From: "Saved by Windows Internet Explorer 8"
Subject: Federal Register, Volume 69 Issue 240 (Wednesday, December 15, 2004)
Date: Fri, 28 Dec 2012 17:57:49 -0500
MIME-Version: 1.0
Content-Type: text/html;
	charset="utf-8"
Content-Transfer-Encoding: quoted-printable
Content-Location: http://www.gpo.gov/fdsys/pkg/FR-2004-12-15/html/04-27462.htm
X-MimeOLE: Produced By Microsoft MimeOLE V6.1.7601.17609

=EF=BB=BF<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.0 Transitional//EN">
<HTML><HEAD><TITLE>Federal Register, Volume 69 Issue 240 (Wednesday, =
December 15, 2004)</TITLE>
<META content=3D"text/html; charset=3Dutf-8" http-equiv=3DContent-Type>
<META name=3DGENERATOR content=3D"MSHTML 8.00.7601.17940"></HEAD>
<BODY><PRE>[Federal Register Volume 69, Number 240 (Wednesday, December =
15, 2004)]
[Notices]
[Pages 75079-75081]
From the Federal Register Online via the Government Printing Office [<A =
href=3D"http://www.gpo.gov/">http://www.gpo.gov/</A>]
[FR Doc No: 04-27462]


-----------------------------------------------------------------------

DEPARTMENT OF HOMELAND SECURITY

Federal Emergency Management Agency

[DHS-2004-0019]
RIN 1660-ZA07


National Emergency Management Information System--Mitigation=20
Electronic Grants Management System; Privacy Act System of Record

AGENCY: Federal Emergency Management Agency, Emergency Preparedness and=20
Response Directorate, Department of Homeland Security.

ACTION: Notice of a new system of records.

-----------------------------------------------------------------------

SUMMARY: Pursuant to the requirements of the Privacy Act of 1974, as=20
amended, the Department of Homeland Security, Emergency Preparedness=20
and Response Directorate, Federal Emergency Management Agency is=20
establishing a new system of records entitled National Emergency=20
Management Information System--Mitigation Electronic Grants Management=20
System. Some (but not all) applications for mitigation grants propose=20
activities that impact properties that are privately owned by=20
individuals (e.g., acquisition of a home that has been repeatedly=20
flooded) and these applications include personally identifiable=20
information about the property owners. Potentially, this personally=20
identifying information may be part of a State's application, and also=20
part of a local community's application as a sub-applicant. Personal=20
information collected in these applications includes the minimum amount=20
necessary to ascertain the eligibility of that property and/or=20
structure (e.g., house or commercial building) under mitigation grant=20
program regulations. See <A =
href=3D"https://portal.fema.gov/famsVu/dynamic/mitigation.html">https://p=
ortal.fema.gov/famsVu/dynamic/
mitigation.html</A>.

EFFECTIVE DATE: The addition of a new system of records and routine=20
uses will become effective on January 24, 2005, unless comments are=20
received that result in a contrary determination.

ADDRESSES: You may submit comments, identified by EPA Docket Number:=20
DHS-2004-0019 and/or 1660-ZA07 by one of the following methods:
    <BULLET> EPA Federal Partner EDOCKET Web Site: <A =
href=3D"http://www.epa.gov/feddocket">http://www.epa.gov/
feddocket</A>. Follow instructions for submitting comments on the Web =
site.=20
DHS has joined the Environmental Protection Electronic Docket System=20
(Partner EDOCKET). DHS and its agencies (excluding the United States=20
Coast Guard (USCG) and Transportation Security Administration (TSA))=20
will use the EPA Federal Partner EDOCKET system. The USCG and TSA=20
[legacy Department of Transportation (DOT) agencies] will continue to=20
use the DOT Docket Management System until full migration to the=20
electronic rulemaking federal docket management system occurs in 2005.
    <BULLET> Federal e-Rulemaking Portal: <A =
href=3D"http://www.regulations.gov/">http://www.regulations.gov/</A>.=20
Follow the instructions for submitting comments.
    <BULLET> Fax: (202) 646-4536.
    <BULLET> Mail: Rules Docket Clerk, Federal Emergency Management=20
Agency, Office of General Counsel, Room 840, 500 C Street SW.,=20
Washington, DC 20472.

FOR FURTHER INFORMATION CONTACT: Rena Y. Kim, Privacy Act Officer,=20
Federal Emergency Management Agency, Room 840, 500 C Street SW.,=20
Washington, DC 20472, (202) 646-3949, (not a toll free call), (telefax)=20
(202) 646-3949, or email Rena.K<A =
href=3D"mailto:im@dhs.gov">im@dhs.gov</A>.

SUPPLEMENTARY INFORMATION: The Privacy Act embodies fair information=20
principles in a statutory framework governing the means by which the=20
United States Government collects, maintains, uses, and disseminates=20
personally identifiable information. 5 U.S.C. 552a. The Privacy Act=20
applies to information that is maintained in a ``system of records.'' A=20
``system of records'' is a group of any records under the control of an=20
agency from which information is retrieved by the name of the=20
individual or by some identifying number, symbol, or other identifying=20
particular assigned to the individual. Individuals may request their=20
own records that are maintained in a system of records in the=20
possession or under the control of Department of Homeland Security=20
(DHS) by complying with DHS Privacy Act regulations, 6 CFR part 5,=20
subpart B and Federal Emergency Management Agency's (FEMA) Privacy Act=20
regulations, 44 CFR part 6.
    The Privacy Act requires each agency to publish in the Federal=20
Register a description denoting the type and character of each system=20
of records that the agency maintains, and the routine uses that are=20
contained in each system in order to make agency recordkeeping=20
practices transparent, to notify individuals regarding the uses to=20
which personally identifiable information is put, and to assist the=20
individual to more easily find such files within the Agency.
    The Emergency Preparedness and Response Directorate/FEMA is=20
establishing a new system of records pursuant to the Privacy Act of=20
1974 for the National Emergency Management Information System--
Mitigation Electronic Grants Management System (NEMIS-MT eGrants). FEMA=20
intends to collect personal information in applications for its=20
mitigation grant programs through the NEMIS-MT eGrants via the=20
Internet. The FEMA mitigation grant programs are the Flood Mitigation=20
Assistance (FMA) grant program (42 U.S.C. 4104c) and the Pre-Disaster=20
Mitigation (PDM) grant program, (42 U.S.C. 5133). The purpose of FEMA=20
mitigation grant programs is to provide funds to eligible Applicants/
States to implement mitigation activities to reduce or eliminate the=20
risk of future damage to life and property from disasters.
    Eligible applicants for FEMA mitigation grants are State emergency=20
management agencies or a similar State office that has emergency=20
management responsibility, the District of Columbia, the United States=20
Virgin Islands, the Commonwealth of Puerto Rico, Guam, American Samoa,=20
and the Commonwealth of the Northern Mariana Islands, and Federally=20
recognized Indian Tribal governments. Eligible Sub-applicants of FEMA=20
mitigation grants are State agencies, local governments, or Indian=20
Tribal governments to which a sub-grant is awarded. Examples of=20
mitigation activities that impact privately owned properties (and which=20
may include personally identifiable information in a State or local=20
community application) include retrofitting structures, elevation of=20
structures, acquisition and demolition or relocation of structures,=20
minor structural flood control projects, or construction of safe rooms.=20
The personally identifying information

[[Page 75080]]

collected includes an individual's name, home phone number, office=20
phone number, cell phone number, damaged property address, and mailing=20
address of the individual property owner(s), and the individual's=20
status regarding flood insurance, National Flood Insurance Program=20
(NFIP) Policy Number and Insurance Policy Provider for the property=20
proposed to be mitigated with FEMA funds. This notice will make the=20
public aware of routine management and oversight information sharing=20
between FEMA and other Federal agencies, State and local governments,=20
and contractors providing services in support of FEMA mitigation grant=20
programs.
    Accordingly, the NEMIS-MT eGrants Privacy Act system of records is=20
added to read as follows:


System Name:
    National Emergency Management Information System--Mitigation=20
Electronic Grants Management System (NEMIS-MT eGrants).

System location:
    All servers are operated at FEMA, Mount Weather Emergency=20
Operations Center (MWEOC), 19844 Blue Ridge Mountain Road, Bluemont, VA=20
20135.

Categories of individuals covered by the system:
    This system of records notice applies only to individuals=20
identified by name or other individual identifier, such as home=20
address, in the NEMIS-MT eGrants, and includes individuals who are=20
private property owners. These individuals voluntarily request that=20
their State, Territory or local community submit an application for=20
FEMA mitigation grant funds for the purpose of mitigating their=20
property and/or structure (e.g., house or commercial building).

Categories of records in the system:
    The categories of records in the system are grant applications. The=20
personally identifying information collected includes an individual's=20
name, home phone number, office phone number, cell phone number,=20
damaged property address, and mailing address of the individual=20
property owner(s), and the individual's status regarding flood=20
insurance, National Flood Insurance Program (NFIP) Policy Number and=20
Insurance Policy Provider for the property proposed to be mitigated=20
with FEMA funds.

Authority for maintenance of the System:
    The Robert T. Stafford Disaster Relief and Emergency Assistance=20
Act, 42 U.S.C. 5133, and the National Flood Insurance Act, 42 U.S.C.=20
4104c.

Purpose(s):
    The purpose of this system of records is to collect and maintain=20
individually identifiable information in applications for FEMA=20
mitigation grants that are submitted electronically, via the Internet,=20
through the NEMIS-MT eGrants from eligible Applicants/States and Sub-
applicants/local communities. The personally identifiable information=20
will be collected and maintained in order for FEMA to ascertain=20
eligibility of the property or structure for FEMA's mitigation grant=20
programs, to verify eligibility of activities for mitigation grants, to=20
identify repetitive loss properties, and to implement measures to=20
reduce future disaster damage.

Routine uses of records maintained in the system, including categories=20
of users and the purposes of such uses:
    In addition to those disclosures generally permitted under 5 U.S.C.=20
552a(b), all or a portion of the records or information contained in=20
this system may be disclosed outside FEMA/EP&amp;R/DHS as a routine use=20
pursuant to 5 U.S.C. 552a(b)(3) as follows:
    (1) To another Federal agency, State, United States Territory or=20
Tribal government agency charged with administering Federal mitigation=20
or disaster relief programs to prevent a duplication of efforts or a=20
duplication of benefits between FEMA and the other agency. FEMA may=20
disclose information to a State, U.S. Territory, Indian Tribal, or=20
local community agency eligible to apply for mitigation grant programs=20
administered by FEMA.
    (2) To contractors, grantees, experts, consultants, students and=20
others performing or working on a contract, service, grant, cooperative=20
agreement, or other assignment for the Federal government, when=20
necessary to accomplish an agency function related to this system of=20
records.
    (3) To an agency, organization, or individual for the purposes of=20
performing authorized audit or oversight operations.
    (4) To a congressional office from the record of an individual in=20
response to an inquiry from that congressional office made at the=20
request of the individual to whom the record pertains.
    (5) Where a record, either on its face or in conjunction with other=20
information, indicates a violation or potential violation of law--
criminal, civil, or regulatory--the relevant records may be referred to=20
an appropriate Federal, state, territorial, tribal, local,=20
international, or foreign agency law enforcement authority or other=20
appropriate agency charged with investigating or prosecuting such a=20
violation or enforcing or implementing such law.
    (6) To the Department of Justice (DOJ) or other federal agency=20
conducting litigation or in proceedings before any court, adjudicative=20
or administrative body, when: (a) DHS, or (b) any employee of DHS in=20
his/her official capacity, or (c) any employee of DHS in his/her=20
individual capacity where DOJ or DHS has agreed to represent the=20
employee, or
    (d) the United States or any agency thereof, is a party to the=20
litigation or has an interest in such litigation.
    (7) To the NARA or other Federal Government agencies pursuant to=20
records management inspections being conducted under the authority of=20
44 U.S.C. sections 2904 and 2906.

Policies and Practices for Storing, Retrieving, Accessing, Retaining,=20
and Disposing of Records in the System:
Storage:
    All information is stored on secure-access servers operated at a=20
single site at the FEMA, MWEOC, 19844 Blue Ridge Mountain Road,=20
Bluemont, VA 20135. Backup is provided on a separate server at the same=20
secure facility. MWEOC is only accessible by authorized persons,=20
including FEMA employees and contractors, and entry to the facility is=20
permitted only with a badge issued by the MWEOC.

Safeguards:
    Safeguards exist in the NEMIS-MT eGrants to prevent the=20
unauthorized access or misuse of data. First, FEMA maintains security=20
safeguards that prevent unauthorized access to the system by assigning=20
each authorized user a unique user profile, username and password based=20
upon his/her official use of the NEMIS-MT eGrants. Each unique profile=20
includes different levels of access rights. For Applicants/States and=20
Sub-applicants/local communities, roles in the system via the Internet=20
are assigned as Read-Only, Create/Edit, or Sign/Submit, and levels of=20
access are assigned by mitigation grant program (i.e., FMA and/or PDM).=20
For FEMA employees and contractors, levels of access via the FEMA=20
Intranet are assigned by mitigation grant program (i.e., FMA and/or=20
PDM) and by Region(s), and roles for FEMA users do not allow FEMA users=20
View information submitted in applications. Passwords expire after a=20
limited time, and users only have access to the system during the=20
period of time that both the assigned username and password are active.

[[Page 75081]]

Access to NEMIS-MT eGrants via the Intranet is assigned to the FEMA=20
employees and contractors for official purposes only through the NEMIS=20
Access Control System (NACS), which controls access to all software=20
available on the FEMA Intranet, and manages roles for FEMA officials=20
accessing the system. Access to NEMIS-MT eGrants via the Internet is=20
assigned to the Applicants/States and Sub-applicants/local communities=20
for official purposes only through the FEMA Access Management System,=20
which performs a similar function to NACS, but for eligible mitigation=20
grant program Applicants/States and Sub-applicants/local communities,=20
and managed roles for these non-FEMA users. The functions of these two=20
databases will be combined into the Integrated Security and Access=20
Control System. While the system is accessed, if an active NEMIS-MT=20
eGrants browser window is left open with no actions taken within the=20
system, the displayed page will expire after 30 minutes. The user can=20
then re-login using the username and password to access the system. In=20
addition, the system will not allow a user to bookmark the URL of the=20
MT eGrants with the intent of returning to that page at another time=20
without first entering the authorized username and password. Finally,=20
FEMA Enterprise Operations and the Office of Cyber Security are able to=20
monitor system use and determine whether information integrity has been=20
compromised by unauthorized access or use, and whether corrective=20
action by the Office of the Chief Information Officer is necessary.=20
Procedures are compliant with Title III of the E-Government Act of 2000=20
(Federal Information Security Management Act).

Retention and Disposal:
    In accordance with U.S. National Archives &amp; Records =
Administration=20
records retention regulations (GRS 3, 13), records are retained for 6=20
years and 3 months. Unsuccessful grant application files will be stored=20
in NEMIS-MT eGrants for 3 years from the date of denial, and then=20
deleted. Successful grant application files will be stored in the=20
NEMIS-MT eGrants for 6 years and 3 months from the date of closeout=20
(where closeout is the date FEMA closes the grant in its financial=20
system) and then deleted. Computerized records are stored in a database=20
server in a secured file server room. Hard copy records are maintained=20
for 6 years and 3 months years, at which time they are retired to the=20
Federal Records Center. The same retention schedule that applies to=20
paper records will be followed. This is consistent with the records=20
retention schedule that has been developed for this system.

System Manager(s) and Address:
    Patricia Bowman, Program Manager, IT-SE-CS, 500 C Street SW.,=20
Washington DC 20472, Pat.B<A =
href=3D"mailto:owman@dhs.gov">owman@dhs.gov</A>, (202) 646-2661.

Notification Procedures:
    Address inquiries to the System Manager named above.

Record Access Procedures:
    A request for access to records in this system may be made by=20
writing to the System Manager, identified above, in conformance with 6=20
CFR part 5, subpart B, which provides the rules for requesting access=20
to Privacy Act records maintained by DHS and FEMA's Privacy Act=20
regulations at 44 CFR part 6.

Contesting Record Procedures:
    Same as Notification procedures above. A request for access to=20
records in this system may be made by writing to the System Manager,=20
identified above, in conformance with 6 CFR part 5, subpart B, which=20
provides the rules for requesting access to Privacy Act records=20
maintained by DHS and FEMA's Privacy Act regulations at 44 CFR part 6.

Records Source Categories:
    Information in this system of records is obtained from State/
Territory, local government, or Indian Tribal governmentvia the=20
Internet to FEMA. While individuals are not eligible Applicants/States=20
or Sub-applicants/local communities, and cannot apply directly to FEMA=20
for assistance, some (but not all) applications for FEMA mitigation=20
grants propose activities that impact properties that are privately=20
owned by individuals (e.g., acquisition of a home that has been=20
repeatedly flooded) and these applications include personal information=20
about the property owners. These individuals voluntarily request that=20
their State, Territory, or local community submit an application for=20
FEMA mitigation grant funds for the purpose of mitigating their=20
property and/or structure (e.g., house or commercial building).

Exemptions Claimed for the System:
    None.

    Dated: December 10, 2004.
David A. Trissell,
Associate General Counsel, Emergency Preparedness and Response,=20
Department of Homeland Security.
[FR Doc. 04-27462 Filed 12-14-04; 8:45 am]
BILLING CODE 9110-41-P


</PRE></BODY></HTML>
