Consortium of Cybersecurity Clinics
  • About
    • Consortium History
    • Our Funders
    • Meet the Team
  • Members
  • Resources
  • Newsroom
    • In the News
    • Blog
  • Contact
    • Contact Us
    • Consortium FAQs
  • Support
  • About
    • Consortium History
    • Our Funders
    • Meet the Team
  • Members
  • Resources
  • Newsroom
    • In the News
    • Blog
  • Contact
    • Contact Us
    • Consortium FAQs
  • Support

Welcoming new members & data policies for clinics

Month: February 2022

Welcoming new members & data policies for clinics

By Ann Cleaveland | February 28, 2022June 22, 2023

Our February gathering was our largest yet. We were thrilled to welcome faculty and staff to our discussions from cybersecurity programs at the University of Washington, Cleveland State, Clemson University, and the Universidad Católica del Perú (expanding our international membership). We were able to connect with many of our newer participants through joint engagement with the Public Interest Technology University Network.
 
 This month’s discussion centered on a best-practice sharing conversation about policies and technical infrastructure that protect the privacy and security of both clients and students during a clinic engagement. Each clinic needs to have an instructor, teaching assistant, or other staff person who is responsible for OpSec. Depending on the risk of the clinic’s target client demographic, individual clinics will elect different technical infrastructure and policies to protect student and client anonymity – for example, using VPNs, providing students with dedicated laptops and phones for client engagement, anonymizing client identities in class projects and written materials, among other measures. For managing data and communication risks between clients and clinics, Consortium members have been developing a framework that prompts new clinics to decide on policies and practices that address: Confidential data sharing, Access controls, Data protection (at rest, in use, and in transit), and Endpoint protection. Just a few examples of the questions that clinics need to solve before they launch include: What are the procedures for how faculty and students handle sensitive client data? What level of encryption is needed? How will the work product and final report from the clinic to client be stored and used by the school? Under what circumstances, and how, should client data be anonymized during and after an engagement?
 
Reach out to us at info@cybersecurityclinics.org to join the conversation!

Recent Posts

  • Event Recap: Spring 2025 “Clinic of Clinics”
  • Arizona High Schools to Launch Cybersecurity Clinics
  • The Feds Need to Step Up on Cybersecurity
  • West Virginia State University Celebrates Opening of Cybersecurity Clinic
  • SBA-Backed NJRIC Offering Free Accelerator Program and Cyber Risk Assessments

Recent Comments

No comments to show.

Archives

  • May 2025
  • March 2025
  • February 2025
  • January 2025
  • December 2024
  • November 2024
  • October 2024
  • July 2024
  • June 2024
  • May 2024
  • April 2024
  • March 2024
  • February 2024
  • January 2024
  • November 2023
  • October 2023
  • July 2023
  • June 2023
  • May 2023
  • March 2023
  • October 2022
  • September 2022
  • August 2022
  • May 2022
  • March 2022
  • February 2022
  • January 2022
  • November 2021
  • August 2020
  • July 2019

Categories

  • Consortium Blog
  • Featured
  • In The News
  • Uncategorized

Donate to the Consortium

Help build and expand university-based cybersecurity clinics.
Make a Gift Today

Subscribe to the Consortium

    Consortium of Cybersecurity Clinics
    • About
    • Resources
    • Newsroom
    • Contact
    • Support

    © 2025 The Consortium of Cybersecurity Clinics. All Rights Reserved. Privacy Policy Accessibility Nondiscrimination