Information Security Management and Compliance
This document outlines procedures and protocols for notification of and response to a security breach involving unencrypted electronic personal information processed and/or maintained by the university and its auxiliary organizations.
Any employee or data owner who believes that a security incident has occurred, shall immediately notify the Vice President, Administration and Finance and the Information Security Officer. After business hours, notification shall be made to University Police (562) 985-4101.
Upon notification by an employee, Information Technology Services, or University Police of a suspected unauthorized acquisition of confidential information the Information Security Officer, or the Assistant Information Security Officer, shall promptly notify with the Security Breach Response Planning Group.
The Information Security Officer and/or the Assistant Information Security Officer will conduct an investigation into the security incident to determine whether there has been a security breach. As part of the investigation, and when applicable, the appropriate administrator shall require the data owner to complete and submit an Employee Identification of Stored Data statement to the Information Security Officer or Assistant Information Security Officer. All investigatory work will be documented within an Incident Report.
Upon completion of the investigation, the Information Security Officer or the Assistant Information Security Officer will inform the Security Breach Response Planning Group of the result of the investigation.
If it is determined after investigation that a security breach involving notice triggering information has occurred, the Information Security Officer shall notify the Vice President of Administration and Finance and Office of General Counsel.
If it is determined that a breach is of the appropriate magnitude and may require a press release, the Information Security Officer shall notify the Senior Director, Information Security Management, Associate Vice President, University Relations, Office of the Chancellor and copy the CIO/Assistant Vice Chancellor.
The Information Security Officer or Assistant Information Security Officer will notify the responsible department, confirming the security breach of notice triggering information and provide advice and guidance. The Information Security Officer or Assistant Information Security Officer shall also initiate the campus breach notification process and work closely with the Division Executive or designee of the department responsible for controlling access to, and security of, the breached electronic equipment to ensure the appropriate handling of the breach response and inquiries. The Information Security Officer or Assistant Information Security Officer will provide guidance to designated employees responsible for responding to breach notification inquiries.
The department or office responsible for controlling access to, and security of, the breached electronic equipment shall compile the list of the names of persons whose personal information was, or is reasonably believed to have been, acquired by an unauthorized person. In consultation with the Information Security Officer or the Assistant Information Security Officer , a list of individuals to notify shall be compiled based on the following criteria:
If notices are sent to more than 10,000 individuals, the Information Security Officer or the Assistant Information Security Officer shall notify the following consumer credit reporting agencies:
The process for determining inclusion in the notification group shall be included in the Incident Report.
Individuals whose notice-triggering information has been compromised shall be notified in the most expedient time possible, and without unreasonable delay, consistent with the legitimate needs of law enforcement or any measures necessary to determine the scope of the breach and restore the reasonable integrity of the data system.
The information considered when determining the notification date shall be included within the Incident Report.
The breach notification will provide a brief description of the security breach, a contact for inquiries, and helpful references to individuals regarding identity theft and fraud. The content of the breach notification, and when appropriate, the content of both the web site page and the press release will be reviewed and approved by the Information Security Officer or Assistant Information Security Officer.
With the exception of the Office of Public Affairs, University Police, and Safety, Risk Management & Information Security, university personnel are not authorized to speak on behalf of the university to media personnel or representatives of other outside agencies. All media inquiries or other public affairs inquiries should be directed to the Office of Public Affairs at (562) 985-4134. All other inquiries should be directed to Safety, Risk Management & Information Security at (562) 985-4862 or to the University Police at (562) 985-4101.
A letter shall be printed with official California State University, Long Beach letterhead, addressed to the individual at the last recorded home address, or if only an email address is known, the last recorded email address with the University. Any notices returned with address forwarding information will be re-sent by the responsible department.
If less than 500,000 individuals were affected, or if the cost of disseminating individual notices is less than $250,000, notices shall be sent by first class mail or email address.
If more than 500,000 individuals were affected or if the cost of giving individual notices to `affected individuals is greater than $250,000 or if there is insufficient contact information, the following substitute notification procedures shall be followed:
Subsequent to a security breach notification, the University can expect several inquiries from notified users, their parents/spouse, and security vendors. The Information Security Officer or the Assistant Information Security Officer will provide a written Inquiry Response Guide to be used by the Division Executive, or designee(s), to respond to any phone calls/emails/letters/walk in traffic with inquiries regarding the breach.
The department responsible for controlling access to, and security of, the breached electronic information is responsible for financial and human resources used to notify and respond to the affected individuals.
Subsequent to a breach, the University may be reviewed by a governing state or federal agency or a civil action could be brought against the University. The University office of Safety, Risk Management & Information Security will represent all complaints and agency inquiries submitted to the University as a result of the security breach. Legal counsel will be solicited as needed to respond to complaints or actions. The University is responsible for the payment of fines, penalties, or retributions levied by agencies or the courts..