Critical.
Authoritative.
Strategic.
Subscribe to CIO Magazine »

US Sets Deadline for Gov't Breach-Notification Plans

As part of the new privacy measures, agencies are now required to review all of the personal data currently in their possession and make sure the data is "accurate, relevant, timely and complete", and to reduce that data to the minimum needed for official purposes

The White House Office of Management and Budget (OMB) is giving US federal agencies 120 days to develop and implement a security breach notification policy. Agencies have also been instructed in that time to review their use of personally identifiable information (PII), and to develop plans to reduce or eliminate the unnecessary use of Social Security numbers and other personal data.

The deadlines were set forth in a memorandum sent to the heads of executive departments and agencies last week by Clay Johnson, the OMB's deputy director for management. In the memo, Johnson also outlined several other data loss mitigation measures that he wanted agencies to implement. The measures included designing strategies for protecting data during remote access, assigning roles and responsibilities for individuals with access to personal data, and implementing policies for corrective actions for failures to follow security guidelines.

The measures are needed to better protect against and respond to security breaches involving private data, Johnson said in his 22-page[memo. "Safeguarding personally identifiable information in the possession of the government and preventing its breach are essential to ensure the government retains the trust of the American public," he wrote.

The memo directs the agencies to use "a best judgment standard" in developing a breach notification policy and urges them to ensure the "widest possible" distribution of the standards across each agency.

It reiterates several of the existing privacy and security measures that agencies are obligated to fulfil, such as prioritizing their information systems, doing privacy impact analysis and performing continuous monitoring of sensitive systems. In addition to these requirements, Johnson's memo establishes two new privacy controls and discusses five other security measures that federal agencies need to undertake.

As part of the new privacy measures, agencies are now required to review all of the personal data currently in their possession and make sure the data is "accurate, relevant, timely and complete", and to reduce that data to the minimum needed for official purposes. Agencies will also need to review their use of Social Security numbers (SSNs) and identify areas where such information is unnecessary, or where alternative information could be used. Also, agencies are required by mid-September to come up with a plan for eliminating the SSNs within 18 months.

On the security front, Johnson's directive asks federal agencies to encrypt all data on mobile computers and devices carrying agency data. It also asks them to control remote access to agency networks via two-factor authentication and to use a "timeout" function for remote devices, requiring user re-authentication. In addition, the memorandum calls for database access monitoring to make sure that all access to private data is logged.

Security incident reporting and handling requirements for agencies have been modified as well. Going forward, agencies will be required to report all suspected and confirmed information breaches to US-CERT. The memo formalizes the need for agencies to notify individuals whose personal information might have been compromised in a security breach.

Johnson's May 22 memo was released exactly one year after the disclosure of the massive security breach at the US Department of Veterans Affairs in May 2006. That breach involved the potential compromise of personal data belonging to over 26 million veterans.

The memo follows through on a set of interim recommendations released in April by the President Bush's Identity Theft Task Force. The task force offered nine specific recommendations for protecting personal data and responding to data breaches that it wanted the OMB to communicate to all federal agencies. It is those recommendations that were articulated in Johnson's memo.

Join the CIO Australia group on LinkedIn. The group is open to CIOs, IT Directors, COOs, CTOs and senior IT managers.

More about: CERT, FTC, HIS Limited, Office of Management and Budget, VIA

Comments

Post new comment

The content of this field is kept private and will not be shown publicly.
Users posting comments agree to the CIO comments policy.
Login or register to link comments to your user profile, or you may also post a comment without being logged in.
Related Whitepapers
Latest Stories
Community Comments
Latest Blog Posts
Whitepapers
  • 10 Essential Steps to Email Security
    Modern business is reliant on email. All organisations using email need to answer the following questions: How do we control spam volumes without the risk of trapping a business email? How do we prevent infections from email-borne viruses? How do we stop leakage of confidential information? Can we detect and stop exploitation from phishing attacks? How do we control brand damage from occurring due to employee misuse? How do we prevent inappropriate content from being circulated?
    Learn more »
  • Oracle Business Process Analysis Suite
    Careful analysis and continuous optimization of business processes delivers real competitive advantage. Conversely, a random approach to process design negatively impacts a company’s bottom line. This insight is one reason successful companies adopt business process management (BPM) as a way of aligning their business processes with business and customer requirements. Success with BPM eliminates the gap between business strategy and implementation. Business users are empowered to participate in all stages of the business process lifecycle. Closed-loop integration between modeling, execution, and monitoring enables continuous and holistic business process improvement.
    Learn more »
  • Reducing Costs Through Better Server Utilisation
    By consolidating systems onto the latest server technology and taking advantage of virtualization techniques, enterprises can optimize datacenter efficiency, gain flexibility, and reduce operating costs—without sacrificing performance or impacting service levels. Read on.
    Learn more »
All whitepapers
rhs_login_lockGet exclusive access to Invitation only events CIO, reports & analysis.
Recent comments