<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0" xml:base="http://connect.educause.edu" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd">
<channel>
 <title>EDUCAUSE | SEC06</title>
 <link>http://connect.educause.edu/browse/content/blog/2047</link>
 <image>
    <title>EDUCAUSE CONNECT</title> 
    <link>http://connect.educause.edu/browse/content/blog/2047</link> 
    <url>http://connect.educause.edu/educause/images/e_rss.png</url> 
 </image>

  <itunes:subtitle>events, concepts, and conversation from EDUCAUSE</itunes:subtitle>
  <itunes:author>The EDUCAUSE Podcast Crew</itunes:author>
  <itunes:summary>EDUCAUSE is a nonprofit association whose mission is to advance higher education by promoting the intelligent use of information technology.  Our podcasts provide information about a range of topics including Leadership, Policy and Law, Teaching and Learning, Emerging Technologies, Open Source, Research Computing, Cyberinfrastructure, and Digitial Libraries. </itunes:summary>
  <itunes:new-feed-url>http://connect.educause.edu/browse/content/node/691/list/feed</itunes:new-feed-url>
  <itunes:image href="http://connect.educause.edu/educause/images/e_rss.png" />
  <itunes:category text="Education">
  	<itunes:category text="Education Technology"/>
  	<itunes:category text="Higher Education"/>
  </itunes:category>
  <itunes:category text="Technology">
  	<itunes:category text="Tech News"/>
  </itunes:category>

 <description>Recent blog entries tagged with SEC06.</description>
 <language>en</language>

<item>
 <title>EDUCAUSE Security Professionals Conference 2006.  Summary:  Winning the Battle against Cyber Criminals</title>
 <link>http://connect.educause.edu/display/2277</link>
 <description>&lt;p class=&quot;MsoNormal&quot;&gt;&lt;span&gt;Winning the Battle against Cyber Criminals&lt;span&gt; &lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class=&quot;MsoNormal&quot;&gt;&lt;span&gt;&lt;span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span&gt;Dan Larkin Unit Chief, Internet Crime Complaint Center , Federal Bureau of Investigation &lt;/span&gt;&lt;/p&gt;&lt;span&gt;This opening keynote presentation covered the work of the federal government&amp;rsquo;s Internet Crime Complaint Center , generally referred to as the IC3, and their industry and academic partners.&lt;span&gt;&amp;nbsp; &lt;/span&gt;The IC3 is a joint initiative between the FBI and the National White Collar Crime Center (NW3C)&lt;span&gt; &lt;/span&gt;&lt;/span&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;&lt;span&gt;&lt;span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span&gt;&lt;span&gt;&lt;span&gt;The IC3 has multiple teams in multiple locations, from Pittsburgh, to Nambia, to , working on issues of internet crime.&lt;span&gt;&amp;nbsp; &lt;/span&gt;The efforts of their rapid referral teams push incidents out to law enforcement forces. &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span&gt;&lt;span&gt;&lt;span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;span&gt;The IC3 has identified more than 100 significant spammers and more than 200 Government sites that have been compromised or mis-configured. &lt;/span&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;&amp;nbsp;&lt;span&gt;They collaborate with industry &amp;amp; law enforcement against phishing schemes and are working to develop better approaches to and more impact on these scams.&lt;span&gt;&amp;nbsp; &lt;/span&gt;Key elements are keeping a strong focus in this area, enhancing timely intelligence exchange and broadcasting information appropriately as soon as it is confirmed.&lt;span&gt;&amp;nbsp; &lt;/span&gt;Public service announcements are important in the work of the IC3 as a means to getting the word out about new criminal activities.&lt;span&gt;&amp;nbsp;&amp;nbsp; &lt;/span&gt;This is critically important as so many of the criminal sites pop up quickly and are gone quickly too.&lt;span&gt;&amp;nbsp; &lt;/span&gt;More than 5000 Katrina scam sites were up within days of the hurricane.&lt;span&gt;&amp;nbsp; &lt;/span&gt;More than 1000 Tsunami scam sites were active.&lt;span&gt;&amp;nbsp; &lt;/span&gt;Identity theft and online pharmacy fraud are major issues as well. &lt;/span&gt;&lt;/p&gt;&lt;p&gt;&amp;nbsp;&lt;span&gt;Strategic elements of these collaborations are joint work, joint intelligence development and analysis and an ongoing effort to collaboratively develop strategy with their partners. &lt;/span&gt;&lt;/p&gt;&lt;p&gt;&amp;nbsp;&lt;span&gt;The IC3 also develops and refines initiatives thru joint training with industry and law enforcement &lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span&gt;Critical and significant to their process philosophy is to investigate first and prosecute second.&lt;span&gt;&amp;nbsp; &lt;/span&gt;They work to lock down evidence quickly to minimize victim impact and maximize understanding of the situation.&lt;span&gt;&amp;nbsp; &lt;/span&gt;They must have a central team to work through leads &amp;ndash; where&amp;rsquo;s the real criminal &amp;ndash;which box is compromised?&lt;span&gt;&amp;nbsp; &lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span&gt;The IC3 has three major obstacles: smooth intelligence gathering, lack of resources, and turf issues as in who gets credit for the work.&lt;span&gt;&amp;nbsp;&amp;nbsp; &lt;/span&gt;Some key wins are their work on the Digital Phishnet, Operation Identity Shield, and their work, in general, against organized crime.&lt;span&gt;&amp;nbsp; &lt;/span&gt;They have enabled arrests world-wide.&lt;span&gt;&amp;nbsp; &lt;/span&gt;They also have a public service website for awareness education and Lookstoogoodtobetrue.com which makes internet crime a personal issue for people.&amp;nbsp;&lt;/span&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;&lt;span&gt;Larkin suggested that we all participate.&lt;span&gt;&amp;nbsp; &lt;/span&gt;If you don&amp;rsquo;t have someone you can put onsite at a triage center then consider hiring someone, perhaps jointly with others to represent your community.&lt;span&gt;&amp;nbsp; &lt;/span&gt;They currently have 10 onsite from industry.&lt;span&gt;&amp;nbsp; &lt;/span&gt;To back up the desirability of the West Virginia location, Larkin showed a quick AV clip made by a member of the staff. &lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span&gt;It&amp;rsquo;s important to get information about the IC3 out to the endusers asking them to contribute information.&lt;span&gt;&amp;nbsp; &lt;/span&gt;They are the only ones aggregating internet crime information.&lt;span&gt;&amp;nbsp; &lt;/span&gt;The byword should be &amp;ldquo;Send to IC3, don&amp;rsquo;t hit delete&amp;rdquo; &lt;/span&gt;&lt;/p&gt;&lt;p&gt;&amp;nbsp;&lt;span&gt;The presentation site is &lt;a href=&quot;http://www.educause.edu/SEC06/Program/8339?PRODUCT_CODE=SEC06/GS01&quot;&gt;http://www.educause.edu/SEC06/Program/8339?PRODUCT_CODE=SEC06/GS01&lt;/a&gt; &lt;/span&gt;&lt;/p&gt;&lt;p&gt;&amp;nbsp;&lt;span&gt;The IC3 website is located at &lt;a href=&quot;http://www.ic3.gov/&quot;&gt;http://www.ic3.gov/&lt;/a&gt; &lt;/span&gt;&lt;/p&gt;</description>
 <comments>http://connect.educause.edu/display/2277#comments</comments>
 <category domain="http://connect.educause.edu/tag/Cybersecurity/56">Cybersecurity</category>
 <category domain="http://connect.educause.edu/tag/federal+government/1961">federal government</category>
 <category domain="http://connect.educause.edu/tag/Internet+Crime+Complaint+Center/1962">Internet Crime Complaint Center</category>
 <category domain="http://connect.educause.edu/tag/Phishing/476">Phishing</category>
 <category domain="http://connect.educause.edu/tag/SEC06/2047">SEC06</category>
 <category domain="http://connect.educause.edu/tag/security/870">security</category>
 <category domain="http://connect.educause.edu/tag/Security+Awareness/258">Security Awareness</category>
 <category domain="http://connect.educause.edu/tag/Spam/1107">Spam</category>
 <pubDate>Tue, 25 Apr 2006 13:48:51 -0500</pubDate>
 <dc:creator>llarsen</dc:creator>
 <guid isPermaLink="false">2277 at http://connect.educause.edu</guid>
</item>
<item>
 <title>EDUCAUSE Security Professionals Conference 2006. Summary: Defining the Security Domain</title>
 <link>http://connect.educause.edu/display/2278</link>
 <description>&lt;p class=&quot;MsoNormal&quot;&gt;&lt;span&gt;&lt;strong&gt;Defining the Security Domain&lt;/strong&gt; &lt;/span&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;/p&gt;&lt;div&gt;Marilu Goodyear, ECAR Fellow and Professor, University of Kansas&lt;/div&gt;&lt;div&gt;John H. Louis, Assistant Vice Provost for Information Systems, University of Kansas&lt;/div&gt;&lt;div&gt;&amp;nbsp;&lt;/div&gt;&lt;div&gt;This session took a detailed look at how an institution might define their various domains (network, users, and data) for writing and implementing security policy.&lt;/div&gt;&lt;div&gt;&amp;nbsp;&lt;/div&gt;&lt;div&gt;To prepare for writing and implementing security policy one needs to know for whom the policy will apply, how it will apply, and when.&amp;nbsp; This defines the scope statement for your security policy.&amp;nbsp; It is a statement of the network, people, data, and administrative structure of the institution.&amp;nbsp; &lt;/div&gt;&lt;div&gt;&amp;nbsp;&lt;/div&gt;&lt;div&gt;This can be a daunting task in the academic community.&amp;nbsp;&amp;nbsp; This session provided a grid of decision points to help identify the gates that need to be kept to ensure that freely available university data is available to all and that restricted or confidential data is protected and made available to only those who are authorized to have access.&amp;nbsp; &lt;/div&gt;&lt;div&gt;&amp;nbsp;&lt;/div&gt;&lt;div&gt;Public networks are available to anyone for a price.&amp;nbsp; Universities networks are considered private and therefore must manage the network and the privacy of both users and data.&amp;nbsp; Because of additional federal requirements it is important to understand all relevant boundaries.&amp;nbsp;&amp;nbsp; When academic institutions run their own networks, whether centralized or decentralized they are responsible the security of the data and the privacy of the user.&amp;nbsp; If the network is outsourced there must be clear contract language that delineates responsibility for these issues.&amp;nbsp; Academic institutions also must be aware of public and other networks where members of the community may have individual accounts.&amp;nbsp; &lt;/div&gt;&lt;div&gt;&amp;nbsp;&lt;/div&gt;&lt;div&gt;However, the security domain for academic institutions is limited to networks managed by the institution be they centrally managed or run by a department.&amp;nbsp; A good network policy should define the network boundary which in turn affects the definition of the security domain.&amp;nbsp; Along with creating a good network policy, the institution must also consider the &amp;ldquo;who, what, how&amp;rdquo; of providing awareness training across the boundaries. Goodyear and Louis provide a checklist to determine who is inside or outside of the security domain.&amp;nbsp; It incorporates three dimensions: who (student, employee, visiting scholar, etc), what (public system, public data, institutional data, institutional systems, etc), and how (network &amp;ndash; public or private). These are the same dimensions that determine the affect on an institution if a security breach occurs.&lt;/div&gt;&lt;div&gt;&amp;nbsp;&lt;/div&gt;&lt;div&gt;The presentation slides include a number of hypothetical examples who is in the &amp;ldquo;security domain.&amp;rdquo;&lt;/div&gt;&lt;div&gt;&amp;nbsp;&lt;/div&gt;&lt;div&gt;Defining the Security Domain &amp;ndash; &lt;a href=&quot;http://www.educause.edu/upload/presentations/SEC06/SESS04/Security%20Domain%20EDUCAUSE%20Security%20Conf%204-11-06.ppt&quot;&gt;presentation slides&lt;/a&gt;&lt;/div&gt;&lt;div&gt;&amp;nbsp;&lt;/div&gt;&lt;div&gt;Individuals in the Security Domain - &lt;a href=&quot;http://www.educause.edu/upload/presentations/SEC06/SESS04/Security%20Domain%20Why%20and%20Who.xls&quot;&gt;spreadsheet&lt;/a&gt;&lt;/div&gt;</description>
 <comments>http://connect.educause.edu/display/2278#comments</comments>
 <category domain="http://connect.educause.edu/tag/Cybersecurity+Policy/633">Cybersecurity Policy</category>
 <category domain="http://connect.educause.edu/tag/SEC06/2047">SEC06</category>
 <category domain="http://connect.educause.edu/tag/Security+Policies/254">Security Policies</category>
 <category domain="http://connect.educause.edu/tag/security+policy/1963">security policy</category>
 <pubDate>Tue, 25 Apr 2006 13:54:00 -0500</pubDate>
 <dc:creator>llarsen</dc:creator>
 <guid isPermaLink="false">2278 at http://connect.educause.edu</guid>
</item>
<item>
 <title>EDUCAUSE Security Professionals Conference 2006. Summary: The Path to Becoming a Security Professional</title>
 <link>http://connect.educause.edu/display/2282</link>
 <description>&lt;div&gt;&lt;strong&gt;The Path to Becoming a Security Professional&lt;/strong&gt;&lt;/div&gt;&lt;div&gt;&lt;strong&gt;Andrea C. Hoy&lt;/strong&gt;&lt;br /&gt;President, Orange County Chapter of the Information Systems Security Association (ISSA)&lt;/div&gt;&lt;div&gt;&amp;nbsp;&lt;/div&gt;&lt;div&gt;Notes from the 2006 Security Conference Closing General Session&lt;/div&gt;&lt;div&gt;&amp;nbsp;&lt;/div&gt;&lt;div&gt;Security org charts vary from organization to organization and your reporting structure can help or hinder you in your work and career growth.&amp;nbsp; A critical factor is &amp;ldquo;who is your boss and &lt;em&gt;who&lt;/em&gt; &lt;em&gt;that person is&lt;/em&gt;.&amp;rdquo;&amp;nbsp; Most of the time it is the long-known factor of working relationships&amp;nbsp; - who you know not what you know &amp;ndash; that helps one&amp;rsquo;s professional work and development.&amp;nbsp; &lt;/div&gt;&lt;div&gt;&amp;nbsp;&lt;/div&gt;&lt;div&gt;There are many reporting paths for security professionals.&amp;nbsp; All have pluses and minuses.&amp;nbsp; Take a look at your reporting path.&amp;nbsp; Does your path up go to the right people?&amp;nbsp; Does your path down go to the right people?&amp;nbsp; Can you communicate your work appropriately?&lt;/div&gt;&lt;div&gt;&amp;nbsp;&lt;/div&gt;&lt;div&gt;Most of the time those you are working for do not know what they want and you will need to tell them what they need to know and then tell that to them.&amp;nbsp; At the same time, they all know what they don&amp;rsquo;t want to know and so you need to figure that out in advance and couch your messages appropriately.&amp;nbsp; Institutions need to know their vulnerability and so risk assessments are important, however, some institutions don&amp;rsquo;t want to know because they think it makes them &amp;ldquo;look bad.&amp;rdquo;&amp;nbsp; How will you handle these kinds of issues?&lt;/div&gt;&lt;div&gt;&amp;nbsp;&lt;/div&gt;&lt;div&gt;Establishing policies for your work is important, especially in what outside requests you will respond to and how.&amp;nbsp; For example, no one likes email discovery requests so you need good policies to protect you.&lt;/div&gt;&lt;div&gt;&amp;nbsp;&lt;/div&gt;&lt;div&gt;Even if your organization, and your boss, understands that information security is important, most will not understand what they need and what it will cost.&amp;nbsp; Job descriptions for professional security positions vary widely and can include many different aspects.&amp;nbsp; &amp;nbsp;An annual survey notes that CISO/CSO/CRO are now considered a strategic permanent position by 58% of the respondents.&amp;nbsp; Forty-nine percent now believe that information security is a business enabler and essential to business and they believe it is no long just an overhead cost.&lt;/div&gt;&lt;div&gt;&amp;nbsp;&lt;/div&gt;&lt;div&gt;CISCO Forum 2006 statistics: &lt;/div&gt;&lt;div&gt;&amp;nbsp;&lt;/div&gt;&lt;div&gt;Education:&lt;/div&gt;&lt;ul type=&quot;disc&quot;&gt;&lt;li&gt;Academic degree &amp;ndash; 100% &lt;/li&gt;&lt;li&gt;JD &amp;ndash; 1 of 56 &lt;/li&gt;&lt;li&gt;MBA / masters 19 of 56 &lt;/li&gt;&lt;li&gt;PhD&amp;nbsp;&amp;nbsp; 2 of 56 &lt;/li&gt;&lt;/ul&gt;&lt;div&gt;Certifications: &lt;/div&gt;&lt;ul type=&quot;disc&quot;&gt;&lt;li&gt;CISSP 99% (security professional) &lt;/li&gt;&lt;li&gt;CISA&amp;nbsp; &amp;nbsp;7%&amp;nbsp;&amp;nbsp; (auditing) &lt;/li&gt;&lt;li&gt;CPP&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 3%&amp;nbsp;&amp;nbsp; (physical security) &lt;/li&gt;&lt;li&gt;CISM&amp;nbsp;&amp;nbsp;&amp;nbsp; 13%&amp;nbsp; (manager) &lt;/li&gt;&lt;/ul&gt;&lt;div&gt;The presentation slides are available at &lt;a href=&quot;http://www.educause.edu/LibraryDetailPage/666?ID=SPC0627&quot;&gt;http://www.educause.edu/LibraryDetailPage/666?ID=SPC0627&lt;/a&gt;&lt;/div&gt;&lt;div&gt;&amp;nbsp;&lt;/div&gt;&lt;div&gt;&amp;nbsp;&lt;/div&gt;&lt;div&gt;&amp;nbsp;&lt;/div&gt;</description>
 <comments>http://connect.educause.edu/display/2282#comments</comments>
 <category domain="http://connect.educause.edu/tag/Cybersecurity+Professionals/1964">Cybersecurity Professionals</category>
 <category domain="http://connect.educause.edu/tag/Professional+Development/224">Professional Development</category>
 <category domain="http://connect.educause.edu/tag/SEC06/2047">SEC06</category>
 <pubDate>Tue, 25 Apr 2006 17:12:54 -0500</pubDate>
 <dc:creator>llarsen</dc:creator>
 <guid isPermaLink="false">2282 at http://connect.educause.edu</guid>
</item>
<item>
 <title>EDUCAUSE Security Professionals Conference 2006. Summary: The Phishing Ecosystem: Analyzing the Dynamics for Maximum Defense</title>
 <link>http://connect.educause.edu/display/2281</link>
 <description>&lt;div&gt;&lt;strong&gt;The Phishing Ecosystem: Analyzing the Dynamics for Maximum Defense&lt;/strong&gt;&lt;/div&gt;&lt;div&gt;Cathy Hubbs, IT Security Coordinator, George Mason University&lt;/div&gt;&lt;div&gt;Darlene Quackenbush,&amp;nbsp; Information Security Officer, James Madison University&lt;/div&gt;&lt;div&gt;Andrew Klein, E-mail Threat Research Manager, Sonicwall&lt;/div&gt;&lt;div&gt;&amp;nbsp;&lt;/div&gt;&lt;div&gt;This corporate presentation was essentially an overview of the Phishing ecosystem with representatives from two institutions.&lt;/div&gt;&lt;div&gt;&amp;nbsp;&lt;/div&gt;&lt;div&gt;Phishers need the following to create and implement an attack.&lt;/div&gt;&lt;div&gt;-&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Email list&lt;/div&gt;&lt;div&gt;-&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Develop the attack&lt;/div&gt;&lt;div&gt;-&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;Locate sites to send phishing email from (compromised machines - botnets) &lt;/div&gt;&lt;div&gt;-&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Locate sites to host the phishing site &amp;ndash; usually 5-10-20 sites&lt;/div&gt;&lt;div&gt;-&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Launch the coordinated attack &lt;/div&gt;&lt;div&gt;-&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;Collect info&lt;/div&gt;&lt;div&gt;-&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;Transform into cash &lt;/div&gt;&lt;div&gt;&amp;nbsp;&lt;/div&gt;&lt;div&gt;Typical attack goes out to 2million email addresses&lt;/div&gt;&lt;div&gt;5% get to end user (100.000)&lt;/div&gt;&lt;div&gt;5% click on the link&lt;/div&gt;&lt;div&gt;2% enter data&lt;/div&gt;&lt;div&gt;Good for $100K&lt;/div&gt;&lt;div&gt;&amp;nbsp;&lt;/div&gt;&lt;div&gt;In reality, phishing kits are available and there are a number of phishing gangs&lt;/div&gt;&lt;div&gt;&amp;nbsp;&lt;/div&gt;&lt;div&gt;9715 phishing sites in Jan 06&amp;nbsp; &lt;/div&gt;&lt;div&gt;34% are US&amp;nbsp; &lt;/div&gt;&lt;div&gt;31% on &amp;ldquo;real&amp;rdquo; web servers that were hacked -&lt;/div&gt;&lt;div&gt;Only need to run the phish for 8 hours.&lt;/div&gt;&lt;div&gt;&amp;nbsp;&lt;/div&gt;&lt;div&gt;Eighty-two percent of incoming mail is still spam, virus, etc.&amp;nbsp; These spurious emails need to be caught and quarantined.&amp;nbsp; Most institutions look for some technical help to block the phish emails.&amp;nbsp; However, technology can not stop the problem. &lt;/div&gt;&lt;div&gt;&amp;nbsp;&lt;/div&gt;&lt;div&gt;Why students are more at risk:&lt;/div&gt;&lt;ul type=&quot;disc&quot;&gt;&lt;li&gt;Some students are impulsive and gullible &lt;/li&gt;&lt;li&gt;Students are trying a lot of new things &amp;ndash; so they tend to be more socially open and technically experimental and will reply to something that comes in IM etc. &lt;/li&gt;&lt;li&gt;Nigerian scams &amp;ndash; social engineering scams have been around a long time to older people have seen these.&amp;nbsp; &lt;/li&gt;&lt;li&gt;As a rule students haven&amp;rsquo;t been burned by fraud and so are more trusting. &lt;/li&gt;&lt;/ul&gt;&lt;div&gt;Phishing awareness education ideas&lt;/div&gt;&lt;ul type=&quot;disc&quot;&gt;&lt;li&gt;General security awareness programs &lt;/li&gt;&lt;li&gt;Online reviews and refreshers &lt;/li&gt;&lt;li&gt;Face to face discussions in the fall for both incoming students/parents &lt;/li&gt;&lt;li&gt;Instructors and advisors should tell students &amp;ldquo;how&amp;rdquo; to expect their emails &lt;/li&gt;&lt;li&gt;Central IT with liaisons can push out messages via liaisons to their respective departments. &lt;/li&gt;&lt;li&gt;Look for ways to get their attention all year round and in multiple formats &lt;/li&gt;&lt;/ul&gt;&lt;div&gt;The presentation slides are available at &lt;a href=&quot;http://www.educause.edu/LibraryDetailPage/666?ID=SPC0603&quot;&gt;http://www.educause.edu/LibraryDetailPage/666?ID=SPC0603&lt;/a&gt;&lt;/div&gt;&lt;div&gt;&amp;nbsp;&lt;/div&gt;&lt;div&gt;&amp;nbsp;&lt;/div&gt;</description>
 <comments>http://connect.educause.edu/display/2281#comments</comments>
 <category domain="http://connect.educause.edu/tag/Cybersecurity/56">Cybersecurity</category>
 <category domain="http://connect.educause.edu/tag/Phishing/476">Phishing</category>
 <category domain="http://connect.educause.edu/tag/SEC06/2047">SEC06</category>
 <category domain="http://connect.educause.edu/tag/Security+Awareness/258">Security Awareness</category>
 <pubDate>Tue, 25 Apr 2006 17:06:29 -0500</pubDate>
 <dc:creator>llarsen</dc:creator>
 <guid isPermaLink="false">2281 at http://connect.educause.edu</guid>
</item>
<item>
 <title>EDUCAUSE Security Professionals Conference 2006. Summary:System-wide Strategies for Achieving IT Security at Univ. of California</title>
 <link>http://connect.educause.edu/display/2280</link>
 <description>&lt;div&gt;&lt;strong&gt;System-wide Strategies for Achieving IT Security at the University of California&lt;/strong&gt;&lt;/div&gt;&lt;div&gt;Jacqueline Craig, Director of Policy, University of California Office of the President&lt;/div&gt;&lt;div&gt;David H. Walker, Director of Advanced Technology, University of California Office of the President&lt;/div&gt;&lt;div&gt;&amp;nbsp;&lt;/div&gt;&lt;div&gt;How do you effectively achieve appropriate stewardship of both personal and restricted information which is used across an institution&amp;rsquo;s academic, administrative, and other operations?&amp;nbsp; This session took a close look at the efforts of the University of California system efforts.&lt;/div&gt;&lt;div&gt;&amp;nbsp;&lt;/div&gt;&lt;div&gt;UC has experienced a number of serious security breaches across the 18 campuses, centers and labs.&amp;nbsp; In 2003, California passed legislation requiring notification if there is a reasonable belief that unauthorized access of information has occurred and there is reason to believe that privacy of individuals has been compromised.&amp;nbsp; UC responded by instituting a university-wide security workgroup to come up with solutions.&amp;nbsp; The workgroup was comprised of faculty, deans, vice-chancellors, general counsel, security officers, CIOs and directors.&lt;/div&gt;&lt;div&gt;&amp;nbsp;&lt;/div&gt;&lt;div&gt;The working group agreed upon a number of recommendations: &lt;/div&gt;&lt;ul type=&quot;disc&quot;&gt;&lt;li&gt;Leadership actions to achieve accountability &lt;/li&gt;&lt;li&gt;University-wide communication and security education &amp;amp; training &lt;/li&gt;&lt;li&gt;Stronger IT security policies &lt;/li&gt;&lt;li&gt;Risk assessment guidelines and mitigation with focus on both academic and administrative strategies. &lt;/li&gt;&lt;li&gt;Campus-based encryption strategies &lt;/li&gt;&lt;li&gt;Improved security incident guidelines &lt;/li&gt;&lt;/ul&gt;&lt;div&gt;This session emphasized encryption and forensic decisions. &lt;/div&gt;&lt;div&gt;&amp;nbsp;&lt;/div&gt;&lt;div&gt;Encryption at the UC will include:&lt;/div&gt;&lt;div&gt;&amp;nbsp;&lt;/div&gt;&lt;div&gt;Encryption for data when stored in a location that does not have appropriate physical security and access controls.&amp;nbsp; This includes whole disk encryption including mobile devices, file encryption for data that will be &amp;ldquo;carried&amp;rdquo; or transmitted, and database encryption.&amp;nbsp; &amp;nbsp;Encrypted backups are also under consideration.&amp;nbsp; UC is setting up appropriate infrastructure and working on contracts with vendors at this time.&amp;nbsp; Note that all copies of restricted data are being assessed.&lt;/div&gt;&lt;div&gt;&amp;nbsp;&lt;/div&gt;&lt;div&gt;Encryption for data transmission at &amp;ldquo;all&amp;rdquo; times.&amp;nbsp; This will include file transfers, email, network printer communication, remote file services, and VPN.&lt;/div&gt;&lt;div&gt;&amp;nbsp;&lt;/div&gt;&lt;div&gt;A workflow plan and a communication plan for incident response are being developed.&lt;/div&gt;&lt;div&gt;&amp;nbsp;&lt;/div&gt;&lt;div&gt;Response will include the following initial steps:&lt;/div&gt;&lt;div&gt;Communication to appropriate staff/teams and others as required&lt;/div&gt;&lt;div&gt;Maintenance of a log of actions&lt;/div&gt;&lt;div&gt;Securing the area/facility&lt;/div&gt;&lt;div&gt;Determining the need for forensics and collecting forensic evidence as possible&lt;/div&gt;&lt;div&gt;Regaining control and analyzing the situation.&lt;/div&gt;&lt;div&gt;&amp;nbsp;&lt;/div&gt;&lt;div&gt;Forensic services are being put into place including established local teams and outside help/backup when needed.&amp;nbsp; Operational responsibility is at the campus level to preserve evidence first, provide audit log analysis, and restore service later.&amp;nbsp; Having swaps available critical infrastructure where possible.&amp;nbsp; It was noted that managers are held responsible for doing the right things in preparation and at the time of an incident but they are not held responsible if there is a breach.&lt;/div&gt;&lt;div&gt;&amp;nbsp;&lt;/div&gt;&lt;div&gt;UC is establishing an &amp;ldquo;instant services&amp;rdquo; vendor service to ensure chain of evidence if needed and pre-set agreements and process procedures for incidents with law enforcement so timely decisions are easier and good relations are maintained.&amp;nbsp; &lt;/div&gt;&lt;div&gt;&amp;nbsp;&lt;/div&gt;&lt;div&gt;Guidelines are being established for management of application log, system logs, network device logs, change management logs, and others as appropriate, ie, surveillance, physical access, etc.&amp;nbsp; They emphasized the importance of building a case for taking logs and putting them into a centrally located log management service that is a repository with appropriate tools. &amp;nbsp;&amp;nbsp;&lt;/div&gt;&lt;div&gt;&amp;nbsp;&lt;/div&gt;&lt;div&gt;The presentation went into depth on each of the types of logs and the content that can be monitored for uses such as access, change, cost allocation, malfunctions, resource utilization, user activity, and, of course, security incidents.&lt;/div&gt;&lt;div&gt;&amp;nbsp;&lt;/div&gt;&lt;div&gt;As university records, logs must be appropriately managed and preserved and able to be retrieved as needed.&amp;nbsp; Retention periods must balance confidentiality of specific individual&amp;rsquo;s activities, the need to support investigations, and the cost of retaining the records within what is legally required unless there are extenuated circumstances.&lt;/div&gt;&lt;div&gt;&amp;nbsp;&lt;/div&gt;&lt;div&gt;The presentation slides are available at &lt;a href=&quot;http://www.educause.edu/upload/presentations/SEC06/SESS20/EDUCAUSESecurity.2006-04-11.ppt&quot;&gt;http://www.educause.edu/upload/presentations/SEC06/SESS20/EDUCAUSESecurity.2006-04-11.ppt&lt;/a&gt;&lt;/div&gt;&lt;div&gt;&amp;nbsp;&lt;/div&gt;&lt;div&gt;&amp;nbsp;&lt;/div&gt;&lt;div&gt;&amp;nbsp;&lt;/div&gt;</description>
 <comments>http://connect.educause.edu/display/2280#comments</comments>
 <category domain="http://connect.educause.edu/tag/Cybersecurity/56">Cybersecurity</category>
 <category domain="http://connect.educause.edu/tag/Data+Security/256">Data Security</category>
 <category domain="http://connect.educause.edu/tag/SEC06/2047">SEC06</category>
 <category domain="http://connect.educause.edu/tag/Security+Architecture/262">Security Architecture</category>
 <category domain="http://connect.educause.edu/tag/Security+Planning/249">Security Planning</category>
 <category domain="http://connect.educause.edu/tag/Security+Policies/254">Security Policies</category>
 <category domain="http://connect.educause.edu/tag/Security+Risk+Assessment+and+Analysis/261">Security Risk Assessment and Analysis</category>
 <pubDate>Tue, 25 Apr 2006 16:59:57 -0500</pubDate>
 <dc:creator>llarsen</dc:creator>
 <guid isPermaLink="false">2280 at http://connect.educause.edu</guid>
</item>
<item>
 <title>EDUCAUSE Security Professionals Conference 2006.Summary: Implementing HIPAA Security Rule Training Program for Sys Admins at ECU</title>
 <link>http://connect.educause.edu/display/2279</link>
 <description>&lt;span&gt;&lt;span&gt;&lt;div&gt;Implementing a HIPAA Security Rule Training Program for System Administrators at East Carolina University.&amp;nbsp;&amp;nbsp;&amp;nbsp; Carol Davis, DRP Coordinator, East Carolina University&lt;/div&gt;&lt;div&gt;&amp;nbsp;&lt;/div&gt;&lt;div&gt;This session walked us through the planning and implementation process that created a training program for systems administrators at ECU for the HIPAA Security Rule.&amp;nbsp; The program was added to a privacy program that already existed but was in need of revision.&amp;nbsp; A key resource was the SANS Press HIPAA Security Implementation book. &lt;/div&gt;&lt;div&gt;&amp;nbsp;&lt;/div&gt;&lt;div&gt;Key questions for the planning process were&lt;/div&gt;&lt;ul type=&quot;disc&quot;&gt;&lt;li&gt;What is the training? &lt;/li&gt;&lt;li&gt;Who needs the training? &lt;/li&gt;&lt;li&gt;What are the overall project alternatives? &lt;/li&gt;&lt;li&gt;How will it be delivered? &lt;/li&gt;&lt;li&gt;What will the cost be? &lt;/li&gt;&lt;li&gt;What is the &amp;ldquo;completion&amp;rdquo; point? &lt;/li&gt;&lt;li&gt;How will effectiveness be measured? &lt;/li&gt;&lt;li&gt;How often must the training be taken? &lt;/li&gt;&lt;li&gt;Who will do the Public Relations on the project and what will be included? &lt;/li&gt;&lt;li&gt;Who will continue to update the training content and monitor? &lt;/li&gt;&lt;/ul&gt;&lt;div&gt;The project was developed over three months using their HIPAA Committee as the key advisory group. &amp;nbsp;This committee developed the policies for the project.&amp;nbsp; &amp;nbsp;Time was spent on fully understanding the rule sets: the privacy rule, the transaction and code set rule, and the security rule.&amp;nbsp; Technical safeguards and related policies were to be included in the training. &amp;nbsp;Initial options considered included purchasing a full set of modules or customizing the training using Blackboard which was already an established resource.&amp;nbsp; &lt;/div&gt;&lt;div&gt;&amp;nbsp;&lt;/div&gt;&lt;div&gt;Awareness training was to be included for all members of their health care workforce including management.&amp;nbsp; Visitors and students complete an abbreviated version of the training and students take a web-based quiz and take the results to their faculty.&lt;/div&gt;&lt;div&gt;&amp;nbsp;&lt;/div&gt;&lt;div&gt;The course objectives were:&lt;/div&gt;&lt;ul type=&quot;disc&quot;&gt;&lt;li&gt;Familiarity with HIPAA and the security rule &lt;/li&gt;&lt;li&gt;Understanding rule sets &lt;/li&gt;&lt;li&gt;Understanding why both Privacy and Security rules are needed &lt;/li&gt;&lt;li&gt;Understanding how the rule applies to the trainee. &lt;/li&gt;&lt;li&gt;Understanding safeguards &lt;/li&gt;&lt;li&gt;Review of security policies &lt;/li&gt;&lt;li&gt;Understanding technical security awareness &lt;/li&gt;&lt;li&gt;Understanding individual responsibility for protecting health information &lt;/li&gt;&lt;/ul&gt;&lt;div&gt;&amp;nbsp;&lt;/div&gt;&lt;div&gt;The content was created in five sections:&lt;/div&gt;&lt;ul type=&quot;disc&quot;&gt;&lt;li&gt;Overview and structure &lt;/li&gt;&lt;li&gt;Security rule principles &lt;/li&gt;&lt;li&gt;ITCS safeguards &lt;/li&gt;&lt;li&gt;Security awareness &lt;/li&gt;&lt;li&gt;Security incident notifications &lt;/li&gt;&lt;/ul&gt;&lt;div&gt;&amp;nbsp;&lt;/div&gt;&lt;div&gt;A Blackboard course was populated &amp;amp; information on the program was distributed &lt;/div&gt;&lt;div&gt;Training guidelines were provided electronically and course deadlines were included&lt;/div&gt;&lt;div&gt;Management helped to ensure course completion.&lt;/div&gt;&lt;div&gt;&amp;nbsp;&lt;/div&gt;&lt;div&gt;Current knowledge was sampled by having administrators complete the quiz before the online training and again afterwards.&amp;nbsp; The specific training assessment is a quiz of 10 questions based on HIPAA privacy but concentrating on security specifics.&amp;nbsp; Instant feedback is provided for both correct and incorrect answers.&amp;nbsp; The training and quiz can be retaken to improve learning.&amp;nbsp; Certificates are awarded for 80% or better scores.&amp;nbsp; The certificates are popular and being hung on office walls and added to resumes.&lt;/div&gt;&lt;div&gt;&amp;nbsp;&lt;/div&gt;&lt;div&gt;Each person taking the training is asked to complete an evaluation survey that includes the question of the application of the training to their position and a blank field for additional comments.&amp;nbsp; &lt;/div&gt;&lt;div&gt;&amp;nbsp;&lt;/div&gt;&lt;div&gt;The latest phase is to more fully utilize Blackboard with one training package that includes two modules and to incorporate student training into the system as well as reviewing role-based training opportunities.&amp;nbsp; HR is assisting in identifying new departments or individual positions that require compliancy or other special training.&amp;nbsp; And, of course, the training content is continually reviewed and revised when appropriate.&lt;/div&gt;&lt;div&gt;&amp;nbsp;&lt;/div&gt;&lt;div&gt;HIPAA Security Rule Training &amp;ndash; &lt;a href=&quot;http://www.educause.edu/upload/presentations/SEC06/SESS25/HIPAA%20Security%20Rule%20EDUCAUSE.ppt&quot;&gt;presentation slides&lt;/a&gt;&lt;/div&gt;&lt;div&gt;&amp;nbsp;&lt;/div&gt;&lt;div&gt;HIPAA System Admin Training Guidelines &amp;ndash; &lt;a href=&quot;http://www.educause.edu/upload/presentations/SEC06/SESS25/Blackboard%20Guidelines%20-%20HIPAA%20System%20Admin%20Training.doc&quot;&gt;4 page document&lt;/a&gt; &amp;ndash; instructions for training program.&lt;/div&gt;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;</description>
 <comments>http://connect.educause.edu/display/2279#comments</comments>
 <category domain="http://connect.educause.edu/tag/HIPAA/1678">HIPAA</category>
 <category domain="http://connect.educause.edu/tag/SEC06/2047">SEC06</category>
 <category domain="http://connect.educause.edu/tag/Security+Awareness/258">Security Awareness</category>
 <category domain="http://connect.educause.edu/tag/Training/230">Training</category>
 <pubDate>Tue, 25 Apr 2006 14:31:00 -0500</pubDate>
 <dc:creator>llarsen</dc:creator>
 <guid isPermaLink="false">2279 at http://connect.educause.edu</guid>
</item>
</channel>
</rss>
