<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0" xml:base="http://connect.educause.edu" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd">
<channel>
 <title>EDUCAUSE | Audit and Compliance</title>
 <link>http://connect.educause.edu/browse/content/blog/4421</link>
 <image>
    <title>EDUCAUSE CONNECT</title> 
    <link>http://connect.educause.edu/browse/content/blog/4421</link> 
    <url>http://connect.educause.edu/educause/images/e_rss.png</url> 
 </image>

  <itunes:subtitle>events, concepts, and conversation from EDUCAUSE</itunes:subtitle>
  <itunes:author>The EDUCAUSE Podcast Crew</itunes:author>
  <itunes:summary>EDUCAUSE is a nonprofit association whose mission is to advance higher education by promoting the intelligent use of information technology.  Our podcasts provide information about a range of topics including Leadership, Policy and Law, Teaching and Learning, Emerging Technologies, Open Source, Research Computing, Cyberinfrastructure, and Digitial Libraries. </itunes:summary>
  <itunes:new-feed-url>http://connect.educause.edu/browse/content/node/691/list/feed</itunes:new-feed-url>
  <itunes:image href="http://connect.educause.edu/educause/images/e_rss.png" />
  <itunes:category text="Education">
  	<itunes:category text="Education Technology"/>
  	<itunes:category text="Higher Education"/>
  </itunes:category>
  <itunes:category text="Technology">
  	<itunes:category text="Tech News"/>
  </itunes:category>

 <description>Recent blog entries tagged with Audit and Compliance.</description>
 <language>en</language>

<item>
 <title>Building a Security Program to Include Metrics</title>
 <link>http://connect.educause.edu/display/47167</link>
 <description>&lt;p&gt;In &amp;quot;&lt;a href=&quot;http://connect.educause.edu/Library/EDUCAUSE+Quarterly/SecurityMetricsASolutioni/47083&quot;&gt;Security Metrics: A Solution in Search of a Problem&lt;/a&gt;&amp;quot;, a recent &lt;em&gt;&lt;a href=&quot;http://connect.educause.edu/Library/EDUCAUSE+Quarterly/EDUCAUSEQuarterlyMagazine/46014&quot;&gt;EDUCAUSE Quarterly&lt;/a&gt;&lt;/em&gt; article, Joel Rosenblatt (Manager of Computer and Network Security, Columbia University) describes how the creation and collection of appropriate metrics can enhance an institution&#039;s security program. Learn about some potential metrics in the following areas: policy and compliance, network and machine monitoring, outreach and education, legal compliance, authorization and authentication, asset protection, and privacy. &lt;/p&gt;</description>
 <comments>http://connect.educause.edu/display/47167#comments</comments>
 <category domain="http://connect.educause.edu/tag/Audit+and+Compliance/4421">Audit and Compliance</category>
 <category domain="http://connect.educause.edu/tag/Security+Awareness/258">Security Awareness</category>
 <category domain="http://connect.educause.edu/tag/Security+Implementation/265">Security Implementation</category>
 <category domain="http://connect.educause.edu/tag/Security+Metrics/5521">Security Metrics</category>
 <category domain="http://connect.educause.edu/tag/Security+Planning/249">Security Planning</category>
 <category domain="http://connect.educause.edu/tag/Security+Policies/254">Security Policies</category>
 <category domain="http://connect.educause.edu/tag/Security+Task+Force+Announcements/699">Security Task Force Announcements</category>
 <pubDate>Wed, 13 Aug 2008 15:04:31 -0500</pubDate>
 <dc:creator>vvogel</dc:creator>
 <guid isPermaLink="false">47167 at http://connect.educause.edu</guid>
</item>
<item>
 <title>E07 Podcast: Improving IT Governance Through Formal Change Management</title>
 <link>http://connect.educause.edu/display/45625</link>
 <description>&lt;p&gt;This 24-minute podcast recorded during the EDUCAUSE 2007 Annual Conference features &lt;a href=&quot;http://www.educause.edu/PeerDirectory/750?ID=110150&quot;&gt;Danny Smith&lt;/a&gt;, Senior Director IT Services, Marquette University speaking on &lt;a href=&quot;http://www.educause.edu/E07/Program/11073?Product_Code=E07/SESS020&quot;&gt;Improving IT Governance Through Formal Change Management&lt;/a&gt;.&lt;/p&gt;&lt;p&gt;The session abstract:&lt;/p&gt;&lt;p&gt;Changes to complex systems require careful planning and coordination to ensure additional incidents are not created in the production environment. This presentation will detail how Marquette University implemented ITIL-based change management to stabilize the infrastructure, gain visibility of work, and comply with financial audits.&lt;/p&gt;&lt;p&gt;&lt;img alt=&quot;Sponsored by Real Networks&quot; height=&quot;26&quot; src=&quot;http://edit.educause.edu/elements/images/Uploaded_Images/CONNECT/podcast_Sponsor_real.png&quot; width=&quot;315&quot; /&gt;&lt;/p&gt;</description>
 <comments>http://connect.educause.edu/display/45625#comments</comments>
 <enclosure url="http://connect.educause.edu/files/kellywalker-E07-ImprovingITGovernance.mp3" length="17245981" type="audio/mpeg" />
 <category domain="http://connect.educause.edu/tag/Audit+and+Compliance/4421">Audit and Compliance</category>
 <category domain="http://connect.educause.edu/tag/Change+Management/202">Change Management</category>
 <category domain="http://connect.educause.edu/tag/EDUCAUSE2007/5576">EDUCAUSE2007</category>
 <category domain="http://connect.educause.edu/tag/Podcasts/691">Podcasts</category>
 <category domain="http://connect.educause.edu/tag/Project+Management/204">Project Management</category>
 <pubDate>Fri, 16 Nov 2007 10:31:15 -0600</pubDate>
 <dc:creator>kellywalker</dc:creator>
 <guid isPermaLink="false">45625 at http://connect.educause.edu</guid>
</item>
<item>
 <title>EDUCAUSE Security Conference: Herding cats and campuses: addressing distributed security and compliance issues</title>
 <link>http://connect.educause.edu/display/24188</link>
 <description>&lt;div&gt;Summary&lt;/div&gt;&lt;div&gt;Herding cats and campuses:&amp;nbsp;addressing distributed security and compliance issues&lt;/div&gt;&lt;div&gt;Kathleen Kimball, Senior Director, ITS Security Operations and Services, PennState&lt;/div&gt;&lt;div&gt;David Lindstrom, Chief Privacy Office, PennState&lt;/div&gt;&lt;div&gt;&amp;nbsp;&lt;/div&gt;&lt;div&gt;2007 EDUCAUSE Security Professionals Conference&lt;/div&gt;&lt;div&gt;Thursday, April 12, 2007&lt;/div&gt;&lt;div&gt;Denver, CO&lt;/div&gt;&lt;div&gt;&amp;nbsp;&lt;/div&gt;&lt;div&gt;Notes:&lt;/div&gt;&lt;div&gt;Kimball and Lindstrom began their presentation with a quick overview of their statewide environment which serves 83,721 students plus more than 60K staff and faculty at 24 campuses, a medical school, agriculture extensions, and their World Campus online learning program.&amp;nbsp;They have one backbone network statewide and push terabits of data.&lt;/div&gt;&lt;div&gt;&amp;nbsp;&lt;/div&gt;&lt;div&gt;Their distributed governance and other issues make the security problem more difficult.&amp;nbsp;Many users aren&amp;rsquo;t doing the &amp;ldquo;traditional&amp;rdquo; things like teaching and many are &amp;ldquo;home users&amp;rdquo; and that&amp;rsquo;s the level of their skills as well.&amp;nbsp;In addition, culturally there is a tradition of independence among the campuses and the emphasis on process by committee and consensus makes for a slow process.&lt;/div&gt;&lt;div&gt;&amp;nbsp;&lt;/div&gt;&lt;div&gt;They see their major security threats coming from constant hostile probes in a situation where security is often dependent on non-technical users.&lt;/div&gt;&lt;div&gt;&amp;nbsp;&lt;/div&gt;&lt;div&gt;What&amp;rsquo;s happening in the security arena?&lt;/div&gt;&lt;div&gt;Watching trends they note that there is &lt;/div&gt;&lt;ul type=&quot;disc&quot;&gt;&lt;li&gt;growing sophistication of network attacks (bots, bots, and more bots) &lt;/li&gt;&lt;li&gt;increasing complexity of detecting and removing residual malicious software&lt;/li&gt;&lt;li&gt;growing number of vendor security updates to be handled&lt;/li&gt;&lt;li&gt;Increasingly mobile population of Internet capable devices connecting to unmanaged networks and then returning to PennState nets.&lt;/li&gt;&lt;/ul&gt;&lt;div&gt;At the same time they see &lt;/div&gt;&lt;ul type=&quot;disc&quot;&gt;&lt;li&gt;decreasing amount of time for global spread of worms and other malware&lt;/li&gt;&lt;li&gt;less ability to stop intruders at the network border&lt;/li&gt;&lt;li&gt;less time available to keep up with vendor security updates&lt;/li&gt;&lt;li&gt;Decreasing window of time to detect and deter network based attacks.&lt;/li&gt;&lt;/ul&gt;&lt;div&gt;Legal and regulatory landscape&lt;/div&gt;&lt;div&gt;Lindstrom suggested that when in doubt, laws are passed, or policy is written, in an attempt to control what is increasingly becoming uncontrollable.&amp;nbsp;He pointed out the 9 or so policies that PennState has produced relating to security and privacy.&amp;nbsp;&lt;/div&gt;&lt;div&gt;&amp;nbsp;&lt;/div&gt;&lt;div&gt;Lindstrom and Kimball represent the two sides of the house: &amp;nbsp;administrative and academic and find that they work together well in their respective institutional duties to reasonably secure sensitive data in their care.&lt;/div&gt;&lt;div&gt;&amp;nbsp;&lt;/div&gt;&lt;div&gt;At PennState, the network is distributed and so is the responsibility for data security.&amp;nbsp;Each Dean or Administrative Officer is responsible for the data security policies and security implementations in their respective units.&amp;nbsp;These local policies have the force of overall university policy and are intended to be guidelines for systems administrators.&lt;/div&gt;&lt;div&gt;&amp;nbsp;&lt;/div&gt;&lt;div&gt;In order for any unit to connect to the university network they must have a network administrative, technical, and security contact.&amp;nbsp;These folks are key in incident notifications.&amp;nbsp;There are financial officers in each unit and they help with compliance issues.&amp;nbsp;Currently the biggest problem is that only a network address is generally knows for university systems when an incident response begins.&lt;/div&gt;&lt;div&gt;&amp;nbsp;&lt;/div&gt;&lt;div&gt;Lindstrom noted that units handing administrative data have additional requirements that are outlined in their &amp;ldquo;Trusted Network Specifications&amp;rdquo; and access to the net is not given unless they sign in ink that they&amp;rsquo;ll be responsible.&amp;nbsp;Units with an exception to hold SSNs have even more requirements.&amp;nbsp;In spite of these policies and security precautions--there is a perceived gap between policy and performance for a number of reasons.&amp;nbsp;Those reasons are primarily the plethora of compliance issues such as FERPA, HIPPA, Graham Leach Bliley, Pennsylvania&amp;rsquo;s Breach of Personal Information Notification, PCI-DSS (credit card industry standards) and undoubtedly more coming.&lt;/div&gt;&lt;div&gt;&amp;nbsp;&lt;/div&gt;&lt;div&gt;PennState feels that they must do better.&lt;/div&gt;&lt;ul type=&quot;disc&quot;&gt;&lt;li&gt;Improving the state of privacy and network security practices is essential and it is a distributed problem that needs a distributed solution&lt;/li&gt;&lt;li&gt;Raising the bar with regard to security practices and policies, ability to comply with existing policies and laws, and increase their agility for responding to new laws that come along.&amp;nbsp;&lt;/li&gt;&lt;/ul&gt;&lt;div&gt;--and all of this across the 24+ fiefdoms that comprise PennState.&lt;/div&gt;&lt;div&gt;&amp;nbsp;&lt;/div&gt;&lt;div&gt;From this the PennState Information Privacy and Security (IPAS) project was born.&lt;/div&gt;&lt;div&gt;It developed from a joint effort between ITS and the Corporate Controller who sold university leadership on the gap between policy and practice.&amp;nbsp;It is sponsored jointly by the Provost and CFO and the responsibility for oversight rests on the CIO and University Controller.&amp;nbsp;Similarly, Kimball and Lindstrom represent the two sides of the house in their roles.&amp;nbsp;It is a big enough central project that it was split 3 ways between budgets/budget executives.&amp;nbsp;Audit, finance, corporate controller and firewall audit (small piece of the overall) was something they could all get their arms around.&lt;/div&gt;&lt;div&gt;&amp;nbsp;&lt;/div&gt;&lt;div&gt;IPAS&lt;/div&gt;&lt;div&gt;This is a multi-year, multi-phase, university-wide project with some overlap in the timing of the phases.&lt;/div&gt;&lt;div&gt;Phase 1 &amp;ndash; evaluate and remediate if necessary PCI-DSS systems and networks&lt;/div&gt;&lt;div&gt;Phase 2 &amp;ndash; take lessons learned and apply to systems and networks handling sensitive university information&lt;/div&gt;&lt;div&gt;&amp;nbsp;&lt;/div&gt;&lt;div&gt;Three project team members were drafted from existing staff for two year assignments to the project: Project Manager, Senior Network Analyst, and Project Technical Coordinator.&amp;nbsp;Copies of the brochure for IPAS were distributed to the session attendees and it was noted that it includes these three staff members, their responsibilities, and their contact information.&amp;nbsp;Leadership from distributed units provided the staff resources.&lt;/div&gt;&lt;div&gt;&amp;nbsp;&lt;/div&gt;&lt;div&gt;Lindstrom and Kimball listed the specifics of the two phases. &lt;/div&gt;&lt;div&gt;Phase 1 included detailed requirements, payment card industry data security standards (also covered in their brochure), and a qualified data security company was engaged.&amp;nbsp;&amp;nbsp; Incident response involving credit card data is now centralized.&amp;nbsp;If someone is compromised it&amp;rsquo;s a compromise for the unit.&amp;nbsp;Detail for a sample requirement of Phase 1 was covered for &amp;ldquo;build and maintain a secure network&amp;rdquo; during the session and full details for all 12 key requirements are available at http://ipas.psu.edu. &lt;/div&gt;&lt;div&gt;&amp;nbsp;&lt;/div&gt;&lt;div&gt;Phase 2 included overall privacy and networking security improvement and review and improvement of associated policy.&amp;nbsp;Lindstrom and Kimball also covered 12 selected tasks in Phase 2 which basically outline a thorough and detailed review of the entire security infrastructure at PennState including people, policy, and technology &amp;ndash; and physical safety is also being examined. &amp;nbsp;&amp;nbsp;Two specifics: Distributed risk assessment process refined and Improve security role in the software development lifecycle.&lt;/div&gt;&lt;div&gt;&amp;nbsp;&lt;/div&gt;&lt;div&gt;They noted that they are moving quite fast and architecture changes will be very sensitive because they are so fine tuned at the moment.