The University of Utah's Independent Student Voice

The Daily Utah Chronicle

The University of Utah's Independent Student Voice

The Daily Utah Chronicle

The University of Utah's Independent Student Voice

The Daily Utah Chronicle

Write for Us
Want your voice to be heard? Submit a letter to the editor, send us an op-ed pitch or check out our open positions for the chance to be published by the Daily Utah Chronicle.
@TheChrony
Print Issues
Write for Us
Want your voice to be heard? Submit a letter to the editor, send us an op-ed pitch or check out our open positions for the chance to be published by the Daily Utah Chronicle.
@TheChrony

Students at risk for fraud

By Jeffrey Jenkins

Advances in Internet technology in the past several decades have been both amazing and precarious. With Internet access, you can purchase almost anything from thousands of online vendors, receive updates on news and market info with little delay, even schedule your next semester and pay tuition8212;all from the comfort of your couch. However, with these advances come more opportunities for dishonesty.

Key findings in a 2007 report from the Web Hacking Incidents Database highlight the criminality involved in Internet use. According to the report, 67 percent of all reported computer hackings were done with the intention to gain monetary profit. Also, 44 percent of the reported hackings were tied to non-commercial sites that include both government and university sites.

In recent years, the private sector has increased its spending on computer security to avoid losing data to hackers and to limit corporate espionage, leaving universities as easy targets. A report on Educational Security Incidents from 2007 reported there were 139 university security breaches around the world that year. This number increased 67.5 percent from 2006.

With these statistics in mind, the Utah Legislature enacted the Consumer Credit Protection Act in 2006. The CCPA defined what constitutes a security breach and laid out the protocol that public institutions such as the U are required to follow in the event of a security breach. A security breach is defined as “an unauthorized acquisition of computerized data maintained by a person that comprises the security, confidentiality or integrity of personal information.” The CCPA further articulates that a “reasonable and prompt” investigation is to occur, and “if an investigation reveals the misuse of personal information for identity theft or fraud purposes has occurred, or is reasonably likely to occur, the person shall provide notification to each affected Utah resident.”

The term “reasonably likely” leaves the decision as to whether or not individuals are going to be notified of a security breach to the investigators at theU ‘s Information Security Office. In light of the statistics that show the No. 1 reason for breaching a secure network is to gain profit, “reasonably likely” is at best a sub-par standard.
It has been several years since an announcement was officially made by the U that a breach of the U’s network has occurred. With the ambiguity of the CCPA, one can only assume there have been breaches that have not been fraudulent.

The ISO did not comment as to whether there have been breaches that were not made public.

An ambiguous law left to the interpretation of a U office with a reputation to protect does not adequately protect the financial interests of students. The ISO needs to always assume security breaches include fraudulent purposes or the old CCPA should be revised to protect the personal information of students.

[email protected]

Jeffrey Jenkins

Leave a Comment

Comments (0)

The Daily Utah Chronicle welcomes comments from our community. However, the Daily Utah Chronicle reserves the right to accept or deny user comments. A comment may be denied or removed if any of its content meets one or more of the following criteria: obscenity, profanity, racism, sexism, or hateful content; threats or encouragement of violent or illegal behavior; excessively long, off-topic or repetitive content; the use of threatening language or personal attacks against Chronicle members; posts violating copyright or trademark law; and advertisement or promotion of products, services, entities or individuals. Users who habitually post comments that must be removed may be blocked from commenting. In the case of duplicate or near-identical comments by the same user, only the first submission will be accepted. This includes comments posted across multiple articles. You can read more about our comment policy here.
All The Daily Utah Chronicle Picks Reader Picks Sort: Newest

Your email address will not be published. Required fields are marked *