WPC #X$}lm\V,FZ\Nk/Ը4Qp>{ݱLRPa~XbiSf|HOd5̪6_gEoC5)ea]5aj0<uA|}2op~qTJh3n#@+ ^+(zy~ͨ3E `89k{|Ԅ1jԪ=Qo(' gRqZ@f㘓ܜqtJO5k(#ʿ6F!.4lA-|"5xtÜ JvGyDqIv<3X֩ [g߀LH\{=V={pz.l#8Бodu!xoַTVoDIv'sg (UM%Y&IS@cXki4x EЬ0'˾'bRlŐŪt~+v9 # UN % 0(w@4Sgv-~Acrobat PDFWriter v2.11PDFWRITR((((((((0vL(9 Z 6Times New Roman RegularX($ tPuUvDwUxyEz{ e|D}E%3|x} ##8Xd# !  {{{rr{ c{{xACTIONITEM#xyx2xyz1zwwMEMORANDUM:{{SUBJECT: ` SECURITYRELATED{{INFORMATIONsALs{{{{MATERIALu ` uu  uu ` u{{FORALLAIRS{{vt h  h tvUSERS{{FROM: ` MICHAELW.HAMLIN $ t PURPOSE  L  ThisinformationalmaterialwasdevelopedtooutlinebrieflythesecuritymeasuresfortheAIRSsystemandtoexplainwhythesemeasuresweredeveloped,andtorequestthesupportofallAIRSusersincomplyingwiththesemeasures.ThesecuritymeasuresforAIRSareintendedtoprotecttheairquality,emissionsandcompliancedatathatStateandlocalagenciesperiodicallysubmittoEPA.Thisprotectionincludesunauthorizedmodificationorlossofdata,whileatthesametimeprotectingtheunderlyingcomputersystemthatEPAoperates.TheAIRSapplication(andthedataitcontains)supportsEPA,aswellasStateandlocalagenciesneedinginformationtocarryoutairqualitymanagementprograms.AllAIRSusersmustensurethattheAIRSapplicationanditsdataareprotectedfromloss,misuse,andunauthorizedaccessormodification.Itisalsoparamountthatanysensitiveinformation(e.g.,enforcement,compliance)intheAIRSapplicationisprotectedfromunauthorizedaccess.EPAsSecurityMeasuresforAIRS   TheAIRS,whichconsistsoftwomajorsubsystems,AirQualitySubsystem(AQS)andAirFacilitySubsystem(AFS),isaADABASdatabasemanagementsystemlocatedonEPAsNationalComputerCenter(NCC)mainframe.Assuch,AIRSfollowsthesecurityproceduressetforthbytheNCCwhichprimarilyinvolvestheuseofuseraccounts,userids,passwordsandADABAS/NaturalSecurity.Briefly,theseproceduresrequirethat:  a.AnyindividualwantingtobeabletoaccessdataintheAIRSdatabasemustbegivenauthorizationtouseamainframeaccountandobtainanNCCuserid.Theidandasecurepassword(determinedbytheuser)mustbeusedwhenaccessingtheNCCmainframeandAIRSdatabase.Stateandlocalagencyusersaregivenlimitedupdateauthority(i.e.,theymayonlyaddormodifydatafortheirparticularagency).  b.Auseridisonlyassignedtoanindividual(ratherthananagency)andonlytoanindividualthatisrecommendedforaccessbytheStateorlocalagency(inwriting)andapprovedbytheappropriateEPARegionalOfficeAIRScontactandRegionalRACFAdministrator.Individualsgranteduseridshavearesponsibilitytousetheiridsinanappropriatemanneratalltimesandensurethattheaccesstheyhavebeenpersonallygrantedisnotsharedwithothers(eitherdeliberatelyorinadvertently). @-(,  c7EXXdXXd7  { c750XXdXXd7  {{ c7mXXdXXd7  {v c7HXXdXXd7  vAIRSApplicationGuidelinesforAllUsers (  TherearecertainsecuritypracticesandproceduresthatshouldbefollowedtominimizethepotentialmisuseordamagetotheAIRSdatabase.Someoftheseinclude:General  ` ̄8  BefamiliarwiththesecuritypoliciesandpracticesinvolvingtheAIRSapplication, 8  especiallythoseforconfidentialorsensitiveinformation(seeAIRSSecurityPlan).    ̄8  Maintainsecurityfortheapplicationbycorrectlyusingestablishedsecurity `  mechanisms(useofuniqueuseridandpassword)andpracticeswhenaccessingtheAIRSapplication.    ̄8  Donotattempttoview,change,ordeletedataunlessyouareauthorizedtodoso.   ̄8  Donotuseyoursystemprivilegestoobtaindata/filesorrunapplicationsfor  anyonewhoisnotauthorizedtovieworusedatathataresensitive.    ̄8  BealerttopotentialthreatstocorruptordestroyAIRSapplicationanddatabase.H   ̄8  Ensurethatnoonepersonhassoleaccessto,orcontrolover,AIRSinformation   andprocessingresources.    ̄8  Guarduseridandpassword.Donotloanouttoothers.H   SensitiveData  ! ̄8  Besuretoprovideonlyauthorizedpersonnelwithsensitivedata(whetherthedata " areonyourscreenoronpaper).    ̄8  Whenviewingorprocessingconfidentialorsensitivedata,besurethePCisina %X" nontrafficareaandthatonlypersonsauthorizedtoseethedataareinthearea.    ̄8  Protectalldocumentsandreportscontainingsensitivedata.Besurethattheyare ("% labeled sensitive.    ̄8  Destroysensitivedocumentswhenfinishedwiththem.D+$(   ̄8  Donotsavesensitivedatatoyourharddrive,diskette,orfloppy.-&*   М|  d Л@*|||8  Logoffyourcomputerwhenyouaretobeawayfromyourworkstation.d   ̄8  Lockuporputawaysensitivedata.<   PasswordProtection   ̄8  ControlaccesstoyourPC.Logoutwheneveryouleaveyourmachine.    ̄8  Changeyourapplicationpasswordevery90days.Useatleast8charactersinyour  ` applicationpassword.    ̄8  Useamixofalphaandnumericcharacters.$    ̄8  Donotusefamilynames,birthdays,sportsteamsnames,orwordsthatcanbe `  foundinthedictionary.    ̄8  Donotuseconsecutivekeysonakeyboardorallthesamecharacter.$   ̄8  Usenewpasswords.Donotusethelast8versionsofyourpassword.   ̄8  Ifyoubelieveyourpasswordhasbeencompromised,changeitimmediately.p   ̄8  Memorizeyourpasswordratherthanwritingitdownsomewhere.H   WhoToNotify   ̄8  NotifytheAIRSSecurityOfficerimmediatelyofsecurityincidents.\   ̄8  NotifytheAQSorAFSapplicationmanager(JakeSummers(AQS)at919541 4  5695orChuckIsbell(AFS)at9195415448)whenstaffhavebeenterminatedorchangedpositionstohavetheiraccesstotheapplicationterminated.    Summary #  ThisinformationwascompiledtoassurethatthecontentsandintegrityofAIRSdatawillbesecure.InordertomaintainsecurityforthedataprovidedinAIRS,wesuggestthattheguidelinesabovebefollowed.ThesecuritymeasuresthathavebeenestablishedaredesignedtoprotectthedatathatStateandlocalagenciessubmit,whileatthesametimeprotectingthecomputersystemsthatEPAoperates.AnyquestionsconcerningtheaboveinformationshouldbereferredtoMichaelHamlin,AIRSSecurityOfficer,at(919)5415232.̜} -&* }