Attachment 11 -OIT Rules of the Road.pdf
PDF 546 KB Posted
- Attached to
- Technical Surveillance Countermeasure Services Federal contract opportunity
- Solicitation number
- 50310220Q0059
- Issued by
- Securities and Exchange Commission
View the file
Other files for this federal contract opportunity
| File | Type | Posted |
|---|---|---|
| Amendment 2 to RFQ 50310220Q0059.pdf | ||
| Questions and Answers_June 25 2020.pdf | ||
| Amendment 1 to RFQ 50310220Q0059.pdf | ||
| Questions and Answers_June 19 2020.pdf | ||
| Attachment 10 - Dec for Fed Employ OF 306.pdf | ||
| Attachment 9 - Request for PERSEC Determination.pdf | ||
| Attachment 7 - Auth for Release of Credit Info.pdf | ||
| Attachment 4rev - Past Performance Questionnaire.pdf | ||
| Attachment 6 - Contract Terms and Conditions.pdf | ||
| Attachment 8 - Privacy Act Statement.pdf | ||
| Attachment 3 - SOW.pdf | ||
| RFQ 50310220Q0059.pdf | ||
| Attachment 2 - NDA - Contractor Personnel.pdf | ||
| Attachment 4 - Past Performance Questionnaire.pdf | ||
| Attachment 1 - NDA - Contractor Entity.pdf | ||
| Attachment 5 - Price Spreadsheet.xlsx | XLSX spreadsheet |
Show all 16
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
OP 24-04B Rules of the Road v9 (Rev. 1) (formerly 24-04.A01) December 21, 2017
Office of Information Technology Washington, DC 20549
Rules of the Road
Table of Contents
Rule #1: Don’t Conduct Unauthorized Business on SEC Automated Systems or Networks Rule #2: Don’t Abuse the Privilege of Using the Internet/Intranet Rule #3: Use E-mail Responsibly and Sensibly Rule #4: Save Federal Records Rule #5: Protect Your Computer Passwords Rule #6: Protect the Privacy of Others Rule #7: Don’t Transmit Non-public or Sensitive Information over Non-secure Systems Rule #8: Don’t Copy or Misuse Copyrighted Material, Including Software Rule #9: Protect SEC Network and Automated System Assets Rule #10: Use Remote Connections and Wireless/Handheld Devices Responsibly Rule #11: Don’t Send or Read Text Messages or E-mail while Operating a Motor Vehicle Rules of the Road Exceptions and Waivers
Purpose
The U.S. Securities and Exchange Commission (SEC) “Rules of the Road” is the agency’s official “Acceptable Use Policy” for information technology. This document is intended to help you use agency computing and network facilities responsibly, safely and efficiently, thereby maximizing the availability of these resources to everyone within the agency. All SEC users (i.e., federal employees, interns, visiting fellows, contractors and anyone else who is granted access to SEC systems) must follow the Rules of the Road when using SEC Information Technology (IT) resources, except as described in the “Rules of the Road Exceptions and Waivers” section.
IT resources subject to the “Rules of the Road” include any government-owned IT equipment, software, capability or any item consisting of or containing SEC data, such as:
Desktop computers, laptop computers, handheld devices, e.g., a BlackBerry® device, Apple devices, and/or other portable devices, such as USB (Universal Serial Bus) drives, external hard drives, optical storage media (such as CDs or DVDs), etc.
Printers, scanners and other external peripheral devices that may connect to a computer or to the SEC network Network connectivity, including connection to non-SEC networks with SEC devices The SEC electronic mail (e-mail) system
SEC business areas may supplement or augment the “Rules of the Road” within their own organizations, provided such policies do not contradict, modify or relax the rules detailed here.
Your Responsibilities
The SEC’s Office of Information Technology (OIT) uses advanced technologies to secure the SEC network. However, OIT cannot do it effectively without your help. As an information system user, you play a critical role in safeguarding our IT assets and protecting the SEC’s data. As a federal employee, intern, visiting fellow or contractor of the SEC, you have a responsibility to adhere to the “Rules of the Road” at all times when using equipment connected to an SEC network. Your specific responsibilities include:
Following all SEC policies, processes and controls Protecting IT resources within your control or possession Notifying the OIT Service Desk at 202-551-HELP (extension 14357), and your supervisor when:
Attachment 11
SECURITIES AND EXCHANGE COMMISSION
SECURITIES AND EXCHANGE COMMISSION OP 24-04B Rules of the Road v9 (Rev. 1)
December 21, 2017
Office of Information Technology Washington, DC 20549
Rules of the Road o Your RSA SecurID® Token or any other IT resource assigned to you is lost or stolen o A device in your custody that may contain sensitive information has been lost or otherwise compromised (Note: See “Reporting Incidents” below for more information.)
Avoiding the use of SEC IT resources for any activity that:
o Discredits the agency (e.g., seeking, transmitting, collecting, downloading, or storing pornographic or sexually-explicit material) o Violates laws or statutes o Involves using public office for personal gain (e.g., by using SEC IT resources to conduct or facilitate a personal business or service offering) o Impedes the mission of the SEC
Ensuring that you do not disclose data to unauthorized persons Completing any security awareness training as directed by the Office of Information Technology
Please be aware that lists of prohibited uses presented throughout this policy are not comprehensive.
There may be situations not listed that could be harmful to the SEC’s reputation, data, or systems, and are therefore prohibited.
Consent to Monitoring
All users of SEC network resources, whether authorized or unauthorized, are subject to monitoring by OIT and by law enforcement officials. Such monitoring may be used as necessary in the course of any official investigation. Users are reminded that there is no expectation of privacy when using network resources and that they expressly consent to such monitoring, including retrieval and disclosure of information stored on other devices, such as hard drives or other media in use (e.g., USB drives, handheld devices, and CD-ROMs). Misuse of government computer resources, including the accessing or downloading of pornographic or sexually-explicit materials, may result in disciplinary action, up to and including dismissal, and, in some circumstances, criminal prosecution.
Reporting Incidents
Report immediately (i) security-related incidents, compromises, and/or violations or (ii) damage, theft, abuse, loss, or unauthorized use of government-owned computer hardware (including mobile devices) to the OIT Service Desk at 202-551-HELP (extension 14357) and your supervisor
You may also report incidents using askIT (https://seceamsprod.service-now.com/secsp?id=home), under “Report an IT Problem” in the “Get Help” menu. Due to the risks accompanying any security- or computer hardware-related incident, calling the OIT Service Desk is the preferred method of reporting as it will allow staff to address the incident immediately If you are a regional office employee or third party (e.g., contractor, intern), also alert your IT Specialist of any security- or computer hardware-related incidents
Evidence of violations of criminal law or other misconduct by SEC employees, interns, visiting fellows or contractors should be reported immediately to the SEC’s Office of Inspector General (OIG) hotline by calling 877-442-0854 or filing an online report with the OIG.
Personal Use of IT Resources
SEC users are permitted limited use of SEC IT resources for personal reasons during non-work time (i.e., lunch periods, authorized breaks, or weekends and holidays), provided that:
Such use is consistent with the “Rules of the Road” and other established SEC regulations, policies and procedures.
December 21, 2017
Office of Information Technology
This limited use does not disrupt or interfere with official business and involves minimal additional expense to the government.
This privilege may be revoked or limited at any time due to policy violations. For more information concerning use of SEC information resources, please see SEC Regulation (SECR) 24-4.3, “Use of SEC Office Equipment.”
Provisions for Privileged Users
If you are a user of SEC systems and IT resources with escalated access privileges (i.e., are a “privileged user” or an “Administrator”):
Use/access privileged accounts ONLY in the performance of your official duties and only as necessary to complete assigned tasks.
Do not make unauthorized changes to systems.
Do not deploy patches, updates, or upgrades except as authorized.
Do NOT conduct personal activities while logged into a privileged account.
Use different passwords for standard and privileged accounts.
Follow best business practices and privileged user training.
The SEC’s mission is to protect investors; maintain fair, orderly, and efficient markets; and facilitate capital formation. The SEC strives to promote a market environment that is worthy of the public's trust.
SEC IT resources, networks, and other computing resources are shared among SEC users to support the critical work of the agency. The SEC network provides access to SEC business systems that operate on the SEC IT infrastructure (which includes devices, systems, and networks), and to remote locations using secure technologies. The SEC network also provides access to the Internet and the intranet.
As an SEC user, you have an obligation to conduct your system activities in keeping with the SEC’s mission, goals and objectives. All use of SEC network and automated systems, including accessing the Internet, intranet, and e-mail, must be consistent with this purpose.
Authorized Uses of the SEC’s Network and Automated Systems:
Performance of job-related activities.
Exchange of information that supports the SEC mission, goals, and objectives.
Job-related professional development for SEC management and staff.
Communications and exchange of information intended to maintain job currency or gain additional knowledge that is directly or indirectly related to job functions.
December 21, 2017
Office of Information Technology
Prohibited Uses of the SEC’s Network and Automated Systems:
DO NOT use SEC IT resources for commercial purposes to conduct, support, or promote any type of personal business interests; or for the business interests of relatives, friends, or other persons. Examples of this prohibition include using an SEC computer in furtherance of personal business activities such as real estate business, consulting business, or operating an online “store.”
DO NOT interfere with the administrative functions of any SEC network or automated system or attempt to gain unauthorized rights or privileges to SEC networks or systems.
DO NOT use unapproved hardware or software on SEC networks or devices.
In the normal course of SEC operations and maintenance activities, system usage is monitored to ensure the continued operational effectiveness and integrity of the SEC network, systems, and other computing resources. You are reminded that such monitoring does occur.
Unauthorized or improper use may result in disciplinary action (up to and including removal), civil and criminal penalties, and financial liability for the cost of improper use. Misuse of SEC IT resources may constitute a federal criminal offense under the Computer Fraud and Abuse Act of 1986 (P.L. 99-474, 18 U.S.C. § 1030). Evidence of criminal activity or other misconduct will be provided to the SEC’s Office of Inspector General, which may refer the matter for criminal prosecution.
Access to the Internet is a privilege. Access may be revoked at any time for inappropriate conduct or non-compliance with SEC policy. The SEC considers inappropriate use of the Internet or intranet to be an extremely serious matter.
While on the Internet, your activities can be traced back to the SEC. Since the public can observe your actions and behavior on the Internet, you have a responsibility and obligation to maintain the SEC’s reputation by conducting your Internet activities with integrity. You must abide by all federal and SEC rules and regulations governing official and ethical conduct. Misuse of government computer resources, including the accessing or downloading of pornographic or sexually explicit material may result in disciplinary action, up to and including dismissal, and, in some circumstances, criminal prosecution.
SEC’s Internet filters block inappropriate Web sites, including those containing pornography, and access logs record each blocked attempt. If you receive a warning that a Web site has been blocked because it contains pornography or other inappropriate content, you should not attempt to access this site again.
The SEC allows the use of social networking technologies to support Commission objectives. However, social networking interactions must always take place within the framework of the Rules of the Road, and be conducted securely and professionally. For example, do not post sensitive government material on a social networking site, do not post material someone could use to guess your SEC passwords, and be mindful that criminals often attempt to use social networking sites to obtain sensitive information or compromise your computer. Always familiarize yourself with the security and privacy capabilities of social networking sites you visit and apply those that afford the best opportunity to protect your reputation and ours.
December 21, 2017
Office of Information Technology
For more information, please refer to SECR 24-4.3, “Use of SEC Office Equipment.”
Recommended Practices When Using the Internet:
When using the Internet, you should:
Access and retrieve information from the Internet only in accordance with official duties or for limited personal use that does not violate activities highlighted in the “Personal Use of IT Resources” section Use only standard SEC-authorized Internet browsing capabilities, e.g., Microsoft Internet Explorer®, Google Chrome® or Apple Safari® for accessing the Web.
NOT store personal e-mail archives (.pst files) on public network drives, such as the J:\ drive.
Files ending in "pst" or “ost” should only be stored on the F:\ drive. Please note, files on the C:\ drive are not backed up, just the network drives like (F:\). Because of this, federal records should never be stored on the C:\ drive except as a temporary, emergency measure where network storage is unavailable.
Prohibited Uses of the Internet:
Use of the Internet for private matters (not outlined under “Authorized Uses of the SEC’s Network and Automated Systems”) or for personal gain is expressly prohibited. The following examples, while not exhaustive, are prohibited uses of the Internet:
DO NOT engage in any activity that would discredit the SEC, which includes, but is not limited to:
creating, seeking, transmitting, collecting, downloading, uploading, viewing or storing pornographic, sexually-explicit or offensive materials or any material related to illegal activities, e.g., child pornography, gambling, terrorist acts, etc.
DO NOT download or install any software that has not been approved for use on SEC equipment.
DO NOT use anonymous access or aliases when requesting or submitting information to conduct official business. (You must identify yourself properly at all times when conducting official business.)
DO NOT use any Internet-based e-mail accounts from SEC computers to conduct SEC business while at work or home or on travel unless authorized by OIT in the course of your duties. This includes e-mail portals such as Gmail, Hotmail, MSN, Yahoo, AOL, etc.
DO NOT download, distribute, store, watch, or play any files in violation of copyright laws.
Users should also remember that records of Internet and intranet activity are available for review under the Freedom of Information Act (FOIA) and the Privacy Act and for other official purposes.
You are authorized and encouraged to communicate with others using the SEC’s electronic mail (e-mail) service whenever appropriate. The use of e-mail enhances your ability to reach an intended message recipient, saves time, provides enhanced search, retrieval and filing capabilities, and makes electronic information available to many users simultaneously. All users of the e-mail system, whether authorized or not, are subject to monitoring by system personnel and by law enforcement officials. Anyone using SEC systems expressly consents to such monitoring.
December 21, 2017
Office of Information Technology
E-mail is not inherently confidential and SEC users should have no expectation of privacy when using the e-mail system.
SEC User Responsibilities Regarding E-mail:
Treat the e-mail system and the e-mail messages contained therein as government property. All e-mail messages may be available for review under FOIA and the Privacy Act and for other official purposes.
Be aware that if you misuse government computer resources, including the e-mail system, you may be subject to disciplinary action, including termination of employment and prosecution.
Report any threats received over e-mail or any e-mail security violations to the OIT Service Desk at 202-551-HELP (extension 14357) or through askIT (https://seceamsprod.service- now.com/secsp?id=home), as described in the ”Reporting Incidents” section of this document.
