Spirion Identity Finder
Spirion Identity Finder (IDF) is an application that identifies potentially sensitive information stored on a computer. IDF is part of the System Office’s mandated security initiative
What does IDF scan for on a computer?
The software scans the contents of a computer (weekly) for files that contain text that may be sensitive. Some examples of sensitive information are Social Security numbers (SSN), credit card numbers, debit card numbers, bank account information, and driver license numbers.
Who will be required to use IDF?
Initially, IDF will only impact those with Banner SSN access. IDF deployment may be expanded in the future.
In a more perfect world, sensitive information would reside and be used solely in secure systems of record. Storing sensitive information on one’s computer is inappropriate and increases the risk of a breach. Unfortunately, the realization is that sensitive information may occasionally find its way onto an individual’s computer. For this reason, IDF is deployed to those computers identified to be at risk.
How do I activate IDF software?
On first launch, IDF will prompt the employee to define a unique password that is used solely for the purpose of accessing this software application. This password is not affiliated with the SCSU NetID password. Make sure to securely retain the password.
When does IDF scan and how long does it take?
IDF is set to scan a computer every Thursday night. The scan should be done by Friday morning. However, scan duration is dependent upon the amount of data that needs to be analyzed. Any computer not on Thursday night will be scanned the next time the individual starts the computer and logs in. One is able to perform all of their normal work activities while the scan occurs.
What is an individual’s responsibility?
Once the scan is complete, the results will be displayed in the IDF application Search Summary window. The individual assigned to and responsible for the computer (Ref: property records) is expected to mitigate the IDF findings by taking one of the actions listed below.
- Shred: Shredding a file will securely and permanently delete the file - this action is irreversible.
- Redact: Redacting a file will create a copy of the file in text format (.txt). The sensitive data in this copy will be “masked” and the original file will be shredded. Rather than using the redact action, DCL3 data in files can be manually removed or masked so that the original file type can be retained.
- Ignore: Ignoring a file should only be performed on false-positive readings. This action will mark the file and/or file location as “safe” and never flag it again.
Video tutorials:
1. How to Set-Up Spirion Identity Finder (IDF)
2. Understanding the scan process in Spirion Identity Finder (IDF)
3. Reviewing and acting on scan results in Spirion Identity Finder (IDF)