83_FR_57741 83 FR 57520 - Privacy Act of 1974; System of Records

83 FR 57520 - Privacy Act of 1974; System of Records

SOCIAL SECURITY ADMINISTRATION

Federal Register Volume 83, Issue 221 (November 15, 2018)

Page Range57520-57523
FR Document2018-24853

In accordance with the Privacy Act, we are issuing public notice of our intent to establish a new system of records entitled, Security and Suitability Files (60-0377). This notice publishes details of the new system as set forth under the caption, SUPPLEMENTARY INFORMATION.

Federal Register, Volume 83 Issue 221 (Thursday, November 15, 2018)
[Federal Register Volume 83, Number 221 (Thursday, November 15, 2018)]
[Notices]
[Pages 57520-57523]
From the Federal Register Online  [www.thefederalregister.org]
[FR Doc No: 2018-24853]


-----------------------------------------------------------------------

SOCIAL SECURITY ADMINISTRATION

[Docket No. SSA-2018-0004]


Privacy Act of 1974; System of Records

AGENCY: Deputy Commissioner for Human Resources, Social Security 
Administration (SSA).

ACTION: Notice of a new system of records.

-----------------------------------------------------------------------

SUMMARY: In accordance with the Privacy Act, we are issuing public 
notice of our intent to establish a new system of records entitled, 
Security and Suitability Files (60-0377). This notice publishes details 
of the new system as set forth under the caption, SUPPLEMENTARY 
INFORMATION.

DATES: The system of records notice (SORN) is applicable upon its 
publication in today's Federal Register, with the exception of the 
routine uses, which are effective December 17, 2018. We invite public 
comment on the routine uses or other aspects of this SORN. In 
accordance with 5 U.S.C. 552a(e)(4) and (e)(11), the public is given a 
30-day period in which to submit comments. Therefore, please submit any 
comments by December 17, 2018.

ADDRESSES: The public, Office of Management and Budget (OMB), and 
Congress may comment on this publication by writing to the Executive 
Director, Office of Privacy and Disclosure, Office of the General 
Counsel, SSA, Room G-401 West High Rise, 6401 Security Boulevard, 
Baltimore, Maryland 21235-6401, or through the Federal e-Rulemaking 
Portal at http://www.regulations.gov, please reference docket number 
SSA-2018-0004. All comments we receive will be available for public 
inspection at the above address and we will post them to http://www.regulations.gov.

FOR FURTHER INFORMATION CONTACT: Jasson Seiden, Government Information 
Specialist, Privacy Implementation Division, Office of Privacy and 
Disclosure, Office of the General Counsel, SSA, Room G-401 West High 
Rise, 6401 Security Boulevard, Baltimore, Maryland 21235-6401, 
telephone: (410) 597-4307, email: Jasson.Seiden@ssa.gov.

SUPPLEMENTARY INFORMATION: Persons appointed to, and under 
consideration for, Federal service or contract employment are required, 
with limited exceptions, to submit to a suitability background 
investigation. In addition, other individuals granted access to agency 
facilities and records may be required to complete such an 
investigation. The Deputy Commissioner for Human Resources, Office of 
Personnel, Center for Suitability and Personnel Security (CSPS) 
oversees and is responsible for adjudicating these investigations. 
Suitability and security related information that we collect during the 
investigations process and send to the Office of Personnel Management 
(OPM) is covered by OPM/Central-9, Personnel Investigations Records. 
The new Security and Suitability Files system of records covers 
suitability and security related information that we generate during 
the investigation process but that we do not send to OPM. We will use 
the information we collect to conduct background investigations for the 
purpose of establishing that individuals employed by us, working under 
contract for us, or otherwise granted access to our facilities and 
records are suitable for such employment or access.
    In accordance with 5 U.S.C. 552a(r), we have provided a report to 
OMB and Congress on this new system of records.

    Dated: June 5, 2018.
Mary Ann Zimmerman,
Acting Executive Director, Office of Privacy and Disclosure, Office of 
the General Counsel.

    Editorial note:  This document was received for publication by 
the Office of the Federal Register on November 8, 2018.
System Name and Number
Security and Suitability Files, 60-0377

SECURITY CLASSIFICATION:
    Unclassified.

SYSTEM LOCATION:
    Social Security Administration, Deputy Commissioner for Human 
Resources, Office of Personnel, Center for Suitability and Personnel 
Security (CSPS), 6401 Security Boulevard, Baltimore, MD 21235; or the 
initiating regional office (See Appendix C for address information).
    Office of Personnel Management, National Background Investigations 
Bureau (NBIB), 1137 Branchton Road, PO Box 618, Boyers, PA 16018.
    Defense Information Systems Agency (DISA), DISA Defense Enterprise 
Computing Center (DECC), 3990 E Broad Street, Columbus, OH 43213-1152.

SYSTEM MANAGER(S):
    Social Security Administration, Deputy Commissioner for Human 
Resources, Office of Personnel, Center for Suitability and Personnel 
Security (CSPS), 6401 Security Boulevard, Baltimore, MD 21235; or the 
initiating regional office (See Appendix C for address information).
    csps.controls.response@ssa.gov.

AUTHORITY FOR MAINTENANCE OF THE SYSTEM:
    Section 205(a) of the Social Security Act, as amended, HSPD-12 
(Policy for a Common Identification Standard for Federal Employees and 
Contractors), Executive Orders 13764 (Amending the Civil Service Rules, 
Executive Order 13488, and Executive Order 13467 To Modernize the 
Executive Branch-Wide Governance Structure and Processes for Security 
Clearances, Suitability and Fitness for Employment, and Credentialing, 
and Related Matters) and 12968 (Access to Classified Information), 
Sections 3301 and 3302 of Title 5, U.S.C., and Parts 5, 731, 732, and 
736 of Title 5 of the Code of Federal Regulations; and Fair Credit 
Reporting Act.

[[Page 57521]]

PURPOSE(S) OF THE SYSTEM:
    We will use the information in the Security and Suitability Files 
to determine the suitability of individuals for appointment or 
retention as an SSA employee, for access to SSA facilities and 
information systems, to hold sensitive positions, and to perform work 
or services for or on behalf of SSA as a contractor or volunteer. This 
will ensure that all of our prospective, current, and former employees, 
students, contractors, grantees, appointees, cooperative agreement 
awardees, volunteers, and others granted access to our facilities and 
records are investigated appropriately for security and suitability, 
and that the results of the investigations when necessary, are 
adjudicated based on federal law and regulations and are recorded in 
the official records.

CATEGORIES OF INDIVIDUALS COVERED BY THE SYSTEM:
    Individuals seeking, or who have sought, to fill an available 
vacancy with SSA, or to otherwise be granted access to SSA facilities 
and records. This category of individuals include, but are not limited 
to, prospective, current, and former employees, students, contractors, 
grantees, appointees, cooperative agreement awardees, volunteers, and 
others who perform services for SSA.

CATEGORIES OF RECORDS IN THE SYSTEM:
    This system maintains information collected as part of our security 
and suitability investigative process. This information may include the 
individual's name, address, date of birth (DOB), Social Security number 
(SSN), phone number, driver's license information, fingerprints, 
residential and employment addresses, employment history (e.g., names 
of supervisors and colleagues), financial and educational background, 
professional experience information, and information from personal and 
professional references. We may also collect information about personal 
and professional conduct that could include disciplinary, criminal, and 
credit histories. This system may also include determinations of 
sensitivity and risk level for different positions and information to 
ensure compliance with security and suitability requirements, and 
information necessary to monitor and track security and suitability 
investigations for management workload purposes.

RECORD SOURCE CATEGORIES:
    We obtain information in this system primarily from the individuals 
to whom the record pertains. Information may also be obtained from, but 
not limited to references, credit reporting agencies, other federal 
agencies, and educational institutions.

ROUTINE USES OF RECORDS MAINTAINED IN THE SYSTEM, INCLUDING CATEGORIES 
OF USERS AND THE PURPOSES OF SUCH USES:
    We will disclose records pursuant to the following routine uses; 
however, we will not disclose any information defined as ``return or 
return information'' under 26 U.S.C. 6103 of the Internal Revenue 
Service Code, unless authorized by statute, the Internal Revenue 
Service (IRS), or IRS regulations.
    1. To the Office of the President in response to an inquiry from 
that office made on behalf of, and at the request of, the subject of 
the record or third party acting on the subject's behalf.
    2. To a congressional office in response to an inquiry from that 
office made on behalf of, and at the request of, the subject of the 
record or a third party acting on the subject's behalf.
    3. To the Department of Justice (DOJ), a court or other tribunal, 
or another party before such court or tribunal, when:
    (a) SSA, or any component thereof; or
    (b) any SSA employee in his/her official capacity; or:
    (c) any SSA employee in his/her individual capacity where DOJ (or 
SSA where it is authorized to do so) has agreed to represent the 
employee; or
    (d) the United States or any agency thereof where SSA determines 
the litigation is likely to affect SSA or any of its components,
    is a party to the litigation or has an interest in such litigation, 
and SSA determines that the use of such records by DOJ, a court or 
other tribunal, or another party before the tribunal is relevant and 
necessary to the litigation, provided, however, that in each case, the 
agency determines that disclosure of the records to DOJ, a court or 
other tribunal, or another party is a use of the information contained 
in the records that is compatible with the purpose for which the 
records were collected.
    4. To contractors and other Federal agencies, as necessary, for 
assisting SSA in the efficient administration of its programs. We 
disclose information under this routine use only in situations in which 
SSA may enter into a contractual or similar agreement with a third 
party to assist the accomplishing an agency function relating to this 
system of records.
    5. To student volunteers, individuals working under a personal 
services contract, and other workers who technically do not have the 
status of Federal employees, when they are performing work for SSA, as 
authorized by law, and they need access to personally identifiable 
information (PII) in SSA records in order to perform their assigned 
agency functions.
    6. To the Equal Employment Opportunity Commission (EEOC or 
Commission) when requested in connection with investigations into 
alleged or possible discriminatory practices in the Federal sector, 
examination of Federal affirmative employment programs, compliance by 
Federal agencies with the Uniform Guidelines on Employee Selection 
Procedures, or other functions vested in the Commission.
    7. To the Federal Labor Relations Authority, its General Counsel, 
the Federal Mediation and Conciliation Service, the Federal Service 
Impasses Panel, or an arbitrator when information is requested in 
connection with investigations of allegations of unfair practices, 
matters before an arbitrator or the Federal Service Impasses Panel.
    8. To the Office of Personnel Management (OPM), the Merit Systems 
Protection Board, or the Office of Special Counsel in connection with 
appeals, special studies of the civil service and other merit systems, 
review of rules and regulations, investigations of alleged or possible 
prohibited practices, and other such functions promulgated in 5 U.S.C. 
Chapter 12, or as may be required by law.
    9. To Federal, State, and local law enforcement agencies and 
private security contractors, as appropriate, information necessary:
    (a) To enable them to protect the safety of SSA employees and 
customers, the security of the SSA workplace, and the operation of SSA 
facilities, or
    (b) to assist in investigations or prosecutions with respect to 
activities that affect such safety and security or activities that 
disrupt the operation of SSA facilities.
    10. To the National Archives and Records Administration (NARA) 
under 44 U.S.C. 2904 and 2906.
    11. To a Federal agency in response to its request, or at SSA's 
initiative, in connection with decisions to hire or retain an employee, 
issue a security clearance, conduct a security or suitability 
investigation, classify a job, award a contract, or regarding the 
requesting agency's decision to issue a license, grant, or other 
benefit, to the extent that the information is relevant and necessary 
to the requesting agency's decision.
    12. To officials of labor organizations recognized under 5 U.S.C. 
Chapter 71 when relevant and necessary to their

[[Page 57522]]

duties of exclusive representation concerning personnel policies, 
practices, and matters affecting conditions of employment.
    13. To appropriate agencies, entities, and persons when:
    (a) SSA suspects or has confirmed that there has been a breach of 
the system of records;
    (b) SSA has determined that as the result of the suspected or 
confirmed breach there is a risk of harm to individuals, SSA (including 
its information systems, programs, and operations), the Federal 
Government, or national security; and
    (c) the disclosure made to such agencies, entities, and persons is 
reasonably necessary to assist in connection with SSA's efforts to 
respond to the suspected or confirmed breach or to prevent, minimize, 
or remedy such harm.
    14. To any source from which information is requested in the course 
of an investigation, to the extent necessary to identify the 
individual, inform the source of the nature and purpose of the 
investigation, and to identify the type of information requested.
    15. To another Federal agency or Federal entity, when SSA 
determines that information from this system of records is reasonably 
necessary to assist the recipient agency or entity in:
    (a) Responding to a suspected or confirmed breach; or
    (b) preventing, minimizing, or remedying the risk of harm to 
individuals, the recipient agency or entity (including its information 
systems, programs, and operations), the Federal Government, or national 
security, resulting from a suspected or confirmed breach.
    16. To the Department of Defense or other Federal agencies in 
connection with providing approved shared services to subscribing 
agencies for hiring or retaining an employee; classifying a position; 
conducting a security, suitability, fitness, or credentialing 
background investigation (including continuous evaluation/continuous 
vetting); issuing a security clearance or sensitive position 
eligibility; making a suitability, fitness, or credentialing decision; 
or recording the results of any agency decision with respect to these 
functions.

POLICIES AND PRACTICES FOR STORAGE OF RECORDS:
    We will maintain records in this system in paper and electronic 
form.

DISCLOSURE TO CONSUMER REPORTING AGENCIES:
    None.

POLICIES AND PRACTICES FOR RETRIEVAL OF RECORDS:
    We will retrieve records in this system by name, SSN, and DOB.

POLICIES AND PRACTICES FOR RETENTION AND DISPOSAL OF RECORDS:
    These records are temporary. We retain and destroy this information 
in accordance with the NARA approved General Records Schedules (GRS) 
2.0, Human Resources, and GRS 5.6, Security Records. We retain 
investigative records on employees or applicants for employment, 
whether or not a security clearance is granted, and other persons, such 
as those performing work under contract or as volunteers in accordance 
with the approved records schedules. We retain investigative reports in 
accordance with OPM Central-9 (81 FR 70191) or successor Records 
Disposition Authority. Our shared service provider for tracking post-
investigation data, the Department of Defense (DoD), retains post-
investigative files and the computerized data bases in accordance with 
the Defense Manpower Data Center (DMDC) retention policies as published 
in DMDC 24 DoD (81 FR 39032) or successor Records Disposition 
Authority.

ADMINISTRATIVE, TECHNICAL, AND PHYSICAL SAFEGUARDS:
    We retain electronic and paper files with personal identifiers in 
secure storage areas accessible only by our authorized employees and 
contractors who have a need for the information when performing their 
official duties. Security measures include, but are not limited to, the 
use of codes and profiles, personal identification number and password, 
and personal identification verification cards. We keep paper records 
in locked cabinets within secure areas, with access limited to only 
those employees who have an official need for access in order to 
perform their duties.
    We annually provide our employees and contractors with appropriate 
security awareness training that includes reminders about the need to 
protect personally identifiable information (PII) and the criminal 
penalties that apply to unauthorized access to, or disclosure of, PII 
(5 U.S.C. 552a(i)(1)). Furthermore, employees and contractors with 
access to databases maintaining PII must sign a sanctions document 
annually, acknowledging their accountability for inappropriately 
accessing or disclosing such information.
    The system is protected against compromise of PII and cyberattack 
by the full suite of defenses and sensors of the DoD cybersecurity 
perimeter. Data is encrypted where it is stored, and network traffic is 
encrypted based on the type of user traffic and risk to PII data. User 
access to data is protected using Identity and Access Management with 
multifactor authentication that will only allow an authenticated user 
to access and manipulate the specific records based on user role and 
permissions. The system audits access to information. Physical entry is 
restricted by the use of locks, guards, and administrative procedures. 
All individuals granted access to the system must complete Information 
Assurance and Privacy Act training before initially accessing the 
system and annually thereafter, and these users must have also been 
through the information technology and/or security clearance 
eligibility process.

RECORD ACCESS PROCEDURES:
    This system of records has been exempted from the Privacy Act's 
access, contesting, and notification provisions as stated below. 
However, individuals may submit requests for information about whether 
this system contains a record about them by submitting a written 
request to the system manager at the above address, which includes 
their name, SSN, or other information that may be in this system of 
records that will identify them. Individuals requesting notification 
of, or access to, a record by mail must include (1) a notarized 
statement to us to verify their identity or (2) must certify in the 
request that they are the individual they claim to be and that they 
understand that the knowing and willful request for, or acquisition of, 
a record pertaining to another individual under false pretenses is a 
criminal offense.
    Individuals requesting notification of, or access to, records in 
person must provide their name, SSN, or other information that may be 
in this system of records that will identify them, as well as provide 
an identity document, preferably with a photograph, such as a driver's 
license. Individuals lacking identification documents sufficient to 
establish their identity must certify in writing that they are the 
individual they claim to be and that they understand that the knowing 
and willful request for, or acquisition of, a record pertaining to 
another individual under false pretenses is a criminal offense.
    These procedures are in accordance with our regulations at 20 CFR 
401.40 and 401.45.

CONTESTING RECORD PROCEDURES:
    Same as record access procedures. Individuals should also 
reasonably

[[Page 57523]]

identify the record, specify the information they are contesting, and 
state the corrective action sought and the reasons for the correction 
with supporting justification showing how the record is incomplete, 
untimely, inaccurate, or irrelevant. These procedures are in accordance 
with our regulations at 20 CFR 401.65(a).

NOTIFICATION PROCEDURES:
    Same as record access procedures. These procedures are in 
accordance with our regulations at 20 CFR 401.40 and 401.45.

EXEMPTIONS PROMULGATED FOR THE SYSTEM:
    This system of records has been exempted from certain provisions of 
the Privacy Act pursuant to 5 U.S.C. 552a(k)(5). Rules have been 
promulgated in accordance with the requirements of 5 U.S.C. 553(b), 
(c), and (e) and have been published in today's Federal Register.

HISTORY:
    None.

[FR Doc. 2018-24853 Filed 11-14-18; 8:45 am]
 BILLING CODE 4191-02-P



                                               57520                     Federal Register / Vol. 83, No. 221 / Thursday, November 15, 2018 / Notices

                                               provide their name, SSN, or other                       with the exception of the routine uses,               our facilities and records are suitable for
                                               information that may be in this system                  which are effective December 17, 2018.                such employment or access.
                                               of records that will identify them, as                  We invite public comment on the                         In accordance with 5 U.S.C. 552a(r),
                                               well as provide an identity document,                   routine uses or other aspects of this                 we have provided a report to OMB and
                                               preferably with a photograph, such as a                 SORN. In accordance with 5 U.S.C.                     Congress on this new system of records.
                                               driver’s license. Individuals lacking                   552a(e)(4) and (e)(11), the public is
                                                                                                                                                               Dated: June 5, 2018.
                                               identification documents sufficient to                  given a 30-day period in which to
                                                                                                                                                             Mary Ann Zimmerman,
                                               establish their identity must certify in                submit comments. Therefore, please
                                               writing that they are the individual they               submit any comments by December 17,                   Acting Executive Director, Office of Privacy
                                                                                                                                                             and Disclosure, Office of the General Counsel.
                                               claim to be and that they understand                    2018.
                                               that the knowing and willful request for,               ADDRESSES:   The public, Office of                      Editorial note: This document was
                                               or acquisition of, a record pertaining to               Management and Budget (OMB), and                      received for publication by the Office of the
                                               another individual under false pretenses                                                                      Federal Register on November 8, 2018.
                                                                                                       Congress may comment on this
                                               is a criminal offense.                                  publication by writing to the Executive               System Name and Number
                                                  These procedures are in accordance                   Director, Office of Privacy and                       Security and Suitability Files, 60–0377
                                               with our regulations at 20 CFR 401.40                   Disclosure, Office of the General
                                               and 401.45.                                             Counsel, SSA, Room G–401 West High                    SECURITY CLASSIFICATION:

                                               CONTESTING RECORD PROCEDURES:                           Rise, 6401 Security Boulevard,                          Unclassified.
                                                 Same as record access procedures.                     Baltimore, Maryland 21235–6401, or
                                                                                                       through the Federal e-Rulemaking Portal               SYSTEM LOCATION:
                                               Individuals should also reasonably
                                               identify the record, specify the                        at http://www.regulations.gov, please                   Social Security Administration,
                                               information they are contesting, and                    reference docket number SSA–2018–                     Deputy Commissioner for Human
                                               state the corrective action sought and                  0004. All comments we receive will be                 Resources, Office of Personnel, Center
                                               the reasons for the correction with                     available for public inspection at the                for Suitability and Personnel Security
                                               supporting justification showing how                    above address and we will post them to                (CSPS), 6401 Security Boulevard,
                                               the record is incomplete, untimely,                     http://www.regulations.gov.                           Baltimore, MD 21235; or the initiating
                                               inaccurate, or irrelevant. These                        FOR FURTHER INFORMATION CONTACT:                      regional office (See Appendix C for
                                               procedures are in accordance with our                   Jasson Seiden, Government Information                 address information).
                                               regulations at 20 CFR 401.65(a).                        Specialist, Privacy Implementation                      Office of Personnel Management,
                                                                                                       Division, Office of Privacy and                       National Background Investigations
                                               NOTIFICATION PROCEDURES:                                                                                      Bureau (NBIB), 1137 Branchton Road,
                                                                                                       Disclosure, Office of the General
                                                 Same as record access procedures.                     Counsel, SSA, Room G–401 West High                    PO Box 618, Boyers, PA 16018.
                                               These procedures are in accordance                      Rise, 6401 Security Boulevard,                          Defense Information Systems Agency
                                               with our regulations at 20 CFR 401.40                   Baltimore, Maryland 21235–6401,                       (DISA), DISA Defense Enterprise
                                               and 401.45.                                             telephone: (410) 597–4307, email:                     Computing Center (DECC), 3990 E Broad
                                               EXEMPTIONS PROMULGATED FOR THE SYSTEM:
                                                                                                       Jasson.Seiden@ssa.gov.                                Street, Columbus, OH 43213–1152.
                                                  None.                                                SUPPLEMENTARY INFORMATION:     Persons                SYSTEM MANAGER(S):
                                                                                                       appointed to, and under consideration
                                               HISTORY:                                                for, Federal service or contract                        Social Security Administration,
                                                  None.                                                employment are required, with limited                 Deputy Commissioner for Human
                                               [FR Doc. 2018–24908 Filed 11–14–18; 8:45 am]            exceptions, to submit to a suitability                Resources, Office of Personnel, Center
                                                                                                       background investigation. In addition,                for Suitability and Personnel Security
                                               BILLING CODE P
                                                                                                       other individuals granted access to                   (CSPS), 6401 Security Boulevard,
                                                                                                       agency facilities and records may be                  Baltimore, MD 21235; or the initiating
                                               SOCIAL SECURITY ADMINISTRATION                          required to complete such an                          regional office (See Appendix C for
                                                                                                       investigation. The Deputy                             address information).
                                               [Docket No. SSA–2018–0004]
                                                                                                       Commissioner for Human Resources,                       csps.controls.response@ssa.gov.
                                               Privacy Act of 1974; System of                          Office of Personnel, Center for
                                                                                                                                                             AUTHORITY FOR MAINTENANCE OF THE SYSTEM:
                                               Records                                                 Suitability and Personnel Security
                                                                                                       (CSPS) oversees and is responsible for                  Section 205(a) of the Social Security
                                               AGENCY:  Deputy Commissioner for                        adjudicating these investigations.                    Act, as amended, HSPD–12 (Policy for
                                               Human Resources, Social Security                        Suitability and security related                      a Common Identification Standard for
                                               Administration (SSA).                                   information that we collect during the                Federal Employees and Contractors),
                                               ACTION: Notice of a new system of                       investigations process and send to the                Executive Orders 13764 (Amending the
                                               records.                                                Office of Personnel Management (OPM)                  Civil Service Rules, Executive Order
                                                                                                       is covered by OPM/Central-9, Personnel                13488, and Executive Order 13467 To
                                               SUMMARY:   In accordance with the                       Investigations Records. The new                       Modernize the Executive Branch-Wide
                                               Privacy Act, we are issuing public                      Security and Suitability Files system of              Governance Structure and Processes for
                                               notice of our intent to establish a new                 records covers suitability and security               Security Clearances, Suitability and
                                               system of records entitled, Security and                related information that we generate                  Fitness for Employment, and
khammond on DSK30JT082PROD with NOTICES




                                               Suitability Files (60–0377). This notice                during the investigation process but that             Credentialing, and Related Matters) and
                                               publishes details of the new system as                  we do not send to OPM. We will use the                12968 (Access to Classified
                                               set forth under the caption,                            information we collect to conduct                     Information), Sections 3301 and 3302 of
                                               SUPPLEMENTARY INFORMATION.                              background investigations for the                     Title 5, U.S.C., and Parts 5, 731, 732,
                                               DATES: The system of records notice                     purpose of establishing that individuals              and 736 of Title 5 of the Code of Federal
                                               (SORN) is applicable upon its                           employed by us, working under contract                Regulations; and Fair Credit Reporting
                                               publication in today’s Federal Register,                for us, or otherwise granted access to                Act.


                                          VerDate Sep<11>2014   16:53 Nov 14, 2018   Jkt 247001   PO 00000   Frm 00122   Fmt 4703   Sfmt 4703   E:\FR\FM\15NON1.SGM   15NON1


                                                                         Federal Register / Vol. 83, No. 221 / Thursday, November 15, 2018 / Notices                                           57521

                                               PURPOSE(S) OF THE SYSTEM:                               also be obtained from, but not limited to             Federal employees, when they are
                                                 We will use the information in the                    references, credit reporting agencies,                performing work for SSA, as authorized
                                               Security and Suitability Files to                       other federal agencies, and educational               by law, and they need access to
                                               determine the suitability of individuals                institutions.                                         personally identifiable information (PII)
                                               for appointment or retention as an SSA                                                                        in SSA records in order to perform their
                                                                                                       ROUTINE USES OF RECORDS MAINTAINED IN THE
                                               employee, for access to SSA facilities                                                                        assigned agency functions.
                                                                                                       SYSTEM, INCLUDING CATEGORIES OF USERS AND
                                               and information systems, to hold                                                                                 6. To the Equal Employment
                                                                                                       THE PURPOSES OF SUCH USES:
                                               sensitive positions, and to perform work                                                                      Opportunity Commission (EEOC or
                                                                                                          We will disclose records pursuant to               Commission) when requested in
                                               or services for or on behalf of SSA as a
                                                                                                       the following routine uses; however, we               connection with investigations into
                                               contractor or volunteer. This will ensure
                                                                                                       will not disclose any information                     alleged or possible discriminatory
                                               that all of our prospective, current, and
                                                                                                       defined as ‘‘return or return                         practices in the Federal sector,
                                               former employees, students, contractors,
                                                                                                       information’’ under 26 U.S.C. 6103 of                 examination of Federal affirmative
                                               grantees, appointees, cooperative
                                                                                                       the Internal Revenue Service Code,                    employment programs, compliance by
                                               agreement awardees, volunteers, and
                                                                                                       unless authorized by statute, the                     Federal agencies with the Uniform
                                               others granted access to our facilities
                                                                                                       Internal Revenue Service (IRS), or IRS                Guidelines on Employee Selection
                                               and records are investigated
                                                                                                       regulations.                                          Procedures, or other functions vested in
                                               appropriately for security and                             1. To the Office of the President in
                                               suitability, and that the results of the                                                                      the Commission.
                                                                                                       response to an inquiry from that office                  7. To the Federal Labor Relations
                                               investigations when necessary, are                      made on behalf of, and at the request of,
                                               adjudicated based on federal law and                                                                          Authority, its General Counsel, the
                                                                                                       the subject of the record or third party              Federal Mediation and Conciliation
                                               regulations and are recorded in the                     acting on the subject’s behalf.
                                               official records.                                                                                             Service, the Federal Service Impasses
                                                                                                          2. To a congressional office in                    Panel, or an arbitrator when information
                                               CATEGORIES OF INDIVIDUALS COVERED BY THE                response to an inquiry from that office               is requested in connection with
                                               SYSTEM:                                                 made on behalf of, and at the request of,             investigations of allegations of unfair
                                                 Individuals seeking, or who have                      the subject of the record or a third party            practices, matters before an arbitrator or
                                               sought, to fill an available vacancy with               acting on the subject’s behalf.                       the Federal Service Impasses Panel.
                                               SSA, or to otherwise be granted access                     3. To the Department of Justice (DOJ),                8. To the Office of Personnel
                                               to SSA facilities and records. This                     a court or other tribunal, or another                 Management (OPM), the Merit Systems
                                               category of individuals include, but are                party before such court or tribunal,                  Protection Board, or the Office of
                                               not limited to, prospective, current, and               when:                                                 Special Counsel in connection with
                                               former employees, students, contractors,                   (a) SSA, or any component thereof; or              appeals, special studies of the civil
                                               grantees, appointees, cooperative                          (b) any SSA employee in his/her                    service and other merit systems, review
                                               agreement awardees, volunteers, and                     official capacity; or:                                of rules and regulations, investigations
                                               others who perform services for SSA.                       (c) any SSA employee in his/her                    of alleged or possible prohibited
                                                                                                       individual capacity where DOJ (or SSA                 practices, and other such functions
                                               CATEGORIES OF RECORDS IN THE SYSTEM:                    where it is authorized to do so) has                  promulgated in 5 U.S.C. Chapter 12, or
                                                 This system maintains information                     agreed to represent the employee; or                  as may be required by law.
                                               collected as part of our security and                      (d) the United States or any agency                   9. To Federal, State, and local law
                                               suitability investigative process. This                 thereof where SSA determines the                      enforcement agencies and private
                                               information may include the                             litigation is likely to affect SSA or any             security contractors, as appropriate,
                                               individual’s name, address, date of birth               of its components,                                    information necessary:
                                               (DOB), Social Security number (SSN),                       is a party to the litigation or has an                (a) To enable them to protect the
                                               phone number, driver’s license                          interest in such litigation, and SSA                  safety of SSA employees and customers,
                                               information, fingerprints, residential                  determines that the use of such records               the security of the SSA workplace, and
                                               and employment addresses,                               by DOJ, a court or other tribunal, or                 the operation of SSA facilities, or
                                               employment history (e.g., names of                      another party before the tribunal is                     (b) to assist in investigations or
                                               supervisors and colleagues), financial                  relevant and necessary to the litigation,             prosecutions with respect to activities
                                               and educational background,                             provided, however, that in each case,                 that affect such safety and security or
                                               professional experience information,                    the agency determines that disclosure of              activities that disrupt the operation of
                                               and information from personal and                       the records to DOJ, a court or other                  SSA facilities.
                                               professional references. We may also                    tribunal, or another party is a use of the               10. To the National Archives and
                                               collect information about personal and                  information contained in the records                  Records Administration (NARA) under
                                               professional conduct that could include                 that is compatible with the purpose for               44 U.S.C. 2904 and 2906.
                                               disciplinary, criminal, and credit                      which the records were collected.                        11. To a Federal agency in response
                                               histories. This system may also include                    4. To contractors and other Federal                to its request, or at SSA’s initiative, in
                                               determinations of sensitivity and risk                  agencies, as necessary, for assisting SSA             connection with decisions to hire or
                                               level for different positions and                       in the efficient administration of its                retain an employee, issue a security
                                               information to ensure compliance with                   programs. We disclose information                     clearance, conduct a security or
                                               security and suitability requirements,                  under this routine use only in situations             suitability investigation, classify a job,
                                               and information necessary to monitor                    in which SSA may enter into a                         award a contract, or regarding the
                                                                                                       contractual or similar agreement with a
khammond on DSK30JT082PROD with NOTICES




                                               and track security and suitability                                                                            requesting agency’s decision to issue a
                                               investigations for management workload                  third party to assist the accomplishing               license, grant, or other benefit, to the
                                               purposes.                                               an agency function relating to this                   extent that the information is relevant
                                                                                                       system of records.                                    and necessary to the requesting agency’s
                                               RECORD SOURCE CATEGORIES:                                  5. To student volunteers, individuals              decision.
                                                 We obtain information in this system                  working under a personal services                        12. To officials of labor organizations
                                               primarily from the individuals to whom                  contract, and other workers who                       recognized under 5 U.S.C. Chapter 71
                                               the record pertains. Information may                    technically do not have the status of                 when relevant and necessary to their


                                          VerDate Sep<11>2014   16:53 Nov 14, 2018   Jkt 247001   PO 00000   Frm 00123   Fmt 4703   Sfmt 4703   E:\FR\FM\15NON1.SGM   15NON1


                                               57522                     Federal Register / Vol. 83, No. 221 / Thursday, November 15, 2018 / Notices

                                               duties of exclusive representation                      POLICIES AND PRACTICES FOR RETRIEVAL OF               the DoD cybersecurity perimeter. Data is
                                               concerning personnel policies,                          RECORDS:                                              encrypted where it is stored, and
                                               practices, and matters affecting                          We will retrieve records in this                    network traffic is encrypted based on
                                               conditions of employment.                               system by name, SSN, and DOB.                         the type of user traffic and risk to PII
                                                  13. To appropriate agencies, entities,                                                                     data. User access to data is protected
                                                                                                       POLICIES AND PRACTICES FOR RETENTION AND
                                               and persons when:                                                                                             using Identity and Access Management
                                                                                                       DISPOSAL OF RECORDS:
                                                  (a) SSA suspects or has confirmed                                                                          with multifactor authentication that will
                                               that there has been a breach of the                       These records are temporary. We                     only allow an authenticated user to
                                               system of records;                                      retain and destroy this information in                access and manipulate the specific
                                                  (b) SSA has determined that as the                   accordance with the NARA approved                     records based on user role and
                                               result of the suspected or confirmed                    General Records Schedules (GRS) 2.0,                  permissions. The system audits access
                                               breach there is a risk of harm to                       Human Resources, and GRS 5.6,                         to information. Physical entry is
                                               individuals, SSA (including its                         Security Records. We retain                           restricted by the use of locks, guards,
                                               information systems, programs, and                      investigative records on employees or                 and administrative procedures. All
                                               operations), the Federal Government, or                 applicants for employment, whether or                 individuals granted access to the system
                                               national security; and                                  not a security clearance is granted, and              must complete Information Assurance
                                                  (c) the disclosure made to such                      other persons, such as those performing               and Privacy Act training before initially
                                               agencies, entities, and persons is                      work under contract or as volunteers in               accessing the system and annually
                                               reasonably necessary to assist in                       accordance with the approved records                  thereafter, and these users must have
                                               connection with SSA’s efforts to                        schedules. We retain investigative                    also been through the information
                                               respond to the suspected or confirmed                   reports in accordance with OPM                        technology and/or security clearance
                                               breach or to prevent, minimize, or                      Central-9 (81 FR 70191) or successor                  eligibility process.
                                               remedy such harm.                                       Records Disposition Authority. Our
                                                  14. To any source from which                         shared service provider for tracking                  RECORD ACCESS PROCEDURES:

                                               information is requested in the course of               post-investigation data, the Department                  This system of records has been
                                               an investigation, to the extent necessary               of Defense (DoD), retains post-                       exempted from the Privacy Act’s access,
                                               to identify the individual, inform the                  investigative files and the computerized              contesting, and notification provisions
                                               source of the nature and purpose of the                 data bases in accordance with the                     as stated below. However, individuals
                                               investigation, and to identify the type of              Defense Manpower Data Center (DMDC)                   may submit requests for information
                                               information requested.                                  retention policies as published in                    about whether this system contains a
                                                  15. To another Federal agency or                     DMDC 24 DoD (81 FR 39032) or                          record about them by submitting a
                                               Federal entity, when SSA determines                     successor Records Disposition                         written request to the system manager at
                                               that information from this system of                    Authority.                                            the above address, which includes their
                                               records is reasonably necessary to assist                                                                     name, SSN, or other information that
                                                                                                       ADMINISTRATIVE, TECHNICAL, AND PHYSICAL
                                               the recipient agency or entity in:                      SAFEGUARDS:
                                                                                                                                                             may be in this system of records that
                                                  (a) Responding to a suspected or                                                                           will identify them. Individuals
                                                                                                         We retain electronic and paper files                requesting notification of, or access to,
                                               confirmed breach; or                                    with personal identifiers in secure
                                                  (b) preventing, minimizing, or                                                                             a record by mail must include (1) a
                                                                                                       storage areas accessible only by our                  notarized statement to us to verify their
                                               remedying the risk of harm to                           authorized employees and contractors
                                               individuals, the recipient agency or                                                                          identity or (2) must certify in the request
                                                                                                       who have a need for the information                   that they are the individual they claim
                                               entity (including its information                       when performing their official duties.
                                               systems, programs, and operations), the                                                                       to be and that they understand that the
                                                                                                       Security measures include, but are not                knowing and willful request for, or
                                               Federal Government, or national                         limited to, the use of codes and profiles,
                                               security, resulting from a suspected or                                                                       acquisition of, a record pertaining to
                                                                                                       personal identification number and                    another individual under false pretenses
                                               confirmed breach.                                       password, and personal identification
                                                  16. To the Department of Defense or                                                                        is a criminal offense.
                                                                                                       verification cards. We keep paper                        Individuals requesting notification of,
                                               other Federal agencies in connection                    records in locked cabinets within secure
                                               with providing approved shared                                                                                or access to, records in person must
                                                                                                       areas, with access limited to only those              provide their name, SSN, or other
                                               services to subscribing agencies for                    employees who have an official need for
                                               hiring or retaining an employee;                                                                              information that may be in this system
                                                                                                       access in order to perform their duties.              of records that will identify them, as
                                               classifying a position; conducting a                      We annually provide our employees
                                               security, suitability, fitness, or                                                                            well as provide an identity document,
                                                                                                       and contractors with appropriate                      preferably with a photograph, such as a
                                               credentialing background investigation                  security awareness training that
                                               (including continuous evaluation/                                                                             driver’s license. Individuals lacking
                                                                                                       includes reminders about the need to                  identification documents sufficient to
                                               continuous vetting); issuing a security                 protect personally identifiable
                                               clearance or sensitive position                                                                               establish their identity must certify in
                                                                                                       information (PII) and the criminal                    writing that they are the individual they
                                               eligibility; making a suitability, fitness,             penalties that apply to unauthorized
                                               or credentialing decision; or recording                                                                       claim to be and that they understand
                                                                                                       access to, or disclosure of, PII (5 U.S.C.            that the knowing and willful request for,
                                               the results of any agency decision with                 552a(i)(1)). Furthermore, employees and
                                               respect to these functions.                                                                                   or acquisition of, a record pertaining to
                                                                                                       contractors with access to databases                  another individual under false pretenses
                                                                                                       maintaining PII must sign a sanctions
khammond on DSK30JT082PROD with NOTICES




                                               POLICIES AND PRACTICES FOR STORAGE OF                                                                         is a criminal offense.
                                               RECORDS:                                                document annually, acknowledging                         These procedures are in accordance
                                                 We will maintain records in this                      their accountability for inappropriately              with our regulations at 20 CFR 401.40
                                               system in paper and electronic form.                    accessing or disclosing such                          and 401.45.
                                                                                                       information.
                                               DISCLOSURE TO CONSUMER REPORTING                          The system is protected against                     CONTESTING RECORD PROCEDURES:
                                               AGENCIES:                                               compromise of PII and cyberattack by                    Same as record access procedures.
                                                  None.                                                the full suite of defenses and sensors of             Individuals should also reasonably


                                          VerDate Sep<11>2014   16:53 Nov 14, 2018   Jkt 247001   PO 00000   Frm 00124   Fmt 4703   Sfmt 4703   E:\FR\FM\15NON1.SGM   15NON1


                                                                         Federal Register / Vol. 83, No. 221 / Thursday, November 15, 2018 / Notices                                          57523

                                               identify the record, specify the                        PD, SA–5, Suite 5H03, Washington, DC                  part 515, and the Department of
                                               information they are contesting, and                    20522–0505.                                           Commerce’s Bureau of Industry and
                                               state the corrective action sought and                  SUPPLEMENTARY INFORMATION: The                        Security (BIS) published a final rule in
                                               the reasons for the correction with                     foregoing determinations were made                    the Federal Register amending, among
                                               supporting justification showing how                    pursuant to the authority vested in me                other sections, the section of the Export
                                               the record is incomplete, untimely,                     by the Act of October 19, 1965 (79 Stat.              Administration Regulations (EAR)
                                               inaccurate, or irrelevant. These                        985; 22 U.S.C. 2459), E.O. 12047 of                   regarding Cuba, 15 CFR part 746. The
                                               procedures are in accordance with our                   March 27, 1978, the Foreign Affairs                   regulatory amendment to the CACR
                                               regulations at 20 CFR 401.65(a).                        Reform and Restructuring Act of 1998                  added § 515.209, which generally
                                                                                                       (112 Stat. 2681, et seq.; 22 U.S.C. 6501              prohibits direct financial transactions
                                               NOTIFICATION PROCEDURES:                                                                                      with certain entities and subentities
                                                                                                       note, et seq.), Delegation of Authority
                                                 Same as record access procedures.                     No. 234 of October 1, 1999, and                       identified on the State Department’s
                                               These procedures are in accordance                      Delegation of Authority No. 236–3 of                  Cuba Restricted List, which the State
                                               with our regulations at 20 CFR 401.40                   August 28, 2000.                                      Department is updating as published
                                               and 401.45.                                                                                                   below, and accessible on the State
                                                                                                       Marie Therese Porter Royce,                           Department’s website. The regulatory
                                               EXEMPTIONS PROMULGATED FOR THE SYSTEM:                  Assistant Secretary for Educational and               amendment to the EAR, specifically
                                                  This system of records has been                      Cultural Affairs, Department of State.                § 746.2, notes BIS will generally deny
                                               exempted from certain provisions of the                 [FR Doc. 2018–24957 Filed 11–14–18; 8:45 am]          applications to export or reexport items
                                               Privacy Act pursuant to 5 U.S.C.                        BILLING CODE 4710–05–P                                for use by entities or subentities
                                               552a(k)(5). Rules have been                                                                                   identified on the Cuba Restricted List.
                                               promulgated in accordance with the                                                                            (http://www.state.gov/e/eb/tfs/spi/cuba/
                                               requirements of 5 U.S.C. 553(b), (c), and               DEPARTMENT OF STATE                                   cubarestrictedlist/index.htm). This
                                               (e) and have been published in today’s                  [Public Notice: 10602]                                update includes 26 newly identified
                                               Federal Register.                                                                                             subentities and five amendments to
                                                                                                       Updating the State Department’s List                  previously-listed subentities including
                                               HISTORY:
                                                                                                       of Entities and Subentities Associated                three name-changes, one new alias, and
                                                  None.                                                With Cuba (Cuba Restricted List)                      one typographical correction (the
                                               [FR Doc. 2018–24853 Filed 11–14–18; 8:45 am]                                                                  subentity ‘‘Hotel Palacio del Marqués de
                                               BILLING CODE 4191–02–P                                  ACTION:  Updated publication of list of               San Felipe y Santiago de Bejucal
                                                                                                       entities and subentities.                             (Habaguanex)’’ was incorrectly split
                                                                                                       SUMMARY:   The Department of State is                 between two lines). The State
                                               DEPARTMENT OF STATE                                     publishing an update to its List of                   Department will continue to update the
                                                                                                       Restricted Entities and Subentities                   Cuba Restricted List periodically.
                                               [Public Notice: 10604]
                                                                                                       Associated with Cuba (Cuba Restricted                    The publication of the updated Cuba
                                                                                                       List) with which direct financial                     Restricted List further implements the
                                               Notice of Determinations; Culturally                                                                          directive in paragraph 3(a)(i) of the
                                               Significant Objects Imported for                        transactions are generally prohibited
                                                                                                       under the Cuban Assets Control                        NSPM for the Secretary of State to
                                               Exhibition—Determinations: ‘‘Vija                                                                             identify the entities or subentities, as
                                               Celmins: To Fix the Image in Memory’’                   Regulations (CACR). This Cuba
                                                                                                       Restricted List is also considered during             appropriate, that are under the control
                                               Exhibition                                                                                                    of, or act for or on behalf of, the Cuban
                                                                                                       review of license applications submitted
                                               SUMMARY:    Notice is hereby given of the               to the Department of Commerce’s                       military, intelligence, or security
                                               following determinations: I hereby                      Bureau of Industry and Security (BIS)                 services or personnel, and publish a list
                                               determine that certain objects to be                    pursuant to the Export Administration                 of those identified entities and
                                               included in the exhibition ‘‘Vija                       Regulations (EAR).                                    subentities with which direct financial
                                               Celmins: To Fix the Image in Memory,’’                                                                        transactions would disproportionately
                                                                                                       DATES: The updates to the Cuba
                                               imported from abroad for temporary                                                                            benefit such services or personnel at the
                                                                                                       Restricted List are effective on                      expense of the Cuban people or private
                                               exhibition within the United States, are                November 15, 2018.
                                               of cultural significance. The objects are                                                                     enterprise in Cuba.
                                                                                                       FOR FURTHER INFORMATION CONTACT:
                                               imported pursuant to loan agreements                    Benjamin Barron, Office of Economic                   Electronic Availability
                                               with the foreign owners or custodians.                  Sanctions Policy and Implementation,                    This document and additional
                                               I also determine that the exhibition or                 tel.: 202–647–7489; Office of the                     information concerning the Cuba
                                               display of the exhibit objects at the San               Coordinator for Cuban Affairs, tel.: 202–             Restricted List are available from the
                                               Francisco Museum of Modern Art, San                     453–8456, Department of State,                        Department of State’s website (http://
                                               Francisco, California, from on or about                 Washington, DC 20520.                                 www.state.gov/e/eb/tfs/spi/cuba/).
                                               December 15, 2018, until on or about                    SUPPLEMENTARY INFORMATION:
                                               March 31, 2019; and at possible                                                                               List of Restricted Entities and
                                               additional exhibitions or venues yet to                 Background                                            Subentities Associated With Cuba as of
                                               be determined, is in the national                         On June 16, 2017, the President                     November 15, 2018
                                               interest. I have ordered that Public                    signed the National Security                             Below is the U.S. Department of
                                               Notice of these determinations be                       Presidential Memorandum on                            State’s list of entities and subentities
khammond on DSK30JT082PROD with NOTICES




                                               published in the Federal Register.                      Strengthening the Policy of the United                under the control of, or acting for or on
                                               FOR FURTHER INFORMATION CONTACT: Julie                  States Toward Cuba (NSPM). As                         behalf of, the Cuban military,
                                               Simpson, Attorney-Adviser, Office of                    directed by the NSPM, on November 9,                  intelligence, or security services or
                                               the Legal Adviser, U.S. Department of                   2017, the Department of the Treasury’s                personnel with which direct financial
                                               State (telephone: 202–632–6471; email:                  Office of Foreign Assets Control (OFAC)               transactions would disproportionately
                                               section2459@state.gov). The mailing                     published a final rule in the Federal                 benefit such services or personnel at the
                                               address is U.S. Department of State, L/                 Register amending the CACR, 31 CFR                    expense of the Cuban people or private


                                          VerDate Sep<11>2014   16:53 Nov 14, 2018   Jkt 247001   PO 00000   Frm 00125   Fmt 4703   Sfmt 4703   E:\FR\FM\15NON1.SGM   15NON1



Document Created: 2018-11-15 04:00:08
Document Modified: 2018-11-15 04:00:08
CategoryRegulatory Information
CollectionFederal Register
sudoc ClassAE 2.7:
GS 4.107:
AE 2.106:
PublisherOffice of the Federal Register, National Archives and Records Administration
SectionNotices
ActionNotice of a new system of records.
DatesThe system of records notice (SORN) is applicable upon its publication in today's Federal Register, with the exception of the routine uses, which are effective December 17, 2018. We invite public comment on the routine uses or other aspects of this SORN. In accordance with 5 U.S.C. 552a(e)(4) and (e)(11), the public is given a 30-day period in which to submit comments. Therefore, please submit any comments by December 17, 2018.
ContactJasson Seiden, Government Information Specialist, Privacy Implementation Division, Office of Privacy and Disclosure, Office of the General Counsel, SSA, Room G-401 West High Rise, 6401 Security Boulevard, Baltimore, Maryland 21235-6401, telephone: (410) 597-4307, email: [email protected]
FR Citation83 FR 57520 

2024 Federal Register | Disclaimer | Privacy Policy
USC | CFR | eCFR