Category Archives: Compliance

Think Purposefully, Act Knowledgably

A recent tweet by Microsoft (MS) referenced a long-standing free file-hosting website the company supports called DOCS.COM.  File-hosting websites are provided by online vendors (such as MS and Google) as a place where individuals may post personal electronic files and documents, often for the purpose of making them available to the general public.

The post on Twitter linked to a page on Microsoft’s website which included this information:


What is Docs.com?
Docs.com is an online showroom where you can collect and publish Word documents, Excel workbooks, PowerPoint and Office Mix presentations, OneNote notebooks, PDF files, and Sways. With Docs.com, it’s easy for you to share with others what interests you, and your content looks great on any device. 

Can I use my Office 365 account with Docs.com?
Yes. You can use your work or school account to use Docs.com, or you can choose to use a personal Microsoft account — an email address and password that you use to sign in to services like Sway, Outlook.com, Skype, OneDrive, and Xbox Live. If you prefer, you can also sign in to Docs.com with a Facebook account.


As indicated in the article, it appears as though MS has recently extended the permissions to log into and use this website intended for the storage of personal  files to the credentials used by those schools using Office 365 (O365).  Because we are an O365 customer, this means it is possible to use your Bellevue College (BC) login to post documents to DOCS.COM.

This is not necessarily an issue for students who wish to use DOCS.COM for personal documents to supplement the online storage and electronic document sharing capabilities provided by the college through Microsoft’s OneDrive.

However, DOCS.COM is NOT, and I want to repeat this, NOT an authorized location for the storage of any electronic college documents by BC employees, despite the fact that you can access it with college credentials.  The use of the website has not been deemed compliant with FERPA and other campus information security requirements.

It is becoming an increasingly challenging issue in higher education that college employees with access to data and information protected by law (such as FERPA and HIPAA) are copying some of that information to personal file-hosting websites (such as DropBox, Box, DOCS.COM, etc.) without regard as to whether that cloud storage resource meets the information security requirements for the data.  Sadly, many people don’t even take the security of the data into consideration at all; they simply copy it anywhere that makes it more convenient to work with.

It is of utmost importance that each of us think purposefully and act knowledgably  when it comes to the information or data we work with on a daily basis.  Always protecting electronic information is of the highest priority.

The only authorized cloud repository of protected electronic Bellevue College data at the time of this writing is a college-provided OneDrive space or SharePoint Online file storage space (being rolled out soon!), unless a specific exception has been authorized through a Data Sharing Agreement (I’ll discuss these more at a later time).

Despite these services being sanctioned repositories, it is still critical that individual users of these authorized resources are cognizant of how they are sharing or providing access for others to the electronic files and data stored in them.

If you are not certain whether you can share electronic college information with someone, or whether you can store it somewhere, check with your supervisor.  If they are not certain, you or they can contact the Technology Service Desk for assistance, or let me know.

Safe Computing!

Beware Humans with Computers!

At a recent presentation to state risk managers in Olympia, representatives of the law firm BakerHostetler, which includes a number of attorney’s who specialize in resolving information security data breach issues, identified that cyber attacks using Phishing and Malware  was the cause of 31% of the more than 300 data security incidents the firm handled nationwide in 2015.  This is not much of a surprise given the recent increases in the number of these types of attacks.

The second highest category identified at 24% was Employee Action/Mistake, which includes failures of employees to follow organizational policies resulting in a data breach.

Interestingly, the next highest causes of data losses include other categories which also have significant ties to how authorized users interact with information technology and the data stored and manipulated with that technology.  These include: Loss or Theft of a Device (17%); Vendor/ Contractor Actions (14%); Internal Employee Theft (8%); and Lost or Improperly Disposed Data (6%).

These statistics show that the human component of data protection is significantly more important with regard to modern IT security issues than is the technology component.

The underlying source of ALL of these top kinds (92%) of data breaches can easily be attributed to the authorized users of the compromised data and either a deliberate disregard for organizational policies or a lack of information security awareness on their part.

Clearly, it is important for each of us to understand that we each need to constantly protect the college data we access during the course of our daily work, and to ask questions of our supervisors when we are not certain how best to do that.

The college has published a number of policies and procedures related to technology use by college employees and the protection of college data.  Here are links to a few of those current documents:

Take some time this week to update yourself on the information in these important documents and, as always:  Safe Computing!