Are we undermining data breaches? Protecting education sector from data breaches
作者
Ram Govind Singh,D Naveenkumar
标识
DOI:10.1109/ic2e357697.2023.10262570
摘要
Compliance with data protection frameworks such as GDPR is a new necessity for a data fiduciary. Indian DPDPB-2022 (draft) is also one step towards this. Applying appropriate security and safeguard to data is an essential requisite in the framework and the absence of it may lead to a data breach. Currently, data breaches are happening and education sectors are being actively targeted along with other sectors. On regular basis, multiple incidents are announced under this category. This is possible due to more information being available to threat actors easily due to poor security infrastructures. The institutions are not able to determine the scope, consequences, and impact of data breaches and are not able to take corrective actions to revamp the security.In this paper, we have analyzed the latest data breaches as claimed by threat actors over public breach forums such as breached. We discuss common causes that may lead to breaches, challenges in their prevention, and issues in data breach handling (if an event happens). We analyzed the reasons why data breaches are indeed threatful to an educational institution and should not be undermined. Redesigning systems and infrastructure after considering data breach consequences is a new essential requisite to provide greater security assurance. We provide a detailed list of constituents that needs to be integrated to prevent data breaches. The descriptions show the necessity and efficacy of the constituents. Each method is equally important and provides a stronger level of compliance to prevent data breaches and minimize the impact of a data breach (if happens) to the organization.