CS 9.2 - Masking SSN on EMPLID Lookup in Search Criteria
Purpose: A security change will be applied with DG6B (April 25, 2022) that will re-apply masking of the Social Security Number (SSN) or National Identification (NID) in the pop up window activated by clicking the spyglass icon in the EMPLID field in Search Criteria on pages where the lookup option exists. This guide explains the impact of the change and how to utilize the other search fields to narrow searches down to yield the desired results without needing to see a clear text SSN for all employees and students that ever existed in the system. This guide will also address the impacts of masking on the Student Self Service (Student) page used by CS staff to assist students.
Audience: CS Staff who have Primary and Row Level permissions set to allow them to view clear text SSN in Search Results.
Overview of Applied Change
With the deployment of DG6A a change was applied in ctcLink Production to set masking of the Social Security Number on any Search Criteria page where the EMPLID had a Lookup icon available. This change was applied when it was discovered that the page itself restricted the user to only view records relative to their allowed institution(s), but the Lookup display did not restrict access to data to a specific institution. The lookup return results pane displayed clear text Social Security Number (SSN) or National Identification (NID) and Date of Birth (DOB) to any user with masking permissions set to allow the display of those fields.
Managing each individual search criteria code was not sustainable for total cost of ownership. Oracle does provide a delivered feature known as Demographic Data Access (DDA) security that enables PeopleSoft system users to manage the obfuscation of Category 4 data (highly sensitive) holistically within the application.
Per Oracle's published information:
With DDA security, you can mask the display of national ID and birth date data in search records, prompt records, and on the Bio/Demo Data and the Relationships pages if these pages have display-only security. You can mask entire fields, the first five characters of the national ID field, or the year of the birth date field. You can apply masking to one, both, or neither field. No matter which masking configuration you use, users can search on the entire national ID field.
By applying this fix, using DDA security, all EMPLID lookup features related to Bio/Demo data can be masked, and should apply regardless of future PUM releases granting additional lookup features on any new pages.
At initial release there were concerns raised:
- Change impacted search behavior and staff were not prepared for altering search entry behavior to accommodate for this new masking approach.
- Partial masking of the DOB impacted user's confidence that the correct record was located, due to the number of students with similar names and close dates of birth.
- Impact of this applied masking on the Student Self-Service page where staff engage in the student experience caused concerns about how this access was distributed to users who had become accustomed to accessing category 4 data.
Because of the above concerns, the initial release was removed, the Working Group (Governance) participated in a lengthy testing exercise and approved a re-release of the DDA security application with no masking on the DOB. The information in the sections below are intended to address the other concerns raised by our college community.
How to Use Search Criteria to Narrow Search Results
Fundamental PeopleSoft functionality for pages that contain multiple transactions is to land a user on a Search Criteria page to enter in selection parameters that limit the user's returned set of transactions to a single record, or up to 300 transaction rows at a time. The majority of Search Criteria pages that allow for searching by EMPLID (or simplified to ID in some pages) will have a Look Up (spy glass) icon, but not every page will.
When clicking on the EMPLID (or ID) lookup, a pop up window will appear and a set of search criteria fields are displayed allowing a user to narrow do the returned EMPLID results to include a single EMPLID in the page's Search Criteria (see example). The following are key behaviors of all Search Criteria Look Up panes.
- Any of the listed fields shown in the Advanced Look Up ID pane can be used to narrow down the search to a single EMPLID.
- Search 'operators' can be used to widen the search range (e.g. using 'Contains' rather than 'Begins with').
- Clicking a row below will insert the ID in the search field on the main 'Find an Existing Value' pane to access the specific transaction on the page.
Searching with Known SSN Value
Key to isolating returned Search Result records to ONLY the desired transaction row sought is to enter the National ID (NID) or Social Security Number (SSN) in the search field in the Look Up EMPL ID pop-up window, if known. The Date of Birth (DOB) is clear text and in full (MM/DD/CCYY) view format for those with that masking access level.
Searching for Students Known to Lack an SSN in Bio/Demo
One concern expressed by those who regularly search through Bio/Demo records was "How do I determine if someone is missing an SSN?"
The visual below displays how you can isolate a student record that is missing an SSN by entering 'XXX' in the National ID field. The rows returned that match all other criteria used for selection will all represent student Bio/Demo records that lack an SSN.
Searching for Possible Students Sharing an SSN in Bio/Demo
Another concern expressed by those who regularly search through Bio/Demo records was related to the possibility that multiple students were 'sharing' a SSN. If a concern is raised with an individual student, the Look Up Empl ID pop up can be searched by either simply entering the National ID (NID or SSN) and seeing whether multiple rows are returned. Other criteria can be added, such as the example below showing last name, but entering the SSN alone will pull up ANY bio/demo record that shares an SSN.
How Masking Impacts Function of Person Info Student Roles
The Student Services Center (Student) page has been a source utilized for staff for viewing student Personal Information.
Navigation: NavBar>Navigator>Campus Community>Student Services Center (Student)
Users who access the Student Services Center (Student) page to view personal demographic data for students will not see a clear text SSN on this page, even if their masking allows them to view a Clear Text SSN, if they have the ZD CC Personal Info Student role. Only those users who have been granted the ZZ CC Personal Info Student, ZC CC Personal Info Student or ZZ CC Pers Info NID Update role are able to view a clear text SSN and edit the SSN in the various pages where SSN appears within the CS Pillar.
Those users with the security role ZZ CC Person Info-Biogra Stdnt are granted edit rights to the Add/Update page Only.
- Main Menu>Campus Community>Personal Information (Student)>Add/Update a Person
- 15-Add Update/Display Update/Display All Correction
- Main Menu>Campus Community>Personal Information (Student)>Address Search
- 2-Update/Display
- Main Menu>Campus Community>Personal Information (Student)>Biographical (Student)>Addresses/Phones>Addresses
- 6-Update/Display Update/Display All
- Main Menu>Campus Community>Personal Information (Student)>Biographical (Student)>Addresses/Phones>Electronic Addresses
- 2-Update/Display
- Main Menu>Campus Community>Personal Information (Student)>Biographical (Student)>Addresses/Phones>Phones
- 2-Update/Display
- Main Menu>Campus Community>Personal Information (Student)>Biographical (Student)>Addresses/Phones>Seasonal Addresses
- 2-Update/Display
- Main Menu>Campus Community>Personal Information (Student)>Biographical (Student)>Addresses/Phones>View Addresses
- 8-Correction
- Main Menu>Campus Community>Personal Information (Student)>Biographical (Student)>Addresses/Phones>View Electronic Addresses
- 8-Correction
- Main Menu>Campus Community>Personal Information (Student)>Biographical (Student)>Addresses/Phones>View Names
- 8-Correction
- Main Menu>Campus Community>Personal Information (Student)>Biographical (Student)>Addresses/Phones>View Phones
- 8-Correction
- Main Menu>Campus Community>Personal Information (Student)>Biographical (Student)>Emergency Contacts
- 2-Update/Display
- Main Menu>Campus Community>Personal Information (Student)>Biographical (Student)>Names
- 6-Update/Display Update/Display All
- Main Menu>Campus Community>Personal Information (Student)>Biographical (Student)>Personal Attributes>Communication Preference
- 3-Add Update/Display
- Main Menu>Campus Community>Personal Information (Student)>Biographical (Student)>Personal Attributes>Decedent Data
- 2-Update/Display
- Main Menu>Campus Community>Personal Information (Student)>Biographical (Student)>Personal Attributes>Ethnicity
- 2-Update/Display
- Main Menu>Campus Community>Personal Information (Student)>Biographical (Student)>Personal Attributes>Languages
- 2-Update/Display
- Main Menu>Campus Community>Personal Information (Student)>Biographical (Student)>Personal Attributes>Notification Preference
- 3-Add Update/Display
- Main Menu>Campus Community>Personal Information (Student)>Biographical (Student)>Personal Attributes>Religious Preference
- 2-Update/Display
- Main Menu>Campus Community>Personal Information (Student)>Biographical (Student)>Relationships>Person-to-Person Summary
- 2-Update/Display
- Main Menu>Campus Community>Personal Information (Student)>Biographical (Student)>Relationships>Relations with Institution
- 2-Update/Display
- Main Menu>Campus Community>Personal Information (Student)>Biographical (Student)>Relationships>Relationships
- 7-Add Update/Display Update/Display All
- Main Menu>Campus Community>Personal Information (Student)>Biographical (Student)>Student FERPA>FERPA Quick Entry
- 2-Update/Display
- Main Menu>Campus Community>Personal Information (Student)>Biographical (Student)>Work Experience
- 2-Update/Display
- Main Menu>Campus Community>Personal Information (Student)>Identification (Student)>Citizenship>Citizenship and Passport
- 2-Update/Display
- Main Menu>Campus Community>Personal Information (Student)>Identification (Student)>Citizenship>Visa Permit Data
- 6-Update/Display Update/Display All
- Main Menu>Campus Community>Personal Information (Student)>Identification (Student)>Driver's License Data
- 2-Update/Display
- Main Menu>Campus Community>Personal Information (Student)>Identification (Student)>PIN
- 2-Update/Display
- Main Menu>Campus Community>Personal Information (Student)>Identification (Student)>Photo
- 2-Update/Display
- Main Menu>Campus Community>Personal Information (Student)>Identification (Student)>Residency Data
- 6-Update/Display Update/Display All
- Main Menu>Campus Community>Personal Information (Student)>Participation Data (Student)>Accomplishments>Honors and Awards
- 2-Update/Display
- Main Menu>Campus Community>Personal Information (Student)>Participation Data (Student)>Accomplishments>Licenses and Certificates
- 2-Update/Display
- Main Menu>Campus Community>Personal Information (Student)>Participation Data (Student)>Accomplishments>Memberships
- 2-Update/Display
