Title:     Data Confidentiality Procedures  Owning Department:  Responsibilities:   Current Date:   Revision History:  Date of  Revision  Description  Information Technology   Information Technology, Managers, FAFCU Staff  12/2/2020  10/21/10  4/09/2012  New Procedure Implemented  Added Clean Desk Procedure, Checklist and Disciplinary Actions  08/04/2015 Modified owning department title, added smartphones to list of items  FAFCU staff must secure  12/16/16  Reviewed by MBrands  Added E-mail Encryption to procedure  4/26/18  4/19/19  Added data encryption – Reviewed by AMehta  Reviewed/Updated by J.Vitkuske  12/2/2020  Policy Reference:  Purpose:  Forms:  Procedure:  Data Confidentiality and IT Security.   The purpose of this procedure is to establish management  direction, procedures, and requirements to ensure the  appropriate protection of First Atlantic Federal Credit  Union confidential information and records to control and  protect sensitive information. To establish guidelines for  the administration of access controls to sensitive data.  End of the Day Checklist, Disciplinary Notice.  I.  RESPONSIBILITY OF ADMINISTERING AND MONITORING  SECURITY OF CONFIDENTIAL INFORMATION AND RECORDS   The responsibility rests with the Director of Technology.  II.    PURPOSE  The standards apply to all staff members, contractors, consultants, temporaries, and other  users at First Atlantic Federal Credit Union (FAFCU), including those users affiliated  with third parties who access First Atlantic Federal Credit Union computer networks or  otherwise provide services.     The standards must be applied to e-mail use, Internet, fax, printers, electronic media,  CDs, Personal computers, servers, memory sticks and cartridges. Transmission of  confidential data is not permitted unless encrypted or password protected.         III. PROCEDURES    The matrix and procedures below identify non sensitive and confidential information. It  is a guideline to assist but is not all inclusive; there could be other documents in addition  to those listed. Statutorily protected, non-public member information or sensitive  information must always be treated as confidential and protected.                 GENERAL –  APPLIES TO ALL  NON-SENSITIVE  INFORMATION  CONFIDENTIAL  INFORMATION   • Journals/Publications  • Books  • Internal Phone Directory  • Blank Forms  • Brochures  • Annual Reports  • Deposit and Loan Rates  • Routine Correspondence or  Interoffice memos that do not  include any confidential or  sensitive information  • E-mail that does not include  sensitive or confidential  information  • Any document of a non sensitive matter  • Reports that do not include  sensitive or non- public  information         • Statutorily protected, non-public  member or sensitive information  (i.e.i.e., social security #s,  account numbers, members date  of birth, and any other sensitive  information)  • Passwords  • Payroll Information  • Employee Annual Reviews or  disciplinary information  • Vendor Contracts  • E-mails with confidential  Information  • Internal Policies and Procedures  • Employee Handbook  • Interoffice memos that contain  confidential or sensitive  information  • Correspondence that contains  confidential or sensitive  information  • Audit Reports  • Budget Information and Reports  • Reports with sensitive or  confidential information  • Consumer, Real Estate and  Collection files  • CIF files and Membership  applications  • Member Statements            HUMAN  RESOURCES  • All items listed under the  General Category  • Blank applications   • Job Interest Forms  • Blank Benefit Enrollment Form  • Blank I-9 Forms  • Blank W-4 Forms  • Compliance Signs  • Requisition Forms  • Benefit Booklets    • All items listed under the  General Category  • Employee Handbook  • Business Continuity Plan  • Vendor Contracts  • Completed I-9 Form  • Completed W-4  • Applicant Data Record  • Performance Improvement Plan  • Direct Deposit Form  • AAP Plan  • Disciplinary Notices  • Performance Appraisals  • Personnel Committee Minutes  • Workers Comp Claim Forms  • ADA Information  • Doctors Notes  • Disability Claims  • Personnel Files  • Payroll Files  • FMLA Documentation  • ADA Documentation  • Wage Garnishments    EXECUTIVE • All items listed under the  General Category    • All items listed under the  General Category  • Papers of Incorporation  • Bi-Laws  • Charter Documents  • Strategic Plan  • Legal Information  • NCUA Exam Reports  • Attorney Correspondence  • Board and Committee Packages  • Financial data and reports  • Internal and External Audit  Reports  • Bond/Insurance Information  • Purchasing Information  • Reports with confidential or  sensitive information  • Budget Information  • Employee Information      INFORMATION  SYSTEMS                      • All items listed under the  General Category  • Blank Tapes or CDs    • All items listed under the  General Category  • Network Topology  • IT Logs  • Server and Hard Drive  Information  • Backup data  • Tapes/CDs with sensitive or  nonpublic information  • Operating procedures  • Software licenses  • Workbook with daily operating  instructions  • Testing Information  • Nonpublic member information  and confidential information  stored on PCs and servers.     FINANCE AND  ACCOUNTING                  • All items listed under the  General Category  • Call Reports  • Financial Statements    • All items listed under the  General Category  • Accounting Records  • Bank Statements  • Corporate Resolutions  • General Ledger Information  • Chart of Accounts  • Investment Records  • Procedures and Policies  CIF VAULT  ROOM                            • All items listed under the  General Category    • All items listed under the  General Category  • Documents with confidential  information in consumer, Real  Estate, Collections loan files  • Documents in CIF files   • Membership Applications  • Vendor Contracts  • Any document with sensitive or  non-public member information  • Spreadsheets with member  account numbers  • Reports with member account  numbers and nonpublic member  information  CALL CENTER      • All items listed under the  General Category    • All items listed under the  General Category  • Membership applications                    • Wire Forms with  member info  • Member correspondence  with confidential  information  • Address change forms  with confidential  information  • Loan applications    OPERATIONS                                • All items listed under the  General Category    • All items listed under the  General Category  • Adjustment forms from BOA  and FRB with confidential  information  • Returned statements or other  correspondence with  confidential information  • Reconciliations  • Original checks (ck21)  • Copies NSF checks  • Savings Bonds  • Returned Debit Cards  • Wire forms  INTERNAL  AUDITOR                      • All items listed under the  General Category    • All items listed under the  General Category  • Work papers with confidential  information  • Audit Reports Internal and  External  • Supervisory Committee Reports  • Management Letter  • NCUA Exam Reports  • Confidential Board of Directors  correspondence and information    MARKETING                • All items listed under the  General Category  • Brochures  • Advertisements  • News Releases  • Marketing Material  • All items listed under the  General Category  • Strategic Marketing Plan  • Vendor Contracts        REAL ESTATE  LENDING and  CONSUMER  LENDING                  • All items listed under the  General Category  • Blank applications  • Manuals  • Journals  • Dealer Information Lists  • Secondary Market Information    • All items listed under the  General Category  • Statutorily protected, non-public  member or sensitive information  • Reports with sensitive or non public information  • Completed applications and  disclosures  • Member payroll and  employment information  • Consumer and Real Estate Loan  folders  • Credit Reports    COLLECTIONS                        • All items listed under the  General Category  • Work Schedules  • Repo Directories  • NADA and Galves Guides  • Glaves Price Guides      • All items listed under the  General Category  • Delinquent Reports  • Delinquency Notices  • Member checks or copies  • Repo Files  • Repo Reports  • Foreclosure Files  • Credit Reports  • General Ledger Reports  • Smarti Collection Reports  • Smarti Print outs  • Agency/ Attorney Reports  • Bankruptcy Information  • Status Reports  • Modification/TDR Reports    FACILITIES                  • All items listed under the  General Category  • Vendor blank Forms  • Task Info  • Real Estate Listing    • All items listed under the  General Category  • Burglar and Fire Alarm details  • Security System Information  • Tenant Lease  • Confidential attorney  information    SERVICE  CENTERS  • All items listed under the  General Category  • Compliance Signs  • Marketing Material  • Blank Forms    • All items listed under the  General Category  • Deposit, withdrawal, and  transfer tickets with confidential  member information  • Completed loan applications and  member identification  • Completed Membership and  account applications  Guidelines and Procedures for Confidential Information:  Contracts with third parties that provide services will require that the third parties  implement appropriate measures to meet the objectives of the 501(b) guidelines.  Sensitive information provided to contractors will be encrypted or otherwise password  protected or transferred via secured transfer method. Management is responsible for  ensuring that employee and contract personnel who perform services or tests or have  access to the test results have passed appropriate background checks, and that contracts  reflect compliance with applicable laws  The distribution of all testing information (external or internal) is limited. Management is  responsible for clearly identifying the individuals responsible for protecting the data and  providing guidance for that protection, while making the results available in a useable  form to those who are responsible for following up on the tests. Contractors are required  to sign nondisclosure agreements and to return to the institution information they  obtained during their testing or to properly destroy the information and advise credit  union of destruction.  IT management will ensure secure transportation and storage of all back-up data. Systems  will be backed up and data stored in accordance with IT procedures.  Access to the host and servers is password protected to ensure security of sensitive data.  Additionally, access to the data center is restricted to only those staff members that have  a need to enter the area.  The confidentiality and integrity of data stored on company computer systems is  protected by access controls to ensure that only authorized staff members have access.  This access shall be restricted to only those capabilities (need to know basis) that are  appropriate to each staff member’s job duties.   All external users wishing to establish a connection with FAFCU computers via the  Internet must authenticate themselves before gaining access to FAFCU’S internal  network unless otherwise authorized.   Access to member account information is password controlled and assigned according to  job need through authority levels, i.e.i.e., teller, platform, lending, collections, managers,  etc,  Board and Finance committee reports will be stored in a secure location, access is limited  to authorized staff, FAFCU counsel, examiners and auditors.  All FAFCU confidential information such as documents related to lawsuits and bonding  issues is maintained by FAFCU counsel, the President/CEO or otherwise authorized  individual and held under strictest confidence. Information can only be released with the  approval of the president or FAFCU counsel.  Vendor Contracts are maintained in the CIF Vault room in a secure cabinet. Only staff  with the proper authorization will be provided with access.  Software Licenses and other license agreements are maintained in a locked cabinet in the  data center. Only staff with the proper authorization will be provided with access.  Papers of incorporation, original bylaws and charter documents, copies of credit union  mergers and all other corporate documents are maintained in the CIF Vault room in a  secure cabinet. Only staff with the proper authorization will be provided with access.  All NCUA Exam reports will be maintained under the control of the Risk/Security  Officer, all sensitive data will be protected and only staff with the proper authorization  will be provided with access to a minimum of the data that is required to perform their  responsibilities.  All other Audit reports will be maintained under the control of the Internal Auditor and  the Risk/Security officer, all sensitive data will be protected and only staff with the  proper authorization will be provided with access to a minimum of the data that is  required to perform their responsibilities.  Vital accounting records are maintained by CFO and the controller. Only staff with the  proper authorization will be provided with access.  Employee records are maintained in the Human Resources department. Access to the  department is limited to HR staff and controlled via card access control.  All member records that include non-public member information records are stored in the  CIF vault room. The access to the vault room is restricted to authorized staff only and  controlled through card access control. Requests for files from authorized staff is  properly documented and tracked.   Member data (in any media format) must be stored out of sight when not in use. If it  contains highly sensitive (nonpublic information) or confidential data, it should be locked  up in a secure area.  Guidelines for Sensitive Data on Laptops:  The storage of sensitive data in portable devices, such as laptops, that may be removed  from FAFCU and not protected by any physical security is not allowed unless properly  encrypted or password protected.  Staff members shall not take shared portable equipment such as laptop computers out of  the office without the informed consent of their department manager. Informed consent  means that the manager knows what equipment is leaving, what data is on it, and for what  purpose it will be used. All data contained on the laptop must be encrypted or password  protected  Staff members using laptop or desktop computers out of the office must safeguard  member Confidential Information. Computers must be password protected and access by  others controlled to avoid misuse and unauthorized access and exposure to member data.   Guidelines for Confidential Information in E-Mails:  Staff members are not permitted to transmit confidential information. If it is necessary to  transmit nonpublic or confidential information, it must be in compliance with procedures  and either encrypted or password protected. Staff members are required to take steps  reasonably intended to ensure that information is delivered to the proper person who is  authorized to receive such information for a legitimate use.  In the event you must send an e-mail that contains confidential information, the email  may be encrypted by typing the word “Encrypt” in the subject line.  The email and any  attachments will be sent encrypted.  Data Encryption  All files stored on First Atlantic’s servers are to be encrypted using at minimum AES 256  standard. This standard is also to be used when transmitting and storing member  information on networks, devices, and systems.   Physical Security Standards:  Computer and workstations are not to be left unattended. The PC must be locked or  signed off upon leaving the workstation. Passwords must be used to sign into the  network, Core application and any other critical system. Non-public member and  confidential information should be protected by encryption.  Printed documents must not be left unattended to preserve the sensitive of confidential  information.  Fax documents must not be left unattended to preserve the sensitive of confidential  information.  Guidelines for Reporting Loss of Confidential Information:  If sensitive First Atlantic Federal Credit Union information is lost, disclosed to  unauthorized parties, or suspected of being lost or disclosed to unauthorized parties, the  IS Manager, Security Officer and CEO must be notified immediately.  If any unauthorized use of FAFCU’s information systems has taken place, or is suspected  of taking place, the IS Manager must likewise be notified immediately. Similarly,  whenever passwords or other system access control mechanism are lost, stolen, or  disclosed, or are suspected of being lost, stolen, or disclosed, the IS Manager must be  notified immediately.  Because it may indicate a computer virus infection or similar security problem, all  unusual systems behavior, such as missing files, frequent system crashes, misrouted  messages, and the like must also be immediately reported. The specifics of security  problems should not be discussed widely but should instead be shared on a need-to-know  basis. The IS manager is responsible to advise CEO and Security Officer.  Disposal of Confidential Data:  All sensitive and confidential data (paper based or electronic) must be maintained in a  secured area or shredding bin until it can be shredded or properly destroyed in  compliance with disposal policies. Policies prohibit employees from discarding media  containing sensitive information along with regular trash to avoid accidental disclosure.   All nonpublic member or confidential information is to be shredded. Disposal in  recycling or regular trash bins is strictly prohibited.  Electronic Devices:   All electronic equipment that has a storage device or persistent memory, such as desk top  computers, laptops, servers, personal data assistants (PDAs), cell phones, printers,  copiers, routers, switches, firewall hardware, etc. Electronic devices or hard drives such  as magnetic tapes, diskettes, CDs, DVDs and USB storage devices must be erased so that  the data-containing component is unreadable, before the item is disposed of via trash or  recycling.  Electronic Media:   All media on which electronic data can be stored, including, but not limited to hard  drives, magnetic tapes, diskettes, CDs, DVDs and USB storage devices. Electronic  devices or hard drives temporarily leaving the FAFCU for repair must have their data  encrypted or removed.  Software and Data Files:  All software and data files must be removed by FAFCU-approved procedures from  electronic devices and electronic media that are surplus or transferred from one FAFCU  employee to another employee having different software and data access privileges.  When electronic devices are sent outside FAFCU for repair, all data must be either  encrypted or removed. Electronic devices or media being transferred within the FAFCU  (between departments or employees having different software and data access privileges)  must have their data removed.       IS&T Responsibilities:  The IS Manager shall be responsible for the administration of access controls to all  company computer systems. The IS Manager will process additions, deletions, and  changes upon receipt of a written request from the end user’s supervisor. Deletions may  be processed by an oral request prior to receipt of the written request on an emergency  basis.   Monitor compliance with Internet security requirements, including hardware, software,  and data safeguards. IS staff must also provide administrative support and technical  guidance to management on matters related to Internet security.  Annually conduct a risk assessment of Network to determine both risks and  vulnerabilities.  Ensures that all systems are scanned using Virus scanner.   Monitor that appropriate security measures are implemented on these systems in a  manner consistent with the level of information sensitivity.  Monitor that user access controls are defined on these systems in a manner consistent  with the need-to-know.  FAFCU Staff Responsibility:  FAFCU information owners must see to it that data is managed in a manner consistent  with in-house sensitivity classifications.  All employees must comply with the Clean Desk Requirements:  Securing sensitive and confidential papers, media, and other assets when not in use.   Securing sensitive information, laptops, smartphones, personal digital assistants (PDAs),  and other valuable items when not in use.   Personal computers and computer terminals should be protected by authentication codes  and other controls when not in use.    Passwords must be kept confidential.  Wrongful or careless disclosure and discussion of privileged information  Maintaining a neat work environment.    In the teller area, removing cash, negotiable instruments, etc. from the work area as soon  as practicable and placing them in designated secure areas.  Preserve confidentiality of member information for over the teller counter and drive  updrive-up transactions – unauthorized individuals could be listening.  Putting away non-essential documents and items when hosting a visitor in the work area.  Putting away documents or electronic media containing member and proprietary credit  union information whenever an extended absence (i.e., lunchtime, break, committee  meeting, etc.) from the work area is anticipated.    Never send confidential and protected information through e-mail without encryption or  password security.  Discard items with confidential information in designated secure shred bins.   Promptly return any documents and files when they are no longer needed.   In the teller area, promptly sell excess cash to the vault.   Remove member or credit union confidential information from your desktop, bookcase,  credenza, or other location that can be seen by the general public during any extended  absence. This also applies to platform staff and managers when they must leave their  desk with members there and to go to the teller area.  Always clear your desktop before you go home, securing appropriate items.    Discipline for non-compliance:  As an employee of First Atlantic, all staff members are required to maintain the security  and confidentiality of all non-public information in its possession.  Failure to safeguard  the information will result in disciplinary action.  Violation of Data Confidentiality Procedures  1st  offense in rolling 12-month period  Disciplinary Action  Written Warning  2nd  offense in rolling 12-month period  3rd   offense in rolling 12-month period  Written Warning – PIP   Dismissal  Violations of this procedure will be measured on a rolling 12-month basis.  Management  reserves the right to use its discretion in applying this procedure under special or unique  circumstances.  Managers Responsibility  Staff under their supervision implements security measures as defined in this document.  Staff under their supervision delete sensitive (confidential) data from their files when the  data is no longer needed or useful.  Staff under their supervision authorized to use personal computers are aware of and  comply with the policies and procedures outlined in all First Atlantic Federal Credit  Union documents that address information security.  Staff and contractor personnel under their supervision complete the pre-exit clearance  process upon their official termination of employment or contractual agreement.  Staff and contractor personnel under their supervision make backup copies of sensitive,  critical, and valuable data files as often as is deemed reasonable.  End of Day Checklist required by all department managers.  Discipline for noncompliance:  When a written warning must be given to an employee, the department manager will  review with the Human Resources Department. It should be the intent of both the  supervisor and employee to work together in an attempt to avoid future violations.   Written warnings must be completed no later than 48 hours following the identification  of the violation.