AttachmentE_Security_Procedures_12_pagenumbers.doc

DOC document 36 KB Posted

Attached to
2011-12 NATIONAL POSTSECONDARY STUDENT AID STUDY (NPSAS:12) Federal contract opportunity
Solicitation number
ED-IES-09-R-0015
Issued by
Department of Education Contracts and Acquisition Management

About this file

Attachment E - Security Procedures (PWS)

View the file

Other files for this federal contract opportunity

Other files attached to 2011-12 NATIONAL POSTSECONDARY STUDENT AID STUDY (NPSAS:12), newest first.
File Type Posted
AttachmentA_PWS 5-28-08.doc DOC document
AttachmentB_AwardFeeExhAB_12_revised 5-28-09.xls XLS spreadsheet
AttachmentF_AdditionalSecurityCompliance_12_pagenumbers.doc DOC document
AttachmentM_SmallBusinessSubcontractingPlan_12_pagenumbers.doc DOC document
RFP - NPSAS.pdf PDF
Attachment N - Pricing Table.doc DOC document
AttachmentL_ContractorInformationForm_12_pagenumbers.doc DOC document
AttachmentD_WebDASspecs_12_pagenumbers.doc DOC document
AttachmentJ_BusinessProposalWorksheet_12_revised_5-28-09.xls XLS spreadsheet
AttachmentG_DataElements_12.xls XLS spreadsheet
AttachmentI_TechnicalProposalWorksheet_12.xls XLS spreadsheet
AttachmentC_Billing_Instructions_12_pagenumbers.doc DOC document
Attachment O - Conflict of Interest Certification Form.doc DOC document
NPSAS Draft SOW 4-15-09.doc DOC document
Show all 14

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

PAGE

ATTACHMENT E

SECURITY PROCEDURES

I. Introduction

These are the minimum requirements that a Licensee must meet in order to ensure the security of the individually identifiable information (referred to as "subject data" in the license) while in the custody of the Licensee.

A. Responsibilities

It is the responsibility of the Licensee to ensure that adequate protections are in place to provide for the security and integrity of the licensed information (subject data).

An individual(s) must be assigned the responsibility for the security of the provided subject data. This assignment must be made in such a way that there is no confusion as to what individuals are responsible for.

II. Security Requirements for Automation

A. General

In general, the guidance provided in the National Institute of Standards and Technology Federal Information Processing Standard Publication (FIPSPUB) 41, Computer security guidelines for implementing the Privacy Act of 1974 should be used to ensure that government provided individually identifiable information (subject data) is adequately protected in accordance with the Act.

The subject data provided under license must be protected to ensure that it will not be changed. The integrity of information produced with these data will rely on the integrity of the source data.

B. Access

The data must always be secured from unauthorized access.

Where possible, the data must be protected by passwords. When passwords are used they must comply with the requirements of FIPSPUB 112.

C. Password Usage

A unique password must be assigned to each individual working with provided subject data. These passwords must be changed frequently, at a minimum every three months.

D. Automatic Shutdown of Inactive Computer

Computers should be equipped with mechanisms that automatically shutdown, logout, or lock-up (e.g., password protected screen-savers) when a period of a defined inactivity is detected. This feature may be used in place of or in addition to locking the computer and/or room. When used, the defined period of activity shall be 3 to 5 minutes.

E. Notification

Where possible, a statement should appear on the computer screen before access is permitted. This statement should stay on the screen for at least ten seconds to ensure that it is readable. Readable. The statement should be worded to ensure that the intent of the following is conveyed:

Unauthorized access to licensed individually identifiable information is a violation of federal law and will result in prosecution.

If is not feasible to force this statement to appear on the screen of the computer, it should be typed and attached to the monitor in a prominent location.

F. Magnetic Media Protection

Magnetic media storage devices include tapes, floppy diskettes, CD-ROMS, DVDs, removable and fixed hard disks. While data are maintained on these devices, they are required to be secured in the same manner as if they were printed material (e.g. locked in a secure cabinet when not in use, only necessary copies made). This may require extensive physical security of computer with hard disks.

To ensure that license dates are not exceeded, all magnetic media must be labeled with the expiration date of the license. This requirement addresses all data files, software and related files.

G. Compression

Data items may be received in a compressed, password-protected format to ensure privacy.

H. Communication Licensed information must be protected to ensure that it is not deliberately or inadvertently communicated to unauthorized personnel. Modems should be disconnected while licensed data are being stored or processed on microcomputer or minicomputers. In addition, extreme care should be exercised to ensure that licensed data are not inadvertently made available through use of networking technology. One precaution to take would be requiring password protection of the file containing the licensed data in addition to access to the computer.

III. Avoiding Disclosure from Printed Material

Printed material containing individually identifiable information must always be secured from unauthorized access; e.g. locked in a secure cabinet when not in use and only necessary copies made.

It is possible to disclose, inadvertently, individually identifiable information in printed material even when there is more than a single record in a printed cell. To avoid this the uniqueness of the records must be considered. Records with very low values or records which, through their linkage to other records makes the combination unique, may permit disclosure when placed in the context of information that is general knowledge outside the group of sworn recipients of subject data.

In planning and producing analyses and tabulations, the general rule is that there should be no cell published in which there are fewer than three (3) respondents or where the cell information could be obtained by subtraction. In addition, one must be careful not to disclose information through subsequent crosstabulation of the same data by other variables.

File details come from the government source that posted it. Updated .