Contributed by Organizations or Campuses; Articles, Papers, and Reports; and Data Security

2008 Data Breach Investigations Report

Added by the EDUCAUSE Librarian
Title:2008 Data Breach Investigations Report (ID: CSD5395)
Author(s):Wade H. Baker (Verizon Business), C D. Hylender (Verizon Business), and J A. Valentine (Verizon Business)
Source:Verizon Business
Origin:Contributed by Organizations or Campuses (07/01/2008)
Type:Articles, Papers, and Reports
Abstract:

The 2008 Data Breach Investigations Report draws from over 500 forensic engagements handled by the Verizon Business Investigative Response team over a four-year period. Tens of thousands of data points weave together the stories and statistics from compromise victims around the world. This report seeks to answer the following questions;

  • Who is behind data breaches?
  • How do breaches occur?
  • What commonalities exist?
  • Where should mitigation efforts be focused?
View this resource:

Data Breaches Hit More Campuses

Added by the EDUCAUSE Librarian
Title:Data Breaches Hit More Campuses (ID: CSD5333)
Author(s):Andrew Guess (Inside Higher Ed)
Origin:Contributed by Organizations or Campuses (02/12/2008)
Type:Articles, Papers, and Reports
Abstract:

Review of news sources and databases shows an increase in the number of both security incidents and affected institutions in the last year.

View this resource:

Straight Talk About Data Security

Added by the EDUCAUSE Librarian
Title:Straight Talk About Data Security (ID: CSD5298)
Author(s):Walter Conway (Walter Conway Associates, LLC) and Dennis Reedy (Indiana University System)
Source:Business Officer Magazine
Origin:Contributed by Organizations or Campuses (12/26/2007)
Type:Articles, Papers, and Reports
Abstract:

"If you accept payment cards on campus, you need to comply with a standard designed for safe handling of sensitive consumer information. Indiana University’s compliance plans offer some guidance."

View this resource:

Why 'Anonymous' Data Sometimes Isn't

Added by the EDUCAUSE Librarian
Title:Why 'Anonymous' Data Sometimes Isn't (ID: CSD5291)
Author(s):Bruce Schneier (BT Counterpane, Inc.)
Source:Wired Magazine Group Inc
Origin:Contributed by Organizations or Campuses (12/13/2007)
Type:Articles, Papers, and Reports
Abstract:

"Last year, Netflix published 10 million movie rankings by 500,000 customers, as part of a challenge for people to come up with better recommendation systems than the one the company was using. The data was anonymized by removing personal details and replacing names with random numbers, to protect the privacy of the recommenders. "

View this resource:

Large Scale Collection and Sanitization of Network Security Data: Risks and Challenges

Added by the EDUCAUSE Librarian
Title:Large Scale Collection and Sanitization of Network Security Data: Risks and Challenges (ID: CSD5281)
Author(s):Phillip Porras (SRI International) and Vitaly Shmatikov (University of Texas at Austin)
Origin:Contributed by Organizations or Campuses (09/26/2006)
Type:Articles, Papers, and Reports
Abstract:

"Over the last several years, there has been an emerging interest in the development of wide-area data collection and analysis centers to help identify, track, and formulate responses to the ever-growing number of coordinated attacks and malware infections that plague computer networks worldwide. As large-scale network threats continue to evolve in sophistication and extend to widely deployed applications, we expect that interest in collaborative security monitoring infrastructures will continue to grow, because such attacks may not be easily diagnosed from a single point in the network. The intent of this position paper is not to argue the necessity of Internet-scale security data sharing infrastructures, as there is ample research [13, 48, 51, 54, 41, 47, 42] and operational examples [43, 17, 32, 53] that already make this case. Instead, we observe that these well-intended activities raise a unique set of risks and challenges.

View this resource:

PCI Confusion Is The Norm

Added by the EDUCAUSE Librarian
Title:PCI Confusion Is The Norm (ID: CSD5261)
Author(s):Evan Schuman (eWeek.com)
Source:Storefront Backtalk
Origin:Contributed by Organizations or Campuses (12/07/2007)
Type:Articles, Papers, and Reports
Abstract:

With all of the concern today about retailers inadequately protecting their credit card data, it's logical to assume that retail IT managers would have made themselves quite familiar with the ins-and-outs of the Payment Card Industry Data Security Standard (PCI DSS).

View this resource:

The University's Role in Advancing Data Encryption, Part 1

Added by the EDUCAUSE Librarian
Title:The University's Role in Advancing Data Encryption, Part 1 (ID: CSD5214)
Author(s):Andrew K. Burger (ECT News Network)
Source:TechNewsWorld
Origin:Contributed by Organizations or Campuses (11/02/2007)
Type:Articles, Papers, and Reports
Abstract:

"Much like Moore's Law, PGP has seen huge advances in encryption technologies over the years -- specifically the ability for encryption to work faster and easier in a network while still being transparent to the end user," said Phillip Dunkelberger, President and CEO, PGP Corporation. Excellent encryption research is being carried out at a number of major universities, though it's still at a nascent stage.

View this resource:

The University's Role in Advancing Data Encryption, Part 2

Added by the EDUCAUSE Librarian
Title:The University's Role in Advancing Data Encryption, Part 2 (ID: CSD5213)
Author(s):Andrew K. Burger (ECT News Network)
Source:TechNewsWorld
Origin:Contributed by Organizations or Campuses (11/02/2007)
Type:Articles, Papers, and Reports
Abstract:

"Identity theft is one of the fastest-growing cyber-crimes, and, as a result, 38 states have identity theft legislation -- with some states using encryption as a safe haven," said Southwestern Illinois Community College CIO Christine Leja. "The education market as a whole is becoming more serious about protecting student information and is looking to encryption as the means to making that happen."

View this resource:

How Ready Are IT Managers for a Crisis?

Added by the EDUCAUSE Librarian
Title:How Ready Are IT Managers for a Crisis? (ID: CSD5207)
Author(s):Andrew Guess (Inside Higher Ed)
Origin:Contributed by Organizations or Campuses (10/24/2007)
Type:Articles, Papers, and Reports
Abstract:

The annual Campus Computing Survey focuses on IT security and crisis management, finding gaps in preparation but fewer attacks on networks.

View this resource:

Why File Sharing Networks Are Dangerous

Added by the EDUCAUSE Librarian
Title:Why File Sharing Networks Are Dangerous (ID: CSD5127)
Author(s):Dan McGuire (Dartmouth College), M. Eric Johnson (Dartmouth College), and Nicholas D. Willey (Dartmouth College)
Source:Communications of the ACM
Origin:Contributed by Organizations or Campuses (09/10/2007)
Type:Articles, Papers, and Reports
Abstract:

In this paper the authors analyze P2P security issues, establishing vulnerabilities that software
clients represent. The authors go on to present experimental evidence of the risk through honeypot
experiments that expose both business and personal financial information and they track the resulting consequences. Their analysis and experimental results show the security risk of P2P file sharing networks.

View this resource: