Question

Difficulty: HardData Privacy and Compliance Regulations

A tier-2 IT support specialist at a regional educational institution is configuring a new administrative workstation for an employee in the registrar's office. The office handles student academic transcripts, federal student loan application records, and campus bookstore credit card payments. The specialist must ensure that access controls on the workstation comply with relevant privacy laws. Which of the following technical or administrative controls is specifically mandated by FERPA when managing access to student educational records on this system?

  1. Enforce strict role-based access controls to limit record access exclusively to school officials with a legitimate educational interest.Answer
  2. B
    Purge and shred storage media containing primary account numbers immediately after payment transaction settlement.
  3. C
    Configure automated auditing tools to report unauthorized record access incidents directly to the Department of Health and Human Services.
  4. D
    Implement automated user workflows allowing individuals to request the permanent erasure of their complete personal data history upon request.

Answer

Enforce strict role-based access controls to limit record access exclusively to school officials with a legitimate educational interest.
The Family Educational Rights and Privacy Act (FERPA) protects the privacy of student education records. It requires educational institutions to implement controls ensuring that non-directory information and transcripts are disclosed only to school officials who have been determined to have legitimate educational interests.

Step-by-Step Solution

1
Identify the target regulation and data type in the scenario.
The scenario focuses on student educational records (academic transcripts) handled by an educational institution, which falls under the scope of FERPA (Family Educational Rights and Privacy Act).
Different compliance frameworks apply to distinct data types such as PHI, PII, cardholder data, or student records.
2
Evaluate the technical and administrative requirements of FERPA.
FERPA requires educational agencies and institutions to protect the privacy of student education records and mandates that access be limited to individuals with a verified, legitimate educational interest.
Proper access management prevents unauthorized disclosure of student PII and academic history.
3
Differentiate FERPA requirements from other compliance frameworks mentioned in the distractor options.
Cardholder data management relates to PCI-DSS, health notification workflows relate to HIPAA, and data erasure rights relate to GDPR.
Selecting the correct compliance control requires distinguishing FERPA's scope from healthcare, payment card, and international data privacy regulations.

Key Concept

Regulatory Compliance Scopes (FERPA vs. PCI-DSS, HIPAA, and GDPR)
Estimated Time:1m 30s
Rate this question