żěèapp¶ĚĘÓ

Sensitive Data

Protecting Sensitive Data

If sensitive data falls into the wrong hands, it can lead to a security breach, fraud, and/or identity theft. By taking steps to secure confidential data, you can protect the University community from these cyber security risks. Keep reading to learn more about sensitive data and how to secure it.

Classifying Sensitive Data

Knowing which types of data are classified as “sensitive” can help you make informed decisions about when and how to store University data. In ITS, we classify sensitive data in the following categories:

Personally Identifiable Information (PII)

Personally identifiable information (PII) is any data that could potentially identify a specific individual. PII can be labeled sensitive or nonsensitive. Nonsensitive PII can be easily gathered from public records, phone books, corporate directories and websites.

Sensitive PII is information that, when disclosed, could result in harm to an individual. This type of sensitive data often has legal, contractual or ethical requirements for restricted disclosure. Examples of sensitive PII include: social security numbers, driver’s license numbers, and passwords.

Payment Card Industry (PCI) Data

The PCI Security Standards Council (SSC) developed the Payment Card Industry Data Security Standard (PCI DSS) in 2004 to combat credit card fraud. PCI data includes cardholder data such as the cardholder’s name, the primary account number, and the card’s expiration date and security code.

PCI data can also include sensitive authentication data, including magnetic-stripe data, the equivalent data contained on a chip, and PINs.

Family Educational Rights & Privacy Act (FERPA) Data

FERPA classifies protected information into three categories: educational information, personally identifiable information, and directory information. Although personally identifiable and directory information are often similar or related, FERPA provides different levels of protection for each. PII can only be disclosed if the educational institution obtains the signature of the parent or student (if over 18 years of age) on a document specifically identifying the information to be disclosed, the reason for the disclosure, and the parties to whom the disclosure will be made.

Protected Health Information (PHI)

Under HIPAA, protected health information is considered to be individually identifiable information relating to the health status of an individual. Health information such as diagnoses, treatment information, medical test results, and prescription information are considered protected health information under HIPAA, as are national identification numbers and demographic information such as birth dates, gender, ethnicity, and contact and emergency contact information. 

Managing Sensitive Data

The first step in managing sensitive data is to identify where the data is being stored. ITS offers Spirion, a data discovery and remediation tool that helps organizational units throughout the University not only find where their sensitive data may be located, but also facilitates remediation of that information.

Secure File Storage

Georgia Southern provides a secure Google drive for departments who utilize sensitive data to assist with secure storage needs.

Spirion

Identity theft, fraud, and security breaches can occur when sensitive data, such as social security numbers and credit card numbers, fall into the wrong hands. Spirion is software that helps organizational units find and remove sensitive information stored on University-owned systems and networks. Keep reading to learn how to use this software.

How it Works

Spirion facilitates the discovery and remediation of sensitive data. This tool works by first identifying where sensitive data is located and then providing options for managing and securing that data.

What does Spirion search for?

Spirion is configured to specifically look for sensitive data. Examples include: social security numbers, credit card numbers, bank account numbers, drivers license numbers, and passwords.

Spirion has the ability to search for sensitive data in file types such as Microsoft Word, Excel, Access, PowerPoint, Adobe PDF, txt files, web files and other common file types.  The tool also has the ability to search through compressed files.

Where can Spirion search?

Spirion is allowed to scan Google Drive, home directories, departmental drives, workstations, and applications.

What happens if sensitive data is found on my computer?

By using Spirion, organizational units are empowered to manage their own data to protect University resources. This tool allows organizational units to locate their own sensitive data to prevent data breaches in their areas. Identifying the location is the first step in managing and protecting this data. Afterwards, users can choose how to protect the data.

Who will Spirion scan results be shared with?

There are two different types of scans: administrator scans and local scans.  Administrator scans provide specific details pertaining to resources and data types. 

Local scans are performed by the user at the workstation.  These reports are defined by the user and not shared with anyone else.  This allows you (the user) the opportunity to investigate your own resources and take action.

Using Spirion

Performing a local scan on your device with Spirion can help you locate and manage your sensitive data.

Step 1: Locate Your Sensitive Data

Local scans can be run using the Spirion Search Wizard on both PC and Mac. Scans typically take 20 – 40 minutes to run–you can still use your machine to do other work while the scan is running. When the scan has finished, results of the scan will be displayed.

Use the steps below or view our detailed documentation to locate your sensitive data:

  1. In the Search Wizard or the Spirion interface, click on Start or Start Search Now.
  2. A pop-up window will be displayed during scanning and will show search results once the scan has completed.
  3. You may the select Wizard to move through each item step by step, or select Advanced Mode to choose their own action for each item.

Step 2: Managing Your Sensitive Data

If a scan locates sensitive data, you can choose to shred or redact that data in order to mitigate risk. The shred function permanently deletes data and should be used if you no longer need to store the file locally. This is the most commonly used method of managing sensitive data since most users find that they don’t need to store the sensitive data. The redact function removes sensitive information from files while leaving the file in its location. This function is used less frequently and can only be used on local or network drives (not email or Google Drive). Alternatively, if sensitive information must be stored, users can choose to securely store the information using a departmental or personal secure storage drive.

How to Shred

Use the steps below or view detailed documentation to shred sensitive data:

  1. Click the Shred button on the main ribbon in the Spirion interface.
  2. Right click the result, then click Shred.
  3. Click the result to highlight it and press the delete key on your keyboard.
How to Redact

Use the steps below or view detailed documentation to redact sensitive data:

  1. Click the Redact button on the main ribbon in the Spirion interface.
  2. Right click the result, then click Redact.
How to Securely Store Files

Have you determined that it’s necessary to store sensitive data? If data cannot be shredded or redacted, use our secure storage options to ensure that the data is protected.

Secure Storage

Secure File Storage allows Georgia Southern faculty, staff, and departments to store Sensitive Data. Secure Storage drives are available for University departments who utilize and store Sensitive Data. Keep reading to learn more about using Secure File Storage.

The university provides a secure Google drive for departments to assist with storage needs for Personally Identifiable Information (PII), Family Educational Rights & Privacy Act (FERPA) Data, and Payment Card Industry (PCI) Data.

Protected Health Information (PHI), which is specific to areas of the University, is managed separately from the other types of sensitive data. To discuss your PHI storage needs, please contact our MyTech Support staff, who will be happy to discuss storage options for you.

To locate your departmental secure storage drive, follow the steps below:

  1. Sign into the MyGS portal.
  2. In the MyApps tile, locate the Google Drive icon.
  3. In the left navigation menu, locate the “Shared Drives” option and click to expand.
  4. Your department’s secure drive is located here, with the naming convention “Secure_DeptName.”

Documents stored in your departmental secure storage drive are viewable only by those who have access to the drive and may not be shared outside of those resources.

To locate your departmental secure storage drive, follow the steps below:

  1. Sign into the MyGS portal.
  2. In the MyApps tile, locate the Google Drive icon.
  3. In the left navigation menu, locate the “Shared Drives” option and click to expand.
  4. Your personal secure drive is located here, with the naming convention “Secure_Username.”

Documents stored in your personal secure storage drive are viewable only by you and may not be shared.