SYSTEM NAME:
Counterintelligence Management Information System (CIMIS). (September 30, 2015, 80 FR 58720)
SYSTEM LOCATION:
Pentagon Force Protection Agency (PFPA), 9000 Defense Pentagon, Washington, DC 20301-9000.
CATEGORIES OF INDIVIDUALS COVERED BY THE SYSTEM:
Any individual involved, or suspected of being involved, in intelligence collection on behalf of a foreign government or foreign terror organization which may harm PFPA employees, U.S. property or interests. Individuals involved in or suspected of being involved in National Security Crimes of assassination, sedition, subversion, treason, espionage, sabotage or terrorism. Individuals who provide information that is relevant to the case, such as victims or witnesses, and individuals who report such crimes or acts.
CATEGORIES OF RECORDS IN THE SYSTEM:
Data on suspect: Name; other names used (former and aliases); other identification (ID) numbers (e.g., DoD ID number, passport, VISA, resident alien); driver's license (state, number, and expiration date); date and place of birth; citizenship; legal status; gender; race/ethnicity; description (height, weight, hair color, etc.); name of current employer and address; college/university (major and/or degree); military records; home/office address; home/work/cell phone numbers; personal/work email address; personal property information (e.g., vehicle, photographic equipment (make/model/serial number)); marital status; spouse location (city and state); and CIMIS incident number.
Data on individuals (victims, witnesses, complainant):
Name; DoD ID number; work/home/cell phone numbers; and employer information (e.g. organization, address).
Additional data:
Law Enforcement Reports; National Crime Information Center (NCIC); Intelligence Information Reports (IIR).
Individuals may voluntarily offer additional personal information in an effort to establish their identity. While not specifically requested, the information will be retained in the record if it is deemed beneficial to the inquiry.
AUTHORITY FOR MAINTENANCE OF THE SYSTEM:
10 U.S.C. 2674, Operation and control of Pentagon Reservation and defense facilities in National Capital Region; 18 U.S.C. 794, Gathering or Delivering Defense Information to Aid Foreign Government; E.O. 12333, United States Intelligence Activities; E.O. 12968, Access to Classified Information; DoD Directive (DoDD) 5105.68, Pentagon Force Protection Agency (PFPA); DoDD 5200.27, Acquisition of Information Concerning Persons and Organizations not Affiliated with the Department of Defense; DoDD 5240.01, DoD Intelligence Activities, as amended; DoDD 5240.02, Counterintelligence; DoDD 5240.06, DoD Counterintelligence Awareness and Reporting (CIAR); DoD Instruction (DoDI) O-5240.21, Counterintelligence Inquiries; and Administrative Instruction 30, Force Protection on the Pentagon Reservation.
PURPOSE(S):
To conduct and exercise overall responsibility within PFPA for all matters pertaining to acts involving counterintelligence (CI) activities against PFPA employees, U.S. property, or interests. Also used as a management tool for statistical analysis, tracking, reporting, evaluating program effectiveness, and conducting research.
ROUTINE USES OF RECORDS MAINTAINED IN THE SYSTEM, INCLUDING CATEGORIES OF USERS AND THE PURPOSES OF SUCH USES:
In addition to those disclosures generally permitted under 5 U.S.C. 552a(b) of the Privacy Act of 1974, as amended, the records contained herein may specifically be disclosed outside the DoD as a routine use pursuant to 5 U.S.C. 552a(b)(3) as follows:
To Federal counterintelligence and law enforcement agencies that administer programs or employ individuals involved in an incident or inquiry.
Law Enforcement Routine Use:
If a system of records maintained by a DoD Component to carry out its functions indicates a violation or potential violation of law, whether civil, criminal, or regulatory in nature, and whether arising by general statute or by regulation, rule, or order issued pursuant thereto, the relevant records in the system of records may be referred, as a routine use, to the agency concerned, whether federal, state, local, or foreign, charged with the responsibility of investigating or prosecuting such violation or charged with enforcing or implementing thestatute, rule, regulation, or order issued pursuant thereto.
Congressional Inquiries Disclosure Routine Use:
Disclosure from a system of records maintained by a DoD Component may be made to a congressional office from the record of an individual in response to an inquiry from the congressional office made at the request of that individual.
Disclosure to the Department of Justice for Litigation Routine Use:
A record from a system of records maintained by a DoD Component may be disclosed as a routine use to any component of the Department of Justice for the purpose of representing the Department of Defense, or any officer, employee or member of the Department in pending or potential litigation to which the record is pertinent.
Disclosure of Information to the National Archives and Records Administration Routine Use:
A record from a system of records maintained by a DoD Component may be disclosed as a routine use to the National Archives and Records Administration for the purpose of records management inspections conducted under authority of 44 U.S.C. 2904 and 2906.
Data Breach Remediation Purposes Routine Use:
A record from a system of records maintained by a Component may be disclosed to appropriate agencies, entities, and persons when (1) The Component suspects or has confirmed that the security or confidentiality of the information in the system of records has been compromised; (2) the Component has determined that as a result of the suspected or confirmed compromise there is a risk of harm to economic or property interests, identity theft or fraud, or harm to the security or integrity of this system or other systems or programs (whether maintained by the Component or another agency or entity) that rely upon the compromised information; and (3) the disclosure made to such agencies, entities, and persons is reasonably necessary to assist in connection with the Components efforts to respond to the suspected or confirmed compromise and prevent, minimize, or remedy such harm.
The DoD Blanket Routine Uses set forth at the beginning of the Office of the Secretary of Defense (OSD) compilation of systems of records notices may apply to this system. The complete list of DoD Blanket Routine Uses can be found online at: http://dpcld.defense.gov/Privacy/SORNsIndex/BlanketRoutineUses.aspx
POLICIES AND PRACTICES FOR STORING, RETRIEVING, ACCESSING, RETAINING, AND DISPOSING OF RECORDS IN THE SYSTEM:
STORAGE:
Electronic storage media.
RETRIEVABILITY:
Name, date of birth, and other identification (DoD ID number, passport, VISA or driver's license number).
SAFEGUARDS:
Electronically stored records are maintained in “fail-safe” system software with password-protected access. Access to these records is role-based and is limited to those individuals requiring access in performance of their official duties. Entry to the area is restricted by the use of cipher and combination locks, security guards, identification badges and closed circuit TV (CCTV). Data in transit and at rest is encrypted and computer servers are scanned to assess system vulnerabilities. Encryption of backups containing sensitive PII is in place. Firewalls are in place to control the incoming and outgoing data traffic based on an applied rule set. DoD Public Key Infrastructure Certificates are used to authenticate authorized users. Periodic security audits are maintained to document access to data. Regular monitoring of user's security practice is conducted and methods are used to ensure only authorized personnel have access to PII. All individuals granted access to this system of records receives annual Information Assurance and Privacy Act training.
RETENTION AND DISPOSAL:
Files relating to Foreign Nationals:
Close annually upon determination that the individual is no longer a threat to DoD, the Pentagon, Pentagon Reservation or DoD Facilities within the Capitol Region (NCR). Destroy 25 year(s) after cut off.
Files relating to U.S. Citizens:
Cut off after determination person(s) are no longer a CI threat to DoD, the Pentagon, Pentagon Reservation or DoD Facilities within the NCR. Destroy/delete 90 days after cut off.
SYSTEM MANAGER(S) AND ADDRESS:
Pentagon Force Protection Agency (PFPA), 9000 Defense Pentagon, Washington, DC 20301-9000.
NOTIFICATION PROCEDURE:
An exemption rule has been published, and this Privacy Act system of records is exempt from the notification provisions described in 5 U.S.C. 552a(e)(4)(H).
RECORD ACCESS PROCEDURES:
An exemption rule has been published, and this Privacy Act system of records is exempt from the access provisions described in 5 U.S.C. 552a(d).
CONTESTING RECORD PROCEDURES:
An exemption rule has been published, and this Privacy Act system of records is exempt from the amendment and appeal provisions described in 5 U.S.C. 552a(f).
RECORD SOURCE CATEGORIES:
PFPA officers and investigators, state and local law enforcement, Federal departments and agencies, and intelligence agencies.
EXEMPTIONS CLAIMED FOR THE SYSTEM:
This system of records is used by the Department of Defense for a law enforcement purpose (k)(2), and the records contained herein are used for criminal, civil, and administrative enforcement requirements. As such, allowing individuals full exercise of the Privacy Act would compromise the existence of any criminal, civil, or administrative enforcement activity. This system of records is exempt from the following provisions of 5 U.S.C. 552a section (c)(3), (d), (e)(1), (e)(4)(G) through (I), and (f) of the Act.
An exemption rule for this system has been promulgated in accordance with requirements of 5 U.S.C. 553(b)(1), (2), and (3), (c), and (e) and published in 32 CFR part 311. For additional information contact the system manager.
FEDERAL REGISTER HISTORY: