Policy and Program Guide
The Virginia Department of Social Services uses sensitive information, such as personal, financial and tax data daily to serve individuals and families across Virginia. Some of this information is sensitive. It includes personal and financial details.
This policy explains how we protect that information and what is expected of anyone who uses VDSS systems or data. Keeping information safe helps protect people, maintain trust and ensure services continue without interruption.
مبادئنا التوجيهية
نحن نتبع هذه المبادئ الأساسية عند حماية المعلومات:
- المعلومات هي مورد قيم ويجب حمايتها.
- Access is limited to people who need it to do their jobs.
- يدعم أمن المعلومات كلاً من عملنا وتقنيتنا.
- تعتمد القرارات الأمنية على المخاطر والعملية.
- Policies guide the work, but leaders carry them out.
- Everyone shares responsibility for keeping information safe
Keeping information safe helps:
- حماية العملاء والموظفين
- Maintain public trust
- Ensure services remain available
Information security is a shared responsibility.
من يجب أن يتبع هذه السياسة
This policy applies to all individuals who use VDSS systems or information, including:
- Employees and supervisors
- Local department staff
- المقاولون والمقاولون من الباطن
- Volunteers and interns
- شركاء الأعمال والموردون
مبادئنا التوجيهية
VDSS follows these core principles:
Information is a valuable asset and must be protected
- Access is limited to people who need the information to do their job
- Security supports both daily work and technology
- Security decisions should be practical and risk-based
- السياسات توجه العمل، لكن الفرق تقوم به
- Everyone plays a role in protecting information
المسؤوليات الخاصة بك
If you use VDSS systems or information, you are expected to:
Follow Required Policies
- Following all VDSS security, privacy and acceptable use policies
- إكمال التدريب المطلوب للأمان والخصوصية في الوقت المحدد
- Protecting sensitive information you can access
- الحفاظ على خصوصية كلمات المرور وأمانها
- استخدام التشفير عند إرسال البيانات الحساسة أو تخزينها
- الإبلاغ عن المخاوف الأمنية على الفور
- قم بالتوقيع على اتفاقية الإقرار بسياسة أمن المعلومات وعدم الإفشاء قبل تلقي الوصول.
- Re-acknowledge this agreement each year as part of required training.
You are not expected to fix problems on your own. Reporting concerns quickly helps limit harm and protect people.
Complete Required Training
- New employees must complete security and privacy training within 30 days.
- All users must complete annual refresher training.
- يعتمد التدريب على الدور الوظيفي والوصول إلى النظام.
Protect Information
- Use secure methods to store and send sensitive information.
- قم بتشفير البيانات الحساسة عند تخزينها أو مشاركتها.
- لا تشارك كلمات المرور أو معلومات تسجيل الدخول.
- Protect paper files and printed records.
- حافظ على خصوصية المحادثات الخاصة. لا تناقش الحالات الحساسة التي يمكن للآخرين سماعها.
تحدث عندما يحدث خطأ ما
- Report any suspected or actual security issue right away.
- لا يُتوقع منك إصلاح المشكلة بنفسك.
- تساعد التقارير على حماية الأشخاص ومنع المزيد من الضرر.
ما الذي يعتبر معلومات حساسة
Sensitive information is any data that could cause harm if it is lost, shared or changed without permission.
وهذا يشمل:
- المعلومات الشخصية التي يمكنها تحديد شخص ما
- معلومات الضرائب الفيدرالية
- معلومات سرية من شركاء خارجيين
- Certain internal leadership documents
Sensitive information must always be handled with care to protect privacy and safety.
معلومات التعريف الشخصية
Personally identifiable information includes details that can identify a person, such as:
- Names and addresses
- أرقام الهواتف وعناوين البريد الإلكتروني
- Social Security numbers
- Bank account numbers
- تواريخ وأماكن الميلاد
- البيانات البيومترية
يجب حماية هذه المعلومات في جميع الأوقات.
Federal Tax Information
Federal Tax Information has special Requirements.
النقاط الرئيسية التي يجب معرفتها:
- Access is limited: Only people with a job-related need may access this information.
- يجب عدم مشاركتها أو تخزينها بدون حماية مناسبة
- لا تعتبر المعلومات الواردة مباشرة من العميل معلومات ضريبية فيدرالية.
- Federal Tax Information must never be altered to bypass security rules.
- يتم اختبار الأنظمة التي تخزن هذه المعلومات بانتظام من أجل الأمان
تستمر متطلبات الحماية حتى بعد انتهاء التوظيف.
Safeguards and Reviews
Safeguards help protect taxpayers and maintain trust.
VDSS regularly reviews how sensitive information is protected.
هذه المراجعات:
- May be conducted on-site, remotely or a mix of both
- Focus on security controls, ليس الأداء الفردي أو الوظيفي
- Help ensure protections remain effective
Reviews occur three-year cycle as needed to support improvement and accountability.
الإبلاغ عن الحوادث الأمنية
قم بالإبلاغ عن المخاوف الأمنية في أقرب وقت ممكن.
وهذا يشمل:
- Improper sharing of information
- Unauthorized access
- Lost or stolen devices
- Suspicious system activity
- تسرب البيانات أو الاختراقات
ما يجب القيام به:
- قم بالإبلاغ عن المشكلة فورًا باستخدام قنوات إعداد التقارير المعتمدة
- Share only the necessary details
- استخدم أساليب آمنة عند إرسال معلومات حساسة
Reporting quickly helps protect people and systems.
Reporting Timelines
- Most incidents must be reported within 24 hours.
- Incidents involving certain data types may require faster reporting.
يجب أن تتضمن التقارير التفاصيل الأساسية وأن تستخدم الأساليب المشفرة عند مشاركة المعلومات الحساسة.
القوانين والحماية
تتطلب العديد من قوانين الولايات والقوانين الفيدرالية من VDSS حماية المعلومات الشخصية والضريبية.
Misuse of information can result in:
- Disciplinary action
- Fines or penalties
- التهم الجنائية في الحالات الخطيرة
تستمر هذه القوانين في التطبيق حتى بعد انتهاء عملك في VDSS لأنها موجودة لحماية الأفراد، وليس لخلق الخوف.
الامتثال
تراقب VDSS الامتثال من خلال المراجعات والتدقيقات والتفتيش. قد تتم إزالة الأنظمة أو البيانات إذا لزم الأمر لحماية المعلومات.
يتحقق نظام VDSS من الامتثال من خلال:
- المراجعات وعمليات التدقيق
- Monitoring systems
- عمليات التقييم والتفتيش
يساعد الامتثال على ضمان حماية المعلومات واستمرار الخدمات.
Requesting an Exception
In rare cases, following a policy may cause serious operational challenges.
When this happens:
- قد يتم تقديم طلب مكتوب
- The request must explain the reason and how risks will be managed
- الموافقة مطلوبة قبل استخدام أي استثناء
- يمكن استئناف الطلبات المرفوضة
Exceptions are reviewed carefully to protect people and systems.
Information security is about protecting people, not assigning blame. Asking questions, following guidance and reporting concerns help keep everyone safe.
يساعد هذا الدليل الجميع:
- فهم دورهم في حماية المعلومات
- اتخذ خيارات آمنة ومستنيرة
- Report concerns without fear
- Support the mission of VDSS
الأمن لا يتعلق باللوم. يتعلق الأمر بالرعاية والوعي والمسؤولية المشتركة. إذا لم تكن متأكدًا مما يجب فعله، تواصل معنا. اتصل بـ VDSS.Security@dss.virginia.gov.