Title: Data Confidentiality Procedures Owning Department: Responsibilities: Current Date: Revision History: Date of Revision Description Information Technology Information Technology, Managers, FAFCU Staff 12/2/2020 10/21/10 4/09/2012 New Procedure Implemented Added Clean Desk Procedure, Checklist and Disciplinary Actions 08/04/2015 Modified owning department title, added smartphones to list of items FAFCU staff must secure 12/16/16 Reviewed by MBrands Added E-mail Encryption to procedure 4/26/18 4/19/19 Added data encryption – Reviewed by AMehta Reviewed/Updated by J.Vitkuske 12/2/2020 Policy Reference: Purpose: Forms: Procedure: Data Confidentiality and IT Security. The purpose of this procedure is to establish management direction, procedures, and requirements to ensure the appropriate protection of First Atlantic Federal Credit Union confidential information and records to control and protect sensitive information. To establish guidelines for the administration of access controls to sensitive data. End of the Day Checklist, Disciplinary Notice. I. RESPONSIBILITY OF ADMINISTERING AND MONITORING SECURITY OF CONFIDENTIAL INFORMATION AND RECORDS The responsibility rests with the Director of Technology. II. PURPOSE The standards apply to all staff members, contractors, consultants, temporaries, and other users at First Atlantic Federal Credit Union (FAFCU), including those users affiliated with third parties who access First Atlantic Federal Credit Union computer networks or otherwise provide services. The standards must be applied to e-mail use, Internet, fax, printers, electronic media, CDs, Personal computers, servers, memory sticks and cartridges. Transmission of confidential data is not permitted unless encrypted or password protected. III. PROCEDURES The matrix and procedures below identify non sensitive and confidential information. It is a guideline to assist but is not all inclusive; there could be other documents in addition to those listed. Statutorily protected, non-public member information or sensitive information must always be treated as confidential and protected. GENERAL – APPLIES TO ALL NON-SENSITIVE INFORMATION CONFIDENTIAL INFORMATION • Journals/Publications • Books • Internal Phone Directory • Blank Forms • Brochures • Annual Reports • Deposit and Loan Rates • Routine Correspondence or Interoffice memos that do not include any confidential or sensitive information • E-mail that does not include sensitive or confidential information • Any document of a non sensitive matter • Reports that do not include sensitive or non- public information • Statutorily protected, non-public member or sensitive information (i.e.i.e., social security #s, account numbers, members date of birth, and any other sensitive information) • Passwords • Payroll Information • Employee Annual Reviews or disciplinary information • Vendor Contracts • E-mails with confidential Information • Internal Policies and Procedures • Employee Handbook • Interoffice memos that contain confidential or sensitive information • Correspondence that contains confidential or sensitive information • Audit Reports • Budget Information and Reports • Reports with sensitive or confidential information • Consumer, Real Estate and Collection files • CIF files and Membership applications • Member Statements HUMAN RESOURCES • All items listed under the General Category • Blank applications • Job Interest Forms • Blank Benefit Enrollment Form • Blank I-9 Forms • Blank W-4 Forms • Compliance Signs • Requisition Forms • Benefit Booklets • All items listed under the General Category • Employee Handbook • Business Continuity Plan • Vendor Contracts • Completed I-9 Form • Completed W-4 • Applicant Data Record • Performance Improvement Plan • Direct Deposit Form • AAP Plan • Disciplinary Notices • Performance Appraisals • Personnel Committee Minutes • Workers Comp Claim Forms • ADA Information • Doctors Notes • Disability Claims • Personnel Files • Payroll Files • FMLA Documentation • ADA Documentation • Wage Garnishments EXECUTIVE • All items listed under the General Category • All items listed under the General Category • Papers of Incorporation • Bi-Laws • Charter Documents • Strategic Plan • Legal Information • NCUA Exam Reports • Attorney Correspondence • Board and Committee Packages • Financial data and reports • Internal and External Audit Reports • Bond/Insurance Information • Purchasing Information • Reports with confidential or sensitive information • Budget Information • Employee Information INFORMATION SYSTEMS • All items listed under the General Category • Blank Tapes or CDs • All items listed under the General Category • Network Topology • IT Logs • Server and Hard Drive Information • Backup data • Tapes/CDs with sensitive or nonpublic information • Operating procedures • Software licenses • Workbook with daily operating instructions • Testing Information • Nonpublic member information and confidential information stored on PCs and servers. FINANCE AND ACCOUNTING • All items listed under the General Category • Call Reports • Financial Statements • All items listed under the General Category • Accounting Records • Bank Statements • Corporate Resolutions • General Ledger Information • Chart of Accounts • Investment Records • Procedures and Policies CIF VAULT ROOM • All items listed under the General Category • All items listed under the General Category • Documents with confidential information in consumer, Real Estate, Collections loan files • Documents in CIF files • Membership Applications • Vendor Contracts • Any document with sensitive or non-public member information • Spreadsheets with member account numbers • Reports with member account numbers and nonpublic member information CALL CENTER • All items listed under the General Category • All items listed under the General Category • Membership applications • Wire Forms with member info • Member correspondence with confidential information • Address change forms with confidential information • Loan applications OPERATIONS • All items listed under the General Category • All items listed under the General Category • Adjustment forms from BOA and FRB with confidential information • Returned statements or other correspondence with confidential information • Reconciliations • Original checks (ck21) • Copies NSF checks • Savings Bonds • Returned Debit Cards • Wire forms INTERNAL AUDITOR • All items listed under the General Category • All items listed under the General Category • Work papers with confidential information • Audit Reports Internal and External • Supervisory Committee Reports • Management Letter • NCUA Exam Reports • Confidential Board of Directors correspondence and information MARKETING • All items listed under the General Category • Brochures • Advertisements • News Releases • Marketing Material • All items listed under the General Category • Strategic Marketing Plan • Vendor Contracts REAL ESTATE LENDING and CONSUMER LENDING • All items listed under the General Category • Blank applications • Manuals • Journals • Dealer Information Lists • Secondary Market Information • All items listed under the General Category • Statutorily protected, non-public member or sensitive information • Reports with sensitive or non public information • Completed applications and disclosures • Member payroll and employment information • Consumer and Real Estate Loan folders • Credit Reports COLLECTIONS • All items listed under the General Category • Work Schedules • Repo Directories • NADA and Galves Guides • Glaves Price Guides • All items listed under the General Category • Delinquent Reports • Delinquency Notices • Member checks or copies • Repo Files • Repo Reports • Foreclosure Files • Credit Reports • General Ledger Reports • Smarti Collection Reports • Smarti Print outs • Agency/ Attorney Reports • Bankruptcy Information • Status Reports • Modification/TDR Reports FACILITIES • All items listed under the General Category • Vendor blank Forms • Task Info • Real Estate Listing • All items listed under the General Category • Burglar and Fire Alarm details • Security System Information • Tenant Lease • Confidential attorney information SERVICE CENTERS • All items listed under the General Category • Compliance Signs • Marketing Material • Blank Forms • All items listed under the General Category • Deposit, withdrawal, and transfer tickets with confidential member information • Completed loan applications and member identification • Completed Membership and account applications Guidelines and Procedures for Confidential Information: Contracts with third parties that provide services will require that the third parties implement appropriate measures to meet the objectives of the 501(b) guidelines. Sensitive information provided to contractors will be encrypted or otherwise password protected or transferred via secured transfer method. Management is responsible for ensuring that employee and contract personnel who perform services or tests or have access to the test results have passed appropriate background checks, and that contracts reflect compliance with applicable laws The distribution of all testing information (external or internal) is limited. Management is responsible for clearly identifying the individuals responsible for protecting the data and providing guidance for that protection, while making the results available in a useable form to those who are responsible for following up on the tests. Contractors are required to sign nondisclosure agreements and to return to the institution information they obtained during their testing or to properly destroy the information and advise credit union of destruction. IT management will ensure secure transportation and storage of all back-up data. Systems will be backed up and data stored in accordance with IT procedures. Access to the host and servers is password protected to ensure security of sensitive data. Additionally, access to the data center is restricted to only those staff members that have a need to enter the area. The confidentiality and integrity of data stored on company computer systems is protected by access controls to ensure that only authorized staff members have access. This access shall be restricted to only those capabilities (need to know basis) that are appropriate to each staff member’s job duties. All external users wishing to establish a connection with FAFCU computers via the Internet must authenticate themselves before gaining access to FAFCU’S internal network unless otherwise authorized. Access to member account information is password controlled and assigned according to job need through authority levels, i.e.i.e., teller, platform, lending, collections, managers, etc, Board and Finance committee reports will be stored in a secure location, access is limited to authorized staff, FAFCU counsel, examiners and auditors. All FAFCU confidential information such as documents related to lawsuits and bonding issues is maintained by FAFCU counsel, the President/CEO or otherwise authorized individual and held under strictest confidence. Information can only be released with the approval of the president or FAFCU counsel. Vendor Contracts are maintained in the CIF Vault room in a secure cabinet. Only staff with the proper authorization will be provided with access. Software Licenses and other license agreements are maintained in a locked cabinet in the data center. Only staff with the proper authorization will be provided with access. Papers of incorporation, original bylaws and charter documents, copies of credit union mergers and all other corporate documents are maintained in the CIF Vault room in a secure cabinet. Only staff with the proper authorization will be provided with access. All NCUA Exam reports will be maintained under the control of the Risk/Security Officer, all sensitive data will be protected and only staff with the proper authorization will be provided with access to a minimum of the data that is required to perform their responsibilities. All other Audit reports will be maintained under the control of the Internal Auditor and the Risk/Security officer, all sensitive data will be protected and only staff with the proper authorization will be provided with access to a minimum of the data that is required to perform their responsibilities. Vital accounting records are maintained by CFO and the controller. Only staff with the proper authorization will be provided with access. Employee records are maintained in the Human Resources department. Access to the department is limited to HR staff and controlled via card access control. All member records that include non-public member information records are stored in the CIF vault room. The access to the vault room is restricted to authorized staff only and controlled through card access control. Requests for files from authorized staff is properly documented and tracked. Member data (in any media format) must be stored out of sight when not in use. If it contains highly sensitive (nonpublic information) or confidential data, it should be locked up in a secure area. Guidelines for Sensitive Data on Laptops: The storage of sensitive data in portable devices, such as laptops, that may be removed from FAFCU and not protected by any physical security is not allowed unless properly encrypted or password protected. Staff members shall not take shared portable equipment such as laptop computers out of the office without the informed consent of their department manager. Informed consent means that the manager knows what equipment is leaving, what data is on it, and for what purpose it will be used. All data contained on the laptop must be encrypted or password protected Staff members using laptop or desktop computers out of the office must safeguard member Confidential Information. Computers must be password protected and access by others controlled to avoid misuse and unauthorized access and exposure to member data. Guidelines for Confidential Information in E-Mails: Staff members are not permitted to transmit confidential information. If it is necessary to transmit nonpublic or confidential information, it must be in compliance with procedures and either encrypted or password protected. Staff members are required to take steps reasonably intended to ensure that information is delivered to the proper person who is authorized to receive such information for a legitimate use. In the event you must send an e-mail that contains confidential information, the email may be encrypted by typing the word “Encrypt” in the subject line. The email and any attachments will be sent encrypted. Data Encryption All files stored on First Atlantic’s servers are to be encrypted using at minimum AES 256 standard. This standard is also to be used when transmitting and storing member information on networks, devices, and systems. Physical Security Standards: Computer and workstations are not to be left unattended. The PC must be locked or signed off upon leaving the workstation. Passwords must be used to sign into the network, Core application and any other critical system. Non-public member and confidential information should be protected by encryption. Printed documents must not be left unattended to preserve the sensitive of confidential information. Fax documents must not be left unattended to preserve the sensitive of confidential information. Guidelines for Reporting Loss of Confidential Information: If sensitive First Atlantic Federal Credit Union information is lost, disclosed to unauthorized parties, or suspected of being lost or disclosed to unauthorized parties, the IS Manager, Security Officer and CEO must be notified immediately. If any unauthorized use of FAFCU’s information systems has taken place, or is suspected of taking place, the IS Manager must likewise be notified immediately. Similarly, whenever passwords or other system access control mechanism are lost, stolen, or disclosed, or are suspected of being lost, stolen, or disclosed, the IS Manager must be notified immediately. Because it may indicate a computer virus infection or similar security problem, all unusual systems behavior, such as missing files, frequent system crashes, misrouted messages, and the like must also be immediately reported. The specifics of security problems should not be discussed widely but should instead be shared on a need-to-know basis. The IS manager is responsible to advise CEO and Security Officer. Disposal of Confidential Data: All sensitive and confidential data (paper based or electronic) must be maintained in a secured area or shredding bin until it can be shredded or properly destroyed in compliance with disposal policies. Policies prohibit employees from discarding media containing sensitive information along with regular trash to avoid accidental disclosure. All nonpublic member or confidential information is to be shredded. Disposal in recycling or regular trash bins is strictly prohibited. Electronic Devices: All electronic equipment that has a storage device or persistent memory, such as desk top computers, laptops, servers, personal data assistants (PDAs), cell phones, printers, copiers, routers, switches, firewall hardware, etc. Electronic devices or hard drives such as magnetic tapes, diskettes, CDs, DVDs and USB storage devices must be erased so that the data-containing component is unreadable, before