State Operations Manual (Pub. 100-07), Ch. 4 § 4146.8
System Security
4146.8 - System Security
(Rev. 1, 05-21-04)
As distinguished from confidentiality and privacy, which primarily focus on the rules for
release on information when it is authorized, security relates to the means by which the
information is protected from unauthorized access, disclosure and misuse. The State
must ensure that the electronic data in the MDS system is protected to the same degree
that paper records containing any identifiable data must be safeguarded. Additionally,
any printed copies of reports from the system must be maintained in a secure locked area
while they are needed and shredded when no longer needed.
The State must issue a policy that delimits the qualifications for an individual to access
the MDS system and the system administrator must issue passwords and user IDs in strict
adherence to those requirements. Those who receive passwords must be aware of the
requirement of the State’s security policies and those of the System of Records and the
Privacy Act. The system administrator and those who have received passwords must
protect passwords. Passwords must be disabled at the time an individual leaves a
position requiring MDS system access.
No one should leave the MDS system in a logged-on status when leaving the area. If
possible, the system hardware should be located in an enclosed area, with a door having
interior hinges that can be locked. Keys or a combination should be available to only a
minimal group of individuals with a need for access to the system.
In addition to the specific guidance above, the safeguards must provide a level of security
at least equivalent to that required by the Office of Management and Budget Circular A-
130 (revised) Appendix III, Security of Federal Automated Systems.