Logout Manage Profile Contact EDUCAUSE Home Page Login Contact EDUCAUSE Home Page
Arlington, Virginia, May 4–6

Detailed Program Information

Registration Desk Open

Session Details

Tuesday, May 06, 2008
7:30 a.m. - 12:00 p.m.
Regency Ballroom Foyer

Breakfast
Sponsored by Blackboard Connect

Session Details

Tuesday, May 06, 2008
7:30 a.m. - 8:30 a.m.
Regency ABCD Ballroom

E-Mail Room Open
Sponsored by MPC/Gateway, An EDUCAUSE Gold Partner

Session Details

Tuesday, May 06, 2008
7:30 a.m. - 11:00 a.m.
Lincoln (Third Floor)

Collecting and Preserving Data in the Wake of a Tragedy

Session Details

Tuesday, May 06, 2008
8:30 a.m. - 9:30 a.m.
Potomac 1/2 (Ballroom Level)

Session Type: Track 1

Speaker(s)

  • William Dougherty, Assistant Director, Systems Support, Network Infrastructure and Services, Virginia Tech
  • Session convener: Ken Connelly, Associate Director, Security and Systems, University of Northern Iowa

Abstract

After the tragic events of April 16, 2007, at Virginia Tech, IT professionals and university legal counsel had to quickly address the need to collect and preserve data in the event of future litigation. Performing tasks while dealing with grief and protecting academic freedom and privacy issues has required a delicate approach.

Available Resources

More Information

For more information, see:

http://connect.educause.edu/Library/Abstract/CollectingandPreservingDa/46753

The Data Center Within a Data Center: Building a Secure Environment for Compliance

Session Details

Tuesday, May 06, 2008
8:30 a.m. - 9:30 a.m.
Potomac 3 (Ballroom Level)

Session Type: Track 2

Speaker(s)

  • David Seidl, Information Security Program Manager, University of Notre Dame
  • Session convener: H. Morrow Long, University Information Security Officer, Yale University

Abstract

PCI compliance can be daunting, particularly in a university network environment. Notre Dame chose a data center within a data center approach to simplify compliance and minimize integration issues. This project includes implementing the data center, a virtual network to support point-of-sale devices, and related operational procedures.

Available Resources

More Information

For more information, see:

http://connect.educause.edu/Library/Abstract/TheDataCenterWithinaDataC/47038

Using Nontraditional Security Risk Assessments to Measure Risk, Request Budgets, and Illustrate Trends

Session Details

Tuesday, May 06, 2008
8:30 a.m. - 9:30 a.m.
Potomac 4 (Ballroom Level)

Session Type: Track 3

Speaker(s)

  • Benjamin Nathan, Associate Director, Security & Identity Management Services, Weill Cornell Medical College
  • Session convener: Thomas Siu, Chief Information Security Officer, Case Western Reserve University

Abstract

Learn how Weill Cornell Medical College employs a nontraditional risk management methodology to accurately measure risk, build compelling and successful budget requests, and graphically illustrate trends understandable to technical and nontechnical stakeholders. Attendees will receive Excel tools they can use to manage their own risk assessments in this way.

Available Resources

More Information

For more information, see:

http://connect.educause.edu/Library/Abstract/UsingNontraditionalSecuri/46754

The Shifting Landscape

Session Details

Tuesday, May 06, 2008
8:30 a.m. - 9:30 a.m.
Potomac 5 (Ballroom Level)

Session Type: Track 4

Speaker(s)

Abstract

Operating system and application vendors are finally starting to ship products secure by default. Not to be outdone, the attacker community has changed both motivation and operation: Careless vandals are being replaced by organized cybercriminals with advanced attack techniques. See how this shifting landscape affects traditional security strategies.

Available Resources

More Information

For more information, see:

http://connect.educause.edu/Library/Abstract/TheShiftingLandscape/46804

Securing and Leveraging the Power of Virtual Servers and Desktops

Session Details

Tuesday, May 06, 2008
8:30 a.m. - 9:30 a.m.
Potomac 6 (Ballroom Level)

Session Type: Track 5

Speaker(s)

Abstract

Virtualized server environments provide many benefits from cost and space savings to ease of deployment and administration. We will demonstrate how we secure our virtual environment at Sacred Heart University and how we leverage that environment to provide better secured and isolated server applications and user workspace.

Available Resources

More Information

For more information, see:

http://connect.educause.edu/Library/Abstract/SecuringandLeveragingtheP/46755

McAfee and Georgia State University - Taking Aim at Network Intruders with Intrushield's Intrusion Prevention System

Session Details

Tuesday, May 06, 2008
8:30 a.m. - 9:30 a.m.
Arlington room (Third Floor)

Session Type: Track 6

Speaker(s)

Abstract

McAfee and Georgia State University have enjoyed a successful association since 2005 in optimizing the university's use of the Intrushield intrusion prevention system. Join us for a discussion of key advantages we've discovered: how to do more with less, achieve flexibility through distributed/centralized management, and provide comprehensive protection against threats and exploits.

Available Resources

More Information

For more information, see:

http://connect.educause.edu/Library/Abstract/McAfeeandGeorgiaStateUniv/46734

Refreshment Break
Sponsored by PGP Corporation

Session Details

Tuesday, May 06, 2008
9:30 a.m. - 9:45 a.m.
Regency Ballroom Foyer

An ARP Spoofing and Router Impersonation Incident

Session Details

Tuesday, May 06, 2008
9:45 a.m. - 10:45 a.m.
Potomac 1/2 (Ballroom Level)

Session Type: Track 1

Speaker(s)

Abstract

Follow along as we track down the source of JavaScript injection into web pages through the use of ARP flooding and router impersonation on the IU network. How did it happen, what tools did we use to track it down, and what can we do about this type of attack?

Available Resources

More Information

For more information, see:

http://connect.educause.edu/Library/Abstract/AnARPSpoofingandRouterImp/46756

Security Uncertainty: What Matters, Motivates, and Moves!

Session Details

Tuesday, May 06, 2008
9:45 a.m. - 10:45 a.m.
Potomac 3 (Ballroom Level)

Session Type: Track 2

Speaker(s)

  • James Lowe, Chief Information Security Officer, University of Wisconsin-Madison
  • Stefan Wahe, IT Security Officer, University of Wisconsin-Madison
  • Session convener: Cherry Delaney, Network Services Outreach & Training, Purdue University

Abstract

Good security requires good communications and understanding. It is key to agree on effective and efficient processes and technologies that implement security controls. How do we get senior administrators, security professionals, and technologists all speaking the same language so smart decisions can be made?

Available Resources

More Information

For more information, see:

http://connect.educause.edu/Library/Abstract/SecurityUncertaintyWhatMa/46757

Identity Finder LLC and Carnegie Mellon University - Find and Protect Personal Information Before It's Too Late

Session Details

Tuesday, May 06, 2008
9:45 a.m. - 10:45 a.m.
Potomac 4 (Ballroom Level)

Session Type: Track 3

Speaker(s)

  • Mary Ann Blair, Director of Information Security, Carnegie Mellon University
  • Todd Feinman, Chief Executive Officer, Identity Finder LLC
  • Session convener: Kathy Bergsma, Information Security Manager, University of Florida

Abstract

It's estimated that the black market trafficking of stolen electronic identities will increase to $1.6 billion in 2010. Finding personal information is an increasingly complex problem due the myriad places it can reside and forms it can take on computers. Learn not only how to find it but also how to easily and quickly protect it.

Available Resources

More Information

For more information, see:

http://connect.educause.edu/Library/Abstract/IdentityFinderLLCandCarne/46735

Bridging Security and Identity Management: Can't We Just Get Along?

Session Details

Tuesday, May 06, 2008
9:45 a.m. - 10:45 a.m.
Potomac 5 (Ballroom Level)

Session Type: Track 4

Speaker(s)

  • Christopher Misra, Information Security Officer, University of Massachusetts Amherst
  • John J. Suess, Vice President of Information Technology/CIO, University of Maryland, Baltimore County
  • Session convener: Joanna Lyn Grama, Information Security Policy and Compliance Director, Purdue University

Abstract

Security staff want to keep the bad guys out, and identity management (IdM) staff want to let the good guys in. This session will explore this generalization and how to bridge issues in technology, policy, process, and reporting structures relating to security and IdM to achieve shared institutional goals.

Available Resources

More Information

For more information, see:

http://connect.educause.edu/Library/Abstract/BridgingSecurityandIdenti/46791

Effective Windows Desktop Security: XP and Vista

Session Details

Tuesday, May 06, 2008
9:45 a.m. - 10:45 a.m.
Potomac 6 (Ballroom Level)

Session Type: Track 5

Speaker(s)

  • John Bruggeman, Director of Information Systems, Hebrew Union College-Jewish Institute of Religion
  • Session convener: William E. Terry, Assoc. Dean of Information Services & CTO, Bard College

Abstract

Windows desktops are widely deployed and can be subject to multiple attack vectors. Windows XP and Vista have vulnerabilities that need to be mitigated effectively by security teams or by end users. This session will cover the top security vulnerabilities in Windows desktops and how to secure them quickly and effectively, along with the tools to use.

Available Resources

More Information

For more information, see:

http://connect.educause.edu/Library/Abstract/EffectiveWindowsDesktopSe/46758http://connect.educause.edu/Library/Abstract/EffectiveWindowsDesktopSe/46758

FireEye, Inc. and University of California, Berkeley - Combating Stealth Malware and Botnets in Higher Education

Session Details

Tuesday, May 06, 2008
9:45 a.m. - 10:45 a.m.
Arlington room (Third Floor)

Session Type: Track 6

Speaker(s)

Abstract

UC Berkeley's Electrical Engineering and Computer Sciences department wanted to strengthen security for mobile users on the wireless network. This talk will cover practical knowledge required to address network security incidents in a forensically sound manner. The university selected FireEye's antimalware solution to protect against targeted stealth malware.

Available Resources

More Information

For more information, see:

http://connect.educause.edu/Library/Abstract/CombatingStealthMalwarean/46786

Refreshment Break
Sponsored by PGP Corporation

Session Details

Tuesday, May 06, 2008
10:45 a.m. - 11:00 a.m.
Regency Ballroom Foyer

Addressing Complex Security Threats Through Risk Management

Session Details

Tuesday, May 06, 2008
11:00 a.m. - 12:00 p.m.
Regency ABCD Ballroom

Session Type: General Session

Speaker(s)

  • Rebecca Whitener, Former Vice President Enterprise Risk Management and Chief Risk Officer, EDS

Abstract

In this session, we will address the current cybersecurity issues that are challenging higher education leaders today as they try to stay on top of the risks associated with attacks on information systems from internal and external sources. Emerging enterprise risk management (ERM) methodologies will be examined as a source of guidance for creating an effective risk-based approach for managing current and future threats.

Available Resources

More Information

For more information, see:

http://connect.educause.edu/Library/Abstract/AddressingComplexSecurity/46776

Lunch for Postconference Seminar Participants

Session Details

Tuesday, May 06, 2008
12:00 p.m. - 1:00 p.m.
Boxed lunch (available inside meeting room)

Security Task Force Team Leadership Meeting (by invitation only)

Session Details

Tuesday, May 06, 2008
12:00 p.m. - 5:00 p.m.
Jefferson Room (Third Floor)

REN-ISAC Members Meeting Invitation Only
PLEASE NOTE: Separate registration and fee are required to attend this meeting.

Session Details

Tuesday, May 06, 2008
12:00 p.m. - 5:30 p.m.
Potomac 3/4 and 5/6 (Ballroom Level)

Session Type: Postconference Seminar

Abstract

The REN-ISAC is an integral part of higher education's strategy to improve network security. This meeting will gather members of the REN-ISAC for a face-to-face meeting. This meeting is open only to REN-ISAC members by invitation. Registration will be limited to 100 people and one attendee per institution. Lunch provided. If you are ONLY attending the REN ISAC meeting, please call Member Services at (303) 449-4430 to register by phone.

Seminar P1 - Developing an Effective Electronic Records Management Process
PLEASE NOTE: Separate registration and fee are required to attend this seminar.

Session Details

Tuesday, May 06, 2008
1:00 p.m. - 4:30 p.m.
Roosevelt (Third Floor)

Session Type: Postconference Seminar

Speaker(s)

  • Michael Sermersheim, Associate Vice President and Deputy General Counsel Emeritus, University of Akron

Abstract

Once considered predominantly an archival function, records management is now relevant at all levels. With the advent of electronic discovery rules, legal compliance requirements, and best-practices considerations, electronically stored information is of great concern to IT professionals, campus executive leadership, and legal counsel. Hear considerations for your creation, or review, of campus records retention policies, records destruction requirements, e-discovery protocols, considerations about forensic information preservation and assessment, document authentication and chain-of-custody guidelines, and sample policies and resources from others.


 
© Copyright 1999-2009 EDUCAUSE