Educause Security Discussion mailing list archives

Re: Bare Social Social Security Numbers


From: "Thomas R. Davis" <tdavis () IU EDU>
Date: Mon, 27 Mar 2006 12:03:03 -0500

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

On Mar 27, 2006, at 11:39 AM, Geoffrey S. Nathan wrote:

Suppose a file was stolen/accessed containing only social security
numbers with no names attached.  Would this constitute a security
breach
necessitating notification of those whose numbers were compromised?
(Leaving aside the question of whether the theft/access itself is a
breach).

The Indiana disclosure/notification law that goes into effect July
1st of this year only requires notification if the SSN is exposed
along with an individual's first and last name *or* first initial and
last name.

Unless I'm missing something obvious, an SSN by itself would be of
little value.

- --
Tom Davis, IT Security Officer, CISSP, CISM, GCIA
Office of the VP for Information Technology, Indiana University
PGP key or S/MIME certificate: https://itso.iu.edu/Tom_Davis


-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.2.2 (Darwin)

iD8DBQFEKBrMcxDtdAa0EQ0RApMeAJ9z7hDCslKuA3JDyLTkDsztzeY83ACeN+ZT
IcHqwhLEusUoZBrbCGxEwe0=
=QLIK
-----END PGP SIGNATURE-----

Current thread: