Datatel Colleague Account
Data security is one of the most critical issues associated with installing and supporting an ERP solution. Morehead State University uses a holistic approach for protecting Datatel Colleague institutional data. This approach incorporates a policies and procedures related to Datatel Colleague system security:
- User Training Requirements
- Account Creation and Access
- Initialization (EAC)
- Password Authentication
- Account Termination
- Administration
- Auditing
User Training Requirements
Not all university employees will need a Datatel Colleague account. Typically, those who maintain prospect, applicant, student or employee data will need an account.
In order to obtain a Datatel Colleague account, employees must complete the following online training workshops:
Account Creation and Access
Once the required training has been completed and verification received in the Office of Information Technology Applications Services (ITAS), supervisors should complete a User Security Form to request an initial Datatel Colleague account and relevant access or to modify access for a current account.
The User Security Form should be returned to ITAS, Howell McDowell 301 or FAX to 606-783-5091. ITAS will obtain data custodial approval for requested access.
Data custodians have a responsibility to the University to ensure they grant access to data to only those who require that access to perform their job responsibilities. The data custodian must be familiar with the data and the methods for accessing that data for which they are responsible. The custodian should know how this data is used with the business functions of the University. If for any reason the data custodian has a question of whether an employee’s position would require that access, they should feel free to interview the requester and/or supervisor to verify the access is needed.
ITAS will contact the supervisor if access is denied by the data custodian. The employee and his/her supervisor will be contacted when the account has been created and access granted. The same procedure is followed when additional access is requested.
Initialization (EAC)
In order to reduce the number of account names and passwords to remember, many applications authenticate using a centralized id and password which are maintained on the Eagle Account Center (EAC).
Logging in to the EAC for the first time requires the account be initialized. Initializing the account requires the default password (last 4 digits of SSN and complete date of birth) be changed (password specifications--at least one letter and one number, and must be a minimum of 8 characters in length).
Initialization is completed after setting up three verification questions and answers. EAC allows for account maintenance features such as changing the password and creating new verification questions/answers.
Password Authentication
Logging into a Datatel Colleague account requires authentication, a mechanism that validates via an account ID and password that users have a right to use the system. There are many technology resources – or applications - which require this kind of authentication, including Datatel Colleague.
Account Termination
ITAS receives notification of employee terminations from the Office of Human Resources (OHR) or from the hiring department in the case of student workers. The termination dates are entered into the user’s .profile, prohibiting Datatel Colleague account login beginning with the date of termination. Notification of internal employee transfers (from one position or job department to another) is received from OHR and the account terminated via the .profile. The employee’s new supervisor must follow the same procedures for requesting a new account (see Account Creation and Access). If user training requirements were previously met, the employee does not need to complete the orientation and/or FERPA trainings again.
Administration
Requiring ITAS to obtain data custodian approval for all access requests strengthens security via a checks and balances system by not allowing one person to grant access permissions. This process also allows departments who maintain a database of users with access to their records to keep an accurate listing when new employees are added.
Auditing
Datatel Colleague security reports are generated by ITAS and made available via email to all data custodians and supervisors. Reports are generated on a quarterly basis with requests for security changes made via written notification. If for any reason a data custodian questions whether an employee’s position would require current access, they are encouraged to interview the requester and/or supervisor to verify the access is needed. Access deletion (or modification in rights--maintenance to inquiry rights) would be made immediately upon notification. ITAS communicates the access modification to the respective employee and supervisor.