Essential information only

Connect with state & local government leaders
 

Connecting state and local government leaders

Agencies starting to produce data breach and notification procedures.

The surest way for agencies to avoid losing personal information would be to not have it in the first place. But since that's not possible, the next best step is to keep only what's necessary.That's part of the idea behind the Office of Management and Budget's order that agencies get better control over personal information held in their paper and electronic files and develop policies for responding when those controls are breached.The prime directive in OMB Memo 07-16 for reducing the likelihood that such information is stolen is to 'limit its collection,' said Tim Grance, manager of systems and network security at the National Institute of Standards and Technology. There is no need to manage or protect what you do not have.The memo, issued May 22, is a response to heightened concerns about identity theft and the large amount of sensitive information held in government systems, some of it unnecessarily.Although agency policies must spell out conditions for notification of potential victims of data theft, the memo stops short of actually requiring such notification.Agencies have until Sept. 22 to complete and implement their policies, and some already are well on their way toward compliance.The Federal Trade Commission had its policy in place by the end of June, chief privacy officer Marc Groman said during a recent panel discussion on the OMB memo.It is a broad policy that establishes a team to respond to data breaches and defines a 13-step plan for evaluating a breach's severity. This rapid response is due in part to the fact that FTC is a small agency, Groman said. But work had begun on the policy even before the guidelines were issued.The current requirements had been foreshadowed by a similar memo in 2006, Groman said. 'It wasn't news to us in May of 2007.'The Homeland Security Department has its policy drafted and is reviewing it, said chief privacy officer Hugo Teufel III. The policy is called the Personally Identifiable Information Guidelines, and 'this PIIG should fly by the end of August,' he said.Work on the DHS policy also began before the OMB memo was issued, Teufel said. It was spurred by the loss in April of a drive containing 100,000 personnel records from the Transportation Security Administration. Despite the security breach that the loss represented, Teufel called the department's response to it 'a model of how things should be done.' The department began codifying that response in a policy memorandum shortly after the breach occurred.The requirement that agencies develop formal policies for dealing with breaches of personal information was recommended in the April report of the president's Identity Theft Task Force, established last year. The new guidelines expand on recommendations issued by OMB in its June 2006 memo, 'Protection of Sensitive Agency Information,' which spurred FTC's policy. In addition to reminding agencies that they already should be following existing NIST guidance for protecting information, the 2006 memo recommended encryption, two-factor authentication, automatic time-outs and logs of data extractions (see chart).The May 2007 memo focuses specifically on what it calls personally identifiable information, which contains enough data ' such as names, Social Security number and addresses ' to allow an individual to be identified and create a risk of identity theft if exposed.The current memo recaps many of the requirements in last year's memo in addition to NIST guidelines for data protection, but it adds additional requirements, including a policy for notification of potential victims when there has been a breach.Although OMB requires that all data breaches be reported to US-CERT within one hour of discovery, the new memo does not require notification of potential victims when personally identifiable information is exposed, acknowledging that notification is 'not always necessary or desired.' It does not set thresholds for when notification should occur.Each agency must develop its own thresholds and policy for notification, educate its employees about requirements to report breaches and losses, and specify disciplinary action when that policy is violated.Agencies also are required to identify and review their current holdings of personally identifiable information and reduce the use of Social Security numbers where possible.A discussion of the new OMB requirements was hosted in Washington this month by Homeland Defense Journal.Although participants from DHS, FTC, NIST and the Justice Department agreed that limiting collection of data and the use of Social Security numbers is key to improving protections against identity theft, 'it is going to be a while' before SSNs and other data are scrubbed from files, said Justice chief information technology security technologist Mischel Kwon. In the meantime, 'education is our interim solution.'Education is an integral part of the FTC policy. All employees must understand their responsibility to report incidents before the breach notification team can work, Groman said.The policy, which spells out disciplinary actions for violations, is included in the FTC administrative manual and in the agency's mandatory computer training program. Each employee must sign a PIIG policy compliance form.Grance said NIST is responding to the OMB memo in its usual way: 'Writing publications.' A series of publications will be released on protecting personally identifiable information and other sensitive data.'In a few weeks, we'll come out with something on virtual private networks using' Secure Sockets Layer for remote access, he said.Other publications will cover storage and encryption technology for users and enterprises, remote access security, incident handling and operating system security.Implementing a meaningful breach response policy will require common sense as well as technology, Grance said. Responsibility will be broad-based and extend well beyond the traditional confines of IT and security shops.'All the groups that never had to talk to each other now need to talk to each other and live with each other,' he said.

OMB's Marching Orders

The Office of Management and Budget's June 2006 memo, 'Protection of Sensitive Agency Information,' recommended that agencies:

  • Encrypt all data on mobile computers and other devices carrying agency data.
  • Use two-factor authentication for remote access to this data.
  • Implement an automatic time-out with re-authentication after 30 minutes of inactivity on a connection to sensitive data.
  • Log all data extractions and confirm that data has been erased after 90 days.

OMB's memo in May required agencies to develop notification policies, educate employees, establish punishments for violations, and review and reduce where possible their holdings of personally identifiable information. 'It is important to emphasize that a few simple and cost-effective steps may well deliver the greatest benefits,' the memo said. It recommended that agencies:

  • Reduce the volume of data collected and retained to the minimum necessary.
  • Limit access to the data to those with a need for it.
  • Use encryption, strong authentication procedures and other security controls to keep data out of the hands of unauthorized persons.

' William Jackson






Big concern























When to tell
























NEXT STORY: Secure that line!

