A tier-2 IT support specialist at a regional educational institution is configuring a new administrative workstation for an employee in the registrar's office. The office handles student academic transcripts, federal student loan application records, and campus bookstore credit card payments. The specialist must ensure that access controls on the workstation comply with relevant privacy laws. Which of the following technical or administrative controls is specifically mandated by FERPA when managing access to student educational records on this system?
- Enforce strict role-based access controls to limit record access exclusively to school officials with a legitimate educational interest.Cevap
- BPurge and shred storage media containing primary account numbers immediately after payment transaction settlement.
- CConfigure automated auditing tools to report unauthorized record access incidents directly to the Department of Health and Human Services.
- DImplement automated user workflows allowing individuals to request the permanent erasure of their complete personal data history upon request.
Cevap
Enforce strict role-based access controls to limit record access exclusively to school officials with a legitimate educational interest.
The Family Educational Rights and Privacy Act (FERPA) protects the privacy of student education records. It requires educational institutions to implement controls ensuring that non-directory information and transcripts are disclosed only to school officials who have been determined to have legitimate educational interests.
Adım Adım Çözüm
Anahtar Kavram
Regulatory Compliance Scopes (FERPA vs. PCI-DSS, HIPAA, and GDPR)
Tahmini Süre:1m 30s