Educause Security Discussion mailing list archives

Re: risk asessment in edu


From: Kevin Wilcox <wilcoxkm () APPSTATE EDU>
Date: Thu, 18 Jun 2009 16:19:27 -0400

2009/6/18 jeff murphy <jcmurphy () buffalo edu>:

On Jun 18, 2009, at 3:18 PM, reflect ocean wrote:

Hi.Recently I've been assigned information security responsabilities
and my first step is to determine what assets the organization wants
to protect.i'm struggling trying to come up with something else rather
than student data.

<snip>

as an aside, posting from an ostensibly anonymous account is, imo, bad form.

I read the first paragraph, then checked the email address, and
decided it was better to ignore. Someone in the business that is
tasked with IS responsibilities will almost certainly know, beyond
student data, what they are being tasked with protecting.

That said, I'm more than willing to reply to the thread with my work
address...even though now the poster knows we're on the list, the
format of at least one email address and associated user details at
each of our institutions, that our institutions follow the list, etc.

kmw

Current thread: