to inform respondents that                 reginfo.gov (http://www.reginfo.gov/
                                                  1121–0111 .....     NCVS.
                                                  1121–0184 .....     School Crime Supplement to           their data may be accessed by others for              public/do/PRAMain).
                                                                        the NCVS.                          non-statistical purposes. BJS also                    DATES: Written comments must be
                                                  1121–0317 .....     Identity Theft Supplement to         directed the commenter to the                         submitted to the office shown in the
                                                                        the NCVS.                          information added to the BJS Data                     Addresses section on or before July 21,
                                                  1121–0260 .....     Police Public Contact Sup-           Protection guidelines (Section V.                     2017.
                                                                        plement to the NCVS.               Information System Security and
                                                  1121–0302 .....     Supplemental Victimization                                                                 ADDRESSES: G. Christopher Cosby,
                                                                                                           Privacy Requirements) that provides                   Department of Labor, Employee Benefits
                                                                        Survey to the NCVS.                more details about the Act and the                    Security Administration, 200
                                                                                                           associated monitoring activities. BJS is              Constitution Avenue NW., Room
                                                     Affected Public: Survey respondents                   not proposing edits to its confidentiality
                                                  to applicable BJS information                                                                                  N–5718, Washington, DC 20210,
                                                                                                           pledge, though it will consider                       ebsa.opr@dol.gov, (202) 693–8410, FAX
                                                  collections.                                             conducting pretesting activities on its
                                                     Total Respondents: Unchanged from                                                                           (202) 693–4745 (these are not toll-free
                                                                                                           various respondent populations and                    numbers).
                                                  current collection.                                      developing more detailed guidance for
                                                     Frequency: Unchanged from current                     staff and contractors on how to answer                SUPPLEMENTARY INFORMATION: This
                                                  collection.                                              respondents’ questions about the Act.                 notice requests public comment on the
                                                     Total Responses: Unchanged from                         If additional information is required               Department’s request for extension of
                                                  current collection.                                      contact: Melody Braswell, Department                  the Office of Management and Budget’s
                                                     Average Time per Response:                            Clearance Officer, United States                      (OMB) approval of ICRs contained in
                                                  Unchanged from current collection.                       Department of Justice, Justice                        the rules and prohibited transaction
                                                     Estimated Total Burden Hours:                         Management Division, Policy and                       exemptions described below. The
                                                  Unchanged from current collection.                       Planning Staff, Two Constitution                      Department is not proposing any
                                                     Estimated Total Cost: Unchanged                       Square, 145 N Street NE., 3E.405A,                    changes to the existing ICRs at this time.
                                                  from current collection.                                 Washington, DC 20530.                                 An agency may not conduct or sponsor,
                                                     The 60-day FRN submitted by the                                                                             and a person is not required to respond
                                                  Census Bureau can be accessed at                           Dated: May 17, 2017.
                                                                                                                                                                 to, an information collection unless it
                                                  https://www.federalregister.gov/                         Melody Braswell,
                                                                                                                                                                 displays a valid OMB control number. A
                                                  documents/2016/12/23/2016-30959/                         Department Clearance Officer for PRA, U.S.            summary of the ICRs and the current
                                                  agency-information-collection-activities-                Department of Justice.
                                                                                                                                                                 burden estimates follows:
                                                  request-for-comments-revision-of-the-                    [FR Doc. 2017–10345 Filed 5–19–17; 8:45 am]
                                                                                                                                                                    Agency: Employee Benefits Security
                                                  confidentiality-pledge. The Census                       BILLING CODE 4410–18–P
                                                                                                                                                                 Administration, Department of Labor.
                                                  Bureau is currently reviewing and                                                                                 Title: Prohibited Transaction
                                                  preparing responses to the comments it                                                                         Exemption (PTE) 81–8 for Investment of
                                                  received and will publish a 30-day FRN                   DEPARTMENT OF LABOR                                   Plan Assets in Certain Types of Short-
                                                  to solicit additional public comment.                                                                          Term Investments.
                                                  Comments on the Census Bureau’s                          Employee Benefits Security
                                                                                                                                                                    Type of Review: Extension of a
                                                  revised confidentiality pledge should be                 Administration
                                                                                                                                                                 currently approved collection of
                                                  submitted directly to the point-of-                                                                            information.
                                                                                                           Proposed Extension of Information
                                                  contact listed in the notice.                                                                                     OMB Number: 1210–0061.
                                                                                                           Collection Requests Submitted for
                                                  III. Data                                                Public Comment                                           Affected Public: Businesses or other
                                                                                                                                                                 for-profits, Not-for-profit institutions.
                                                    OMB Control Number: 1121–0358.
mstockstill on DSK30JT082PROD with NOTICES




                                                                                                           AGENCY: Employee Benefits Security                       Respondents: 65,000.
                                                    Legal Authority: 44 U.S.C. 3506(e) and                 Administration, Department of Labor.                     Responses: 325,000.
                                                  42 U.S.C. 3789g.                                         ACTION: Notice.                                          Estimated Total Burden Hours:
                                                    Form Number(s): None.                                                                                        81,000.
                                                                                                           SUMMARY:  The Department of Labor (the                   Estimated Total Burden Cost
                                                  IV. Request for Comments                                 Department), in accordance with the                   (Operating and Maintenance): $99,000.
                                                    Comments are invited on the efficacy                   Paperwork Reduction Act of 1995                          Description: PTE 81–8 permits the
                                                  of BJS’s revised confidentiality pledge                  (PRA), provides the general public and                investment of plan assets that involve


                                             VerDate Sep<11>2014    23:17 May 19, 2017   Jkt 241001   PO 00000   Frm 00134   Fmt 4703   Sfmt 4703   E:\FR\FM\22MYN1.SGM   22MYN1



Document Created: 2018-11-08 08:51:23
Document Modified: 2018-11-08 08:51:23
CategoryRegulatory Information
CollectionFederal Register
sudoc ClassAE 2.7:
GS 4.107:
AE 2.106:
PublisherOffice of the Federal Register, National Archives and Records Administration
SectionNotices
ActionNotice.
DatesComments are encouraged and will be accepted for 30 days until June 21, 2017.
ContactAllina Lee by telephone at 202-305- 0765 (this is not a toll-free number); by email at [email protected]; or by mail or courier to the Bureau of Justice Statistics, Office of Justice Programs, U.S. Department of Justice, ATTN: Allina Lee, 810 7th Street NW., Washington, D.C. 20531. Because of delays in the receipt of regular mail related to security screening, respondents are encouraged to use electronic communications.
FR Citation82 FR 23301 

2025 Federal Register | Disclaimer | Privacy Policy
USC | CFR | eCFR