Policy #600 Security

    Approved By:
    ESPCC
    Approval Date:
    February 24, 2012
    Revision Date(s):
    July 27, 2018; January 22, 2021
    Date Last Reviewed:December 8, 2023

    Confidential Documents

    Confidential information is defined in the confidentiality policy #106. All confidential information will be retained in a secure manner as required by this policy.

    Credentialing exams, role delineation studies, cut score reports, item banks, answer keys, and all other exam development documents are confidential and the sole property of the credential program.

    Access

    Access to confidential/secure materials (both printed and electronic) will be limited to only those staff, Council members, and subject matter experts who need to view the information. These individuals will sign a confidentiality agreement before being granted access to any confidential information. 

    Any outside companies, vendors, consultants or contractors given access to confidential information will be required to maintain strict security of all confidential materials.

    Eligibility files, pass/fail files, and examination/testing information will be shared with the designated testing vendor, the testing vendor, through encrypted file sharing software to ensure its secure transmission.

    APSE employees who are involved in developing educational courses are not granted access to exam items, exam forms, or any other confidential exam documentation.

    Physical Security

    Confidential materials in hard copy format will be stored in locked file cabinets and secured in APSE's locked storage unit until such time as they can be scanned for electronic storage or it is no longer necessary to store these documents. All hard copy documents scheduled for disposal will be shredded per Policy 601.

    Electronic Security

    Routine backups will be performed at least weekly for all electronic data and backup data will be stored in a separate off-site location.

    If confidential documents are transmitted via email, or other electronic means, the electronic files will be encrypted and secured with a password before being sent. Confidential materials stored on CD-ROM or similar media will be encrypted and password protected.

    Confidential materials stored on APSE servers and hard drives will have limited, password protected access for authorized credential program personnel only. Personal computers/laptops will be password protected.

    Exam Administration

    The testing vendor, and Exam Hosting Location Liaison for hosted exams, will ensure that the examination is administered securely and in a standardized method to ensure a fair and consistent testing experience for all candidates.

    To provide a fair and consistent environment for all candidates, the exam is delivered using standardized procedures and following strict security protocols. Candidates are required to follow all proctored examination rules at all times.

    Examination time limits have been developed by the ESPCC in consultation with the testing/psychometric consultant. Time limits will allow sufficient time for completing the exam without providing unnecessary additional time that could facilitate security breaches by test takers.

    Security Violations

    The continued security of the examination is an essential component of all phases of the exam development, maintenance, and administration process.

    A test security plan is a comprehensive collection of policies, procedures, and documents that outline a guide of actions related to exam security. The ESPCC has approved thresholds for behavior for test taker conduct as outlined in the Candidate Handbook.

    Irregularities observed during the testing period, including but not limited to creating a disturbance, giving or receiving unauthorized information or aid to or from other persons, or attempting to remove test materials or notes from the testing room, may be sufficient cause to terminate candidate participation in the examination administration or to invalidate scores. Routine statistical and psychometric analyses (data forensics) and regular web searches for compromised content should be conducted.
    • Any candidates possessing prohibited items in the examination area shall immediately have his or her test results invalidated.
    • Any candidates who leave the examination area without pre-approved breaks shall immediately have test results invalidated.
    • Any candidates seen giving or receiving assistance on an examination, found with unauthorized materials, or who violates any security regulations shall immediately have test results invalidated.
    • Copying or communicating examination content is in violation of a candidate’s contract with the ESPCC/APSE, and federal and state law. Either may result in the disqualification of examination results and may lead to legal action.
    • No exam questions are to be discussed during or after the exam administration. Any infraction of these terms is considered to be a violation of the ESPCC Code of Conduct. It is also a violation of copyright law and exam security.
    NOTE: If any of these are violated, the candidate’s test will be suspended. Individuals will need to reschedule your exam and may incur an additional fee.

    When security violations are brought to the Credentialing Director and/or assigned APSE staff for investigation and/or correction, the ESPCC follows the Disciplinary Policy outlined in Policy #400.