New
collection (Request for a new OMB Control Number)
No
Regular
02/03/2022
Requested
Previously Approved
36 Months From Approved
622
0
622
0
20,588
0
As a result of proposed rule, RIN
2105-AE26: Streamline and Update the Department of Transportation
Acquisition Regulation posted to the Federal Register, 86FR69452,
on December 7, 2021, TAR Case 2020-001, this is a request from the
Department of Transportation (DOT) for OMB approval of a new
Information Collection (IC). Under Public Law 113-283, Federal
Information Security Modernization Act of 2014, each agency of the
Federal Government must provide security for the information and
information systems that support the operations and assets of the
agency, including those provided or managed by another agency,
contractor, or other source. In order for DOT to comply with Public
Law 113-283, Federal Information Security Modernization Act of
2014, DOT developed clause 1252.239-75, DOT Protection of
Information About Individuals, PII, and Privacy Risk Management
Requirements, and contains the following information collection
requirements from the public: • Notification / reporting
non-compliance with DOT data protection standards with respect to
Personally Identifiable Information (PII) • Notification of new or
unanticipated threats or hazards, or if existing safeguards have
ceased to function • Execution and submittal of confidentiality
agreements (protection of PII) • Notification and secure return of
PII to Government when any part of PII, in any form, the Contractor
obtains from or behalf of DOT ceases to be required by Contractor
or upon termination of contract, within ten (10) business days; or,
at DOT’s written request to destroy, un-install and /or remove all
copies of such PII and provide certification that PII has been
returned, or remove or destroyed; and subcontractor certification
of return of all records within 30 days of subcontractor’s
completion of services • Breach reporting; and subcontractor breach
reporting • Notification of subcontractor access to PII
PL:
Pub.L. 113 - 283 1 Name of Law: Federal Information Security
Modernization Act of 2014
On behalf of this Federal agency, I certify that
the collection of information encompassed by this request complies
with 5 CFR 1320.9 and the related provisions of 5 CFR
1320.8(b)(3).
The following is a summary of the topics, regarding
the proposed collection of information, that the certification
covers:
(i) Why the information is being collected;
(ii) Use of information;
(iii) Burden estimate;
(iv) Nature of response (voluntary, required for a
benefit, or mandatory);
(v) Nature and extent of confidentiality; and
(vi) Need to display currently valid OMB control
number;
If you are unable to certify compliance with any of
these provisions, identify the item by leaving the box unchecked
and explain the reason in the Supporting Statement.