Hi all - If you are seeing this message then you have successfully navigated to the blog where you will be interacting with me and your fellow classmates. Your first assignment is to post and example of a current security policy in place at your institution.
Good luck!
Angi
Subscribe to:
Post Comments (Atom)
19 comments:
Professor Angi, you're sooo cool!
One of the security policies in place at my university is the automatic locking of persons' accounts when they leave their computers unattended for more than 5 minutes. To reduce the chance of someone else having access to the information available to that person, the computer is locked and only that person or an administrator can unlock the computer to access that person's account and information.
That's an excellent example, Avril. This is one of the most common policies in place, and is easily managed in most user directory environments such as Microsoft's Active Directory. We do this at USN as well, and apply the policy as a group policy.
Do you also have a policy in place requiring users to update their password on some interval?
Our security policy at EU causes us to change our network password every 3 months (can't reuse the last 4 passwords). In our offices we can reset our own screen saver to require a password (or not) - I would guess that most faculty do not use this... As far as student computers/lab computers, I do not know if they have an automatic 5 minute password protection. To all appearances, they do not. Students cannot change the settings of University managed computers.
Our policy is set to expire passwords every 90 days. You cannot use a password you used in the past. Faculty complain about it saying they can't remember all the different passwords and I understand to some degree. I see it however as a necessary evil so that confidential material is secure.
In response to Jeremy's comment about persons setting their own passwords on the screen savers, in my opinion it is risky to leave it up to the faculty to do this. For faculty with individual offices where no one has access to the computer, that may not be a big problem but for any situation where space is shared and persons may be called away unexpectedly from their computers, it would be good to lend them the extra security of locking the system until they are able to attend to it when they return. The University of Iowa recognizes the importance of this when they considered the use of robust passwords as a “major defense against unauthorized use of our systems.” (http://cio.uiowa.edu/policy/enterprise-password.shtml) In today’s environments where we have single sign on, allowing us into many applications, it is important to ensure those who are accessing those applications are indeed authorized to do so. [Linked was accessed through the Security Policies and Procedures page, access control link.]
I agree, the policy of "it's up to the faculty to decide" is not a positive one. Having taught at a state institution (where office doors were to be closed at all times and locked, screen savers password protected, no loose items lift out, etc.) previous to my current position, it is a matter of culture, I guess. At EU, professors will go to class and leave their offices wide open, computers on with no password, exams left out... It is a matter of trust, I guess. Of course, it must be up to individual institutions. Cornell did not mention anything at all about mandatory password protection in its security policy.
Video 1 – Avoid Infection
Providing your computer with the latest updates for your virus protection software and placing your computer behind a firewall is analogous to providing your body with the best immune system boosting vitamins and not putting yourself in harm’s way. If we think of all the things our computers enable us to do, we should do our best to try and protect them from intrusions that can cause them to malfunction.
Video 2 – Whoa, That’s Awkward
A very striking way to get a message across but since the message was at the end of the awkward sounds, there is no guarantee that the user will wait around long enough to get the message. The point made was don’t click on every link you receive and ensure you have virus protection enabled on your computer in case you do encounter a virus.
Video 3 – Protected
This video plays on the prophylactic nature of the term “getting protection”. Two young ladies speaking about protection before entering into this new “thing” appear to be speaking about preventing catching viruses themselves. The punch line is done so smoothly and quickly that persons get the message quickly and effectively. Various methods of protection are given at the end of the recording adding to the value of the video.
Video 1: For Their Inconvenience
A college guy comes out of a university computer lab with a laptop. At second look, it appears he has stolen it. He’s running down the hall making sure not to be caught or seen. One scene shows the guy running but a cord or rope is trailing behind him. All of a sudden he trips over the cord and falls down. While he’s looking around, bewildered, a girl comes along, takes the laptop, sits on top of the guy and opens a screen with the For Their Inconvenience – Lock up your laptop. Bad acting, can’t really tell that the cord is actually a security cable…but, does get the point across; lock up your laptop or it will get stolen.
Video 2: It’s Here
Video showing faces of college students. A stat pops up that says that 55% of people own computers. Another, that there are an estimated 114,000 viruses. The faces become distressed and the looks turn to ones of grief. Another message flashes – the virus is here, don’t become another statistic, protect your computer. Interesting, but doesn’t quite make the connection between the number of computers vs. number of viruses.
Video 3: When You Least Expect It
A Girl is working at a computer at an internet cafĂ©. She looks across the room and sees a guy typing on his laptop. She smiles at him coyly. He smiles back. A sign flashes over the coffee bar: Hot Spot. The guy closes his laptop, takes his iced coffee, smiles at her, and leaves. A new message overlies the girl – He has just stolen her identity. Then the next message says: Get wireless protection. Definitely, the best of the three I viewed. But, what if the place has open access? How do you encrypt your end of the wireless?
Responses to Avril’s video selections:
Video 1 – Avoid Infection
It is interesting to note how many students do not have virus protection nor update the protection they may have. It does not occur to them to update a virus protection that may be a year old or more. Cost may be a factor; more than not, however, they do not realize that an update adds to the list of known viruses. If they have virus protection but have not updated with even the free updates, they are playing Russian roulette. Without protection, a completely loaded gun!
Video 2 – Whoa, That’s Awkward
One of the most discussed topics in my computers 101 course is security: types of viruses, how to protect yourself, etc. It is neat to see students realize that those messages of “Click here to win a new iPod” or “Claim your Xbox Here!” are nothing more than Trojan horses. They may not be lethal on the back end, but tracking data could be collected that lead to bigger problems.
Video 3 – Protected
Getting the message out in ways they will understand. The venue of the message probably wouldn’t work as well for seasoned adults our age (still young at heart, though). But with intimate viruses so much a problem amongst teens and 20 somethings, why not include computer viruses to the list of “get protected?”
Response to the videos chosen by Jeremy
Video 1 – For their inconvenience
We have cases of theft reported when students leave their laptops unattended to go to the washroom, for example. The message is “don’t make it so easy for thieves to walk/run away with your property.” Schools need to lock down their systems as well as provide students with methods to lock their personal laptops or students have to keep them in their possession or suffer the consequences of thieves running away with their portable devices.
Video 2 – It’s here
The use of facial expressions extends the feeling of frustration when someone falls victim to a virus attack. Showing how a carefree lifestyle can suddenly be turned upside down by an unexpected attack can send a message to ensure you are protected. No one likes grief so this would nudge persons to do something about it. It was not a very powerful video in its delivery but the message is there.
Video 3 – When you least expect it
With all the business travel that occurs in the world today, this may be more of an important issue than we realize. I believe the video did its job in getting me as well as Jeremy and any other viewer to ask the important question “how do we protect our laptops in a wireless world where the only access sometimes is open access?” The video does not answer the question but it provokes the question so that we can now go out and search for the answer.
As per your descriptions of the videos, we can see there are many concerns to be aware of. With so many potential threats, how can we best mitigate the risks? In short, we can’t! Through the development of appropriate security policies, however, institutions can encourage best practices while minimizing liability should a security breach occur. Jeremy makes an excellent point that much of our target audience falls within a younger demographic. Speaking to this audience is paramount to having a significant impact.
Avril’s observation regarding theft is difficult to address. More and more institutions are requiring students to purchase laptops. How do we protect those students from the inevitable threat of threat? This is one area that likely cannot be addressed through policy development.
This week we will be looking at the elements of security policy. Another aspect to consider, while looking at security policy elements, is how do you know what policies are appropriate for your specific environment?
Security Policies - Overall importance to security policy development
Access Control
One of the policies deals with access control. A major issue surrounding the security of information is who has access to the information. If an organization has established procedures for access control, breaches in security can be kept to a minimum. Organizations also have to train the persons who do have access to the information on the appropriate use of the information as well as how they manage the security of their systems so that others do not have access to the information left available through the authentication of the authorized person.
University of Iowa states four technical controls: identification, authentication, access control and auditing. An enterprise log in is needed so persons can access the system with credentials that state who is logging in. Password controls are also needed to ensure the security of passwords. There are minimum standards for appropriate passwords to ensure it is as difficult as possible for persons to guess the password. Access control is seen as authentication to various databases containing data and information and manages who is allowed varying access to information. Finally, there should be a security policy that addresses the auditing requirements for confidential information.
Compliance with Law and Policy
As recognized by the University of Berkeley, there are certain federal and state laws that must be upheld and security policies need to reflect the compliance with such laws. Personal information is protected by these laws and institutions need to have security policies in place to provide this security. Policies such as the UC Electronic Communications Policy and the campus Computer Use Policy, BFB IS-3 and also the Implementing IS-3 Electronic Information Security apply to campus electronic information resource security. Other disruptive behavior such as intentionally transmitting computer viruses, accessing unauthorized information, and tampering with resources are also prohibited by policies addressing this issue. Institutions need to show they are complying with these regulations by having policies in place that address these issues. They also need to have regulations in place for persons who knowing break the rules.
Security Plans:
Information security plans are part of an organizations information management plan. Higher level plans record management and executive security initiatives for the next 3-5 years. Lower level plans outline details for the upcoming 12-18 months. IS plans are based on risk assessment and should be congruent with organizational priorities, staff, and budget considerations. Governing boards and organizational executives can also address or accept known risk rather than be inadvertently accepted (without a plan).
IT Incident Reporting:
IT Incidents could be accidental or deliberate, benign or malicious. Careful response to each incident is needed in order to assess the potential impact on individuals and the organization at a whole. IT security incidents can be defined as the, “result in misappropriation or misuse of confidential information (social security number, grades, health records, financial transactions, etc.) of an individual or individuals, significantly imperil the functionality of the information technology infrastructure of the ISU campus, provide for unauthorized access to university resources or information, allow ISU information technology resources to be used to launch attacks against the resources and information of other individuals or organizations” (ISU IT Incident Reporting, 2006). Determination of the potential of an incident is the responsibility of the organization rather than individuals. Established procedures should be in place in order to verify that specific IT incident resolution is implemented.
Access Control
Access control can have two layers: Nominal end user and management. Nominal end user access control deals with patrons (students, teachers, staff) accessing data from a provided network. Access control from management users would include limited access to sensitive materials, access based on job related information, and need to know access. Management access control could also include restricted access to database materials gleaned from searches. Who should know the information? Where should it be stored?
Compliance with Law and Policy
Are these laws similar to HIPPA laws? What if a small university is unaware of regulations such as this? Is there a “didn’t know” way out?
Response to Jeremy
Security Plans – I agree with Jeremy that any comprehensive information management plan would have information security as an integral part. The robustness of the plan would also depend on the associated risks in the given context. Based on the identified risks, management should place certain security features in place to reduce the chance of breaches in security.
IT Incident Reporting – Even with plans in place to minimize incidents, they will still occur either through willful actions of perpetrators or some error that was unintentionally caused by a user. Organizations must have procedures in place to deal with such cases to handle the incidents carefully and, when necessary, notify persons of the extent of the damage that could be caused. Failure to do this will be a second assault on victims.
Compliance with HIPPA...
I believe this is a case where the phrase "ignorance is no excuse" would apply. Persons in the Registrar's office and other student information processing offices need to put themselves out to know all there is to know to protect the students and their health information. Grades and any other personal information are also protected.
Lesson Summarization
I believe that of all the postings that we had on the blog, the lesson that stuck with me the most is the protection of our systems in wireless environments. All other issues have been addressed in one way or the other at my educational institution. The wireless issue is probably addressed on some level that I am not aware of. I know I log on to any hotel’s non-secure wireless if that is the only connection I have while traveling. I have never worried too much about it in the past but I will inquire at the university on how to protect the laptop in such cases. I do not know the answers and we did not uncover them during the lesson, so Jeremy’s questions still stand and I will take those back to the network guys at work. If there is no emphasis placed on wireless protection then I will be a driving force to ensure that it becomes a “thought about” issue.
Lesson Summary:
Next to gaming, it is said that security is one of the only growing sectors of the computer industry. From what all has been seen within this lesson, I can sure believe it! Avril raises some good questions about wireless security - it is really safe to login to an airport unsecured wireless network? Is there someone close by sapping my signal and trying to gain access to my computer? A piece of the puzzle for me has been an overall security plan - published plan, mind you. Where I work, I know of no such document. There are policies and procedures in place, but nothing all in writing encompassing what would happen if... Should everyday users know all these things? Should only the backroom IT guys have all the knowledge? Don't know - but, I for one would sure like to know...!
Post a Comment