diff --git a/app/assets/images/product/security-review-message.png b/app/assets/images/product/security-review-message.png new file mode 100644 index 000000000..ffb59076c Binary files /dev/null and b/app/assets/images/product/security-review-message.png differ diff --git a/app/templates/views/security.html b/app/templates/views/security.html index f55ad3de5..d676b37bf 100644 --- a/app/templates/views/security.html +++ b/app/templates/views/security.html @@ -15,22 +15,52 @@
  • manage risks around information
  • -

    Data

    -

    On Notify, data is encrypted:

    - -

    Any recipient data you upload is only held for seven days.

    - +

    Infrastructure

    -

    Technical security

    - +

    Notify.gov is comprised of two applications both running on cloud.gov:

    + + +

    Notify.gov utilizes several cloud.gov-provided services through Amazon Web Services (AWS):

    + + +

    Notify.gov also provisions and uses two AWS services via a supplemental service broker:

    + + +

    Current security review

    +

    Currently, Notify.gov operates under a GSA Lightweight Authority to Operate (LATO). This federal security authorization + process leverages security controls provided by National Institute of Standards and Technology (NIST). The process is + focused on operational security from both a functional and assurance perspective.

    +

    We are pursuing a full Authority to Operate (ATO)

    + +

    Data

    +

    To send a message, agencies upload a spreadsheet of phone numbers and other necessary data from their existing data + management system. On Notify.gov, data is encrypted when it passes through the service and when it’s stored on the + service.

    +

    Notify.gov is not a system of record and as a result does not have a SORN. Agencies are responsible for managing their + data outside of Notify.gov.

    + + +

    Data retention

    +

    Any recipient data uploaded is only held for seven days; all personally identifiable information (PII) is deleted for + successful messages, so data is retained only for unsuccessful messages. +

    + +

    Technical security

    Protect sensitive information

    Some messages include sensitive information like security codes or password reset links.

    @@ -46,6 +76,23 @@

    If signing in with a text message is a problem for your team, contact us to find out about using an email link instead.

    + Screenshot of a teat message in review with the link to 'hide personalization after sending' circled. + +

    How to hide PII after sending a message

    + +

    User permissions and signing in

    +

    You can set different user permissions in Notify. This lets you control who in your team has access to certain parts of + the service.

    + +

    Multi-factor authentication (MFA)

    +

    Notify.gov uses Login.gov to authenticate users.

    + +

    If signing in with a text message is a problem for your team, contact us to find out about using an email link instead.

    +