The IT Law Wiki
Advertisement

Citation[]

Intelligence Reform and Terrorism Protection Act of 2004 (IRTPA), Pub. L. No. 108-458, 118 Stat. 3638 (Dec. 17, 2004), codified at 42 U.S.C. §2000ee, 50 U.S.C. §403-1 et seq., §403-3 et seq., §404o et. seq.

Overview[]

The Act was passed largely in response to recommendations from the National Commission on Terrorist Attacks Upon the United States (the 9/11 Commission), which investigated the September 11, 2001 terrorist attacks. The Commission recognized that before the attacks of September 11, 2001, federal agencies had been unable to effectively share information about suspected terrorists and their activities.

In addressing this problem, the 9/11 Commission recommended that the sharing and uses of information be guided by a set of practical policy guidelines that would simultaneously empower and constrain officials, closely circumscribing what types of information they would be permitted to share as well as the types of information they would need to protect. This Act provided for sweeping changes to the U.S. Intelligence Community structure and processes, and creates new systems that are specially designed to combat terrorism.

Among other actions, the Act:

Requirements[]

The Act requires the President to establish an Information Sharing Environment (ISE) "for the sharing of terrorism information in a manner consistent with national security and with applicable legal standards relating to privacy and civil liberties."[1] It also requires designation of a Program Manager for the Information Sharing Environment (PM-ISE) "responsible for information sharing across the Federal Government" to oversee the implementation of and manage the ISE.[2] Working in consultation with the Information Sharing Council (ISC),[3] an interagency advisory body for federal departments and agencies with counterterrorism missions, the PM-ISE is charged with planning and overseeing the ISE's implementation and management. The PM-ISE's responsibilities include:

  1. Planning for and overseeing the implementation of, and managing, the ISE;
  2. Assisting in the development of policies, procedures, guidelines, rules, and standards as appropriate to foster the development and proper operation of the ISE; and
  3. Assisting, monitoring, and assessing the implementation of the ISE by Federal departments and agencies to ensure adequate progress, technological consistency and findings to Congress.[4]

Among other duties, the PM-ISE is responsible for assisting the President in submitting to Congress an ISE Implementation Plan (ISE IP) that addresses eleven requirements set forth in Section 1016(e) of IRTPA.

Privacy considerations[]

Section 1011[]

Section 1011 of the Act requires the Director of National Intelligence to appoint a Civil Liberties Protection Officer and gives this officer the following functions:[5]

The Bush Administration took steps, beginning in 2005, to establish an information sharing environment to facilitate the sharing of terrorism-related information. The move was driven by the recognition that before the attacks of September 11, 2001, federal agencies had been unable to effectively share information about suspected terrorists and their activities.

Section 1016[]

Section 1016 of the Act applied the lessons of the September 11th attacks to reform the Intelligence Community and the intelligence and intelligence-related activities of the U.S. Government. Section 1016 requires the President to establish an Information Sharing Environment (ISE) "for the sharing of terrorism information in a manner consistent with national security and with applicable legal standards relating to privacy and civil liberties."[6] Moreover, the section defines the ISE to mean "an approach that facilitates the sharing of terrorism information."[7]

The Act also required that the ISE incorporate protections for individuals' privacy and civil liberties. Among other things, the Act established the Privacy and Civil Liberties Oversight Board. The Board, composed of five members, two of whom (the chairman and vice-chairman) must be confirmed by the U.S. Senate.

The Board's mandate is to ensure that privacy and civil liberties are not neglected when implementing terrorism-related laws, regulations, and policies. The 9/11 Commission had recommended creation of such a Board because of concern that the USA PATRIOT Act of 2001, enacted soon after the attacks, shifts the balance of power to the government.

Section 1016 was amended in 2007 to include homeland security information and weapons of mass destruction information. It codifies many of the recommendations developed in response to the President's information sharing guidelines, such as the creation of the ITACG and the development of a national network of state and major urban area fusion centers.

The Act also required the designation of a Program Manager for the Information Sharing Environment (PM-ISE) "responsible for information sharing across the Federal Government" to oversee the implementation of and manage the ISE.[8]

Application to cybersecurity[]

The Act does not contain a single reference to cyber, cybersecurity, or related activities. Its stated purpose is to "reform the intelligence community and the intelligence and intelligence-related activities of the United States Government, and for other purposes." The Act contains findings and recommendations offered in the 9/11 Commission Report and other assessments that address national and homeland security shortcomings associated with the terrorist attacks of September 11, 2001.

Numerous organizations, programs, and activities in the Act currently address cybersecurity-related issues. IRPTA addresses many types of risks to the nation and threats emanating from man-made and naturally occurring events. The broad themes of the Act could be categorized as how the federal government identifies, assesses, defeats, responds to, and recovers from current and emerging threats. The Act might be updated to incorporate cybersecurity-related issues. However, any such update could affect numerous organizations and activities.

References[]

  1. IRTPA § 1016(b)(1)(A).
  2. Id. §1016(f).
  3. Id. §1016(g).
  4. Id. §1016(f)(2)(A).
  5. Id. §1011.
  6. Id. §1016(b)(1)(A).
  7. Id. §1016(a)(2).
  8. Id. §1016(f).
Advertisement