Top Banner
mandatory online training
33

Mandatory online training. intro why we are doing this why you should care what we hope you get out of this.

Jan 04, 2016

Download

Documents

Pearl Lyons
Welcome message from author
This document is posted to help you gain knowledge. Please leave a comment to let me know what you think about it! Share it to your friends and learn new things together.
Transcript
Page 1: Mandatory online training. intro why we are doing this why you should care what we hope you get out of this.

mandatory online training

Page 2: Mandatory online training. intro why we are doing this why you should care what we hope you get out of this.

intro

• why we are doing this

• why you should care

• what we hope you get out of this

Page 3: Mandatory online training. intro why we are doing this why you should care what we hope you get out of this.

How does info sec affect me?

• need to understand the info sec policy

• need to follow safe data handling practices, including disposal

• need to practice safe computing

Page 4: Mandatory online training. intro why we are doing this why you should care what we hope you get out of this.

What Information Security is

• definition

• examples

Page 5: Mandatory online training. intro why we are doing this why you should care what we hope you get out of this.

University Information Security policy

• Summarize policy– what covered – who covered– define principles

Page 6: Mandatory online training. intro why we are doing this why you should care what we hope you get out of this.

University Information

• University Data - Data created or maintained by the University related to carrying out the University's mission. It’s a University resources, owned by the University.

• Exclusions – Research data, class notes, lesson plans, personal papers, materials covered in the University’s Intellectual Property Policy

Page 7: Mandatory online training. intro why we are doing this why you should care what we hope you get out of this.

defined roles in policy

• cio• data oversight• data steward• university community (faculty, staff, students)• info sec department• Univ archives• audit and advistory• procurement

Page 8: Mandatory online training. intro why we are doing this why you should care what we hope you get out of this.

Data Steward

• An individual who is responsible for ensuring the confidentiality, integrity, and availability of University information. A Data Steward defines access to and restrictions on use of the information for which he or she is responsible.

• A data steward also:– Ensures the confidentiality, integrity and availability of

University data– Classifies all University information as Public, Internal,

Sensitive, or Highly Sensitive, according to Data Classification Guidelines

Page 9: Mandatory online training. intro why we are doing this why you should care what we hope you get out of this.

who are the data stewards?

• do we list them?

Page 10: Mandatory online training. intro why we are doing this why you should care what we hope you get out of this.

Univ community

• Protect the privacy and security of University information, applications, computer systems, and networks under their control

• Adhere to all relevant data handling standards

• Report suspected violations of this policy to the Director of Information Security or to the appropriate Data Steward

Page 11: Mandatory online training. intro why we are doing this why you should care what we hope you get out of this.

Categorization of University data

• Determined by the degree of expected impact on the University or individuals if University information is mishandled.

Page 12: Mandatory online training. intro why we are doing this why you should care what we hope you get out of this.

Categories of University Data

• Public

• Internal

• Sensitive

• Highly sensitive

Page 13: Mandatory online training. intro why we are doing this why you should care what we hope you get out of this.

Data category: Public

• Information intended for public use that, when used as intended and not altered, would have no adverse impact on University operations, University assets, or individuals.

Page 14: Mandatory online training. intro why we are doing this why you should care what we hope you get out of this.

examples of public data

• PR releases

Page 15: Mandatory online training. intro why we are doing this why you should care what we hope you get out of this.

Data category: Internal

• Information not intended for parties outside the University community that, if disclosed, would have minimal or no adverse impact on University operations, University assets or individuals.

Page 16: Mandatory online training. intro why we are doing this why you should care what we hope you get out of this.

examples of Internal data

• directory info?

Page 17: Mandatory online training. intro why we are doing this why you should care what we hope you get out of this.

Data category: Sensitive

• Information that, if mishandled, could be expected to have a serious adverse effect on University operations, University assets or individuals.

Page 18: Mandatory online training. intro why we are doing this why you should care what we hope you get out of this.

examples of restricted data

Page 19: Mandatory online training. intro why we are doing this why you should care what we hope you get out of this.

Data category: Highly sensitive

• Information that, if mishandled, could be expected to have a severe or catastrophic adverse effect on University operations, University assets or individuals.

Page 20: Mandatory online training. intro why we are doing this why you should care what we hope you get out of this.

examples of highly sensitive data

Page 21: Mandatory online training. intro why we are doing this why you should care what we hope you get out of this.

interaction

• sorting data by types?

Page 22: Mandatory online training. intro why we are doing this why you should care what we hope you get out of this.

Enforcement of info sec policy

• The University will investigate suspected violations, and may recommend disciplinary action in accordance with University codes of conduct, policies, or applicable laws. Sanctions may include one or more of the following:– Suspension or termination of access – Disciplinary action up to and including termination of

employment – Student discipline in accordance with applicable

University policy– Civil or criminal penalties

Page 23: Mandatory online training. intro why we are doing this why you should care what we hope you get out of this.

Transition?

• how do we move from Info sec policy to rest of topics?

Page 24: Mandatory online training. intro why we are doing this why you should care what we hope you get out of this.

Data Handling Standards

• Get permission from data steward for access

• Use and share info with others only according to standards

Page 25: Mandatory online training. intro why we are doing this why you should care what we hope you get out of this.

Safe data handling (could be interactive—choose correct answers)

• Secure handling procedures:• Lock screen when leaving computer• Turn monitor from door• Keep hard copies locked in desk when not in

use• Lock your office door when leaving room• Never leave hard copies in printer/copier• Store electronic files in Netfile

Page 26: Mandatory online training. intro why we are doing this why you should care what we hope you get out of this.

Disposal methods

• Data/information – Shred paper copies– Use spy-bot to electronically shred files

• Technology– clean hard drives before disposal

Page 27: Mandatory online training. intro why we are doing this why you should care what we hope you get out of this.

Safe computing

• Includes using tools such as – TakeCharge– virus protection– anti-spyware– Use SENF to find files containing sensitive data

– laptop encryption

• Safe Web surfing– all your precautions can be undone by visiting the

wrong site

Page 28: Mandatory online training. intro why we are doing this why you should care what we hope you get out of this.

Myths about security

• No one wants my stuff

• A little surfing hurts no one

• The University/OIT is protecting me

Page 29: Mandatory online training. intro why we are doing this why you should care what we hope you get out of this.

Points to remember

• Information Security is an ever evolving responsibility

• policies are being developed and implemented over time

Page 30: Mandatory online training. intro why we are doing this why you should care what we hope you get out of this.

Want more info?

• secure.nd.edu

• reporting violations

Page 31: Mandatory online training. intro why we are doing this why you should care what we hope you get out of this.

my points

• Missing:– secure work space

Page 32: Mandatory online training. intro why we are doing this why you should care what we hope you get out of this.

presentation issues

• travel theme– road signs (caution signs, stop signs, billboards, street signs,

etc.)– could use roadmap (sorry!) to mark progression through course

• interactions– click to advance to next slide?– questions interspersed with text?

• how often?

– does wrong answer send them back or just get right answer told to them?

– Matching? Multiple choice?– do we keep score?

Page 33: Mandatory online training. intro why we are doing this why you should care what we hope you get out of this.

More issues

• length– this covers topics chosen but seems way too

long– any ideas on what to cut, if anything?

• adverse effects maybe?

– ideas on focus of subsequent training?