• Embed Doc
  • Readcast
  • Collections
  • 1
    CommentGo Back
Download
 
1
 
 I 
 NFORMATION 
 
 S 
 ECURITY 
 
 AND
 
 P 
 RIVACY 
 A
 DVISORY 
 
 B
OARD
 _____________________________ 
 Established by the Computer Security Act of 1987 [Amended by the Federal Information Security Management Act of 2002]
Toward A 21st Century Framework for Federal Government Privacy Policy
May 2009
 
2
 I 
 NFORMATION 
 
 S 
 ECURITY 
 
 AND
 
 P 
 RIVACY 
 A
 DVISORY 
 
 B
OARD
 _____________________________ 
 Established by the Computer Security Act of 1987 [Amended by the Federal Information Security Management Act of 2002]
May27,2009TheHonorablePeterOrszagDirectorTheOfficeofManagementandBudget72517thStreet,NWWashington,DC20503DearMr.Orszag:IamwritingtoyouonbehalfoftheInformationSecurityandPrivacyAdvisoryBoard(ISPAB).TheISPABwasoriginallycreatedbytheComputerSecurityActof1987(P.L.100‐35)astheComputerSystemSecurityandPrivacyAdvisoryBoard,andamendedbyTheE‐GovernmentActof2002,TitleIII,TheFederalInformationSecurityManagementAct(FISMA)(P.L.107‐347).OneofthestatutoryobjectivesoftheBoardistoidentifyemergingmanagerial,technical,administrative,andphysicalsafeguardissuesrelativetoinformationsecurityandprivacy.AttachedtothisletterisaBoardreportthatanalyzesissuesandmakesrecommendationsaroundupdatingprivacylawandpolicyinlightoftechnologicalchange.ThePrivacyActof1974isthebasisformuchofthelegalandpolicyframeworkbywhichtheU.S.Governmenthandlespersonalinformation.Atthesametime,vastchangesintechnologysince1974havetransformedhowFederalagenciescollect,use,anddistributeinformationinmajorways.WhilethefundamentalsoftheAct—theprinciplesoffairinformationpractices—remainrelevantandcurrent,theletteroftheActandrelatedlawandpolicymaynotreflecttherealitiesofcurrenttechnologiesandinformationsystemsanddonotprotectagainstmanyimportantthreatstoprivacy.Moreover,newtechnologies,notcoveredbytheAct,aregeneratingnewquestionsandconcerns;andgovernmentuseofprivate‐sectordatabasesnowallowsthecollectionanduseofdetailedpersonalinformationwithlittleprivacyprotections.Theattachedreportexaminestheseissues,andisbasedonarecordthathasbeendevelopedthroughtheBoard’havingheardfromnumerouspanelsofexpertsforseveralyears.TheBoardprovidesanalysisandmakesrecommendationsfortheAdministrationandCongresstoconsider.
of 00

Leave a Comment

You must be to leave a comment.
Submit
Characters: ...

Very informative report. I would like to make it available on a new LinkedIn Group " Data Security & Compliance Network", where members can keep up to date on state, federal and international regulations on data privacy security and compliance, as well as get questions answered and learn best practices from others. This is an open group, so all are welcome to join. http://www.linkedin.com/groups?gid=19...

You must be to leave a comment.
Submit
Characters: ...