180 likes | 257 Views
Title V Risk Assessment. Progress Report 8/17/2005. Awareness Video. EDUCAUSE Security Awareness Task Force produced Educate Executive Level. Title V Grant.
E N D
Title V Risk Assessment Progress Report 8/17/2005
Awareness Video • EDUCAUSE Security Awareness Task Force produced • Educate Executive Level
Title V Grant Partner Colleges and Universities:California State University, San Bernardino (Coordinating Institution) - a public, four-year university that enrolls 16,927 students, 32.4% of whom are Hispanic.California State University, Los Angeles - a public, four-year university that enrolls 20,637 students, 52.4% of whom are Hispanic.California Polytechnic State University, Pomona - a public, four-year university that enrolls 19,804 students, 24% of whom are Hispanic.Mt. San Antonio College - a public, two-year community college that enrolls 64,552 students, 36.8% of whom are Hispanic.Oxnard College - a public, two-year community college that enrolls 7,061 students, 59.2% of whom are Hispanic.
Title V – Activities • Staff and faculty training and development • Conducting complete assessments at each campus • The acquisition of H/W and S/W systems to facilitate assessments • Developing curriculum • Assisting each campus to develop new policies and procedures • Conduct security awareness training
Title V - Outcomes • Reduce vulnerabilities and reaction time • Increase in the number of trained staff • Increase in the number of trained faculty • Increase course offerings
Assessment – Year One • Title V vulnerability assessment training • Posture analysis – identify hosts • Develop assessment procedure • Prepare hardware and software • Conduct vulnerability assessment • Provide report to each campus • Notify system administrators and help with corrective action
Year Three Assessment • Title V calls for repeat of year one assessment • Vulnerability scans alone - not adequate • H/W and S/W controls alone - not adequate • Higher level risk assessment required • Asset and risk management – level of risk • Improve policies and procedures • Assess security awareness • Qualitative assessment calls for a structured process
Preventative Measures • Tighter firewall rules and ACLs • Border firewall (Title V funded) • Better patch coordination • Security tools • Awareness and technical training (Title V) • Enterprise anti-virus • Product evaluation • Periodic scanning • Better communication to the campus • Discontinue use of insecure protocols
Risk Assessment Process • Create detailed project plan – updated often • Update database of known systems (Posture) • Training for risk team • Consultation with CSUSB • Scanning infrastructure and procedures • Conduct vulnerability scans • Conduct wireless scans • Produce reports – notify stakeholders and system administrators • Help with corrective measures
Risk Team – Blackboard Hosted A Blackboard organization is used to facilitate: • Ease of communication • Meeting notes • Documentation • Sub-projects • Surveys
Risk Assessment Process • Risk team continues to meet biweekly • Risk team leads meet during off weeks • Student assistance was offered by CIS • Special thanks go to Fred Gallegos and Dan Manson for their invaluable support • Student projects were integral
Risk Assessment – Develop Procedure • Research best practices • Identify possible report templates • Create surveys • Produce interim report • Bleeding edge security technology evaluations – presentations • Understand legal liability
Risk Assessment – Develop Procedure • Methods and best practices plentiful • Documentation collected from many sources • EDUCAUSE, Burton Group, SANS, NIST, Others • Common Thread • Understand liability • Asset identification and valuation • Threat analysis • Assign risk to assets • Determine tolerable level of risk • Cost basis analysis for mitigation costs
Risk Management and Mitigation • Provide awareness training • Product demonstration and recommendations • Participate on EDUCAUSE Awareness Task force • Possible recommendations • Central policy enforcement – logging • Enterprise scanning • Policy development • Intrusion prevention • Email security implementation • Safeguarding data – education (in the works)
Risk Assessment • Professional Consultant • Help refine our process and procedures • Provide training and education • Assist with risk assessment reporting • Provide external validation
Risk Assessment - Consultant • Review existing documentation and surveys • Recommend additional data gathering approaches • Conduct interviews • Identify missing pieces in the methodology • Help develop report templates • Help prepare an executive report