Attachment 3.pdf
PDF 203 KB Posted
- Attached to
- SCDMV IT SERVICE MANAGEMENT SYSTEM State and local contract opportunity
- Solicitation number
- 5400024224
- Issued by
- Richland County, Bucksport CDP, South Carolina
About this file
This document is a security policy issued by the South Carolina Department of Motor Vehicles (SCDMV) under Policy AD-551, effective February 7, 2022. The policy establishes comprehensive information security standards and responsibilities for all DMV personnel, including employees, contractors, vendors, and third-party users who access DMV data or systems. The policy defines information security responsibilities across multiple organizational levels, including supervisors, managers, data owners, deputy directors, directors, the Chief Information Officer, the Information Security Officer, and the Executive Director. DMV personnel are required to read and acknowledge the policy through PowerDMS, with supervisors responsible for ensuring compliance and maintaining acknowledgment records. The policy mandates that all personnel achieve full compliance before accessing DMV-owned data or systems, and the policy will be reviewed and updated annually as needed.
The policy establishes specific procedures for reporting security incidents, distinguishing between computer-related and non-computer-related incidents, with computer incidents reported immediately to the Information Technology Help Desk at (803) 896-0566 during business hours or to the Network Operation Center at (803) 896-8792 after hours. Security awareness training is mandatory for all employees, initially conducted during orientation and reinforced through quarterly refresher courses via the agency's learning management system, with training records retained for a minimum of five years. The policy references multiple related DMV policies and state procedures covering appropriate computer use, email retention, personally identifiable information protection, data protection, access control, and incident response. Employees who violate the policy may face corrective action up to and including termination in accordance with DMV disciplinary policies. The Information Security Officer maintains primary responsibility for program implementation, compliance verification, incident coordination with law enforcement and state authorities, and annual penetration testing.
View the file
Other files for this state and local contract opportunity
| File | Type | Posted |
|---|---|---|
| Amendment 1.pdf | ||
| Attachment 1.pdf | ||
| Amendment 2.pdf | ||
| Attachment 2.pdf | ||
| Attachment 4.pdf | ||
| Solicitation.pdf | ||
| Amendment 3.pdf | ||
| Notice of Cancellation.pdf |
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
South Carolina Department of Motor Vehicles
POLICY AD-551 INFORMATION SECURITY
THE LANGUAGE USED IN THIS DOCUMENT DOES NOT CREATE AN EMPLOYMENT CONTRACT BETWEEN THE EMPLOYEE AND THE AGENCY. THIS DOCUMENT DOES NOT CREATE ANY CONTRACTUAL RIGHTS OR ENTITLEMENTS. THE AGENCY RESERVES THE RIGHT TO REVISE THE CONTENT OF THIS DOCUMENT, IN WHOLE OR IN PART. NO PROMISES OR ASSURANCES, WHETHER WRITTEN OR ORAL, WHICH ARE CONTRARY TO OR INCONSISTENT WITH THE TERMS OF THIS PARAGRAPH CREATE ANY CONTRACT OF EMPLOYMENT.
SECTION OF LAW: N/A
REQUIRED ACTION
• All DMV personnel are responsible for reading and following this policy.
• Supervisors/Managers are responsible to have every employee and new hire read this policy and electronically acknowledge it in PowerDMS. Supervisors/Managers must maintain acknowledgement reports for their area.
• DMV personnel must be in full compliance with Policy AD-551 Information Security before access will be granted to
DMV-owned data or systems.
• This policy will be reviewed annually and updated as needed.
DEFINITIONS
Computer related information security incidents: Suspected or actual unauthorized access, use, or disclosure of DMV confidential/restricted data or customer personal identification data contained in, on, or within DMV-owned or leased computers, servers, laptops, smart devices, cellular phones, electronic media storage devices, network devices, or any other electronic device capable of displaying or storing electronic data.
Data: Any information that is stored in DMV systems for supporting DMV operations. The format of the data can be structured as in a database, unstructured as in email, or a collection of data items such as an image library. Data is information about something, someone, or someplace.
Non-Computer related information security incidents: Suspected or actual unauthorized access, use, or disclosure of DMV confidential/restricted data or customer personal identification data contained in, on, or within paper products (forms, titles, letters, emails, etc.) and DMV-issued driver’s licenses and identification cards.
Non-Data: Programs, applications, control files, and such are not considered data. These entities are used to control and access data but in and of themselves do not describe anything specific.
Operational Data: Data that directly supports DMV functions. This generally does not include personal or ancillary data such as training presentations, project plans, etc.
Personnel: All individuals employed by the DMV and contractors/vendors/third parties who are authorized to perform services or do jobs for the DMV.
Third parties: ALL users of DMV data including Member Services accounts.
Personally Identifiable Information (PII): Refer to Policy AD-502 Personally Identifiable Information for this definition.
Security Incident: An occurrence that actually or potentially jeopardizes the confidentiality, integrity, or availability of an information system or the information the system processes, stores, or transmits or that constitutes a violation or imminent threat of violation of security policies, security procedures, or acceptable use policies.
PURPOSE/BACKGROUND
The DMV seeks a culture of security awareness, and this policy provides direction, clear standards and enhances, amplifies, and augments security consciousness for all DMV personnel. The DMV, as a public trust agency, must ensure full compliance with this policy to protect all forms of information from a wide variety of threats and loss.
GUIDELINES
A. INFORMATION SECURITY RESPONSIBILITIES
1. All DMV Personnel: The DMV seeks a culture of Information Security. All DMV Personnel are responsible for full compliance with this policy. Further, all employees are responsible for reporting any Information Security incidents through their chains of command in accordance with Paragraphs C and D below. Any suspected breach or loss of Social Security related information must be immediately reported in accordance with Paragraphs C and D below.
2. Supervisors: As first line leaders, they must know the processes and reduce the risks of information loss, theft, damage, or destruction.
3. Managers
a. Must function as the critical component within the chains of command with regards to Information
Security.
b. Must know all business processes regarding Information Security within their designated areas.
https://powerdms.com/link/IDS/document/?id=1225588
c. Must identify processes and make decisions in accordance with this policy regarding the security and safeguarding of information within their areas of responsibility to mitigate and reduce risk.
d. Must be vigilant with regards to all aspects of information, data, and PII use, storage, and distribution.
e. Shall be responsible to ensure PII data (including paper records) are secured and protected
ESPECIALLY after business hours.
4. Data Owners
a. Must ensure the integrity and accuracy of all data.
b. Must coordinate with the IT Department to validate all back-up copies of data.
c. Must coordinate with IT to ensure back-up copies of data are available, loaded, tested, and validated in a production environment, at least annually.
5. Deputy Directors are responsible for:
a. All forms of access control within their designated areas of responsibility. They determine who is granted and/or denied access to information as well as to what specific degree.
b. Physical security within their areas and the access to information distribution and filing systems which contain PII for either citizens or employees.
6. Directors are responsible for:
a. Participating in agency risk making decisions.
b. Making sound fiscal and personnel decisions regarding Information Security.
c. Ensuring the overall management and compliance of all aspects of this policy within their Directorates.
d. Informing South Carolina citizens of loss, damage, destruction, or theft of citizen data upon approval from the Executive Director.
7. Chief Information Officer is responsible for:
a. The technical security of data and information as well as ensuring the safe distribution of information by electronic conveyance.
b. Reporting any successful intrusion and/or penetration of DMV database information to the Director of Operations and the Information Security Officer within one hour of discovery of the compromise.
c. Ensuring a technical forensic capability remains persistently active regarding all aspects of Information Security.
d. Ensuring segregation of duties with regards to all aspects of data base management.
e. Establishing and maintaining a segregation of duties for data base administrators.
f. Establishing and maintaining segregation of duties and responsibilities associated with purchasing, development, testing, production, and end of lifecycle technical systems.
g. Reviewing quarterly the segregation of duties with the Information Technology Department.
h. Establishing and maintaining a data information intrusion alarm system which alerts a minimum of five
Information Technology employees when unauthorized personnel are within existing databases.
i. Establishing and maintaining an e-mail security system that protects the network from a wide variety of viruses, malware, and bot intrusion devices.
j. Reviewing and taking corrective action on email vulnerability scans and security email alerts that are generated from the security tools.
k. Establishing and maintaining an internet security system that protects the network from a wide variety of viruses, malware, and bot intrusion devices.
l. Reviewing and recording the results of Internet vulnerability reports that are generated by the security tools.
m. Reviewing and taking corrective actions for all threat alerts that are reported from all vulnerability software or appliances as part of network security risk reporting.
n. Monitoring Member Services for potential misuse of information.
o. Providing details of potential misuse to the Inspector General and to the Information Security Officer within eight working hours of discovery of potential misuse.
p. Overseeing e-mail retention; firewall and server security; password and biometric protections; VPN access program; data and information recovery planning; information back-up and disaster recovery systems; and all aspects of network security.
8. Information Security Officer is responsible for:
a. Establishing and managing the Information Security Program which includes audits, inspections, training and business decisions regarding the security of citizen’s information while working closely with the Chief Information Officer for strategic implementation.
b. Recommending priorities in all aspects of DMV business operations on matters affecting Information Security.
c. Ensuring full agency-wide compliance with all aspects of this policy as the responsible agent for DMV’s Information Security programs.
d. Conducting Branch Office and Headquarters checks to ensure compliance with this policy.
e. Studying internal processes and recommending more secure methods of conveyance and distribution of all aspects of PII to Directors.
f. Cultivating, reviewing, and interpreting new sources of information on current and emerging laws, rules, regulations, and industry practice relating to Information Technology and Agency security.
g. Working as a liaison between DMV and state authorities (including law enforcement agencies) to provide security incident reports and information. The ISO has the authority to coordinate internally and externally regarding all aspects of information security including federal, state, and local officials.
h. Coordinating with Inspector General on all security related matters.
i. Scheduling, coordinating, and conducting annual penetration testing and reporting the results to the
Executive Leadership Team.
j. If there is a suspected or confirmed breach or loss of PII or a security incident which includes Social
Security Administration (SSA) provided information, the ISO or designated representative must contact the SSA Regional Office Contact or the SSA Systems Security Contact identified in the SSA agreement.
If for any reason the ISO is unable to contact the SSA Regional Office or SSA Systems Contact within one hour, the ISO must report the incident by contacting the SSA’s National Network Service Center (NNSC) toll free at 1-877-697-4889 (select “Security and PII Reporting” from the options list). The ISO will provide updates as become available to the SSA contact as appropriate. Refer to DMV Information Security Incident Response Plan, AD-552 for more incident responses.
k. The ISO or designated representative will use DMV Form 551A, SSA – PII Loss Worksheet to compile the incident information and assist in reporting the incident to the SSA.
9. Executive Director
a. Is responsible for ensuring all aspects of the Information Security Policy and program are fully implemented and in full compliance with all standards established within this policy as well as all other applicable state and/or lawful directives.
b. Must make sound fiscal decisions to ensure citizen’s information is protected. This includes responsibility for all major security enhancements and equipment purchases that affect network security and the protection of citizens’ data and information.
c. Is the only individual authorized to release certain data (to include information, systems protection devices, security systems, and security software) to the public, or to the Executive, Judicial, or Legislative Branches of state government.
d. Is the only authorized official who can permanently terminate a systems interface with any public or private entity due to DMV security concerns.
B. INFORMATION SECURITY INCIDENTS
Examples of security incidents could include activities such as:
1. Attempts (either failed or successful) to gain unauthorized access to a system or its data.
2. Unwanted disruption or denial of service.
3. Unauthorized use of a system for the processing or storage of data.
4. Changes to system hardware, firmware, or software characteristics without the owner's knowledge, instruction, or consent.
C. REPORTING COMPUTER INFORMATION SECURITY INCIDENTS
DMV personnel must report any suspected security or security related event immediately upon discovery to Information Technology Help Desk at (803) 896-0566, option 6, during normal business hours. If the Help Desk is not immediately available, an employee should use the after normal business hours contact procedure listed below. The IT Help Desk will notify the ISO (803) 896-3985, email ISO@SCDMV.net, the CIO (803) 766-8659, CIO@SCDMV.net and the ISIRT at ISIRT@SCDMV.net. If the suspected security or security related event occurs after hours, it must be reported to the Network Operation Center (NOC) at (803) 896-8792 or email SCDMVNOC@SCDMV.net. The NOC will notify the ISO and the CIO by telephone and email and the ISIRT by email.
An employee should contact his supervisor as soon as possible after notifying one of the individuals listed above. If the event involves an individual’s immediate supervisor/manager and the employee is uncomfortable reporting to the supervisor/manager, the employee may report the incident to his deputy director, his director, or the Inspector General.
mailto:CIO@SCDMV.net mailto:ISIRT@SCDMV.net.
mailto:SCDMVNOC@SCDMV.net
Should an employee have any general questions concerning what constitutes a security incident or what policies and procedures are in place to govern institutional data, the employee can telephone or email the Chief Information Security Officer.
D. REPORTING NON-COMPUTER INFORMATION SECURITY RELATED INCIDENTS
DMV personnel must report any suspected security or security related event immediately upon discovery to their immediate supervisors and complete DMV Form 552B in accordance with DMV Procedure AD-552, Information Security Incident Response Plan.
E. IMPORTANT INFORMATION SECURITY RELATED DOCUMENTATION
1. All DMV personnel are required to read, acknowledge and follow the following Information Security-related DMV policies:
a. Policy AD-021 Property Responsibility
b. Policy AD-022 Telephone Usage (required for users assigned cell phones)
c. Policy AD-500 Appropriate Use of Computing Resources
d. Policy AD-501 Email Retention and Use
e. Policy AD-502 Personally Identifiable Information
f. Policy AD-503 Confidentiality of Information
g. Policy AD-504 Data Protection and Privacy
h. Policy AD-505 National Crime Information Center System (NCIC)
i. Policy AD-800 Investigations and Internal Affairs
j. Policy AD-900 Access to, Sale and Release of Information
k. Policy HR-205 Code of Conduct
l. Policy HR-601 Separation of Employment
2. The following Information Security-related DMV procedures must be read, acknowledged and followed by DMV personnel if it pertains to their job duties:
a. Procedure AD-023 Mobile Device Management
b. Procedure AD-526 Access Control
c. Procedure AD-527 SCDMV Remote Network Access
d. Procedure AD-528 SCDMV Network Management
e. Procedure AD-529 Information Technology Compliance
f. Procedure AD-530 Information Technology Strategy
g. Procedure AD-531 Software Development Life Cycle
h. Procedure AD-552 Information Security Incident Response Plan
i. Procedure AD-553 Information Security Risk Management
j. Procedure AD-554 Information Security Acquisitions, Development and Maintenance
k. Procedure AD-555 Information Security Asset Management
l. Procedure AD-556 Information Security Threat and Vulnerability Management
3. All DMV personnel are to comply with the following South Carolina Divisions of Information Security policies:
a. Master Policy
b. Asset Management Policy
c. Data Protection and Privacy Policy
d. Access Control Policy
e. Information Systems Acquisitions, Development, and Maintenance Policy
f. Threat Vulnerability Management Policy
g. Business Continuity Management Policy
h. IT Risk Strategy Policy
i. Mobile Security Policy
j. Human Resources and Security Awareness Policy
k. Physical Environmental Security Policy
l. Risk Management Policy
m. IT Compliance Policy
F. SECURITY AWARENESS TRAINING
The purpose of security and awareness training is to define the information security training requirements for DMV Employees, contractors, and third party users. User access to information assets and systems will only be authorized https://powerdms.com/link/IDS/document/?id=1224465 https://powerdms.com/link/IDS/document/?id=1225515 https://powerdms.com/link/IDS/document/?id=1225517 https://powerdms.com/link/IDS/document/?id=1225574 https://powerdms.com/link/IDS/document/?id=1225586 https://powerdms.com/link/IDS/document/?id=1225588 https://powerdms.com/link/IDS/document/?id=1225591 https://powerdms.com/link/IDS/document/?id=1225595 https://powerdms.com/link/IDS/document/?id=1225598 https://powerdms.com/link/IDS/document/?id=1225639 https://powerdms.com/link/IDS/document/?id=1225656 https://powerdms.com/link/IDS/document/?id=1225276 https://powerdms.com/link/IDS/document/?id=1225316 https://powerdms.com/link/IDS/document/?id=1225328 https://powerdms.com/link/IDS/document/?id=1225332 https://powerdms.com/link/IDS/document/?id=1225334 https://powerdms.com/link/IDS/document/?id=1225336 https://powerdms.com/link/IDS/document/?id=1225338 https://powerdms.com/link/IDS/document/?id=1225342 https://powerdms.com/link/IDS/document/?id=1225346 https://powerdms.com/link/IDS/document/?id=1225355 https://powerdms.com/link/IDS/document/?id=1225360 https://powerdms.com/link/IDS/document/?id=1225364 https://powerdms.com/link/IDS/document/?id=1225368 https://powerdms.com/link/IDS/document/?id=1225371 http://www.admin.sc.gov/files/Information%20Security%20Policy%20-%20Master%2006.13.14.pdf http://www.admin.sc.gov/files/InformationSecurityPolicy-AssetManagement9-25-2013.pdf http://www.admin.sc.gov/files/InformationSecurityPolicy-DataProtectionandPrivacy.pdf http://www.admin.sc.gov/files/InformationSecurityPolicy-AccessControl.pdf http://www.admin.sc.gov/files/InformationSecurityPolicy-InformationSystemsAcquisitionsDevelopment.pdf http://www.admin.sc.gov/files/Information%20Security%20Policy%20-%20Threat%20%20Vulnerability%20Management%20-%20042114.pdf http://www.admin.sc.gov/files/Information%20Security%20Policy%20-%20Business%20Continuity%20Management%20-%20042114.pdf http://www.admin.sc.gov/files/Information%20Security%20Policy%20-%20IT%20Risk%20Strategy%20-%20042114.pdf http://www.admin.sc.gov/files/InformationSecurityPolicy-MobileSecurity.pdf http://www.admin.sc.gov/files/Information%20Security%20Policy%20-%20HR%20and%20Security%20Awareness%209-25-2013.pdf http://www.admin.sc.gov/files/Information%20Security%20Policy%20-%20Physical%20%20Environmental%20Security%20-%20042114.pdf http://www.admin.sc.gov/files/InformationSecurityPolicy-RiskManagement.pdf http://www.admin.sc.gov/files/Information%20Security%20Policy%20-%20IT%20Compliance%20-%20042114.pdf for those users whose cyber security awareness training is current (e.g., having passed the most recent required training stage).
• The Training Unit will ensure initial security awareness training is conducted by all DMV employees during orientation and publish an annual refresher course via Power DMS.
• Human Resources will ensure that this policy is disseminated during the orientation of all new agency employees.
• An agency-designated security awareness training solution (e.g., KnowBe4) facilitates security awareness training. An agency-wide email notifies employees of enrollment.
• The Agency must provide security awareness training quarterly using our learning management system. Quarterly security awareness training will also serve as refresher training.
• The security awareness training solutions designate role-based security awareness training into two primary roles; agency role and IT Shared Services. The Agency role includes all employees that are not a member of IT Shared Services. The IT Shared Services role contains full time employees and contract personnel that provide operational security and technical support. IT Shared Services reports to the Chief Information Officer.
• Security awareness training records are retained for a minimum of five years.
G. CORRECTIVE ACTION: Employees violating this policy may be investigated in accordance with Policy AD-806, Internal Audits and/or Policy AD-800, Investigations and Internal Affairs. Employees violating this policy may be subject to corrective action up to and including termination in accordance with HR-202 Progressive Corrective Action Disciplinary Policy.
CONTACT/TELEPHONE: Information Security Officer (803) 896-3985
APPROVED BY:
DMV Executive Director
EFFECTIVE DATE: 02/07/2022
ATTACHEMENTS: AD-551A Restricted Cover Sheet, AD-551B Confidential Cover Sheet, AD-551C Internal Use Cover Sheet, AD-551D Reporting Loss of Social Security Administration-PII https://powerdms.com/link/IDS/document/?id=1225644 https://powerdms.com/link/IDS/document/?id=1225644 https://powerdms.com/link/IDS/document/?id=1225639 https://powerdms.com/link/IDS/document/?id=1225706 https://powerdms.com/link/IDS/document/?id=1225706 https://powerdms.com/link/IDS/document/?id=1224321 https://powerdms.com/link/IDS/document/?id=1224325 https://powerdms.com/link/IDS/document/?id=1224330 https://powerdms.com/link/IDS/document/?id=1224330 https://powerdms.com/link/IDS/document/?id=1224335
| THE LANGUAGE USED IN THIS DOCUMENT DOES NOT CREATE AN EMPLOYMENT CONTRACT BETWEEN THE EMPLOYEE AND THE AGENCY. THIS DOCUMENT DOES NOT CREATE ANY CONTRACTUAL RIGHTS OR ENTITLEMENTS. THE AGENCY RESERVES THE RIGHT TO REVISE THE CONTENT OF THIS DOCUMENT, ... |
| DEFINITIONS |
| GUIDELINES |
| F. SECURITY AWARENESS TRAINING |
File details come from the government source that posted it. Updated .