Security Awareness and Employee Sanctions. The EIEP must designate a department or party to take the responsibility to provide ongoing security awareness training for employees who access SSA-provided information. Training must include: o The sensitivity of SSA-provided information and address the Privacy Act and other Federal and state laws governing its use and misuse o Rules of behavior concerning use and security in systems processing SSA-provided information o Restrictions on viewing and/or copying SSA-provided information o The employee’s responsibility for proper use and protection of SSA-provided information including its proper disposal o Security incident reporting procedures o Basic understanding of procedures to protect the network from malware attacks o Spoofing, Phishing, and Pharming scam prevention o The possible sanctions and penalties for misuse of SSA-provided information SSA requires the EIEP to provide security awareness training to all employees and contractors who access SSA-provided information. The training should be annual, mandatory, and certified by the personnel who receive the training. SSA also requires the EIEP to certify that each employee or contractor who views SSA-provided data also certify that they understand the potential criminal and administrative sanctions or penalties for unlawful disclosure.
Appears in 4 contracts
Samples: Computer Matching and Privacy Protection Act Agreement, Computer Matching and Privacy Protection Act Agreement, Information Exchange Agreement