Federation - Privacy Analysis and Privacy Impact Assessment, v1.0

Agencies engaging in federated activities must undergo a thorough privacy analysis and impact assessment publishing the results.

Assessment Steps (4)

1
SAOP Privacy Analysis (SAOPPrivacyAnalysis)
Has the agency performed a privacy analysis that sufficiently covers their functional role for federated activities?
Artifact
A1
Provide evidence (e.g. organizational policies, compliance/assessment reports, sample data, etc.) that support whether the privacy assessment was performed.
2
SORN Coverage (SORNCoverage)
Has the agency published a System of Records Notice (SORN) or identified an existing SORN that covers federated activity?
Artifact
A1
Provide a copy or link to the SORN that covers the federated activity of this agency and/or system.
3
SAOP Analysis (SAOPAnalysis)
Has the agency performed an analysis to determine whether the E-Government Act applies to any of the agency's federated activity?
Artifact
A1
Provide evidence (e.g. organizational policies, compliance/assessment reports, sample data, etc.) that support whether the e-government act assessment was performed.
4
Privacy Impact Assessment (PrivacyImpactAssessment)
Has the agency published a Privacy Impact Assessment (PIA) or specified an existing PIA that covers their federated activity?
Artifact
A1
Provide a copy or link to the PIA that covers the federated activity of this agency and/or system.

Conformance Criteria (4)

C1
The agency SHALL consult with their Senior Agency Official for Privacy (SAOP) to conduct an analysis determining whether the requirements of the Privacy Act are triggered by the agency that is acting as an IdP, by the agency that is acting as an RP, or both
Citation
NIST SP 800-63C
Section 5.2 (1)
C2
The agency SHALL publish or identify coverage by a System of Records Notice (SORN) as applicable.
Citation
NIST SP 800-63C
Section 5.2 (2)
C3
The agency SHALL consult with their SAOP to conduct an analysis determining whether the requirements of the E-Government Act are triggered by the agency that is acting as an IdP, the agency that is acting as an RP, or both.
Citation
NIST SP 800-63C
Section 5.2 (3)
C4
The agency SHALL publish or identify coverage by a Privacy Impact Assessment (PIA) as applicable.
Citation
NIST SP 800-63C
Section 5.2 (4)