Educause Security Discussion mailing list archives

Re: Storing SSN on file server


From: "Gioia, Matthew P." <MGioia () STLCC EDU>
Date: Mon, 19 Mar 2018 16:48:14 +0000

Has anyone used SharePoint and web folders for this type of use-case? That is my envisioned solution right now - use 
TDE on the SharePoint DB, and secure connections w/ TLS. This seems to be the most elegant solution since you could 
still map the folders to a drive - but I am sure I am missing something here.

Regards,

Matthew Gioia
314.539.5075
Information Security, IT
St. Louis Community College

From: The EDUCAUSE Security Constituent Group Listserv [mailto:SECURITY () LISTSERV EDUCAUSE EDU] On Behalf Of Barton, 
Robert W.
Sent: Monday, March 19, 2018 11:41 AM
To: SECURITY () LISTSERV EDUCAUSE EDU
Subject: Re: [SECURITY] Storing SSN on file server

Morning,

Although not exactly the same, we had this kind of debate over student complaint forms.  For the short term, we moved 
to a cloud solution/form for their needs.  We are looking to move to a AaaS solution in the coming months.

Robert W. Barton
Director of Information Security
Lewis University
One University Parkway
Romeoville, IL  60446-2200
815-836-5663

From: The EDUCAUSE Security Constituent Group Listserv [mailto:SECURITY () LISTSERV EDUCAUSE EDU] On Behalf Of Minh 
Nguyen
Sent: Monday, March 19, 2018 11:19 AM
To: SECURITY () LISTSERV EDUCAUSE EDU
Subject: [SECURITY] Storing SSN on file server

Hello All,

I have several users who need to store social security numbers in spreadsheets and PDF's as part of their work.   They 
cannot get rid of the SSN because the federal government requires the SSN for reporting purposes.   This group has 
access to my file server where they have been storing the Excel and PDF files.   I am not comfortable with this.   Does 
anyone have any suggestions on how I can securely save these files?   I could ask them to encrypt every single Excel 
and PDF file, but I don't know if they will do this.     The files does have to be stored on our file server for backup 
purposes since we do not backup local desktop.   In addition, the files are shared among a few users, so it can't be 
store locally.

Any other suggestions?

Thanks
Minh

===========================================
Minh T. Nguyen, CISSP
Graduate Studies - Director of Information Technology
University of California, Davis
Google Voice: (530) 454-7647
E-Mail: mtnguyen () ucdavis edu<mailto:mtnguyen () ucdavis edu>
LinkedIn:  www.linkedin.com/in/DiverMinh<http://www.linkedin.com/in/DiverMinh>
===========================================


This message (including any attachments) is intended only for the use of the individual or entity to which it is 
addressed and may contain information that is non-public, proprietary, privileged, confidential, and exempt from 
disclosure under applicable law or may constitute as attorney work product. If you are not the intended recipient, you 
are hereby notified that any use, dissemination, distribution, or copying of this communication is strictly prohibited. 
If you have received this communication in error, notify us immediately by telephone at (815)-836-5950 and (i) destroy 
this message if a facsimile or (ii) delete this message immediately if this is an electronic communication. Thank you.

Current thread: