§293.106. Safeguarding information about individuals. — Inbound Citations
5 C.F.R. § 293.106
Statutory Authority
Cited by 5 regulations in release Current.
Citations to 5 U.S.C. § 293.106 as a whole
-
(a) In addition to following the security requirements of § 293.106 of this part, managers of automated personnel records shall establish administrative, technical, physical, and security safeguards for data about individuals in automated records, including input and output documents, reports, punched cards, magnetic tapes, disks, and on-line computer storage. The safeguards must be in writing to comply with the standards on automated data processing physical security issued by the National Bureau of Standards, U.S. Department of Commerce, and, as a minimum, must be sufficient to:(1) Prevent careless, accidental, or unintentional disclosure, modification, or destruction of identifiable personal data;(2) Minimize the risk that skilled technicians or knowledgeable persons could improperly obtain access to, modify, or destroy identifiable personnel data;(3) Prevent casual entry by unskilled persons who have no official reason for access to such data;(4) Minimize the risk of an unauthorized disclosure where use is made of identifiable personal data in testing of computer programs;(5) Control the flow of data into, through, and from agency computer operations;(6) Adequately protect identifiable data from environmental hazards and unneccessary exposure; and
-
(c) Records in an EMF, whether or not located in an office other than where the OPF is maintained, must be properly safeguarded using procedures ensuring equal or greater levels of protection as those in § 293.106. Disclosures must be made only to those authorized to receive them, as described in § 293.504(b), and employees must be able to ascertain from agency implementing instructions the location of all of their medical records. An EMF must be under the control of a specifically designated medical, health, safety, or personnel officer as prescribed in the agency's implementing internal procedures.
-
(1) Personnel and employment records maintained by the Farm Credit Administration which are not covered by §§ 293.101 through 293.108 of the regulations of the Office of Personnel Management (5 CFR 293.101 through 293.108), and
-
(1) Personnel and employment records maintained by the Farm Credit System Insurance Corporation not covered by §§ 293.101 through 293.108 of the regulations of the Office of Personnel Management (5 CFR 293.101 through 293.108); and
-