RisksPotential that a given threat will exploit the vulnerability of an asset or group of assets to cause loss or damage to the assets. to the security of the personal and sensitive information include careless practices by employees, such as:

  • leaving a student or employee file on a printer or copier
  • forgetting a laptop on the bus or leaving it in an unlocked car
  • talking about confidential information to friends, family, or in public places
  • shredding a document before it is scheduled to be destroyed
  • allowing “shoulder surfing” where someone watches over a person’s shoulder to observe and gather information


Risks also include making mistakes:

  • disposing of computer equipment with confidential information still on it
  • losing computer tapes containing personal and sensitive information
  • faxing confidential student or employee information to a wrong number
