<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title><![CDATA[[SecurityRatty] tag: colleges]]></title>
    <link>http://securityratty.com/tag/colleges</link>
    <description></description>
    <pubDate>Wed, 20 Feb 2008 21:00:00 +0000</pubDate>
    <generator>iRatty Engine</generator>
    <docs>http://blogs.law.harvard.edu/tech/rss</docs>
    <item>
      <title><![CDATA[IT security education continues to evolve]]></title>
      <link>http://securityratty.com/article/12f71b7b79d710d8bc043972aaa1f439</link>
      <guid>http://securityratty.com/article/12f71b7b79d710d8bc043972aaa1f439</guid>
      <description><![CDATA[The majority of programs at colleges and universities around the country are certainly doing a good job of training people to go into positions in IT. In fact, we have a greater demand among employers...]]></description>
      <content:encoded><![CDATA[The majority of programs at colleges and universities around the country are certainly doing a good job of training people to go into positions in IT. In fact, we have a greater demand among employers for students than we have students to fill positions. That said, there are some areas where we lack students who graduate with the right amount of expertise and focus. IT security and cyber forensics are areas where we have a critical need for workers in the field.<p><A href="http://ad.doubleclick.net/jump/idg.us.nwf.rss/security;sz=468x60;ord=55251?">
<IMG src="http://ad.doubleclick.net/ad/idg.us.nwf.rss/security;sz=468x60;ord=55251?" border="0" width="468" height="60"></A>
</p>]]></content:encoded>
      <pubDate>Sun, 16 Nov 2008 21:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/students">students</category>
      <category domain="http://securityratty.com/tag/lack students">lack students</category>
      <category domain="http://securityratty.com/tag/fill positions">fill positions</category>
      <category domain="http://securityratty.com/tag/positions">positions</category>
      <category domain="http://securityratty.com/tag/cyber forensics">cyber forensics</category>
      <category domain="http://securityratty.com/tag/security">security</category>
      <category domain="http://securityratty.com/tag/workers">workers</category>
      <category domain="http://securityratty.com/tag/focus">focus</category>
      <category domain="http://securityratty.com/tag/critical">critical</category>
      <source url="http://www.networkworld.com/news/2008/111708-it-security-education-continues-to.html?fsrc=rss-security">IT security education continues to evolve</source>
    </item>
    <item>
      <title><![CDATA[P2P legislation forcing university IT to get tough on piracy]]></title>
      <link>http://securityratty.com/article/ce474834bcbcbf28fb06a36647808e4f</link>
      <guid>http://securityratty.com/article/ce474834bcbcbf28fb06a36647808e4f</guid>
      <description><![CDATA[A new law aimed at stopping illegal peer-to-peer file-sharing of digital entertainment content, such as music and videos, requires the nation's colleges and universities to educate students that P2P...]]></description>
      <content:encoded><![CDATA[A new law aimed at stopping illegal peer-to-peer file-sharing of digital entertainment content, such as music and videos, requires the nation's colleges and universities to educate students that P2P piracy is illegal and strongly encourages the use of technology to monitor and block illegal P2P.]]></content:encoded>
      <pubDate>Wed, 22 Oct 2008 20:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/illegal">illegal</category>
      <category domain="http://securityratty.com/tag/block illegal p2p">block illegal p2p</category>
      <category domain="http://securityratty.com/tag/illegal peer-to-peer">illegal peer-to-peer</category>
      <category domain="http://securityratty.com/tag/digital entertainment content">digital entertainment content</category>
      <category domain="http://securityratty.com/tag/law aimed">law aimed</category>
      <category domain="http://securityratty.com/tag/p2p piracy">p2p piracy</category>
      <category domain="http://securityratty.com/tag/strongly encourages">strongly encourages</category>
      <category domain="http://securityratty.com/tag/nation">nation</category>
      <category domain="http://securityratty.com/tag/monitor">monitor</category>
      <source url="http://www.networkworld.com/news/2008/102308-p2p-college-legislation.html?fsrc=rss-security">P2P legislation forcing university IT to get tough on piracy</source>
    </item>
    <item>
      <title><![CDATA[The first steps in reducing the embarrassing frequency of college system breaches]]></title>
      <link>http://securityratty.com/article/655ab0e39d157dd8b64f4a44bdd8e2a3</link>
      <guid>http://securityratty.com/article/655ab0e39d157dd8b64f4a44bdd8e2a3</guid>
      <description><![CDATA[Heres a scenario that could happen to anybody in any organization. But with the staggering number of information security breaches occurring at colleges and universities recently, this scenario is...]]></description>
      <content:encoded><![CDATA[Here&#8217;s a scenario that could happen to anybody in any organization. But with the staggering number of information security breaches occurring at colleges and universities recently, this scenario is perhaps more common in within educational institutions.