the item is disposed of via trash or recycling. Electronic Media: All media on which electronic data can be stored, including, but not limited to hard drives, magnetic tapes, diskettes, CDs, DVDs and USB storage devices. Electronic devices or hard drives temporarily leaving the FAFCU for repair must have their data encrypted or removed. Software and Data Files: All software and data files must be removed by FAFCU-approved procedures from electronic devices and electronic media that are surplus or transferred from one FAFCU employee to another employee having different software and data access privileges. When electronic devices are sent outside FAFCU for repair, all data must be either encrypted or removed. Electronic devices or media being transferred within the FAFCU (between departments or employees having different software and data access privileges) must have their data removed. IS&T Responsibilities: The IS Manager shall be responsible for the administration of access controls to all company computer systems. The IS Manager will process additions, deletions, and changes upon receipt of a written request from the end user’s supervisor. Deletions may be processed by an oral request prior to receipt of the written request on an emergency basis. Monitor compliance with Internet security requirements, including hardware, software, and data safeguards. IS staff must also provide administrative support and technical guidance to management on matters related to Internet security. Annually conduct a risk assessment of Network to determine both risks and vulnerabilities. Ensures that all systems are scanned using Virus scanner. Monitor that appropriate security measures are implemented on these systems in a manner consistent with the level of information sensitivity. Monitor that user access controls are defined on these systems in a manner consistent with the need-to-know. FAFCU Staff Responsibility: FAFCU information owners must see to it that data is managed in a manner consistent with in-house sensitivity classifications. All employees must comply with the Clean Desk Requirements: Securing sensitive and confidential papers, media, and other assets when not in use. Securing sensitive information, laptops, smartphones, personal digital assistants (PDAs), and other valuable items when not in use. Personal computers and computer terminals should be protected by authentication codes and other controls when not in use. Passwords must be kept confidential. Wrongful or careless disclosure and discussion of privileged information Maintaining a neat work environment. In the teller area, removing cash, negotiable instruments, etc. from the work area as soon as practicable and placing them in designated secure areas. Preserve confidentiality of member information for over the teller counter and drive updrive-up transactions – unauthorized individuals could be listening. Putting away non-essential documents and items when hosting a visitor in the work area. Putting away documents or electronic media containing member and proprietary credit union information whenever an extended absence (i.e., lunchtime, break, committee meeting, etc.) from the work area is anticipated. Never send confidential and protected information through e-mail without encryption or password security. Discard items with confidential information in designated secure shred bins. Promptly return any documents and files when they are no longer needed. In the teller area, promptly sell excess cash to the vault. Remove member or credit union confidential information from your desktop, bookcase, credenza, or other location that can be seen by the general public during any extended absence. This also applies to platform staff and managers when they must leave their desk with members there and to go to the teller area. Always clear your desktop before you go home, securing appropriate items. Discipline for non-compliance: As an employee of First Atlantic, all staff members are required to maintain the security and confidentiality of all non-public information in its possession. Failure to safeguard the information will result in disciplinary action. Violation of Data Confidentiality Procedures 1st offense in rolling 12-month period Disciplinary Action Written Warning 2nd offense in rolling 12-month period 3rd offense in rolling 12-month period Written Warning – PIP Dismissal Violations of this procedure will be measured on a rolling 12-month basis. Management reserves the right to use its discretion in applying this procedure under special or unique circumstances. Managers Responsibility Staff under their supervision implements security measures as defined in this document. Staff under their supervision delete sensitive (confidential) data from their files when the data is no longer needed or useful. Staff under their supervision authorized to use personal computers are aware of and comply with the policies and procedures outlined in all First Atlantic Federal Credit Union documents that address information security. Staff and contractor personnel under their supervision complete the pre-exit clearance process upon their official termination of employment or contractual agreement. Staff and contractor personnel under their supervision make backup copies of sensitive, critical, and valuable data files as often as is deemed reasonable. End of Day Checklist required by all department managers. Discipline for noncompliance: When a written warning must be given to an employee, the department manager will review with the Human Resources Department. It should be the intent of both the supervisor and employee to work together in an attempt to avoid future violations. Written warnings must be completed no later than 48 hours following the identification of the violation.