National Reconnaissance Office

QNRO-31

PRINT  |  E-MAIL

SYSTEM NAME:

Software Security Risk Evaluations  (July 11, 2012,  77 FR 40863)

SYSTEM LOCATION:

National Reconnaissance Office (NRO), 14675 Lee Road, Chantilly, VA 20151-1715.

 

CATEGORIES OF INDIVIDUALS COVERED BY THE SYSTEM:

Software developers that support products that NRO is considering purchasing or leasing.

CATEGORIES OF RECORDS IN THE SYSTEM:

Individual's name; company name; registered business telephone number and address (which for small businesses may also be an individual's residential telephone number and address); additional information relevant to conducting a software risk evaluation, such as the company an individual works for or other software products the individual has developed.

AUTHORITY FOR MAINTENANCE OF THE SYSTEM:

National Security Act of 1947, as amended; 5 U.S.C. 301, Departmental Regulations; E.O. 12333, as amended; DoD 5200.1-M, Acquisition Systems Protection Program; DoD 5240.1-R, Procedures Governing the Activities of DoD Intelligence Components That Affect United States Persons; DoDD 5200.27, Acquisition of Information Concerning Persons and Organizations not Affiliated with the Department of Defense; DoDD 5240.2, DoD Counterintelligence (CI); DoDI 5240.8, Security Classification Guide for Information Concerning the DoD Counterintelligence Program.

PURPOSE(S):

The Software Security Risk Evaluations (SSRE) system is used to evaluate potential security risks or counterintelligence threats associated with purchasing or using software products.

ROUTINE USES OF RECORDS MAINTAINED IN THE SYSTEM, INCLUDING CATEGORIES OF USERS AND THE PURPOSES OF SUCH USES:

In addition to the disclosures generally permitted under 5 U.S.C. 552a(b) of the Privacy Act of 1974, these records may specifically be disclosed outside the DoD as a routine use pursuant to 5 U.S.C. 552a(b)(3) as follows:

The DoD Blanket Routines Uses published at the beginning of the NRO compilation of systems of records notices apply to this system.

POLICIES AND PRACTICES FOR STORING, RETRIEVING, ACCESSING, RETAINING, AND DISPOSING OF RECORDS IN THE SYSTEM:


STORAGE:

Records are maintained in paper files and on electronic storage media.

RETRIEVABILITY:

Records are retrieved by the individual's name.

SAFEGUARDS:

Records are maintained in a controlled facility. Physical entry is restricted by use of locks, guards, badges, and is accessible only to authorized personnel. Access to records is limited to persons responsible for servicing the record in performance of official duties and who are properly screened and cleared for need-to-know. Access to computerized data is restricted by passwords, which are changed periodically.

RETENTION AND DISPOSAL:

Records are destroyed when superseded, obsolete, or no longer needed. Records are destroyed by erasing or shredding.

SYSTEM MANAGER(S) AND ADDRESS:

National Reconnaissance Office, ATTN: Chief, Counter Intelligence Operations, Office of Security and Counter Intelligence, 14675 Lee Road, Chantilly, VA 20151-1715.

NOTIFICATION PROCEDURE:

Individuals seeking to determine whether information about themselves is contained in this system of records should address written inquiries to the National Reconnaissance Office, Information Access and Release Center, 14675 Lee Road, Chantilly, VA 20151-1715.

Request should contain full name, current address, telephone number, date and place of birth, and other such personal information necessary to locate the record sought. While the Social Security Number (SSN) is not required, providing it will expedite the authentication of the requestor's identity and clearance level.

In addition, the requester must provide a notarized statement or an unsworn declaration in accordance with 28 U.S.C. 1746, in the following format:

If executed outside the United States: I declare (or certify, verify, or state) under penalty of perjury under the laws of the United States of America that the foregoing is true and correct. Executed on (date). (Signature).

If executed within the United States, its territories, possessions, or commonwealths: I declare (or certify, verify, or state) under penalty of perjury that the foregoing is true and correct. Executed on (date). (Signature).

RECORD ACCESS PROCEDURES:

Individuals seeking access to information about themselves contained in this system should address written inquiries to the National Reconnaissance Office, Information Access and Release Center, 14675 Lee Road, Chantilly, VA 20151-1715.

Request should include full name, current address, telephone number, date and place of birth, and other such personal information necessary to locate the record sought. While the Social Security Number (SSN) is not required, providing it will expedite the authentication of the requestor's identity and clearance level.

In addition, the requester must provide a notarized statement or an unsworn declaration in accordance with 28 U.S.C. 1746, in the following format:

If executed outside the United States: I declare (or certify, verify, or state) under penalty of perjury under the laws of the United States of America that the foregoing is true and correct. Executed on (date). (Signature).

If executed within the United States, its territories, possessions, or commonwealths: I declare (or certify, verify, or state) under penalty of perjury that the foregoing is true and correct. Executed on (date). (Signature).

CONTESTING RECORD PROCEDURES:

The NRO rules for accessing records, for contesting contents and appealing initial agency determinations are published in 32 CFR part 326 or may be obtained from the Privacy Act Coordinator, National Reconnaissance Office, 14675 Lee Road, Chantilly, VA 20151-1715.

RECORD SOURCE CATEGORIES:

From available research tools.

EXEMPTIONS CLAIMED FOR THE SYSTEM:

An exemption rule for this system has been promulgated in accordance with requirements of 5 U.S.C. 553(b)(1), (2), and (3), and published in 32 CFR part 326. For additional information contact the system manager.

FEDERAL REGISTER HISTORY:

July 11, 2012, 77 FR 40863