February 13, 2008 4:00 AM PST

Perspective: Going back to school on security

See all Perspectives
perspective Little more than one month into 2008, and already this is shaping up to be a year rife with data security incidents at sundry educational institutions.

Data maintained at universities contains private and sensitive information. But a recent report by Campus Technology magazine suggests that best practices are not being followed to protect this information. Consider the following:

• A student employee accessed personal information relating to more than 500 users of Baylor University's communication network.

• A student employee from Central Piedmont Community College in North Carolina was arrested and charged with alleged identity theft relating to Social Security numbers and birthdates from records of employees.

• Social Security numbers of some 260 students at Murray State University's College of Education, in Kentucky, got posted online and remained accessible for well more than a year.

• Passwords and more than 200 Social Security numbers for approximately 300 students at the Warner College of Natural Resources, a branch of Colorado State University, wound up being posted online.

• Personal information relating to about 89 Brigham Young University medical students was posted online.

• Employment and other information about faculty and administrators of Southwest Texas State University was posted online.

• Names, Social Security numbers, and additional private data on 42 employees were posted on the Montana State University Web site.

• Tennessee Tech lost track of a flash drive housing the names and Social Security numbers of almost 1,000 students.

• A hard drive containing employee names and Social Security numbers was stolen from New Mexico State University.

• The University of Akron lost a hard drive with the Social Security numbers and other personal information of about 800 people.

• A security breach at the University of Georgia may have exposed more than 4,000 Social Security numbers.

• A hacking incident at California State University, Stanislaus, is suspected of having revealed credit card numbers and names.

Plainly, an educational institution cannot guarantee that private data will not be compromised. On the other hand, the sheer number of recent breaches would seem to indicate that perhaps more could be done. In terms of private data posted on university Web sites, at least three steps could be taken.

First, those persons with access to private data should be educated as to how to and how not to handle the data. Instruction from an academic institution with expertise in the subject would be well advised.

Second, employees and other persons within the control of the school should agree in writing to safeguard private data and they should be advised of the consequences for failing to comply.

Third, schools routinely should police their own sites to ensure that private data has not been posted online improperly; and naturally, when there is such a discovery, the data must be removed immediately.

With respect to lost hard drives, flash drives, and the like, here again universities should educate their employees and others within their ambit on how to safeguard devices containing private data.

Perhaps only certain persons should be allowed to take offsite private data contained in portable devices. Consideration also could be given to identifying the types of offsite locations that are suitable and unsuitable for devices containing private data, and rules could be established to require authorized persons to keep the devices in their possession when offsite.

And, of course, methods can be employed for encryption and for routinely changing IDs and passwords for such devices.

As far as hack attacks, universities should utilize technology that makes their systems as impenetrable as possible--recognizing that these technologies are not bulletproof. Here, too, frequently changing IDs and passwords could be beneficial.

But even the adoption of best practices won't eliminate the possibility of a breach, so when security is compromised, the schools should immediately notify anyone who might be affected. They might also extend fraud protection services.

There is no one perfect answer to security threats, so educational institutions should seek out insurance coverage for potential breaches. They also should engage legal counsel skilled in this area to provide proactive advice to help head off potential problems, and then deal with trouble as soon as it arises.

Biography
Eric J. Sinrod is a partner in the San Francisco office of Duane Morris. His focus includes information technology and intellectual-property disputes. To receive his weekly columns, send an e-mail to ejsinrod@duanemorris.com with "Subscribe" in the subject line. This column is prepared and published for informational purposes only, and it should not be construed as legal advice. The views expressed in this column are those of the author and do not necessarily reflect the views of the author's law firm or its individual partners.

More Perspectives

See more CNET content tagged:
social security number, Social Security, institution, back-to-school, university

Add a Comment (Log in or register) 3 comments
don't collect it
by tgrenier February 13, 2008 7:07 AM PST
I've worked a bit higher education IT and although everyone whines that they need it, there is no reason what so ever to store social sec #'s or credit card info.
Reply to this comment
High Education
by sanenazok February 13, 2008 8:42 AM PST
Having worked in several higher education institutions I can tell you that weak security is but one of many, many, problems. To put it simply, even bad businesses don't make idiotic decisions at the rate most universities do. Bad data retention policies are but one, small example.
Reply to this comment
Need to teach Educators how to read!
by wbenton February 16, 2008 10:18 AM PST
With all the coverage given security thefts left and right all over the US and publicized by most major news agencies, only one conclusion can be drawn from this:

Educators DON'T know how to read!

That said, somebody should teach the educators how to read... or better yet... replace them with educators whom can read!!!

Stupidity... total and sheer stupidity.

Walt
Reply to this comment
Powered by Jive Software
advertisement

Latest tech news headlines

RSS Feeds

Add headlines from CNET News to your homepage or feedreader.

More feeds available in our RSS feed index.

advertisement

Inside CNET News

Scroll Left Scroll Right
  • News - Business Tech

    Dell planning to ditch factories

    Dell's new CFO Brian Gladden has said that the company "more work to be done," to improve profitability and decrease costs. The Wall Street Journal is reporting that the company is planning to lower costs by selling off its factories.

  • Gallery

    Photos: Ron Paul's RNC alternative

    As the Republican convention took place just miles away, a crowd rallied for the former presidential candidate and his message of limited government, ensured civil liberties, lower taxes, and peace.

  • Negative Approach

    Online content and services via game consoles will generate $8 billion in revenue in 2013

    The revenue possibilities in gaming continue to grow, at least for the big console manufacturers.

  • Beyond Binary

    Microsoft begins big ad push

    Microsoft's multi-year push, estimated at $300 million, begins with a spot featuring Bill Gates and Jerry Seinfeld aired during Thursday's NFL game.

  • Video

    YouTube plays party politics

    During the presidential campaigning four years ago, YouTube didn't even exist. Now it's a tool candidates must master to get their message across. CNET's Kara Tsuboi stops by the YouTube upload booths at the Democratic and Republican conventions to find out why Google's video site has such a big presence in Denver and St. Paul, Minn.

  • News - Wireless

    Was EarthLink's failed citywide Wi-Fi a blessing in disguise?

    Wireless Philadelphia, the nonprofit charged with providing broadband bundles to low-income families in Philadelphia, may be better off in the long run without EarthLink.

  • Video

    Political party playlists

    We know the Democrats and Republicans are split over policy issues, but does their musical taste fall down party lines too? And what kind of gadgets did they bring to the conventions to listen to their music? CNET reporter Kara Tsuboi finds out.

  • News - Gaming and Culture

    Behind the prototyping of 'Spore'

    Many of the components of Will Wright's highly anticipated evolution game started out as small concept projects that are now available to the public.

  • News - Cutting Edge

    Execs predict next Google-like tech

    On eve of company's 10-year anniversary, researchers and business pundits speculate about what technologies might someday have as much impact as Google.

  • Gallery

    Photos: The brains behind Google Chrome

    Here's a look at some of the engineers and executives who took the stage at the company's headquarters as they unveiled the new browser.

  • The Cheapskate

    Record TV in style with a refurbished TiVo HD, $179.99 shipped

    TiVo is offering refurb HD units for cheap, though you'll still have to pay for the TiVo service.

  • Green Tech

    Clean-tech group forms to support Obama

    "Clean Tech and Green Business for Obama" aims to raise $1 million for the Democratic presidential nominee while elevating issues of climate change and alternative energy.