Recommendations for NSF. NSF to provide guideance on how to provide security plans. NIST already provides standards used by other agencies, a simple recommendation that sites should consider following these standard. Long term goal would be to have a standard that could be used at all sites. SSL certificates are becoming more important. Many sites are currently using self signed certs because of the costs involved. It would be benefical if NSF could provide a CA service, or negotiate a discount with a known provider. Much like the NIST documentation, it would be nice for NSF to provide a location for best practices documents. Many sites are running into the same problems and re-inventing solutions. Having a place to find how others have solved these problems would benefit all. A wiki for site comments/discussions. Since NSF has gone through a Cyber Training program, would it be possible to provide that to the sites as a template on how to construct their own training system. Personal Identification Information what is it? what needs to be protected? We'd like guidance on this. Another group at the conference is covering this in detail. We'd like to see some guidance on how to deal with Cooperative agreements Compliance with multiple policy sets. HIPPA, UCNI, .. Discussions Configuration mgmt issues Getting buy-in on the use of cfg management being needed. common config is along the lines of: jumpstart/kickstart/systemimager/ghost to install minimum image then build on that with custom "firstboot script" cfengine bcfg2 Patches applied by yum custom scripts bcfg2 Monitoring system for config compliance ganglia to monitor specific files tripwire or aide redhat entreprise system to monitor updates and failures User management Lots of issues with visitors. account retention data storage foreign national access? Traditional group accounts are being phased out at most sites. sites want individual accountability on system use. "Portal" usage is defined to use group accounts. conflicts with user tracking. serious issues with a project on how to remove individual troublemaker. If problems occur curerntly it's shutting down access to all. Data management Integrity This is a big concern, but hasn't been a serious problem for the admins. Malicious intent is a problem, but low probability. Bit-rot over time Vendor software problems. Archiving The admin responsibiity is that the data is recoverable, and safe. Basic hardware functionality. IF the system supports it, validating the checksums on that data. The responisblity of how that data is maintained/documented is up to the application owners. What to do about the data of people that have left? Written policy on how sites deal with this. Notify users that unless they want it, the data WILL be purged on a specific date. Handling self-admin machines. Visiting scientists machines. netreg for network access. Logging people set thing to ingnore or summarize the known. send alerts on the odditiies.