Thursday, April 25, 2013

D
epartment of Homeland Security
DHS Directives System
Instruction Number:
110
-
01
-
001
Revision Number:
00
Issue Date:
6/8/2012
PRIVACY POLICY FOR
OPERATIONAL USE OF SOCIAL
MEDIA
I.
Purpose
Th
is
Instruction
implement
s
Department of Ho
meland Security (DHS) Directi
ve
110
-
01,
Privacy Policy for
Operational Use of Social Media
.
II.
Scope
This Instruction applies throughout DHS regarding the
access
to and collection, use,
maintenance
,
retention
, disclosure, deletion, and destruction of Personally Identifiable
Information
(PII) in relation to operational use of social media, with the exception
of
operational use of social media for
:
(a)
communications and
outreach
with the public
authorized by the Office of Public Affairs
;
(b) situational awareness
by the
National
Operatio
ns Center
;
(
c)
situational awareness
by
C
omponents
other than the
National
Operations Center, upon approval by the Chief Privacy Officer following completion of a
Social Media Operational Use Template
;
and (
d
)
the conduct of authorized intelligence
activit
ies carried out by the Office of Intelligence and Analysis, the intelligence and
counterintelligence elements of the United States Coast Guard, or any other
Component
performing authorized foreign intelligence or counterintelligence functions,
in accordance with the provisions of Executive Order 12333
, as amended
.
This
Instruction does not apply to the Office of the Inspector General; however, the OIG will
comply with the spirit of the Instruction.
III.
References
A.
Public Law 107
-
347, “E
-
Government Act of 200
2,
”
as amended
, Section
208 [44 U.S.C.
§
3501 note]
B.
Title 5, United States Code (U.S.C.), Section 552a, “Records maintained
on individuals” [The Privacy Act of 1974, as amended]
C.
Title 6, U.S.C., Section 142,
“
Privacy
o
fficer
”
D.
Title 44, U.S.C., Chapter 3
5, Subchapter III, “
I
nformation Security” [The
Federal Information Security Management Act of 2002, as amended
(FISMA)
]
-
1
Instruction #
110
-
01
-
001
Revision
#
00
­
E.
Title 6
,
C.F.R., Chapter 1, Part 5, “
Disclosure o
f
records and information”
F.
Directive 047
-
01, “Privacy Policy and Compliance”
G.
DHS Sen
sitive Systems Policy Directive 4300A
H.
Privacy
-
related memoranda issued by the Office of Management and
Budget
,
including:
1.
OMB Memorandum 10
-
22
, “Guidance for Online Use of Web
Measurement and Customization Technologies” (June 25, 2010)
2.
OMB Memorandum 10
-
23
, “Guidance for Agency Use of Third
-
Party Websites and Applications”
(June 25, 2010)
3.
OMB
Memorandum 07
-
16, “Safeguarding Against and Responding
to the Breach of Personally Identifiable Information" (May 22, 2007
)
4.
OMB
Memorandum 06
-
20, “FY 2006 Reporting Instructions
for
the
Federal Information Security Management Act and Agency Privacy
Management” (July 17, 2006)
5.
OMB
Memorandum 06
-
19, “Reporting Incidents Involving
Personally Identifiable Information and Incorporating the Cost for
S
ecurity
in Agency Information Technology Investments” (July 12, 2006)
6.
OMB
Memorandum 06
-
15, “Safeguarding Personally Identifiable
Information” (May 22, 2006)
7.
OMB
Circular No. A
-
130, “
Transmittal Memorandum #4,
Management of Federal Information Resources” (November 28, 2000
)
I.
Privacy policy guidance and requirements issued (as updated) by the
Chief Privacy Officer
and published on the Privacy Office website
, including:
1.
Privacy Policy Guidance Memorandum 2008
-
02,
DHS Policy
Regarding Privacy Impact Assessments
(December 30,
2008)
2.
Privacy Policy Guidance Memorandum 2008
-
01,
The Fair
Information Practice Principles: Framework for Privacy Policy at the
Department of Homeland Security
(December 29, 2008)
3.
Handbook for Safeguarding Sensitive Personally Identifiable
Information at
DHS (
March
20
12)
-
2
Instruction #
110
-
01
-
001
Revision
#
00
­
IV.
Definitions
A.
Counsel means the Office of the General Counsel attorney, from either the
Immediate Office of the General Counsel or component counsel, assigned to
provide legal advice to the component covered by this Instruction.
B.
Fair Inf
ormation Practice Principles
means the policy framework
adopted by the Department in
Directive
047
-
01
, Privacy Policy and Compliance,
regarding the
collection, use, maintenance
, disclosure
, deletion
, or destruction
of
Personally Identifiable Information.
C.
Individual
means a natural person, including a United States citizen,
Legal Permanent Resident, visitor to the United States,
alien,
DHS employee, or
DHS contractor.
D.
Operational Use
means
authorized use of social media to
collect
personally identifiable
i
nformation
for the purpose of enhancing situational
awareness, investigating an individual
in a criminal, civil, or administrative
context, making a benefit
determination about a person,
making
a personnel
d
etermination about a
Department employee
,
making
a suitability determination
about a prospective Department employee, or for any other
official Department
purpose that has the potential to affect the rights, privileges, or benefits of
an
individual
.
Operational use does not include the use of search eng
ines for
general Internet research, nor does it include the use of social media for
professional development such as training and continuing education
or for
facilitating
internal meetings
.
E.
Personally Identifiable Information (PII
)
means
any
i
nformation
that
permits the identity of an individual to be directly or indirectly inferred,
including
other information
that is
linked or linkable to
an
individual
.
For example, when linked or linkable to an individual, such information
includes a
name,
S
ocial
S
ecurity number, date and place of birth, mother’s maiden name,
Alien Registration
Number
,
account number, license number, vehicle identifier
number,
license plate
number
,
device identifier or serial number
, internet protocol
address,
biometric
identifier
(
e.g.,
facial recognition
photograph, fingerprint, iris
scan, voice print)
,
education
al information
, financial
information
, medical
information
, criminal or employment
information
,
information created specifically
to identify or authenticate an individual (
e.g.,
a random generated number)
.
F.
Privacy
Compliance Documentation
means any document required by
statute or by the Chief Privacy Officer that supports compliance with DHS privacy
policy, procedures, or requirements, including but not limited to the Social Media
Operational Use Template (Template)
, Privacy Impact Assessments
(PIAs)
,
System of Records Notices
(SORNs)
,
Notices of Proposed Rulemaking for
-
3
Instruction #
110
-
01
-
001
Revision
#
00
­
---
-
_JU
,
IL
Mary
Ellen
Callahan
Date
Chief
Privacy
O icer
2.
Components
complete
implementation
of
this
Instruction,
including
obtaining
approval
from
the
Chief
Privacy
O icer
of
Templates
for
categories
of
operational
use
of
social
media
in
existence
prior
to
this
Instruction,
within
120
days,
except
that
Compo
nents
complete
training
of
all
pe%inent
employees
within
165
days.
VII.
Questions
Address
any
questions
or
concerns
regarding
these
Instructions
to
the
DHS
Privacy
O ice
or
to
the
relevant
Component
Privacy
O icer
or
PPOC.
-
10
-
Instruction
#
110-01-001
Revision
#
00
<iframe width="400" height="225" src="http://www.democracynow.org/embed/headline/2013/4/25/late_boston_marathon_suspect_was_on_terrorism_watch_list" frameborder="0"></iframe>

Late Boston Marathon Suspect Was on Terrorism Watch List

More details have emerged on how U.S. intelligence agencies handled warnings about one of the Boston Marathon bombing suspects well before the attacks. The National Counterterrorism Center added Tamerlan Tsarnaev to the government’s main terrorism watch list more than a year ago at the CIA’s request. The move came after the Russian government relayed concerns about Tsarnaev to the CIA, as it had also done with the FBI. The FBI had interviewed him but had found no evidence of wrongdoing. On Wednesday, White House Press Secretary Jay Carney defended the FBI’s claim it did everything it could with the information it had at the time.
White House Press Secretary Jay Carney: "You know, all of these — all of these issues are obviously under investigation. What we do know is that the FBI took action in response to that notification, investigated the elder brother, and investigated thoroughly, and came to the conclusion that there was no derogatory information, no indication of terrorist activity or associations, either foreign or domestic, at that time."
News that Tamerlan Tsarnaev was on the intelligence radar is spurring calls for federal agencies to re-examine their priorities, particularly a focus on sting operations that critics say constitute entrapment. In an editorial, The Washington Post writes: "The FBI has devoted considerable resources to sting operations against people it judges to be terror suspects, sometimes on what look like dubious grounds. ... [I]t’s not clear that a sometimes far-fetched plot would have gone forward without the encouragement and help of FBI informants."

Justice Department “Reclassifies Documents,” Fights to Withhold Ground-breaking Immigration Court Decision on El Salvadorian Vides Casanova

April 15, 2013
written decision imageThe Department of Justice (DOJ) continues to earn its second annual Rosemary Award for Worst Open Government Performance with its abysmal performance regarding a ground breaking decision in an immigration case of Carlos Eugenio Vides Casanova, former defense minister of El Salvador who is implicated in dozens of cases of torture and extrajudicial execution.  To withhold this information from the public the DOJ made up FOIA procedures and erroneously withheld previously declassified information in its misguided attempt to preserve secrecy surrounding the case.
The New York Times filed a FOIA request, numerous appeals, and eventually filed suit against the DOJ, for copies of Judge Grim’s final decision regarding the U.S. Immigration Court case against Vides Casanova. Last week, the New York Times partially won the FOIA case by getting a copy of Judge Grim’s February 2012 decision  released, but with redactions. Among the redactions were all of the witnesses’ names, even though it was a public hearing and their names are available thanks to extensive news coverage.  Additionally, the expert witness report, which includes hundreds of pages of declassified U.S. documents obtained by the National Security Archive and used as evidence in the court is being held from the public as “confidential.” These documents remain confidential despite the fact that they were released through the FOIA and through President Clinton’s executive orders for declassification in response to the El Salvador Truth Commission request.
sample doc picture
Example of “reclassified” document – Reports meeting of Ambassador White and leaders of El Salvador Armed Forces during which officers attempt to deny military involvement in and subsequent cover-up of American churchwomen killings. See full document here.
Here is the chronology of the New York Times battle to get the written decision of a public trial released:
  • September 2012 – NYT submits a FOIA for the full release of both decisions written by Judge Grim in February and August of 2012.
  • October 2012 – DOJ denies request claiming that the decisions were “preliminary,” and the agency had not issued a final agency decision. The DOJ also cited personal privacy concerns. [This is absurd. The hearing was public, and the general outline of the decision was made public in February of 2012, while the details were withheld.]
  • November 2012 – NYT files an administrative appeal, arguing that it knew “nothing about the FOIA exemption determination that would turn on the absence or existence of a final decision,” arguing that the denial was improper.
  • January 2013 – DOJ denies the appeal, simply citing the B6 exemption, making no reference to whether the decisions were preliminary or not.
  • February 2013 – NYT submitted a letter to the DOJ stating that the denial of access is contrary to the First Amendment and common law rights of access.
  • April 2, 2013 – NYT files suit against the DOJ in the District Court of New York after receiving no response to February letter.
  • April 4, 2013 – DOJ responds to February letter without mention of lawsuit, treating the February letter as “request for reconsideration” (which does not exist as a procedure of the FOIA) and releases a redacted version of Judge Grim’s February 2012 decision.
The DOJ is the agency in charge of enforcing the FOIA. How can the DOJ appropriately enforce the FOIA if it does not follow the FOIA itself?  This is also especially worrisome considering the rosy report on the state of FOIA presented by Melanie Pustay, director of the Office of Information Policy at DOJ.
Why this all the more important…
Carolyn Patty Blum, a human rights attorney of the Center for Justice and Accountability explains that “this [Vides Casanova] may be the highest military commander of any country” who has been subject to a new law stating that a commander can be ordered removed from the United States, if he has “ordered, assisted or participated in torture or extrajudicial killing. Key to the ruling is that it is sufficient to know or have reason to know about the acts of subordinates and then fail to prevent or punish those acts.” The New York Times reports that this is the first time that a high-ranking foreign military commander will be deported under the new human rights violations law which was passed in 2004.
This is also the first time to have a ruling about very specific cases of torture, extrajudicial killings and/or disappearance. Judge Grim’s finding that General Vides Casanova “assisted or otherwise participated” in the killing of four churchwomen is probably the best known case in the US.
The implications that this case has on the human rights world are huge, and important precedents have been set – all the more important that the DOJ moves to release the report in its entirely, along with expert witness reports and accompanying documentation, rather than going out of its way to act contrary to DOJ’s very own Attorney General Eric Holder’s memo calling agencies to act with a “presumption of openness.”