Proposal for Version 2: Network Citizenship Policy - PowerPoint PPT Presentation

1 / 9
About This Presentation
Title:

Proposal for Version 2: Network Citizenship Policy

Description:

Jane Drews, IT Security Office (chair) Nancy Grout, CIO Office. Maggie Jesse, College of Business. Barb Kelley, College of Pharmacy ... – PowerPoint PPT presentation

Number of Views:38
Avg rating:3.0/5.0
Slides: 10
Provided by: janed5
Category:

less

Transcript and Presenter's Notes

Title: Proposal for Version 2: Network Citizenship Policy


1
Proposal for Version 2 Network Citizenship Policy
  • Jane Drews
  • 8/27/2004

2
Agenda
  • Background
  • Why is the policy change needed?
  • What does it involve?
  • Who is affected?
  • Questions

3
Background
  • Original Version Network Citizenship Policy
  • Adopted April 2002
  • Protect integrity of campus network and mitigate
    risk/loss associated with threats to networked
    devices
  • Establish responsibility
  • Promote use of Security Best Practices
  • Provide recourse for systems posing a threat

4
Why change the policy?
  • Feedback from CITL Reliable Computing Discussions
  • Clarify responsibility
  • Include basic security requirements
  • Strengthen the language

5
Change Detail
  • Scope Section
  • Policy covers any device connected to the UI
    network, with no exceptions
  • Initial responsibility is whoever connects device
  • Thereafter, responsibility is
  • Primary User
  • IT Support
  • Department in physical space
  • Technical staff are responsible for Multi-User
    Shared Resources

6
Change Detail
  • Policy Section
  • Require Baseline Security Standards which must be
    met, and include them as appendix
  • Updates, Anti-Virus, Administrator Passwords,
    Support, Backups, and Best Practices
  • Strengthen language to require resolution of high
    risk security issues detected through scans
  • Strengthen language for reporting incidents to
    require immediate reporting to ITSO or local IT
    Support staff

7
Change Detail
  • Procedures Section
  • Strengthen name to Enforcement from
    Procedures
  • Change ambiguous requirement for having Security
    Best Practices implemented before reconnecting a
    problem machine to the network, to a requirement
    for the specific Baseline Security Standards

8
Who is Affected?
  • Stakeholder population will not change
  • Current NCP covers all faculty, staff, and
    students as well as all devices
  • Changes will affect all Stakeholders
  • Requirement to implement Baseline Security
    Standards instead of Security Best Practices

9
Summary
  • Questions?
  • Who (what groups) need to review this proposal?
  • Time frame Thanksgiving
Write a Comment
User Comments (0)
About PowerShow.com