AttachmentE_Security_Procedures_12_pagenumbers.doc
DOC document 36 KB Posted
- Attached to
- 2011-12 NATIONAL POSTSECONDARY STUDENT AID STUDY (NPSAS:12) Federal contract opportunity
- Solicitation number
- ED-IES-09-R-0015
About this file
Attachment E - Security Procedures (PWS)
View the file
Other files for this federal contract opportunity
| File | Type | Posted |
|---|---|---|
| AttachmentA_PWS 5-28-08.doc | DOC document | |
| AttachmentB_AwardFeeExhAB_12_revised 5-28-09.xls | XLS spreadsheet | |
| AttachmentF_AdditionalSecurityCompliance_12_pagenumbers.doc | DOC document | |
| AttachmentM_SmallBusinessSubcontractingPlan_12_pagenumbers.doc | DOC document | |
| RFP - NPSAS.pdf | ||
| Attachment N - Pricing Table.doc | DOC document | |
| AttachmentL_ContractorInformationForm_12_pagenumbers.doc | DOC document | |
| AttachmentD_WebDASspecs_12_pagenumbers.doc | DOC document | |
| AttachmentJ_BusinessProposalWorksheet_12_revised_5-28-09.xls | XLS spreadsheet | |
| AttachmentG_DataElements_12.xls | XLS spreadsheet | |
| AttachmentI_TechnicalProposalWorksheet_12.xls | XLS spreadsheet | |
| AttachmentC_Billing_Instructions_12_pagenumbers.doc | DOC document | |
| Attachment O - Conflict of Interest Certification Form.doc | DOC document | |
| NPSAS Draft SOW 4-15-09.doc | DOC document |
Show all 14
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
PAGE
ATTACHMENT E
SECURITY PROCEDURES
I. Introduction
These are the minimum requirements that a Licensee must meet in order to ensure the security of the individually identifiable information (referred to as "subject data" in the license) while in the custody of the Licensee.
A. Responsibilities
It is the responsibility of the Licensee to ensure that adequate protections are in place to provide for the security and integrity of the licensed information (subject data).
An individual(s) must be assigned the responsibility for the security of the provided subject data. This assignment must be made in such a way that there is no confusion as to what individuals are responsible for.
II. Security Requirements for Automation
A. General
In general, the guidance provided in the National Institute of Standards and Technology Federal Information Processing Standard Publication (FIPSPUB) 41, Computer security guidelines for implementing the Privacy Act of 1974 should be used to ensure that government provided individually identifiable information (subject data) is adequately protected in accordance with the Act.
The subject data provided under license must be protected to ensure that it will not be changed. The integrity of information produced with these data will rely on the integrity of the source data.
B. Access
The data must always be secured from unauthorized access.
Where possible, the data must be protected by passwords. When passwords are used they must comply with the requirements of FIPSPUB 112.
C. Password Usage
A unique password must be assigned to each individual working with provided subject data. These passwords must be changed frequently, at a minimum every three months.
D. Automatic Shutdown of Inactive Computer
Computers should be equipped with mechanisms that automatically shutdown, logout, or lock-up (e.g., password protected screen-savers) when a period of a defined inactivity is detected. This feature may be used in place of or in addition to locking the computer and/or room. When used, the defined period of activity shall be 3 to 5 minutes.
E. Notification
Where possible, a statement should appear on the computer screen before access is permitted. This statement should stay on the screen for at least ten seconds to ensure that it is readable. Readable. The statement should be worded to ensure that the intent of the following is conveyed:
Unauthorized access to licensed individually identifiable information is a violation of federal law and will result in prosecution.
If is not feasible to force this statement to appear on the screen of the computer, it should be typed and attached to the monitor in a prominent location.
F. Magnetic Media Protection
Magnetic media storage devices include tapes, floppy diskettes, CD-ROMS, DVDs, removable and fixed hard disks. While data are maintained on these devices, they are required to be secured in the same manner as if they were printed material (e.g. locked in a secure cabinet when not in use, only necessary copies made). This may require extensive physical security of computer with hard disks.
To ensure that license dates are not exceeded, all magnetic media must be labeled with the expiration date of the license. This requirement addresses all data files, software and related files.
G. Compression
Data items may be received in a compressed, password-protected format to ensure privacy.
H. Communication Licensed information must be protected to ensure that it is not deliberately or inadvertently communicated to unauthorized personnel. Modems should be disconnected while licensed data are being stored or processed on microcomputer or minicomputers. In addition, extreme care should be exercised to ensure that licensed data are not inadvertently made available through use of networking technology. One precaution to take would be requiring password protection of the file containing the licensed data in addition to access to the computer.
III. Avoiding Disclosure from Printed Material
Printed material containing individually identifiable information must always be secured from unauthorized access; e.g. locked in a secure cabinet when not in use and only necessary copies made.
It is possible to disclose, inadvertently, individually identifiable information in printed material even when there is more than a single record in a printed cell. To avoid this the uniqueness of the records must be considered. Records with very low values or records which, through their linkage to other records makes the combination unique, may permit disclosure when placed in the context of information that is general knowledge outside the group of sworn recipients of subject data.
In planning and producing analyses and tabulations, the general rule is that there should be no cell published in which there are fewer than three (3) respondents or where the cell information could be obtained by subtraction. In addition, one must be careful not to disclose information through subsequent crosstabulation of the same data by other variables.
File details come from the government source that posted it. Updated .