806 - Protected Information
806.1 PURPOSE AND SCOPE
The purpose of this policy is to provide guidelines for the access, transmission, release and security of protected information by members of the Hartwell County Sheriff’s Department. This policy addresses the protected information that is used in the day-to-day operation of the Office and not the public records information covered in the Records Maintenance and Release Policy.
806.1.1 DEFINITIONS
Protected information — Any information or data that is collected, stored or accessed by members of the Hartwell County Sheriff’s Department and is subject to any access or release restrictions imposed by law, regulation, order or use agreement. This includes all information contained in federal, state or local law enforcement databases that is not accessible to the public.
806.2 POLICY
Members of the Hartwell County Sheriff’s Department will adhere to all applicable laws, orders, regulations, use agreements and training related to the access, use, dissemination and release of protected information.
806.3 RESPONSIBILITIES
The Sheriff shall select a member of the Office to coordinate the use of protected information.
The responsibilities of this position include but are not limited to:
- Ensuring member compliance with this policy and with requirements applicable to protected information, including requirements for the National Crime Information Center (NCIC) system, National Law Enforcement Telecommunications System (NLETS), Department of Motor Vehicles (DMV) records, and California Law Enforcement Telecommunications System (CLETS).
- Developing, disseminating, and maintaining procedures that adopt or comply with the U.S. Department of Justice's current Criminal Justice Information Services (CJIS) Security Policy. See the Hartwell County Sheriff’s Department CJIS Access, Maintenance, and Security Policy for additional guidance.
- Developing, disseminating, and maintaining any other procedures necessary to comply with any other requirements for the access, use, dissemination, release, and security of protected information.
- Developing procedures to ensure training and certification requirements are met.
- Resolving specific questions that arise regarding authorized recipients of protected information.
- Ensuring security practices and procedures are in place to comply with requirements applicable to protected information.
Access to Protected Information
806.4 ACCESS TO PROTECTED INFORMATION
Protected information shall not be accessed in violation of any law, order, regulation, user agreement, Hartwell County Sheriff’s Department policy, or training. Only those members who have completed applicable training and met any applicable requirements, such as a background check, may access protected information, and only when the member has a legitimate work-related reason for such access.
Media Storage and Access
806.4.1 MEDIA STORAGE AND ACCESS
Controls shall be in place to protect electronic and physical media containing CJI while at rest, stored, or actively being accessed. “Electronic media” includes memory devices in laptops and computers (hard drives) and any removable, transportable digital memory media, such as magnetic tape or disk, backup medium, optical disk, flash drives, external hard drives, or digital memory card. “Physical media” includes printed documents and imagery that contain CJI.
To protect CJI, the Hartwell County Sheriff’s Department and County IT Department personnel shall:
- Securely store electronic and physical media within a physically secure or controlled area. A secured area includes a locked drawer, cabinet, or room.
- Restrict access to electronic and physical media to authorized individuals.
- Ensure that only authorized users remove printed form or digital media from the CJI.
- Physically protect CJI until media end of life. End of life CJI is destroyed or sanitized using approved equipment, techniques and procedures.(See Sanitization Destruction Policy)
- Not use personally owned information system to access, process, store, or transmit CJI.
- Not utilize publicly accessible computers to access, process, store, or transmit CJI. Publicly accessible computers include but are not limited to: hotel business center computers, convention center computers, public library computers, public kiosk computers, etc.
- Store all hardcopy CJI printouts maintained by the Hartwell County Sheriff’s Department and County IT Department in a secure area accessible to only those employees whose job function require them to handle such documents.
- Safeguard all CJI by the Hartwell County Sheriff’s Department against possible misuse by complying with the Physical Protection Policy, Personally Owned Device Policy, and Disciplinary Policy.
- Take appropriate action when in possession of CJI while not in a secure area:
- CJI must not leave the employee's immediate control. CJI printouts cannot be left unsupervised while physical controls are not in place.
- Precautions must be taken to obscure CJI from public view, such as by means of an opaque file folder or envelope for hard copy printouts. For electronic devices like laptops, use session lock use and /or privacy screens. CJI shall not be left in plain public view. When CJI is electronically transmitted outside the boundary of the physically secure location, the data shall be immediately protected using encryption.
i. When CJI is at rest (i.e. stored electronically) outside the boundary of the physically secure location, the data shall be protected using encryption. Storage devices include external hard drives from computers, printers and copiers used with CJI. In addition, storage devices include thumb drives, flash drives, back-up tapes, mobile devices, laptops, etc.
ii. When encryption is employed, the cryptographic module used shall be certified to meet FIPS 140-2 standards.
- Lock or log off computer when not in immediate vicinity of work area to protect CJI. Not all personnel have same CJI access permissions and need to keep CJI protected on a need-to-know basis.
- Establish appropriate administrative, technical and physical safeguards to ensure the security and confidentiality of CJI.(See Physical Protection Policy) Transportation of Information
806.4.2 TRANSPORTATION OF INFORMATION
Controls shall be in place to protect electronic and physical media containing CJI while in transport (physically moved from one location to another) to prevent inadvertent or inappropriate disclosure and use. “Electronic media” means electronic storage media including memory devices in laptops and computers (hard drives) and any removable, transportable digital memory media, such as magnetic tape or disk, backup medium, optical disk, flash drives, external hard drives, or digital memory card.
Dissemination to another agency is authorized if:
- The other agency is an Authorized Recipient of such information and is being serviced by the accessing agency, or
- The other agency is performing personnel and appointment functions for criminal justice employment applicants.
The Hartwell County Sheriff’s Department and County IT Department personnel shall:
- Protect and control electronic and physical media during transport outside of controlled areas.
- Restrict the pickup, receipt, transfer and delivery of such media to authorized personnel.
The Hartwell County Sheriff’s Department and County IT Department personnel will control, protect, and secure electronic and physical media during transport from public disclosure by:
- Use of privacy statements in electronic and paper documents.
- Limiting the collection, disclosure, sharing and use of CJI.
- Following the least privilege and role-based rules for allowing access. Limit access to CJI to only those people or roles that require access.
- Securing hand carried confidential electronic and paper documents by:
- Storing CJI in a locked briefcase or lockbox.
- Only viewing or accessing the CJI electronically or document printouts in a physically secure location by authorized personnel.
- For hard copy printouts or CJI documents:
i. Package hard copy printouts in such a way as to not have any CJI information viewable.
ii. That are mailed or shipped, agency must document procedures and only release to authorized individuals. DO NOT MARK THE PACKAGE TO BE MAILED CONFIDENTIAL.
Packages containing CJI material are to be sent by method(s) that provide for complete shipment tracking and history, and signature confirmation of delivery. (Agency Discretion)
- Not taking CJI home or when traveling unless authorized by the Records Supervisor. When disposing confidential documents, use a shredder.
Electronic Media Sanitization and Disposal
806.4.3 ELECTRONIC MEDIA SANITIZATION AND DISPOSAL
The agency shall sanitize, that is, overwrite at least three times or degauss electronic media prior to disposal or release for reuse by unauthorized individuals. Inoperable electronic media shall be destroyed (cut up, shredded, etc.). The agency shall maintain written documentation of the steps taken to sanitize or destroy electronic media. Agencies shall ensure the sanitization or destruction is witnessed or carried out by authorized personnel. Physical media shall be securely disposed of when no longer required, using formal procedures. For end of life media policy, refer to “Sanitization Destruction Policy”.
806.4.4 BREACH NOTIFICATION AND INCIDENT REPORTING
The agency shall promptly report incident information to appropriate authorities.
Information security events and weaknesses associated with information systems shall be communicated in a manner allowing timely corrective action to be taken. Incident-related information can be obtained from a variety of sources including, but not limited to, audit monitoring, network monitoring, physical access monitoring, and user/administrator reports.
Penalties for Misue of Records
806.4.5 PENALTIES FOR MISUSE OF RECORDS
It is a misdemeanor to furnish, buy, receive or possess Department of Justice criminal history information without authorization by law (Penal Code § 11143).
Release or Dissemination of Protected Information
806.5 RELEASE OR DISSEMINATION OF PROTECTED INFORMATION
Protected information may be released only to authorized recipients who have both a right to know and a need to know.
A member who is asked to release protected information that should not be released should refer the requesting person to a supervisor or to the Records Manager for information regarding a formal request.
Unless otherwise ordered or when an investigation would be jeopardized, protected information maintained by the Office may generally be shared with authorized persons from other law enforcement agencies who are assisting in the investigation or conducting a related investigation. Any such information should be released through the Records Division to ensure proper documentation of the release (see the Records Maintenance and Release Policy).
Review of Criminal Offender Record – Refer to California DOJ
806.5.1 REVIEW OF CRIMINAL OFFENDER RECORD
Individuals requesting to review their own California criminal history information shall be referred to the Department of Justice (Penal Code § 11121).
Individuals shall be allowed to review their arrest or conviction record on file with the Office of The Sheriff after complying with all legal requirements regarding authority and procedures in Penal Code § 11120 through Penal Code § 11127 (Penal Code § 13321).
Improperly Disclosed, Lost, or Not Received Criminal Justice Info
806.5.2 IMPROPERLY DISCLOSED, LOST, OR NOT RECEIVED CRIMINAL JUSTICE
INFORMATION PROCEDURES If CJI is improperly disclosed, lost, or reported as not received, the following procedures must be immediately followed:
- Personnel shall notify his/her supervisor or Agency CLETS Coordinator, and an incident-report form must be completed and submitted within 24 hours of discovery of the incident. The submitted report is to contain a detailed account of the incident, events leading to the incident, and steps taken/to be taken in response to the incident. (Agency Discretion)
- The supervisor will communicate the situation to the Records Supervisor to notify of the loss or disclosure of CJI records.
- The Records Supervisor will ensure the CSA ISO (CJIS System Agency Information Security Officer) is promptly informed of security incidents.
- The CSA ISO will:
- Establish a security incident response and reporting procedure to discover, investigate, document, and report to the CSA, the affected criminal justice agency, and the FBI CJIS Division ISO major incidents that significantly endanger the security or integrity of CJI.
- Collect and disseminate all incident-related information received from the Department of Justice (DOJ), FBI CJIS Division, and other entities to the appropriate local law enforcement POCs within their area.
- Act as a single POC for their jurisdictional area for requesting incident response assistance.
806.5.3 TRANSMISSION GUIDELINES
Protected information, such as restricted Criminal Justice Information (CJI), which includes Criminal History Record Information (CHRI), should not be transmitted via unencrypted radio. When circumstances reasonably indicate that the immediate safety of deputies, other office members, or the public is at risk, only summary information may be transmitted.
In cases where the transmission of protected information, such as Personally Identifiable Information, is necessary to accomplish a legitimate law enforcement purpose, and utilization of an encrypted radio channel is infeasible, a MDT or office-issued cellular telephone should be utilized when practicable. If neither are available, unencrypted radio transmissions shall be subject to the following:
- Elements of protected information should be broken up into multiple transmissions, to minimally separate an individual’s combined last name and any identifying number associated with the individual, from either first name or first initial.
- Additional information regarding the individual, including date of birth, home address, or physical descriptors, should be relayed in separate transmissions.
Nothing in this policy is intended to prohibit broadcasting warrant information.
Security of Protected Information
806.6 SECURITY OF PROTECTED INFORMATION
The Sheriff will select a member of the Office to oversee the security of protected information.
The responsibilities of this position include but are not limited to (see the CJIS Access, Maintenance, and Security Policy for additional guidance):
- Developing and maintaining security practices, procedures, and training.
- Ensuring federal and state compliance with the CJIS Security Policy and the requirements of any state or local criminal history records systems.
- Establishing procedures to provide for the preparation, prevention, detection, analysis, and containment of security incidents, including computer attacks.
- Tracking, documenting, and reporting all breach of security incidents to the Sheriff and appropriate authorities.
806.6.1 MEMBER RESPONSIBILITIES
Members accessing or receiving protected information shall ensure the information is not accessed or received by persons who are not authorized to access or receive it. This includes leaving protected information, such as documents or computer databases, accessible to others when it is reasonably foreseeable that unauthorized access may occur (e.g., on an unattended table or desk; in or on an unattended vehicle; in an unlocked desk drawer or file cabinet; on an unattended computer terminal).
806.7 TRAINING
California Religious Freedom Act
806.8 CALIFORNIA RELIGIOUS FREEDOM ACT
Members shall not release personal information from any agency database for the purpose of investigation or enforcement of any program compiling data on individuals based on religious belief, practice, affiliation, national origin or ethnicity (Government Code § 8310.3).
Computers and Digital Evidence