Security Management; Data Security; and Articles, Papers, and Reports

Out of the Breach and into the Fire

Added by the EDUCAUSE Librarian
Title:Out of the Breach and into the Fire (ID: ERM08510)
Author(s):Heidi Wachs (Georgetown University), Kent Wada (UCLA), and Timothy Lance (NYSERNet, Inc.)
Origin:EDUCAUSE Review Articles (09/15/2008)
Type:Articles, Papers, and Reports
Abstract:

Two of the entries on the long list of data breaches in higher education are Georgetown University and UCLA. Timothy Lance recently talked with the IT policy officers at these two institutions to identify some of the policy implications of handling data breaches.

View this resource:

2008 Data Breach Investigations Report

Added by the EDUCAUSE Librarian
Title:2008 Data Breach Investigations Report (ID: CSD5395)
Author(s):Wade H. Baker (Verizon Business), C D. Hylender (Verizon Business), and J A. Valentine (Verizon Business)
Source:Verizon Business
Origin:Contributed by Organizations or Campuses (07/01/2008)
Type:Articles, Papers, and Reports
Abstract:

The 2008 Data Breach Investigations Report draws from over 500 forensic engagements handled by the Verizon Business Investigative Response team over a four-year period. Tens of thousands of data points weave together the stories and statistics from compromise victims around the world. This report seeks to answer the following questions;

  • Who is behind data breaches?
  • How do breaches occur?
  • What commonalities exist?
  • Where should mitigation efforts be focused?
View this resource:

Data Breaches Hit More Campuses

Added by the EDUCAUSE Librarian
Title:Data Breaches Hit More Campuses (ID: CSD5333)
Author(s):Andrew Guess (Inside Higher Ed)
Origin:Contributed by Organizations or Campuses (02/12/2008)
Type:Articles, Papers, and Reports
Abstract:

Review of news sources and databases shows an increase in the number of both security incidents and affected institutions in the last year.

View this resource:

Data Breaches in Higher Education: From Concern to Action

Added by the EDUCAUSE Librarian
Title:Data Breaches in Higher Education: From Concern to Action (ID: ERM08111)
Author(s):Peter M. Siegel (University of California, Davis)
Origin:EDUCAUSE Review Articles (01/18/2008)
Type:Articles, Papers, and Reports
Abstract:

"When is higher education going to get serious about safeguarding the private information of students,
faculty, and staff?"

View this resource:

Large Scale Collection and Sanitization of Network Security Data: Risks and Challenges

Added by the EDUCAUSE Librarian
Title:Large Scale Collection and Sanitization of Network Security Data: Risks and Challenges (ID: CSD5281)
Author(s):Phillip Porras (SRI International) and Vitaly Shmatikov (University of Texas at Austin)
Origin:Contributed by Organizations or Campuses (09/26/2006)
Type:Articles, Papers, and Reports
Abstract:

"Over the last several years, there has been an emerging interest in the development of wide-area data collection and analysis centers to help identify, track, and formulate responses to the ever-growing number of coordinated attacks and malware infections that plague computer networks worldwide. As large-scale network threats continue to evolve in sophistication and extend to widely deployed applications, we expect that interest in collaborative security monitoring infrastructures will continue to grow, because such attacks may not be easily diagnosed from a single point in the network. The intent of this position paper is not to argue the necessity of Internet-scale security data sharing infrastructures, as there is ample research [13, 48, 51, 54, 41, 47, 42] and operational examples [43, 17, 32, 53] that already make this case. Instead, we observe that these well-intended activities raise a unique set of risks and challenges.
We outline some of the most salient issues faced by global network security centers, survey proposed defense mechanisms, and pose several research challenges to the computer security community. We hope that this position paper will serve as a stimulus to spur groundbreaking new research in protection and analysis technologies that can facilitate the collaborative sharing of network security data while keeping data contributors safe and secure."

View this resource:

Final Report of the 2007 Cybersecurity Summit

Added by the EDUCAUSE Librarian
Title:Final Report of the 2007 Cybersecurity Summit (ID: CYB0701)
Origin:Contributed by the Security Task Force, Presented at Cybersecurity Summit (11/30/2007)
Type:Articles, Papers, and Reports
Abstract:

This is the final report for the 2007 NSF Cybersecurity Summit, held February 22 & 23rd, 2007, in Arlington, VA.

View this resource:

The University's Role in Advancing Data Encryption, Part 1

Added by the EDUCAUSE Librarian
Title:The University's Role in Advancing Data Encryption, Part 1 (ID: CSD5214)
Author(s):Andrew K. Burger (ECT News Network)
Source:TechNewsWorld
Origin:Contributed by Organizations or Campuses (11/02/2007)
Type:Articles, Papers, and Reports
Abstract:

"Much like Moore's Law, PGP has seen huge advances in encryption technologies over the years -- specifically the ability for encryption to work faster and easier in a network while still being transparent to the end user," said Phillip Dunkelberger, President and CEO, PGP Corporation. Excellent encryption research is being carried out at a number of major universities, though it's still at a nascent stage.

View this resource:

The University's Role in Advancing Data Encryption, Part 2

Added by the EDUCAUSE Librarian
Title:The University's Role in Advancing Data Encryption, Part 2 (ID: CSD5213)
Author(s):Andrew K. Burger (ECT News Network)
Source:TechNewsWorld
Origin:Contributed by Organizations or Campuses (11/02/2007)
Type:Articles, Papers, and Reports
Abstract:

"Identity theft is one of the fastest-growing cyber-crimes, and, as a result, 38 states have identity theft legislation -- with some states using encryption as a safe haven," said Southwestern Illinois Community College CIO Christine Leja. "The education market as a whole is becoming more serious about protecting student information and is looking to encryption as the means to making that happen."

View this resource:

Training Your Staff to Protect SIS Data

Added by the EDUCAUSE Librarian
Title:Training Your Staff to Protect SIS Data (ID: CSD5118)
Author(s):Marcia Layton Turner (University Business)
Origin:Contributed by Organizations or Campuses (09/05/2007)
Type:Articles, Papers, and Reports
Abstract:

"No matter how robust your firewall, trained faculty and staff are your first line of defense against system breaches."

View this resource:

2006 Annual Study: Cost of a Data Breach Understanding Financial Impact, Customer Turnover, and Preventative Solutions

Added by the EDUCAUSE Librarian
Title:2006 Annual Study: Cost of a Data Breach Understanding Financial Impact, Customer Turnover, and Preventative Solutions (ID: CSD5015)
Source:Inc., PGP Corporation and Vontu
Origin:Contributed by Organizations or Campuses (07/24/2006)
Type:Articles, Papers, and Reports
Abstract:

This study summarizies the actual costs incurred by 31 organizations that lost confidential customer information and had a regulatory requirement to publicly notify affected individuals.

View this resource: