Loading...
4.5. SR 07-06-2015 EOty1� ,.,�� Request for Action River To Item Number Mayor and City Council 4.5 Agenda Section Meeting Date Prepared by ConsentJuly 6, 2015 Tina Allard, City Clerk Item Description Reviewed by Policy for Ensuring Security of Not Public Data Cal Portner, City Administrator Reviewed by Action Requested Adopt,by motion, the Policy for Ensuring Security of Not Public Data Background/Discussion Staff discussed the draft policy at the June 15, 2015, Council worksession meeting. This policy is developed to meet state law requirements regarding data breaches and security. Financial Impact There would be cost requests coming forward as part of budget discussions regarding a security assessment of our data. Attachments ■ June 15, 2015, Staff Report ■ Draft Policy POWERED 6T Template Updoted 4/14 INAWRE1 Oty Elk Request for Action R.iVer To Item Number Mayor and City Council 9.2 Agenda Section Meeting Date Prepared by Worksession June 15, 2015 Tina Allard, City Clerk Item Description Reviewed by Policy for Ensuring Security of Not Public Data Cal Portner, City Administrator Reviewed by Action Requested Review policy and direct staff on changes. Policy will be approved on a future regular meeting agenda. Background/Discussion The legislature made changes to the data practices law regarding access to Not Public Data. Some of these changes came about due to many of the breaches highlighted in the news media in recent years. The city is mandated to establish additional security measures "...ensuring data that is not public is only accessible to persons whose work assignments reasonably require access to the data..." What this means is the city needs to develop a policy designed to prevent employees from accessing not public data unless they have a legitimate work reason to do so. The policy covers the following: 1. Who must follow the policy ■ City employees ■ Firefighters ■ Volunteers ■ Appointed/elected officials ■ City vendors and consultants 2. How the city secures data ■ Protected folder structures on shared network drives ■ Locking offices/file cabinets ■ Password protection of computers, tablets, and phones ■ Shredding documents before disposal 3. Responsibilities of supervisor's and employees 4. Breach investigation process with step-by-step procedures and letter templates for staff. 5. Requirements for preparing a final report. 6. Annual security assessment of Personallnfoa-mation. Personallnfoa-mation is defined in state law as a person's name kept in combination with a social security number, driver's license, or account numbers with passwords or access codes. Financial Impact N/A Attachments ■ Draft Policy POWERED 6T Template Updoted 4/14 INAMIRE1 Policy for Ensuring Security of Not Public Data Applicability This policy is applicable to all City of Elk River employees,including firefighters,volunteers, appointed, and elected officials. This policy is also applicable to all city vendors and consultants. Security The types of Not Public Data maintained by the city are retained in the City Data Inventory Document. All Not Public Data will be stored in files or databases which are not readily accessible to individuals who are not authorized to access the data. The files and databases shall be secured during hours when the offices are closed. Security shall include: 1. Storing Not Public Data only in city offices, except when necessary for city business. 2. Assigning appropriate security roles, limiting access to appropriate shared network drives, and implementing password protections for not public electronic data. 3. Password protecting employee computers and locking computers before leaving workstations. 4. Securing Not Public Data within locked work spaces and in locked file cabinets. 5. Shredding Not Public Data documents before disposal. Access Employee position descriptions shall include language outlining the employee's responsibility when working with Not Public Data. Only those whose job responsibilities require access will be allowed access to files and records that contain Not Public Data. Within the City of Elk River, department directors may assign tasks by employee or by job classifications. The responsible authority,in conjunction with department directors and employee supervisors shall determine which employee's job responsibilities require them to have access to Not Public Data. If a department maintains Not Public Data that all employees within such department do not have a work assignment allowing access to the Not Public Data, the department will ensure that the Not Public Data are secure. This policy also applies to departments that share workspaces with other departments within the city where Not Public Data are maintained. In the event of a temporary duty assigned by a manager or supervisor, an employee may access certain Not Public Data for as long as the work is assigned to the employee. The responsible authority or designee and department directors may have access to all Not Public Data maintained by the city if necessary for specified duties. Any access to Not Public Data will be strictly limited to the data necessary to complete the work assignment. Employees with access to Not Public Data will be instructed to: 1. not discuss, disclose or otherwise release private or confidential data to city employees whose job responsibilities do not require access to the data•, 2. not leave private or confidential data where non-authorized individuals might see it; and 3. shred private or confidential data before discarding, or dispose through confidential locked recycling. When a contract with an outside party requires access to private or confidential information, the contracting party will be required to use and disseminate the information consistent with the Minnesota Data Practices Act. Data Sharing with Authorized Entities or Individuals State or federal law may authorize the sharing of Not Public Data in specific circumstances. Not Public Data may be shared with another entity if a federal or state law allows or mandates it. Individuals will have notice of any sharing applicable Tennessen warnings (see Minn. Stat. § 13.04) or the city will obtain the individual's informed consent. Any sharing of Not Public Data will be strictly limited to the data necessary or required to comply with the applicable law. Security Assessment Annually, the city will conduct a security assessment of any personal information maintained by the city. The city administrator shall supervise preparation of a report on the status of security of the personal information. For the purposes of this subdivision,personal information is defined as a person's name kept in combination with a social security number, driver's license number, or account numbers with passwords or access codes. Personal information does not include publicly available information that is lawfully made available to the general public from federal, state, or local government records. Penalties for Unlawfully Accessing Not Public Data The city will utilize the penalties for unlawful access to not public data as provided for in Minnesota Statutes, section 13.09,if necessary. Penalties include suspension without pay, dismissal, or referring the matter to the appropriate prosecutorial authority who may pursue a criminal misdemeanor charge. Breach in Security Data Application This section applies to breaches of the security of Not Public Data maintained by or on behalf of the City of Elk River. The city administrator will implement and oversee these procedures and may delegate responsibilities to other city personnel as appropriate. Definitions For purposes of this section the definitions in Minn. Stat, § 13.055 shall apply. Reporting a Suspected Breach Any person who knows of, or reasonably believes, a security breach of Not Public Data has occurred shall immediately report the breach to the city adminstrator, and if they are a city employee or contractor, to their supervisor. City employees who report a breach under this policy shall not be subject to retaliation. Response to Suspected Breach Upon the report of a suspected breach, the city administrator shall take any and all actions necessary to secure the data and to protect the data from continued or repeated breach and shall conduct a preliminary internal assessment of the scope of the breach. If the breach is suspected on a city computing system that contains or has network access to Not Public Data, the city administrator shall consult with city IT personnel and consider control measures, including, but not limited to, removing the computer system from the city network. Determination of Breach The city administrator,in conjunction with the city attorney, shall determine whether a breach has occurred. Due consideration should be given to the potential for damage to individuals if no breach is determined and notice is not provided. Contact the League of Minnesota Cities (LMCIT) Claims Department. LMCIT may provide a breach coach to assist with the handling of a data security breach or cyber event. Notice If it is determined that a breach has occurred, the city administrator shall provide notice to all data subjects affected by the breach. The city administrator,in conjunction with the city attorney, shall determine whether notice is required to be provided and to whom such notice is to be provided. At a minimum,individuals shall be notified if their private or confidential data was, or is reasonably believed to have been, acquired by an unauthorized person. If specific individuals cannot be identified, notice should be sent to groups of individuals likely to have been affected, such as all whose information is stored in the database or files involved in the breach. Appropriate measures should also be taken to prevent notice lists from being over-inclusive. The forms of notice to be provided are attached. 1. Timing. Notice shall be provided to all affected data subjects without unreasonable delay, subject to: a) The legitimate needs of a law enforcement agency; and b) any measures necessary to determine the scope of the breach and restore the reasonable security of the data. Immediate notification may be appropriate in the event of a breach that could have immediate deleterious impact on individuals whose data may have been acquired by an unauthorized person. 2. Content. The notice shall generally include the following information: a) A general description of what happened, and when, to the extent known. b) The nature of the individual's private or confidential information that was involved (not listing the specific private/confidential data). c) Information about what the city has done to protect the individual's private/confidential information from further disclosure. d) City assistance (such as website information or phone number of a city resource) for further information about the incident. e) Information, such as websites, about what individuals can do to protect themselves against identity theft including; contact information for nationwide credit reporting agencies; the Federal Trade Commission and appropriate state agency resources. Information that a report will be prepared as noted below, on how the individual may obtain access to the report, and that the individual may request delivery of the report by mail or email. 3. Method. Notice under this section may be provided by one of the following methods: a) Written notice by first class mail to each affected individual; b) electronic notice to each affected individual,if the notice provided is consistent with the provisions regarding electronic records and signatures as set forth in the United States Code, title 15, section 7001; or C) substitute notice,if the city demonstrates that the cost of providing the written notice required by paragraph (a) would exceed$250,000, or that the affected class of individuals to be notified exceeds 500,000, or the city does not have sufficient contact information. Substitute notice consists of all the following: i. email notice if the city has an email address for the affected individuals; ii. conspicuous posting of the notice on the website page of the city; and iii. notification to major media outlets that reach the general public within the city's jurisdiction. Contacting Law Enforcement The city administrator,in conjunction with the city attorney, shall determine if it is appropriate to contact law enforcement in relation to any breach or suspected breach. Information may be shared with law enforcement consistent with applicable data privacy laws. If law enforcement is contacted,it should be informed of the city's practice to provide notice to affected individuals. If law enforcement advises that such notice would impede an active criminal investigation, notice may be delayed. Delayed notice should be sent out as soon as law enforcement advises that it would be no longer impede the criminal investigation. Coordination with Credit Reporting Agencies If notice is required to be given to 1,000 or more individuals at one time, the city shall notify, without unreasonable delay, all consumer reporting agencies that compile and maintain files on consumers on a nationwide basis as defined in 15 U.S.C. Sect. 1681a, of the timing, distribution and content of the notice to be sent. Such contacts shall include but not limited to the following: ■ Equifax Experian TransUnion US Consumer Services Experian Security Assistance 1.800.680.7289 Equifax Information PO Box 72 Services, LLC Allen,TX 75013 Phone: 1.800.525.6285 1.888.397.3742 Report Upon completion of an investigation into any breach in the security of data and final disposition of any disciplinary action under Minn. Stat. § 13.43,including exhaustion of all rights of appeal under any applicable collective bargaining agreement, the city administrator shall prepare a report on the facts and results of the investigation. If the breach involves unauthorized access to or acquisition of data by an employee, contractor, or agent of the government entity, the report must at minimum include: 1. A description of the type of data that were accessed or acquired; 2. the number of individuals whose data was improperly accessed or acquired; 3. if there has been final disposition of disciplinary action for purposes of Minn. Stat. § 13.43, the name of each employee determined to be responsible for the unauthorized access or acquisition, unless the employee was performing duties under Minn. Stat. ch. 5B; 4. the final disposition of any disciplinary action taken against each employee in response. Documentation The city administrator or designee must document each reported breach,regardless of whether notice is given. Documentation should be completed at the time of the initial report or as soon thereafter as practical. When appropriate, all documentation related to the breach and investigation shall be labeled and maintained as not public pursuant to the applicable data privacy classification,including,but not limited to, "security information" as defined by Minn. Stat. § 13.37. Subd. 1(a). The documentation shall be retained in accordance with the applicable records retention policy. Was the data accessed Did the indivival have the data Did the individual's work private or YE5 subject's informed consent to NO assignment reasonably confidential? access the data? require access to the private or confidential data? Was the data accessed for No data security breach YES that work related purpose? NO Data Breach! Standard Breach Notification Letter Pate] [Name] [Address] [City, State, Zip] RE: Important Notice Regarding Possible Disclosure of Private Information Dear [Name]: We are sending this letter to you as part of the City of Elk River's commitment to privacy. We take privacy very seriously, and it is important to us that you are made fully aware of a potential privacy issue. We have learned that your personal information,including , , and ,may have been compromised. On [give date of discovery],it was discovered that [describe incident and give date of breach]. We have not received any indication that the information has been accessed or used by an unauthorized individual. We sincerely apologize and regret that this situation has occurred. The City of Elk River is committed to providing quality care,including protecting your protected information, and we want to assure you that we have policies and procedures to protect your privacy. If you have any questions,please contact the City of Elk River's Human Resources Director at 763.635.1024. Sincerely, [Name,Title]* *Likely senders of the letter include the entity's city administrator, responsible authority, or data practices compliance official. Standard Breach Notification Letter Pate] [Name] [Address] [City, State, Zip] RE: Important Notice Regarding Possible Disclosure of Private Information Dear [Name]: [Entity] takes seriously its responsibility to protect information about the individuals it serves. I am writing to inform you of a concern regarding possible unauthorized access of your private information. On [date], [Entity] discovered that [description of the issue/what occurred]. The records included [description of data]. OPTIONAL: At this time,your data has not been used inappropriately;rather we have determined that your data could have been vien)ed by an unauthorized person. The [description of issue] was immediately corrected upon discovery. Upon completion of our investigation,you have the right to receive a report on the details of the investigation. If you would like a copy of the report, contact us to request delivery of the report via mail or email. We recommend you take precautionary measures to protect yourself, such as monitoring your personal credit reports. Under federal law,you have the right to receive, at your request, a free copy of your credit report every 12 months from each of the three consumer credit reporting companies. A credit report can provide information regarding those who have received information about your credit history within a certain period of time. You may request a free credit report online at www.annualcreditreport.com or by telephone at 1.877.322.8228. When you receive your credit reports, check for any transactions or accounts you do not recognize. If you see anything you do not understand, call the telephone number listed on the credit report or visit the Federal Trade Commission's Web site on identity theft at www.consumer.gov/idtheft/. [Entity] deeply regrets that this occurred and apologizes for any uneasiness and inconvenience this may cause you. If you have any questions,please contact [name, address, email,phone]. We will keep you informed of any additional developments that may be of importance to you. Sincerely, [Name,Title]* *Likely senders of the letter include the entity's city administrator, responsible authority, or data practices compliance official. Standard Breach Notification Letter P)/Remedial Measures Pate] [Name] [Address] [City, State, Zip] RE: Important Notice Regarding Possible Disclosure of Private Information Dear [Name]: We are sending this letter to you as part of the City of Elk River's commitment to privacy. We take privacy very seriously, and it is important to us that you are made fully aware of a potential privacy issue. We have learned that your personal information,including , and , may have been compromised. On]give date of discovery], it paras discovered that]describe incident and give date of breach]. 1F`e reported the incident to lana enforcement because theft may have been involved[if applicable]. However,we have not received any indication that the information has been accessed or used by an unauthorized individual. We are keenly aware of how important your personal information is to you. If you choose, as a measure of added security,we are offering one year of credit monitoring and reporting services at no cost to you. This service is performed through [Vendor], an organization that watches for and reports to you unusual credit activity, such as creating new accounts in your name. [Vendor] will also request that the three credit bureaus place a"Fraud Alert" on your credit report. If you would Eke to receive this service,please respond yes by or We understand that this may pose an inconvenience to you. We sincerely apologize and regret that this situation has occurred. The City of Elk River is committed to providing quality care,including protecting your personal information, and we want to assure you that we have policies and procedures to protect your privacy. If you want to take advantage of the free credit monitoring service, or if you have any questions please contact the Human Resources Director at 763.635.1024. Sincerely, [Name,Title]* *Likely senders of the letter include the entity's city administrator, responsible authority, or data practices compliance official. Standard Breach Notification Letter P)/Remedial Measures& Investigative Report Due to Acquisition by an Unauthorised Person Pate] [Name] [Address] [City, State, Zip] RE: Important Notice Regarding Possible Disclosure of Private Information Dear [Name]: We are sending this letter to you as part of the City of Elk River's commitment to privacy. We take privacy very seriously, and it is important to us that you are made fully aware of a potential privacy issue. We have learned that your personal information,including , and , may have been compromised. On]give date of discovery], it paras discovered that]describe incident and give date of breach]. lie reported the incident to Ian)enforcement because theft may have been involved[if applicable]. Based upon our investigation,we reasonably believe that the data was acquired by an unauthorized person individual. Accordingly, the City of Elk River will prepare a report upon completion of an investigation and final disposition of any disciplinary action (if applicable). You may obtain access to the completed report via mail or email by making a request to We are keenly aware of how important your personal information is to you. If you choose, as a measure of added security,we are offering one year of credit monitoring and reporting services at no cost to you. This service is performed through [Vendor], an organization that watches for and reports to you unusual credit activity, such as creating new accounts in your name. [Vendor] will also request that the three credit bureaus place a"Fraud Alert" on your credit report. If you would Eke to receive this service,please respond yes by to at the above- listed address. We understand that this may pose an inconvenience to you. We sincerely apologize and regret that this situation has occurred. The City of Elk River is committed to providing quality care,including protecting your personal information, and we want to assure you that we have policies and procedures to protect your privacy. If you want to take advantage of the free credit monitoring service, or if you have any questions please contact the Human Resources Director at 763.635.1024. Sincerely, [Name,Title]* *Likely senders of the letter include the entity's city administrator, responsible authority, or data practices compliance official.