Attention Web Voucher and General Ledger Users: Important Data Security Update

The following information comes from the Office of the Controller concerning Data Security and Financial Transaction Processing, dated February 2, 2010.

Based upon the University's Enterprise Security policy all web voucher and journal transactions within Oracle that contain confidential information have been modified as part of an initiative to remove confidential data elements from modules within Oracle where broad end user access is allowed.

The modified financial records contain a notation of DSCU (data security clean up) indicating that secure data elements such as SSN, credit card, and bank account information has been removed from the record to ensure compliance with the University's Enterprise Security policy. A complete list of confidential data elements are contained in the HEISP policy.

Business process guidelines to ensure compliance are as follows:

  1. When submitting information requests to University Financial Services, SSN or credit card numbers must not be included in any email correspondence.
  2. Social security numbers of independent contractors must not be included anywhere in the Web Voucher. This information is stored and accessible through the vendor table in Oracle. It is not necessary to repeat the information in the Web Voucher process.
  3. Journals (ADI, Manual or Feed) must not contain confidential data in either the Journal Batch description, Journal Header description, or Journal Line description.
  4. JPMC Corporate card numbers must not be included anywhere on Web Voucher and Web Voucher Reimbursement transactions. This includes JPMC Direct Pay and third party payment transactions.
  5. Remittance slips for all third party payments to JPMC must be attached to the Web Voucher Reimbursement for processing. Do not enter the credit card number in the Web Voucher Reimbursement description field.
  6. Correspondence containing confidential data elements should not be stored locally and should be destroyed following proper procedures for destruction of confidential data. In an effort to further secure the personal information of Harvard employees and to safeguard Harvard University's assets, the University Technology Security Officer, the University Archivist, and the Office for Strategic Procurement selected DataShredder Corp. as the provider for a campus wide Data Destruction Program. Please see http://vpf-web.harvard.edu/ofs/procurement/ven_par_dsr.shtml for security, http://grs.harvard.edu/ for the General Records Schedule, and http://www.greencampus.harvard.edu/ for environmental policy.
Email | Top