H The Entity
Stay Safe in any place
Free Cybersecurity Awareness Training
Part 1 and Part 2
Time: 0:00 - 31:27
Recording password: NudnTGY6
Time: 0:00 - 8:51
Recording password: cJyU3men
About
H The Entity was formed to educate everyday users and businesses on Information Technology safety. Whether you use laptops, tablets, or a phone to conduct business, pay bills, complete school work, or plan personal travel, we aim to help users do so in the safest way possible. We highlight methods and tools that can be used in your personal life or business to protect consumers during online activity.
H The Entity.
Educate.
Train.
Spread IT Safety Knowledge.
Best Practices For Organizations
Quarterly Feature:
Securing organizational assets regarding policies for acceptable use, mobile devices, passwords, and personally identifiable information (PII)
Acceptable Use Policy
Acceptable Use Policy (AUP) sets rules for technology use, preventing misuse, data leakage, and ensuring compliance.
NIST SP 800-53 (PL-4) clarifies this rule via a control statement:
a. Establish and provide to individuals requiring access to the system, the rules that describe their responsibilities and expected behavior for information and system usage, security, and privacy.
b. Receive a documented acknowledgment from such individuals, indicating that they have read, understand, and agree to abide by the rules of behavior, before authorizing access to information and the system.
c. Review and update the rules of behavior [Assignment: organization-defined frequency] ; and
d. Require individuals who have acknowledged a previous version of the rules of behavior to read and re-acknowledge [Assignment (one or more): [Assignment: organization-defined frequency] , when the rules are revised or updated]. (2024)
Mobile Devices and Passwords
NIST SP 800-53 (AC-19) Access Controls for Mobile Devices states how access should be handled via the following control statement.
a. Establish configuration requirements, connection requirements, and implementation guidance for organization-controlled mobile devices, to include when such devices are outside of controlled areas; and
b. Authorize the connection of mobile devices to organizational systems. (Tools, 2024)
Passwords
NIST guidance emphasizes that passwords should be at least 15 characters long and that special characters and numbers enhance password complexity.
“NIST guidance recommends that a password should be at least 15 characters long. At 100 billion guesses per second, it would take a computer more than five hundred years to guess all the possible combinations of 15 lowercase letters.”
(JMiks & Shutterstock, 2025)
“NIST no longer recommends that passwords require special characters and numbers. But that doesn’t mean you can’t include them in your own passwords. Ultimately, adding these extra complexities will make the password harder to guess, but it’s more important for the password to be long, so that should be your main priority. That said, you may not have a choice, as many websites still require numbers, capital letters and special characters, but that may change as more websites adopt NIST’s new guidance.”
(JMiks & Shutterstock, 2025)
Personally Identifiable Information (PII)
NIST SP 800-122 explains steps an organization can take to secure PII and to reduce the likelihood of harm caused by a breach involving PII. Suggestions such as minimizing the amount of PII collected and stored, reviewing current holdings of PII for relevance and accuracy, developing a schedule for periodic review of PII holdings; and establishing a plan to eliminate the unnecessary collection and use of social security numbers (SSNs).
NIST SP 800-122 states “The likelihood of harm caused by a breach involving PII is greatly reduced if an organization minimizes the amount of PII that it uses, collects, and stores.
OMB (see Memorandum M-07-16 in the More Information section below) specifically requires agencies to:
• Review current holdings of PII and ensure they are accurate, relevant, timely, and complete
• Reduce PII holdings to the minimum necessary for proper performance of agency functions
• Develop a schedule for periodic review of PII holdings
• Establish a plan to eliminate the unnecessary collection and use of social security numbers (SSNs).” (Radack, 2010)
Applying Appropriate Safeguards for PII
NIST SP 800-122 states that organizations should apply safeguards for PII based on the PII confidentiality impact level.
NIST recommends using security controls, operational safeguards and privacy-specific safeguards. Details on these suggestions are noted below:
“NIST recommends using operational safeguards, privacy-specific safeguards, and security controls, such as:
● Creating Policies and Procedures. Organizations should develop comprehensive policies and procedures for protecting the confidentiality of PII.
● Conducting Training. Organizations should reduce the possibility that PII will be accessed, used, or disclosed inappropriately by requiring that all individuals receive appropriate training before being granted access to systems containing PII.
● De-Identifying PII. Organizations can de-identify records by removing enough PII such that the remaining information does not identify an individual and there is no reasonable basis to believe that the information can be used to identify an individual. De-identified records can be used when full records are not necessary, such as for examinations of correlations and trends.
● Using Access Enforcement. Organizations can control access to PII through access control policies and access enforcement mechanisms (e.g., access control lists).
● Implementing Access Control for Mobile Devices. Organizations can prohibit or strictly limit access to PII from portable and mobile devices, such as laptops, cell phones, and personal digital assistants (PDA), which are generally higher-risk than non-portable devices (e.g., desktop computers at the organization‘s facilities).
● Providing Transmission Confidentiality. Organizations can protect the confidentiality of transmitted PII. This is most often accomplished by encrypting the communications or by encrypting the information before it is transmitted.
● Auditing Events. Organizations can monitor events that affect the confidentiality of PII, such as inappropriate access to PII.” (McCallister et al., 2010)
NIST SP 800-122 also states:
“Organizations should develop an incident response plan to handle breaches involving PII.” (McCallister et al., 2010)
What are the guidelines for mobile device use?
When using mobile devices, ensure that they are secured with strong passwords and updated regularly. Avoid connecting to public Wi-Fi networks without a VPN, and always lock your device when not in use to prevent unauthorized access.How should I manage my passwords and what about 2FA?
Use complex passwords that combine letters, numbers, and symbols. Change your passwords regularly and avoid using the same password across multiple accounts. Consider using a password manager to keep track of your credentials securely.
Incorporating 2 Factor Authentication(2FA) into your online practices is highly recommended.
2FA can help protect your unique login credentials from misuse for school, work and when conducting personal business you want to keep confidential such as working with banks.
One secondary (2 Factor) method of authenticating a user's login outside of a password is called something you have. This refers to a device such as your mobile phone or another mobile device type. The idea is that once you provide your password at your login attempt and the system you are attempting to access requests your 2FA credentials, a code (with a time usage expiration. For example, 5 minutes) will be generated and sent to your device you have registered for 2FA.
Since the device is something that only you ideally should have, only you would have access to the device and can enter the code needed to complete the login attempt.
What is personally identifiable information (PII)?
PII refers to any data that can be used to identify an individual, such as names, addresses, phone numbers, and social security numbers. Protecting PII is crucial to maintaining privacy and preventing identity theft.How can I protect my PII?
Limit the sharing of your PII online and be cautious about the information you provide to websites. Use encryption tools when transmitting sensitive data and regularly review your privacy settings on social media platforms.What should I do if I suspect a security breach?
If you suspect a security breach of one of your online accounts, immediately change your password and notify the business (bank, school, airline etc) where you believe the breach occurred. Monitor your accounts for unusual activity and consider placing a fraud alert on your credit report.
References
Atlassian. (2025). Get to know the incident response lifecycle. https://www.atlassian.com/incident-management/incident-response/lifecycle#incident-response-for-devops
CSF Tools. (2024, December 6). Rules of behavior - CSF tools. CSF Tools - The Cybersecurity Framework for Humans. https://csf.tools/reference/nist-sp-800-53/r5/pl/pl-4/
JMiks, & Shutterstock. (2025, August 20). How do I create a good password?. How Do I Create a Good Password? https://www.nist.gov/cybersecurity/how-do-i-create-good-password#:~:text=NIST%20guidance%20recommends%20that%20a,combinations%20of%2015%20lowercase%20letters
McCallister, E., Grance, T., & Scarfone, K. (2010, April). Guide to Protecting the Confidentiality of Personally Identifiable Information (PII) - NIST technical series publications. National Institute of Standards and Technology. https://nvlpubs.nist.gov/nistpubs/legacy/sp/nistspecialpublication800-122.pdf
Merritt, M., Hansche, S., Ellis, Dr. B. E., Sanchez-Cherry, K., Snyder, J. N., & Walden, D. (2024, September). NIST Special Publication 800 NIST SP 800-50R1. National Institute of Standards and Technology. https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-50r1.pdf
National Institute of Standards and Technology. (2020, September). NIST Special Publication 800-53 revision 5 security and Privacy Controls for. National Institute of Standards and Technology. https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r5.pdf
NICCS. (2025, August 28). Nice Workforce Framework for cybersecurity (NICE frame
work) | NICCS. National Initiative for Cybersecurity Careers and Studies. https://niccs.cisa.gov/tools/nice-framework
OVH SAS. (n.d.). What is a Business Continuity Plan?. OVHcloud. https://www.ovhcloud.com/en-ie/learn/what-is-business-continuity-plan/#:~:text=Lack%20of%20Executive%20Buy%2DIn%20and%20Resources%20One,insufficient%20allocation%20of%20time%2C%20budget%2C%20and%20personnel
Radack, S. (2010, April). ITL bulletin for April 2010. GUIDE TO PROTECTING PERSONALLY IDENTIFIABLE INFORMATION. https://tsapps.nist.gov/publication/get_pdf.cfm?pub_id=905656
Security Standards Council, P. (2015, May 15). PCI DSS Quick Reference Guide Understanding the Payment Card Industry. https://listings.pcisecuritystandards.org. https://listings.pcisecuritystandards.org/documents/PCIDSS_QRGv3_1.pdf
TASK FORCE, J. (2020, September). NIST Special Publication 800-53 revision 5 security and Privacy Controls for. National Institute of Standards and Technology. https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r5.pdf
The Regents of the University of California - University of California, San Francisco, Controller’s Office. (n.d.). Understanding payment card industry data security standard (PCI DSS). Understanding Payment Card Industry Data Security Standard (PCI DSS) | Controller’s Office.
Tools, C. (Ed.). (2024, December 6). Access control for mobile devices - CSF tools. CSF Tools - The Cybersecurity Framework for Humans. https://csf.tools/reference/nist-sp-800-53/r5/ac/ac-19/
Wolford, B. (2023, September 14). Does the GDPR apply to companies outside of the EU?. GDPR.eu. https://gdpr.eu/companies-outside-of-europe/#:~:text=The%20GDPR%20is%20an%20EU,territorial%20scope%20of%20the%20law:
Stay Secure
Stay Informed
Organizations that develop an Acceptable Use Policy, and Incident Response Plan fortify their networks and prepare key IT members to respond if any breach of data or systems occur.
H The Entity
Contact us
We're here to help! Send any questions you have over to us. We look forward to hearing from you.
Get in Touch
Have questions about cybersecurity or our content? Fill out the form below, and our team at H The Entity will get back to you.
