Toronto University Personally Identifiable Information Research Paper Please find the attached question and full fill all the question asked. No external r

Toronto University Personally Identifiable Information Research Paper Please find the attached question and full fill all the question asked. No external references required just use the attached journal. Please use clear APA format with Abstract and Conclusion. Special Publication 800-122
Guide to Protecting the
Confidentiality of Personally
Identifiable Information (PII)
Recommendations of the National Institute
of Standards and Technology
Erika McCallister
Tim Grance
Karen Scarfone
NIST Special Publication 800-122

Guide to Protecting the Confidentiality of
Personally Identifiable Information (PII)
Recommendations of the National
Institute of Standards and Technology
Erika McCallister
Tim Grance
Karen Scarfone
C O M P U T E R
S E C U R I T Y
Computer Security Division
Information Technology Laboratory
National Institute of Standards and Technology
Gaithersburg, MD 20899-8930
April 2010
U.S. Department of Commerce
Gary Locke, Secretary
National Institute of Standards and Technology
Dr. Patrick D. Gallagher, Director
Reports on Computer Systems Technology
The Information Technology Laboratory (ITL) at the National Institute of Standards and
Technology (NIST) promotes the U.S. economy and public welfare by providing technical
leadership for the nation‘s measurement and standards infrastructure. ITL develops tests, test
methods, reference data, proof of concept implementations, and technical analysis to advance the
development and productive use of information technology. ITL‘s responsibilities include the
development of technical, physical, administrative, and management standards and guidelines for
the cost-effective security and privacy of sensitive unclassified information in Federal computer
systems. This Special Publication 800-series reports on ITL‘s research, guidance, and outreach
efforts in computer security and its collaborative activities with industry, government, and
academic organizations.
National Institute of Standards and Technology Special Publication 800-122
Natl. Inst. Stand. Technol. Spec. Publ. 800-122, 59 pages (Apr. 2010)
Certain commercial entities, equipment, or materials may be identified in this
document in order to describe an experimental procedure or concept adequately.
Such identification is not intended to imply recommendation or endorsement by the
National Institute of Standards and Technology, nor is it intended to imply that the
entities, materials, or equipment are necessarily the best available for the purpose.
ii
GUIDE TO PROTECTING THE CONFIDENTIALITY OF PERSONALLY IDENTIFIABLE INFORMATION (PII)
Acknowledgments
The authors, Erika McCallister, Tim Grance, and Karen Scarfone of the National Institute of Standards
and Technology (NIST), wish to thank their colleagues who reviewed drafts of this document and
contributed to its technical content. Of particular note are the efforts of Joseph Nusbaum of Innovative
Analytics & Training, Deanna DiCarlantonio of CUNA Mutual Group, and Michael L. Shapiro and
Daniel I. Steinberg of Booz Allen Hamilton, who contributed significant portions to previous versions of
the document. The authors would also like to acknowledge Ron Ross, Kelley Dempsey, and Arnold
Johnson of NIST; Michael Gerdes, Beth Mallory, and Victoria Thompson of Booz Allen Hamilton;
Brendan Van Alsenoy of ICRI, K.U.Leuven; David Plocher and John de Ferrari of the Government
Accountability Office; Toby Levin of the Department of Homeland Security; Idris Adjerid of Carnegie
Mellon University; The Federal Committee on Statistical Methodology: Confidentiality and Data Access
Committee; The Privacy Best Practices Subcommittee of the Chief Information Officers Council; and
Julie McEwen and Aaron Powell of The MITRE Corporation, for their keen and insightful assistance
during the development of the document.
iii
GUIDE TO PROTECTING THE CONFIDENTIALITY OF PERSONALLY IDENTIFIABLE INFORMATION (PII)
Table of Contents
Executive Summary ………………………………………………………………………………………………ES-1
1.
Introduction ……………………………………………………………………………………………………. 1-1
1.1
1.2
1.3
1.4
2.
Introduction to PII ……………………………………………………………………………………………. 2-1
2.1
2.2
2.3
3.
3.3
Impact Level Definitions ……………………………………………………………………………..3-1
Factors for Determining PII Confidentiality Impact Levels …………………………………3-2
3.2.1 Identifiability ………………………………………………………………………………….. 3-3
3.2.2 Quantity of PII ……………………………………………………………………………….. 3-3
3.2.3 Data Field Sensitivity ………………………………………………………………………. 3-3
3.2.4 Context of Use ………………………………………………………………………………. 3-4
3.2.5 Obligation to Protect Confidentiality…………………………………………………… 3-4
3.2.6 Access to and Location of PII …………………………………………………………… 3-5
PII Confidentiality Impact Level Examples ……………………………………………………..3-5
3.3.1 Example 1: Incident Response Roster ……………………………………………… 3-5
3.3.2 Example 2: Intranet Activity Tracking ……………………………………………….. 3-6
3.3.3 Example 3: Fraud, Waste, and Abuse Reporting Application………………… 3-7
PII Confidentiality Safeguards ………………………………………………………………………….. 4-1
4.1
4.2
4.3
5.
Identifying PII ……………………………………………………………………………………………2-1
Examples of PII Data ………………………………………………………………………………….2-2
PII and Fair Information Practices…………………………………………………………………2-3
PII Confidentiality Impact Levels ………………………………………………………………………. 3-1
3.1
3.2
4.
Authority …………………………………………………………………………………………………..1-1
Purpose and Scope ……………………………………………………………………………………1-1
Audience ………………………………………………………………………………………………….1-1
Document Structure …………………………………………………………………………………..1-1
Operational Safeguards………………………………………………………………………………4-1
4.1.1 Policy and Procedure Creation …………………………………………………………. 4-1
4.1.2 Awareness, Training, and Education …………………………………………………. 4-2
Privacy-Specific Safeguards ………………………………………………………………………..4-3
4.2.1 Minimizing the Use, Collection, and Retention of PII ……………………………. 4-3
4.2.2 Conducting Privacy Impact Assessments …………………………………………… 4-4
4.2.3 De-Identifying Information ……………………………………………………………….. 4-4
4.2.4 Anonymizing Information …………………………………………………………………. 4-5
Security Controls ……………………………………………………………………………………….4-6
Incident Response for Breaches Involving PII …………………………………………………… 5-1
5.1
5.2
5.3
5.4
Preparation……………………………………………………………………………………………….5-1
Detection and Analysis ……………………………………………………………………………….5-3
Containment, Eradication, and Recovery……………………………………………………….5-3
Post-Incident Activity ………………………………………………………………………………….5-3
iv
GUIDE TO PROTECTING THE CONFIDENTIALITY OF PERSONALLY IDENTIFIABLE INFORMATION (PII)
Appendices
Appendix A— Scenarios for PII Identification and Handling ……………………………………… A-1
A.1 General Questions …………………………………………………………………………………… A-1
A.2 Scenarios ……………………………………………………………………………………………….. A-1
Appendix B— Frequently Asked Questions (FAQ) ……………………………………………………. B-1
Appendix C— Other Terms and Definitions for Personal Information ………………………… C-1
Appendix D— Fair Information Practices …………………………………………………………………. D-1
Appendix E— Glossary ………………………………………………………………………………………….. E-1
Appendix F— Acronyms and Abbreviations …………………………………………………………….. F-1
Appendix G— Resources ………………………………………………………………………………………..G-1
v
GUIDE TO PROTECTING THE CONFIDENTIALITY OF PERSONALLY IDENTIFIABLE INFORMATION (PII)
Executive Summary
The escalation of security breaches involving personally identifiable information (PII) has contributed to
the loss of millions of records over the past few years.1 Breaches involving PII are hazardous to both
individuals and organizations. Individual harms 2 may include identity theft, embarrassment, or blackmail.
Organizational harms may include a loss of public trust, legal liability, or remediation costs. To
appropriately protect the confidentiality of PII, organizations should use a risk-based approach; as
McGeorge Bundy3 once stated, ―If we guard our toothbrushes and diamonds with equal zeal, we will lose
fewer toothbrushes and more diamonds.‖ This document provides guidelines for a risk-based approach to
protecting the confidentiality4 of PII. The recommendations in this document are intended primarily for
U.S. Federal government agencies and those who conduct business on behalf of the agencies, 5 but other
organizations may find portions of the publication useful. Each organization may be subject to a different
combination of laws, regulations, and other mandates related to protecting PII, so an organization‘s legal
counsel and privacy officer should be consulted to determine the current obligations for PII protection.
For example, the Office of Management and Budget (OMB) has issued several memoranda with
requirements for how Federal agencies must handle and protect PII. To effectively protect PII,
organizations should implement the following recommendations.
Organizations should identify all PII residing in their environment.
An organization cannot properly protect PII it does not know about. This document uses a broad
definition of PII to identify as many potential sources of PII as possible (e.g., databases, shared network
drives, backup tapes, contractor sites). PII is ―any information about an individual maintained by an
agency, including (1) any information that can be used to distinguish or trace an individual‘s identity,
such as name, social security number, date and place of birth, mother‘s maiden name, or biometric
records; and (2) any other information that is linked or linkable to an individual, such as medical,
educational, financial, and employment information.‖ 6 Examples of PII include, but are not limited to:
 Name, such as full name, maiden name, mother‘s maiden name, or alias
 Personal identification number, such as social security number (SSN), passport number, driver‘s
license number, taxpayer identification number, or financial account or credit card number
 Address information, such as street address or email address
 Personal characteristics, including photographic image (especially of face or other identifying
characteristic), fingerprints, handwriting, or other biometric data (e.g., retina scan, voice signature,
facial geometry)
1
2
3
4
5
6
Government Accountability Office (GAO) Report 08-343, Protecting Personally Identifiable Information, January 2008,
http://www.gao.gov/new.items/d08343.pdf
For the purposes of this document, harm means any adverse effects that would be experienced by an individual whose PII
was the subject of a loss of confidentiality, as well as any adverse effects experienced by the organization that maintains the
PII. See Section 3.1 for additional information.
Congressional testimony as quoted by the New York Times, March 5, 1989. McGeorge Bundy was the U.S. National
Security Advisor to Presidents Kennedy and Johnson (1961-1966).

For the purposes of this document, confidentiality is defined as ―preserving authorized restrictions on information access
and disclosure, including means for protecting personal privacy and proprietary information.‖ 44 U.S.C. § 3542.
http://uscode.house.gov/download/pls/44C35.txt.
For the purposes of this publication, both are referred to as ―organizations‖.
This definition is the GAO expression of an amalgam of the definitions of PII from OMB
Memorandums 07-16 and 06-19. GAO Report 08-536, Privacy: Alternatives Exist for Enhancing Protection of Personally
Identifiable Information, May 2008, http://www.gao.gov/new.items/d08536.pdf.
ES-1
GUIDE TO PROTECTING THE CONFIDENTIALITY OF PERSONALLY IDENTIFIABLE INFORMATION (PII)
 Information about an individual that is linked or linkable to one of the above (e.g., date of birth, place
of birth, race, religion, weight, activities, geographical indicators, employment information, medical
information, education information, financial information).
Organizations should minimize the use, collection, and retention of PII to what is strictly necessary
to accomplish their business purpose and mission.
The likelihood of harm caused by a breach involving PII is greatly reduced if an organization minimizes
the amount of PII it uses, collects, and stores. For example, an organization should only request PII in a
new form if the PII is absolutely necessary. Also, an organization should regularly review its holdings of
previously collected PII to determine whether the PII is still relevant and necessary for meeting the
organization‘s business purpose and mission. For example, organizations could have an annual PII
purging awareness day.7
OMB M-07-168 specifically requires agencies to:
 Review current holdings of PII and ensure they are accurate, relevant, timely, and complete
 Reduce PII holdings to the minimum necessary for proper performance of agency functions
 Develop a schedule for periodic review of PII holdings
 Establish a plan to eliminate the unnecessary collection and use of SSNs.
Organizations should categorize their PII by the PII confidentiality impact level.
All PII is not created equal. PII should be evaluated to determine its PII confidentiality impact level,
which is different from the Federal Information Processing Standard (FIPS) Publication 1999
confidentiality impact level, so that appropriate safeguards can be applied to the PII. The PII
confidentiality impact level—low, moderate, or high—indicates the potential harm that could result to the
subject individuals and/or the organization if PII were inappropriately accessed, used, or disclosed. This
document provides a list of factors an organization should consider when determining the PII
confidentiality impact level. Each organization should decide which factors it will use for determining
impact levels and then create and implement the appropriate policy, procedures, and controls. The
following are examples of factors:
 Identifiability. Organizations should evaluate how easily PII can be used to identify specific
individuals. For example, a SSN uniquely and directly identifies an individual, whereas a telephone
area code identifies a set of people.
 Quantity of PII. Organizations should consider how many individuals can be identified from the
PII. Breaches of 25 records and 25 million records may have different impacts. The PII
confidentiality impact level should only be raised and not lowered based on this factor.
 Data Field Sensitivity. Organizations should evaluate the sensitivity of each individual PII data
field. For example, an individual‘s SSN or financial account number is generally more sensitive than
7
8
9
Disposal of PII should be conducted in accordance with the retention schedules approved by the National Archives and
Records Administration (NARA), as well as in accordance with agency litigation holds.
OMB Memorandum 07-16, Safeguarding Against and Responding to the Breach of Personally Identifiable Information,
http://www.whitehouse.gov/omb/memoranda/fy2007/m07-16.pdf.
FIPS 199, Standards for Security Categorization of Federal Information and Information Systems,
http://csrc.nist.gov/publications/fips/fips199/FIPS-PUB-199-final.pdf.
ES-2
GUIDE TO PROTECTING THE CONFIDENTIALITY OF PERSONALLY IDENTIFIABLE INFORMATION (PII)
an individual‘s phone number or ZIP code. Organizations should also evaluate the sensitivity of the
PII data fields when combined.
 Context of Use. Organizations should evaluate the context of use—the purpose for which the PII is
collected, stored, used, processed, disclosed, or disseminated. The context of use may cause the same
PII data elements to be assigned different PII confidentiality impact levels based on their use. For
example, suppose that an organization has two lists that contain the same PII data fields (e.g., name,
address, phone number). The first list is people who subscribe to a general-interest newsletter
produced by the organization, and the second list is people who work undercover in law enforcement.
If the confidentiality of the lists is breached, the potential impacts to the affected individuals and to
the organization are significantly different for each list.
 Obligations to Protect Confidentiality. An organization that is subject to any obligations to protect
PII should consider such obligations when determining the PII confidentiality impact level.
Obligations to protect generally include laws, regulations, or other mandates (e.g., Privacy Act, OMB
guidance). For example, some Federal agencies, such as the Census Bureau and the Internal Revenue
Service (IRS), are subject to specific legal obligations to protect certain types of PII. 10
 Access to and Location of PII. Organizations may choose to take into consideration the nature of
authorized access to and the location of PII. When PII is accessed more often or by more people and
systems, or the PII is regularly transmitted or transported offsite, then there are more opportunities to
compromise the confidentiality of the PII.
Organizations should apply the appropriate safeguards for PII based on the PII confidentiality
impact level.
Not all PII should be protected in the same way. Organizations should apply appropriate safeguards to
protect the confidentiality of PII based on the PII confidentiality impact level. Some PII does not need to
have its confidentiality protected, such as information that the organization has permission or authority to
release publicly (e.g., an organization‘s public phone directory). NIST recommends using operational
safeguards, privacy-specific safeguards, and security controls,11 such as:
 Creating Policies and Procedures. Organizations should develop comprehensive policies and
procedures for protecting the confidentiality of PII.
 Conducting Training. Organizations should reduce the possibility that PII will be accessed, used, or
disclosed inappropriat…
Purchase answer to see full
attachment

Don't use plagiarized sources. Get Your Custom Essay on
Toronto University Personally Identifiable Information Research Paper Please find the attached question and full fill all the question asked. No external r
For $10/Page 0nly
Order Essay
Calculator

Calculate the price of your paper

Total price:$26

Need a better grade?
We've got you covered.

Order your paper