- Main Menu>Campus Community>Personal Information (Student)>Participation Data (Student)>Accomplishments>Publications
- 2-Update/Display
- Main Menu>Campus Community>Personal Information (Student)>Participation Data (Student)>Athletic Participation
- 6-Update/Display Update/Display All
- Main Menu>Campus Community>Personal Information (Student)>Participation Data (Student)>Extracurricular Activities
- 2-Update/Display
- Main Menu>Campus Community>Personal Information (Student)>Search/Match
- 2-Update/Display
- Main Menu>Campus Community>Personal Information>Add/Update a Person
- 15-Add Update/Display Update/Display All Correction
- Main Menu>Campus Community>Personal Information>Address Search
- 2-Update/Display
- Main Menu>Campus Community>Personal Information>Biographical>Addresses/Phones>Addresses
- 6-Update/Display Update/Display All
- Main Menu>Campus Community>Personal Information>Biographical>Addresses/Phones>Electronic Addresses
- 2-Update/Display
- Main Menu>Campus Community>Personal Information>Biographical>Addresses/Phones>Phones
- 2-Update/Display
- Main Menu>Campus Community>Personal Information>Biographical>Addresses/Phones>Seasonal Addresses
- 2-Update/Display
- Main Menu>Campus Community>Personal Information>Biographical>Addresses/Phones>View Addresses
- 8-Correction
- Main Menu>Campus Community>Personal Information>Biographical>Addresses/Phones>View Electronic Addresses
- 8-Correction
- Main Menu>Campus Community>Personal Information>Biographical>Addresses/Phones>View Names
- 8-Correction
- Main Menu>Campus Community>Personal Information>Biographical>Addresses/Phones>View Phones
- 8-Correction
- Main Menu>Campus Community>Personal Information>Biographical>Emergency Contacts
- 2-Update/Display
- Main Menu>Campus Community>Personal Information>Biographical>Names
- 6-Update/Display Update/Display All
- Main Menu>Campus Community>Personal Information>Biographical>Person FERPA>FERPA Quick Entry
- 2-Update/Display
- Main Menu>Campus Community>Personal Information>Biographical>Personal Attributes>Communication Preferences
- 3-Add Update/Display
- Main Menu>Campus Community>Personal Information>Biographical>Personal Attributes>Decedent Data
- 2-Update/Display
- Main Menu>Campus Community>Personal Information>Biographical>Personal Attributes>Ethnicity
- 2-Update/Display
- Main Menu>Campus Community>Personal Information>Biographical>Personal Attributes>Languages
- 2-Update/Display
- Main Menu>Campus Community>Personal Information>Biographical>Personal Attributes>Notification Preferences
- 3-Add Update/Display
- Main Menu>Campus Community>Personal Information>Biographical>Personal Attributes>Religious Preferences
- 2-Update/Display
- Main Menu>Campus Community>Personal Information>Biographical>Relationships>Person-to-Person Summary
- 2-Update/Display
- Main Menu>Campus Community>Personal Information>Biographical>Relationships>Relations with Institution
- 2-Update/Display
- Main Menu>Campus Community>Personal Information>Biographical>Relationships>Relationships
- 7-Add Update/Display Update/Display All
- Main Menu>Campus Community>Personal Information>Biographical>Work Experience
- 2-Update/Display
- Main Menu>Campus Community>Personal Information>Identification>Citizenship>Citizenship and Passport
- 2-Update/Display
- Main Menu>Campus Community>Personal Information>Identification>Citizenship>Visa Permit Data
- 6-Update/Display Update/Display All
- Main Menu>Campus Community>Personal Information>Identification>Driver's License Data
- 2-Update/Display
- Main Menu>Campus Community>Personal Information>Identification>PIN
- 2-Update/Display
- Main Menu>Campus Community>Personal Information>Identification>Photo
- 2-Update/Display
- Main Menu>Campus Community>Personal Information>Identification>Residency Data
- 6-Update/Display Update/Display All
- Main Menu>Campus Community>Personal Information>Participation Data>Accomplishments>Honors and Awards
- 2-Update/Display
- Main Menu>Campus Community>Personal Information>Participation Data>Accomplishments>Licenses and Certificates
- 2-Update/Display
- Main Menu>Campus Community>Personal Information>Participation Data>Accomplishments>Memberships
- 2-Update/Display
- Main Menu>Campus Community>Personal Information>Participation Data>Accomplishments>Publications
- 2-Update/Display
- Main Menu>Campus Community>Personal Information>Participation Data>Athletic Participation
- 6-Update/Display Update/Display All
- Main Menu>Campus Community>Personal Information>Participation Data>Extracurricular Activities
- 2-Update/Display
- Main Menu>Campus Community>Personal Information>Search/Match
- 2-Update/Display
- Main Menu>Campus Community>Student Services Ctr (Student)
- 2-Update/Display
- Main Menu>Student Financials>Refunds>AP Refunding>Student Vendor IDs
- 12-Update/Display All Correction
ZZ CC Person Info-Biogra Stdnt - Page Access List with Permissions
- Main Menu>Campus Community>Personal Information>Add/Update a Person
- 15-Add Update/Display Update/Display All Correction
0 Comments
Add your comment