Quickly Establishing A Workable IT Security Program EDUCAUSE Mid-Atlantic Regional Conference January 10-12, 2006 Copyright Robert E. Neale This work is the intellectual property of the author. Permission is granted for this material to be shared for non-commercial, educational purposes, provided that this copyright statement appears on the reproduced materials and notice is given that the copying is by permission of the author. To disseminate otherwise or to republish requires written permission from the author.
What this presentation will cover Background information on VCU Driving forces for our Security Program Getting Started Tips for quickly starting a Security Program VCU Security Program – Experiences and Examples Summary
VCU Background Information Virginia Commonwealth University Located in Richmond, Va. Monroe Park Campus MCV Campus 29,000 students – 4,000 in VCU housing 9,000 faculty/staff
VCU Information Technology Environment Central IT – Technology Services Separate IT Structure for Hospital Additional IT staffs in some schools Replacing IBM MF with SCT Banner on Sun/Solaris Critical servers (350) in the VCU Computer Center Scan indicates 600 addition servers on network At least 10,000 PC’s connect to the network Network – Primarily Cisco, mostly fiber Wireless in some parts of Campus
Driving forces Federal, State Mandates – HIPPA, FERPA,SEC 501 Lack of coordination of security efforts Various cyber attacks Loss of productivity due to security incidents News of incidents at other universities
Getting Started Form a Security Program Development Team – Key decision makers in IT initially – High level security expertise – Keep group small (4-6) Weekly Meetings for review & discussion Start with an existing program or standards Set a completion goal of 6 weeks
Tips for developing a Security Program – Don’t start from scratch – use other programs NIS, SANS, Educause, Universities VASCAN - – Consolidate all existing security activities into Security Program – Address what you can first – Iterative process – Get initial plan out quickly – Prioritize security activities based on current needs
Tips – Continued Create Partnerships -- Seek Sponsors IT Professionals Forum & Intranet Site Desktop Management Groups Emergency Response Team Campus Police Human Resources Information Systems Professors Other Universities Vendors
Tips Continued – Security Team Search for technical staff showing an interest in security Work with managers to allocate time Team size - 4 to 5 FTE equivalents Develop action items from Security Program to be assigned to Security Team
Tips Continued – IT Security Web Site Search your web for existing security related material Develop a role base security web site – Students – Faculty and staff – Technical staff Sections for Communicating Security Program, Policies, and Standards Links to other Security Sites
Tips Continued – Understand your environment What are your network devices? How many servers and PC’s are on your network? Who manages these devices? Evaluate current protection – IDS, IPS,AV Use regular scans to monitor environment
Tips Continued – Managed network environment Server Consolidation Single Mail System Directory Services – AD, Novell Desktop Management Software Authenticate access to network Change Management
Tips Continued – Simple Risk Assessment Initially Define Sensitive Data Categories Simple list of questions Interview process – 1 hour Follow up in 1 week with report
Tips Continued – Security Awareness Make it fun and interesting Integrate it with current HR and student processes Policy and role based training material Multimedia approach to training material Provide materials for others to use
Review Security Program Development Team Quick results – build on other plans Create partnerships Draw security team from interested staff Consolidate existing security web content Know environment, then manage it Use a simple security assessment tool Security Awareness key – make it interesting
Summary Make your security program an integral part of your organization. Use other projects and initiatives to help drive security in your organization. Have others champion parts of your security program. Make it truly a shared program made up of many partnerships between your security staff and other parts of your organization.
Questions?
Additional Material – VCU Security Program - Components Authentication, Authorization and Encryption Business Analysis & Risk Assessment Business Continuity Planning Data Security Incident Handling Monitoring and Controlling System Activity Physical Security Personnel Security Security Awareness Security Tool Kit Systems Interoperability Security Technical Communications Technical Training Threat Detection