Incident Handling and Response and Security Management

Recent resources tagged with Incident Handling and Response and Security Management.

REN-ISAC: Community Support for Cybersecurity Protection and Response

Added by the EDUCAUSE Librarian
Title:REN-ISAC: Community Support for Cybersecurity Protection and Response (ID: LIVE0822)
Author(s):Doug Pearson (Indiana University)
Origin:EDUCAUSE Live!, Web Seminars Contributed by EDUCAUSE (11/10/2008)
Type:Presentations/Speeches
Abstract:

As with many institutional endeavors, successful practice in cybersecurity requires that the players (individuals and teams) operate in the context of a community that faces similar challenges, objectives, and goals. Several community-based organizations support higher education and research institutions in their cybersecurity endeavors.

The EDUCAUSE/Internet2 Security Task Force coordinates community work in the areas of governance, policy, data privacy and security, effective practice, awareness, and professional development. As an independent organization aligned closely with EDUCAUSE and Internet2, the REN-ISAC has primary focus on supporting situational awareness and operational protection and response, through the sharing of actionable information. This presentation will highlight the value of institutional participation in security communities and describe in detail the REN-ISAC organization and community.

View this resource:

Tune In November 10: Community Support for Cybersecurity Protection and Response

Created by Peggy Kurkowski (EDUCAUSE) on November 04, 2008

ELive LogoAs with many institutional endeavors, successful practice in cybersecurity requires that the players (individuals and teams) operate in the context of a community that faces similar challenges, objectives, and goals. Several community-based organizations support higher education and research institutions in their cybersecurity endeavors.

The EDUCAUSE/Internet2 Security Task Force coordinates community work in the areas of governance, policy, data privacy and security, effective practice, awareness, and professional development. As an independent organization aligned closely with EDUCAUSE and Internet2, the REN-ISAC has primary focus on supporting situational awareness and operational protection and response, through the sharing of actionable information.

Out of the Breach and into the Fire

Added by the EDUCAUSE Librarian
Title:Out of the Breach and into the Fire (ID: ERM08510)
Author(s):Heidi Wachs (Georgetown University), Kent Wada (UCLA), and Timothy Lance (NYSERNet, Inc.)
Origin:EDUCAUSE Review Articles (09/15/2008)
Type:Articles, Papers, and Reports
Abstract:

Two of the entries on the long list of data breaches in higher education are Georgetown University and UCLA. Timothy Lance recently talked with the IT policy officers at these two institutions to identify some of the policy implications of handling data breaches.

View this resource:

2008 Data Breach Investigations Report

Added by the EDUCAUSE Librarian
Title:2008 Data Breach Investigations Report (ID: CSD5395)
Author(s):Wade H. Baker (Verizon Business), C D. Hylender (Verizon Business), and J A. Valentine (Verizon Business)
Source:Verizon Business
Origin:Contributed by Organizations or Campuses (07/01/2008)
Type:Articles, Papers, and Reports
Abstract:

The 2008 Data Breach Investigations Report draws from over 500 forensic engagements handled by the Verizon Business Investigative Response team over a four-year period. Tens of thousands of data points weave together the stories and statistics from compromise victims around the world. This report seeks to answer the following questions;

  • Who is behind data breaches?
  • How do breaches occur?
  • What commonalities exist?
  • Where should mitigation efforts be focused?
View this resource:

Incident Response Tracker: Centralized Monitoring, Distributed Response

Added by the EDUCAUSE Librarian
Title:Incident Response Tracker: Centralized Monitoring, Distributed Response (ID: SEC08063)
Author(s):Martin Manjak (University at Albany, SUNY)
Origin:Presented at Security Professionals Conference (05/04/2008)
Type:Presentations/Speeches
Abstract:

With a mixture of centralized and local IT service providers, higher ed presents unique challenges to effective incident response. The University at Albany has developed a web-based incident management and reporting tool that provides immediate sharing of incident information with local responders and real-time incident response functionality (e.g., switch port control).

View this resource:

Incident Response from the Ground Up

Added by the EDUCAUSE Librarian
Title:Incident Response from the Ground Up (ID: NCP08071)
Author(s):Adam Goldstein (Dartmouth College) and Ellen L. Young (Dartmouth College)
Origin:Presented at NERCOMP Conferences (03/10/2008)
Type:Presentations/Speeches
Abstract:

Recognizing that an incident response policy is only as good as the procedures that support it, Dartmouth College developed its approach to incident response from the bottom up. This session will highlight the advantages of establishing procedures first and policy second when it comes to incident response planning.

View this resource:

Data Breaches Hit More Campuses

Added by the EDUCAUSE Librarian
Title:Data Breaches Hit More Campuses (ID: CSD5333)
Author(s):Andrew Guess (Inside Higher Ed)
Origin:Contributed by Organizations or Campuses (02/12/2008)
Type:Articles, Papers, and Reports
Abstract:

Review of news sources and databases shows an increase in the number of both security incidents and affected institutions in the last year.

View this resource:

Data Breaches in Higher Education: From Concern to Action

Added by the EDUCAUSE Librarian
Title:Data Breaches in Higher Education: From Concern to Action (ID: ERM08111)
Author(s):Peter M. Siegel (University of California, Davis)
Origin:EDUCAUSE Review Articles (01/18/2008)
Type:Articles, Papers, and Reports
Abstract:

"When is higher education going to get serious about safeguarding the private information of students,
faculty, and staff?"

View this resource:

Final Report of the 2007 Cybersecurity Summit

Added by the EDUCAUSE Librarian
Title:Final Report of the 2007 Cybersecurity Summit (ID: CYB0701)
Origin:Contributed by the Security Task Force, Presented at Cybersecurity Summit (11/30/2007)
Type:Articles, Papers, and Reports
Abstract:

This is the final report for the 2007 NSF Cybersecurity Summit, held February 22 & 23rd, 2007, in Arlington, VA.

View this resource:

Some Frontiers of Security Work

Added by the EDUCAUSE Librarian
Title:Some Frontiers of Security Work (ID: EDU07115)
Author(s):Joseph E. St Sauver (University of Oregon)
Origin:Presented at EDUCAUSE Annual Conferences (10/23/2007)
Type:Presentations/Speeches
Abstract:

The higher education community faces increasingly difficult issues of security in a networked world, compounded by the demands of advanced applications. Performance requirements (high bandwidth, end-to-end transparency, new protocols) are essential for the academic mission and innovation, but are not easily accommodated in current approaches to network security. The Salsa group is forging new frontiers to address these issues.

View this resource: