Download presentation
Presentation is loading. Please wait.
Published byJanel Stevens Modified over 6 years ago
1
Sean Moriarty, Oswego State CTS 2016 Cyber Security Update
The title for the day and for our planning process is “The Digital Campus – technology for an enhanced Tomorrow” Obviously the Tomorrow refers to Oswego’s new strategic plan. And I think there is no doubt that technology is going to play a large part in helping to achieve it. About a year ago President Stanley did a presentation where she talked about the Digitally Enhanced Campus and our need to get there. So I have used that theme for all of my presentations since then and tried to ensure that we are moving in that direction. But I think it is time to start defining what the digital campus looks like, examine how close we are to being there and set the direction on how we get there. We want your help in achieving those tasks. Sean Moriarty, Oswego State CTS 2016 Cyber Security Update Faculty Assembly - October 24, 2016
2
Agenda General information on Cyber security risks and campus activities Cyber Security Month activities Risks that faculty should be aware of Cloud computing
3
Worldwide Top Issues and risks of the Past Year
Phishing Spoofing Accidental sharing of data Auto-complete in Human error Forgetting/losing documents/laptop in the taxi or at airport security Lost mobile device Compromised accounts
4
2015-16 Cyber security activities
Activation of Google 2 step login Defined a position and hired an Information Security Analyst New website - Member in the SUNY SOC (Security Operations Center) Encrypt hard drives of all new laptops User account reduction New user account processes; i.e. requiring alumni to annually renew their account reviewed other options to authenticate s (SPF,DKIM)
5
CyberSecurity Awareness Month
Weekly Topics October 3-7: Don’t Get Hooked on Phishing - Phishing Derby Contest October 10-14: Protect Your Environment October 17-21: Protect Your Mobile Devices October 24-28: Protect Your Login - Introducing Pass- Phrases You will notice additional information on campus in the form of posters, digital signage, Oswegonian ads and articles, and pamphlets.
9
Tips for Faculty Change your Lakernet passwords next week when the Passphrases are available Use 2-factor authentication for your ALWAYS have a password on your mobile device Be wary of phishing Be wary of open networks (tether to your mobile device instead and use eduroam when you are at other institutions who use it)
10
Cloud Computing Pros Cons Examples at Oswego
New services are only available in the cloud Services are more fully featured Require different staff skillset to administer the applications Can address increased requirements more quickly (increased bandwidth for the website during emergencies) Cons Different budgeting model (CapX vs OpX) Need to develop a legal trust relationship with the vendor – there may be risk in this Examples at Oswego Gmail, Aquia Web site, Starfish, Adirondak Residence System, Maxient, CSO, Adobe Creative Cloud
11
Cloud Computing (cont’d)
Managing Risk Dependent on the data in the cloud, need more oversight when it is Personally Identifiable Information (PII) and Confidential data Manage by Reputation/References of the vendor Legal contracts (CTO and SUNY legal approval) Auditing contracts
12
Cloud Computing (cont’d)
Points to Consider Is there already an existing SUNY contract with this vendor? If not, does the contract need to be reviewed by the CTO office and/or SUNY legal? Should a SUNY wide contract be considered? What data will this service use? Will Personally Identifiable Information (PII) or confidential information be shared with a vendor? Are there FERPA requirements that need to be considered to protect the shared data? Does the application meet accessibility requirements? Does the vendor have the appropriate security measures in place for the data being stored and do they have audits available?
13
Cloud Computing (cont’d)
Points to Consider Will authentication be required to utilize the service? If so, has a plan to integrate the application with the institution’s identity management system been scheduled into the project timelines? Will a data exchange project be required to obtain the service? If required, has a project been scheduled to implement the exchange? Will the application need to be customized with logo and branding? Has the proper team been created to implement these aspects of the project?
14
CTS Annual report Available at Reports on our progress towards our 4 Digital Campus Strategic Goals: Students, faculty and staff thrive by seamlessly integrating technology into their teaching, learning and scholarly activities. Our community is efficient and creates value with our technical resources. Service excellence provides efficient support through robust, green and secure infrastructure and processes. Effective IT planning and governance ensure campus priorities are achieved.
15
Questions/Comments
Similar presentations
© 2025 SlidePlayer.com. Inc.
All rights reserved.