(IJCSIS) International Journal of Computer Science and Information Security,Vol. 10, No. 2, February 2012
discussed. Finally, several recommendations and conclusionsare provided.II.
M
ISSION
S
TATEMENT
,
T
ECHNOLOGY
,
AND
P
RIVACY
I
SSUES AT
UTC-TIn order to illustrate the importance of privacy and the roleof information technology to support the university’s strategicgoals, the mission statement of UTC-T is offered below:
The mission of the university is to provide qualityeducational programs that produce academically-prepared and business-world ready men and women for acompetitive global environment. The colleges of theuniversity provide high quality educational programs that prepare online and traditional students for managerial, professional, or entrepreneurial opportunities.
This mission statement indicates the importance of technology to support the strategic goals of UTC-T. Thesegoals include fostering multidisciplinary programs andinnovative curriculum design and delivery, increasing globalperspectives and providing international opportunities forstudents and faculty, and supporting research andprofessionally engaged faculty. It is implied that technologycan also be used to strengthen financial and programsustainability, engage, challenge and support students, andbuild strong relationships with key stakeholders.The dependence on technology becomes a source of potential violation of privacy laws and regulations. UTC-Tmust protect its students, faculty, and other employees fromcybercrime in general and must ensure their privacy inparticular. In order to achieve this goal, UTC-T must complywith federal, state, and organizational regulations.
III.
M
ISSION
S
TATEMENT
,
T
ECHNOLOGY
,
AND
P
RIVACY
I
SSUES AT
UMUC-OLUMUC has a clear mission statement. In order to illustratethe importance of privacy and the role of informationtechnology to support the university’s strategic goals, themission statement of the university which is directly related toUMUC-OL is summarized below:
UMUC provides programs for part-time, adult students at off-campus sites on an as-needed basis. Its brokering functions include assessing needs, monitoring the scope of off-campus offerings, and coordinating System resourcesto address off-campus needs. UMUC conducts postsecondary degree and non-degree programsthroughout the nation and the world.
In order to reach large numbers of students throughout theworld, UMUC-OL offers several online services: course andprogram offerings, online library resources, online registrationservices, online financial transactions, and online advising.UMUC-OL makes every effort to protect the privacy of itsstudents, faculty, and staff. Pertinent to privacy concerns isthe requirement that the university must release specificinformation to law enforcement agencies according to ForeignIntelligence Surveillance Act, 50 U.S.C. 1861, as amended bythe USA PATRIOT Act.IV.
M
ISSION
S
TATEMENT
,
T
ECHNOLOGY
,
AND
P
RIVACY
I
SSUES AT
UTC-OLUTC-OL is an integral component of UTC, and, as aresult, UTC’s mission statement is similar to the futurestatement of UTC-OL. Similarly to UMUC-OL, UTC-OLmust strive to reach a large number of students, locally,regionally, and worldwide. As such, privacy concerns of UTC-OL are similar to those of UMUC-OL. Such concernsare raised due to potential violations of privacy as a result of information storage and communications in course deliverysystems, online library resources, online registration services,online financial transactions, and online advising. Also, UTC-OL must make every effort to protect the privacy of students,faculty, and staff following federal, state, and local privacylaws.V.
FERPA
AND
O
THER
P
RIVACY
L
AWS AT
I
NSTITUTIONSOF
H
IGHER
E
DUCATION
Traditional and online education must comply with the fairinformation practices (FIP), which provide students and facultywith control over the disclosure and use of personalinformation. FIP also states organizational obligations for dataprotection. As a result, FIP provides the basis for both privacylaws and self-regulatory programs. Regulations related tohigher education include FERPA, the Health InsurancePortability and Accountability Act (HIPAA), and the Gramm-Leach-Bliley (GLP) Act.The main regulatory requirement related to cyber crime atan institution of higher education is the Family EducationalRights and Privacy Act (FERPA). FERPA is a federal law thatapplies to all schools that receive funds under an applicableprogram of the U.S. Department of Education. In order toprotect the privacy of students and their records, the universityand its colleges must follow FERPA requirements as applied tothe college:
•
Parents have certain rights when children are less than18 years old. Since college students are typically overthis age, the college must recognize that parents havetransferred these rights to the "eligible students."
•
At a college level, students have the right to inspect,and, if needed, correct their education records.Students have the right to a formal hearing if theschool does not correct the records.
•
The college must have written permission from theeligible student in order to release any informationfrom a student's education record.
•
The college may disclose, without consent,information such as a student's name, address,telephone number, date and place of birth, honors andawards, and dates of attendance. However, schools
7http://sites.google.com/site/ijcsis/ISSN 1947-5500