Educause Security Discussion mailing list archives

Re: FERPA and E-mailing grades


From: "Mclaughlin, Kevin (mclaugkl)" <mclaugkl () UCMAIL UC EDU>
Date: Fri, 6 Jan 2012 13:37:40 -0500

I think that the cornerstone of Dean's argument was that a contractual relationship existed between the entities (in 
particular he referenced Google - not Yahoo, hotmail, ACME mail, etc. )   without that contractual relationship (just 
my opinion here) I believe that it is prohibited under FERPA.

- Kevin


Kevin L. McLaughlin,  CISM, CISSP, GIAC-GSLC, CRISC, PMP, ITIL Master Certified
Assistant Vice President, Information Security & Special Projects
University of Cincinnati
513-556-9177

The University of Cincinnati is one of America's top public research institutions and the region's largest employer, 
with a student population of more than 41,000.

[cid:image001.gif@01CCCC78.7FFD99D0]

From: The EDUCAUSE Security Constituent Group Listserv [mailto:SECURITY () LISTSERV EDUCAUSE EDU] On Behalf Of Nathan 
Zierfuss
Sent: Friday, January 06, 2012 1:22 PM
To: SECURITY () LISTSERV EDUCAUSE EDU
Subject: Re: [SECURITY] FERPA and E-mailing grades

I have to agree with Dean. I'm not convinced FERPA prohibits providing students grades via email. In fact some CMSs can 
be configured to automatically email or text students their grades when the grade-book is updated. I use this feature 
and suspect most students do.

My experience has been our institution is struggling with not being the source of a digital identity for students that 
we used to be and coming to trust the one students have established for themselves prior to entering university. I 
believe FERPA requires us to validate who we are communicating with but not to secure the communications methods they 
elect.

Has anyone explored identity validation via credit report questions similar to what banks do when you open an account 
online and accepting gmail, yahoo, ect. as a students email address rather then issuing them a new one?

Nathan

On Fri, Jan 6, 2012 at 6:44 AM, Dean Halter <Dean.Halter () notes udayton edu<mailto:Dean.Halter () notes udayton edu>> 
wrote:
I agree that course management systems and ERPs are better ways of accessing/providing this information.  That said, 
I'm not sure that FERPA prohibits use of email to provide grade information.  Whether internal or contracted w/ a 
provider (Google, for example, is a "school official" per contract within Google Apps for Edu), I believe you should be 
able to use email as long as the solution is "secure."  Making sure faculty and staff address the information from and 
to university provided accounts is as important as the technical transport and storage.  Students, on the other hand, 
should be able to forward or share their mail if they choose.  Very interesting conversation and I appreciate 
everyone's insight.

Dean
___________
Dean Halter, CISA, CISSP
IT Risk Management Officer, UDit
University of Dayton

"Security is a process, not a product."  Bruce Schneier



--
Nathan Zierfuss, CISSP, Information Security Officer
-
Technology Oversight Services, University of Alaska
910 Yukon Dr. Suite 105, PO Box 755320
Fairbanks, Alaska 99775-5320
-
Phone: 907-450-8112  Fax: 907-450-8381


Current thread: