Join our Newsletter — 33% off our NHI Course
Home Glossary Cyber Security Directory Information
Cyber Security

Directory Information

← Back to Glossary
By NHI Mgmt Group Updated August 24, 2026 Domain: Cyber Security

Directory information is student information a school may disclose without prior consent if the student or parent has not opted out. Typical examples include name, address, participation in activities, and awards. It is less sensitive than protected education data, but it still requires careful policy controls and notice.

Expanded Definition

Directory information is a compliance term used in education records governance to describe a limited set of student data that a school may disclose without prior consent unless a student or parent has opted out. The category is narrower than protected education records, but it still depends on formal notice, local policy, and consistent handling. In practice, schools decide which data elements qualify, publish that designation, and explain how opt-out rights work.

The concept is often misunderstood because it sounds like a generic contact list, when it is really a legally bounded disclosure category. Under the Family Educational Rights and Privacy Act, institutions can define directory information within permitted limits, but they cannot treat all student data as automatically public. That means the same attribute may be disclosable in one context and restricted in another, depending on policy, notice, and student status. For broader governance context, security teams often align handling practices with the NIST Cybersecurity Framework 2.0 to support controlled disclosure and accountability.

The most common misapplication is assuming directory information is always safe to share, which occurs when staff ignore opt-out status or disclose beyond the approved data elements.

Examples and Use Cases

Implementing directory-information controls rigorously often introduces administrative overhead, requiring organisations to balance easier public disclosure against precise notice and opt-out management.

  • A registrar publishes a student name in a graduation program because the school has designated it as directory information and provided required notice.
  • A communications office shares a student’s participation in athletics with local media, but only after verifying the disclosure category and checking whether the student opted out.
  • An alumni office uses listed awards and honors for a newsletter, while withholding the same student’s address because it was not designated for disclosure.
  • An SIS administrator configures field-level controls so that directory data can be exported for approved purposes without exposing protected records.
  • A school district updates its annual notice after reviewing whether current directory elements still match policy, legal requirements, and actual operational need.

These use cases show why directory information is not a one-time label but an ongoing governance decision. For policy design and risk framing, schools often pair disclosure rules with identity and access discipline from the NIST Cybersecurity Framework 2.0, especially where staff, vendors, and systems touch student data.

Why It Matters for Security Teams

Directory information matters because it sits at the boundary between operational disclosure and privacy protection. If the category is poorly defined, schools can over-disclose student data, undermine trust, and create avoidable compliance exposure. If it is too restrictive, routine communications and reporting become cumbersome, leading staff to work around policy and create shadow processes.

Security and privacy teams need to understand that this term is not only about legal compliance. It also affects identity verification workflows, data minimisation, records lifecycle controls, and who can publish student details through portals, websites, or third-party platforms. When student records are synchronised into non-school systems, directory fields must be separated from protected attributes to avoid accidental exposure. Governance should also account for role-based access, because staff with broad system permissions may be able to export more than their job function requires. The NIST Cybersecurity Framework 2.0 is useful here as a governance lens for access control, data management, and incident response readiness.

Organisations typically encounter the operational cost of directory-information mistakes only after an unwanted disclosure, at which point the category becomes operationally unavoidable to review and tighten.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Non-Human Identity Top 10 address the attack surface, NIST CSF 2.0, NIST SP 800-63 and NIST AI RMF set the technical controls, and EU AI Act define the regulatory obligations.

FrameworkControl / ReferenceRelevance
NIST CSF 2.0PR.ACDirectory information handling depends on access control and authorised disclosure decisions.
NIST SP 800-63IAL1Identity proofing context matters when schools verify who may view or request student records.
NIST AI RMFAI systems used in student services need governance over data disclosure and privacy risk.
EU AI ActAutomated profiling or decision systems involving student data require stronger governance.
OWASP Non-Human Identity Top 10Non-human identities may access student systems and must be limited to approved disclosure scope.

Verify requester identity before releasing non-public student information beyond directory data.

NHIMG Editorial Note
Reviewed and updated by the NHIMG editorial team on August 24, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org