Educause Security Discussion mailing list archives

Re: Security Awareness Program assistance


From: James Farr <jfarr () UTICA EDU>
Date: Thu, 28 May 2015 14:45:12 -0400

I would be grateful if you could also share this information with me.



James Farr

Information Security Officer

Instructional Technologist

Utica College

jfarr () utica edu

315-223-2386







*From:* The EDUCAUSE Security Constituent Group Listserv [mailto:
SECURITY () LISTSERV EDUCAUSE EDU] *On Behalf Of *Shamblin, Quinn
*Sent:* Wednesday, May 27, 2015 11:48 AM
*To:* SECURITY () LISTSERV EDUCAUSE EDU
*Subject:* Re: [SECURITY] Security Awareness Program assistance



Harry Hoffman and I put together a framework for doing this.  I’d be happy
to share the documents for reference if you are interested.



Best,



*Quinn R Shamblin                                                  .*

Executive Director of Information Security, Boston University



*Security Tip: *

*One of the most effective things you can do to keep your devices safe is
to keep them and the software on them up to date.*





*From:* The EDUCAUSE Security Constituent Group Listserv [
mailto:SECURITY () LISTSERV EDUCAUSE EDU <SECURITY () LISTSERV EDUCAUSE EDU>] *On
Behalf Of *Ullman, Catherine
*Sent:* Wednesday, May 27, 2015 11:19 AM
*To:* SECURITY () LISTSERV EDUCAUSE EDU
*Subject:* [SECURITY] Security Awareness Program assistance



Greetings!



I have been asked to put together a University-wide security awareness
program that is phased in over the next two years and ideally includes
measurements of success.  I would very much like to hear from any of you
who have successfully undertaken such a project and how you’ve accomplished
it, because this is a larger undertaking than I’ve ever been expected to
complete.  I also would prefer not to reinvent the wheel if there are
already great ideas out there!



The kinds of things I’m looking for include the approach, how the rollout
was accomplished, tools being used, measures of success.  FWIW I’d prefer
our awareness program to be a positive reinforcement type thing,
encouraging folks to want to be involved rather than a stick-based program.



Feel free to email me off-line if you’d prefer.  Thanks in advance for your
help.



Sincerely,

Cathy





Dr. Catherine J Ullman

Information Security Analyst

Information Security Office

University at Buffalo

cende () buffalo edu

Current thread: