skip navigation

Secure IT page banner

Security of Sensitive Data

Overview

Creighton University has legal and ethical obligations to ensure that private and legally protected institutional information such as the SSN and other personal identifying information (PII) is secured in a manner that minimizes risk of unauthorized or inappropriate use or disclosure, (personal identifying information is defined here as social security number, credit or debit card number, and banking account numbers).

Creighton will no longer use Social Security Numbers to identify students, employees, or other persons with a CU relationship, except for those uses required by law, such as payroll, benefits, and financial aid. Our intent is to prevent unauthorized use of or access to SSNs and other PII.

Neither the Social Security Number nor any portion of the Social Security Number will be collected, stored, or transmitted unless authorized in writing by the Information Security Office. Departments or individuals who are authorized to collect, store, or transmit Social Security Numbers will be required follow stringent guidelines to secure such data that must be stored on central University resources where extra levels of security will be applied.

 

Guidelines

Schools, divisions, and departments must follow a set of administrative, physical, and technical procedures to protect the confidentiality of private information.

Access Guidelines

Access to sensitive information is limited to those who need to use the information in the performance of their job responsibilities.

 

Transmission Guidelines

Sending SSN over the Internet or by email is prohibited unless done in a secure environment. Appropriate measures must be taken to ensure the confidentiality of fax and paper transmissions containing SSN.

 

Use Guidelines

SSN data may only be used for the stated legal and/or business purpose for which it was collected.  In addition, SSN data may not be shared with others and may only be disclosed as authorized by law or with specific consent from the individual from whom it was collected.

 

 

 

Storage Guidelines

Units must actively work to remove SSN data from local electronic files, databases, images, and paper documents. Any University office that collects and maintains an individual's SSN must ensure that the SSN is stored in a secure and confidential environment, eliminate use of the SSN for any purpose except that for which it was collected, and follow the guidelines below for the disposal of records containing the SSN. The objective is that private "data at rest", i.e., "stored private data", should be encrypted unless it has been transmitted to a secure network as authorized by the Information Security Officer.

Disposal Guidelines

As SSN is eliminated from the normal course of business, organizational units must follow these standards for secure disposal.

 

Password Tips

  1. Never tell your password to anyone!
  2. Never write down your password in an obvious location.
  3. Make your password hard to guess — do not use the name of your pet (or your kid).
  4. Avoid using words found in a dictionary.
  5. Never write down your password in an obvious location.
  6. The more random your password, the better.
  7. Be sure that you don't use personal identifiers in your password (like your name or NetID).
  8. Never write down your password in an obvious location.   
  9. Take responsibility for your NetID.
  10. ...and never tell your password to anyone!
Sensitive Data Resources

Neither the Social Security Number nor any portion of the Social Security Number or other PII will be collected, stored, or transmitted by university services unless its use is authorized in writing by the Information Security Officer. Departments or individuals who are authorized to collect, store, or transmit Social Security Numbers and other sensitive data will follow guidelines to secure such data as established by the Information Security Office.

Applicable Policies
Password Vidoes

-George Mason University

-University of Tennessee

-Virginia Commonweath University

Password Brochures

2500 California Plaza
Omaha, NE 68178
Phone - 402.280-2700
Contact Information Security
Copyright © 2009
Creighton University
Contact the Webmaster
Search   :   A-Z Index