EXECUTIVE SUMMARY REPORT
INTRODUCTION TO THE PIA
The Department of Labor (DOL) is responsible for ensuring proper
protections of the information contained within its information systems,
including PII. To that end, the Department developed a Privacy Impact
Methodology to assess whether a system that contains PII meets legal privacy
requirements. This methodology, based on the evaluation of applicable law and
executive branch guidance as well as internal policy, was the foundation for
determining question sets and remediation guidance for developing the PIA
Questionnaire that was applied to the Mine Accident Injury and Employment
System.
Purpose
A PIA is used to evaluate privacy vulnerabilities and risks, and their
implications on information systems. It provides a number of benefits that
include enhancing policy decision making and system design, anticipating the
public's possible privacy concerns, and generating confidence that privacy
objectives are addressed in the development and implementation of single-agency
or integrated information systems. The IT PIA Questionnaire provides a
framework by which the Mine Safety and Health Administration (MSHA) can ensure
that they have complied with all relevant privacy policies, regulations, and
guidance, both internal and external to DOL.
Objective
- Detect what PII exists on MAIES;
- Determining who has access to the PII and for what purposes;
- Ensuring compliance with federal privacy laws concerning PII;
- Enabling management to make informed decisions regarding
implementation of security controls and countermeasures related to privacy
vulnerabilities;
- Promoting a repeatable approach to measuring the effectiveness of
privacy protections; and
- Preventing unintended mishandling, abuse, or fraudulent use of PII
creating noncompliance that could impede the overall mission of DOL.
Scope
This PIA assessment was conducted on the components that make up the
MAIES system, the data collected and the data disseminated.
PIA Summary and Results
The MAIES Systems of Records Notice (PARN) was updated in the Federal
Register in April of 2002.
The MAIES is scheduled to be incorporated in the Mine Safety and Health
Administration (MSHA) Standardized Information System (MSIS) by FY 2007. The
MSIS remediation will include the MAIES PII shortcomings.
|