Incident Handling and Response and Data Security

Recent resources tagged with Incident Handling and Response and Data Security.

2008 Data Breach Investigations Report

Added by the EDUCAUSE Librarian
Title:2008 Data Breach Investigations Report (ID: CSD5395)
Author(s):Wade H. Baker (Verizon Business), C D. Hylender (Verizon Business), and J A. Valentine (Verizon Business)
Source:Verizon Business
Origin:Contributed by Organizations or Campuses (07/01/2008)
Type:Articles, Papers, and Reports
Abstract:

The 2008 Data Breach Investigations Report draws from over 500 forensic engagements handled by the Verizon Business Investigative Response team over a four-year period. Tens of thousands of data points weave together the stories and statistics from compromise victims around the world. This report seeks to answer the following questions;

  • Who is behind data breaches?
  • How do breaches occur?
  • What commonalities exist?
  • Where should mitigation efforts be focused?
View this resource:

Collecting and Preserving Data in the Wake of a Tragedy

Added by the EDUCAUSE Librarian
Title:Collecting and Preserving Data in the Wake of a Tragedy (ID: SEC08073)
Author(s):William Dougherty (Virginia Tech)
Origin:Presented at Security Professionals Conference (05/04/2008)
Type:Presentations/Speeches
Abstract:

After the tragic events of April 16, 2007, at Virginia Tech, IT professionals and university legal counsel had to quickly address the need to collect and preserve data in the event of future litigation. Performing tasks while dealing with grief and protecting academic freedom and privacy issues has required a delicate approach.

View this resource:

Data Breaches Hit More Campuses

Added by the EDUCAUSE Librarian
Title:Data Breaches Hit More Campuses (ID: CSD5333)
Author(s):Andrew Guess (Inside Higher Ed)
Origin:Contributed by Organizations or Campuses (02/12/2008)
Type:Articles, Papers, and Reports
Abstract:

Review of news sources and databases shows an increase in the number of both security incidents and affected institutions in the last year.

View this resource:

Data Breaches in Higher Education: From Concern to Action

Added by the EDUCAUSE Librarian
Title:Data Breaches in Higher Education: From Concern to Action (ID: ERM08111)
Author(s):Peter M. Siegel (University of California, Davis)
Origin:EDUCAUSE Review Articles (01/18/2008)
Type:Articles, Papers, and Reports
Abstract:

"When is higher education going to get serious about safeguarding the private information of students,
faculty, and staff?"

View this resource:

Final Report of the 2007 Cybersecurity Summit

Added by the EDUCAUSE Librarian
Title:Final Report of the 2007 Cybersecurity Summit (ID: CYB0701)
Origin:Contributed by the Security Task Force, Presented at Cybersecurity Summit (11/30/2007)
Type:Articles, Papers, and Reports
Abstract:

This is the final report for the 2007 NSF Cybersecurity Summit, held February 22 & 23rd, 2007, in Arlington, VA.

View this resource:

How Ready Are IT Managers for a Crisis?

Added by the EDUCAUSE Librarian
Title:How Ready Are IT Managers for a Crisis? (ID: CSD5207)
Author(s):Andrew Guess (Inside Higher Ed)
Origin:Contributed by Organizations or Campuses (10/24/2007)
Type:Articles, Papers, and Reports
Abstract:

The annual Campus Computing Survey focuses on IT security and crisis management, finding gaps in preparation but fewer attacks on networks.

View this resource:

Information Security: Zero to 60 in 10 Years

Added by the EDUCAUSE Librarian
Title:Information Security: Zero to 60 in 10 Years (ID: EDU07251)
Author(s):Howard Muffler (Embry-Riddle Aeronautical University) and Joseph Progar (Embry-Riddle Aeronautical University)
Origin:Presented at EDUCAUSE Annual Conferences (10/23/2007)
Type:Presentations/Speeches
Abstract:

The focus on information security at Embry-Riddle Aeronautical University, as in many institutions, has evolved gradually over a number of years. Beginning with what can best be described as ad hoc initiatives driven by afterthought oversight, the university's focus on information security is maturing into a formalized, integrated business component and directive.

View this resource:

Training Your Staff to Protect SIS Data

Added by the EDUCAUSE Librarian
Title:Training Your Staff to Protect SIS Data (ID: CSD5118)
Author(s):Marcia Layton Turner (University Business)
Origin:Contributed by Organizations or Campuses (09/05/2007)
Type:Articles, Papers, and Reports
Abstract:

"No matter how robust your firewall, trained faculty and staff are your first line of defense against system breaches."

View this resource:

2006 Annual Study: Cost of a Data Breach Understanding Financial Impact, Customer Turnover, and Preventative Solutions

Added by the EDUCAUSE Librarian
Title:2006 Annual Study: Cost of a Data Breach Understanding Financial Impact, Customer Turnover, and Preventative Solutions (ID: CSD5015)
Source:Inc., PGP Corporation and Vontu
Origin:Contributed by Organizations or Campuses (07/24/2006)
Type:Articles, Papers, and Reports
Abstract:

This study summarizies the actual costs incurred by 31 organizations that lost confidential customer information and had a regulatory requirement to publicly notify affected individuals.

View this resource:

GAO Releases Report on Data Breaches and Identity Theft

Created by Rodney J. Petersen (EDUCAUSE) on July 24, 2007

The Government Accountability Office (GAO) has released a Report on Data Breaches that concludes while "breaches of sensitive information have occurred frequently and under widely varying circumstances, . . . the extent to which data breaches have resulted in identity theft is not well known." It further concludes that "should Congress choose to enact a federal notification requirement, use of a risk-based standard could avoid undue burden on organizations and unnecessary and counterproductive notifications of breaches that present little risk."

Some further higher education references in the report: