03/21/2013. Security Incident Requirements. Information Security Webinar. Administrative Announcements. Security Incident Requirements
|
|
|
- Baldwin Henry
- 9 years ago
- Views:
Transcription
1 Security Incident Requirements Information Security Webinar Security Incident Requirements Host: Lisa Rainey, SAPPC Information Security Curriculum Manager, DSS - CDSE Distinguished career-security professional Security Asset Protection Professional Certification (SAPPC) Retired US Army Security Manager/Antiterrorism Officer Physical Security Program management Personnel Security Program management Mobilization/Readiness management 03/21/2013 OPSEC Officer Contracting Officers Representative Administrative Announcements Use the Q & A box to ask questions. These slides can be downloaded. Select the file in the File Share box below. Enclosure 6 of Volume 3 DoD Manual is also provided in the File Share box. This webinar will present poll questions. 1
2 Poll 1 DoDM , Vol 3, Encl. 6 Personnel have a responsibility to: Promptly report security incidents Ensure incidents are properly investigated Minimize adverse effects of unauthorized disclosure Preclude recurrence through education Common Sense Approach If no adverse effect on national security, resolve at lowest appropriate level. Any incident involving classified information must involve an inquiry and/or investigation. 2
3 Compromise vs. Loss COMPROMISE Security Incident (Violation) Unauthorized Disclosure LOSS Missing Classified Information/Equipment Chat Question When would a security incident require an investigation? Enter your responses in the chat box. Security Violation Unauthorized Disclosure Misclassification Continue or discontinue a SAP Anything else outside of Manual requirements Requires an inquiry, investigation, or both Actual or Potential loss or compromise of classified information Administrative in Nature Negligent Willful Knowing 3
4 Security Infraction Failure to comply with DoDM or other policy Does not result in loss, suspected compromise, or compromise May be unintentional or inadvertent Does not require an in-depth investigation If the incident does not fit under the violation categories below, it is an infraction. Administrative in Nature Negligent Willful Knowing Inquiry Identifies the facts Determines infraction or violation Identifies possible causes and person(s) responsible Reports corrective actions Makes recommendations for further action or investigation Investigation Conduct an investigation if the inquiry does not resolve all issues. 4
5 Security Tips Dangerous practices: Recycling box next to copier Burn bags next to unclassified trash containers Personal business during hand-carrying Failing to change security container combinations Poll 2 Consequences of Compromise After a compromise occurs: Regain custody of compromised material Identify source and reason Take remedial action 5
6 Reporting and Notifications Must be safeguarded Notify, using secure communications If necessary, report to authorities at next higher level. Reporting Notify Director of Security, OUSD(I) of: Espionage UD to public media Establishment or continuance of a SAP Compromise likely to cause significant damage Con t Reporting, con t Also report violations involving: Knowing, willful, or negligent unauthorized disclosure Potential for attracting significant attention Large amounts of information Potential weakness in classification policies 6
7 Classification of Reports At minimum, designate reports FOUO Classify commensurate with level of compromised material If disseminated outside of DoD, use an expanded marking Inquiries and Investigations Suspicion of Criminal Activity If criminal activity is suspected: Inquiry and investigation ceases Begin coordination with cognizant DCIO or Defense CI component Continue inquiry or investigation if jurisdiction is declined 7
8 Coordination with OCA If it is determined that a compromise occurred: The originator (OCA) is notified. If the OCA no longer exists, or the inheriting activities cannot be determined, the DoD Component of the OCA shall be notified. The notification should not be delayed pending further investigation or resolution. Security Inquiries Inquiry actions: Complete an inquiry in fewer than 10 duty days Report findings to activity head, activity security manager, and others as appropriate Request extension, if needed Security Inquiries, con t Inquiry Report: Punitive action not recommended Prevention actions documented Discipline is the responsibility of appropriate military commander or management official. 8
9 Security Investigations Conduct an investigation if the inquiry does not resolve all of the issues. The Investigator Is a disinterested person Has appropriate clearance and access Has the ability to conduct an effective investigation Information Appearing in the Public Media DoD personnel must not: Confirm or verify information Discuss with anyone who does not have appropriate clearance Neither confirm nor deny Workforce may need to be reminded of actions to be taken or not taken in response to the disclosure. Results of Inquiries and Investigations Compromise Occurred Responsible security official issues revised guidance as necessary. If there are defects in the procedures and requirements of the Manual, report to Director of Security, OUSD(I). Compromise did not Occur Responsible security official takes action as appropriate to resolve incident and/or failures to comply with procedures. Notification to OCAs will not be delayed pending completion of additional investigations. 9
10 Poll 3 Compromises involving more than one Agency Affected activities are responsible for coordinating their efforts in assessing damage. Debriefing in Cases of Unauthorized Access The activity head shall determine if a debriefing is warranted. A nondisclosure agreement (SF 312) may be executed. 10
11 Reporting and Oversight Mechanisms Timely and efficient reporting and oversight Eliminate the probability of further incidents Simple disciplinary action is not an acceptable response to a security incident. Contacts and Resources Slides and frequently asked questions from this webinar will be posted at information security training related questions to DSS at [email protected] 11
Defense Security Service (DSS)
Defense Security Service (DSS) Center for Development of Security Excellence (CDSE) ADMINISTRATIVE INQUIRY (AI) PROCESS JOB AID July 2011 TABLE OF CONTENTS 1. INTRODUCTION... 1 1.1 Scope... 1 2. PRELIMINARY
There are many examples of sensitive information falling into the wrong hands. What s the worst that can happen? The worst has already happened.
Data Spills Short Introduction There are many examples of sensitive information falling into the wrong hands. What s the worst that can happen? The worst has already happened. When data spills occur, they
Introduction. Derivative Classification Training JOB AID
Introduction Derivative Classification Training The purpose of this job aid is to provide reference information for the responsibilities and procedures associated with derivative classification. This job
Department of Commerce Office of Security. Initial Information Security Briefing
Department of Commerce Office of Security Initial Information Security Briefing Security Clearance A security clearance is a determination of trust, which makes you eligible for access to classified information.
Outside Director and Proxy Holder Training: Module 1: Intro to DSS and Foreign Ownership, Control, or Influence (FOCI) Defense Security Service
Outside Director and Proxy Holder Training: Module 1: Intro to DSS and Foreign Ownership, Control, or Influence (FOCI) Defense Security Service February 2014 Training Objectives DSS Agency DSS Mission
DSS Monthly Newsletter
(Sent on behalf of ISR) Dear FSO, DSS Monthly Newsletter December 2012 This is the monthly email containing recent information, policy guidance, security education and training updates. If you have any
Annual DoD Security Refresher Training
Annual DoD Security Refresher Training Welcome to your annual security refresher training. The purpose of this briefing is to remind you of your personal responsibilities and liabilities under United States
Department of Defense INSTRUCTION
Department of Defense INSTRUCTION NUMBER 5200.39 May 28, 2015 USD(I)/USD(AT&L) SUBJECT: Critical Program Information (CPI) Identification and Protection Within Research, Development, Test, and Evaluation
Standard No. 576-056-0000 MOTOR VEHICLE HISTORY CHECK. Purpose and Applicability
Standard No. 576-056-0000 MOTOR VEHICLE HISTORY CHECK Purpose and Applicability (1) Oregon State University is committed to protecting the security, safety, and health of faculty, staff, students and others,
DISTRIBUTION: ASSISTANT G-1 FOR CIVILIAN PERSONNEL POLICY, DEPARTMENT OF THE ARMY DIRECTOR, PLANS, PROGRAMS, AND DIVERSITY, DEPARTMENT OF THE NAVY
DISTRIBUTION: ASSISTANT G-1 FOR CIVILIAN PERSONNEL POLICY, DEPARTMENT OF THE ARMY DIRECTOR, PLANS, PROGRAMS, AND DIVERSITY, DEPARTMENT OF THE NAVY DEPUTY DIRECTOR, PERSONNEL FORCE MANAGEMENT, DEPARTMENT
Commanding Officer and Executive Officer. Information and Personnel Security Reference Handbook
Commanding Officer and Executive Officer Information and Personnel Security Reference Handbook Assistant for Information and Personnel Security (N09N2) Office of the Chief of Naval Operations Governing
Department of Defense MANUAL. DoD Information Security Program: Overview, Classification, and Declassification
Department of Defense MANUAL NUMBER 5200.01, Volume 1 February 24, 2012 USD(I) SUBJECT: DoD Information Security Program: Overview, Classification, and Declassification References: See Enclosure 1 1. PURPOSE
2015 Cybersecurity Awareness
2015 Cybersecurity Awareness CDSE Cybersecurity Thomas N. LeBaron, CISSP Cybersecurity Curriculum Manager Mr. LeBaron has been the Cybersecurity Curriculum Manager for CDSE since October 2012 Mr. LeBaron
Department of Defense DIRECTIVE
Department of Defense DIRECTIVE NUMBER 5240.06 May 17, 2011 Incorporating Change 1, May 30, 2013 USD(I) SUBJECT: Counterintelligence Awareness and Reporting (CIAR) References: See Enclosure 1 1. PURPOSE.
Department of Defense DIRECTIVE
Department of Defense DIRECTIVE NUMBER 2311.01E May 9, 2006 Incorporating Change 1, November 15, 2010 Certified Current as of February 22, 2011 GC, DoD SUBJECT: DoD Law of War Program References: (a) DoD
TRAINING PRODUCTS & RESOURCES
c e C e n r t e f o r D e v e l o p m e n t o f S C e n t e r i t y e c u r f o r E x D c e e v e l o p m e n l l e n t o f S e c u r i t y E x c e l l e n c e TRAINING PRODUCTS & RESOURCES Industrial
NOTICE OF THE NATHAN ADELSON HOSPICE PRIVACY PRACTICES
THIS NOTICE DESCRIBES HOW MEDICAL INFORMATION ABOUT YOU MAY BE USED AND DISCLOSED AND HOW YOU CAN GET ACCESS TO THIS INFORMATION PLEASE REVIEW IT CAREFULLY. DEFINITIONS PROTECTED HEALTH INFORMATION (PHI):
Privacy and Data Security Update for Defense Contractors
Privacy and Data Security Update for Defense Contractors T.J. Crane May 19, 2017 Overview DoD interim rule Expanded DFAR reporting obligations New DFAR definitions Cloud services Changes to local breach
Army Regulation 380 5. Security. Department of the Army. Information Security Program. Headquarters. Washington, DC 29 September 2000 UNCLASSIFIED
Army Regulation 380 5 Security Department of the Army Information Security Program Headquarters Department of the Army Washington, DC 29 September 2000 UNCLASSIFIED SUMMARY of CHANGE AR 380 5 Department
Department of Defense MANUAL
Department of Defense MANUAL NUMBER 5220.22, Volume 3 April 17, 2014 USD(I) SUBJECT: National Industrial Security Program: Procedures for Government Activities Relating to Foreign Ownership, Control, or
Security and Emergency Services Community of Interest 0080-Information/Personnel Security Administration Career Road Map
Security and Emergency Services Community of Interest 0080-Information/Personnel Security Administration Career Road Map Prepared by: Booz Allen Hamilton Career progression within the 0080-Information/Personnel
Standard: Information Security Incident Management
Standard: Information Security Incident Management Page 1 Executive Summary California State University Information Security Policy 8075.00 states security incidents involving loss, damage or misuse of
Who Should Know This Policy 2 Definitions 2 Contacts 3 Procedures 3 Forms 5 Related Documents 5 Revision History 5 FAQs 5
Information Security Policy Type: Administrative Responsible Office: Office of Technology Services Initial Policy Approved: 09/30/2009 Current Revision Approved: 08/10/2015 Policy Statement and Purpose
Unauthorized Use of the GPC Page 1 of 29 Welcome to Unauthorized Use of the GPC
Unauthorized Use of the GPC Page 1 of 29 Welcome to Unauthorized Use of the GPC In this topic you will be introduced to the many possible misuses of the Government Purchase Card (GPC), including the definition
CONSOLIDATED RECORDS MANAGEMENT SYSTEM (CRMS) USER AGREEMENT
CONSOLIDATED RECORDS MANAGEMENT SYSTEM (CRMS) USER AGREEMENT I. PURPOSE STATEMENT The TENNESSEE FUSION CENTER (TFC) is an initiative of the Tennessee Bureau of Investigation (TBI) and the Department of
R345, Information Technology Resource Security 1
R345, Information Technology Resource Security 1 R345-1. Purpose: To provide policy to secure the private sensitive information of faculty, staff, patients, students, and others affiliated with USHE institutions,
Department of Defense MANUAL
Department of Defense MANUAL NUMBER 5205.07, Volume 2 November 24, 2015 USD(I) SUBJECT: Special Access Program (SAP) Security Manual: Personnel Security References: See Enclosure 1 1. PURPOSE a. Manual.
BEFORE THE BOARD OF COUNTY COMMISSIONERS FOR MULTNOMAH COUNTY, OREGON RESOLUTION NO. 05-050
BEFORE THE BOARD OF COUNTY COMMISSIONERS FOR MULTNOMAH COUNTY, OREGON RESOLUTION NO. 05-050 Adopting Multnomah County HIPAA Security Policies and Directing the Appointment of Information System Security
JOB AID. Derivative Classification Training U N I T E D A M E R I C A S TAT E S O F. Center for Development of Security Excellence (CDSE) www.cdse.
Center for Development of Security Excellence Learn. Perform. Protect. www.cdse.edu DEFENSE SECURITY SERVICE U N I T E D S TAT E S O F A M E R I C A Center for Development of Security Excellence (CDSE)
Office of Security Management (213) 974-7926
PREPARED BY OCCUPATIONAL HEALTH PROGRAMS CHIEF EXECUTIVE OFFICE RISK MANAGEMENT BRANCH October 2007 Section Page STATEMENT OF PURPOSE...3 Psychiatric Emergencies AUTHORITY & CIVIL SERVICE RULES... 4 Application
COMPLIANCE WITH THIS PUBLICATION IS MANDATORY
BY ORDER OF THE SECRETARY OF THE AIR FORCE AIR FORCE INSTRUCTION 16-1404 29 MAY 2015 Operations Support AIR FORCE INFORMATION SECURITY PROGRAM COMPLIANCE WITH THIS PUBLICATION IS MANDATORY ACCESSIBILITY:
COMMUNITY RELATIONS 4411 Page 1 of 5
1 1 1 1 1 1 1 1 0 1 0 1 0 1 Livingston School District COMMUNITY RELATIONS Page 1 of Interrogation and Investigations Conducted by School Officials The administration has the authority and duty to conduct
United States Department of Agriculture Office of Inspector General
United States Department of Agriculture Office of Inspector General U.S. Department of Agriculture s Office of Homeland Security and Emergency Coordination - Classification Management Audit Report 61701-0001-32
Outside Director and Proxy Holder Training: Module 2: Managing Foreign Ownership, Control, or Influence (FOCI) Mitigation Defense Security Service
Outside Director and Proxy Holder Training: Module 2: Managing Foreign Ownership, Control, or Influence (FOCI) Mitigation Defense Security Service February 2014 Training Objectives FOCI Control Procedures
COUNTERINTELLIGENCE VULNERABILITY ASSESSMENT FOR CORPORATE AMERICA
COUNTERINTELLIGENCE VULNERABILITY ASSESSMENT FOR CORPORATE AMERICA 09/1 8/2009 version UNCLASSIFIED//FOR OFFICIAL USE ONLY Cl VULNERABILITY ASSESSMENT FOR CORPORATE AMERICA DEFINING COUNTERINTELLIGENCE
National Home Health Care HIPAA Notice of Privacy Practices
Effective Date: THIS NOTICE DESCRIBES HOW MEDICAL INFORMATION ABOUT YOU MAY BE USED AND DISCLOSED AND HOW YOU CAN GET ACCESS TO THIS INFORMATION. PLEASE REVIEW IT CAREFULLY. If you have any questions about
Department of Homeland Security DHS Directives System Directive Number: 140-04 Revision Number: 00 Issue Date: SPECIAL ACCESS PROGRAM MANAGEMENT
I. Purpose Department of Homeland Security DHS Directives System Directive Number: 140-04 Revision Number: 00 Issue Date: 08/12/2009 SPECIAL ACCESS PROGRAM MANAGEMENT This Directive establishes the Department
Privacy Notice Document (HIPAA)
Privacy Notice Document (HIPAA) THIS NOTICE DESCRIBES HOW MEDICAL INFORMATION ABOUT YOU MAY BE USED AND DISCLOSED AND HOW YOU CAN GET ACCESS TO THIS INFORMATION. PLEASE REVIEW IT CAREFULLY. This Privacy
ALMS TERMS OF USE / TERMS OF SERVICE Last Updated: 19 July 2013
ALMS TERMS OF USE / TERMS OF SERVICE Last Updated: 19 July 2013 Welcome to the Army Learning Management Service (ALMS), which is provided by the United States Army. These Terms of Use / Terms of Service
Security-in-Depth 4/26/2013. Physical Security Webinar. DCO Meeting Room Navigation. Host: Danny Jennings
Security-in-Depth Physical Security Webinar Host: Danny Jennings Physical Security Curriculum Manager responsible for: Curriculum development Course instruction Curriculum review Retired military; over
COMPLIANCE ALERT 10-12
HAWAII HEALTH SYSTEMS C O R P O R A T I O N "Touching Lives Every Day COMPLIANCE ALERT 10-12 HIPAA Expansion under the American Recovery and Reinvestment Act of 2009 The American Recovery and Reinvestment
Public Law 113 283 113th Congress An Act
PUBLIC LAW 113 283 DEC. 18, 2014 128 STAT. 3073 Public Law 113 283 113th Congress An Act To amend chapter 35 of title 44, United States Code, to provide for reform to Federal information security. Be it
HIPAA PRIVACY AND SECURITY TRAINING P I E D M O N T COMMUNITY H EA LT H P L A N
HIPAA PRIVACY AND SECURITY TRAINING P I E D M O N T COMMUNITY H EA LT H P L A N 1 COURSE OVERVIEW This course is broken down into 4 modules: Module 1: HIPAA Omnibus Rule - What you need to know to remain
This directive establishes the Department of Homeland Security (DHS) Security Education, Training, and Awareness (SETA) Program.
Department of Homeland Security Management Directive System MD Number: 11053 Issue Date: 10/12/2004 SECURITY EDUCATION, TRAINING, AND AWARENESS PROGRAM DIRECTIVE 1. Purpose This directive establishes the
What Personally Identifiable Information does EducationDynamics collect?
EducationDynamics, LLC GradSchools.com Privacy Policy Thank you for visiting GradSchools.com (hereinafter referred to as the Site ), which is owned and/or operated, in whole or in part, by EducationDynamics,
Department of Defense DIRECTIVE. SUBJECT: United States Security Authority for North Atlantic Treaty Organization Affairs (USSAN)
Department of Defense DIRECTIVE NUMBER 5100.55 February 27, 2006 USD(P) SUBJECT: United States Security Authority for North Atlantic Treaty Organization Affairs (USSAN) References: (a) DoD Directive 5100.55,
This directive applies to all DHS organizational elements with access to information designated Sensitive Compartmented Information.
Department of Homeland Security Management Directives System MD Number: 11043 Issue Date: 09/17/2004 SENSITIVE COMPARTMENTED INFORMATION PROGRAM MANAGEMENT I. Purpose This directive establishes Department
Notification and Federal Employee Antidiscrimination and Retaliation (No FEAR) Act Training
INSTALLATION MANAGEMENT COMMAND Updated Dec 09 Notification and Federal Employee Antidiscrimination and Retaliation (No FEAR) Act Training Our Mission: Our mission is to provide the Army the installation
Department of Defense INSTRUCTION
Department of Defense INSTRUCTION NUMBER 8910.01 May 19, 2014 DoD CIO SUBJECT: Information Collection and Reporting References: See Enclosure 1 1. PURPOSE. This instruction: a. Reissues DoD Instruction
Suggested Contractor File Folder Headings
Suggested Contractor File Folder Headings 1. Facility Clearance 2. Personnel Clearances 3. Recurring Security Education 4. Self-Inspection 5. Security Correspondence 6. Standard Practice Procedures 7.
Department of Defense DIRECTIVE
Department of Defense DIRECTIVE NUMBER 5505.13E March 1, 2010 ASD(NII)/DoD CIO SUBJECT: DoD Executive Agent (EA) for the DoD Cyber Crime Center (DC3) References: See Enclosure 1 1. PURPOSE. This Directive:
USES AND DISCLOSURES OF HEALTH INFORMATION
HIPAA Privacy Policy NOTICE OF PRIVACY PRACTICES This notice describes how health information about you may be used and disclosed. Please review carefully. The privacy of your health information is important
ADMINISTRATIVE POLICY # 32 8 2 (2014) Information Security Roles and Responsibilities
Policy Title: Information Security Roles Policy Type: Administrative Policy Number: ADMINISTRATIVE POLICY # 32 8 2 (2014) Information Security Roles Approval Date: 05/28/2014 Revised Responsible Office:
Home Trust & Savings Bank www.hometrustbank.com
Home Trust & Savings Bank www.hometrustbank.com Terms & Conditions Please read the following Electronic Banking Agreement before you sign the enrollment form. GENERAL TERMS This agreement (the Agreement
Issue 1.0. UoG/ILS/IS 001. Information Security and Assurance Policy. Information Security and Compliance Manager
Document Reference Number Date Title Author Owning Department Version Approval Date Review Date Approving Body UoG/ILS/IS 001 January 2016 Information Security and Assurance Policy Information Security
DUUS Information Technology (IT) Incident Management Standard
DUUS Information Technology (IT) Incident Management Standard Issue Date: October 1, 2013 Effective Date: October 1,2013 Revised Date: Number: DHHS-2013-001-E 1.0 Purpose and Objectives Computer systems
( U ) T H I S P A G E I N T E N T I O N A L LY L E F T B L A N K DODIG-2013-142 ii
( U ) T H I S PA G E I N T E N T I O N A L LY L E F T B L A N K DODIG-2013-142 ii Results in Brief DoD Evaluation of Over-Classification of National Security Information September 30, 2013 We also concluded
COMPUTER USE POLICY. 1.0 Purpose and Summary
COMPUTER USE POLICY 1.0 Purpose and Summary 1. This document provides guidelines for appropriate use of the wide variety of computing and network resources at Methodist University. It is not an all-inclusive
SECURITY CLEARANCE DENIED: THE MOST COMMON PITFALLS FOR SECURITY CLEARANCE APPLICATIONS
SECURITY CLEARANCE DENIED: THE MOST COMMON PITFALLS FOR SECURITY CLEARANCE APPLICATIONS By: Ziran Zhang "There is a strong presumption against granting a security clearance." Dorfmont v. Brown, 913 F.2d
ACCG Identity Theft Prevention Program. ACCG 50 Hurt Plaza, Suite 1000 Atlanta, Georgia 30303 (404)522-5022 (404)525-2477 www.accg.
ACCG Identity Theft Prevention Program ACCG 50 Hurt Plaza, Suite 1000 Atlanta, Georgia 30303 (404)522-5022 (404)525-2477 www.accg.org July 2009 Contents Summary of ACCG Identity Theft Prevention Program...
Information Security: Roles, Responsibilities, and Data Classification. Technology Services 1/4/2013
Information Security: Roles, Responsibilities, and Data Classification Technology Services 1/4/2013 Roles, Responsibilities, and Data Classification The purpose of this session is to: Establish that all
STANDARD ADMINISTRATIVE PROCEDURE
STANDARD ADMINISTRATIVE PROCEDURE 16.99.99.M0.26 Investigation and Response to Breach of Unsecured Protected Health Information (HITECH) Approved October 27, 2014 Next scheduled review: October 27, 2019
DoD Whistleblower Protection
DoD Whistleblower Protection Appropriated Fund Civilians What You Need to Know Department of Defense Inspector General Patrick Gookin DoD Whistleblower Protection Ombudsman [email protected]
ADMINISTRATIVE REGULATION EFFECTIVE DATE: 1/1/2016
Page 1 of 9 CITY OF CHESAPEAKE, VIRGINIA NUMBER: 2.62 ADMINISTRATIVE REGULATION EFFECTIVE DATE: 1/1/2016 SUPERCEDES: N/A SUBJECT: HUMAN RESOURCES DEPARTMENT CITY OF CHESAPEAKE EMPLOYEE/RETIREE GROUP HEALTH
1 LAWS of MINNESOTA 2015 Ch 67, s 2. CHAPTER 67--S.F.No. 86 BE IT ENACTED BY THE LEGISLATURE OF THE STATE OF MINNESOTA:
1 LAWS of MINNESOTA 2015 Ch 67, s 2 CHAPTER 67--S.F.No. 86 An act relating to data practices; classifying data related to automated license plate readers and requiring a governing policy; requiring a log
WORKPLACE VIOLENCE POLICY
WORKPLACE VIOLENCE POLICY SUNY Canton is committed to providing a safe work environment for all employees that is free from intimidation, threats, and violent acts. The college will respond promptly to
Consultant Annual DoD Security Refresher
Consultant Annual DoD Security Refresher 1 About This Course This course should be taken by Consultants Only in this PDF format All others should take this course online LMPeople > LMCareers > Learning
Data Security Incident Response Plan. [Insert Organization Name]
Data Security Incident Response Plan Dated: [Month] & [Year] [Insert Organization Name] 1 Introduction Purpose This data security incident response plan provides the framework to respond to a security
HIPAA Data Breaches: Managing Them Internally and in Response to Civil/Criminal Investigations
HIPAA Data Breaches: Managing Them Internally and in Response to Civil/Criminal Investigations Health Care Litigation Webinar Series March 22, 2012 Spence Pryor Paula Stannard Jason Popp 1 HIPAA/HITECH
SUMMARY OF CHANGES This revision aligns the instruction with AFPD 36-1, General Civilian Personnel Provisions and Authorities.
Template modified: 27 May 1997 14:30 BY ORDER OF THE SECRETARY OF THE AIR FORCE AIR FORCE PAMPHLET 36-106 20 DECEMBER 1993 Personnel SUPERVISOR S RECORDS NOTICE: This publication is available digitally
Department of Defense MANUAL
Department of Defense MANUAL NUMBER 5105.21, Volume 3 October 19, 2012 USD(I) SUBJECT: Sensitive Compartmented Information (SCI) Administrative Security Manual: Administration of Personnel Security, Industrial
INSIDER TRADING POLICY AND GUIDELINES
INSIDER TRADING POLICY AND GUIDELINES As a public company, Northern Power Systems Corp. ( Northern Power or the Company ) and its officers, directors and employees are subject to the requirements and restrictions
Tampa Bay Catastrophic Plan ANNEX L: HURRICANE PHOENIX EXERCISE
Tampa Bay Catastrophic Plan ANNEX L: HURRICANE PHOENIX EXERCISE This page intentionally left blank Tampa Bay Catastrophic Plan Hurricane Phoenix A Storm Recovery Tabletop Exercise August 5, 2010 EXERCISE
Using Technology Control Plans in Export Compliance. Mary Beran, Georgia Tech David Brady, Virginia Tech
Using Technology Control Plans in Export Compliance Mary Beran, Georgia Tech David Brady, Virginia Tech What is a Technology Control Plan (TCP)? The purpose of a TCP is to control the access and dissemination
Self-Inspection Handbook for NISP Contractors TABLE OF CONTENTS
Self-Inspection Handbook for NISP Contractors TABLE OF CONTENTS The Contractor Security Review Requirement... 2 The Self-Inspection Handbook for NISP Contractors... 2 The Elements of Inspection... 2 Self-Inspection
ISO IEC 27002 2005 (17799 2005) TRANSLATED INTO PLAIN ENGLISH
13.1 REPORT INFORMATION SECURITY EVENTS AND WEAKNESSES 1 GOAL Make sure that information system security incidents are promptly reported. 2 GOAL Make sure that information system security events and weaknesses
Harris County - Texas HIPAA Notice of Privacy Practices
Harris County - Texas HIPAA Notice of Privacy Practices Effective Date: September 23, 2013. THIS NOTICE DESCRIBES HOW MEDICAL INFORMATION ABOUT YOU MAY BE USED AND DISCLOSED AND HOW YOU CAN GET ACCESS
COURSES AND. Courses & Products LEARN. PERFORM. PROTECT. CENTER FOR DEVELOPMENT OF SECURITY EXCELLENCE REVISED AS OF MARCH 2015 PRODUCTS
DEFENSE SECURITY SERVICE CENTER FOR DEVELOPMENT OF SECURITY EXCELLENCE LEARN. PERFORM. PROTECT. COURSES AND REVISED AS OF MARCH 2015 PRODUCTS Courses & Products Revised as of April 2014 A M E R I C A U
DEALERSHIP IDENTITY THEFT RED FLAGS AND NOTICES OF ADDRESS DISCREPANCY POLICY
DEALERSHIP IDENTITY THEFT RED FLAGS AND NOTICES OF ADDRESS DISCREPANCY POLICY This Plan we adopted by member, partner, etc.) on Our Program Coordinator (date). (Board of Directors, owner, We have appointed
Department of Defense MANUAL. DoD Information Security Program: Protection of Classified Information
Department of Defense MANUAL NUMBER 5200.01, Volume 3 February 24, 2012 Incorporating Change 2, March 19, 2013 USD(I) SUBJECT: DoD Information Security Program: Protection of Classified Information References:
Rowan University Data Governance Policy
Rowan University Data Governance Policy Effective: January 2014 Table of Contents 1. Introduction... 3 2. Regulations, Statutes, and Policies... 4 3. Policy Scope... 4 4. Governance Roles... 6 4.1. Data
AP 417 Information and Communication Services
AP 417 Information and Communication Services Background Access and use of information and communication services (ICS) are an integral component of the learning and working environment. The ability for
PRIVACY NOTICE. In certain situations, we may also disclose patient information to another provider or health plan for their health care operations.
1 PRIVACY NOTICE THIS NOTICE DESCRIBES HOW MEDICAL INFORMATION ABOUT YOU MAY BE USED AND DISCLOSED AND HOW YOU CAN GET ACCESS TO THIS INFORMATION. PLEASE REVIEW IT CAREFULLY. This Privacy Notice is being
HIPAA Notice of Privacy Practices
HIPAA Notice of Privacy Practices Date of Last Revision: 09/20/2013 Effective Date: Immediately THIS NOTICE DESCRIBES HOW MEDICAL INFORMATION ABOUT YOU MAY BE USED AND DISCLOSED AND HOW YOU CAN GET ACCESS
HIPAA NOTICE TO PATIENTS
HIPAA NOTICE TO PATIENTS THIS NOTICE DESCRIBES HOW MEDICAL INFORMATION ABOUT YOU MAY BE USED AND DISCLOSED AND HOW YOU CAN GET ACCESS TO THIS INFORMATION. PLEASE REVIEW IT CAREFULLY. Federal regulations
