University Business - September 2007 - (Page 63)

‘you’re exposing the college and yourself to security and confidentiality issues’ by transferring data to a laptop,” he says. They will also be informed that information should not be taken off campus and that such data should only be accessed remotely through a VTN line-encrypted server. Fill the Security Gaps Most security training is designed to guard SISs from the outsider, when teaching system users how to use technology to safeguard personal information is equally—and perhaps more—important. “A lot of the security training that needs to be provided is awareness-type training,” says Volz. EDUCAUSE’s Petersen advises that it is increasingly important to emphasize the following as part of any security training session: • Roles and responsibilities. Make it clear what information each SIS user is authorized to access and who is a “data steward”—someone authorized to share confidential data with others. For example, in student records, the data steward is frequently the registrar. • Security practices. Training users in such tactics as password protection, operating system updates, antivirus protection, and spyware protection, to fortify the system’s defenses. • Privacy protections for personally identifiable information (PII). This includes: limiting the type of information that is accessed or displayed to that which is essential for the function to be performed; limiting downloads of SIS data into spreadsheets or other formats to workstations, laptops, or storage devices unless the data is encrypted or under strict controls; and effective methods of disposing of devices or data. User group: Coppin State recruited faculty and students to determine how much training would be needed on a new security system. weight). However, years ago, student Social Security numbers were also routinely published, he says. “Rules change over time to address the threats that are out there,” he explains. More recently, the university decided it would no longer publish e-mail addresses. That doesn’t necessarily mean that all students are included in the institution’s directory, however, since FERPA provides students the option to prohibit release of any personal information. Most SISs have an attribute, or field, within the system to identify students who have declared their privacy rights, says Volz. Spotting that attribute can be tricky, however, and system users need to be trained to look for that identifier to prevent unauthorized release of information. Make Training an Ongoing Effort At Ursinus College in Collegeville, Pa., Chief Information Officer John King reports that the institution’s approach to security and confidentiality has been revamped in the last three to four years. “We’ve had some turnover, but no incidents, and we wanted to make sure everyone understood their role in securing data and the importance of confidentiality,” King explains. Today, security training is done on an ongoing basis at Ursinus, following a process the college has developed to ensure that everyone is aware of the college’s policies and their own responsibility. When new employees are hired they are required to complete and sign a form indicating their understanding of the college’s data security policies and procedures. Learning the importance of information security is now part of the college’s orientation procedure, which also applies to student workers. Their supervisor sits down with them to review the policies and procedures and they, too, sign the confidentiality form indicating their understanding and compliance. The college is in the process of implementing a new SIS—the Blackbaud Education Edge—and as part of that, says King, they will incorporate a new module into the security training regarding safeguarding data on laptops. “We’ll remind [employees] that universitybusiness.com ‘The breaches are absolutely increasing in frequency.’ —Rob Guido, Oracle Identify Weaknesses Cindy Bixler, CIO of Embry-Riddle Aeronautical University, which has campuses in Prescott, Ariz., Daytona Beach, Fla., and at more than 130 centers in the United States through its Worldwide Campus, says that about two years ago the university instituted an integrated student services training program for staff to increase awareness of the need for data security. While that training has been successful, there is currently no ongoing training to remind longtime employees of their responsibilities and to correct risky behavior, such as downloading information from the university’s core SIS onto a laptop or USB drive. The university is conducting an information systems audit of its Oracle Portal with the help of Ernst & Young, whose auditors are looking over the system to identify weaknesses that need to be addressed. Bixler says that lack of ongoing security training will September 2007 | 63 http://universitybusiness.com

Table of Contents for the Digital Edition of University Business - September 2007

University Business - September 2007
Contents
College Index
Company Index
Advisory Board
Editor's Note
People Watach
Sense of Place
Viewpoint
Human Resources
Money Matters
Financial Aid
Community Colleges
Una Fuerza to Reckon With
The Right Stuff
Making an Impact
Going VoIP
Training Your Staff to Protect SIS Data
Summer Conference Report
Business Technology
What's New
Calendar of Events
End Note

University Business - September 2007

https://www.nxtbook.com/pmg/UB/UB_0520
https://www.nxtbook.com/pmg/UB/UB_0320
https://www.nxtbook.com/pmg/UB/UB_0120
https://www.nxtbook.com/pmg/UB/UB_1119
https://www.nxtbook.com/pmg/UB/UB_1019
https://www.nxtbook.com/pmg/UB/UB_0819
https://www.nxtbook.com/pmg/UB/UB_0719
https://www.nxtbook.com/pmg/UB/UB_0619
https://www.nxtbook.com/pmg/UB/UB_0419
https://www.nxtbook.com/pmg/UB/UB_0319
https://www.nxtbook.com/pmg/UB/UB_0119
https://www.nxtbook.com/pmg/UB/UB_1218
https://www.nxtbook.com/pmg/UB/UB_1118
https://www.nxtbook.com/pmg/UB/UB_1018
https://www.nxtbook.com/pmg/UB/UB_0918
https://www.nxtbook.com/pmg/UB/UB_0818
https://www.nxtbook.com/pmg/UB/UB_0718
https://www.nxtbook.com/pmg/UB/UB_0618
https://www.nxtbook.com/pmg/UB/UB_0518
https://www.nxtbook.com/pmg/UB/UB_0418
https://www.nxtbook.com/pmg/UB/UB_0318
https://www.nxtbook.com/pmg/UB/UB_0218
https://www.nxtbook.com/pmg/UB/UB_0118
https://www.nxtbook.com/pmg/UB/UB_1217
https://www.nxtbook.com/pmg/UB/UB_1117
https://www.nxtbook.com/pmg/UB/UB_1017
https://www.nxtbook.com/pmg/UB/UB_0917
https://www.nxtbook.com/pmg/UB/UB_0817
https://www.nxtbook.com/pmg/UB/UB_0717
https://www.nxtbook.com/pmg/UB/UB_0617
https://www.nxtbook.com/pmg/UB/UB_0517
https://www.nxtbook.com/pmg/UB/UB_0417
https://www.nxtbook.com/pmg/UB/UB_0317
https://www.nxtbook.com/pmg/UB/UB_0217EPUB
https://www.nxtbook.com/pmg/UB/UB_0217
https://www.nxtbook.com/pmg/UB/UB_0117
https://www.nxtbook.com/pmg/UB/UB_1216
https://www.nxtbook.com/pmg/UB/UB_1116
https://www.nxtbook.com/pmg/UB/UB_1016
https://www.nxtbook.com/pmg/UB/UB_0916
https://www.nxtbook.com/pmg/UB/UB_0816
https://www.nxtbook.com/pmg/UB/UB_0816CG
https://www.nxtbook.com/pmg/UB/UB0716
https://www.nxtbook.com/pmg/UB/GlobalSellSheet
https://www.nxtbook.com/pmg/UB/UB_0616
https://www.nxtbook.com/pmg/UB/UB_0516
https://www.nxtbook.com/pmg/UB/UB0416
https://www.nxtbook.com/pmg/UB/UB0316
https://www.nxtbook.com/pmg/UB/UB_0216r2
https://www.nxtbook.com/pmg/UB/UBGuide
https://www.nxtbook.com/pmg/UB/UB0116
https://www.nxtbook.com/pmg/UB/UB
https://www.nxtbook.com/nxtbooks/pmg/ub201511
https://www.nxtbook.com/nxtbooks/pmg/ub201510
https://www.nxtbook.com/nxtbooks/pmg/ub201509
https://www.nxtbook.com/nxtbooks/pmg/ub201508
https://www.nxtbook.com/nxtbooks/pmg/ub201508_ConsultantsGuide
https://www.nxtbook.com/nxtbooks/pmg/ub201507
https://www.nxtbook.com/nxtbooks/pmg/ub201506
https://www.nxtbook.com/nxtbooks/pmg/ub201506_AudioVisualSolutions
https://www.nxtbook.com/nxtbooks/pmg/ub201505
https://www.nxtbook.com/nxtbooks/pmg/ub201504
https://www.nxtbook.com/nxtbooks/pmg/ub201503
https://www.nxtbook.com/nxtbooks/pmg/ub201502
https://www.nxtbook.com/nxtbooks/pmg/ub201501
https://www.nxtbook.com/nxtbooks/pmg/ub201501_FinancialServicesGuide
https://www.nxtbook.com/nxtbooks/pmg/ub201412
https://www.nxtbook.com/nxtbooks/pmg/ub201411
https://www.nxtbook.com/nxtbooks/pmg/ub201410
https://www.nxtbook.com/nxtbooks/pmg/ub201409
https://www.nxtbook.com/nxtbooks/pmg/ub201408
https://www.nxtbook.com/nxtbooks/pmg/ub201408_ConsultantsGuide
https://www.nxtbook.com/nxtbooks/pmg/ub201407
https://www.nxtbook.com/nxtbooks/pmg/ub201406
https://www.nxtbook.com/nxtbooks/pmg/ub201406_AudioVisualSolutions
https://www.nxtbook.com/nxtbooks/pmg/ub201405
https://www.nxtbook.com/nxtbooks/pmg/ub201404
https://www.nxtbook.com/nxtbooks/pmg/ub201403
https://www.nxtbook.com/nxtbooks/pmg/ub201402
https://www.nxtbook.com/nxtbooks/pmg/ub201401
https://www.nxtbook.com/nxtbooks/pmg/ub201401_FinancialServicesGuide
https://www.nxtbook.com/nxtbooks/pmg/ub201312
https://www.nxtbook.com/nxtbooks/pmg/ub201311
https://www.nxtbook.com/nxtbooks/pmg/ub201310
https://www.nxtbook.com/nxtbooks/pmg/ub201309
https://www.nxtbook.com/nxtbooks/pmg/ub201308
https://www.nxtbook.com/nxtbooks/pmg/ub201308_ConsultantsGuide
https://www.nxtbook.com/nxtbooks/pmg/ub201307
https://www.nxtbook.com/nxtbooks/pmg/ub201306_AudioVisualSolutions
https://www.nxtbook.com/nxtbooks/pmg/ub201306
https://www.nxtbook.com/nxtbooks/pmg/ub201305
https://www.nxtbook.com/nxtbooks/pmg/ub201304
https://www.nxtbook.com/nxtbooks/pmg/ub201303
https://www.nxtbook.com/nxtbooks/pmg/ub201302
https://www.nxtbook.com/nxtbooks/pmg/ub201301
https://www.nxtbook.com/nxtbooks/pmg/ub201301_FinancialServicesGuide
https://www.nxtbook.com/nxtbooks/pmg/ub1212
https://www.nxtbook.com/nxtbooks/pmg/ub1112
https://www.nxtbook.com/nxtbooks/pmg/ub1012
https://www.nxtbook.com/nxtbooks/pmg/ub0912
https://www.nxtbook.com/nxtbooks/pmg/ub_cg12
https://www.nxtbook.com/nxtbooks/pmg/ub070812
https://www.nxtbook.com/nxtbooks/pmg/ub0612
https://www.nxtbook.com/nxtbooks/pmg/ub_avguide0612
https://www.nxtbook.com/nxtbooks/pmg/ub0512
https://www.nxtbook.com/nxtbooks/pmg/ub0412
https://www.nxtbook.com/nxtbooks/pmg/ub0312
https://www.nxtbook.com/nxtbooks/pmg/ub0212
https://www.nxtbook.com/nxtbooks/pmg/ub_financeguide0112
https://www.nxtbook.com/nxtbooks/pmg/ub1211
https://www.nxtbook.com/nxtbooks/pmg/ub1011
https://www.nxtbook.com/nxtbooks/pmg/ub0911
https://www.nxtbook.com/nxtbooks/pmg/ub_cg11
https://www.nxtbook.com/nxtbooks/pmg/ub0711
https://www.nxtbook.com/nxtbooks/pmg/ub0611_av
https://www.nxtbook.com/nxtbooks/pmg/ub0611
https://www.nxtbook.com/nxtbooks/pmg/ub0511
https://www.nxtbook.com/nxtbooks/pmg/ub0411
https://www.nxtbook.com/nxtbooks/pmg/ub0311
https://www.nxtbook.com/nxtbooks/pmg/ub0211
https://www.nxtbook.com/nxtbooks/pmg/ub0111
https://www.nxtbook.com/nxtbooks/pmg/ub_financeguide0111
https://www.nxtbook.com/nxtbooks/pmg/ub1110
https://www.nxtbook.com/nxtbooks/pmg/ub1010
https://www.nxtbook.com/nxtbooks/pmg/ub0910
https://www.nxtbook.com/nxtbooks/pmg/ub_2010financeguide
https://www.nxtbook.com/nxtbooks/pmg/ub_2010consultants
https://www.nxtbook.com/nxtbooks/pmg/ub_2010avguide
https://www.nxtbook.com/nxtbooks/pmg/ub0710
https://www.nxtbook.com/nxtbooks/pmg/ub0610
https://www.nxtbook.com/nxtbooks/pmg/ub0510
https://www.nxtbook.com/nxtbooks/pmg/ub0410
https://www.nxtbook.com/nxtbooks/pmg/ub0310
https://www.nxtbook.com/nxtbooks/pmg/ub0210
https://www.nxtbook.com/nxtbooks/pmg/ub0110
https://www.nxtbook.com/nxtbooks/pmg/ub1109
https://www.nxtbook.com/nxtbooks/pmg/ub1009
https://www.nxtbook.com/nxtbooks/pmg/ub0909
https://www.nxtbook.com/nxtbooks/pmg/ub0709
https://www.nxtbook.com/nxtbooks/pmg/ub_fg09
https://www.nxtbook.com/nxtbooks/pmg/ub0609
https://www.nxtbook.com/nxtbooks/pmg/ub0509
https://www.nxtbook.com/nxtbooks/pmg/ub0409
https://www.nxtbook.com/nxtbooks/pmg/ub0309
https://www.nxtbook.com/nxtbooks/pmg/ub0209
https://www.nxtbook.com/nxtbooks/pmg/ub0109
https://www.nxtbook.com/nxtbooks/pmg/ub1208
https://www.nxtbook.com/nxtbooks/pmg/ub1108
https://www.nxtbook.com/nxtbooks/pmg/ub1008
https://www.nxtbook.com/nxtbooks/pmg/ub0908
https://www.nxtbook.com/nxtbooks/pmg/ub0808
https://www.nxtbook.com/nxtbooks/pmg/ub0708
https://www.nxtbook.com/nxtbooks/pmg/ub0608
https://www.nxtbook.com/nxtbooks/pmg/ub0508
https://www.nxtbook.com/nxtbooks/pmg/ub0408
https://www.nxtbook.com/nxtbooks/pmg/ub0308
https://www.nxtbook.com/nxtbooks/pmg/ub0208
https://www.nxtbook.com/nxtbooks/pmg/ub0907
https://www.nxtbook.com/nxtbooks/pmg/ub0807
https://www.nxtbook.com/nxtbooks/pmg/ub0707
https://www.nxtbook.com/nxtbooks/pmg/ub0607
https://www.nxtbook.com/nxtbooks/pmg/ub0507
https://www.nxtbook.com/nxtbooks/pmg/ub0407
https://www.nxtbook.com/nxtbooks/pmg/ub0307
https://www.nxtbook.com/nxtbooks/pmg/ub0207
https://www.nxtbook.com/nxtbooks/pmg/ub0107
https://www.nxtbook.com/nxtbooks/pmg/ub1206
https://www.nxtbook.com/nxtbooks/pmg/ub1106
https://www.nxtbook.com/nxtbooks/pmg/ub1006
https://www.nxtbook.com/nxtbooks/pmg/ub0906
https://www.nxtbook.com/nxtbooks/pmg/ub0806
https://www.nxtbook.com/nxtbooks/pmg/ub0706
https://www.nxtbook.com/nxtbooks/pmg/ub0606-GG
https://www.nxtbook.com/nxtbooks/pmg/ub0606
https://www.nxtbook.com/nxtbooks/pmg/ub0506
https://www.nxtbook.com/nxtbooks/pmg/ub0406
https://www.nxtbookmedia.com