<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0" xml:base="http://connect.educause.edu" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd">
<channel>
 <title>EDUCAUSE | Data Security</title>
 <link>http://connect.educause.edu/browse/content/blog/256</link>
 <image>
    <title>EDUCAUSE CONNECT</title> 
    <link>http://connect.educause.edu/browse/content/blog/256</link> 
    <url>http://connect.educause.edu/educause/images/e_rss.png</url> 
 </image>

  <itunes:subtitle>events, concepts, and conversation from EDUCAUSE</itunes:subtitle>
  <itunes:author>The EDUCAUSE Podcast Crew</itunes:author>
  <itunes:summary>EDUCAUSE is a nonprofit association whose mission is to advance higher education by promoting the intelligent use of information technology.  Our podcasts provide information about a range of topics including Leadership, Policy and Law, Teaching and Learning, Emerging Technologies, Open Source, Research Computing, Cyberinfrastructure, and Digitial Libraries. </itunes:summary>
  <itunes:new-feed-url>http://connect.educause.edu/browse/content/node/691/list/feed</itunes:new-feed-url>
  <itunes:image href="http://connect.educause.edu/educause/images/e_rss.png" />
  <itunes:category text="Education">
  	<itunes:category text="Education Technology"/>
  	<itunes:category text="Higher Education"/>
  </itunes:category>
  <itunes:category text="Technology">
  	<itunes:category text="Tech News"/>
  </itunes:category>

 <description>Recent blog entries tagged with Data Security.</description>
 <language>en</language>

<item>
 <title>August 8: Free Web Seminar on Identity Management at University of Southern California</title>
 <link>http://connect.educause.edu/display/47143</link>
 <description>&lt;p&gt;&lt;a href=&quot;http://net.educause.edu/SPTIDM088&quot;&gt;&lt;img alt=&quot;STLIDM&quot; class=&quot;left&quot; src=&quot;http://www.educause.edu/elements/images/highlights/Copy%20of%20spt_idm.png&quot; /&gt;&lt;/a&gt;The &lt;a href=&quot;http://www.educause.edu/SpotlightSeries/15139&quot; title=&quot;http://www.educause.edu/SpotlightSeries/15139&quot;&gt;EDUCAUSE Live! Spotlight on Identity Management&lt;/a&gt; series is a six-month series that will feature one or two speakers from a campus that have analyzed or solved a problem in a way that many people will find instructive.&lt;/p&gt;&lt;p&gt;Identity and access management (IAM) at University of Southern California (USC) has been a policy-driven, grassroots effort for the past five years. During that time collaborative committees with representatives from many academic and administrative units have enabled the accelerated growth of applications relying on identity data while governing the release of that data. With the backing of the university data stewards in the offices of the registrar, provost, and personnel services, policies have been implemented regarding the release of identifying sensitive information to both internal departments and external vendors. In this free web seminar on August 8, &lt;a href=&quot;http://net.educause.edu/SPTIDM088&quot;&gt;Identity Management at USC: Collaboration, Governance, and Access&lt;/a&gt;, presenters &lt;strong&gt;Brendan Bellina&lt;/strong&gt;, identity services architect and manager of enterprise middleware development, and &lt;strong&gt;Margaret Harrington&lt;/strong&gt;, director of the Office of Organization Improvement Services, both at USC, will discuss the composition of these committees, the governance policies that have been implemented, and some of the dozens of applications that have been enabled securely through this process.&lt;/p&gt;&lt;p&gt;The event is free, but registration is required and virtual seating is limited. &lt;a href=&quot;http://net.educause.edu/RegisterNow/1020020&quot; title=&quot;http://www.educause.edu/RegisterNow%2521/15807&quot;&gt;Register now&lt;/a&gt;.&lt;/p&gt;</description>
 <comments>http://connect.educause.edu/display/47143#comments</comments>
 <category domain="http://connect.educause.edu/tag/Data+Classification+Policies/5334">Data Classification Policies</category>
 <category domain="http://connect.educause.edu/tag/Data+Security/256">Data Security</category>
 <category domain="http://connect.educause.edu/tag/EDUCAUSE+News/698">EDUCAUSE News</category>
 <category domain="http://connect.educause.edu/tag/EDUCAUSE+Spotlight+Series/5986">EDUCAUSE Spotlight Series</category>
 <category domain="http://connect.educause.edu/tag/free+web+seminar/3938">free web seminar</category>
 <category domain="http://connect.educause.edu/tag/Identity+Management/474">Identity Management</category>
 <category domain="http://connect.educause.edu/tag/Spotlight+on+Identity+Management+series/5923">Spotlight on Identity Management series</category>
 <category domain="http://connect.educause.edu/tag/web+seminar/3069">web seminar</category>
 <pubDate>Fri, 01 Aug 2008 15:54:42 -0500</pubDate>
 <dc:creator>cluckett</dc:creator>
 <guid isPermaLink="false">47143 at http://connect.educause.edu</guid>
</item>
<item>
 <title>Podcast: The FTC as an Educational Partner in Improving Data Security and Privacy</title>
 <link>http://connect.educause.edu/display/46774</link>
 <description>&lt;p&gt;This 38 minute podcast features a keynote address by &lt;a href=&quot;http://www.educause.edu/PeerDirectory/750?ID=173901&quot;&gt;Mary Beth Richards&lt;/a&gt;, Deputy Director of the Bureau of Consumer Protection for the Federal Trade Commission. Her speech, &amp;quot;&lt;a href=&quot;http://net.educause.edu/POL08/Program/14797?PRODUCT_CODE=POL08/GS02&amp;amp;ITIN=False&quot;&gt;The FTC as an Educational Partner in Improving Data Security and Privacy&lt;/a&gt;,&amp;quot; was recorded at the EDUCAUSE 2008 Policy Conference in Arlington, Virgina.&lt;/p&gt;&lt;p&gt;The Federal Trade Commission deals with issues that touch the economic lives of most Americans. The current portfolio includes protecting consumers in the areas of data security and privacy, identity theft, Social Security number misuse, identity management, spam, maintaining the National Do Not Call Registry, and other IT issues of interest to colleges and universities. The FTC&#039;s Bureau of Consumer Protection, although a regulator of businesses, is also an educator: it seeks to educate consumers and provide businesses and other organizations with the information they need to comply with the rules of the road and to provide consumers with the necessary tools to engage in commerce intelligently. This session highlights information policy issues the FTC is addressing and educational resources institutions of higher education can leverage to improve student, faculty, and staff awareness of data security and privacy risks. &lt;/p&gt;</description>
 <comments>http://connect.educause.edu/display/46774#comments</comments>
 <enclosure url="http://connect.educause.edu/files/gbayne_richards-pol08.mp3" length="27136232" type="audio/mpeg" />
 <category domain="http://connect.educause.edu/tag/Data+Security/256">Data Security</category>
 <category domain="http://connect.educause.edu/tag/EDUCAUSE_POL08/6251">EDUCAUSE_POL08</category>
 <category domain="http://connect.educause.edu/tag/Podcasts/691">Podcasts</category>
 <category domain="http://connect.educause.edu/tag/Policy+and+Law/51">Policy and Law</category>
 <category domain="http://connect.educause.edu/tag/Security+Planning/249">Security Planning</category>
 <category domain="http://connect.educause.edu/tag/Security+Policies/254">Security Policies</category>
