Six essential steps to secure academia
- 16 September, 2008 11:18
- Comments
Computer networks in the academic world are a lot like the Wild West: It's hard to tell the good guys from the bad, and the sheriff's ability to maintain order is severely limited.
The long list of data security breaches reported since early 2005 is heavy with the names of such academic institutions as San Diego State University, Ohio University, the University of California at Berkeley; Boston College and Tufts; George Mason University; the University of Northern Colorado; and Purdue University, among many others.
It's a world all too familiar to Stan Gatewood, CISO for the University System of Georgia's Board of Regents.
Georgia's system is much the same as other university settings. Maintaining open access to information is paramount, whether it's a Web page students use to access class schedules, an e-mail portal faculty use to communicate assignments or a database researchers rely on to store and access highly sensitive information.
Meanwhile, students, professors, outside contractors and others are constantly showing up on campus with their own computers -- some secure, others full of unpatched flaws and still others that are used to probe the network for weaknesses to exploit.
The information at risk in this environment is immense: financial aid and health records, credit card numbers used in the college bookstore or cafeteria, proprietary information relating to sensitive research being done on campus, and so on.
"We deal with tremendously unique and varied access needs, and the biggest challenge is identity management -- properly identifying and classifying individuals," Gatewood says. "It's tremendously hard to coral everyone and balance their needs with the security needs in one area."
There's also a growing challenge with mobile security, since students and faculty never stay in one place but still need access to the campus network. They need identity and access credentials that will move with them, he says.
While no security program is 100-percent successful in meeting these challenges, Gatewood lives by a six-point plan that has served his institution successfully thus far. In a recent interview, he outlines those steps:
Step 1: Risk management No matter how much he learns about information security, Gatewood says the main lesson always comes back to an organization's ability to manage risks and threats. He advises security pros in academia to hammer out a formal risk management program outlining how to lower risk to an acceptable level. "You have to inventory machines, pinpoint high-risk, medium-risk and low-risk systems, then consider the specific risks to each," he says. "You need to be able to express the risk with actual numbers. You need to inventory each identity, categorize and rate them; then deal with countermeasures." Developing a risk management plan cannot be done with a set-it-and-forget-it mentality, he says. Organizations must start from scratch and repeat the process every year, and getting upper-management support is essential.
Join the CIO Australia group on LinkedIn. The group is open to CIOs, IT Directors, COOs, CTOs and senior IT managers.
- Bookmark this page
- Share this article
- Got more on this story? Email CIO
- Follow CIO on twitter
-
Pfizer's Future Depends on IT Transformation
-
10 Tips for Dealing with a Bully Boss
-
Social networking security in the workplace
-
Facebook stock slumps for third day
-
Dell's profit shrinks in the first quarter
-
How progressive companies are using social technologies
Social networks and collaborative technologies are now commonplace in many workplaces. Having first been used “on the quiet” by highly-networked employees, in increasing numbers they are now being proactively used by businesses keen to connect more effectively with their internal and external audiences. Web collaboration is now viewed as critical to company success and as having multiple benefits and applications to the business. Read on. -
Spear Phishing Attacks - Why they are successful and how to stop them
There's been a rapid shift from broad, scattershot attacks to advanced target attacks that have had serious consequences for victim organisations. The increased use of spear phishing is directly related to the fact that it works, as traditional security defences simply do not stop these types of attacks. This paper provides a detailed look at how spear phishing is used within advanced attacks and the key capabilities organisations need in order to effectively combat these emerging and evolving threats. -
The mobile print enterprise - How IT consumerisaton is driving anytime, anywhere printing
As the office extends to an ever-wider range of work locations and businesses find themselves supporting a diverse range of mobile platforms, the print infrastructure is extending to the mobile worker, improving both employee and business productivity. Even in the era of smartphones and tablets, businesses continue to rely on printing. Quocirca’s research reveals that there is certainly the appetite for mobile printing, with almost 60% of respondents stating that their organisations would like to print from their mobile devices, with around 25% currently investigating mobile print solutions. Read more.
-
Microsoft Access 2000 Bible
-
Primality & Crytography
-
Secrets of Award-winning Digital Artists
-
Macs All-In-One Desk Reference for Dummies®
-
Microsoft Access Small Business Solutions:state-of-the-art Database Models for Sales, Marketing, Customer Management, and More Key Business Activities
-
UML Weekend Crash Course
-
PC Magazine Office 2007 Solutions
-
AutoCAD 2009 & AutoCAD LT 2009 Bible
-
Mac OS X Panther Timesaving Techniques for Dummies








Comments
Post new comment