Intelligent SME.tech Issue 17 | Page 38

// INDUSTRY UNLOCKED

There are multiple regulations and standards that require Personally Identifiable Information ( PII ) to be protected . If educational institutions are or are going to be processing PII digitally , they must adhere to these standards to ensure they are safeguarding the information of their teachers and students .

TEACHERS , STUDENTS AND EVERYONE ELSE
INVOLVED IN THE EDUCATION PROCESS NEED
TO LEARN ABOUT
RISKS OF THE NEW TEACHING ENVIRONMENT .
The other aspect to consider is that educators who previously only had access to student data within the confines of the school network now may have access to this data on their home networks . Are they accessing it a secure manner ? Have they secured their home networks ? Are they using personal devices or devices issued and managed by the school board ?
How should organisations respond to these challenges ?
The first thing to consider is who has access to what data and on what devices . Following the principle of least privilege , are those accessing the data authorised to access it ? Are the devices they are using to access the data secured ? In order to do this , the IT personnel need to start by taking an accurate inventory of the devices accessing the data .
Next , they need to ensure that the devices that are accessing data are doing so within a secure environment . This can be done by implementing VPN connectivity to the data , implementing Zero Trust methodologies and verifying that the devices connecting in are configured securely , up to date with the latest security patches and not running any known malicious software .
38 intelligent
. tech
Intelligent SME . tech