board_policy:ehbcap1
Differences
This shows you the differences between two versions of the page.
Both sides previous revisionPrevious revisionNext revision | Previous revision | ||
board_policy:ehbcap1 [Monday, November 20, 2023 12:41 AM] – removed - external edit (Unknown date) 127.0.0.1 | board_policy:ehbcap1 [Monday, November 20, 2023 12:42 AM] (current) – ↷ Links adapted because of a move operation Nathan C. McGuire | ||
---|---|---|---|
Line 1: | Line 1: | ||
+ | <WRAP right 300px> | ||
+ | | Status | ||
+ | | Original Adopted Date | 09/ | ||
+ | | Last Revised Date | | | ||
+ | | Last Reviewed Date | 09/ | ||
+ | </ | ||
+ | ====== Procedure EHBC-AP(1): Data Governance and Security - (Incident and Data Breach Response Plan) ====== | ||
+ | |||
+ | The goal of the district is to eliminate security incidents and avoid any breach of district data. For that reason, all district employees and agents are required to immediately report to the information security officer (ISO) or designee when they know or suspect that a security incident or data breach has occurred. The superintendent, | ||
+ | |||
+ | Definitions | ||
+ | |||
+ | Data Breach, Breach of Security or Breach – A security incident in which there was unauthorized access to and unauthorized acquisition of personal information maintained in computerized form that compromises the security, confidentiality or integrity of the information. A breach includes, but is not limited to, incidents in which confidential or critical data has potentially been accessed without authorization or stolen; confidential or critical data has been compromised; | ||
+ | |||
+ | Personal Information – An individual' | ||
+ | |||
+ | 1. | ||
+ | |||
+ | 2. | ||
+ | |||
+ | 3. | ||
+ | |||
+ | 4. | ||
+ | |||
+ | 5. Any information regarding an individual' | ||
+ | |||
+ | 6. An individual' | ||
+ | |||
+ | Personal information does not include information that is encrypted, redacted or altered in such a manner that the name or data elements are unreadable or unusable. It also does not include information that is lawfully obtained from publicly available sources or from government records made available to the general public. | ||
+ | |||
+ | Security Incident – An event that 1) actually or potentially jeopardizes the confidentiality, | ||
+ | |||
+ | Incident Response | ||
+ | |||
+ | Once notified of an event, the ISO or designee will identify and remedy the weakness that allowed the security incident to occur, repair any damage that has been done, minimize risk associated with the event, and determine who caused the incident. If the incident was intentional or occurred because a user violated district policies, procedures or training, the individual will be referred to the superintendent or designee for discipline and/or other consequences. | ||
+ | |||
+ | Data Breach | ||
+ | |||
+ | The district' | ||
+ | |||
+ | The ISO or designee will investigate the incident immediately and make a determination as to whether a breach did occur. If a breach did occur, the following steps will be taken as quickly as possible: | ||
+ | |||
+ | 1. The superintendent and other appropriate administrative staff will be notified immediately. The superintendent or designee will contact the district' | ||
+ | |||
+ | 2. The ISO will determine the status of the breach and will take all appropriate measures to prevent additional loss of data and future breaches. | ||
+ | |||
+ | 3. If possible, the ISO will preserve any and all evidence of the breach for future investigation, | ||
+ | |||
+ | 4. The ISO will determine the scope of the breach and will work with law enforcement (when appropriate), | ||
+ | |||
+ | 5. Once the district' | ||
+ | |||
+ | Notice of Breach of Personal Information | ||
+ | |||
+ | Breaches of confidential personal information are particularly problematic, | ||
+ | |||
+ | If the superintendent or designee, after an appropriate investigation or consultation with the relevant federal, state or local agencies responsible for law enforcement, | ||
+ | |||
+ | This notice may be delayed if a law enforcement agency informs the superintendent or designee that notification may impede a criminal investigation or jeopardize national or homeland security, provided that such request by law enforcement is made in writing or the superintendent or designee documents such request contemporaneously in writing, including the name of the law enforcement officer making the request and the officer' | ||
+ | |||
+ | If the district must provide notice to more than 1,000 individuals, | ||
+ | |||
+ | Student Personal Information | ||
+ | |||
+ | In addition to the requirements above, if there is a breach of data maintained in electronic form that includes personal information about a student, the district shall send written notification to the student' | ||
+ | |||
+ | Notice Content | ||
+ | |||
+ | The notice provided to persons whose information was breached shall minimally include: | ||
+ | |||
+ | 1. A description of the incident in general terms. | ||
+ | |||
+ | 2. A description of the type of personal information that was obtained as a result of the breach of security. | ||
+ | |||
+ | 3. A telephone number that affected consumers may call for further information and assistance, if one exists. | ||
+ | |||
+ | 4. | ||
+ | |||
+ | 5. | ||
+ | |||
+ | The notice may be made in writing or by e-mail if the person has agreed to receive communications from the district electronically in accordance with federal law. Telephone notice may be used if contact is made directly with the affected person. | ||
+ | |||
+ | Substitute notice may be used if the cost of providing notice would exceed $100,000 or if the district needs to notify more than 150,000 individuals. The district may also use substitute notice for individuals the district is unable to identify or for whom the district does not have sufficient contact information, | ||
+ | |||
+ | Substitute notice shall include: | ||
+ | |||
+ | 1. | ||
+ | |||
+ | 2. | ||
+ | |||
+ | 3. | ||
+ | |||
+ | Note: The reader is encouraged to review policies and/or forms for related information in this administrative area. | ||
+ | |||
+ | |||
+ | |||
+ | |||
+ | |||
+ | |||
+ | |||
+ | |||
+ | |||
+ | |||
+ | |||
+ | |||
+ | |||
+ | Federal | ||
+ | |||
+ | 15 U.S.C. § 7001-7006 Electronic Signatures In Global And National Commerce Act | ||
+ | 15 U.S.C. §§ 6501-6506 The Children' | ||
+ | 20 U.S.C. § 1232g Family Educational Rights and Privacy Act | ||
+ | 20 U.S.C. § 1232h Protection of Pupil Rights Amendment | ||
+ | 20 U.S.C. § 1400-1417 Individuals with Disabilities Education Act | ||
+ | 20 U.S.C. § 7926 Elementary and Secondary Education Act | ||
+ | 29 C.F.R. § 1630.14 | ||
+ | |||
+ | BDC CLOSED MEETINGS, RECORDS AND VOTES | ||
+ | [[BDDL]] | ||
+ | |||
+ | [[BDDLAP1]] | ||
+ | |||
+ | [[policy: | ||
+ | |||
+ | DJF-1-AP(1) | ||
+ | |||
+ | [[GBEBC]] | ||
+ | |||
+ | GBEBC-AP(1) | ||
+ | |||
+ | [[GBL]] | ||
+ | |||
+ | [[GBLB]] | ||
+ | |||
+ | IGBA-1 | ||
+ | |||
+ | JHDA SURVEYING, | ||
+ | [[policy: | ||
+ | |||
+ | JO-1-AP(1) | ||
+ | |||
+ | JO-1-AP(2) STUDENT RECORDS - (Disclosure of Photographs, | ||
+ | KI PUBLIC SOLICITATIONS/ | ||
+ | ===== References ===== | ||
+ | |||
+ | ==== Cross References ==== | ||
+ | [[rsmo> | ||
+ | § 407.1500, RSMo | ||
+ | |||
+ | [[rsmo> | ||
+ | |||
+ | [[rsmo> | ||
+ | |||
+ | [[rsmo> | ||
+ | |||
+ | [[rsmo> | ||
+ | § 43.540, RSMo | ||
+ | |||
+ | ==== Missouri Revisor of Statutes ==== | ||
+ | ==== Missouri School Improvement Program ==== | ||
+ | ==== United States Code ==== | ||
+ | ==== Code of Federal Regulations ==== | ||
+ | ==== Court Cases ==== | ||