PRIVACY IMPACT ASSESSMENT

Size: px
Start display at page:

Download "PRIVACY IMPACT ASSESSMENT"

Transcription

1 PRIVACY IMPACT ASSESSMENT Microsoft Office SharePoint Collaboration & Communication Solution June 2013 FDIC Internal System Table of Contents System Overview Personally Identifiable Information (PII) in SharePoint Purpose & Use of Information in SharePoint Sources of Information in SharePoint Notice & Consent Access to Data in SharePoint Data Sharing Data Accuracy in SharePoint Data Security for SharePoint System of Records Notice (SORN) Contact Us

2 Microsoft Office SharePoint Collaboration System Overview SharePoint is a Microsoft-based product that provides an integrated enterprise environment, allowing users to collaborate, share, and manage electronic information within workgroups and project teams. The Microsoft SharePoint program utilized by the FDIC provides a growing selection of functionalities to improve business collaboration and communications. This includes browser-based process management modules, a document/records management platform, enterprise search modules, personalization, blogs and wikis 1, and advanced indexing and searching capabilities. FDIC mainly uses SharePoint to host Division/Office websites, shared workspaces, information repository and document storage. Authorized users can manipulate certain controls or interact with pieces of content, such as lists and document libraries. SharePoint allows site owners to manage content and security for sites under their responsibility. Acting in coordination with Division/Office SharePoint points of contact, site owners/administrators are responsible for monitoring and maintaining the content of their respective sites. The site owners/administrators ensure that information collected or placed into the FDIC SharePoint sites are appropriate and in line with FDIC data protection and retention policies. FDIC SharePoint sites are the Corporation s secure workspace for collaboration on active documents and other content for business purposes. Data stored on FDIC SharePoint sites may potentially include agency-sensitive information (SI) and personally identifiable information (PII) as necessary to accomplish authorized FDIC business needs. Users are prohibited from storing personal, non-business documents within any FDIC SharePoint site. They must also identify documents containing SI or PII, in accordance with the Corporation s SharePoint Governance Plan and associated policies and procedures. SharePoint also provides a secure work area, known as My Site, where users have the capability to post a professional picture and enter business-related and personal information, such as their professional biography and skills and interests, for others within the FDIC to view. The public profile information is managed by the individual user, and the user may choose privacy levels that help ensure that data stored in their profiles is visible only to intended parties within the Corporation. Personally Identifiable Information (PII) in SharePoint FDIC SharePoint sites will host a variety of data. In general, all electronically stored information found on FDICshare and FDICbcs SharePoint sites must be related to official FDIC business and, as such, may include SI and PII about internal (FDIC) and external (non-fdic) entities as necessary for authorized FDIC business needs. The specific types of PII maintained within FDICshare and FDICbcs SharePoint sites vary depending on the particular business purpose(s) for which the site was designed. FDICmysite ( My Site ) provides a secure workspace for individual users to store business-related and personal information about themselves for others within the Corporation to view. 1 The use of wikis and blogs functionality within FDIC SharePoint is prohibited without prior authorization from Division and Office Directors. 1

3 Microsoft Office SharePoint Collaboration The Document Library section of all SharePoint sites must use the FDIC Document Library template, which requires users to specify a sensitivity level (sensitive, sensitive PII, or non-sensitive) for all documents stored in FDICshare and FDICbcs SharePoint sites. Although users are allowed to store business related SI/PII in SharePoint, users are strongly encouraged to store such records in the official System of Records (SOR) or other appropriate document repositories prescribed in the official business processes and file plans. Moreover, the FDIC SharePoint Governance Plan and associated FDIC policies prohibit users from storing personal (non-business) data in FDICshare and FDICbcs SharePoint sites. Purpose & Use of Information in SharePoint The collection and use of SharePoint data is relevant and necessary to accomplish authorized FDIC business needs. The specific types of PII maintained within SharePoint vary based on the business need(s) for which each SharePoint site was designed (i.e., examination and enforcement, resolution and receivership, legal, vendor/contract management, Human Resources/personnel, etc.). Sources of Information in SharePoint Data maintained in FDICshares and FDICbcs SharePoint sites is obtained and uploaded by authorized FDIC staff and contractors in connection with their various Corporate and Receivership job responsibilities. For example, many documents and items maintained in FDICbcs SharePoint repositories are obtained from failed financial institutions as part of the Division of Resolutions and Receiverships (DRR) bank closing activities performed by FDIC staff and contractors. With regard to FDICmysite, the following types of business and organizational tree information are pulled from Microsoft Active Director (AD) to populate individual users My Site public profile pages: FDIC user name, work address, work telephone number, title, division, supervisors, work groups, etc. Additionally, individual FDIC users can choose to post a professional picture and enter additional business-related and personal data about themselves on their respective My Site profile pages, including a professional biography, skills and interests, languages spoken, schools attended, personal telephone numbers, and birthday. All content posted by users to My Site must be business appropriate and professional in nature. With the exception of a professional photograph, users are not able to upload any other documents to their public profile sites; information may only be entered into predefined text box fields on their respective page. The FDIC SharePoint environment is only accessible to internal FDIC network users. However, FDIC staff or contractors may obtain or receive business data from federal, state, and local agencies as part of their official business functions. They may also receive business data from third-party sources, such as commercial databases (i.e., Lexis-Nexis), nonpublic investigatory databases, credit bureaus, etc. They may store this data in designated SharePoint repositories. In addition, FDIC network users may include federal, state, or local agencies who require access to FDIC SharePoint sites in order to review or post data for official business purposes. All network users are authenticated in order to access or post documents to SharePoint. 2

4 Microsoft Office SharePoint Collaboration Notice & Consent Individual FDIC users have the right to opt out of providing their information for inclusion in SharePoint. FDIC users must affirmatively choose to add personal information to their public profile page within FDICmysite. Business and organizational information (non-pii) is included in FDICmysite. For documents posted on FDICbcs and FDICshare sites, the individuals whose PII is contained in these documents may or may not have the opportunity to opt out of providing their personal information. For example, information posted to FDICbcs sites may be obtained from failed financial institutions, not directly from individuals; this information may be necessary to support the Corporation s resolution and receivership activities. Therefore, the individual is not provided with an opt-out notice. In general, the specific circumstances under which individuals are offered a choice to opt out is dependent on the source of the data. Access to Data in SharePoint In general, only authorized users who require access to SharePoint information in order to perform their official job responsibilities will be granted access to their respective SharePoint sites. Farm Administrator Responsible for all servers in the SharePoint server farm and able to perform all administrative tasks in the SharePoint Central Administration Website for the server or server farm; responsible for global SharePoint configuration, shared services, policies, procedures, and SharePoint vision. Site Collection Administrator Responsible for SharePoint area content. Site Administrator Responsible for site provisioning; maintains and administers site. Site Administrator Assistant Backup to Site Administrators; assists Site Administrator with all tasks but does not manage security, provision new sites, or apply any customizations. Division/Office SharePoint Coordinator Responsible for overall management of Division/Office SharePoint site. Contributor Responsible for adding, editing, and collaborating with other contributors. Reader Adhere to internal Division/Office procedures for approval information on SharePoint and ensure organizational compliance with FDIC policies, procedures, standards, and guidelines governing information resources. In addition, authorized staff and contractors in the Division of Information Technology (DIT) have global access to all FDIC SharePoint sites for information technology purposes. With regard to FDICmysite, the public profile information is edited and managed by the individual user. Users can choose privacy levels that help ensure their data is visible only to intended individuals within the Corporation. 3

5 Data Sharing Other Systems that Share of Have Access to Data in the System: Microsoft Office SharePoint Collaboration There are no direct interconnections between FDIC SharePoint sites and other systems at this time, aside from the business-related data provided by Microsoft Active Director (AD) to FDICmysite. System Name Microsoft Active Directory (AD) System Description Active Directory is a Microsoft program that serves as a database for information about users such as phone numbers, address, user names, etc. Type of Information Processed FDIC user name, work address, work telephone number, title, division, supervisor, work groups, etc. Data Accuracy in SharePoint Each individual user is responsible for ensuring the completeness and accuracy of the data they post to SharePoint sites. Users are required to specify a sensitive level (sensitive, sensitive PII, or non-sensitive) for all documents stored in SharePoint. Additionally, each Division/Office is responsible for conducting annual access and content reviews of their site collections, along with periodic site reviews, in accordance with FDIC SharePoint rules and regulations. Data Security for SharePoint Access to data within the FDIC SharePoint environment is based on business need and a user s need to know. Additionally, access is determined according to the principle of least privilege whereby user accounts are provided the minimal, most restrictive set of permissions required to perform their work. Data contained in the SharePoint environment is secured through controlled access and passwords, and is only accessible to authenticated network users. An audit trail process captures activities on SharePoint sites and monitors usage of the SharePoint servers to prevent unauthorized and suspicious activities. Only the DIT Administrator and his/her designee have access to run the SharePoint audit reporting tool and generate reports. System of Records Notice (SORN) The FDIC SharePoint sites do not currently operate as a Privacy Act System of Records (SORs), nor do they require changes to any existing system of records. FDICshare and FDICbcs may be used to process and store Privacy Act Records from existing FDIC Privacy Act SORs by authorized FDIC staff and contractors in connection with their various Corporate and Receivership job responsibilities. 4

6 Contact Us To learn more about the FDIC s Privacy Program, please visit: Microsoft Office SharePoint Collaboration If you have a privacy-related question or request, Privacy@fdic.gov or one of the FDIC Privacy Program Contacts. You may also mail your privacy question or request to the FDIC Privacy Program at the following address: 3501 Fairfax Drive, Arlington, VA

PRIVACY IMPACT ASSESSMENT

PRIVACY IMPACT ASSESSMENT PRIVACY IMPACT ASSESSMENT Enterprise Communications Services November 2012 FDIC Internal System Table of Contents System Overview Personally Identifiable Information (PII) in ECS Purpose & Use of Information

More information

How To Use The Fdic External Service For Mortgage Servicing Rights

How To Use The Fdic External Service For Mortgage Servicing Rights PRIVACY IMPACT ASSESSMENT Financial Advisory Service for Mortgage Servicing Rights November 2013 FDIC External Service Table of Contents System Overview Personally Identifiable Information (PII) in MSR

More information

PRIVACY IMPACT ASSESSMENT

PRIVACY IMPACT ASSESSMENT PRIVACY IMPACT ASSESSMENT Customer Communication and Tracking System December 2012 FDIC Internal System Table of Contents System Overview Personally Identifiable Information (PII) in CCATS Purpose & Use

More information

PRIVACY IMPACT ASSESSMENT

PRIVACY IMPACT ASSESSMENT PRIVACY IMPACT ASSESSMENT Environmental Request Tracking System April 2014 FDIC Internal System Table of Contents System Overview Personally Identifiable Information (PII) in ERTS Purpose & Use of Information

More information

PRIVACY IMPACT ASSESSMENT

PRIVACY IMPACT ASSESSMENT PRIVACY IMPACT ASSESSMENT Outsourced Litigation Support Services September 2013 FDIC External Service Table of Contents System Overview Personally Identifiable Information (PII) in OLSS Purpose & Use of

More information

PRIVACY IMPACT ASSESSMENT

PRIVACY IMPACT ASSESSMENT PRIVACY IMPACT ASSESSMENT Virtual Data Room August 2012 FDIC External Service Table of Contents System Overview Personally Identifiable Information (PII) in VDR Purpose & Use of Information in VDR Sources

More information

PRIVACY IMPACT ASSESSMENT

PRIVACY IMPACT ASSESSMENT PRIVACY IMPACT ASSESSMENT Deloitte Forensic Data Capture Services January 2013 FDIC External Service Table of Contents System Overview Personally Identifiable Information (PII) in Deloitte Purpose & Use

More information

PRIVACY IMPACT ASSESSMENT

PRIVACY IMPACT ASSESSMENT PRIVACY IMPACT ASSESSMENT Electronic Litigation Support System June 2012 FDIC Internal System Table of Contents System Overview Personally Identifiable Information (PII) in ELS Purpose & Use of Information

More information

PRIVACY IMPACT ASSESSMENT

PRIVACY IMPACT ASSESSMENT PRIVACY IMPACT ASSESSMENT First Financial Network July 2011 FDIC External Service Table of Contents System Overview Personally Identifiable Information (PII) in FFN Purpose & Use of Information in FFN

More information

PRIVACY IMPACT ASSESSMENT

PRIVACY IMPACT ASSESSMENT PRIVACY IMPACT ASSESSMENT Mission Capital Advisors April 2011 FDIC External Service Table of Contents System Overview Personally Identifiable Information (PII) in MISSION Purpose & Use of Information in

More information

PRIVACY IMPACT ASSESSMENT

PRIVACY IMPACT ASSESSMENT PRIVACY IMPACT ASSESSMENT Garnet Capital Advisors January 2011 FDIC External Service Table of Contents System Overview Personally Identifiable Information (PII) in GARNET Purpose & Use of Information in

More information

PRIVACY IMPACT ASSESSMENT

PRIVACY IMPACT ASSESSMENT PRIVACY IMPACT ASSESSMENT U.S. Office of Personnel Management (OPM) Electronic Delivery System March 2013 FDIC External System Table of Contents System Overview Personally Identifiable Information (PII)

More information

Designing IT Platform Collaborative Applications with Microsoft SharePoint 2003 Workshop

Designing IT Platform Collaborative Applications with Microsoft SharePoint 2003 Workshop Designing IT Platform Collaborative Applications with Microsoft SharePoint 2003 Workshop Course 8036: Two days; Instructor-led Microsoft Certified Professional Exams No Microsoft Certified Professional

More information

PRIVACY IMPACT ASSESSMENT

PRIVACY IMPACT ASSESSMENT PRIVACY IMPACT ASSESSMENT Examination Tools Suite-Automated Loan Examination Review Tool July 2012 FDIC Internal System Table of Contents System Overview Personally Identifiable Information (PII) in ETS-ALERT

More information

PRIVACY IMPACT ASSESSMENT

PRIVACY IMPACT ASSESSMENT PRIVACY IMPACT ASSESSMENT National Finance Center Payroll/Personnel System April 2013 FDIC External System Table of Contents System Overview Personally Identifiable Information (PII) in NFC PPS Purpose

More information

PRIVACY IMPACT ASSESSMENT

PRIVACY IMPACT ASSESSMENT PRIVACY IMPACT ASSESSMENT New Financial Environment December 2014 FDIC Internal System Table of Contents System Overview Personally Identifiable (PII) - NFE Purpose & Use of - NFE Sources of in NFE Notice

More information

PRIVACY IMPACT ASSESSMENT

PRIVACY IMPACT ASSESSMENT PRIVACY IMPACT ASSESSMENT Document Imaging and Indexing Services Advanced System Design/VASTEC May 2013 FDIC External Service Table of Contents System Overview Personally Identifiable Information (PII)

More information

PRIVACY IMPACT ASSESSMENT

PRIVACY IMPACT ASSESSMENT PRIVACY IMPACT ASSESSMENT Employee Benefits Management Services December 2013 FDIC External Service Table of Contents System Overview Personally Identifiable Information (PII) in EBMS Purpose & Use of

More information

How To Understand And Understand The Role Of Reverse Mortgage Solutions

How To Understand And Understand The Role Of Reverse Mortgage Solutions PRIVACY IMPACT ASSESSMENT Reverse Mortgage Solutions January 2014 FDIC External Service Table of Contents System Overview Personally Identifiable Information (PII) in RMS Purpose & Use of Information in

More information

Microsoft Technology Practice Capability document. MOSS / WSS Building Portal based Information Worker Solutions. Overview

Microsoft Technology Practice Capability document. MOSS / WSS Building Portal based Information Worker Solutions. Overview Microsoft Technology Practice Capability document Overview Microsoft Office SharePoint Server (MOSS) and Windows SharePoint Services (WSS) facilitate rapid website creation that supports specific content

More information

PRIVACY IMPACT ASSESSMENT

PRIVACY IMPACT ASSESSMENT PRIVACY IMPACT ASSESSMENT Examination Tools Suite March 2015 FDIC Internal System Table of Contents System Overview Personally Identifiable Information (PII) in ETS Purpose & Use of Information in ETS

More information

Office of Audits and Evaluations Report No. AUD-13-007. The FDIC s Controls over Business Unit- Led Application Development Activities

Office of Audits and Evaluations Report No. AUD-13-007. The FDIC s Controls over Business Unit- Led Application Development Activities Office of Audits and Evaluations Report No. AUD-13-007 The FDIC s Controls over Business Unit- Led Application Development Activities September 2013 Executive Summary The FDIC s Controls over Business

More information

A. SYSTEM DESCRIPTION

A. SYSTEM DESCRIPTION NOTE: The following reflects the information entered in the PIAMS Website. A. SYSTEM DESCRIPTION Authority: Office of Management Budget (OMB) Memorandum (M) 03-22, OMB Guidance for Implementing the Privacy

More information

Federal Trade Commission Privacy Impact Assessment

Federal Trade Commission Privacy Impact Assessment Federal Trade Commission Privacy Impact Assessment for the: W120023 ONLINE FAX SERVICE December 2012 1 System Overview The Federal Trade Commission (FTC, Commission or the agency) is an independent federal

More information

PINAL COUNTY POLICY AND PROCEDURE 2.50 ELECTRONIC MAIL AND SCHEDULING SYSTEM

PINAL COUNTY POLICY AND PROCEDURE 2.50 ELECTRONIC MAIL AND SCHEDULING SYSTEM PINAL COUNTY POLICY AND PROCEDURE 2.50 Subject: ELECTRONIC MAIL AND SCHEDULING SYSTEM Date: November 18, 2009 Pages: 1 of 5 Replaces Policy Dated: April 10, 2007 PURPOSE: The purpose of this policy is

More information

Zubi Advertising Privacy Policy

Zubi Advertising Privacy Policy Zubi Advertising Privacy Policy This privacy policy applies to information collected by Zubi Advertising Services, Inc. ( Company, we or us ), on our Latino Emoji mobile application or via our Latino Emoji

More information

Privacy Impact Assessment

Privacy Impact Assessment MAY 24, 2012 Privacy Impact Assessment matters management system Contact Point: Claire Stapleton Chief Privacy Officer 1700 G Street, NW Washington, DC 20552 202-435-7220 claire.stapleton@cfpb.gov DOCUMENT

More information

U.S. Securities and Exchange Commission. Mailroom Package Tracking System (MPTS) PRIVACY IMPACT ASSESSMENT (PIA)

U.S. Securities and Exchange Commission. Mailroom Package Tracking System (MPTS) PRIVACY IMPACT ASSESSMENT (PIA) U.S. Securities and Exchange Commission (MPTS) PRIVACY IMPACT ASSESSMENT (PIA) February 24, 2013 General Information 1. Name of Project or System. (MPTS) 2. Describe the project and its purpose or function

More information

The Bureau of the Fiscal Service. Privacy Impact Assessment

The Bureau of the Fiscal Service. Privacy Impact Assessment The Bureau of the Fiscal Service Privacy Impact Assessment The mission of the Bureau of the Fiscal Service (Fiscal Service) is to promote the financial integrity and operational efficiency of the federal

More information

Approved 12/14/11. FIREWALL POLICY INTERNAL USE ONLY Page 2

Approved 12/14/11. FIREWALL POLICY INTERNAL USE ONLY Page 2 Texas Wesleyan Firewall Policy Purpose... 1 Scope... 1 Specific Requirements... 1 PURPOSE Firewalls are an essential component of the Texas Wesleyan information systems security infrastructure. Firewalls

More information

Canine Website System (CWS System) DHS/TSA/PIA-036 January 13, 2012

Canine Website System (CWS System) DHS/TSA/PIA-036 January 13, 2012 for the (CWS System) DHS/TSA/PIA-036 January 13, 2012 Contact Point Carolyn Y. Dorgham Program Manager, National Explosives Detection Canine Team Program Carolyn.Dorgham@dhs.gov Reviewing Official Mary

More information

Department of Homeland Security Web Portals

Department of Homeland Security Web Portals for the Department of Homeland Security Web Portals June 15, 2009 Contact Point Mary Ellen Callahan Chief Privacy Officer Department of Homeland Security (703) 235-0780 Page 2 Abstract Many Department

More information

CORRELATE for Microsoft Sharepoint Windows Services

CORRELATE for Microsoft Sharepoint Windows Services CORRELATE for Microsoft Sharepoint Windows Services White Paper Purpose The purpose of this document is to describe the integration of Correlate and Microsoft Windows Sharepoint Services (WSS). This description

More information

A. SYSTEM DESCRIPTION

A. SYSTEM DESCRIPTION A. SYSTEM DESCRIPTION Authority: Office of Management Budget (OMB) Memorandum (M) 03 22, OMB Guidance for Implementing the Privacy Provisions of the E Government Act of 2002 & PVR #10 Privacy Accountability

More information

PRIVACY IMPACT ASSESSMENT

PRIVACY IMPACT ASSESSMENT PRIVACY IMPACT ASSESSMENT Submit in Word format electronically to: Linda Person (person.linda@epa.gov) Office of Environmental Information System Name: The Inspector General Enterprise Management System

More information

General Support System

General Support System PRIVACY IMPACT ASSESSMENT JUNE 30, 2015 General Support System Does the CFPB use the information to benefit or make a determination about an individual? No. What is the purpose? Store and Transmit all

More information

Department of the Interior Privacy Impact Assessment

Department of the Interior Privacy Impact Assessment Department of the Interior September 3, 2013 Name of Project: BisonConnect Google Apps for Government Bureau: Office of the Secretary Project s Unique ID: 010-000000330 Once the PIA is completed and the

More information

Synapse Privacy Policy

Synapse Privacy Policy Synapse Privacy Policy Last updated: April 10, 2014 Introduction Sage Bionetworks is driving a systems change in data-intensive healthcare research by enabling a collective approach to information sharing

More information

Estate Agents Authority

Estate Agents Authority INFORMATION SECURITY AND PRIVACY PROTECTION POLICY AND GUIDELINES FOR ESTATE AGENTS Estate Agents Authority The contents of this document remain the property of, and may not be reproduced in whole or in

More information

WatchDox Administrator's Guide. Application Version 3.7.5

WatchDox Administrator's Guide. Application Version 3.7.5 Application Version 3.7.5 Confidentiality This document contains confidential material that is proprietary WatchDox. The information and ideas herein may not be disclosed to any unauthorized individuals

More information

United States Citizenship and Immigration Services (USCIS) Enterprise Service Bus (ESB)

United States Citizenship and Immigration Services (USCIS) Enterprise Service Bus (ESB) for the United States Citizenship and Immigration Services (USCIS) June 22, 2007 Contact Point Harry Hopkins Office of Information Technology (OIT) (202) 272-8953 Reviewing Official Hugo Teufel III Chief

More information

9/11 Heroes Stamp Act of 2001 File System

9/11 Heroes Stamp Act of 2001 File System for the 9/11 Heroes Stamp Act of 2001 File System Contact Point Elizabeth Edge US Fire Administration Federal Emergency Management Agency (202) 646-3675 Reviewing Official Nuala O Connor Kelly Chief Privacy

More information

Veson Nautical Website Privacy Policy

Veson Nautical Website Privacy Policy Veson Nautical Website Privacy Policy Veson Nautical Corporation (including its affiliated companies, Veson, we, or us ) has created this Privacy Policy ("Policy") in order to provide you with information

More information

Privacy Impact Assessment

Privacy Impact Assessment Technology, Planning, Architecture, & E-Government Version: 1.1 Date: April 14, 2011 Prepared for: USDA OCIO TPA&E Privacy Impact Assessment for the April 14, 2011 Contact Point Charles McClam Deputy Chief

More information

E-Mail Secure Gateway (EMSG)

E-Mail Secure Gateway (EMSG) for the E-Mail Secure Gateway (EMSG) DHS/MGMT/PIA-006 March 22, 2012 Contact Point David Jones MGMT/OCIO/ITSO/ESDO DHS HQ (202) 447-0167 Reviewing Official Mary Ellen Callahan Chief Privacy Officer Department

More information

U.S. Securities and Exchange Commission. Integrated Workplace Management System (IWMS) PRIVACY IMPACT ASSESSMENT (PIA)

U.S. Securities and Exchange Commission. Integrated Workplace Management System (IWMS) PRIVACY IMPACT ASSESSMENT (PIA) U.S. Securities and Exchange Commission (IWMS) PRIVACY IMPACT ASSESSMENT (PIA) March 21, 2013 General Information 1. Name of Project or System. (IWMS) 2. Describe the project and its purpose or function

More information

Authentication and Provisioning Services (APS)

Authentication and Provisioning Services (APS) for the (APS) DHS/FEMA/PIA-031 August 6, 2013 Contact Point Tina Wallace-Fincher Information Technology Security Branch FEMA Information Technology (202) 646-4605 Reviewing Official Jonathan R. Cantor

More information

Federal Trade Commission Privacy Impact Assessment

Federal Trade Commission Privacy Impact Assessment Federal Trade Commission Privacy Impact Assessment for the: StenTrack Database System September, 2011 1 System Overview The Federal Trade Commission (FTC) protects America s consumers. As part of its work

More information

PII Compliance Guidelines

PII Compliance Guidelines Personally Identifiable Information (PII): Individually identifiable information from or about an individual customer including, but not limited to: (a) a first and last name or first initial and last

More information

Using ADOBE LIVECYCLE ES4 Connector for MICROSOFT SHAREPOINT

Using ADOBE LIVECYCLE ES4 Connector for MICROSOFT SHAREPOINT Using ADOBE LIVECYCLE ES4 Connector for MICROSOFT SHAREPOINT Legal notices Legal notices For legal notices, see http://help.adobe.com/en_us/legalnotices/index.html. iii Contents Using the Connector for

More information

MS 50547B Microsoft SharePoint 2010 Collection and Site Administration

MS 50547B Microsoft SharePoint 2010 Collection and Site Administration MS 50547B Microsoft SharePoint 2010 Collection and Site Administration Description: Days: 5 Prerequisites: This five-day instructor-led Site Collection and Site Administrator course gives students who

More information

Information Security Risk Assessment Checklist. A High-Level Tool to Assist USG Institutions with Risk Analysis

Information Security Risk Assessment Checklist. A High-Level Tool to Assist USG Institutions with Risk Analysis Information Security Risk Assessment Checklist A High-Level Tool to Assist USG Institutions with Risk Analysis Updated Oct 2008 Introduction Information security is an important issue for the University

More information

Information Technology Cyber Security Policy

Information Technology Cyber Security Policy Information Technology Cyber Security Policy (Insert Name of Organization) SAMPLE TEMPLATE Organizations are encouraged to develop their own policy and procedures from the information enclosed. Please

More information

Your 12 step plan to a successful SharePoint implementation. SharePoint Project Checklist

Your 12 step plan to a successful SharePoint implementation. SharePoint Project Checklist Your 12 step plan to a successful SharePoint implementation SharePoint Project Checklist SharePoint Project Checklist Your 12 step plan to success in implementing SharePoint 1. Pre-Project Planning Identify

More information

PRIVACY IMPACT ASSESSMENT (PIA) GUIDE

PRIVACY IMPACT ASSESSMENT (PIA) GUIDE U.S. Securities and Exchange Commission Office of Information Technology Alexandria, VA PRIVACY IMPACT ASSESSMENT (PIA) GUIDE Revised January 2007 Privacy Office Office of Information Technology PRIVACY

More information

Minnesota State Colleges and Universities System Guideline Chapter 5 Administration

Minnesota State Colleges and Universities System Guideline Chapter 5 Administration Minnesota State Colleges and Universities System Guideline Chapter 5 Administration Appropriate Use and Implementation of Electronic Part 1. Purpose. To establish requirements and responsibilities for

More information

Department of the Interior Privacy Impact Assessment Template

Department of the Interior Privacy Impact Assessment Template Department of the Interior Template May 28, 2014 Name of Project: Consolidated Financial System (CFS) Bureau: Office of the Secretary Project s Unique ID: 010-000000308 A. CONTACT INFORMATION: Teri Barnett

More information

126 SW 148 th Street Suite C-100, #105 Seattle, WA 98166 Tel: 877-795-9372 Fax: 866-417-6192 www.seattlepro.com

126 SW 148 th Street Suite C-100, #105 Seattle, WA 98166 Tel: 877-795-9372 Fax: 866-417-6192 www.seattlepro.com SharePoint 2010 Bootcamp This five-day course is designed to equip Systems Administrators, Integrators and Developers with a strong foundation for implementing solutions on Microsoft SharePoint 2010. Attendees

More information

PRIVACY IMPACT ASSESSMENT

PRIVACY IMPACT ASSESSMENT PRIVACY IMPACT ASSESSMENT Seneca Mortgage Servicing, LLC March 2015 FDIC External Services Table of Contents System Overview Personally Identifiable Information (PII) in SMS Purpose & Use of Information

More information

Department of Homeland Security Management Directives System MD Number: 4500.1 Issue Date: 03/01/2003 DHS E-MAIL USAGE

Department of Homeland Security Management Directives System MD Number: 4500.1 Issue Date: 03/01/2003 DHS E-MAIL USAGE Department of Homeland Security Management Directives System MD Number: 4500.1 Issue Date: 03/01/2003 DHS E-MAIL USAGE I. Purpose This directive establishes Department of Homeland Security (DHS) policy

More information

The SharePoint Shepherd s Course for End Users

The SharePoint Shepherd s Course for End Users 3 Riverchase Office Plaza Hoover, Alabama 35244 Phone: 205.989.4944 Fax: 855.317.2187 E-Mail: rwhitney@discoveritt.com Web: www.discoveritt.com Course 50562A: The SharePoint Shepherd s Course for End Users

More information

Compliance and Security Solutions

Compliance and Security Solutions Content-aware Compliance and Security Solutions for Microsoft SharePoint SharePoint and the ECM Challenge The numbers tell the story. According to the consulting firm Doculabs, 80 percent of the information

More information

Achieving PCI COMPLIANCE with the 2020 Audit & Control Suite. www.lepide.com/2020-suite/

Achieving PCI COMPLIANCE with the 2020 Audit & Control Suite. www.lepide.com/2020-suite/ Achieving PCI COMPLIANCE with the 2020 Audit & Control Suite 7. Restrict access to cardholder data by business need to know PCI Article (PCI DSS 3) Report Mapping How we help 7.1 Limit access to system

More information

LITIGATION SUPPORT SYSTEM (SYSTEM NAME)

LITIGATION SUPPORT SYSTEM (SYSTEM NAME) Privacy Impact Assessment Form LITIGATION SUPPORT SYSTEM (SYSTEM NAME) This template is used when the Chief Privacy Officer determines that the system contains Personally Identifiable Information and a

More information

e-performance System

e-performance System Updated Privacy Impact Assessment for the e-performance System Contact Point John Allen HRMS Human Capital Business Systems Department of Homeland Security (202) 357-8285 Reviewing Official Hugo Teufel

More information

CASE MATTER MANAGEMENT TRACKING SYSTEM

CASE MATTER MANAGEMENT TRACKING SYSTEM for the CASE MATTER MANAGEMENT TRACKING SYSTEM September 25, 2009 Contact Point Mr. Donald A. Pedersen Commandant (CG-0948) (202) 372-3818 Reviewing Official Mary Ellen Callahan Chief Privacy Officer Department

More information

R345, Information Technology Resource Security 1

R345, Information Technology Resource Security 1 R345, Information Technology Resource Security 1 R345-1. Purpose: To provide policy to secure the private sensitive information of faculty, staff, patients, students, and others affiliated with USHE institutions,

More information

8. Does this system collect, display, store, maintain or disseminate Personally Identifiable Information (PII)? Yes

8. Does this system collect, display, store, maintain or disseminate Personally Identifiable Information (PII)? Yes NOTE: The following reflects the information entered in the PIAMS Website. A. SYSTEM DESCRIPTION Authority: Office of Management Budget (OMB) Memorandum (M) 03-22, OMB Guidance for Implementing the Privacy

More information

Privacy Policy Last Modified: April 3, 2015 1

Privacy Policy Last Modified: April 3, 2015 1 Privacy Policy Last Modified: April 3, 2015 1 Introduction Jamberry Nails, LLC, a Utah limited liability company, U.S.A., (referred to herein as Jamberry, we, us and our ) understands the importance of

More information

Niagara County Community College

Niagara County Community College Niagara County Community College NCCCnet Computer Usage Policy Document: NCCCnet Computer Usage Policy Owner: Chief Information Officer Version: 2.0 NCCCnet Policy Page 1 of 7 NCCCnet Use Policy Introduction:

More information

PRIVACY IMPACT ASSESSMENT

PRIVACY IMPACT ASSESSMENT Name of System/Application: LAN/WAN PRIVACY IMPACT ASSESSMENT U. S. Small Business Administration LAN/WAN FY 2011 Program Office: Office of the Chief Information Officer A. CONTACT INFORMATION 1) Who is

More information

VES Privacy Policy Effective Date: June 25, 2015

VES Privacy Policy Effective Date: June 25, 2015 VES Privacy Policy Effective Date: June 25, 2015 1. Privacy Statement 2. Information Collected by VES (i) Information that you Knowingly and Willingly Provide (ii) Student Information from Partner Schools.

More information

10231B: Designing a Microsoft SharePoint 2010 Infrastructure

10231B: Designing a Microsoft SharePoint 2010 Infrastructure 10231B: Designing a Microsoft SharePoint 2010 Infrastructure Course Number: 10231B Course Length: 5 Days Course Overview This 5 day course teaches IT Professionals to design and deploy Microsoft SharePoint

More information

Stakeholder Engagement Initiative: Customer Relationship Management

Stakeholder Engagement Initiative: Customer Relationship Management for the Stakeholder Engagement Initiative: December 10, 2009 Contact Point Christine Campigotto Private Sector Office Policy 202-612-1623 Reviewing Official Mary Ellen Callahan Chief Privacy Officer Department

More information

Federal Trade Commission Privacy Impact Assessment. for the: Analytics Consulting LLC Claims Management System and Online Claim Submission Website

Federal Trade Commission Privacy Impact Assessment. for the: Analytics Consulting LLC Claims Management System and Online Claim Submission Website Federal Trade Commission Privacy Impact Assessment for the: Analytics Consulting LLC Claims Management System and Online Claim Submission Website January 2015 Page 1 of 14 1 System Overview The Federal

More information

SHAREPOINT 2016 POWER USER BETA. Duration: 4 days

SHAREPOINT 2016 POWER USER BETA. Duration: 4 days SHAREPOINT 2016 POWER USER BETA Duration: 4 days Overview This course delivers the complete site owner story from start to finish in an engaging and practical way to ensure you have the confidence to plan

More information

A. SYSTEM DESCRIPTION

A. SYSTEM DESCRIPTION NOTE: The following reflects the information entered in the PIAMS website. A. SYSTEM DESCRIPTION Authority: Office of Management Budget (OMB) Memorandum (M) 03-22, OMB Guidance for Implementing the Privacy

More information

8. Does this system collect, display, store, maintain or disseminate Personally Identifiable Information (PII)? Yes

8. Does this system collect, display, store, maintain or disseminate Personally Identifiable Information (PII)? Yes NOTE: The following reflects the information entered in the PIAMS Website. A. SYSTEM DESCRIPTION Authority: Office of Management Budget (OMB) Memorandum (M) 03-22, OMB Guidance for Implementing the Privacy

More information

Privacy Impact Assessment

Privacy Impact Assessment M AY 2, 2013 Privacy Impact Assessment CFPB BUSINESS INTELLIGENCE TOOL Contact Point: Claire Stapleton Chief Privacy Officer 1700 G Street, NW Washington, DC 20552 202-435-7220 claire.stapleton@cfpb.gov

More information

Course: 10174B: Configuring and Administering Microsoft SharePoint 2010

Course: 10174B: Configuring and Administering Microsoft SharePoint 2010 Course: 10174B: Configuring and Administering Microsoft SharePoint 2010 Description: This five-day instructor-led course teaches students how to install, configure, and administer Microsoft SharePoint

More information

WHITE PAPER Practical Information Governance: Balancing Cost, Risk, and Productivity

WHITE PAPER Practical Information Governance: Balancing Cost, Risk, and Productivity WHITE PAPER Practical Information Governance: Balancing Cost, Risk, and Productivity Sponsored by: EMC Corporation Laura DuBois August 2010 Vivian Tero EXECUTIVE SUMMARY Global Headquarters: 5 Speen Street

More information

FHFA. Privacy Impact Assessment Template FM: SYSTEMS (SYSTEM NAME)

FHFA. Privacy Impact Assessment Template FM: SYSTEMS (SYSTEM NAME) FHFA Privacy Impact Assessment Template FM: SYSTEMS (SYSTEM NAME) This template is used when the Chief Privacy Officer determines that the system contains Personally Identifiable Information and a more

More information

Federal Trade Commission Privacy Impact Assessment. for the: Gilardi & Co., LLC Claims Management System and Online Claim Submission Website

Federal Trade Commission Privacy Impact Assessment. for the: Gilardi & Co., LLC Claims Management System and Online Claim Submission Website Federal Trade Commission Privacy Impact Assessment for the: Gilardi & Co., LLC Claims Management System and Online Claim Submission Website January 2015 Page 1 of 14 1 System Overview The Federal Trade

More information

A. SYSTEM DESCRIPTION

A. SYSTEM DESCRIPTION NOTE: The following reflects the information entered in the PIAMS website. A. SYSTEM DESCRIPTION Authority: Office of Management Budget (OMB) Memorandum (M) 03-22, OMB Guidance for Implementing the Privacy

More information

A. SYSTEM DESCRIPTION

A. SYSTEM DESCRIPTION NOTE: The following reflects the information entered in the PIAMS website. A. SYSTEM DESCRIPTION Authority: Office of Management Budget (OMB) Memorandum (M) 03-22, OMB Guidance for Implementing the Privacy

More information

Department of Information Technology Active Directory Audit Final Report. August 2008. promoting efficient & effective local government

Department of Information Technology Active Directory Audit Final Report. August 2008. promoting efficient & effective local government Department of Information Technology Active Directory Audit Final Report August 2008 promoting efficient & effective local government Executive Summary Active Directory (AD) is a directory service by Microsoft

More information

Personal Information Collection and the Privacy Impact Assessment (PIA)

Personal Information Collection and the Privacy Impact Assessment (PIA) SEPTEMBER 27, 2012 Privacy Impact Assessment NATIONWIDE MORTGAGE LICENSING SYSTEM AND REGISTRY Contact Point: Claire Stapleton Chief Privacy Officer 1700 G Street, NW Washington, DC 20552 202-435-7220

More information

SAFELY ENABLING MICROSOFT OFFICE 365: THREE MUST-DO BEST PRACTICES

SAFELY ENABLING MICROSOFT OFFICE 365: THREE MUST-DO BEST PRACTICES SAFELY ENABLING MICROSOFT OFFICE 365: THREE MUST-DO BEST PRACTICES Netskope 2015 Enterprises are rapidly adopting Microsoft Office 365. According to the Netskope Cloud Report, the suite is among the top

More information

ELECTRONIC INFORMATION SECURITY A.R.

ELECTRONIC INFORMATION SECURITY A.R. A.R. Number: 2.6 Effective Date: 2/1/2009 Page: 1 of 7 I. PURPOSE In recognition of the critical role that electronic information systems play in City of Richmond (COR) business activities, this policy

More information

DHS SharePoint and Collaboration Sites

DHS SharePoint and Collaboration Sites for the March 22, 2011 Robert Morningstar Information Systems Security Manager DHS Office of the Chief Information Officer/Enterprise Service Delivery Office (202) 447-0467 Reviewing Official Mary Ellen

More information

W H I T E P A P E R E X E C U T I V E S U M M AR Y S I T U AT I O N O V E R V I E W. Sponsored by: EMC Corporation. Laura DuBois May 2010

W H I T E P A P E R E X E C U T I V E S U M M AR Y S I T U AT I O N O V E R V I E W. Sponsored by: EMC Corporation. Laura DuBois May 2010 W H I T E P A P E R E n a b l i n g S h a r e P o i n t O p e r a t i o n a l E f f i c i e n c y a n d I n f o r m a t i o n G o v e r n a n c e w i t h E M C S o u r c e O n e Sponsored by: EMC Corporation

More information

Justice Management Division

Justice Management Division Justice Management Division Privacy Impact Assessment for the Justice Communication System (JCS) Issued by: Arthur E. Gary General Counsel and Senior Component Official for Privacy Approved by: Erika Brown

More information

Department of Information Technology Remote Access Audit Final Report. January 2010. promoting efficient & effective local government

Department of Information Technology Remote Access Audit Final Report. January 2010. promoting efficient & effective local government Department of Information Technology Remote Access Audit Final Report January 2010 promoting efficient & effective local government Background Remote access is a service provided by the county to the Fairfax

More information

Microsoft Office SharePoint Server (MOSS) 2007 Overview

Microsoft Office SharePoint Server (MOSS) 2007 Overview Microsoft Office SharePoint Server (MOSS) 2007 Overview for Technology Manager Wei Wang MOSS Technical Expert Consultant shangmeizhai@hotmail.commsiw 17.04.2010 - Seite 1 Agenda Collaboration Portal Search

More information

HiSoftware Policy Sheriff. SP HiSoftware Security Sheriff SP. Content-aware. Compliance and Security Solutions for. Microsoft SharePoint

HiSoftware Policy Sheriff. SP HiSoftware Security Sheriff SP. Content-aware. Compliance and Security Solutions for. Microsoft SharePoint HiSoftware Policy Sheriff SP HiSoftware Security Sheriff SP Content-aware Compliance and Security Solutions for Microsoft SharePoint SharePoint and the ECM Challenge The numbers tell the story. According

More information

Corporate Leadership Council Metrics

Corporate Leadership Council Metrics for the Corporate Leadership Council Metrics Contact Point Chris Cejka Director, Strategic Planning and Evaluation Division Human Capital Innovation Office of the Chief Human Capital Officer Department

More information

Implementing SharePoint 2010 as a Compliant Information Management Platform

Implementing SharePoint 2010 as a Compliant Information Management Platform Implementing SharePoint 2010 as a Compliant Information Management Platform Changing the Paradigm with a Business Oriented Approach to Records Management Introduction This document sets out the results

More information

HIPAA: The Role of PatientTrak in Supporting Compliance

HIPAA: The Role of PatientTrak in Supporting Compliance HIPAA: The Role of PatientTrak in Supporting Compliance The purpose of this document is to describe the methods by which PatientTrak addresses the requirements of the HIPAA Security Rule, as pertaining

More information

HIPAA: MANAGING ACCESS TO SYSTEMS STORING ephi WITH SECRET SERVER

HIPAA: MANAGING ACCESS TO SYSTEMS STORING ephi WITH SECRET SERVER HIPAA: MANAGING ACCESS TO SYSTEMS STORING ephi WITH SECRET SERVER With technology everywhere we look, the technical safeguards required by HIPAA are extremely important in ensuring that our information

More information

SharePoint 2013 for End Users

SharePoint 2013 for End Users Page 1 of 8 Overview Who should attend? This SharePoint 2013 End User class is for end users working in a SharePoint 2013 environment. The course teaches SharePoint basics such as working with lists and

More information