In brief, Penn's policies require every individual who works with sensitive data to share in the responsibility for keeping that data secure. Some important elements of the policies include:

  • Never use SSN's as an identifier unless absolutely necessary. Choose Penn ID number or another alternative if at all possible.
  • If SSN's are necessary, then data containing SSN's must be encrypted at all times.
  • A computer that stores sensitive data is subject to additional security requirements beyond, eg, an administrative workstation.

