Managing professional and personal sensitive information

  • Authors:
  • Jason Rakers

  • Affiliations:
  • Youngstown State University, Youngstown, OH, USA

  • Venue:
  • Proceedings of the 38th annual ACM SIGUCCS fall conference: navigation and discovery
  • Year:
  • 2010

Quantified Score

Hi-index 0.00

Visualization

Abstract

All organizations have to manage sensitive information related to their business operations. Unfortunately, universities have the added challenge of not only managing administrative and academic sensitive information, but often times the personal sensitive information of students and employees. This study reflects on the current best practices in managing sensitive information and discusses how Youngstown State University implements controls for sensitive information. According to the United States Federal Trade Commission, not only is managing sensitive information a good practice, but most industries are mandated by local and state regulations, as well as federal statutes such as the Gramm-Leach-Bliley Act (GLBA), Family Educational Rights and Privacy Act (FERPA), and the Federal Trade Commission Act. Universities like many commercial organizations which handle credit card transactions must comply with the Payment Card Industry's Data Security Standard. With the unique requirements of each regulation, it is often difficult to address each adequately. This study provides a framework for approaching the management of professional and personal sensitive information given the unique requirements faced by higher education