A university professor receives an email from another colleague working in the university. The subject line says, &#8220;Here&#8217;s a good [...]]]></content:encoded>
      <pubDate>Fri, 20 Jun 2008 12:52:59 +0000</pubDate>
      <category domain="http://securityratty.com/tag/university">university</category>
      <category domain="http://securityratty.com/tag/university professor receives">university professor receives</category>
      <category domain="http://securityratty.com/tag/information security breaches">information security breaches</category>
      <category domain="http://securityratty.com/tag/scenario">scenario</category>
      <category domain="http://securityratty.com/tag/universities recently">universities recently</category>
      <category domain="http://securityratty.com/tag/subject line">subject line</category>
      <category domain="http://securityratty.com/tag/educational institutions">educational institutions</category>
      <category domain="http://securityratty.com/tag/common">common</category>
      <category domain="http://securityratty.com/tag/email">email</category>
      <source url="http://securityviews.com/blog/2008/06/20/the-first-steps-in-reducing-the-embarrassing-frequency-of-college-system-breaches/">The first steps in reducing the embarrassing frequency of college system breaches</source>
    </item>
    <item>
      <title><![CDATA[Oklahoma State breach points to higher-ed security problems]]></title>
      <link>http://securityratty.com/article/b69e6277e7ec24e0dd21278816095767</link>
      <guid>http://securityratty.com/article/b69e6277e7ec24e0dd21278816095767</guid>
      <description><![CDATA[A seemingly neverending string of data breaches at various colleges around the U.S. highlights precisely why university systems and networks continue to have a reputation for being notoriously...]]></description>
      <content:encoded><![CDATA[A seemingly neverending string of data breaches at various colleges around the U.S. highlights precisely why university systems and networks continue to have a reputation for being notoriously insecure.]]></content:encoded>
      <pubDate>Wed, 14 May 2008 20:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/notoriously insecure">notoriously insecure</category>
      <category domain="http://securityratty.com/tag/networks continue">networks continue</category>
      <category domain="http://securityratty.com/tag/highlights precisely">highlights precisely</category>
      <category domain="http://securityratty.com/tag/data breaches">data breaches</category>
      <category domain="http://securityratty.com/tag/university systems">university systems</category>
      <category domain="http://securityratty.com/tag/colleges">colleges</category>
      <category domain="http://securityratty.com/tag/reputation">reputation</category>
      <category domain="http://securityratty.com/tag/seemingly">seemingly</category>
      <source url="http://www.networkworld.com/news/2008/051508-oklahoma-state-breach-points-to.html?fsrc=rss-security">Oklahoma State breach points to higher-ed security problems</source>
    </item>
    <item>
      <title><![CDATA[Stolen SunGard laptop affects at least 10 post-secondary schools]]></title>
      <link>http://securityratty.com/article/1617ae0ac3225e4776e688f447ddbccc</link>
      <guid>http://securityratty.com/article/1617ae0ac3225e4776e688f447ddbccc</guid>
      <description><![CDATA[Technorati Tag: Security Breach

Date Reported
4/17/08

Organization
Various post-secondary schools, including but not necessarily limited to
Central Connecticut State University
Eastern Connecticut...]]></description>
      <content:encoded><![CDATA[Technorati Tag: <a href="http://technorati.com/tag/security+breach" rel="tag">Security Breach</a><br><br>
<img src="http://breachblog.com/images/95781-88451/sungard.jpg" align="right" height="72" width="199"><font size="2"><span style="font-weight: bold;">Date Reported: </span><br>4/17/08<br><br><span style="font-weight: bold;">Organization: </span><br>Various post-secondary schools, including but not necessarily limited to:<br><a href="http://www.ccsu.edu/">Central Connecticut State University</a> <br><a href="http://www.easternct.edu/">Eastern Connecticut State University</a> <br><a href="http://www.southernct.edu/">Southern Connecticut State University</a> <br><a href="http://www.wcsu.edu/%203502">Western Connecticut State University</a> <br><a href="http://www.nmc.edu/">Northwestern Michigan College</a> <br><a href="http://www.nwmissouri.edu/%201100">Northwest Missouri State University</a> <br><a href="http://www.buffalostate.edu/">Buffalo State College</a><br><a href="http://www.brockport.edu/">State University College at Brockport</a><br><a href="http://www.monroecc.edu/">Monroe Community College</a> <br><br><span style="font-weight: bold;">Contractor/Consultant/Branch:</span><br><a href="http://www.sungardhe.com/index.aspx">SunGard Higher Education</a>*<br><br><font size="1">*From the SunGard Higher Education "About Us" page:<br>"SunGard Higher Education provides software, strategic consulting, and technology management services to colleges and universities. We help more than 1,600 institutions worldwide strengthen institutional performance by improving constituent services, increasing accountability, and enhancing the education experience.<br><br>SunGard Higher Education has a vision to unify people, process, and technology in an environment that addresses the needs of higher education institutions and the people they serve. We call this vision the Unified Digital Campus."</font><br><font style="font-style: italic;" size="1">[Evan] All of "the needs" except one critical one... SECURITY!</font><br><br><span style="font-weight: bold;">Victims:</span><br>Students and a limited number of employees<br><br><span style="font-weight: bold;">Number Affected:</span><br>Unknown, but at least 23702<br><br><span style="font-weight: bold;">Types of Data:</span><br>Personal information including names, Social Security numbers and financial aid information<br><br><span style="font-weight: bold;">Breach Description:</span><br>"A laptop belonging to a consultant at SunGard Higher Education was stolen on March 13, 2008. The theft was immediately reported to law enforcement but the laptop has not been recovered. After analyzing a backup of the computer, SunGard Higher Education found that the stolen laptop contained data from projects with a number of customers."<br><br><span style="font-weight: bold;">Reference URL:</span><br><a href="http://www.sungardhe.com/laptoptheft">SunGard Higher Education (general)</a> <br><a href="http://www.newstimes.com/ci_8956150?source=most_emailed">The News-Times (Connecticut State University Schools)</a> <br><a href="http://www.newsday.com/news/local/wire/connecticut/ny-bc-ct--stolenlaptop0417apr17,0,6006519.story">Associated Press Connecticut (Connecticut State University System)</a> <br><a href="http://www.mlive.com/newsflash/michigan/index.ssf?/base/news-52/1208630945313100.xml&amp;storylist=newsmichigan">Associated Press Michigan (Northwestern Michigan College)</a> <br><a href="http://www.maryvilledailyforum.com/articles/2008/04/17/news/news3.txt">Maryville Daily Forum (Northwest Missouri State University)</a> <br><a href="http://www.buffalonews.com/home/story/325975.html">The Buffalo News (Buffalo State College)</a> <br><a href="http://www.democratandchronicle.com/apps/pbcs.dll/article?AID=/20080419/NEWS01/804190328/1002/NEWS">Democrat and Chronicle (State University of New York schools)</a> <br><a href="http://www.nmc.edu/news/2008/041804-potential-data-theft.html">Northwestern Michigan College</a> <br><a href="http://www.buffalostate.edu/privatedata/">Buffalo State College</a> <br><a href="http://www.brockport.edu/newsbureau/1063.html">State University College at Brockport</a> <br><br><span style="font-weight: bold;">Report Credit:</span><br>SunGard Higher Education<br><br><span style="font-weight: bold;">Response:</span><br>From the online sources cited above:<br><br>A laptop belonging to a consultant at SunGard Higher Education was stolen on March 13, 2008. The theft was immediately reported to law enforcement but the laptop has not been recovered. After analyzing a backup of the computer, SunGard Higher Education found that the stolen laptop contained data from projects with a number of customers.<br><br>Security teams from affected institutions and SunGard Higher Education are working together to analyze and verify the data and notify affected individuals.<br><br>The laptop was protected with a strong password to access the operating system.<br><span style="font-style: italic;">[Evan] It could be the strongest damn password in the world and still not provide an adequate level of security in my opinion.&nbsp; Operating system passwords (especially Windows) can be bypassed in a matter of seconds.&nbsp; This is a poor attempt to minimize the incident.</span><br><br>The computer was password-protected but contained unencrypted files with personally identifiable data<br><span style="font-style: italic;">[Evan] Even though encryption is not the "end all", it would have (in conjunction with other controls) reduced the risk of exposure to a level that is acceptable to many organizations (mine included).</span><br><br>All affected customers have been notified. Customer names will not be disclosed for privacy and security reasons as the investigation continues.<br><span style="font-style: italic;">[Evan] We already know of at least 10 post-secondary institutions.</span><br><br>The laptop was stolen in New York on March 13 and state officials say it contains the names and personal information of 3,502 present and former students of the four CSU universities. <br><br>could put the personal information of 1,600 Northern Michigan College students from 2003 at risk.<br><br>could potentially put personal information about Northwest Missouri State University students and alumni in the wrong hands.<br><br>Northwest believes it followed all appropriate internal procedures for protecting the privacy of its students. For its part, SunGard Higher Education has accepted responsibility for this incident and is working with the University to minimize any adverse consequences.<br><span style="font-style: italic;">[Evan] This is a classic misunderstanding of the roles and responsibilities for information security governance and management.&nbsp; The custodians of the personal information were the schools AND SunGard, not only SunGard.&nbsp; It is the responsibility of the schools (as co-custodians) to require certain information protections from their vendors and contractors.&nbsp; This should be done through policy, contractual language and regular audit/enforcement.</span><br><br>Social Security numbers of about 16,000 current and former Buffalo State College students<br><br>affected thousands of students at State University College at Buffalo, State University College at Brockport and Monroe Community College.<br><br>We believe that the laptop was stolen for the hardware rather than the data. We do not know if any personally identifiable data was accessed by the thieves.<br><span style="font-style: italic;">[Evan] This is another statement meant to minimize the impact of the incident.&nbsp; I do not doubt that often times computer equipment is stolen for the hardware value, but how do we know?&nbsp; I am guessing that more and more criminals are examining the contents of poorly secured computing devices and looking for additional opportunities.&nbsp; The "laptop was stolen for the hardware" argument doesn't work anymore.</span><br><br>The nature of that employee’s job included analysis of customer data as part of software implementation and upgrade projects.<br><br>The laptop was taken from an employee of SunGard, a Pennsylvania-based computer software company that provides Buffalo State’s records system, said Voldemar Innus, a college vice president and chief information officer.<br><br>Innus also said the laptop was secure.<br><span style="font-style: italic;">[Evan] No offense Mr. Innus, but the laptop <span style="font-weight: bold;">WAS NOT</span> secure.</span><br><br>"The laptop was stolen for its own worth as hardware," Innus said. "We do not believe it was stolen because of the information that was on it. And it was heavily password protected, we’re told."<br><br>"The risk I would say is not that high, but that doesn’t matter," Innus said. "There are steps we need to take because of what happened."<br><span style="font-style: italic;">[Evan] People like to throw these terms like "secure" and "risk" around without any validation.&nbsp; How did Mr. Innus determine the risk (of exposure and/or misuse) with respect to this incident?</span><br><br>The data was originally provided for SunGard to perform various services for the university system, but it was apparently retained longer than necessary to perform those services,<br><br>A dedicated Web site containing updated information may be accessed at <a href="http://www.sungardhe.com/laptoptheft.%3Cbr%3E%3Cbr%3EA">www.sungardhe.com/laptoptheft.<br><br></a>A help desk has been established with a toll-free number, (866) 520-2408, to respond to questions from affected individuals.<br><br>Credit monitoring will be provided at no cost to the affected individuals, for a period of one year.<br><span style="font-style: italic;">[Evan] Credit monitoring is a post-fraud activity.&nbsp; One year is very limited for information that has a much longer lifespan.</span><br><br>Buffalo State student reaction:<br>In a campus dormitory, Ben Bissell, a sophomore special education major, and his friend Thomas Dennis, a freshman English education major, were making housing arrangements for next year. Bissell said he got the e-mail and was aware of the situation. Dennis was not. <br><br>Bissell was surprised such sensitive information could be placed in such a portable device as a laptop, which could easily be lost or stolen. <br><span style="font-style: italic;">[Evan] Mr. Bissell is a "data owner" in this instance.&nbsp; The school and SunGard are "data custodians".&nbsp; In simplistic terms, data owners dictate what level of protection is required for the data that they own and data custodians apply the designated level of protection.&nbsp; Did the school and SunGard apply the designated level of protection in this case?</span><br><br>"You’d think it would be somewhat secure," Bissell said of his personal information. <br><br>He plans to closely monitor his bank statements and account activity following the announcement.<br>&nbsp;<br>Omar Vargas, a sophomore elementary education major, told a reporter it was the first he had heard of the stolen laptop, admitting he feels "less secure" knowing about it.<br>&nbsp;<br>"There’s enough things to handle being on campus, like going to classes and deadlines," Vargas said. "Then, just to find out my personal information is threatened is like, man, who knows what that could jeopardize."<br><span style="font-style: italic;">[Evan] Very true.&nbsp; If we all just did what we were supposed to do, we wouldn't have to worry so much about what others aren't doing.</span><br><br>"I could wind up with bad credit when I’m on a good roll."<br><br><span style="font-weight: bold;">Commentary:</span><br>I provided a lot of my commentary above.&nbsp; There is no excuse that I can think of for such poor information security practice and management.&nbsp; Can the people running these companies (such as SunGard) and those responsible for information security claim they didn't know any better?&nbsp; Does it not go against SunGard Higher Education (or school) policy to store confidential information on a laptop while relying solely on operating system level passwords?<br><br>Nuts. <br><br><span style="font-weight: bold;">Past Breaches:</span><br>Unknown</font><br><br>
<script src="http://feeds.feedburner.com/%7Es/breachblog?i=http://breachblog.com/2008/04/21/sungard.aspx" type="text/javascript" charset="utf-8"></script>]]></content:encoded>
      <pubDate>Mon, 21 Apr 2008 10:49:39 +0000</pubDate>
      <category domain="http://securityratty.com/tag/information">information</category>
      <category domain="http://securityratty.com/tag/personal information">personal information</category>
      <category domain="http://securityratty.com/tag/store confidential information">store confidential information</category>
      <category domain="http://securityratty.com/tag/university">university</category>
      <category domain="http://securityratty.com/tag/university system">university system</category>
      <category domain="http://securityratty.com/tag/data custodians apply">data custodians apply</category>
      <category domain="http://securityratty.com/tag/data custodians">data custodians</category>
      <category domain="http://securityratty.com/tag/information security governance">information security governance</category>
      <category domain="http://securityratty.com/tag/sungard">sungard</category>
      <source url="http://breachblog.com/2008/04/21/sungard.aspx">Stolen SunGard laptop affects at least 10 post-secondary schools</source>
    </item>
    <item>
      <title><![CDATA[College Degrees in Homeland Security]]></title>
      <link>http://securityratty.com/article/617e8cc678d5cbe87422a69645a70a64</link>
      <guid>http://securityratty.com/article/617e8cc678d5cbe87422a69645a70a64</guid>
      <description><![CDATA[It's a growing field : More than 200 colleges have created homeland-security degree and certificate programs since 9/11, and another 144 have added emergency management with a terrorism...]]></description>
      <content:encoded><![CDATA[<p>It's a <a href="http://www.slate.com/?id=2187648">growing field</a>:</p>

<blockquote>More than 200 colleges have created homeland-security degree and certificate programs since 9/11, and another 144 have added emergency management with a terrorism bent.</blockquote><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/schneier/fulltext?a=jq9LVUG"><img src="http://feeds.feedburner.com/~f/schneier/fulltext?i=jq9LVUG" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/schneier/fulltext?a=XINQy0G"><img src="http://feeds.feedburner.com/~f/schneier/fulltext?i=XINQy0G" border="0"></img></a>
</div>]]></content:encoded>
      <pubDate>Wed, 09 Apr 2008 02:40:45 +0000</pubDate>
      <category domain="http://securityratty.com/tag/emergency management">emergency management</category>
      <category domain="http://securityratty.com/tag/degree">degree</category>
      <category domain="http://securityratty.com/tag/colleges">colleges</category>
      <category domain="http://securityratty.com/tag/programs">programs</category>
      <category domain="http://securityratty.com/tag/terrorism">terrorism</category>
      <category domain="http://securityratty.com/tag/field">field</category>
      <source url="http://www.schneier.com/blog/archives/2008/04/college_degrees.html">College Degrees in Homeland Security</source>
    </item>
    <item>
      <title><![CDATA[Getting students, faculty to sign up for campus alerts]]></title>
      <link>http://securityratty.com/article/89f0eacbe3a7fa513cd7bb22833d5937</link>
      <guid>http://securityratty.com/article/89f0eacbe3a7fa513cd7bb22833d5937</guid>
      <description><![CDATA[Although many colleges and universities have been installing or updating their emergency notification systems for students, faculty and staff since last April's shootings at Virginia Tech, technology...]]></description>
      <content:encoded><![CDATA[Although many colleges and universities have been installing or updating their emergency notification systems for students, faculty and staff since last April's shootings at Virginia Tech, technology can't fix one problem: not everyone who's eligible for the emergency alerts wants them.]]></content:encoded>
      <pubDate>Wed, 20 Feb 2008 21:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/emergency notification systems">emergency notification systems</category>
      <category domain="http://securityratty.com/tag/faculty">faculty</category>
      <category domain="http://securityratty.com/tag/emergency alerts">emergency alerts</category>
      <category domain="http://securityratty.com/tag/students">students</category>
      <category domain="http://securityratty.com/tag/virginia tech">virginia tech</category>
      <category domain="http://securityratty.com/tag/fix">fix</category>
      <category domain="http://securityratty.com/tag/shootings">shootings</category>
      <category domain="http://securityratty.com/tag/staff">staff</category>
      <category domain="http://securityratty.com/tag/eligible">eligible</category>
      <source url="http://www.networkworld.com/news/2008/022108-getting-students-faculty-to-sign.html?fsrc=rss-security">Getting students, faculty to sign up for campus alerts</source>
    </item>
  </channel>
</rss>
