Attachment 5 AD-502.pdf

PDF 257 KB Posted

Attached to
SCDMV CUSTOMER MANAGEMENT SOLUTION State and local contract opportunity
Solicitation number
5400020925
Issued by
South Carolina

About this file

This is a policy document from the South Carolina Department of Motor Vehicles (SCDMV) establishing guidelines for the handling, storage, protection, and destruction of Personally Identifiable Information (PII). Policy AD-502 defines PII categories including customer records (photographs, social security numbers, addresses, telephone numbers, dates of birth, driver's license numbers, medical information, and financial account numbers), employee records (social security numbers, dates of birth, home addresses, and personal contact information), and information used for commercial solicitation purposes. The policy establishes mandatory responsibilities for all employees and contractors to access only authorized information necessary for job functions, maintain confidentiality and integrity of data, create secure passwords, report suspected breaches to supervisors or the Information Security Officer, and destroy PII when no longer needed. Managers and supervisors must ensure departmental procedures support confidentiality and integrity objectives, communicate restrictions to staff, and verify employee understanding of information security responsibilities. Technology managers are responsible for developing secure environments with appropriate architectural policies, implementation standards, and account administration procedures. Data owners must work with the Information Security Officer to understand legal restrictions, segregate information into logical groupings, define sensitivity levels, and authorize appropriate user access.

The policy mandates specific storage requirements for PII on both paper and electronic media, including encryption of customer-related PII while at rest, use of locked containers and secured rooms for physical documents, and restriction of PII storage to authorized servers rather than personal computer hard drives or unrestricted shared network drives. Electronic transfers of PII to non-DMV entities require Director-level approval and must be encrypted using IT-authorized software. Transportation of PII outside DMV facilities requires prior written approval from a Director and must be secured in locked carry-on luggage when traveling by air, with passwords or encryption keys transmitted through separate communication channels. The policy prohibits storage or transport of PII in checked baggage and requires protection of data during ground transportation through proper wrapping, labeling, and positive control by responsible individuals. Destruction of PII must occur through approved shredders, Sensitive Security Information disposal bins, or the IT Department Desktop Support Team for electronic media. The policy became effective October 30, 2019, and references related policies including AD-551 Information Security and AD-900 Access to, Sale of, and Release of Information.

View the file

Other files for this state and local contract opportunity

Other files attached to SCDMV CUSTOMER MANAGEMENT SOLUTION, newest first.
File Type Posted
Attachment 9 AD-503.pdf PDF
Attachment 6 NIST.pdf PDF
Amendment No.1.docx DOCX document
Attachment 7 AD-504.pdf PDF
Attachment 3 Card Design Standard.pdf PDF
Attachment 2 Web Services.docx DOCX document
Notice of Extension Of Award Posting #1.doc DOC document
Attachment 4 Customer Lookup Business Specifications.docx DOCX document
Attachment 13 Customer_Queue Table Data Requirements.txt TXT text file
Attachment 10.doc DOC document
Attachment 12 Eligibility Check For Appointments.docx DOCX document
Solicitation.docx DOCX document
Attachment 11 Software Table.docx DOCX document
Attachment 1 MVN Diagram.pdf PDF
Attachment 12 Eligibility Check For Appointments-Revised.docx DOCX document
Attachment 8 AD-551.pdf PDF
Show all 16

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

SOUTH CAROLINA DEPARTMENT OF MOTOR VEHICLES

POLICY AD-502 – PERSONALLY IDENTIFIABLE INFORMATION

THE LANGUAGE USED IN THIS DOCUMENT DOES NOT CREATE AN EMPLOYMENT CONTRACT BETWEEN THE EMPLOYEE AND THE AGENCY.

THIS DOCUMENT DOES NOT CREATE ANY CONTRACTUAL RIGHTS OR ENTITLEMENTS. THE AGENCY RESERVES THE RIGHT TO REVISE THE CONTENT OF THIS DOCUMENT, IN WHOLE OR IN PART. NO PROMISES OR ASSURANCES, WHETHER WRITTEN OR ORAL, WHICH ARE CONTRARY TO OR INCONSISTENT WITH THE TERMS OF THIS PARAGRAPH CREATE ANY CONTRACT OF EMPLOYMENT.

