![]() |
|
![]() |
![]() |
|
Cybersecurity Initiative
|
![]() |
Announcements
7 Things You Should Know About Federated Identity ManagementCreated by Valerie M. Vogel (EDUCAUSE) on September 10, 2009
EDUCAUSE has released "7 Things You Should Know About Federated Identity Management". Learn more about what federated identity management is, who's doing it, why it's significant, and what the implications are for higher education by reading this 2-page publication.
Federated Identity Management Systems Recognized with the 2009 EDUCAUSE Catalyst AwardCreated by Valerie M. Vogel (EDUCAUSE) on September 10, 2009
The EDUCAUSE Catalyst Award highlights IT-based innovations and initiatives that provide groundbreaking solutions to major challenges in higher education or change prevailing conditions in remarkable ways. In 2009, EDUCAUSE recognizes federated identity management systems with this award.
Security of .edu Internet Domain to IncreaseCreated by Valerie M. Vogel (EDUCAUSE) on September 3, 2009
EDUCAUSE and VeriSign announced today the initiation of a project to enhance Internet reliability and stability. By the end of March 2010, the project will deploy a security system known as Domain Name Security Extensions (DNSSEC) within the .edu portion of the Internet, which EDUCAUSE manages under a cooperative agreement with the U.S. Department of Commerce. When the project is completed, institutions whose domain names end in .edu will be able to incorporate a digital signature into those names to limit a variety of security vulnerabilities. Read more in the press release, view DNSSEC resources, or visit the DNSSEC for .edu FAQ.
FTC Issues Final Breach Notification Rule for Electronic Health InformationCreated by Valerie M. Vogel (EDUCAUSE) on August 21, 2009
The Federal Trade Commission (FTC) has issued a final rule on Health Breach Notification, which "requires vendors of personal health records and related entities to notify consumers following a breach involving unsecured information". The rule provides additional details about the "timing, method, and content of notification" in the event of a breach, and requires companies to notify the FTC, as well as the media (in cases involving 500 or more people). This rule is effective September 24, 2009. Full compliance will be required by February 22, 2010. For more information, please visit the FTC's Health Breach Notification Rule website or recent press release.
Electronic Records Management Toolkit Now AvailableCreated by Valerie M. Vogel (EDUCAUSE) on August 18, 2009
The Higher Education Information Security Council (formerly the Security Task Force) has recently developed an Electronic Records Management Toolkit in order to provide a practical set of resources that will assist members of the higher education community in addressing related issues of electronic records management, e-discovery, and data retention on their own campuses.
2009 Computer Security Awareness Poster & Video Contest Winners AnnouncedCreated by Valerie M. Vogel (EDUCAUSE) on August 14, 2009
The EDUCAUSE/Internet2 Higher Education Information Security Council (formerly the Security Task Force), the National Cyber Security Alliance, CyberWATCH, and ResearchChannel are pleased to announce the availability of new security awareness posters and videos. The posters and videos are the winning entries in the 2009 Computer Security Awareness Poster and Video Contest, which was conducted to raise awareness of and increase computer security at colleges and universities.
Social Networking Security: Social AnxietyCreated by Valerie M. Vogel (EDUCAUSE) on August 7, 2009
Randy Marchany, Director of the Virginia Tech IT Security Testing Lab, is featured in Social Network Security: Social Anxiety, an article in the August 2009 issue of SCMagazine. Marchany discusses the unique opportunities and challenges that social networking sites present from a security standpoint.
NIST Requests Nominations for Federal Advisory CommitteesCreated by Valerie M. Vogel (EDUCAUSE) on August 5, 2009
The National Institute of Standards and Technology (NIST) recently announced that it is seeking nominations of individuals for appointment to its eight existing Federal Advisory Committees: Technology Innovation Program Advisory Board, Board of Overseers of the Malcolm Baldrige National Quality Award, Judges Panel of the Malcolm Baldrige National Quality Award, Information Security and Privacy Advisory Board, Manufacturing Extension Partnership Advisory Board, National Construction Safety Team Advisory Committee, Advisory Committee on Earthquake Hazards Reduction, and Visiting Committee on Advanced Technology. Nominations for all committees will be accepted on an ongoing basis and will be considered as and when vacancies arise.
Security Remains a Top-Three IT Issue According to EDUCAUSE 2009 Current Issues Survey ResultsCreated by Valerie M. Vogel (EDUCAUSE) on July 31, 2009
EDUCAUSE has just published the results of the 2009 Current Issues Survey. The latest EDUCAUSE Review article identifies the issues that IT leaders in higher education see as the most critical challenges they and their institutions face.
Don't Cut Your Security Budget: 10 Cost-Saving Tips for Your IT DepartmentCreated by Valerie M. Vogel (EDUCAUSE) on July 31, 2009
Many higher education IT organizations are facing pressure to reduce spending due to the current economic situation. This recent EDUCAUSE Quarterly article, "Rationalizing IT Rationing: 10 Ways to Cut the IT Budget (and What Not to Cut)", demonstrates one institution’s quest to cut technology costs while maintaining a high level of service. Author Fred Miller (Furman University) provides a list of 10 cost-cutting tips. He also emphasizes the importance of 4 things a campus should not cut (when possible), including security.
Red Flags Rule Enforcement Deadline Extended by FTC AgainCreated by Valerie M. Vogel (EDUCAUSE) on July 31, 2009
The Federal Trade Commission (FTC) announced that it will delay enforcement of the Red Flags Rule until November 1, 2009, to allow creditors and financial institutions more time to develop and implement written Identity Theft Prevention Programs. This new extension will allow FTC staff to "redouble its efforts to educate [small businesses and other entities] about compliance with the Red Flags Rule and ease compliance by providing additional resources and guidance to clarify whether businesses are covered by the Rule and what they must do to comply."
National Campus Safety and Security Survey Results ReleasedCreated by Valerie M. Vogel (EDUCAUSE) on July 24, 2009
Emergency preparedness is a priority for all colleges and universities, with a large majority reporting that they have instituted campus-wide emergency preparedness plans covering a wide spectrum of possible emergencies, according to results of the National Campus Safety and Security Project survey. The survey probed campus preparedness for all types of threats-natural disasters, acts of violence, and cyber disruptions. The project was funded in part by the Lilly Endowment. Responses to the lengthy survey, launched in August 2008, were received from 342 institutions.
NACUA Virtual Seminar on HIPAA and the HITECH Act: New Compliance Obligations for Colleges and UniversitiesCreated by Valerie M. Vogel (EDUCAUSE) on July 20, 2009
On Thursday, July 23, 12:00-2:00 pm ET, NACUA (in conjunction with EDUCAUSE) will present a virtual seminar, HIPAA and the HITECH Act: New Compliance Obligations for Colleges and Universities. The recent Health Information Technology for Economic and Clinical Health Act (HITECH Act), part of the federal stimulus bill, contained sweeping changes to HIPAA’s security and privacy requirements. These changes include:
Tune In July 8: Information Security from the Ground UpCreated by Valerie M. Vogel (EDUCAUSE) on July 1, 2009
In 2005 the University of Notre Dame suffered a serious incident that brought information security into the campus spotlight. In response, the university partnered with a Big Four consulting firm to conduct a comprehensive IT risk assessment. Three years later, they're almost done with a four-year risk management program. In this free July 8 EDUCAUSE Live! Web Seminar, Information Security from the Ground Up, presenter David Seidl, Information Security Program Manager, University of Notre Dame, will discuss the reasons for the program, how it was designed, what went into it, and how they have succeeded, as well as what was learned during this ground-up security redesign.
ECAR Publishes New Occasional Paper on IT Security Officer CareersCreated by Valerie M. Vogel (EDUCAUSE) on July 1, 2009
The Career of the IT Security Officer in Higher Education reports the result of a study designed to understand and document the attributes and responsibilities of the relatively new role of information security officer in higher education. The study employed multiple research strategies, including a literature review, an analysis of 59 job announcements and descriptions, 311 responses to a web-based quantitative survey, and qualitative interviews with individuals who answered the survey and agreed to be contacted for additional information. As a result of broad interest in this topic, the EDUCAUSE Center for Applied Research (ECAR) is delighted to make this research available online to everyone now.
NIST Publishes Final Version of the Guide to Enterprise Telework and Remote Access SecurityCreated by Valerie M. Vogel (EDUCAUSE) on June 16, 2009
NIST has published a final version of the Guide to Enterprise Telework and Remote Access Security (SP 800-46 Revision 1), which is intended to help organizations understand and mitigate the risks associated with the technologies used for telework.
2009 Security Professionals Conference: Post-Event Resources Now OnlineCreated by Rodney J. Petersen (EDUCAUSE) on May 18, 2009
Proceedings are now available for several sessions from the recent EDUCAUSE & Internet2 Security Professionals Conference. You can access them online. Podcasts of the general sessions: Protecting Privacy in a Sea of Data
CERT Podcast: Cyber Security, Safety, and Ethics for the Net GenerationCreated by Valerie M. Vogel (EDUCAUSE) on April 14, 2009
Capitalizing on the cultural norms of the Net Generation is essential when developing security awareness programs. Students and employees born between 1981 and 1994 are members of the Internet (Net) Generation. This generation has grown up with the Internet, World Wide Web, cell phones, instant messaging, blogs, and social networks.
FTC Guide: Fighting Fraud with the Red Flags RuleCreated by Valerie M. Vogel (EDUCAUSE) on April 8, 2009
The Federal Trade Commission (FTC) recently released Fighting Fraud with the Red Flags Rule: A How-To Guide for Business.The Red Flags Rule requires many businesses and organizations to implement a written Identity Theft Prevention Program designed to detect the warning signs – or "red flags" – of identity theft in their day-to-day operations.
Consensus Audit Guidelines Version 1.0 ReleasedCreated by Valerie M. Vogel (EDUCAUSE) on March 24, 2009
A consortium of federal agencies and private organizations recently released Version 1.0 of the Consensus Audit Guidelines (CAG), which define the 20 most important controls and metrics for effective cyber defense and dontinuous FISMA compliance. The public review period for the draft will end on March 25, 2009 (send comments to cag@sans.edu). The CAG initiative is part of a larger effort housed at the Center for Strategic and International Studies in Washington, DC, to advance key recommendations from the CSIS Commission report on Securing Cyberspace for the 44th Presidency.
June CAMP Workshop: Practical Building Blocks for Access ManagementCreated by Valerie M. Vogel (EDUCAUSE) on March 20, 2009
The upcoming CAMP Workshop, Practical Building Blocks for Access Management, will provide academic and administrative stakeholders and their IT partners, IT managers, security staff, and technical implementers from smaller to larger schools the chance to learn more about the basic building blocks campuses can use to get started in this complex area. Institutions are encouraged to send a team representing IT management, security, and technical staff and department stakeholders who will be employing access management to learn about these issues together and leave with next steps for access management efforts back home. Come to CAMP June 15–17 and :
National Cybersecurity Strategy: Key Improvements Are Needed to Strengthen the Nation's PostureCreated by Valerie M. Vogel (EDUCAUSE) on March 16, 2009
The U.S. Government Accountability Office (GAO) released the report "National Cybersecurity Strategy: Key Improvements Are Needed to Strengthen the Nation's Posture" on March 10, 2009. View the full report or the highlights page. Summary:
What's Behind the Rash of University Data Breaches?Created by Valerie M. Vogel (EDUCAUSE) on March 9, 2009
The March 9, 2009, Computerworld article, "What's Behind the Rash of University Data Breaches?", states:
PCI DSS (and more!) WorkshopCreated by Valerie M. Vogel (EDUCAUSE) on March 5, 2009
The Treasury Institute for Higher Education is sponsoring its fourth PCI DSS Workshop, May 4-6, 2009, in Indianapolis, IN.
The agenda and registration are now available online.
NIST Updates Secure Domain Name System (DNS) Deployment GuideCreated by Valerie M. Vogel (EDUCAUSE) on March 5, 2009
NIST has drafted a new version of the document “Secure Domain Name System (DNS) Deployment Guide (SP 800-81r1)”.Comments from federal agencies and private organizations, as well as individuals, will be accepted until March 31, 2009, and should be sent via e-mail to SecureDNS@nist.gov.
|
![]() |
| Unless otherwise noted, EDUCAUSE holds the copyright on all materials published by the association, whether in print or electronic form. In certain cases the work remains the intellectual property of the individual author(s) (see Special Circumstances). Content from conference speeches, presentations, blogs, wikis and feeds reflect the opinions of the author, and not necessarily those of EDUCAUSE or its members. | |||