 <category domain="http://connect.educause.edu/tag/Security+Risk+Assessment+and+Analysis/261">Security Risk Assessment and Analysis</category>
 <pubDate>Mon, 19 May 2008 16:40:38 -0500</pubDate>
 <dc:creator>gbayne</dc:creator>
 <guid isPermaLink="false">46774 at http://connect.educause.edu</guid>
</item>
<item>
 <title>EDUCAUSE Live! Podcast: What Price Insularity? Reflections About Computer Security Failings.</title>
 <link>http://connect.educause.edu/display/45849</link>
 <description>&lt;p&gt;In this &lt;a href=&quot;http://www.educause.edu/content.asp?SECTION_ID=34&quot;&gt;EDUCAUSE Live!&lt;/a&gt; podcast, join host, &lt;a href=&quot;http://www.educause.edu/YourHost/2720&quot;&gt;Steve Worona&lt;/a&gt;, for the topic &amp;quot;&lt;a href=&quot;http://www.educause.edu/LIVE081&quot;&gt;What Price Insularity? Reflections About Computer Security Failings&lt;/a&gt;&amp;quot;. Steve&#039;s guest is &lt;a href=&quot;http://www.educause.edu/PeerDirectory/750?ID=169388&quot;&gt;Fred Schneider&lt;/a&gt;, Professor of Computer Science at Cornell University.&lt;/p&gt;&lt;p&gt;Presentation slides for this audio can be found &lt;a href=&quot;http://www.educause.edu/ir/library/powerpoint/LIVE081.ppt&quot;&gt;here&lt;/a&gt;.&lt;/p&gt;&lt;p&gt;Why is it risky for technologists to ignore the nontechnical context where their systems will be deployed? Furthermore, what is the risk when policymakers ignore the limits and potential of technology? How can we structure dialogue between technologists and policymakers to address &lt;em&gt;security failings&lt;/em&gt;&amp;#8212;to revisit identity theft, electronic voting machines, digital rights management, and network neutrality? Fred Schneider, editor of the National Research Council study &lt;em&gt;Trust in Cyberspace&lt;/em&gt; and longtime researcher on what makes computer systems secure, considers these and other questions. &lt;/p&gt;</description>
 <comments>http://connect.educause.edu/display/45849#comments</comments>
 <enclosure url="http://connect.educause.edu/files/ELIVE-Schneider.mp3" length="42457989" type="audio/mpeg" />
 <category domain="http://connect.educause.edu/tag/Cybersecurity/56">Cybersecurity</category>
 <category domain="http://connect.educause.edu/tag/Cybersecurity+Policy/633">Cybersecurity Policy</category>
 <category domain="http://connect.educause.edu/tag/Data+Security/256">Data Security</category>
 <category domain="http://connect.educause.edu/tag/EDUCAUSE+Live/1680">EDUCAUSE Live</category>
 <category domain="http://connect.educause.edu/tag/EDUCAUSE+Live%21/3068">EDUCAUSE Live!</category>
 <category domain="http://connect.educause.edu/tag/Podcasts/691">Podcasts</category>
 <category domain="http://connect.educause.edu/tag/Policy+and+Law/51">Policy and Law</category>
 <category domain="http://connect.educause.edu/tag/Security+Planning/249">Security Planning</category>
 <pubDate>Mon, 07 Jan 2008 12:27:05 -0600</pubDate>
 <dc:creator>gbayne</dc:creator>
 <guid isPermaLink="false">45849 at http://connect.educause.edu</guid>
</item>
<item>
 <title>E07 Video &amp; Podcast: &quot;Bruce Schneier on Information Security: Ten Trends&quot;</title>
 <link>http://connect.educause.edu/display/45698</link>
 <description>&lt;p&gt;&lt;a href=&quot;http://hosted.mediasite.com/hosted4/Viewer/Viewers/Viewer320TL.aspx?mode=Default&amp;amp;peid=bd13bfdd-8226-4ff2-89bd-d0aa6d080766&amp;amp;pid=ced6e3bf-5644-4fac-ad5c-7ca754d890fb&amp;amp;playerType=Port25&quot;&gt;Watch the video&lt;/a&gt; or &lt;a href=&quot;http://connect.educause.edu/blog/gbayne/e07podcastbruceschne/45426&quot;&gt;listen to the podcast&lt;/a&gt; of Bruce Schneier&#039;s recent keynote speech, &amp;quot;&lt;a href=&quot;http://connect.educause.edu/library/abstract/BruceSchneieronInfor/45362&quot;&gt;Bruce Schneier on Information Security: Ten Trends&lt;/a&gt;&amp;quot;, which was delivered at the EDUCAUSE 2007 Annual Conference in Seattle, Washington on October 26, 2007. &lt;/p&gt;&lt;p&gt;You can also hear a &lt;a href=&quot;http://connect.educause.edu/blog/mpasiewicz/e07podcastanintervie/45439&quot;&gt;14 minute interview&lt;/a&gt; with &lt;a href=&quot;https://www.educause.edu/PeerDirectory/750?ID=160267&quot;&gt;Bruce Schneier&lt;/a&gt;. Listen in as he shares some insightful words about privacy along with interesting commentary about ethics, cybersecurity, and blogging.&lt;/p&gt;</description>
 <comments>http://connect.educause.edu/display/45698#comments</comments>
 <category domain="http://connect.educause.edu/tag/Cybersecurity/56">Cybersecurity</category>
 <category domain="http://connect.educause.edu/tag/Data+Security/256">Data Security</category>
 <category domain="http://connect.educause.edu/tag/EDUCAUSE2007/5576">EDUCAUSE2007</category>
 <category domain="http://connect.educause.edu/tag/Security+Management/631">Security Management</category>
 <category domain="http://connect.educause.edu/tag/Security+Planning/249">Security Planning</category>
 <category domain="http://connect.educause.edu/tag/Security+Task+Force+Announcements/699">Security Task Force Announcements</category>
 <category domain="http://connect.educause.edu/tag/Trends+and+Visions/5011">Trends and Visions</category>
 <pubDate>Thu, 29 Nov 2007 16:51:51 -0600</pubDate>
 <dc:creator>vvogel</dc:creator>
 <guid isPermaLink="false">45698 at http://connect.educause.edu</guid>
</item>
<item>
 <title>E07 Podcast: Bruce Schneier on Information Security: Ten Trends</title>
 <link>http://connect.educause.edu/display/45426</link>
 <description>&lt;p&gt;In this 43 minute podcast, we feature a keynote speech by &lt;a href=&quot;http://www.educause.edu/PeerDirectory/750?ID=160267&quot;&gt;Bruce Schneier&lt;/a&gt;, author and Chief Technology Officer for BT Counterpane, Inc. This speech was delivered at the EDUCAUSE 2007 Annual Conference in Seattle, Washington on October 26th, 2007. It is entitled &amp;quot;&lt;a href=&quot;http://www.educause.edu/E07/Program/11073?PRODUCT_CODE=E07/GS02&quot;&gt;Bruce Schneier on Information Security: Ten Trends&lt;/a&gt;&amp;quot;.&lt;/p&gt;&lt;p&gt;Surveying current trends in information security, it&amp;#8217;s clear that a myriad of forces are at work. But fundamentally, security is all about economics: both attacker and defender are trying to maximize the return on their investments. Economics can both explain why security fails so often and offer new solutions for its success. For example, often the people who could protect a system are not those who suffer the costs of failure. Changing these economic incentives will do more to improve security than will more technology. &lt;/p&gt;&lt;p&gt;&lt;img alt=&quot;REAL&quot; height=&quot;26&quot; src=&quot;http://edit.educause.edu/elements/images/Uploaded_Images/CONNECT/podcast_Sponsor_real.png&quot; width=&quot;315&quot; /&gt;&lt;/p&gt;</description>
 <comments>http://connect.educause.edu/display/45426#comments</comments>
 <enclosure url="http://connect.educause.edu/files/gbayne_E07schneier.mp3" length="35829760" type="audio/mpeg" />
 <category domain="http://connect.educause.edu/tag/current+trends/4477">current trends</category>
 <category domain="http://connect.educause.edu/tag/Cybersecurity/56">Cybersecurity</category>
 <category domain="http://connect.educause.edu/tag/Data+Security/256">Data Security</category>
 <category domain="http://connect.educause.edu/tag/E07/5486">E07</category>
 <category domain="http://connect.educause.edu/tag/economics/5703">economics</category>
 <category domain="http://connect.educause.edu/tag/EDUCAUSE2007/5576">EDUCAUSE2007</category>
