Presented at EDUCAUSE Annual Conferences and Security Risk Assessment and Analysis

Lassoing the Beast: How a Large, Diverse University Is Wrapping Its Arms Around Confidential Data

Added by the EDUCAUSE Librarian
Title:Lassoing the Beast: How a Large, Diverse University Is Wrapping Its Arms Around Confidential Data (ID: EDU07330)
Author(s):Donna M. Milici (University of Pennsylvania), Jim Cunningham (University of Pennsylvania), and Maura Johnston (University of Pennsylvania)
Origin:Presented at EDUCAUSE Annual Conferences (10/23/2007)
Type:Presentations/Speeches
Abstract:

Penn designed the security and privacy impact assessment (SPIA) process and tool to raise awareness about where confidential data reside and to assess risks in seven major threat areas, which can be mitigated by a list of safeguards. Learn about successful outcomes from our early SPIA adopters.

View this resource:

GSU's Roadmap for a World-Class Information Security Management System: ISO 27001:2005

Added by the EDUCAUSE Librarian
Title:GSU's Roadmap for a World-Class Information Security Management System: ISO 27001:2005 (ID: EDU07237)
Author(s):Tammy L. Clark (Georgia State University) and William Monahan (Georgia State University)
Origin:Presented at EDUCAUSE Annual Conferences (10/23/2007)
Type:Presentations/Speeches
Abstract:

Georgia State University is one of the first universities to embrace the ISO 27001:2005 standard for establishing an information security management system (ISMS). A systematic and disciplined approach helps us leverage technology to develop a world-class ISMS that empowers users and improves processes. This session will discuss the importance of developing a comprehensive, risk-management based information security program.

View this resource:

Stop, Drop, and Roll: Prevent and Douse Cyber Incidents

Added by the EDUCAUSE Librarian
Title:Stop, Drop, and Roll: Prevent and Douse Cyber Incidents (ID: EDU07210)
Author(s):Cedric Bennett (Stanford University), Susan A. Blair (University of Florida), and Kathleen Roberts (iSecure Solutions)
Origin:Presented at EDUCAUSE Annual Conferences (10/23/2007)
Type:Presentations/Speeches
Abstract:

Presenting two best-practice models for cyber incidents: To prevent cyber incidents, learn how to use an uncomplicated cyber risk assessment to help you focus your institution's limited resources. When an incident occurs, know how to douse the effect of breach events when notification is required.

View this resource:

Effective IT Security Practices

Added by the EDUCAUSE Librarian
Title:Effective IT Security Practices (ID: EDU06165)
Author(s):John Bruggeman (Hebrew Union College-Jewish Institute of Religion), H. Morrow Long (Yale University), and Christopher Misra (University of Massachusetts Amherst)
Origin:Presented at EDUCAUSE Annual Conferences (10/09/2006)
Type:Presentations/Speeches
Abstract:IT security is a critical issue in higher education. This seminar will focus on network security architectures, infrastructure, data security, incident detection, prevention, and response. A framework and set of tools that participants can take back to their institutions for handling IT security incidents will also be provided. Participants will learn how to bypass typical mistakes, develop incident-handling protocols and procedures, use shareware and open source tools, interpret logs, and leverage other forensic and investigative resources. The effective practices work of the EDUCAUSE/Internet2 Computer Network Security Task Force will also be discussed.
View this resource:

IT Security in Higher Education: A Sea Change

Added by the EDUCAUSE Librarian
Title:IT Security in Higher Education: A Sea Change (ID: EDU06286)
Author(s):Robert B. Kvavik (University of Minnesota) and John Voloudakis (BearingPoint, Inc.)
Origin:Presented at EDUCAUSE Annual Conferences (10/11/2006)
Type:Presentations/Speeches
Abstract:ECAR data from 2003 and 2005 make it possible to compare the state of IT security over a critical two-year period. The findings from this analysis are striking, revealing an organizational, technological, and behavioral sea change as U.S. and Canadian universities and colleges have significantly improved all aspects of their IT security.
View this resource:

A Successful Tool to Create Positive Change: Result of an IT Risk Assessment and Benchmark at Scandinavian Universities

Added by the EDUCAUSE Librarian
Title:A Successful Tool to Create Positive Change: Result of an IT Risk Assessment and Benchmark at Scandinavian Universities (ID: EDU05254)
Author(s):Magnar Antonsen, Jonas Everbrand, Johan Lidros, and Jan-Martin Lowendahl
Origin:Presented at EDUCAUSE Annual Conferences (10/21/2005)
Type:Presentations/Speeches
Abstract:Current cost pressures, technology changes, and new requirements meant that changes were needed in the way IT was managed at Scandinavian universities. This session will present results from an IT risk assessment and benchmark (costs, risk management, quality) at 26 Scandinavian universities and how those results have been used to improve IT management at our universities.
View this resource:

Security Assessments for Information Technology

Added by the EDUCAUSE Librarian
Title:Security Assessments for Information Technology (ID: EDU05190)
Author(s):Jon Allen (Baylor University) and Robert Paul Hartland (Baylor University)
Origin:Presented at EDUCAUSE Annual Conferences (10/20/2005)
Type:Presentations/Speeches
Abstract:

Baylor University recently conducted a campus-wide information technology security assessment. The session will present the assessment process, from choosing a consultant to remediation of the assessment's discoveries. The result is a long-term strategy and metrics for information technology security within the university.

View this resource:

Systemic Barriers to IT Security

Added by the EDUCAUSE Librarian
Title:Systemic Barriers to IT Security (ID: EDU04117)
Author(s):Clair W. Goldsmith (University of Texas System) and Lewis Watkins (University of Texas System)
Origin:Presented at EDUCAUSE Annual Conferences (10/21/2004)
Type:Presentations/Speeches
Abstract:The University of Texas System chancellor's security initiative required the 15 academic and health institutions to evaluate IT security, both centrally and in all departments. A security group was charged with reviewing these assessments to identify systemic barriers to IT security. The systemic barriers and mitigation strategies will be discussed.
View this resource:

Centralizing IT Risk Assessment and Measuring Security Policy Compliance

Added by the EDUCAUSE Librarian
Title:Centralizing IT Risk Assessment and Measuring Security Policy Compliance (ID: EDU0460)
Author(s):Kent Knudsen (Texas A&M University) and Jeffrey C. McCabe (Texas A&M University)
Origin:Presented at EDUCAUSE Annual Conferences (10/20/2004)
Type:Presentations/Speeches
Abstract:In a decentralized environment, centralizing the periodic risk assessment process offers many advantages, including the ability to derive a composite view of the institutional risks and highlight security policy compliance issues. This session will focus on a centralized solution that Texas A&M University has implemented and share some of the outcomes.
View this resource:

Defining Risk and Fixing the Top 20: Security 101 for a Small School

Added by the EDUCAUSE Librarian
Title:Defining Risk and Fixing the Top 20: Security 101 for a Small School (ID: EDU03136)
Author(s):John Bruggeman (Hebrew Union College-Jewish Institute of Religion)
Origin:Presented at EDUCAUSE Annual Conferences (2003)
Type:Presentations/Speeches
Abstract:What are the security issues for a small school with small budgets? Am I a target if I'm a small school with a low profile? Basic security rules and policies should be implemented at any school and home. What you have to address will vary depending on your risk assessment, not your budget.
View this resource: