Educause Security Discussion mailing list archives

Re: [External]:Re: [SECURITY] [EXTERNAL] SECURITY Digest - 14 Jan 2020 to 15 Jan 2020 (#2020-11)


From: "Ferland, William" <wferland () CCRI EDU>
Date: Wed, 22 Jan 2020 21:22:53 +0000

Please include me as well.

-----Original Message-----
From: The EDUCAUSE Security Community Group Listserv <SECURITY () LISTSERV EDUCAUSE EDU> On Behalf Of Hollis, Michael
Sent: Thursday, January 16, 2020 5:18 PM
To: SECURITY () LISTSERV EDUCAUSE EDU
Subject: [External]:Re: [SECURITY] [EXTERNAL] SECURITY Digest - 14 Jan 2020 to 15 Jan 2020 (#2020-11)

CAUTION: This email was generated from outside of CCRI. Please do not click on links or attachments unless you have 
verified legitimacy of this email.


I would like a copy of the playbooks as well.  Thanks again for providing such a valuable service.

Thanks,
Mike


Michael Hollis  CISSP,CISA
Information Security Officer
University of North Texas Health Science Center
3500 Camp Bowie Blvd.
Fort Worth, TX  76107
817-735-2136
Michael.hollis () unthsc edu



-----Original Message-----
From: The EDUCAUSE Security Community Group Listserv [mailto:SECURITY () LISTSERV EDUCAUSE EDU] On Behalf Of SECURITY 
automatic digest system
Sent: Wednesday, January 15, 2020 4:00 PM
To: SECURITY () LISTSERV EDUCAUSE EDU
Subject: [EXTERNAL] SECURITY Digest - 14 Jan 2020 to 15 Jan 2020 (#2020-11)

There are 11 messages totalling 6346 lines in this issue.

Topics of the day:

  1. SECURITY Digest - 13 Jan 2020 to 14 Jan 2020 (#2020-10) (2)
  2. Reminder: IAM Online Wednesday: Passwordless Authentication with
     Shibboleth and WebAuthn (2)
  3. SOP for Releasing Private Data Generated by Deceased Student? (4)
  4. VA Tech SANS Onsite Class 3/9-14/2020 Simulcast Update
  5. HECVAT Tool with Current Vendors
  6. ResearchSOC Cybersecurity Webinars

**********
Replies to EDUCAUSE Community Group emails are sent to the entire community list. If you want to reply only to the 
person who sent the message, copy and paste their email address and forward the email reply. Additional participation 
and subscription information can be found at 
https://nam02.safelinks.protection.outlook.com/?url=https%3A%2F%2Fwww.educause.edu%2Fcommunity&amp;data=02%7C01%7Cwferland%40ccri.edu%7C7031cfce83124235a2b008d79e97786b%7Caf75351b37eb4405bf7a7327cec380a5%7C0%7C1%7C637152245732176556&amp;sdata=lghNpHqWpApAOSpREmSF29bRAB3FKXOONL817rh1Pb4%3D&amp;reserved=0

----------------------------------------------------------------------

Date:    Tue, 14 Jan 2020 22:01:21 +0000
From:    "Carianna, Marie" <marie.carianna () TOURO EDU>
Subject: Re: SECURITY Digest - 13 Jan 2020 to 14 Jan 2020 (#2020-10)

Touro would also like to have the playbook.

Kind regards,
Marie

Marie Carianna, PMP, ITIL
Deputy Chief Information Officer for Business Systems, Project and Portfolio Management
Touro College & University System  |  500 7th Avenue, room 510 NY, NY 10018

-----Original Message-----
From: The EDUCAUSE Security Community Group Listserv <SECURITY () LISTSERV EDUCAUSE EDU> On Behalf Of SECURITY 
automatic digest system
Sent: Tuesday, January 14, 2020 5:00 PM
To: SECURITY () LISTSERV EDUCAUSE EDU
Subject: SECURITY Digest - 13 Jan 2020 to 14 Jan 2020 (#2020-10)

There are 4 messages totalling 4010 lines in this issue.

Topics of the day:

  1. Ransomware Playbook (4)

**********
Replies to EDUCAUSE Community Group emails are sent to the entire community list. If you want to reply only to the 
person who sent the message, copy and paste their email address and forward the email reply. Additional participation 
and subscription information can be found at 
https://nam02.safelinks.protection.outlook.com/?url=https%3A%2F%2Furldefense.proofpoint.com%2Fv2%2Furl%3Fu%3Dhttps-3A__www.educause.edu_community%26d%3DDwIFaQ%26c%3DodzYs1kPF7h99M0Vn1uLzg%26r%3DjKMTIfZiBnBYrk_cRkqhrq0vZwXKksqj0lGxPgjosOo%26m%3DPCH4pSQdJHnemwXCid22jVtPnrEXBJK3q7fAp2ujQXk%26s%3DipDfAu95YytXt6pdbXXudY9CcmGpIRo-e8vMZATurtU%26e&amp;data=02%7C01%7Cwferland%40ccri.edu%7C7031cfce83124235a2b008d79e97786b%7Caf75351b37eb4405bf7a7327cec380a5%7C0%7C0%7C637152245732186547&amp;sdata=ZhHbjJ%2F994qHsAD6wWXWd2vpjTS%2FCtq6VBV6lyIf4UE%3D&amp;reserved=0=

----------------------------------------------------------------------

Date:    Tue, 14 Jan 2020 16:00:24 +0000
From:    Paul Usama <paul.usama () SAIT CA>
Subject: Re: Ransomware Playbook

Hi,

Am not sure if this is still shared, I am interested in the Ransomware Playbook.


[cid:image001.gif@01D1A152.13E94560]
Paul Usama
Information Security Analyst
Information Technology Services

Southern Alberta Institute of Technology E.H. Crandell, G200
1301 - 16 Avenue NW, Calgary AB, T2M 0L4
(Cell) 403.836.3489 (Ph) 403.284.8328
Paul.Usama () sait ca<mailto:Paul.Usama () sait ca>







From: The EDUCAUSE Security Community Group Listserv <SECURITY () LISTSERV EDUCAUSE EDU> On Behalf Of Jamie Schademan
Sent: Friday, October 4, 2019 11:08 AM
To: SECURITY () LISTSERV EDUCAUSE EDU
Subject: Re: [SECURITY] Ransomware Playbook

Me too please.
Jamie
CWU

Jamie Schademan, CISM
Chief Information Security Officer
CWU

________________________________
From: The EDUCAUSE Security Community Group Listserv <SECURITY () LISTSERV EDUCAUSE EDU<mailto:SECURITY () LISTSERV 
EDUCAUSE EDU>> on behalf of Oberlin, Craig <coberlin1 () CCCD EDU<mailto:coberlin1 () CCCD EDU>>
Sent: Friday, October 4, 2019 11:03:02 AM
To: SECURITY () LISTSERV EDUCAUSE EDU<mailto:SECURITY () LISTSERV EDUCAUSE EDU> <SECURITY () LISTSERV EDUCAUSE 
EDU<mailto:SECURITY () LISTSERV EDUCAUSE EDU>>
Subject: Re: [SECURITY] Ransomware Playbook

Caution: This email originated from outside the university.
Do not click on links, open attachments, or reply unless you recognize the sender and know the content is safe. If you 
have questions about this email please forward it to cwuservicedesk () cwu edu<mailto:cwuservicedesk () cwu edu>.



John,
  My thanks and I would appreciate copies as well.

Craig


Craig Oberlin, CISSP
Sr. Director IT, Users Services & Chief Information Security Officer Coast Community College District P 714.438.6808 
coberlin1 () cccd edu<mailto:coberlin1 () cccd edu>
[coast]



From: The EDUCAUSE Security Community Group Listserv [mailto:SECURITY () LISTSERV EDUCAUSE EDU] On Behalf Of Babak 
Oskouian
Sent: Friday, October 4, 2019 9:49 AM
To: SECURITY () LISTSERV EDUCAUSE EDU<mailto:SECURITY () LISTSERV EDUCAUSE EDU>
Subject: Re: [SECURITY] Ransomware Playbook

Hi John,

It goes without saying that you and your team must have done a tremendous amount of work to put these playbooks 
together and it is very generous of you to be willing to share them with the community.

So, thank you very much indeed.

Babak


Babak Oskouian, Ph.D. | Director of Networking and Infrastructure

Mills College | 5000 MacArthur Blvd | Oakland, CA 94613-1301

Office: Stern Hall 007; Phone: 510-430-2224 <tel:510-430-2224>




On Fri, Oct 4, 2019 at 4:47 AM John Ramsey <jramsey () studentclearinghouse org<mailto:jramsey () studentclearinghouse 
org>> wrote:
Everybody,

The interest in playbooks, especially ransomware, is great to see (as playbooks are time consuming to create and there 
aren't enough hours in the day as it is).  I've been through a few ransomware incidents, so the playbook is battle 
ready.  However, as some have pointed out, you'll want to customize to your organization where applicable.  When my 
team creates playbooks, our goal is to keep it simple and flexible and easy to follow (versus flipping back and forth 
as you might in a plan.)  The first page is almost always how to easily and quickly contain and then triage.  Once that 
is done, the rest is post event activities.  If you have any questions, please don't hesitate to ask me.  Since the NSC 
is a third-party service provider for most of you, I'm happy to share what we're doing in order to further gain your 
confidence in our processes to protect your data.  At the end of the day, we're one team!

We also have other playbooks that I'm happy to share (maybe it makes sense for Educause or REN-ISAC or both to post 
what all of us are willing to share amongst ourselves.  Then we'll have a pretty robust set to select from and modify 
as appropriate).  Here are some others that we have finalized:


  1.  Notifications and Escalations Playbook.  This walks through the first six hours of an incident in 30-minute 
increments indicating what each stakeholder is doing as well as what message gets communicated and to whom.
  2.  DDOS Playbook.  Being one of the top attacks in the Education industry, this was one of the first ones we did.  
Internet 2 was kind enough to provide some guidance on the playbook (which we incorporated.)
  3.  Foreign Travel Playbook.  Actions we take when somebody travels overseas and has the requirement to take a 
company device.
  4.  Incident Handling Checklists/Chains of Custody forms.
  5.  Network Compromise Playbook.
  6.  Spoofed URL Playbook.

John

John Ramsey, Chief Information Security Officer, National Student Clearinghouse
Certified:  CISSP, CISM, PMP, CSSLP, CRISC, CGEIT
2300 Dulles Station Blvd., Suite 220, Herndon, VA 20171
P: 703.742.4428  |   
https://nam02.safelinks.protection.outlook.com/?url=https%3A%2F%2Furldefense.proofpoint.com%2Fv2%2Furl%3Fu%3Dhttp-3A__www.studentclearinghouse.org%26d%3DDwIFaQ%26c%3DodzYs1kPF7h99M0Vn1uLzg%26r%3DjKMTIfZiBnBYrk_cRkqhrq0vZwXKksqj0lGxPgjosOo%26m%3DPCH4pSQdJHnemwXCid22jVtPnrEXBJK3q7fAp2ujQXk%26s%3DDYLwvVGFZ86lTat6NxteKGY0Nal1lJiGpnys2patNJA%26e&amp;data=02%7C01%7Cwferland%40ccri.edu%7C7031cfce83124235a2b008d79e97786b%7Caf75351b37eb4405bf7a7327cec380a5%7C0%7C0%7C637152245732186547&amp;sdata=E%2Fnq8NR2t9kPiGzOWihzMlZTwQmDpzX5RqOXgEi7y%2FI%3D&amp;reserved=0=
 
<https://nam02.safelinks.protection.outlook.com/?url=https%3A%2F%2Furldefense.proofpoint.com%2Fv2%2Furl%3Fu%3Dhttp-3A__www.studentclearinghouse.org_%26d%3DDwMFaQ%26c%3DfH4LSaxSgjWoCqli9ejpOKSimqfdcqwvdi9ZfjV67eI%26r%3DL2JLRtXHlhmcrIANbzJ5bJIItX7BypJgN7IAY1kklS0%26m%3D0-1lrb9bNf5O_UNDlxFb2Xqz31Z6UafxAW4sVo70TsY%26s%3D6KKsFoIKTYgAD7pi6C5TjYlGRwjXxnpP9eNEoUg6tCk%26e&amp;data=02%7C01%7Cwferland%40ccri.edu%7C7031cfce83124235a2b008d79e97786b%7Caf75351b37eb4405bf7a7327cec380a5%7C0%7C0%7C637152245732186547&amp;sdata=e1hklCSmYkruhsxHuGNtmKlBG%2FtnIU5rWUde0Vp0njw%3D&amp;reserved=0=>
Read the Clearinghouse Today 
Blog<https://nam02.safelinks.protection.outlook.com/?url=https%3A%2F%2Furldefense.proofpoint.com%2Fv2%2Furl%3Fu%3Dhttps-3A__nscblog.org_%26d%3DDwMFaQ%26c%3DfH4LSaxSgjWoCqli9ejpOKSimqfdcqwvdi9ZfjV67eI%26r%3DL2JLRtXHlhmcrIANbzJ5bJIItX7BypJgN7IAY1kklS0%26m%3D0-1lrb9bNf5O_UNDlxFb2Xqz31Z6UafxAW4sVo70TsY%26s%3Dbr2kQUxQhQEaZoZzMS3ZTNXObY1JGi_7GUtwR3uC7kg%26e&amp;data=02%7C01%7Cwferland%40ccri.edu%7C7031cfce83124235a2b008d79e97786b%7Caf75351b37eb4405bf7a7327cec380a5%7C0%7C0%7C637152245732186547&amp;sdata=5V5Q0uE0LPZCzYdb3LZMXtg9Ti9b%2FVIqt%2BtZYLNz2NA%3D&amp;reserved=0=>

Winner "2016 When Work Works" & "Excellence in Work-Life Balance"


