Active Directory Security Improvements (ITCRB) CIO Council Update

Slides:



Advertisements
Similar presentations
Auditing, Assurance and Governance in Local Government
Advertisements

NIST Special Publication Revision 1
Roles and Responsibilities
Financial Capability Strategy for UK Older people in retirement Presentation to the Age Action Alliance Money Matters group Rebecca Langford, Policy Manager.
From Policies to Programs to Practices Establishing the Green Infrastructure Eric Friedman Director of State Sustainability Mass. Executive Office of Env.
National Provider Identifier HIPAA Summit 13 September 25, 2006 Peter Barry Hospital Implementation Planning.
Health Delivery Services May 29, Eastern Massachusetts Healthcare Initiative Policy Work Group Session 2 May 29, 2009.
Knoxville, TN October 20, 2009 SG-Systems Systems Requirements Specification Team Status and Breakout Session.
TDRp Implementation Challenges David Vance, Executive Director Peggy Parskey, Assistant Director October 23, 2014.
Project Discovery – Monday Holyoke 561 Most updates will only have 30 minutes maximum for their presentations. At least 10 minutes should be left for Q&A.
CI R1 LCO Review Panel Preliminary Report. General Comments –Provide clear definition of the goals of the phase (e.g. inception), the scope, etc. in order.
Vision to Reality: How Knowledge Sharing Promotes Efficiencies Through Process Improvement  History of the Knowledge Collaboration Centre (KCC)  The.
U.S. Department of Agriculture eGovernment Program Enabler’s Steering Committee Meeting January 9 th, 2003.
Implementing Clinical Governance COMPASS Consultant Outcome Indicators Programme.
1 GR-PBA 22 September This presentation covers  What does an AC do? ToR & Vision  Work done by AC in the16 months  Assurances to CM on:  internal.
FY16 End of Year Goals Summary HUIT Top 40 GoalsFY16: Top 40 Goals Assessment Top 40 Goals Status Summary 82% Complete (33 of 40) 18% Incomplete (7 of.
© Crown copyright Met Office Report of the Chair Stuart Goldstraw, UK Met Office, Chair ET-SBO-1, July 2013.
Asset Management Working Group & Bridge Condition Indicator Project Achievements, Updates & Future Work Paul Monaghan LoBEG Chairman May 2015.
IT Vendor Management March, 2015 Peter Baskette Pratike Patel.
Digital Asset Management & Storage Program Program Summary
CIO Strategic Initiative: Cloud Enterprise Cloud Overview
Project Management Project Reviews
Collaboration Program CIO Council Update
Quantum Leap Project Management
Group Services CIO Council Update
FY17 End of Year Goals Summary FY17: Top 40 Goals Assessment
City-wide Active Directory Project Town Hall II
ITCRB FY18 Funding Cycle Kickoff
CBP Biennial Strategy Review System
CRISP Update January 2017.
Video CIO Council Update
Collaboration Program Update
IT Governance at the SCO
Safety Accountabilities
Common API Platform Project (CAPP) – CIO Council Update
Harvard CRM Service Strategy
CIO Council User Experience Strategic Initiative Update
IT and Project Management Best Practice Training
Project & Program Governance
Description of Revision
Establishing Strategic Process Roadmaps
Information Security Services CIO Council Update
Enterprise Architecture EA Principles Revisions CIO Council Update
Storage & Digital Asset Management CIO Council Update
Collaboration File Share Update and Discussion
Active Directory Security Improvements
IT Governance Planning Overview
Identity and Access Management Program Update CIO Council Update
Change Assurance Dashboard
Alignment of COBIT to Botswana IT Audit Methodology
Bull Run Middle School School Advisory Meeting, 6:30 – 8:00 p.m. Library.
CBP Biennial Strategy Review System
12/28/2018 3:03 PM © Microsoft Corporation. All rights reserved. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN.
Shared Assessment Committees Update
Memorandum of Understanding
Data Migration Assessment Jump Start – Engagement Kickoff
JOINED AT THE HIP: DEVSECOPS AND CLOUD-BASED ASSETS
Finance & Planning Committee of the San Francisco Health Commission
Portfolio, Programme and Project
Preparatory Workshop of the Pilot Boreal Natura 2000 Seminar
DSC Contract Management Committee Meeting
Next Generation HR and Pay National Capital Region
(Project) SIGN OFF PROCESS MONTH DAY, YEAR
Project Kick-off <Customer Name> <Project Name>
{Project Name} Organizational Chart, Roles and Responsibilities
DSC Contract Management Committee Meeting
Speaker’s Name, SAP Month 00, 2017
(Insert Title of Project Here) Kickoff Meeting
Bridging the ITSM Information Gap
Project Name Here Kick-off Date
Presentation transcript:

Active Directory Security Improvements (ITCRB) CIO Council Update September 5 Tuesday 2:00 – 2:15 p.m. Smith 561

Purpose and Intended Outcome 9/14/2018 Purpose and Intended Outcome Purpose Update CIO Council on the Active Directory (AD) Security Improvements Project Obtain feedback on the Vision and Plan Intended Outcome CIO Council understands the Vision, Scope and Status of the AD Security Improvements Project Project Team understands any concerns and advice that the CIO Council members have about the project

Agenda Vision Plan and resources Current status Active Directory shared service Questions and feedback

Vision: Active Directory Security Improvements The Vision for Active Directory Security Improvements To significantly increase the security and resiliency of the University’s Active Directory environment by reducing complexity, cost, and the number of successful attacks. Objectives Guiding Principles Key Performance Indicators Design a reference architecture for University Active Directory Build a University Active Directory offered as a shared service Establish and deploy the Active Directory using standards from Microsoft and standards bodies (e.g. NIST) Focus on the data and the risks, not just Active Directory itself Active Directory is a service that must meet the needs of users, including application owners Collaborate closely with Schools to understand the effort required to move into the shared service and provide assistance wherever possible Allow local control and decision-making where we can Incorporate principles of automation to ensure scalability and cloud readiness Utilize published security standards and recommendations as baseline Design audit, monitoring, and alerting in accordance with ITIL and ITSM Schools know and understand the design and value of a shared architecture Existence of shared architecture and documented plan for onboarding of Schools Number of Schools whose AD instances can be demonstrated to meet the Microsoft/NIST standards

Plan and resources Our plan involves four key actions: Resources: Perform a gap analysis of each Active Directory and remediate critical issues Build a reference architecture for Active Directory Design and implement a shared University-wide Active Directory Investigate and implement, as appropriate for the University, Microsoft’s “Red Forest” architecture Resources: Virtual team of seven people from HUIT including members of IAM, Messaging and Collaboration Technologies (MCT), Information Security Representatives from each school Vendors (Microsoft and other Active Directory experts)

Current Status Event Status Notes Finalize MS SOW Complete ADH SOW signed RedForest in review Hire Architect/Engineer positions On Target One position hired (start 9/11/2017) Second position in interview state RMAS AD Audit RMAS/HUIT/Schools efforts are coordinated Identify initial schools for Gap Analysis HKS/HLS have agreed to be participants Begin Gap Analysis Expected dated in early October Build reference architecture Initial Architecture defined. Planned internal, Steering Committee, external reviews Investigate/implement Red Forest Pending Determine value of Red Forest – if we move forward, Schools will need to dedicate resources for work to join Red Forest Define financial/ operational model for FY20+ Ongoing Initial talks underway for running AD service

Active Directory shared service University Active Directory Shared Service Delivered as: Platform As A Service (PAAS) Needs: University wide adoption Requires: support from CIOs and buy in from IT departments

Questions and feedback