Same principles. Different consequences.
These synthetic U.S. examples distinguish K–12 student records from university research; FERPA coverage depends on Department of Education funding, and CISA recommendations are guidance.
Openness has a purpose
Teaching and research often depend on sharing, guest participation, and experimentation. Applying the same restriction everywhere can obstruct learning, while treating all campus information as public exposes people. Separate approved public materials from identifiable records and restricted research before choosing controls.
Roles change throughout the year
Students graduate, staff change assignments, and visiting researchers arrive for short projects. Accounts, groups, devices, and vendor connections can outlive those relationships. Identity reviews should follow the academic calendar and preserve necessary records without preserving unnecessary access.
An outage affects people differently
A registration deadline, an examination, and an ordinary teaching day create different restoration priorities. Schools and universities need recovery decisions that account for students who cannot use an alternative channel, while maintaining access controls during hurried service restoration.
How to use this path
Read each situation, inspect the synthetic evidence, and choose a response. Every answer explains its tradeoffs. Follow the linked foundation lessons when you need a concept explained, then mark the decision practiced when you are ready.
All organizations, people, events, and evidence in these exercises are fictional. The controls stay in the browser.
APPLIED LESSON 1 / 8 MIN
Separate student records from open research
Choose a sharing boundary that preserves useful collaboration.
A fictional university team prepares a public research workshop using a shared folder. It contains published teaching slides, a draft research dataset, and a spreadsheet connecting student names to assessment results. The invitation requests access for everyone attending. These materials have different purposes and owners. A shared project label does not make every file suitable for the same audience, even when openness is central to the event.
The team identifies which materials have approval for public release and moves them to a separate publication location. The records owner reviews student information and the research lead confirms the dataset’s release conditions. Removing visible names alone may leave identifiers or combinations that reveal individuals. Participants receive the minimum approved materials needed for the workshop, while restricted collaboration continues through named access with an owner and review date.
What should the workshop organizer publish?
CONNECT TO THE FUNDAMENTALS
APPLIED LESSON 2 / 8 MIN
Review identities when educational roles change
Reconcile people, delegated access, and vendor data needs.
In a fictional school district, a teaching assistant changes schools while a learning platform begins a new term. The assistant’s old class groups remain active, and the platform requests a complete student export to refresh its rosters. Both requests concern identity lifecycle, but they need different decisions. A valid staff account does not establish a continuing need to read previous classes, and a vendor relationship does not justify every field.
An authorized administrator compares current assignments with group memberships and records the removal of access that no longer serves the role. The platform owner checks the agreed service purpose and required roster fields before approving a transfer through the established channel. Retaining official educational records is a separate decision from retaining user permissions. Vendor accounts and integrations need owners, review dates, and a process for ending access when the service changes.
Which response best addresses the two access questions?
CONNECT TO THE FUNDAMENTALS
APPLIED LESSON 3 / 8 MIN
Restore a student service around its deadline
Plan recovery that preserves both access and accurate records.
A fictional college’s registration service becomes unavailable on the final afternoon of course selection. A backup can restore the morning’s records, but several students received confirmation messages later in the day. Restoring that backup without reconciliation could erase valid choices. The service owner must consider the academic deadline, the uncertain transactions, and the needs of students who cannot easily return to campus or use another channel.
The recovery team identifies the trusted checkpoint and preserves available registration confirmations and audit records. An approved temporary process gives students a way to record requests without placing personal information in a public document. Staff reconcile those requests and uncertain transactions before declaring recovery complete. A rehearsal should test the temporary process, communication channels, and ownership of exceptions, rather than measuring success only by whether the website loads.
What is needed before declaring the registration service recovered?
CONNECT TO THE FUNDAMENTALS
Standards & scope
These are signposts for further study. The examples use U.S. regulatory context where noted; applicability depends on your organization, jurisdiction, services, and data.
FERPA coverage ↗
U.S. FERPA applies to educational agencies and institutions receiving funds under programs administered by the Department of Education; it does not automatically cover every private school or research dataset.
CISA Protecting Our Future: K–12 cybersecurity ↗
Recommendations help K–12 organizations prioritize security, recovery, and collaboration; following the report is not a FERPA certification.