290 likes | 1.16k Vues
Personally Identifiable Information (PII). An overview January 16, 2008. Objective:. Protect personal identity Combat theft. What is PII?.
E N D
Personally Identifiable Information (PII) An overview January 16, 2008
Objective: • Protect personal identity • Combat theft
What is PII? • USDA considers PII to be information that can be used to distinguish or trace an individual's identity, such as your social security number or medical records, or information that when combined or used with other identifying information is linked or linkable to a specific individual.
Steps to Safeguard Examples include: • Encrypt electronic PII • Remove PII • Restrict access • Confidentiality statement
Steps to Safeguard (cont) • Alternate unique identifier • Secure areas only • Transporting/Shipping PII (AS-2137) • Secure destruction (AS-2087) • Terminate system access
Encrypting Sensitive/Privacy Data • WinZip • Page 4 “Encrypting” handout • IT Help desk # 690-1000 • IRM-378
Shipment of PII • Encrypt before shipping • Prevent inadvertent opening • Signs of tampering apparent • Approved methods: • FedEX and USPS • Exception: single envelope • AD-2137
Terminating Info System Access • Terminate access: • Reassigned, separated, deceased • Modify access: • Reassigned within HRD • FSA-13A • IRM-400
Breach Policy • One (1) hour • OCIO, Office of Cyber Security • (DM) 3505-000