{"id":122,"date":"2014-02-08T23:07:50","date_gmt":"2014-02-08T23:07:50","guid":{"rendered":"https:\/\/www.visionations.com\/blog\/?p=122"},"modified":"2014-02-08T23:19:28","modified_gmt":"2014-02-08T23:19:28","slug":"iacp-releases-technology-policy-framework-2","status":"publish","type":"post","link":"https:\/\/www.visionations.com\/blog\/?p=122","title":{"rendered":"IACP Releases Technology Policy Framework"},"content":{"rendered":"<p>Last month IACP released its Technology Policy Framework. The Framework was developed to help identify useful technologies for public safety and associated metrics for value and performance. The Framework was also motivated by the need to address integration challenges such as infrastructure, multiple platforms, security, technical support, and hardware. A key factor in IACP\u2019s effort is the importance of maintaining public trust, and the implications of new technologies for potentially violating that trust and losing the public\u2019s approval.<!--more--><\/p>\n<p>IACP identified the following \u201cuniversal principles\u201d * to guide policy development for technologies \u201cthat can, or have the potential to monitor, capture, store, transmit and or share data, including audio, video, visual images, or other personally identifiable information which may include the time, date, and geographic location where the data were captured\u201d:<\/p>\n<p>\u2022 Specification of Use \u2014Agencies should define the purpose, objectives, and requirements for implementing specific technologies, and identify the types of data captured, stored, generated, or otherwise produced.<\/p>\n<p>\u2022 Policies and Procedures \u2014Agencies should articulate in writing, educate personnel regarding, and enforce agency policies and procedures governing adoption, deployment, use, and access to the technology and the data it provides. These policies and procedures should be reviewed and updated on a regular basis, and whenever the technology or its use, or use of the data it provides significantly changes.<\/p>\n<p>\u2022 Privacy and Data Quality \u2014The agency should assess the privacy risks and recognize the privacy interests of all persons, articulate privacy protections in agency policies, and regularly review and evaluate technology deployment, access, use, data sharing, and privacy policies to ensure data quality (i.e., accurate, timely, and complete information) and compliance with local, state, and federal laws, constitutional mandates, policies, and practice.<\/p>\n<p>\u2022 Data Minimization and Limitation\u2014 The agency should recognize that only those technologies, and only those data, that are strictly needed to accomplish the specific objectives approved by the agency will be deployed, and only for so long as it demonstrates continuing value and alignment with applicable constitutional, legislative, regulatory, judicial, and policy mandates.<\/p>\n<p>\u2022 Performance Evaluation\u2014 Agencies should regularly monitor and evaluate the performance and value of technologies to determine whether continued deployment and use is warranted on operational, tactical, and technical grounds.<\/p>\n<p>\u2022 Transparency and Notice \u2014Agencies should employ open and public communication and decision \u2010 making regarding the adoption, deployment, use, and access to technology, the data it provides, and the policies governing its use. When and where appropriate, the decision \u2010 making process should also involve governing\/oversight bodies, particularly in the procurement process. Agencies should provide notice, when applicable, regarding the deployment and use of technologies, as well as make their privacy policies available to the public. There are practical and legal exceptions to this principle for technologies that are lawfully deployed in undercover investigations and legitimate, approved covert operations.<\/p>\n<p>\u2022 Security \u2014Agencies should develop and implement technical, operational, and policy tools and resources to establish and ensure appropriate security of the technology (including networks and infrastructure) and the data it provides to safeguard against risks of loss, unauthorized access or use, destruction, modification, or unintended or inappropriate disclosure. This principle includes meeting state and federal security mandates (e.g., the FBI\u2019s CJIS Security Policy 7 ), and having procedures in place to respond if a data breach, loss, compromise, or unauthorized disclosure occurs, including whether, how, and when affected persons will be notified, and remedial and corrective actions to be taken.<\/p>\n<p>\u2022 Data Retention, Access and Use \u2014Agencies should have a policy that clearly articulates that data collection, retention, access, and use practices are aligned with their strategic and tactical objectives, and that data are retained in conformance with local, state, and\/or federal statute\/law or retention policies, and only as long as it has a demonstrable, practical value.<\/p>\n<p>\u2022 Auditing and Accountability \u2014Agencies and their sworn and civilian employees, contractors, subcontractors, and volunteers should be held accountable for complying with agency, state, and federal policies surrounding the deployment and use of the technology and the data it provides. All access to data derived and\/or generated from the use of relevant technologies should be subject to specific authorization and strictly and regularly audited to ensure policy compliance and data integrity. Sanctions for non\u2010compliance should be defined and enforced.<\/p>\n<p>These universal principles are intended to provide structural guidance for developing agency-specific policies and operating procedures that should address the following factors:<\/p>\n<p>\u2022 Purpose<br \/>\n\u2022 Policy<br \/>\n\u2022 Definitions<br \/>\n\u2022 Management, including strategic alignment, objectives and<br \/>\nperformance, classification of<br \/>\ndata and privacy impact<br \/>\n\u2022 Operations, including installation, deployment, and training,<br \/>\noperational use, and record<br \/>\nkeeping<br \/>\n\u2022 Data Collection, Access, Use, and Retention, including<br \/>\ninformation sharing and security<br \/>\n\u2022 Oversight, Evaluation, Auditing, and Enforcement.<\/p>\n<p>These guidelines will be very helpful to agencies who are adopting new technologies, especially where the technology has implications not seen previously. Even if the outcome is not perfect (and it never is) a good faith effort to adopt this framework is likely to be viewed favorably when the inevitable challenges occur. If you are procuring a new technology from a vendor, be sure to ask if it has been evaluated with respect to the framework.<\/p>\n<p>*Universal principles taken <em>verbatim<\/em> from the IACP Technology Policy Framework which can be found here:<br \/>\nhttp:\/\/www.theiacp.org\/Portals\/0\/documents\/pdfs\/IACP%20Technology%20Policy%20Framework%20January%202014%20Final.pdf<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Last month IACP released its Technology Policy Framework. The Framework was developed to help identify useful technologies for public safety and associated metrics for value and performance. The Framework was also motivated by the need to address integration challenges such &hellip; <a href=\"https:\/\/www.visionations.com\/blog\/?p=122\">Continue reading <span class=\"meta-nav\">&rarr;<\/span><\/a><\/p>\n","protected":false},"author":4,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[10],"tags":[],"class_list":["post-122","post","type-post","status-publish","format-standard","hentry","category-research"],"_links":{"self":[{"href":"https:\/\/www.visionations.com\/blog\/index.php?rest_route=\/wp\/v2\/posts\/122","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.visionations.com\/blog\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.visionations.com\/blog\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.visionations.com\/blog\/index.php?rest_route=\/wp\/v2\/users\/4"}],"replies":[{"embeddable":true,"href":"https:\/\/www.visionations.com\/blog\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=122"}],"version-history":[{"count":3,"href":"https:\/\/www.visionations.com\/blog\/index.php?rest_route=\/wp\/v2\/posts\/122\/revisions"}],"predecessor-version":[{"id":136,"href":"https:\/\/www.visionations.com\/blog\/index.php?rest_route=\/wp\/v2\/posts\/122\/revisions\/136"}],"wp:attachment":[{"href":"https:\/\/www.visionations.com\/blog\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=122"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.visionations.com\/blog\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=122"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.visionations.com\/blog\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=122"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}