Educause Security Discussion mailing list archives

Re: Removing Sensitive Data from Paper Documents


From: Ellen Smout <esmout () UWO CA>
Date: Mon, 26 Oct 2009 17:05:43 -0400

Hi Patty

This issue arose for us in PCI.  We had many forms redesigned so that
information can be cut off the bottom of the form and then shredded
while other information on the form can be kept as needed.

Permanent stickers could also be an option, you would have to sticker
both sides.

I am leery of scanning then removing, as that puts into scope systems
that were not previously in scope of containing any sensitive data.
These systems now have to be purged of sensitive data as well.

Blacking out and then scanning is a good option, although it's a lot of
work.

thxs,

Ellen


Patria, Patricia wrote:
Is anyone aware of a technique that will allow you to modify a paper
record to make the personal identifying information unreadable while
keeping the rest of the document intact? Aside from cutting the
information from the document (which is not practical), are there
special markers, pens or white-out designed for this purpose?



In an effort to comply with MA 201 CMR, we would like to remove PI from
certain paper files, while keeping the document intact.



Thanks in advance for any advice you can offer.



Patty



*Patty Patria*

*Chief Information Security Administrator |** Bentley University*

*175 Forest Street, Waltham, MA 02452 **|**781.891.2364 *



Attachment: esmout.vcf
Description:


Current thread: