Security Awareness

Recent resources tagged with Security Awareness.

Protecting Your Institution from Phishing Attacks: Education and Awareness Resources

Created by Valerie M. Vogel (EDUCAUSE) on August 26, 2008

Although phishing is not a new threat to the higher ed community, many schools have experienced an increasing number of targeted phishing attacks over the past several months. These phishing e-mails ask students, faculty, and staff to provide their institutional username and password. Once an account is compromised, it is typically used to send out more spam, which creates a new set of problems for the institution.

Many schools are working to combat these phishing attacks through education and awareness activities over the next few weeks as students return to campus. In an effort to assist institutions, EDUCAUSE has compiled a number of phishing resources that include websites on phishing, quizzes and games, and downloadable materials (e.g., posters, brochures, bookmarks, postcards, and videos). Please share any additional suggested resources with the Security Task Force.

Building a Security Program to Include Metrics

Created by Valerie M. Vogel (EDUCAUSE) on August 13, 2008

In "Security Metrics: A Solution in Search of a Problem", a recent EDUCAUSE Quarterly article, Joel Rosenblatt (Manager of Computer and Network Security, Columbia University) describes how the creation and collection of appropriate metrics can enhance an institution's security program. Learn about some potential metrics in the following areas: policy and compliance, network and machine monitoring, outreach and education, legal compliance, authorization and authentication, asset protection, and privacy.

Security Metrics: A Solution in Search of a Problem

Added by the EDUCAUSE Librarian
Title:Security Metrics: A Solution in Search of a Problem (ID: EQM0832)
Author(s):Joel Rosenblatt (Columbia University)
Origin:EDUCAUSE Quarterly Articles (08/04/2008)
Type:Articles, Papers, and Reports
Abstract:

The multifaceted aspects of security programs become clearer with the creation and collection of appropriate metrics.

View this resource:

Policy on Institutional Data

Added by the EDUCAUSE Librarian
Title:Policy on Institutional Data (ID: CSD5463)
Source:Ohio State University
Origin:Contributed by Organizations or Campuses (10/18/2007)
Type:Policies and Procedures
Abstract:

Ohio State University's policy includes institutional data procedures and resources. It also defines the scope and applicability of the policy, as well as enforcement.

View this resource:

Sensitive Data Best Practices

Added by the EDUCAUSE Librarian
Title:Sensitive Data Best Practices (ID: CSD5462)
Source:Louisiana State University
Origin:Contributed by Organizations or Campuses (01/10/2007)
Type:Policies and Procedures
Abstract:

Louisiana State University's Best Practices for Sensitive Data covers the following: Electronic Handling, Storage and Disposal; Physical Handling, Storage and Disposal; Security; and Legal Disclosure Requirements.

View this resource:

Cybersecurity Research Challenges

Added by the EDUCAUSE Librarian
Title:Cybersecurity Research Challenges (ID: CYB08010)
Author(s):Jeannette Wing (National Science Foundation)
Origin:Presented at Cybersecurity Summit (05/07/2008)
Type:Presentations/Speeches
Abstract:

Today’s most prevalent and widely discussed attacks exploit code-level flaws such as buffer overruns and type-invalid input. We need to anticipate tomorrow’s attacks and think beyond buffer overruns, beyond code-level bugs, and beyond the horizon. To be ready for threats of the future, we need to be doing more basic research in cybersecurity today. This talk will outline a few suggestions for important research directions in cybersecurity: the foundations of trustworthy computing, security architectures, privacy, usability, and security metrics.

View this resource:

NSF Response to 2007 Summit Final Report

Added by the EDUCAUSE Librarian
Title:NSF Response to 2007 Summit Final Report (ID: CYB08006)
Author(s):Ardoth A. Hassler (Georgetown University) and Clifford A. Jacobs (National Science Foundation)
Origin:Presented at Cybersecurity Summit (05/07/2008)
Type:Presentations/Speeches
Abstract:

The Cybersecurity Summit meetings have proven to be a useful forum to foster dialog between awardees, cybersecurity experts and NSF. NSF will provide feedback on the 2007 Summit meeting and discuss best practices in cybersecurity that might be useful to large facilities.

View this resource:

The Big Brother Dilemma

Added by the EDUCAUSE Librarian
Title:The Big Brother Dilemma (ID: ENT08005)
Author(s):Gregory A. Jackson (University of Chicago)
Origin:Presented at Enterprise Technology Conferences (05/28/2008)
Type:Presentations/Speeches
Abstract:

We want cameras watching for problems, but we worry that they will observe or disclose things we'd like to keep private. We want network administrators to track harassing e-mail to its source, but we don't want anyone monitoring our e-mail. We want our buildings to admit occupants and keep strangers out, but we don't want anyone keeping track of when we arrive and leave. In other words, we want big brothers to watch out for us, but we don't want Big Brother to watch us. And IT is caught in the middle.

View this resource:

A Cybersecurity Agenda for the Next President

Added by the EDUCAUSE Librarian
Title:A Cybersecurity Agenda for the Next President (ID: POL08004)
Author(s):Amelia A. Tynan (Tufts University), Martha Stansell-Gamm (United States Department of Justice), and Paul Nicholas (Microsoft Corporation)
Origin:Presented at Policy Conferences (05/07/2008)
Type:Presentations/Speeches
Abstract:

There has been much improvement in securing cyberspace in the last five years, but much still needs to be done. The Center for Strategic and International Studies (CSIS) has established a Commission on Cyber Security for the 44th Presidency, the administration that will take office in January 2009. The goal of the commission is to identify a strategy and set of recommendations for the next administration to move ahead in securing cyberspace. This session will provide a status report on the commission's work to date. It will also provide an opportunity to offer input regarding progress that has been made in the higher education sector, remaining challenges and opportunities, and the role of the federal government to help improve cybersecurity at colleges and universities.

View this resource:

Creating and Maintaining a Security Awareness Program

Added by the EDUCAUSE Librarian
Title:Creating and Maintaining a Security Awareness Program (ID: SEC08066)
Author(s):Cherry Delaney (Purdue University)
Origin:Presented at Security Professionals Conference (05/04/2008)
Type:Presentations/Speeches
Abstract:

Information security and the protection of a university's information assets and intellectual property begin with security awareness and education. This session will discuss Purdue University's approach to security education and training, focused on the university community at large, which is designed to develop and preserve a culture of security awareness.

View this resource: