![]() |
|
![]() |
![]() |
|
Cybersecurity Initiative
|
![]() |
Announcements
NIST Updates Recommendations for IT Security ControlsCreated by Valerie M. Vogel (EDUCAUSE) on February 17, 2009
NIST has announced the release of the Initial Public Draft (IPD) of Special Publication 800-53, Revision 3, Recommended Security Controls for Federal Information Systems and Organizations. Comments will be accepted until March 27, 2009. Comments should be sent via e-mail to sec-cert@nist.gov.
2009 Academic Medical Center Security and Privacy Conference: New Challenges, New SolutionsCreated by Valerie M. Vogel (EDUCAUSE) on February 17, 2009
The 2009 Academic Medical Center (AMC) Security and Privacy Conference: New Challenges, New Solutions will take place March 1-4, 2009 in Chapel Hill, NC. This conference provides an excellent opportunity to learn about how other AMCs are handling important issues like security for mobile devices, compliance with e-discovery mandates and data protection regulations, and research productivity and funding. As with our prior conferences, the 2009 conference is based on the principle that AMC privacy and security leaders gain great value from contact with their peers. Each session is led by panelists from AMCs across the country. There are plenary sessions and breakout sessions on Compliance/Governance, Research, and Security topics. The sessions include time for discussion, and there is ample time to network with peers outside the sessions as well. View the program or register now.
Security Task Force Leadership Update (February 2009)Created by Valerie M. Vogel (EDUCAUSE) on February 6, 2009
We would like to thank Mely Tynan (Vice President for IT and CIO, Tufts University) for her 2 years of service as a co-chair and member of the EDUCAUSE/Internet2 Computer and Network Security Task Force. We would also like to welcome Brian Voss (Vice Chancellor for Information Technology & CIO, Louisiana State University), who begins his term as co-chair of the Security Task Force. He will serve alongside Pete Siegel (CIO & Vice Provost, Information & Educational Technology, University of California, Davis), a co-chair since 2006.
New Data Protection Contractual Language Toolkit AvailableCreated by Valerie M. Vogel (EDUCAUSE) on February 5, 2009
The Security Task Force Policies & Legal Issues Working Group wishes to inform higher education information security practioners of a new resource which is now available in the IT Security Guide. The Data Protection Contractual Language toolkit provides sample contract language for common themes related to data protection as well as practical guidance as to when and how to consider the themes when drafting or reviewing a contract.
Register Now for the 2009 EDUCAUSE & Internet2 Security Professionals ConferenceCreated by Valerie M. Vogel (EDUCAUSE) on February 5, 2009
We are facing many challenges as a nation during this economic downturn. However, with a change of administration in Washington, D.C., increased threats to the security of our cyberinfrastructure, and reconsideration of campus priorities, it's clearly time to share, explore, and work together toward the common good. Attend the Security Professionals Conference 2009, "Safeguarding Our IT Assets, Protecting Our Community's Privacy," which will offer a unique setting to meet with fellow security practitioners and other IT professionals focused on data privacy and security, discuss similar problems, and learn about useful solutions.
Obama Administration Outlines Cybersecurity StrategyCreated by Valerie M. Vogel (EDUCAUSE) on February 5, 2009
The Obama administration has posted on its website its agenda for Homeland Security, including several key strategies related to cybersecurity. Under the heading of "Protect our Information Networks," they write:
Final Report Issued on "Securing Cyberspace for the 44th Presidency"Created by Valerie M. Vogel (EDUCAUSE) on February 5, 2009
The Center for Strategic and International Studies (CSIS) Commission on Cybersecurity for the 44th Presidency has released its final report, "Securing Cyberspace for the 44th Presidency." The Commission’s three major findings are:
Recommendations include:
Final FERPA Rules Announced by Department of EducationCreated by Valerie M. Vogel (EDUCAUSE) on February 5, 2009
The U.S. Department of Education, through its Family Policy Compliance Office, has issued its Final Rules on the Family Educational Rights and Privacy Act (FERPA). The rules cover a variety of issues of interest to IT leaders, ranging from information security topics to the use of SSN's and Student ID's as electronic identifiers. A more thorough analysis will be available in the next few days. For more information, see: Federal Register Notice: http://www.access.gpo.gov/su_docs/aces/fr-cont.html Final Rule (PDF): http://www.ed.gov/legislation/FedRegister/finrule/2008-4/120908a.pdf Final Rule (HTML): http://www.ed.gov/legislation/FedRegister/finrule/2008-4/120908a.html
