department-of-veterans-affairs / va.gov-team

Public resources for building on and in support of VA.gov. Visit complete Knowledge Hub:
https://depo-platform-documentation.scrollhelp.site/index.html
281 stars 197 forks source link

ICN as PII Risk Assessment #89136

Open parkerbees opened 1 month ago

parkerbees commented 1 month ago

User story: As an Identity Team Product Owner, I would like to understand the risks associated with classifying an ICN as PII, and any potential courses of action to remediate that risk, so that I can thoroughly understand the risks and communicate them with OCTO leadership as appropriate.

Background: PO Tom Black asked Joe to assess the risks and recommendations associated with the proposed policy, announced here, that ICN should be treated as PII. Once complete, Tom will review the document and discuss it with Chris Johnston.

Additional Criteria: The documentation should strive for a minimum Flesch Reading Score of 70 for ease of understanding and scannability. Scoring can be done via MS365 Word (instructions). As with all output, the document should also strive for accessibility; if stored in Word, it should pass an accessibility check (instructions) with no errors.

Definition of Done:

Testing:

Acceptance Criteria:

Additional Notes: a draft has already been created in Google Docs here.

parkerbees commented 1 month ago

Tagging myself so this gets moved to Jira