&amp;nbsp;In addition, there is the question of funding to do the necessary steps.&amp;nbsp;No one knows for sure where the money will come from to do all of this.&lt;/div&gt;&lt;div&gt;&amp;nbsp;&lt;/div&gt;&lt;div&gt;Additional points:&lt;/div&gt;&lt;div&gt;Support is crucial from the President and Provost to the Budget Executive and other unit IT and financial personnel must be involved as designated by the Budget Executive&lt;/div&gt;&lt;div&gt;&amp;nbsp;&lt;/div&gt;&lt;div&gt;Technical contacts, financial contacts, administrative contacts must all be assigned and there will be mandatory training for everyone in the project.&amp;nbsp;At the moment 78 of the possible 90 are registered for training&lt;/div&gt;&lt;div&gt;&amp;nbsp;&lt;/div&gt;&lt;div&gt;IPAS will continue to define and implement cost effective solutions towards the objectives in the two phases.&lt;/div&gt;&lt;div&gt;&amp;nbsp;&lt;/div&gt;&lt;div&gt;In Phase 2 Faculty will be involved in the evaluation.&amp;nbsp;&lt;/div&gt;&lt;div&gt;For training the curriculum covers security awareness and compliance.&lt;/div&gt;&lt;div&gt;&amp;nbsp;&lt;/div&gt;&lt;div&gt;They noted that many units don&amp;rsquo;t want to believe the documentation so it has been necessary to obtain outside consultants on regulatory issues.&lt;/div&gt;&lt;div&gt;&amp;nbsp;&lt;/div&gt;&lt;div&gt;Common issues&lt;/div&gt;&lt;div&gt;Slow vendor responses&lt;/div&gt;&lt;div&gt;Getting right language in the contracts and oversight (we don&amp;rsquo;t want to get in the way of business process, for example, the idea of wireless vending in the field house)&lt;/div&gt;&lt;div&gt;Storage of paper records is not good&lt;/div&gt;&lt;div&gt;They may now be compliant but didn&amp;rsquo;t get rid of the old stuff that isn&amp;rsquo;t&lt;/div&gt;&lt;div&gt;Skill level at the local level isn&amp;rsquo;t in place yet&lt;/div&gt;&lt;div&gt;Shadow systems cause many problems.&lt;/div&gt;&lt;div&gt;&amp;nbsp;&lt;/div&gt;&lt;div&gt;Some questions:&lt;/div&gt;&lt;div&gt;Measurement to date?&amp;nbsp;Will be easier in Phase 1 than in Phase 2?&lt;/div&gt;&lt;div&gt;&amp;nbsp;&lt;/div&gt;&lt;div&gt;What happens after the 2 years &amp;ndash; Phase 3?&amp;nbsp;What will it be?&amp;nbsp;Perhaps ongoing issues that will not go away.&lt;/div&gt;&lt;div&gt;&amp;nbsp;&lt;/div&gt;&lt;div&gt;The presentation slides for &amp;ldquo;Herding cats and campuses:&amp;nbsp;addressing distributed security and compliance issues&amp;rdquo; is available on the conference website at http://www.educause.edu/SEC07/Program/11616?PRODUCT_CODE=SEC07/SESS32.&lt;/div&gt;&lt;div&gt;&amp;nbsp;&lt;/div&gt;&lt;div&gt;&amp;nbsp;&lt;/div&gt;&lt;div&gt;&amp;nbsp;&lt;/div&gt;&lt;div&gt;&amp;nbsp;&lt;/div&gt;&lt;div&gt;&amp;nbsp;&lt;/div&gt;&lt;div&gt;&amp;nbsp;&lt;/div&gt;</description>
 <comments>http://connect.educause.edu/display/24188#comments</comments>
 <category domain="http://connect.educause.edu/tag/Audit+and+Compliance/4421">Audit and Compliance</category>
 <category domain="http://connect.educause.edu/tag/Cybersecurity/56">Cybersecurity</category>
 <category domain="http://connect.educause.edu/tag/EDUCAUSE_SEC07/4420">EDUCAUSE_SEC07</category>
 <category domain="http://connect.educause.edu/tag/Security+Management/631">Security Management</category>
 <category domain="http://connect.educause.edu/tag/Security+Planning/249">Security Planning</category>
 <category domain="http://connect.educause.edu/tag/Security+Policies/254">Security Policies</category>
 <pubDate>Tue, 17 Apr 2007 22:34:16 -0500</pubDate>
 <dc:creator>llarsen</dc:creator>
 <guid isPermaLink="false">24188 at http://connect.educause.edu</guid>
</item>
</channel>
</rss>
