Practices, policies key to data security


On Board Online • June 13, 2016

By Jessica Goldstein
Deputy Director of Policy Services

"Data breach!" Does that phrase conjure an image of hackers in a dark room, possibly in another country, infiltrating your computer network using advanced coding skills honed from years of nefarious activities? Or do you picture a disgruntled employee, surreptitiously copying files to be sold or made public?

In reality, however, data breaches typically lack such drama. They can occur due to a multitude of reasons, ranging from infiltration by high tech wizards to the most mundane forms of carelessness - like failing to pay attention to the name in the "To" email field and sending confidential information to the wrong party.

School boards must be aware of these potential weak points and ensure that the proper practices and policies are in place.

Human error dominates public sector data breaches

The public sector in particular is more likely to have a data breach from human error "oops" moments than from Mission Impossible-esque capers involving copied fingerprints, faked retinal scans, and rappelling from the air vents.

For a comprehensive examination of the subject, check out Verizon's 2016 Data Breach Investigations Report (their ninth annual). It contains a wealth of information detailing how and why data breaches occur, and what to do about them, delivered with a healthy dose of humor. In the public sector, human error was the most common causes of data breaches (see chart).

While many employers and organizations try to keep 100 percent of the data out of the public, school districts have a mixture of information that it has a duty to disclose and other information that it must keep confidential. Some information is made confidential by state and federal laws relating to students, such as information pertaining to grades, discipline or health/medical information. , , programs, services, the nature of the disability). Protecting access to this information is a legal responsibility.

Other types of information are discretionary - allowed to be disclosed or withheld. Sensitive information that should always be protected includes:

  • Financial - district bank account numbers (e.g., of the district, employees, or vendors), credit card numbers (e.g., of the district, employees, or parents), access codes or passwords.
  • Personnel - information pertaining to employees, such as social security numbers, driver's license numbers, credit history, payroll deductions/withholdings/garnishments, tax information, retirement information, counseling memos, performance review evaluations (in some circumstances), certain disciplinary records, and medical records.
  • Educational - test questions and answers prior to the test being given.
  • Managerial/governance - litigation or negotiations strategies, information about buying or selling real estate prior to the sale.

Due to the complexity of this issue, school districts need to work with their attorneys to ensure that the types of information that must be protected under the law, and that which may be protected, is identified and communicated to those individuals who have control over release of that information.

Buy-in, training and testing

To combat these areas of potential weakness, it is essential to have proper technological and internal controls. However, if staff do not buy-in to your processes, even the best possible system can fail to protect data. Somewhere in between internal information technology (IT) protocols and staff training are employee handbooks. This is a good place to put staff expectations in plain language for easy reference.

Like school emergency drills, it is crucial to periodically test your system to make sure it is functioning correctly.

Strengthen your board policies

There is no substitute for a skilled IT team devising and implementing procedures designed to safeguard district data. Nor can you overlook the significance of appropriately trained staff who understand their roles and responsibilities.

However, boards should also set the tone and expectations from the top - i.e., board policy. Earlier this year, NYSSBA Policy Services modified some of its sample board policies to provide stronger internal controls over sensitive district information:

1120, School District Records (policy and regulation). Make sure that district personnel in charge of releasing district records are aware of their responsibilities, and are appropriately trained in the types of information to be withheld.

4750, Grading Procedures. Ensure that the proper personnel have access to input and change student grades, and that changes to grades are appropriately documented. (See "What would the state comptroller say about your grading policy?" in the January 25 issue of On Board 1/25/16.)

6900, Disposal of District Property. When reassigning, discarding or selling equipment or supplies that contains district data, make sure such data is permanently and completely removed. If that cannot be done, the equipment/supplies should be destroyed prior to discarding or selling.

8630, Computer Resources and Data Management (policy and regulation). This policy already set expectations for passwords, remote access, encryption, data back-up, and disaster recovery. We strengthened this policy and regulation to direct district administrators to address user access permissions, disposal of equipment, and inventory of computer resources. The regulation also now requires staff to take reasonable precautions in responsible use of district devices to protect sensitive or confidential information. Such behavior includes protecting passwords and not leaving devices unattended.

NYSSBA also recommends you review the following policies:

4526, Computer Use in Instruction (aka the Acceptable Use Policy). This policy should set expectations, acceptable uses, and unacceptable conduct for users of the district's network, including prohibiting uploading software, or accessing private or off-limit areas. If students are allowed to access the district's network on their own devices, additional security layers should be implemented.

5500, Student Records. NYSSBA revised this policy and regulation in 2014 to address state requirements known as the "Parents Bill of Rights for Data Privacy and Security" pertaining to agreements with third-party vendors with access to student personally identifiable information.

If you would like samples of the policies referenced above, please call (800) 342-3360 or email policy@nyssba.org .




Back to top