March 9, 2023
August 13, 2021
Initial Report 1. Is there a person in your agency who is responsible for coordinating and overseeing the implementation of the records management program? (36 CFR 1220.34(a)) Answer: Yes Response: 2. Please provide the person's name, position title, and office. Response: Nancy Morgan, Director, Information Management Services 3. Does your agency have a Senior Agency Official for Records Management (SAORM)? (If you are a component of a department, you may answer "Yes" if this is being done at the component level.) Answer: Yes 4. Does your agency have a Chief Records Officer for the Federal Government? Answer: Yes 5. Does your agency have a network of designated employees within each program and administrative area who are assigned records management responsibilities? These individuals are often called Records Liaison Officers (RLOs), though their titles may vary. (36 CFR 1220.34(d)) Answer: Yes 6. Does your agency have a documented and approved records management directive(s)? (36 CFR 1220.34(c)) Answer: No, pending final approval 7. When was your agency's directive(s) last reviewed and/or revised to ensure it includes all new records management policy issuances and guidance? Answer: FY 2015 -2017 8. Does your agency have internal records management training*, based on agency policies and directives, for employees assigned records management responsibilities? (36 CFR 1220.34(f)) *Includes NARA's records management training workshops that were customized specifically for your agency or use of an agency-customized version of the Federal Records Officer Network (FRON) RM 101 course. Answer: Yes 9. Has your agency developed mandatory internal, staff-wide, formal training", based on agency policies and directives, covering records in all formats, including communications such as email, text messages, chat, or other messaging platforms or apps, such as social media or mobile device applications, which helps employees and contractors fulfill their recordkeeping responsibilities?'" (36 CFR 1220.34(f)) *Includes NARA's records management training workshops that were customized for your agency or use of an agency-customized version of the Federal Records Officer Network (FRON) RM 101 course. **Components of departmental agencies may answer "Yes" if this is handled by the department. Department Records Officers may answer "Yes" if this is handled at the component level. Answer: Yes 10. Does your agency require that all senior and appointed officials, including those incoming and newly promoted, receive training on the importance of managing records under their immediate control? (36 CFR 1220.34(f)) Answer: No 11. Please add any additional comments about your agency for Section I: Activities. (Optional) Response: Regarding questions 8 and 10, CIA has not instituted mandatory records management training; however, CIA does have comprehensive introductory web-based training and this is made available at new hire orientation. CIA also offers additional training on records control schedule, records inventories and system approvals, classification, and other topics, as well as an instructor-led class on the records control schedule. In addition, records management professionals meet with incoming and outgoing officials regarding records management responsibilities. 12. In addition to your agency's established records management policies and records schedules, has your agency's records management program implemented internal controls to ensure that all eligible, permanent agency records in all media are transferred to NARA according to approved records schedules? (36 CFR 1222.26(e)) "'These controls must be internal to your agency. Reliance on information from external agencies (e.g., NARA's Federal Records Centers) should not be considered when responding to this question. *Examples of records management internal controls include but are not limited to: meetings with records creators, monitoring and testing of file plans, regular review of records inventories, internal tracking database of transfer authorities and dates. Answer: No, pending final approval 13. In addition to your agency's established policies and records schedules, has your agency developed and implemented internal controls to ensure that records are not destroyed before the end of their retention period? (36 CFR 1222.26(e)) "'These controls must be internal to your agency. Reliance on information from external agencies (e.g., NARA's Federal Records Centers) or other organizations should not be considered when responding to this question. *Examples of records management controls include but are not limited to: regular review of records inventories, approval process for disposal notices from off-site storage, monitoring and testing of file