Status: Archived
Approved Date: February 10, 2024
PII Definition
Personally Identifiable Information (PII) is information used to distinguish or trace an individual's identity, such as their name, Social Security Number, biometric records, alone or when combined with other personal or identifying information linked or linkable to a specific individual. An item such as date and place of birth, mother's maiden name, or father's surname is PII, regardless of whether combined with other data. SSA defines a PII loss as a circumstance when an employee, contractor or agent has reason to believe that information on hard copy or in electronic format, which contains PII provided by SSA, left the Agency's custody or the Agency disclosed it to an unauthorized individual or entity. PII loss is a reportable incident.
General
Remote access and SSA-provided information
Access management and administration
Safeguarding the SSA-provided PII information while in use, at rest, during transmission or after archiving
Management oversight and Quality Assurance
Annual Certification (NDA, Security Awareness Training Attestation, proper use and securty of systems) for Staff or Contractors with access to systems with SSA-provided data
Incident reporting
To be included in NDE COOP document:
5. Data Security in case of a disastrous event
a. Business Impact Analysis and Security of SSA-provided information
- In case of a complete power or network outage during a disaster event:
BIA: VR would not be able to accept the SSA provided data, as the transfer service (FTP) relies on a working network connection. This would cause VR to miss the scheduled quarterly transfer, but this service could be resumed once the network is operational.
Security of SSA-provided information: Not Applicable, VR would not possess any SSA-provided information in this case.
- In case of working network but physical inaccessibility to the building:
BIA: There should be limited to no impact to business. Transfer and purging operations can be performed off-site.
Security of SSA-provided information: Security would be enforced by existing processes, namely that the data would be co-mingled with existing VR data, and original files securely deleted.
- In case of building destruction:
BIA: Signifcant impact/inability to process ticket to work reimbursement payments. VR would also be dependent on STC re-enabling their process, after which point VR would need to provide a secure and encrypted FTP storage space.
Security of SSA-provided information: Security would be enforced by the locked server cabinet. Furthermore, the FTP storage is encrypted, so in case SSA-provided data resided on the hard drive, after a power shutdown, it would be in an encrypted state, and only VR authorized administrators would have the ability to unencrypt it.