Content area
Full Text
alleges and universities are Increasingly falling victim to information security breaches and data exposures. According to the Privacy Rights Clearinghouse, more than 1,5 million records were exposed in the 84 breaches disclosed by educational institutions in ton. In 1O13, we saw big data breaches ara range ofhigher learning orgaiiiîadons, including the University of Maryland, Indiana University and Johns Hopkins University.
No college or university is immune, regardless of site, What was once an occasional problem is now something chat happens with startling regularity, and higher learning institutions may soon view privacy breaches as ncar-cmain events. Thoughtful planning and effective resource deployment arc crucial to stem die tide,
EDUCATIONAL CHALLENGES
Each industry faces unique challenges in managing the security and privacy of the information they possess. The open, collaborative environment of most colleges is often counter to the control required for proper treatment of confidential information.
The systems and network assets used by students and faculty often evolve over time-for example, computers and servers used to store enroll ment i nformation can be 5« aside after a class endsLater, they can be pot back into service without being cleaned, exposing legacy data to the entire student and faculty population-, or worse, the internet.
Because data assets may be managed by individual students or faculty outside of a records or information management program, colleges have a difficult time keeping track of the type and amount of sensitive data they hold, The range of information collected by and stored within these systems not only encompasses current students and faculty, but also applicants, administrative Staff, alumni, collaborators, research and project participants, vendors and even parents.
In many cases, 'consumer data' is lurking in the environment without adequate protection. Student applications necessarily contain personally identifiable information as part of the admission process. As students and their parents pay tuition, housing and meal costs, payment card information is processed through the university's systems. Students who visit a campos health center will have their personal health information stored in their medical records.
Educational institutions housing intellectual property and research projects often produce massive amounts of information, some of which include data on research subjects and participants. Collaborations may bring in datasets that involve commercial partners or govern ment entities. Each typeofdata should...