 <category domain="http://connect.educause.edu/tag/Educause2007+General_Session/5669">Educause2007 General_Session</category>
 <category domain="http://connect.educause.edu/tag/hot+topics/5562">hot topics</category>
 <category domain="http://connect.educause.edu/tag/Podcasts/691">Podcasts</category>
 <category domain="http://connect.educause.edu/tag/Security+Implementation/265">Security Implementation</category>
 <category domain="http://connect.educause.edu/tag/Security+Planning/249">Security Planning</category>
 <category domain="http://connect.educause.edu/tag/Security+Risk+Assessment+and+Analysis/261">Security Risk Assessment and Analysis</category>
 <category domain="http://connect.educause.edu/tag/Trends+and+Visions/5011">Trends and Visions</category>
 <pubDate>Wed, 31 Oct 2007 15:35:49 -0500</pubDate>
 <dc:creator>gbayne</dc:creator>
 <guid isPermaLink="false">45426 at http://connect.educause.edu</guid>
</item>
<item>
 <title>Tune In September 5: Free Web Seminar on Payment Card Industry (PCI) Compliance in Higher Education</title>
 <link>http://connect.educause.edu/display/45016</link>
 <description>&lt;p&gt;Many of us are working within our institutions to achieve Payment Card Industry (PCI) compliance. We see a number of merchants on campuses with different business needs, systems, and vendor relationships in place. In many cases, achieving compliance with PCI DSS, the Data Security Standard, is proving difficult. In this free Sept. 5 EDUCAUSE Live! Web seminar, &lt;a href=&quot;http://www.educause.edu/live0717&quot; title=&quot;http://educause.informz.net/z/cjUucD9taT0zNTIxMyZwPTEmdT0xMDAwMTU2MDkzJmxpPTI0MDA/index.html&quot;&gt;Lessons Learned on the Road to PCI Compliance&lt;/a&gt;, &lt;strong&gt;Mark Welch&lt;/strong&gt;, project coordinator for the Credit Card Support Program at University of Notre Dame, and &lt;strong&gt;Walt Conway&lt;/strong&gt;, president of Walter Conway Associates, LLC, will share experiences and valuable lessons learned in implementing PCI DSS, including merchant levels (does it matter?), limiting the scope of the PCI effort (yes, it can be done), the Payment Applications Best Practices list (is it required?), and recent findings on information security breaches. &lt;/p&gt;&lt;p&gt;In addition, Welch and Conway will represent NACUBO and all of higher education at the first PCI Security Standards Council meeting of participating organizations to be held in Toronto next month. Bring your questions, suggestions, and observations to share with them in advance of that meeting.&lt;/p&gt;&lt;p&gt;Those unable to attend may wish to visit the &lt;a href=&quot;http://www.educause.edu/Events/2719&quot;&gt;archives&lt;/a&gt; after the event or browse related EDUCAUSE resources on &lt;a href=&quot;http://connect.educause.edu/term_view/PCI+DSS&quot;&gt;PCI DSS&lt;/a&gt;.&lt;/p&gt;</description>
 <comments>http://connect.educause.edu/display/45016#comments</comments>
 <category domain="http://connect.educause.edu/tag/Data+Security/256">Data Security</category>
 <category domain="http://connect.educause.edu/tag/EDUCAUSE+Live/1680">EDUCAUSE Live</category>
 <category domain="http://connect.educause.edu/tag/EDUCAUSE+Live%21/3068">EDUCAUSE Live!</category>
 <category domain="http://connect.educause.edu/tag/EDUCAUSE+News/698">EDUCAUSE News</category>
 <category domain="http://connect.educause.edu/tag/information+security+breaches/5528">information security breaches</category>
 <category domain="http://connect.educause.edu/tag/nacubo/2970">nacubo</category>
 <category domain="http://connect.educause.edu/tag/payment+card+industry/5482">payment card industry</category>
 <category domain="http://connect.educause.edu/tag/pci+compliance/5526">pci compliance</category>
 <category domain="http://connect.educause.edu/tag/PCI+DSS/5338">PCI DSS</category>
 <category domain="http://connect.educause.edu/tag/security+standards/5527">security standards</category>
 <category domain="http://connect.educause.edu/tag/web+seminar/3069">web seminar</category>
 <pubDate>Tue, 28 Aug 2007 15:46:56 -0500</pubDate>
 <dc:creator>cluckett</dc:creator>
 <guid isPermaLink="false">45016 at http://connect.educause.edu</guid>
</item>
<item>
 <title>Podcast: Privacy and Security in Higher Education: Filling the Policy Vacuum</title>
 <link>http://connect.educause.edu/display/44910</link>
 <description>&lt;p&gt;In this hour and ten minute long podcast from the &lt;a href=&quot;http://www.educause.edu/content.asp?Section_ID=266&quot;&gt;2007 Seminars on Academic Computing&lt;/a&gt;, we hear from &lt;a href=&quot;http://www.educause.edu/PeerDirectory/750?ID=147903&quot;&gt;Fred H. Cate&lt;/a&gt;, Distinguished Professor at the School of Law and Director of the Center for Applied Cybersecurity Research at Indiana University, with a speech entitled, &lt;a href=&quot;http://www.educause.edu/SA07/Program/12665?PRODUCT_CODE=SA07/DGS02&quot;&gt;Privacy and Security in Higher Education: Filling the Policy Vacuum&lt;/a&gt; .&lt;/p&gt;&lt;p&gt;Colleges and universities possess an exceptional volume and variety of personal information. Our stewardship of such information has been inconsistent and inadequate, and we often implement new technologies and systems without considering systemic privacy and security implications. Although many publicly reported security breaches occur on campuses, we have been slow to provide training in privacy and security issues, rarely audit for compliance, and lag far behind industry and government in appointing privacy and security officers. This session will address the information policy challenges facing colleges and universities, today and in the future, and will offer practical steps for overcoming them.&lt;/p&gt;&lt;p&gt;&lt;br /&gt; &lt;/p&gt;</description>
 <comments>http://connect.educause.edu/display/44910#comments</comments>
 <enclosure url="http://connect.educause.edu/files/gbayne_fredcate-cybersecurity1.mp3" length="49815301" type="audio/mpeg" />
 <category domain="http://connect.educause.edu/tag/Cyber-Security/1426">Cyber-Security</category>
 <category domain="http://connect.educause.edu/tag/Cybersecurity/56">Cybersecurity</category>
 <category domain="http://connect.educause.edu/tag/Data+Mining/503">Data Mining</category>
 <category domain="http://connect.educause.edu/tag/Data+Security/256">Data Security</category>
 <category domain="http://connect.educause.edu/tag/data+stewardship/1068">data stewardship</category>
 <category domain="http://connect.educause.edu/tag/EDUCAUSE+Conferences/1433">EDUCAUSE Conferences</category>
 <category domain="http://connect.educause.edu/tag/Educause_SA07/5477">Educause_SA07</category>
 <category domain="http://connect.educause.edu/tag/Podcasts/691">Podcasts</category>
 <category domain="http://connect.educause.edu/tag/Policy+and+Law/51">Policy and Law</category>
 <category domain="http://connect.educause.edu/tag/Privacy/255">Privacy</category>
 <category domain="http://connect.educause.edu/tag/Privacy+Policies/172">Privacy Policies</category>
 <category domain="http://connect.educause.edu/tag/RIAA/1040">RIAA</category>
 <category domain="http://connect.educause.edu/tag/SAC/730">SAC</category>
 <pubDate>Mon, 13 Aug 2007 11:57:22 -0500</pubDate>
 <dc:creator>gbayne</dc:creator>
 <guid isPermaLink="false">44910 at http://connect.educause.edu</guid>
</item>
<item>
 <title>New PCI DSS Resource Page Posted on EDUCAUSE Connect </title>
 <link>http://connect.educause.edu/display/44882</link>
 <description>&lt;p&gt;&lt;img alt=&quot;Connect logo&quot; height=&quot;11&quot; src=&quot;http://www.educause.edu/elements/images/highlights/connect.gif&quot; width=&quot;147&quot; /&gt;EDUCAUSE has posted the new Connect resource page, &lt;a href=&quot;http://connect.educause.edu/term_view/PCI+DSS&quot;&gt;Payment Card Industry Data Security Standard (PCI DSS)&lt;/a&gt;.&amp;#160;Explore conference resources, member blogs, wikis, and more.&lt;/p&gt;</description>
 <comments>http://connect.educause.edu/display/44882#comments</comments>
 <category domain="http://connect.educause.edu/tag/Data+Security/256">Data Security</category>
 <category domain="http://connect.educause.edu/tag/data+security+standard/5485">data security standard</category>
 <category domain="http://connect.educause.edu/tag/dss/5483">dss</category>
 <category domain="http://connect.educause.edu/tag/EDUCAUSE+News/698">EDUCAUSE News</category>
 <category domain="http://connect.educause.edu/tag/payment+card+industry/5482">payment card industry</category>
 <category domain="http://connect.educause.edu/tag/pci/5484">pci</category>
 <pubDate>Mon, 06 Aug 2007 13:42:12 -0500</pubDate>
 <dc:creator>cluckett</dc:creator>
 <guid isPermaLink="false">44882 at http://connect.educause.edu</guid>
</item>
<item>
 <title>GAO Releases Report on Data Breaches and Identity Theft</title>
 <link>http://connect.educause.edu/display/44809</link>
 <description>&lt;p&gt;The Government Accountability Office (GAO) has released a &lt;a href=&quot;http://www.gao.gov/new.items/d07737.pdf&quot;&gt;Report on Data Breaches&lt;/a&gt; that concludes while &amp;quot;breaches of sensitive information have occurred frequently and under widely varying circumstances, . . . the extent to which data breaches have resulted in identity theft is not well known.&amp;quot; It further concludes that &amp;quot;should Congress choose to enact a federal notification requirement, use of a risk-based standard could avoid undue burden on organizations and unnecessary and counterproductive notifications of breaches that present little risk.&amp;quot;&lt;/p&gt;&lt;p&gt;Some further higher education references in the report:&lt;/p&gt;&lt;ul&gt;	&lt;li&gt;EDUCAUSE, a nonprofit association that addresses technology issues in higher education, conducted a survey in 2005 on data security at higher education institutions in the United States and Canada. Twenty-six percent of the 490 institutions that responded said they had experienced a security incident in the past year that resulted in the compromise of confidential information.&amp;quot; (page 16)&lt;/li&gt;	&lt;li&gt;Representatives of the American Council on Education and two other higher education associations stated that while data breaches at colleges and universities were not uncommon, they were aware of little to no identity theft that had resulted from such breaches. (page 23)&lt;/li&gt;	&lt;li&gt;7 higher education institutions are identified (although not by name) among the 24 large publicly reported data breaches from January 2000 - June 2005 that were examined by the GAO which included interviews with educational institutions. (page 26)&lt;/li&gt;	&lt;li&gt;There are also costs associated with actual notifications - potentially including printing, postage, legal, investigate, and public relations expenses . . . Entities also may incur costs related to staffing call centers to field inquiries from consumers about the breach. For example, representatives of the University of California at Berkeley told us that following a 2005 breach of 98,000 records, the university spent $75,000 in staffing, telecommunications, and other call center costs. (page 34)&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;The report also makes frequent reference to the &lt;a href=&quot;http://www.ftc.gov/opa/2007/04/idtheft.shtm&quot;&gt;President&#039;s Identity Theft Task Force Report&lt;/a&gt; released in April.&lt;/p&gt;</description>
 <comments>http://connect.educause.edu/display/44809#comments</comments>
 <category domain="http://connect.educause.edu/tag/data+incident+notification/5455">data incident notification</category>
 <category domain="http://connect.educause.edu/tag/Data+Security/256">Data Security</category>
 <category domain="http://connect.educause.edu/tag/Identity+Theft/661">Identity Theft</category>
 <category domain="http://connect.educause.edu/tag/Incident+Handling+and+Response/4388">Incident Handling and Response</category>
 <category domain="http://connect.educause.edu/tag/security+breaches/5456">security breaches</category>
 <category domain="http://connect.educause.edu/tag/Washington+Update/5405">Washington Update</category>
 <pubDate>Tue, 24 Jul 2007 15:00:19 -0500</pubDate>
 <dc:creator>Rodney</dc:creator>
 <guid isPermaLink="false">44809 at http://connect.educause.edu</guid>
</item>
<item>
 <title>Podcast:: Security Breaches and Identity Theft</title>
 <link>http://connect.educause.edu/display/44581</link>
 <description>&lt;p&gt;In this 55 minute podcast, we present a general session from the EDUCAUSE 2007 Policy Conference entitled, &amp;#8220;&lt;a href=&quot;http://connect.educause.edu/library/abstract/SecurityBreachesandI/42898&quot;&gt;Security Breaches and Identity Theft&lt;/a&gt;&amp;#8221;. This is a panel discussion moderated by EDUCAUSE Government Relations Officer and Security Task Force Coordinator, Rodney Peterson. The discussion features:&lt;strong&gt;&amp;#160;&lt;/strong&gt;&lt;/p&gt;&lt;p&gt;&lt;strong&gt;&lt;a href=&quot;http://connect.educause.edu/eprofile/161005&quot;&gt;Michael Atleson&lt;/a&gt;,&lt;/strong&gt; Attorney, Division of Privacy and Identity Protection, Federal Trade Commission&lt;/p&gt;&lt;p&gt;&lt;strong&gt;&lt;a href=&quot;http://connect.educause.edu/eprofile/159458&quot;&gt;Liz Gasster&lt;/a&gt;,&lt;/strong&gt; General Counsel and Acting Executive Director of the Cyber Security Industry Alliance&lt;/p&gt;&lt;p&gt;As Congress strives to pass legislation that would provide a uniform federal law for security breach notifications, a number of related privacy and security policy proposals are under consideration in the Congress and executive branch agencies. This panel will address topics such as preventing misuse of Social Security numbers, requirements for a personal data privacy and security programs, and measures to prevent identity theft.&lt;/p&gt;</description>
 <comments>http://connect.educause.edu/display/44581#comments</comments>
 <enclosure url="http://connect.educause.edu/files/gbayne_securitybreaches.mp3" length="39112516" type="audio/mpeg" />
 <category domain="http://connect.educause.edu/tag/Data+Security/256">Data Security</category>
 <category domain="http://connect.educause.edu/tag/EDUCAUSE_POL07/5363">EDUCAUSE_POL07</category>
 <category domain="http://connect.educause.edu/tag/Federal+Privacy+Law/326">Federal Privacy Law</category>
 <category domain="http://connect.educause.edu/tag/Identity+Management/474">Identity Management</category>
 <category domain="http://connect.educause.edu/tag/Identity+Theft/661">Identity Theft</category>
 <category domain="http://connect.educause.edu/tag/Podcasts/691">Podcasts</category>
 <category domain="http://connect.educause.edu/tag/Privacy/255">Privacy</category>
 <category domain="http://connect.educause.edu/tag/Privacy+Risk+Assessment/268">Privacy Risk Assessment</category>
 <pubDate>Tue, 26 Jun 2007 15:05:47 -0500</pubDate>
 <dc:creator>gbayne</dc:creator>
 <guid isPermaLink="false">44581 at http://connect.educause.edu</guid>
</item>
</channel>
</rss>
