<?xml version="1.0" encoding="UTF-8"?><marc:collection xmlns:marc="http://www.loc.gov/MARC21/slim">
  <marc:record>
    <marc:leader>00000nam  2200000za 4500</marc:leader>
    <marc:controlfield tag="001">9.833070</marc:controlfield>
    <marc:controlfield tag="003">CaOODSP</marc:controlfield>
    <marc:controlfield tag="005">20221107150133</marc:controlfield>
    <marc:controlfield tag="007">cr |||||||||||</marc:controlfield>
    <marc:controlfield tag="008">170307s2016    onc     o    f000 0 eng d</marc:controlfield>
    <marc:datafield tag="040" ind1=" " ind2=" ">
      <marc:subfield code="a">CaOODSP</marc:subfield>
      <marc:subfield code="b">eng</marc:subfield>
    </marc:datafield>
    <marc:datafield tag="043" ind1=" " ind2=" ">
      <marc:subfield code="a">n-cn---</marc:subfield>
    </marc:datafield>
    <marc:datafield tag="086" ind1="1" ind2=" ">
      <marc:subfield code="a">D58-271/2015E-PDF</marc:subfield>
    </marc:datafield>
    <marc:datafield tag="245" ind1="0" ind2="0">
      <marc:subfield code="a">Audit of Civilian Human Resources Management System (HRMS(Civ)) application access rights </marc:subfield>
      <marc:subfield code="h">[electronic resource].</marc:subfield>
    </marc:datafield>
    <marc:datafield tag="246" ind1="1" ind2="7">
      <marc:subfield code="a">Audit of HRMS(Civ) application access rights</marc:subfield>
    </marc:datafield>
    <marc:datafield tag="260" ind1=" " ind2=" ">
      <marc:subfield code="a">[Ottawa] : </marc:subfield>
      <marc:subfield code="b">National Defence, </marc:subfield>
      <marc:subfield code="c">[2016]</marc:subfield>
    </marc:datafield>
    <marc:datafield tag="300" ind1=" " ind2=" ">
      <marc:subfield code="a">33 p. in various pagings</marc:subfield>
    </marc:datafield>
    <marc:datafield tag="500" ind1=" " ind2=" ">
      <marc:subfield code="a">Issued also in French under title: Audit des droits d’accès à l’application du Système de gestion des ressources humaines civiles (SGRH(Civ)).</marc:subfield>
    </marc:datafield>
    <marc:datafield tag="500" ind1=" " ind2=" ">
      <marc:subfield code="a">Cover title.</marc:subfield>
    </marc:datafield>
    <marc:datafield tag="500" ind1=" " ind2=" ">
      <marc:subfield code="a">At head of title: Reviewed by ADM(RS) in accordance with the Access to Information Act. Information UNCLASSIFIED.</marc:subfield>
    </marc:datafield>
    <marc:datafield tag="500" ind1=" " ind2=" ">
      <marc:subfield code="a">"December 2015."</marc:subfield>
    </marc:datafield>
    <marc:datafield tag="520" ind1=" " ind2=" ">
      <marc:subfield code="a">“The current HRMS(Civ) user access management framework is not sufficiently rigorous to ensure the integrity and confidentiality of HR data. There is a lack of key system accreditation requirements, limited documentation on the consistent use of the HR data, weak access controls, unclear roles and responsibilities, and the wide distribution of the HR data outside of the HRMS system. The Department is thus unable to ensure that the HR data has been safeguarded, used appropriately, and secured from unauthorized use. As a result, a privacy breach involving the personal data of current and former employees and CAF members may have occurred. Taken in its entirety, these factors create a risk to people's personal information, as well as to the reputation of the Department. Given the sensitive nature and pervasive use of personal information within the Department, stakeholders must be proactive and provide an enterprise approach to the assessment and management of this situation. Based on TBS policy requirements and guidelines, the Department should take expedient action to resolve the identified privacy and security issues and should ensure that the proper user access framework is in place going forward”--Conclusion, p. 15.</marc:subfield>
    </marc:datafield>
    <marc:datafield tag="692" ind1="0" ind2="7">
      <marc:subfield code="2">gccst</marc:subfield>
      <marc:subfield code="a">Human resources</marc:subfield>
    </marc:datafield>
    <marc:datafield tag="692" ind1="0" ind2="7">
      <marc:subfield code="2">gccst</marc:subfield>
      <marc:subfield code="a">Computer security</marc:subfield>
    </marc:datafield>
    <marc:datafield tag="692" ind1="0" ind2="7">
      <marc:subfield code="2">gccst</marc:subfield>
      <marc:subfield code="a">Audit</marc:subfield>
    </marc:datafield>
    <marc:datafield tag="710" ind1="1" ind2=" ">
      <marc:subfield code="a">Canada.</marc:subfield>
      <marc:subfield code="b">Department of National Defence.</marc:subfield>
      <marc:subfield code="b">Chief Review Services.</marc:subfield>
    </marc:datafield>
    <marc:datafield tag="775" ind1="0" ind2="8">
      <marc:subfield code="t">Audit des droits d’accès à l’application du Système de gestion des ressources humaines civiles (SGRH(Civ)) </marc:subfield>
      <marc:subfield code="w">(CaOODSP)9.833457</marc:subfield>
    </marc:datafield>
    <marc:datafield tag="856" ind1="4" ind2="0">
      <marc:subfield code="q">PDF</marc:subfield>
      <marc:subfield code="s">705 KB</marc:subfield>
      <marc:subfield code="u">https://publications.gc.ca/collections/collection_2017/mdn-dnd/D58-271-2015-eng.pdf</marc:subfield>
    </marc:datafield>
    <marc:datafield tag="986" ind1=" " ind2=" ">
      <marc:subfield code="a">7050-33-9 (ADM(RS))</marc:subfield>
    </marc:datafield>
  </marc:record>
</marc:collection>
