NCIC Quality Assurance & Compliance 3 — Questions and Answers
Question 1: Which federal regulation specifically requires that criminal intelligence systems receiving federal funding have documented operating policies?
- Title 18 U.S.C. § 2511
- The Freedom of Information Act (FOIA)
- 28 CFR Part 23 (Correct answer)
- Executive Order 12333
Correct answer: 28 CFR Part 23
28 CFR Part 23 establishes operating principles and policy requirements for federally funded multijurisdictional criminal intelligence systems.
Question 2: The reasonable suspicion standard under 28 CFR Part 23 requires information entered into a criminal intelligence system to be based on:
- A preponderance of evidence linking the individual to criminal activity
- Articulable facts indicating involvement in criminal conduct or activity with criminal organizations (Correct answer)
- An official criminal complaint filed with the charging agency
- Probable cause sufficient to support a search warrant
Correct answer: Articulable facts indicating involvement in criminal conduct or activity with criminal organizations
28 CFR Part 23 requires articulable facts—not mere suspicion or guesswork—that a subject is involved in criminal conduct before entry into the system.
Question 3: Under the Privacy Act of 1974, federal agencies maintaining records about individuals must:
- Destroy all personally identifiable records after one year
- Share records freely with all state and local law enforcement partners
- Allow individuals to access and request correction of records about themselves (Correct answer)
- Classify all records containing personally identifiable information
Correct answer: Allow individuals to access and request correction of records about themselves
The Privacy Act grants individuals the right to access records federal agencies maintain about them and to request corrections of inaccuracies.
Question 4: Which DHS policy framework mandates that fusion centers maintain protections for privacy, civil rights, and civil liberties as a condition of federal support?
- The National Infrastructure Protection Plan
- The Information Sharing Environment (ISE) guidelines
- The Fusion Center Privacy, Civil Rights, and Civil Liberties (PCRCL) policy requirements (Correct answer)
- The National Incident Management System (NIMS)
Correct answer: The Fusion Center Privacy, Civil Rights, and Civil Liberties (PCRCL) policy requirements
DHS requires fusion centers to develop and implement PCRCL policies as a condition for receiving federal resources and recognition.
Question 5: Intelligence 'minimization procedures' are designed primarily to:
- Reduce the number of analysts assigned to sensitive investigations
- Limit collection, retention, and dissemination of U.S. person information beyond authorized purposes (Correct answer)
- Minimize the operational cost of intelligence gathering activities
- Reduce the length of intelligence products for easier distribution
Correct answer: Limit collection, retention, and dissemination of U.S. person information beyond authorized purposes
Minimization restricts how intelligence agencies handle information about U.S. persons when it is not relevant to the authorized intelligence purpose.
Question 6: A fusion center analyst proposes including information about a U.S. citizen's lawful political activities in an intelligence report. Under PCRCL compliance standards, this is:
- Permitted if the citizen is suspected of any criminal offense
- Acceptable to provide contextual background for the report
- Generally prohibited unless the activity is directly linked to criminal conduct (Correct answer)
- Allowed only with approval from a federal judge
Correct answer: Generally prohibited unless the activity is directly linked to criminal conduct
Collecting or retaining information about lawful political activities of U.S. persons violates First Amendment protections and civil liberties compliance requirements.
Question 7: When auditing a federally funded criminal intelligence system, one primary compliance check is verifying that:
- All analysts possess federal security clearances at the appropriate level
- The system's software meets current DHS cybersecurity benchmarks
- Each retained record is supported by the reasonable suspicion standard required for entry (Correct answer)
- The agency transmits intelligence daily to a designated FBI field office
Correct answer: Each retained record is supported by the reasonable suspicion standard required for entry
28 CFR Part 23 compliance audits specifically examine whether every record in the system meets the evidentiary threshold for lawful retention.
Which federal regulation specifically requires that criminal intelligence systems receiving federal funding have documented operating policies?