board_policy:ehbc
Differences
This shows you the differences between two versions of the page.
Both sides previous revisionPrevious revisionNext revision | Previous revision | ||
board_policy:ehbc [Monday, November 20, 2023 12:41 AM] – removed - external edit (Unknown date) 127.0.0.1 | board_policy:ehbc [Monday, November 20, 2023 12:42 AM] (current) – ↷ Links adapted because of a move operation Nathan C. McGuire | ||
---|---|---|---|
Line 1: | Line 1: | ||
+ | <WRAP right 300px> | ||
+ | | Status | ||
+ | | Original Adopted Date | 03/ | ||
+ | | Last Revised Date | | | ||
+ | | Last Reviewed Date | ||
+ | </ | ||
+ | ====== EHBC: Data Governance and Security ====== | ||
+ | Last Revised Date: 11/27/2017 | ||
+ | To accomplish the district' | ||
+ | |||
+ | Definitions | ||
+ | |||
+ | Confidential Data/ | ||
+ | |||
+ | Critical Data/ | ||
+ | |||
+ | Responsibility and Data Stewardship | ||
+ | |||
+ | All district employees, volunteers and agents are responsible for accurately collecting, maintaining and securing district data including, but not limited to, information that is confidential or is critical to district operations. | ||
+ | |||
+ | Information Security Officer | ||
+ | |||
+ | Deputy Superintendent is the district' | ||
+ | |||
+ | Director of Technology and Innovation is the district' | ||
+ | |||
+ | Data Managers | ||
+ | |||
+ | All district administrators are data managers for all data collected, maintained, used and disseminated under their supervision as well as data they have been assigned to manage in the district' | ||
+ | |||
+ | Confidential and Critical Information | ||
+ | |||
+ | The district will collect, create or store confidential information only when the superintendent or designee determines it is necessary. The district will provide access to confidential information to appropriately trained district employees and volunteers only when the district determines that such access is necessary for the performance of their duties. The district will disclose confidential information only to authorized district contractors or agents who need access to the information to provide services to the district and who agree not to disclose the information to any other party except as allowed by law and authorized by the district. | ||
+ | |||
+ | District employees, contractors and agents will notify the ISO or designee immediately if there is reason to believe confidential information has been disclosed to an unauthorized person or any information has been compromised, | ||
+ | |||
+ | Likewise, the district will take steps to ensure that critical information is secure and is not inappropriately altered, deleted, destroyed or rendered inaccessible. Access to critical information will only be provided to authorized individuals in a manner that keeps the information secure. | ||
+ | |||
+ | All district staff, volunteers, contractors and agents who are granted access to critical and confidential information are required to keep the information secure and are prohibited from disclosing or assisting in the unauthorized disclosure of confidential information. All individuals using confidential and critical information will strictly observe protections put into place by the district including, but not limited to, maintaining information in locked rooms or drawers, limiting access to electronic files, updating and maintaining the confidentiality of password protections, | ||
+ | |||
+ | Using Online Services and Applications | ||
+ | |||
+ | District staff members are encouraged to research and utilize online services or applications to engage students and further the district' | ||
+ | |||
+ | Training | ||
+ | |||
+ | The ISO will provide appropriate training to employees who have access to confidential or critical information to prevent unauthorized disclosures or breaches in security. In accordance with law, all school employees will receive annual training in the confidentiality of student records. | ||
+ | |||
+ | Data Retention and Deletion | ||
+ | |||
+ | The ISO or designee shall establish a retention schedule for the regular archiving and deletion of data stored on district technology resources. The retention schedule must comply with the Public School District Records Retention Manual as well as the General Records Retention Manual published by the Missouri Secretary of State. | ||
+ | |||
+ | Litigation Hold | ||
+ | |||
+ | In the case of pending or threatened litigation, the district' | ||
+ | |||
+ | Consequences | ||
+ | |||
+ | Employees who fail to follow the law or district policies or procedures regarding data governance and security may be disciplined or terminated. Volunteers may be excluded from providing services to the district. The district will end business relationships with any contractor who fails to follow the law, district policies or procedures, or the confidentiality provisions of any contract. In addition, the district reserves the right to seek all other legal remedies, including criminal and civil action and seeking discipline of an employee' | ||
+ | |||
+ | The district may suspend all access to data or use of district technology resources pending an investigation. Violations may result in temporary, long-term or permanent suspension of user privileges. The district will cooperate with law enforcement in investigating any unlawful actions. The superintendent or designee has the authority to sign any criminal complaint on behalf of the district. | ||
+ | |||
+ | Any attempted violation of district policies, procedures or other rules will result in the same consequences, | ||
+ | |||
+ | |||
+ | |||
+ | |||
+ | |||
+ | |||
+ | |||
+ | |||
+ | |||
+ | |||
+ | |||
+ | |||
+ | |||
+ | Federal | ||
+ | |||
+ | 15 U.S.C. § 7001-7006 Electronic Signatures In Global And National Commerce Act | ||
+ | 15 U.S.C. §§ 6501-6506 The Children' | ||
+ | 20 U.S.C. § 1232g Family Educational Rights and Privacy Act | ||
+ | 20 U.S.C. § 1232h Protection of Pupil Rights Amendment | ||
+ | 20 U.S.C. § 1400-1417 Individuals with Disabilities Education Act | ||
+ | 20 U.S.C. § 7926 Elementary and Secondary Education Act | ||
+ | 29 C.F.R. § 1630.14 | ||
+ | |||
+ | BDC CLOSED MEETINGS, RECORDS AND VOTES | ||
+ | [[BDDL]] | ||
+ | |||
+ | [[BDDLAP1]] | ||
+ | |||
+ | [[policy: | ||
+ | |||
+ | DJF-1-AP(1) | ||
+ | |||
+ | [[GBEBC]] | ||
+ | |||
+ | GBEBC-AP(1) | ||
+ | |||
+ | [[GBL]] | ||
+ | |||
+ | [[GBLB]] | ||
+ | |||
+ | IGBA-1 | ||
+ | |||
+ | JHDA SURVEYING, | ||
+ | [[policy: | ||
+ | |||
+ | JO-1-AP(1) | ||
+ | |||
+ | JO-1-AP(2) STUDENT RECORDS - (Disclosure of Photographs, | ||
+ | KI PUBLIC SOLICITATIONS/ | ||
+ | ===== References ===== | ||
+ | |||
+ | ==== Cross References ==== | ||
+ | [[rsmo> | ||
+ | § 407.1500, RSMo | ||
+ | |||
+ | [[rsmo> | ||
+ | |||
+ | [[rsmo> | ||
+ | |||
+ | [[rsmo> | ||
+ | |||
+ | [[rsmo> | ||
+ | § 43.540, RSMo | ||
+ | |||
+ | ==== Missouri Revisor of Statutes ==== | ||
+ | ==== Missouri School Improvement Program ==== | ||
+ | ==== United States Code ==== | ||
+ | ==== Code of Federal Regulations ==== | ||
+ | ==== Court Cases ==== | ||