TE 09 E-Mail and SharePoint Procedures DRAFT.docx

DOCX document 2 MB Posted

Attached to
FEMA Housing Inspection Services Programs Federal contract opportunity
Solicitation number
70FB8022I0FEMAHIS
Issued by
Federal Emergency Management Agency Community Survivor Assistance Section

About this file

This document is the FEMA Enterprise SharePoint (ESP) Governance Policies and Processes. It establishes the governance framework for FEMA's Enterprise SharePoint implementation, which includes both a SharePoint Online (SPO) and a SharePoint 2016 On-Premises (SP2016) environment. The purpose is to provide policies, rules of behavior, and general processes and procedures to support the effective delivery of SharePoint services across FEMA.

The key details include:

  • The environment is organized into two web applications - "teams" and "sites" - to support different collaboration and content sharing needs.
  • All sites must have Site Collection Administrator rights granted to the ESP Technical Support Team group.
  • There are specific requirements around storage limits, prohibited content, file types, permissions, security, and records management that Site Collection Administrators and Team Owners must adhere to.
  • Change requests to the environment are managed through the Enterprise SharePoint Change Control Board.
  • The document outlines the roles, responsibilities and functions of different user groups, including ESP Users, Site Security Owners, Site Collection Administrators, the ESP Technical Support Team, and the ESP System Owner.

View the file

Other files for this federal contract opportunity

Other files attached to FEMA Housing Inspection Services Programs, newest first.
File Type Posted
DRAFT RFP SELECT QandA.docx DOCX document
TE 14 Training Request SOO DRAFT.docx DOCX document
TE 15 Hello Letter DRAFT.docx DOCX document
Attachment 1 - Performance Work Statement_04112024 DRAFT.docx DOCX document
Customer Service FAQ DRAFT.docx DOCX document
TE 18 DSA SOW DRAFT.docx DOCX document
TE 13 JIT Hiring Activation SOW DRAFT.docx DOCX document
TE 10 Mandatory Training DRAFT.docx DOCX document
Attachment 8 - Questions Submission Matrix - IHP Field Services.xlsx XLSX spreadsheet
TE 06 FEMA Corrections DRAFT.docx DOCX document
Attachment 2 - Performance Requirement Summary_03202024 DRAFT.docx DOCX document
Attachment 4 - Inspector WD 2000-0127 Rev 47 06302023DRAFT .pdf PDF
TE 17 DRC SOW DRAFT.docx DOCX document
TE 11 Mobile Device Agreement DRAFT.docx DOCX document
Attachment 5 FEMA Personnel Standards of Conduct DirectiveDRAFT .pdf PDF
TE 02 Remote Assessment Guidelines DRAFT.docx DOCX document
TE 05 Remote Housing Assessment Job Aid DRAFT.docx DOCX document
TE 04 Remote Housing Assessment Script.xlsx XLSX spreadsheet
DRAFT SOLICITATION - 70FB8024R00000028.pdf PDF
TE 03 ACE 5 UserGuide November 2023 DRAFT.docx DOCX document
TE 12 Personnel Security DRAFT.docx DOCX document
TE 08 Key Contractor Personnel DRAFT.docx DOCX document
TE 16 Missed You Letter DRAFT.docx DOCX document
Table A - Historical Inspection Activity DRAFT.docx DOCX document
TE 01 On-Site Assessment Guidelines DRAFT.docx DOCX document
TE 07 QC Spreadsheet.xlsx XLSX spreadsheet
Attachment 3 - QASP DRAFT.docx DOCX document
Attachment 7 Instruction 119-7-1 FEMA Personal Property Asset Management ProgramDRAFT.pdf PDF
DRAFT TE 13 JIT Hiring Activation SAMPLE SOW.docx DOCX document
DRAFT TE 06 FEMA Corrections.docx DOCX document
DRAFT Attachment 2 Performance Requirement Summary.docx DOCX document
DRAFT Table A - Historical Inspection Activity.docx DOCX document
DRAFT TE 10 Mandatory Training.docx DOCX document
DRAFT TE 08 Key Contractor Personnel.docx DOCX document
DRAFT Attachment 3 QASP.docx DOCX document
DRAFT TE 18 DSA SOW.docx DOCX document
DRAFT TE 17 DRC SOW.docx DOCX document
DRAFT TE 12 Personnel Security.docx DOCX document
DRAFT Performance Work Statement REVISED 01-30-2024.docx DOCX document
HIS_RFI_04282022.docx DOCX document
HIS PWS_Draft.docx DOCX document
Show all 41

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

2024 Housing Assessment Services Technical Exhibit #XX E-Mail and SharePoint Procedures

In compliance DHS Policy Directive 047-01-007 Handbook for Safeguarding Sensitive PII, the sharing of information between FEMA personnel and the HIS Contractor containing Personal Identifying Information (PII) will be encrypted.

FEMA Privacy considers Registrant Identification Numbers (Reg. ID’s) a PII data element equal to any other standard PII field such as full name, address or phone number requiring protection within the DHS safeguarding guidelines.

DHS’s Handbook for Safeguarding Sensitive PII requires the encryption of documents and e-mail containing PII. In meeting this requirement, FEMA requires users to select a minimum of a 12-character password on documents/files containing Reg. ID’s or any data to be shared containing elements disclosed in the attached Privacy Threshold Analysis, Section 3.

Contracted members may only send, receive and review PII on Government Provided Equipment (GFE) and Government e-mail accounts.

E-Mail Procedures

FEMA and HIS Contracted personal are not to display applicant PII in e-mail correspondence. All sensitive applicant information transmitted via e-mail will be through an encrypted document following this outline:

1. Subject Line: Suggested e-mail subject line text:

· DR#/Situation/Date

· Example: DR-5568 ASL Need 6/23/2022

2. Message body: Content may include FEMA personnel names and contact information, time and date of the situation or requesting need.

3. Attachment: All applicant PII must be encrypted through an attached document.

SharePoint Procedures:

Each HIS Vendor has a unique SharePoint folder to transmit information with FEMA personnel. Information that may be shared includes all reports, staffing lists, quality control data and information pertinent to performance or otherwise requested through a partnering atmosphere.

1. All data containing PII must be encrypted using aes-256-bit encryption and a 12-character password. Microsoft Word and Excel, along with Adobe Acrobat include aes-256-bit encryption.

References:

1. DHS Policy 047-01-007 Handbook for Safeguarding Sensitive PII:

2. FEMA Enterprise SharePoint Governance Policies and Processes:

3. Privacy Threshold Analysis:

2024 Housing Assessment Services Technical Exhibit # 09

TE 09 E-Mail and SharePoint Procedures.docx 1 10/1/2023 image1.emf dhs policy directive 047-01-007 handbook for safeguarding sensitive PII 12-4-2017.pdf

Handbook for Safeguarding Sensitive PII

Privacy Policy Directive 047-01-007, Revision 3

Published by the DHS Privacy Office

December 4, 2017

2 | Handbook for Safeguarding Sensitive PII DHS Privacy Policy Directive 047-01-007

Table of Contents

Introduction

Authorities

Definitions

PII and Sensitive PII Defined

Additional Definitions

Collecting Sensitive PII

Proper Auhtorization is Needed

Best Practices

Collection of PII via Mobile Applications

Storing Sensitive PII

IT Systems

Internal Websites and Shared Network Drives

Using Sensitive PII

Proper Auhtorization is Needed

Best Practices

Equipment

Paper

In Transit

Teleworking

Disseminating Sensitive PII — Information Sharing

Proper Auhtorization is Needed

Unauthorized Dissemination of Sensitive PII

Social Engineering

Phishing

Best Practices

Email

Mail

Equipment

Disposing of Sensitive PII

Reporting a Privacy Incident

Resources

DHS Privacy Policy Directive 047-01-007 Handbook for Safeguarding Sensitive PII | 3

Introduction

In its mission to secure the Homeland, the Department of Homeland Security (DHS) collects personal information, also known as Personally Identifiable Information (PII), from U.S. citizens, Lawful

Permanent Residents (LPR), visitors to the U.S., and employees or contractors to the Department. As an employee, contractor, appointee, detailee, intern, or consultant (hereafter referred to as “DHS staff”), you are obligated by law and by DHS policy to protect PII to prevent identity theft or other adverse consequences, such as a privacy incident, compromise, or misuse of data.

You should exercise care when handling all PII. Sensitive PII

(SPII), however, requires special handling due to the increased risk of harm to an individual if it is compromised. The loss or compromise of SPII can result in embarrassment, inconvenience, reputational harm, emotional harm, financial loss, unfairness, and in rare cases, a risk to personal safety.

This Handbook provides best practices and DHS policy requirements to prevent a privacy incident involving PII/SPII during all stages of the information lifecycle: when collecting, storing, using, disseminating, or disposing of PII/SPII.

This handbook explains:

how to identify PII and SPII, how to protect PII and SPII in different contexts and formats, and what to do if you believe PII and/or SPII has been lost or compromised.

Most privacy incidents at DHS are accidental, so by following these guidelines, you can help to prevent them.

Please note that your Component Privacy Officer, Privacy Point of Contact (PPOC), Program Office, or System Owner may establish additional or more specific rules for handling PII/SPII based on the sensitivity of the information involved.

A complete list of DHS Component Privacy Office contacts can be found on our website: www.dhs.gov/privacy. Questions http://www.dhs.gov/privacy

4 | Handbook for Safeguarding Sensitive PII DHS Privacy Policy Directive 047-01-007

Authorities

All DHS staff are obligated to safeguard PII/SPII, as described in numerous federal statutes, regulations, agency-wide directives, and DHS policies, of which the following is a sampling:

Federal Statutes

5 U.S.C. § 552a, Privacy Act of 1974, as amended

5 U.S.C. § 552a (note), Judicial Redress Act of 2015

5 U.S.C. § 552, Freedom of Information Act (FOIA)

6 U.S.C. § 142, Homeland Security Act, Privacy Officer

44 U.S.C. 3501 et seq., Paperwork Reduction Act (PRA)

E-government Act of 2002 (Public Law 107-347)

OMB/Government-wide Guidance

Office of Management and Budget (OMB) Memorandum M-17-12, Preparing for and

Responding to a Breach of Personally Identifiable Information (January 2017)

OMB Circular No. A-108, Federal Agency Responsibilities for Review, Reporting, and Publication under the Privacy Act (December 2016)

OMB Circular No. A-130, Managing Information as a Strategic Resource (July 2016)

DHS Policy

DHS Management Directive 11042.1, Safeguarding Sensitive But Unclassified (For Official Use

Only) Information;

DHS Management Instruction 123-05-001, Telework Program

DHS Privacy Policy Instruction 047-01-008, DHS Privacy Incident Handling Guidance, (November

2017)

DHS Privacy Policy Guidance Memorandum 2017-01, DHS Privacy Policy Regarding Collection, Use, Retention, and Dissemination of Personally Identifiable Information (April 2017)

DHS Policy Directive 121-07, Standard Procedures When Restricted Personal Information is Posted

On the Internet or Social Media (Doxxing) (April 2016)

DHS Privacy Policy Instruction 047-01-003 for DHS Mobile Applications (March 2016)

DHS Privacy Policy Instruction 047-01-006, Privacy Incident Responsibilities and Breach Response

Team (December 2017)

DHS Sensitive Systems Policy Directive 4300A and DHS 4300A Sensitive Systems Handbook;

DHS Privacy Policy Directive 110-01 and Instruction 110-01-001, Operational Use of Social Media

DHS Privacy Policy Directive 140-06, The Fair Information Practice Principles: Framework for

Privacy Policy at the Department of Homeland Security (December 2008);

DHS Privacy Policy Directive 140-11, Use of Social Security Numbers at the Department of

Homeland Security (June 2007).

https://www.justice.gov/opcl/privacy-act-1974 https://www.congress.gov/114/plaws/publ126/PLAW-114publ126.pdf http://uscode.house.gov/view.xhtml?edition=2012&req=granuleid%3AUSC-prelim-title5-section552&f=treesort&num=0 http://uscode.house.gov/view.xhtml?req=(title:6%20section:142%20edition:prelim) https://www.gpo.gov/fdsys/pkg/PLAW-104publ13/pdf/PLAW-104publ13.pdf https://www.whitehouse.gov/sites/whitehouse.gov/files/omb/memoranda/2017/m-17-12_0.pdf https://obamawhitehouse.archives.gov/sites/default/files/omb/assets/OMB/circulars/a108/omb_circular_a-108.pdf https://www.whitehouse.gov/sites/whitehouse.gov/files/omb/circulars/A130/a130revised.pdf https://www.dhs.gov/sites/default/files/publications/Management%20Directive%2011042.1%20Safeguarding%20Sensitive%20But%20Unclassified%20%28For%20Official%20Use%20Only%29%20Information.pdf http://dhsconnect.dhs.gov/policies/Instruction%20Supplements/123-05-001_Telework_Program.pdf https://www.dhs.gov/publication/privacy-incident-handling-guidance https://www.dhs.gov/publication/dhs-privacy-policy-guidance-memorandum-2017-01 http://dhsconnect.dhs.gov/policies/Policies%20and%20Guidance%20Memoranda/Policy%20Directive%20Memorandum%20121-07,%20Standard%20Procedures%20When%20Sensitive%20Personal%20Data%20is%20Posted%20on%20the%20Internet.pdf http://dhsconnect.dhs.gov/policies/Instruction%20Supplements/047-01-003_Privacy_Policy_for_DHS_Mobile_Applications.pdf https://www.dhs.gov/policy https://www.dhs.gov/policy http://dhsconnect.dhs.gov/org/comp/mgmt/cio/iso/Documents/4300A%20Sensitive%20Systems%20Policy.pdf http://dhsconnect.dhs.gov/org/comp/mgmt/cio/iso/Documents/4300A%20Sensitive%20Systems%20Handbook.pdf http://dhsconnect.dhs.gov/org/comp/nppd/privacy/Documents/DHS%20Directive%20110-01_Privacy%20Policy%20for%20Operational%20Use%20of%20Social%20Media.pdf http://dhsconnect.dhs.gov/org/comp/nppd/privacy/Documents/DHS%20Instruction%20110-01-001_Privacy%20Policy%20for%20Operational%20Use%20of%20Social%20Media.pdf http://dhsconnect.dhs.gov/policies/Policies%20and%20Guidance%20Memoranda/Policy%20Directive%20Memorandum%20140-06,%20The%20Fair%20Information%20Practice%20Principles%20Framework%20for%20Privacy%20Policy%20at%20the%20Department.pdf http://dhsconnect.dhs.gov/policies/Policies%20and%20Guidance%20Memoranda/Policy%20Directive%20Memorandum%20140-11,%20Use%20of%20Social%20Security%20Numbers%20at%20the%20Department%20of%20Homeland%20Security.pdf

DHS Privacy Policy Directive 047-01-007 Handbook for Safeguarding Sensitive PII | 5

Definitions

PII and Sensitive PII Defined

DHS defines personal information as “Personally

Identifiable Information” or PII, which is any information that permits the identity of an individual to be directly or indirectly inferred, including any other information that is linked or linkable to that individual, regardless of whether the individual is a U.S. citizen, legal permanent resident, visitor to the U.S., or employee or contractor to the

Department.

PII is a form of Sensitive Information,1 which includes, but is not limited to, PII and Sensitive PII.

Sensitive PII (SPII) is Personally Identifiable Information, which if lost, compromised, or disclosed without authorization, could result in substantial harm, embarrassment, inconvenience, or unfairness to an individual.

SPII requires stricter handling guidelines because of the increased risk to an individual if the data is inappropriately accessed or compromised. Some categories of PII are sensitive as stand-alone data elements, including your Social Security number (SSN) and driver’s license or state identification number. Other data elements such as citizenship or immigration status, medical information, ethnic, religious, sexual orientation, or lifestyle information, in conjunction with the identity of an individual

(directly or indirectly inferred), are also SPII.

See the table on the next page for more examples of PII and SPII.

When determining the sensitivity of PII, agencies should evaluate the sensitivity of each individual

PII data field, as well as the sensitivity of data fields together.

For example, an individual’s SSN, medical history, or financial account information is generally considered more sensitive than an individual's phone number or zip code.

PII can become more sensitive when combined with other information.

For example, name and credit card number are more sensitive when combined than apart.

Generally non-SPII, such as a name, might become sensitive in certain contexts, such as on a clinic’s patient list.

1. Sensitive Information is any information, which if lost, misused, disclosed, or, without authorization is accessed, or modified, could adversely affect the national or homeland security interest, the conduct of federal programs, or the privacy of individuals, but which has not been specifically authorized under criteria established by an

Executive Order or an Act of Congress to be kept secret in the interest of national defense, homeland security or foreign policy. See DHS Sensitive Systems Policy Directive 4300A, version 13.1, July 27, 2017.

6 | Handbook for Safeguarding Sensitive PII DHS Privacy Policy Directive 047-01-007

Context matters. This table should not be regarded as an all-inclusive list of sensitive data elements. Context is also important in determining the sensitivity of PII. PII that might not include the data elements identified may still be sensitive and require special handling if its compromise could cause substantial harm, inconvenience, embarrassment, or unfairness to an individual.

For example, a collection of names:

Is not SPII if it is a list, file, query result of:

attendees at a public meeting or stakeholders who subscribe to a DHS email distribution list

Is SPII if it is a list, file, query result of:

law enforcement personnel, such as investigators, agents, or support personnel, or employee performance ratings, or employees with overdue mandatory training course completions

9. See footnote 1, supra, for the definition of “privacy incident.”

What is PII?

PII includes your name and your work email, address, and phone

What is Sensitive PII?

STAND ALONE

Social Security numbers

Driver’s license or state ID numbers

Passport numbers

Alien Registration numbers

Financial account numbers

Biometric identifiers

IN COMBINATION

Citizenship or immigration status

Medical information

Ethnic or religious affiliation

Personal email, address, and

Account passwords

Last 4 digits of the SSN

Date of birth

Criminal History

Mother’s maiden name

DHS Privacy Policy Directive 047-01-007 Handbook for Safeguarding Sensitive PII | 7

Additional Definitions

Fair Information Practice Principles (FIPP)2

The FIPPs form the basis of the Department’s privacy compliance policies and procedures governing the use of PII. DHS uses the FIPPs to assess and enhance privacy protections by analyzing the nature and purpose of the collection of PII to fulfill DHS’s mission, and how to best apply privacy protections in light of these principles. These eight principles are:

1. Transparency: DHS should be transparent and provide notice to the individual regarding its collection, use, dissemination, and maintenance of PII.

2. Individual Participation: DHS should involve the individual in the process of using PII and, to the extent practicable, seek individual consent for the collection, use, dissemination, and maintenance of PII. DHS should also provide mechanisms for appropriate access, correction, and redress regarding DHS’s use of PII.

3. Purpose Specification: DHS should specifically articulate the authority that permits the collection of PII and specifically articulate the purpose or purposes for which the PII is intended to be used.

4. Data Minimization: DHS should only collect PII that is directly relevant and necessary to accomplish the specified purpose(s) and only retain PII for as long as is necessary to fulfill the specified purpose(s).

5. Use Limitation: DHS should use PII solely for the purpose(s) specified in the notice. Sharing PII outside the Department should be for a purpose compatible with the purpose for which the PII was collected.

6. Data Quality and Integrity: DHS should, to the extent practicable, ensure that PII is accurate, relevant, timely, and complete.

7. Security: DHS should protect PII (in all media) through appropriate security safeguards against risks such as loss, unauthorized access or use, destruction, modification, or unintended or inappropriate disclosure.

8. Accountability and Auditing: DHS should be accountable for complying with these principles, providing training to all employees and contractors who use PII, and auditing the actual use of

PII to demonstrate compliance with these principles and all applicable privacy protection requirements.

Information life cycle:3 The stages through which information passes, typically characterized as creation or collection, processing, dissemination, use, storage, and disposition, to include destruction and deletion.

2. See DHS Privacy Policy Guidance Memorandum 2008-01/Privacy Policy Directive 140-06, The Fair Information

Practice Principles: Framework for Privacy Policy at the Department of Homeland Security (Dec. 29, 2008). See also DHS Privacy Policy Guidance Memorandum 2017-01, DHS Privacy Policy regarding Collection, Use, Retention, and Dissemination of Personally Identifiable Information (April 27, 2017).

8 | Handbook for Safeguarding Sensitive PII DHS Privacy Policy Directive 047-01-007

Need to Know: Refers to an exception under the Privacy Act that authorizes disclosures of Privacy

Act protected records within an agency to agency staff to fulfill their job responsibilities for necessary, official agency purposes and mission needs. See 5 U.S.C. § 552a(b)(1). For disclosures not covered by the Privacy Act, access to the information must be necessary for a person to conduct his or her official duties. This is separate from whether the person has all the necessary official approvals (such as a security clearance) to access certain information. We recommend you consult your supervisor or Component Privacy Officer or PPOC to determine if an individual seeking access to PII/SPII has a need to know.

Privacy Incident:4 The loss of control, compromise, unauthorized disclosure, unauthorized acquisition, or any similar occurrence where (1) a person other than an authorized user accesses or potentially accesses PII; or (2) an authorized user accesses or potentially accesses PII for an unauthorized purpose. The term encompasses both suspected and confirmed incidents involving PII, in either paper or electronic format, whether intentional or inadvertent, which raise a reasonable risk of harm.

3. As defined in OMB Circular No. A-130. See Authorities.

4. DHS changed its long standing definition of privacy incident to comport with OMB’s definition of a breach in

OMB Memorandum M-17-12, Preparing for and Responding to a Breach of PII (Jan. 3, 2017), but added the final sentence to address suspected and accidental incidents. We kept the term “privacy incident” to be consistent with other DHS incident types.

DHS Privacy Policy Directive 047-01-007 Handbook for Safeguarding Sensitive PII | 9

Collecting Sensitive PII

Proper Authorization is Needed

Consistent with the FIPPs, be certain of the following before collecting or maintaining PII/SPII:

1. You have the legal authority to collect the specific information;

2. The data collection is covered by a Privacy Act System of Records Notice (SORN), if necessary;

and

3. The database or information technology (IT) system is covered by an approved Privacy Threshold

Analysis (PTA) or Privacy Impact Assessment (PIA), if necessary.

4. Social Media: The Department engages in the operational use of social media5 only as authorized by DHS privacy policy, privacy laws applicable to DHS, applicable Federal

Government-wide policies, and other applicable statutory authorities. Consult DHS Privacy

Policy Instruction 110-01-001 for the Operational Use of Social Media, and your Component

Office of Public Affairs, Privacy Officer or PPOC for additional guidance.

For more information on DHS privacy compliance documentation, please consult our website.

Best Practices

When collecting PII/SPII from members of the public, ensure that all paper or electronic forms or processes are reviewed and approved by the DHS Forms Management Office (forms@hq.dhs.gov) prior to collection, and if possible, only collect PII/SPII directly from the individual.6 Collecting personal information from members of the public may trigger separate requirements under the

Paperwork Reduction Act (PRA),7 and may also require that the form contain a Privacy Act

Statement (see 5 U.S.C. §552a(e)(3)) by law or a separate Privacy Notice8 by policy to provide transparency and notice to the person about whom PII/SPII is being collected, and describe how the Department will use their PII/SPII. Additionally, a Forms Privacy Threshold Analysis should be completed on all forms, whether they be DHS-owned or from another agency, like OPM. Please contact your Component Privacy Office for instructions.

Consistent with the FIPP on data minimization, you should only collect PII that is directly relevant

5. “Operational use” means authorized use of social media to collect personally identifiable information for the purpose of enhancing situational awareness, investigating an individual in a criminal, civil, or administrative context, making a benefit determination about a person, making a personnel determination about a

Department employee, making a suitability determination about a prospective Department employee, or for any other official Department purpose that has the potential to affect the rights, privileges, or benefits of an individual. Operational use does not include the use of search engines for general Internet research, nor does it include the use of social media for professional development such as training and continuing education or for facilitating internal meetings.

6. For example, subsection (e)(2) of the Privacy Act of 1974, 5 U.S.C. § 552a, states that “[e]ach agency that maintains a system of records shall…collect information to the greatest extent practicable directly from the subject individual when the information may result in adverse determinations about an individual’s rights, benefits, and privileges under Federal programs.”

7. For more information about the Paperwork Reduction Act (PRA), 44 U.S.C. 3501 et seq., contact the DHS PRA

Program Office at DHS.PRA@hq.dhs.gov.

8. Privacy Act Statements should only be used when the information collection is from U.S. citizens or Lawful

Permanent Residents (LPR). Because Privacy Act rights are no longer granted to non-U.S. Citizens/non-LPRs, a form that collects information regarding such individuals should have a Privacy Notice pursuant to DHS policy.

https://www.dhs.gov/sites/default/files/publications/Instruction_110-01-001_Privacy_Policy_for_Operational_Use_of_Social_Media_0.pdf1 https://www.dhs.gov/sites/default/files/publications/Instruction_110-01-001_Privacy_Policy_for_Operational_Use_of_Social_Media_0.pdf1 https://www.dhs.gov/topic/privacy mailto:forms@hq.dhs.gov mailto:DHSPRA@hq.dhs.gov

10 | Handbook for Safeguarding Sensitive PII DHS Privacy Policy Directive 047-01-007 and necessary to accomplish the specified purpose, retain PII only for as long as necessary to fulfill the specified purpose, and destroy it when permitted to do so, in accordance with the applicable records retention schedule.

Social Security numbers: DHS programs shall only collect, use, maintain, and disseminate

SSNs when required by statute or regulation, or pursuant to a specific authorized purpose.

Absent these requirements, DHS programs shall not collect or use an SSN as a unique identifier; rather, programs should create their own unique identifiers, or use a different piece of information to identify or link information concerning an individual. If you need to use a unique number or data element to identify individuals, the DHS Privacy Office suggests using email addresses or case record numbers instead of SSNs.

Provide instructions to the individual, as appropriate, on how to properly submit SPII, for example:

“The information requested is Sensitive

Personally Identifiable Information. To properly secure this information, please email it to me within an encrypted or password-protected attachment, and email the password separately.”

Collection of PII via Mobile Applications

As the use of mobile technology to send and receive information becomes more prevalent, DHS has begun to develop and deploy mobile applications, also known as

“mobile apps,” for use by the public and by DHS staff.

Mobile apps present privacy risks that are unique to mobile app technology. The risks involve how PII, SPII, and other sensitive content such as location information, third party data, mobile device identifiers, and metadata are collected, stored, used, and shared. Additionally, mobile devices and mobile apps may be more vulnerable to Internet security threats, which could potentially compromise a user’s information, and even pose a threat to DHS systems.

To address these concerns, the DHS Privacy Office issued Instruction 047-01-003, Privacy Policy for

DHS Mobile Applications to ensure that appropriate privacy protections are incorporated into mobile apps developed by, on behalf of, or in coordination with the Department. The policy also requires that DHS mobile apps be run through the DHS “Carwash” process, which scans the application’s code to ensure that it does not contain privacy or security vulnerabilities.

https://www.dhs.gov/publication/privacy-policy-dhs-mobile-applications https://www.dhs.gov/publication/privacy-policy-dhs-mobile-applications

DHS Privacy Policy Directive 047-01-007 Handbook for Safeguarding Sensitive PII | 11

Storing Sensitive PII

IT Systems

Once collected, SPII should be stored based on the specifications for either electronic or paper storage outlined in the SORN, if necessary and applicable, under the section titled: Policies and

Practices for Storage of Records. Databases or IT systems storing SPII should employ technical safeguards and access controls to restrict access to staff with an official need to know the Sensitive

Information. The same rule applies to PII (not just SPII) stored in the cloud. Be sure to consult the

Program Manager for specific guidance on storage and access controls for the applicable system or program.

Internal Websites and Shared Network Drives

When saving or posting SPII on shared network drives, SharePoint collaboration sites, or Outlook calendars, follow these guidelines:

Shared Network Drives

Shared network drives must have access restrictions in place so only individuals with an official need to know can access SPII saved on them. Contact your Help Desk for instructions.

SharePoint Collaboration Sites

All collaboration sites must display visual cues indicating whether SPII is authorized to be posted. DHS

Components may build more detailed controls and technical enhancements into their respective collaboration sites, so please contact your Component Privacy Officer or PPOC before establishing a new collaboration site that will contain SPII. A PTA may also be required.

Outlook Calendars

It is best to avoid posting SPII on your Outlook Calendar, but if you absolutely need to, always activate Microsoft Outlook’s “Private” feature to mark a meeting or appointment containing SPII as

“Private” so that other people who do not have an official need to know, but have access to your calendar, cannot see details of the item. For example, do not post information regarding confidential personnel matters. Also, do not include SPII in the subject line of a meeting or appointment.

12 | Handbook for Safeguarding Sensitive PII DHS Privacy Policy Directive 047-01-007

Using Sensitive PII

Proper Authorization is Needed

Access or use of SPII is only permitted when you have an official need to know the information, that is, when the information relates to your official duties. As stated above, databases or IT systems storing SPII should employ technical safeguards and access controls to restrict access to staff with an official need to know the Sensitive Information. Never browse files containing SPII out of curiosity or for personal reasons.

Guidance and Training

Use of PII must be compatible with the purpose stated in DHS notices, such as a SORN, PIA, Privacy

Act Statement, or, for those not covered by the Privacy Act, a Privacy Notice provided to the individuals from whom the information was collected. If you are unsure about whether a specific use is appropriate, you should confirm with your Component Privacy Officer or PPOC.

In addition, prior to accessing SPII, all DHS staff, including contractors, must complete onboarding privacy awareness training and the mandatory online privacy awareness course, Privacy at DHS:

Protecting Personal Information, available on all Component Learning Management Systems.9

Online privacy training must be completed annually.

Finally, contractors are required to follow Federal Acquisition Regulation (FAR) provisions when handling PII and SPII (see, e.g., Title 48 of the Code of Federal Regulations (CFR), Federal Acquisition

Regulations System). Moreover, the Department has established policies and procedures for how contractors should handle SPII (e.g., Management Directive 11042.1, Safeguarding Sensitive But

Unclassified (For Official Use Only) Information.)

When accessing or using SPII, take proactive steps to prevent a privacy incident.10

Equipment

SPII may only be accessed, viewed, saved, stored, or hosted on DHS-approved, encrypted portable electronic devices (PEDs), such as laptops, tablets, and smartphones, as well as encrypted government-issued USB flash drives, CDs, DVDs, and external hard drives. Personally-owned equipment and software cannot be used to process, access, or store sensitive information without the written prior approval of the DHS CISO.11

All portable media must be encrypted pursuant to DHS Sensitive Systems Policy Directive 4300A, and kept locked and secured while unattended at work, teleworking, and in transit.

Protect against “shoulder surfing” when viewing SPII on your PED.

Never share user names, passwords, or PIV cards with anyone, including co-workers.

9. Onboarding privacy training is mandated by OMB Circulars A-130 and A-108, and annual online privacy training is mandated by OMB Memorandum M-17-12.

10. See definition of a privacy incident on page 7.

11. Pursuant to DHS Sensitive Systems Policy Directive 4300-A, version 13.1, July 27, 2017.

https://www.dhs.gov/publication/md-110421 https://www.dhs.gov/publication/md-110421

DHS Privacy Policy Directive 047-01-007 Handbook for Safeguarding Sensitive PII | 13

Paper

Physically secure SPII (e.g., in a locked office, drawer, cabinet, desk, or safe) when not in use.

Never leave SPII unattended on a desk, network printer, fax machine, or copier.

Avoid sending SPII using a fax machine unless you can confirm the fax is sent directly to the intended recipient. If possible, scan, encrypt, or password-protect the document, and email it instead.

Protect against “shoulder surfing” or eavesdropping by being aware of your surroundings when processing or discussing SPII and employee or contractor personnel data.

Consider using a Privacy Data coversheet when handling hard copy SPII.

In transit

Obtain authorization from your supervisor before removing electronic or hard copy documents containing SPII from the workplace.

Do not take SPII home or to any non-DHS approved worksite in either paper or electronic format, unless appropriately secured.

Never perform official work on your laptop or tablet while on mass transit (e.g., train, plane) where SPII may be viewed by shoulder surfers who do not have a need to know. Furthermore, working while in transit increases the risk for equipment and documents to be left behind and then compromised.

Do not leave your PED in a car. If lost or stolen, immediately report it as a lost asset according to your Component’s reporting procedures, and inform your supervisor.

When traveling by plane, never place your PED inside of your checked luggage, unless TSA officials instruct you otherwise.

Teleworking

Consult the three previous sections under Best Practices above, as well as DHS Management

Instruction 123-05-001, Telework Program.

Do not transfer files to your home computer or print agency records on your home printer.

Never use your personal email to conduct official business. Contractors should not utilize contractor email addresses to conduct DHS business unless specifically authorized by the contract.

Do not send emails containing SPII to or from your personal email account, or to another person’s personal email account.

Obtain authorization from your supervisor to remove electronic or hard copy documents containing SPII from the workplace.

Secure your PED and any hard copy SPII while teleworking, and ensure that any other household members cannot access them. For example, in a locked home office, file cabinet, drawer, or hotel safe.

http://dhsconnect.dhs.gov/policies/Instruction%20Supplements/123-05-001_Telework_Program.pdf http://dhsconnect.dhs.gov/policies/Instruction%20Supplements/123-05-001_Telework_Program.pdf

14 | Handbook for Safeguarding Sensitive PII DHS Privacy Policy Directive 047-01-007

Disseminating Sensitive PII — Information Sharing

Proper Authorization Is Needed

Internally

You are authorized to share SPII with other DHS staff only if the recipient has an official need to know, and/or the person whose SPII is being shared consents to the sharing.

Externally

You are authorized to share PII outside of

DHS if:

1. The person whose PII is being shared requests or consents to the sharing; or

2. The recipient’s need for the information is related to his or her official duties;

and

3. If the PII is contained in records covered by a system of records, there must be an authorized disclosure exception (e.g., a published routine use in the applicable SORN12) that permits sharing pursuant to the Privacy Act, 5

U.S.C. § 552a(b); and

4. The sharing of PII to third parties must be consistent with Department policy, including DHS’s privacy policies13 and information-sharing policies;14 and

5. Sharing must be consistent with all

Component policies. For example, Component Privacy Officers should evaluate any proposed instances of sharing SPII with third parties to assess whether the sharing is authorized, and if a new or updated Privacy Notice is required.

Refer External Requests for

Sensitive PII

From the public to your FOIA

Officer

From the media to your Office of Public Affairs

From Congress to your Office of

Legislative Affairs

From law enforcement to your

Component Privacy Officer or

PPOC and Chief Counsel

From other U.S. and foreign government agencies to your

Component Privacy Officer or

PPOC.

12. All DHS SORNs are posted on the DHS Privacy Office website (www.dhs.gov/privacy).

13. See, e.g., DHS Directive 047-01, Privacy Policy and Compliance [with associated DHS Instruction 047-01-001, Privacy Policy and Compliance]; DHS Privacy Policy Guidance Memorandum 2017-01, DHS Privacy Policy

Regarding Collection, Use, Retention, and Dissemination of Personally Identifiable Information (April 27, 2017);

DHS Privacy and Civil Liberties Policy Guidance Memorandum 2009-01/Privacy Policy Directive 262-11, The

Department of Homeland Security’s Federal Information Sharing Environment Privacy and Civil Liberties

Protection Policy.

14. See, e.g., DHS Directive 262-03, DHS Information Sharing Environment Technology Program [with associated DHS

Instruction 262-03-001, Implementing the DHS Information Sharing Technology Program]; DHS Directive 103-01, Enterprise Data Management Policy; DHS Directive 262-05, Information Sharing and Safeguarding [see associated Instructions at http://dhsconnect.dhs.gov/policies/Pages/directives.aspx]; DHS Directive 262-07, Disclosure of Homeland Security Information.

http://www.dhs.gov/privacy) http://dhsconnect.dhs.gov/policies/Pages/directives.aspx

DHS Privacy Policy Directive 047-01-007 Handbook for Safeguarding Sensitive PII | 15

Unauthorized Dissemination of SPII

Social Engineering

Social engineering is the use of deception to manipulate individuals into divulging confidential or personal information that may be used for fraudulent purposes. Please be wary of callers posing as authorized users, Help Desk representatives, or senior officials, asking for personal information or assistance to access DHS information or IT systems. Do not give sensitive information to anyone until you have confirmed their identity15 and that they have an official need to know.

Phishing

Phishing is a technical form of social engineering that uses email or malicious websites to elicit personal information by posing as a trustworthy individual or organization. Be suspicious of emails from unknown senders that solicit personal information or direct you to a website that requests personal information.

To counter these attacks, follow these anti-phishing practices:

Exercise caution when asked for information – personal or professional – through emails, websites, social media interactions, and even phone calls.

Never enter SPII in a pop-up window.

Avoid clicking on hyperlinks in emails or on websites, if possible.

Forward all suspicious emails to DHSSPAM@hq.dhs.gov, or your Component spam email box.

Minimize Dissemination of SPII

Whenever possible, minimize the duplication and dissemination of electronic files and papers containing SPII.

Only print, extract, or copy SPII when there are no other means of disseminating the data.

Before emailing, printing, or copying, redact SPII that is beyond the scope of the data request or is not appropriate for the requestor to have.

In some instances, it may be appropriate to create new spreadsheets or databases that contain

SPII from a larger file or database. Before doing so, consult Attachment S1 in the DHS Sensitive

Systems Policy Directive 4300A: DHS Policy and Procedures for Managing Computer-Readable

Extracts (CRE) Containing Sensitive PII, which can be found on DHS Connect. This document outlines DHS policies on how to manage computer readable extracts containing SPII.16

Unauthorized replication or commingling of records may constitute an unauthorized or illegal

Privacy Act system of records. Your Component Privacy Officer or PPOC should be consulted to provide guidance specific to the situation.

Social Media: The Department engages in the operational use of social media17 only as authorized by DHS privacy policy, privacy laws applicable to DHS, applicable Federal

15. The OCSO recommends the following methods to confirm identity: (1) ask for their government identification card; (2) check their name in the government email address (GAL); or (3) ask your security officer; they can check with personnel security.

mailto:DHSSPAM@hq.dhs.gov http://dhsconnect.dhs.gov/org/comp/mgmt/cio/iso/Pages/sspolicy.aspx

16 | Handbook for Safeguarding Sensitive PII DHS Privacy Policy Directive 047-01-007

Government-wide policies, and other applicable statutory authorities. Consult DHS Privacy

Policy Instruction 110-01-001 for the Operational Use of Social Media, and your Component

Office of Public Affairs, Privacy Officer or PPOC for additional guidance.

Email

Although DHS policy permits emailing SPII within the DHS network without encryption or password

-protection to a recipient with an official need to know, some Components do require encryption or password-protection. The DHS Privacy Office strongly recommends that you redact, password-protect, or encrypt SPII emailed internally.18 Use particular caution when emailing SPII to distribution lists.

Externally [beyond the DHS.gov domain/network]

Never email SPII to or from a personal email account. Use of personal email accounts over DHS furnished equipment or network connections or to perform government business requires the approval of the DHS Under Secretary for Management (USM).19 Email SPII externally only within an encrypted or password-protected attachment using WinZip or Adobe Acrobat,20 and provide the password separately by phone or email. Send only to individuals with an official need to know.

Note: If someone outside of DHS sends you SPII in an unprotected manner, you must protect that data in the same manner as all SPII you handle once you receive it.

For example, if someone outside of DHS sends you unsecured SPII in the body of an email, you must delete the SPII from the body of the email, put it in a separate attachment, and encrypt or password-protect the data if you wish to respond to that individual or email it to another recipient outside the dhs.gov domain. Alternatively, you can redact the SPII before responding to or forwarding the email.

16. The Chief Human Capital Office’s (CHCO) Lockbox process is a best practice for the safe handling of non-routine or ad hoc CREs. Contact CHCO for the Lockbox Standard Operating Procedure.

17. “Operational use” means authorized use of social media to collect personally identifiable information for the purpose of enhancing situational awareness, investigating an individual in a criminal, civil, or administrative context, making a benefit determination about a person, making a personnel determination about a

Department employee, making a suitability determination about a prospective Department employee, or for any other official Department purpose that has the potential to affect the rights, privileges, or benefits of an individual. Operational use does not include the use of search engines for general Internet research, nor does it include the use of social media for professional development such as training and continuing education or for facilitating internal meetings.

18. More information on the standards and use of encryption within the Federal Government and DHS can be found in the Department of Commerce’s National Institute of Standards and Technology (NIST) (https:// www.nist.gov/), including the following publications: NIST Special Publication 800-53, “Security Controls and

Assessment Procedures for Federal Information Systems and Organizations”; NIST Special Publication 800-171, “Protecting Controlled Unclassified Information in Nonfederal Information Systems and Organizations”; and

Federal Information Processing Standards Publication (FIPS) 140-2, “Security Requirements for Cryptographic

Modules.”

19. Sending email to a personal account can trigger numerous vulnerabilities. See DHS Sensitive Systems Policy

Directive 4300A, version 13.1, July 27, 2017. However, in some cases, it may be necessary to do so, for example, when CHCO communicates with job applicants.

20. For instructions on how to encrypt documents with WinZip or Adobe Acrobat Editor, consult your Help Desk.

Note that OMB Circular A-130 requires the use of encryption for all Sensitive Information (FIPS 199 moderate- or high-impact) at rest and in transit. DHS is currently working to implement Public Key Infrastructure encryption for emailing Sensitive Information both internally and externally in HQ and all Components.

https://www.dhs.gov/sites/default/files/publications/Instruction_110-01-001_Privacy_Policy_for_Operational_Use_of_Social_Media_0.pdf1 https://www.dhs.gov/sites/default/files/publications/Instruction_110-01-001_Privacy_Policy_for_Operational_Use_of_Social_Media_0.pdf1 https://www.nist.gov/ https://www.nist.gov/ http://dhsconnect.dhs.gov/org/comp/mgmt/cio/iso/Documents/4300A%20Sensitive%20Systems%20Handbook.pdf http://dhsconnect.dhs.gov/org/comp/mgmt/cio/iso/Documents/4300A%20Sensitive%20Systems%20Handbook.pdf

DHS Privacy Policy Directive 047-01-007 Handbook for Safeguarding Sensitive PII | 17

Mail21

SPII should be sent in accordance with your Component’s inter-office mail procedures or by DHS courier. Consult your supervisor for your office’s accountable inter-office mail procedures.

Confirm that the intended recipient received the information.

Externally

For mailings containing a small amount of SPII (such as individual employee actions):

Seal SPII materials in an opaque envelope or container and mail it using First Class Mail, Priority Mail, or a traceable commercial delivery service (e.g., UPS, FedEx).

Never place SPII on an address label, mailing address, package, box, etc.

For large data extracts, database transfers, backup tape transfers, or similar collections of SPII:

Encrypt the data (if possible), and use a receipted delivery service (i.e., Return Receipt, Certified or Registered mail) or a tracking service (e.g., "Track & Return") to ensure secure delivery is made to the appropriate recipient.

Equipment

Avoid sending SPII using a fax machine unless you can confirm the fax will be received by the intended recipient. If possible, scan, encrypt, or password-protect the document, and email it instead.

DHS staff are prohibited from using any non-government-issued removable media (such as USB drives), or from connecting such devices to DHS equipment or networks, or to store sensitive information on such devices. Some Components prohibit the use of all USB drives. Contact your

Component Privacy Officer for guidance.

21. Components should follow the procedures established by DHS Management Directive (MD) 11042.1, Safeguarding Sensitive But Unclassified (For Official Use Only) Information, for the transportation or mailing of backup media.

http://dhsconnect.dhs.gov/policies/Instructions/11042.1%20Safeguarding%20Sensitive%20But%20Unclassified%20(For%20Official%20Use%20Only)%20Information.pdf http://dhsconnect.dhs.gov/policies/Instructions/11042.1%20Safeguarding%20Sensitive%20But%20Unclassified%20(For%20Official%20Use%20Only)%20Information.pdf

18 | Handbook for Safeguarding Sensitive PII DHS Privacy Policy Directive 047-01-007

Disposing of Sensitive PII

You should periodically review the hard copy and electronic SPII in your possession to determine if it is still needed, especially prior to an office move or when leaving the agency. SPII, including that found in archived emails, must be disposed of when no longer required, consistent with the applicable NARA-approved records retention schedule,22 or as identified in the applicable SORN or

PIA published on www.dhs.gov/privacy, in a manner that prevents loss, theft, misuse, or unauthorized access. In addition, you should determine whether the SPII is subject to a litigation hold or FOIA request before determining the appropriate course of action.23

For questions about records retention schedules, contact your Component Records Officer, or email

DHSRecordsManagement@hq.dhs.gov.

If destruction is required, take the following steps:

Printed material must be destroyed using an approved cross-cut shredder or burn bag, or secured in a locked and properly-marked bin.

Be especially alert during office moves and times of transition when large numbers of records are at risk.

PEDs containing SPII must be sanitized according to your Information Security System Manager’s standards when no longer needed.

Retention of data in SharePoint must be consistent with the applicable records retention schedule for the original data collection.

If you are leaving the agency and determine that the SPII in your possession should not be destroyed, ask your supervisor to transfer it to a trusted DHS employee who either has an official need to know the SPII for official purposes, or who can secure it upon your departure. Follow the instructions in the factsheet, How to Safeguard PII When Leaving DHS, to properly secure, transfer, or destroy any SPII you may have stored in paper or electronic form during your tenure. Do not leave any SPII unattended in the office space you are vacating.

22. A records schedule provides mandatory instructions for the disposition of the records (including the transfer of permanent records and disposal of temporary records) when they are no longer needed by the agency. As part of the ongoing records life cycle, disposition should occur in the normal course of agency business. All

Federal records must be scheduled (6 C.F.R. Part 1225) either by an agency schedule or a General Records

Schedule (GRS).

23. To make this determination, contact your Component FOIA Officer or General Counsel.

http://www.dhs.gov/privacy mailto:DHSRecordsManagement@hq.dhs.gov

DHS Privacy Policy Directive 047-01-007 Handbook for Safeguarding Sensitive PII | 19

Reporting a Privacy Incident

You must report all privacy incidents, whether suspected or confirmed, immediately to your

Component Help Desk, Security Operations Center (SOC), Privacy Officer, or PPOC.

For privacy incident response Points of Contact in every Component, please refer to Appendix

A of the Privacy Incident Handling Guidance, listed in the Authorities section.

Respond promptly to any requests about a privacy incident from your Component Help

Desk, SOC, or Privacy Office.

Document or maintain records of information and actions relevant to the privacy incident, as they may be required to investigate and remediate the incident.

Any alleged violations that may constitute criminal misconduct, identity theft, or other serious misconduct, or reflect systemic violations within the

Department, will be reported to the DHS Office of the Inspector General (OIG) by the appropriate individuals as part of the privacy incident reporting and investigation process.

For more information on privacy incident reporting and handling, consult:

DHS’s Privacy Incident Handling Guidance, listed in the Authorities section;

specific Component guidance; and

DHS Privacy Policy Instruction 047-01-006, Privacy Incident Responsibilities and Breach Response

Team, listed in the Authorities section.

https://www.dhs.gov/publication/privacy-incident-handling-guidance https://www.dhs.gov/publication/privacy-incident-handling-guidance

20 | Handbook for Safeguarding Sensitive PII DHS Privacy Policy Directive 047-01-007

Resources

Factsheets:

How to Safeguard Sensitive PII

How to Safeguard Sensitive PII When Leaving DHS

How to Prevent Online Harassment From “Doxxing”

DHS privacy policies

Federal Privacy Council identity theft resources

Identity Theft Resource Center

US-CERT’s cyber tip sheets offer advice on common security issues for non-technical computer users https://www.dhs.gov/policy https://www.fpc.gov/identity-theft/ http://www.idtheftcenter.org/ https://www.us-cert.gov/ncas/tips image2.emf

FEMA_SharePoint_and_Teams_Governance.pdf

FEMA Enterprise SharePoint Governance Policies and Processes

FEMA Enterprise SharePoint Governance Policies and Processes

Table of Contents

ADMINISTRATION

PURPOSE

SCOPE

FEMA INTRANET GOVERNANCE PROCESS

FEMA INTRANET GOVERNANCE PRINCIPLES

CONTENT WEB APPLICATIONS

FEMA…

This is the start of the file's text. The full file is on GovTribe.

File details come from the government source that posted it. Updated .