EDUCAUSE | Privacy http://www.educause.edu/Resources/Browse/Privacy/16915 en EDUCAUSE | Privacy http://www.educause.edu/Resources/Browse/Privacy/16915 http://www.educause.edu/sites/all/themes/educause/images/e_rss.png Getting Started in Privacy: Recommendations from the Higher Education Chief Privacy Officers (HE-CPO) http://www.educause.edu/library/resources/getting-started-privacy-recommendations-higher-education-chief-privacy-officers-he-cpo <p>Whether you are a Chief Privacy Officer (CPO) at your institution, have responsibility for privacy on your campus, or just want to learn more about becoming a privacy professional in higher education, this list of key resources compiled by current CPOs is a great starting point. Find out where to learn more about privacy (listservs, newsletters, conferences, or webinars), which standards you should be familiar with, recommended reading, joining professional organizations, how to become a certified privacy professional, and how to convince your institution that privacy is important.</p><p><a href="http://www.educause.edu/library/resources/getting-started-privacy-recommendations-higher-education-chief-privacy-officers-he-cpo" target="_blank">read more</a></p> Mon, 01 Apr 2013 21:29:11 +0000 285691 at http://www.educause.edu Call for Participation: The Multi-Factor Authentication Cohortium http://www.educause.edu/blogs/vvogel/call-participation-multi-factor-authentication-cohortium <p>The <a href="https://spaces.internet2.edu/display/scalepriv/Scalable+Privacy">Internet2 Scalable Privacy Project (ScalePriv)</a>, funded with the recent National Strategy for Trusted Identities in Cyberspace (NSTIC) grant to <a href="http://www.internet2.edu">Internet2</a>, is seeking campuses to participate in the Multi-Factor Authentication (MFA) Cohortium*. Applications are open until April 26, 2013 (<em>note the deadline extension</em>).</p><p><a href="http://www.educause.edu/blogs/vvogel/call-participation-multi-factor-authentication-cohortium" target="_blank">read more</a></p> Wed, 20 Mar 2013 15:49:09 +0000 284860 at http://www.educause.edu Who is checking your email? http://www.educause.edu/blogs/rodney/who-checking-your-email <div class="left-align">What is your campus policy and procedure for access to employee email?&#160; If you don&#39;t know - or you don&#39;t have it written down - it might be time to review your practice, write it down, and vet it with the appropriate governance bodies.&#160; The issue of administration access to employee email has been peaked on campus because of a <a href="http://www.nytimes.com/2013/03/11/us/harvard-e-mail-search-stuns-faculty-members.html?pagewanted=1&amp;_r=2&amp;">New York Times article</a> that described a controversy brewing at Harvard University.&#160; The University had become concerned about a leak to news media regarding a student disciplinary matter that they suspected was attributable to a University administrator.&#160; According to a <a href="http://www.fas.harvard.edu/home/content/deans-communications">statement released by the University</a>:</div><div class="left-align">&#160;</div><p class="smoky">. . .</p><p><a href="http://www.educause.edu/blogs/rodney/who-checking-your-email" target="_blank">read more</a></p> Tue, 12 Mar 2013 18:44:03 +0000 283911 at http://www.educause.edu Privacy and Security Initiatives and Recommendations from the U.S. Department of Education http://www.educause.edu/ero/article/privacy-and-security-initiatives-and-recommendations-us-department-education <ul> <li>At EDUCAUSE 2012, <strong>U.S. Department of Education</strong> speakers discussed new privacy and security initiatives, as well as offering recommendations on <strong>navigating privacy efforts </strong>and <strong>preparing for and managing security breaches</strong>.</li> <li>Many of the new <strong>amendments to FERPA exceptions </strong>were developed in order to <strong>improve accountability in data sharing</strong>.</li> <li>At the heart of <strong>breach prevention and response</strong> are solid, <strong>established processes</strong> and <strong>targeted oversight</strong>.</li></ul><p><a href="http://www.educause.edu/ero/article/privacy-and-security-initiatives-and-recommendations-us-department-education" target="_blank">read more</a></p> Wed, 13 Feb 2013 20:53:58 +0000 282510 at http://www.educause.edu ED CPO on Privacy, Emerging Technologies, and New Uses of Data http://www.educause.edu/blogs/kathleen-styles/ed-cpo-privacy-emerging-technologies-and-new-uses-data <p>When I first accepted the position as ED&#8217;s Chief Privacy Officer the workload revolved heavily around privacy issues in the K-12 context, especially issues relating the Family Educational Rights Privacy Act (FERPA) and its applicability to State Longitudinal Databases. Recently our office is spending an increasing amount of time providing guidance in the higher ed arena. Colleges, universities, and other postsecondary institutions often have research agendas that involve data; they often have medical facilities; and most importantly, colleges and universities often function as change agents, particularly for technological and social change. The combination of new technologies and new uses of data create today&#8217;s cutting-edge privacy issues, including &#8220;Big Data,&#8221; matching with wage data, data sharing in general, the use of analytics, cloud computing, MOOCs, and school use of web engagement tools.</p><p><a href="http://www.educause.edu/blogs/kathleen-styles/ed-cpo-privacy-emerging-technologies-and-new-uses-data" target="_blank">read more</a></p> Mon, 28 Jan 2013 20:26:33 +0000 281147 at http://www.educause.edu A Few Things about E-FERPA http://www.educause.edu/blogs/smcdonal/few-things-about-e-ferpa <p>Probably no statute affects higher education more, but is understood less, than the Family Educational and Privacy Rights Act, or &#8220;FERPA,&#8221; the primary federal law that regulates how we handle our records about our students. And that is no doubt especially true when it comes to electronic records (which for some reason seem to baffle us in almost every context). Data Privacy Month seems a good time to clear up some of the most common misunderstandings:</p><p><strong>1. FERPA makes no distinction between electronic and other records.</strong> FERPA governs <em>all</em> records that we maintain about our students, be they written on paper; captured in film, photographs, or audiotape; made up solely of electrons; or, for that matter, carved into stone tablets, and it governs them in <em>exactly</em> the same way. At least for purposes of FERPA, the medium is <em>not</em> the message.</p><p><a href="http://www.educause.edu/blogs/smcdonal/few-things-about-e-ferpa" target="_blank">read more</a></p> Mon, 28 Jan 2013 16:34:17 +0000 281099 at http://www.educause.edu Higher Education Activities during Data Privacy Month http://www.educause.edu/blogs/vvogel/higher-education-activities-during-data-privacy-month <p>Although this is only the second year that colleges and universities are working together to observe and promote <a href="http://www.educause.edu/focus-areas-and-initiatives/policy-and-security/educause-policy/community-engagement/data-privacy-month">Data Privacy Month</a>, many campuses are busy planning local or regional events, tweeting daily with the hashtags <a href="https://twitter.com/search?q=%23dataprivacy">#dataprivacy</a> and <a href="https://twitter.com/search?q=%23dpd13">#dpd13</a>, and writing blogs or articles about data privacy. We hope these activities will encourage you to consider ways to promote Data Privacy Month this year or begin thinking about how yor campus will participate in 2014.</p><p><a href="http://www.educause.edu/blogs/vvogel/higher-education-activities-during-data-privacy-month" target="_blank">read more</a></p> Fri, 18 Jan 2013 22:31:21 +0000 280532 at http://www.educause.edu January 28th is Data Privacy Day–Respecting Privacy, Safeguarding Data and Enabling Trust http://www.educause.edu/blogs/aimeemlk/january-28th-data-privacy-day%E2%80%93respecting-privacy-safeguarding-data-and-enabling-trust <p>As the <a href="http://www.staysafeonline.org/">National Cyber Security Alliance (NCSA)</a>, we have the honor of coordinating <a href="http://www.staysafeonline.org/data-privacy-day/">Data Privacy Day (DPD)</a>. Data Privacy Day is held on January 28th annually and is an effort to empower people to protect their privacy, control their digital footprint, and escalate the protection of privacy and data as everyone&#8217;s priority. The success of Data Privacy Day relies on everyone, including our trusted partners such as EDUCAUSE and the higher education community, to educate and create awareness about the importance of data privacy.</p><p><a href="http://www.educause.edu/blogs/aimeemlk/january-28th-data-privacy-day%E2%80%93respecting-privacy-safeguarding-data-and-enabling-trust" target="_blank">read more</a></p> Fri, 18 Jan 2013 21:57:21 +0000 280509 at http://www.educause.edu Lance Spitzner on Data Privacy Awareness http://www.educause.edu/blogs/lspitzner/lance-spitzner-data-privacy-awareness <p>A common challenge many schools share is protecting the privacy of their students. Institutions maintain a surprising amount of highly confidential student information including medical, financial, personal, and educational data. As a result, institutions have to comply with numerous regulations including HIPAA, FERPA, or GLBA. Remembering all of these different compliance rules and regulations can be confusing or overwhelming for faculty and staff. However, if you take a step back, many of these regulations have the same goal&#8211;protection of private information. In addition, the steps people are expected to follow in order to protect data are often the same.</p><p><a href="http://www.educause.edu/blogs/lspitzner/lance-spitzner-data-privacy-awareness" target="_blank">read more</a></p> Fri, 18 Jan 2013 16:55:14 +0000 280428 at http://www.educause.edu Data Privacy Month Awareness Video, 2013 http://www.educause.edu/library/resources/data-privacy-month-awareness-video-2013 <p><a href="http://www.sans.org/">SANS</a> and EDUCAUSE have developed a free privacy awareness video that colleges and universities can use during<a href="http://www.educause.edu/focus-areas-and-initiatives/policy-and-security/educause-policy/community-engagement/data-privacy-month"> Data Privacy Month</a> in January, and throughout the year, in their privacy education and training efforts. High and low resolution versions of the video are available.</p><p><a href="http://www.educause.edu/library/resources/data-privacy-month-awareness-video-2013" target="_blank">read more</a></p> Mon, 14 Jan 2013 17:08:11 +0000 280031 at http://www.educause.edu ERO Video Conversation: The Relationship Between Privacy and Security http://www.educause.edu/ero/article/ero-video-conversation-relationship-between-privacy-and-security <p><a href="http://www.educause.edu/ero/article/ero-video-conversation-relationship-between-privacy-and-security" target="_blank">read more</a></p> Tue, 08 Jan 2013 17:13:46 +0000 279531 at http://www.educause.edu Data Privacy Month: Are You Smarter Than Your Phone? http://www.educause.edu/library/resources/data-privacy-month-are-you-smarter-your-phone <p>Nearly everyone on a college campus today has a mobile phone, capable of accomplishing amazing tasks while on the go. But, how SHOULD you make use of your smartphone? You are smarter than your phone if you know that you need to make careful choices about using your geo-location feature. You might post a picture to Facebook while on your European trip if there are other people still living at your address back home. But, if your house is empty while you travel, you would be smarter to wait to post until you get home. Do you really want everyone to know you are out alone at midnight by &#34;checking in&#34; at your local donut shop? You are smarter than your phone if you use sound judgment about revealing your location. You&#8217;re smarter than your phone if you know you need to think critically about the sensitivity of the data you put on or access through your phone. Do you use your phone for banking, without password protecting the device? Your phone is happy to do it. But you are smarter than your phone if you protect it with a password. If you&#8217;re not thinking critically about what you do with your phone, we&#8217;ll help you think again!</p><p>This session is part of a <a href="http://www.educause.edu/focus-areas-and-initiatives/policy-and-security/educause-policy/community-engagement/data-privacy-month">Data Privacy Month series of events.</a></p><p>&#160;</p><p><a href="http://www.educause.edu/library/resources/data-privacy-month-are-you-smarter-your-phone" target="_blank">read more</a></p> Fri, 04 Jan 2013 22:38:31 +0000 279315 at http://www.educause.edu EDUCAUSE Review: Print Edition, Volume 48, Number 1, January/February 2013 http://www.educause.edu/ero/educause-review-print-edition-volume-48-number-1-januaryfebruary-2013 <p>This is the full issue of EDUCAUSE Review: Print Edition, Volume 48, Number 1, January/February 2013</p><p><a href="http://www.educause.edu/ero/educause-review-print-edition-volume-48-number-1-januaryfebruary-2013" target="_blank">read more</a></p> Fri, 04 Jan 2013 19:56:45 +0000 279299 at http://www.educause.edu Privacy, Security, and Compliance: Strange Bedfellows, or a Marriage Made in Heaven? http://www.educause.edu/ero/article/privacy-security-and-compliance-strange-bedfellows-or-marriage-made-heaven <p>The authors examine several campus issues lying at the intersection of privacy, security, and compliance and provide insight for institutional leaders planning strategic directions.</p><p><a href="http://www.educause.edu/ero/article/privacy-security-and-compliance-strange-bedfellows-or-marriage-made-heaven" target="_blank">read more</a></p> Fri, 04 Jan 2013 18:00:24 +0000 279281 at http://www.educause.edu Information Privacy Revealed http://www.educause.edu/ero/article/information-privacy-revealed <p>IT senior leaders and IT staff should learn what privacy is, why it is important in higher education today, and how they can identify and address privacy risks.</p><p><a href="http://www.educause.edu/ero/article/information-privacy-revealed" target="_blank">read more</a></p> Fri, 04 Jan 2013 17:48:04 +0000 279280 at http://www.educause.edu January 2013 is Data Privacy Month! Free Webinars and Easy Ways to Increase Awareness http://www.educause.edu/blogs/vvogel/january-2013-data-privacy-month-free-webinars-and-easy-ways-increase-awareness <p><a href="http://www.educause.edu/focus-areas-and-initiatives/policy-and-security/educause-policy/community-engagement/data-privacy-month">Data Privacy Month</a> is an annual effort to empower people to protect their privacy and control their digital footprint, as well as escalate the protection of privacy and data as everyone&#39;s priority. Spend the month helping to ensure your campus community is respecting privacy, safeguarding data, and enabling trust. This year&#8217;s Data Privacy Month Planning Task Force has selected weekly themes for the higher education community to focus on. Several free webinars will also be offered throughout the month of January.</p><p><a href="http://www.educause.edu/blogs/vvogel/january-2013-data-privacy-month-free-webinars-and-easy-ways-increase-awareness" target="_blank">read more</a></p><fieldset><legend>Uploads</legend>Attachments:<div class="filefield-icon field-icon-image-jpeg"><img class="field-icon-image-jpeg" alt="image/jpeg icon" src="http://www.educause.edu/sites/all/modules/contrib/filefield/icons/protocons/16x16/mimetypes/image-x-generic.png" /></div> <a href="http://www.educause.edu/sites/default/files/PrivacyTower2.jpg">PrivacyTower2.jpg</a><div class="filefield-icon field-icon-image-jpeg"><img class="field-icon-image-jpeg" alt="image/jpeg icon" src="http://www.educause.edu/sites/all/modules/contrib/filefield/icons/protocons/16x16/mimetypes/image-x-generic.png" /></div> <a href="http://www.educause.edu/sites/default/files/PrivacyHero2.jpg">PrivacyHero2.jpg</a></fieldset> Fri, 21 Dec 2012 19:05:38 +0000 278613 at http://www.educause.edu Privacy Officers around the Virtual Water Cooler http://www.educause.edu/library/resources/privacy-officers-around-virtual-water-cooler <p>This conversational webinar explores how three higher education Chief Privacy Officers (CPOs) are addressing current privacy challenges on campus.</p><p><a href="http://www.educause.edu/library/resources/privacy-officers-around-virtual-water-cooler" target="_blank">read more</a></p> Thu, 20 Dec 2012 21:52:47 +0000 278551 at http://www.educause.edu The Family Educational Rights and Privacy Act: 7 Myths — and the Truth http://www.educause.edu/node/277419 <p>The author tried to clarify common confusions surrounding The Family Educational Rights and Privacy Act (FERPA).</p><p>This aritcle riginally appeared in the Chronicle of Higher Education<br /> Section: Commentary Volume 54, Issue 32, Page A53<br /> April 18, 2008</p><p><a href="http://www.educause.edu/node/277419" target="_blank">read more</a></p> Fri, 30 Nov 2012 22:06:21 +0000 277419 at http://www.educause.edu PTAC Data Breach Response Checklist http://www.educause.edu/blogs/vvogel/ptac-data-breach-response-checklist <p>The <a href="http://ptac.ed.gov/">Privacy Technical Assistance Center (PTAC)</a> recently published a <a href="http://ptac.ed.gov/document/checklist-data-breach-response-sept-2012">Data Breach Response Checklist</a> that institutions of higher education may use to develop a comprehensive data breach response plan. The checklist is meant to be used as a general example illustrating some current industry best practices in data breach response and mitigation applicable to education community. A <a href="http://ptac.ed.gov/sites/default/files/checklist_data_breach_response_092012.pdf">PDF version</a> is available to download.</p><p><a href="http://www.educause.edu/blogs/vvogel/ptac-data-breach-response-checklist" target="_blank">read more</a></p> Thu, 25 Oct 2012 16:31:06 +0000 274274 at http://www.educause.edu Security and Privacy Sessions at EDUCAUSE 2012 http://www.educause.edu/blogs/vvogel/security-and-privacy-sessions-educause-2012 <p>The <a href="http://www.educause.edu/annual-conference/2012">annual EDUCAUSE Conference</a> (November 6-9) offers a variety of <a href="http://www.educause.edu/annual-conference/agenda-and-program/search?filters=tid%3A44961">security and privacy-related sessions</a>. Whether you plan to join us in Denver or participate online, we encourage you to attend as many of these presentations as possible. Also remember to mark your calendar for the upcoming <a href="http://www.educause.edu/events/security-professionals-conference">Security Professionals Conference</a>, which will be held April 15-17, 2013 in St. Louis, Missouri, and Online. A <a href="http://www.educause.edu/events/security-professionals-conference/call-proposals">Call for Proposals </a>is currently out, with a November 13, 2012 deadline.</p><h4><em><strong>Tuesday, November 6, 2012</strong></em></h4><p><strong>Preconference Seminars (<em>separate registration required</em>)</strong></p><p><a href="http://www.educause.edu/blogs/vvogel/security-and-privacy-sessions-educause-2012" target="_blank">read more</a></p> Tue, 16 Oct 2012 19:47:48 +0000 273154 at http://www.educause.edu National Cyber Security Awareness Month 2012 is HERE! http://www.educause.edu/blogs/vvogel/national-cyber-security-awareness-month-2012-here <p><em><strong>It&#8217;s that time of year again! October is National Cyber Security Awareness Month.</strong></em></p><p>Help us raise awareness with your faculty, staff, and students this October by promoting National Cyber Security Awareness Month (NCSAM).</p><p>We will start the month off with an EDUCAUSE Live! webinar on <strong>October 4</strong> (1-2 pm EDT). Register <a href="http://www.educause.edu/events/educause-live-security-awareness-and-communication-c-suite">here</a> and join Dave Cullinane, Chief Information Security Officer at eBay (retired) and Co-Founder of the Cloud Security Alliance, as he discusses &#8220;<a href="http://www.educause.edu/events/educause-live-security-awareness-and-communication-c-suite">Security Awareness and Communication in the C-Suite</a>.&#8221;</p><p>If you plan on holding an event in October, please share your plans and any applicable URL&#8217;s with this group or send an e-mail to <a href="mailto:security-council@educause.edu">security-council@educause.edu</a> so your institution&#39;s activities can be included with our list of 2012 campus events.</p><p><a href="http://www.educause.edu/blogs/vvogel/national-cyber-security-awareness-month-2012-here" target="_blank">read more</a></p> Mon, 01 Oct 2012 18:52:25 +0000 271438 at http://www.educause.edu Privacy and Data Management on Mobile Devices http://www.educause.edu/library/resources/privacy-and-data-management-mobile-devices <p>A new survey by the Pew Research Center&#8217;s Internet &#38; American Life Project found that more than half of mobile application users have uninstalled or avoided certain apps due to concerns about the way personal information is shared or collected by the app. This report was authored by Jan Lauren Boyles, Aaron Smith, Mary Madden.</p><p><a href="http://www.educause.edu/library/resources/privacy-and-data-management-mobile-devices" target="_blank">read more</a></p> Thu, 06 Sep 2012 15:23:17 +0000 269092 at http://www.educause.edu Cybersecurity: Selected Legal Issues http://www.educause.edu/library/resources/cybersecurity-selected-legal-issues <p>The federal government&#8217;s role in protecting U.S. citizens and critical infrastructure from cyber attacks has been the subject of recent congressional interest. Critical infrastructure commonly refers to those entities that are so vital that their incapacitation or destruction would have a debilitating impact on national security, economic security, or the public health and safety. This report discusses selected legal issues that frequently arise in the context of recent legislation to address vulnerabilities of critical infrastructure to cyber threats, efforts to protect government networks from cyber threats, and proposals to facilitate and encourage sharing of cyber threat information among private sector and government entities. This report also discusses the degree to which federal law may preempt state law.</p><p><a href="http://www.educause.edu/library/resources/cybersecurity-selected-legal-issues" target="_blank">read more</a></p> Fri, 17 Aug 2012 20:41:35 +0000 267893 at http://www.educause.edu 7 Ways BYOD Could Get You Sued http://www.educause.edu/library/resources/7-ways-byod-could-get-you-sued <p>The author, Sam Narisi, discusses some of the biggest legal issues to consider when coming up with a BYOD policy and strategy.</p><p><a href="http://www.educause.edu/library/resources/7-ways-byod-could-get-you-sued" target="_blank">read more</a></p> Tue, 07 Aug 2012 20:27:47 +0000 267328 at http://www.educause.edu ECPA Amendment Letter http://www.educause.edu/library/resources/ecpa-amendment-letter <p>In this letter sent to Senate Majority Leader Reid and Minority Leader McConnell, EDUCAUSE joined with the Association of Research Libraries, businesses, and other trade associations to support <a class="ext" href="http://www.gpo.gov/fdsys/pkg/CREC-2012-07-25/pdf/CREC-2012-07-25-pt1-PgS5401-3.pdf" target="_blank">Senate Amendment 2580</a>, cited as the &#8220;Electronic Communications Privacy Act,&#8221; to the Cybersecurity Act (<a class="ext" href="http://www.opencongress.org/bill/112-s3414/text" target="_blank">S. 3414</a>). This amendment would provide privacy protections for email and other electronic communications &#8212; including requiring that the government obtain a search warrant based on probable cause in order to obtain email content. The amendment would also implement the first principle of the <a class="ext" href="http://digitaldueprocess.org/index.cfm?objectid=37940370-2551-11DF-8E02000C296BA163" target="_blank">Digital Due Process</a> (DDP) coalition -- of which EDUCAUSE is a member -- whose goal is to simplify, clarify, and unify the ECPA standards.</p><p>More information can be found in the August 3, 2012 blog, &#34;<a href="http://www.educause.edu/blogs/cheverij/educause-joins-letter-support-electronic-communications-privacy-act-amendment">EDUCAUSE Joins Letter in Support of the Electronic Communications Privacy Act Amendment</a>.&#34;</p><p><a href="http://www.educause.edu/library/resources/ecpa-amendment-letter" target="_blank">read more</a></p> Mon, 06 Aug 2012 19:17:22 +0000 267213 at http://www.educause.edu