Laserfiche WebLink
LL <br />A. General Requirements <br />For information disclosed and systems used to disclose information under this agreement, <br />SSA and the Reporter will comply with applicable requirements of the Privacy Act of <br />1974, 5 U.S.C. $ 552a; the Federal Information Security Management Act (FISMA), <br />44 U.S.C. Chapter 35, Subchapter II, as amended by the Federal Information Security <br />Modernization Act of 2014 (Pub. L. No. l13-283); related Office of Management and <br />Budget (OMB) circulars and memoranda, such as Circular A-130, "Managing <br />Information as a Strategic Resource" (July 28, 2016), and Memorandum M-17-12, <br />"Preparing for and Responding to a Breach of Personally Identifiable Information" <br />(January 3,2017); National Institute of Standards and Technology (NIST) directives; the <br />Federal Acquisition Regulations; and other Federal laws, regulations, and directives that <br />include requirements for safeguarding Federal information systems and personally <br />identifiable information (PID. SSA and the Reporter recognize and will implement any <br />applicable laws, regulations, NIST standards, and OMB directives including those <br />published subsequent to the effective date of this agreement. <br />FISMA requirements apply to all Federal contractors, organizations, or entities that <br />possess or use Federal information, or that operate, use, or have access to Federal <br />information systems on behalf of an agency. Both parties are responsible for oversight <br />and compliance of their contractors and agents. <br />B. PII Loss Reporting and Breach Notification <br />If SSA experiences a suspected or actual loss of PII received from the Reporter under the <br />terms of this agreement, SSA will follow the loss reporting guidelines and breach <br />notification procedures issued by OMB and notify the Reporter of the incident. <br />If an employee, contractor, or agent of the Reporter becomes aware of suspected or actual <br />loss of PII received from SSA under the terms of this agreement (i.e., information about <br />suspended individuals), he or she must immediately contact the Reporter's Systems <br />Security Contact identified below or his/her delegate. The Reporter must then notiff the <br />SSA Regional Prisoner Coordinator and SSA Systems Security Contact identified below. <br />If, for any reason, the Reporter is unable to notify the SSA Regional Prisoner Coordinator <br />or the SSA Systems Security Contact within I hour, the Reporter must report the incident <br />by contacting SSA's National Network Service Center at l-877-697-4889- The Reporter <br />will use the worksheet, attached as Attachment B, to quickly gather and organize <br />information about the incident. In the future, SSA may update this worksheet to ensure <br />continued compliance with OMB requirements. If SSA provides the Reporter with an <br />updated worksheet, the Reporter will use the updated worksheet. The Reporter must <br />provide to SSA information gathered about the incident and timely updates as any <br />additional information about the loss of PII as it becomes available. <br />If the party that experienced the breach determines that the risk of harm requires <br />notification to affected individuals or other remedies, that agency will carry out these <br />remedies without cost to the other party.