A double-edged sword

In the post-Sept. 11 world, biometrics has finally managed to transform its image. Once seen as the ultimate invasion-of-privacy tool, many now view it as a valid security shield that can actually protect citizens from identity thieves and other malevolent types.

But that doesn't mean privacy is no longer a major issue of concern in biometric applications. Privacy advocates warn against the dangers of biometric information being misused or combined with personal data in large databases in such a way as to make it a de facto national identifier.

"One of the reasons privacy is such a problem in this country is that the Social Security number has been so widely adopted," said David Pierce, research director for the Independence Institute. "But if you end up substituting this national ID database and, in effect, turn it into a national biometric database, then the possibility of collecting too much data on individuals becomes all the more serious."

Still, privacy advocates recognize the potential benefits biometrics offers for safeguarding privacy. To ensure that the technology is beneficial and not abused, they suggest that agencies adhere to the following guidelines:

n Adopt strict procedures to ensure that the biometric data is used only for its core purpose and is promptly destroyed when no longer needed.

n Do not share the data with other agencies or with private organizations.

n Keep the biometric data in a separate database and do not link it with other personal identifiers, such as Social Security number, date of birth or mother's maiden name.

n Provide users with an easily accessible privacy policy specific to biometrics that includes all fair information practices.

n If biometric data is somehow compromised, make sure there are procedures in place for users to file a complaint and receive adequate redress.

n Consider having a privacy audit performed. This will provide an objective view of whether system security is appropriate for the data being held, and it can help highlight potential privacy weak points.

n Use biometrics in tandem with a public-key infrastructure or password system. That way if biometric data is corrupted, a user has another way to prove his or her identity.

IN THIS SERIES

Main story: Positive ID required

FCW in Print

In the latest issue: Looking back on three decades of big stories in federal IT.

Featured

  • FCW @ 30 GPS

    FCW @ 30

    Since 1986, FCW has covered it all -- the major contracts, the disruptive technologies, the picayune scandals and the many, many people who make federal IT function. Here's a look back at six of the most significant stories.

  • Shutterstock image.

    A 'minibus' appropriations package could be in the cards

    A short-term funding bill is expected by Sept. 30 to keep the federal government operating through early December, but after that the options get more complicated.

  • Defense Secretary Ash Carter speaks at the TechCrunch Disrupt conference in San Francisco

    DOD launches new tech hub in Austin

    The DOD is opening a new Defense Innovation Unit Experimental office in Austin, Texas, while Congress debates legislation that could defund DIUx.

  • Shutterstock image.

    Merged IT modernization bill punts on funding

    A House panel approved a new IT modernization bill that appears poised to pass, but key funding questions are left for appropriators.

  • General Frost

    Army wants cyber capability everywhere

    The Army's cyber director said cyber, electronic warfare and information operations must be integrated into warfighters' doctrine and training.

  • Rising Star 2013

    Meet the 2016 Rising Stars

    FCW honors 30 early-career leaders in federal IT.

Reader comments

Please post your comments here. Comments are moderated, so they may not appear immediately after submitting. We will not post comments that we consider abusive or off-topic.

Please type the letters/numbers you see above

More from 1105 Public Sector Media Group