1. Grant Least-Privilege Access
Start with the most restrictive permissions. Loosen them only when there is a clear need. “Once you’ve given them access, it becomes difficult to justify why you’re pulling that back. You can’t put the toothpaste back in the tube,” says Jenn Judkins, technology director at Wayland Public Schools in Massachusetts.
2. Limit The Data You Collect
Collect only the data you need and delete it when you’re done. Don’t collect data that has no clear purpose, says Melissa Tebbenkamp, technology director for CoSN. Start with enrollment, where unnecessary data accumulates. Delete residency documents such as bills once they are no longer required. Don’t collect Social Security numbers unless there’s a specific need. “You don’t have to protect what you don’t collect,” Judkins says.
3. Separate Administrative Accounts From Daily-Use Accounts
Staffers who have administrative access should have two accounts: one for administrative needs and one for daily use. That way, if a daily-use account is compromised, the attack surface is limited, Tebbenkamp says.
4. Don’t Give Unlimited Access, Especially for Temporary Employees
Grant access only for as long as it’s needed. If employees need system access for a limited time, such as a teacher who assists with student scheduling for six weeks each year, grant it for that time frame only, and set a calendar reminder to revoke access when the work is done, Judkins says.
5. Review Data Before It Goes to the State
Have data stewards review state reports before submission. The director of the English learner program will catch errors that IT never would. "They’re the ones that would have the ability, more than we would, to say, ‘Wait a minute, that can’t be right,’” Judkins says.
6. Check for Access Creep
When staffers change roles, old permissions often don’t get removed. Review access at least annually to ensure employees aren’t carrying permissions from previous positions. “Once a year, are you going in and checking?” says Karen Winsper of Norton Public Schools.
