Updated: December 2, 2008
SANS is very sensitive to privacy issues on the Internet. We believe it is important that you understand how we treat the information you may provide to
us. Unless specifically stated otherwise, the information you provide is never shared with anyone other than SANS employees, instructors or authorized
contractors. SANS never trades or sells its student.s personal information.
This privacy statement applies to information collected by web addresses in the sans.org, sans.edu, giac.org, and other domains owned and operated by
SANS, GIAC, and the Escal Institute, hereafter referred to collectively as SANS.
How We Gather Information
To save you time and make our web services even easier to use, you may create a SANS portal account using your personal information. You may do this by
visiting https://portal.sans.org. The SANS portal system saves your information and references it to your email address
and password. The next time you visit the SANS website, you can simply enter your email address and password. If you purchase a product or service from us,
we request certain personally identifiable information from you on our order form. You must provide contact information (such as name, email, and shipping
address) and financial information (such as credit card number, expiration date). We use this information for billing purposes and to fill your orders. If we
have trouble processing an order, we will use this information to contact you. We also use the mailing address to send you conference brochures and other
items of interest.
When you register online for a conference, you have the opportunity to opt out of being included in a paper attendee list. We give a copy to every student
and vendor that attends the conference. The information on the attendee list consists of first name, last name, company, city, state and country. If you do
not wish to be included in the conference attendee list, simply opt out where the form lists "Include my name in attendee list".
Some SANS training events are co-sponsored by other organizations. Examples include SANS OnSite events that are held in conjunction with private industry,
government agencies, or education institutions. When you register for one of these events, the co-sponsoring organization may have access to your
registration data. The co-sponsor may use this information for purposes related to the event but may not share it with others or use the data for marketing
purposes.
Many organizations purchase vouchers that may be used by their employees to pay for SANS training. By using a voucher, the student understands and agrees
that their student data, including contact information and course-related data may be shared with the organization's designated contact.
SANS occasionally presents courses in conjunction with events sponsored by other organizations. In these cases, event registration may be handled by the
event sponsor. When attempting to register via link from the SANS web site, you will be presented with a web page informing you that the registration is not
being handled by SANS. In these cases, you should familiarize yourself with the privacy policy of the sponsor organization.
When you register for a free vendor-sponsored webcast, you have the opportunity to opt out from a registrant list that will be sent to the sponsoring vendor.
The information SANS provides to the vendor is for their organization only and the sponsoring vendor agrees not to share or resell the provided information.
The data given to the sponsoring vendor includes email address, first name, last name, title, work phone, company name, address, city, state, postal code and
country.
SANS may occasionally provide you the opportunity to participate in contests or surveys on our site. If you participate, we may request certain personally
identifiable information from you. Participation in these surveys or contests is completely voluntary and you therefore have a choice whether or not to
disclose this information. The requested information typically includes contact and demographic information such as name and address. We may share aggregated
demographic information about our user base with our partners and advertisers. This information does not identify individual users.
GIAC Certification Information
GIAC Certified Professionals are listed on the GIAC website and is considered public information. Published data includes Analyst Number, Certificate
Holder's Name, Practical Title (if applicable), Exam Grades, and Certification Expiration Date. No personal contact information is published.
Log Files
As is true of most Web sites, we gather certain information automatically and store it in log files. This information may include IP addresses, browser
type, referring/exit pages, operating system, date/time stamp, and clickstream data.
We use this information to analyze trends, to administer the site, to track how visitors interact with the site.
Cookies
A cookie is a small text file that is stored on a users computer for record-keeping purposes. We do use cookies on our site. SANS may use both session ID
cookies and persistent cookies. We use session cookies to make it easier for you to navigate our site. A session cookie expires when you close your browser.
A persistent cookie remains on your hard drive for an extended period of time. You can remove persistent cookies by following directions provided in your
Internet browsers help file.
When you log into your SANS portal account you may select the "Remember me" check box to set a persistent cookie to store your password, so you don't have
to enter it more than once. You can remove the portal login cookie by clicking the "Logout" link.
If you reject cookies, you may still use our site, but your ability to use some areas of our site, such as the portal, contests or surveys, will be limited
and you may need to reenter personal information when you register for events.
How We Protect Your Personal Information
SANS safeguards the security of the data you send us with physical, electronic, and managerial procedures. Likewise, we urge you to take every precaution
to protect your personal data when you are on the Internet. These precautions include changing your password often, using a combination of letters, numbers
and symbols, and using a secure browser.
The SANS website uses SSL v3 and TLS v1 encryption on all web pages where personal information is submitted. This protects the confidentiality of your
personal and credit card information as it is transmitted over the Internet.
SANS does not store credit card numbers on our servers. Credit card numbers are submitted to a credit card authorization service. This service provides
SANS with credit card validation information only. We do not have access to your personal financial data.
SANS may employ independent contractors to help manage data services, and such contractors may have access to data, similar to the access we give our
employees. Also, SANS may store sales account data, including personally identifiable information, with a third party application service provider.
Access To Your Personal Information
You always have access to the information we have about you. To review and update your personal contact information, simply click https://portal.sans.org and log in with your email address and password, then click Update Your Account. We encourage you
to review your preferences regularly to keep the information current. You may also write sans@sans.org to have the
information changed or removed.
Newsletters And Promotional Email
If you no longer wish to receive our newsletters and promotional communications from SANS, you may opt-out of receiving them by following the instructions
included in each newsletter or communication or by accessing your preferences by logging into https://portal.sans.org
as described in the previous paragraph.
Links To Other Sites
The SANS web site contains links to other sites that are not owned or controlled by SANS. Please be aware that SANS is not responsible for the privacy
practices of such other sites. We encourage you to be aware when you leave our site and to read the privacy statements of each and every web site that
collects personally identifiable information.
Information Obtained From Third Parties
SANS does not sell or trade your personal information. We may at times receive contact lists from other organizations. We may send mailings such as
brochures to these addresses. Typically, these are one-time mailings, and the data is not entered into our database. If you want to remove yourself from the
third party's database, you must contact them directly. These mailings have a brochure code printed on the mailing label. By providing this code, we will be
able to tell you from what provider we received your contact info.
Changes To This Privacy Statement
We reserve the right to modify this privacy statement at any time, so please review it frequently. If we decide to change our privacy policy, we will post
those changes to this privacy statement, the homepage, and other places we deem appropriate so that you are aware of what information we collect, how we use
it, and under what circumstances, if any, we disclose it.
Contact Us
If you have any questions or suggestions regarding our privacy policy, please contact us at privacy@sans.org.