Вы находитесь на странице: 1из 2

3410

Proposed Rules Federal Register


Vol. 73, No. 13

Friday, January 18, 2008

This section of the FEDERAL REGISTER use of SSNs in certain functions, Social Security Numbers in employee
contains notices to the public of the proposed inconsistencies in approaches and records and human resources
issuance of rules and regulations. The standards for protecting the SSN creates information systems.
purpose of these notices is to give interested a risk that can lead to misuse. The OPM also proposes to add paragraphs
persons an opportunity to participate in the Office of Personnel Management (OPM)
rule making prior to the adoption of the final (a)(8) through (10) to § 293.107, which
rules.
has been working with the President’s requires special safeguards for
Identity Theft Task Force and the automated records. The additional
agencies on a number of identity theft paragraphs will ensure that agencies
OFFICE OF PERSONNEL protection initiatives, and was tasked know what they must do to improve
MANAGEMENT with issuing formal guidance to the their data security measures. These
agencies on the appropriate ways to safeguards pertain specifically to
5 CFR Part 293 restrict the use, and conceal the SSNs in improving the protection of employee
RIN 3260–AL24
employee records and human resources Social Security Numbers.
information systems. OPM issued
formal guidance to the Federal Chief E.O. 12866, Regulatory Review
Personnel Records
Human Capital Officers on June 18, This rule has been reviewed by the
AGENCY: Office of Personnel 2007, to help agencies achieve a Office of Management and Budget in
Management. consistent and effective policy for accordance with E.O. 12866.
ACTION: Proposed rule with request for safeguarding the Social Security
comments. Numbers of Federal employees. A copy Regulatory Flexibility Act
of the guidance package can be obtained I certify that these regulations would
SUMMARY: The Office of Personnel
by going to http://www.chcoc.gov. These not have a significant economic impact
Management is issuing proposed
proposed regulations are intended to on a substantial number of small entities
regulations to achieve a consistent and
update OPM’s regulations governing because they would apply only to
effective policy for the use of Social
personnel records so they are consistent Federal agencies and employees.
Security Numbers by Federal agencies
with that guidance. These proposed
to combat fraud and identity theft. List of Subjects in 5 CFR Part 293
regulations impose significant
Federal agencies must reduce the threat
restrictions on the use of SSNs, leading Government employees, Privacy,
of identity theft by eliminating the
to enhanced protection of sensitive Records.
unnecessary use and collection of Social
personal information. Applying the
Security Numbers. This proposed Office of Personnel Management.
guidance and regulations is a first step
regulation imposes significant Linda M. Springer,
in protecting the personal identity of
restrictions on the use of Social Security Director.
Federal employees.
Numbers throughout the Federal Accordingly, OPM proposes to amend
Efforts are underway to develop
Government and is consistent with the 5 CFR part 293 as follows:
requirements for a new Government-
recommendations made by the
wide employee identifier which will
President’s Identity Theft Task Force. PART 293—PERSONNEL RECORDS
replace the Social Security Number as
DATES: Comments must be received on the primary employee identifier. Once
or before March 18, 2008. 1. The authority citation for part 293
this new employee identifier is is revised to read as follows:
ADDRESSES: Send or deliver written established, Federal agencies will have
comments to the Deputy Associate a viable alternative to the use of SSNs Authority: 5 U.S.C. 552, 552a, 1103, 1104,
Director for Workforce Information and 1302, 2951(2), 3301, and 4315; E.O. 12107
in their business activities. The use of
System Requirements, Strategic Human (December 28, 1978), 3 CFR 1954–1958
this new employee identifier as a Comp.; 5 CFR 7.2; E.O. 9830; 3 CFR 1943–
Resources Policy Division, Office of substitute for the SSN would diminish 1948 Comp.
Personnel Management, Room 7439, the risk of identity theft by eliminating
1900 E Street, NW., Washington, DC the unnecessary use of the SSN as an Subpart A—Basic Policies on
20415–8200; by fax at (202) 606–4891. employee identifier in many situations. Maintenance of Personnel Records
FOR FURTHER INFORMATION CONTACT: OPM is proposing the following
Leroy McKnight, by telephone at (202) specific changes, which we believe will 2. In § 293.102 the definitions of
606–4054; by fax at (202) 606–1719; or assist Federal agencies in their efforts to Exposure and Primary Key are added in
by e-mail at Leroy.Mcknight@opm.gov. combat fraud and identity theft: alphabetical order as follows:
SUPPLEMENTARY INFORMATION: In an In § 293.102 we are proposing to add § 293.102 Definitions.
effort to better protect sensitive personal definitions of Exposure, and Primary
information, particularly Social Security Key, which are new terms used in the * * * * *
Numbers (SSNs), Federal agencies must proposed regulations. Exposure means the unprotected
take immediate action to restrict the In § 293.105, which addresses display, storage, and transmission of
rfrederick on PROD1PC67 with PROPOSALS

unnecessary use of this important restrictions on collection and use of personally identifiable information (PII),
personal identifier. Continued exposure information, we propose to add e.g., Social Security Numbers;
of individuals’ SSNs increases their paragraphs (b)(3) through (13). These * * * * *
vulnerability to identity theft and other new paragraphs provide agencies with Primary Key means a particular item
harmful situations. While some Federal specific information on the appropriate chosen to uniquely identify a specific
agencies have taken steps to reduce the and inappropriate use of employee individual or to associate information

VerDate Aug<31>2005 15:11 Jan 17, 2008 Jkt 214001 PO 00000 Frm 00001 Fmt 4702 Sfmt 4702 E:\FR\FM\18JAP1.SGM 18JAP1
Federal Register / Vol. 73, No. 13 / Friday, January 18, 2008 / Proposed Rules 3411

with a specific individual in an agreements are in compliance with are enforced in both test and production
automated environment; Federal privacy protection policies, environments.
* * * * * including policies governing protection * * * * *
3. In § 293.105, paragraphs (b)(3) of personally identifiable information, [FR Doc. E8–858 Filed 1–17–08; 8:45 am]
through (13) are added to read as e.g., Social Security Numbers. BILLING CODE 6325–39–P
follows: (10) Agencies must require
supervisory approval before authorized
§ 293.105 Restrictions on collection and
individuals may access, transport, or DEPARTMENT OF AGRICULTURE
use of information.
transmit information containing a Social
* * * * * Security Number outside of the
(b) * * * Federal Crop Insurance Corporation
agencies’ facilities. Electronic records
(3) If Social Security Numbers are
containing Social Security Numbers 7 CFR Part 457
collected, they will be collected only at
must be transported or transmitted in an
the time of the employee’s appointment RIN 0563–AC14
encrypted or protected format as
to be entered into the human resources
prescribed in all established guidance Common Crop Insurance Regulations;
and payroll systems. The collection tool
regarding the protection of sensitive Dry Pea Crop Provisions
(if paper-based) will be stored in a
agency information. Paper-based records
protected location to guard against AGENCY: Federal Crop Insurance
containing Social Security Numbers
exposure until it is no longer required. Corporation, USDA.
must be transported in wheeled
The Guide to Personnel Recordkeeping
containers, portfolios, briefcases, or ACTION: Proposed rule.
will be used to determine retention
similar devices that can be locked when
requirements for certain paper-based SUMMARY: The Federal Crop Insurance
not in use. In addition, these containers
collection tools. Disposal of all paper- Corporation (FCIC) proposes to amend
must be identifiable by tag or decal with
based collection tools (i.e., forms, the Common Crop Insurance
contact and mailing address
letters, and other correspondence) will Regulations; Dry Pea Crop Insurance
information.
be in accordance with the General Provisions to include the insurability of
Record Schedule issued by the National (11) Agencies must ensure access to
Social Security Numbers, including additional types of dry peas, to offer
Archives and Records Administration. winter coverage, to allow replanting
(4) Agencies may not use the Social access involving data entry, printing,
and screen displays, occurs in a payments, and to make chickpeas
Security Number as an employee’s insurable under the Dry Pea Crop
primary key, i.e., unique identifier, in protected location to guard against
exposure. Provisions rather than the Dry Bean
internal or external data processing Crop Provisions. The intended effect of
activities. (12) Agencies must ensure all security
this action is to provide policy changes,
(5) Agencies must ensure that Social incidents involving personally
to clarify existing policy provisions to
Security Numbers are not printed, e.g., identifiable information, especially
better meet the needs of the producers,
on forms, or reports, or displayed on Social Security Numbers, are reported
and to reduce vulnerability to program
computer display screens. in accordance with all established
(6) Access to Social Security Numbers fraud, waste, and abuse. The changes
guidance regarding the reporting of
must be restricted to those individuals will apply for the 2009 and succeeding
incidents involving personally
whose official duties require such crop years.
identifiable information. In addition,
access. A listing of all individuals with agencies must inform all employees of DATES: Written comments and opinions
access authorization based on legitimate all established incident reporting on this proposed rule will be accepted
business needs must be maintained and requirements annually. until close of business March 18, 2008
reviewed for continued applicability. and will be considered when the rule is
(13) Agencies must ensure all
(7) Agencies must ensure, through to be made final.
authorized disclosures of information
appropriate annual training and containing Social Security Numbers and ADDRESSES: Interested persons are
educational programs, including other personally identifiable data are invited to submit written comments,
training on Privacy Act and Freedom of made in accordance with established titled ‘‘Dry Pea Crop Provisions’’, by any
Information Act requirements, that regulations and procedures. of the following methods:
those individuals who are authorized to • By Mail to: Director, Product
4. In § 293.107, paragraphs (a)(8) Administration and Standards Division,
access Social Security Numbers
through (10) are added to read as Risk Management Agency, United States
understand their responsibility to
follows: Department of Agriculture, Beacon
protect sensitive and personal
information. This responsibility § 293.107 Special safeguards for Facility, Stop 0812, Room 421, PO Box
includes securing this information when automated records. 419205, Kansas City, MO 64141–6205.
working from home or another remote • By Express Mail to: Director,
(a) * * *
location. Product Administration and Standards
(8) Agencies must use privacy and (8) Minimize the risk of unauthorized Division, Risk Management Agency,
confidentiality statements that describe disclosure of Social Security Numbers United States Department of
accountability clearly and warn of during data entry activities by Agriculture, Beacon Facility, Stop 0812,
possible disciplinary action for concealing the Social Security Number 9240 Troost Avenue, Kansas City, MO
unauthorized release of the Social on the screens. 64131–3055.
(9) Assure adequate internal control • E-mail: DirectorPDD@rma.usda.gov.
rfrederick on PROD1PC67 with PROPOSALS

Security Number and other personally


identifiable information. These procedures to properly monitor • Federal eRulemaking Portal: http://
statements must be signed by all authorized and unauthorized access to www.regulations.gov. Follow the
individuals who have access to Social Social Security Numbers and other instructions for submitting comments.
Security Numbers. personally identifiable data. A copy of each response will be
(9) Agencies must ensure their (10) Assure all Social Security available for public inspection and
telework policies and written Number safeguards and protection rules copying from 7 a.m. to 4:30 p.m., CST,

VerDate Aug<31>2005 15:11 Jan 17, 2008 Jkt 214001 PO 00000 Frm 00002 Fmt 4702 Sfmt 4702 E:\FR\FM\18JAP1.SGM 18JAP1

Вам также может понравиться