This is a short list of information-security-related terms.
authorized person: An authorized person is one whose individual DCCCD account/password authorizes access based on a business need to know; when in doubt, check with your supervisor.
confidential information: This information is private and requires protection with the highest levels of security, as prescribed by applicable laws, regulations and standards including, but not limited to PCI Data Security Standard, GLB, FERPA, HIPAA, USA PATRIOT Act and Texas Administrative Code, Information Security Standards for Higher Education. This information is available to District school officials on a need-to-know basis (based on applicable laws, regulations and standards).
event: An observable occurrence; an aspect of an investigation that can be documented, verified, and analyzed.
FERPA: Family Educational Rights and Privacy Act
GLB: Gramm-Leach Bliley
HIPAA: Health Insurance Portability and Accountability Act
incident: An adverse event or series of events that impact the privacy/security of the District, its customers, its public image and/or the ability of the District to do business.
information classification scheme: The classification level given to information — according to its use, sensitivity, and importance — that determines how information is to be handled and protected within DCCCD. The three Categories of information are as follows:
- Category I – Public Information
- Category II – Internal Information
- Category III – Confidential Information
|
internal information: This information is generally considered only for internal use by District school officials as needed for their job functions and is not disclosable to the public unless required by law.
IPSO: Information Privacy and Security Officer
IPSP: Information Privacy and Security Program
location ipsp incident response coordinator: The Vice President-level location employee and/or their designee responsible for coordinating the location’s response (in conjunction with the District IPS Incident Response Coordinator) to a privacy/security event or incident.
PCI: Payment Card Industry
personal identifiable information: Information that alone or in conjunction with other information identifies an individual.
school officials: Any employees, Trustees, or agents of the District, as well as attorneys, consultants, and independent contractors who are retained by the District. School officials have a "legitimate educational interest" in a student's record when they are working with the student; considering disciplinary or academic actions or the student's case; compiling statistical data; or investigating or evaluating programs.
USA PATRIOT Act: Uniting and Strengthening America by Providing Appropriate Tools Required to Intercept and Obstruct Terrorism