|
|
| Pacific Islands Area Bulletins : Title 270 - Information Resources Managment : |
|
|
|
PIA Bulletin: |
PI-270-07-02 |
||||||||||||||
|
Subject: |
IRM - Handling of Private and Sensitive Information |
||||||||||||||
|
Date: |
July 19, 2007 |
||||||||||||||
|
Expiration Date: September 30, 2007 Background: Recently released National Bulletin 170-7-2 (should have been 270 – Information Resources Management) provided guidance on the handling and storage of private and sensitive information. (http://directives.sc.egov.usda.gov/viewerFS.aspx?id=3367). Examples of Private Data: Social Security number (SSN); tax ID; employee NFC ID; account numbers; and farm, tract, or common land unit (CLU) numbers. Examples of Sensitive Data: Name, address, or other geographic indicators; e-mail address; phone number; race; gender; ethnicity; disability; birth date. Private and sensitive information must be requested and used only when the transaction cannot be completed without it; it must be entered for that one transaction only and not stored for any future use unless it is absolutely necessary. When private and sensitive information must be stored, it must be secured. If this information is on paper, it must be secured in a locked file cabinet or drawer where only authorized employees have access to it. If this information is in electronic form, the computer system, including laptops, tablets, and desktops; USB drives; external hard drives; and similar devices, whether they are encrypted or not, must be secured in a way that prevents the information from being lost or stolen. If the electronic files cannot be secured, the information must not be stored on that computer or device. The information may be best secured in an access-controlled, shared-drive folder on a physically secure server that is accessed over the network. Action: Action: All employees will review files on their work station computers to assure that any file containing private and/or sensitive information is 1) necessary to retain, and 2) stored in a secure location from both electronic and physical theft. Supervisors must report to Keith Harada, Assistant Director for Administration by e-mail at keith.harada@hi.usda.gov that their employees have removed or secured any sensitive and/or private data from their computers and that all paper copies of sensitive or private material is in locked storage so that the NRCS PIA certification can be sent to National Headquarters by July 31, 2007. The following information will assist you with compliance to secure electronic files:
All employees will assure that “hard copy” files or documents containing private and/or sensitive data are secured from access by non-authorized persons. The following information will assist you with compliance to secure hard copy files:
/s/
LAWRENCE T. YAMAMOTO
Attachments: |
|||||||||||||||