From Deseret News archives:

Is student data safe?

Utah colleges need more security, audit indicates

Published: Tuesday, Nov. 28, 2006 12:50 a.m. MST
 |  E-MAIL | PRINT | FONT + - 
Utah's universities are working to protect students' personal information, but some schools need to get their policies up to date to block hackers and comply with federal law, according to a report obtained by the Deseret Morning News.

The first comprehensive information technology audit for the state system of nine public colleges and universities reveals a need for more formalized security policies to protect private information ranging from Social Security numbers to health data.

"Because of the open nature of universities, they've generally been a little bit more at risk. They can't be as open as they used to," said Steve Hess, chief information officer for Utah's System of Higher Education, who spearheaded the report.

Without clear security policies, Hess said, Utah's schools could be vulnerable to hackers and at risk for violation of the federal Family Educational Rights and Privacy Act, which bars colleges from releasing student records that include personally identifiable information.

While Hess said there were no glaring gaps in the networks of most Utah schools, there is a need for better training of certified security officers and more streamlined policies on how to monitor the system's vulnerability.

Currently, some schools rely on uncertified operations staff to perform security functions, the report said.

Story continues below
The audit recommends a systemwide update of each school's information technology policy to include at least 19 protocols such as how to report security breaches and acceptable use of technology. While most schools have security procedures in place, Hess said, many have not concretely included them in the school's information technology policy.

In particular, a majority of Utah institutions did not have clear policies controlling student identifiers in place of Social Security numbers and personnel clearances. About half of the schools did not have formal policies on security monitoring and enforcement.

The audit does not specify which universities are lacking formal protocols.

"They're just catching up to get those policies updated. That doesn't mean that they don't have them, they just need to get them into their policy," Hess said. "Everybody who has a desktop is at potential for some breach in security; a policy just lays down the law of the land."

Since Sept. 11, 2001, Hess said, universities across the nation have been re-evaluating their security processes, fueled by the fear that a terrorist hack could rob students of their identities and schools of their security.

Comments

You can be the first to comment on this story.

previousnext

Latest comments

These time spans are mind boggling. Interesting that an ancestor of T-rex...

Christmas gifts for your Mormon scholar

How about microfilm(cd) copies from the library of the Church Historian: The...

Y. profs: Beck not all-knowing

I think that it's safe to say that anyone criticizing these professors either...

At least the whole game could've been as competitive as the first three...

BYU's Unga weighing his options

Why run the risk of a major injury playing one more year of college ball when...

Austria passes gay civil unions bill

When this happens in the United States, not Europe, the gay rights lobby...

This is all a joke the prosecution tells there Dr. hey we want this guy...

Letters: Earth at center?

RedShirt | 12:43 p.m. Dec. 10, 2009 To 'tree-hugger | 11:32 a.m." do we...

To Outraged @ 2:50 Good point. Also, you can tell the county sheriff that...

TRAX has been darn good for Utah. Keep building them.

Advertisements