2
INTERNET SECURITY: Ensuring Confidenality and Privacy When Using Virtual Technology 1 1 2 This Naonal Responsible Fatherhood Clearinghouse (NRFC) Tip Sheet is a Companion Document to the NRFC Spotlight Using Virtual Technology In Fatherhood Programs. LINK TO SPOTLIGHT WILL BE ADDED WHEN THE SPOTLIGHT IS POSTED TO NRFC WEBSITE SELECTING A VIRTUAL PLATFORM If possible, use a web conferencing plaorm that is FedRAMP 2 cerfied. See hps://marketplace.fedramp.gov/#!/ products for a list of FedRAMP authorized cloud-service products. Any organizaon that purchases a subscripon or license to the service can use these products. However, the versions of the products in this list are designed to be used by government agencies. Ensure that all staff are trained in the privacy and security funcons of the plaorm(s) you select. LIMIT ATTENDANCE TO INVITEES ONLY Set up passwords for all meengs. Change meeng IDs or codes frequently. Do not post informaon about the meeng on social media, unless necessary. Enable the “waing room” opon (if it is available on the plaorm you are using) to: Ensure that the meeng cannot begin unl the host joins. Allow the meeng host to verify all parcipants before adming them to the meeng. NRFC TIPSHEET Rupinder Randhawa, IT Project Manager, ICF, compiled these ps. FedRAMP (Federal Risk and Authorizaon Management Program) is a government-wide program that provides a standardized approach to security assessment, authorizaon, and connuous monitoring for cloud products and services.

Internet Security: Ensuring Confidentiality and Privacy When … · 2020. 9. 11. · • Ensure that all staff are trained in the privacy and security functions of the platform(s)

  • Upload
    others

  • View
    2

  • Download
    0

Embed Size (px)

Citation preview

Page 1: Internet Security: Ensuring Confidentiality and Privacy When … · 2020. 9. 11. · • Ensure that all staff are trained in the privacy and security functions of the platform(s)

INTERNET SECURITY:Ensuring Confidentiality and Privacy When Using Virtual Technology1

1

2

This National Responsible Fatherhood Clearinghouse (NRFC) Tip Sheet is a Companion Document to the NRFC Spotlight Using Virtual Technology In Fatherhood Programs.

L I N K TO S P OT L I G H T W I L L B E A D D E D W H E N T H E S P OT L I G H T I S P O S T E D TO N R F C W E B S I T E

SELECTING A VIRTUAL PLATFORM

• If possible, use a web conferencing platform that is FedRAMP2 certified.

• See https://marketplace.fedramp.gov/#!/products for a list of FedRAMP authorized cloud-service products.

• Any organization that purchases a subscription or license to the service can use these products. However, the versions of the products in this list are designed to be used by government agencies.

• Ensure that all staff are trained in the privacy and security functions of the platform(s) you select.

LIMIT ATTENDANCE TO INVITEES ONLY

• Set up passwords for all meetings.

• Change meeting IDs or codes frequently.

• Do not post information about the meeting on social media, unless necessary.

• Enable the “waiting room” option (if it is available on the platform you are using) to:

• Ensure that the meeting cannot begin until the host joins.

• Allow the meeting host to verify all participants before admitting them to the meeting.

NRFC TIPSHEET

Rupinder Randhawa, IT Project Manager, ICF, compiled these tips.

FedRAMP (Federal Risk and Authorization Management Program) is a government-wide program that provides a standardized approach to security assessment, authorization, and continuous monitoring for cloud products and services.

Page 2: Internet Security: Ensuring Confidentiality and Privacy When … · 2020. 9. 11. · • Ensure that all staff are trained in the privacy and security functions of the platform(s)

NRFC Tipsheet National Responsible Fatherhood Clearinghouse2

MANAGING AN ONLINE MEETING

A. Enable notification when attendees join by playing a tone or announcing names.

• If this is not an option, make sure the meeting host asks new attendees to identify themselves.

B. If a dashboard (or similar platform control) is available, use it to monitor and identify all attendees.

C. For web-based video meetings:

• Caution all users who intend to share their screen to be mindful not to inadvertently share other sensitive information during the meeting.

• Allow users the option either to preview video and select a virtual background, or to join without video.

D. Enable and use the following options as needed:

Ҍ Put participants on hold

Ҍ Disable video

Ҍ Disable annotation

Ҍ Remove participants

Ҍ Disable file sharing

Ҍ Control screensharing

Ҍ Mute participants

Ҍ Disable private chat

Ҍ Control recording

FOR EXTRA SECURITY

Require participants to use a personal identification number (PIN) or two-factor authentication to access a meeting.

If part of a meeting will cover sensitive or confidential information restricted to a subgroup of attendees, enable “remove participants” and/or “terminate access” options.

• This ensures that participants not invited to a specific portion of the meeting have indeed left and cannot rejoin until the host permits.

RECORDING ONLINE MEETINGS

A. Obtain consent from all participants before you record a meeting.

B. Make sure meeting recordings are encrypted.

C. Only record the meeting when absolutely necessary.

Disclaimer:

Some virtual meeting platforms may not offer all of the features mentioned in this list of tips. In addition, users may need to update their equipment and/or software to utilize some features.

facebook.com/fatherhoodgov @fatherhoodgov 1-877-4DAD411 www.fatherhood.gov