Penn Computing
Computing Menu Computing A-Z
Computing Home Information Systems & Computing Penn

SSN IT Privacy Initiative

Overview

The Social Security Number (SSN) IT Privacy Initiative is a collaborative project between Data Administration and the Office of Audit and Compliance to reduce SSN-related risks in IT systems. The benefits generally are to reduce the risk of identity theft and to make progress on Penn’s announced SSN-related goals and the SSN Action Plan.

The primary objective of the effort is to eliminate the unnecessary use and dissemination of SSNs from administrative systems and the Data Warehouse, usually to individuals and systems managed locally within Schools and Centers. In many cases, this will involve converting to PennID instead of SSNs to uniquely identify individuals.

Secondary objectives include:

  1. Investigating the use and appplication of web scanning tools that can uncover SSN vulnerabilities on the Penn web not related to administrative systems and processes.
  2. Reviewing policies and procedures governing access to applications and data stores that contain SSNs and making improvements where needed.

SSN Usage Survey

The first phase of the project is to gather information through interviews and surveys aimed at determining where SSNs are extracted (generally) from central administrative systems and the Data Warehouse. This information gathering will result in an inventory of applications, extracts and queries. Through this inventory, we will attempt to determine whether there is a need for recipients to have access to SSNs and if not, what process and timeline is appropriate for eliminating their receipt of such sensitive data. If access to such data is required, we will also evaluate the security in place to protect it.

Follow this link to complete the SSN Usage Survey (PennKey Login required).

Related Resources

Privacy of Personal Information - Social Security Numbers

Strategies for Schools and Centers (PennKey Login required)

top

Information Systems and Computing
University of Pennsylvania
Comments & Questions


University of Pennsylvania Penn Computing University of Pennsylvania Information Systems & Computing (ISC)
Information Systems and Computing, University of Pennsylvania