Spirion: Clean Up PII

Spirion: Clean Up PII

Personally Identifiable Information (PII), and Spirion

Data containing Personally Identifiable Information, or PII, is prohibited from being stored on workstations maintained by the University of Northern Iowa.
PII includes Social Security numbers, driver's license numbers, credit card numbers, passport numbers, bank account information, and so on.
For detailed information, see University Policy 14.03 - Data Security Policy: https://policies.uni.edu/1403.

Departments wishing to keep data containing PII must seek and receive approval and assistance from Information Technology to be sure it is stored securely.

Spirion, formerly Identity Finder, is used by UNI to scan for PII and notifies Information Technology as well as Internal Audit about its presence.
If data containing PII is determined to be on your workstation, you will be contacted by Information Technology's Information Security office and instructed to clear said data from your workstation.
Odds are good that this (being contacted to make sure PII is removed) is why you are reading this page.

Spirion can also be used to remediate PII, by "Shredding" the data (deleting the files containing PII), or flagging false-positives in the event that information is misidentified as PII.

Opening and Using Spirion to Remediate PII

Opening the Program

Spirion should be installed on your device by default.
Search for the program and open it as you would any other, with your operating system's application list or search function to locate it.

When Spirion first opens, you'll be prompted to create a password for a new profile for saving reports. You can skip this option.

A Spirion program window showing a prompt for creating a Spirion Profile Password. Two boxes for entering and confirming a password are shown. A button marked 'Skip' is bracketed in a red rectangle to indicate it should be used.

Running a Search

After skipping creating a password for saving reports, Spirion will look something like this.
(Large screenshot, click image to enlarge if desired)

A Spirion program window depicting an empty program which has yet to run. Most of the image area is dedicated to showing results of searches and is empty as such.

On this screen, there is basically only one option available to you, and it's just what you need to do:
Click the "Start" button within the Search options at the top left.

The search will proceed in the background. You can continue working using other windows as it runs.

If you find the search causes any impact to your workstation's performance, you can Pause the search to resume later.
While the search is running, this progress window will be displayed.

A Spirion program window, showing the Status of an ongoing search. A progress bar indicates the search is 28.82 percent complete, with 72 files and 5 compressed files containing over 53 thousand social security numbers.

Remediating Results

After your search has completed, you will be presented with a Search Summary, detailing all the detections that Spirion has found.
Click on the Advanced button to proceed.

A Spirion program window showing a prompt for handling search results, with a summary of the search results displayed. A button marked 'Advanced' is bracketed in a red rectangle to indicate it should be used.

With the Search Summary closed, Spirion will look something like this.
(Large screenshot, click image to enlarge if desired)

A Spirion program window depicting the program with a variety of results shown.

The results consist of a list of files where PII was located (including the full path to the file), and details about that file, including the number of PII matches found within it.

Files Containing PII, and 'Shredding' them

Individual results in this list can be selected using the checkbox along the left side of the screen.
The checkbox at the top of the search results, in the header row of the table, can be used to select all the results.

With any number of the results selected, click the Shred button at the top of the screen to remove the files.

A Spirion program window, focused on the Actions available in the program's Main tool ribbon. A button marked 'Shred' is bracketed in a red rectangle to indicate it ought to be used for removing correctly identified PII files.

False Positives, and 'Ignoring' them

If there is a file flagged for containing PII by Spirion that you know to not actually contain any PII, you can instead select it and choose the "Ignore" option.

A Spirion program window, focused on the Actions available in the program's Main tool ribbon. A button marked 'Ignore' is bracketed in a red rectangle to indicate it ought to be used for leaving alone files which have been incorrectly identified as containing PII, but which the person using Spirion knows are, in fact, clean.

Reminder: Storing PII on your workstation is prohibited

All items "ignored" as false positives are rigorously reviewed by the offices of IT-IS and Internal Audit to ensure compliance with University policy.


Any questions with regard to using Spirion, or requests for assistance with using Spirion, can be directed to your ordinary IT support personnel.
Please reach out by submitting a request for help on Service Hub or commenting on an existing Service Hub issue.
https://servicehub.uni.edu/

Questions regarding the definitions of PII, or proper handling of PII, can be directed to the office of IT-Information Security.

All screenshots in this document depicting PII detections by Spirion utilized realistic-but-fake generated PII in accordance with University policy.