public school governance and cyber security v 2

22
Public School Governance and Cyber Security: School Districts Provide Easy Targets for Cyber Thieves Michael A. Alao Salmon P. Chase College of Law Northern Kentucky University 1

Upload: michael-alao

Post on 16-Jan-2016

10 views

Category:

Documents


0 download

DESCRIPTION

2014 Student Scholarship ShowcaseThursday, February 27, 2014Noon - 1 p.m.Student Union, Room 104Highland Heights, KY To kick-start the 2014 Law Review Symposium, Law + Informatics Society hosted a Student Scholarship Showcase during which law review students presented their student notes on cyber defense strategies and responsibilities for business and industry. Some of the papers presented will be published in forthcoming issues of the Northern Kentucky Law Review. Lunch was provided by the Law + Informatics Institute.Public School Governance and Cyber Security: School Districts Provide Easy Targets for Cyber ThievesMr. Alao argued that current laws make school districts particularly vulnerable to cyber security threats, but that states can take meaningful steps toward improving cyber security for their school districts without waiting or relying on federal legislation.

TRANSCRIPT

Page 1: Public School Governance and Cyber Security v 2

1

Public School Governance and Cyber Security: School Districts Provide Easy Targets for Cyber Thieves

Michael A. AlaoSalmon P. Chase College of LawNorthern Kentucky University

Page 2: Public School Governance and Cyber Security v 2

2

Agenda

1. Who cares?

2. The law, school districts, and [lack of?] cyber security

3. How can states improve things?

Page 3: Public School Governance and Cyber Security v 2

3

Who cares?

Page 4: Public School Governance and Cyber Security v 2

4

Who cares?

Taxpayers

• $500 billion per year on K-12 public schools• FY 2012 -Ohio School Districts spent $18 billion• FY 2010 – Kentucky: $6.1 billion• Local Funding (e.g., property taxes)

Page 5: Public School Governance and Cyber Security v 2

5

Who cares?

Taxpayers

Source: National Center for Education Statistics

Page 6: Public School Governance and Cyber Security v 2

6

Who cares?

Criminals prefer vulnerable targets:

• Small businesses• Local governments• Public school districts

Page 7: Public School Governance and Cyber Security v 2

7

Current Laws

• What makes school districts vulnerable?

1. Regulations do not focus on cyber security

A. Responsibility for SD cyber securityB. Data breach notification lawsC. Liability for bank fraudD. Government auditing standards

Page 8: Public School Governance and Cyber Security v 2

8

Current Laws

• Who has responsibility for SD cyber security?

OH SDs must “take reasonable precautions to protect personal information . . . from unauthorized. . . use or disclosure.”

OHIO REV. CODE ANN. § 1347.05(G).

Page 9: Public School Governance and Cyber Security v 2

9

Current Laws• Who has responsibility for SD cyber security?

1. SD must “appoint one individual to be directly responsible for the system . . .”

2. SD must develop procedures to monitor system for accuracy, relevance, timeliness, and completeness.

OHIO REV. CODE ANN. § 1347.05(A), (F).

Page 10: Public School Governance and Cyber Security v 2

10

Current Laws

• Who has responsibility for SD cyber security?

1. SD must “appoint one individual to be directly responsible for the system . . .”

2. SD must develop procedures to monitor system for accuracy, relevance, timeliness, and completeness.

Ohio has 600+ school districts!

Page 11: Public School Governance and Cyber Security v 2

11

Current Laws

• Who has responsibility for SD cyber security?

Board of Education

Superintendent Treasurer

Page 12: Public School Governance and Cyber Security v 2

12

Current Laws

• What makes school districts vulnerable?

1. Regulations do not focus on cyber security

A. Responsibility for SD cyber securityB. Data breach notification lawsC. Liability for bank fraudD. Government auditing standards

Page 13: Public School Governance and Cyber Security v 2

13

Current Laws

• Data breach notification laws

Page 14: Public School Governance and Cyber Security v 2

14

Current Laws

• Data breach notification laws

– 695 breaches at educational institutions (FY’s 2005-13)• 11 million records of personal information

– 34 breach incidents at OH colleges and universities

– 6 breach incidents at OH SDs

Page 15: Public School Governance and Cyber Security v 2

15

Current Laws

• Data breach notification laws

– OH school districts must report breach incidents(unless exempted) within 45 days of discovery

– Some states exempt state agencies from breach notification laws

– KY does not have a breach notification law (as of July 1, 2013)

Page 16: Public School Governance and Cyber Security v 2

16

Current Laws

• Data breach notification laws

– OH school districts must report breach incidents(unless exempted) within 45 days of discovery

• Federal law may preempt state law (e.g., HIPAA)

Law of unintended consequences?

Page 17: Public School Governance and Cyber Security v 2

17

Current Laws

• Data breach notification laws

– Do not increase cyber security

– Increase public awareness

– Public can pressure School Boards

Page 18: Public School Governance and Cyber Security v 2

18

Current Laws

• What makes school districts vulnerable?

1. Regulations do not focus on cyber security

A. Responsibility for SD cyber securityB. Data breach notification lawsC. Liability for bank fraudD. Government auditing standards

Page 19: Public School Governance and Cyber Security v 2

19

Current Laws

• Liability for Bank Fraud

– EFTA protects individuals only

– Congressional bill to amend EFTA• Senator Charles Schumer (D-NY)• September 29, 2010

Page 20: Public School Governance and Cyber Security v 2

20

Current Laws

• What makes school districts vulnerable?

1. Regulations do not focus on cyber security

A. Responsibility for SD cyber securityB. Data breach notification lawsC. Liability for bank fraudD. Government auditing standards

Page 21: Public School Governance and Cyber Security v 2

21

Current Laws

• Government Auditing Standards

– Sarbanes-Oxley Act – not applicable

– Testing of IT General Controls – not required

Page 22: Public School Governance and Cyber Security v 2

22

What can states do?

• Don’t wait for Feds to fix things

1. Add testing of IT controls to annual audits

2. Use financial leverage to

(a) shift liability to banks, or

(b) make banks provide better security and training.