Cybersecurity Requirements in Education
FERPA expects reasonable security but specifies no particular controls; the GLBA Safeguards Rule applies to universities holding financial aid information as financial institutions; and state laws like California's SOPIPA and New York's Education Law 2-D (NIST-based) plus all-50-state breach-notification laws add requirements.
Under FERPA, schools must take reasonable security measures, but FERPA does not require specific security controls. Data breaches are not explicitly addressed but can lead to FERPA violations and Department of Education investigation.
The Department of Education has reminded universities holding financial aid information that they are covered by the Gramm-Leach-Bliley Act as financial institutions. The GLBA Safeguards Rule requires maintaining an information security program, conducting risk assessments, and selecting service providers that maintain appropriate safeguards. Schools are also encouraged to implement the NIST Framework.
| Law | Requirement |
|---|---|
| California SOPIPA | Edtech companies must ensure reasonable security measures for student data |
| New York Education Law 2-D | School districts must adopt cybersecurity policies adhering to the NIST Cybersecurity Framework |
| All 50 states | Have enacted data breach notification laws (check whether schools are covered) |