Detailed Program InformationRegistration Desk OpenSession DetailsTuesday, May 06, 2008 7:30 a.m. - 12:00 p.m. Regency Ballroom Foyer
Breakfast Sponsored by Blackboard ConnectSession DetailsTuesday, May 06, 2008 7:30 a.m. - 8:30 a.m. Regency ABCD Ballroom
E-Mail Room Open Sponsored by MPC/Gateway, An EDUCAUSE Gold PartnerSession DetailsTuesday, May 06, 2008 7:30 a.m. - 11:00 a.m. Lincoln (Third Floor)
Collecting and Preserving Data in the Wake of a TragedySession DetailsTuesday, May 06, 2008 8:30 a.m. - 9:30 a.m. Potomac 1/2 (Ballroom Level)
Session Type: Track 1
Speaker(s)- William Dougherty, Assistant Director, Systems Support, Network Infrastructure and Services, Virginia Tech
- Session convener: Ken Connelly, Associate Director, Security and Systems, University of Northern Iowa
AbstractAfter the tragic events of April 16, 2007, at Virginia Tech, IT professionals and university legal counsel had to quickly address the need to collect and preserve data in the event of future litigation. Performing tasks while dealing with grief and protecting academic freedom and privacy issues has required a delicate approach. Available ResourcesMore InformationFor more information, see: http://connect.educause.edu/Library/Abstract/CollectingandPreservingDa/46753 The Data Center Within a Data Center: Building a Secure Environment for ComplianceSession DetailsTuesday, May 06, 2008 8:30 a.m. - 9:30 a.m. Potomac 3 (Ballroom Level)
Session Type: Track 2
Speaker(s)- David Seidl, Information Security Program Manager, University of Notre Dame
- Session convener: H. Morrow Long, University Information Security Officer, Yale University
AbstractPCI compliance can be daunting, particularly in a university network environment. Notre Dame chose a data center within a data center approach to simplify compliance and minimize integration issues. This project includes implementing the data center, a virtual network to support point-of-sale devices, and related operational procedures. Available ResourcesMore InformationFor more information, see: http://connect.educause.edu/Library/Abstract/TheDataCenterWithinaDataC/47038 Using Nontraditional Security Risk Assessments to Measure Risk, Request Budgets, and Illustrate TrendsSession DetailsTuesday, May 06, 2008 8:30 a.m. - 9:30 a.m. Potomac 4 (Ballroom Level)
Session Type: Track 3
Speaker(s)- Benjamin Nathan, Associate Director, Security & Identity Management Services, Weill Cornell Medical College
- Session convener: Thomas Siu, Chief Information Security Officer, Case Western Reserve University
AbstractLearn how Weill Cornell Medical College employs a nontraditional risk management methodology to accurately measure risk, build compelling and successful budget requests, and graphically illustrate trends understandable to technical and nontechnical stakeholders. Attendees will receive Excel tools they can use to manage their own risk assessments in this way. Available ResourcesMore InformationFor more information, see: http://connect.educause.edu/Library/Abstract/UsingNontraditionalSecuri/46754 The Shifting LandscapeSession DetailsTuesday, May 06, 2008 8:30 a.m. - 9:30 a.m. Potomac 5 (Ballroom Level)
Session Type: Track 4
Speaker(s)AbstractOperating system and application vendors are finally starting to ship products secure by default. Not to be outdone, the attacker community has changed both motivation and operation: Careless vandals are being replaced by organized cybercriminals with advanced attack techniques. See how this shifting landscape affects traditional security strategies. Available ResourcesMore InformationFor more information, see: http://connect.educause.edu/Library/Abstract/TheShiftingLandscape/46804 Securing and Leveraging the Power of Virtual Servers and DesktopsSession DetailsTuesday, May 06, 2008 8:30 a.m. - 9:30 a.m. Potomac 6 (Ballroom Level)
Session Type: Track 5
Speaker(s)AbstractVirtualized server environments provide many benefits from cost and space savings to ease of deployment and administration. We will demonstrate how we secure our virtual environment at Sacred Heart University and how we leverage that environment to provide better secured and isolated server applications and user workspace. Available ResourcesMore InformationFor more information, see: http://connect.educause.edu/Library/Abstract/SecuringandLeveragingtheP/46755 McAfee and Georgia State University - Taking Aim at Network Intruders with Intrushield's Intrusion Prevention System Session DetailsTuesday, May 06, 2008 8:30 a.m. - 9:30 a.m. Arlington room (Third Floor)
Session Type: Track 6
Speaker(s)- Tammy L. Clark, Chief Information Security Officer, Georgia State University
- William Charles Monahan, Lead Information Security Administrator
- John Vecchi, Director, Product Marketing, Network Security Solutions, McAfee, Inc.
- Session convener: Cheryl Lyn Granto, IT Security Officer, Florida International University
AbstractMcAfee and Georgia State University have enjoyed a successful association since 2005 in optimizing the university's use of the Intrushield intrusion prevention system. Join us for a discussion of key advantages we've discovered: how to do more with less, achieve flexibility through distributed/centralized management, and provide comprehensive protection against threats and exploits. Available ResourcesMore InformationFor more information, see: http://connect.educause.edu/Library/Abstract/McAfeeandGeorgiaStateUniv/46734 Refreshment Break Sponsored by PGP CorporationSession DetailsTuesday, May 06, 2008 9:30 a.m. - 9:45 a.m. Regency Ballroom Foyer
An ARP Spoofing and Router Impersonation IncidentSession DetailsTuesday, May 06, 2008 9:45 a.m. - 10:45 a.m. Potomac 1/2 (Ballroom Level)
Session Type: Track 1
Speaker(s)AbstractFollow along as we track down the source of JavaScript injection into web pages through the use of ARP flooding and router impersonation on the IU network. How did it happen, what tools did we use to track it down, and what can we do about this type of attack? Available ResourcesMore InformationFor more information, see: http://connect.educause.edu/Library/Abstract/AnARPSpoofingandRouterImp/46756 Security Uncertainty: What Matters, Motivates, and Moves!Session DetailsTuesday, May 06, 2008 9:45 a.m. - 10:45 a.m. Potomac 3 (Ballroom Level)
Session Type: Track 2
Speaker(s)- James Lowe, Chief Information Security Officer, University of Wisconsin-Madison
- Stefan Wahe, IT Security Officer, University of Wisconsin-Madison
- Session convener: Cherry Delaney, Network Services Outreach & Training, Purdue University
AbstractGood security requires good communications and understanding. It is key to agree on effective and efficient processes and technologies that implement security controls. How do we get senior administrators, security professionals, and technologists all speaking the same language so smart decisions can be made? Available ResourcesMore InformationFor more information, see: http://connect.educause.edu/Library/Abstract/SecurityUncertaintyWhatMa/46757 Identity Finder LLC and Carnegie Mellon University - Find and Protect Personal Information Before It's Too LateSession DetailsTuesday, May 06, 2008 9:45 a.m. - 10:45 a.m. Potomac 4 (Ballroom Level)
Session Type: Track 3
Speaker(s)- Mary Ann Blair, Director of Information Security, Carnegie Mellon University
- Todd Feinman, Chief Executive Officer, Identity Finder LLC
- Session convener: Kathy Bergsma, Information Security Manager, University of Florida
AbstractIt's estimated that the black market trafficking of stolen electronic identities will increase to $1.6 billion in 2010. Finding personal information is an increasingly complex problem due the myriad places it can reside and forms it can take on computers. Learn not only how to find it but also how to easily and quickly protect it. Available ResourcesMore InformationFor more information, see: http://connect.educause.edu/Library/Abstract/IdentityFinderLLCandCarne/46735 Bridging Security and Identity Management: Can't We Just Get Along?Session DetailsTuesday, May 06, 2008 9:45 a.m. - 10:45 a.m. Potomac 5 (Ballroom Level)
Session Type: Track 4
Speaker(s)- Christopher Misra, Information Security Officer, University of Massachusetts Amherst
- John J. Suess, Vice President of Information Technology/CIO, University of Maryland, Baltimore County
- Session convener: Joanna Lyn Grama, Information Security Policy and Compliance Director, Purdue University
AbstractSecurity staff want to keep the bad guys out, and identity management (IdM) staff want to let the good guys in. This session will explore this generalization and how to bridge issues in technology, policy, process, and reporting structures relating to security and IdM to achieve shared institutional goals. Available ResourcesMore InformationFor more information, see: http://connect.educause.edu/Library/Abstract/BridgingSecurityandIdenti/46791 Effective Windows Desktop Security: XP and VistaSession DetailsTuesday, May 06, 2008 9:45 a.m. - 10:45 a.m. Potomac 6 (Ballroom Level)
Session Type: Track 5
Speaker(s)- John Bruggeman, Director of Information Systems, Hebrew Union College-Jewish Institute of Religion
- Session convener: William E. Terry, Assoc. Dean of Information Services & CTO, Bard College
AbstractWindows desktops are widely deployed and can be subject to multiple attack vectors. Windows XP and Vista have vulnerabilities that need to be mitigated effectively by security teams or by end users. This session will cover the top security vulnerabilities in Windows desktops and how to secure them quickly and effectively, along with the tools to use. Available ResourcesMore InformationFor more information, see: http://connect.educause.edu/Library/Abstract/EffectiveWindowsDesktopSe/46758http://connect.educause.edu/Library/Abstract/EffectiveWindowsDesktopSe/46758 FireEye, Inc. and University of California, Berkeley - Combating Stealth Malware and Botnets in Higher EducationSession DetailsTuesday, May 06, 2008 9:45 a.m. - 10:45 a.m. Arlington room (Third Floor)
Session Type: Track 6
Speaker(s)AbstractUC Berkeley's Electrical Engineering and Computer Sciences department wanted to strengthen security for mobile users on the wireless network. This talk will cover practical knowledge required to address network security incidents in a forensically sound manner. The university selected FireEye's antimalware solution to protect against targeted stealth malware. Available ResourcesMore InformationFor more information, see: http://connect.educause.edu/Library/Abstract/CombatingStealthMalwarean/46786 Refreshment Break Sponsored by PGP CorporationSession DetailsTuesday, May 06, 2008 10:45 a.m. - 11:00 a.m. Regency Ballroom Foyer
Addressing Complex Security Threats Through Risk Management Session DetailsTuesday, May 06, 2008 11:00 a.m. - 12:00 p.m. Regency ABCD Ballroom
Session Type: General Session
Speaker(s)- Rebecca Whitener, Former Vice President Enterprise Risk Management and Chief Risk Officer, EDS
AbstractIn this session, we will address the current cybersecurity issues that are challenging higher education leaders today as they try to stay on top of the risks associated with attacks on information systems from internal and external sources. Emerging enterprise risk management (ERM) methodologies will be examined as a source of guidance for creating an effective risk-based approach for managing current and future threats. Available ResourcesMore InformationFor more information, see: http://connect.educause.edu/Library/Abstract/AddressingComplexSecurity/46776 Lunch for Postconference Seminar ParticipantsSession DetailsTuesday, May 06, 2008 12:00 p.m. - 1:00 p.m. Boxed lunch (available inside meeting room)
Security Task Force Team Leadership Meeting (by invitation only)Session DetailsTuesday, May 06, 2008 12:00 p.m. - 5:00 p.m. Jefferson Room (Third Floor)
REN-ISAC Members Meeting Invitation Only PLEASE NOTE: Separate registration and fee are required to attend this meeting.Session DetailsTuesday, May 06, 2008 12:00 p.m. - 5:30 p.m. Potomac 3/4 and 5/6 (Ballroom Level)
Session Type: Postconference Seminar
AbstractThe REN-ISAC is an integral part of higher education's strategy to improve network security. This meeting will gather members of the REN-ISAC for a face-to-face meeting. This meeting is open only to REN-ISAC members by invitation. Registration will be limited to 100 people and one attendee per institution. Lunch provided. If you are ONLY attending the REN ISAC meeting, please call Member Services at (303) 449-4430 to register by phone. Seminar P1 - Developing an Effective Electronic Records Management Process PLEASE NOTE: Separate registration and fee are required to attend this seminar.Session DetailsTuesday, May 06, 2008 1:00 p.m. - 4:30 p.m. Roosevelt (Third Floor)
Session Type: Postconference Seminar
Speaker(s)- Michael Sermersheim, Associate Vice President and Deputy General Counsel Emeritus, University of Akron
AbstractOnce considered predominantly an archival function, records management is now relevant at all levels. With the advent of electronic discovery rules, legal compliance requirements, and best-practices considerations, electronically stored information is of great concern to IT professionals, campus executive leadership, and legal counsel. Hear considerations for your creation, or review, of campus records retention policies, records destruction requirements, e-discovery protocols, considerations about forensic information preservation and assessment, document authentication and chain-of-custody guidelines, and sample policies and resources from others.
|