Showing posts with label PCLOB. Show all posts
Showing posts with label PCLOB. Show all posts

Sunday, July 31, 2016

I Con the Record Rolls Out Its 3-Page Intel Collection Efficacy Process

Screen Shot 2016-07-30 at 2.50.04 PMLast year, PCLOB suggested that the intelligence community formalize its process to assess the efficacy of intelligence collection. While it made the recommendation as part of its 702 report, the recommendation itself came against the background of Congress and the IC having decided that the phone dragnet wasn’t really worth the cost and privacy exposure.

I Con the Record just released a report on the processes the IC now uses to conduct such efficacy assessments; the report itself is actually dated February 8. Here’s what the report addressing this complex subject includes:

Page 1: Formal cover

Page 2: [PAGE INTENTIONALLY LEFT BLANK]

Page 3:

  • Introductory paragraph
  • Two paragraphs laying out PCLOB recommendation
  • Two paragraphs discussing “Assessing Efficacy and Value”
    • One paragraph describing that one must make both quantitative and qualitative judgements
    • One paragraph introducing the “comprehensive processes”

Page 4:

  • Four paragraphs on the National Intelligence Priorities Framework (see this document for a summary of what the NIPF looked like in 2013), citing both PPD-28’s mandate to consider privacy implications and ODNI’s updated ICD 204 which includes this paragraph (but no mention of the FBI and military/covert operations exceptions to this mandate):

PPD-28 specifically requires consideration of the value of Signals Intelligence activities and the risks of potential exposure of those activities to U.S. foreign policy, defense, commercial, economic, and financial interests, international agreements, privacy concerns, and the protection of intelligence sources and methods.

  • The first of two paragraphs on the IC’s “Refined Process on SIGINT Targeting” describing how requiring heads of policy departments to sign off on priorities ensures that senior policymakers provide “comprehensive” oversight of “potentially sensitive” SIGINT collection

Page 5:

  • The second paragraph on the IC’s “Refined Process on SIGINT Targeting” describing how, if the senior policymakers decide the risks of collection on a target outweighs its value, they will terminate the collection
  • Four paragraphs on “Assessing IC Reporting,” describing how ODNI performs a quantitative (counting reports, including those that get into important reports like the President’s Daily Briefing) and qualitative review of resources dedicated to priorities and production from those units

Page 6 (a half page):

  • Two paragraphs on other processes
    • One paragraph noting that individual elements conduct their own assessment
    • One paragraph describing the Intelligence Community Inspector General’s own assessments, noting especially that USA Freedom Act required he complete an assessment of the information acquired under FISA’s Business Records provision
  • One paragraph describing a “Path Forward” that might include using prediction markets to identify the most valuable intelligence, but noting such an approach is in a “nascent stage”

Overall, there are just three pages of meat, none of which is terrifically impressive.The reference to the USAF report on assessing the value of intelligence coming from a program underscores that such reporting requirements don’t exist for all other programs. And nowhere in the discussion is any consideration whether the same information might be acquired via less intrusive means (as has happened with the phone dragnet), something that would seem central to balancing trade-offs.

In short, it’s not so much a real process for assessing the value of intelligence against the risks of it, rather than a declaration that policymakers (you know? The people who want to expand their budgets?) will decide.

 

Tuesday, May 17, 2016

For Second Year in a Row, HPSCI Tries to Gut PCLOB

As I reported, during the passage of Intelligence Authorization last year (which ultimately got put through on the Omnibus bill, making it impossible for people to vote against), Congress implemented Intelligence Community wishes by undercutting PCLOB authority in two ways: prohibiting PCLOB from reviewing covert activities, and stripping an oversight role for PCLOB that had been passed in all versions of CISA.

In the 2017 Intelligence Authorization HPSCI passed on April 29, it continued more of the same. It does so in two ways:

Requires it to get its appropriations approved by Congress

Section 303 changes the authorizing language for PCLOB to state that it can only spend money on things if Congress specifically authorized it.

SEC. 303. AUTHORIZATION OF APPROPRIATIONS FOR PRIVACY AND CIVIL LIBERTIES OVERSIGHT BOARD.

(a) REQUIREMENT FOR AUTHORIZATIONS.—Sub-section (m) of section 1061 of the Intelligence Reform and Terrorism Prevention Act of 2004 (42 U.S.C. 2000ee(m)) is amended to read as follows:

(m) FUNDING.—

(1) SPECIFIC AUTHORIZATION REQUIRED.— Appropriated funds available to the Board may be obligated or expended to carry out activities under this section only if such funds were specifically authorized by Congress for use for such activities for such fiscal year.

(2) DEFINITION.—In this subsection, the term ‘specifically authorized by Congress’ has the meaning given that term in section 504(e) of the National Security Act of 1947 (50 U.S.C. 3094(e)).’

(b) AUTHORIZATION OF APPROPRIATIONS.—There is authorized to be appropriated to the Privacy and Civil Liberties Oversight Board for fiscal year 2017 the sum of $10,081,000 to carry out the activities of the Board under section 1061 of the Intelligence Reform and Terrorism Prevention Act of 2004 (42 U.S.C. 2000ee(m)).

At one level, this looks like nothing more than bureaucratic dick-waving, a reminder to PCLOB that Congress can cut off funding if it does things like deign to comment on covert spying activities.

But — particularly given the way the Intelligence Communities stripped PCLOB’s involvement in CISA oversight at the last minute — I wonder whether this will restrict what PCLOB can do under presidential orders. Congress set up PCLOB such that its mandate covers only counterterrorism programs. But with EO 13636 (the EO that set up the information sharing system that, with significant changes, became CISA) and PPD 28, President Obama gave PCLOB a cybersecurity role beyond that defined in statute. So I wonder whether this is a way to further PCLOB remove from cybersecurity oversight than those last minute changes already did.

The authorization still granted PCLOB its requested funding (and that request did lay out those cybersecurity activities), so this may just be, for the moment, a shot across the bow.

Requires the Committee to warn the Intelligence Committees and Intelligence Agency heads before they conduct any oversight

The bill also adds new reporting requires on PCLOB, beyond the biennial reports that go to a number of congressional committees. In short, the new language requires PCLOB to warn the Intelligence Committees and the heads of an intelligence agency before they start doing any oversight.

SEC. 307. INFORMATION ON ACTIVITIES OF PRIVACY AND CIVIL LIBERTIES OVERSIGHT BOARD

Section 1061(d) of the Intelligence Reform and Terrorism Prevention Act of 2004 (42 U.S.C. 2000ee(d)) is further amended by adding at the end the following new paragraph:

(5) INFORMATION.—

(A) ACTIVITIES.—In addition to the reports submitted to Congress under subsection (e)(1)(B), the Board shall ensure that each official and congressional committee specified in subparagraph (B) is kept fully and currently informed of the activities of the Board, including any significant anticipated activities.

(B) OFFICIALS AND CONGRESSIONAL COMMITTEES SPECIFIED.—The officials and congressional committees specified in this subparagraph are the following:

(i) The Director of National Intelligence.

(ii) The head of any element of the intelligence community (as defined in section 3(4) of the National Security Act of 1947 (50 U.S.C. 3003(4)) the activities of which are, or are anticipated to be, the subject of the review or advice of the Board.

(iii) The Permanent Select Committee on Intelligence of the House of Representatives and the Select Committee on Intelligence of the Senate.

Of particular note: if PCLOB warned the spooks, and the spooks prohibited PCLOB oversight (again), it’s not clear how the other committees of jurisdiction — which include the Judiciary, Homeland Security and House Oversight Committee, in addition to the Intelligence Committees — would get notice.

These changes are being made based on an Intelligence Committee claim that they give PCLOB — one of the very few entities that has proven to effectively oversee the Intelligence Community — more “oversight.” But it’s hard to understand how they’ll do anything more than ensure that the Intelligence Committees return to the status quo position where they’re the only entities permitted to (not) oversee the IC.

In other words, HPSCI — of all entities !!! — claims that that committee, which has serially failed at overseeing just about anything, must give the overseers greater oversight.

Tuesday, March 29, 2016

With Upcoming David Medine Departure, Will PCLOB Slip Back into Meaninglessness?

The Chair of the Privacy and Civil Liberties Oversight Board, David Medine, has announced he will resign effective  July 1 to work with a development organization “advising on data privacy and consumer protection for lower-income financial consumers.”

The move comes not long after Congress has, in several ways, affirmatively weakened or unexpectedly stopped short of expanding PCLOB’s mandate, by ensuring it could not review any covert programs, and by eliminating a PCLOB oversight role under OmniCISA.

In Medine’s statement, he promised the board would continue to work on their examination of CT activities relating to EO 12333.

I look forward to continuing to work on PCLOB’s current projects until my departure. I am pleased to know that, even after my departure, the Board Members and our dedicated staff remain committed to carrying forward the Board’s critical work, including its ongoing examination of counterterrorism activities under Executive Order 12333.

The EO 12333 approach (and the two CIA programs to examine) was formally approved July 1, a year to the day before Medine’s departure. It was initially scheduled to be done by the end of last year. But in their most recent semi-annual report (released at the end of December), PCLOB noted they were just starting on their public report.

In July, the Board voted to approve two in-depth examinations of CIA activities conducted under E.O. 12333. Board staff has subsequently attended briefings and demonstrations, as well as obtained relevant documents, related to the examinations. The Board also received a series of briefings from the NSA on its E.O. 12333 activities. Board staff held follow-up sessions with NSA personnel on the topics covered and on the agency’s E.O. 12333 implementing procedures. Just after the conclusion of the Reporting Period, the Board voted to approve one in-depth examination of an NSA activity conducted under E.O. 12333. Board staff are currently engaging with NSA staff to gather additional information and documents in support of this examination. Board staff also began work developing the Board’s public report on E.O. 12333, described above.

So while Medine promises PCLOB will continue to work on the EO 12333 stuff, I do worry that it will stall after his departure. I’m concerned, as well, about the makeup of the board. Board member Jim Dempsey’s term officially ended on January 29, though President Obama nominated him for another term on March 17, which means he will serve out 2016 (I believe as a temporary appointment until the end of the congressional term, but am trying to confirm), and longer if and when the Senate confirms him. But Medine’s departure will leave 2 members (counting Dempsey) who have been firmly committed to conducting this review, Rachel Brand, who has been lukewarm but positive, and Elisabeth Collins Cook who was originally opposed. That is, unless Medine is replaced in timely fashion (and given that this is a multiple year appointment, Republicans would have incentive to stall to get a GOP Chair), the board may be split on its commitment to investigating these issues.

There are a few other things happening on the EO 12333 front. Most urgently, the Intelligence Community is as we speak implementing new procedures for the sharing of EO 12333 with law enforcement agencies. PCLOB was involved in a review of those procedures, and had successfully pressed for more controls on the FBI’s back door access to 702 data (which is one reason I find the timing of Medine’s departure of particular concern). Two years after PCLOB first outed Treasury as having no EO 12333 implementing guidelines, they still have none.

That is, particularly after Congress’ successful attempts at undercutting PCLOB’s power, Medine’s departure has me seriously worried about whether the Intelligence Committee is willing to undergo any scrutiny of its EO 12333 activities.