Academics
Security questions for exams, gradebooks, and report cards
Security questions for exams, gradebooks, and report cards, covering identity, permissions, assessment integrity, exports, suppliers, incidents, recovery, retention, and monitoring.
1. Define what must be protected
List learner, teacher, subject, cohort, assessment, submission, mark, grade, report, moderation, comment, identity, permission, audit, support, and integration records.
Classify confidentiality, integrity, availability, correction, history, reporting, safeguarding, privacy, records, and continuity needs. Name owner, purpose, source, audience, retention, and consequence of compromise or loss.
2. Ask identity and access questions
How are users invited, authenticated, recovered, disabled, reviewed, and assigned to subjects, cohorts, campuses, learners, reports, moderation, and support? How are staff leavers, substitutes, families, suppliers, and shared devices handled?
Map view, create, mark, edit, moderate, approve, publish, export, correct, archive, and delete. Test whether a role can access more than the decision requires.
3. Ask integrity questions
How are assessment setup, scale, weighting, rounding, boundaries, missing values, moderation, approval, publication, correction, resit, special consideration, withdrawal, transfer, and duplicate handling validated and recorded?
Test ordinary, boundary, missing, late, absent, amended, moderated, duplicate, withdrawn, changed-period, report-correction, replay, and outage cases. Keep original, moderated, approved, published, and corrected history.
4. Ask data-flow questions
What leaves the system through exports, reports, notifications, integrations, support tickets, backups, suppliers, subcontractors, or family views? Who can receive it, for what purpose, for how long, and under whose instruction?
The U.S. Department of Education data governance checklist covers quality, access, security, lifecycle, sharing, disposal, and monitoring. Record source, destination, fields, retry, failure, correction, retention, and deletion.
5. Ask incident and recovery questions
How are suspicious access, wrong publication, corrupted gradebook, failed integration, lost device, account compromise, report error, outage, backup restore, and data-loss events detected, contained, communicated, investigated, and closed?
Define safe continuity for teachers, administrators, records, leaders, learners, and families. A temporary record must have an owner, protection, reconciliation, retention, and disposal route.
6. Ask supplier and lifecycle questions
Clarify security evidence, support access, subcontractors, storage, incident notification, audit, access review, backup, restoration, retention, disposal, export, return, transition, and contract-end deletion.
GOV.UK guidance emphasises accountable handling of school data. Apply qualified local privacy, safeguarding, records, security, accessibility, and legal review rather than treating a certification or vendor statement as a complete assessment.
7. Test and monitor
Record scenario, expected result, observed result, evidence, limitation, owner, remedy, due date, and retest. Include teachers, assessment, academic, records, leadership, IT, support, privacy, safeguarding, accessibility, and security owners.
At 30, 60, and 90 days, review access exceptions, exports, corrections, incidents, support demand, staff effort, report confidence, recovery tests, retention actions, and outcome. Expand, repair, narrow, consolidate, or hold.
Turn the guidance into an accountable decision
Apply this guidance to one bounded part of security questions for school exam and gradebook software. Define the assessment or reporting decision, authoritative record, accountable owner, permitted users, correction route, evidence, and review date.
Test an ordinary assessment and meaningful exceptions such as a missing submission, late work, absent learner, moderation change, amended result, withdrawn learner, duplicate mark, grading-period change, report correction, access failure, or outage.
Keep supplier capability, school responsibility, professional judgement, local policy, legal advice, and measured outcome separate. If evidence is incomplete, narrow the claim and pilot the smallest safe change.
Review at 30, 60, and 90 days. Check completeness, timeliness, consistency, moderation, corrections, access exceptions, staff effort, support demand, reporting confidence, and the original outcome. Decide whether to expand, repair, consolidate, narrow, or hold.
Before approval, ask a reviewer who was not involved in the design to challenge the strongest assumption. Replace broad language with the exact evidence, population, date, and limitation the school can verify.
Document what was tested and what was not. A successful demonstration with a simple gradebook does not establish readiness for moderation, resits, special consideration, changed grading periods, multiple campuses, or a changed assessment policy.
Keep evidence beside the decision record so a later reviewer can distinguish observed behaviour from an assumption, estimate, or supplier statement. Name the next test where evidence remains incomplete.
Revisit the boundary when the school adds a subject, year group, campus, grading scale, role, integration, reporting period, or policy. A small change can alter permissions, definitions, calculation, timing, retention, or support demand.
Set the next review date and owner. A dependable exams and gradebook operation is maintained through clear definitions, controlled change, professional judgement, and visible accountability rather than a one-time setup.
Make the handoff readable to a teacher, administrator, leader, learner, and reviewer. State what passed, what remains manual, which records are authoritative, who owns unresolved conflicts, and how a correction is communicated without creating an uncontrolled copy.
Keep approved definitions beside calculation rules, moderation notes, training, support routes, and change history. New subjects, scales, integrations, or reporting windows can change the risk even when field names stay the same.
