The file's text, extracted by GovTribe without its formatting.
ENTERPRISE SECURITY STANDARDS, POLICIES, AND GUIDELINES
EXTERNAL DATA HOSTING STANDARD
1.0 Purpose
| The | purpose | of | this | policy | is | to | establish | a | standard | in | order | to | execute | the | proper | retrieval, | storage, |
| transmission, | processing, | and | handling | of | electronic | data. | | | | | | | | | | | |
2.0 Scope
| This | document | applies | to | all | vendors, | networks, | systems, | and | applications | that | will | transmit, | process, | store, | or |
| handle | electronic | data | provided | by | Orange | County | Government | Board | of | County | Commissioners | (OCGBCC). | | | |
3.0 Audience
| This | document | is | intended | for | distribution | to | those | that | are | involved | in | the | retrieval, | storage, | transmission, |
| processing, | and | handling | of | electronic | data. | | | | | | | | | | |
4.0 Policies
4.1 Data Input and Processing
| 4.1.1 Any | use | of | Social | Security | Number | information | shall | adhere | to | and | abide | by | Florida |
| Statutes, | specifically | F.S. | 119.071. | | | | | | | | | | |
| 4.1.2 The | hosted | application | shall | not | have | access | to | social | security | information. | | | |
| 4.1.3 The | hosted | application | shall | not | have | access | to | data | containing | bank | information. | | |
| 4.1.4 The | hosted | application | shall | not | be | granted | direct | or | indirect | access | to | OCGBCC | Active |
| Directory | usernames. | | | | | | | | | | | | |
| 4.1.5 The | hosted | application | shall | not | have | access | to | the | OCGCC | internal | or | DMZ | networks. |
| 4.2 Data | Storage | and | Handling | | | | | | | | | |
| 4.2.1 Any | data | accessible | from | the | hosted | application | meeting | the | following | criteria | shall | be |
| encrypted | at | a | field-level | and | in | transit: | usernames, | passwords, | names, | addresses, |
| phone | numbers, | email | addresses, | birthdates, | federal/state/local | document | numbers, | | | |
| account | numbers, | race | or | religious | information, | usernames, | passwords, | employee | | |
| identification | numbers | and | all | HIPAA | and | PCI | information. | | | |
| 4.2.2 Any | data | accessible | from | the | hosted | application | or | directly | accessible | from | it | should | be |
| encrypted | at | a | field | level. | | | | | | | | | |
| 4.3 Transmission | of | Data | | | | | | | | |
| 4.3.1 Any | data | referenced | above | shall | be | transmitted | within | an | encrypted | tunnel. |
| 4.4 Disposal | of | Data | | | | | | | | | | | | | | | |
| Once | data | is | no | longer | needed | or | must | be | removed | from | the | system | it | shall | be | sanitized | and |
| disposed | using | one | of | the | methods | below: | | | | | | | | | | | |
| 4.4.1 Sanitization | - | Overwriting | of | data | previously | stored | on | a | disk | or | drive | with | a | random |
| pattern | of | meaningless | information. | | | | | | | | | | | |
| 4.4.2 Destruction | - | Physically | damaging | a | medium | so | that | it | is | not | usable | by | any | device | that |
| may | normally | be | used | to | read | information | on | the | media | such | as | a | computer, | tape | |
| reader, | audio | or | video | player. | | | | | | | | | | | |
| 4.4.3 Purging | data | - | Using | strong | magnetic | devices; | such | as | a | degausser, | it | is | possible | to |
| render | data | unrecoverable. | | | | | | | | | | | | |
| 4.5 External | Audit | | | | | | | | | | | |
| 4.5.1 The | vendor | must | ensure | that | the | web | hosting | environment | and | the | application | is |
| secured | using | information | security | best | practices. | | | | | | |
| 4.5.2 The | external | service, | system, | and | application | must | pass | a | yearly | penetration | test |
| performed | by | Orange | County | ISS | personnel. | Alternatively | the | vendor | can | provide | the | |
| results | of | an | external | audit | conducted | by | a | reputable | 3rd | party | security | company. |
5.0 Definitions
| Term | | Definition | | | | | | | | | |
| Bank | Information | Checking | account | numbers, | credit | card | numbers, | or | any | unique | number |
| from | a | bank | institution. | | | | | | | | | | | | |
| Electronic | Media | Physical | objects | on | which | data | can | be | stored, | such | as | hard | drives, | zip | drives, |
| CD-ROMs, | DVDs, | USB | drives, | and | tapes. | | | | | | | |
| Sanitization | To | expunge | data | from | storage | media | so | that | data | recovery | is | impossible. |
| Physical | Destruction | A | sanitization | method | for | optical | media, | such | as | CDs. | | |
| Florida | Statue | 119.071 | Detailed | guidelines | on | usage | of | Social | Security | information | | |
6.0 Revision History
| October | 2017 Specified | “field-level | encryption” | for | sensitive | data | at | rest | in | 4.2.1 |
| Added | usernames | and | passwords | to | the | list | in | 4.2.1 | | |
| Added | an | option | for | a | 3rd | party | vendor | in | 4.5.2 | |
| Added | definition | for | field-level | encryption | | | | | | |
August 2012 Added “Bank Information” to list of definitions in 5.0