Gate-Swipe Data Flow
Data captured by the Siemens gate system is managed by the HUPD.  This system does not comprehensively capture the data points desired by the Harvard Library. HUPD PACS Data will be augmented with data from IAM.  Anonymized data will be securely stored in an LTS maintained database, and exposed to authorized users via HART.
Data Flow
- Library users swipe into libraries using SIEMENS CCure system.
- User data is written to the HUPD PACS SystemsÂ
- Weekly report of key person data points (HUID, Date/Time Stamp, Swipe location/door name) is created and pushed to secure location for library use.
- Scott Waite to confirm with HUPD signoffs needed for data feed.
- Scott Waite to confirm details of secure file transfer with SIEMENS. Preference is that data file with be automatically pushed to an LTS, but LTS could script secure retrieval if needed.
- What breach plan would be in place for monitoring and resolving unauthorized access to this file?
- Is there need for an opt-out notice for users? Advanced notice of tracking?
- LTS script uses HUID to retrieve additional data points about the library user.
- Steve Beardsley to confirm with IAM that PDS API, rather than a DB view, would be used to retrieve data.
- Steve Beardsley to confirm sign off process with IAM for access to data.
- Allison Powers will review the desired data fields spec drafted by Steve Beardsley and Kim Noh with Kara Young.
- Steve Beardsley and Kim Noh will finalize IAM code mapping logic.
- Laura Morse will facilitate EAI review process with HUIT.
- Should EPPN be used for primary key for user records? Or would this need to be hashed in someway.
- LTS writes anonymized record for each swipe to database.
- Sharon Bayer will determine database to environment for the anonymized data.
- Allison Powers will finalize technical spec for PACS data file retrieval.
- Allison Powers will finalize technical spec for IAM process to retrieve people data/map IAM codes to HL desired codes.
- Allison Powers will finalize technical spec for writing records to the database.
- ProdOps assignee will script PACS data file retrieval.
- ProdOps assignee will script IAM people data record retrieval/mapping transformation.
- ProdOps assignee will script writing to gate-swipe database.
- What breach plan would be in place for monitoring and resolving unauthorized access to this data files create as part of update process as well as direct access to database?
- Authorized users use HART to access data.
- Rachel Lewellen and Allison Powers will draft policies related to authorized user requirements and login provisioning workflow.
- Rachel Lewellen and Allison Powers will draft policies on publication and reuse of gate-swipe data (into other systems like tableau, and for internal and external formal and informal communications/dashboards).
- Allison Powers will create model to expose gate-swipe database in HART.
- Sharon Bayer will perform Tableau Server security review.
- Team will review policies.
- Allison Powers will update HART wiki pages with data model and policy information.
- Allison Powers/Rachel Lewellen will announce service.
- Should Hart be the primary took used to access this data?
- What breach plan would be in place for monitoring and resolving unauthorized access to this data files create as part of update process as well as direct access to database?