Educause Security Discussion mailing list archives
Re: [EXTERNAL] SECURITY Digest - 3 Oct 2019 (#2019-192)
From: "Hollis, Michael" <Michael.Hollis () UNTHSC EDU>
Date: Thu, 3 Oct 2019 22:08:42 +0000
I would e interested as well. Thanks, Mike Get Outlook for iOS<https://aka.ms/o0ukef> ________________________________ From: The EDUCAUSE Security Community Group Listserv <SECURITY () LISTSERV EDUCAUSE EDU> on behalf of SECURITY automatic digest system <LISTSERV () LISTSERV EDUCAUSE EDU> Sent: Thursday, October 3, 2019 5:00:00 PM To: SECURITY () LISTSERV EDUCAUSE EDU <SECURITY () LISTSERV EDUCAUSE EDU> Subject: [EXTERNAL] SECURITY Digest - 3 Oct 2019 (#2019-192) There are 2 messages totalling 1305 lines in this issue. Topics of the day: 1. Ransomware Playbook (2) ********** Replies to EDUCAUSE Community Group emails are sent to the entire community list. If you want to reply only to the person who sent the message, copy and paste their email address and forward the email reply. Additional participation and subscription information can be found at https://nam04.safelinks.protection.outlook.com/?url=https%3A%2F%2Fwww.educause.edu%2Fcommunity&data=02%7C01%7Cmichael.hollis%40UNTHSC.EDU%7Cd91ce35d56f449f767fd08d7484d0c8f%7C70de199207c6480fa318a1afcba03983%7C0%7C0%7C637057368131225171&sdata=tQN2S9xCgjRGrjYPOGouZzxbVA3VgeXKz%2BZpUzRLFpo%3D&reserved=0 ---------------------------------------------------------------------- Date: Thu, 3 Oct 2019 21:32:01 +0000 From: Larry Carson <larry.carson () TJC EDU> Subject: Re: Ransomware Playbook I'm interested too, thank you! Larry Carson Office of Technology Services 903.510.2989 [TJC Logo]<https://nam04.safelinks.protection.outlook.com/?url=http%3A%2F%2Fwww.tjc.edu%2F&data=02%7C01%7Cmichael.hollis%40UNTHSC.EDU%7Cd91ce35d56f449f767fd08d7484d0c8f%7C70de199207c6480fa318a1afcba03983%7C0%7C0%7C637057368131225171&sdata=vb%2FL%2BDo1JUb%2Bp%2FQ5kXF4Cf1FZ0nSmnehZPVh7pqsvAg%3D&reserved=0> PO Box 9020, Tyler, TX 75711 1400 East Fifth St., Tyler, TX 75798 Attention: The information contained in this message and/or attachments is intended only for the person or entity to which it is addressed and may contain confidential and/or nonpublic material. Any review, retransmission, dissemination or other use of, or taking of any action in reliance upon, this information by persons or entities other than the intended recipient is prohibited. If you received this in error, please contact the sender and delete the material from any system and destroy any copies. ********** Replies to EDUCAUSE Community Group emails are sent to the entire community list. If you want to reply only to the person who sent the message, copy and paste their email address and forward the email reply. Additional participation and subscription information can be found at https://nam04.safelinks.protection.outlook.com/?url=https%3A%2F%2Fwww.educause.edu%2Fcommunity&data=02%7C01%7Cmichael.hollis%40UNTHSC.EDU%7Cd91ce35d56f449f767fd08d7484d0c8f%7C70de199207c6480fa318a1afcba03983%7C0%7C0%7C637057368131225171&sdata=tQN2S9xCgjRGrjYPOGouZzxbVA3VgeXKz%2BZpUzRLFpo%3D&reserved=0 ------------------------------ Date: Thu, 3 Oct 2019 21:59:32 +0000 From: Dewight Fredrick Kramer <dfkramer () UCDAVIS EDU> Subject: Re: Ransomware Playbook We have looked into this here at UC Davis but have not developed anything formal, as such we would also be interested! Thank you, Dewight F. Kramer Assistant CISO University of California, Davis One Shields Avenue Davis, CA 95616 (530)752-1700 dfkramer () ucdavis edu<mailto:dfkramer () ucdavis edu> https://nam04.safelinks.protection.outlook.com/?url=http%3A%2F%2Fsecurity.ucdavis.edu&data=02%7C01%7Cmichael.hollis%40UNTHSC.EDU%7Cd91ce35d56f449f767fd08d7484d0c8f%7C70de199207c6480fa318a1afcba03983%7C0%7C0%7C637057368131225171&sdata=I7M3RY0jFabRwC8GruRj%2F%2Bh4%2BLRk4z8Sy1uGtTUaAyA%3D&reserved=0<https://nam04.safelinks.protection.outlook.com/?url=http%3A%2F%2Fsecurity.ucdavis.edu%2F&data=02%7C01%7Cmichael.hollis%40UNTHSC.EDU%7Cd91ce35d56f449f767fd08d7484d0c8f%7C70de199207c6480fa318a1afcba03983%7C0%7C0%7C637057368131225171&sdata=lfgvk8PqPSqJgxsx9sq7lEFoooI%2FQ1PGVoDGftkL6UI%3D&reserved=0> From: The EDUCAUSE Security Community Group Listserv <SECURITY () LISTSERV EDUCAUSE EDU> on behalf of "King, Ronald A." <raking () NSU EDU> Reply-To: The EDUCAUSE Security Community Group Listserv <SECURITY () LISTSERV EDUCAUSE EDU> Date: Thursday, October 3, 2019 at 2:15 PM To: "SECURITY () LISTSERV EDUCAUSE EDU" <SECURITY () LISTSERV EDUCAUSE EDU> Subject: Re: [SECURITY] Ransomware Playbook Me too, please. Ronald King Chief Information Security Officer Office of Information Technology (757) 823-2916 (Office) raking () nsu edu<mailto:raking () nsu edu> https://nam04.safelinks.protection.outlook.com/?url=www.nsu.edu&data=02%7C01%7Cmichael.hollis%40UNTHSC.EDU%7Cd91ce35d56f449f767fd08d7484d0c8f%7C70de199207c6480fa318a1afcba03983%7C0%7C0%7C637057368131225171&sdata=zvWV4gSCWZLNH%2BNTe7fFSf4wnd%2FV5VrG2XbkEICT8fA%3D&reserved=0<https://nam04.safelinks.protection.outlook.com/?url=http%3A%2F%2Fwww.nsu.edu%2F&data=02%7C01%7Cmichael.hollis%40UNTHSC.EDU%7Cd91ce35d56f449f767fd08d7484d0c8f%7C70de199207c6480fa318a1afcba03983%7C0%7C0%7C637057368131225171&sdata=yCLniq9ODdAcXLfwKtNYt3tkirvjv%2BX5%2FME5VAUtaBs%3D&reserved=0> @NSUCISO (Twitter) [NSU_logo_horiz_tag_4c - Smaller] From: The EDUCAUSE Security Community Group Listserv <SECURITY () LISTSERV EDUCAUSE EDU> On Behalf Of Joey Rego Sent: Thursday, October 3, 2019 5:13 PM To: SECURITY () LISTSERV EDUCAUSE EDU Subject: Re: [SECURITY] Ransomware Playbook I am interested as well. Thank you. Joey Rego Associate Director of Information Security Information Technology Lynn University 3601 N Military Trail Boca Raton, FL 33462 561-237-7982 https://nam04.safelinks.protection.outlook.com/?url=www.lynn.edu&data=02%7C01%7Cmichael.hollis%40UNTHSC.EDU%7Cd91ce35d56f449f767fd08d7484d0c8f%7C70de199207c6480fa318a1afcba03983%7C0%7C0%7C637057368131225171&sdata=TKd1naxIMi2Q3LKFUkiO51qptR4fDTxBgsnqKcIoN8A%3D&reserved=0<https://nam04.safelinks.protection.outlook.com/?url=http%3A%2F%2Fwww.lynn.edu&data=02%7C01%7Cmichael.hollis%40UNTHSC.EDU%7Cd91ce35d56f449f767fd08d7484d0c8f%7C70de199207c6480fa318a1afcba03983%7C0%7C0%7C637057368131225171&sdata=aJLexFMdfDvBGhfOGjUBRXl9pkzrGIu1fiYxusU%2Fjp0%3D&reserved=0> ________________________________ From: The EDUCAUSE Security Community Group Listserv <SECURITY () LISTSERV EDUCAUSE EDU<mailto:SECURITY () LISTSERV EDUCAUSE EDU>> on behalf of John Ramsey <jramsey () STUDENTCLEARINGHOUSE ORG<mailto:jramsey () STUDENTCLEARINGHOUSE ORG>> Sent: Thursday, October 3, 2019 4:50:20 PM To: SECURITY () LISTSERV EDUCAUSE EDU<mailto:SECURITY () LISTSERV EDUCAUSE EDU> <SECURITY () LISTSERV EDUCAUSE EDU<mailto:SECURITY () LISTSERV EDUCAUSE EDU>> Subject: Re: [SECURITY] Ransomware Playbook I have one and am happy to share! Sent from my Verizon, Samsung Galaxy smartphone Get Outlook for Android<https://nam04.safelinks.protection.outlook.com/?url=https%3A%2F%2Furldefense.proofpoint.com%2Fv2%2Furl%3Fu%3Dhttps-3A__aka.ms_ghei36%26d%3DDwMFAg%26c%3DtSGu_Pc6mPnB6zIYTZr3Sw%26r%3DPTnT2JXctjp4MTPziGqcrg%26m%3DSynK17bceWMbt_dooTOo-leAVssO48qPL8MzLnn_EXI%26s%3DwPjf0flvlyR164RzC6qod76IJztI6nHPHP-lEfY7Df4%26e&data=02%7C01%7Cmichael.hollis%40UNTHSC.EDU%7Cd91ce35d56f449f767fd08d7484d0c8f%7C70de199207c6480fa318a1afcba03983%7C0%7C0%7C637057368131225171&sdata=k6trSr4941meB5%2B4q2HqMJO0nIEATQcuzh6EkMXQqrU%3D&reserved=0=> ________________________________ From: The EDUCAUSE Security Community Group Listserv <SECURITY () LISTSERV EDUCAUSE EDU<mailto:SECURITY () LISTSERV EDUCAUSE EDU>> on behalf of Kip Bates <kbates () HOUSING UCSB EDU<mailto:kbates () HOUSING UCSB EDU>> Sent: Thursday, October 3, 2019 4:34:08 PM To: SECURITY () LISTSERV EDUCAUSE EDU<mailto:SECURITY () LISTSERV EDUCAUSE EDU> <SECURITY () LISTSERV EDUCAUSE EDU<mailto:SECURITY () LISTSERV EDUCAUSE EDU>> Subject: [SECURITY] Ransomware Playbook Colleagues: I am hoping that I can find someone or someplace that has made an effort to develop a Ransomware Response playbook that they would not mind sharing. I understand all the preparation that needs to occur prior to an attack but I am looking for something that we can provide users, help desk folks, technicians and such on what actions to take if (when) they experience a ransomware attack. I have found a few on the web and I was wondering if someone has adapted one of these for their institution or have developed one that they think is particularly good. Feel free to comment here or off-list. Kip Bates Associate Chief Information Security Officer University of California, Santa Barbara ********** Replies to EDUCAUSE Community Group emails are sent to the entire community list. If you want to reply only to the person who sent the message, copy and paste their email address and forward the email reply. Additional participation and subscription information can be found at https://nam04.safelinks.protection.outlook.com/?url=https%3A%2F%2Fwww.educause.edu%2Fcommunity&data=02%7C01%7Cmichael.hollis%40UNTHSC.EDU%7Cd91ce35d56f449f767fd08d7484d0c8f%7C70de199207c6480fa318a1afcba03983%7C0%7C0%7C637057368131235167&sdata=oOdAdwrZnrdKrmmdGh85We8fU3D%2FpQWDpuH9J%2FsYGec%3D&reserved=0<https://nam04.safelinks.protection.outlook.com/?url=https%3A%2F%2Furldefense.proofpoint.com%2Fv2%2Furl%3Fu%3Dhttps-3A__nam01.safelinks.protection.outlook.com_-3Furl-3Dhttps-253A-252F-252Fwww.educause.edu-252Fcommunity-26data-3D02-257C01-257Cjramsey-2540studentclearinghouse.org-257Ceeb9effb345442318b0a08d748429912-257C8cc02fea054043a688b6069d3eac0119-257C0-257C1-257C637057323178918904-26sdata-3DjUWrk2Wt4Gr-252BBW9ZZXxvxCnl0II1IpaYOvaKgjB5XWY-253D-26reserved-3D0%26d%3DDwMFAg%26c%3DtSGu_Pc6mPnB6zIYTZr3Sw%26r%3DPTnT2JXctjp4MTPziGqcrg%26m%3DSynK17bceWMbt_dooTOo-leAVssO48qPL8MzLnn_EXI%26s%3DwRiqkwHXt6Jf5tWQ1QiT68gVcu1m5m3M9X1VAYqNvJ4%26e&data=02%7C01%7Cmichael.hollis%40UNTHSC.EDU%7Cd91ce35d56f449f767fd08d7484d0c8f%7C70de199207c6480fa318a1afcba03983%7C0%7C0%7C637057368131235167&sdata=8ErlWkCHZ6X66%2BBAFuhNJUe%2F8W0JxBveBqZpuOTaXmg%3D&reserved=0=> ======================================================= This message has been analyzed by Deep Discovery Email Inspector. ********** Replies to EDUCAUSE Community Group emails are sent to the entire community list. If you want to reply only to the person who sent the message, copy and paste their email address and forward the email reply. Additional participation and subscription information can be found at https://nam04.safelinks.protection.outlook.com/?url=https%3A%2F%2Fwww.educause.edu%2Fcommunity&data=02%7C01%7Cmichael.hollis%40UNTHSC.EDU%7Cd91ce35d56f449f767fd08d7484d0c8f%7C70de199207c6480fa318a1afcba03983%7C0%7C0%7C637057368131235167&sdata=oOdAdwrZnrdKrmmdGh85We8fU3D%2FpQWDpuH9J%2FsYGec%3D&reserved=0<https://nam04.safelinks.protection.outlook.com/?url=https%3A%2F%2Furldefense.proofpoint.com%2Fv2%2Furl%3Fu%3Dhttps-3A__www.educause.edu_community%26d%3DDwMFAg%26c%3DtSGu_Pc6mPnB6zIYTZr3Sw%26r%3DPTnT2JXctjp4MTPziGqcrg%26m%3DSynK17bceWMbt_dooTOo-leAVssO48qPL8MzLnn_EXI%26s%3DfKkuKv3i6k7W-LRIBSa1iIePP8_8E9PyJhCtYBo-r1U%26e&data=02%7C01%7Cmichael.hollis%40UNTHSC.EDU%7Cd91ce35d56f449f767fd08d7484d0c8f%7C70de199207c6480fa318a1afcba03983%7C0%7C0%7C637057368131235167&sdata=xxjgW3CPXzsl176%2B88wOmlX6dv4Hfrq2Qqaw5asbFGo%3D&reserved=0=> This email is intended for the designated recipient only, and may be confidential, non-public, proprietary, protected by the attorney/client or other privilege. Unauthorized reading, distribution, copying or other use of this communication is prohibited and may be unlawful. Receipt by anyone other than the intended recipients should not be deemed a waiver of any privilege or protection. If you are not the intended recipient or if you believe that you have received this email in error, please notify the sender immediately and delete all copies from your computer system without reading, saving, or using it in any manner. Although it has been checked for viruses and other malicious software, malware, we do not warrant, represent or guarantee in any way that this communication is free of malware or potentially damaging defects. All liability for any actual or alleged loss, damage, or injury arising out of or resulting in any way from the receipt, opening or use of this email is expressly disclaimed. ********** Replies to EDUCAUSE Community Group emails are sent to the entire community list. If you want to reply only to the person who sent the message, copy and paste their email address and forward the email reply. Additional participation and subscription information can be found at https://nam04.safelinks.protection.outlook.com/?url=https%3A%2F%2Fwww.educause.edu%2Fcommunity&data=02%7C01%7Cmichael.hollis%40UNTHSC.EDU%7Cd91ce35d56f449f767fd08d7484d0c8f%7C70de199207c6480fa318a1afcba03983%7C0%7C0%7C637057368131235167&sdata=oOdAdwrZnrdKrmmdGh85We8fU3D%2FpQWDpuH9J%2FsYGec%3D&reserved=0 ********** Replies to EDUCAUSE Community Group emails are sent to the entire community list. If you want to reply only to the person who sent the message, copy and paste their email address and forward the email reply. Additional participation and subscription information can be found at https://nam04.safelinks.protection.outlook.com/?url=https%3A%2F%2Fwww.educause.edu%2Fcommunity&data=02%7C01%7Cmichael.hollis%40UNTHSC.EDU%7Cd91ce35d56f449f767fd08d7484d0c8f%7C70de199207c6480fa318a1afcba03983%7C0%7C0%7C637057368131235167&sdata=oOdAdwrZnrdKrmmdGh85We8fU3D%2FpQWDpuH9J%2FsYGec%3D&reserved=0 ********** Replies to EDUCAUSE Community Group emails are sent to the entire community list. If you want to reply only to the person who sent the message, copy and paste their email address and forward the email reply. Additional participation and subscription information can be found at https://nam04.safelinks.protection.outlook.com/?url=https%3A%2F%2Fwww.educause.edu%2F&data=02%7C01%7Cmichael.hollis%40UNTHSC.EDU%7Cd91ce35d56f449f767fd08d7484d0c8f%7C70de199207c6480fa318a1afcba03983%7C0%7C0%7C637057368131235167&sdata=ybapxTSl0jrRTyUZaNDzhRUFg3hpfnQabRsFyT%2F2B%2Fk%3D&reserved=0 ------------------------------ End of SECURITY Digest - 3 Oct 2019 (#2019-192) *********************************************** ********** Replies to EDUCAUSE Community Group emails are sent to the entire community list. If you want to reply only to the person who sent the message, copy and paste their email address and forward the email reply. Additional participation and subscription information can be found at https://www.educause.edu/community
Current thread:
- Re: [EXTERNAL] SECURITY Digest - 3 Oct 2019 (#2019-192) Hollis, Michael (Oct 03)