Document status:  undergoing stakeholder review

This material supports the  Person Directory Access Control Policy.

The Risk Factors help the directory-support team and application owners assess applications for suitability for access to the UW Person Directory.

Risk Factors for Exposure of Protected Student Data in Current Directory

Factors leading to low risk:

  1. Application doesn't access name attributes, eg only does identifier mapping.
  2. Application deals only with employee entries.
  3. Application has small user population.
  4. Application is only used in scenarios appropriate for access to protected student data.

Factors leading to high risk (in addition to inverse of above factors):

  1. Application is used by students.
  2. Application has people-picker that permits browsing directory entries.
  3. Application doesn't have well-defined usage or administration policies.
  4. Application maintains internal per-person records with copies of directory data.