nevada legislature audit division obtaining, storing, and using confidential data

9
NEVADA LEGISLATURE AUDIT DIVISION Obtaining, Storing, and Using Confidential Data

Upload: monica-ball

Post on 18-Dec-2015

214 views

Category:

Documents


0 download

TRANSCRIPT

Page 1: NEVADA LEGISLATURE AUDIT DIVISION Obtaining, Storing, and Using Confidential Data

NEVADA LEGISLATUREAUDIT DIVISION

Obtaining, Storing, and Using Confidential Data

Page 2: NEVADA LEGISLATURE AUDIT DIVISION Obtaining, Storing, and Using Confidential Data

ENTRANCE CONFERENCELETTER OUTLINING OUR ACCESS TO EVERYTHING

Page 3: NEVADA LEGISLATURE AUDIT DIVISION Obtaining, Storing, and Using Confidential Data

ENTRANCE CONFERENCELetter outlining our confidentiality of work we collect

All working papers from an audit are confidential

Page 4: NEVADA LEGISLATURE AUDIT DIVISION Obtaining, Storing, and Using Confidential Data

IF ALL ELSE FAILS

• Keep data on site at agency

• Review data or documentation with the agency

• Obtain a Legislative Counsel opiniono Usually results in the agency obtaining an

Attorney General opinion

Page 5: NEVADA LEGISLATURE AUDIT DIVISION Obtaining, Storing, and Using Confidential Data

KEEPING DATA SAFE

Page 6: NEVADA LEGISLATURE AUDIT DIVISION Obtaining, Storing, and Using Confidential Data

KEEPING DATA SAFE

• IronKey continuedo Contractor for Nevada dropped USB drive,

containing confidential data, in parking lot.o She is no longer a contractor for the state.

• Truecrypt-now defunct (closed down with no explanation)

• BitLocker (native windows product)

• CISCO VPNo Hit and miss when using TeamMate

Page 7: NEVADA LEGISLATURE AUDIT DIVISION Obtaining, Storing, and Using Confidential Data

USING CONFIDENTIAL DATA

• Two levels of “confidential”

o All our work is confidential

o SS#, HIPA, etc.

Page 8: NEVADA LEGISLATURE AUDIT DIVISION Obtaining, Storing, and Using Confidential Data

USING CONFIDENTIAL DATA

Page 9: NEVADA LEGISLATURE AUDIT DIVISION Obtaining, Storing, and Using Confidential Data

USING CONFIDENTIAL DATA

• Normally not kept in work papers

o Social Security numbers

Keep names & other data

Annotate with auditor observation