Attachment 8 AD-551.pdf
PDF 189 KB Posted
- Attached to
- SCDMV CUSTOMER MANAGEMENT SOLUTION State and local contract opportunity
- Solicitation number
- 5400020925
- Issued by
- South Carolina
About this file
This is an Information Security Policy document issued by the South Carolina Department of Motor Vehicles (SCDMV) establishing mandatory security standards and responsibilities for all personnel, contractors, and vendors with access to SCDMV-owned data or systems. The policy establishes a comprehensive framework for information security governance, defining roles and responsibilities across organizational levels from individual employees through the Executive Director. All SCDMV personnel are required to read and electronically acknowledge the policy through PowerDMS before gaining access to SCDMV-owned data or systems. The policy addresses both computer-related security incidents involving unauthorized access to electronic systems and non-computer-related incidents involving unauthorized access to paper records or DMV-issued credentials. Computer-related security incidents must be reported immediately to the IT Help Desk at (803) 896-0566 option 7 during business hours, or to the Network Operation Center at (803) 896-8792 after hours, with notification requirements to the Information Security Officer, Chief Information Officer, and the Information Security Incident Response Team.
The policy establishes specific duties for various organizational roles, including requirements for the Chief Information Officer to maintain technical security controls, establish intrusion detection systems alerting a minimum of five IT employees to unauthorized database access, and implement email and internet security systems protecting against viruses, malware, and bot devices. The Information Security Officer bears responsibility for managing the overall Information Security Program, conducting compliance audits, coordinating with state authorities and law enforcement, and scheduling annual penetration testing. Employees violating the policy are subject to corrective action up to and including termination in accordance with progressive disciplinary procedures. The policy references and incorporates fourteen related SCDMV policies and procedures and twelve South Carolina Division of Information Security policies addressing aspects including data protection, access control, asset management, mobile device security, and incident response. The policy was effective as of April 30, 2018, with annual review and update requirements.
View the file
Other files for this state and local contract opportunity
| File | Type | Posted |
|---|---|---|
| Attachment 9 AD-503.pdf | ||
| Attachment 6 NIST.pdf | ||
| Amendment No.1.docx | DOCX document | |
| Attachment 7 AD-504.pdf | ||
| Attachment 3 Card Design Standard.pdf | ||
| Attachment 2 Web Services.docx | DOCX document | |
| Notice of Extension Of Award Posting #1.doc | DOC document | |
| Attachment 13 Customer_Queue Table Data Requirements.txt | TXT text file | |
| Attachment 10.doc | DOC document | |
| Attachment 12 Eligibility Check For Appointments.docx | DOCX document | |
| Solicitation.docx | DOCX document | |
| Attachment 11 Software Table.docx | DOCX document | |
| Attachment 5 AD-502.pdf | ||
| Attachment 1 MVN Diagram.pdf | ||
| Attachment 12 Eligibility Check For Appointments-Revised.docx | DOCX document | |
| Attachment 4 Customer Lookup Business Specifications.docx | DOCX document |
Show all 16
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
South Carolina Department of Motor Vehicles
POLICY AD-551 INFORMATION SECURITY
THE LANGUAGE USED IN THIS DOCUMENT DOES NOT CREATE AN EMPLOYMENT CONTRACT BETWEEN THE EMPLOYEE AND THE AGENCY. THIS DOCUMENT DOES NOT CREATE ANY CONTRACTUAL RIGHTS OR ENTITLEMENTS. THE AGENCY RESERVES THE RIGHT TO REVISE THE CONTENT OF THIS DOCUMENT, IN WHOLE OR IN PART. NO PROMISES OR ASSURANCES, WHETHER WRITTEN OR ORAL, WHICH ARE CONTRARY TO OR INCONSISTENT WITH THE TERMS OF THIS PARAGRAPH CREATE ANY CONTRACT OF EMPLOYMENT.
SECTION OF LAW: N/A
REQUIRED ACTION
All SCDMV personnel are responsible for reading and following this policy.
Supervisors/Managers are responsible to have every employee and new hire read this policy and electronically acknowledge it in PowerDMS. Supervisors/Managers must maintain acknowledgement reports for their area.
SCDMV personnel must be in full compliance with Policy AD-551 Information Security before access will be granted to SCDMV-owned data or systems.
This policy will be reviewed and updated annually.
DEFINITIONS
Computer related information security incidents: Suspected or actual unauthorized access, use, or disclosure of SCDMV confidential/restricted data or customer personal identification data contained in, on, or within SCDMV owned or leased computers, servers, laptops, smart devices, cellular phones, electronic media storage devices, network devices, or any other electronic device capable of displaying or storing electronic data.
Data: Any information that is stored in SCDMV systems for supporting SCDMV operations. The format of the data can be structured as in a database, unstructured as in email, or a collection of data items such as an image library. Data is information about something, someone, or someplace.
Non-Computer related information security incidents: Suspected or actual unauthorized access, use, or disclosure of SCDMV confidential/restricted data or customer personal identification data contained in, on, or within paper products (forms, titles, letters, emails, etc.) and DMV issued credentials (driver licenses and identification cards).
Non-Data: Programs, applications, control files, and such are not considered data. These entities are used to control and access data but in and of themselves do not describe anything specific.
Operational Data: Data that directly supports SCDMV functions. This generally does not include personal or ancillary data such as training presentations, project plans, etc.
Personnel: All individuals employed by SCDMV and contractors/vendors/third parties who are authorized to perform services or do jobs for SCDMV.
Third parties: ALL users of SCDMV data including Member Services accounts.
Personally Identifiable Information (PII): Refer to Policy AD-502 Personally Identifiable Information for this definition.
Security Incident: an occurrence that actually or potentially jeopardizes the confidentiality, integrity, or availability of an information system or the information the system processes, stores, or transmits or that constitutes a violation or imminent threat of violation of security policies, security procedures, or acceptable use policies.
PURPOSE/BACKGROUND
SCDMV seeks a culture of security awareness, and this policy provides direction and clear standards and enhances, amplifies, and augments security consciousness for all SCDMV personnel. SCDMV, as a public trust agency, must ensure full compliance with this policy to protect all forms of information from a wide variety of threats and loss.
GUIDELINES
A. INFORMATION SECURITY RESPONSIBILITIES
1. All SCDMV Personnel: SCDMV seeks a culture of Information Security. All SCDMV Personnel are responsible for full compliance with this policy. Further, all employees are responsible for reporting any Information Security incidents through their chains of command in accordance with Paragraphs C and D below. Any suspected breach or loss of Social Security related information must be immediately reported in accordance with Paragraphs C and D below.
2. Supervisors: As first line leaders, they must know the processes and reduce the risks of information loss, theft, damage, or destruction.
3. Managers
a. Must function as the critical component within the chains of command with regards to Information
Security.
b. Must know all business processes regarding Information Security within their designated areas.
https://powerdms.com/link/IDS/document/?id=1225588
c. Must identify processes and make decisions in accordance with this policy regarding the security and safeguarding of information within their areas of responsibility to mitigate and reduce risk.
d. Must be vigilant with regards to all aspects of information, data, and PII use, storage, and distribution.
e. Shall be responsible to ensure PII data (including paper records) are secured and protected
ESPECIALLY after business hours.
4. Data Owners
a. Must ensure the integrity and accuracy of all data.
b. Must coordinate with the IT Department to validate all back-up copies of data.
c. Must coordinate with IT to ensure back-up copies of data are available, loaded, tested, and validated in a production environment, at least annually.
5. Deputy Directors are responsible for:
a. All forms of access control within their designated areas of responsibility. They determine who is granted and/or denied access to information as well as to what specific degree.
b. Physical security within their areas and the access to information distribution and filing systems which contain PII for either citizens or employees.
c. All aspects of the sale of information to vendors.
6. Directors are responsible for:
a. Serving as members of the Threat Assessment and Mitigation Board.
b. Making sound fiscal and personnel decisions regarding Information Security.
c. Ensuring the overall management and compliance of all aspects of this policy within their Directorates.
d. Informing South Carolina citizens of loss, damage, destruction, or theft of citizen data upon approval from the Executive Director.
7. Chief Information Officer is responsible for:
a. The technical security of data and information as well as ensuring the safe distribution of information by electronic conveyance.
b. Reporting any successful intrusion and/or penetration of SCDMV database information to the Director of Operations and the Information Security Officer within one hour of discovery of the compromise.
c. Ensuring a technical forensic capability remains persistently active regarding all aspects of Information Security.
d. Ensuring segregation of duties with regards to all aspects of data base management.
e. Establishing and maintaining a segregation of duties for data base administrators.
f. Establishing and maintaining segregation of duties and responsibilities associated with purchasing, development, testing, production, and end of lifecycle technical systems.
g. Reviewing quarterly the segregation of duties with the Information Technology Department.
h. Establishing and maintaining a data information intrusion alarm system which alerts a minimum of five
Information Technology employees when unauthorized personnel are within existing databases.
i. Establishing and maintaining an e-mail security system that protects the network from a wide variety of viruses, malware, and bot intrusion devices.
j. Reviewing and taking corrective action on email vulnerability scans and security email alerts that are generated from the security tools.
k. Establishing and maintaining an internet security system that protects the network from a wide variety of viruses, malware, and bot intrusion devices.
l. Reviewing and recording the results of Internet vulnerability reports that are generated by the security tools.
m. Reviewing and taking corrective actions for all threat alerts that are reported from all vulnerability software or appliances as part of network security risk reporting.
n. Monitoring Member Services for potential misuse of information.
o. Providing details of potential misuse to the Inspector General and to the Information Security Officer within eight working hours of discovery of potential misuse.
p. Overseeing e-mail retention; firewall and server security; password and biometric protections; VPN access program; data and information recovery planning; information back-up and disaster recovery systems; and all aspects of network security.
8. Information Security Officer is responsible for:
a. Establishing and managing the Information Security Program which includes audits, inspections, training and business decisions regarding the security of citizen’s information while working closely with the Chief Information Officer for strategic implementation.
b. Recommending priorities in all aspects of SCDMV business operations on matters affecting Information Security.
c. Ensuring full agency-wide compliance with all aspects of this policy as the responsible agent for SCDMV’s Information Security programs.
d. Conducting Field Office and Headquarters checks to ensure compliance with this policy.
e. Studying internal processes and recommending more secure methods of conveyance and distribution of all aspects of PII to Directors.
f. Cultivating, reviewing, and interpreting new sources of information on current and emerging laws, rules, regulations, and industry practice relating to Information Technology and Agency security.
g. Working as a liaison between SCDMV and state authorities (including law enforcement agencies) to provide security incident reports and information. The ISO has the authority to coordinate internally and externally regarding all aspects of information security including federal, state, and local officials.
h. Coordinating with Inspector General on all security related matters.
i. Scheduling, coordinating, and conducting annual penetration testing and reporting the results to the
Executive Leadership Team.
j. If there is a suspected or confirmed breach or loss of PII or a security incident which includes Social
Security Administration (SSA) provided information, the ISO or designated representative must contact the SSA Regional Office Contact or the SSA Systems Security Contact identified in the SSA agreement.
If for any reason the ISO is unable to contact the SSA Regional Office or SSA Systems Contact within one hour, the ISO must report the incident by contacting the SSA’s National Network Service Center (NNSC) toll free at 1-877-697-4889 (select “Security and PII Reporting” from the options list). The ISO will provide updates as become available to the SSA contact as appropriate. Refer to DMV Information Security Incident Response Plan, AD-552 for more incident responses.
k. The ISO or designated representative will use DMV Form 551A, SSA – PII Loss Worksheet to compile the incident information and assist in reporting the incident to the SSA.
9. Executive Director
a. Is responsible for ensuring all aspects of the Information Security Policy and program are fully implemented and in full compliance with all standards established within this policy as well as all other applicable state and or lawful directives.
b. Must make sound fiscal decisions to ensure citizen’s information is protected. This includes responsibility for all major security enhancements and equipment purchases that affect network security and the protection of citizens’ data and information.
c. Is the only individual authorized to release certain data (to include information, systems protection devices, security systems, and security software) to the public, or to the Executive, Judicial, or Legislative Branches of state government.
d. Is the only authorized official who can permanently terminate a systems interface with any public or private entity due to SCDMV security concerns.
B. INFORMATION SECURITY INCIDENTS
Examples of security incidents could include activities such as:
1. Attempts (either failed or successful) to gain unauthorized access to a system or its data.
2. Unwanted disruption or denial of service.
3. Unauthorized use of a system for the processing or storage of data.
4. Changes to system hardware, firmware, or software characteristics without the owner's knowledge, instruction, or consent.
C. REPORTING COMPUTER INFORMATION SECURITY INCIDENTS
SCDMV personnel must report any suspected security or security related event immediately upon discovery to Information Technology Help Desk at (803) 896-0566, option 7, during normal business hours. If the Help Desk is not immediately available, an employee should use the after normal business hours contact procedure listed below. The IT Help Desk will notify the ISO (803) 896-3985, email ISO@SCDMV.net, the CIO (803) 766-8659, CIO@SCDMV.net and the ISIRT at ISIRT@SCDMV.net. If the suspected security or security related event occurs after hours, it must be reported to the Network Operation Center (NOC) at (803) 896-8792 or email SCDMVNOC@SCDMV.net. The NOC will notify the ISO and the CIO by telephone and email and the ISIRT by email.
An employee should contact his supervisor as soon as possible after notifying one of the individuals listed above. If the event involves an individual’s immediate supervisor/manager and the employee is uncomfortable reporting to the supervisor/manager, the employee may report the incident to his deputy director, his director, or the Inspector General.
mailto:CIO@SCDMV.net mailto:ISIRT@SCDMV.net.
mailto:SCDMVNOC@SCDMV.net
Should an employee have any general questions concerning what constitutes a security incident or what policies and procedures are in place to govern institutional data, the employee can telephone or email the Chief Information Security Officer.
D. REPORTING NON-COMPUTER INFORMATION SECURITY RELATED INCIDENTS
SCDMV personnel must report any suspected security or security related event immediately upon discovery to their immediate supervisors and complete DMV Form 552B in accordance with SCDMV Procedure AD-552, Information Security Incident Response Plan.
E. IMPORTANT INFORMATION SECURITY RELATED DOCUMENTATION
1. All SCDMV personnel are required to read, acknowledge and follow the following Information Security-related
SCDMV policies:
a. Policy AD-021 Property Responsibility
b. Policy AD-022 Telephone Usage (required for users assigned cell phones)
c. Policy AD-500 Appropriate Use of Computing Resources
d. Policy AD-501 Email Retention and Use
e. Policy AD-502 Personally Identifiable Information
f. Policy AD-503 Confidentiality of Information
g. Policy AD-504 Data Protection and Privacy
h. Policy AD-505 National Crime Information Center System (NCIC)
i. Policy AD-800 Investigations and Internal Affairs
j. Policy AD-900 Access to, Sale and Release of Information
k. Policy HR-205 Code of Conduct
l. Policy HR-601 Separation of Employment
2. The following Information Security-related SCDMV procedures must be read, acknowledged and followed by SCDMV personnel if it pertains to their job duties:
a. Procedure AD-023 Mobile Device Management
b. Procedure AD-526 Access Control
c. Procedure AD-527 SCDMV Remote Network Access
d. Procedure AD-528 SCDMV Network Management
e. Procedure AD-529 Information Technology Compliance
f. Procedure AD-530 Information Technology Strategy
g. Procedure AD-531 Software Development Life Cycle
h. Procedure AD-552 Information Security Incident Response Plan
i. Procedure AD-553 Information Security Risk Management
j. Procedure AD-554 Information Security Acquisitions, Development and Maintenance
k. Procedure AD-555 Information Security Asset Management
l. Procedure AD-556 Information Security Threat and Vulnerability Management
3. All SCDMV personnel are to comply with the following South Carolina Divisions of Information Security policies:
a. Master Policy
b. Asset Management Policy
c. Data Protection and Privacy Policy
d. Access Control Policy
e. Information Systems Acquisitions, Development, and Maintenance Policy
f. Threat Vulnerability Management Policy
g. Business Continuity Management Policy
h. IT Risk Strategy Policy
i. Mobile Security Policy
j. Human Resources and Security Awareness Policy
k. Physical Environmental Security Policy
l. Risk Management Policy
m. IT Compliance Policy
F. CORRECTIVE ACTION: Employees violating this policy may be investigated in accordance with Policy AD-806, Internal Audits and/or Policy AD-800, Investigations and Internal Affairs. Employees violating this policy may be https://powerdms.com/link/IDS/document/?id=1224465 https://powerdms.com/link/IDS/document/?id=1225515 https://powerdms.com/link/IDS/document/?id=1225517 https://powerdms.com/link/IDS/document/?id=1225574 https://powerdms.com/link/IDS/document/?id=1225586 https://powerdms.com/link/IDS/document/?id=1225588 https://powerdms.com/link/IDS/document/?id=1225591 https://powerdms.com/link/IDS/document/?id=1225595 https://powerdms.com/link/IDS/document/?id=1225598 https://powerdms.com/link/IDS/document/?id=1225639 https://powerdms.com/link/IDS/document/?id=1225656 https://powerdms.com/link/IDS/document/?id=1225276 https://powerdms.com/link/IDS/document/?id=1225316 https://powerdms.com/link/IDS/document/?id=1225328 https://powerdms.com/link/IDS/document/?id=1225332 https://powerdms.com/link/IDS/document/?id=1225334 https://powerdms.com/link/IDS/document/?id=1225336 https://powerdms.com/link/IDS/document/?id=1225338 https://powerdms.com/link/IDS/document/?id=1225342 https://powerdms.com/link/IDS/document/?id=1225346 https://powerdms.com/link/IDS/document/?id=1225355 https://powerdms.com/link/IDS/document/?id=1225360 https://powerdms.com/link/IDS/document/?id=1225364 https://powerdms.com/link/IDS/document/?id=1225368 https://powerdms.com/link/IDS/document/?id=1225371 http://www.admin.sc.gov/files/Information%20Security%20Policy%20-%20Master%2006.13.14.pdf http://www.admin.sc.gov/files/InformationSecurityPolicy-AssetManagement9-25-2013.pdf http://www.admin.sc.gov/files/InformationSecurityPolicy-DataProtectionandPrivacy.pdf http://www.admin.sc.gov/files/InformationSecurityPolicy-AccessControl.pdf http://www.admin.sc.gov/files/InformationSecurityPolicy-InformationSystemsAcquisitionsDevelopment.pdf http://www.admin.sc.gov/files/Information%20Security%20Policy%20-%20Threat%20%20Vulnerability%20Management%20-%20042114.pdf http://www.admin.sc.gov/files/Information%20Security%20Policy%20-%20Business%20Continuity%20Management%20-%20042114.pdf http://www.admin.sc.gov/files/Information%20Security%20Policy%20-%20IT%20Risk%20Strategy%20-%20042114.pdf http://www.admin.sc.gov/files/InformationSecurityPolicy-MobileSecurity.pdf http://www.admin.sc.gov/files/Information%20Security%20Policy%20-%20HR%20and%20Security%20Awareness%209-25-2013.pdf http://www.admin.sc.gov/files/Information%20Security%20Policy%20-%20Physical%20%20Environmental%20Security%20-%20042114.pdf http://www.admin.sc.gov/files/InformationSecurityPolicy-RiskManagement.pdf http://www.admin.sc.gov/files/Information%20Security%20Policy%20-%20IT%20Compliance%20-%20042114.pdf https://powerdms.com/link/IDS/document/?id=1225644 https://powerdms.com/link/IDS/document/?id=1225644 https://powerdms.com/link/IDS/document/?id=1225639 subject to corrective action up to and including termination in accordance with HR-202 Progressive Corrective Action Disciplinary Policy.
CONTACT/TELEPHONE: Information Security Officer (803) 896-3985
APPROVED BY:
SCDMV Executive Director
EFFECTIVE DATE: April 30, 2018
ATTACHEMENTS: AD-551A Restricted Cover Sheet, AD-551B Confidential Cover Sheet, AD-551C Internal Use Cover Sheet, AD-551D Reporting Loss of Social Security Administration-PII https://powerdms.com/link/IDS/document/?id=1225706 https://powerdms.com/link/IDS/document/?id=1225706 https://powerdms.com/link/IDS/document/?id=1224321 https://powerdms.com/link/IDS/document/?id=1224325 https://powerdms.com/link/IDS/document/?id=1224330 https://powerdms.com/link/IDS/document/?id=1224330 https://powerdms.com/link/IDS/document/?id=1224335
File details come from the government source that posted it. Updated .