Protecting more than privacy in schools

Regulations protect privacy, but what about the overall cybersecurity of public schools that already function on limited resources


Larger enterprises have the resources to not only afford the technology needed to grow in the digital age, but they also have the budget and manpower to build security into their overall ecosystems.


今年秋天早些时候,数据创新中心发布了一份报告,Building a Data-Driven Education System in the United States,in which they said 93 percent of teachers are regularly using digital tools to assist classroom instruction in some capacity.


全球安全情报公司Nuix USG高级副总裁Keith Lowry说:“ K-12在州和地方一级运行,他们将单独负责保护这些基础设施。”

Who then, at the state and local level, is thinking about security in education? "In general terms," said Lowry, "most people and organizations including government agencies are either turning a blind eye or are not technologically tuned in to the tremendous threat that happens to be at our doorstep in our digital world."

安全begins with administrators and leaders. Before schools start collecting this myriad data on students, they have to spend some time and write policies and work out processes and procedures to plan for an attack, but are they too late?


Daniel Castro, director, Center for Data Innovation, said that in some ways the challenges in education aren’t too different from what you see in other industries. "We know there’s a lot of best practices from thinking about authentication to vulnerability testing, but school districts don't have to have all that expertise."

[ ALSO ON CSO:学校跟踪学生的在线行为,但父母甚至知道吗?这是给予的


Being able to differentiate between secure and insecure products and having model clauses for cloud computing within the education sector are other ways to think about risk, said Castro, but "The solution can’t be each school needs to do X, Y, and Z. It has to be looking at how do you get vendors to secure the quality of their products?"


Daniel Castro, director, Center for Data Innovation

卡斯特罗说:“这种情况有可能使教育得以更好地标准。”"The other challenge is authentication, and that goes beyond education as well. Without it, there’s not much you can do on the security side. I’m not terribly optimistic that the US is going to solve it, but schools can put more pressure to resolve those challenges."

卡内基Learning的首席产品建筑师史蒂夫·里特(Steve Ritter)表示,不幸的是,法规并没有跟上技术的步伐。“费尔帕是一项非常古老的法律。即使对于最善良的人来说,它也很难映射。它具有该模型,学校正在向第三方提供数据,但学校没有数据并选择选择将其发送给供应商,”里特说。

Two kinds of potential problems include technical security and standard practices of being encrypted so that data isn't sent unencrypted. There's also privacy protection in general.

Developing a common standard around how data is collected, for what purposes it is used, with whom it is shared, how it is stored, and how it is eliminated would help to bring everyone onto the same page because there seems to be some discrepancy over what kind of data has the greatest value.


Koedinger, professor in the Human-Computer Interaction Institute at Carnegie Mellon's School of Computer Science said, "If vendors are using the data to improve the curriculum, they don’t need to know who the students are. If the data is vigorously de-identified, eliminating record and demographic information, we might not have so much to worry about."

卡内基学习的首席产品架构师史蒂夫·里特(Steve Ritter)

On the other hand, chief learning officer at Kaplan, Bror Saxberg, said, "There are ways to do rich analyses of large sets of data that anonymize and also protect identity of students while doing some very valuable work, which can lead you to understand how to personalize, but if the goal is to de-identify data, then don't collect data."

One way to address concerns is that as the risk goes higher, the access is more highly limited. "We have public data sets of K-12 student interactions that anybody can access because they are so de-identified," Koedinger said.

According to Koedinger, the National Academy of Education is starting to have these conversations, but there needs to be some way to get the word out to the schools that they should be putting pressure on the developers and vendors.

"The school should be demanding that security. A school could say to a vendor 'we will use your product, but only if you guarantee that the data you keep is fully de-identified'," Koedinger said.






