Topics Map > Office of Cybersecurity > Tools and Software > Spirion
Spirion (Identity Finder) - Taking Action on the Scan Results
This document discusses general considerations when evaluating the results of scans. More detailed information can be found in the Spirion Help documentation in the Protecting Personal Information Topic. All documentation was performed with the Windows client of Spirion version 11.7.1.
Note: All data shown is false.
Viewing Scan Results
When Spirion finishes a scan, the user is returned to the Main window.
The main windows has two sections. The left section is the results pane and the right section is the preview pane.
The results pane shows found matches, their location, and other attributes where possible data matches (eg. SSN and CCN) were found.
If more than one match was found within a file, all matches can be displayed by clicking the icon next to the location name.
The preview pane highlights sensitive information within the context of the file. This allows you check the found match to ensure that it is sensitive information that must be secured or if it is a false positive eg. a 9-digit number in the same format as a SSN (which is not sensitive information).
Taking Action on Scan ResultsAcross the top of the Main Spirion Window are buttons that correspond to actions you can take on found matches highlighted in the results pane.
An action can be taken on a single file or on a group of files. Multiple files can be selected by checking the box next to each file you wish to perform actions on.Shred:
If a file has sensitive information in it and you are sure you do not need the file, use the Shred feature. Unlike a normal delete, Shred wipes the data from the disk, byte by byte, so that it can never be recovered either by you or by an adversary.
Encrypt (not recommended):
This option encrypts the file containing the match. The risk is that there is no password recovery feature available, so if the password is lost, the data can not be recovered.
When a file has sensitive information and you wish to move it to a secure location, you should use the Quarantine feature. Quarantine moves the file and shreds the original so that the data can not be accessed by someone who gains access to your computer. It is important for the quarantine location to be highly secure, such as an encrypted hard drive or location that unauthorized individuals do not have access to.
This option allows you to classify the match. Classifications allow you to track the severity of the match, ranging from Low to Confidential.
This feature will overwrite sensitive data, such as SSNs, with X or some other placeholder character you choose, but leaves other data unchanged. This is often appropriate with older records that included SSNs unnecessarily. Like shred, this is an irreversible step. Use with caution.
If the file does not contain sensitive information (a false positive) or it is sample data, you can choose to ignore the results. This will add the file to the Ignore List. The file will not be scanned in subsequent scans and it will not show up in the results list.