DAOD 6500-1, Data Access
Table of Contents
Date of Issue: 2023-01-26
Application: This DAOD is a directive that applies to employees of the Department of National Defence (DND employees) and an order that applies to officers and non-commissioned members of the Canadian Armed Forces (CAF members).
Approval Authority: Assistant Deputy Minister (Data, Innovation and Analytics) (ADM(DIA))
Enquiries: Director Data Policy and Digital Innovation (DDPDI)
access by default (accès par défaut)
The principle by which access to data or information is made available unless a significant risk associated with such access can be demonstrated. (Defence Terminology Bank record number to be assigned)
big data (mégadonnées)
Data produced in high volume, at high speed and in various formats, and which is too complex to be handled with traditional data-processing software. (Defence Terminology Bank record number 695863)
data (données)
Set of values of subjects with respect to qualitative or quantitative variables representing facts, statistics, or items of information in a formalized manner suitable for communication, reinterpretation, or processing. (Policy on Service and Digital, Treasury Board)
Note: In the DND and the CAF, data is created, collected and used both in military operations and exercises, and in corporate administrative processes.
data asset (ressource des données)
An entity comprised of data from any source that can be governed and managed and that has potential to provide value or produce benefit. This can include data sets, databases, big data, and system and application output files. (Defence Terminology Bank record number 696417)
data domain (domaine des données)
A functional grouping of data assets governed by a shared set of principles, processes, standards and best practices.
Notes:
- There are three categories of data domains in the DND and the CAF: corporate, common and operational.
- A data domain can impact several level one advisor organizations. (Defence Terminology Bank record number to be assigned)
data governance (gouvernance des données)
A system of decision rights and accountabilities applicable to data-related processes.
Note: This system describes which action can be taken on which data asset, by whom, under which circumstances and using which methods. (Defence Terminology Bank record number 695865)
data management (gestion des données)
The development, execution and supervision of plans, policies, programs and practices that deliver, control, protect and enhance the value of data and information assets throughout their lifecycles. (Defence Terminology Bank record number 27521)
data quality (qualité des données)
A degree or level of confidence that the data provided meets requirements of the data user in terms of characteristics such as accuracy, completeness and reliability. (Defence Terminology Bank record number 33436)
data steward (responsable des normes de données)
The individual responsible for the life cycle of the data in a specific system or functional area. (Defence Terminology Bank record number 33440)
domain (domaine)
A specific field of knowledge or expertise. (Defence Terminology Bank record number 21857)
information (information)
The representation that a human or a machine assigns to data, facts or knowledge by means of known conventions such as reports, events, processes, decisions, ideas or opinions in any medium or form. (Defence Terminology Bank record number 696374)
information technology (technologie de l’information)
Involves both technology infrastructure and information technology applications. Technology infrastructure includes any equipment or system that is used in the automatic acquisition, storage, manipulation, management, movement, control, display, switching, interchange, transmission or reception of data or information. Information technology applications include all matters concerned with the design, development, installation and implementation of information systems and applications to meet business requirements. (Defence Terminology Bank record number 3161)
interoperability (interopérabilité)
The ability of different types of electronic devices, networks, operating systems, and applications to work together effectively, without prior communication, to exchange information in a useful and meaningful manner. (Policy on Service and Digital, Treasury Board)
reference data (données de référence)
Data that defines a set of permissible values that are used by other data fields and do not generally change, for example, units of measurement and country codes. (Defence Terminology Bank Record number 696420)
Context
3.1 The CDS/DM Joint Directive on Data Management (the Joint Directive):
- provides that ensuring access to data to increase operational efficiency is a strategic objective for defence data management;
- directs ADM(DIA), as functional authority for data management and data governance, to introduce new policy instruments, standards and guidance to advance the strategic objectives of the Joint Directive;
- provides that level one (L1) organizations are expected to adopt a posture of data access by default within the DND and the CAF, withholding data only if they can articulate a specific operational risk to disclosure;
- provides that, with increased access to data across the DND and the CAF, comes the expectation that there will be increased vigilance and monitoring for unauthorized access or disclosure; and
- directs that Assistant Deputy Minister (Information Management) (ADM(IM)) will work with ADM(DIA) to develop and implement a risk-based data security approach to ensure that data can be easily accessible.
3.2 The Treasury Board Policy on Service and Digital:
- outlines the responsibility of departments to maximize the release of their information and data as open resources, while respecting information security, privacy and legal requirements; and
- applies to all data created, collected, held, used, shared or managed in any repository or system, in any format, and at any point in the data life cycle, regardless of origin.
Objective
3.3 The objective of this DAOD is to establish the roles, responsibilities and processes to facilitate timely access to data for planning, operations, decision support, and research and development, in the DND and the CAF.
Expected Results
3.4 The expected results of this DAOD in the DND and the CAF are:
- improved governance and management of data as a shared and strategic asset through a data stewardship model;
- the implementation of an access-by-default approach to data; and
- the implementation of a flexible, risk-based security approach to protect data from unauthorized access, use, sharing, disclosure, alteration or deletion.
General
4.1 The DND and the CAF must establish accurate, consistent, integrated and authoritative data that is managed as a shared and strategic asset to support the DND and CAF mandate.
Process
4.2 L1s must ensure that DND and CAF data in their organizations is:
- searchable and findable across DND and CAF platforms, through unique identifiers, accessible indices, catalogues, tools, knowledge and support, to enable data users to locate data;
- interoperable across different data domains and systems using shared terminology, metadata and reference data that allow for data content, context and meaning to be preserved;
- accessible to authorized users based on standardized processes for authentication and authorization;
- trusted by the use of enterprise-wide data quality and data governance frameworks, standards, platforms and tools;
- able to be securely shared to enhance operations and improve performance;
- usable for the purposes for which it is collected and capable of subsequent reuse in other contexts;
- secured from risks and threats such as unauthorized access, use, sharing, disclosure, alteration or deletion, using a flexible risk-based approach; and
- disposed of in accordance with established retention periods applicable to DND and CAF data.
Data Access
4.3 The DND and the CAF must promote timely data access and sharing through the development of policies, directives, instructions and standards.
4.4 The DND and the CAF must protect security and privacy as required through role-based data access, appropriate authentication, authorization, encryption and an audit trail.
4.5 Decisions on data access must be taken through the data governance structure established in the Data Governance Framework.
4.6 Decisions about data access must be timely, transparent, documented and auditable.
Monitoring
4.7 ADM(DIA) must monitor the effectiveness of this DAOD.
Disputes and Conflicts
4.8 Any dispute over data access, or any conflict between the instructions in this DAOD and those in other instruments, should be referred to the Chief Data Officer, who will determine a process for resolution. The Defence Data Management Board (DDMB) has final decision-making authority on data access.
4.9 Those with responsibility for data under the Data Governance Framework may withhold access only if a specific operational risk, such as security, privacy, confidentiality and intellectual property concern, can be articulated.
Compliance
5.1 DND employees and CAF members must comply with this DAOD. Should clarification of the policies or instructions set out in this DAOD be required, DND employees and CAF members may seek direction through their channel of communication or chain of command, as appropriate. Managers and military supervisors have the primary responsibility for and means of ensuring the compliance of their DND employees and CAF members with this DAOD.
Consequences of Non-Compliance
5.2 DND employees and CAF members are accountable to their respective managers and military supervisors for any failure to comply with the direction set out in this DAOD. Non-compliance with this DAOD may result in administrative action, including the imposition of disciplinary measures, for a DND employee, and administrative or disciplinary action, or both, for a CAF member. Non-compliance may also result in the imposition of liability on the part of Her Majesty in right of Canada, DND employees and CAF members.
Note – In respect to the compliance of DND employees, see the Treasury Board Framework for the Management of Compliance for additional information.
Responsibility Table
6.1 The following table identifies the responsibilities associated with this DAOD:
The, a or an … | is or are responsible for … |
---|---|
ADM(IM) |
|
Assistant Deputy Minister (Defence Research and Development Canada) |
|
ADM(DIA) |
|
L1s |
|
data users |
|
DND employees and CAF members |
|
Acts, Regulations, Central Agency Policies and Policy DAOD
- Access to Information Act
- Financial Administration Act
- Library and Archives of Canada Act
- National Defence Act
- Official Languages Act
- Privacy Act
- Report to the Clerk of the Privy Council: A Data Strategy Roadmap for the Federal Public Service
- Values and Ethics Code for the Public Sector
- Framework for the Management of Compliance, Treasury Board
- Policy on Service and Digital, Treasury Board
- Policy on Government Security, Treasury Board
- Directive on Automated Decision-Making, Treasury Board
- Directive on Open Government, Treasury Board
- Directive on Service and Digital, Treasury Board
- Guideline on Service and Digital, Treasury Board
- Government of Canada Digital Standards: Playbook, Treasury Board
- DAOD 6500-0, Data Management and Analytics
Other References
- DAOD 1002-0, Administration of the Privacy Act
- DAOD 2006-1, Procedures for the Safeguarding and Authorized Disclosure of Information in the DND and the CAF
- DAOD 2011-0, Enterprise Architecture
- DAOD 3000-0, Materiel Acquisition and Support
- DAOD 3003-0, Controlled Technology Access and Transfer
- DAOD 3003-1, Management, Security and Access Requirements Relating to Controlled Goods
- DAOD 3008-0, Intellectual Property
- DAOD 5050-0, Canadian Forces Personnel Records
- DAOD 5050-1, Canadian Forces Personnel Records of the Director General Military Careers and the Director Human Resources Information Management, and Service Estate Records of the Judge Advocate General
- DAOD 6000-0, Information Management and Information Technology
- DAOD 6001-0, Information Management
- DAOD 6001-1, Information Management Programme
- DAOD 6003-0, Information Technology Security
- DAOD 6003-1, Information Technology Security Programme
- DAOD 6003-2, Information Technology Security Risk Management
- DAOD 6003-3, Information Technology Security Monitoring and Auditing
- DAOD 7023-0, Defence Ethics
- DAOD 8001-0, Canadian Special Operations Forces Command – Information and Asset Security
- DAOD 8001-1, Canadian Special Operations Forces Command – Information and Asset Security Management
- DAOD 8008-0, Defence Intelligence
- Department of National Defence and Canadian Forces Code of Values and Ethics
- Strong, Secure, Engaged: Canada’s Defence Policy
- CDS/DM Joint Directive on Data Management
- The Department of National Defence and Canadian Armed Forces Data Strategy
- Data Governance Framework
- ARA Framework for ADM(DIA) (available in English only)
- DND/CAF Open Data Framework (TBD)
Report a problem or mistake on this page
- Date modified: