Pub. L. 111-83, tit. V, sec. 567
Pub. L. 111-83, tit. V, sec. 567
Sec. 567. (a) In General.—Any company that collects or retains personal information directly from individuals who participated in the Registered Traveler program shall safeguard and dispose of such information in accordance with the requirements in—(1) the National Institute for Standards and Technology Special Publication 800–30, entitled “Risk Management Guide for Information Technology Systems”; and(2) the National Institute for Standards and Technology Special Publication 800–53, Revision 3, entitled “Recommended Security Controls for Federal Information Systems and Organizations,”;(3) any supplemental standards established by the Assistant Secretary, Transportation Security Administration (referred to in this section as the “Assistant Secretary”).(b) Certification.—The Assistant Secretary shall require any company through the sponsoring entity described in subsection (a) to provide, not later than 30 days after the date of the enactment of this Act, written certification to the sponsoring entity that such procedures are consistent with the minimum standards established under paragraph (a)(1–3) with a description of the procedures used to comply with such standards.(c) Report.—Not later than 90 days after the date of the enactment of this Act, the Assistant Secretary shall submit a report to Congress that—(1) describes the procedures that have been used to safeguard and dispose of personal information collected through the Registered Traveler program; and(2) provides the status of the certification by any company described in subsection (a) that such procedures are consistent 123 STAT. 2186 with the minimum standards established by paragraph (a)(1–3).