Security Implementation

Recent resources tagged with Security Implementation.

Georgia State University's IT Procurement Review Process--Practical Approach to Assessing Risks of IT Projects

Added by the EDUCAUSE Librarian
Title:Georgia State University's IT Procurement Review Process--Practical Approach to Assessing Risks of IT Projects (ID: EPS302)
Author(s):Tammy L. Clark (Georgia State University)
Origin:Contributed by Organizations or Campuses (10/02/2008)
Type:Effective Practices
Abstract:

In late 2005, the Security Review Policy was adopted by the University, which states "Where appropriate, information security personnel will conduct risk assessments of technologies/processes that are being evaluated and/or used at Georgia State University. The purpose of these assessments is to quantify the impact and probability of potential threats and vulnerabilities.

View this resource:

Implementing Information Security Governance Using ISO 27000

Added by the EDUCAUSE Librarian
Title:Implementing Information Security Governance Using ISO 27000 (ID: EPS303)
Author(s):Tammy L. Clark (Georgia State University)
Origin:Contributed by Organizations or Campuses (10/02/2008)
Type:Effective Practices
Abstract:

GSU's CIO sponsored the ISO 27001 certification initiative at Georgia State University in mid 2007 and the Information Security Department and Office of Disbursements were the first GSU departments to be included. We were successful in obtaining the certification in March 2008, which is a very prestigious achievement given that our university is one of the first (if not the first) in the nation to be awarded this
international designation.

View this resource:

Building a Security Program to Include Metrics

Created by Valerie M. Vogel (EDUCAUSE) on August 13, 2008

In "Security Metrics: A Solution in Search of a Problem", a recent EDUCAUSE Quarterly article, Joel Rosenblatt (Manager of Computer and Network Security, Columbia University) describes how the creation and collection of appropriate metrics can enhance an institution's security program. Learn about some potential metrics in the following areas: policy and compliance, network and machine monitoring, outreach and education, legal compliance, authorization and authentication, asset protection, and privacy.

Security Metrics: A Solution in Search of a Problem

Added by the EDUCAUSE Librarian
Title:Security Metrics: A Solution in Search of a Problem (ID: EQM0832)
Author(s):Joel Rosenblatt (Columbia University)
Origin:EDUCAUSE Quarterly Articles (08/04/2008)
Type:Articles, Papers, and Reports
Abstract:

The multifaceted aspects of security programs become clearer with the creation and collection of appropriate metrics.

View this resource:

Building a Risk-Based Information Security Program

Added by the EDUCAUSE Librarian
Title:Building a Risk-Based Information Security Program (ID: SEC08054)
Author(s):Michael Chapple (University of Notre Dame)
Origin:Presented at Security Professionals Conference (05/04/2008)
Type:Presentations/Speeches
Abstract:

In 2005, the University of Notre Dame suffered a serious incident that brought information security into the campus spotlight. In response, we partnered with a Big Four consulting firm to conduct a comprehensive IT risk assessment. Two years later, we're halfway through a four-year risk management program.

View this resource:

Effective Windows Desktop Security: XP and Vista

Added by the EDUCAUSE Librarian
Title:Effective Windows Desktop Security: XP and Vista (ID: SEC08081)
Author(s):John Bruggeman (Hebrew Union College-Jewish Institute of Religion)
Origin:Presented at Security Professionals Conference (05/04/2008)
Type:Presentations/Speeches
Abstract:

Windows desktops are widely deployed and can be subject to multiple attack vectors. Windows XP and Vista have vulnerabilities that need to be mitigated effectively by security teams or by end users. This session will cover the top security vulnerabilities in Windows desktops and how to secure them quickly and effectively, along with the tools to use.

View this resource:

Implementing Information Security and Compliance: Four Questions and a Roadmap to Guide the Way

Added by the EDUCAUSE Librarian
Title:Implementing Information Security and Compliance: Four Questions and a Roadmap to Guide the Way (ID: SEC08071)
Author(s):Lewis Watkins (University of Texas System) and Miguel Soldi (University of Texas System)
Origin:Presented at Security Professionals Conference (05/04/2008)
Type:Presentations/Speeches
Abstract:

In 2006, the University of Texas System launched a system-wide initiative to bolster information security. The process involves following an implementation roadmap and answering four fundamental questions: What's happening? What's important? What's effective? What's next? The purpose of this session is to share the roadmap and answers the questions.

View this resource:

Implementing Whole Disk Encryption in a Higher Education Environment

Added by the EDUCAUSE Librarian
Title:Implementing Whole Disk Encryption in a Higher Education Environment (ID: SEC08072)
Author(s):Jon Allen (Baylor University), Adam Sealey (Baylor University), and Robert Paul Hartland (Baylor University)
Origin:Presented at Security Professionals Conference (05/04/2008)
Type:Presentations/Speeches
Abstract:

Baylor University has spent two years working on a large-scale deployment of whole disk encryption. The session will present the process from selecting the encryption technology to the culminating deployment process. The result is mediation of data loss that can result from the loss or theft of a technology asset.

View this resource:

CA Options: Buy or Build, and Signed by Whom?

Added by the EDUCAUSE Librarian
Title:CA Options: Buy or Build, and Signed by Whom? (ID: PKI08001)
Author(s):James A. Jokl (University of Virginia), Paul Caskey (University of Texas System), and Nicholas Davis (University of Wisconsin-Madison)
Origin:Presented at PKI Meetings (04/16/2008)
Type:Presentations/Speeches
Abstract:

One of the first decisions facing campuses that have decided to deploy a PKI is whether to build their PKI in house, with the necessary personnel and infrastructure it entails, or to buy their PKI from a vendor, which can have a seemingly high sticker price. What are the driving factors behind this decision? How do you accurately assess all costs, both short- and long-term? How do you measure the benefits/ROI of a given choice? What signing options should you consider? Come to this session to participate in a discussion with panelists who have made decisions in each of these directions.

View this resource:

Campus Success Stories: How We Did It Here

Added by the EDUCAUSE Librarian
Title:Campus Success Stories: How We Did It Here (ID: PKI08004)
Author(s):William A. Weems (The University of Texas Health Science Center at Houston), Phil Saunders (University of Wisconsin-Madison), and Scott A. Rea (Dartmouth College)
Origin:Presented at PKI Meetings (04/16/2008)
Type:Presentations/Speeches
Abstract:

Deploying PKI can be complex and tricky, but more and more campuses are solving the technical and logistical problems and reporting positive outcomes. This session will feature representatives from three campuses where PKI has been successfully rolled out. They'll tell you how they did it.

View this resource: