|
Vice President for Finance
|
|
|
|
![]() |
University
of Louisville Non-Public Personal Information Policy
On November 12, 1999,
the Gramm-Leach-Bliley Act (GLBA) was passed into law. The Federal Trade
Commission requires Financial Institutions to ensure the security and confidentiality
of Non-Public Personal Information (NPI) as of May 23, 2003. For purposes
of administering the act, Colleges and Universities must ensure that NPI
is secure, confidential, and protected from unauthorized access and threats.
The following safeguarding policies and practices are administered at the
University of Louisville (U of L).
|
|||||
Check references prior to hiring employees who will have access to customer information. Require employees to sign an agreement to follow U of L’s confidentiality and security standards for handling customer information. Employees are trained to take basic steps to maintain security, confidentiality, and integrity of customer information, such as: __locking rooms and cabinets containing paper records __properly shred documents with sensitive information __using password activated screen savers __using strong passwords __routinely require password prompted changes __encryption of sensitive customer information when it is transmitted electronically over networks or stored online __referring calls or other request for customer information to designated individuals who have had safeguards training, and recognizing fraudulent attempts to obtain customer information and reporting to appropriate law enforcement agencies. __limits access to customer information to employees who have a business reason for seeing it. __Consumers are cautioned against transmission of sensitive data via email. Advise customers to utilize password protection in transmitting sensitive information. |
Information Systems
Security is maintained throughout the life cycle of customer information from data entry to data disposal as follows:
__Electronic information is stored in secure locked computer centers, protected against destruction and damage form potential physical hazards. __Electronic customer information is maintained on a physically secure dedicated server accessible by password. __Sensitive information is not stored on a machine with a non secure internet connection. __Data is secured on back-up media and archived for disaster recovery. __E-Commerce and other Credit Card data is collected utilizing servers that employ top level SSL encryption software. __Customer information is disposed of in a secure manner; outdated information residing on hardware no longer in use is completely destroyed. |
Managing System Failures
The following procedures are endorsed to prevent, detect, and respond to attacks, intrusions or other system failures.
__IT maintains a written contingency plan to address any breaches of physical, administrative or technical safeguards __Routinely applies vendor’s software patches that resolve vulnerabilities, and maintain automatic anti-virus software updates. __IT maintains up-to-date firewalls and provides central management of security tools for IT employees. __Routinely backs-up all non-personal customer information. __Notifies customers promptly if their non-public personal information is subject to loss damage or unauthorized access. |
