Close

Global Education Security Standard (GESS)

gess_full_large_color

About the Global Education Security Standard (GESS)

With the range of technical, functional, cyber security, data protection, privacy and other requirements, it is an increasingly laborious job to try to have a single way of showing suitability to potential customers or to demonstrating compliance during procurement exercises.

With the growing number of security standards and frameworks, there is a significant amount of crossover, and much of it not in a language that allows for consideration of educational or operational needs of educational institutions.

Building on the success of the ST4S assessments across Australia and New Zealand, the Student Data Privacy Consortium has brought together a working group of educational departments, leading vendors and academics to develop a Global Education Security Standard, to provide a common grounding baseline for all, as well as regional requirements.

The following frameworks and sets of controls have been reviewed and mapped during this process:

Whilst this standard might seem like a large undertaking for an EdTech vendor, the goal is to ensure that you have clear coverage for all your possible markets, existing and new, with output framed to provide educational institutions with both technical information and clear language around how it makes a difference to them as educational institutes.

The following explains the standard and questions involved, and provides you with a starting point for meeting the criteria. It is also important to remember that the standard is assessed against a product, not just the vendor. This means questions will be asked about you as a vendor/product producer/service provider and also about the product/service itself.

GESS Disclaimer:

This GESS Documentation and Portal contains copyright material which has been reproduced with the permission of Education Services Australia Limited. Copyright is owned by Education Services Australia Limited. All rights reserved.

The SDPC model Data Privacy Agreements (DPAs) have had a huge impact on the K12 EdTech ecosystem by establishing common expectations and streamlining the DPA execution process for both districts and providers.

Since 2016, over 222,000 standard DPAs have been executed and subscribed to.

By applying an average legal fee of $250 per hour, and minimal negotiation time of 1hr for each district and vendor per DPA, these standard DPAs have saved participating districts and vendors over $111 million.