Attachment 7 AD-504.pdf
PDF 156 KB Posted
- Attached to
- SCDMV CUSTOMER MANAGEMENT SOLUTION State and local contract opportunity
- Solicitation number
- 5400020925
- Issued by
- South Carolina
About this file
This is a Data Protection and Privacy Policy (Policy AD-504) from the South Carolina Department of Motor Vehicles (SCDMV) that establishes mandatory standards for handling, protecting, and managing all forms of data and personally identifiable information. The policy applies to all SCDMV personnel, including employees, contractors, vendors, and third-party service providers authorized to perform services for the agency. The policy requires annual training and acknowledgment of compliance, with supervisors responsible for ensuring all employees and new hires complete training through PowerDMS. Compliance with Policy AD-551 Information Security is mandatory before personnel can access SCDMV-owned data or systems.
The policy establishes four data classification categories—Public, Internal Use, Confidential, and Restricted—with corresponding protection requirements based on sensitivity levels and potential risk to the State. Key requirements include implementation of FIPS-140 validated encryption technologies such as AES 128-bit encryption for restricted and confidential data, encryption of wireless transmissions using WPA2 standards, and use of secure file transfer protocols for data transmission. The policy mandates Privacy Impact Assessments for systems handling personally identifiable information, certificates of data destruction for all equipment with storage capabilities, and three-year retention of purge certificates. Personnel violations may result in investigation and corrective action up to termination, with the SCDMV Privacy Officer providing contact support at (803) 896-3985.
View the file
Other files for this state and local contract opportunity
| File | Type | Posted |
|---|---|---|
| Attachment 4 Customer Lookup Business Specifications.docx | DOCX document | |
| Attachment 11 Software Table.docx | DOCX document | |
| Attachment 5 AD-502.pdf | ||
| Attachment 1 MVN Diagram.pdf | ||
| Attachment 12 Eligibility Check For Appointments-Revised.docx | DOCX document | |
| Attachment 8 AD-551.pdf | ||
| Attachment 9 AD-503.pdf | ||
| Attachment 6 NIST.pdf | ||
| Amendment No.1.docx | DOCX document | |
| Attachment 3 Card Design Standard.pdf | ||
| Attachment 2 Web Services.docx | DOCX document | |
| Notice of Extension Of Award Posting #1.doc | DOC document | |
| Attachment 13 Customer_Queue Table Data Requirements.txt | TXT text file | |
| Attachment 10.doc | DOC document | |
| Attachment 12 Eligibility Check For Appointments.docx | DOCX document | |
| Solicitation.docx | DOCX document |
Show all 16
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
South Carolina Department of Motor Vehicles
POLICY AD-504 DATA PROTECTION AND PRIVACY
THE LANGUAGE USED IN THIS DOCUMENT DOES NOT CREATE AN EMPLOYMENT CONTRACT BETWEEN THE EMPLOYEE AND THE AGENCY. THIS DOCUMENT DOES NOT CREATE ANY CONTRACTUAL RIGHTS OR ENTITLEMENTS. THE AGENCY RESERVES THE RIGHT TO REVISE THE CONTENT OF THIS DOCUMENT, IN WHOLE OR IN PART. NO PROMISES OR ASSURANCES, WHETHER WRITTEN OR ORAL, WHICH ARE CONTRARY TO OR INCONSISTENT WITH THE TERMS OF THIS PARAGRAPH CREATE ANY CONTRACT OF EMPLOYMENT.
SECTION OF LAW: N/A
REQUIRED ACTION
All SCDMV personnel are responsible for reading and following this policy.
Supervisors/Managers are responsible to have every employee and new hire read this policy and electronically acknowledge it in PowerDMS. Supervisors/Managers must maintain acknowledgement reports for their area.
SCDMV personnel must be in full compliance with Policy AD-551 Information Security before access will be granted to SCDMV-owned data or systems.
This policy will be trained, reviewed, and updated annually.
DEFINITIONS
Data: Any information that is stored in SCDMV systems for supporting SCDMV operations. The format of the data can be structured as in a database, unstructured as in email, or a collection of data items such as an image library. Data is information about something, someone, or someplace.
Personnel: all individuals employed by SCDMV and contractors/vendors/third parties who are authorized to perform services or do jobs for SCDMV.
Personally Identifiable Information (PII): Refer to Policy AD-502 Personally Identifiable Information for this definition.
Privacy Impact Assessment: A process which helps an organization to identify and reduce the privacy risks of a project or system.
