Cybersecurity Requirements in Education
Last reviewed:
FERPA expects reasonable security but specifies no particular controls; the GLBA Safeguards Rule applies to universities holding financial aid information as financial institutions; and state laws like California's SOPIPA and New York's Education Law 2-D (NIST-based) plus all-50-state breach-notification laws add requirements.
Under FERPA, schools must take reasonable security measures, but FERPA does not require specific security controls. Data breaches are not explicitly addressed but can lead to FERPA violations and Department of Education investigation.
The Department of Education has reminded universities holding financial aid information that they are covered by the Gramm-Leach-Bliley Act as financial institutions. The GLBA Safeguards Rule requires maintaining an information security program, conducting risk assessments, and selecting service providers that maintain appropriate safeguards. Schools are also encouraged to implement the NIST Framework.
| Law | Requirement |
|---|---|
| California SOPIPA | Edtech companies must ensure reasonable security measures for student data |
| New York Education Law 2-D | School districts must adopt cybersecurity policies adhering to the NIST Cybersecurity Framework |
| All 50 states | Have enacted data breach notification laws (check whether schools are covered) |
Key terms - quick answers
What is “GLBA Safeguards Rule”?
What is “NIST Framework”?
Keep going - free
Every study note on this site is free. So are these: