Policy and Program Guide

The Virginia Department of Social Services uses sensitive information, such as personal, financial and tax data daily to serve individuals and families across Virginia. Some of this information is sensitive. It includes personal and financial details. 

This policy explains how we protect that information and what is expected of anyone who uses VDSS systems or data. Keeping information safe helps protect people, maintain trust and ensure services continue without interruption. 

Our Guiding Principles 

ہم معلومات کے تحفظ کے لیے یہ بنیادی اصول اپناتے ہیں: 

  • معلومات ایک قیمتی وسیلہ ہے اور اس کی حفاظت ضروری ہے۔ 
  • Access is limited to people who need it to do their jobs. 
  • انفارمیشن سیکیورٹی ہمارے کام اور ہماری ٹیکنالوجی دونوں کی حمایت کرتی ہے۔ 
  • سیکیورٹی فیصلے خطرے اور عملی حیثیت پر مبنی ہوتے ہیں۔ 
  • Policies guide the work, but leaders carry them out. 
  • Everyone shares responsibility for keeping information safe

Keeping information safe helps: 

  • کلائنٹس اور ملازمین کا تحفظ کریں 
  • Maintain public trust 
  • Ensure services remain available 

Information security is a shared responsibility.

کون اس پالیسی کی پیروی کرے گا 

This policy applies to all individuals who use VDSS systems or information, including: 

  • Employees and supervisors 
  • Local department staff 
  • ٹھیکیدار اور سب کنٹریکٹرز 
  • Volunteers and interns 
  • کاروباری شراکت دار اور وینڈرز 

 Our Guiding Principles 

VDSS follows these core principles: 

Information is a valuable asset and must be protected 

  • Access is limited to people who need the information to do their job 
  • Security supports both daily work and technology 
  • Security decisions should be practical and risk-based 
  • پالیسیاں کام کی رہنمائی کرتی ہیں، لیکن ٹیمیں اسے انجام دیتی ہیں 
  • Everyone plays a role in protecting information 

 آپ کی ذمہ داریاں 

If you use VDSS systems or information, you are expected to: 

Follow Required Policies 

  • Following all VDSS security, privacy and acceptable use policies 
  • ضروری سیکیورٹی اور پرائیویسی کی تربیت وقت پر مکمل کرنا 
  • Protecting sensitive information you can access 
  • پاس ورڈز کو نجی اور محفوظ رکھنا 
  • حساس ڈیٹا بھیجنے یا ذخیرہ کرنے کے دوران انکرپشن کا استعمال 
  • سیکیورٹی خدشات کی فوری اطلاع دینا 
  • رسائی حاصل کرنے سے پہلے انفارمیشن سیکیورٹی پالیسی کی تصدیق اور عدم انکشاف معاہدے پر دستخط کریں۔
  • Re-acknowledge this agreement each year as part of required training. 

You are not expected to fix problems on your own. Reporting concerns quickly helps limit harm and protect people. 

Complete Required Training

  • New employees must complete security and privacy training within 30 days.
  • All users must complete annual refresher training.
  • تربیت ملازمت کے کردار اور نظام کی رسائی پر مبنی ہے۔

Protect Information

  • Use secure methods to store and send sensitive information.
  • حساس ڈیٹا کو محفوظ یا شیئر کرنے پر انکرپٹ کریں۔
  • کبھی بھی پاس ورڈز یا لاگ ان معلومات شیئر نہ کریں۔
  • Protect paper files and printed records.
  • نجی گفتگو کو نجی رکھیں۔ حساس کیسز پر بات نہ کریں جہاں دوسرے سن سکیں۔

جب کچھ غلط ہو جائے تو آواز اٹھائیں

  • Report any suspected or actual security issue right away.
  • آپ سے یہ توقع نہیں کی جاتی کہ آپ خود مسئلہ حل کریں۔
  • رپورٹنگ لوگوں کی حفاظت میں مدد دیتی ہے اور مزید نقصان کو روکنے میں مدد دیتی ہے۔

حساس معلومات کو کیا سمجھا جاتا ہے

Sensitive information is any data that could cause harm if it is lost, shared or changed without permission.

This includes:

  • ذاتی معلومات جو کسی کی شناخت کر سکتی ہیں
  • وفاقی ٹیکس معلومات
  • بیرونی شراکت داروں سے خفیہ معلومات
  • Certain internal leadership documents

Sensitive information must always be handled with care to protect privacy and safety.

ذاتی شناختی معلومات

Personally identifiable information includes details that can identify a person, such as:

  • Names and addresses
  • فون نمبرز اور ای میل ایڈریسز
  • Social Security numbers
  • Bank account numbers
  • تاریخ پیدائش اور مقامات
  • بایومیٹرک ڈیٹا

یہ معلومات ہر وقت محفوظ رکھنی چاہیے۔

Federal Tax Information 

Federal Tax Information has special Requirements. 

اہم نکات جاننے کے لیے: 

  • Access is limited: Only people with a job-related need may access this information. 
  • اسے مناسب تحفظ کے بغیر کبھی شیئر یا محفوظ نہیں کیا جانا چاہیے 
  • کلائنٹ سے براہ راست موصول ہونے والی معلومات کو وفاقی ٹیکس معلومات نہیں سمجھا جاتا۔ 
  • Federal Tax Information must never be altered to bypass security rules. 
  • وہ سسٹمز جو اس معلومات کو محفوظ کرتے ہیں، باقاعدگی سے سیکیورٹی کے لیے جانچے جاتے ہیں 

تحفظ کی ضروریات ملازمت ختم ہونے کے بعد بھی برقرار رہتی ہیں۔ 

 Safeguards and Reviews 

Safeguards help protect taxpayers and maintain trust. 

VDSS regularly reviews how sensitive information is protected. 

یہ جائزے: 

  • May be conducted on-site, remotely or a mix of both  
  • Focus on security controls, نہ انفرادی اور نہ ہی ملازمت کی کارکردگی 
  • Help ensure protections remain effective 

Reviews occur three-year cycle as needed to support improvement and accountability.  

 سیکیورٹی واقعات کی رپورٹنگ 

سیکیورٹی کے خدشات جتنی جلدی ہو سکے رپورٹ کریں۔  

This includes: 

  • Improper sharing of information 
  • Unauthorized access 
  • Lost or stolen devices 
  • Suspicious system activity 
  • ڈیٹا کا رساؤ یا خلاف ورزیاں 

کیا کرنا چاہیے: 

  • فوری طور پر منظور شدہ رپورٹنگ چینلز کے ذریعے مسئلہ رپورٹ کریں 
  • Share only the necessary details 
  • حساس معلومات بھیجتے وقت محفوظ طریقے استعمال کریں 

Reporting quickly helps protect people and systems. 

Reporting Timelines 

  • Most incidents must be reported within 24 hours. 
  • Incidents involving certain data types may require faster reporting. 

رپورٹس میں بنیادی تفصیلات شامل ہونی چاہئیں اور حساس معلومات شیئر کرتے وقت انکرپٹڈ طریقے استعمال کیے جائیں۔ 

قوانین اور تحفظات 

کئی ریاستی اور وفاقی قوانین VDSS کو ذاتی اور ٹیکس معلومات کی حفاظت کے لیے پابند کرتے ہیں۔ 

Misuse of information can result in: 

  • Disciplinary action 
  • Fines or penalties 
  • سنگین مقدمات میں فوجداری الزامات 

یہ قوانین VDSS میں کام کرنے کے بعد بھی لاگو ہوتے ہیں کیونکہ یہ افراد کی حفاظت کے لیے موجود ہیں، خوف پیدا کرنے کے لیے نہیں۔ 

 تعمیل 

VDSS جائزہ لینے، آڈٹ اور معائنے کے ذریعے تعمیل کی نگرانی کرتا ہے۔ اگر ضرورت ہو تو معلومات کی حفاظت کے لیے سسٹمز یا ڈیٹا ہٹایا جا سکتا ہے۔ 

VDSS تعمیل کی جانچ اس طرح کرتا ہے: 

  • جائزے اور آڈٹس 
  • Monitoring systems 
  • جائزے اور معائنے 

تعمیل اس بات کو یقینی بنانے میں مدد دیتی ہے کہ معلومات محفوظ رہیں اور خدمات جاری رہیں۔ 

 Requesting an Exception 

In rare cases, following a policy may cause serious operational challenges. 

When this happens: 

  • تحریری درخواست جمع کرائی جا سکتی ہے 
  • The request must explain the reason and how risks will be managed 
  • کسی بھی استثنا کے استعمال سے پہلے منظوری درکار ہوتی ہے 
  • مسترد شدہ درخواستوں کے خلاف اپیل کی جا سکتی ہے  

Exceptions are reviewed carefully to protect people and systems. 

Information security is about protecting people, not assigning blame. Asking questions, following guidance and reporting concerns help keep everyone safe. 

یہ رہنمائی سب کی مدد کرتی ہے: 

  • معلومات کے تحفظ میں ان کے کردار کو سمجھیں 
  • محفوظ اور باخبر فیصلے کریں 
  • Report concerns without fear 
  • Support the mission of VDSS 

سیکیورٹی الزام تراشی کے بارے میں نہیں ہے۔ یہ دیکھ بھال، آگاہی اور مشترکہ ذمہ داری کے بارے میں ہے۔ اگر آپ کو معلوم نہیں کہ کیا کرنا ہے تو رابطہ کریں۔ رابطہ VDSS.Security@dss.virginia.gov۔