National Cyber Security Awareness Month 2008 Wrap-UpCreated by Valerie M. Vogel (EDUCAUSE) on November 4, 2008
This year's National Cyber Security Awareness Month (NCSAM) is now over and the list of 2008 campus events on the EDUCAUSE Security Task Force NCSAM Resource Kit website, demonstrates the tremendous effort, creativity and hard work that many of you contributed in support of this important initiative. THANK YOU to all of you for your support. If your event is not yet listed on the website, please share the URL or brief description of your NCSAM-related initiatives, as well as the outcomes you realized, with the participants on this discussion list or send an email to Security-Task-Force@educause.edu. Sincerely, Awareness and Training Working Group Co-Chairs Cherry Delaney (Purdue University) and Jodi Ito (University of Hawaii)
Participate as a Presenter at the 2009 Security Professionals ConferenceCreated by Valerie M. Vogel (EDUCAUSE) on October 20, 2008
The 2009 EDUCAUSE and Inernet2 Security Professionals Conference—featuring keynote speakers Joanne McNabb, Chief of the Office of Privacy Protection, State of California, and Edward Amoroso, Chief Information Security Officer, AT&T—will address privacy and security topics in the areas of management and operations, policy and compliance, and technology. Participate as a presenter: Presenters help create an innovative and informative program, make valuable contacts, and gain recognition for their achievements and their organization's. Presentations will need to address one of the following categories:
Free EDUCAUSE Webcast 10/22/08 on Identity Theft RulesCreated by Valerie M. Vogel (EDUCAUSE) on October 13, 2008
New federal regulations to address identity theft go into effect November 1, 2008, and are likely to affect colleges and universities in nuanced ways. Compliance will require careful study and collaboration among business officers, human resources, legal counsel, student services, IT, and other affected campus units. The rules require users of consumer reports to develop reasonable policies and procedures to apply when they receive a notice of address discrepancy from a consumer reporting agency. They also require that institutions develop and implement an Identity Theft Prevention Program for combating identity theft in connection with new and existing accounts.
DNSSEC Notice of InquiryCreated by Valerie M. Vogel (EDUCAUSE) on October 10, 2008
The National Telecommunications and Information Administration (NTIA) is inviting comments regarding Domain Name and Addressing System Security Extensions (DNSSEC) implementation at the root zone. Comments are due on November 24, 2008. EDUCAUSE and Internet2 are planning to prepare joint comments so your input is welcome. Below are a few additional resources:
DHS Releases IT Security Essential Body of KnowledgeCreated by Valerie M. Vogel (EDUCAUSE) on October 2, 2008
The U.S. Department of Homeland Security (DHS) has published the IT Security Essential Body of Knowledge (EBK). A Glossary of Key Terms used in the EBK is also provided. According to the overview on the US-CERT website:
The EBK was featured in a November 2007 EDUCAUSE Live! presentation when DHS was accepting comments on a draft version of the document.
National Cyber Security Awareness Month 2008 is HERE!Created by Valerie M. Vogel (EDUCAUSE) on October 1, 2008
October is National Cyber Security Awareness Month (NCSAM). As we rely more on technology-based solutions in our everyday lives, cybersecurity becomes everyone's responsibility. We encourage you to consider ways you can raise awareness among your faculty, staff, and students and invite you to help promote NCSAM. For further suggestions, please consult the Resource Kit for National Cyber Security Awareness Month, developed by the EDUCAUSE/Internet2 Higher Education Information Security Council (formerly the Security Task Force). Additional EDUCAUSE resources include:
Security & Privacy-Related Sessions at EDUCAUSE 2008Created by Valerie M. Vogel (EDUCAUSE) on September 24, 2008
Explore the security and privacy-related conference sessions at EDUCAUSE 2008 (October 28-31 in Orlando, Florida). Register for the conference by September 29 to receive the low early-bird rates.
Share Your Campus Plans to Observe National Cyber Security Awareness Month 2008Created by Valerie M. Vogel (EDUCAUSE) on September 17, 2008
October is National Cyber Security Awareness Month (NCSAM)...but it's never too soon to start planning your campus events!!! We encourage you to consider ways that you can raise awareness among your faculty, staff, and students, and invite you to help promote NCSAM. For further suggestions, please consult the Resource Kit for National Cyber Security Awareness Month, developed by the EDUCAUSE/Internet2 Security Task Force.
Security Task Force 2008–2009 Strategic Plan: "Safeguarding Our IT Assets, Protecting Our Community's Privacy"Created by Valerie M. Vogel (EDUCAUSE) on September 8, 2008
The EDUCAUSE/Internet2 Computer and Network Security Task Force 2008-2009 Strategic Plan is now available online. The Security Task Force (STF) has adopted the theme of "Safeguarding Our IT Assets, Protecting Our Community's Privacy" for 2008-2009. The STF strategic planning process aims to anticipate higher education security issues, enabling campuses to forge joint efforts and solutions and recognizing that security challenges continue to evolve in our digital information world. The following goals have been identified for 2008-2009 to help focus working group priorities in the near term (12-18 months):
Protecting Your Institution from Phishing Attacks: Education and Awareness ResourcesCreated by Valerie M. Vogel (EDUCAUSE) on August 26, 2008
Although phishing is not a new threat to the higher ed community, many schools have experienced an increasing number of targeted phishing attacks over the past several months. These phishing e-mails ask students, faculty, and staff to provide their institutional username and password. Once an account is compromised, it is typically used to send out more spam, which creates a new set of problems for the institution.
Building a Security Program to Include MetricsCreated by Valerie M. Vogel (EDUCAUSE) on August 13, 2008
In "Security Metrics: A Solution in Search of a Problem", a recent EDUCAUSE Quarterly article, Joel Rosenblatt (Manager of Computer and Network Security, Columbia University) describes how the creation and collection of appropriate metrics can enhance an institution's security program. Learn about some potential metrics in the following areas: policy and compliance, network and machine monitoring, outreach and education, legal compliance, authorization and authentication, asset protection, and privacy.
Information Sharing for IT Security ProfessionalsCreated by Valerie M. Vogel (EDUCAUSE) on August 13, 2008
Learn how to develop a network of professional contacts in order to create an effective support system for information sharing within the IT Security community. Read the article "Information Sharing for IT Security Professionals" by EDUCAUSE Security Task Force Coordinator, Rodney Petersen in the latest EDUCAUSE Quarterly.
Security is Number One IT Issue According to 2008 Current Issues Survey ReportCreated by Valerie M. Vogel (EDUCAUSE) on May 29, 2008
EDUCAUSE has published the results of the 2008 Current Issues Survey, and this year Security edged out Funding IT as the top strategic challenge. The latest EDUCAUSE Quarterly article, "Current Issues Survey Report, 2008", states:
Security Task Force Submits Comments on Proposed FERPA RulesCreated by Valerie M. Vogel (EDUCAUSE) on May 29, 2008
Help Promote the 2009 Computer Security Awareness Student Poster & Video ContestCreated by Valerie M. Vogel (EDUCAUSE) on May 1, 2008
The EDUCAUSE/Internet2 Computer and Network Security Task Force, in cooperation with the ResearchChannel, is conducting its third annual contest in search of computer security awareness posters and short videos developed by college students for college students. The contest, which is co-sponsored by the National Cyber Security Alliance (NCSA) and CyberWATCH, offers cash prizes ($1,000, $800 and $400) to the winners in each of the four categories. It also provides an opportunity for students to gain experience by developing creative and effective short videos or posters. The deadline for submission of entries is April 30, 2009.
Baker College Takes First Place in the 2008 National Collegiate Cyber Defense Competition (NCCDC)Created by Valerie M. Vogel (EDUCAUSE) on April 24, 2008
Congratulations to Baker College (Flint, Michigan) on winning the third annual National Collegiate Cyber Defense Competition! After competing for the last three years, the Baker College team finally made it past the regional level to beat the 2007 winners from Texas A&M University. The competition is a three day event hosted by the University of Texas at San Antonio's Center for Infrastructure Assurance and Security, a cybersecurity research and education center. Students have the opportunity to test their knowledge of network infrastructure management and protection in an operational environment. The competition also provides students with a chance to interact and discuss the security and operational challenges they will face upon entering the job market.
Security Task Force Provides Briefing to CSIS Commission on Cyber Security for the 44th PresidencyCreated by Valerie M. Vogel (EDUCAUSE) on March 26, 2008
The EDUCAUSE/Internet Security Task Force provided a briefing to the CSIS Commission on Cyber Security for the 44th Presidency on March 12, 2008, during the event "Improving Cybersecurity: Recommendations from Private Sector Experts". A 1-page summary of the briefing is available, as well as the complete transcript.
|
![]() |
| Unless otherwise noted, EDUCAUSE holds the copyright on all materials published by the association, whether in print or electronic form. In certain cases the work remains the intellectual property of the individual author(s) (see Special Circumstances). Content from conference speeches, presentations, blogs, wikis and feeds reflect the opinions of the author, and not necessarily those of EDUCAUSE or its members. | |||