National Survey of Student Engagement

Security of the NSSE Computing Environment

The NSSE Institution Interface and Survey are programmed and administered by the Indiana University (IU) Center for Survey Research (CSR). The computing environment at the CSR requires a high level of computer and data security per the policies governing IU information technology resources and data . The University Information Technology Services Policy Office (UIPO) at IU provides a baseline level of enforced security requirements including protocols to prevent unauthorized access to IU computers. The CSR computing staff follows industry-standard security best practices. Each CSR workstation is updated daily with virus protection software. CSR endpoints are scanned regularly for required security patches and hot fixes. Operating system security updates are deployed through Indiana University's standard Enterprise Windows Administration (EWA) patch management process, with scheduled monthly maintenance windows and expedited deployment of critical security updates when necessary.

The CSR employs the Principle of Least Privilege when assigning access rights to staff. The systems administration staff have designed several processes for preventing intrusions or data loss on the CSR's servers. Remote access to the servers is restricted through authenticated user accounts and multi-factor authentication (Duo), with access granted according to Indiana University security policies. Physical access to servers is restricted by the security protocols of IU’s data center . Access to directories on the file servers is restricted to only those employees who need access. Security processes like those run on the workstations are used to prevent, detect, and repair security problems on the servers. The servers are located on a range of private IP addresses restricting their access from the outside world. The servers sit behind a network firewall and utilize host-based firewalls. IU performs routine vulnerability scanning of the servers to identify potential security issues, and the CSR computing staff monitor server event logs for indications of unauthorized access or other security events.

Individual workstations reside on a Virtual Local Area Network (VLAN), providing additional network segmentation and access restrictions. Authorized remote access requires a secure VPN connection protected by Duo multi-factor authentication.

The files on the servers are backed up each night, and all project data is encrypted at rest within the backup. CSR systems are hosted within Indiana University's Intelligent Infrastructure virtual server environment and reside in secure IU-managed data centers that employ physical and environmental safeguards appropriate for enterprise computing environments.

The CSR uses industry-standard TLS (Transport Layer Security) to protect survey data and other sensitive information transmitted across the Internet. Web server certificates are issued through Indiana University's InCommon certificate service. A respondent's web browser verifies the authenticity of the website's digital certificate before establishing an encrypted TLS session. Encryption keys are exchanged securely to protect all data transmitted during the session. These security measures meet or exceed Indiana University's requirements for the secure transmission of confidential information.

Please contact NSSE if you have further questions.