IT Best Practices for Community Colleges Part 3: Configuration Management Donald Hester March 30, 2010 For audio call Toll Free 1-888-886-3951 and use.

Slides:



Advertisements
Similar presentations
Michelle Pacansky-Brock October 27, 2008 This is a VoIP session. All audio will be through your computer without any phone. Building Community Online,
Advertisements

Marlene Cvetko November 18, 2009 For audio call Toll Free and use PIN/code Make Teaching Easier with Dragon Naturally Speaking.
Osman Parada Senior Technology Support Specialist San Bernardino Community College District November 4, 2009 For audio call Toll Free
Micah Orloff March 17, 2010 For audio call Toll Free and use PIN/code What's New with Blackboard 9: Increase Student Success by.
Marti Atkinson October 29, 2009 For audio call Toll Free and use PIN/code Free and Easy Collaboration Tools.
Photoshop Tips and Tricks, Part 1: Cropping, Selecting, and Improving Quality Donna Eyestone February 27, 2008 For audio call Toll Free
Sean Keegan August 5, 2008 For audio call Toll Free and use PIN/code The ABCs of PDFs Part 3: Creating Accessible PDF Documents.
Donald Hester May 4, 2010 For audio call Toll Free and use PIN/code Windows 7 for IT Professionals Part 1: Security and Control.
Ryan Eash September 30, 2009 For audio call Toll Free and use PIN/code Camtasia for the Mac: Enhancing Online Learning for Mac.
Donald Hester October 21, 2009 For audio call Toll Free and use PIN/code Getting the Most from Word 2007, Part 2: References and.
The Art of PowerPoint, Part 2: Animations and Audio Zachary Schroeder April 9, 2008 For audio call Toll Free and use PIN/code
Janet Davis October 29, 2008 This is a VoIP session. All audio will be through your computer without any phone. The ABCs of PDFs with Acrobat 9, Part 2:
Bill Doherty and Pat James 2/25/2010 For audio call Toll Free and use PIN/code Professional Development on a Shoe String Budget.
The Art of PowerPoint, Part 1: Tools, Views and Master Slides Zachary Schroeder April 2, 2008 For audio call Toll Free and use PIN/code.
Micah Orloff September 21, 2010 For audio call Toll Free and use PIN/code
Donna Eyestone February 23, 2011 For audio call Toll Free and use PIN/code
Gregory Beyrer July 22, 2010 For audio call Toll Free and use PIN/code From Blackboard to Desire2Learn.
Michelle Macfarlane March 5, 2009 For audio call Toll Free and use PIN/code Engaging Millennial Students with Fun Tech: Animoto.
Donna Eyestone 2/24/2010 For audio call Toll Free and use PIN/code Free Podcast Hosting with 3CRSS.
Tony McKinley August 11, 2009 For audio call Toll Free and use PIN/code Save $$ with Nuance's New PDF Converter.
Micah Orloff March 10, 2010 For audio call Toll Free and use PIN/code What's New with Blackboard 9: Increase Student Retention.
Online Tutoring made Easy Kakwasi Somadhi April 29, 2008 For audio call Toll Free and use PIN/code
Donald Hester March 30, 2010 For audio call Toll Free and use PIN/code IT Best Practices for Community Colleges Part 3: Configuration.
Donald Hester March 9, 2010 For audio call Toll Free and use PIN/code IT Best Practices for Community Colleges Part 2: Business.
Donald Hester February 9, 2010 For audio call Toll Free and use PIN/code IT Best Practices for Community Colleges Part 1: IT Risk.
Richard Mundell November 11, 2009 For audio call Toll Free and use PIN/code Free and Easy Course Authoring with myUDUTU.
Eric Wilson, MS Ed March 16, 2010 For audio call Toll Free and use PIN/code Online Collaborative Groups.
Micah Orloff March 3, 2010 For audio call Toll Free and use PIN/code What's New with Blackboard 9: Getting Acquainted.
Joan Van Duzer October 1, 2009 For audio call Toll Free and use PIN/code Engaging Millennial Students with Fun Tech: Learning with.
Donna Eyestone 4/21/2010 For audio call Toll Free and use PIN/code The Power of iLife.
Sharon Beynon November 12, 2008 This is a VoIP session. All audio will be through your computer without any phone. Add Fun and Interest to Teaching Writing.
Eric Wilson August 5, 2010 For audio call Toll Free and use PIN/code
Sharon Beynon October 22, 2009 For audio call Toll Free and use PIN/code Add Fun and Interest to Teaching Online with Audio Clips.
Donald Hester April 20, 2010 For audio call Toll Free and use PIN/code IT Best Practices for Community Colleges Part 4: Awareness.
Michelle Macfarlane November 10, 2009 For audio call Toll Free and use PIN/code Building Community Online, Part 5: Social Networking.
Micah Orloff August 7, 2008 For audio call Toll Free and use PIN/code The Art of PowerPoint 2007 Part 2: Animations and Audio.
Micah Orloff July 7, 2009 For audio call Toll Free and use PIN/code What's New on Blackboard: Exploring the Grade Center.
Tahiya Marome October 8, 2009 For audio call Toll Free and use PIN/code Engaging Millennial Students with Fun Tech: Games.
Donald Hester October 7, 2009 For audio call Toll Free and use PIN/code Getting the Most from OneNote 2007.
Michelle Macfarlane September 24, 2009 For audio call Toll Free and use PIN/code Engaging Millennial Students with Fun Tech: Jing.
Donald E. Hester July 23, 2008 For audio call Toll Free and use PIN/code Get up to Speed with 2007 Office Part 2: PowerPoint, Outlook,
Catherine Werst November 5, 2009 For audio call Toll Free and use PIN/code Collaborate with Social Bookmarking.
Micah Orloff May 5, 2011 For audio call Toll Free and use PIN/code
Donald Hester October 14, 2009 For audio call Toll Free and use PIN/code Getting the Most from Word 2007, Part 1: Creating and.
Blaine Morrow 3/2/2010 For audio call Toll Free and use PIN/code New Video Collboration with Elluminate.
Anna Stirling and Micah Orloff May 22, 2012 For audio call Toll Free and use PIN/code Take Your Online Teaching to New Heights:
Donald E. Hester 19-Mar-2010 For audio call Toll Free and use PIN/code
Donald E. Hester October 30, 2009 For audio call Toll Free and use PIN/code Windows 7: The View Beyond Vista is Great.
Donald Hester October 21, 2010 For audio call Toll Free and use PIN/code
Catherine Werst July 27, 2010 For audio call Toll Free and use PIN/code
Donna Eyestone May 25, 2010 For audio call Toll Free and use PIN/code iPad in Education.
Larry Green July 15, 2010 For audio call Toll Free and use PIN/code Online Math Games and Resources.
Joan Van Duzer April 13, 2011 For audio call Toll Free and use PIN/code
Micah Orloff and Donna Eyestone October 19, 2010 For audio call Toll Free and use PIN/code
Lynn Strand March 30, 2011 For audio call Toll Free and use PIN/code
Marsha Fralick and Keith Franco July 13, 2010 For audio call Toll Free and use PIN/code A College Success Course for New Millennial.
James Glapa-Grossklag July 20, 2010 For audio call Toll Free and use PIN/code
Marsha Fralick and Keith Franco July 13, 2010 For audio call Toll Free and use PIN/code A College Success Course for New Millennial.
Donna Eyestone February For audio call Toll Free and use PIN/code
Eric Wilson July 30, 2010 For audio call Toll Free and use PIN/code
Principles of Computer Security: CompTIA Security + ® and Beyond, Third Edition © 2012 Principles of Computer Security: CompTIA Security+ ® and Beyond,
TMS - Cooperation partner of TÜV SÜD EFFECTIVE SERVICE MANAGEMENT based on ISO/IEC & ISO/IEC
Changing IT Managing Networks in a New Reality Alex Bakman Founder and CEO Ecora Software.
What’s It All About, SACM?
Building an Online Writing Center
Integrating Social Media Management in Your Classroom
Special Publication Protecting Controlled Unclassified Information in Nonfederal Information Systems and Organizations Dr. Ron Ross Computer Security.
Release Management Release Management.
Information Technology Service Management
EDUCAUSE Security Professionals Conference 2018 Jason Pufahl, CISO
Presentation transcript:

IT Best Practices for Community Colleges Part 3: Configuration Management Donald Hester March 30, 2010 For audio call Toll Free 1-888-886-3951 and use PIN/code 133206

Housekeeping Maximize your CCC Confer window. Phone audio will be in presenter-only mode. Ask questions and make comments using the chat window.

Do not listen on both computer and phone. Adjusting Audio If you’re listening on your computer, adjust your volume using the speaker slider. If you’re listening over the phone, click on phone headset. Do not listen on both computer and phone.

Saving Files & Open/close Captions Save chat window with floppy disc icon Open/close captioning window with CC icon

Emoticons and Polling Raise hand and Emoticons Polling options

IT Best Practices for Community Colleges Part 3: Configuration Management Donald Hester

Configuration Management “The management of security features and assurances through control of changes made to hardware, software, firmware, documentation, test, test fixtures, and test documentation throughout the life cycle of an information system.” National Information Systems Security Glossary

IT Standards Control Objectives for Information and related Technology (COBIT) Information Technology Infrastructure Library (ITIL) International Standards Organization (ISO) National Institute of Standards and Technology (NIST)

The facts 80% of IT systems outages are caused by operator and application errors.

High-Performance IT organizations Common Characteristics 1 admin for every 100 servers More planned work than unplanned work More staff early in lifecycle Collaboration Posture of compliance (IT standards) Culture of change management Understand causality Manage by facts

The missing pieces Configuration Management Change Management Release Management Incident Management Problem Management

Benefits of Configuration Management Good CM does not increase workload it decreases it Fewer Incidents Greater Return on Investment (ROI) Faster Recovery (MTTR) Improve IS quality Improve IT service

CM Lifecycle Configuration identification Configuration control Baseline, gold standard Configuration control Change management, change control Configuration status accounting Enforcement Configuration audits Testing

Configuration Identification Configuration Management Database (CMDB) A repository of information related to all the components of an information system Configuration files Group Policy settings Image files for operating systems Details about the important attributes and relationships between them

Policy Develop, disseminate, and review/update A documented configuration management policy Addresses purpose, scope, roles, responsibilities, management commitment, coordination among organizational entities, and compliance

Baseline Develop, document, and maintain under configuration control, a current baseline configuration Images Builds CMDB Configuration files GPO (Group policy objects)

Baselines A place to start Modify based upon your needs Federal Desktop Core Configuration (FDCC) CIS Benchmarks Modify based upon your needs You may have different configurations for different workstations Compatibility issues Interoperability issues

Control Change Determine the types of changes to the information system that are configuration controlled Approve configuration-controlled changes Coordinate and provide oversight for configuration change control activities Document approved configuration-controlled changes

Impact Analysis Analyze changes to the information system to determine potential security impacts prior to change implementation Confidentiality Integrity Availability Interoperability Compatibility

Restrict changes to the system Define, document, approve, and enforce physical and logical access restrictions associated with changes to the information system Limit who can make changes This means no local admins Automate if possible

Least Functionality Configure the information system to provide only essential capabilities and specifically prohibit or restrict the use of functions, ports, protocols, and/or services If it is not needed why have it?

Inventory Develop, document, and maintain an inventory of information system components Accurately reflect the current system At a level of granularity deemed necessary

NIST There is no compulsory IT standard required for local governments The National Institute of Standards and Technology (NIST)encourages state, local and tribal governments to consider the use of these guidelines, as appropriate In adopting NIST standards the local government demonstrates due diligence

Resources Institute of Configuration Management NIST (FDCC) http://www.icmhq.com/ NIST (FDCC) http://nvd.nist.gov/fdcc/index.cfm Center for Internet Security (CIS) Benchmarks http://cisecurity.org/ IT Governance Institute (ITGI) http://www.itgi.org/

Q&A Donald E. Hester CISSP, CISA, CAP, MCT, MCITP, MCTS, MCSE Security, Security+ Maze & Associates @One / San Diego City College www.LearnSecurity.org http://www.linkedin.com/in/donaldehester http://www.facebook.com/group.php?gid=245570977486 25

Evaluation Survey Link Help us improve our seminars by filing out a short online evaluation survey at: http://www.surveymonkey.com/s/10SpIT3

Join us in San Diego at the 2010 Online Teaching Conference “Engaging every online student in lean and green times.” June 16, 17, & 18 - San Diego City College Register now at http://otc10.org

IT Best Practices for Community Colleges Part 3: Configuration Management Thanks for attending For upcoming events and links to recently archived seminars, check the @ONE Web site at: http://onefortraining.org/