Close

A Call To Action for Education Technology Stakeholders

The time has come for all stakeholders to unite and tackle the pressing security challenges in the Educational Technology (EdTech) sector. Data breaches are escalating in both frequency and severity, leaving student information vulnerable. A lack of coordination across the marketplace, driven by inconsistent controls and fragmented legal requirements, has only exacerbated the problem. However, there is hope. Through collaboration and a shared commitment to securing the educational ecosystem, we can create a safer environment for all EdTech products and services. Adopting and consistently adhering to standardized controls is essential. Many recent data breaches may have been avoided entirely if these measures had been in place.

Access 4 Learning (A4L), through the Student Data Privacy Consortium (SDPC), has a proven track record of facilitating the collaborative work required across the EdTech ecosystem. The SDPC’s development of and implementation of the National Data Privacy Agreement (NDPA), in use in over 6000 US districts addressing over 12,000 applications, is evidence of the potential of a Community driven effort to make a difference. I believe we can build upon this success and leverage the Community to address the increasing security issues.

In such an effort to address the lack of common expectations around security controls in EdTech products, the SDPC developed the Global Education Security Standard (GESS). GESS is not a new set of controls, but rather a matrix, or crosswalk of existing security controls in cybersecurity frameworks that are appropriate and required for EdTech products. These are intended to be a single set of controls to be adopted across the ecosystem, meeting any jurisdictional requirements that may exist across all US States, the UK, Australia and New Zealand. At their core are the principles of ‘Privacy by Design’, ’Privacy by Default’, ‘Security by Design’ and ‘Security by Default’. If these controls had been adopted and adhered to by EdTech providers many of the recent data breaches may have been avoided.

I believe we all want the same thing; a secure and effective EdTech ecosystem for learners. The only way to accomplish this is to work together with a common goal. It is not easy work, but as the SDPC’s success with the NDPA illustrates, it is possible. Thus, I’m calling for everyone associated with the EdTech ecosystem to join us in continuing to develop, adopt, build awareness of and create a certification program for GESS. Schools, districts, state educational agencies, education service agencies, and marketplace providers are all encouraged to join in this effort. Together we can create a secure learning environment for all learners.

For more information on joining the Community and contributing to GESS please visit A4L or contact staff@a4l.org

Steve Smith

Executive Director

Access 4 Learning Community