Skip the navigation
News

DHS must assess privacy risk before using data mining tool, GAO says

The tool would be used to cull data for the fight on terrorism

By Jaikumar Vijayan
March 22, 2007 12:00 PM ET

Computerworld - A tool being developed by the U.S. Department of Homeland Security (DHS) to help it sift through large volumes of data in the search for terrorist threats poses several privacy concerns, the Government Accountability Office (GAO) warned in a report released yesterday. The agency also called on the DHS to conduct a privacy impact assessment of the tool immediately to help ameliorate those risks.

The tool, called ADVISE, for Analysis, Dissemination, Visualization, Insight and Semantic Enhancement, is designed to cull very large databases and search for patterns, such as relationships between individuals and organizations, to ferret out suspicious people or activity. ADVISE is currently under development by the DHS.

In its report, the GAO raised questions about whether ADVISE could erroneously associate individuals with terrorism because of faulty data, misidentify people with similar names and rely on data collected for other purposes.

The DHS has added some security controls over ADVISE, such as data access restrictions and strong authentication processes. But these are not enough to address broader privacy concerns, the GAO said.

"A privacy impact assessment would identify specific privacy risks and help officials determine what controls are needed to mitigate those risks," the agency noted. Doing so now, while the tool is still being developed, would make it easier to implement effective controls, the report said.

In a response to the GAO report, the DHS said that ADVISE is little more than a "generic set of IT tools" that do not actually gather or use any personal data. Rather, they are simply designed to sift through and analyze information from several existing databases from multiple sources. As a result, ADVISE does not need a formal privacy impact assessment of the sort called for by the GAO, the agency said.

But the GAO noted that the tool's intended uses include applications involving personal data, which would bring it under the purview of the E-Government Act. That law emphasizes the need for privacy impact assessments.

"We agree that it is a tool that is intended to help analysts make decisions," Linda Koontz, director of information management issues at the GAO and author of the report, said in e-mailed comments to Computerworld. "Nonetheless, ADVISE has significant privacy implications.

"Our point is that these privacy implications need to be thoroughly analyzed early in the development process," she said. "ADVISE is clearly intended to analyze personal information and, therefore, we think this assessment is required now so that technical controls can be built into the application."

Christopher Pierson, a partner with Lewis and Roca LLP, a Phoenix-based law-firm, agreed with the GAO's recommendations.

"The ADVISE tool, as I understand it, is just being run over already existing databases from multiple owners," Pierson said. It does not store or create records of individuals. But when a suspicious person is identified, that information will be collected and disseminated to others. Such dissemination is covered by the E-Government Act and will require a privacy impact assessment first, he said.

"It may not be right now, but sometime or the other that line has to be crossed," he said. "The bottom line is [that] the most important place for privacy to be considered is at the early stages of any data collection or analysis activity in the federal government. They have to be done early and often."

Read more about BI and Analytics in Computerworld's BI and Analytics Topic Center.



Additional Resources
Forrester Consulting - Optimizing Users and Applications in a Mobile World
WHITE PAPER
Solving application issues over the WAN requires careful consideration. Based on their independent research, Forrester Consulting offers recommendations on how to tackle application performance issues, insufficient bandwidth and the inability to quickly restore users in a disaster.

Read now.

Security KnowledgeVault
WHITE PAPER
Security is not an option. This KnowledgeVault Series offers professional advice how to be proactive in the fight against cybercrimes and multi-layered security threats; how to adopt a holistic approach to protecting and managing data; and how to hire a qualified security assessor. Make security your Number 1 priority.

Read now.

Cut Communications Costs Once and for All
WHITE PAPER
New IP-based communications systems are being deployed by small and midsized businesses at a rapid rate. Learn how these organizations are enabling faster responsiveness, creating better customer experiences, speeding office or mobile interactions, and dramatically reducing existing communications costs.

Read now.

BI and Analytics White Papers
X-Ray of the PCI Process-4 Proactive Steps
This white paper from Forrester Research Inc., helps break PCI into understandable components. Security and risk professionals will gain knowledge and insight into...
Forrester: Economic Impact of Switching to Google Apps
Content provided by Google

Read this Forrester report on the "total economic impact" of Google Apps, and learn how switching to Google Apps creates...
Intelligent Systems: Unlocking Hidden Business Value with Data
An intelligent system enables data to flow across an enterprise infrastructure, spanning the devices where valuable data is gathered from employees and customers,...
Concepts of NonStop SQL/MX
For DBAs and developers who are familiar with Oracle solutions and want to learn about NonStop SQL/MX, this whitepaper provides an overview of...
HP Advanced Information Services for SAP In-Memory Appliance (SAP HANA)
Organizations are eager to connect the vast amounts of data available within and outside their businesses to compete more effectively and make better...
All BI and Analytics White Papers
BI and Analytics Webcasts
Quantifying the Business Value of VMware View - Webcast
Many enterprises have discovered that the use of virtualization to support desktop workloads creates a range of significant benefits. These benefits include price...
Good to Great - How to Take Business Analytics to the Next Level
By attending this webcast you will learn how you can implement an effective BA strategy that will deliver maximum strategic value to your...
Supporting Mobile Productivity With A Limited IT Budget
Join us and hear from Kaseya mobile IT management experts as we discuss core strategies for supporting the mobile revolution on a shoestring...
User Experience Monitoring
In this webinar, you will learn hints & tips for improving end-user response times from Forrester Research analyst, Jean-Pierre Garbani.
Hints & Tips Cisco
Overwhelmed by tracking your Vblock, Flexpod or Cisco UCS performance? Spend one hour with Nimsoft to learn how you can eliminate the overhead...
All BI and Analytics Webcasts
Newsletter Sign-Up

Receive the latest news test, reviews and trends on your favorite technology topics

Choose a newsletter
  1. View all newsletters | Privacy Policy
IT Jobs