**********
Replies to EDUCAUSE Community Group emails are sent to the entire community list. If you want to reply only to the 
person who sent the message, copy and paste their email address and forward the email reply. Additional participation 
and subscription information can be found at 
https://nam02.safelinks.protection.outlook.com/?url=https%3A%2F%2Furldefense.proofpoint.com%2Fv2%2Furl%3Fu%3Dhttps-3A__www.educause.edu_community%26d%3DDwIFaQ%26c%3DodzYs1kPF7h99M0Vn1uLzg%26r%3DjKMTIfZiBnBYrk_cRkqhrq0vZwXKksqj0lGxPgjosOo%26m%3DPCH4pSQdJHnemwXCid22jVtPnrEXBJK3q7fAp2ujQXk%26s%3DipDfAu95YytXt6pdbXXudY9CcmGpIRo-e8vMZATurtU%26e&amp;data=02%7C01%7Cwferland%40ccri.edu%7C7031cfce83124235a2b008d79e97786b%7Caf75351b37eb4405bf7a7327cec380a5%7C0%7C0%7C637152245732186547&amp;sdata=ZhHbjJ%2F994qHsAD6wWXWd2vpjTS%2FCtq6VBV6lyIf4UE%3D&amp;reserved=0=
 
<https://nam02.safelinks.protection.outlook.com/?url=https%3A%2F%2Furldefense.proofpoint.com%2Fv2%2Furl%3Fu%3Dhttps-3A__www.educause.edu_community%26d%3DDwMFaQ%26c%3DfH4LSaxSgjWoCqli9ejpOKSimqfdcqwvdi9ZfjV67eI%26r%3DL2JLRtXHlhmcrIANbzJ5bJIItX7BypJgN7IAY1kklS0%26m%3D0-1lrb9bNf5O_UNDlxFb2Xqz31Z6UafxAW4sVo70TsY%26s%3DDhYpkgwVTyvpma9kqNW0oPJOoD9fGCjPJNYoFsmlsjU%26e&amp;data=02%7C01%7Cwferland%40ccri.edu%7C7031cfce83124235a2b008d79e97786b%7Caf75351b37eb4405bf7a7327cec380a5%7C0%7C0%7C637152245732196539&amp;sdata=jcb0oL4b9I%2BhTC3xQmWaRn8ZFuMREUlbsiGiRHq0Svw%3D&amp;reserved=0=>
-------------------------------------------------------------------------------------
*** NOTICE *** This message was sent from an external sender and did not originate from Coast Community College 
District. If you are unsure of the authenticity of the sender, DO NOT click any links or download any attachments. 
Instead, click on FORWARD and address to phishing

**********
Replies to EDUCAUSE Community Group emails are sent to the entire community list. If you want to reply only to the 
person who sent the message, copy and paste their email address and forward the email reply. Additional participation 
and subscription information can be found at 
https://nam02.safelinks.protection.outlook.com/?url=https%3A%2F%2Furldefense.proofpoint.com%2Fv2%2Furl%3Fu%3Dhttps-3A__www.educause.edu_community%26d%3DDwIFaQ%26c%3DodzYs1kPF7h99M0Vn1uLzg%26r%3DjKMTIfZiBnBYrk_cRkqhrq0vZwXKksqj0lGxPgjosOo%26m%3DPCH4pSQdJHnemwXCid22jVtPnrEXBJK3q7fAp2ujQXk%26s%3DipDfAu95YytXt6pdbXXudY9CcmGpIRo-e8vMZATurtU%26e&amp;data=02%7C01%7Cwferland%40ccri.edu%7C7031cfce83124235a2b008d79e97786b%7Caf75351b37eb4405bf7a7327cec380a5%7C0%7C0%7C637152245732196539&amp;sdata=ii%2ByQmKmfizyDuIX%2FxN8io1FxYBV8nVCsTnt1jvUmKg%3D&amp;reserved=0=

**********
Replies to EDUCAUSE Community Group emails are sent to the entire community list. If you want to reply only to the 
person who sent the message, copy and paste their email address and forward the email reply. Additional participation 
and subscription information can be found at 
https://nam02.safelinks.protection.outlook.com/?url=https%3A%2F%2Furldefense.proofpoint.com%2Fv2%2Furl%3Fu%3Dhttps-3A__www.educause.edu_community%26d%3DDwIFaQ%26c%3DodzYs1kPF7h99M0Vn1uLzg%26r%3DjKMTIfZiBnBYrk_cRkqhrq0vZwXKksqj0lGxPgjosOo%26m%3DPCH4pSQdJHnemwXCid22jVtPnrEXBJK3q7fAp2ujQXk%26s%3DipDfAu95YytXt6pdbXXudY9CcmGpIRo-e8vMZATurtU%26e&amp;data=02%7C01%7Cwferland%40ccri.edu%7C7031cfce83124235a2b008d79e97786b%7Caf75351b37eb4405bf7a7327cec380a5%7C0%7C0%7C637152245732196539&amp;sdata=ii%2ByQmKmfizyDuIX%2FxN8io1FxYBV8nVCsTnt1jvUmKg%3D&amp;reserved=0=

**********
Replies to EDUCAUSE Community Group emails are sent to the entire community list. If you want to reply only to the 
person who sent the message, copy and paste their email address and forward the email reply. Additional participation 
and subscription information can be found at 
https://nam02.safelinks.protection.outlook.com/?url=https%3A%2F%2Furldefense.proofpoint.com%2Fv2%2Furl%3Fu%3Dhttps-3A__www.educause.edu_community%26d%3DDwIFaQ%26c%3DodzYs1kPF7h99M0Vn1uLzg%26r%3DjKMTIfZiBnBYrk_cRkqhrq0vZwXKksqj0lGxPgjosOo%26m%3DPCH4pSQdJHnemwXCid22jVtPnrEXBJK3q7fAp2ujQXk%26s%3DipDfAu95YytXt6pdbXXudY9CcmGpIRo-e8vMZATurtU%26e&amp;data=02%7C01%7Cwferland%40ccri.edu%7C7031cfce83124235a2b008d79e97786b%7Caf75351b37eb4405bf7a7327cec380a5%7C0%7C0%7C637152245732196539&amp;sdata=ii%2ByQmKmfizyDuIX%2FxN8io1FxYBV8nVCsTnt1jvUmKg%3D&amp;reserved=0=

------------------------------

Date:    Tue, 14 Jan 2020 08:15:05 -0800
From:    Francisco Chavez <fac3 () STMARYS-CA EDU>
Subject: Re: Ransomware Playbook

Paul,

It is available here.

https://nam02.safelinks.protection.outlook.com/?url=https%3A%2F%2Furldefense.proofpoint.com%2Fv2%2Furl%3Fu%3Dhttps-3A__library.educause.edu_resources_2019_10_national-2Dstudent-2Dclearinghouse-2Dplaybooks%26d%3DDwIFaQ%26c%3DodzYs1kPF7h99M0Vn1uLzg%26r%3DjKMTIfZiBnBYrk_cRkqhrq0vZwXKksqj0lGxPgjosOo%26m%3DPCH4pSQdJHnemwXCid22jVtPnrEXBJK3q7fAp2ujQXk%26s%3DeqI_Z2l1fOW2w2EIp5wHWcEClPv1e2GcoSoXfksZ7bs%26e&amp;data=02%7C01%7Cwferland%40ccri.edu%7C7031cfce83124235a2b008d79e97786b%7Caf75351b37eb4405bf7a7327cec380a5%7C0%7C0%7C637152245732196539&amp;sdata=LQ5BbXPr%2BYd7LclhbbsS01W%2FFVACTcKr7o%2BMIA4EF%2BI%3D&amp;reserved=0=
  
<https://nam02.safelinks.protection.outlook.com/?url=https%3A%2F%2Furldefense.proofpoint.com%2Fv2%2Furl%3Fu%3Dhttps-3A__library.educause.edu_resources_2019_10_national-2Dstudent-2Dclearinghouse-2Dplaybooks%26d%3DDwIFaQ%26c%3DodzYs1kPF7h99M0Vn1uLzg%26r%3DjKMTIfZiBnBYrk_cRkqhrq0vZwXKksqj0lGxPgjosOo%26m%3DPCH4pSQdJHnemwXCid22jVtPnrEXBJK3q7fAp2ujQXk%26s%3DeqI_Z2l1fOW2w2EIp5wHWcEClPv1e2GcoSoXfksZ7bs%26e&amp;data=02%7C01%7Cwferland%40ccri.edu%7C7031cfce83124235a2b008d79e97786b%7Caf75351b37eb4405bf7a7327cec380a5%7C0%7C0%7C637152245732206538&amp;sdata=qvNOv7VqCKqqtTBI9jbQD9xg%2FnIExo3XyRmvbEkNd2I%3D&amp;reserved=0=



Regards,
Francisco Chavez






Manager - IT Security
fac3 () stmarys-ca edu <mailto:fac3 () stmarys-ca edu>
Office: (925) 631-8236




On Jan 14, 2020, at 8:00 AM, Paul Usama <paul.usama () SAIT CA> wrote:

Hi,

Am not sure if this is still shared, I am interested in the Ransomware Playbook.


<image002.jpg>
Paul Usama
Information Security Analyst
Information Technology Services

Southern Alberta Institute of Technology E.H. Crandell, G200
1301 – 16 Avenue NW, Calgary AB, T2M 0L4
(Cell) 403.836.3489 (Ph) 403.284.8328
Paul.Usama () sait ca <mailto:Paul.Usama () sait ca>







From: The EDUCAUSE Security Community Group Listserv
<SECURITY () LISTSERV EDUCAUSE EDU
<mailto:SECURITY () LISTSERV EDUCAUSE EDU>> On Behalf Of Jamie Schademan
Sent: Friday, October 4, 2019 11:08 AM
To: SECURITY () LISTSERV EDUCAUSE EDU
<mailto:SECURITY () LISTSERV EDUCAUSE EDU>
Subject: Re: [SECURITY] Ransomware Playbook

Me too please.
Jamie
CWU

Jamie Schademan, CISM
Chief Information Security Officer
CWU

From: The EDUCAUSE Security Community Group Listserv
<SECURITY () LISTSERV EDUCAUSE EDU
<mailto:SECURITY () LISTSERV EDUCAUSE EDU>> on behalf of Oberlin, Craig
<coberlin1 () CCCD EDU <mailto:coberlin1 () CCCD EDU>>
Sent: Friday, October 4, 2019 11:03:02 AM
To: SECURITY () LISTSERV EDUCAUSE EDU
<mailto:SECURITY () LISTSERV EDUCAUSE EDU>
<SECURITY () LISTSERV EDUCAUSE EDU
<mailto:SECURITY () LISTSERV EDUCAUSE EDU>>
Subject: Re: [SECURITY] Ransomware Playbook

Caution: This email originated from outside the university.
Do not click on links, open attachments, or reply unless you recognize the sender and know the content is safe. If 
you have questions about this email please forward it tocwuservicedesk () cwu edu <mailto:cwuservicedesk () cwu edu>.




John,
  My thanks and I would appreciate copies as well.

Craig


Craig Oberlin, CISSP
Sr. Director IT, Users Services & Chief Information Security Officer
Coast Community College District P 714.438.6808 coberlin1 () cccd edu
<mailto:coberlin1 () cccd edu> <image001.png>



From: The EDUCAUSE Security Community Group Listserv
[mailto:SECURITY () LISTSERV EDUCAUSE EDU
<mailto:SECURITY () LISTSERV EDUCAUSE EDU>] On Behalf Of Babak Oskouian
Sent: Friday, October 4, 2019 9:49 AM
To: SECURITY () LISTSERV EDUCAUSE EDU
<mailto:SECURITY () LISTSERV EDUCAUSE EDU>
Subject: Re: [SECURITY] Ransomware Playbook

Hi John,

It goes without saying that you and your team must have done a tremendous amount of work to put these playbooks 
together and it is very generous of you to be willing to share them with the community.

So, thank you very much indeed.

Babak

Babak Oskouian, Ph.D. | Director of Networking and Infrastructure
Mills College | 5000 MacArthur Blvd | Oakland, CA 94613-1301
Office: Stern Hall 007; Phone: 510-430-2224  <tel:510-430-2224>



On Fri, Oct 4, 2019 at 4:47 AM John Ramsey <jramsey () studentclearinghouse org <mailto:jramsey () 
studentclearinghouse org>> wrote:
Everybody,

The interest in playbooks, especially ransomware, is great to see (as playbooks are time consuming to create and 
there aren’t enough hours in the day as it is).  I’ve been through a few ransomware incidents, so the playbook is 
battle ready.  However, as some have pointed out, you’ll want to customize to your organization where applicable.  
When my team creates playbooks, our goal is to keep it simple and flexible and easy to follow (versus flipping back 
and forth as you might in a plan.)  The first page is almost always how to easily and quickly contain and then 
triage.  Once that is done, the rest is post event activities.  If you have any questions, please don’t hesitate to 
ask me.  Since the NSC is a third-party service provider for most of you, I’m happy to share what we’re doing in 
order to further gain your confidence in our processes to protect your data.  At the end of the day, we’re one team!

We also have other playbooks that I’m happy to share (maybe it makes sense for Educause or REN-ISAC or both to post 
what all of us are willing to share amongst ourselves.  Then we’ll have a pretty robust set to select from and modify 
as appropriate).  Here are some others that we have finalized:

Notifications and Escalations Playbook.  This walks through the first six hours of an incident in 30-minute 
increments indicating what each stakeholder is doing as well as what message gets communicated and to whom.
DDOS Playbook.  Being one of the top attacks in the Education
industry, this was one of the first ones we did.  Internet 2 was kind enough to provide some guidance on the playbook 
(which we incorporated.) Foreign Travel Playbook.  Actions we take when somebody travels overseas and has the 
requirement to take a company device.
Incident Handling Checklists/Chains of Custody forms.
Network Compromise Playbook.
Spoofed URL Playbook.

John

John Ramsey, Chief Information Security Officer, National Student
Clearinghouse
Certified:  CISSP, CISM, PMP, CSSLP, CRISC, CGEIT
2300 Dulles Station Blvd., Suite 220, Herndon, VA 20171
P: 703.742.4428  |   
https://nam02.safelinks.protection.outlook.com/?url=https%3A%2F%2Furldefense.proofpoint.com%2Fv2%2Furl%3Fu%3Dhttp-3A__www.studentclearinghouse.org%26d%3DDwIFaQ%26c%3DodzYs1kPF7h99M0Vn1uLzg%26r%3DjKMTIfZiBnBYrk_cRkqhrq0vZwXKksqj0lGxPgjosOo%26m%3DPCH4pSQdJHnemwXCid22jVtPnrEXBJK3q7fAp2ujQXk%26s%3DDYLwvVGFZ86lTat6NxteKGY0Nal1lJiGpnys2patNJA%26e&amp;data=02%7C01%7Cwferland%40ccri.edu%7C7031cfce83124235a2b008d79e97786b%7Caf75351b37eb4405bf7a7327cec380a5%7C0%7C0%7C637152245732206538&amp;sdata=PbvajthWB9mHR%2BLx3XeK%2B4X5jUbghXIScDl8N1uGbEE%3D&amp;reserved=0=
  
<https://nam02.safelinks.protection.outlook.com/?url=https%3A%2F%2Furldefense.proofpoint.com%2Fv2%2Furl%3Fu%3Dhttp-3A__www.studentclearinghouse.org_%26d%3DDwMFaQ%26c%3DfH4LSaxSgjWoCqli9ejpOKSimqfdcqwvdi9ZfjV67eI%26r%3DL2JLRtXHlhmcrIANbzJ5bJIItX7BypJgN7IAY1kklS0%26m%3D0-1lrb9bNf5O_UNDlxFb2Xqz31Z6UafxAW4sVo70TsY%26s%3D6KKsFoIKTYgAD7pi6C5TjYlGRwjXxnpP9eNEoUg6tCk%26e&amp;data=02%7C01%7Cwferland%40ccri.edu%7C7031cfce83124235a2b008d79e97786b%7Caf75351b37eb4405bf7a7327cec380a5%7C0%7C0%7C637152245732206538&amp;sdata=rg0FXpjsW14th2Thx%2BGXDvRxULrzDHUakmgrKpzfu9Y%3D&amp;reserved=0=>
Read the Clearinghouse Today Blog
<https://nam02.safelinks.protection.outlook.com/?url=https%3A%2F%2Furldefense.proofpoint.com%2Fv2%2Furl%3Fu%3Dhttps-3A__nscblog.org_%26d%3DD&amp;data=02%7C01%7Cwferland%40ccri.edu%7C7031cfce83124235a2b008d79e97786b%7Caf75351b37eb4405bf7a7327cec380a5%7C0%7C0%7C637152245732206538&amp;sdata=QdFSXcVKw%2BuEJU1uSrG207IqKcrH0M4%2BrpO2p%2FbsvVc%3D&amp;reserved=0
wMFaQ&c=fH4LSaxSgjWoCqli9ejpOKSimqfdcqwvdi9ZfjV67eI&r=L2JLRtXHlhmcrIAN
bzJ5bJIItX7BypJgN7IAY1kklS0&m=0-1lrb9bNf5O_UNDlxFb2Xqz31Z6UafxAW4sVo70
TsY&s=br2kQUxQhQEaZoZzMS3ZTNXObY1JGi_7GUtwR3uC7kg&e=>

Winner “2016 When Work Works” & “Excellence in Work-Life Balance”


**********
Replies to EDUCAUSE Community Group emails are sent to the entire
community list. If you want to reply only to the person who sent the
message, copy and paste their email address and forward the email
reply. Additional participation and subscription information can be
found at
https://nam02.safelinks.protection.outlook.com/?url=https%3A%2F%2Furldefense.proofpoint.com%2Fv2%2Furl%3Fu%3Dhttps-3A__www.educause.edu_&amp;data=02%7C01%7Cwferland%40ccri.edu%7C7031cfce83124235a2b008d79e97786b%7Caf75351b37eb4405bf7a7327cec380a5%7C0%7C1%7C637152245732206538&amp;sdata=pmgTN%2FHnxfUoVBw306ei15zmDnYeiJcxIDf74Q7UiKU%3D&amp;reserved=0
community&d=DwIFaQ&c=odzYs1kPF7h99M0Vn1uLzg&r=jKMTIfZiBnBYrk_cRkqhrq0v
ZwXKksqj0lGxPgjosOo&m=PCH4pSQdJHnemwXCid22jVtPnrEXBJK3q7fAp2ujQXk&s=ip
DfAu95YytXt6pdbXXudY9CcmGpIRo-e8vMZATurtU&e=
<https://nam02.safelinks.protection.outlook.com/?url=https%3A%2F%2Furldefense.proofpoint.com%2Fv2%2Furl%3Fu%3Dhttps-3A__www.educause.edu&amp;data=02%7C01%7Cwferland%40ccri.edu%7C7031cfce83124235a2b008d79e97786b%7Caf75351b37eb4405bf7a7327cec380a5%7C0%7C1%7C637152245732216535&amp;sdata=GQ8WNgucPRde8rqZEEOAXyJvXlwPuarAxU31BPvltYc%3D&amp;reserved=0
_community&d=DwMFaQ&c=fH4LSaxSgjWoCqli9ejpOKSimqfdcqwvdi9ZfjV67eI&r=L2
JLRtXHlhmcrIANbzJ5bJIItX7BypJgN7IAY1kklS0&m=0-1lrb9bNf5O_UNDlxFb2Xqz31
Z6UafxAW4sVo70TsY&s=DhYpkgwVTyvpma9kqNW0oPJOoD9fGCjPJNYoFsmlsjU&e=>
----------------------------------------------------------------------
---------------
*** NOTICE *** This message was sent from an external sender and did
not originate from Coast Community College District. If you are unsure
of the authenticity of the sender, DO NOT click any links or download
any attachments. Instead, click on FORWARD and address to phishing
**********
Replies to EDUCAUSE Community Group emails are sent to the entire
community list. If you want to reply only to the person who sent the
message, copy and paste their email address and forward the email
reply. Additional participation and subscription information can be
found at
https://nam02.safelinks.protection.outlook.com/?url=https%3A%2F%2Furldefense.proofpoint.com%2Fv2%2Furl%3Fu%3Dhttps-3A__www.educause.edu_&amp;data=02%7C01%7Cwferland%40ccri.edu%7C7031cfce83124235a2b008d79e97786b%7Caf75351b37eb4405bf7a7327cec380a5%7C0%7C1%7C637152245732216535&amp;sdata=SiY%2FVi1lOW%2BAK43EOVEEp%2FRMUdIirOtJLuj8Js81qTs%3D&amp;reserved=0
community&d=DwIFaQ&c=odzYs1kPF7h99M0Vn1uLzg&r=jKMTIfZiBnBYrk_cRkqhrq0v
ZwXKksqj0lGxPgjosOo&m=PCH4pSQdJHnemwXCid22jVtPnrEXBJK3q7fAp2ujQXk&s=ip
DfAu95YytXt6pdbXXudY9CcmGpIRo-e8vMZATurtU&e=
<https://nam02.safelinks.protection.outlook.com/?url=https%3A%2F%2Furldefense.proofpoint.com%2Fv2%2Furl%3Fu%3Dhttps-3A__www.educause.edu&amp;data=02%7C01%7Cwferland%40ccri.edu%7C7031cfce83124235a2b008d79e97786b%7Caf75351b37eb4405bf7a7327cec380a5%7C0%7C1%7C637152245732216535&amp;sdata=GQ8WNgucPRde8rqZEEOAXyJvXlwPuarAxU31BPvltYc%3D&amp;reserved=0
_community&d=DwIFaQ&c=odzYs1kPF7h99M0Vn1uLzg&r=jKMTIfZiBnBYrk_cRkqhrq0
vZwXKksqj0lGxPgjosOo&m=PCH4pSQdJHnemwXCid22jVtPnrEXBJK3q7fAp2ujQXk&s=i
pDfAu95YytXt6pdbXXudY9CcmGpIRo-e8vMZATurtU&e= >
**********
Replies to EDUCAUSE Community Group emails are sent to the entire
community list. If you want to reply only to the person who sent the
message, copy and paste their email address and forward the email
reply. Additional participation and subscription information can be
found at
https://nam02.safelinks.protection.outlook.com/?url=https%3A%2F%2Furldefense.proofpoint.com%2Fv2%2Furl%3Fu%3Dhttps-3A__www.educause.edu_&amp;data=02%7C01%7Cwferland%40ccri.edu%7C7031cfce83124235a2b008d79e97786b%7Caf75351b37eb4405bf7a7327cec380a5%7C0%7C1%7C637152245732216535&amp;sdata=SiY%2FVi1lOW%2BAK43EOVEEp%2FRMUdIirOtJLuj8Js81qTs%3D&amp;reserved=0
community&d=DwIFaQ&c=odzYs1kPF7h99M0Vn1uLzg&r=jKMTIfZiBnBYrk_cRkqhrq0v
ZwXKksqj0lGxPgjosOo&m=PCH4pSQdJHnemwXCid22jVtPnrEXBJK3q7fAp2ujQXk&s=ip
DfAu95YytXt6pdbXXudY9CcmGpIRo-e8vMZATurtU&e=
<https://nam02.safelinks.protection.outlook.com/?url=https%3A%2F%2Furldefense.proofpoint.com%2Fv2%2Furl%3Fu%3Dhttps-3A__www.educause.edu&amp;data=02%7C01%7Cwferland%40ccri.edu%7C7031cfce83124235a2b008d79e97786b%7Caf75351b37eb4405bf7a7327cec380a5%7C0%7C1%7C637152245732216535&amp;sdata=GQ8WNgucPRde8rqZEEOAXyJvXlwPuarAxU31BPvltYc%3D&amp;reserved=0
_community&d=DwIFaQ&c=odzYs1kPF7h99M0Vn1uLzg&r=jKMTIfZiBnBYrk_cRkqhrq0
vZwXKksqj0lGxPgjosOo&m=PCH4pSQdJHnemwXCid22jVtPnrEXBJK3q7fAp2ujQXk&s=i
pDfAu95YytXt6pdbXXudY9CcmGpIRo-e8vMZATurtU&e= >
**********
Replies to EDUCAUSE Community Group emails are sent to the entire
community list. If you want to reply only to the person who sent the
message, copy and paste their email address and forward the email
reply. Additional participation and subscription information can be
found at
https://nam02.safelinks.protection.outlook.com/?url=https%3A%2F%2Furldefense.proofpoint.com%2Fv2%2Furl%3Fu%3Dhttps-3A__www.educause.edu_&amp;data=02%7C01%7Cwferland%40ccri.edu%7C7031cfce83124235a2b008d79e97786b%7Caf75351b37eb4405bf7a7327cec380a5%7C0%7C1%7C637152245732216535&amp;sdata=SiY%2FVi1lOW%2BAK43EOVEEp%2FRMUdIirOtJLuj8Js81qTs%3D&amp;reserved=0
community&d=DwIFaQ&c=odzYs1kPF7h99M0Vn1uLzg&r=jKMTIfZiBnBYrk_cRkqhrq0v
ZwXKksqj0lGxPgjosOo&m=PCH4pSQdJHnemwXCid22jVtPnrEXBJK3q7fAp2ujQXk&s=ip
DfAu95YytXt6pdbXXudY9CcmGpIRo-e8vMZATurtU&e=
<https://nam02.safelinks.protection.outlook.com/?url=https%3A%2F%2Furldefense.proofpoint.com%2Fv2%2Furl%3Fu%3Dhttps-3A__www.educause.edu&amp;data=02%7C01%7Cwferland%40ccri.edu%7C7031cfce83124235a2b008d79e97786b%7Caf75351b37eb4405bf7a7327cec380a5%7C0%7C1%7C637152245732216535&amp;sdata=GQ8WNgucPRde8rqZEEOAXyJvXlwPuarAxU31BPvltYc%3D&amp;reserved=0
_community&d=DwIFaQ&c=odzYs1kPF7h99M0Vn1uLzg&r=jKMTIfZiBnBYrk_cRkqhrq0
vZwXKksqj0lGxPgjosOo&m=PCH4pSQdJHnemwXCid22jVtPnrEXBJK3q7fAp2ujQXk&s=i
pDfAu95YytXt6pdbXXudY9CcmGpIRo-e8vMZATurtU&e= >

**********
Replies to EDUCAUSE Community Group emails are sent to the entire community list. If you want to reply only to the 
person who sent the message, copy and paste their email address and forward the email reply. Additional participation 
and subscription information can be found at 
https://nam02.safelinks.protection.outlook.com/?url=https%3A%2F%2Furldefense.proofpoint.com%2Fv2%2Furl%3Fu%3Dhttps-3A__www.educause.edu_community%26d%3DDwIFaQ%26c%3DodzYs1kPF7h99M0Vn1uLzg%26r%3DjKMTIfZiBnBYrk_cRkqhrq0vZwXKksqj0lGxPgjosOo%26m%3DPCH4pSQdJHnemwXCid22jVtPnrEXBJK3q7fAp2ujQXk%26s%3DipDfAu95YytXt6pdbXXudY9CcmGpIRo-e8vMZATurtU%26e&amp;data=02%7C01%7Cwferland%40ccri.edu%7C7031cfce83124235a2b008d79e97786b%7Caf75351b37eb4405bf7a7327cec380a5%7C0%7C0%7C637152245732226521&amp;sdata=51ra58EVnODmZGEz0YwJ1G8p%2BVfxbs9W7omGbKhQD6E%3D&amp;reserved=0=

------------------------------

Date:    Tue, 14 Jan 2020 17:18:15 +0000
From:    John Ramsey <jramsey () STUDENTCLEARINGHOUSE ORG>
Subject: Re: Ransomware Playbook

I’m also working on getting clearance to share a few more.

John Ramsey, Chief Information Security Officer, National Student Clearinghouse
Certified:  CISSP, CISM, PMP, CSSLP, CRISC, CGEIT
2300 Dulles Station Blvd., Suite 220, Herndon, VA 20171
P: 703.742.4428  |   
https://nam02.safelinks.protection.outlook.com/?url=https%3A%2F%2Furldefense.proofpoint.com%2Fv2%2Furl%3Fu%3Dhttp-3A__www.studentclearinghouse.org%26d%3DDwIFaQ%26c%3DodzYs1kPF7h99M0Vn1uLzg%26r%3DjKMTIfZiBnBYrk_cRkqhrq0vZwXKksqj0lGxPgjosOo%26m%3DPCH4pSQdJHnemwXCid22jVtPnrEXBJK3q7fAp2ujQXk%26s%3DDYLwvVGFZ86lTat6NxteKGY0Nal1lJiGpnys2patNJA%26e&amp;data=02%7C01%7Cwferland%40ccri.edu%7C7031cfce83124235a2b008d79e97786b%7Caf75351b37eb4405bf7a7327cec380a5%7C0%7C0%7C637152245732226521&amp;sdata=vSEA13DPJlu0aAdU75QXlXt1FnbJCPtffPw1C%2FF738I%3D&amp;reserved=0=
 
<https://nam02.safelinks.protection.outlook.com/?url=https%3A%2F%2Furldefense.proofpoint.com%2Fv2%2Furl%3Fu%3Dhttps-3A__nam01.safelinks.protection.outlook.com_-3Furl-3Dhttp-253A-252F-252Fwww.studentclearinghouse.org-252F-26data-3D02-257C01-257Cjramsey-2540studentclearinghouse.org-257Cb9a990ac212442f4966708d7307ccb81-257C8cc02fea054043a688b6069d3eac0119-257C0-257C1-257C637031184868460784-26sdata-3Drnlj9A1ay7hmHTLXDAE0sESGGvBVWkPDO3NekqwvRIM-253D-26reserved-3D0%26d%3DDwIFaQ%26c%3DodzYs1kPF7h99M0Vn1uLzg%26r%3DjKMTIfZiBnBYrk_cRkqhrq0vZwXKksqj0lGxPgjosOo%26m%3DPCH4pSQdJHnemwXCid22jVtPnrEXBJK3q7fAp2ujQXk%26s%3DisxmLtWHwPT0BWzVHGGwHyGPHa8rYjnKJp0m2m-ArcQ%26e&amp;data=02%7C01%7Cwferland%40ccri.edu%7C7031cfce83124235a2b008d79e97786b%7Caf75351b37eb4405bf7a7327cec380a5%7C0%7C0%7C637152245732226521&amp;sdata=eY2e9t469P1ZWT47fYOJNrWKLS1XMcEePhbbKUOIpUs%3D&amp;reserved=0=

Read the Clearinghouse Today 
Blog<https://nam02.safelinks.protection.outlook.com/?url=https%3A%2F%2Furldefense.proofpoint.com%2Fv2%2Furl%3Fu%3Dhttps-3A__nam01.safelinks.protection.outlook.com_-3Furl-3Dhttps-253A-252F-252Fnscblog.org-252F-26data-3D02-257C01-257Cjramsey-2540studentclearinghouse.org-257Cb9a990ac212442f4966708d7307ccb81-257C8cc02fea054043a688b6069d3eac0119-257C0-257C1-257C637031184868460784-26sdata-3D-252BIijkuOIRKNNuBeLyoZeeSAuxkRsldvCfMOFWXWf7wQ-253D-26reserved-3D0%26d%3DDwIFaQ%26c%3DodzYs1kPF7h99M0Vn1uLzg%26r%3DjKMTIfZiBnBYrk_cRkqhrq0vZwXKksqj0lGxPgjosOo%26m%3DPCH4pSQdJHnemwXCid22jVtPnrEXBJK3q7fAp2ujQXk%26s%3DCMq-EIOtSC1ux1H4UmdrlvwTUa7W5JdqF0EgRnromG0%26e&amp;data=02%7C01%7Cwferland%40ccri.edu%7C7031cfce83124235a2b008d79e97786b%7Caf75351b37eb4405bf7a7327cec380a5%7C0%7C0%7C637152245732226521&amp;sdata=%2B4cNw0TMg9yyjbuek5T%2FhfbOSu%2FVUVZjfrDf04tiIMI%3D&amp;reserved=0=


Winner “2016 When Work Works” & “Excellence in Work-Life Balance”

From: The EDUCAUSE Security Community Group Listserv <SECURITY () LISTSERV EDUCAUSE EDU> On Behalf Of Francisco Chavez
Sent: Tuesday, January 14, 2020 11:15 AM
To: SECURITY () LISTSERV EDUCAUSE EDU
Subject: Re: [SECURITY] Ransomware Playbook

Paul,

It is available here.

https://nam02.safelinks.protection.outlook.com/?url=https%3A%2F%2Furldefense.proofpoint.com%2Fv2%2Furl%3Fu%3Dhttps-3A__library.educause.edu_resources_2019_10_national-2Dstudent-2Dclearinghouse-2Dplaybooks%26d%3DDwIFaQ%26c%3DodzYs1kPF7h99M0Vn1uLzg%26r%3DjKMTIfZiBnBYrk_cRkqhrq0vZwXKksqj0lGxPgjosOo%26m%3DPCH4pSQdJHnemwXCid22jVtPnrEXBJK3q7fAp2ujQXk%26s%3DeqI_Z2l1fOW2w2EIp5wHWcEClPv1e2GcoSoXfksZ7bs%26e&amp;data=02%7C01%7Cwferland%40ccri.edu%7C7031cfce83124235a2b008d79e97786b%7Caf75351b37eb4405bf7a7327cec380a5%7C0%7C0%7C637152245732236515&amp;sdata=U%2BEuZ1yWtL35%2Fn1CNgLjtjo2dzHKLlcceyEgvDcgNh0%3D&amp;reserved=0=


Regards,
Francisco Chavez



[cid:image001.jpg@01D5CAD4.B18F1740]


Manager - IT Security
fac3 () stmarys-ca edu<mailto:fac3 () stmarys-ca edu>
Office: (925) 631-8236




On Jan 14, 2020, at 8:00 AM, Paul Usama <paul.usama () SAIT CA<mailto:paul.usama () SAIT CA>> wrote:

Hi,

Am not sure if this is still shared, I am interested in the Ransomware Playbook.


<image002.jpg>
Paul Usama
Information Security Analyst
Information Technology Services

Southern Alberta Institute of Technology E.H. Crandell, G200
1301 – 16 Avenue NW, Calgary AB, T2M 0L4
(Cell) 403.836.3489 (Ph) 403.284.8328
Paul.Usama () sait ca<mailto:Paul.Usama () sait ca>







From: The EDUCAUSE Security Community Group Listserv <SECURITY () LISTSERV EDUCAUSE EDU<mailto:SECURITY () LISTSERV 
EDUCAUSE EDU>> On Behalf Of Jamie Schademan
Sent: Friday, October 4, 2019 11:08 AM
To: SECURITY () LISTSERV EDUCAUSE EDU<mailto:SECURITY () LISTSERV EDUCAUSE EDU>
Subject: Re: [SECURITY] Ransomware Playbook

Me too please.
Jamie
CWU

Jamie Schademan, CISM
Chief Information Security Officer
CWU

________________________________
From: The EDUCAUSE Security Community Group Listserv <SECURITY () LISTSERV EDUCAUSE EDU<mailto:SECURITY () LISTSERV 
EDUCAUSE EDU>> on behalf of Oberlin, Craig <coberlin1 () CCCD EDU<mailto:coberlin1 () CCCD EDU>>
Sent: Friday, October 4, 2019 11:03:02 AM
To: SECURITY () LISTSERV EDUCAUSE EDU<mailto:SECURITY () LISTSERV EDUCAUSE EDU> <SECURITY () LISTSERV EDUCAUSE 
EDU<mailto:SECURITY () LISTSERV EDUCAUSE EDU>>
Subject: Re: [SECURITY] Ransomware Playbook

Caution: This email originated from outside the university.
Do not click on links, open attachments, or reply unless you recognize the sender and know the content is safe. If you 
have questions about this email please forward it tocwuservicedesk () cwu edu<mailto:cwuservicedesk () cwu edu>.




John,
  My thanks and I would appreciate copies as well.

Craig


Craig Oberlin, CISSP
Sr. Director IT, Users Services & Chief Information Security Officer Coast Community College District P 714.438.6808 
coberlin1 () cccd edu<mailto:coberlin1 () cccd edu>
<image001.png>



From: The EDUCAUSE Security Community Group Listserv [mailto:SECURITY () LISTSERV EDUCAUSE EDU] On Behalf Of Babak 
Oskouian
Sent: Friday, October 4, 2019 9:49 AM
To: SECURITY () LISTSERV EDUCAUSE EDU<mailto:SECURITY () LISTSERV EDUCAUSE EDU>
Subject: Re: [SECURITY] Ransomware Playbook

Hi John,

It goes without saying that you and your team must have done a tremendous amount of work to put these playbooks 
together and it is very generous of you to be willing to share them with the community.

So, thank you very much indeed.

Babak

Babak Oskouian, Ph.D. | Director of Networking and Infrastructure Mills College | 5000 MacArthur Blvd | Oakland, CA 
94613-1301
Office: Stern Hall 007; Phone: 510-430-2224 <tel:510-430-2224>



On Fri, Oct 4, 2019 at 4:47 AM John Ramsey <jramsey () studentclearinghouse org<mailto:jramsey () studentclearinghouse 
org>> wrote:
Everybody,

The interest in playbooks, especially ransomware, is great to see (as playbooks are time consuming to create and there 
aren’t enough hours in the day as it is).  I’ve been through a few ransomware incidents, so the playbook is battle 
ready.  However, as some have pointed out, you’ll want to customize to your organization where applicable.  When my 
team creates playbooks, our goal is to keep it simple and flexible and easy to follow (versus flipping back and forth 
as you might in a plan.)  The first page is almost always how to easily and quickly contain and then triage.  Once that 
is done, the rest is post event activities.  If you have any questions, please don’t hesitate to ask me.  Since the NSC 
is a third-party service provider for most of you, I’m happy to share what we’re doing in order to further gain your 
confidence in our processes to protect your data.  At the end of the day, we’re one team!

We also have other playbooks that I’m happy to share (maybe it makes sense for Educause or REN-ISAC or both to post 
what all of us are willing to share amongst ourselves.  Then we’ll have a pretty robust set to select from and modify 
as appropriate).  Here are some others that we have finalized:


  1.  Notifications and Escalations Playbook.  This walks through the first six hours of an incident in 30-minute 
increments indicating what each stakeholder is doing as well as what message gets communicated and to whom.
  2.  DDOS Playbook.  Being one of the top attacks in the Education industry, this was one of the first ones we did.  
Internet 2 was kind enough to provide some guidance on the playbook (which we incorporated.)
  3.  Foreign Travel Playbook.  Actions we take when somebody travels overseas and has the requirement to take a 
company device.
  4.  Incident Handling Checklists/Chains of Custody forms.
  5.  Network Compromise Playbook.
  6.  Spoofed URL Playbook.

John

John Ramsey, Chief Information Security Officer, National Student Clearinghouse
Certified:  CISSP, CISM, PMP, CSSLP, CRISC, CGEIT
2300 Dulles Station Blvd., Suite 220, Herndon, VA 20171
P: 703.742.4428  |   
https://nam02.safelinks.protection.outlook.com/?url=https%3A%2F%2Furldefense.proofpoint.com%2Fv2%2Furl%3Fu%3Dhttp-3A__www.studentclearinghouse.org%26d%3DDwIFaQ%26c%3DodzYs1kPF7h99M0Vn1uLzg%26r%3DjKMTIfZiBnBYrk_cRkqhrq0vZwXKksqj0lGxPgjosOo%26m%3DPCH4pSQdJHnemwXCid22jVtPnrEXBJK3q7fAp2ujQXk%26s%3DDYLwvVGFZ86lTat6NxteKGY0Nal1lJiGpnys2patNJA%26e&amp;data=02%7C01%7Cwferland%40ccri.edu%7C7031cfce83124235a2b008d79e97786b%7Caf75351b37eb4405bf7a7327cec380a5%7C0%7C0%7C637152245732236515&amp;sdata=LHBcKw6vwDY8CDHvdLO4%2F3ZHqMwlJfNb0J6kJPO4R%2Fg%3D&amp;reserved=0=
 
<https://nam02.safelinks.protection.outlook.com/?url=https%3A%2F%2Furldefense.proofpoint.com%2Fv2%2Furl%3Fu%3Dhttp-3A__www.studentclearinghouse.org_%26d%3DDwMFaQ%26c%3DfH4LSaxSgjWoCqli9ejpOKSimqfdcqwvdi9ZfjV67eI%26r%3DL2JLRtXHlhmcrIANbzJ5bJIItX7BypJgN7IAY1kklS0%26m%3D0-1lrb9bNf5O_UNDlxFb2Xqz31Z6UafxAW4sVo70TsY%26s%3D6KKsFoIKTYgAD7pi6C5TjYlGRwjXxnpP9eNEoUg6tCk%26e&amp;data=02%7C01%7Cwferland%40ccri.edu%7C7031cfce83124235a2b008d79e97786b%7Caf75351b37eb4405bf7a7327cec380a5%7C0%7C0%7C637152245732236515&amp;sdata=42pN8keVQ7EFCVC%2FE6bV4QG0c%2FlaiaL8UFasy%2BtAr8c%3D&amp;reserved=0=>
Read the Clearinghouse Today 
Blog<https://nam02.safelinks.protection.outlook.com/?url=https%3A%2F%2Furldefense.proofpoint.com%2Fv2%2Furl%3Fu%3Dhttps-3A__nscblog.org_%26d%3DDwMFaQ%26c%3DfH4LSaxSgjWoCqli9ejpOKSimqfdcqwvdi9ZfjV67eI%26r%3DL2JLRtXHlhmcrIANbzJ5bJIItX7BypJgN7IAY1kklS0%26m%3D0-1lrb9bNf5O_UNDlxFb2Xqz31Z6UafxAW4sVo70TsY%26s%3Dbr2kQUxQhQEaZoZzMS3ZTNXObY1JGi_7GUtwR3uC7kg%26e&amp;data=02%7C01%7Cwferland%40ccri.edu%7C7031cfce83124235a2b008d79e97786b%7Caf75351b37eb4405bf7a7327cec380a5%7C0%7C0%7C637152245732236515&amp;sdata=%2FH%2BR6pM%2FQ9YLATbwfNBoristF74iL%2BfDXKI7gsLx0sk%3D&amp;reserved=0=>

Winner “2016 When Work Works” & “Excellence in Work-Life Balance”

**********
Replies to EDUCAUSE Community Group emails are sent to the entire community list. If you want to reply only to the 
person who sent the message, copy and paste their email address and forward the email reply. Additional participation 
and subscription information can be found at 
https://nam02.safelinks.protection.outlook.com/?url=https%3A%2F%2Furldefense.proofpoint.com%2Fv2%2Furl%3Fu%3Dhttps-3A__www.educause.edu_community%26d%3DDwIFaQ%26c%3DodzYs1kPF7h99M0Vn1uLzg%26r%3DjKMTIfZiBnBYrk_cRkqhrq0vZwXKksqj0lGxPgjosOo%26m%3DPCH4pSQdJHnemwXCid22jVtPnrEXBJK3q7fAp2ujQXk%26s%3DipDfAu95YytXt6pdbXXudY9CcmGpIRo-e8vMZATurtU%26e&amp;data=02%7C01%7Cwferland%40ccri.edu%7C7031cfce83124235a2b008d79e97786b%7Caf75351b37eb4405bf7a7327cec380a5%7C0%7C0%7C637152245732246506&amp;sdata=T%2B74Tdh%2FoPD%2FpnJ98kipjDD6xySG1RuoI1DEW3X9mng%3D&amp;reserved=0=
 
<https://nam02.safelinks.protection.outlook.com/?url=https%3A%2F%2Furldefense.proofpoint.com%2Fv2%2Furl%3Fu%3Dhttps-3A__www.educause.edu_community%26d%3DDwMFaQ%26c%3DfH4LSaxSgjWoCqli9ejpOKSimqfdcqwvdi9ZfjV67eI%26r%3DL2JLRtXHlhmcrIANbzJ5bJIItX7BypJgN7IAY1kklS0%26m%3D0-1lrb9bNf5O_UNDlxFb2Xqz31Z6UafxAW4sVo70TsY%26s%3DDhYpkgwVTyvpma9kqNW0oPJOoD9fGCjPJNYoFsmlsjU%26e&amp;data=02%7C01%7Cwferland%40ccri.edu%7C7031cfce83124235a2b008d79e97786b%7Caf75351b37eb4405bf7a7327cec380a5%7C0%7C0%7C637152245732246506&amp;sdata=VMp74875ktRkY7Sny1bKz2o2kBArGVLfyv2UUFp5tqU%3D&amp;reserved=0=>
-------------------------------------------------------------------------------------
*** NOTICE *** This message was sent from an external sender and did not originate from Coast Community College 
District. If you are unsure of the authenticity of the sender, DO NOT click any links or download any attachments. 
Instead, click on FORWARD and address to phishing
**********
Replies to EDUCAUSE Community Group emails are sent to the entire community list. If you want to reply only to the 
person who sent the message, copy and paste their email address and forward the email reply. Additional participation 
and subscription information can be found at 
https://nam02.safelinks.protection.outlook.com/?url=https%3A%2F%2Furldefense.proofpoint.com%2Fv2%2Furl%3Fu%3Dhttps-3A__www.educause.edu_community%26d%3DDwIFaQ%26c%3DodzYs1kPF7h99M0Vn1uLzg%26r%3DjKMTIfZiBnBYrk_cRkqhrq0vZwXKksqj0lGxPgjosOo%26m%3DPCH4pSQdJHnemwXCid22jVtPnrEXBJK3q7fAp2ujQXk%26s%3DipDfAu95YytXt6pdbXXudY9CcmGpIRo-e8vMZATurtU%26e&amp;data=02%7C01%7Cwferland%40ccri.edu%7C7031cfce83124235a2b008d79e97786b%7Caf75351b37eb4405bf7a7327cec380a5%7C0%7C0%7C637152245732246506&amp;sdata=T%2B74Tdh%2FoPD%2FpnJ98kipjDD6xySG1RuoI1DEW3X9mng%3D&amp;reserved=0=
**********
Replies to EDUCAUSE Community Group emails are sent to the entire community list. If you want to reply only to the 
person who sent the message, copy and paste their email address and forward the email reply. Additional participation 
and subscription information can be found at 
https://nam02.safelinks.protection.outlook.com/?url=https%3A%2F%2Furldefense.proofpoint.com%2Fv2%2Furl%3Fu%3Dhttps-3A__www.educause.edu_community%26d%3DDwIFaQ%26c%3DodzYs1kPF7h99M0Vn1uLzg%26r%3DjKMTIfZiBnBYrk_cRkqhrq0vZwXKksqj0lGxPgjosOo%26m%3DPCH4pSQdJHnemwXCid22jVtPnrEXBJK3q7fAp2ujQXk%26s%3DipDfAu95YytXt6pdbXXudY9CcmGpIRo-e8vMZATurtU%26e&amp;data=02%7C01%7Cwferland%40ccri.edu%7C7031cfce83124235a2b008d79e97786b%7Caf75351b37eb4405bf7a7327cec380a5%7C0%7C0%7C637152245732246506&amp;sdata=T%2B74Tdh%2FoPD%2FpnJ98kipjDD6xySG1RuoI1DEW3X9mng%3D&amp;reserved=0=
**********
Replies to EDUCAUSE Community Group emails are sent to the entire community list. If you want to reply only to the 
person who sent the message, copy and paste their email address and forward the email reply. Additional participation 
and subscription information can be found at 
https://nam02.safelinks.protection.outlook.com/?url=https%3A%2F%2Furldefense.proofpoint.com%2Fv2%2Furl%3Fu%3Dhttps-3A__www.educause.edu_community%26d%3DDwIFaQ%26c%3DodzYs1kPF7h99M0Vn1uLzg%26r%3DjKMTIfZiBnBYrk_cRkqhrq0vZwXKksqj0lGxPgjosOo%26m%3DPCH4pSQdJHnemwXCid22jVtPnrEXBJK3q7fAp2ujQXk%26s%3DipDfAu95YytXt6pdbXXudY9CcmGpIRo-e8vMZATurtU%26e&amp;data=02%7C01%7Cwferland%40ccri.edu%7C7031cfce83124235a2b008d79e97786b%7Caf75351b37eb4405bf7a7327cec380a5%7C0%7C0%7C637152245732246506&amp;sdata=T%2B74Tdh%2FoPD%2FpnJ98kipjDD6xySG1RuoI1DEW3X9mng%3D&amp;reserved=0=


**********
Replies to EDUCAUSE Community Group emails are sent to the entire community list. If you want to reply only to the 
person who sent the message, copy and paste their email address and forward the email reply. Additional participation 
and subscription information can be found at 
https://nam02.safelinks.protection.outlook.com/?url=https%3A%2F%2Furldefense.proofpoint.com%2Fv2%2Furl%3Fu%3Dhttps-3A__www.educause.edu_community%26d%3DDwIFaQ%26c%3DodzYs1kPF7h99M0Vn1uLzg%26r%3DjKMTIfZiBnBYrk_cRkqhrq0vZwXKksqj0lGxPgjosOo%26m%3DPCH4pSQdJHnemwXCid22jVtPnrEXBJK3q7fAp2ujQXk%26s%3DipDfAu95YytXt6pdbXXudY9CcmGpIRo-e8vMZATurtU%26e&amp;data=02%7C01%7Cwferland%40ccri.edu%7C7031cfce83124235a2b008d79e97786b%7Caf75351b37eb4405bf7a7327cec380a5%7C0%7C0%7C637152245732256497&amp;sdata=kMDjGM0zLnJoTeJxb%2Ff3DWJ4Jq9mi1j0FPM4jtsjghs%3D&amp;reserved=0=

**********
Replies to EDUCAUSE Community Group emails are sent to the entire community list. If you want to reply only to the 
person who sent the message, copy and paste their email address and forward the email reply. Additional participation 
and subscription information can be found at 
https://nam02.safelinks.protection.outlook.com/?url=https%3A%2F%2Furldefense.proofpoint.com%2Fv2%2Furl%3Fu%3Dhttps-3A__www.educause.edu_commun%26d%3DDwIFaQ%26c%3DodzYs1kPF7h99M0Vn1uLzg%26r%3DjKMTIfZiBnBYrk_cRkqhrq0vZwXKksqj0lGxPgjosOo%26m%3DPCH4pSQdJHnemwXCid22jVtPnrEXBJK3q7fAp2ujQXk%26s%3DYRUZrE3p-yQqIe_4C1f2UCdi4PJjHfYt60g5qaqrqBw%26e&amp;data=02%7C01%7Cwferland%40ccri.edu%7C7031cfce83124235a2b008d79e97786b%7Caf75351b37eb4405bf7a7327cec380a5%7C0%7C0%7C637152245732256497&amp;sdata=nyL6%2BWO8dWeZo%2FMnSDkYanaubl64d1auC53V7VGN6P4%3D&amp;reserved=0=

------------------------------

Date:    Tue, 14 Jan 2020 17:23:52 +0000
From:    Paul Usama <paul.usama () SAIT CA>
Subject: Re: Ransomware Playbook

Thanks

From: The EDUCAUSE Security Community Group Listserv <SECURITY () LISTSERV EDUCAUSE EDU> On Behalf Of Francisco Chavez
Sent: Tuesday, January 14, 2020 9:15 AM
To: SECURITY () LISTSERV EDUCAUSE EDU
Subject: Re: [SECURITY] Ransomware Playbook

Paul,

It is available here.

https://nam02.safelinks.protection.outlook.com/?url=https%3A%2F%2Furldefense.proofpoint.com%2Fv2%2Furl%3Fu%3Dhttps-3A__library.educause.edu_resources_2019_10_national-2Dstudent-2Dclearinghouse-2Dplaybooks%26d%3DDwIFaQ%26c%3DodzYs1kPF7h99M0Vn1uLzg%26r%3DjKMTIfZiBnBYrk_cRkqhrq0vZwXKksqj0lGxPgjosOo%26m%3DPCH4pSQdJHnemwXCid22jVtPnrEXBJK3q7fAp2ujQXk%26s%3DeqI_Z2l1fOW2w2EIp5wHWcEClPv1e2GcoSoXfksZ7bs%26e&amp;data=02%7C01%7Cwferland%40ccri.edu%7C7031cfce83124235a2b008d79e97786b%7Caf75351b37eb4405bf7a7327cec380a5%7C0%7C0%7C637152245732256497&amp;sdata=sCfv6LRo5jK13zgDx2rIb%2FP%2BwqrsHZgVqSQS1qybQ70%3D&amp;reserved=0=


Regards,
Francisco Chavez



[cid:image001.jpg@01D5CAC4.B737B5E0]


Manager - IT Security
fac3 () stmarys-ca edu<mailto:fac3 () stmarys-ca edu>
Office: (925) 631-8236




On Jan 14, 2020, at 8:00 AM, Paul Usama <paul.usama () SAIT CA<mailto:paul.usama () SAIT CA>> wrote:

Hi,

Am not sure if this is still shared, I am interested in the Ransomware Playbook.


<image002.jpg>
Paul Usama
Information Security Analyst
Information Technology Services

Southern Alberta Institute of Technology E.H. Crandell, G200
1301 – 16 Avenue NW, Calgary AB, T2M 0L4
(Cell) 403.836.3489 (Ph) 403.284.8328
Paul.Usama () sait ca<mailto:Paul.Usama () sait ca>







From: The EDUCAUSE Security Community Group Listserv <SECURITY () LISTSERV EDUCAUSE EDU<mailto:SECURITY () LISTSERV 
EDUCAUSE EDU>> On Behalf Of Jamie Schademan
Sent: Friday, October 4, 2019 11:08 AM
To: SECURITY () LISTSERV EDUCAUSE EDU<mailto:SECURITY () LISTSERV EDUCAUSE EDU>
Subject: Re: [SECURITY] Ransomware Playbook

Me too please.
Jamie
CWU

Jamie Schademan, CISM
Chief Information Security Officer
CWU

________________________________
From: The EDUCAUSE Security Community Group Listserv <SECURITY () LISTSERV EDUCAUSE EDU<mailto:SECURITY () LISTSERV 
EDUCAUSE EDU>> on behalf of Oberlin, Craig <coberlin1 () CCCD EDU<mailto:coberlin1 () CCCD EDU>>
Sent: Friday, October 4, 2019 11:03:02 AM
To: SECURITY () LISTSERV EDUCAUSE EDU<mailto:SECURITY () LISTSERV EDUCAUSE EDU> <SECURITY () LISTSERV EDUCAUSE 
EDU<mailto:SECURITY () LISTSERV EDUCAUSE EDU>>
Subject: Re: [SECURITY] Ransomware Playbook

Caution: This email originated from outside the university.
Do not click on links, open attachments, or reply unless you recognize the sender and know the content is safe. If you 
have questions about this email please forward it tocwuservicedesk () cwu edu<mailto:cwuservicedesk () cwu edu>.




John,
  My thanks and I would appreciate copies as well.

Craig


Craig Oberlin, CISSP
Sr. Director IT, Users Services & Chief Information Security Officer Coast Community College District P 714.438.6808 
coberlin1 () cccd edu<mailto:coberlin1 () cccd edu>
<image001.png>



From: The EDUCAUSE Security Community Group Listserv [mailto:SECURITY () LISTSERV EDUCAUSE EDU] On Behalf Of Babak 
Oskouian
Sent: Friday, October 4, 2019 9:49 AM
To: SECURITY () LISTSERV EDUCAUSE EDU<mailto:SECURITY () LISTSERV EDUCAUSE EDU>
Subject: Re: [SECURITY] Ransomware Playbook

Hi John,

It goes without saying that you and your team must have done a tremendous amount of work to put these playbooks 
together and it is very generous of you to be willing to share them with the community.

So, thank you very much indeed.

Babak

Babak Oskouian, Ph.D. | Director of Networking and Infrastructure Mills College | 5000 MacArthur Blvd | Oakland, CA 
94613-1301
Office: Stern Hall 007; Phone: 510-430-2224 <tel:510-430-2224>



On Fri, Oct 4, 2019 at 4:47 AM John Ramsey <jramsey () studentclearinghouse org<mailto:jramsey () studentclearinghouse 
org>> wrote:
Everybody,

The interest in playbooks, especially ransomware, is great to see (as playbooks are time consuming to create and there 
aren’t enough hours in the day as it is).  I’ve been through a few ransomware incidents, so the playbook is battle 
ready.  However, as some have pointed out, you’ll want to customize to your organization where applicable.  When my 
team creates playbooks, our goal is to keep it simple and flexible and easy to follow (versus flipping back and forth 
as you might in a plan.)  The first page is almost always how to easily and quickly contain and then triage.  Once that 
is done, the rest is post event activities.  If you have any questions, please don’t hesitate to ask me.  Since the NSC 
is a third-party service provider for most of you, I’m happy to share what we’re doing in order to further gain your 
confidence in our processes to protect your data.  At the end of the day, we’re one team!

We also have other playbooks that I’m happy to share (maybe it makes sense for Educause or REN-ISAC or both to post 
what all of us are willing to share amongst ourselves.  Then we’ll have a pretty robust set to select from and modify 
as appropriate).  Here are some others that we have finalized:


  1.  Notifications and Escalations Playbook.  This walks through the first six hours of an incident in 30-minute 
increments indicating what each stakeholder is doing as well as what message gets communicated and to whom.
  2.  DDOS Playbook.  Being one of the top attacks in the Education industry, this was one of the first ones we did.  
Internet 2 was kind enough to provide some guidance on the playbook (which we incorporated.)
  3.  Foreign Travel Playbook.  Actions we take when somebody travels overseas and has the requirement to take a 
company device.
  4.  Incident Handling Checklists/Chains of Custody forms.
  5.  Network Compromise Playbook.
  6.  Spoofed URL Playbook.

John

John Ramsey, Chief Information Security Officer, National Student Clearinghouse
Certified:  CISSP, CISM, PMP, CSSLP, CRISC, CGEIT
2300 Dulles Station Blvd., Suite 220, Herndon, VA 20171
P: 703.742.4428  |   
https://nam02.safelinks.protection.outlook.com/?url=https%3A%2F%2Furldefense.proofpoint.com%2Fv2%2Furl%3Fu%3Dhttp-3A__www.studentclearinghouse.org%26d%3DDwIFaQ%26c%3DodzYs1kPF7h99M0Vn1uLzg%26r%3DjKMTIfZiBnBYrk_cRkqhrq0vZwXKksqj0lGxPgjosOo%26m%3DPCH4pSQdJHnemwXCid22jVtPnrEXBJK3q7fAp2ujQXk%26s%3DDYLwvVGFZ86lTat6NxteKGY0Nal1lJiGpnys2patNJA%26e&amp;data=02%7C01%7Cwferland%40ccri.edu%7C7031cfce83124235a2b008d79e97786b%7Caf75351b37eb4405bf7a7327cec380a5%7C0%7C0%7C637152245732256497&amp;sdata=Wam4V3e%2BJzCCiL%2B7d65VOQgGTGvhHb4WyX3SfhaVFDU%3D&amp;reserved=0=
 
<https://nam02.safelinks.protection.outlook.com/?url=https%3A%2F%2Furldefense.proofpoint.com%2Fv2%2Furl%3Fu%3Dhttp-3A__www.studentclearinghouse.org_%26d%3DDwMFaQ%26c%3DfH4LSaxSgjWoCqli9ejpOKSimqfdcqwvdi9ZfjV67eI%26r%3DL2JLRtXHlhmcrIANbzJ5bJIItX7BypJgN7IAY1kklS0%26m%3D0-1lrb9bNf5O_UNDlxFb2Xqz31Z6UafxAW4sVo70TsY%26s%3D6KKsFoIKTYgAD7pi6C5TjYlGRwjXxnpP9eNEoUg6tCk%26e&amp;data=02%7C01%7Cwferland%40ccri.edu%7C7031cfce83124235a2b008d79e97786b%7Caf75351b37eb4405bf7a7327cec380a5%7C0%7C0%7C637152245732256497&amp;sdata=VhazmqIFsodXmg4wZ%2BHzobFhVvG2d5rZI9Imq9Wzy4c%3D&amp;reserved=0=>
Read the Clearinghouse Today 
Blog<https://nam02.safelinks.protection.outlook.com/?url=https%3A%2F%2Furldefense.proofpoint.com%2Fv2%2Furl%3Fu%3Dhttps-3A__nscblog.org_%26d%3DDwMFaQ%26c%3DfH4LSaxSgjWoCqli9ejpOKSimqfdcqwvdi9ZfjV67eI%26r%3DL2JLRtXHlhmcrIANbzJ5bJIItX7BypJgN7IAY1kklS0%26m%3D0-1lrb9bNf5O_UNDlxFb2Xqz31Z6UafxAW4sVo70TsY%26s%3Dbr2kQUxQhQEaZoZzMS3ZTNXObY1JGi_7GUtwR3uC7kg%26e&amp;data=02%7C01%7Cwferland%40ccri.edu%7C7031cfce83124235a2b008d79e97786b%7Caf75351b37eb4405bf7a7327cec380a5%7C0%7C0%7C637152245732266490&amp;sdata=HTQ9FL6d2hOVuVYoF0VXhm%2BZGyNFqLJgxmLNQrhRc8c%3D&amp;reserved=0=>

Winner “2016 When Work Works” & “Excellence in Work-Life Balance”

**********
Replies to EDUCAUSE Community Group emails are sent to the entire community list. If you want to reply only to the 
person who sent the message, copy and paste their email address and forward the email reply. Additional participation 
and subscription information can be found at 
https://nam02.safelinks.protection.outlook.com/?url=https%3A%2F%2Furldefense.proofpoint.com%2Fv2%2Furl%3Fu%3Dhttps-3A__www.educause.edu_community%26d%3DDwIFaQ%26c%3DodzYs1kPF7h99M0Vn1uLzg%26r%3DjKMTIfZiBnBYrk_cRkqhrq0vZwXKksqj0lGxPgjosOo%26m%3DPCH4pSQdJHnemwXCid22jVtPnrEXBJK3q7fAp2ujQXk%26s%3DipDfAu95YytXt6pdbXXudY9CcmGpIRo-e8vMZATurtU%26e&amp;data=02%7C01%7Cwferland%40ccri.edu%7C7031cfce83124235a2b008d79e97786b%7Caf75351b37eb4405bf7a7327cec380a5%7C0%7C0%7C637152245732266490&amp;sdata=xgKCvfAObyOqJ7YGXyUr%2F92FMYhdNR%2FvQADPumL4LQU%3D&amp;reserved=0=
 
<https://nam02.safelinks.protection.outlook.com/?url=https%3A%2F%2Furldefense.proofpoint.com%2Fv2%2Furl%3Fu%3Dhttps-3A__www.educause.edu_community%26d%3DDwMFaQ%26c%3DfH4LSaxSgjWoCqli9ejpOKSimqfdcqwvdi9ZfjV67eI%26r%3DL2JLRtXHlhmcrIANbzJ5bJIItX7BypJgN7IAY1kklS0%26m%3D0-1lrb9bNf5O_UNDlxFb2Xqz31Z6UafxAW4sVo70TsY%26s%3DDhYpkgwVTyvpma9kqNW0oPJOoD9fGCjPJNYoFsmlsjU%26e&amp;data=02%7C01%7Cwferland%40ccri.edu%7C7031cfce83124235a2b008d79e97786b%7Caf75351b37eb4405bf7a7327cec380a5%7C0%7C0%7C637152245732266490&amp;sdata=ysAgrSCzk8NE0GB%2BEl9FWGZXPAiYoHml67herrNh4dI%3D&amp;reserved=0=>
-------------------------------------------------------------------------------------
*** NOTICE *** This message was sent from an external sender and did not originate from Coast Community College 
District. If you are unsure of the authenticity of the sender, DO NOT click any links or download any attachments. 
Instead, click on FORWARD and address to phishing
**********
Replies to EDUCAUSE Community Group emails are sent to the entire community list. If you want to reply only to the 
person who sent the message, copy and paste their email address and forward the email reply. Additional participation 
and subscription information can be found at 
https://nam02.safelinks.protection.outlook.com/?url=https%3A%2F%2Furldefense.proofpoint.com%2Fv2%2Furl%3Fu%3Dhttps-3A__www.educause.edu_community%26d%3DDwIFaQ%26c%3DodzYs1kPF7h99M0Vn1uLzg%26r%3DjKMTIfZiBnBYrk_cRkqhrq0vZwXKksqj0lGxPgjosOo%26m%3DPCH4pSQdJHnemwXCid22jVtPnrEXBJK3q7fAp2ujQXk%26s%3DipDfAu95YytXt6pdbXXudY9CcmGpIRo-e8vMZATurtU%26e&amp;data=02%7C01%7Cwferland%40ccri.edu%7C7031cfce83124235a2b008d79e97786b%7Caf75351b37eb4405bf7a7327cec380a5%7C0%7C0%7C637152245732266490&amp;sdata=xgKCvfAObyOqJ7YGXyUr%2F92FMYhdNR%2FvQADPumL4LQU%3D&amp;reserved=0=
**********
Replies to EDUCAUSE Community Group emails are sent to the entire community list. If you want to reply only to the 
person who sent the message, copy and paste their email address and forward the email reply. Additional participation 
and subscription information can be found at 
https://nam02.safelinks.protection.outlook.com/?url=https%3A%2F%2Furldefense.proofpoint.com%2Fv2%2Furl%3Fu%3Dhttps-3A__www.educause.edu_community%26d%3DDwIFaQ%26c%3DodzYs1kPF7h99M0Vn1uLzg%26r%3DjKMTIfZiBnBYrk_cRkqhrq0vZwXKksqj0lGxPgjosOo%26m%3DPCH4pSQdJHnemwXCid22jVtPnrEXBJK3q7fAp2ujQXk%26s%3DipDfAu95YytXt6pdbXXudY9CcmGpIRo-e8vMZATurtU%26e&amp;data=02%7C01%7Cwferland%40ccri.edu%7C7031cfce83124235a2b008d79e97786b%7Caf75351b37eb4405bf7a7327cec380a5%7C0%7C0%7C637152245732266490&amp;sdata=xgKCvfAObyOqJ7YGXyUr%2F92FMYhdNR%2FvQADPumL4LQU%3D&amp;reserved=0=
**********
Replies to EDUCAUSE Community Group emails are sent to the entire community list. If you want to reply only to the 
person who sent the message, copy and paste their email address and forward the email reply. Additional participation 
and subscription information can be found at 
https://nam02.safelinks.protection.outlook.com/?url=https%3A%2F%2Furldefense.proofpoint.com%2Fv2%2Furl%3Fu%3Dhttps-3A__www.educause.edu_community%26d%3DDwIFaQ%26c%3DodzYs1kPF7h99M0Vn1uLzg%26r%3DjKMTIfZiBnBYrk_cRkqhrq0vZwXKksqj0lGxPgjosOo%26m%3DPCH4pSQdJHnemwXCid22jVtPnrEXBJK3q7fAp2ujQXk%26s%3DipDfAu95YytXt6pdbXXudY9CcmGpIRo-e8vMZATurtU%26e&amp;data=02%7C01%7Cwferland%40ccri.edu%7C7031cfce83124235a2b008d79e97786b%7Caf75351b37eb4405bf7a7327cec380a5%7C0%7C0%7C637152245732276487&amp;sdata=U9JaM8%2FAjDwmMrunQeZQXY%2FkfHTAh97LOo9W0SzqVFk%3D&amp;reserved=0=


**********
Replies to EDUCAUSE Community Group emails are sent to the entire community list. If you want to reply only to the 
person who sent the message, copy and paste their email address and forward the email reply. Additional participation 
and subscription information can be found at 
https://nam02.safelinks.protection.outlook.com/?url=https%3A%2F%2Furldefense.proofpoint.com%2Fv2%2Furl%3Fu%3Dhttps-3A__www.educause.edu_community%26d%3DDwIFaQ%26c%3DodzYs1kPF7h99M0Vn1uLzg%26r%3DjKMTIfZiBnBYrk_cRkqhrq0vZwXKksqj0lGxPgjosOo%26m%3DPCH4pSQdJHnemwXCid22jVtPnrEXBJK3q7fAp2ujQXk%26s%3DipDfAu95YytXt6pdbXXudY9CcmGpIRo-e8vMZATurtU%26e&amp;data=02%7C01%7Cwferland%40ccri.edu%7C7031cfce83124235a2b008d79e97786b%7Caf75351b37eb4405bf7a7327cec380a5%7C0%7C0%7C637152245732276487&amp;sdata=U9JaM8%2FAjDwmMrunQeZQXY%2FkfHTAh97LOo9W0SzqVFk%3D&amp;reserved=0=

**********
Replies to EDUCAUSE Community Group emails are sent to the entire community list. If you want to reply only to the 
person who sent the message, copy and paste their email address and forward the email reply. Additional participation 
and subscription information can be found at 
https://nam02.safelinks.protection.outlook.com/?url=https%3A%2F%2Furldefense.proofpoint.com%2Fv2%2Furl%3Fu%3Dhttps-3A__www.educause.edu_comm%26d%3DDwIFaQ%26c%3DodzYs1kPF7h99M0Vn1uLzg%26r%3DjKMTIfZiBnBYrk_cRkqhrq0vZwXKksqj0lGxPgjosOo%26m%3DPCH4pSQdJHnemwXCid22jVtPnrEXBJK3q7fAp2ujQXk%26s%3DICJfiJqqh5bP6RqS29xcePtEv4_-1I67OLM8w1eeiA0%26e&amp;data=02%7C01%7Cwferland%40ccri.edu%7C7031cfce83124235a2b008d79e97786b%7Caf75351b37eb4405bf7a7327cec380a5%7C0%7C0%7C637152245732276487&amp;sdata=HrUr3Chv3aGuLTRH1O9wGfeYRlVKI9SA7S099pWkYok%3D&amp;reserved=0=

------------------------------

End of SECURITY Digest - 13 Jan 2020 to 14 Jan 2020 (#2020-10)
**************************************************************

**********
Replies to EDUCAUSE Community Group emails are sent to the entire community list. If you want to reply only to the 
person who sent the message, copy and paste their email address and forward the email reply. Additional participation 
and subscription information can be found at 
https://nam02.safelinks.protection.outlook.com/?url=https%3A%2F%2Fwww.educause.edu%2Fcommunity&amp;data=02%7C01%7Cwferland%40ccri.edu%7C7031cfce83124235a2b008d79e97786b%7Caf75351b37eb4405bf7a7327cec380a5%7C0%7C1%7C637152245732276487&amp;sdata=5vZ1uXB5XbqwInJGEjO3Sk9n5ZksxgI0ftrE1JJCEDI%3D&amp;reserved=0

------------------------------

Date:    Tue, 14 Jan 2020 23:29:12 +0000
From:    Dewight Fredrick Kramer <dfkramer () UCDAVIS EDU>
Subject: Re: Reminder: IAM Online Wednesday: Passwordless Authentication with Shibboleth and WebAuthn

Second this inquiry!

Thank you,

Dewight F. Kramer
Assistant CISO
University of California, Davis
One Shields Avenue
Davis, CA 95616
(530)752-1700
dfkramer () ucdavis edu<mailto:dfkramer () ucdavis edu>
https://nam02.safelinks.protection.outlook.com/?url=http%3A%2F%2Fsecurity.ucdavis.edu&amp;data=02%7C01%7Cwferland%40ccri.edu%7C7031cfce83124235a2b008d79e97786b%7Caf75351b37eb4405bf7a7327cec380a5%7C0%7C1%7C637152245732276487&amp;sdata=s07H8g59tFDsKcfjHncacD8oNALVPW5oVUVLVcVOHDM%3D&amp;reserved=0<https://nam02.safelinks.protection.outlook.com/?url=http%3A%2F%2Fsecurity.ucdavis.edu%2F&amp;data=02%7C01%7Cwferland%40ccri.edu%7C7031cfce83124235a2b008d79e97786b%7Caf75351b37eb4405bf7a7327cec380a5%7C0%7C1%7C637152245732276487&amp;sdata=10e2yUa%2FNjVZiWDWCCz69FWHCYOv4scxv10BI4cP1Bs%3D&amp;reserved=0>


From: The EDUCAUSE Security Community Group Listserv <SECURITY () LISTSERV EDUCAUSE EDU> on behalf of "Jim A. Bole" 
<jbole () STEVENSON EDU>
Reply-To: The EDUCAUSE Security Community Group Listserv <SECURITY () LISTSERV EDUCAUSE EDU>
Date: Monday, January 13, 2020 at 8:44 AM
To: "SECURITY () LISTSERV EDUCAUSE EDU" <SECURITY () LISTSERV EDUCAUSE EDU>
Subject: Re: [SECURITY] Reminder: IAM Online Wednesday: Passwordless Authentication with Shibboleth and WebAuthn

Dean,

This looks interesting, but I may have conflict. Will a recording be available afterward?

Jim Bole
Director of Information Security
Stevenson University
1525 Greenspring Valley Road
Stevenson, MD, 21153-0641
jbole () stevenson edu | O: 443-334-2696



From: The EDUCAUSE Security Community Group Listserv <SECURITY () LISTSERV EDUCAUSE EDU> On Behalf Of Dean Woodbeck
Sent: Thursday, January 9, 2020 9:25 AM
To: SECURITY () LISTSERV EDUCAUSE EDU
Subject: Reminder: IAM Online Wednesday: Passwordless Authentication with Shibboleth and WebAuthn

This email originated from outside of Stevenson University. Use caution with links or attachments unless you know the 
content is safe.
A reminder of the IAM Online this Wednesday, January 15, at 2 pm ET.

From: Dean Woodbeck <woodbeck () internet2 edu<mailto:woodbeck () internet2 edu>>
Date: Wednesday, December 18, 2019 at 3:20 PM
Subject: January IAM Online: Passwordless Authentication with Shibboleth and WebAuthn

January IAM Online: Passwordless Authentication with Shibboleth and WebAuthn
Wednesday, January 15, 2020
2 pm ET | 1 pm CT | Noon MT | 11 am PT | 10 am AKT

Our first IAM Online of 2020 will provide another method of passwordless authentication; this one developed by Duke 
University.

Duke has integrated its Shibboleth Identity Provider with WebAuthn to allow one-step, passwordless multi-factor 
authentication. In this session we’ll discuss the evolution of this pilot, including:
    * Initial drivers
    * Proof of concept
    * Early release
    * Iterations, the feedback they generated, and resulting changes

For each of these phases, we’ll discuss challenges, lessons learned, and policy decisions that helped us move forward. 
We’ll wrap up with recommendations about how to make passwordless authentication a reality at your institution, 
including some thoughts about technical and political challenges and strategies for moving through those issues.

-----
Presenters

Mary McKee, Duke University
Shilen Patel, Duke University

-----
Connecting
Side sharing and audio via Zoom: 
https://nam02.safelinks.protection.outlook.com/?url=https%3A%2F%2Finternet2.zoom.us%2Fj%2F886598327&amp;data=02%7C01%7Cwferland%40ccri.edu%7C7031cfce83124235a2b008d79e97786b%7Caf75351b37eb4405bf7a7327cec380a5%7C0%7C1%7C637152245732276487&amp;sdata=d%2F2rsmrfaYhbxvPwEK%2BS2NrBQ7ZMeJfUNcPCKc6f99s%3D&amp;reserved=0<https://nam02.safelinks.protection.outlook.com/?url=https%3A%2F%2Finternet2.zoom.us%2Fj%2F886598327&amp;data=02%7C01%7Cwferland%40ccri.edu%7C7031cfce83124235a2b008d79e97786b%7Caf75351b37eb4405bf7a7327cec380a5%7C0%7C1%7C637152245732286482&amp;sdata=cEX4KLUoOKsO0B%2BCoZ7x66OBa9200lK9ZAcVEs0HqFs%3D&amp;reserved=0>

Or join by phone:
Dial (US): (669) 900-6833 or (646) 558-8656
Webinar ID: 886 598 327

International numbers available: 
https://nam02.safelinks.protection.outlook.com/?url=https%3A%2F%2Fzoom.us%2Fu%2FbKX4teTZh&amp;data=02%7C01%7Cwferland%40ccri.edu%7C7031cfce83124235a2b008d79e97786b%7Caf75351b37eb4405bf7a7327cec380a5%7C0%7C0%7C637152245732286482&amp;sdata=JMqrIhRGN3JpmpcNw9QMw1rUyABhLjH9ZS2Y4gOPRiM%3D&amp;reserved=0<https://nam02.safelinks.protection.outlook.com/?url=https%3A%2F%2Fzoom.us%2Fu%2FbKX4teTZh&amp;data=02%7C01%7Cwferland%40ccri.edu%7C7031cfce83124235a2b008d79e97786b%7Caf75351b37eb4405bf7a7327cec380a5%7C0%7C0%7C637152245732286482&amp;sdata=JMqrIhRGN3JpmpcNw9QMw1rUyABhLjH9ZS2Y4gOPRiM%3D&amp;reserved=0>

-----
About IAM Online
IAM Online 
(https://nam02.safelinks.protection.outlook.com/?url=https%3A%2F%2Fwww2.internet2.edu%2Fl%2F66332%2F2019-09-20%2Fbwbqvx&amp;data=02%7C01%7Cwferland%40ccri.edu%7C7031cfce83124235a2b008d79e97786b%7Caf75351b37eb4405bf7a7327cec380a5%7C0%7C0%7C637152245732286482&amp;sdata=XIbESg%2FJY39pShZ3iHIAbPnZ84cCIuQeM4Hg%2FLfdT7k%3D&amp;reserved=0<https://nam02.safelinks.protection.outlook.com/?url=https%3A%2F%2Fwww2.internet2.edu%2Fl%2F66332%2F2019-09-20%2Fbwbqvx&amp;data=02%7C01%7Cwferland%40ccri.edu%7C7031cfce83124235a2b008d79e97786b%7Caf75351b37eb4405bf7a7327cec380a5%7C0%7C0%7C637152245732286482&amp;sdata=XIbESg%2FJY39pShZ3iHIAbPnZ84cCIuQeM4Hg%2FLfdT7k%3D&amp;reserved=0>)
 is a monthly online education series brought to you by Internet2’s InCommon community and the EDUCAUSE Higher 
Education Information Security Council (HEISC).


----
Dean Woodbeck
Director of Community Awareness
Internet2 Trust and Identity


**********
Replies to EDUCAUSE Community Group emails are sent to the entire community list. If you want to reply only to the 
person who sent the message, copy and paste their email address and forward the email reply. Additional participation 
and subscription information can be found at 
https://nam02.safelinks.protection.outlook.com/?url=https%3A%2F%2Fwww.educause.edu%2Fcommunity&amp;data=02%7C01%7Cwferland%40ccri.edu%7C7031cfce83124235a2b008d79e97786b%7Caf75351b37eb4405bf7a7327cec380a5%7C0%7C1%7C637152245732286482&amp;sdata=HXn22F09TfnGHt2sSl8ZCqJXdty4gbJg1xgOrOFWOyI%3D&amp;reserved=0<https://nam02.safelinks.protection.outlook.com/?url=https%3A%2F%2Fwww.educause.edu%2Fcommunity&amp;data=02%7C01%7Cwferland%40ccri.edu%7C7031cfce83124235a2b008d79e97786b%7Caf75351b37eb4405bf7a7327cec380a5%7C0%7C1%7C637152245732286482&amp;sdata=HXn22F09TfnGHt2sSl8ZCqJXdty4gbJg1xgOrOFWOyI%3D&amp;reserved=0>

**********
Replies to EDUCAUSE Community Group emails are sent to the entire community list. If you want to reply only to the 
person who sent the message, copy and paste their email address and forward the email reply. Additional participation 
and subscription information can be found at 
https://nam02.safelinks.protection.outlook.com/?url=https%3A%2F%2Fwww.educause.edu%2Fcommunity&amp;data=02%7C01%7Cwferland%40ccri.edu%7C7031cfce83124235a2b008d79e97786b%7Caf75351b37eb4405bf7a7327cec380a5%7C0%7C1%7C637152245732296471&amp;sdata=ddyT752%2B7iZZbp8r8w2cHn%2FaW2M9nFBjTzZB47p1rVU%3D&amp;reserved=0

**********
Replies to EDUCAUSE Community Group emails are sent to the entire community list. If you want to reply only to the 
person who sent the message, copy and paste their email address and forward the email reply. Additional participation 
and subscription information can be found a

------------------------------

Date:    Wed, 15 Jan 2020 04:50:37 +0000
From:    Jamie Schademan <Jamie.Schademan () CWU EDU>
Subject: Re: SECURITY Digest - 13 Jan 2020 to 14 Jan 2020 (#2020-10)

Hello,
CWU would also appreciate the playbook.
Thank you!
Jamie

Jamie Schademan, CISM
CISO
Central Washington University
Ellensburg, WA.
CWU.Edu/security

-----Original Message-----
From: The EDUCAUSE Security Community Group Listserv <SECURITY () LISTSERV EDUCAUSE EDU> On Behalf Of Carianna, Marie
Sent: Tuesday, January 14, 2020 2:01 PM
To: SECURITY () LISTSERV EDUCAUSE EDU
Subject: Re: [SECURITY] SECURITY Digest - 13 Jan 2020 to 14 Jan 2020 (#2020-10)

Touro would also like to have the playbook.

