1 Post-Secondary Security and Confidentiality November 15, 2011 2:45 – 3:45 Dawn Ressel, KS Dr....

18
1 Post-Secondary Security and Confidentiality November 15, 2011 2:45 – 3:45 Dawn Ressel, KS Dr. Domenico "Mimmo" Parisi, MS Arron Frerichs, OR

Transcript of 1 Post-Secondary Security and Confidentiality November 15, 2011 2:45 – 3:45 Dawn Ressel, KS Dr....

Page 1: 1 Post-Secondary Security and Confidentiality November 15, 2011 2:45 – 3:45 Dawn Ressel, KS Dr. Domenico "Mimmo" Parisi, MS Arron Frerichs, OR.

1

Post-Secondary Security and Confidentiality

November 15, 20112:45 – 3:45

Dawn Ressel, KSDr. Domenico "Mimmo" Parisi, MS

Arron Frerichs, OR

Page 2: 1 Post-Secondary Security and Confidentiality November 15, 2011 2:45 – 3:45 Dawn Ressel, KS Dr. Domenico "Mimmo" Parisi, MS Arron Frerichs, OR.

2

Cross-Sector Data Sharing: PRE-SLDS

Sectors Kansas Mississippi OregonEarly Childhood In Progress with SLDS Grant No Connection No Connection

K 12Operational: Executive Order and

MOUOperational with:

Department of EducationMOU based data Share

between sectors

Community Colleges

Data Owner Operational with:All 15 Community and Junior CollegesState Board of Community and Junior Colleges

MOU based data Share between sectors

Public Universities

Data Owner Operational with:All 8 Public Universities

Data Owner

Private Colleges and universities

Place holder in SLDS Grant No Connection No Connection

Workforce and Labor

Postsecondary operational with limited connection. In progress ability to share K-12, Postsecondary, Labor.

Operational with:Department of Employment SecurityDepartment of Human ServicesDepartment of Rehabilitation ServicesDepartment of Corrections

University Limited Connection on Ad Hoc --- Community Colleges have MOU and Sharing Link

Other States Place holder in SLDS Grant (Missouri)

No Connection No Connection

Page 3: 1 Post-Secondary Security and Confidentiality November 15, 2011 2:45 – 3:45 Dawn Ressel, KS Dr. Domenico "Mimmo" Parisi, MS Arron Frerichs, OR.

3

Cross-Sector Data Sharing: CURRENT

Sectors Kansas Mississippi Oregon

Early Childhood

In Progress with SLDS Grant In Progress with: Department of HealthHead Start Association

Operational with:Department of Human ServicesDepartment of Education

In ProgressSLDS Governance Board

K 12 Operational: Executive Order and MOU

Operational with:Department of Education

In ProgressSLDS Governance Board

Community Colleges

Data Owner Operational with:All 15 Community and Junior CollegesState Board of Community and Junior Colleges

In ProgressSLDS Governance Board

Public Universities

Data Owner Operational with:All 8 Public Universities

In ProgressSLDS Governance Board

Private Colleges and universities

Place holder in SLDS Grant No Connection Place holder in SLDS

Page 4: 1 Post-Secondary Security and Confidentiality November 15, 2011 2:45 – 3:45 Dawn Ressel, KS Dr. Domenico "Mimmo" Parisi, MS Arron Frerichs, OR.

4

Cross-Sector Data Sharing: CURRENT (cont’d)

Sectors Kansas Mississippi Oregon

Workforce and Labor

Postsecondary operational with limited connection. In progress ability to share K-12, Postsecondary, Labor.

Operational with:Department of Employment SecurityDepartment of Human ServicesDepartment of Rehabilitation ServicesDepartment of Corrections

In Progress SLDS Governance Board-- problem with getting SSN to match K12 with Labor

Other States

Place holder in SLDS Grant (Missouri)

No Connection In Progress with SLDS -- WICHE supported pilot to share data with Hawaii, Idaho, Washington

Page 5: 1 Post-Secondary Security and Confidentiality November 15, 2011 2:45 – 3:45 Dawn Ressel, KS Dr. Domenico "Mimmo" Parisi, MS Arron Frerichs, OR.

5

Kansas Database - Postsecondary Lens

KBOR

KSDE

DOL

KSBNNSC

KS INSTKBOR

KSDE

DOL

MO

KSBNKDHE

NSC

KS INST

Planned DatabaseCurrent DatabaseP-20 DB

P-20 DB ??

Page 6: 1 Post-Secondary Security and Confidentiality November 15, 2011 2:45 – 3:45 Dawn Ressel, KS Dr. Domenico "Mimmo" Parisi, MS Arron Frerichs, OR.

6

Kansas – Security & Privacy Polices

Presently Who accesses the system and how?• Institutional access to unit level information – secure website file transfer to

institution data only. Approval to access granted by KBOR staff with institutional verification

• Agency Staff access to unit level information – secure website file transfer to all institutions. Approval to access granted by KBOR staff

• Other agency user access to unit level – currently not possible

Planned access to the system and how?• Institutional and Agency Staff access unchanged

• Access for other agencies – website file transfer. Approval to access granted by Data Review Committee

• De-indentified data is released pending demonstration of need

• Create a shared staff position between agencies to gain full access to datao KBOR and Commerce; KBOR and Department of Labor; KBOR and Kansas State

University

Page 7: 1 Post-Secondary Security and Confidentiality November 15, 2011 2:45 – 3:45 Dawn Ressel, KS Dr. Domenico "Mimmo" Parisi, MS Arron Frerichs, OR.

7

Kansas – Security & Privacy Polices

Documents that allow for access• K-12 sharing with KBOR; Executive Order followed by general MOU – completed

• Unique ID

• K-12, KBOR, and DOL sharing ; Executive Order followed by general MOU – in progress

• Board of Nursing and Department of Health; MOU for those agencies to search data for KBOR students – in progress

• Non-Public Higher Education institutions in Kansas (not-for-profit and for-profit) – in development; • For-profit; Regulatory responsibility and Statute

• Non-for-Profit; MOU

• Missouri; MOU – in development

Page 8: 1 Post-Secondary Security and Confidentiality November 15, 2011 2:45 – 3:45 Dawn Ressel, KS Dr. Domenico "Mimmo" Parisi, MS Arron Frerichs, OR.

8

Post-Secondary Security & Confidentiality: MS

Policies and Procedures

• Identifying a neutral 3rd party to be the data clearinghouse

D

H

A

C

G

F

B

E

Neutral 3rd Party

D

H

A

C

G

F

B

E

Page 9: 1 Post-Secondary Security and Confidentiality November 15, 2011 2:45 – 3:45 Dawn Ressel, KS Dr. Domenico "Mimmo" Parisi, MS Arron Frerichs, OR.

9

Post-Secondary Security & Confidentiality: MS

Policies and Procedures

Neutral 3rd party streamlines data sharing process

• Governance Board

• Governor’s Office, Agency Executive Level

• SLDS Data Council

• Programmatic Representatives, Technical Experts, End Users

• MOU from each Partner Agency

• Agency Maintains Data Ownership and Control over Data Use

• IRB certification and other regulatory compliance training for those working with sensitive data

Page 10: 1 Post-Secondary Security and Confidentiality November 15, 2011 2:45 – 3:45 Dawn Ressel, KS Dr. Domenico "Mimmo" Parisi, MS Arron Frerichs, OR.

10

Post-Secondary Security & Confidentiality: MS

How does Technology Help?

• Secure File Transfers

• De-Identify Data

• Remove Name, and other identifying information

• SSN replaced with unique 10-digit Identifier

• Software Package Monitors File/Database Access

• Limited access to Micro-data

• Cleanroom Approach for Research

Page 11: 1 Post-Secondary Security and Confidentiality November 15, 2011 2:45 – 3:45 Dawn Ressel, KS Dr. Domenico "Mimmo" Parisi, MS Arron Frerichs, OR.

11

Post-Secondary Security & Confidentiality: MS

Who Shares PK-20 Data in Mississippi?

•Mississippi Department of Education – (Operational)•Mississippi Department of Human Services –

(Operational)•Institutions of Higher Learning – (Operational)•State Board of Community and Junior Colleges –

(Operational)•Mississippi Department of Health – (In Progress)•Mississippi Head Start Association – (In Progress)•Mississippi Department of Mental Health – (In Progress)•Mississippi Division of Medicaid – (In Progress)

Page 12: 1 Post-Secondary Security and Confidentiality November 15, 2011 2:45 – 3:45 Dawn Ressel, KS Dr. Domenico "Mimmo" Parisi, MS Arron Frerichs, OR.

Walled GardenFour Named AnalystsExcellent history of sharing based on long term trust relationship directly

with analysts in other SectorsEach sector must approved research project accessEveryone else must get access through published public reports

12

Oregon University System PRE SLDS

Page 13: 1 Post-Secondary Security and Confidentiality November 15, 2011 2:45 – 3:45 Dawn Ressel, KS Dr. Domenico "Mimmo" Parisi, MS Arron Frerichs, OR.

Delegation of Authority,Authentication, and Authorization

Governance BoardAuthenticated Users are Authorized accessGovernance approved research project accessEveryone else must get access through published public reports

13

POST SLDS - Data System Access

Page 14: 1 Post-Secondary Security and Confidentiality November 15, 2011 2:45 – 3:45 Dawn Ressel, KS Dr. Domenico "Mimmo" Parisi, MS Arron Frerichs, OR.

14

Oregon Useful Links

• Oregon SLDS Project ALDER website: http://alder.orvsd.org/

• ALDER Data Governance: http://alder.orvsd.org/content/data-governance

• ALDER Timeline: http://alder.orvsd.org/content/slds-history

• ALDER USED: Site Visit: http://alder.orvsd.org/content/used-site-visit

• OUS Data Dictionary: http://www.ous.edu/dept/ir/scarf

• CCWD Data Dictionary: http://www.odccwd.state.or.us/OCCURS/

• ODE Data: http://www.ode.state.or.us/search/results/?id=349

• ODE DCC Website: https://district.ode.state.or.us/search/results/?id=402

• ODE ITMgrs Website: https://district.ode.state.or.us/search/results/?id=403

• ODE DQWG Website: http://data.k12partners.org/content/project-meetings

• ODE DWGC Website: http://alder.orvsd.org/content/data-warehouse-governance-committee

• AEC Website: http://alder.orvsd.org/content/alder-executive-committee

Page 15: 1 Post-Secondary Security and Confidentiality November 15, 2011 2:45 – 3:45 Dawn Ressel, KS Dr. Domenico "Mimmo" Parisi, MS Arron Frerichs, OR.

15

Page 16: 1 Post-Secondary Security and Confidentiality November 15, 2011 2:45 – 3:45 Dawn Ressel, KS Dr. Domenico "Mimmo" Parisi, MS Arron Frerichs, OR.

16

Page 17: 1 Post-Secondary Security and Confidentiality November 15, 2011 2:45 – 3:45 Dawn Ressel, KS Dr. Domenico "Mimmo" Parisi, MS Arron Frerichs, OR.

Oregon Early Grant app Draft

Enterprise Security

Identity Resolution

Data Management

OICA

ODE

OUS

PRISM(Labor)

CCWD Shared Repository

TSPC

*(given compliance with all laws)

Other States

Project includes collaboration on

integration

Vritual

OLAPData

ViewsDe-

identify

Reporting and BI Tools

Page 18: 1 Post-Secondary Security and Confidentiality November 15, 2011 2:45 – 3:45 Dawn Ressel, KS Dr. Domenico "Mimmo" Parisi, MS Arron Frerichs, OR.

Contact Info:Dawn Ressel, (785) 368-7464 [email protected] Parisi, (662) 325-8065 [email protected] Frerichs, (541) 346-5756 [email protected]

Resources:• Privacy Technical Assistance Center (PTAC):

http://nces.ed.gov/programs/PTAC/

18

Post-Secondary Security & Confidentiality:Contact Info and Resources