Office of the Secretary, DoD/Joint Staff

DCIO 01

PRINT  |  E-MAIL

SYSTEM NAME:

Defense Industrial Base (DIB) Cybersecurity (CS) Activities Records  (May 21, 2015,  80 FR 29315)

SYSTEM LOCATION:

Defense Industrial Base (DIB) Cybersecurity Program, 6000 Defense Pentagon, ATTN: DIB CS Program, Washington, DC 20301-6000.
DoD Cyber Crime Center, 911 Elkridge Landing Road, Linthicum, MD 21090-2991.

CATEGORIES OF INDIVIDUALS COVERED BY THE SYSTEM:

Supporting DoD contractor (hereafter referred to as 'DIB company') personnel (points of contact and individuals submitting incident reports) providing DIB company information

CATEGORIES OF RECORDS IN THE SYSTEM:

DIB company point of contact information includes name, company name and mailing address, work division/group, work email, and work telephone number.

AUTHORITY FOR MAINTENANCE OF THE SYSTEM:

10 U.S.C. 2224, Defense Information Assurance Program; 44 U.S.C. 3544, Federal Agency Responsibilities; Public Law 113-58, National Defense Authorization Act for Fiscal Year 2015, Section 1632, Reporting on Cyber Incidents with Respect to Networks and Information Systems of Operationally Critical Contractors (10 U.S.C. Chapter 19, Cyber Matters); Presidential Policy Directive PPD-21, Critical Infrastructure, Security and Resilience; DoD Directive (DoDD) 3020.40, DoD Policy and Responsibilities for Critical Infrastructure; DoDD 5505.13E, DoD Executive Agent (EA) for the DoD Cyber Crime Center (DC3); DoD Manual 3020.45, Defense Critical Infrastructure Program (DCIP): DoD Mission-Based Critical Asset Identification Process (CAIP); and DoD Instruction 5205.13, Defense Industrial Base (DIB) Cyber Security/Information Assurance (CS/IA) Activities.

PURPOSE(S):

To facilitate the sharing of DIB cybersecurity threat information and best practices to DIB companies to enhance and supplement DIB participant capabilities to safeguard DoD information that resides on, or transits, DIB unclassified information systems. When incident reports are received, DoD Cyber Crime Center (DC3) personnel analyze the information reported for cyber threats and vulnerabilities in order to develop response measures as well as improve U.S. Government and DIB understanding of advanced cyber threat activity. DoD may work with a DIB company on a more detailed, digital forensics analysis or damage assessment, which may include sharing of additional electronic media/files or information regarding the incident or the affected systems, networks, or information.

ROUTINE USES OF RECORDS MAINTAINED IN THE SYSTEM, INCLUDING CATEGORIES OF USERS AND THE PURPOSES OF SUCH USES:

In addition to the disclosures generally permitted under 5 U.S.C. 552a(b) of the Privacy Act of 1974, as amended, the records contained herein may specifically be disclosed outside the DoD as a routine use pursuant to 5 U.S.C. 552a(b)(3) as follows:
DIB company point of contact information may be provided to other participating DIB companies to facilitate the sharing of information and expertise related to the DIB CS Program including cyber threat information and best practices, and mitigation strategies.
Law Enforcement Routine Use: If a system of records maintained by a DoD Component to carry out its functions indicates a violation or potential violation of law, whether civil, criminal, or regulatory in nature, and whether arising by general statute or by regulation, rule, or order issued pursuant thereto, the relevant records in the system of records may be referred, as a routine use, to the agency concerned, whether federal, state, local, or foreign, charged with the responsibility of investigating or prosecuting such violation or charged with enforcing or implementing the statute, rule, regulation, or order issued pursuant thereto.
Counterintelligence Purpose Routine Use: A record from a system of records maintained by a DoD Component may be disclosed as a routine use outside the DoD or the U.S. Government for the purpose of counterintelligence activities authorized by U.S. Law or Executive Order or for the purpose of enforcing laws which protect the national security of the United States.
Disclosure of Information to the National Archives and Records Administration Routine Use: A record from a system of records maintained by a DoD Component may be disclosed as a routine use to the National Archives and Records Administration for the purpose of records management inspections conducted under authority of 44 U.S.C. 2904 and 2906.
The DoD Blanket Routine Uses set forth at the beginning of the Office of the Secretary of Defense/Joint Staff compilation of systems of records notices may apply to this system. The complete list of the DoD blanket routine uses can be found online at: http://dpcld.defense.gove/Privacy/SORNsIndex/BlanketRoutineUses.aspx
Any release of information contained in this system of records outside the DoD will be compatible with the purpose(s) for which the information is collected and maintained.

POLICIES AND PRACTICES FOR STORING, RETRIEVING, ACCESSING, RETAINING, AND DISPOSING OF RECORDS IN THE SYSTEM:


STORAGE:

Electronic storage media.

RETRIEVABILITY:

DIB Company POC information is retrieved primarily by company name and work division/group and secondarily by individual POC name.
DIB cyber incident reports are primarily retrieved by incident number but may also be retrieved by company name. They are not retrieved by the individual name.

SAFEGUARDS:

Records are accessed by personnel with security clearances who are properly screened, trained, under a signed confidentiality agreement, and determined to have `need to know'. Access to records requires DoD Common Access Card (CAC) and PIN. Physical access controls include security guards, identification badges, key cards, cipher locks, and combination locks.

RETENTION AND DISPOSAL:

Disposition pending (treat records as permanent until the National Archives and Records Administration has approved the retention and disposition schedule).

SYSTEM MANAGER(S) AND ADDRESS:

Director, DIB Cybersecurity, 6000 Defense Pentagon, ATTN: DIB CS Program, Washington, DC 20301-6000.

NOTIFICATION PROCEDURE:

Individuals seeking to determine whether this system of records contains information on themselves should address written inquiries to Director, DIB Cybersecurity Office, 6000 Defense Pentagon, ATTN: DIB CS Program, Washington, DC 20301-6000.
Signed, written requests should contain the individual's name, and company name and work division/group.

RECORD ACCESS PROCEDURES:

Individuals seeking access to information about themselves contained in this system of records should address a written request to the Office of the Secretary of Defense/Joint Staff (OSD/JS), Freedom of Information Act (FOIA) Requester Service Center, 1155 Defense Pentagon, Washington, DC 20301-1155.
Signed, written requests should contain the individual's name, company name and work division/group, and the name and number of this system of records notice.

CONTESTING RECORD PROCEDURES:

The OSD rules for accessing records, for contesting contents, and appealing initial agency determinations are published in OSD Administrative Instruction 81; 32 CFR part 311; or may be obtained from the system manager.

RECORD SOURCE CATEGORIES:

The individual and participating DIB companies.

EXEMPTIONS CLAIMED FOR THE SYSTEM:

None.

FEDERAL REGISTER HISTORY:

May 18, 2012, 77 FR 29616