FCPS District Information Security Manager Recommendations on Software Account Access methods
Single Sign-On (SSO) Best Practices
It is recommended that all approved applications utilize Single Sign-On (SSO) as part of our internal security best practices.
While some applications may not currently integrate with SSO, this is precisely why the approval process is so critical. It allows us to review the vendor’s authentication methods and ensure they meet our security standards.
Teachers Creating Manual Student Accounts
Teachers should not create manual student accounts using personal Gmail or other non-district credentials.
Doing so could result in the unauthorized disclosure of personally identifiable information (PII) and may place the district in violation of federal regulations such as FERPA and other data privacy requirements.
Manual account creation also circumvents our approved security safeguards and can expose both students and the district to unnecessary risk.
Trial or Limited Access Requests
Even for short-term trials, apps must go through the Software Approval Committee. This allows us to ensure the vendor’s data handling practices align with district standards and that appropriate agreements are in place.
For vendors with an existing district purchase or Data Sharing Agreement (DSA), a limited pilot may be permitted but only after confirming the app’s data use remains within the approved scope.
For vendors without a DSA, teachers should not create student accounts or use the tool until it has been properly vetted and approved.