24
IT Security Essentials Ian Lazerwitz, Information Security Officer

IT Security Essentials Ian Lazerwitz, Information Security Officer

  • View
    222

  • Download
    3

Embed Size (px)

Citation preview

Page 1: IT Security Essentials Ian Lazerwitz, Information Security Officer

IT Security EssentialsIan Lazerwitz, Information Security Officer

Page 2: IT Security Essentials Ian Lazerwitz, Information Security Officer

Fundamentals of Security

• Confidentiality

• Integrity

• Availability

Confidentiality

Integrity Availability

Page 3: IT Security Essentials Ian Lazerwitz, Information Security Officer

Why all the concern about security?

• Computer hacking has become a big business

• We store large amounts of personal data in our systems on students and employees

• We need that data to be accurate and available in order to do our jobs

• We must comply with state and federal regulations

Page 4: IT Security Essentials Ian Lazerwitz, Information Security Officer

What are we doing about it?

• Constantly monitoring our systems and threats to keep our servers and our network secure

• Implementing policies, procedures and practices to assure only authorized users have access to data

• Educating users

Page 5: IT Security Essentials Ian Lazerwitz, Information Security Officer

What can you do?

• Security is everyone’s responsibility

• Contact the IT Security Office with any questions or if you suspect there has been a security breach

• Follow some basic guidelines:

Page 6: IT Security Essentials Ian Lazerwitz, Information Security Officer

Be aware

• Make information security a regular practice

• Recognize poor security practices in your own habits and in your office

• Remain vigilant where information security is concerned

Page 7: IT Security Essentials Ian Lazerwitz, Information Security Officer

Passwords

• Never share a password– If more than one person needs access work with

DoIT to create a network share so each can use their own password

– Even the DoIT Helpdesk should never ask for your password

Page 8: IT Security Essentials Ian Lazerwitz, Information Security Officer

Passwords• Choose a strong password

– We recommend that you change your password regularly

– Use a phase that’s easy to remember but hard to guess– Your password must contain 3 of 4

• Uppercase letters

• Lowercase letters

• Numbers

• Special Characters

Page 9: IT Security Essentials Ian Lazerwitz, Information Security Officer

Password Examples

• Weak Passwords– Fluffy– Password3– Lazerwitz

• Strong Passwords– str0ngPa55– 3plus3=Six– myc@tisf!uffy

Page 10: IT Security Essentials Ian Lazerwitz, Information Security Officer

Passwords

• Never post your password– On your computer monitor– Under your keyboard– In a desk drawer– Anyplace that someone might look

Page 11: IT Security Essentials Ian Lazerwitz, Information Security Officer

Passwords

• Never save passwords in applications– E-mail, Web Authoring, Dialup, VPN– Anyone who site at your computer has access

to those applications

– Equally important at home

Page 12: IT Security Essentials Ian Lazerwitz, Information Security Officer

Personally Identifiable Information

(PII) is information that can be used to steal identities, disrupt University operations and damage Pace’s reputation includes: – Social Security Numbers (SSNs)

– Health Information – including immunization information, FMLA information and

– Credit Card information

– Non public directory information – including student grades

Page 13: IT Security Essentials Ian Lazerwitz, Information Security Officer

PII Date Handling Best Practices

• Assign a complex password and change it regularly;

• Don’t use Internet files sharing software such as Kazaa or BitTorrent.;

• It is important to treat other people’s information as if it was your own!!!!

Page 14: IT Security Essentials Ian Lazerwitz, Information Security Officer

PII Date Handling Best Practices

• Delete files from ALL locations (hard drive and network drive) when no longer valid.

• Do not hold on to old queries or reports that contain personal information. Empty your computer’s recycle bin and clear temporary file folders

Page 15: IT Security Essentials Ian Lazerwitz, Information Security Officer

PII Date Handling Best Practices

• Never share passwords;

• Avoid emailing sensitive files. If email is absolutely necessary, use password protection;

• Use a password protected screen saver;

• Shut down or turn off the computer when not in use;

Page 16: IT Security Essentials Ian Lazerwitz, Information Security Officer

PII Printing Best Practices

• Printed reports with PII data must contain the creator’s name, date and time, data source and a confidential notice.

• Limit display of personal information. Do not leave paper containing personal information on desks or in open view; avoid printing SSN unless required by law.

Page 17: IT Security Essentials Ian Lazerwitz, Information Security Officer

PII Printing Best Practices

• Always store paper reports containing PII in a secure location such as a locked filing cabinet and know who has access to the location. Avoid taking PII reports with you to unsecured locations such as your home or car.

Page 18: IT Security Essentials Ian Lazerwitz, Information Security Officer

PIIPrinting Best Practices

• Limit distribution of documents with PII and know who is receiving the documents and how it will be used.

Page 19: IT Security Essentials Ian Lazerwitz, Information Security Officer

Physical Security

• Always lock your computer when you leave it unattended (ctrl-alt-del)

• Never leave hard copies with sensitive date in plain view

• Always log out of web applications (Banner, e-mail, calendar) and close the browser

Page 20: IT Security Essentials Ian Lazerwitz, Information Security Officer

Laptops and Mobile Devices

• Theft

• Access on unsecure networks

• Strong passwords

• Encryption

Page 21: IT Security Essentials Ian Lazerwitz, Information Security Officer

Did you know? (Antivirus)

• Pace University has a site license to install Symantec Antivirus on all Pace computer

• We also provide Antivirus software for staff, faculty, and student home use

Page 22: IT Security Essentials Ian Lazerwitz, Information Security Officer

Did you know?

• It is a violation of University policy to share your password

• You should keep your computer operating system and applications patched to protect against unwanted intrusions

Page 23: IT Security Essentials Ian Lazerwitz, Information Security Officer

Did you know?

• You should make backups of critical files

• At home use a personal firewall

• Do not open unexpected emails

Page 24: IT Security Essentials Ian Lazerwitz, Information Security Officer

Information Security Office

• Ian Lazerwitz– Information Security Officer

[email protected]

[email protected]

• Http://www.pace.edu/safecomputing