Security Management and Data Security

Recent resources tagged with Security Management and Data Security.

Security Task Force 2008–2009 Strategic Plan: "Safeguarding Our IT Assets, Protecting Our Community's Privacy"

Created by Valerie M. Vogel (EDUCAUSE) on September 08, 2008

The EDUCAUSE/Internet2 Computer and Network Security Task Force 2008-2009 Strategic Plan is now available online. The Security Task Force (STF) has adopted the theme of "Safeguarding Our IT Assets, Protecting Our Community's Privacy" for 2008-2009. The STF strategic planning process aims to anticipate higher education security issues, enabling campuses to forge joint efforts and solutions and recognizing that security challenges continue to evolve in our digital information world.

The following goals have been identified for 2008-2009 to help focus working group priorities in the near term (12-18 months):

Security Task Force 2008–2009 Strategic Plan: Safeguarding Our IT Assets, Protecting Our Community’s Privacy

Added by the EDUCAUSE Librarian
Title:Security Task Force 2008–2009 Strategic Plan: Safeguarding Our IT Assets, Protecting Our Community’s Privacy (ID: CSD5494)
Origin:Contributed by the Security Task Force (09/03/2008)
Type:Plans and Guidelines
Abstract:

The EDUCAUSE/Internet2 Computer and Network Security Task Force (STF) provides a focal point for the academic community to join together to strengthen the ability of the higher education sector to respond to growing threats to information security and to protect the privacy of our community members. This strategic plan is intended to set forth a vision for the higher education community and provide a concise roadmap to guide the efforts of the STF. This roadmap emphasizes continuous and evolutionary community investment in converting our understanding of risks and issues into solutions based on effective practices, as well as the urgent need to build the national capability across the higher education sector to respond quickly and effectively as a community to new threats and vulnerabilities.

View this resource:

Out of the Breach and into the Fire

Added by the EDUCAUSE Librarian
Title:Out of the Breach and into the Fire (ID: ERM08510)
Author(s):Heidi Wachs (Georgetown University), Kent Wada (UCLA), and Timothy Lance (NYSERNet, Inc.)
Origin:EDUCAUSE Review Articles (09/15/2008)
Type:Articles, Papers, and Reports
Abstract:

Two of the entries on the long list of data breaches in higher education are Georgetown University and UCLA. Timothy Lance recently talked with the IT policy officers at these two institutions to identify some of the policy implications of handling data breaches.

View this resource:

2008 Data Breach Investigations Report

Added by the EDUCAUSE Librarian
Title:2008 Data Breach Investigations Report (ID: CSD5395)
Author(s):Wade H. Baker (Verizon Business), C D. Hylender (Verizon Business), and J A. Valentine (Verizon Business)
Source:Verizon Business
Origin:Contributed by Organizations or Campuses (07/01/2008)
Type:Articles, Papers, and Reports
Abstract:

The 2008 Data Breach Investigations Report draws from over 500 forensic engagements handled by the Verizon Business Investigative Response team over a four-year period. Tens of thousands of data points weave together the stories and statistics from compromise victims around the world. This report seeks to answer the following questions;

  • Who is behind data breaches?
  • How do breaches occur?
  • What commonalities exist?
  • Where should mitigation efforts be focused?
View this resource:

Security Standards: Complexity Is the Enemy of Security

Added by the EDUCAUSE Librarian
Title:Security Standards: Complexity Is the Enemy of Security (ID: SEC08060)
Author(s):Brian Smith-Sweeney (New York University), Daniel Adinolfi (Cornell University), and Christopher Misra (University of Massachusetts Amherst)
Origin:Presented at Security Professionals Conference (05/04/2008)
Type:Presentations/Speeches
Abstract:

Everyone wants to know how to "be secure." The myriad higher ed compliance requirements, coupled with a constantly dynamic attacker strategy, have made this question more difficult than ever to answer. Come talk with representatives from three institutions that managed to craft a rational, coherent strategy for standardizing security.

View this resource:

Identity Finder LLC and Carnegie Mellon University - Find and Protect Personal Information Before It's Too Late

Added by the EDUCAUSE Librarian
Title:Identity Finder LLC and Carnegie Mellon University - Find and Protect Personal Information Before It's Too Late (ID: SEC08005)
Author(s):Todd Feinman (Identity Finder LLC) and Mary Ann Blair (Carnegie Mellon University)
Origin:Presented at Security Professionals Conference (05/04/2008)
Type:Presentations/Speeches
Abstract:

It's estimated that the black market trafficking of stolen electronic identities will increase to $1.6 billion in 2010. Finding personal information is an increasingly complex problem due the myriad places it can reside and forms it can take on computers. Learn not only how to find it but also how to easily and quickly protect it.

View this resource:

Applying Data Governance in Identity Management: To Serve and Protect

Added by the EDUCAUSE Librarian
Title:Applying Data Governance in Identity Management: To Serve and Protect (ID: WRC08060)
Author(s):Brendan Bellina (University of Southern California)
Origin:Presented at Western Regional conferences (03/31/2008)
Type:Presentations/Speeches
Abstract:

An identity management system often becomes a critical source of information for electronic services. Demands for data can result in tension between those who collect and safeguard the data and those who leverage it. This presentation will discuss the role that data governance plays at USC to both serve and protect.

View this resource:

It's Past Midnight: Do You Know Where Your Data Are?

Added by the EDUCAUSE Librarian
Title:It's Past Midnight: Do You Know Where Your Data Are? (ID: MWR08072)
Author(s):Mary Pickering (Georgetown University)
Origin:Presented at Midwest Regional Conferences (03/17/2008)
Type:Presentations/Speeches
Abstract:

Since instituting a mandatory review and approval process for all contracts involving IT, we've become aware of how few people know how to prepare a good contract and how few contracts truly protect our data. Whether the amount of data is minor or mind-blowing, processes and templates can help protect our data and our institutions.

View this resource:

Data Breaches Hit More Campuses

Added by the EDUCAUSE Librarian
Title:Data Breaches Hit More Campuses (ID: CSD5333)
Author(s):Andrew Guess (Inside Higher Ed)
Origin:Contributed by Organizations or Campuses (02/12/2008)
Type:Articles, Papers, and Reports
Abstract:

Review of news sources and databases shows an increase in the number of both security incidents and affected institutions in the last year.

View this resource:

Digital Self Defense Workshops

Added by the EDUCAUSE Librarian
Title:Digital Self Defense Workshops (ID: CSD5335)
Source:Rochester Institute of Technology
Origin:Contributed by Organizations or Campuses (01/24/2007)
Type:Certification, Education, Training and Tutorials
Abstract:

The Rochester Institute of Technology provides security awareness online workshops on protecting your computer and yourself from outside online intruders, and other data security information handling.

View this resource: