Download:
pdf |
pdfSave
Privacy Impact Assessment Form
v 1.45
Status Draft
Form Number
F-60235
Form Date
Question
Answer
1
OPDIV:
CDC
2
PIA Unique Identifier:
P-6300963-833315
2a Name:
12/5/2014 6:33:27 AM
Surgeon General's Report Smoking Collaboration Tool (SGR Too
General Support System (GSS)
Major Application
3
Minor Application (stand-alone)
The subject of this PIA is which of the following?
Minor Application (child)
Electronic Information Collection
Unknown
3a
Identify the Enterprise Performance Lifecycle Phase
of the system.
Implementation
Yes
3b Is this a FISMA-Reportable system?
4
Does the system include a Website or online
application available to and for the use of the general
public?
5
Identify the operator.
6
Point of Contact (POC):
7
Is this a new or existing system?
8
Does the system have Security Authorization (SA)?
8b Planned Date of Security Authorization
No
Yes
No
Agency
Contractor
POC Title
ISSO
POC Name
Cindy Allen
POC Organization NCCDPHP
POC Email
clallen@cdc.gov
POC Phone
770-488-5388
New
Existing
Yes
No
January 5, 2015
Not Applicable
Page 1 of 3
Save
11 Describe the purpose of the system.
This system will support the activities of producing the
Surgeon General's Report on Smoking. It will be used to collect,
record updates and track the progress of the SGR through its
many editorial and clearance phases.
Describe the type of information the system will
collect, maintain (store), or share. (Subsequent
12
questions will identify if this information is PII and ask
about the specific data elements.)
The information collected, maintained, and shared will be the
draft content, comments and reviews, supporting
documentation (i.e., study references, tables and figures) and
project management documents (i.e., timelines, style guides)
necessary to track the progress of the report.
Provide an overview of the system and describe the
13 information it will collect, maintain (store), or share,
either permanently or temporarily.
This collaborative website has access through the public
internet, but is closed/secure, allowing access only to
individuals who have been approved or invited. All the
information collected, stored, or shared will be documents and
files dedicated to supporting the production of the SGR. The
only PII collected will be BUSINESS CONTACT information
limited to Name and work Email address.
There is no personal or public information being stored.
14 Does the system collect, maintain, use or share PII?
Yes
No
REVIEWER QUESTIONS: The following section contains Reviewer Questions which are not to be filled out unless the user is an OPDIV
Senior Officer for Privacy.
Reviewer Questions
1
Are the questions on the PIA answered correctly, accurately, and completely?
Answer
Yes
No
Reviewer
Notes
2
Does the PIA appropriately communicate the purpose of PII in the system and is the purpose
justified by appropriate legal authorities?
Yes
Do system owners demonstrate appropriate understanding of the impact of the PII in the
system and provide sufficient oversight to employees and contractors?
Yes
No
Reviewer
Notes
3
No
Reviewer
Notes
4
Does the PIA appropriately describe the PII quality and integrity of the data?
Yes
No
Reviewer
Notes
5
Is this a candidate for PII minimization?
Yes
No
Reviewer
Notes
6
Does the PIA accurately identify data retention procedures and records retention schedules?
Yes
No
Page 2 of 3
Save
Reviewer Questions
Answer
Reviewer
Notes
7
Are the individuals whose PII is in the system provided appropriate participation?
Yes
No
Reviewer
Notes
8
Does the PIA raise any concerns about the security of the PII?
Yes
No
Reviewer
Notes
9
Is applicability of the Privacy Act captured correctly and is a SORN published or does it need
to be?
Yes
No
Reviewer
Notes
10
Is the PII appropriately limited for use internally and with third parties?
Yes
No
Reviewer
Notes
11
Does the PIA demonstrate compliance with all Web privacy requirements?
Yes
No
Reviewer
Notes
12
Were any changes made to the system because of the completion of this PIA?
Yes
No
Reviewer
Notes
General Comments
OPDIV Senior Official
for Privacy Signature
Beverly E.
Walker -S
Digitally signed by Beverly E. Walker -S
DN: c=US, o=U.S. Government,
ou=HHS, ou=CDC, ou=People,
0.9.2342.19200300.100.1.1=100144034
3, cn=Beverly E. Walker -S
Date: 2014.12.08 15:09:44 -05'00'
HHS Senior
Agency Official
for Privacy
Page 3 of 3
File Type | application/pdf |
File Modified | 2014-12-08 |
File Created | 2014-02-07 |