Effective immediately, Handbook AS-805, Information Security, is revised. The November 2009 edition has been updated to do the following:
n Correct some conversion-related minor errors.
n Comply with Payment Card Industry Data Security Standard version 1.2.
n Add a new section for protection of Postal Service™ information during international travel.
n Add a new section for protection of application source code.
n Add a new section on password expiration of Oracle database schema accounts.
n Add a new section for use of nonexpiring service accounts.
Handbook AS-805 is now available on the Postal Service PolicyNet website:
n Go to http://blue.usps.gov.
n Under “Essential Links” in the left-hand column, click PolicyNet.
n On the PolicyNet page, click HBKs.
(The direct URL for the Postal Service PolicyNet website is http://blue.usps.gov/cpim.)
The direct URL for Handbook AS-805 (November 2009) is http://blue.usps.gov/cpim/ftp/hand/as805.pdf (PDF version) and http://blue.usps.gov/cpim/ftp/hand/as805/welcome.htm (HTML 508-compliant version)
Note: Offices should update references/links to Handbook AS-805 in local documents.
— Corporate Information Security, Chief Information Officer, 1-14-10