PURPOSE/BACKGROUND
This policy provides direction and clear standards and enhances, amplifies, and augments security consciousness for all SCDMV personnel. SCDMV, as a public trust agency, must ensure full compliance with this policy to protect all forms of information from a wide variety of threats and loss.
GUIDELINES
A. DATA CLASSIFICATION
SCDMV shall categorize data in accordance with applicable federal and state laws, executive orders, directives, regulations, and information security guidance. Users who encounter information that is improperly labeled, according to the data classification descriptions below, shall consult with the owner of the information and/or the SCDMV Information Security and/or Data Privacy teams to determine the appropriate data classification. If multiple data fields with different classifications have been combined, the highest classification of information included shall determine the classification of the entire set. SCDMV data shall be classified into the following categories:
1. Public: Information intended or required for sharing publicly. Examples of public information include information provided on government websites and reports meant for public distribution. Unauthorized disclosure, alteration, or destruction of public data would result in minimum to no risk to the State.
2. Internal Use: Information that is used in SCDMV’s daily operations. Examples of internal use information include internal procedures and internal communications. Unauthorized disclosure, alteration, or destruction of internal use data would result in little risk to the State.
3. Confidential: Confidential information refers to sensitive information in custody of the SCDMV. Examples of confidential information include Social Security Administration validated full name and date of birth, credit card information, information security plan, system configuration standards, or information exempt from the South Carolina Freedom of Information Act (FOIA). Unauthorized disclosure, alteration, or destruction of confidential data could result in considerable risk to the State.
4. Restricted: Restricted information is highly sensitive information in custody or owned by the SCDMV and/or data which is protected by federal or state laws and regulations. Examples of restricted information may include, but are not limited to, Social Security Administration validated social security number, Federal Tax Information (FTI), and health information protected by the Health Insurance Portability and Accountability Act (HIPAA). Unauthorized disclosure, alteration, or destruction of restricted data could result in considerable risk to the State.
B. DATA PROTECTION
1. SCDMV Data
SCDMV is responsible for two major forms of information and data. SCDMV must provide the highest degree possible of overall information security. Protection of customers’ data is the number one priority of the organization.
a. The first form of data is that information personal to customers necessary to fulfill Department’s designated mission.
b. The second form of data is that information personal to SCDMV employees necessary to manage internal operations of the agency and/or necessary to manage the employees.
https://powerdms.com/link/IDS/document/?id=1225588
2. System and Communications Protection Policy and Procedures: Employees/contractors/vendors/non-paid work experience personnel shall follow acceptable use policies when transmitting data.
3. Cryptographic Key Establishment and Management
a. SCDMV shall implement mechanisms to ensure availability of information in the event of the loss of cryptographic keys by users.
b. SCDMV shall implement mechanisms to ensure the confidentiality of private keys.
c. SCDMV shall develop a mechanism to randomly select a key from the entire key space, using hardware-based randomization.
d. SCDMV shall implement appropriate controls to physically and logically safeguard the key-generating equipment from construction through receipt, installation, operation, and removal from service.
4. Cryptographic Protection (SC 17)
a. For restricted data or data protected by federal or state laws or regulations: SCDMV shall use Federal Information Processing Standards (FIPS)-140 validated [e.g., Advanced Encryption Standards (AES), Triple Data Encryption Algorithm (TDEA), Diffie-Hellman, RSA, Rivest Cipher 5 (RC5)] technology for encrypting confidential data.
b. SCDMV shall implement all encryption mechanisms to comply with this policy and support a minimum of, but not limited to, the industry standard, AES 128-bit encryption.
c. Users shall not use any proprietary encryption algorithms for any purpose, unless approved by the information security officer.
5. Transmission Confidentiality and Integrity
a. Confidential or restricted information transmitted as an email message shall be encrypted based on SCDMV encryption policy.
b. Any confidential or restricted information transmitted through a public network to and from vendors, customers, or entities doing business with SCDMV shall be encrypted or be transmitted through a tunnel encrypted by approved technologies such as virtual private networks (VPN) or point-to-point tunnel protocols (PPTP) like secure socket layers (SSL).
c. SCDMV shall implement wireless encryption standards such as Wi-Fi Protected Access 2 (WPA2), and VPN encryption for remote wireless and/or internal network configurations to encrypt wireless transmissions that are used for transmitting confidential or restricted information.
d. SCDMV shall utilize encrypted file transfer programs such as “secured File Transfer Protocol (SFTP)” ([FTP over Secure Shell (SSH)] and Secure Copy (SCP) to secure transfer of documents and data over the Internet. Only authorized users shall be able to initiate secure transactions.
