HomeNewsArticle Display

Existing tools help users reduce PII breaches

JOINT BASE SAN ANTONIO-LACKLAND, Texas (AFNS) -- Members of 24th Air Force are refurbishing an old email tool to help Air Force users reduce breaches of personally identifiable information, or PII.

The Digital Signature Enforcement Tool, or DSET, which currently prompts users to provide a digital signature when an email contains an active hyperlink or attachment, is being reconfigured to scan emails and attachments for PII. DSET was first introduced to Microsoft Outlook in 2009 by the Air Force Life Cycle Management Center.

"DSET was originally designed to mitigate risk from socially-engineered email or phishing attacks. Now, it provides some protection of messages transmitting PII," said Alonzo Pugh, a cyberbusiness system analyst for 24th AF. "The tool provides awareness for users of risks before the email leaves the workstation, giving users the chance to correct the identified risk."

PII includes items such as an individual's social security number, driver's license information and financial information. Breaches occur when this information is inadvertently released. User awareness is one of the biggest issues associated with PII breaches, Pugh said.

"When users release PII that is not protected, that puts information at risk for being intercepted by adversaries," he said. "These adversaries can then use that information to target users to gain access the network. Air Force network users must do their due diligence when sending an e-mail containing PII. They need to make sure the information is protected."

DSET capability should encourage users to be more involved in the process of preventing PII breaches, Pugh said. "The user is afforded the ability to take action in checking their emails to make sure they are not inadvertently releasing PII, and given the opportunity to protect it. DSET makes users more aware that they need to double check their emails and ensure that they are in accordance with policy; the responsibility for preventing breaches ultimately falls on them."

The tool itself is straightforward to use, Pugh said, and will give users simple prompts to follow in sending emails. In addition, there is a function allowing information which was falsely identified as PII to still be sent.

"While our software solution will support the Air Force's efforts to reduce PII breaches, it is still important for personnel to be aware and vigilant with their handling of documents containing PII," said Col. Eric Oliver, the 24th Air Force director of cyber systems.

The tool's new usage is still in its initial stage, focusing on social security numbers. Developers hope that DSET will ultimately be able to scan for a variety of PII to prevent future breaches.

"It is imperative that we protect one another as we move each Air Force mission forward," said Maj. Gen. J. Kevin McLaughlin, the 24th Air Force commander. "Avoiding the release of PII is part of being a good wingman, but it is also part of protecting the network and accomplishing the Air Force mission."

In preparation for the release of DSET, you can access training for the new tool using the following link:
https://afpki.lackland.af.mil/assets/files/OE-15-40-064_QRG-DSET_v0001.pdf

Additional training on how to encrypt Microsoft Office documents can be accessed at: http://www.24af.af.mil/shared/media/document/AFD-140701-064.pdf

Users have multiple tools at their disposal to protect PII if encrypting e-mail is not feasible, but if electronic transmission of sensitive PII is operationally required, users can leverage approved Department of Defense file exchange services at: https://safe.amrdec.army.mil/safe/
USAF Comments Policy
If you wish to comment, use the text box below. AF reserves the right to modify this policy at any time.

This is a moderated forum. That means all comments will be reviewed before posting. In addition, we expect that participants will treat each other, as well as our agency and our employees, with respect. We will not post comments that contain abusive or vulgar language, spam, hate speech, personal attacks, violate EEO policy, are offensive to other or similar content. We will not post comments that are spam, are clearly "off topic", promote services or products, infringe copyright protected material, or contain any links that don't contribute to the discussion. Comments that make unsupported accusations will also not be posted. The AF and the AF alone will make a determination as to which comments will be posted. Any references to commercial entities, products, services, or other non-governmental organizations or individuals that remain on the site are provided solely for the information of individuals using this page. These references are not intended to reflect the opinion of the AF, DoD, the United States, or its officers or employees concerning the significance, priority, or importance to be given the referenced entity, product, service, or organization. Such references are not an official or personal endorsement of any product, person, or service, and may not be quoted or reproduced for the purpose of stating or implying AF endorsement or approval of any product, person, or service.

Any comments that report criminal activity including: suicidal behaviour or sexual assault will be reported to appropriate authorities including OSI. This forum is not:

  • This forum is not to be used to report criminal activity. If you have information for law enforcement, please contact OSI or your local police agency.
  • Do not submit unsolicited proposals, or other business ideas or inquiries to this forum. This site is not to be used for contracting or commercial business.
  • This forum may not be used for the submission of any claim, demand, informal or formal complaint, or any other form of legal and/or administrative notice or process, or for the exhaustion of any legal and/or administrative remedy.

AF does not guarantee or warrant that any information posted by individuals on this forum is correct, and disclaims any liability for any loss or damage resulting from reliance on any such information. AF may not be able to verify, does not warrant or guarantee, and assumes no liability for anything posted on this website by any other person. AF does not endorse, support or otherwise promote any private or commercial entity or the information, products or services contained on those websites that may be reached through links on our website.

Members of the media are asked to send questions to the public affairs through their normal channels and to refrain from submitting questions here as comments. Reporter questions will not be posted. We recognize that the Web is a 24/7 medium, and your comments are welcome at any time. However, given the need to manage federal resources, moderating and posting of comments will occur during regular business hours Monday through Friday. Comments submitted after hours or on weekends will be read and posted as early as possible; in most cases, this means the next business day.

For the benefit of robust discussion, we ask that comments remain "on-topic." This means that comments will be posted only as it relates to the topic that is being discussed within the blog post. The views expressed on the site by non-federal commentators do not necessarily reflect the official views of the AF or the Federal Government.

To protect your own privacy and the privacy of others, please do not include personally identifiable information, such as name, Social Security number, DoD ID number, OSI Case number, phone numbers or email addresses in the body of your comment. If you do voluntarily include personally identifiable information in your comment, such as your name, that comment may or may not be posted on the page. If your comment is posted, your name will not be redacted or removed. In no circumstances will comments be posted that contain Social Security numbers, DoD ID numbers, OSI case numbers, addresses, email address or phone numbers. The default for the posting of comments is "anonymous", but if you opt not to, any information, including your login name, may be displayed on our site.

Thank you for taking the time to read this comment policy. We encourage your participation in our discussion and look forward to an active exchange of ideas.