Educause Security Discussion mailing list archives

Re: Standard operations question


From: "SPolsky@PACC" <spolsky () PACC-CCAP CA>
Date: Thu, 21 Feb 2019 09:23:34 -0700

Julian, Asking who is "responsible for the account" is, IMHO, a bit ambiguous — and not necessarily the same thing as 
being responsible for the collection, use, processing, and disclosure of personal information done within that account.

A fundamental tenet of data protection and privacy laws is that the entity that collects the information is responsible 
for controlling and securing the information. So even though the department has contracted with an external party 
(presumably with a written contract, and one that addresses data responsibility, liability, and repatriation), 
Northwestern remains responsible for the information. If someone at the third party misuses or inappropriately 
discloses the information, affected individuals would look to Northwestern.

Similarly, managing the account, and granting access, must be controlled by Northwestern; otherwise, it enables the 
third party service provider to have control and grant access to information that Northwestern is responsible to 
safeguard. 

Allowing the tail to wag the dog isn’t often a good strategy.

HTH.

Sharon Polsky BIS MAPP
President & CEO — AMINAcorp.ca <http://aminacorp.ca/> — @AMINAcorp <https://twitter.com/AMINAcorp> 
President — Privacy and Access Council of Canada <http://pacc-ccap.ca/>— @PACC-CCAP <https://twitter.com/PACC_CCAP>
Member, Standards Council of Canada 
<scc.cahttp://www.scc.ca/en/news-events/news/2018/iso-standard-will-help-protect-consumer-privacy-online-0> GDPR 
Advisory Committee —  @StandardsCanada  <https://twitter.com/StandardsCanada>‏       
PbD — Privacy By Design Ambassador 
<http://web.archive.org/web/20121012080217/http://privacybydesign.ca/ambassadors/individuals/page/7/>

On 02 Feb 2019, at 8:41 AM, Frank Barton <bartonf () HUSSON EDU> wrote:

I would agree that the service owner should be responsible for the account, however, in the spirit of 
'checks-and-balances', i would suggest that the datacenter team routinely 'audit' the account, and the continued need 
for the account with the owning team

On Thu, Feb 21, 2019 at 10:37 AM Julian Y Koh <kohster () northwestern edu <mailto:kohster () northwestern edu>> 
wrote:
On Feb 21, 2019, at 09:21, Jared Evans <jared.evans () GALLAUDET EDU <mailto:jared.evans () GALLAUDET EDU>> wrote:

A department has gone with a service provided by an external party and has a support contract with them.  This 
support service necessitates a VPN account along with an user account (along with appropriate access control placed 
upon it).  While we have created and filed the documentation for this account, who is ultimately responsible for 
this account going forward?  

The system owner of the service who has set the justification for the existence of the account or the datacenter 
team which maintains our accounts?



IMO the service owner should be responsible for the account.

-- 
Julian Y. Koh
Associate Director, Telecommunications and Network Services
Northwestern Information Technology

2020 Ridge Avenue #331
Evanston, IL 60208
+1-847-467-5780
Northwestern IT Web Site: <http://www.it.northwestern.edu/ <http://www.it.northwestern.edu/>>
PGP Public Key: <https://bt.ittns.northwestern.edu/julian/pgppubkey.html 
<https://bt.ittns.northwestern.edu/julian/pgppubkey.html>>



-- 
Frank Barton, MBA
Security+, ACMT, MCP
IT Systems Administrator
Husson University


Current thread: