Home Site Map Contact Us Benefit Online Services Benefit Forms & Publications  
"" Introduction
ERS Security Categorization
"" Assigning risk levels to potential breach of security
"" Potential impact of a breach of security
  "" Determining the required assurance level
"" Assurance Level 2 Authentication
"" Summary
RELATED LINKS
'' Employer Online Services
'' ERI Security Guidelines
'' LRI Security Guidelines
Employer Reporting System (ERS)
Security Categorization and E-Authentication
ERS Security Categorization View this document in PDF

 
To view and download PDF documents, you need the free Acrobat Reader Read RRB's external link disclaimer
. We recommend using the latest version.
Viewers with visual disabilities can go to Adobe's Access Website Read RRB's external link disclaimer
. for tools and information that will help make PDF files accessible.

Assigning risk levels to potential breach of security

The FIPS Publication 199 defines three levels of potential impact on organizations or individuals should there be a breach of security; low, medium, and high risk. In general, the potential risk is low if the loss of confidentiality, integrity, or availability could be expected to have limited adverse effect on organizational operations, organizational assets, or individuals. For example, the RRB is able to perform its primary functions but the effectiveness of the functions may be

  • noticeably reduced;
  • result in minor damage to organizational assets:
  • result in minor financial loss; or
  • result in minor harm to individuals.

We assigned risk levels to ERS according to the guidelines in FIPS PUB 199. Details are in Summary section.

Potential Impact of a breach of security

There are many checks and balances in the application process to prevent an unauthorized individual from receiving an ERS password. If, through human error or other means, an unauthorized individual or impersonator attains access to ERS, there is a low risk:

  • that they will have access to private information;
  • that the private information will cause distress to the private party;
  • that civil or criminal violations will be enforced; or
  • that the individual will cause financial loss to the agency.

See Summary for additional details.

Determining the required assurance level

The generally low risk levels indicate that ERS requires an assurance level 2 authentication. See the table in Summary section for determination of the authentication level based on the risk level.


Privacy Policy Policies & Links Freedom of Information Act No FEAR Act Data Frequently Asked Questions About Us

Link to USA.gov: The U.S. government's official web portal. U.S. Railroad Retirement Board RRB Seal links to home page
844 North Rush Street
Chicago Illinois, 60611-2092
Telephone: (312) 751-4500 TTY: (312) 751-4701
Contact an RRB office near you
     
     
Date posted: 02/17/2006
Date updated: 02/16/2006