General Security Certification and Compliance Review Programs. SSA’s security certification and compliance review programs are distinct processes. The certification program is a one-time process when an EIEP initially requests electronic access to SSA-provided information. The certification process entails two rigorous stages intended to ensure that technical, management, and operational security measures work as designed. SSA must ensure that the EIEPs fully conform to SSA’s security requirements and satisfy both stages of the certification process before SSA will permit online access to its data in a production environment. The compliance review program, however, ensures that the suite of security measures implemented by an EIEP to safeguard SSA-provided information remains in full compliance with SSA’s security standards and requirements. The compliance review program applies to both online and batch access to SSA-provided information. Under the compliance review program, EIEPs are subject to ongoing and periodic security reviews by SSA.
Appears in 2 contracts
Samples: Computer Matching and Privacy Protection Act Agreement, Computer Matching and Privacy Protection Act Agreement