Good morning,
I'm working as a program manager for a state agency within a multi-agency IT program, which, due to lack of funding is getting (at least temporarily) shut down. The decision was made to move the system and its contents into warm storage. Since this is a federated data system, we have a series of API calls with each partner agency to exchange data between each partner agency and a central hub. While the central hub does not "own" the data, it serves to pull in data from various sources (state agencies) to pre-populate customer data and send that as a referral to another participating agency. Very few, if any resources in this program (at least on the state side) have experience in this sort of with this.
Given my CIO's primary concern being data security (and justifiably so), what are some best practices to ensure that our data is protected in moving this federated system into warm storage? Should we be shutting down API connections? Should we request each partner agency remove (and certify that removal) of the data that we shared with them while the system was active?
This was unforeseen by the program, and we are doing our best to mitigate the risk on an extremely tight timeline, as funding expires at the end of the year. Any guidance would be much appreciated.
Thanks!