Report e-mails evidencing violations of criminal law or other misconduct by SEC employees, interns, visiting fellows, contractors, or anyone else who is granted access to SEC Systems to the Office of Inspector General, as described in the ”Reporting Incidents” section of this document.
Exercise common sense, good judgment and propriety in the use of e-mail and use e-mail responsibly.
Recommended Practices When Using E-mail:
Determine whether e-mail messages you receive should be classified as federal records in accordance with Rule #4, “Save Federal Records” Periodically review e-mail messages and documents maintained in electronic file folders to determine whether you need to keep them. Delete those that are no longer needed unless they must be preserved as federal records. This review process also should include emptying items stored in your deleted, trash, junk or quarantine folders to remove spam and unwanted attachments.
Be careful when addressing e-mail. Know your intended recipients.
Be cautious when sending very large attachments (over five megabytes). Very large e-mails can leave a recipient’s mailbox overloaded.
When sending Personally Identifiable Information (PII), non-public, or sensitive data to non-SEC recipients, encrypt e-mails by placing “Smail” (without quotation marks) in the subject line. This action will direct users to an SEC-approved external, secure service. PII is defined in the E- Government Act of 2002 and related Office of Management and Budget (OMB) memoranda as information that could be used to distinguish or trace an individual’s identity, such as a person’s name, Social Security number, date and place of birth, mother’s maiden name and biometric records. See Rule #6 below and SECR 24-08, “Privacy Policy and Compliance” for more guidance on this subject.
Prohibited Uses of E-mail:
DO NOT use e-mail to send material that is sensitive or that contains personally identifiable information (PII) to your personal e-mail account(s).
DO NOT alter the “To,” “From,” or “Cc” lines of e-mail messages or other attributes of origin or destination in electronic mail.
DO NOT create, store, send or forward electronic chain e-mail messages. Chain e-mail messages attempt to induce the recipient to forward the e-mail to one or more new recipients.
Common types of chain e-mail messages include emotionally-manipulative stories, get-rich-quick pyramid schemes, and the exploitation of superstition to threaten the recipient with bad luck if the chain is broken.
December 21, 2017
Office of Information Technology
DO NOT send or post messages to external newsgroups, bulletin boards, or other public forums, unless it is a business-related requirement.
DO NOT use the e-mail system in any activity that would discredit the SEC. Use of the system to harass or denigrate individuals or groups is specifically prohibited.
DO NOT open any e-mail message containing an attachment from a source outside of the SEC unless you know the originator of the message and can confirm its validity DO NOT establish an automated system or rule that sends/forwards e-mail directed to an SEC e-mail account to a non-SEC account or directs mail from any non-SEC account to an SEC e-mail account.
The Federal Records Act (44 USC 3301) defines records as:
‘‘(A) … all recorded information, regardless of form or characteristics, made or received by a Federal agency under Federal law or in connection with the transaction of public business and preserved or appropriate for preservation by that agency or its legitimate successor as evidence of the organization, functions, policies, decisions, procedures, operations, or other activities of the United States Government or because of the informational value of data in them; and
‘‘(B) does not include—
‘‘(i) library and museum material made or acquired and preserved solely for reference or exhibition purposes;
or ‘‘(ii) duplicate copies of records preserved only for convenience.”
Any electronic file created and used in the conduct of the SEC’s business has the potential to be a federal record and should be treated like any hardcopy of a document when it comes to determining its status as a federal record.
An electronic file can be a message transmitted through electronic mail; a file transmitted via the Internet; text posted on an electronic bulletin board discussion group or news group; a Web log (blog) post; a document created via Microsoft Office or another application, system or program used within the
SEC.
Responsibilities Related to Federal Records:
Use the following guidelines to determine if an electronic file made or received in the conduct of government business is considered a federal record:
If an electronic file documents an official action taken by you and/or someone else on behalf of the SEC, and if the file is needed for adequate and complete documentation of the action, the file is considered a record, regardless of whether copies are retained elsewhere.
If the record already exists in official files, your copy is not a record and may be deleted.
If the file is only for information exchange and requires no action, the copy is not a record.
If attachments or related files are an integral part of the record, keep them together.
December 21, 2017
Office of Information Technology
If you determine that an electronic file is a record:
Follow the division/program office file plan and records disposition schedule for retention and destruction. Generally, as a rule of thumb, short-term records can be deleted when no longer needed. Direct specific questions about data preservation or destruction to the Office of Records Management Services. Additional records and information management guidance is located in the “Records Management” section of the Insider.
Maintain the body, subject, date transmitted and names of the sender(s) and receiver(s) for all e-mail messages considered federal records. The SEC’s electronic mail system captures the subject, date transmitted and names of the sender(s) and receiver(s).
Back up critical data that may include federal records. Storing data on SEC shared drives (i.e., storage spaces accessible through the SEC network) ensures that your information is backed up.
For additional policies concerning electronic federal records, refer to SECR 7-1, “Records and Information Management Program”.
You should never let anyone know your account passwords or personal identification numbers (PINs) for network credentials (including those for your Personal Identity Verification (PIV) card). This includes trusted friends and family, colleagues, supervisors, and technical support personnel.
Telling or even temporarily lending someone else your password or access credentials is like giving that person a signed blank check or your charge card. Anyone who has your password can use your account, and whatever he or she does that affects the system can be traced back to your username. If your username or network account is used in an abusive or otherwise inappropriate manner, the SEC will hold you responsible.
SEC User Responsibilities Related to Passwords and Network Credentials:
Safeguard system passwords, SecurID® Tokens or PINs from unauthorized disclosure and report any compromises or suspected compromises OIT Service Desk at 202-551-HELP (extension 14357) or through askIT (https://seceamsprod.service- now.com/secsp?id=home)as described in the ”Reporting Incidents” section of this document.
Lock your computer whenever it will be left unattended, even briefly, by pressing the “Ctrl+Alt+Delete” keys simultaneously and then selecting “Lock Computer” or use the Window button “L” shortcut.
Always use a password that you can easily remember but is unique enough that it cannot be easily guessed.
Prohibited Uses of Computer Passwords and PINs:
DO NOT share or reveal passwords or network credentials at any time or under any circumstances. No one, under any circumstances, should ever ask you for your password or PIN, either in person or on the phone. If you are asked for your password or PIN, report the incident to OIT Service Desk at 202-551-HELP (extension 14357) or through askIT (https://seceamsprod.service- now.com/secsp?id=home), as described in the ”Reporting Incidents” section of this document.
December 21, 2017
Office of Information Technology
DO NOT leave passwords lying around. Do not write down entire passwords. If you must write down even part of a password to remember it, be sure to store it in a very safe place. (A good rule of thumb is to treat passwords written on a piece of paper as though it were cash. You wouldn’t leave your wallet lying around so don’t leave your passwords lying around.) Try to avoid writing down the entire password and instead just write down enough information to remind you of what the password is. Do not store unencrypted lists of passwords on a computer, handheld device, or on a networked drive.
DO NOT wait to change passwords that have been or are suspected to have been compromised. Change them immediately and then notify OIT Service Desk at 202-551-HELP (extension 14357) or through askIT (https://seceamsprod.service- now.com/secsp?id=home), as described in the ”Reporting Incidents” section of this document.
DO NOT use your SEC credentials (e.g., username or password) on external or non-SEC computer systems, such as your personal Internet account on your home computer. A hacker may be able to access your account and crack your password on a less secure computer system and then attempt to use the same username and password to gain access to the SEC network.
DO NOT use passwords that can be easily guessed. Never use birth dates or the names of spouses, children, or pets as these can easily be compromised if associated with the user.
DO NOT use passwords that are primarily composed of any word found in any dictionary, English or foreign. Hackers often use electronic dictionaries and commonly available tools to automate password cracking. For example, a password of “1summer$” contains the word “summer,” making it relatively easy to crack. A better choice would be “1$u^^M3r5.” The transposition of letters and the insertion of special characters into a password increase the time it would take to crack the password.
DO NOT attempt to change password protection settings on any government-owned equipment.
This includes attempting to lengthen the timeout feature of security screen savers on desktops and laptops or the security timeout feature on mobile devices such as BlackBerry or Apple devices.
The Privacy Act of 1974 (Title 5 U.S.C. §552a), the Electronic Communications Privacy Act (18 USC 2510 et seq., as amended) and the Federal Information Security Management Act (FISMA) of 2002 and E- Government Act of 2002” (Public Law 107-347, Title III) protect the privacy of users concerning electronic communications. The SEC’s network and automated systems are in place to facilitate the sharing of information among SEC users and our customers. When using these resources, make sure that your actions do not violate the privacy of other users, whether intentionally or unintentionally. The SEC has established rules for protecting Privacy Act records and personally identifiable information (PII). Protect PII from unauthorized disclosure, modification or destruction to preserve its security and confidentiality.
Examples of PII include but are not limited to:
Social Security number (SSN) Date and place of birth Demographic data, such as age, education and passport number Contact information, such as address, phone number and email address Financial information and account numbers Other unique identifiers, such as marital status and mother’s maiden name
December 21, 2017
Office of Information Technology
Prohibited Practices Concerning the Privacy of Others:
DO NOT access the files or accounts (i.e., directories) of another user without clear authorization from that user.
DO NOT intercept or otherwise monitor any network communications not explicitly intended for you.
DO NOT disclose Privacy Act records to any person (including SEC employees) or to another agency without a request from or the written consent of the individual to whom the record pertains, unless an appropriate exception, defined in SECR 24-08, “Privacy Policy and Compliance”, is provided concerning the disclosure.
DO NOT use names or other personal identifiers that might be of a sensitive or confidential nature in electronic communications.
DO NOT disclose any PII contained in any systems of records except as authorized by federal law or by SEC regulation or directive.
DO NOT intentionally view or modify agency data (including e-mail messages, passwords and PII) unless the owner of that data has explicitly authorized you to access such data or you have been specifically authorized to do so as described in the “Rules of the Road Exceptions and Waivers.”
DO NOT attempt to decrypt or translate encrypted material belonging to another person or organization (including e-mail), unless this action is part of your regular duties and the originator/sender supplies you with the password to access such material.
DO NOT create or distribute any programs that secretly collect information about SEC users.
DO NOT access another SEC user’s computer using his or her logon credentials, such as a username and password.
For more information on the SEC’s privacy program and policies, visit the SEC Privacy Office Web site.
The SEC uses a number of security mechanisms to protect information from unintended access, both from within the SEC network system and from the outside. However, these mechanisms by themselves are not sufficient. Users of the SEC network and automated systems should ensure they take appropriate action to safeguard the information contained in these systems from unauthorized access or inadvertent modification, disclosure, destruction and use. Use of voice mail greetings to advise callers not to leave PII in voice mail messages is also strongly encouraged to prevent its inadvertent disclosure.
Users of the SEC network and automated systems must also understand that sensitive or non-public information may NOT be processed on non-SEC workstations unless such workstations utilize SEC-approved remote operation utilities, such as Citrix® software. Should SEC users work with classified information at any time, such information will only be processed on systems approved for such activity.
For more policy concerning safeguarding non-public information and data, refer to SECR 23-2a “Safeguarding Non-Public Information.”
December 21, 2017
Office of Information Technology
SEC information that must be protected from unauthorized disclosure or access due to its sensitive nature is considered non-public information. Non-public information is information generated by or in the possession of the SEC that is commercially valuable, market sensitive, proprietary, related to an enforcement or examination matter, subject to privilege, or deemed non-public by a division director or office head and not otherwise available to the public. The two subcategories of non-public information are “Non-Public (SEC Restricted)” and “Non-Public (SEC Use Only).”
“Non-Public (SEC Restricted)” Information
“Non-Public (SEC Restricted)” information is sensitive, non-public material, in any format. “Non-Public (SEC Restricted)” information must be clearly marked and can be disclosed or distributed only on a need-to-know basis.
Examples of “Non-Public (SEC Restricted)” information include, but are not limited to:
Materials with substantial commercial value or market sensitivity, such as correspondence or other materials regarding pre-public transactions (e.g., documenting mergers or other planned transactions) Auditor independence inquiries Information regarding pre-public bankruptcies Non-public financial projections Filings subject to a confidential treatment order Materials or information related to proposed or ongoing undercover criminal investigations Procurement-sensitive information Any additional material deemed to be "Non-Public (SEC Restricted)" by the information custodian (a division director or office head or his or her senior staff designee)
“Non-Public (SEC Use Only)” Information
“Non-Public (SEC Use Only)” information is all non-public information that is not considered SEC-restricted based on the definition provided above. “Non-Public (SEC Use Only)” information or information otherwise deemed non-public by a division director or office head should be made available only to SEC employees and/or approved agents of the SEC in accordance with SECR 23-2a “Safeguarding Non- Public Information.” In accordance with Office of Management and Budget (OMB) Memorandum M-06-16, “Protection of Sensitive Agency Information” dated June 23, 2006, SEC users who access personally identifiable information from databases holding sensitive information must maintain a personal log of all data retrieved from these systems, whether in electronic or hardcopy format. The log will indicate information identifying the extract, including the data source, the date the data was obtained, the business reason that necessitated the extract, the format (i.e., electronic or hardcopy) and the date of destruction.
In addition, SEC users holding sensitive data will verify that each extract has been erased within 90 days or that its use is still required. Some “Non-Public (SEC Use Only)” information, such as certain investigatory and personnel files, must be disclosed or distributed only on a need-to-know basis.
Examples of “Non-Public (SEC Use Only)” information include but are not limited to:
Sensitive internal documents or staff procedures Draft no-action and interpretive letters or exemption applications Correspondence from registrants, auditors or other market participants Enforcement materials Examination materials Draft rule proposals, legal opinions and briefs
December 21, 2017
Office of Information Technology
Pre-release economic studies Technical assistance to Congress Memoranda to the SEC Draft SEC orders and releases The Commission calendar Personnel information
Prohibited Practices Concerning Non-Public Information:
DO NOT transmit non-public information or sensitive data to authorized recipients outside the SEC through the Internet or via e-mail, unless you have encrypted it using the SEC’s approved procedures and technologies. To encrypt an outgoing e-mail, enter the word “smail” into the subject line of the message (i.e., if the normal subject of your message is “Big Announcement,” the new subject line would be “smail Big Announcement.”) You can get more information by following this link: Learn How To Use the SEC's E-mail Encryption Solution.
DO NOT store or transmit non-public information or sensitive data on personal IT resources or SEC IT resources without proper protection/encryption.
DO NOT leave laptop computers containing non-public information or sensitive data unprotected.
o Laptops must require the use of a PIV credential to activate them unless a specific device exclusion is issued by OIT.
If a laptop computer, handheld device or data storage device such as a CD or external hard drive containing non-public, sensitive, or PII is lost or stolen, the incident must be reported immediately to all of the following:
The OIT Service Desk at 202-551-HELP (extension 14357) or through askIT (https://seceamsprod.service- now.com/secsp?id=home), as described in the ”Reporting Incidents” section of this document Your supervisor Your division director or office head Your division/office IT Specialist
DO NOT assume that non-public information or sensitive data erased from a computer hard drive has been destroyed. Consult The OIT Service Desk at 202-551-HELP (extension 14357) or through askIT (https://seceamsprod.service- now.com/secsp?id=home) when destroying information in electronic form to ensure that it has been permanently erased.
The SEC network and automated systems allow you to access external information through the Internet, thus helping you to perform your job more effectively. As a result of this expanded capability, you need to understand copyright restrictions and be vigilant when it comes to using copyrighted materials. Many computer programs and documentation are owned by individuals or third-party entities and are protected by copyright, licenses and other laws or contractual agreements. When not in use, copyrighted software media should be stored in a secure location, in either a locked cabinet or office.
December 21, 2017
Office of Information Technology
Copyright considerations also apply to electronic documents that are obtainable through the Internet.
Failure to abide by legal and contractual restrictions on the use of copyrighted products could make you subject to civil and criminal prosecution and may place the SEC at risk.
Prohibited Practices Related to Copyrighted Material and Software:
DO NOT use copyrighted and licensed materials, including software, music, or images on any SEC automated system, without the copyright or license owner’s approval.
DO NOT copy any commercial software onto any electronic medium for backup purposes unless the copyright owner (i.e., the software company) specifically grants permission in the software licensing agreement.
DO NOT install SEC-owned or SEC-licensed software on any personally-owned computer, unless authorized by OIT.
The SEC has established an environment that provides timely access to the computing resources and information you need. To ensure that you continue to receive the service you require, you must take certain actions to protect SEC IT assets.
Prohibited Practices Related to the SEC Network and Automated System Assets:
DO NOT power off your computer at the end of the day, unless specifically directed to do so by OIT. SEC computers must be logged off but left powered on to facilitate remote software upgrades, virus protection, and other maintenance as necessary. Log off the network at the end of each workday by saving your work, closing all open applications, clicking “Start” from the bottom left-hand corner of screen and then selecting “Log Off.” Leaving your computer powered on will not damage it.
DO NOT introduce non-approved software or hardware technology into the SEC network environment. Any software or device that is connected to an SEC network or device must be examined and approved prior to that connection.
DO NOT interfere with the virus-scanning software installed on SEC workstations. If a virus is detected when a file is opened or during the weekly automatic virus scan, contact The OIT Service Desk at 202-551-HELP (extension 14357) or through askIT (https://seceamsprod.service-now.com/secsp?id=home) as described in the ”Reporting Incidents” section of this document DO NOT reconfigure SEC computer hardware and software assets.
DO NOT modify system files (instructions used by software to carry out commands). Modification includes deliberate editing, changing, adding or deleting of program code within a system file.
This modification restriction does not prohibit you from changing desktop parameters such as backgrounds, network printer selections, etc., through the desktop operating system environment.
DO NOT cut, break, or remove any lock or physical security device attached to any SEC printer or other IT equipment.
DO NOT try to perform your own repairs on government-owned computer equipment.
Contact The OIT Service Desk at 202-551-HELP (extension 14357) or through askIT (https://seceamsprod.service- now.com/secsp?id=home), as described in the ”Reporting Incidents” section of this document if your equipment is malfunctioning or requires maintenance.
December 21, 2017
Office of Information Technology
DO NOT move your computer workstation or peripheral equipment to a new location.
Contact The OIT Service Desk at 202-551-HELP (extension 14357) or through askIT (https://seceamsprod.service- now.com/secsp?id=home) as described in the ”Reporting Incidents” section of this document if your IT equipment needs to be moved.
DO NOT execute any network scanning/monitoring programs unless you are authorized to do so as part of your assigned job responsibilities.
DO NOT leave PII material in uncontrolled areas.
DO NOT grant access to PII materials to individuals unauthorized to handle such information.
The SEC has established the ability to connect remotely to the SEC network. Remote network connectivity includes laptops configured with Internet service provider (ISP) accounts, virtual private networks (VPNs), Citrix® software, and Outlook Web Access (OWA). Remote network connectivity also includes handheld devices, e.g., a BlackBerry or iPhone device.
In general the SEC has few restrictions on using personal devices to remotely access the SEC’s infrastructure. The major exception is if you're working in another entity's office on behalf on the SEC (such as performing an on-site examination of a Registrant) you must work on SEC-issued equipment. In this situation, you cannot use your personal equipment and standard remote access tools, such as Citrix®. This requirement is in place to assure the individuals you're working with that any data you come into contact with goes directly into the SEC environment where it's protected.
SEC users are responsible for the protection of agency-issued portable computing devices at all times.
This responsibility extends to the physical custody of such devices as well as the protection of agency data contained on these devices. This responsibility also includes the protection of agency data stored on personally-owned handheld devices.
Recommended Practices When Using Remote Connections and Wireless/Handheld Devices:
Use the access protection features available on portable computing devices. Handheld and wireless e-mail devices are set to protect the device with a password after no more than 15 minutes of user inactivity. Laptops are set to activate a password-protected screen-saver after 15 minutes of user inactivity.
Exercise care when using these devices in public places to avoid allowing screen displays to be read or captured by others.
Prohibited Practices Related to the Use of Remote Connections, Wireless/Handheld Devices:
DO NOT directly connect personally owned portable computing devices (i.e., handheld devices, such as BlackBerry or Apple’s iPhone, etc.) to agency computers or networks. The SEC is not responsible for any such damage to personally owned devices.
DO NOT store portable IT resources in unsecured locations. Store them in locked containers or areas secured by a guard or key or key card access.
DO NOT use a personally owned handheld device to store mission-critical information, network
December 21, 2017
Office of Information Technology access information, or any other sensitive information. Do not use any handheld device to store agency passwords or other agency codes (e.g., safe combinations).
DO NOT transfer agency data on handheld devices or other mobile computing devices to any other non-agency device or to a person who has no legal or legitimate reason to access agency data.
DO NOT leave laptops and other transportable information systems or devices containing PII unattended or unsecured in a public area at any time.
DO NOT place PII or other sensitive information on portable devices or otherwise remove any such devices containing PII from SEC offices unless you are specifically authorized to do so.
The SEC provides Federal employees and contractors hand-held devices and other mobile electronic devices to facilitate timely communication and transmission of information and data essential to conducting SEC business. Every day, agency employees and contractors drive privately owned vehicles (POVs) or vehicles that are owned, leased, or rented by the SEC (collectively GOVs) when conducting official Government business, and some agency employees may be tempted to use agency-supplied electronic devices or their own personal electronic devices to send/read text messages or e-mail while operating a motor vehicle. However, text messaging and responding to e-mail causes drivers to take their eyes off the road and at least one hand off the steering wheel, thereby endangering both themselves and others.
Executive Order 13513, dated October 1, 2009 and SEC policy prohibit text messaging:
On an electronic device supplied by the SEC when driving a GOV or when driving a POV whether or not on official agency business On an electronic device that is personally owned when driving a GOV, or when driving a POV while on official agency business
See the Human Resources Directive SECR 5-3, entitled, “Prohibition on Text Messaging While Driving” for more information.
Examples of electronic devices that employees should not use to text or send/read e-mail while operating a motor vehicle include handheld mobile devices, such as personal digital assistants (PDAs), cell phones, global positioning systems (GPS) or any handheld or other electronic device, such as a laptop computer, that allows you to read or enter data.
If you send/read text messages or e-mail while operating a motor vehicle on official Government business, or use an SEC-issued electronic device to send/read text messages or e-mail while operating a POV on non-official government business, you may be subject to disciplinary actions, adverse actions, criminal prosecution or civil prosecution as appropriate to the specific circumstances of misuse.
Prohibited Practices When Using Electronic Devices While Operating a Motor Vehicle:
DO NOT engage in text messaging on an electronic device supplied by the SEC when driving a GOV, or when driving a POV whether or not on official agency business.
December 21, 2017
Office of Information Technology
DO NOT engage in text messaging on an electronic device that is personally owned when driving a GOV, or when driving a POV while on official agency business.
Recommended Practices When Using Electronic Devices While Operating a Motor Vehicle DO pull over to the side of or off the roadway and bring the motor vehicle to a complete stop in a location where you can safely remain stationary if you must type on or read from any portable electronic device while operating a motor vehicle.
Some SEC employees and contractors may be required, as part of their assigned duties, to engage in activities that are otherwise prohibited by these rules but are necessary or required to protect the SEC network. When such activities are required as part of assigned duties, they shall be authorized by the OIT Chief Information Security Officer (CISO) or designee as exceptions to these rules. These exceptions are position based.
Individual waivers to specific components of this policy may be requested via OIT Service Desk at 202- 551-HELP (extension 14357) or through askIT (https://seceamsprod.service- now.com/secsp?id=home).
The party seeking the waiver must demonstrate that adherence to a specific requirement of the “Rules of the Road” will hinder the completion of a specific mission, detrimentally impact an SEC business function or result in a serious financial impact. OIT will coordinate the waiver request, as appropriate.
Waivers, which are based on business need and granted on a case-by-case basis, must be consistent with federal law and policy and may be subject to periodic review.
File details come from the government source that posted it. Updated .