24

Privacy Conundrums in Higher Academic EnvironmentThe Three P’s •Policy, Procedure and Practice –If there isn’t a policy against it I can do what I please –We’ve always

  • Upload
    others

  • View
    1

  • Download
    0

Embed Size (px)

Citation preview

Page 1: Privacy Conundrums in Higher Academic EnvironmentThe Three P’s •Policy, Procedure and Practice –If there isn’t a policy against it I can do what I please –We’ve always
Page 2: Privacy Conundrums in Higher Academic EnvironmentThe Three P’s •Policy, Procedure and Practice –If there isn’t a policy against it I can do what I please –We’ve always

Privacy Conundrums in Higher Education: Corralling Squirrels in an

Academic Environment

Sarah Morrow, CIPP/US, GISP

Chief Privacy Officer

Jennifer Stewart, CIPP/IT

Privacy Coordinator

Page 3: Privacy Conundrums in Higher Academic EnvironmentThe Three P’s •Policy, Procedure and Practice –If there isn’t a policy against it I can do what I please –We’ve always

Show of Hands

How many of you have a multi-faceted company to protect without an overall single industry to which you adhere and multiple regulations to which you must comply?

Page 4: Privacy Conundrums in Higher Academic EnvironmentThe Three P’s •Policy, Procedure and Practice –If there isn’t a policy against it I can do what I please –We’ve always

Talk about a large diverse environment

– Multiple buildings, multiple locations

• 24 Campuses, 26 Colleges

• Distributed environment

Page 5: Privacy Conundrums in Higher Academic EnvironmentThe Three P’s •Policy, Procedure and Practice –If there isn’t a policy against it I can do what I please –We’ve always

And…

Page 6: Privacy Conundrums in Higher Academic EnvironmentThe Three P’s •Policy, Procedure and Practice –If there isn’t a policy against it I can do what I please –We’ve always

And…

Page 7: Privacy Conundrums in Higher Academic EnvironmentThe Three P’s •Policy, Procedure and Practice –If there isn’t a policy against it I can do what I please –We’ve always

and…you get the picture…

Page 8: Privacy Conundrums in Higher Academic EnvironmentThe Three P’s •Policy, Procedure and Practice –If there isn’t a policy against it I can do what I please –We’ve always

The Forest’s Laws

• Federal Regulations

• State Regulations

• Military Regulations

• International Regulations

• Industry Standards

Page 9: Privacy Conundrums in Higher Academic EnvironmentThe Three P’s •Policy, Procedure and Practice –If there isn’t a policy against it I can do what I please –We’ve always
Page 10: Privacy Conundrums in Higher Academic EnvironmentThe Three P’s •Policy, Procedure and Practice –If there isn’t a policy against it I can do what I please –We’ve always

The Burrow’s Laws

• Academic Freedom

• Intellectual Property

• Institutional Policy

• Institutional Practices

• Open Environment

• Students and Faculty come first

Page 11: Privacy Conundrums in Higher Academic EnvironmentThe Three P’s •Policy, Procedure and Practice –If there isn’t a policy against it I can do what I please –We’ve always

History

• 1855 Land Grant

• Commonwealth affiliated

• Students identified by SSN

• PO created in 2004

• Policy disseminated simultaneously

–Data Stewards

–Faculty/staff/student population

–Approval to use and store

Page 12: Privacy Conundrums in Higher Academic EnvironmentThe Three P’s •Policy, Procedure and Practice –If there isn’t a policy against it I can do what I please –We’ve always

Organizational Structure

Corporate Controller

Risk Management

Privacy

Contracts

Claims

Insurance

Page 13: Privacy Conundrums in Higher Academic EnvironmentThe Three P’s •Policy, Procedure and Practice –If there isn’t a policy against it I can do what I please –We’ve always

Show of Hands – Privacy Structure

Where is the Privacy Office in

your organization? What part do you play in the forest?

Page 14: Privacy Conundrums in Higher Academic EnvironmentThe Three P’s •Policy, Procedure and Practice –If there isn’t a policy against it I can do what I please –We’ve always

New Chief Privacy Squirrel

• Hired in 2009

–No transition period

–Not from Higher Ed

• Initial Trials

–Whack-a-mole (or squirrel in this case)

–Squirrel identification

–Office visibility

Page 15: Privacy Conundrums in Higher Academic EnvironmentThe Three P’s •Policy, Procedure and Practice –If there isn’t a policy against it I can do what I please –We’ve always

The Three P’s

• Policy, Procedure and Practice

–If there isn’t a policy against it I can do what I please

–We’ve always done it this way

–Taking the Higher Road because it’s the right thing to do

Page 16: Privacy Conundrums in Higher Academic EnvironmentThe Three P’s •Policy, Procedure and Practice –If there isn’t a policy against it I can do what I please –We’ve always

Squirrels Working Together

• Identity and Access Management

– EDUCAUSE & Internet 2 for cloud collaboration

– Federated Identities

● Export?

– Faculty Abroad

– Students

– ‘Gifting’

● Research – Grants

– Human Subject – NIH

– Applied Research Lab - DOD

Page 17: Privacy Conundrums in Higher Academic EnvironmentThe Three P’s •Policy, Procedure and Practice –If there isn’t a policy against it I can do what I please –We’ve always

Incident Response

• Investigation

• Security Privacy

Discovery

• Addresses

• FAQs

• Mailing

Procedure

• Costs (unit level) • Forensics/Data

Mining

• Notification Services

Accountability

Page 18: Privacy Conundrums in Higher Academic EnvironmentThe Three P’s •Policy, Procedure and Practice –If there isn’t a policy against it I can do what I please –We’ve always

What to do?

• Initiate & Champion Cultural Change

– Relationships are the key

– Involve people

– Reduce exposure

– Partner for change

• IAM

• SOS

• OPP

• UHS

• MSHMC

Page 19: Privacy Conundrums in Higher Academic EnvironmentThe Three P’s •Policy, Procedure and Practice –If there isn’t a policy against it I can do what I please –We’ve always

How to do it

• Raising Awareness

–Road Trips!

–Classroom training

• HRDC

• Private excursions

• Guest lecturing

• On-line modules

– Internal venues

–Privacy Summit 2013

Page 20: Privacy Conundrums in Higher Academic EnvironmentThe Three P’s •Policy, Procedure and Practice –If there isn’t a policy against it I can do what I please –We’ve always

Help at Last

• A Data Classification Scheme

• A Governance, Compliance, and Risk analysis tool (GRC)

Page 21: Privacy Conundrums in Higher Academic EnvironmentThe Three P’s •Policy, Procedure and Practice –If there isn’t a policy against it I can do what I please –We’ve always

GRC Tool

• Vendor search

• Evaluation process

• Utilization of tool

• Lessons learned

Page 22: Privacy Conundrums in Higher Academic EnvironmentThe Three P’s •Policy, Procedure and Practice –If there isn’t a policy against it I can do what I please –We’ve always

Show of Hands

Currently using a GRC tool?

Page 23: Privacy Conundrums in Higher Academic EnvironmentThe Three P’s •Policy, Procedure and Practice –If there isn’t a policy against it I can do what I please –We’ve always

Take Aways

• Patience

• Communication

• Acceptance

• Assertiveness

• Awareness

Page 24: Privacy Conundrums in Higher Academic EnvironmentThe Three P’s •Policy, Procedure and Practice –If there isn’t a policy against it I can do what I please –We’ve always

QUESTIONS?

Sarah Morrow

[email protected]

– (814)863-3049

Jennifer (Jenn) Stewart

[email protected]

– (814)863-7820

[email protected]

www.psu.edu/Privacy