DHS unveils post-CISA privacy assessment

Shutterstock image: digital fingerprint, cyber crime.

The post-CISA privacy regime is here. Will it satisfy critics?

A new Department of Homeland Security privacy assessment of a cyberthreat information-sharing program concedes that there are still some kinks to work out in protecting privacy.

Despite checks on the transmission of unrelated personally identifiable information, there is still a "residual privacy risk that these processes may not always identify and remove unrelated PII, thereby disseminating more PII than is directly related to the cybersecurity threat," the privacy impact assessment states.

To address that "residual" risk to privacy, DHS plans to periodically assess the automated and manual review processes for checking that PII is not spilled through the Automated Indicator Sharing program. The department can adjust the definition of a given threat indicator based on this feedback, according to the assessment.

The new privacy assessment is an update to the DHS information-sharing regime which accounts for the Cybersecurity Information Sharing Act. CISA, which became law in December 2016, encourages private firms to share threat data with the government by protecting them from lawsuits for doing so. The new guidance replaces previous privacy policy on sharing threat indicators from the private sector.

CISA's passage was a defeat for privacy activists who had fiercely opposed what they cast as enhanced surveillance measures.

The Obama administration has defended CISA's privacy provisions, and argued that DHS' National Cybersecurity and Communications Integration Center, as a civilian agency, is the right conduit for protecting privacy.

DHS has taken a layered approach to stripping PII from cyberthreat indicators, an umbrella term for security vulnerabilities and attack patterns.

"If an entity submits a cyber threat indicator or defensive measure with data fields beyond what the [Automated Indicator Sharing] profile includes, AIS will automatically delete those prohibited fields and will retain only fields that are part of the profile," the assessment states. "AIS then performs a series of automated analyses and technical mitigations to ensure that the information within the data fields meets certain predetermined criteria and does not contain unrelated PII or other sensitive information." 

The system is designed to work via machine-to-machine connections that share threat information in a common format over a common platform. The DHS Structured Threat Information eXchange, dubbed STIX, is the structured language for conveying threat information on a machine-to-machine basis. The common platform is TAXII (for Trusted Automated eXchange of Indicator Information) to which participants connect to share threat information, The DHS TAXII server received a three-year authority to operate on Jan. 19, 2016, according to the privacy assessment. 

Among the data potentially collected by the AIS initiative are descriptions of a threat indicator, descriptions of methods of countering such a threat, "observable facts" about a threat such as URLs and hashes, and metadata about those observable facts.

DHS analysts may use the threat indicators provided through the program to create "analytical products, bulletins, and network defense guidance," the document says. 

Though DHS is moving to fully automate it dissemination of cyberthreat information, some data still require a human touch. In certain cases, the AIS program may overlay a field with auto-generated text and put it in a queue for human review to check it for PII. The DHS analyst then checks if there is PII in the field, and if it is relevant to a cyber threat and therefore considered worth disseminating.

"Some AIS fields may contain information that is not recognizable the first time it is submitted, but upon review by a human analyst becomes a known good value," the assessment states.

The AIS profile, or template of indicators, will likely evolve with cyber threats. An interagency board will have to unanimously approve any changes to the AIS profile.

About the Author

Sean Lyngaas is an FCW staff writer covering defense, cybersecurity and intelligence issues. Prior to joining FCW, he was a reporter and editor at Smart Grid Today, where he covered everything from cyber vulnerabilities in the U.S. electric grid to the national energy policies of Britain and Mexico. His reporting on a range of global issues has appeared in publications such as The Atlantic, The Economist, The Washington Diplomat and The Washington Post.

Lyngaas is an active member of the National Press Club, where he served as chairman of the Young Members Committee. He earned his M.A. in international affairs from The Fletcher School of Law and Diplomacy at Tufts University, and his B.A. in public policy from Duke University.

Click here for previous articles by Lyngaas, or connect with him on Twitter: @snlyngaas.


    sensor network (agsandrew/

    Are agencies really ready for EIS?

    The telecom contract has the potential to reinvent IT infrastructure, but finding the bandwidth to take full advantage could prove difficult.

  • People
    Dave Powner, GAO

    Dave Powner audits the state of federal IT

    The GAO director of information technology issues is leaving government after 16 years. On his way out the door, Dave Powner details how far govtech has come in the past two decades and flags the most critical issues he sees facing federal IT leaders.

  • FCW Illustration.  Original Images: Shutterstock, Airbnb

    Should federal contracting be more like Airbnb?

    Steve Kelman believes a lighter touch and a bit more trust could transform today's compliance culture.

Stay Connected

FCW Update

Sign up for our newsletter.

I agree to this site's Privacy Policy.