Defining Terms and Federal Regulations

Video Activity
Join over 3 million cybersecurity professionals advancing their career
Sign up with
Required fields are marked with an *

Already have an account? Sign In »

2 hours 19 minutes
Video Transcription
Welcome back to student out of privacy fundamentals. This lesson is on defining terms and federal regulations.
In this video, you will learn important definitions for key terms in your student data privacy policy.
You will also learn term definitions in key federal regulations.
Confidentiality is data or information that is not made available or disclosed to unauthorized users.
Confidential data or information is information that the district is prohibited by law, policy or contract from disclosing, or that the district may disclose Onley in limited circumstances. Confidential data includes, but is not limited
two P II or personally identifiable information regarding students and employees.
Critical data or information is determined to be essential to district operations, and that must be accurately and securely maintained to avoid disruption to district operations. It is important to note here that critical data is not necessarily confidential data. For example,
confidential data would be someone's Social Security number or grade information.
But critical data could be something that would pose a risk, like a leaked password to a district WiFi network. But it would not put any individual person a harm.
Data is facts or information. It could be in any form, Orel written or electronic
a data breach, breach of security or breach all
basically referring to the same thing. Meaning a security incident in which there was unauthorized access to an unauthorized acquisition of personal information maintained in computerized form that compromises security, confidentiality or integrity of that information.
Data integrity means that data is current accurate and has not been altered or destroyed in an unauthorized manner.
Data management is the development and execution of policies, practices and procedures in order to manage the accuracy and security of district instructional and operational data in an effective manner.
A data owner is a user responsible for the creation of data. The owner may be the primary user of that information or the person responsible for the accurate collection of recording of data.
Ownership does not signify proprietary interest and ownership may be shared. The owner of information has the responsibility for
knowing the information for which she or he is responsible, determining a data retention period for the information, according to board policy and state statue.
Ensuring appropriate procedures are in effect to protect the integrity, confidentiality and availability of the data used or created,
reporting promptly to the eye so the loss or misuse of data,
initiating and or implementing corrective actions when problems are identified
and following existing approval processes for the selection, budgeting, purchase and implementation of any digital resource.
The information security officer, also called the ICE so, is responsible for working with the superintendent data governance team, data managers, data owners and users to develop and implement prudent security policies, procedures and controls
the ice So will oversee all security audits and will act as an adviser to data owners for the purpose of identification and classification of technology and data. Related Resource is
in an adviser to systems development and application owners in the implementation of security controls for information on systems from the point of system design through testing and production Implementation
Quiz time. What does I so stand for? And what are three things they're responsible for?
The correct answer is the I so stands for information security officer
and some of the things that they're responsible for is working with Superintendent Data Governance team data managers, etcetera, overseeing all security audits and acting as an adviser to data owner system development and application owners
System includes any hardware systems, including computers, laptops, mobile devices, printing and ER scanning devices, network appliance equipment, A V equipment, servers, internal or external storage communication device. Or any other current or future Elektronik or technological device,
whether hosted by the district or provider.
And it's important to note here where you state current or future, because as technology changes, we want to make sure that any new technologies that may not even exist right now would also be covered. And we're not constantly having to go back and revise our policies.
Also, it includes any current or future software systems, including student information systems, payroll software, software supporting curriculum, etcetera. Again, note the use of the phrase current or future.
A security incident is an event that actually or potentially jeopardizes the confidentiality, integrity or availability of an information system or the information the system processes stores or transmits. So it doesn't even have to be a really security breach.
It really could be something that is potentially jeopardizing.
It's also something that constitutes a violation or imminent threat of violation of security policies, security procedures or acceptable use policies.
P i I or personally identifiable information is any information about an individual maintained by an agency that includes
anything that really could distinguish her trace and individuals identity. So name Social Security number, State I D. Date and place of birth Mothers may name biometric records
Any other information that's link your link herbal to an individual like medical records, educational records, financial records and employment information.
Risk is the probability of a loss of confidentiality, integrity or availability of information. Resource is
a user is any person who has been authorized to read inter print or update information, and they are expected to access information on Lee in support of their authorized job responsibilities.
Comply with all data security procedures and guidelines. Keep personal authentication confidential so all of their user eighties passwords, etcetera, knees to be kept to themselves.
Report promptly to the ice. So the loss or misuse of data and follow corrective actions when problems are identified.
In today's video, we discussed important definitions for key terms such as ice, so user data breach etcetera.
We also talked about some term definitions in key federal regulations such as P I. I.
So any of these definitions that we outlined here can be taken and put directly into your term definitions, a glossary section, for example, in your own student data privacy policy.
In our next lesson, we will discuss digital resource acquisition procedure. See you soon.
Up Next