Information sharing is fast becoming a top priority for federal, state, and local government agencies. After all, the only way to get a complete picture of anyone – from a local juvenile offender to an internationally suspected terrorist – is to gather information from a range of sources.
Information sharing is fast becoming a top priority for federal, state and local government agencies. After all, the only way to get a complete picture of anyone – from a local juvenile offender to an internationally suspected terrorist – is to gather information from a range of sources.
Data sharing is also becoming a regulatory requirement. In 2004 and again in 2005 the President of the United States issued Executive Orders (stemming from the Intelligence Reform and Terrorism Prevention Act of 2004) to enhance information sharing among agencies.
Yet some agencies are resistant, fearing security compromises and privacy concerns – particularly, determining and controlling who has access to highly sensitive information. Attempts have been made to create information sharing networks, such as the Joint Regional Information Exchange System (JRIES), but few have been successful. In that particular case, the differences in privacy and security needs and expectations between the parties involved became insurmountable.
The need, therefore, is to share information – and reap the benefits of information exchange – in a way that is secure and allows access only to authorized users while protecting data integrity. The goal is to create a single version of the truth while protecting the privacy of our nation’s citizens.
Is there a way to achieve this seemingly unattainable goal? Yes, in fact some agencies are already meeting this goal by focusing on how they share information and making unique choices based on individual agency needs.
Getting started
Rather than looking at specific products or services, the first step toward implementing an information-sharing environment is to take a closer look at the different ways organizations can share data. Examine and understand the varied types of architecture that will provide the underlying interconnections.
The architecture underneath your information sharing infrastructure will determine your levels of security and performance. In other words, the first action is to determine which architecture will be used. There are three primary options: centralized, peer-to-peer and hybrid.
Centralized: The centralized architecture is the simplest to implement, and one of the most powerful. In this method, all data to be shared is moved into a central hub, and all participants are connected to that hub. In other words, federal, state and local participants would move their most relevant information – the information they intend to share – to one place. This is essentially a data warehouse.
This approach has few functional drawbacks. It has a single point of control, which handles all queries against the shared data. Yet, because information is moved out of its original database and, potentially, outside original firewalls and existing access rights policies, security, privacy and trust are major areas of concern. For some organizations, this movement of data is unacceptable – or simply not possible.
Peer-to-peer: The second option is peer-to-peer. In this model, there are multiple hubs, one for each information-sharing participant. For example, federal, state and local organizations can remain in charge of their own databases and control access to that information. Participants implement their own policies to ensure access to sensitive data is not compromised.
In this scenario there is no central search capability. To find information within a peer-to-peer-based architecture the participant issues a search request that polls all participants’ hubs.
While inherently secure, the peer-to-peer model struggles with scalability and performance. Because every search request must be passed to every participant and processed by every participant, the system can be strained as more parties participate and share information.
Some organizations have combined their peer-to-peer architecture with a common search service, which can take some of the load off individual nodes and bring an increased level of consistency to information searches. However, the common search service still has no knowledge of which nodes it should poll for information – each node is still polled for every search.
Hybrid: An increasing number of organizations are looking to a “hybrid” model, which has elements of both centralized and peer-to-peer architectures.
In the hybrid model, participants create a central store of “identifying” data – data that determines a match when a search is issued. This is the only data kept centrally; all other information remains in its native database. The central hub acts as an index of “pointers” to data stored in original source systems. A central search service and a central matching and scoring facility called a Record Locator Service (RLS) process all searching and matching activity centrally.
In this scenario, participating law-enforcement groups may choose to share the names of individuals about whom they have information without sharing more details. The central hub would then respond “yes” to a search request, if there was a name match, pointing the searcher to the individual agency to get further details.
This approach has several benefits. Like the peer-to-peer model, the participants’ data does not move, keeping the information secure. Like the centralized model, since the central search service polls only those systems suspected of holding records of interest, performance issues are significantly reduced. Consistency and accuracy are additional benefits. Because all searches go through the same RLS, search results are more consistent across participant information.
Case in point
Many local and federal agencies assume they have to create a data warehouse in order to meet information sharing directives. That is simply not the case. In a hybrid scenario, for example, a local law-enforcement agency can maintain local autonomy and local control while sharing information on a national level or with federal agencies.
One regional law-enforcement group in the Puget Sound area in the Northwest United States is proof that this can be done.
Currently seven regional police departments, two county sheriffs’ departments and the Washington State Police all pool matching data in a central law-enforcement records management system. The FBI and Naval Criminal Investigative Service (NCIS) are also connected to that system, which is simultaneously sharing information with the state’s jail records management system.
The entire network is based on a hybrid architecture, with all parties sharing only basic search-related information. Each is maintaining security and protecting personally identifiable information of citizens while meeting federal information sharing mandates.
The same technology and configuration is being used to drive the development of the FBI’s National Data Exchange (N-DEx) network. While still in development, N-DEx is expected to link more than 18,000 law-enforcement participants in a way that will let regional organizations share basic search information while maintaining local autonomy and local control.
Information sharing is not all or nothing. You do not have to pool your most sensitive information in order to share it. Just remember the key to successful information sharing is to start with the right architecture for your situation and build from there, keeping an eye on security, access and control at every step of the initiative.
Schumacher is chief scientist at Initiate Systems, a provider of customer-centric master data management solutions. He can be reached at sschumacher@initiatesystems.com.




