Presented at Security Professionals Conference

The Data Center Within a Data Center: Building a Secure Environment for Compliance

Added by the EDUCAUSE Librarian
Title:The Data Center Within a Data Center: Building a Secure Environment for Compliance (ID: SEC08074)
Author(s):David Seidl (University of Notre Dame)
Origin:Presented at Security Professionals Conference (05/04/2008)
Type:Presentations/Speeches
Abstract:

PCI compliance can be daunting, particularly in a university network environment. Notre Dame chose a data center within a data center approach to simplify compliance and minimize integration issues. This project includes implementing the data center, a virtual network to support point-of-sale devices, and related operational procedures.

View this resource:

The Shifting Landscape

Added by the EDUCAUSE Librarian
Title:The Shifting Landscape (ID: SEC08076)
Author(s):Brian Smith-Sweeney (New York University)
Origin:Presented at Security Professionals Conference (05/04/2008)
Type:Presentations/Speeches
Abstract:

Operating system and application vendors are finally starting to ship products secure by default. Not to be outdone, the attacker community has changed both motivation and operation: Careless vandals are being replaced by organized cybercriminals with advanced attack techniques. See how this shifting landscape affects traditional security strategies.

View this resource:

Security Standards: Complexity Is the Enemy of Security

Added by the EDUCAUSE Librarian
Title:Security Standards: Complexity Is the Enemy of Security (ID: SEC08060)
Author(s):Brian Smith-Sweeney (New York University), Daniel Adinolfi (Cornell University), and Christopher Misra (University of Massachusetts Amherst)
Origin:Presented at Security Professionals Conference (05/04/2008)
Type:Presentations/Speeches
Abstract:

Everyone wants to know how to "be secure." The myriad higher ed compliance requirements, coupled with a constantly dynamic attacker strategy, have made this question more difficult than ever to answer. Come talk with representatives from three institutions that managed to craft a rational, coherent strategy for standardizing security.

View this resource:

Creating and Maintaining a Security Awareness Program

Added by the EDUCAUSE Librarian
Title:Creating and Maintaining a Security Awareness Program (ID: SEC08066)
Author(s):Cherry Delaney (Purdue University)
Origin:Presented at Security Professionals Conference (05/04/2008)
Type:Presentations/Speeches
Abstract:

Information security and the protection of a university's information assets and intellectual property begin with security awareness and education. This session will discuss Purdue University's approach to security education and training, focused on the university community at large, which is designed to develop and preserve a culture of security awareness.

View this resource:

Bridging Security and Identity Management: Can't We Just Get Along?

Added by the EDUCAUSE Librarian
Title:Bridging Security and Identity Management: Can't We Just Get Along? (ID: SEC08080)
Author(s):Christopher Misra (University of Massachusetts Amherst) and John J. Suess (University of Maryland, Baltimore County)
Origin:Presented at Security Professionals Conference (05/04/2008)
Type:Presentations/Speeches
Abstract:

Security staff want to keep the bad guys out, and identity management (IdM) staff want to let the good guys in. This session will explore this generalization and how to bridge issues in technology, policy, process, and reporting structures relating to security and IdM to achieve shared institutional goals.

View this resource:

Welcome and Introductions

Added by the EDUCAUSE Librarian
Title:Welcome and Introductions (ID: SEC08010)
Author(s):Mark A. Luker (EDUCAUSE), Gary R. Bachula (Internet2), Peter M. Siegel (University of California, Davis), Mark S. Bruhn (Indiana University System), and Gary Dobbins (University of Notre Dame)
Origin:Presented at Security Professionals Conference (05/04/2008)
Type:Presentations/Speeches
Abstract:

The following presentations are from the "Welcome and Introductions"of the 2008 Security Professionals Conference.

View this resource:

First-Time Attendees: How to Get the Most Out of the Conference Experience

Added by the EDUCAUSE Librarian
Title:First-Time Attendees: How to Get the Most Out of the Conference Experience (ID: SEC08011)
Author(s):Rodney J. Petersen (EDUCAUSE) and Gary Dobbins (University of Notre Dame)
Origin:Presented at Security Professionals Conference (05/04/2008)
Type:Presentations/Speeches
Abstract:

This session will help you get the most out of your attendance at the Security Professionals Conference. Beyond a conference overview, we will address how to make smart choices about which sessions to attend, network with colleagues in similar situations, be intentional about taking home what you learned, and become more professionally involved in the activities of the EDUCAUSE/Internet2 Security Task Force.

View this resource:

Combating Stealth Malware and Botnets in Higher Education

Added by the EDUCAUSE Librarian
Title:Combating Stealth Malware and Botnets in Higher Education (ID: SEC08004)
Author(s):Michael J. Staggs (FireEye, Inc.) and Fred Archibald (University of California, Berkeley)
Origin:Presented at Security Professionals Conference (05/04/2008)
Type:Presentations/Speeches
Abstract:

UC Berkeley's Electrical Engineering and Computer Sciences department wanted to strengthen security for mobile users on the wireless network. This talk will cover practical knowledge required to address network security incidents in a forensically sound manner. The university selected FireEye's antimalware solution to protect against targeted stealth malware.

View this resource:

Securing a Free and Open University Environment

Added by the EDUCAUSE Librarian
Title:Securing a Free and Open University Environment (ID: SEC08001)
Author(s):Brian Foster (Symantec Corporation) and Seth Shestack (Temple University)
Origin:Presented at Security Professionals Conference (05/04/2008)
Type:Presentations/Speeches
Abstract:

University computing environments can be a security nightmare of unpredictability, diversity, and ongoing demand for availability with minimal restrictions. Simultaneously, university IT must protect the students, faculty, and staff they support. The answer? Deploy the right tools and tactics at the right time to enforce security policy compliance.

View this resource:

Addressing Complex Security Threats Through Risk Management

Added by the EDUCAUSE Librarian
Title:Addressing Complex Security Threats Through Risk Management (ID: SEC08008)
Author(s):Rebecca Whitener (EDS)
Origin:Presented at Security Professionals Conference (05/04/2008)
Type:Presentations/Speeches
Abstract:

In this session, we will address the current cybersecurity issues that are challenging higher education leaders today as they try to stay on top of the risks associated with attacks on information systems from internal and external sources. Emerging enterprise risk management (ERM) methodologies will be examined as a source of guidance for creating an effective risk-based approach for managing current and future threats.

View this resource:

Security Uncertainty: What Matters, Motivates, and Moves!

Added by the EDUCAUSE Librarian
Title:Security Uncertainty: What Matters, Motivates, and Moves! (ID: SEC08079)
Author(s):James Lowe (University of Wisconsin-Madison) and Stefan Wahe (University of Wisconsin-Madison)
Origin:Presented at Security Professionals Conference (05/04/2008)
Type:Presentations/Speeches
Abstract:

Good security requires good communications and understanding. It is key to agree on effective and efficient processes and technologies that implement security controls. How do we get senior administrators, security professionals, and technologists all speaking the same language so smart decisions can be made?

View this resource:

Effective Windows Desktop Security: XP and Vista

Added by the EDUCAUSE Librarian
Title:Effective Windows Desktop Security: XP and Vista (ID: SEC08081)
Author(s):John Bruggeman (Hebrew Union College-Jewish Institute of Religion)
Origin:Presented at Security Professionals Conference (05/04/2008)
Type:Presentations/Speeches
Abstract:

Windows desktops are widely deployed and can be subject to multiple attack vectors. Windows XP and Vista have vulnerabilities that need to be mitigated effectively by security teams or by end users. This session will cover the top security vulnerabilities in Windows desktops and how to secure them quickly and effectively, along with the tools to use.

View this resource:

An ARP Spoofing and Router Impersonation Incident

Added by the EDUCAUSE Librarian
Title:An ARP Spoofing and Router Impersonation Incident (ID: SEC08078)
Author(s):David Greenberg (Indiana University)
Origin:Presented at Security Professionals Conference (05/04/2008)
Type:Presentations/Speeches
Abstract:

Follow along as we track down the source of JavaScript injection into web pages through the use of ARP flooding and router impersonation on the IU network. How did it happen, what tools did we use to track it down, and what can we do about this type of attack?

View this resource:

Collecting and Preserving Data in the Wake of a Tragedy

Added by the EDUCAUSE Librarian
Title:Collecting and Preserving Data in the Wake of a Tragedy (ID: SEC08073)
Author(s):William Dougherty (Virginia Tech)
Origin:Presented at Security Professionals Conference (05/04/2008)
Type:Presentations/Speeches
Abstract:

After the tragic events of April 16, 2007, at Virginia Tech, IT professionals and university legal counsel had to quickly address the need to collect and preserve data in the event of future litigation. Performing tasks while dealing with grief and protecting academic freedom and privacy issues has required a delicate approach.

View this resource:

Using Nontraditional Security Risk Assessments to Measure Risk, Request Budgets, and Illustrate Trends

Added by the EDUCAUSE Librarian
Title:Using Nontraditional Security Risk Assessments to Measure Risk, Request Budgets, and Illustrate Trends (ID: SEC08075)
Author(s):Benjamin Nathan (Weill Cornell Medical College)
Origin:Presented at Security Professionals Conference (05/04/2008)
Type:Presentations/Speeches
Abstract:

Learn how Weill Cornell Medical College employs a nontraditional risk management methodology to accurately measure risk, build compelling and successful budget requests, and graphically illustrate trends understandable to technical and nontechnical stakeholders. Attendees will receive Excel tools they can use to manage their own risk assessments in this way.

View this resource: