首页> 外文学位 >The utility of incident response plans for data breaches in higher education.
【24h】

The utility of incident response plans for data breaches in higher education.

机译:高等教育中数据泄露事件响应计划的实用性。

获取原文
获取原文并翻译 | 示例

摘要

This study intended to determine if an incident response program for data breaches in higher education provides a proactive approach to protecting an institution's cost for recovery and slow the economic damages for individuals whose personal information was stolen in a data breach. An analysis of the Family Educational Rights and Privacy Act (FERPA), the Health Insurance Portability and Accountability Act of 1996 (HIPAA), the Health Information Technology for Economic and Clinical Health Act (HITECH), and the Graham-Leach-Bliley Act (GLBA) revealed extensive legislative mandates for protecting student confidential information in higher education. Despite federal and state mandates to secure data in physical and electronic formats, education institutions experience challenges with data protection. Data is a valuable commodity, so even with strong security controls and meticulous risk management practices in place, it is still possible for a data breach to occur. The federal government recommends an Incident Response Plan for institutions of higher education to prepare for and mitigate a data breach, but the development and implementation of an Incident Response Plan is expensive. Ambiguity among state notification laws allows for confusion about who is to report a data breach, how long an institution can wait before reporting the breach, and what exact information is necessary to report in a notification letter. Higher education institutions can use a risk analysis to their advantage and skip reporting a data breach to affected individuals. The research proposed the establishment of a standardized federal data breach law. Without government intervention, many people may continue to have their private and personal information stolen and never know about it.
机译:这项研究旨在确定针对高等教育中数据泄露的事件响应程序是否提供了一种积极的方法来保护机构的恢复成本,并减缓其个人信息因数据泄露而被盗的个人的经济损失。对《家庭教育权利和隐私权法案》(FERPA),《 1996年健康保险可移植性和责任法案》(HIPAA),《经济和临床健康信息技术法案》(HITECH)以及《格雷厄姆-里奇-比利莱法案》( GLBA)披露了广泛的立法授权,以保护高等教育中的学生机密信息。尽管联邦和州要求保护物理和电子格式的数据,但教育机构在数据保护方面仍面临挑战。数据是一种宝贵的商品,因此即使采用了强大的安全控制措施和细致的风险管理实践,数据泄漏仍然有可能发生。联邦政府建议高等教育机构制定《事件响应计划》,以准备和缓解数据泄露,但是制定和实施事件响应计划的成本很高。各州通知法律之间的歧义使得人们对谁要报告数据泄露,机构在报告该泄露之前可以等待多长时间以及需要在通知函中进行报告的确切信息产生混淆。高等教育机构可以利用风险分析来发挥自己的优势,而无需向受影响的个人报告数据泄露事件。该研究建议建立标准化的联邦数据泄露法律。没有政府干预,许多人可能会继续窃取其私人和个人信息,却一无所知。

著录项

  • 作者

    Stokes, Melissa.;

  • 作者单位

    Utica College.;

  • 授予单位 Utica College.;
  • 学科 Higher education.;Law.
  • 学位 M.S.
  • 年度 2015
  • 页码 52 p.
  • 总页数 52
  • 原文格式 PDF
  • 正文语种 eng
  • 中图分类
  • 关键词

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号