82_FR_58714 82 FR 58477 - Privacy Act of 1974; System of Records

82 FR 58477 - Privacy Act of 1974; System of Records

DEPARTMENT OF STATE

Federal Register Volume 82, Issue 237 (December 12, 2017)

Page Range58477-58479
FR Document2017-26752

The purpose of the Email Archive Management Records system is to capture all emails and attachments that interact with a Department of State email account and to store them in a secure repository that allows for search, retrieval, and view when necessary.

Federal Register, Volume 82 Issue 237 (Tuesday, December 12, 2017)
[Federal Register Volume 82, Number 237 (Tuesday, December 12, 2017)]
[Notices]
[Pages 58477-58479]
From the Federal Register Online  [www.thefederalregister.org]
[FR Doc No: 2017-26752]


-----------------------------------------------------------------------

DEPARTMENT OF STATE

[Public Notice: 10226]


Privacy Act of 1974; System of Records

AGENCY: Department of State.

ACTION: Notice of a New System of Records.

-----------------------------------------------------------------------

SUMMARY: The purpose of the Email Archive Management Records system is 
to capture all emails and attachments that interact with a Department 
of State email account and to store them in a secure repository that 
allows for search, retrieval, and view when necessary.

DATES: In accordance with 5 U.S.C. 552a(e)(4) and (11), this system of 
records takes effect upon publication, with the exception of the 
routine uses that are subject to a 30-day period during which 
interested persons may submit comments to the Department. Please submit 
any comments by January 11, 2018.

ADDRESSES: Comments can be submitted by mail or email. If mail, please 
write to: U.S. Department of State; Office of Global Information 
Systems, Privacy Staff; A/GIS/PRV; SA-2, Suite 8100; Washington, DC 
20522-0208. If email, please address the email to the Chief Privacy 
Officer, Margaret P. Grafeld, at [email protected]. Please write 
``Email Archive Management Records, State-01'' on the envelope or the 
subject line of your email.

FOR FURTHER INFORMATION CONTACT: Margaret P. Grafeld, Chief Privacy 
Officer; U.S. Department of State; Office of Global Information 
Services, A/GIS/PRV; SA-2, Suite 8100; Washington, DC 20522-0208 or 
202-261-8300.

SUPPLEMENTARY INFORMATION: None.
SYSTEM NAME AND NUMBER:
    Email Archive Management Records, State-01.

SECURITY CLASSIFICATION:
    Unclassified and Classified.

SYSTEM LOCATION:
    Department of State (``Department'), located at 2201 C Street NW, 
Washington, DC 20520; Department of State annexes, U.S. Embassies, U.S. 
Consulates General, and U.S. Consulates. Information may also be stored 
within a government-certified cloud, implemented, and overseen by the 
Department's Messaging Systems Office (MSO), 2025 E. St. NW, 
Washington, DC 20006.

SYSTEM MANAGER(S):
    Division Chief, Office of Information Resource Management, 
Messaging Systems Office, Messaging Design Division; U.S. Department of 
State, 7049 Newington Rd; Lorton, VA 22079. The System Manager can be 
reached at (703) 746-2113.

AUTHORITY FOR MAINTENANCE OF THE SYSTEM:
    (a) 5 U.S.C. 301
    (b) Federal Records Act, 44 U.S.C. Ch. 31;
    (c) Freedom of Information Act, 5 U.S.C. 552.
    (d) Privacy Act of 1974, 5 U.S.C.552a(d).
    (e) 22 CFR part 171.

PURPOSE(S) OF THE SYSTEM:
    The purpose of the system is to capture all emails and attachments 
that interact with a Department of State email account and to store 
them in a secure repository that allows for search, retrieval, and view 
when necessary.

CATEGORIES OF INDIVIDUALS COVERED BY THE SYSTEM:
    Individuals who maintain a Department of State email account that 
is archived in the system. The system may also include information 
about individuals who interact with a Department of State email 
account, as well as individuals who are mentioned in a Department of 
State email message or attachment. The Privacy Act defines an 
individual at 5 U.S.C.552a(a)(2) as a United States citizen or lawful 
permanent resident.

CATEGORIES OF RECORDS IN THE SYSTEM:
    The records in this system include email messages and attachments 
associated with a Department of State email account, including any 
information that may be included in such messages or attachments. The 
system may also include biographic and contact information of 
individuals who maintain a Department of State email account, including 
name, address, email address, and phone number.

RECORD SOURCE CATEGORIES:
    These records contain information obtained from individuals who 
maintain a Department of State email account, as well as those who 
interact with such individuals.

ROUTINE USES OF RECORDS MAINTAINED IN THE SYSTEM, INCLUDING CATEGORIES 
OF USERS AND PURPOSES OF SUCH USES:
    The information in the system may be shared with:
    (a) Other federal agencies, foreign governments, and private 
entities where relevant and necessary for them to review or consult on 
documents that implicate their equities;
    (b) a contractor of the Department having need for the information 
in the performance of the contract, but not operating a system of 
records within the meaning of 5 U.S.C. 552a(m).
    (c) appropriate agencies, entities, and persons when (1) the 
Department of State suspects or has confirmed that there has been a 
breach of the system of records; (2) the Department of State has 
determined that as a result of the suspected or confirmed breach there 
is a risk of harm to individuals, the Department of State (including 
its information systems, programs, and operations), the Federal 
Government, or national security; and (3) the disclosure made to such 
agencies, entities, and persons is reasonably necessary to assist in 
connection with the Department of State efforts to respond to the 
suspected or confirmed breach or to prevent, minimize, or remedy such 
harm.
    (d) another Federal agency or Federal entity, when the Department 
of State determines that information from this system of records is 
reasonably necessary to assist the recipient agency

[[Page 58478]]

or entity in (1) responding to a suspected or confirmed breach or (2) 
preventing, minimizing, or remedying the risk of harm to individuals, 
the recipient agency or entity (including its information systems, 
programs, and operations), the Federal Government, or national 
security, resulting from a suspected or confirmed breach.
    (e) an agency, whether federal, state, local or foreign, where a 
record indicates a violation or potential violation of law, whether 
civil, criminal or regulatory in nature, and whether arising by general 
statute or particular program statute, or by regulation, rule or order 
issued pursuant thereto, so that the recipient agency can fulfill its 
responsibility to investigate or prosecute such violation or enforce or 
implement the statute, rule, regulation, or order.
    (f) the Federal Bureau of Investigation, the Department of Homeland 
Security, the National Counter-Terrorism Center (NCTC), the Terrorist 
Screening Center (TSC), or other appropriate federal agencies, for the 
integration and use of such information to protect against terrorism, 
if that record is about one or more individuals known, or suspected, to 
be or to have been involved in activities constituting, in preparation 
for, in aid of, or related to terrorism. Such information may be 
further disseminated by recipient agencies to Federal, State, local, 
territorial, tribal, and foreign government authorities, and to support 
private sector processes as contemplated in Homeland Security 
Presidential Directive/HSPD-6 and other relevant laws and directives, 
for terrorist screening, threat-protection and other homeland security 
purposes.
    (g) a congressional office from the record of an individual in 
response to an inquiry from the Congressional office made at the 
request of that individual.
    (h) a court, adjudicative body, or administrative body before which 
the Department is authorized to appear when (a) the Department; (b) any 
employee of the Department in his or her official capacity; (c) any 
employee of the Department in his or her individual capacity where the 
U.S. Department of Justice (``DOJ'') or the Department has agreed to 
represent the employee; or (d) the Government of the United States, 
when the Department determines that litigation is likely to affect the 
Department, is a party to litigation or has an interest in such 
litigation, and the use of such records by the Department is deemed to 
be relevant and necessary to the litigation or administrative 
proceeding.
    (i) the Department of Justice (``DOJ'') for its use in providing 
legal advice to the Department or in representing the Department in a 
proceeding before a court, adjudicative body, or other administrative 
body before which the Department is authorized to appear, where the 
Department deems DOJ's use of such information relevant and necessary 
to the litigation, and such proceeding names as a party or interests:
    (a) The Department or any component of it;
    (b) Any employee of the Department in his or her official capacity;
    (c) Any employee of the Department in his or her individual 
capacity where DOJ has agreed to represent the employee; or
    (d) The Government of the United States, where the Department 
determines that litigation is likely to affect the Department or any of 
its components.
    (j) the National Archives and Records Administration and the 
General Services Administration: For records management inspections, 
surveys and studies; following transfer to a Federal records center for 
storage; and to determine whether such records have sufficient 
historical or other value to warrant accessioning into the National 
Archives of the United States.

POLICIES AND PRACTICES FOR STORAGE OF RECORDS:
    Records are stored on electronic media. A description of standard 
Department of State policies concerning storage of electronic records 
is found here https://fam.state.gov/FAM/05FAM/05FAM0440.html.

POLICIES AND PRACTICES FOR RETRIEVAL OF RECORDS:
    By individual name or other personal identifier, if available.

POLICIES AND PRACTICES FOR RETENTION AND DISPOSAL OF RECORDS:
    The Department of State is in the process of finalizing a retention 
schedule for these records. Once the schedule is approved by the 
National Archives and Records Administration, the Records will be 
retired in accordance with the published Department of State Records 
Disposition Schedule that shall be published here: https://foia.state.gov/Learn/RecordsDisposition.aspx. More specific information 
may be obtained by writing to the following address: U.S. Department of 
State; Director, Office of Information Programs and Services; A/GIS/
IPS; SA-2, Suite 8100; Washington, DC 20522-0208.

ADMINISTRATIVE, TECHNICAL, AND PHYSICAL SAFEGUARDS:
    All users are given cyber security awareness training which covers 
the procedures for handling Sensitive But Unclassified information, 
including personally identifiable information (PII). Annual refresher 
training is mandatory. In addition, all Foreign Service and Civil 
Service employees and those Locally Employed Staff who handle PII are 
required to take a distance learning course instructing employees on 
privacy and security requirements, including the rules of behavior for 
handling PII and the potential consequences if it is handled 
improperly. Before being granted access to Email Archive Management 
Records, a user must first be granted access to the Department of State 
computer system.
    Remote access to the Department of State network from non-
Department-owned systems is authorized only to unclassified systems and 
through a Department-approved access program. Remote access to the 
network is configured with the authentication requirements contained in 
the Office of Management and Budget Circular Memorandum A-130.
    All Department of State employees and contractors with authorized 
access have undergone a thorough background security investigation. 
Access to the Department of State, its annexes and posts abroad is 
controlled by security guards, and admission is limited to those 
individuals possessing a valid identification card or individuals under 
proper escort. Access to Department of State workstations/networks 
requires a valid PKI identification card protected by a user's PIN that 
must first be entered before accessing the Department of State network. 
Access to computerized files is password-protected and under the direct 
supervision of the system manager. The system manager has the 
capability of printing audit trails of access from the computer media, 
thereby permitting regular and ad hoc monitoring of computer usage. 
When it is determined that a user no longer needs access, the user 
account is disabled.
    The safeguards in the following paragraphs apply only to records 
that are maintained in cloud systems. All cloud systems that provide IT 
services and process Department of State information must be 
specifically authorized by the Department of State Authorizing Official 
and Senior Agency Official for Privacy.
    Information that conforms with Department-specific definitions for 
FISMA low, moderate, or high categorization are permissible for cloud 
usage and must specifically be authorized by the Cloud Computing 
Governance Board. Specific security measures and safeguards will depend 
on

[[Page 58479]]

the FISMA categorization of the information in a given cloud system. 
The Email Archive Management Records system is rated as a FISMA high 
system. In accordance with Department policy, systems that process more 
sensitive information will require more stringent controls and review 
by Department cybersecurity experts prior to approval. Prior to 
operation, all Cloud systems must comply with applicable security 
measures that are outlined in FISMA, FedRAMP, OMB regulations, NIST 
Federal Information Processing Standards (FIPS) and Special Publication 
(SP), and Department of State policies and standards.
    All data stored in cloud environments categorized above a low FISMA 
impact risk level must be encrypted at rest and in-transit using a 
federally-approved encryption mechanism. The encryption keys shall be 
generated, maintained, and controlled in a Department data center by 
the Department key management authority. Deviations from these 
encryption requirements must be approved in writing by the Authorizing 
Official. Data in Email Archive Management Records categorized at a 
high FISMA impact risk level will additionally be subject to continual 
auditing and monitoring, multifactor authentication mechanisms 
utilizing PKI, NIST 800-53 controls concerning virtualization, servers, 
storage and networking as well as stringent measures to sanitize data 
from the cloud service once the contract is terminated.

RECORD ACCESS PROCEDURES:
    Individuals who wish to gain access to or to amend records 
pertaining to themselves should write to U.S. Department of State; 
Director, Office of Information Programs and Services; A/GIS/IPS; SA-2, 
Suite 8100; Washington, DC 20522-0208. The individual must specify that 
he or she wishes the Email Archive Management Records to be checked. At 
a minimum, the individual must include: Full name (including maiden 
name, if appropriate) and any other names used; current mailing address 
and zip code; date and place of birth; notarized signature or statement 
under penalty of perjury; a brief description of the circumstances that 
caused the creation of the record (including the city and/or country 
and the approximate dates) which gives the individual cause to believe 
that the Email Archive Management Records include records pertaining to 
him or her. Detailed instructions on Department of State procedures for 
accessing and amending records can be found at https://foia.state.gov/Request/Guide.aspx.

CONTESTING RECORD PROCEDURES:
    Individuals who wish to contest record procedures should write to 
U.S. Department of State; Director, Office of Information Programs and 
Services; A/GIS/IPS; SA-2, Suite 8100; Washington, DC 20522-0208.

 NOTIFICATION PROCEDURES:
    Individuals who have reason to believe that this system of records 
may contain information pertaining to them may write to U.S. Department 
of State; Director, Office of Information Programs and Services; A/GIS/
IPS; SA-2, Suite 8100; Washington, DC 20522-0208. The individual must 
specify that he or she wishes the Email Archive Management Records to 
be checked. At a minimum, the individual must include: Full name 
(including maiden name, if appropriate) and any other names used; 
current mailing address and zip code; date and place of birth; 
notarized signature or statement under penalty of perjury; a brief 
description of the circumstances that caused the creation of the record 
(including the city and/or country and the approximate dates) which 
gives the individual cause to believe that the Email Archive Management 
Records include records pertaining to him or her.

EXEMPTIONS PROMULGATED FOR THE SYSTEM:
    Pursuant to 5 U.S.C. 552a (j)(2), records in this system may be 
exempted from subsections (c)(3) and (4), (d), (e)(1), (2), (3), and 
(e)(4)(G), (H), and (I), and (f) of the Privacy Act.
    Pursuant to 5 U.S.C. 552a (k)(1), (k)(2), (k)(3), (k)(4), (k)(5), 
(k)(6), and (k)(7), records in this system may be exempted from 
subsections (c)(3), (d)(1), (d)(2), (d)(3), (d)(4), (d)(5), (e)(1), 
(e)(4)(G), (e)(4)(H), (e)(4)(I), (f)(1), (f)(2), (f)(3), (f)(4), and 
(f)(5).
    Any other exempt records from other agencies' systems of records 
that are recompiled into this system are also considered exempt to the 
extent they are claimed as such in the original systems.

HISTORY:
    None.

Mary R. Avery,
Senior Agency Official for Privacy, Senior Advisor, Office of Global 
Information Services, Bureau of Administration, Department of State.
[FR Doc. 2017-26752 Filed 12-11-17; 8:45 am]
 BILLING CODE 4710-24-P



                                                                          Federal Register / Vol. 82, No. 237 / Tuesday, December 12, 2017 / Notices                                           58477

                                               GIS/IPS; SA–2, Suite 8100; Washington,                  ADDRESSES:   Comments can be submitted                is archived in the system. The system
                                               DC 20522–0208.                                          by mail or email. If mail, please write to:           may also include information about
                                                                                                       U.S. Department of State; Office of                   individuals who interact with a
                                               NOTIFICATION PROCEDURES:
                                                                                                       Global Information Systems, Privacy                   Department of State email account, as
                                                  Individuals who have reason to                       Staff; A/GIS/PRV; SA–2, Suite 8100;                   well as individuals who are mentioned
                                               believe that this system of records may                 Washington, DC 20522–0208. If email,                  in a Department of State email message
                                               contain information pertaining to them                  please address the email to the Chief                 or attachment. The Privacy Act defines
                                               may write to U.S. Department of State;                  Privacy Officer, Margaret P. Grafeld, at              an individual at 5 U.S.C.552a(a)(2) as a
                                               Director, Office of Information Programs                Privacy@state.gov. Please write ‘‘Email               United States citizen or lawful
                                               and Services; A/GIS/IPS; SA–2, Suite                    Archive Management Records, State-01’’                permanent resident.
                                               8100; Washington, DC 20522–0208. The                    on the envelope or the subject line of
                                               individual must specify that he or she                  your email.                                           CATEGORIES OF RECORDS IN THE SYSTEM:
                                               wishes the Network User Account                         FOR FURTHER INFORMATION CONTACT:                        The records in this system include
                                               Records to be checked. At a minimum,                    Margaret P. Grafeld, Chief Privacy                    email messages and attachments
                                               the individual must include: Full name                  Officer; U.S. Department of State; Office             associated with a Department of State
                                               (including maiden name, if appropriate)                 of Global Information Services, A/GIS/                email account, including any
                                               and any other names used; current                       PRV; SA–2, Suite 8100; Washington, DC                 information that may be included in
                                               mailing address and zip code; date and                  20522–0208 or 202–261–8300.                           such messages or attachments. The
                                               place of birth; notarized signature or                  SUPPLEMENTARY INFORMATION: None.                      system may also include biographic and
                                               statement under penalty of perjury; a                                                                         contact information of individuals who
                                               brief description of the circumstances                  SYSTEM NAME AND NUMBER:                               maintain a Department of State email
                                               that caused the creation of the record                    Email Archive Management Records,                   account, including name, address, email
                                               (including the city and/or country and                  State-01.                                             address, and phone number.
                                               the approximate dates) which gives the
                                               individual cause to believe that the                    SECURITY CLASSIFICATION:                              RECORD SOURCE CATEGORIES:
                                               Network User Account Records include                      Unclassified and Classified.                          These records contain information
                                               records pertaining to him or her.                                                                             obtained from individuals who maintain
                                                                                                       SYSTEM LOCATION:
                                                                                                                                                             a Department of State email account, as
                                               EXEMPTIONS PROMULGATED FOR THE SYSTEM:                    Department of State (‘‘Department’),                well as those who interact with such
                                                  None.                                                located at 2201 C Street NW,                          individuals.
                                                                                                       Washington, DC 20520; Department of
                                               HISTORY:                                                State annexes, U.S. Embassies, U.S.                   ROUTINE USES OF RECORDS MAINTAINED IN THE
                                                  This SORN was previously published                   Consulates General, and U.S.                          SYSTEM, INCLUDING CATEGORIES OF USERS AND
                                               at 75 FR 7210.                                          Consulates. Information may also be                   PURPOSES OF SUCH USES:

                                               Mary R. Avery,
                                                                                                       stored within a government-certified                     The information in the system may be
                                                                                                       cloud, implemented, and overseen by                   shared with:
                                               Senior Agency Official for Privacy, Senior
                                               Advisor, Office of Global Information
                                                                                                       the Department’s Messaging Systems                       (a) Other federal agencies, foreign
                                               Services, Bureau of Administration,                     Office (MSO), 2025 E. St. NW,                         governments, and private entities where
                                               Department of State.                                    Washington, DC 20006.                                 relevant and necessary for them to
                                               [FR Doc. 2017–26750 Filed 12–11–17; 8:45 am]                                                                  review or consult on documents that
                                                                                                       SYSTEM MANAGER(S):
                                                                                                                                                             implicate their equities;
                                               BILLING CODE 4710–24–P                                    Division Chief, Office of Information                  (b) a contractor of the Department
                                                                                                       Resource Management, Messaging                        having need for the information in the
                                                                                                       Systems Office, Messaging Design                      performance of the contract, but not
                                               DEPARTMENT OF STATE                                     Division; U.S. Department of State, 7049              operating a system of records within the
                                               [Public Notice: 10226]                                  Newington Rd; Lorton, VA 22079. The                   meaning of 5 U.S.C. 552a(m).
                                                                                                       System Manager can be reached at (703)
                                                                                                                                                                (c) appropriate agencies, entities, and
                                               Privacy Act of 1974; System of                          746–2113.
                                                                                                                                                             persons when (1) the Department of
                                               Records
                                                                                                       AUTHORITY FOR MAINTENANCE OF THE SYSTEM:              State suspects or has confirmed that
                                               AGENCY:  Department of State.                             (a) 5 U.S.C. 301                                    there has been a breach of the system of
                                               ACTION: Notice of a New System of                         (b) Federal Records Act, 44 U.S.C. Ch.              records; (2) the Department of State has
                                               Records.                                                31;                                                   determined that as a result of the
                                                                                                         (c) Freedom of Information Act, 5                   suspected or confirmed breach there is
                                               SUMMARY:    The purpose of the Email                    U.S.C. 552.                                           a risk of harm to individuals, the
                                               Archive Management Records system is                      (d) Privacy Act of 1974, 5                          Department of State (including its
                                               to capture all emails and attachments                   U.S.C.552a(d).                                        information systems, programs, and
                                               that interact with a Department of State                  (e) 22 CFR part 171.                                operations), the Federal Government, or
                                               email account and to store them in a                                                                          national security; and (3) the disclosure
                                                                                                       PURPOSE(S) OF THE SYSTEM:
                                               secure repository that allows for search,                                                                     made to such agencies, entities, and
                                               retrieval, and view when necessary.                       The purpose of the system is to
                                                                                                                                                             persons is reasonably necessary to assist
                                                                                                       capture all emails and attachments that
                                               DATES: In accordance with 5 U.S.C.                                                                            in connection with the Department of
                                                                                                       interact with a Department of State
                                               552a(e)(4) and (11), this system of                                                                           State efforts to respond to the suspected
ethrower on DSK3G9T082PROD with NOTICES




                                                                                                       email account and to store them in a
                                               records takes effect upon publication,                                                                        or confirmed breach or to prevent,
                                                                                                       secure repository that allows for search,
                                               with the exception of the routine uses                                                                        minimize, or remedy such harm.
                                                                                                       retrieval, and view when necessary.
                                               that are subject to a 30-day period                                                                              (d) another Federal agency or Federal
                                               during which interested persons may                     CATEGORIES OF INDIVIDUALS COVERED BY THE              entity, when the Department of State
                                               submit comments to the Department.                      SYSTEM:                                               determines that information from this
                                               Please submit any comments by January                     Individuals who maintain a                          system of records is reasonably
                                               11, 2018.                                               Department of State email account that                necessary to assist the recipient agency


                                          VerDate Sep<11>2014   20:03 Dec 11, 2017   Jkt 244001   PO 00000   Frm 00100   Fmt 4703   Sfmt 4703   E:\FR\FM\12DEN1.SGM   12DEN1


                                               58478                      Federal Register / Vol. 82, No. 237 / Tuesday, December 12, 2017 / Notices

                                               or entity in (1) responding to a                        Department in a proceeding before a                   procedures for handling Sensitive But
                                               suspected or confirmed breach or (2)                    court, adjudicative body, or other                    Unclassified information, including
                                               preventing, minimizing, or remedying                    administrative body before which the                  personally identifiable information (PII).
                                               the risk of harm to individuals, the                    Department is authorized to appear,                   Annual refresher training is mandatory.
                                               recipient agency or entity (including its               where the Department deems DOJ’s use                  In addition, all Foreign Service and
                                               information systems, programs, and                      of such information relevant and                      Civil Service employees and those
                                               operations), the Federal Government, or                 necessary to the litigation, and such                 Locally Employed Staff who handle PII
                                               national security, resulting from a                     proceeding names as a party or interests:             are required to take a distance learning
                                               suspected or confirmed breach.                             (a) The Department or any component                course instructing employees on privacy
                                                  (e) an agency, whether federal, state,               of it;                                                and security requirements, including
                                               local or foreign, where a record                           (b) Any employee of the Department                 the rules of behavior for handling PII
                                               indicates a violation or potential                      in his or her official capacity;                      and the potential consequences if it is
                                               violation of law, whether civil, criminal                  (c) Any employee of the Department                 handled improperly. Before being
                                               or regulatory in nature, and whether                    in his or her individual capacity where               granted access to Email Archive
                                               arising by general statute or particular                DOJ has agreed to represent the                       Management Records, a user must first
                                               program statute, or by regulation, rule or              employee; or                                          be granted access to the Department of
                                               order issued pursuant thereto, so that                     (d) The Government of the United                   State computer system.
                                               the recipient agency can fulfill its                    States, where the Department                             Remote access to the Department of
                                               responsibility to investigate or prosecute              determines that litigation is likely to               State network from non-Department-
                                               such violation or enforce or implement                  affect the Department or any of its                   owned systems is authorized only to
                                               the statute, rule, regulation, or order.                components.                                           unclassified systems and through a
                                                  (f) the Federal Bureau of Investigation,                (j) the National Archives and Records              Department-approved access program.
                                               the Department of Homeland Security,                    Administration and the General                        Remote access to the network is
                                               the National Counter-Terrorism Center                   Services Administration: For records                  configured with the authentication
                                               (NCTC), the Terrorist Screening Center                  management inspections, surveys and                   requirements contained in the Office of
                                               (TSC), or other appropriate federal                     studies; following transfer to a Federal              Management and Budget Circular
                                               agencies, for the integration and use of                records center for storage; and to                    Memorandum A–130.
                                               such information to protect against                     determine whether such records have                      All Department of State employees
                                               terrorism, if that record is about one or               sufficient historical or other value to               and contractors with authorized access
                                               more individuals known, or suspected,                   warrant accessioning into the National                have undergone a thorough background
                                               to be or to have been involved in                       Archives of the United States.                        security investigation. Access to the
                                               activities constituting, in preparation                                                                       Department of State, its annexes and
                                               for, in aid of, or related to terrorism.                POLICIES AND PRACTICES FOR STORAGE OF                 posts abroad is controlled by security
                                               Such information may be further                         RECORDS:                                              guards, and admission is limited to
                                               disseminated by recipient agencies to                     Records are stored on electronic                    those individuals possessing a valid
                                               Federal, State, local, territorial, tribal,             media. A description of standard                      identification card or individuals under
                                               and foreign government authorities, and                 Department of State policies concerning               proper escort. Access to Department of
                                               to support private sector processes as                  storage of electronic records is found                State workstations/networks requires a
                                               contemplated in Homeland Security                       here https://fam.state.gov/FAM/05FAM/                 valid PKI identification card protected
                                               Presidential Directive/HSPD–6 and                       05FAM0440.html.                                       by a user’s PIN that must first be entered
                                               other relevant laws and directives, for                 POLICIES AND PRACTICES FOR RETRIEVAL OF
                                                                                                                                                             before accessing the Department of State
                                               terrorist screening, threat-protection and              RECORDS:
                                                                                                                                                             network. Access to computerized files is
                                               other homeland security purposes.                                                                             password-protected and under the
                                                  (g) a congressional office from the                    By individual name or other personal
                                                                                                                                                             direct supervision of the system
                                               record of an individual in response to                  identifier, if available.
                                                                                                                                                             manager. The system manager has the
                                               an inquiry from the Congressional office                POLICIES AND PRACTICES FOR RETENTION AND              capability of printing audit trails of
                                               made at the request of that individual.                 DISPOSAL OF RECORDS:                                  access from the computer media,
                                                  (h) a court, adjudicative body, or                     The Department of State is in the                   thereby permitting regular and ad hoc
                                               administrative body before which the                    process of finalizing a retention                     monitoring of computer usage. When it
                                               Department is authorized to appear                      schedule for these records. Once the                  is determined that a user no longer
                                               when (a) the Department; (b) any                        schedule is approved by the National                  needs access, the user account is
                                               employee of the Department in his or                    Archives and Records Administration,                  disabled.
                                               her official capacity; (c) any employee of              the Records will be retired in                           The safeguards in the following
                                               the Department in his or her individual                 accordance with the published                         paragraphs apply only to records that
                                               capacity where the U.S. Department of                   Department of State Records Disposition               are maintained in cloud systems. All
                                               Justice (‘‘DOJ’’) or the Department has                 Schedule that shall be published here:                cloud systems that provide IT services
                                               agreed to represent the employee; or (d)                https://foia.state.gov/Learn/                         and process Department of State
                                               the Government of the United States,                    RecordsDisposition.aspx. More specific                information must be specifically
                                               when the Department determines that                     information may be obtained by writing                authorized by the Department of State
                                               litigation is likely to affect the                      to the following address: U.S.                        Authorizing Official and Senior Agency
                                               Department, is a party to litigation or                 Department of State; Director, Office of              Official for Privacy.
                                               has an interest in such litigation, and                 Information Programs and Services; A/                    Information that conforms with
ethrower on DSK3G9T082PROD with NOTICES




                                               the use of such records by the                          GIS/IPS; SA–2, Suite 8100; Washington,                Department-specific definitions for
                                               Department is deemed to be relevant                     DC 20522–0208.                                        FISMA low, moderate, or high
                                               and necessary to the litigation or                                                                            categorization are permissible for cloud
                                               administrative proceeding.                              ADMINISTRATIVE, TECHNICAL, AND PHYSICAL               usage and must specifically be
                                                  (i) the Department of Justice (‘‘DOJ’’)              SAFEGUARDS:                                           authorized by the Cloud Computing
                                               for its use in providing legal advice to                  All users are given cyber security                  Governance Board. Specific security
                                               the Department or in representing the                   awareness training which covers the                   measures and safeguards will depend on


                                          VerDate Sep<11>2014   21:18 Dec 11, 2017   Jkt 244001   PO 00000   Frm 00101   Fmt 4703   Sfmt 4703   E:\FR\FM\12DEN1.SGM   12DEN1


                                                                          Federal Register / Vol. 82, No. 237 / Tuesday, December 12, 2017 / Notices                                                58479

                                               the FISMA categorization of the                         CONTESTING RECORD PROCEDURES:                         LLP on behalf of Trinity Industries, Inc.
                                               information in a given cloud system.                      Individuals who wish to contest                     (WB17–51—12/05/17) for permission to
                                               The Email Archive Management                            record procedures should write to U.S.                use certain data from the Board’s 2016
                                               Records system is rated as a FISMA high                 Department of State; Director, Office of              Carload Waybill Sample. A copy of this
                                               system. In accordance with Department                   Information Programs and Services; A/                 request may be obtained from the Office
                                               policy, systems that process more                       GIS/IPS; SA–2, Suite 8100; Washington,                of Economics.
                                               sensitive information will require more                 DC 20522–0208.                                          The waybill sample contains
                                               stringent controls and review by                                                                              confidential railroad and shipper data;
                                                                                                       NOTIFICATION PROCEDURES:
                                               Department cybersecurity experts prior                                                                        therefore, if any parties object to these
                                               to approval. Prior to operation, all Cloud                 Individuals who have reason to                     requests, they should file their
                                               systems must comply with applicable                     believe that this system of records may               objections with the Director of the
                                               security measures that are outlined in                  contain information pertaining to them                Board’s Office of Economics within 14
                                               FISMA, FedRAMP, OMB regulations,                        may write to U.S. Department of State;                calendar days of the date of this notice.
                                               NIST Federal Information Processing                     Director, Office of Information Programs              The rules for release of waybill data are
                                               Standards (FIPS) and Special                            and Services; A/GIS/IPS; SA–2, Suite                  codified at 49 CFR 1244.9.
                                               Publication (SP), and Department of                     8100; Washington, DC 20522–0208. The                    Contact: Alexander Dusenberry, (202)
                                               State policies and standards.                           individual must specify that he or she                245–0319.
                                                  All data stored in cloud environments                wishes the Email Archive Management
                                               categorized above a low FISMA impact                    Records to be checked. At a minimum,                  Jeffrey Herzig,
                                               risk level must be encrypted at rest and                the individual must include: Full name                Clearance Clerk.
                                               in-transit using a federally-approved                   (including maiden name, if appropriate)               [FR Doc. 2017–26674 Filed 12–11–17; 8:45 am]
                                               encryption mechanism. The encryption                    and any other names used; current                     BILLING CODE 4915–01–P
                                               keys shall be generated, maintained, and                mailing address and zip code; date and
                                               controlled in a Department data center                  place of birth; notarized signature or
                                               by the Department key management                        statement under penalty of perjury; a                 DEPARTMENT OF TRANSPORTATION
                                               authority. Deviations from these                        brief description of the circumstances
                                               encryption requirements must be                         that caused the creation of the record                Federal Aviation Administration
                                               approved in writing by the Authorizing                  (including the city and/or country and
                                               Official. Data in Email Archive                         the approximate dates) which gives the                Notice of Opportunity for Public
                                               Management Records categorized at a                     individual cause to believe that the                  Comment on a Land Use Change From
                                               high FISMA impact risk level will                       Email Archive Management Records                      Aeronautical to Non-Aeronautical Use
                                               additionally be subject to continual                    include records pertaining to him or                  for 419 Acres of Airport Land for Solar
                                               auditing and monitoring, multifactor                    her.                                                  Farm Use at Sanford Seacoast
                                               authentication mechanisms utilizing                                                                           Regional Airport, Sanford, ME
                                                                                                       EXEMPTIONS PROMULGATED FOR THE SYSTEM:
                                               PKI, NIST 800–53 controls concerning                       Pursuant to 5 U.S.C. 552a (j)(2),                  AGENCY:  Federal Aviation
                                               virtualization, servers, storage and                    records in this system may be exempted                Administration (FAA), DOT.
                                               networking as well as stringent                         from subsections (c)(3) and (4), (d),                 ACTION: Request for public comments.
                                               measures to sanitize data from the cloud                (e)(1), (2), (3), and (e)(4)(G), (H), and (I),
                                               service once the contract is terminated.                and (f) of the Privacy Act.                           SUMMARY:   Notice is being given that the
                                               RECORD ACCESS PROCEDURES:                                  Pursuant to 5 U.S.C. 552a (k)(1),                  FAA is considering a request from the
                                                  Individuals who wish to gain access                  (k)(2), (k)(3), (k)(4), (k)(5), (k)(6), and           Sanford Seacoast Regional Airport, to
                                               to or to amend records pertaining to                    (k)(7), records in this system may be                 change the current land use from
                                               themselves should write to U.S.                         exempted from subsections (c)(3), (d)(1),             aeronautical use to non-aeronautical use
                                               Department of State; Director, Office of                (d)(2), (d)(3), (d)(4), (d)(5), (e)(1),               of 419 acres of land. The parcels are
                                               Information Programs and Services; A/                   (e)(4)(G), (e)(4)(H), (e)(4)(I), (f)(1), (f)(2),      located along the southwesterly side of
                                               GIS/IPS; SA–2, Suite 8100; Washington,                  (f)(3), (f)(4), and (f)(5).                           Runway 07/25, the northerly end of
                                               DC 20522–0208. The individual must                         Any other exempt records from other                Runway 25 and in a portion of the
                                               specify that he or she wishes the Email                 agencies’ systems of records that are                 infield area between Runway 07/25 and
                                               Archive Management Records to be                        recompiled into this system are also                  Runway 14/32. There is adequate
                                               checked. At a minimum, the individual                   considered exempt to the extent they are              developable area on the airport to meet
                                               must include: Full name (including                      claimed as such in the original systems.              the future twenty year need for
                                               maiden name, if appropriate) and any                    HISTORY:
                                                                                                                                                             projected activity and the Airport
                                               other names used; current mailing                                                                             Layout Plan was updated with a Pen
                                                                                                         None.
                                               address and zip code; date and place of                                                                       and Ink change to designate the parcels
                                               birth; notarized signature or statement                 Mary R. Avery,                                        for non-aeronautical use. The airport
                                               under penalty of perjury; a brief                       Senior Agency Official for Privacy, Senior            will obtain fair market value for the
                                               description of the circumstances that                   Advisor, Office of Global Information                 lease of the land and the income derived
                                                                                                       Services, Bureau of Administration,                   from this lease will be placed in the
                                               caused the creation of the record
                                                                                                       Department of State.                                  airport’s operation and maintenance
                                               (including the city and/or country and
                                               the approximate dates) which gives the                  [FR Doc. 2017–26752 Filed 12–11–17; 8:45 am]          funds for the facility.
                                               individual cause to believe that the                    BILLING CODE 4710–24–P                                DATES: Comments must be received on
ethrower on DSK3G9T082PROD with NOTICES




                                               Email Archive Management Records                                                                              or before January 11, 2018.
                                               include records pertaining to him or                                                                          ADDRESSES: You may send comments
                                               her. Detailed instructions on                           SURFACE TRANSPORTATION BOARD                          using any of the following methods:
                                               Department of State procedures for                                                                              • Federal eRulemaking Portal: Go to
                                                                                                       Release of Waybill Data
                                               accessing and amending records can be                                                                         http://www.regulations.gov, and follow
                                               found at https://foia.state.gov/Request/                  The Surface Transportation Board has                the instructions on providing
                                               Guide.aspx.                                             received a request from Neville Peterson              comments.


                                          VerDate Sep<11>2014   20:03 Dec 11, 2017   Jkt 244001   PO 00000   Frm 00102   Fmt 4703   Sfmt 4703   E:\FR\FM\12DEN1.SGM   12DEN1



Document Created: 2018-10-25 10:49:44
Document Modified: 2018-10-25 10:49:44
CategoryRegulatory Information
CollectionFederal Register
sudoc ClassAE 2.7:
GS 4.107:
AE 2.106:
PublisherOffice of the Federal Register, National Archives and Records Administration
SectionNotices
ActionNotice of a New System of Records.
DatesIn accordance with 5 U.S.C. 552a(e)(4) and (11), this system of records takes effect upon publication, with the exception of the routine uses that are subject to a 30-day period during which interested persons may submit comments to the Department. Please submit any comments by January 11, 2018.
ContactMargaret P. Grafeld, Chief Privacy Officer; U.S. Department of State; Office of Global Information Services, A/GIS/PRV; SA-2, Suite 8100; Washington, DC 20522-0208 or 202-261-8300.
FR Citation82 FR 58477 

2025 Federal Register | Disclaimer | Privacy Policy
USC | CFR | eCFR