Protecting Patron Information in a Consortial Environment Issues and Strategies Jennifer Kuntz

Slides:



Advertisements
Similar presentations
Privacy and Library Systems Karen Coyle for InfoPeople November, 2004.
Advertisements

Access & Identity Management “An integrated set of policies, processes and systems that allow an enterprise to facilitate and control access to online.
South Dakota Library Network MetaLib Management Basics Updating Resources South Dakota Library Network 1200 University, Unit 9672 Spearfish, SD
The future’s so bright…. DAITSS DIGITAL PRESERVATION SYSTEM: RE-ARCHITECTED, RE- WRITTEN, AND OPEN SOURCE Priscilla Caplan Florida Center for Library Automation.
Testing Web Applications. Applications Architecture Client Server Architecture.
PDS User Management DigiTool Version 3.0. User Management 2 PDS Overview PDS Setup Single Sign On Agenda.
Remote User Authentication in Digital Libraries
ELAG Trondheim Distributed Access Control - BIBSYS and the FEIDE solution Sigbjørn Holmslet, BIBSYS, Norway Ingrid Melve, UNINET, Norway.
ICOLC October 4, 2001 OCLC Services. Purpose Libraries’ web-based information portal needs –Maximize consortia’s role in their members’ use of database.
Library Online Catalog Tutorial Pentagon Library Last Updated March 2008.
Patron Initiated Resource Sharing Carmit Marcus. Patron Initiated Resource Sharing 2 The cliches … in this era of reduced funds for acquisitions… … imperative.
Document Imaging and Customer Relationship Management (CRM) alive in VisualRATEX Tuesday, August 2 nd, 2:30 – 3:30pm By Thomas Romantic, Cornell Business.
Library integrated system -Aleph Fang Peng Stony Brook University.
C102 Managing Electronic Resources for Multiple Audiences Alvin Sherman Library, Research, and Information Technology Center A joint use facility with.
Introduction to Integrated Library Systems
Improving access to digital resources: a mandate for order mandate: managing digital assets in tertiary education craig green,
Registration and Invention Disclosure (ID) Training.
Agenda  Overview  Configuring the database for basic Backup and Recovery  Backing up your database  Restore and Recovery Operations  Managing your.
Federated Searching Pre-Conference Workshop - The federated searching cookbook Qin Zhu HP Labs Research Library February 18, 2007.
OCLC Online Computer Library Center A Global OpenURL Resolver Registry Phil Norman OCLC Dlsr4lib Workshop March 23 rd, 2006 Arlington VA.
6/1/2001 Supplementing Aleph Reports Using The Crystal Reports Web Component Server Presented by Bob Gerrity Head.
FireRMS SQL Audit, Archiving & Purging Presented by Laura Small FireRMS Quality Assurance.
March 20, 2008Electronic Resources and Libraries College Center for Library Automation Tallahassee, FL Susan B. Campbell Susan.
Login Screen This is the Sign In page for the Dashboard New User Registration Enter Id and Password to sign In.
University of Kentucky Proxy Service Presentation By Kelly Vickery
EBSCOadmin. Select Change Password Select EBSCOadmin Security.
Connecting users to Collections Collection Development/Resource Sharing Conference March 26, 2009 Jean Phillips Florida Center for Library Automation
Title Level Patron Placed Holds: Taking Resource Sharing Via the OPAC a Step Beyond Patron Placed Holds in the University System of Maryland and Affiliated.
Project Overview Bibliographic merging, Endeca, and Web application.
University of Palestine Faculty of Applied Engineering and Urban Planning Software Engineering Department Prepared By Ahmed Obaid Wassim Salem Supervised.
DAS/BEST ITSecurity Division. RSA SecurID Software Tokens: Make strong authentication a convenient part of doing business. Deploy RSA software tokens.
OPAC Training aid (Library solutions & Library world)
ALEPH version 19.01/20.01 Systems Librarian Updates South Dakota Library Network 1200 University, Unit 9672 Spearfish, SD © South Dakota.
Athabasca University Library Athabasca, Alberta Canada Steve Schafer Director Library Services
Crystal Reports and Circulation Workflow Margie Fiels  Head, Access Services Bob Gerrity  Head, Systems Boston College Libraries.
1 Client/Server Databases and the Oracle Relational Database.
Warehouse Report. Log into EDS using your Address/User Id and Password. If you have forgotten your password, click on the Forgot Password? link.
David Kennedy, UMD Shibboleth and Library Resources Internet2 Library/Shibboleth Project.
PS Security By Deviprasad. Agenda Components of PS Security Security Model User Profiles Roles Permission List. Dynamic Roles Static Roles Building Roles/Rules.
Patron Privacy Issues Cindy Cunningham – OHSU. Overview Balancing demands (academic environment) Privacy in Libraries System Privacy  Vendor  Institution/Library.
Resnet Enhancements and Directions Part 1, Bruce Campbell, Information Systems and Technology.
Flinders University Library Opening Hours, RSS and Authentication Modules.
6/1/2001 Supplementing Aleph Reports Using The Crystal Reports Web Component Server Presented by Bob Gerrity Head.
Hatrak Scheduler UsOn Line Demo HATRAK SCHEDLER.
 Empowers to your customer  Product Rating and its Management in Ecommerce Framework  Product Reviews and Management: Collecting customer opinion about.
Carla Pfahl Minitex Reference Outreach & Instruction AskMN Coordinator
Syllabus Management System Matt Bernstein, Paul Capelli, Jared Segal.
Aleph Restful APIs Ori Miller June 2012.
1 AHM, 2–4 Sept 2003 e-Science Centre GRID Authorization Framework for CCLRC Data Portal Ananta Manandhar.
1 Yoel Kortick Senior Librarian Alma Product Management 245 $$a Group Settings for Electronic Resources 246 $$a How to control access to electronic resources.
ASSIGNMENT 2 Salim Malakouti. Ticketing Website  User submits tickets  Admins answer tickets or take appropriate actions.
Z39.50 A Basic Introduction Kathleen R. Murray, Ph.D. William E. Moen, Ph.D. May 2002.
Bibliographic Record Description of a book or other library material.
The Periodical Cat Amy Kreitzer College of St. Catherine Library.
Building Preservation Environments with Data Grid Technology Reagan W. Moore Presenter: Praveen Namburi.
EZAccess User Guide. EZAccess is a web proxy server that allows authorized users to access IP-restricted electronic resources subscribed by UiTM library.
Step 1 Lead Notifications Dear Partner, New leads have been assigned to your organization based on customer preference and are available for you.
 Project Team: Suzana Vaserman David Fleish Moran Zafir Tzvika Stein  Academic adviser: Dr. Mayer Goldberg  Technical adviser: Mr. Guy Wiener.
Library Elf Tech Talk presented by South Jersey Regional Library Cooperative November 15, 2006 Ralph Bingham Technology Librarian Gloucester County Library.
Libraries Organizations & Users Updated: 18-Jun-2006.
Presented by [Harshit Agrawal] 04/03/2017
Architecture Review 10/11/2004
ILL2 with partner type Aleph
Archiving and Document Transfer Utilities
z/Ware 2.0 Technical Overview
New features and customization options
Aleph Circulation Loans & Returns Version 19
University of Kentucky E-IRB
“All About Me” Staff Development Day
PDS, Primo, Aleph, MetaLib, SFX General workflow
Presentation transcript:

Protecting Patron Information in a Consortial Environment Issues and Strategies Jennifer Kuntz

FCLA Mission “The Florida center for library automation (FCLA) provides automation services that assist the libraries of Florida’s publicly-funded universities in meeting their teaching and research objectives for students and faculty…..”

Consortial Issues What patron data needs to be retained for the business operations of supported libraries? What patron data needs to be retained for data integrity in event of a system failure? How long must such data be retained? What data is necessary to provide value-added services desired by patrons? How should patrons be educated regarding how their personally identifiable data is used and retained, and what role should FCLA play in their education?

NOTIS Mainframe-based integrated library management system Libraries access only their own patron data Link to patron removed when loans returned, unless a charge is incurred Bills/fines exported to university bursar; Export files age off weekly Daily change log maintained in event of system failure; May contain some links no longer present in primary data

WebLUIS Web-based interface to NOTIS – serves as OPAC and portal to electronic resources Users assigned session id for tracking – not linked to personally identifiable patron information Apache logs contain IP address, session id, query and return code Patron services such as online renewal and ILL requests do not require retention of identifiable patron data

ALEPH Client-server architecture means lots more places data could potentially be retained Personally identifiable patron data retained in multiple Oracle tables must be explicitly removed Patron features that allow saving and retrieval of searches and records contain personally identifiable data Web server logs contain a session id and query but actual results not retained

Electronic Resources FCLA does not sign vendor licenses requiring patron information for basic services Vendors receive only a range of valid IP addresses University libraries “own” their patron data, and can therefore choose to provide to vendors for additional services if desired Web logs contain IP address, URL of database queried, and vendor server response

Proxy Server Patrons authenticated against library management system patron data – yes/no response and institution returned Apache access logs contain IP address, query, and server response Error logs may contain invalid userids; retained only long enough for troubleshooting

At Each Institution Each university’s policies determine how patron data is used and retained outside of systems run by FCLA Individual library policies determine how patrons are educated regarding the use and retention of personally identifiable data

Future Challenges Should FCLA play more of a role in patron education regarding retention of patron data by systems we run? Will later versions of ALEPH retain patron data differently? What value-added features will patrons want and what data will this require to be retained?