Scan for Confidential Data: Mac
The information in this article is intended technical staff who support end-users. It is unusual for an end-user to need this information.
This article applies to: Spirion (formerly Identity Finder)
Spirion is a tool to help you locate stored confidential data, but you'll need to work through the results before you can be sure your machine is in compliance with University policy and local practices. Spirion is configured to run automatically, but you can also perform manually-triggered scans.
The copy of Spirion installed has been configured by Cornell to scan specific areas of your machine and to look for particular data types. Cornell classifies as confidential any of the following (when they appear in conjunction with an individual’s name or other identifier):
- Social Security numbers
- Credit card numbers
- Driver’s license numbers
- Bank account numbers
- Protected health information, as defined by HIPAA (Data scanning tools cannot identify this type of data. You'll need to search for it separately.)
- Spirion produces a list of possible matches.
- You must check each match and decide how to handle it securely.
Spirion does not scan Outlook mailbox files. You are strongly encouraged to scan your mailbox folders by eye. If you do find confidential data in your mail folders, delete the message and then empty the Trash. Policy 5.10 states that you should not send confidential data in email unless it is encrypted.
Scan for Confidential Data
It is a good idea to back up your machine before scanning. If you shred data accidentally, you can recover it from the backup.
- In a Finder window, open the Applications folder, and then double-click Spirion.
Enter your Spirion password, and then click
If this is the first time you are using Spirion, you'll be asked to create a new password. Do not use your NetID password. Enter the new password, enter it again to confirm, and then click .
- Click .
- Spirion begins scanning. To pause the scan, click .
(optional) You can save the list of scan results, if desired.
- From the File menu, choose Save.
- For Save As, enter a name for the file.
- From the Location list, choose a location to save the file.
- For Password, enter a password for the file.
- For Confirm, re-enter the password.
- Click Save.
Review the list of files identified by the scan.
You must look at each file and decide how to deal with it. Always follow local practices to determine the best way to handle files identified by the scan.
- When you have dealt with all the files in the list, quit Spirion.
Warning: Using Spirion to shred email will shred or corrupt your entire mailbox. If confidential data is identified in an email message, to permanently delete the mail message without damaging your mailbox, open your email application, delete the message, then empty the trash and compact your folders.