IT Trends -
[Cached Version]
Published on: 12/14/2006
Last Visited: 12/21/2006
Here's Peter Adler, of Adler InfoSec & Privacy Group LLC and former interim Chief Information Security Officer at the University of Colorado puts it in a recent EDUCAUSE Review article:
[C]ontrolling risks to personal information through enhanced information security has become the subject of state and federal laws.The recent upsurge in the number of state and federal laws and regulations represents an emerging legal standard that imposes obligations on colleges and universities to protect the data they collect, store, process, use, and disclose.These laws increasingly affect how higher education institutions, often operating in multiple jurisdictions, handle personal information, including sensitive health and financial data.Many of the new laws require disclosures to victims when there is unauthorized access to systems containing sensitive information.Failure to protect this type of information will inevitably result in public embarrassment and the financial costs associated with managing the response to incidents and may also result in investigations, fines, and other penalties
Adler is a proponent of centralized control and security for this kind of information. (Note, also, that the EDUCAUSE Resource Center on the topic of Cybersecurity.)