{"schema_version":"ICEQC_NEWS_ARTICLE_V1","id":"iceqc-news-b019ebe1da46bf89","slug":"2021-02-03-monitoring-evidence-for-digital-data-protection","language":"en","publication_status":"READY_FOR_IMPORT","publication_date":"2021-02-03","last_modified_date":"2021-02-03","title":"Monitoring evidence for digital data protection","summary":"Explains how monitoring evidence for digital data protection should be applied in practice, including scope, evidential sufficiency, accountable decisions and justified.","category":{"code":"STANDARDS_INTERPRETATION","label":"Standards Interpretation"},"article_type":"Standards interpretation","publisher":"International Council for Education Quality Certification (ICEQC)","jurisdictional_scope":"International","historical_reference_basis":"Institutional reliance on online systems","reference_authority":"Relevant public authorities and official international sources","sections":[{"heading":null,"paragraphs":["The institutional reliance on online systems provides the immediate context for evidence for digital data protection. The analysis of the stated expectation proceeds on the basis that a standard is effective only when its terms lead to consistent decisions without displacing professional judgement or applicable law. In relation to monitoring evidence for digital data protection, the appropriate administrative form will depend on the jurisdiction and the allocation of lawful responsibility.","The contemporaneous context is established by the institutional reliance on online systems. It does not, without setting-specific evidence, demonstrate the operation of the control. Reporting should preserve the different status of facts, public expectations and choices made by institutions.","The quality significance of the stated expectation follows from a basic distinction between availability and effective provision. A decision concerning the control should recognise that education information should be collected for a defined purpose, protected in proportion to its sensitivity and retained only for an authorised period."]},{"heading":"Scope and application of monitoring evidence for digital data protection","paragraphs":["In practical terms, evidence for digital data protection should be reviewed against a stated method rather than general assurance. In reviewing the control, the subject should be examined as a connected system of policy, people, resources, decisions and evidence. Assurance should not overlook failures arising at the boundary between otherwise adequate controls. Those required to act should be able to understand the method and its material limitations.","The governing expectation for the stated expectation should be capable of consistent application. A decision concerning the relevant requirement should recognise that conformity should not be inferred from a policy document alone; operating records and outcomes should show that the stated arrangements are in use. Criteria affecting learners should not permit materially different interpretation without an evidenced reason."]},{"heading":"Evidence required","paragraphs":["Risk assessment of evidence for digital data protection should give particular attention to retention beyond an identified need, inaccurate data affecting decisions, and secondary use without adequate authority. A provider should also consider uncontrolled supplier access or transfer and excessive access to learner information."],"bullets":["Test incident and recovery arrangements.","Control third-party processing before it is relied on for a decision with material effect.","Limit and review access before using it to determine a learner or provider outcome.","Provide accessible correction and complaint routes.","Assign accountable data owners before it informs a consequential decision."]},{"heading":"Decision criteria and exceptions","paragraphs":["In relation to monitoring evidence for digital data protection, the evidential record should be limited to material that can answer the question under review. For evidence for digital data protection, the most relevant material is likely to include role-based access and access reviews, supplier and transfer arrangements, a register of information assets and purposes, and data-quality and correction controls.","A proportionate method is available for the stated expectation. For the issue under review, the reviewer should map the complete process, identify the intended result and responsible authority at each stage, and test normal cases together with exceptions. Recurrence, common cause or wider exposure requires systemic action in addition to correction of individual cases. Contrary evidence should not be removed merely because aggregate performance appears acceptable.","Interpretation of the issue under review should produce a test that another competent reviewer can apply to comparable evidence."]},{"heading":"Continuing assurance","paragraphs":["The analysis of evidence for digital data protection should remain within the limits of the evidence. The analysis of the stated expectation proceeds on the basis that interpretive guidance should not create an obligation that is absent from the governing instrument or applicable law. The analysis of the issue under review proceeds on the basis that security, privacy and data quality are related but distinct. A secure record may still be inaccurate or used without adequate authority, and a lawful use may still be poorly governed. Material uncertainty should result in further enquiry or an expressly limited finding.","Records relating to the relevant requirement should preserve both the conclusion and its limits. If further evidence changes the position, the correction should identify its scope and any earlier decision requiring reconsideration. This is material where learners, authorities or institutions relied on information that cannot be corrected by replacing the current text alone.","Public reporting on the control should distinguish established fact, analytical judgement and planned action. Material revisions should be traceable to their reason and effective date.","No individual measure is sufficient to establish effective operation of the issue under review across the affected scope. A reasoned conclusion should reconcile the governing requirement, evidence of operation, learner outcomes and residual risk, and remain open to better evidence."]}],"word_count":734,"content_hash":"sha256-6444c840685e0cb583706510b04b29a07b9c06ce8a916d0773c38ebde910cbac","seo_keywords":["monitoring evidence for digital data protection","education quality standards","education quality","ICEQC"],"schema_type":"TechArticle"}
