DEPARTMENT OF TRANSPORTATION
Office of the Secretary of Transportation (OST)
PRIVACY IMPACT ASSESSMENT
June 30, 2009
The Tiger Collector Reporting Tool (TCRT) adapt the existing RITA Research Notification System "R2NS" GOTS software developed for the Research and Innovative Technology Administration (RITA) to perform the "data consolidation and reporting" tasks set forth in a web-enabled application situated on the Department of Transportation (DOT) intranet.
The TCRT application contains and publicly posts the following information to include: business email information, address, and telephone number.
The TCRT adopts a "user interface" for Departmental staff that is similar to that of the R2NS and permits "user account administration" by the Operating Administrations implementing the American Recovery and Reinvestment Act (ARRA) of 2009 (FAA, FRA, FHWA, FTA, MARAD, and Office of the Secretary). User roles are provided to control access to various system functions. There are four (3) roles in the TCRT. They are System Administrator, TEAM User, and Mode Admin. The System Administrators is the highest level of access then the Mode Administrator, then the TEAM User. The job description of personnel defines the role they are assigned.
The TCRT tool adapted the existing “R2N” GOTS software developed for the Research and Innovative Technology Administration (RITA) to perform the "data consolidation and reporting" tasks set forth below in a web-enabled application situated on the DOT intranet. The information processed by the TCRT is unclassified.
The TCRT is comprised of three primary servers, a Compaq DL-380 Server running Microsoft Windows Server 2003 with SP1, a Compaq DL-360 with Microsoft Windows Server 2003 and a DELL Power Edge R300 with Microsoft Windows Server 2008. Table 3 depicts the hardware/software characteristic of the system. Two of the servers functions as a WEB Server which is utilizing an application front end developed with Macromedia Cold Fusion. The other server hosts a Microsoft SQL 2000 database engine populated with the TCRT data. The system access is limited to login accounts within the DOT Intranet and the TCRT has a trust relationship with the OST Resource Domain.
The TCRT relies on native security controls of Microsoft Windows 2003 Server and MS SQL2000 as well as IIS 6.0. All Operating System and Application patch histories are current. The servers also have Semantic End Point (SEP) Virus and Spam protection installed and updates occur regularly once the update files are verified.
The requestor’s form data is written to the protected DOT TCRT database. Only a limited number or system administrators can access this database, where the requests can be more effectively processed and, if approved, automate many of the continuing management functions.
The TCRT data reporting functions conform to the most recent OMB Guidance and Data Architecture specifications for the ARRA (most recent versions attached) and available templates.
The TCRT provide a data structure with the following tables:
Management and control of the Tiger Collector Reporting Tool is conducted via the Electronic Capital Planning and Investment Control (eCPIC) System. eCPIC is a web-based, government-owned technology system (GOTS) application designed to help agencies with the management and control of their initiatives, portfolios, and investment priorities, as well as in the preparation and submission of budget data to the Office of Management and Budget (OMB). DOT currently hosts the eCPIC Domain. eCPIC is maintained in the Worklenz data base. The system is used by fourteen Federal agencies to help them determine the most efficient allocation of information technology spending to meet agency missions. Federal agencies that use the system consider it best practice for government portfolio management. Decisions on operations, maintenance, functionality, and enhancements are implemented through the eCPIC Service Level Agreement (SLA). Through the eCPIC Change Management Committee (CMC), agency SLA members participate in monthly meetings to share lessons learned, review the status of the project, and prioritize change requests associated with the operation, maintenance, and enhancement of the application.
TCRT displays the DOT approved system warning banner to alert users of notice and consent to monitoring prior to login.
TCRT employs the data accuracy checks inherit in Oracle database software to ensure data validity and accuracy. The system has been reviewed to ensure, to the greatest extent possible, it is accurate, relevant, timely and complete via security testing and evaluation.
Validation checks are built into the application software that both prompt the user that an incorrect entry has been entered and must be corrected, and that a user has successfully input data.
TCRT takes appropriate security measures to safeguard PII and other sensitive data. TCRT applies DOT security standards, including but not limited to routine scans and monitoring, back-up activities, and background security checks of OST employees and contractors.
|
ROLE |
ACCESS |
SAFEGUARDS |
|---|---|---|
|
System Administrators |
Access and change own profile information | Can only be granted by ADMIN level users |
|
TEAM User |
|
Specialized privilege, granted on an as needed basis |
|
Mode Administrator |
|
Specialized privilege, granted on an as needed basis |
TCRT retains PII information for a minimum of one year.
TCRT contains information that will be part of existing System of Records subject to the Privacy Act, because it is searched by an individual’s email address. In some cases, such as DOT/OST 101, the Department of Transportation controls the data and maintains System of Records responsibilities. In other cases, other government entities providing TCRT source data control the data and retain Privacy Act responsibilities.
OST has certified and accredited the security of TCRT in accordance with DOT information technology security standard requirements.