Main Nav

Participate in this Group

Search This Group

April 9, 2012 | Quentin L. McCallum

 

Lansing Community College implemented Forefront in Summer 2011. Starting in 2011 Q4  Forefront was detecting and reporting Alureon infections. Forefront was not able to quarantine nor remove the malware. Currently our solution is to use a couple of anti-malware products in tandem to completely remove Alureon (certain variants).

 

A/V environment:

·         Forefront client, server, and reporting server are 2010.

·         Clients are configured via AD/GP for daily, quick scans and weekly, full scans.

·         Signatures are updated before all scans.

 

Other...

April 6, 2012 | Eric Sabo

We are seeking information on how universities are handling their end users that are using dropbox.    

 

Any information on this subject would be greatly appreciated.

 

 

 

April 5, 2012 | Steven Lovaas
Hello everyone, We were approached by our research services group with a request to consider implementing iThenticate, the service that several Federal granting agencies use to detect plagiarism in grant submissions. Apparently they may be wanting to use it locally (just as professors let students use TurnItIn to check their own work), but we wonder about how it's going to authenticate internally. Does anyone have experience with this product they could share? Thanks, Steve =================== Steven Lovaas IT Security Manager Colorado State University steven.lovaas@colostate.edu 970-297-3707 ===================
April 3, 2012 | Listserv Anonymous User
Message from nxg13@psu.edu

I want to thank all of you who participated in this survey.  If you haven’t yet, this is a LAST CALL for anyone who wanted to get their opinions registered.  I will be closing this survey on Friday.

 

https://pennstate.qualtrics.com/SE/?SID=SV_23Sp1dE6fBSQ9ko

 

Again, thank you for your assistance!

 

-- Nick

 

---

Nick Giacobe

Research Technologist V and Ph.D Candidate

College of Information Sciences and Technology

Penn State University

...
April 3, 2012 | Dennis Devlin

The George Washington University Division of Information Technology is currently actively considering qualified candidates for the positions of Computer Forensic Information Security Systems Engineer (http://lnkd.in/sCcksN ) and Network Security Systems Engineer (http://lnkd.in/gP94tj ) to join its Information Security and Compliance Services team.  If you or someone you know is interested and has what it takes to become part of the team please apply for the position online or contact me for more information.

 

...
April 3, 2012 | Geoffrey S. Nathan
Wayne State is looking for a Systems Security Specialist, Lead, who would be responsible for:

overall network and systems related security including firewalls, VPN, NAC, SIEM, routing, monitoring, data integrity. Act as a liaison between police entities and provide campus leadership in the field of information security.  

Interested folks should seek more information at jobs.wayne.edu, and look for posting  038504  or search for 'Security' under keywords.
I can help with additional information for those who seek it.

Geoff Nathan

Geoffrey S. Nathan
Faculty Liaison, C&IT
and Professor, Linguistics Program
http://blogs.wayne.edu/proftech/
+1 (313) 577-1259 (C&IT)
+1 (313) 577-8621 (English/Linguistics)

...
April 3, 2012 | Hetty Bouwhuis

Hallo there,

 

Which good examples do you know of digital testing systems in higher education and how do they provide for a secure testing environment? This is on behalf of a Dutch programme on digital testing of Dutch universities we coordinate.

 

Thanks,

Hetty

 

 

April 2, 2012 | Quinn Shamblin

Hi All

 

We have a need for an Information Security person to fill a leadership position at the Boston University Medical Campus.  The details are below.  We are looking for someone that has proven their technical chops, but has the skills to engage with people at all levels.  This position is to run a program on the med campus that is part of the larger InfoSec program here at BU.  It reports to  the Executive Director of Information Security for Boston University.

 

Details are provided below and at the job posting site:...

March 30, 2012 | Listserv Anonymous User
Message from lazerwit@yu.edu

Does anyone have any data recovery services that they have used local to the NYC area?

 

Regards,

 

Ian

 

Keep Your Account Safe – ITS Will Never Ask for Your Password

 

March 30, 2012 | Doug Markiewicz
Hey all, Curious what others are currently doing for PCI DSS training. Did you purchase something or are did you build your own? If home grown, is your training online or in-person taining? If purchased, what solution did you go with and are you happy with it? Thanks, Doug
March 29, 2012 | Eme Ejike
This is certainly interesting. I believe we all have some wonderful opinions....... BYOD is here with all the intricacies involved in generating an apt SLA model for such devices on campus. As part of the MDM service push for these devices, policies, standards and guidelines need to be defined to build a solid foundation on our foray into this arena. What do our members believe an official stance on jail-broken devices should be? Bearing in mind that our objectives are to provide security conscious access when on campus (i.e connected to an elevated access SSID with a purview into secure segments of the network --Network shares, ERP applications.. etc). A reference on some industry SME view would help in supporting your response. Sincerely, Eme Ejike OCCS, ITSO Supervisor Old Dominion University
March 29, 2012 | Brian Helman
I'm not one to resend articles, but I'm going to make an exception here. I was listening to yesterday's episode of Security Now and Steve Gibson mentioned this article. A lot of times, these things are serious, but not really something I'd worry about in the short-term. This one has some serious potential though. I just thought I'd pass it along to this (and the wireless) list: "An Ars[technical] story from earlier this month reported that iPhones expose the unique identifiers of recently accessed wireless routers, which generated no shortage of reader outrage. What possible justification does Apple have for building this leakage capability into its entire line of wireless products when smartphones, laptops, and tablets from competitors don't? And how is it that Google, Wigle.net, and others get away with publishing the MAC addresses of millions of wireless access devices and their precise geographic location?" Here's the link:...
March 29, 2012 | Theodore Pham
Carnegie Mellon's Information Security Office has an opening for a senior security engineer focusing on improving our network monitoring systems, performing attack and penetration tests and maintaining our systems infrastructure. If you or someone you know fits the description below, please apply or encourage them to apply. Please feel free to forward this information to interested colleagues. Senior Information Security Engineer - Carnegie Mellon University - Information Security Office Location: Pittsburgh, PA Job Number: 9002 Description The Senior Information Security Engineer (SISE) is responsible for helping to provide computer and network security to the campus community. This will include responding to incidents; scanning and monitoring for security problems on the network; analyzing network traffic; developing, classifying, deploying, and debugging custom threat signatures; performing attack and penetration tests; executing procedures such as account password security...
March 29, 2012 | David Seidl
Folks, I'm curious if you currently require all or most of your IT staff to sign a confidentiality agreement at hire on a recurring basis, and if so, what your reasons for doing so are. We've had one in place for new hires for years, and our business staff has asked if we can dispense with it as a general requirement for all IT staff. I've done a bit of review, and can't find a direct requirement to point to for people who don't have direct compliance related assignments. Thanks in advance for your feedback and comments! David David Seidl, CISSP, GCIH, GPEN Director of Information Security Office of Information Technologies University of Notre Dame Notre Dame, IN 46556 (574) 631-7305 dseidl@nd.edu
March 28, 2012 | Eme Ejike
Hello All,

Old Dominion University's Office of Computing and Communications  services SEC/IDM team has a job opening for an Information systems security administrator position. The job duties would encompass tasks involved in the day-to-day security operations that include incident handling, security monitoring and occasionally some custom code writing.  Proficiency in scripting is a plus.
This position is  currently advertised on the Educause Job postings and can be found on the university website via the link provided below. Please feel free to pass on this information to all interested colleagues.

Old Dominion University
5115 Hampton Boulevard
Norfolk, VA 23529
Phone: (757) 683-3000
http://www.odu.edu/fusion/about/...
March 28, 2012 | Ken Connelly
During the upcoming Security Professionals Conference, REN-ISAC is sponsoring a PGP key signing event that is *open to all* SPC attendees. The event is scheduled for Wednesday evening at 6:30pm, following the reception, and is listed in the program for the conference. * What: PGP key signing event * Where: Security Professional Conference, JW Marriott hotel, Indianapolis, IN * When: Wednesday, May 16, 2012 at 6:30pm EDT * Details: http://www.ren-isac.net/events/spc_2012_keysigning.html -- - Ken ================================================================= Ken Connelly Associate Director, Security and Systems ITS Network Services University of Northern Iowa email: Ken.Connelly@uni.edu p: (319) 273-5850 f: (319) 273-7373...
March 27, 2012 | Carlos S. Lobato

Hello All,

 

NMSU is currently having some discussion about the possibility to install “Security Cameras” at various places throughout campus such as parking lots, etc., but would like to inquire from those of you who have already installed cameras to share with us a copy of your policies and/or other feedback that would be helpful.

 

Thanks in advance,

 

Carlos S. Lobato, CISA, CIA

IT Compliance Officer

 

New Mexico State University

Information and Communication Technologies

MSC 3AT PO Box 30001

Las Cruces, NM  88003-8001

 

...
March 23, 2012 | Dennis Tracz

The University of Calgary has an opening for a Senior Security Architect. 

 

To apply go to: 

www.ucalgary.ca/hr/careers

(JOB ID 2287)

 

Please pass on to anyone who might be interested. 

 

Thanks,

 

Dennis N. Tracz, CISSP-ISSMP, CISM, CGEIT

Director, Information Security & Compliance

University of Calgary

Office: (403) 220-4010

Cell: (403) 305-4010

 

 

 

March 23, 2012 | Listserv Anonymous User
Message from dsarazen@umassp.edu

Hi All,

 

Quick Question: If Windows were to release a critical patch for a server today, how long should it take to install the patch before you’d consider it TOO long?

 

Thanks, 

 

:: Daniel Sarazen, CISSP, CISA

:: Senior Information Technology Auditor
:: University Internal Audit
:: University of Massachusetts President's Office

:: 774-455-7558

:: 781-724-3377 Cell
:: 774-455-7550 Fax
::...

March 23, 2012 | Angela Embree

Drake University in Des Moines, Iowa is looking to hire an Identity and Access Management Software Engineer.  Click the link below for a more detailed description of the position and info on how to apply.  Please pass on to anyone who might be interested.  Thanks!

 

o    Identity and Access Management Software Engineer, Level 2 - 998528

The Identity and Access Management Software Engineer will play a leadership role in the design, development, deployment and administration of applications used as part of Drake's Identity and Access Management strategic initiatives. This includes, but is not limited to identity...

January 9, 2013 | James Pardonek
I'm looking for some information of what your University's stance is on the use of applications such as Jump Desktop, LogMeIn, GoToMyPC, etc.  I tend to have an issue with users connecting to their desktop without the security of our VPN and ability to audit who is connecting and when.  As we all know, most users are not as creative as we would like them to be when it comes to creating passwords for services like the ones above and although I don't think there have been any successful attempts at getting accounts and passwords from these services, you never know.
 
Loyola currently has no policy regarding these services so I'm not sure, based on what others are doing if we should, or do we just let it go.
 
Thanks,
 
Jim
 
 
James Pardonek, CISSP, CEH
Information Security Officer
Loyola University Chicago...
January 9, 2013 | Justin C. Klein Keane
-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Hello all, yesterday I released the latest in a series of capture the flag exercises as part of the LAMP Security project, hosted at SourceForge.net (read: free training!). This exercise was run at the Philadelphia OWASP chapter meeting. It includes a full virtual machine image with custom and open source web applications that demonstrate a number of common web application vulnerabilities and misconfigurations. The goal of the exercise is to break into the target and get access to the root account with no prior information about the target. The exercise includes a full 43 page PDF walk-through that is suited for folks of all levels of technical expertise. You can complete the exercise with or without the walk-through. The exercise uses the BackTrack Linux distribution to demonstrate a number of open source testing tools that you can use in your own organization as well as highlight the strengths and weaknesses of each tool....
January 2, 2013 | Cathy Hubbs
Carlos,
The EDUCAUSE Security Guide has a great Data Incident Notification Toolkit available at https://wiki.internet2.edu/confluence/display/itsg2/Data+Incident+Notification+Toolkit

Section 2 discusses constructing a Data Notification letter and includes links to several University's samples.

Best wishes,

Cathy

Cathy Hubbs
Chief Information Security Officer
Office of Information Technology
American University




From:        Carlos Lobato <clobato@NMSU.EDU>
To:        SECURITY@LISTSERV.EDUCAUSE.EDU,
Date:        01/02/2013 01:39 PM
Subject:        [SECURITY] Sample Notification Letter to Affected Parties related to IT Data Breaches
Sent by:...
December 7, 2012 | Dick Jacobson

Apologies – address auto-completion is NOT always your friend ;-(

December 3, 2012 | Doug Pearson
SANS and REN-ISAC are partnering to bring exceptional security awareness and technical training to the education community at substantially discounted pricing. An interactive webcast is scheduled for December 18 to explain the program and provide opportunity for Q&A. The special pricing is available during a purchase commitment window, January 1 through February 28, for: - SANS Securing The Human security awareness training, and - SANS NetWars interactive technical skills challenges In addition, a second window will occur during June 1 - July 31, for: - SANS Securing The Human security awareness training, and - SANS OnDemand & GIAC, technical training & certification The SANS and REN-ISAC partnership creates economies of scale for purchasing at a significant (75% - 90%) discount during specific time frames (60-day windows of opportunity). The special pricing is available to staff, faculty, and undergraduate students at higher education institutions, and K...
December 2, 2012 | Joseph Clark
We are looking for someone to join our Network Security Team at the College of Charleston. If interested please appy at https://jobs.cofc.edu/applicants/Central?quickFind=51088. Thank you and I apologize for the intrusion. Thanks, Joseph Clark
November 27, 2012 | Aaron Hockett
We were hit by a DDOS yesterday. After some investigation it was discovered that it appears to have been caused by the web crawler 80legs. Things started to quiet down about 5-10 minutes after I blocked them in our robots.txt however, I'm not 100% positive if this was what stopped them as others have reported seeing this agent ignore that file. As you may know, the experience isn't very pleasant. I've been doing a bit of googleing and see a number of home-brewed solutions. I've also been looking in our AWStats and it appears that most of the spiders come through as "unknown robot"; which isn't very helpful. On top of reevaluating some of the firewall rules and tweaking our system monitors, I was curious if any of the rest of you know of any other abusive crawlers that we should be blocking access. Your best practice advice is welcome as well. Thanks, David Pirolo Warner Pacific College
November 19, 2012 | Travis Foschini
SECURITY Digest - 16 Nov 2012 to 18 Nov 2012 (#2012-212)

Has anyone evaluated the risks associated with Wordpress and AD authentication? It’s being considered for a special purpose intranet.

 

Thanks in advance,

Travis Foschini

 

November 16, 2012 | Andrea Santurro

Hi

 

I am trying to gather information regarding Oracle Database encryption. Are your databases encrypted? What tool do you use and how long have your databases been encrypted.

What are the challenges that you found with encrypting the databases what are the benefits

 

Thank you so much,

 

Andrea Santurro

 

IT Auditor|Salt Lake Community College|4600 South Redwood Road, AD 026D, Salt Lake City, UT 84123 Phone: 801.957.4006|Fax: 801.957.5123

 

 


This message, and any attachments, is intended only for the use of the addressee and may contain information that is privileged and confidential or otherwise exempt from...
November 13, 2012 | Nick Recchia
We have a couple question regarding PCI SAQ D version 2.0. requirement 8.5.

Requirement 8.5:
"Are proper user identification and authentication management controls in place for non-consumer users and administrators on all system components, as follows...." [1]
 
1) We had proposed to use Active Directory (AD) to manage requirement 8.5. Does anyone have experience to indicate that AD will not work for this implementation?

2) Is anyone managing local user accounts, instead of AD user accounts, within their PCI implementation?  

Thanks for your input.

Sincerely,
-Nick

[1] there are 16 sub-requirements (8.5.1 - 8.5.16) that I did not paste into this e-mail, but maybe found on https://www.pcisecuritystandards.org/security_standards/documents.php

--
...
November 13, 2012 | Valerie M. Vogel
Last Call for Security Proposals

Today is the last day to submit a proposal for the 2013 Security Professionals Conference! The online submission form is available here: http://www.educause.edu/events/security-professionals-conference/call-proposals

 

Thank you,

Valerie

 

Valerie Vogel Program Manager

EDUCAUSE
Uncommon Thinking for the Common Good
direct: 202.331.5374 | main: 202.872.4200 | educause.edu

 

From: EDUCAUSE
Sent: Tuesday, October...

November 9, 2012 | Donald J. Schattle, II

Hello All,

 

Looking to see if anyone has any security/compliance feedback on a company called Vivature which is a division of OrchestrateHR (http://www.orchestratehr.com/vivature).  

 

Thanks,

Don

 

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

Donald J. Schattle II, CISM

Information Security Officer

GLB-Act Coordinator

Providence College

schattle@providence.edu

401.865.1558

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

...
November 5, 2012 | William Kyle
We currently have two positions available here at Johns Hopkins University, one is an entry level, requisition # 48873, and the other a senior level, requisition #54345. Entry level: https://hrnt.jhu.edu/jhujobs/job_view.cfm?view_req_id=48873&view=sch Senior level: https://hrnt.jhu.edu/jhujobs/job_view.cfm?view_req_id=54345&view=sch Links are provided on job description pages above to the Hopkins' information on benefits, pay (These are "Administrative/Technical Professional Role" positions.), policies, etc. Even though these are University positions we also have the responsibility for the Johns Hopkins Medical...
November 5, 2012 | Yvonne Poul

Dear all,

 

I would like to invite you to submit a paper to the the 2013 Asian Conference on Availability, Reliability and Security (AsiaARES 2013) which will take place in Yogyakarta (Indonesia) 25th-29th March 2013 (http://www.AsiaAres.org).

 

AsiaARES will be held as a Special Track Conference within ICT-EurAsia 2013 (http://www.ifs.tuwien.ac.at/ict-eurasia/), which is supported by ASEA-Uninet (ASEAN-European University Network), EPU (Eurasian Pacific University Network), IFIP (International Federation for Information Processing).

 

AsiaARES is a new conference that builds on the success of seven subsequent annual ARES conferences and specifically aims at a...

November 2, 2012 | Yvonne Poul

Dear all,

 

I would like to invite you to submit a paper to the Information Communication Technology-Eurasia Conference (ICT-EurAsia 2013) which will take place in Yogyakarta (Indonesia) 25th-29th March 2013.

 

           http://www.ifs.tuwien.ac.at/ict-eurasia/

 

The conference is supported by ASEA-Uninet (ASEAN-European University Network), EPU (Eurasian Pacific University Network), IFIP (International Federation for Information Processing).

 

ICT-Eurasia 2013 provides an international forum for researchers and practitioners to present their latest research findings and innovations. The conference is...

October 25, 2012 | Valerie M. Vogel
The U.S. Department of Education’s Privacy Technical Assistance Center (PTAC) recently published a Data Breach Response Checklist that institutions of higher education may use to develop a comprehensive data breach response plan. The checklist is meant to be used as a general example illustrating some current industry best practices in data breach response and mitigation applicable to education community.
 
 
Thank you,
Valerie
 
Valerie Vogel Program Manager

EDUCAUSE
Uncommon Thinking for the Common Good
direct: 202.331.5374 | main: 202.872.4200 | twitter: @HEISCouncil |...
October 23, 2012 | Quinn Shamblin

Hello All,

 

A few questions related to application vulnerability scanning and management:

 

·         Do you have a program to ensure that applications are tested for vulnerabilities?

o   Is it embedded in the application QA or release process, or is scanning done once the app is in prod (or both)?

o   Who runs the tests?  (Developers?  QA?  InfoSec personnel?  Other?)

·         What tool do you use for static cost testing?

·         What tool do you use for dynamic code testing?

o...

October 17, 2012 | James Pardonek
We currently have several computers in our Health Sciences Information Commons area that require an ID and password for authentication.  We have discovered that this is a pain point for our helpdesk as we have doctors and clinical faculty that come over from our neighboring hospital to use the computers.  Although they all have credentials, the hospital does not require them to use them and many of them don't remember what they are or that their password expired several months (years) ago.
 
We are looking for a way to allow them to use a method similar to our guest wireless where we ask for a name and email address in order to connect.  We would like the workstation to boot up and present them with this type of screen prior to getting a desktop.
 
Is there anyone that is already doing this or even a commercial product that we can look at?
 
Thanks,
 
Jim...
October 16, 2012 | Mary B. Dunker
Virginia Tech Information Technology is seeking a qualified individual for the Manager of Quality Assurance and Verification in Secure Enterprise Technology Initiatives. Manager, Quality Assurance and Verification The successful candidate will direct efforts to design and implement testing procedures for multiple enterprise software development projects involving middleware, authentication, directories, and PKI, in order to ensure successful and secure implementations. A strong understanding of testing methodologies including black and white box testing, unit testing, bounds testing, and experience in testing and troubleshooting enterprise applications is required. The candidate must have experience programming in languages such as Perl, SAS, SQL, in configuring and using digital certificates for multiple browsers, S/MIME, and SSL, and must be familiar with Web-based products, LDAP, and multiple operating systems (UNIX, Linux, Macintosh, Windows.) Bachelor's degree in IT-related...
October 14, 2012 | Chris Kidd
We have several departments that have entered into contracts with Health and Human Services and other federal agencies. The contracts require compliance with Part 352.239-70-73 (http://www.hhs.gov/policies/hhsar/subpart352-30s.html). The Contracting Officers from the federal government are now asking for the documentation associated with compliance. I'm hoping others have had the opportunity to respond to similar language. If so, could I bounce a few questions off of you privately? Or - even better - let me know if you are willing to share any documentation or checklists! Regards, Chris Kidd Chief Information Security and Privacy Officer University of Utah and University of Utah Health Sciences 650 Komas Suite 102 Salt Lake City, UT 84108 office 801.587.9241 cell 801.747.9028

Group Leaders

The University of Arizona
University of Maryland, Baltimore
EDUCAUSE

Related to this Group...

Close
Close


Annual Conference
October 15–18, 2013
Register now!

Events for all Levels and Interests

Whether you're looking for a conference to attend face-to-face to connect with peers, or for an online event for team professional development, see what's upcoming.

Close

EDUCAUSE Institute
Leadership/Management Programs
Explore More

Career Center

Leadership and Management Programs

EDUCAUSE Institute
Advanced Programs
Project Management

 

Fellowships and Awards

Fellowships
Awards Programs

Getting Involved

Mentoring
Volunteer
Speak at an Event

 

 

Jump Start Your Career Growth

Explore EDUCAUSE professional development opportunities that match your career aspirations and desired level of time investment through our interactive online guide.

 

Close
EDUCAUSE organizes its efforts around three IT Focus Areas

 

 

Join These Programs If Your Focus Is

Close

From the Blogs

Get on the Higher Ed IT Map

Employees of EDUCAUSE member institutions and organizations are invited to create individual profiles.
 

 

Close

2013 Strategic Priorities

  • Connected Learning
  • Enterprise IT
  • Foundations


Learn More >

Uncommon Thinking for the Common Good™

EDUCAUSE is the foremost community of higher education IT leaders and professionals.