SECTIONS OF LAW: 18 USC §§ 2721 et seq., the Driver Privacy Protection Act; S.C. Code §§ 30-2-310 et seq., and S.C.

Code §§16-13-510, et seq., the Personal Financial Security Act; and S.C. Code §§ 30-2-30, et seq., the Family Privacy Protection Act

REQUIRED ACTION:

All employees are responsible for reading and following this policy.

Supervisors/Managers are responsible to have every employee and new hire read this policy and electronically acknowledge it PowerDMS. Supervisors/Managers must maintain acknowledgement reports for their area.

SECTION I: DEFINITIONS

Data at rest: Refers to inactive data which is stored physically in any digital form (e.g. databases, data warehouses, spreadsheets, archives, tapes, off-site backups, mobile devices etc.). Data that is travelling over the network or temporarily residing in computer memory to be read or updated is not considered at rest.

Protected Health Information (PHI): Any information about health status, provision of health care, or payment for health care that can be linked to a specific individual.

SECTION II: PURPOSE/BACKGROUND

This policy establishes guidelines for what the Department of Motor Vehicles considers Personally Identifiable Information (PII) to be and how PII should be handled.

SECTION III: GUIDELINES

A. PERSONALLY IDENTIFIABLE INFORMATION

PII is any representation of information that permits the identity of an individual to whom the information applies to be reasonably gathered or figured out by any means.

Below is a listing of PII based on situations that routinely occur in the DMV. The information below should be considered in its entirety. This information is grouped according to Customer Records, Employee Records, Commercial Solicitation and Combinations of Information that can constitute PII.

1. Customer Records

a. In all cases for Customer Records, PII specifically includes:

1. an individual's photograph or digitized image;

2. social security numbers;

3. name;

4. address (but not the 5-digit zip code);

5. telephone number;

6. dates of birth;

7. driver's license or identification number;

8. home telephone number;

9. medical or disability information;

10. checking account numbers;

11. savings account numbers;

12. credit card numbers;

13. debit card numbers;

14. personal identification (PIN) numbers;

15. electronic identification numbers; and

16. digital signatures.

b. In all cases for Customer Records, the following PII shall be considered “highly restricted personal information”:

1. social security number;

2. an individual’s photograph or digitized image; and

3. medical or disability information.

2. Employee Records (In all cases)

a. Social security numbers;

b. Dates of birth;

c. Home address;

d. Home telephone numbers;

e. Personal cell phone numbers; and

f. Medical and/or disability information.

3. Commercial Solicitation

The following information is PII only for purposes of commercial solicitation as defined in the Family Privacy Protection Act SC Code §30-2-10:

a. education level;

b. financial status;

c. account or identification number issued by or used, or both, by any federal or state governmental agency or private financial institution;

d. employment history;

e. height;

f. weight;

g. race;

h. other physical details;

i. signature;

j. biometric identifiers; and

k. any credit records or reports.

4. Combinations of Information

Although individually these items may already be PII based on the lists above (for example, a social security number by itself), the following information is also PII when two (2) or more of these pieces of information are together:

a. Current or former names, including first and last names, middle and last names, or first, middle, and last names (not including electronic identification names or parent’s legal surname before marriage);

b. Current or former addresses (not including electronic mail addresses);

c. dates of birth;

d. driver’s license or identification number;

e. checking account numbers;

f. savings account numbers;

g. credit card numbers;

h. debit card numbers;

i. personal identification (PIN) numbers;

j. electronic identification numbers;

k. digital signatures; and

l. other numbers, passwords, or information which may be used to access a person’s financial resources, numbers, or information issued by a governmental or regulatory entity that uniquely will identify an individual or an individual’s financial resources.

B. PII RESPONSIBILITES

1. Employees and Contractors

a. You may only access information needed to perform your legitimate duties as a DMV employee and only when authorized by the appropriate Data Owner or designee.

b. You are expected to ascertain and understand the sensitivity level of information to which you have access through training, other resources or by consultation with your manager.

c. You may not in any way divulge, copy, release, sell, loan, alter or destroy any information except as authorized by the Data Owner within the scope of your professional activities.

d. You must understand and comply with the Agency’s requirements related to personally identifiable information

(PII).

e. You must adhere to the Agency’s requirements for protecting any computer used to conduct/transact DMV business regardless of the sensitivity level of the information held on that system.

f. You must protect the confidentiality, integrity and availability of the Agency’s information as appropriate for the information's sensitivity level wherever the information is located, e.g., held on physical documents, stored on computer media, communicated over voice or data networks, exchanged in conversation, etc.

g. You must handle information deemed internal use, confidential, or restricted under this policy in accordance with the Agency’s requirements for protecting internal use, confidential, or restricted data.

h. You must safeguard any physical key, ID card or computer/network account that allows you to access Agency information. This includes creating difficult-to-guess computer passwords and/or passphrases.

i. You must destroy or render unusable any internal use, confidential, or restricted information contained in any physical document (e.g., memos, reports, microfilm, microfiche) or any electronic, magnetic or optical storage medium (e.g., USB key, CD, hard disk, magnetic tape, diskette) before it is discarded.

j. You must report any activities that you suspect may compromise sensitive information to your supervisor or to the Agency Information Security Officer (ISO).

k. Your obligation to protect sensitive information continues after you leave the Agency.

l. While many federal and state laws create exceptions allowing for the disclosure of confidential information in order to comply with investigative subpoenas, court orders and other compulsory requests from law enforcement agencies, you will contact the Office of the General Counsel before taking any action against a request for such compulsory requests.

m. If you are performing work in an office that handles information subject to specific security regulations, you will be required to acknowledge that you have read, understand and agree to comply with the terms of this policy annually.

n. Email containing PII will not be sent outside the DMV without specific approval of the data owner. Any email containing PII data will be encrypted in accordance with DMV approved procedures.

o. An actual or possible loss of control, unauthorized disclosure, or unauthorized access of PII where unauthorized users gain potential access is known as a breach. Accordingly, once a breach is discovered, there are required remedial actions that must be taken promptly.

2. Managers and Supervisors

In addition to complying with the requirements listed above for all employees and contractors, managers and supervisors must:

a. Ensure that departmental procedures support the objectives of confidentiality, integrity and availability defined by the data owner and designees, and that those procedures are followed.

b. Ensure that restrictions are effectively communicated to those who use, administer, capture, store, process or transfer the information in any form, physical or electronic.

c. Ensure that each staff member understands his or her information security-related responsibilities.

3. Technology Managers In addition to complying with the policy requirements defined for all employees and contractors, and managers and supervisors, those who manage computing and network environments that capture, store, process and/or transmit Agency information, are responsible for ensuring that the requirements for confidentiality, integrity and availability as defined by the appropriate data owner are being satisfied within their environments. This includes:

a. Understanding the sensitivity level of the information that will be captured by, stored within, processed by, and/or transmitted through their technologies.

b. Developing, implementing, operating and maintaining a secure technology environment that includes:

1. A cohesive architectural policy,

2. Product implementation and configuration standards,

3. Procedures and guidelines for administering network and system accounts and access privileges in a manner that satisfies the security requirements defined by the data owners, and

4. An effective strategy for protecting information against generic threats posed by computer hackers that adheres to industry-accepted "best practices" for the technology.

c. Ensuring that staff members understand the sensitivity levels of the data being handled and the measures used to secure it.

4. Data Owners In addition to complying with the requirements listed above, Data Owners are responsible for:

a. Working with the Agency Information Security Officer and the Office of the General Counsel to understand the restrictions on the access and use of information as defined by federal and state laws and contractual obligations.

b. Segregating the information for which he or she is responsible into logical groupings, called information collections.

c. Defining the confidentiality, integrity and availability requirements (sensitivity level) for each of his or her information collections.

d. Conveying in writing the sensitivity level of each information collection for which he or she is responsible to the managers of departments that will have access to the collection.

e. Working with department managers to determine what users, groups, roles or job functions will be authorized to access the information collection and in what manner (e.g., who can view the information, who can update the information).

C. STORAGE OF PII

1. Customer Related PII on Paper Media

a. Branch Offices: All customer related PII shall be stored in the secured room or spare room that is locked and accessible by management only as directed by Procedure RA-004 End of Day Processing.

b. Headquarters: All customer related PII shall be secured in a locked container that is accessible by authorized personnel only.

2. Employee Related PII on Paper Media

a. All employee related records including Employee Performance Management System (EPMS) will be stored in a locked file cabinet and when possible in a secured room or office that is locked and accessible by authorized personnel only. When unattended, file cabinets will be locked and when an individual is away from their office for extended periods, the door closed and locked.

b. All materials containing PII will be stored and locked when not in use.

c. Social Security numbers will be redacted from EPMS copies other than those in official HR files.

3. Customer Related PII on Stored Electronic Media

a. All customer related PII will be encrypted while at rest. Customer PII is to be stored in authorized locations.

Customer PII is NOT to be stored on PC hard drives, removable storage devices (other than authorized servers) or in unrestricted shared files (P, G, X, etc. drives), i.e. shared files that do not have access restricted to those who need it.

b. In some instances, when approved by the data owner and the Information Security Officer, PII data may be stored on USB devices or CD/DVD. In those cases, the device will be password protected with a strong password with 256-bit encryption.

c. Storage devices containing PII shall be afforded the same security rating as the highest security rating of the data on devices.

d. Passwords for storage devices will be strong and afforded the same security rating as the highest security rating of the data on the devices.

e. Access to PII data stored on servers/SANs is restricted to business need only and any individual accessing that data will have their access granted only after meeting Agency security, training, and access requirements and data owner approval.

f. Server administrators will be granted access to servers containing PII only after being approved by the Network Administrator, Chief Information Officer (CIO) and the ISO. That approval process will include a training and certification process as defined and agreed upon by the CIO and ISO.

g. Fully privileged server administration rights will be limited to only those individuals whose job specifically requires such access.

h. Employees are granted access only to what they need to know for their work tasks and job functions.

4. Customer Related PII Storage

a. Official back-up copies of customer PII will be stored in authorized, secure containers.

b. Those back-up copies are routinely updated and stored at predetermined intervals.

c. Access to those files and data is controlled by the same processes identified for servers.

d. Records stored on non-magnetic tape will be treated as Paper Media.

D. SECURING/SHIPPING OF PII

1. Prepare PII (interoffice mail, scanning, etc.) to be sent to Blythewood Headquarters.

2. List all PII sent on Mail Checklist (located on the X: drive) to include quantities.

3. Place PII in approved polybag (do not seal at this time).

4. Review Mail Checklist to be sure all items are listed and placed in the polybag along with the PII.

5. Polybag must be shipped inside an approved box (either UPS produced box or for heavier volume, the approved box that is ordered from the DMV warehouse).

6. After determining which box to use, place the bagged work in the box and record the weight using the scales supplied to the branch offices.

7. Log into UPS’s CampusShip system to generate a shipping label to mail the PII. When completing this process, select two copies of the shipping label to be printed.

8. Record the tracking number off the waybill in the “Tracking Number” field on the Mail Checklist and place in the polybag.

9. The polybag must be sealed.

10. Tape one copy of the waybill to the sealed polybag.

11. The box must be sealed.

12. Tape the second copy of the waybill to the approved shipping box.

13. Stage box in designated area for UPS pickup.

E. RECEVING SHIPPED PII

1. Upon receipt of the PII from the branch office, open box and compare items listed on the Mail Checklist to actual PII received. Record any discrepancies and bring to manager (Mail Services) attention.

2. After verifying received PII, sort items for delivery to departments. Rubber band the verified Mail Checklist with the PII for scanning.

3. Take scanning PII to the Scanning Department. Take a copy of incoming PII from the Branch Office Report (Mail Services runs this report first thing in the morning) and compare to Mail Checklist from branches after scanning has verified on their side.

4. Compare the incoming PII from the Branch Office Report to the Mail Checklist to ensure all PII mailed to Headquarters was received.

5. If there is a discrepancy, notify the manager (Mail Services) so that an investigation can be begin to find out where that PII was sent.

F. ELECTRONIC TRANSFER OF PII TO NON-DMV ENTITIES

1. Customer Related PII

a. Customer related PII will not be released to non-DMV entities without prior, official approval by the data owner at the Director level.

b. All approved transfers of data will be encrypted before transmission using IT approved and authorized software.

2. Employee Related PII will be released only by the HR Department as approved by the Deputy Director of HR.

G. TRANSPORTING PII

1. PII shall not be transported outside a DMV facility without prior approval of a Director or, for Field Services

Administration personnel, the Field Services Administration Deputy Director.

2. Every DMV employee is responsible for protecting personally identifiable information (PII).

3. If an individual is approved to transport data in physical form during DMV approved air travel, the files must be wrapped in envelopes and properly labeled, and stored in locked carry-on luggage (PII cannot be a part of checked baggage when traveling). Note, approval to transport PII will be authorized in writing by the employee’s Director.

a. If an individual is approved to transport data in electronic portable media form during DMV approved travel;

the data must have appropriate safeguards to ensure adequate protections are in place. Electronic media will be stored in locked carry-on luggage (PII cannot be a part of checked baggage when traveling).

b. Ensure that portable media, when authorized for use, is encrypted and enforce current DMV password standards.

c. Disclose passwords or encryption keys through a different medium, such as a separate e-mail or a phone call, never in notes or documents accompanying the actual media.

d. Ensure that transported PII or Protected Health Information is delivered only to the appropriate individuals who are authorized to receive such information.

4. When traveling by automobile or other ground transportation, the PII must be wrapped in in envelopes, properly labeled, and under the positive control by the responsible individual at all times. PII must never be left in an unsecured vehicle nor in plain view in a locked vehicle.

H. DESTRUCTION OF PII

1. Destroy all PII when it is no longer needed and continued retention is not required.

2. Destruction may be accomplished by either shredding it in an approved shredder or disposing it in Sensitive Security

Information (SSI) disposal bins deployed throughout the Agency. These bins are gray in color and are locked with a padlock and chain and secured from movement. There are two kind of disposal bins to be used to recycle PII information. Bins that are have grey lids are to be used for normal recyclable paper and bins with red colored lids are to be used for Tyvec and cardboard PII envelopes. These bins will be secured for movement and only authorized personnel will move these bins to the loading dock for pick up by the recycling vendor for destruction.

3. Electronic media must be destroyed by the IT Department Desktop Support Team in conjunction with Warehouse personnel.

4. Diskettes or other magnetic media must be cleared (i.e. overwritten or zeroed) by the IT Department Desktop Support Team before re-use.

5. Records that are stored pending a scheduled destruction must be safeguarded to prevent unauthorized access during the interval before destruction.

6. Smart devices (iPads, iPhones, Blackberry, etc.) and cellular devices (phones, MiFI, etc.) will be sent to the Network Operations Center for removal and destruction of PII.

7. The NOC shall ensure all data is removed from all returned/unused/unassigned smart and cellular devices.

8. ALL unused cellular/smart devices will be treated as if they contain PII and sent to the NOC. Under no circumstances will a user, department head, or directorate ―store or retain unused smart or cellular devices.

CONTACT/TELEPHONE: Privacy Officer (803) 896-3985

APPROVED BY:

Executive Director

EFFECTIVE DATE: October 30, 2019

ATTACHMENTS: Policy AD-551 Information Security; Policy AD-900 Access to, Sale of, and Release of Information; AD Table 1: Release of Information Matrix; Procedure RA-004 End of Day Processing;

https://powerdms.com/link/IDS/document/?id=1225606 https://powerdms.com/link/IDS/document/?id=1225656 https://powerdms.com/link/IDS/document/?id=1225472 https://powerdms.com/link/IDS/document/?id=1225472 https://powerdms.com/link/IDS/document/?id=1225559

File details come from the government source that posted it. Updated .