Schreibman v. U.S. Department of Commerce

785 F. Supp. 164, 1991 U.S. Dist. LEXIS 19777, 1991 WL 325467
District Court, District of Columbia·Decided June 28, 1991·No. Civ. A. 91-0339·Published·Cited by 5 cases

Opinion

MEMORANDUM

JOHN GARRETT PENN, Chief Judge.

This is an action under the Freedom of Information Act (“FOIA”), 5 U.S.C. section 552, in which plaintiff Vigdor Schreibman seeks access to records or documents pertaining to federal computer systems from defendant U.S. Department of Commerce (“DOC”). This case presently comes before the Court on a Motion to Dismiss filed by DOC. After careful consideration of the motion, the opposition thereto, and the entire record in this case, the Court concludes that the motion should be granted in part and denied in part.

BACKGROUND

On August 27, 1990, plaintiff filed a FOIA request with the National Institute of Standards and Technology (“NIST"). Plaintiff sought access to records regarding federal computer systems identified by the Land and Natural Resources Division of the Department of Justice pursuant to the Computer Security Act of 1987. Plain *165 tiff also sought documents concerning plans for the security and privacy of those computer systems. Finally, plaintiff requested copies of the Presidential directive establishing data security policy and standards. On September 14, 1990, NIST provided plaintiff with a copy of the requested Presidential directive. NIST also informed plaintiff that the other records sought were exempt from disclosure. By letter dated August 27, 1990, plaintiff filed an administrative FOIA appeal. The appeal was decided by DOC on December 21,1990. DOC advised plaintiff that the withheld documents were exempt from disclosure. DOC has withheld five documents in their entirety on the basis of exemptions (b)(2) and (b)(5) of FOIA. On February 14, 1991, plaintiff filed this suit alleging that the requested records have been improperly withheld.

DISCUSSION

Defendants argue that this case should be dismissed because no documents have been improperly withheld and the documents are exempt from public disclosure under FOIA exemptions 2 and 5. Although defendants have filed a motion to dismiss, the Court will treat the motion as one for summary judgment because the parties have submitted affidavits and other documents in support of their positions. A motion for summary judgment must be granted if “there is no genuine issue as to any material fact and ... the moving party is entitled to a judgment as a matter of law.” Fed.R.Civ.P. 56(c). The burden of justifying nondisclosure of requested documents in a FOIA case is placed upon the defendant agency. Summary judgment is appropriate where the agency’s affidavits are sufficiently detailed to explain each properly claimed FOIA exemption. In addition, there must be no contradictory evidence on the record, nor evidence of bad faith on the part of the agency. Military Audit Project v. Casey, 656 F.2d 724, 728 (D.C.Cir.1981). The Court must review the agency’s claimed exemptions de novo, but affords affidavits “substantial weight” in the review. The agency must create as full a record as possible, with descriptions of the nature of documents and agency justifications for nondisclosure. The court must determine if there is a sufficient basis for making a decision.

DOC has submitted the Declaration of Dennis K. Branstad, Acting Chief of the Computer Security Division, National Institute of Standards and Technology (hereinafter “Branstad Declaration”) pertaining to the files identified as responsive to plaintiff’s request. The Branstad Declaration identifies those records which are responsive to plaintiff’s FOIA request and explains the basis for the various FOIA exemptions invoked by DOC. The five documents withheld from disclosure are each titled “Computer Security Plan Review Project Comments and Recommendations.” They contain an evaluation of the five computer security plans submitted to NIST by the Land and Natural Resources Division at the Department of Justice pursuant to the requirements of the Computer Security Act of 1987, 40 U.S.C. section 759. This Act requires each federal agency to identify its computer systems which are under their supervision and which contain sensitive information, and to develop a computer security plan to protect the system. Such plans are to be submitted to NIST and the National Security Agency for advice and comment. According to the Branstad Declaration, the five documents withheld from disclosure consist of the advice and comment that resulted from a review of the five computer security plans submitted by the Land and Natural Resources Division of the Department of Justice. These records note problems with the computer security plans and contain advice and recommendations on measures that can be taken to insure the security of the computer systems. In Branstad’s view, these documents are classic “vulnerability assessments” and are exempt from public disclosure under FOIA.

To the extent that the documents withheld constitute an assessment of federal computer security plans, the Court is satisfied that the DOC has met its burden of showing that the withheld materials are protected from disclosure under exemption *166 2. FOIA exemption 2 protects from mandatory disclosure material “related solely to the internal personnel rules and practices of an agency.” 5 U.S.C. section 552(b)(2). The withheld documents meet the test established in Crooker v. Bureau of Alcohol, Tobacco & Firearms, 670 F.2d 1051, 1074 (D.C.Cir.1981) (en banc). Under Crooker, an agency may withhold material under exemption 2 when it is able to demonstrate (1) that the material is “predominantly internal” and (2) disclosure of the material would risk circumvention of law or agency regulations.

First, the documents are “predominantly internal.” The documents are evaluations created by one federal agency, NIST, for the sole purpose of advising another agency, the Land and Natural Resources Division at the Department of Justice. According to the Branstad Declaration, these assessments are not made available to any other individual or entity other than the agency that developed the security plan.

Also applicable is the second prong of the Crooker analysis, which protects material the disclosures of which would risk circumvention of lawful agency laws or regulations. In this case, the requested documents contain an assessment of the vulnerabilities of the computer security plans submitted by the Land and Natural Resources Division. If public disclosure were required, there would be a significant risk that the security required for the computer systems would be circumvented. The government correctly argues that if this information was disclosed to the public, there would be no constraint on the ability of persons to utilize this information to obtain unauthorized access to the system resulting in the potential alternation, loss, damage or destruction of data contained in the computer system.

Free access — add to your briefcase to read the full text and ask questions with AI

Schreibman v. U.S. Department of Commerce, 785 F. Supp. 164, 1991 U.S. Dist. LEXIS 19777, 1991 WL 325467 (D.D.C. 1991).

785 F. Supp. 164 (Schreibman v. U.S. Department of Commerce) — published by Counsel Stack Legal Research, free access to 12M+ legal documents.

Related

Electronic Privacy Information Center v. National Security Agency
988 F. Supp. 2d 1 (District of Columbia, 2013)
Milner v. Department of Navy
Supreme Court, 2011
Milner v. Department of the Navy
131 S. Ct. 1259 (Supreme Court, 2011)