Security Management, Data Security, and Presented at EDUCAUSE Annual Conferences

Developing an Information Management Program

Added by the EDUCAUSE Librarian
Title:Developing an Information Management Program (ID: E08_47696)
Author(s):Merri Beth Lavagnino (Indiana University System), Daniel W. Noonan (The Ohio State University), and Jenny Mehmedovic (University of Kansas)
Origin:Presented at EDUCAUSE Annual Conferences (10/28/2008)
Type:Presentations/Speeches
Abstract:

Everyone within an institution of higher education has a responsibility to access, use, and disclose organizational information in a responsible manner, compliant with institutional policy and legal statutes. This responsibility extends to other parties granted access to institutional information. Improper maintenance, disposal, or release of institutional administrative information exposes the organization to significant risk. A comprehensive information management program will improve the information-handling and administrative processes, the security of private information, and the management of institutional records and will facilitate the preservation of the institutional memory. Explore from three different institutional perspectives the interplay of a variety of information management topics including building support and buy-in, developing records retention and disposition schedules, managing electronic records, effectively administering e-discovery and requests for release of records, handling inappropriate release of information, implementing data classification and security requirements, maintaining the privacy and security of information, and developing policies and educational requirements.

View this resource:

Security and Privacy Lightning Round

Added by the EDUCAUSE Librarian
Title:Security and Privacy Lightning Round (ID: E08_47642)
Author(s):Christopher Keslar (University of Pittsburgh), Michael A. Corn (University of Illinois at Urbana-Champaign), Ryan Turner (University of North Carolina at Chapel Hill), Matt Tolbert (University of Pittsburgh), Chandragupta Gudena (Bridgewater State College), David Stack (University of Wisconsin-Milwaukee), and Jamey Hansen (University of Minnesota)
Origin:Presented at EDUCAUSE Annual Conferences (10/30/2008)
Type:Presentations/Speeches
Abstract:

Authenticated Guest Wireless Access: Simplicity and Security
Christopher Keslar, University of Pittsburgh
The need for guest access is growing as more campuses provide wireless coverage. This presentation will explore a solution for on-demand guest wireless access through a user-friendly and secure process.

Automated Network Access Control at the Edge
Michael S. Hawkins, University of North Carolina at Chapel Hill
Hear how, with a small staff, we reliably manage, secure, prioritize, and deliver voice, video, and data services for over 30,000 people while complying with local, state, and federal regulations.

Caught in the Middle: Implementing University Security Policies at the College Level
Jamey Hansen, University of Minnesota
University security mandates are on one side; independent faculty on the other. Learn how our college IT office walked the fine line between security and service.

Discovering Network Usage Trends and Security Risks Through Network Information Analysis
Matt Tolbert, University of Pittsburgh
This session will share how the University of Pittsburgh successfully captures and visualizes network data to understand network traffic patterns and detect network-based security threats.

NEW! Not in your program!

Contract Themes for Data Protection
Michael A. Corn, University of Illinois at Urbana-Champaign
This session will provide a synthesis of data protection considerations when establishing contract relationships, and will introduce attendees to a comprehensive treatment of this topic that was recently completed by the EDUCAUSE/Internet2 Security Task Force.

Securing Data at Rest, Chandragupta Gudena, Bridgewater State College

View this resource:

Information Classification

Added by the EDUCAUSE Librarian
Title:Information Classification (ID: E08_47615)
Author(s):Ajay Gupta (Prince George's Community College)
Origin:Presented at EDUCAUSE Annual Conferences (10/29/2008)
Type:Presentations/Speeches
Abstract:

As demanded by our ERP implementation schedule, PGCC created a comprehensive information classification scheme and the associated access rights and privileges in time for our president's cabinet and college attorney to approve and have implemented. Come hear our lessons learned and walk away with advice for your own effort.

View this resource:

Applying Data Governance in Identity Management: To Serve and Protect

Added by the EDUCAUSE Librarian
Title:Applying Data Governance in Identity Management: To Serve and Protect (ID: E08_47547)
Author(s):Brendan Bellina (University of Southern California)
Origin:Presented at EDUCAUSE Annual Conferences (10/29/2008)
Type:Presentations/Speeches
Abstract:

An identity management system often becomes a critical source of information for electronic services. Demands for data can result in tension between those who collect and safeguard the data and those who leverage it. This presentation will discuss the role data governance plays at USC to both serve and protect.

View this resource:

Bruce Schneier on Information Security: Ten Trends - Sponsored by AT&T, An EDUCAUSE Silver Partner

Added by the EDUCAUSE Librarian
Title:Bruce Schneier on Information Security: Ten Trends - Sponsored by AT&T, An EDUCAUSE Silver Partner (ID: EDU07077)
Author(s):Bruce Schneier (BT Counterpane, Inc.)
Origin:Presented at EDUCAUSE Annual Conferences (10/23/2007)
Type:Presentations/Speeches
Abstract:

Surveying current trends in information security, it’s clear that a myriad of forces are at work. But fundamentally, security is all about economics: both attacker and defender are trying to maximize the return on their investments. Economics can both explain why security fails so often and offer new solutions for its success. For example, often the people who could protect a system are not those who suffer the costs of failure. Changing these economic incentives will do more to improve security than will more technology.

View this resource:

GSU's Roadmap for a World-Class Information Security Management System: ISO 27001:2005

Added by the EDUCAUSE Librarian
Title:GSU's Roadmap for a World-Class Information Security Management System: ISO 27001:2005 (ID: EDU07237)
Author(s):Tammy L. Clark (Georgia State University) and William Monahan (Georgia State University)
Origin:Presented at EDUCAUSE Annual Conferences (10/23/2007)
Type:Presentations/Speeches
Abstract:

Georgia State University is one of the first universities to embrace the ISO 27001:2005 standard for establishing an information security management system (ISMS). A systematic and disciplined approach helps us leverage technology to develop a world-class ISMS that empowers users and improves processes. This session will discuss the importance of developing a comprehensive, risk-management based information security program.

View this resource:

Information Security: Zero to 60 in 10 Years

Added by the EDUCAUSE Librarian
Title:Information Security: Zero to 60 in 10 Years (ID: EDU07251)
Author(s):Howard Muffler (Embry-Riddle Aeronautical University) and Joseph Progar (Embry-Riddle Aeronautical University)
Origin:Presented at EDUCAUSE Annual Conferences (10/23/2007)
Type:Presentations/Speeches
Abstract:

The focus on information security at Embry-Riddle Aeronautical University, as in many institutions, has evolved gradually over a number of years. Beginning with what can best be described as ad hoc initiatives driven by afterthought oversight, the university's focus on information security is maturing into a formalized, integrated business component and directive.

View this resource:

Enhancing Your Institution's Information Security

Added by the EDUCAUSE Librarian
Title:Enhancing Your Institution's Information Security (ID: EDU06039)
Author(s):Brian Fuller (BearingPoint, Inc.) and John Voloudakis (BearingPoint, Inc.)
Origin:Presented at EDUCAUSE Annual Conferences (10/10/2006)
Type:Presentations/Speeches
Abstract:Join BearingPoint and several guests for an interactive discussion on enhancing your institution's information security through development of a standards-based enterprise security program. Topics include benefits of a programmatic approach, sources of standards, components of an effective program, and strategies to apply them to a higher education environment.
View this resource:

How to Successfully Defend Against IRC Bots, Compromises, and Information Leaks

Added by the EDUCAUSE Librarian
Title:How to Successfully Defend Against IRC Bots, Compromises, and Information Leaks (ID: EDU06296)
Author(s):Tammy L. Clark (Georgia State University) and William Monahan (Georgia State University)
Origin:Presented at EDUCAUSE Annual Conferences (10/12/2006)
Type:Presentations/Speeches
Abstract:IRC "bots," Trojan horses, rootkits, "zero day" threats, compromised PCs . . . sound familiar? These threats can result in sensitive data exposures, not to mention the hassles of remediating compromised systems. We will discuss how to implement effective solutions and practices and a distributed management strategy to prevent exploits, IRC bot attacks, and unauthorized access.
View this resource:

Policy and Process for Security of Institutional Data

Added by the EDUCAUSE Librarian
Title:Policy and Process for Security of Institutional Data (ID: EDU06200)
Author(s):Tracy Mitrano (Cornell University) and Steven Schuster (Cornell University)
Origin:Presented at EDUCAUSE Annual Conferences (10/10/2006)
Type:Presentations/Speeches
Abstract:In this session we will discuss both the substance and process of developing an information security program for institutional data.
View this resource: