Technology Solutions Cybersecurity Report to the KCTCS Board of Regents March 14, 2019
Why this presentation? Association for Governing Boards (AGB) Best Practice Recommend periodic updates to Board Inform board what KCTCS is doing with security/disaster recovery Ensure single individual is ultimately accountable but everyone in the institution plays a supporting role Chief Information Security Officer (CISO – “see-so”) 2 FTE dedicated to security on staff
What are Cyberattacks? Data breaches – incident that puts at risk exposure of sensitive data Highest risk (easily monetized data) Student Information System Financial System HR/Payroll Data Warehouse Document imaging (scanned sensitive data)
Not all data are created equally We prioritize/triage the data within systems i.e. directory data less risky than SSN / drivers license number Ensure that systems are secured in “least privileged” manner “The principle in which a subject – whether a user, application, or other entity – should be given the minimum level of rights necessary to do their job”
5 Facets of Security Identification Knowing what to look for and what to protect Protection Implementing protective measures Detection Monitoring for suspicious activity Response Who does what after breach/incident detected Recovery Disaster recovery
Where to start? KCTCS policy 4.2.6 covers security breaches and actions necessary Much of this mandated by external auditors Basics Firewalls (device that regulates access to network) Patching computing devices, hardware, software Phishing Awareness This is the single most important piece of our strategy
Advanced measures Intrusion detection systems Penetration testing Brute force testing Privileged account management Vetting KCTCS contractual partners Data center evaluations Regulatory compliance (effective controls SSAE-16)
Single largest risk? PHISHING Employee unknowingly giving up their credentials via Phishing Over 164 million malicious emails blocked in 2018 Mitigation? Employee training, marketing campaigns Implementing 2-factor authentication with “power users” Something you know (password) & Something you have (i.e. text message to a phone)
Goal is recovery within 60 minutes Some of our systems hosted in the Amazon and Microsoft clouds can recover in seconds
Disaster Recovery/Business Continuity Incremental backups (hot) nightly, full (cold) backups weekly Goal is recovery within 60 minutes Some of our systems hosted in the Amazon and Microsoft clouds can recover in seconds Failover site should be 100-150 miles from primary data center (Atlanta and Nashville for us) We practice full-scale outage annually