Contributed by the Security Task Force

Business Continuity Planning Toolkit

Added by the EDUCAUSE Librarian
Title:Business Continuity Planning Toolkit (ID: CSD5378)
Origin:Contributed by the Security Task Force (05/29/2008)
Type:Tools
Abstract:

The purpose of this toolkit is to provide resources for business continuity and disaster recovery planning, including guides, templates, examples and tips.  The information provided herein is intended to be of value in the development, testing, enactment and revising of business continuity efforts. This Business Continuity Planning and Disaster Recovery toolkit is an ongoing work in progress.  As new resources are developed and best practices shift, updated information will be provided here.

View this resource:

Information Risk Management Policy Template

Added by the EDUCAUSE Librarian
Title:Information Risk Management Policy Template (ID: CSD5368)
Origin:Contributed by the Security Task Force (03/17/2008)
Type:Plans and Guidelines
Abstract:

The purpose of this policy template is to ensure that risks to University information are identified, analyzed, and managed so that they are maintained at acceptable levels. Risks to the confidentiality, integrity, and availability of university information are considered.

View this resource:

Information Security Strategic Plan Template

Added by the EDUCAUSE Librarian
Title:Information Security Strategic Plan Template (ID: CSD5367)
Origin:Contributed by the Security Task Force (03/17/2008)
Type:Plans and Guidelines
Abstract:
  • This plan was adapted from the University of Colorado System’s “IT Security Program Strategic Plan for 2007-2008.”
  • The purpose of this sample plan is to establish a formal IT Security Program for your institution.
  • The intended audience for this plan is your executive leadership, up to and including board members and external constituents where appropriate.
View this resource:

Information Security Risk Assessment Consultants List

Added by the EDUCAUSE Librarian
Title:Information Security Risk Assessment Consultants List (ID: CSD5366)
Origin:Contributed by the Security Task Force (03/14/2008)
Type:Vendors
Abstract:

The Risk Assessment Consultants List is intended as an aid to schools seeking a place to start looking for risk assessment vendors. It provides links to referencing institutions which may be able to provide additional information regarding specific consulting engagements. Note: The only way a vendor can get onto this list is to be placed there by an EDUCAUSE member institution that has engaged the consultant.

View this resource:

Risk Assessment Tools List

Added by the EDUCAUSE Librarian
Title:Risk Assessment Tools List (ID: CSD5365)
Origin:Contributed by the Security Task Force (03/14/2008)
Type:Tools
Abstract:

The Security Task Force Risk Assessment Working Group has developed this list of Risk Assessment tools which can aid with a risk assessment. The tools are a mix of some sold or licensed by vendors, some provided by colleague institutions, and some from associations or standards groups. This list does not contain any comparative or value judgment information regarding the tools. It merely provides the list as a starting point for the product-seeking process.

View this resource:

Briefing to CSIS Commission on Cyber Security for the 44th Presidency

Added by the EDUCAUSE Librarian
Title:Briefing to CSIS Commission on Cyber Security for the 44th Presidency (ID: CSD5363)
Author(s):Rodney J. Petersen (EDUCAUSE) and John J. Suess (University of Maryland, Baltimore County)
Origin:Contributed by the Security Task Force (03/13/2008)
Type:Articles, Papers, and Reports
Abstract:

This "Briefing to CSIS Commission on Cyber Security for the 44th Presidency" By Rodney Petersen and Jack Suess on behalf of the EDUCAUSE/Internet2 IT Security Task Force was presented to the Commission on Cyber Security for the 44th Presidency. The agenda was "Improving Cybersecurity: Recommendations from Private Sector Experts".

View this resource:

NIST 800-88 Guidelines for Media Sanitization

Added by the EDUCAUSE Librarian
Title:NIST 800-88 Guidelines for Media Sanitization (ID: CSD5265)
Author(s):Richard Kissel (National Institute of Standards and Technology), Matthew scholl (National Institute of Standards and Technology), Steven Skolochenko (National Institute of Standards and Technology), and Xing Li (National Institute of Standards and Technology)
Source:National Institute of Standards and Technology
Origin:Contributed by the Security Task Force (09/28/2006)
Type:Plans and Guidelines
Abstract:

This guide will assist organizations and system owners in making practical sanitization decisions based on the level of confidentiality of their information. It does not, and cannot, specifically address all known types of media; however, the described sanitization decision process can be applied universally. It should also be noted that Title 40 USC advises system owners and custodians that excess equipment is "Educationally useful" and "Federal equipment is a vital national resource." Wherever possible, excess equipment and media should be made available to schools and non-profit organizations to the extent permitted by law.

View this resource:

University of Tennessee Sanitization of Electronic Media

Added by the EDUCAUSE Librarian
Title:University of Tennessee Sanitization of Electronic Media (ID: CSD5264)
Source:The University of Tennessee
Origin:Contributed by the Security Task Force (12/07/2007)
Type:Policies and Procedures
Abstract:

These are the regulations governing the use, transfer, and storage of electronic information are changing. Federal regulations (HIPAA, GLBA, and FERPA) require that guidelines be established to ensure that protected information is securely removed from electronic data storage media, prior to its reuse, transfer, or disposal.

View this resource:

Final Report of the 2007 Cybersecurity Summit

Added by the EDUCAUSE Librarian
Title:Final Report of the 2007 Cybersecurity Summit (ID: CYB0701)
Origin:Contributed by the Security Task Force, Presented at Cybersecurity Summit (11/30/2007)
Type:Articles, Papers, and Reports
Abstract:

This is the final report for the 2007 NSF Cybersecurity Summit, held February 22 & 23rd, 2007, in Arlington, VA.

View this resource:

Security Certifications

Added by the EDUCAUSE Librarian
Title:Security Certifications (ID: CSD5087)
Author(s):Bruce Schneier
Origin:Contributed by the Security Task Force (08/28/2007)
Type:Articles, Papers, and Reports
Abstract:

The author explains his change of views on the usefulness of security certifications.

View this resource:

Security Certified Program Certifications

Added by the EDUCAUSE Librarian
Title:Security Certified Program Certifications (ID: CSD5086)
Source:Security Certified Program
Origin:Contributed by the Security Task Force (08/28/2007)
Type:Certification, Education, Training and Tutorials
Abstract:

The Security Certified Program offers certifications in Security Certified Network Specialist (SCNS), Security Certified Network Professional (SCNP), and Security Certified Network Architect (SCNA).

View this resource:

RSA Certified Security Professional

Added by the EDUCAUSE Librarian
Title:RSA Certified Security Professional (ID: CSD5085)
Source:RSA Security Inc.
Origin:Contributed by the Security Task Force (08/28/2007)
Type:Certification, Education, Training and Tutorials
Abstract:

The RSA Certified Security Professional Program offers technology professionals the knowledge, skills, and credentials necessary to deploy and maintain reliable enterprise security systems.

View this resource:

Red Hat Certified Security Specialist (RHCSS)

Added by the EDUCAUSE Librarian
Title:Red Hat Certified Security Specialist (RHCSS) (ID: CSD5084)
Source:Red Hat
Origin:Contributed by the Security Task Force (08/28/2007)
Type:Certification, Education, Training and Tutorials
Abstract:

This security certification provides advanced skills in using Red Hat Enterprise Linux, SELinux, and Red Hat Directory Server.

View this resource:

Microsoft Certified Systems Engineer (MCSE)

Added by the EDUCAUSE Librarian
Title:Microsoft Certified Systems Engineer (MCSE) (ID: CSD5083)
Source:Microsoft
Origin:Contributed by the Security Task Force (08/28/2007)
Type:Certification, Education, Training and Tutorials
Abstract:

This web site provides information about the Microsoftt Certified Systems Engineer (MCSE) program for security candidates on the Microsoft Windows Server 2003 track.

View this resource:

CompTIA Security Certification

Added by the EDUCAUSE Librarian
Title:CompTIA Security Certification (ID: CSD5082)
Source:CompTIA
Origin:Contributed by the Security Task Force (08/28/2007)
Type:Certification, Education, Training and Tutorials
Abstract:

CompTIA Security Certification provides knowledge of communication security, infrastructure security, cryptography, operational security, and general security concepts. It is an international, vendor-neutral certification that is taught at colleges, universities and commercial training centers around the world.

View this resource: