Home > U Pennsylvania Drafts Policy to Minimize Use of SSNs

News

U Pennsylvania Drafts Policy to Minimize Use of SSNs

6/7/2007

The University of Pennsylvania has drafted a policy designed to minimize the use of Social Security numbers at the school after deciding the numbers constitute "sensitive data that can be abused by identity thieves to commit fraud."

The draft policy said, "This abuse can cause privacy harm to Penn constituents and can create compliance and reputational risks to Penn itself."

The policy asks staff, faculty, and university contractors to inventory their online and offline Social Security numbers and take steps to tackle the problem, including:

1. Eliminate the data altogether;
2. Convert it to the school's numerical ID system, PennID;
3. Truncate the data to display only the last four digits; and
4. When the complete SSN is necessary, ensure strict security controls to protect the full data.

In a statement, Penn Vice President of Information Systems and Computing Robin Beck invited the public to comment to the policy by June 21.

"Penn has been committed to a multi-year effort to minimize the use of SSN  and there are now additional tools  that enable faculty and staff to identify where Social Security numbers reside on their systems and to securely delete, convert, or truncate such information," she wrote.

"This draft policy has been created in recognition of the risks that Social Security Numbers present, as well the opportunities to reduce the availability of such data at Penn."

Read More:


Paul McCloskey is a contributing editor for the Campus Technology group of publications.

Cite this Site

Paul McCloskey, "U Pennsylvania Drafts Policy to Minimize Use of SSNs," Campus Technology, 6/7/2007, http://www.campustechnology.com/article.aspx?aid=48451

copy text (above) for proper citation



Recommended Reading
  • Utah Rolls Out Online Document Proofreading

    The University of Utah has acquired a site license of CyProof's ErrNET for online document proofreading. ErrNET runs on CyProof's servers and is accessed through the user's Web browser. To check a document, users upload their files to the Web site, the cost is calculated, payment is requested, the document is processed, and the results are presented for download. The service works with PDF files.

  • Payment Standard for Web Apps Goes Live

    A new payment card industry (PCI) standard for Web application firewalls and source code went into effect July 1. PCI Industry Data Security standard 6.6 gives merchants a framework to ensure that the point-of-sale information uploaded into browser-based applications is sound from "top to bottom," the organization's literature said.

  • U Texas San Antonio To Deploy Wireless Outdoor Emergency Notifications

    The University of Texas at San Antonio has selected Cooper Notification's Wireless Audio Visual Emergency System (WAVES) Mass Notification System (MNS) for its outdoor campus emergency notification system. Through WAVES campus public safety departments can broadcast targeted voice alerts via "Giant Voice" to students, faculty, staff, and visitors.

  • Moraine Valley CC Revamps Administrative Systems

    Moraine Valley Community College in Illinois has selected Datatel Colleague and ActiveCampus Portal software to replace a legacy administration system. A committee consisting of campus-wide representatives chose Datatel after an 18-month evaluation of administrative software systems.

  • Project Wonderland: Good Avatars Make Good Neighbors

    Sun Microsystems's Project Darkstar and the Wonderland Toolkit for building 3D spaces show why virtual reality is better for education than video conferencing. And Project Wonderland has announced its first education space.

  • Sun, Stanford Working To Archive History

    In May in San Francisco, experts from leading universities, libraries, and research institutions around the world met as part of an ongoing effort to address a pressing issue: archiving the world's history, right up to today.