plans, pre-authorization from records management program before records are destroyed, ad hoc monitoring of trash and recycle bins, notification from facilities staff when large trash bins are requested, annual records clean-out activities sponsored and monitored by records management staff. Answer: No, pending final approval 14. Does your agency evaluate, by conducting inspections/audits/reviews, its records management program to ensure that it is efficient, effective, and complies with applicable records management laws and regulations? (36 CFR 1220.34(j)) "'For this question, your agency's records management program, or a major component of the program (e.g., vital records identification and management, the records disposition process, records management training, or the management of your electronic records) must be the primary focus of the inspection/audit/review. Answer: Yes, evaluations are conducted by the Records Management Program 15. How often does your agency conduct formal evaluations of a major component of your agency (i.e., programs or offices)? Answer: Ad hoc 16. Was a formal report written and subsequent plans of corrective action created and monitored for implementation as part of the most recent inspection/audit/review? (Choose all that apply) Answer: Yes, formal report was written; Yes, plans of corrective action were created; Yes, plans of corrective action were monitored for implementation 17. Has your agency established performance goals for its records management program? *Examples of performance goals include but are not limited to: identifying and scheduling all paper and non-electronic records by the end of FY 2018, developing computer-based records management training modules, planning and piloting an electronic records management solution for email by the end of FY 2019, updating records management policies, conducting records management evaluations of at least one program area each quarter. Answer: Yes 18. Has your agency's records management program identified performance measures for records management activities such as training, records scheduling, records transfers, etc.? *Examples of performance measures include but are not limited to: percentage of agency employees that receive records management training in a year, a reduction in the volume of inactive records stored in office space, percentage of eligible permanent records transferred to NARA, percentage of records scheduled, percentage of offices evaluated/inspected for records management compliance, percentage of email managed, development of new records management training modules, audits of internal systems, annual updates of file plans, performance testing of applications to ensure records are captured, percentage of records successfully retrieved by Agency FOIA Officer in response to FOIA requests. Answer: Yes 19. Does your agency's records management program have documented and approved policies and procedures that instruct staff on how your agency's records in all formats must be managed and stored? (36 CFR 1222.34(e)) Answer: Yes 20. Has your agency identified the vital records of all its program and administrative areas? (36 CFR 1223.16) *Components of departmental agencies may answer "Yes" if this is handled by the department. Answer: Yes 21. How often does your agency review and update its vital records inventory? (36 CFR 1223.14) Answer: Annually 22. Is your vital records plan part of the Continuity of Operations (COOP) plan? Answer: Yes 23. Records needed to respond to a FOIA request are readily accessible and located by staff responsible for FOIA: Answer: Most of the time 24. At what point in the FOIA process does your agency inform requesters of the Office of Government Information Services (OGIS) dispute resolution services? (Choose all that apply) Answer: When there is an adverse determination; When responding to the requester's appeal; Other: CIA includes notice of OGIS' dispute resolution services in FOIA response letters that contain appeal rights. 25. How often does the FOIA program submit to agency leadership reports on such measures as pending requests and backlog? Answer: Quarterly 26. Do your agency's employee performance work plans and appraisals include FOIA performance measures for non-FOIA professionals to ensure compliance with the requirements of FOIA? (Note: The 2016-2018 term of the Freedom of Information Act Advisory Committee endorsed inclusion of FOIA performance standards in employee evaluations and work plans government-wide.) Answer: No Response: CIA attorneys and public affairs professionals have taken efforts to sensitize components to the Agency's statutory requirements under the FOIA. Briefings were provided to senior officers, executive assistants, and records managers, and web-based training was provided to the workforce. FOIA-related performance standards are included in the objectives of employees who administer the FOIA. 27. Does your agency have procedures for preparing documents for posting on FOIA reading rooms? (Note: The FOIA Improvement Act of 2016 amended the Federal Records Act, 44 U.S.C., to include a requirement that agencies establish "procedures for identifying records of general interest or use to the public that are appropriate for public disclosure, and for posting such records in a publicly accessible electronic format." This requirement is now included in 5 U.S.C.) Answer: Yes 28. Who is responsible for preparing the documents for posting? (Choose all that apply) Answer: FOIA staff; Program staff; IT/web staff 29. Please add any additional comments about your agency for Section II: Oversight and Compliance. (Optional) [No response provided] 30. When was the last time your agency submitted a records schedule to NARA for approval? (36 CFR 1225.10) Answer: FY 2017 - 2018 31. Are records and information in your agency managed throughout the lifecycle [creation/capture, classification, maintenance, retention, and disposition] so that they are identified, classified using a taxonomy, inventoried, and scheduled? (36 CFR 1222.34; 36 CFR 1222.10 and 36 CFR 1225.12) Answer: Yes 32. Are records and information in your agency easily retrievable and accessible when needed for agency business? (36 CFR 1220.32(c)) Answer: Most records can be retrieved and accessed in a timely manner 33. Does your agency disseminate every approved disposition authority (including newly approved records schedules and General Records Schedules) within six months of approval? (36 CFR 1226.12(a)) Answer: Yes 34. In addition to your agency's records management policies and records schedules, has your agency developed and implemented internal controls to ensure that permanent records are created/captured, classified, filed and managed according to their NARA-approved records schedules? (36 CFR 1222.26(e)) Answer: Yes 35. Did your agency transfer permanent non-electronic records to NARA during FY 2018? (36 CFR 1235.12) Answer: Yes 36. Did your agency transfer permanent electronic records to NARA during FY 2018? (36 CFR 1235.12) Answer: Yes 37. Does your agency conduct and document for accountability purposes training and/or other briefings as part of the on-boarding process for senior officials on records management roles and responsibilities, including the appropriate disposition of records and the use of personal and unofficial email accounts? (36 CFR 1222.24(a)(6) and 36 CFR 1230.10(a & b)) Answer: Yes 38. Is the Agency Records Officer and/or Senior Agency Official for Records Management involved in on-boarding briefings or other processes for new senior officials? Answer: Yes 39. Does your agency conduct and document for accountability purposes exit briefings for departing senior officials on the appropriate disposition of records, including email, under their immediate control? (36 CFR 1222.24(a)(6) and 36 CFR 1230.10(a & b)) Answer: Yes 40. Is the Agency Records Officer and/or Senior Agency Official for Records Management involved in exit briefings or other exit clearance processes for departing senior officials? Answer: Yes 41. Does the exit or separation process for departing senior officials include records management program staff or other designated official(s) reviewing the removal of personal papers and copies of records by those senior officials? (36 CFR 1222.24(a)(6)) Answer: Yes 42. Please add any additional comments about your agency for Section III: Records Disposition. (Optional) Response: Regarding #32, most records can be retrieved and accessed in a timely manner; some take more time. Regarding #40, onsite records management experts provide briefings to senior managers and inform SAORM and ARO. 43. Has your agency incorporated and/or integrated internal controls to ensure the reliability, authenticity, integrity, and usability of agency electronic records in electronic information systems? (36 CFR 1236.10) Answer: Yes 44. Does your agency have documented and approved procedures to enable the migration of records and associated metadata to new storage media to ensure that records are retrievable and usable as long as needed to conduct agency business and to meet NARA-approved dispositions? (36 CFR 1236.10) Answer: Yes 45. Does your agency maintain an inventory of electronic information systems that indicates whether or not each system is covered by an approved records schedule authority? (36 CFR 1236.26(a)) Answer: Yes 46. Does your agency ensure that records management functionality, including the capture, retrieval, and retention of records according to agency business needs and NARA-approved records schedules, is