Spirion: Clean Up PII
Personally Identifiable Information (PII), and Spirion
Data containing Personally Identifiable Information, or PII, is prohibited from being stored on workstations maintained by the University of Northern Iowa.
PII includes Social Security numbers, driver's license numbers, credit card numbers, passport numbers, bank account information, and so on.
For detailed information, see University Policy 14.03 - Data Security Policy: https://policies.uni.edu/1403.
Departments wishing to keep data containing PII must seek and receive approval and assistance from Information Technology to be sure it is stored securely.
Spirion, formerly Identity Finder, is used by UNI to scan for PII and notifies Information Technology as well as Internal Audit about its presence.
If data containing PII is determined to be on your workstation, you will be contacted by Information Technology's Information Security office and instructed to clear said data from your workstation.
Odds are good that this (being contacted to make sure PII is removed) is why you are reading this page.
Spirion can also be used to remediate PII, by "Shredding" the data (deleting the files containing PII), or flagging false-positives in the event that information is misidentified as PII.
Opening and Using Spirion to Remediate PII
Opening the Program
Spirion should be installed on your device by default.
Search for the program and open it as you would any other, with your operating system's application list or search function to locate it.
When Spirion first opens, you'll be prompted to create a password for a new profile for saving reports. You can skip this option.
Running a Search
After skipping creating a password for saving reports, Spirion will look something like this.
(Large screenshot, click image to enlarge if desired)
On this screen, there is basically only one option available to you, and it's just what you need to do:
Click the "Start" button within the Search options at the top left.
The search will proceed in the background. You can continue working using other windows as it runs.
If you find the search causes any impact to your workstation's performance, you can Pause the search to resume later.
While the search is running, this progress window will be displayed.
Remediating Results
After your search has completed, you will be presented with a Search Summary, detailing all the detections that Spirion has found.
Click on the Advanced button to proceed.
With the Search Summary closed, Spirion will look something like this.
(Large screenshot, click image to enlarge if desired)
The results consist of a list of files where PII was located (including the full path to the file), and details about that file, including the number of PII matches found within it.
Files Containing PII, and 'Shredding' them
Individual results in this list can be selected using the checkbox along the left side of the screen.
The checkbox at the top of the search results, in the header row of the table, can be used to select all the results.
With any number of the results selected, click the Shred button at the top of the screen to remove the files.
False Positives, and 'Ignoring' them
If there is a file flagged for containing PII by Spirion that you know to not actually contain any PII, you can instead select it and choose the "Ignore" option.
Reminder: Storing PII on your workstation is prohibited
All items "ignored" as false positives are rigorously reviewed by the offices of IT-IS and Internal Audit to ensure compliance with University policy.
Any questions with regard to using Spirion, or requests for assistance with using Spirion, can be directed to your ordinary IT support personnel.
Please reach out by submitting a request for help on Service Hub or commenting on an existing Service Hub issue.
https://servicehub.uni.edu/
Questions regarding the definitions of PII, or proper handling of PII, can be directed to the office of IT-Information Security.
All screenshots in this document depicting PII detections by Spirion utilized realistic-but-fake generated PII in accordance with University policy.