Everyday Cybersecurity Good Data Habits
Introduction to Information Security
What Is Information Security?
Information security is all about protecting data from unauthorized access or theft. Think of all the information a school handles: student grades, attendance records, parent contact details, and health information. Keeping this data safe is not just an IT problem—it's everyone's responsibility.
The goal is to protect the confidentiality, integrity, and availability of information. This is often called the "CIA Triad," a foundational concept in security.
Let's break down what each of these principles means.
Confidentiality
noun
Ensuring that information is not disclosed to unauthorized individuals, entities, or processes. It's about keeping secrets safe.
Integrity is about maintaining the consistency, accuracy, and trustworthiness of data. Information must not be changed in transit or altered by unauthorized people. For example, a student's final grade in the school's database should be the same grade the teacher originally submitted.
Availability
noun
Ensuring that information is accessible and usable upon demand by an authorized person.
Common Threats in Schools
Educational institutions are attractive targets for cyberattacks because they hold a vast amount of personal data. Two of the most common threats are phishing and ransomware.
Educating teams on phishing and cybersecurity is crucial for preventing attacks and protecting sensitive data.
Phishing attacks use deceptive emails, texts, or websites to trick people into revealing sensitive information, like passwords or financial details. An attacker might send an email that looks like it's from the school's IT department, asking you to "verify" your password by clicking a malicious link.
Ransomware is a type of malicious software that encrypts files on a device, making them unusable. Attackers then demand a ransom, usually in cryptocurrency, to restore access. A successful ransomware attack on a school district could shut down its entire network, preventing access to student records, lesson plans, and email.
Protecting Student Privacy
Protecting student data isn't just a good idea—it's the law. Several regulations govern how educational institutions must handle sensitive information.
The most important of these in the United States is the Family Educational Rights and Privacy Act (FERPA).
FERPA is a federal law that protects the privacy of student education records. It gives parents certain rights with respect to their children's education records, which transfer to the student when they reach the age of 18 or attend a school beyond the high school level. Essentially, it controls who can access a student's records.
Beyond specific laws, our everyday digital habits have a huge impact on data security. Simple actions can either strengthen or weaken our defenses against cyber threats.
| Do | Don't |
|---|---|
| Use strong, unique passwords for different accounts. | Share your password with anyone. |
| Be cautious of unsolicited emails and links. | Use unsecured public Wi-Fi for sensitive tasks. |
| Lock your computer when you step away. | Leave sensitive documents visible on your desk. |
| Report suspicious activity to the IT department. | Assume an email is legitimate just because it looks official. |
Ready to check your understanding? Let's see what you've learned.
In the context of information security, what does the principle of "integrity" primarily ensure?
A teacher receives an urgent email that appears to be from the school's IT department, asking them to click a link and enter their credentials to prevent their email account from being locked. This is a classic example of what type of cyberattack?
Understanding these basics is the first step toward creating a safer digital environment for everyone in the school community. By being mindful of potential threats and following best practices, you can play an active role in protecting sensitive information.
