Free Newsletters




   
CIO magazine chief information officer ERP IT strategy  research  analysis business technology e-business CRM customer relationship management e-business   enterprise resource management leadership
CIO.com
About
Search
Awards Programs
Subscribe
Magazine
Current
Previous
Print Links
Newsletters
CIO Store
CIO Conferences
CIO Executive Council
Blogs
News Alerts
CEO Reading
IT Strategy
Tech Linkletter
Tech Policy
Viewpoints
Experts
Alarmed
Analyst Corner
Beneath the Buzz
Consultant Briefing
Higher Learning
In the Know
Leading Questions
Weigh-In
Discussion Forums
Career
CIO Wanted
Counselor
IT Events Calendar
Movers & Shakers
Research & Polls
CIO Research Rpts
Quick Poll
Tech Poll
Reports & Guides
CIO Bookmark
Reading Room
Special Reports
Compliance
RITLAB
State of the CIO
Webcasts
White Papers
About Us
Advertise at CIO
Conference Info
Editorial Calendar
Editorial Staff
List Services
News Bureau
Reprints
Sales
Related Sites
CSO
CMO
Darwin
IDG Network
Feedback to CIO
© CXO Media Inc.
subscribe to CIO Magazine



Home > CIO Metrics
Regulatory Resource   Threat Intelligence      Resilient IT      Boardroom Strategies      
Threat Intelligence / Spam and Viruses

Infosecurity in Academia

By Scott Cherkin

Unlike commercial or governmental organizations where strict IT policies can be mandated, the culture of higher education is deeply rooted in the free exchange of ideas and information. As such, academic institutions face unique information security threats involving compromised private data, financial losses, and attacks on critical infrastructure -- all of which have significant ramifications for public safety and security. With incidents increasing in severity over time, academia's CIOs have been challenged to establish a delicate balance between maintaining openness for their particular culture and ensuring the security and privacy of sensitive information and networks.

This article will explore four challenges to information security faced by academic institutions: balancing an open culture with security; diverse users and appropriate access methods; the sensitive nature of academic information; and high-risk activities on academia's networks.

Culture-clash: openness vs. security The first challenge academic CIOs face concerns the philosophical and ideological environment of the campus:  CIOs cannot disregard the spirit of academic culture that is built upon free access to information and the open exchange of ideas. At the same time, they can't forgo security and privacy around sensitive and personally identifiable information, government-sponsored research and development (R&D), or raw computing power. As such, efforts to secure the academic network are often limited by the academic philosophy as well as budget constraints. In some cases, even firewalls have not been deployed - widely enough because of a campus belief in open experimentation and collaboration. There comes a point when the open culture of academia needs to protect itself from the onslaught of attacks that are increasing in both number and -severity.

Diverse users and access methods The academic computing environment hosts several types of users with different roles, rights, and responsibilities, including students, faculty, staff, and visitors. Public universities also host the public, as their libraries are open to this group, too. In all cases, turnover is a major element, as each year brings a new freshman class and transferring students. Most students arrive at the university with their own laptops possibly already infected with viruses, spyware, and other malicious code -- and then plug them into the network. In fact, the University of North Texas in Denton found that 4,000 of the school's 5,700 resident students reporting for the fall semester brought computers infected with some sort of virus. An identity management dilemma has arisen as a result of the need to maintain the open exchange of information while keeping tabs on these various user constituencies.

Sensitive nature of information Academic institutions are unique in the amount and -type of sensitive data residing on their networks, such as Social Security numbers, dates of birth, driver's license numbers, tuition account details, payment information, billing information, health records, grades, and coursework. With distance or e-learning increasing in popularity, a university's core intellectual property is made available on Web servers -- creating another area of risk. In addition, academic institutions often host highly sensitive information involved in government-sponsored research and development via grants that topped $36 billion in 2002, according to the National Science Foundation's May 2004 report. Gaps in academic IT policy and procedures endanger the security of this sensitive, and sometimes classified, information.

High-risk activities on academia's networks Increasing academia's risk to emerging threats are pervasive, high-risk activities such as peer-to-peer networking and instant messaging. Such activities can open networks up to serious exposure: A House of Representatives Committee on Government Reform report from May 2003 found that users who surfed through peer-to-peer networking site Kazaa could also access private information residing on users' computers, such as completed 1040s, military records, living wills, and personal in-boxes. These innovations in information sharing have an additional dark side: they provide malicious threats (i.e., worms, viruses and Trojans) an entry point to otherwise secure networks.

While the unique information security issues facing academic institutions are significant and evolving at a rapid pace, they can be addressed by developing and implementing a variety of remediation strategies. Examples of strategies that are relatively easy to implement yet have substantial impact are as follows:

#1: Strengthen your university's information security policy

  • Obtain endorsement from senior administrators.
  • Formalize a policy to address key issues you are currently encountering and believe you will need to address in the future.
  • Ensure students, faculty, and staff are presented with your information security policy.  If nothing else, they will be aware of the policy and any unauthorized activities.
  • Require written agreement to your university's information security policy from students, faculty, and staff. This will greatly enhance enforcement capabilities.

#2: Educate and train end-users

  • Train end-users on their rights, on how fair-use is defined, and their role in safeguarding the network.
  • Make training mandatory and test various methods over time, including in-person, e-learning, periodic email notifications, and the like.  Learn what your end-users' preferences are and leverage them.
  • Provide refresher courses and emergency update training.
  • Explore an "infosecurity training" credential or certificate that can be used on student resumes, and faculty and staff reviews.
  • Consider follow-up training with social engineering tests to monitor your group's effectiveness at curbing risky behavior.

#3: Tighten your countermeasures

  • Make sure antivirus, intrusion detection/prevention, and operating system/application patches are up-to-date.
  • Use firewalls to filter executables out of mail, and close ports, like IRC ports 6666 and 6667, that pose significant threats. 
  • Watch for how botnet traffic evolves, including via peer-to-peer networks, and adapt to guard against their malicious behavior.
  • Explore better identity management solutions to secure critical assets inside the network.
  • Monitor evolving threats -- watch for patterns of interactions in network traffic and stay up-to-date with emerging, blended threats.

It is clear that information security efforts are under-funded and threats may not be fully understood by university management and boards of directors. CIOs must make the case for more funding and resources to help protect public safety and secure critical infrastructure.   

Scott Cherkin is a Director for a National Institute of Justice-funded information security research project exploring the unique attributes of academia and their ramifications for public safety and security.  For more information, go to the Information Security in Academic Institutions Web site.

CIO Strategy Center is a daily editorial resource offering innovative insights and strategies for building an integrated, secure and resilient IT infrastructure.

Articles by Topic
Spam and Viruses
Preparedness
Strategies
Related Content
Fast Fact

"4,000 of the school's 5,700 resident students reporting for the fall semester brought computers infected with some sort of virus."

--University of North Texas, Denton






Advertisers



Free Newsletters
Sponsor Content
 Domains
Compliance CIO Partner Domain for I.T. Productivity
The domain for everything you need to assess, measure and improve
IT Productivity within your organization, Whitepapers, Books, Research, Benchmarking tools and lots more.
 Webcasts
Compliance Failure is not an option: Why online compliance and security can’t wait.
Compliance BI Standardization: Attend our virtual conference for real advice.
Compliance Getting Smart about Offshoring: How Visual Simulation Gets It Right the First Time
Compliance Turning Best Practices to Best Projects
Compliance Securing Enterprise Data In An Unsecured World
Compliance A New Game—The Fast Emerging World of IP Convergence
Compliance All CIO Webcasts
 White Papers
Compliance Organizations Shift Focus to Information Management
Compliance Tera-Scale Data Warehouse Appliances Overcome the Technology Bottleneck
Compliance Knowing the Risk
Compliance Why Asset Management and Discovery are Core Contributors to Effective Business Service Management
Compliance Start your ERP upgrade with a distinctive master data advantage
Compliance Putting your Spend Data Warehouse on steroids
Compliance All CIO White Papers

IDG ENTERPRISE NETWORK

NetApp launches expanded NAS line - Infoworld Staff
IBM, BEA lay out new Java specs - Infoworld Staff
  »More  

Phishing scams rocket
Wi-Fi switches: breakthrough year, future fear
  »More  

Users get going on SP2 rollouts
Shark Tank: Just one more thing to remodel
  »More  

SPONSORED LINKS:
Align IT with business goals. Introducing PlanView Enterprise.
A data warehouse 10-50x faster at ½ the cost. Learn more!
How do you compare with 565 IT organizations?
For real advice on BI Standardization attend the Virtual Conference on Feb 22
Manage IT Change. Manage the Business. Free white paper.
Ten Principles for Knowledge Management Success" - Get the free white paper from ServiceWare
Audit the Data or Else: Un-audited data increases business risk Grid
See Qualcomm, EPL, and Deutsche Post on the Oracle Grid
Preventing Client/Vendor Mismatch: click here to learn more

Free Newsletters

Dated: March 01, 2005
http://www.cio.com/blog_view.html?ID=221


About CIO.com | Welcome | Privacy Policy | Terms of Service | Linking to us

CIO.COM complies with the ASME Guidelines with IDG extensions for new media.

CIO magazine chief information officer ERP strategy IT research analysis business technology management e-business knowledge management intranet CRM cio.com CRM customer relationship management e-business ERP enterprise resource management leadership management measuring IT value outsourcing supply chain

© 1994 - 2005 CXO Media Inc.

An International Data Group (IDG) Company



 HOME  CURRENT ISSUE  ARCHIVE   About CIO :: Advertise :: Subscribe :: Conferences 

Reprints, IDG Network, Privacy Policy

THE IDG NETWORK
CSO :: CMO :: Darwin :: Computerworld :: Network World :: Infoworld :: PC World :: Bio-IT World
IT Careers:: JavaWorld :: Macworld :: Mac Central :: Playlist :: GamePro :: GameStar :: Gamerhelp



Problems/complaints/compliments about this site can be sent to deiben@cio.com.