Detailed Program InformationRegistration Desk OpenSession DetailsMonday, April 10, 2006 7:30 a.m. - 5:00 p.m. Lower Level 2 Registration Desk
E-Mail Room Open - sponsored by Gateway, An EDUCAUSE Gold PartnerSession DetailsMonday, April 10, 2006 7:30 a.m. - 5:00 p.m. Silverton Room
Improving Security with Identity Management: Whoa Nelly!
Session DetailsMonday, April 10, 2006 8:30 a.m. - 12:00 p.m. Denver Ballroom 5
Session Type: Preconference Seminar
Speaker(s)AbstractIdentity management improves security by enabling institutions to keep more accurate and manageable records of who is using what resource. This workshop will present the basics of identity and privilege management and its critical role in campus security plans and infrastructure. Included will be the basics of policy, process, and technology. This workshop is sponsored in part by the NMI-EDIT Consortium of Internet2 and EDUCAUSE. Available ResourcesInformation Security and Privacy Policy Development
Session DetailsMonday, April 10, 2006 8:30 a.m. - 12:00 p.m. Denver Ballroom 1/2
Session Type: Preconference Seminar
Speaker(s)AbstractThis session will discuss the development of a policy framework for information security, including effective policies, procedures, and practices that are in keeping with the legal landscape. Participants should come away from the session with model policy framework, procedures, and practices that can be tailored for their individual institution's needs and culture. Available ResourcesSEM01F - Establishing an Information Security Program
PLEASE NOTE: Separate registration and fee are required to attend this seminar.Session DetailsMonday, April 10, 2006 8:30 a.m. - 4:30 p.m. Denver Ballroom 3
Session Type: Preconference Seminar
Speaker(s)- Cedric Bennett, Emeritus Director, Information Security Services, Stanford University
- Carol Myers, Director, College Technology, Paradise Valley Community College
AbstractThis interactive session will provide an overview of areas such as growing the program, gaining broad support, finding resources, focusing direction, and planning for what comes next. We'll take a look at staffing models, assessing risk, policy development, raising campus-wide awareness, training staff, privacy issues, and operational and technical controls. Participants will be given an opportunity to discuss and potentially address security issues from their own institutions. SEM02F - Incident Handling Tools and Techniques
PLEASE NOTE: Separate registration and fee are required to attend this seminar.Session DetailsMonday, April 10, 2006 8:30 a.m. - 4:30 p.m. Denver Ballroom 4
Session Type: Preconference Seminar
Speaker(s)AbstractThis seminar is designed to provide a framework and set of tools that participants can take back to their institutions for handling IT security incidents. Participants will learn how to bypass typical mistakes, develop incident-handling protocols and procedures, use shareware and open source tools, interpret logs, and leverage other resources. Exercises will give participants hands-on opportunities to diagnose and resolve incidents. Refreshment Break for Preconference Seminar ParticipantsSession DetailsMonday, April 10, 2006 10:00 a.m. - 10:30 a.m. Denver Ballroom Prefunction Area
Lunch for Full-Day Preconference Seminar ParticipantsSession DetailsMonday, April 10, 2006 12:00 p.m. - 1:00 p.m. Mattie Silks (Lower Level 1)
Data-Incident Notification Policies and Procedures
Session DetailsMonday, April 10, 2006 1:00 p.m. - 4:30 p.m. Denver Ballroom 1/2
Session Type: Preconference Seminar
Speaker(s)AbstractInformation security policies and procedures increasingly must respond to legal requirements in the area of notification in the event of a breach of personally identifiable information. This session will also explore technical issues related to meeting legal standards such as "reasonable belief that data has been acquired by an unauthorized user." Members of a panel will also describe their actual responses to incidents at their institutions. Available ResourcesNetwork Architecture for Automatic Security and Policy Enforcement
Session DetailsMonday, April 10, 2006 1:00 p.m. - 4:30 p.m. Denver Ballroom 5
Session Type: Preconference Seminar
Speaker(s)- Kevin Amorin, Information Security Manager, HKS, Harvard University
- Christopher Misra, Information Security Officer, University of Massachusetts Amherst
AbstractThis session will discuss various approaches for automating technical policy enforcement as a condition for network access in colleges and universities, including approaches that allow for host isolation, captive-portal-like remediation systems, and other forms of conditional network access. We will also discuss the work of the Internet2 SALSA-NetAuth working group. Available ResourcesSEM03P - War Games 2006: An Exercise in Ethical Cracking
PLEASE NOTE: Separate registration and fee are required to attend this seminar.Session DetailsMonday, April 10, 2006 1:00 p.m. - 4:30 p.m. Denver Ballroom 6
Session Type: Preconference Seminar
Speaker(s)- David Ripley, Lead Network Security Developer, Advanced Network Management Lab, Indiana University System
- Gregory Travis, Senior Researcher & Assistant Lab Director, Advanced Network Management Lab, Indiana University System
AbstractAttendees, given some ground rules, will attempt to compromise computers connected to an isolated network. The goal will be to "capture" as many of the other hosts as possible in the time allotted. The exercise will be followed by a discussion of methods used, and security issues will be highlighted. Refreshment Break for Preconference Seminar ParticipantsSession DetailsMonday, April 10, 2006 2:30 p.m. - 3:00 p.m. Denver Ballroom Prefunction Area
Birds-of-a-Feather SessionsSession DetailsMonday, April 10, 2006 5:00 p.m. - 6:30 p.m. Colorado Ballroom E
AbstractWe invite you to join colleagues for birds-of-a-feather discussions. During this discussion session you can network with those who are from similar organizations. If you don’t find a group to which you would naturally belong, you can also establish a new group by notifying us in advance (security-task-force@educause.edu) or signing up at the bulletin board near the registration desk.
Groups include: Big Ten/CIC
Commuter Campuses
Ivy-Plus
Minority Serving Institutions
Research Universities
Small Colleges
State Networks
Universities of the Big 12
Virginia Alliance for Secure Computing and Networking (VASCAN) Other Groups: Sign up at bulletin board near the registration desk.
|