incorporated into the design, development, and implementation of its electronic information systems? (36 CFR 1236.10) *Components of departmental agencies may answer "Yes" if this is handled by the department. Answer: Yes 47. Does your agency's records management program staff participate in the design, development, and implementation of new electronic information systems? Answer: Yes 48. Which of these activities does your agency's records management program staff participate in to ensure that records requirements are part of the solution? (Choose all that apply) Answer: Participate in review and acceptance of proposals for new systems; Participate as stakeholder in requirements gathering; Participate as stakeholder in the design phase; Participate as stakeholder in the development phase including testing the system; Provide sign off authority for the implementation of new systems; Monitor system for adherence to standards, policies, and procedures 49. Does your agency have documented and approved policies and procedures for managing permanent electronic records? Answer: Yes 50. Do the policies include requirements for preserving records until eligible for transfer to NARA? Answer: Yes 51. Does your agency have a process or strategy for managing permanent electronic records, and related metadata, in an electronic form? Answer: Yes 52. Does your agency have documented and approved policies against unauthorized use, alteration, alienation or deletion of all electronic records? Answer: Yes 53. Does your agency have a digitization strategy to reformat permanent records created in hard copy or other analog formats (e.g., microfiche, microfilm, analog audio)? Answer: To some extent 54. Does your agency use cloud services for any of the following? (Choose all that apply) Answer: Email; Communication tools other than email (calendars, messaging apps, etc.); Administrative functions such as payroll, purchasing, and financial management; Mission/program-related functions; Customer Relationship Management; Case management; Office tools/software; Streaming services 55. Does your agency have documented and approved policies for cloud service use Does your ageti4�hove documented and approved policies and procedures to implement the guidelines for the transfer of permanent email record - NARA Bulletin 2018-01: Format Guidance for the Transfer of Permanent Electronic Records � Appendix A: Tables of File Formats,-Section 9 -Email? ( Answer 1 ,/Yes 2 X No 3 X Do not know Total Bar Response 58. Does your agency have documented and approved policies that address when employees have more than one agency-administered email accoun records must be preserved in an appropriate agency reaordkeeping system? (36 CFR 1236.22) *Examples of business needs may include but are not Ii separate accounts for public and internal correspondence � Creating accounts for a specific agency initiative which may have multiple users � Usin ! classified information and unclassified information Answer 1 2 3 No, pending final approval 4 �,/ No, under development X Do not know �,/ Yes X N0 Bar Response a Total 59. Does your agency have documented and approved policies that address the use of personal email accounts, whether or not allowed, that state tha � received by such accounts must be preserved in an appropriate agency recordkeeping system and that a complete copy of all email records created an. these accounts must be forwarded to an official electronic messaging account of the officer or employee no later than 20 days after the original creation record? (36 CFR 1236.22(b) and P.L. 113-187) Answer 1 Yes 2 X No 3 No, pending final approval 4 s/ Na, under development 5 X Do not krusv Total Bar Response 60. Does your agency's email system(s) retain the intelligent full names on directories or distribution lists to ensure identification of the sender and a email messages that are Federal records? (36 CFR 1236.22(a)(3)) 1 ' 2 3 Answer s/ Yes X No X Do not know Bar Response Total 61. What method(s) does your agency employ to capture and manage email records? (Choose all that apply) B Answer 1 2 3 5 6 X Other, please be specific: X Captured and stored in an email archiving system X Captured and stored loan electronic records management system X Captured and stored as personal storage table (Psi) files X Print and file X Not captured and email Is managed by the end-user in the native system Other, please be specific: Bar 62. What percentage of your email systems are cloud-based solutions? 0 Answer 1 X�" 2 3 X�" 4 � X 25% 5 X Less than 25% 6 X My agency does not use cloud services for email Bar Response a Approved for Release: 2021/08/10 C06821122 pproved for Release: 2021/08/10 C06821122 Bar Response 0 Approved for Release: 2021/08/10 C06821122 pproved for Release. 