Identity theft ‘red flags’ and information security policies approved

By SHANNON O. WELLS

Faculty Assembly approved two policies — related to identity theft and Pitt IT security — during its April 9 meeting, which then passed Senate Council on April 17. Both were passed with no opposition.

The Identity Theft/“Red Flags” policy is related to the Fair and Accurate Credit Transactions Act. Angie Zack, knowledge integration coordinator in the Health Sciences Library System, said the new policy draft was developed to meet the federal “red flags rule” requirement that financial institutions and creditors adopt policies and procedures to help detect the warning signs, or “red flags,” of identity theft.

The University has identified student accounts associated with federal student-assistance programs as covered accounts and conducts annual risk assessments of those applications associated with student financial accounts to ensure their security.

When policy work is complete, the Compliance, Investigations and Ethics Office will ensure that designated employees at senior management level are responsible for the implementation and administration of the program, staff are properly trained, and appropriate oversight of service-provider arrangements are exercised.

Tom Songer, assistant professor in the Department of Epidemiology, asked how the policy affects interacting with resources such as the UPMC Health Plan and TIAA retirement-savings plans as opposed to “entities that are outside of the University.

“I'm just curious about how this red flag and then the security policy that follows, how those indirect relationships with outside parties are covered under this policy,” he asked.

Tony Graham from Pitt’s policy office said a bullet point in the policy addresses providing authority to CIE to develop the program to also cover processes that the University must validate agreements with a person or other entity that provides a service directly to the University.

“So that would be … Pitt Pay would be an example,” he said. “The policy provides that responsibility to (the compliance office) to make sure that they have a process set up to evaluate those types of agreements. And that would be included in the Identity Theft Prevention Program.”

Songer said his department faces challenges dealing with third parties, “where our safest option lies by accessing the third parties through my.pitt.edu or by accessing those parties individually,” he said. “And it's not part of this policy, but I think that's something that will be an important concern for the faculty and staff and students in the future.”

Information Security Policy

The Information Security Policy draft was developed to establish a comprehensive information-security framework to safeguard the confidentiality, integrity and availability of data the University produces, owns or maintains.

This policy also provides responsibilities for the components of the information-security framework that protect, for example, student records, research data, intellectual property, health records and other information in any physical or electronic form.

The Senate Computing and Information Technology Committee reviewed and unanimously approved the draft at its March meeting without questions. The draft also has been shared with an academic leadership team, the Operations Council, and was available for public comment until April 10.

Responding to a question about Pitt’s information security policy history, Brian Hart, policies and governance coordinator for Pitt IT, said the University has had no comprehensive security policy.

“There are a number of policies that have touched on information-security issues, but the purpose of this is to be a framework for all of the things that deal with information security, both at the University policy level as well as the operational level, in terms of operating standards and those kinds of things,” he said.

Citing the recent AI Acceptable Use Document that Pitt IT published as an example, the policy draft provides the framework that accommodates that.

“Some of the question before about privacy and vendor responsibilities will end up being addressed through this in terms of the operating standards and things that are hanging from it,” he said. “Again, it's a framework policy. It's not replacing anything. It's not introducing anything new, but it is consolidating all that we've had before so that we don't have to address information security issues in every University policy that comes forward.”

Shannon O. Wells is a writer for the University Times. Reach him at shannonw@pitt.edu.

 

Have a story idea or news to share? Share it with the University Times.

Follow the University Times on Twitter and Facebook.