X
This website uses cookies to enhance user experience and to analyze performance and traffic on our website. We also share information about your use of our site with our social media, advertising and analytics partners. Learn More / Do Not Sell My Personal Information
Accept Cookies
X
Cookie Preferences Cookie List

Do Not Sell My Personal Information

When you visit our website, we store cookies on your browser to collect information. The information collected might relate to you, your preferences or your device, and is mostly used to make the site work as you expect it to and to provide a more personalized web experience. However, you can choose not to allow certain types of cookies, which may impact your experience of the site and the services we are able to offer. Click on the different category headings to find out more and change our default settings according to your preference. You cannot opt-out of our First Party Strictly Necessary Cookies as they are deployed in order to ensure the proper functioning of our website (such as prompting the cookie banner and remembering your settings, to log into your account, to redirect you when you log out, etc.). For more information about the First and Third Party Cookies used please follow this link.

Allow All Cookies

Manage Consent Preferences

Strictly Necessary Cookies - Always Active

We do not allow you to opt-out of our certain cookies, as they are necessary to ensure the proper functioning of our website (such as prompting our cookie banner and remembering your privacy choices) and/or to monitor site performance. These cookies are not used in a way that constitutes a “sale” of your data under the CCPA. You can set your browser to block or alert you about these cookies, but some parts of the site will not work as intended if you do so. You can usually find these settings in the Options or Preferences menu of your browser. Visit www.allaboutcookies.org to learn more.

Sale of Personal Data, Targeting & Social Media Cookies

Under the California Consumer Privacy Act, you have the right to opt-out of the sale of your personal information to third parties. These cookies collect information for analytics and to personalize your experience with targeted ads. You may exercise your right to opt out of the sale of personal information by using this toggle switch. If you opt out we will not be able to offer you personalised ads and will not hand over your personal information to any third parties. Additionally, you may contact our legal department for further clarification about your rights as a California consumer by using this Exercise My Rights link

If you have enabled privacy controls on your browser (such as a plugin), we have to take that as a valid request to opt-out. Therefore we would not be able to track your activity through the web. This may affect our ability to personalize ads according to your preferences.

Targeting cookies may be set through our site by our advertising partners. They may be used by those companies to build a profile of your interests and show you relevant adverts on other sites. They do not store directly personal information, but are based on uniquely identifying your browser and internet device. If you do not allow these cookies, you will experience less targeted advertising.

Social media cookies are set by a range of social media services that we have added to the site to enable you to share our content with your friends and networks. They are capable of tracking your browser across other sites and building up a profile of your interests. This may impact the content and messages you see on other websites you visit. If you do not allow these cookies you may not be able to use or see these sharing tools.

If you want to opt out of all of our lead reports and lists, please submit a privacy request at our Do Not Sell page.

Save Settings
Cookie Preferences Cookie List

Cookie List

A cookie is a small piece of data (text file) that a website – when visited by a user – asks your browser to store on your device in order to remember information about you, such as your language preference or login information. Those cookies are set by us and called first-party cookies. We also use third-party cookies – which are cookies from a domain different than the domain of the website you are visiting – for our advertising and marketing efforts. More specifically, we use cookies and other tracking technologies for the following purposes:

Strictly Necessary Cookies

We do not allow you to opt-out of our certain cookies, as they are necessary to ensure the proper functioning of our website (such as prompting our cookie banner and remembering your privacy choices) and/or to monitor site performance. These cookies are not used in a way that constitutes a “sale” of your data under the CCPA. You can set your browser to block or alert you about these cookies, but some parts of the site will not work as intended if you do so. You can usually find these settings in the Options or Preferences menu of your browser. Visit www.allaboutcookies.org to learn more.

Functional Cookies

We do not allow you to opt-out of our certain cookies, as they are necessary to ensure the proper functioning of our website (such as prompting our cookie banner and remembering your privacy choices) and/or to monitor site performance. These cookies are not used in a way that constitutes a “sale” of your data under the CCPA. You can set your browser to block or alert you about these cookies, but some parts of the site will not work as intended if you do so. You can usually find these settings in the Options or Preferences menu of your browser. Visit www.allaboutcookies.org to learn more.

Performance Cookies

We do not allow you to opt-out of our certain cookies, as they are necessary to ensure the proper functioning of our website (such as prompting our cookie banner and remembering your privacy choices) and/or to monitor site performance. These cookies are not used in a way that constitutes a “sale” of your data under the CCPA. You can set your browser to block or alert you about these cookies, but some parts of the site will not work as intended if you do so. You can usually find these settings in the Options or Preferences menu of your browser. Visit www.allaboutcookies.org to learn more.

Sale of Personal Data

We also use cookies to personalize your experience on our websites, including by determining the most relevant content and advertisements to show you, and to monitor site traffic and performance, so that we may improve our websites and your experience. You may opt out of our use of such cookies (and the associated “sale” of your Personal Information) by using this toggle switch. You will still see some advertising, regardless of your selection. Because we do not track you across different devices, browsers and GEMG properties, your selection will take effect only on this browser, this device and this website.

Social Media Cookies

We also use cookies to personalize your experience on our websites, including by determining the most relevant content and advertisements to show you, and to monitor site traffic and performance, so that we may improve our websites and your experience. You may opt out of our use of such cookies (and the associated “sale” of your Personal Information) by using this toggle switch. You will still see some advertising, regardless of your selection. Because we do not track you across different devices, browsers and GEMG properties, your selection will take effect only on this browser, this device and this website.

Targeting Cookies

We also use cookies to personalize your experience on our websites, including by determining the most relevant content and advertisements to show you, and to monitor site traffic and performance, so that we may improve our websites and your experience. You may opt out of our use of such cookies (and the associated “sale” of your Personal Information) by using this toggle switch. You will still see some advertising, regardless of your selection. Because we do not track you across different devices, browsers and GEMG properties, your selection will take effect only on this browser, this device and this website.