2021/08/10 C06821122 4 63. Does your agehey ()Valuate, monitor, or audit staff compliance with the agency's email preservation policies? (36 CFR 1220.18) Answer Bar Response 1 2 3 Yes X No X Do not know Total 64. How often does your agency evaluate, monitor, or audit staff compliance with the agency's email preservation policies? Answer X Annually 2 X Biennially 3 X Once every 3 years 4 X Ad hoc 5 X Do not know Bar Response Total 65. Does your agency have documented and approved policies and procedures in place to manage electronic messages including text messages, ch voice messages, and messages created in social media tools or applications? Answer X Yea 2 X No 3 x No, pending final approval 4 X No, under development 5 '1 X Do not know 6 X Other, please explain Bar Response Total Other, please explain 66. In which of the following areas does your agency have challenges with managing permanent electronic records, and related metadata, in an electr that apply) 0 Answer 1 2 3 4 7 a 10 11 X Email X Communication tools other than email (calendars, messaging apps, etc.) X Administrative functions such es payroll, purchasing, and financial management X Mission/program-related functions x Customer Relationship Management X Case management X Office tools/software X Streaming services X Other, please explain X MY agency does not have challenges managing permanent electronic records and related metadata X Do not know Other, please explain Regarding 066, CIA continues to make progress In managing permanent electronic records by incorporating records management requirements, policies, and processes Into tools and systems. Bar 67. Please add any additional comments about your agency for Section IV: Electronic Records. (Optional) Text Response 68. How many full-time equivalents (FTE) are in your agencyforganrzation? 0 Answer X 500,000 or more FTEs 2 X 100,000 � 499,999 FTEs 3 X 10,000 � 99,999 FTE8 4 X 1.000 � 9,999 F7E8 5 X 100 � 999 FTEa X 1 � 99 FTEs Bar Response Approved for Release: 2021/08/10 C06821122 Approved for Release: 2021/08/10 C06821122 7 X Not Available Total Approved for Release: 2021/08/10 C06821122 Approved for Release: 2021/08/10 C06821122 69. What other staff: offices, or program areas did you consult when you completed this self-assessment? (Choose all that apply) Answer 1 1 X Senior Agency Official � 2 X Office of the General Counsel 3 X Program Managers 4 X FOIA Officer 5 X Information Technology staff 6 X Records Liaison Officers or similar 7 X Administrative staff 8 X Other, please be specific: 9 X None Other, please be specific: Bar Response 70. How much time did it take you to gather the information to complete this self-assessment? Answer 1 X Under 3 hours 2 X More than 3 hour3 but less than 6 hours 3 . X More than 6 hours but less than 10 hours 4 X Over 10 hours Bar 1111�111=11111181111101111111111111=1111M1 Response Total 71. Did your agency's senior management review and concur with your responses to the 2018 Records Management Self-Assessment? Answer 1 X Yes 2 )( No 3 X Do not know Bar Response Total 72. Please provide your contact information. Name: Nancy Morgan Agency, Bureau, or Office: CIA Job Title: 1 Director, Infonnation Management Services Email Address: (b)(3) b 6 � Phone Number: (b)(3) 73. Are you the Agency Records Officer? if 2 Answer X Yes X No Bar Response Total 74. Please provide the Agency Records Officer's contact information. Name: Email Address: Phone Number: 75. Does your agency use your Records Management Self-Assessment scores to measure the effectiveness of the records management program? Answer 1 X Yes 2 X No 3 X Do not know 4 X Comments (Optional): (Please include In your comments how you use the Records Management Self-Assessment) Comments (Optional): (Please include In your comments how you use the Records Management Self-Assessment.) While the CIA does not use the FtMSA score to measure the effectiveness of the records management program, we do use the RMSA as a guideline for improvement Bar 76. Do you have any suggestions for improving the Records Management Self-Assessment next year? Text Response Approved for Release: 2021/08/10 C06821122 Approved for Release: 2021/08/10 C06821122 Text Response Please 0:111,;13110 a small 'waling growl to revise the reports to align with statutes and NARA Mission requtrements to ensure effective reporting to senior leadershHp. Consider consolidebng the thiim; reporis.ifito one to eliminate duplication and suppo �77. Qum_ Value (b)(3) Approved for Release: 2021/08/10 C06821122 pproved for Release. 2021/08/10 C06821122 78. SSID 'il� � Value ' Total 79. Score Statistic Value Mean Score 86.00 Score Standard Deviation 0.00 Weighted Mean of Items 1.08 Weighted Standard Deviation of Items 1.40 Items 80.00 Approved for Release: 2021/08/10 C06821122