System-wide Strategies for Achieving IT Security at the University of California
Jacqueline Craig, Director of Policy, University of California Office of the President
David H. Walker, Director of Advanced Technology, University of California Office of the President
How do you effectively achieve appropriate stewardship of both personal and restricted information which is used across an institution’s academic, administrative, and other operations? This session took a close look at the efforts of the University of California system efforts.
UC has experienced a number of serious security breaches across the 18 campuses, centers and labs. In 2003, California passed legislation requiring notification if there is a reasonable belief that unauthorized access of information has occurred and there is reason to believe that privacy of individuals has been compromised. UC responded by instituting a university-wide security workgroup to come up with solutions. The workgroup was comprised of faculty, deans, vice-chancellors, general counsel, security officers, CIOs and directors.
The working group agreed upon a number of recommendations:
- Leadership actions to achieve accountability
- University-wide communication and security education & training
- Stronger IT security policies
- Risk assessment guidelines and mitigation with focus on both academic and administrative strategies.