6. Information and Data Security Equipment Erase/Turn In
a. Any device capable of storing data will have the storage medium purged before the equipment is returned to a vendor, or transferred to the state Surplus Property Office or any other non-SCDMV entity.
b. Any SCDMV-owned configurations or data will be removed from any stand-alone storage medium, and the individual removing the configurations or data will sign a certificate to verify the removal. A copy of the certificate will include the nomenclature and serial number of the device. The originator of the certificate must retain the original certificate and must send a copy to the IT Network Administrator. The original and the copy must be retained for three years.
c. Desktop workstations, portable laptops, tablets, external hard drives, USB storage devices, printers, fax machines and agency owned multi-function devices (copier, scanner, printer, fax) will be purged by the Desktop Support Team. The Desktop Support Team will sign a certificate to verify the removal. The certificate will list the nomenclature and serial number of the device. The Desktop Support Team Supervisor must retain the certificate for three years.
d. Servers and server related devices (tapes, SANs, switches, etc.) will be purged by the Server Team. If any server or server related devices cannot be purged by the Server Team, the purge will be performed by a third party vendor. The Server Team or the third party vendor will sign a certificate to verify the removal.
The certificate will list the nomenclature and serial number of the device. The originator of the certificate must retain the original certificate and must send a copy to the IT Network Administrator. The original and the copy must be retained for three years.
e. Network hardware, smart devices (iPhones, Blackberry, etc.), and cell phones will be purged by the Network Operations Center. The Network Operations Center will sign a certificate to verify the removal. The certificate will list the nomenclature and serial number of the device. The originator of the certificate must retain the original certificate and must send a copy to the Network Operations Center Manager. The original and the copy must be retained for three years.
f. Data storage devices in leased multi-function devices will be purged by the vendor/lessor. The department business unit responsible for the device must obtain from the vendor/lessor a certificate to verify the data removal. The certificate will list the nomenclature and serial number of the device. The department business unit must retain the certificate for three years.
7. Records Management Refer to SCDMV Policy AD-700 Records Management for guidelines governing the retention of Agency records.
8. Destruction of Sensitive Items Refer to SCDMV Policy AD-701 Destruction of Sensitive Items for guidelines for the proper destruction of credentials and other sensitive items.
9. Access to, Sale and Release of Information Refer to SCDMV Policy AD-900 Access to, Sale of and Release of Information for guidelines regarding the access to, sale and release of data from SCDMV databases and records to entities outside of the Agency.
C. DATA PRIVACY
1. SCDMV shall conduct a Privacy Impact Assessment (PIA) on information systems that will handle Personal Identifiable Information (PII).
2. SCDMV shall publish privacy policies on SCDMVOnline.com.
3. SCDMV shall update PIAs when a system change creates new privacy risks (e.g., when functions applied to existing information collection change anonymous information into information in identifiable form).
4. PIAs shall include:
a. what information is to be collected (e.g., nature and source);
b. why information is being collected (e.g., to determine eligibility);
c. intended use of information (e.g., to verify existing data);
d. with whom the information will be shared;
e. what opportunities individuals have to decline to provide information; and
f. how the information will be secured.
5. The PIA document shall be reviewed by the SCDMV Executive Director or his designee, such as the Chief Information Officer or Information Security Officer.
6. Policy AD-503 Confidentiality of Information details the confidentiality requirement for all SCDMV personnel.
D. CORRECTIVE ACTION: Employees violating this policy may be investigated in accordance with Policy AD-806 Internal Audits and/or Policy AD-800 Investigations and Internal Affairs. Employees violating this policy may be subject to corrective action up to and including termination in accordance with HR-202 Progressive Corrective Action Disciplinary Policy.
CONTACT/TELEPHONE: Privacy Officer (803) 896-3985
APPROVED BY:
SCDMV Executive Director
EFFECTIVE DATE: April 30, 2018 https://powerdms.com/link/IDS/document/?id=1225631 https://powerdms.com/link/IDS/document/?id=1225635 https://powerdms.com/link/IDS/document/?id=1225656 https://powerdms.com/link/IDS/document/?id=1225591 https://powerdms.com/link/IDS/document/?id=1225644 https://powerdms.com/link/IDS/document/?id=1225644 https://powerdms.com/link/IDS/document/?id=1225639 https://powerdms.com/link/IDS/document/?id=1225706 https://powerdms.com/link/IDS/document/?id=1225706
File details come from the government source that posted it. Updated .