Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.

...

E-Logbook data is fisheries confidential data under the trade secrets act.  Unless the e-signature requires it there is not likely to be PII in this data.  ...clarify....

...

Mitigating controls

...

Information collected pursuant to requirements of the MSA, including permit application information, is protected by its confidentiality provisions at § 402 and under its implementing regulations at 50 CFR Part 600 Subpart E, including NOAA Administrative Order (NAO) 216-100. Additional protections of the Privacy Act and FOIA apply to such data as well as those collected under the Halibut Act.

...

Mitigating controls

...

Perhaps the most significant mitigating control is that in commercial fisheries transactions, both parties to the transaction (typically the fisher and the fish processor) are permitted entities and each has some responsibility for accurate and complete record-keeping and reporting (for example, the fisher may be required to keep a logbook showing fishing efforts and catch, while the processor is required to report fish purchased). In these transactions it is typical for the parties to the transactions to have opposite and balancing interests (for example, when a fisher is selling fish to a processor, the fisher wants the amount paid to be high, while the processor wants the amount paid to be low). These multiple sources of information and counter-balanced incentives tend to make deception more difficult to initiate and sustain.

Another mitigating control is that under the authority of the Debt Collection Improvement Act (31 U.S.C. 7701), NMFS would collect Tax Identification Number information from individuals in order to issue, renew, or transfer fishing permits or to make nonpermit registrations.

In the Hawaii longline logbook case we have independent confirmation of the vessel's location through the VMS system.  The e-logbook software application licensing compliance dongle forms a unique identifier for each logbook page and it can tie the logbook page to a particular instance of the e-logbook software. 

These vessels are permitted to fish and therefore have a prior "trusted relationship" with NMFS.  In many cases this prior relationship involves confirming vessel ownership with the US Coast Guard, verifying participation in prior fisheries through previously submitted state or federal fish tickets or logbooks, confirmation of business ownership, etc.  ...need more detail...

Threat and Vulnerability Identification

...