Attachment_2_DHS_Sensitive_System_Policy_Handbook.pdf
PDF 268 KB Posted
- Attached to
- Identity Verification and Authentication Federal contract opportunity
- Solicitation number
- HSFE80-13-R-0005
About this file
Attachment 2 DHS Sensitive System Policy Handbook
View the file
Other files for this federal contract opportunity
Show all 18
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
Attachment 2
Social Media
DHS 4300A
Sensitive Systems Handbook
Version 8.0
23 May 2011
DEPARTMENT OF HOMELAND SECURITY
DHS 4300A SENSITIVE SYSTEMS HANDBOOK ATTACHMENT X – SOCIAL MEDIA
V8.0, May 23, 2011 i
DOCUMENT CHANGE HISTORY
Version Date Description
0.6 March 25, 2010 Final Draft for Comment
0.7 May 12, 2011 Final Draft for Review; Includes Component Comments
8.0 May 23, 2011 Final
V8.0, May 23, 2011 ii
CONTENTS
1.0 INTRODUCTION
1.1 Background
1.2 Purpose and Scope
2.0 USE OF SOCIAL MEDIA
2.1 Official Use of Social Media
2.1.1 Governance
2.1.2 Privacy Issues
2.1.3 Standards of Conduct
2.2 Unofficial/Personal Use of Social Media on Government Equipment
2.3 Unofficial/Personal Use of Social Media on Non-Government Equipment
3.0 RISKS/ATTACK TECHNIQUES ASSOCIATED WITH SOCIAL MEDIA USE
3.1 Common risks of cyber attacks
3.2 Common methods/techniques of cyber attacks
3.2.1 Spear Phishing
3.2.2 Social Engineering
3.2.3 Web Application Attacks
4.0 BEST PRACTICES FOR SOCIAL MEDIA USE
5.0 UNOFFICIAL INTERNET POSTING GUIDELINES
GLOSSARY
REFERENCES
INDEX
V8.0, May 23, 2011 3
1.0 INTRODUCTION
Social media such as Facebook, Twitter and Wikipedia have become integral parts of daily life.
In 2010, nearly two-thirds of all American adult Internet users engaged in some form of social media on a regular basis.1 Due to extensive casual Internet use, it comes as no surprise that Federal employees and contractors may have difficulty deciding what constitutes acceptable and security-conscious behavior while online in social media venues.
While Government organizations are considering how best to leverage the interactivity enabled by social media, they must also ensure a common understanding of how employees are expected to engage there. This applies whether those engagements are: official (work-related) or unofficial (personal); whether they occur on sanctioned “official” social media sites or on commercially managed sites; or whether they are accomplished using Government-issued equipment or on electronic devices owned by the employee or other third-party." This document provides guidance under the authority of the Department of Homeland Security (DHS) Chief Information Officer (CIO) through the Chief Information Security Officer (CISO). It expands on existing DHS policy provided in Section 3.16, Social Media, of DHS Sensitive Systems Policy Directive 4300A, and in DHS Management Directive (MD) 4400.1, Web (Internet, Intranet, and Extranet Information) and Information Systems.
1.1 Background
Cyber security trends have shown increased attacks on and via social media. Due to the high threat of malware infiltration and the sensitive nature of the information maintained at DHS, social media host sites are blocked at the Department’s Trusted Internet Connections (TIC)2.
However, the Assistant Secretary, Office of Public Affairs (OPA), as well as Component public or external affairs offices do permit limited social media use “by exception,” through sanctioned “official” Government and/or commercial social media sites and social networking services.
These managed venues are used to make information and services more widely available to allow the public and Department and Component employees to:
• Support Department and Component missions;
• Showcase the Department’s work and integration;
• Reach a wider audience more efficiently by leveraging social media capabilities;
• Extend Department information by providing additional sources where the public can discover supplemental information (e.g., videos) on the Department’s activities and messages; and
• Provide opportunities for participation and collaboration on Department activities.
1 Kathryn Zickuhr and Lee Raine, Wikipedia, past and present, Pew Internet & American Life Project, 13 January 2011. This 2010 survey reports the following social media usages among American adults, age 18 and older:
Wikipedia (53%), instant messaging (47%), social networking sites (61%), video sharing sites like YouTube (66%).
2 Section 3.16, DHS Sensitive Systems Policy Directive 4300A.
V8.0, May 23, 2011 4
In addition, the Department recognizes that individuals who engage in unofficial (personal) social media may easily become victims of social engineering or other forms of cyber-attack.
Employees need guidance to help minimize the risks their social media use poses to the Department and its missions.
1.2 Purpose and Scope
This document provides information security guidance regarding official (work-related) and unofficial (personal) social media use whether occurring within or outside the Department network. It applies to all DHS employees and contractors, describes the governance of social media sites across DHS, and addresses the use and associated risks of social media technologies in three scenarios:
• Required Work-Related Use
• Unofficial/Personal Use on Government Equipment
• Unofficial/Personal Use on non-Government Equipment
“Equipment” refers to both non-portable devices such as desktop computers as well as mobile devices such as laptop computers and Portable Electronic Devices (e.g. Blackberries, smartphones, PDAs, etc.). This document includes best practices and guidance regarding acceptable social media use. Commonly used social media terms are listed in bold italic typeface throughout this attachment and are defined in the Glossary.
V8.0, May 23, 2011 5
2.0 USE OF SOCIAL MEDIA
2.1 Official Use of Social Media
Many Federal Departments and agencies are required to post Government information to specific sites. dhs.gov is the official website and presence of DHS. Component offices of public or external affairs publish materials on dhs.gov. In addition, some Components maintain their own websites, subject to Departmental oversight. Enforcement officers, as part of child pornography and drug interdiction task forces, routinely peruse external social networks. Instructions for using dhs.gov and commercial/third party social media are provided at the DHS Web Center (see www.dhs.gov/webcenter).
As a result of this technological relationship between the Department and the public, it is imperative that DHS engage the public in a manner that complies with Federal accessibility, privacy, information security, and records laws.
2.1.1 Governance
The DHS Office of Public Affairs (OPA) serves as the primary account holder for all social media websites across the Department and manages and approves all DHS content posted on these public-facing websites. All content disseminated through official Department accounts must be approved by DHS OPA prior to posting. The Department’s public affairs officials will ensure that all posted content falls within the appropriate requirements for publicly available information and materials. OPA will, when necessary, act as the final authority on what content is acceptable for posting.
2.1.2 Privacy Issues
Privacy laws require DHS to protect Personally Identifiable Information (PII) internally and when engaging the public. DHS employees must comply with Federal privacy laws, Office of Management and Budget (OMB) guidance, and DHS privacy policies when using social media in an official capacity. The Privacy Office is responsible for ensuring that DHS use of social media sustains and does not erode privacy protections concerning the use, collection, and disclosure of PII.
It’s imperative that the Department be transparent about its use of social media to avoid concerns about unauthorized surveillance of these social networks, therefore DHS must engage these social media websites in a manner that protects privacy and respects users’ intent. The DHS Privacy Office has concluded that the public user fully expects privacy protections while interacting with the Department. In order to address these and other concerns, DHS has set forth specific requirements for engaging in social media in a privacy sensitive manner.
Each social media website provides its own privacy policy, and while users are typically required to submit some PII during the registration process, the Department will not solicit or collect this PII. The Department will examine the social media website or application privacy policy to evaluate the risks to determine whether the website is appropriate for the Department’s use. If an agency posts a link that leads to a social media website, the agency will provide an alert to the visitor, such as a statement adjacent to the link or a “pop-up,” explaining that visitors are being http://www.dhs.gov/ http://www.dhs.gov/ http://www.dhs.gov/ http://www.dhs.gov/webcenter
V8.0, May 23, 2011 6 directed to a non-government website that may have different privacy policies from those of the agency’s official website.
The Department will only collect the minimum information necessary for the proper performance of official functions. Official DHS accounts across social media websites will be identified by the Component or Department seal as well as an anonymous, easily identifiable user name account displaying a DHS presence, such as “DHS John Q. Employee.”
As part of the Department’s privacy compliance process, the DHS Privacy Office has developed two Department-wide Privacy Impact Assessments (PIAs) to identify and mitigate privacy risks:
1) Use of Social Networking Interactions and Applications (Communications/Outreach/Public Dialogue), September 16, 2010; and 2) Use of Unidirectional Social Media Applications, March 8, 2011 both found at www.dhs.gov/privacy. These PIAs and the DHS privacy policies, including those that are social media specific, govern the Department’s use of social media from a privacy perspective. The DHS privacy policy and social media specific privacy policies can be found at www.dhs.gov.
PIA determination is made on a case by case basis through the social media privacy threshold analysis (PTA) process. Approved PIAs are published on the Department’s Privacy Impact Assessment web page (see www.dhs.gov/privacy) unless they are classified. DHS has issued a PIA addressing the PII the Department may have access to due to its use of social networking applications, how it will use the information, what information is retained and shared, and how individuals can gain access to and correct their information. DHS does not solicit, collect, or disseminate PII from individuals who interact with the Department via social media sites. If PII is posted on a social media site, the Department will attempt to delete it. If that is not possible, the Department will disregard the PII and it will not be maintained in agency files. However PII posted on a social media website or sent to the Department in connection with the transaction of public business may become part of a Federal record and will have to be maintained in accordance with appropriate records retention policies.
If a Component has an operational need to use social media outside the scope of the requirements outlined in the existing PIAs, a separate PIA must be completed and approved by the appropriate Privacy Official. That PIA should address the specific privacy concerns that are unique to the Component.
2.1.3 Standards of Conduct
DHS employees and contractors are responsible for knowing and following the guidelines in DHS Management Directive (MD) 4400.1, Web (Internet, Intranet, and Extranet Information) and Information Systems and Executive Branch conduct guidelines, such as Standards of Ethical Conduct for Employees of the Executive Branch, when using social media in an official capacity.
These standards cover topics of prohibited activities such as:
• Engaging in vulgar or abusive language, personal attacks of any kind, or offensive terms targeting individuals or groups;
• Endorsement of commercial products, services, or entities;
• Endorsement of political parties, candidates, or groups;
• Lobbying members of Congress using DHS or any other appropriated resource; and http://www.dhs.gov/privacy http://www.dhs.gov/privacy
V8.0, May 23, 2011 7
• Use of Government resources to foster commercial interests or individual profit.
Federal employees often inadvertently fail to comply with the stringent requirements of the Hatch Act, which governs political speech by Federal employees. Recently, the U.S. Office of Special Counsel (OSC) issued guidance regarding the applicability of the Hatch Act to social media engagement in the workplace by Federal, intelligence and enforcement agency employees.
The Act’s restrictions may affect whether or not Federal employees are allowed to post certain content that could be interpreted in a political light. Employees should understand the Hatch Act, and Sections 4 and 5 of this document before blogging, interacting through Facebook, engaging thorough Twitter, or revealing professional titles and political affiliations.
2.2 Unofficial/Personal Use of Social Media on Government Equipment Social media is an attack vector routinely exploited by cyber criminals. This may expose the Department to unacceptable risk. Additionally, social network activity consumes bandwidth that can negatively impact employee productivity. DHS prohibits access to social media from Government equipment except by exception.
Although DHS employees are authorized limited personal use of DHS office equipment in accordance with DHS Management Directive (MD) No. 4600.1, Personal Use of Government Office Equipment, this does not apply to use of DHS equipment for personal use of social media. This restriction also applies to contractors or other individuals using DHS equipment.
2.3 Unofficial/Personal Use of Social Media on Non-Government Equipment Employee activities potentially affect DHS job performance, the performance of others, or DHS business interests. Any information posted on the Internet incurs a level of risk, because that information is exposed indefinitely with no reliable methods for deletion or retraction.
Additionally, because of the connected nature of the Internet, even information presumed to be posted in a venue with restricted access is potentially accessible to anyone.
“Unofficial Internet posts” 3 result when DHS personnel express their DHS-related thoughts, ideas, knowledge, experience, and opinions on any Internet site, whether DHS-controlled or otherwise. Unofficial Internet posts are personal expressions developed and released by an employee or contractor that have not been initiated by any part of the DHS organization or reviewed within any official DHS approval process. Employees must remember that any information about another individual is almost surely protected by the Privacy Act and should not be shared.
Social networks are of particular concern because of this potential for users to disseminate personal information about themselves and others. Unless strict privacy controls are applied to online profiles, the information posted is viewable by a wide range of strangers. Normally adversaries would have to engage in detailed information gathering in order to collect sensitive information, but social networks provide them a single source from which to gather this information with relative ease. Adversaries can collect even seemingly harmless facts and use them to assemble profiles and select targets. Even with privacy controls in place, DHS
3 Based on US DHS, ALCOAST 548/08, COMDTNOTE 5700. SUBJ: SOCIAL MEDIA - UNOFFICIAL
INTERNET POSTS
V8.0, May 23, 2011 8 employees and contractors should not post any content that they would not be comfortable disclosing to the public.
Employees must remember that any information that is work-related is sensitive and cannot be repeated outside the workplace without appropriate clearances. In addition, further limits are in place if you identify yourself, whether directly or indirectly, as a DHS employee. Consistent with these risks, the recent guidance issued by the U.S. Office of Special Counsel (OSC) regarding at-home social media use does not differ substantially from the at-work guidance, although more latitude is given for employees to express political thoughts and candidate advocacy/support on their personal websites. See Sections 4 and 5 of this document for additional best practices and guidelines applicable to social media use.
V8.0, May 23, 2011 9
3.0 RISKS/ATTACK TECHNIQUES ASSOCIATED WITH SOCIAL MEDIA USE
Adversaries look for easy opportunities on the Internet to target persons of interest in order to get a foothold for long-term surveillance and exploitation. Social media sites are attractive to hackers since the same technologies that invite user participation make them easy to corrupt with malware such as worms that can shut down networks, spyware, or keystroke loggers that can steal sensitive data. For example, the availability of widgets makes it easier for social networkers to share links, insert pictures, etc. – but it also makes it easier for an attacker to slip in malicious code or to link to off-site content that contains malware.
3.1 Common risks of cyber attacks
The risks associated with social networking fall into a few broad categories:
• The risk of having the social networking account itself hacked
• The risk that users will pick up malware through the social networking site
• The risk that a hacker will gain information through the social networking site that will allow him/her to attack the enterprise network
• The risk of accidentally releasing sensitive information
• The risk of identity theft Government use of social media also poses potential privacy risks. Social media users voluntarily provide PII in their user profiles such as hometown and employer, making such information available to other registered users, including DHS. The availability of this PII does not give the Department the authority or right to collect, use, or disclose that information for purposes unrelated to fostering transparency and open Government absent a separate authority to do so.
The emergence of Location-Based Services (LBS) (geo-location) poses additional privacy concerns. Research undertaken by Carnegie Mellon University in 2009 and 2010 found that “currently available location‐sharing services do not, for the most part, do a good job of informing [users] about how their location information will be used or provide users with expressive location privacy controls and privacy‐protective default settings.” Furthermore, although 222(f) of the Communications Act generally prohibits wireless carriers from using location-based information for commercial purposes without the express prior consent of the consumer, these prohibitions do not currently apply to LBS providers even though their applications are being downloaded on the devices of wireless carriers. Consumers may mistakenly conclude that application providers are subject to the same prohibitions as wireless carriers and that no action by consumers is necessary to ensure that their privacy is protected.4
4 Joint Hearing On “The Collection and Use of Location Information for Commercial Purposes'', February 24, 2010.
V8.0, May 23, 2011 10
3.2 Common methods/techniques of cyber attacks
According to the Guidelines for Secure Use of Social Media by Federal Departments and Agencies, social media technologies such as wikis, blogs, and social networks are especially vulnerable to the following methods/techniques of cyber attacks:5
• Spear Phishing
• Social Engineering
• Web Application Attacks
3.2.1 Spear Phishing
Spear phishing is an attack targeting a specific user or group of users, and attempts to deceive the user into performing an action that launches an attack, such as opening a document or clicking a link. Spear phishers rely on knowing some personal piece of information about their target, such as an event, interest, travel plans, or current issues. Sometimes this information is gathered by hacking into the targeted network, but often it is easier to look up the target on a social media network.
In April 2009, the Federal Bureau of Investigation released a Headline Alert specifically citing social networking sites as a mechanism for attackers to gather information on their targets by harvesting information from publically accessible networks and using the information as an attack vector. Spear phishers use social media as an alternative way to send phishing messages, as the social media platform bypasses traditional email security controls. Security teams have already observed multiple social media websites used as a propagation mechanism to trick users into opening a document or clicking a link. DHS receives many specific attacks via email on a daily basis tailored to specific employees by name and position.
3.2.2 Social Engineering
The second concern regarding social media use by Federal employees is social engineering, which relies on exploiting the human element of trust. The first step in any social engineering attack is to collect information about the attacker’s target. Social networking websites can reveal many details of personal information, including resumes, home addresses, phone numbers, employment information, work locations, family members, education and photos. Social media websites may share more personal information than users expect or need.
For example, a study by the University of Virginia cites that out of the top 150 Facebook applications, all of which are externally hosted, over 90% needed nothing more than publicly available information from members in order to operate. However, in every case users needlessly granted the applications total access to their account and therefore full access to all personal information.
When DHS employees join a social media website, they may identify themselves as DHS employees. Their self-identification creates a DHS Internet footprint, which is valuable information to adversaries. As more Federal employees self-identify on social media websites, 5 Guidelines for Secure Use of Social Media by Federal Departments and Agencies, Version 1.0, Federal CIO Council, September 2009.
V8.0, May 23, 2011 11 the Federal footprint on social networking will grow, creating a target-rich environment to help adversaries target specific individuals to launch various social engineering attacks.
Attackers use social media to learn personal information about an individual. By expressing interest in similar topics, the attacker builds a trust relationship with the victim. This positions the attacker to influence the victim’s friends and co-workers or even to collect sufficient information about the victim to pose as him, providing an easy avenue for penetrating the trust of DHS and its personnel.
Additionally, high-profile Federal employees create an even larger footprint, as they have greater name recognition. A high-profile Federal employee with greater name recognition is a prime target for a social engineer to exploit trust relationships established within social networks.
3.2.3 Web Application Attacks
Malicious content on social networking sites is easy to disguise as valid content. Developers of user-generated games and applications on some sites have the option of going through an approval process; however, the application’s code is not always locked in the state in which it was submitted for approval. This creates a situation in which apparently vetted software can be injected with malicious code at a later time.
Finally, while a hijacked personal social media account may be annoying and personally costly or embarrassing, a hijacked account of a Federal user or a Federal account may have implications that are more serious. Unauthorized posts, tweets or messages may be seen by the public as official messages, or may be used to spread malware by encouraging users to click links or to download unwanted applications or malware.
V8.0, May 23, 2011 12
4.0 BEST PRACTICES FOR SOCIAL MEDIA USE
Online activities often blur the line between individuals’ personal and professional lives. Real-world social and business rules have counterparts in digital environments. Activities of DHS employees or contractors, within or outside the workplace may affect their DHS job performance, the performance of others, or DHS business interests, so they are a proper focus for best practice guidance. The following guidelines are intended to assist DHS employees and contractors in protecting their personal information and reputation while interacting online.
These best practices are based on guidelines established by other Federal and commercial organizations.
1. PERSONAL USE OF SOCIAL MEDIA. This should be done on personal time using a personal computer and e-mail account. You should not be logged into external social networking sites while at work.
2. NO CLASSIFED INFORMATION. Do not post classified or sensitive information. This can lead to significant adverse action and penalties.
3. DO NOT COMMUNICATE DHS POLICIES. You should not answer questions or make statements about or on behalf of DHS on a social networking site without explicit authorization from DHS Office of Public Affairs, the DHS Office of General Counsel, or Component equivalent.
4. LIMIT THE AMOUNT OF PERSONAL INFORMATION YOU WILLINGLY POST
TO SOCIAL NETWORKS. Avoid posting personal information like your home address, personal phone numbers, or details about your schedule or routine. This type of information gives cyber criminals the baseline they need for more targeted activities. Assume that anything you might post to a social network can be seen by anyone and act accordingly. Also, be wary of the type of information — including photographs — that you post about your friends and family, since that information can put them at risk.
5. USE THE PRIVACY/SECURITY SETTINGS. When accessing social networking sites, you can limit disclosure by using the Privacy settings that are available. The default settings for some sites may allow anyone to see your profile. You can customize your settings to restrict access to only certain people. Also be aware of any changes to the site’s privacy/security options.
For example, in 2009 Facebook made major changes to user privacy settings. Some of the new settings replaced previous settings and reset them to be “viewable by everyone.” Users should monitor the privacy policies for social networking sites as they change often and without warning. Remember though, there is a risk that even private information can be exposed, so do not post anything that you would not want the public to see.
6. BE AWARE OF PRIVACY AND SECURITY ISSUES WHEN USING LOCATION-
BASED SERVICES (LBS). Location-based services offer many conveniences such as keeping track of family and friends, getting directions, finding restaurants, and assisting in law enforcement. However, information about your location may be accessible to unintended recipients. Employees should understand that use of LBS introduces significant privacy and personal security risks with their use. The most common example is using a location check-in service (i.e. Foursquare). If you check in from your couch, the precise Global Positioning System (GPS) coordinates of your couch, in your home, are published. If you then check in from your
V8.0, May 23, 2011 13 office, it can be established that you are no longer at your home and your home would be an excellent target. This mere fact can compromise your own personal security.
Employees should also be aware that this information may leak unintentionally. For example, smart phones can attach GPS coordinates to pictures you take. Posts made to social media sites such as Facebook or Twitter may also contain this detailed geo-location data that could, again, compromise your personal security and possibly your workplace security.
Be sure to examine your phone’s privacy, security, and location settings to ensure that GPS coordinates are not automatically associated with services. Be sure never to check in from sensitive locations and avoid establishing patterns where possible.
7. USE PASSWORDS CAREFULLY. Protect your account with passwords that cannot be guessed easily. Instead of your dog’s name, the word “password” plus a digit, or your favorite sports team name, passwords should include a combination of upper and lowercase letters, numbers, and special characters. Even such strongly constructed passwords are vulnerable to keystroke loggers and password cracking tools. In the final analysis, passwords do little to deter a determined attacker.
8. BE JUDICIOUS ABOUT INSTALLING APPLICATIONS FROM SOCIAL MEDIA
SITES. Often, these applications are given full access to your personal information not necessary for operation, but supplied by granting total access to your account to the application.
“Quizzes” are also problematic. For example, Facebook users taking quizzes can reveal far more personal information to applications than they realize. This is mostly due to the fact that Facebook’s default privacy settings allow access to all your profile information whether or not your profile is set to “private.” The American Civil Liberties Union (ACLU) reports that even if you do not take quizzes yourself, your profile information is revealed when one of your friends takes a quiz. Almost everything on your profile, even if you use privacy settings to limit access, is available to the quiz.6
9. BE SKEPTICAL ABOUT ALL LINKS. Vigilance is the best defense against phishing.
Phishing scams can arrive in e-mails that look as though they come from real companies or trusted individuals. For example, you may receive an e-mail message announcing that your bank account will be closed unless you confirm your personal identification number, or that you need to provide your credit card information to confirm an order, or requesting verification of your social security number for billing purposes. Legitimate companies do not ask for your account or personal information via e-mail. To find out whether the message is legitimate, contact the company directly by telephone or letter using contact information from a trusted source, such as your account statements.
10. YOU SHOULD HAVE NO EXPECTATIONS OF PRIVACY. You should assume your thoughts are in the public domain. Remember that social networking sites are generally public and permanent, even if you delete the information you posted. You should understand the security and privacy features available for the social networking sites you use, and exercise discretion and common sense. Most social networks offer settings to keep profiles private and restrict access to your photographs or other personally identifiable details; however, opting for privacy does not guarantee that others will not see your content. Content can be forwarded or
6 S. Perez, “What Facebook Quizzes Know About You,” ReadWriteWeb, August 27, 2009 7:29 AM.
V8.0, May 23, 2011 14 hacked. Facebook has found itself at the center of privacy breakdown controversies numerous times, and confusing Twitter interfaces have resulted in private messages being inadvertently posted to public feeds. Hackers can force access, and friends can forward your content to others.
In short, do not post anything that you would not want the public to see.
11 PROTECT PRIVACY. You should not share personal or contact information about your family, friends, co-workers, clients, or businesses without that individual’s explicit consent. You also should not post or tag pictures of family, friends, co-workers, clients, or business without their consent. At all times, respect the privacy of others. You should always protect sensitive information such as PII.
12. BE PROFESSIONAL. If you identify yourself as a DHS employee or have a public-facing position so that your DHS association is known to the general public, ensure your profile and related content is consistent with how you wish to present yourself as a DHS professional, even if it is of a personal and unofficial nature. Ensure all your posts and interactions are consistent with the public trust associated with your position, and conform to existing standards such as Standards of Ethical Conduct for Employees of the Executive Branch.
If you establish online profiles, you may provide your DHS title and contact information. You may also indicate that DHS is your employer, and you may describe your past and present job responsibilities (as you would on your resume) if you do not disclose any DHS sensitive information or the personal information of others.
13. USE DISCLAIMERS. Be aware of your DHS association in online social networks. If your profile reveals your employment relationship with DHS, you should include a disclaimer stating that your activity and posts represent your personal opinions and do not represent those of DHS. An example of an appropriate disclaimer is “The postings on this site are my own and do not represent DHS positions, strategies, or opinions.”
14. BE THE FIRST TO RESPOND TO YOUR OWN MISTAKES. If you make an error, be up front about your mistake and correct it quickly. In a blog, if you choose to modify an earlier post, make it clear that you have done so.
15. BE YOURSELF. Do not forge or otherwise manipulate identities in your posts in an attempt to disguise, impersonate, or otherwise misrepresent your identity or affiliation with any other person or entity.
Never reply to such e-mails or click on any links they contain. This could expose you to clickjacking, where a web page will trick you into performing undesired actions by clicking on concealed buttons or links that are on a web page hidden by the visible one. For example, the page may list what appears to be a DHS URL (or web page address, such as www.dhs.gov), which in fact hides the link to a web site set up by a cybercriminal. To find out whether the message is legitimate, contact the sending company directly by telephone or letter using data from a trusted source, such as your account statements or the back of your credit/debit card. And instead of simply clicking on an embedded link, manually type the URL into the navigation bar of your web browser to avoid clickjacking.
Phishing attempts can also come in tweets (see Twitter), Facebook wall postings, videos, or pictures. For example, a friend sending a link to a funny video might have had his/her account compromised. Get into the habit of not clicking on hyperlinks, especially those for videos or news-related events. In many cases, these are linked to phishing and social engineering attacks.
V8.0, May 23, 2011 15
16. AVOID THE OFFENSIVE. Do not post any defamatory, libelous, vulgar, obscene, abusive, profane, threatening, racially and ethnically hateful, or otherwise offensive or illegal information or material.
17. DO NOT BREACH TRADEMARKS. Do not use any words, logos, or other marks that would infringe upon the trademark, service mark, certification mark, or other intellectual property rights of the owners of such marks without the permission of such owners.
18. RESPECT COPYRIGHT, FAIR USE, AND FINANCIAL DISCLOSURE LAWS. Do not post any information or other material protected by copyright without the permission of the copyright owner. Also, consider using a Creative Commons license to protect your own work.
Creative Commons offers a flexible copyright model through a collection of free copyright licenses written in plain language. Creators can select several of these licenses to communicate which rights they reserve, and which they waive, when their intellectual property is used by others. Wikipedia is one of the most notable web-based projects using a Creative Commons license. See www.creativecommons.org for additional details.
19. IF IN DOUBT, SEEK GUIDANCE. Seek guidance from the DHS Office of Public Affairs or the DHS Office of General Counsel, or Component equivalent, prior to sharing publicly any personal opinions or statements based on your role within DHS. Those with leadership responsibilities, by virtue of their position, especially must understand that personal thoughts they publish, even in clearly personal venues, inadvertently may be interpreted as expressions of official DHS positions. They should assume that their co-workers, employees, and those outside of DHS will read what they have written.
V8.0, May 23, 2011 16
5.0 UNOFFICIAL INTERNET POSTING GUIDELINES7
Department of Homeland Security (DHS) personnel who post content about DHS on the Internet are responsible for ensuring that any information disclosed (including personal comments) is accurate and appropriate. DHS personnel should keep in mind how their posts will reflect upon themselves and their organization, and also be aware that some individuals and groups use public networking forums to gain information that will help them advance their own causes or agendas at the expense of others. DHS personnel who engage in unofficial posting on the Internet should observe the following guidelines:
1. Release of DHS e-mail addresses, telephone numbers, or fax numbers not already publicly released, including the content manager or content provider’s work contact information, is not authorized.
2. The posting or disclosure of internal DHS documents or information that DHS has not officially released to the public is not authorized. This policy applies no matter how the information was obtained. Examples include, but are not limited to, the following: memos, e-mails, meeting notes, articles for publications, white papers, Public Affairs guidance, and all pre-decisional materials. Additionally, For Official Use Only (FOUO) and PII shall not be released in unofficial Internet posts.
3. DHS personnel are responsible for adhering to DHS policies concerning information security, physical security, and the Privacy Act as in all other forms of communication.
Unauthorized disclosure of protected information may result in disciplinary action.
4. Releasing another DHS employee’s information is not authorized. Release of classified, operational, proprietary, law enforcement sensitive, or investigatory information is not authorized.
5. A photo, video, or sound recording taken of an official DHS activity by DHS personnel is considered official DHS media. Newsworthy media should be released officially to news organizations in conjunction with or copied to OPA or the Component office of public or external affairs before posting unofficially.
6. DHS related media taken while DHS personnel are in a non-working status in public areas, (e.g., photo of a U.S. Coast Guard cutter taken from a public pier while on liberty) is considered private imagery and is not subject to these guidelines.
7. Use of official or protected DHS statements or symbols (e.g., logo) must be approved by the OPA. This prevents the impression of official or implied endorsements.
8. Release of location-based (geospatial) information related to a DHS mission, whether intentional or unintentional, is not authorized. For example, this includes the location of the employee and/or DHS assets at a particular point in time (e.g., auto-tweeting geospatial coordinates while driving, or reporting via a location-based social media tool such as Foursquare.
7 Based on US DHS, ALCOAST 548/08, COMDTNOTE 5700. SUBJ: SOCIAL MEDIA - UNOFFICIAL
INTERNET POSTS.
V8.0, May 23, 2011 17
9. As with other forums of personal public engagement, DHS personnel shall avoid off-duty behavior that negatively impacts or conflicts with their ability to execute their duties for DHS, such as the prohibited personal conduct described in Standards of Ethical Conduct for Employees of the Executive Branch.
V8.0, May 23, 2011 18
GLOSSARY
Terms commonly used in relation to social media are defined below.
Blog
This term is an abbreviation for “weblog.” A blog is a web-based forum where individual content providers contribute regular entries or “posts” in the form of commentary, descriptions of events, or other materials on the website. Visitors to the blog may add their own comments to the posts. Blogs may be “moderated,” where the blog owner oversees the removal of any objectionable material, or they may be “unmoderated,” in which case there is no external control on the posted material.
Clickjacking
A malicious technique of tricking a user into revealing confidential information or taking control of their computer while clicking on seemingly harmless web pages. On a clickjacked page, the attacker shows a set of dummy buttons or links, then loads another page over it in a transparent layer. Users think they are clicking on the visible page while they are actually performing actions on the hidden page which the users never intended, such as changing privacy settings on a social networking site or following someone on Twitter.
Commercial/Third Party Social Media
Social media hosted on servers over which DHS has no control. This includes proprietary social networking sites such as Facebook and MySpace, as well as collaboration services such as Wikipedia, BlogSpot, and Delicious.
Content Manager
Any individual designated to manage web content for DHS or a Component. The duties of the Web Content Manager include ensuring compliance with accessibility standards for persons with disabilities. This individual is the organization’s primary point of contact for web issues.8
Content Provider Any individual who creates content for publication to DHS websites.9
Enterprise Network The communications backbone that interconnects every computer and associated device at every location under the jurisdiction of an organization, such as DHS.
8 DHS 4300A, IV Definitions, J 9 DHS 4300A, IV Definitions, K
V8.0, May 23, 2011 19
External Hosting
An organization purchasing from another company, on a fee-per-service basis, access to the equipment, technology and support to establish and run a website, as opposed to an organization using its own in-house resources.
Farming See Pharming
Fishing See Phishing
Foursquare
A location-based social networking website and application for mobile devices. Users “check in” or report their location by accessing a mobile website, text messaging or a device-specific application, so that their whereabouts can be discovered by others.
Foursquare also incorporates elements of a game by awarding users points for being the first to visit a new place, and for adding new information about the locations they visit.
Hacker
A person who uses their proficiency with electronics, computers and/or programming skills to gain illegal access to others’ digital resources, including personal handheld devices, files, computers and networks.
Internet footprint
The collective activities and behaviors recorded as an individual interacts in a digital environment, including device usage, system logins and logouts, website visits, files, transmitted emails, and posted messages. “Passive footprints” are created when data are collected about individuals’ activities without any deliberate action on their part, such as tracking which products customers are visiting on a vendor’s website regardless of whether purchases occur.
“Active footprints” are created when personal data is released intentionally by individuals for the purpose of sharing information with others online. Footprints are sometimes used as a rough measure of an individual’s “web presence.”
Keystroke loggers
Also called a “keylogger.” It’s a hardware device or program that monitors and records each keystroke a user types on a computing device’s keyboard. Although sometimes used for legitimate purposes, such as diagnostics or monitoring a child’s Internet activity, a more typical use of keystroke loggers is for the unauthorized capture of security credentials such as passwords and personal identification numbers.
http://en.wikipedia.org/wiki/Social_networking http://en.wikipedia.org/wiki/Software http://en.wikipedia.org/wiki/Mobile_phone http://en.wikipedia.org/wiki/Mobile_web http://en.wikipedia.org/wiki/Text_message
V8.0, May 23, 2011 20
Malware
Derived from the phrase “malicious software,” this term is a general reference to any program whose purpose is to cause harm to a computer system. Typically, malware is installed without the user’s knowledge or consent, although it is often packaged with other software the user does in fact choose to install or download. Viruses and worms are examples of malware.
Mashup
A web page or application that enables the fast, easy combination of data and/or functionality from multiple sources to create a new, enriched result that was not necessarily the reason for producing the original sources. Most mashups use publicly-accessible resources.
For example, a mashup might superimpose on a Google map of a neighborhood the average housing prices drawn from a city assessor’s online database.
Metadata
Information about the meaning of other information. Metadata can describe or summarize key attributes of a piece of information to facilitate finding that information when needed. An example of metadata is a time stamp that specifies when a piece of information was created.
Micro-Blog
Extremely short blog posts similar to text messaging. The messages can either be viewed by anyone or by a restricted group that is chosen by the user. Twitter, a popular micro-blog client, allows for posts of up to 140 characters in length to be uploaded and read online through instant messaging or mobile devices via text messaging.
Password Attack An attempt to obtain a legitimate user’s password. Hackers can use common password lists, dictionaries, cracking programs, and password sniffers in password attacks.
Personally Identifiable Information (PII)
Any information that permits the identity of an individual to be directly or indirectly inferred, including other information that is linked or linkable to an individual.10
Pharming
An action whereby a hacker subverts a user’s attempt to visit a legitimate website by instead redirecting him or her to a counterfeit or “spoofed” website. The spoofed site is designed to trick users into revealing personal information such as usernames, passwords, and account information.
10 DHS 4300A, IV Definitions, H
V8.0, May 23, 2011 21
Phishing
An attempt to fraudulently acquire a user’s personal information, such as passwords and credit card details, by masquerading as a trustworthy person or business in an apparently official electronic communication. Phishing is common in e-mail and instant messaging. For example, you might receive an e-mail that appears to come from an official at your bank that instructs you to “confirm” your Internet banking credential by clicking on a link. The “spoofed” website to which you would be directed would capture your credentials in order to enable a third party to access and withdraw all funds from your bank account.
Social Bookmarking
A web-based service where users create and store links to information on topics of particular interest to them. Although web browsers have the ability to bookmark pages, those links are tied to an individual browser on an individual computer. Social bookmarking, by contrast, stores links in an online account which can be made public. These bookmarks can be shared and discovered by others who are interested in finding information on similar topics.
Examples of social bookmarking sites include Delicious, Digg, and Reddit.
Social Engineering
The act of manipulating people into performing actions or divulging confidential information through trickery or deception rather than by breaking in or using technical means. For example, someone posing as a help desk representative might telephone you and claim to be diagnosing a connection problem and request that you verify your login ID and password or other personal information so it can be checked against the items on file.
Social Media
Internet-based applications that build on the foundations of Web 2.0 to allow the creation and exchange of user-generated content. Social media can take many different forms, including but not limited to web-based communities and hosted services, social networking sites, video and photo sharing sites, wikis, blogs, podcasts, virtual worlds, social bookmarking, and other emerging technologies.
Social Networking Services
Tools used to connect people who share the same interests and/or activities, or who are interested in exploring the interests and activities of others. Social network services are Internet-based and provide a variety of ways for users to interact. For example, Facebook is regarded as a place to socialize with friends, whereas LinkedIn caters to those who wish to make professional connections.
Spam Unsolicited or undesired bulk electronic messages. It includes legitimate advertisements, misleading advertisements, and phishing messages.
V8.0, May 23, 2011 22
Spear Fishing See Spear Phishing
Spear Phishing
A technique by which the attacker generates an email or website that is tailored to a specific individual or small group. The goal is to convince the targets to take action, which gives the attacker access to their system by presenting them with text, images, or URLs that they could expect and therefore mistake for legitimate.
Spoofed Website
An impostor website that mimics a real company’s website in order to steal personal information from site visitors. Victims are often directed to these spoofed sites through phishing e-mails. Spoofed sites can look extremely convincing, but often contain small flaws such as spelling errors or “slightly wrong” logos.
Spyware
Any software that covertly gathers users’ information through their computing devices and/or their Internet connection without their knowledge for unauthorized use. Spyware applications are typically hidden components that users inadvertently download along with other legitimate material. Spyware may gather information such as e-mail addresses for advertising purposes, or even passwords and credit card data.
Trusted Internet Connections (TIC)
A DHS Initiative, outlined in OMB Memorandum M-08-05, to optimize and standardize the security of individual external network connections, to include connections to the Internet, currently in use by the Federal Government. A “TIC” is a physical location an agency uses to meet the objectives of the TIC Initiative.
A social networking micro-blogging service that enables its users to send and read…
This is the start of the file's text. The full file is on GovTribe.
File details come from the government source that posted it. Updated .