Kind regards,
Marie

Marie Carianna, PMP, ITIL
Deputy Chief Information Officer for Business Systems, Project and Portfolio Management
Touro College & University System  |  500 7th Avenue, room 510 NY, NY 10018

-----Original Message-----
From: The EDUCAUSE Security Community Group Listserv <SECURITY () LISTSERV EDUCAUSE EDU> On Behalf Of SECURITY 
automatic digest system
Sent: Tuesday, January 14, 2020 5:00 PM
To: SECURITY () LISTSERV EDUCAUSE EDU
Subject: SECURITY Digest - 13 Jan 2020 to 14 Jan 2020 (#2020-10)

There are 4 messages totalling 4010 lines in this issue.

Topics of the day:

  1. Ransomware Playbook (4)

**********
Replies to EDUCAUSE Community Group emails are sent to the entire community list. If you want to reply only to the 
person who sent the message, copy and paste their email address and forward the email reply. Additional participation 
and subscription information can be found at 
https://nam02.safelinks.protection.outlook.com/?url=https%3A%2F%2Furldefense.proofpoint.com%2Fv2%2Furl%3Fu%3Dhttps-3A__www.educause.edu_community%26d%3DDwIFaQ%26c%3DodzYs1kPF7h99M0Vn1uLzg%26r%3DjKMTIfZiBnBYrk_cRkqhrq0vZwXKksqj0lGxPgjosOo%26m%3DPCH4pSQdJHnemwXCid22jVtPnrEXBJK3q7fAp2ujQXk%26s%3DipDfAu95YytXt6pdbXXudY9CcmGpIRo-e8vMZATurtU%26e&amp;data=02%7C01%7Cwferland%40ccri.edu%7C7031cfce83124235a2b008d79e97786b%7Caf75351b37eb4405bf7a7327cec380a5%7C0%7C0%7C637152245732296471&amp;sdata=xsa2nU%2BO2Nmvi22mvYFV4y8UEmCIMO31XSSqGI3ZoYs%3D&amp;reserved=0=

----------------------------------------------------------------------

Date:    Tue, 14 Jan 2020 16:00:24 +0000
From:    Paul Usama <paul.usama () SAIT CA>
Subject: Re: Ransomware Playbook

Hi,

Am not sure if this is still shared, I am interested in the Ransomware Playbook.


[cid:image001.gif@01D1A152.13E94560]
Paul Usama
Information Security Analyst
Information Technology Services

Southern Alberta Institute of Technology E.H. Crandell, G200
1301 - 16 Avenue NW, Calgary AB, T2M 0L4
(Cell) 403.836.3489 (Ph) 403.284.8328
Paul.Usama () sait ca<mailto:Paul.Usama () sait ca>







From: The EDUCAUSE Security Community Group Listserv <SECURITY () LISTSERV EDUCAUSE EDU> On Behalf Of Jamie Schademan
Sent: Friday, October 4, 2019 11:08 AM
To: SECURITY () LISTSERV EDUCAUSE EDU
Subject: Re: [SECURITY] Ransomware Playbook

Me too please.
Jamie
CWU

Jamie Schademan, CISM
Chief Information Security Officer
CWU

________________________________
From: The EDUCAUSE Security Community Group Listserv <SECURITY () LISTSERV EDUCAUSE EDU<mailto:SECURITY () LISTSERV 
EDUCAUSE EDU>> on behalf of Oberlin, Craig <coberlin1 () CCCD EDU<mailto:coberlin1 () CCCD EDU>>
Sent: Friday, October 4, 2019 11:03:02 AM
To: SECURITY () LISTSERV EDUCAUSE EDU<mailto:SECURITY () LISTSERV EDUCAUSE EDU> <SECURITY () LISTSERV EDUCAUSE 
EDU<mailto:SECURITY () LISTSERV EDUCAUSE EDU>>
Subject: Re: [SECURITY] Ransomware Playbook

Caution: This email originated from outside the university.
Do not click on links, open attachments, or reply unless you recognize the sender and know the content is safe. If you 
have questions about this email please forward it to cwuservicedesk () cwu edu<mailto:cwuservicedesk () cwu edu>.



John,
  My thanks and I would appreciate copies as well.

Craig


Craig Oberlin, CISSP
Sr. Director IT, Users Services & Chief Information Security Officer Coast Community College District P 714.438.6808 
coberlin1 () cccd edu<mailto:coberlin1 () cccd edu>
[coast]



From: The EDUCAUSE Security Community Group Listserv [mailto:SECURITY () LISTSERV EDUCAUSE EDU] On Behalf Of Babak 
Oskouian
Sent: Friday, October 4, 2019 9:49 AM
To: SECURITY () LISTSERV EDUCAUSE EDU<mailto:SECURITY () LISTSERV EDUCAUSE EDU>
Subject: Re: [SECURITY] Ransomware Playbook

Hi John,

It goes without saying that you and your team must have done a tremendous amount of work to put these playbooks 
together and it is very generous of you to be willing to share them with the community.

So, thank you very much indeed.

Babak


Babak Oskouian, Ph.D. | Director of Networking and Infrastructure

Mills College | 5000 MacArthur Blvd | Oakland, CA 94613-1301

Office: Stern Hall 007; Phone: 510-430-2224 <tel:510-430-2224>




On Fri, Oct 4, 2019 at 4:47 AM John Ramsey <jramsey () studentclearinghouse org<mailto:jramsey () studentclearinghouse 
org>> wrote:
Everybody,

The interest in playbooks, especially ransomware, is great to see (as playbooks are time consuming to create and there 
aren't enough hours in the day as it is).  I've been through a few ransomware incidents, so the playbook is battle 
ready.  However, as some have pointed out, you'll want to customize to your organization where applicable.  When my 
team creates playbooks, our goal is to keep it simple and flexible and easy to follow (versus flipping back and forth 
as you might in a plan.)  The first page is almost always how to easily and quickly contain and then triage.  Once that 
is done, the rest is post event activities.  If you have any questions, please don't hesitate to ask me.  Since the NSC 
is a third-party service provider for most of you, I'm happy to share what we're doing in order to further gain your 
confidence in our processes to protect your data.  At the end of the day, we're one team!

We also have other playbooks that I'm happy to share (maybe it makes sense for Educause or REN-ISAC or both to post 
what all of us are willing to share amongst ourselves.  Then we'll have a pretty robust set to select from and modify 
as appropriate).  Here are some others that we have finalized:


  1.  Notifications and Escalations Playbook.  This walks through the first six hours of an incident in 30-minute 
increments indicating what each stakeholder is doing as well as what message gets communicated and to whom.
  2.  DDOS Playbook.  Being one of the top attacks in the Education industry, this was one of the first ones we did.  
Internet 2 was kind enough to provide some guidance on the playbook (which we incorporated.)
  3.  Foreign Travel Playbook.  Actions we take when somebody travels overseas and has the requirement to take a 
company device.
  4.  Incident Handling Checklists/Chains of Custody forms.
  5.  Network Compromise Playbook.
  6.  Spoofed URL Playbook.

John

John Ramsey, Chief Information Security Officer, National Student Clearinghouse
Certified:  CISSP, CISM, PMP, CSSLP, CRISC, CGEIT
2300 Dulles Station Blvd., Suite 220, Herndon, VA 20171
P: 703.742.4428  |   
https://nam02.safelinks.protection.outlook.com/?url=https%3A%2F%2Furldefense.proofpoint.com%2Fv2%2Furl%3Fu%3Dhttp-3A__www.studentclearinghouse.org%26d%3DDwIFaQ%26c%3DodzYs1kPF7h99M0Vn1uLzg%26r%3DjKMTIfZiBnBYrk_cRkqhrq0vZwXKksqj0lGxPgjosOo%26m%3DPCH4pSQdJHnemwXCid22jVtPnrEXBJK3q7fAp2ujQXk%26s%3DDYLwvVGFZ86lTat6NxteKGY0Nal1lJiGpnys2patNJA%26e&amp;data=02%7C01%7Cwferland%40ccri.edu%7C7031cfce83124235a2b008d79e97786b%7Caf75351b37eb4405bf7a7327cec380a5%7C0%7C0%7C637152245732296471&amp;sdata=7glGLa1ZxjH1I3FwNj%2Fgqtamf4llNtSq%2BImYM9VTknM%3D&amp;reserved=0=
 
<https://nam02.safelinks.protection.outlook.com/?url=https%3A%2F%2Furldefense.proofpoint.com%2Fv2%2Furl%3Fu%3Dhttp-3A__www.studentclearinghouse.org_%26d%3DDwMFaQ%26c%3DfH4LSaxSgjWoCqli9ejpOKSimqfdcqwvdi9ZfjV67eI%26r%3DL2JLRtXHlhmcrIANbzJ5bJIItX7BypJgN7IAY1kklS0%26m%3D0-1lrb9bNf5O_UNDlxFb2Xqz31Z6UafxAW4sVo70TsY%26s%3D6KKsFoIKTYgAD7pi6C5TjYlGRwjXxnpP9eNEoUg6tCk%26e&amp;data=02%7C01%7Cwferland%40ccri.edu%7C7031cfce83124235a2b008d79e97786b%7Caf75351b37eb4405bf7a7327cec380a5%7C0%7C0%7C637152245732296471&amp;sdata=QFb9zVA%2BzOBnwjYir4k7f07EadMntVoeTHdt3XXVkYE%3D&amp;reserved=0=>
Read the Clearinghouse Today 
Blog<https://nam02.safelinks.protection.outlook.com/?url=https%3A%2F%2Furldefense.proofpoint.com%2Fv2%2Furl%3Fu%3Dhttps-3A__nscblog.org_%26d%3DDwMFaQ%26c%3DfH4LSaxSgjWoCqli9ejpOKSimqfdcqwvdi9ZfjV67eI%26r%3DL2JLRtXHlhmcrIANbzJ5bJIItX7BypJgN7IAY1kklS0%26m%3D0-1lrb9bNf5O_UNDlxFb2Xqz31Z6UafxAW4sVo70TsY%26s%3Dbr2kQUxQhQEaZoZzMS3ZTNXObY1JGi_7GUtwR3uC7kg%26e&amp;data=02%7C01%7Cwferland%40ccri.edu%7C7031cfce83124235a2b008d79e97786b%7Caf75351b37eb4405bf7a7327cec380a5%7C0%7C0%7C637152245732296471&amp;sdata=kJrc3%2BQ0EUxmvoelu%2FimVQt1SnMZr%2Bnl4Y27xqETKDk%3D&amp;reserved=0=>

Winner "2016 When Work Works" & "Excellence in Work-Life Balance"


**********
Replies to EDUCAUSE Community Group emails are sent to the entire community list. If you want to reply only to the 
person who sent the message, copy and paste their email address and forward the email reply. Additional participation 
and subscription information can be found at 
https://nam02.safelinks.protection.outlook.com/?url=https%3A%2F%2Furldefense.proofpoint.com%2Fv2%2Furl%3Fu%3Dhttps-3A__www.educause.edu_community%26d%3DDwIFaQ%26c%3DodzYs1kPF7h99M0Vn1uLzg%26r%3DjKMTIfZiBnBYrk_cRkqhrq0vZwXKksqj0lGxPgjosOo%26m%3DPCH4pSQdJHnemwXCid22jVtPnrEXBJK3q7fAp2ujQXk%26s%3DipDfAu95YytXt6pdbXXudY9CcmGpIRo-e8vMZATurtU%26e&amp;data=02%7C01%7Cwferland%40ccri.edu%7C7031cfce83124235a2b008d79e97786b%7Caf75351b37eb4405bf7a7327cec380a5%7C0%7C0%7C637152245732306469&amp;sdata=pXwZd76Db8AG3xGcC47X5IBonbp%2BIdhd%2BoRRzCDCDUw%3D&amp;reserved=0=
 
<https://nam02.safelinks.protection.outlook.com/?url=https%3A%2F%2Furldefense.proofpoint.com%2Fv2%2Furl%3Fu%3Dhttps-3A__www.educause.edu_community%26d%3DDwMFaQ%26c%3DfH4LSaxSgjWoCqli9ejpOKSimqfdcqwvdi9ZfjV67eI%26r%3DL2JLRtXHlhmcrIANbzJ5bJIItX7BypJgN7IAY1kklS0%26m%3D0-1lrb9bNf5O_UNDlxFb2Xqz31Z6UafxAW4sVo70TsY%26s%3DDhYpkgwVTyvpma9kqNW0oPJOoD9fGCjPJNYoFsmlsjU%26e&amp;data=02%7C01%7Cwferland%40ccri.edu%7C7031cfce83124235a2b008d79e97786b%7Caf75351b37eb4405bf7a7327cec380a5%7C0%7C0%7C637152245732306469&amp;sdata=sffukg5s6qcamU0mkQF7LvjSnIwWjy88pKXZQ1uB63M%3D&amp;reserved=0=>
-------------------------------------------------------------------------------------
*** NOTICE *** This message was sent from an external sender and did not originate from Coast Community College 
District. If you are unsure of the authenticity of the sender, DO NOT click any links or download any attachments. 
Instead, click on FORWARD and address to phishing

**********
Replies to EDUCAUSE Community Group emails are sent to the entire community list. If you want to reply only to the 
person who sent the message, copy and paste their email address and forward the email reply. Additional participation 
and subscription information can be found at 
https://nam02.safelinks.protection.outlook.com/?url=https%3A%2F%2Furldefense.proofpoint.com%2Fv2%2Furl%3Fu%3Dhttps-3A__www.educause.edu_community%26d%3DDwIFaQ%26c%3DodzYs1kPF7h99M0Vn1uLzg%26r%3DjKMTIfZiBnBYrk_cRkqhrq0vZwXKksqj0lGxPgjosOo%26m%3DPCH4pSQdJHnemwXCid22jVtPnrEXBJK3q7fAp2ujQXk%26s%3DipDfAu95YytXt6pdbXXudY9CcmGpIRo-e8vMZATurtU%26e&amp;data=02%7C01%7Cwferland%40ccri.edu%7C7031cfce83124235a2b008d79e97786b%7Caf75351b37eb4405bf7a7327cec380a5%7C0%7C0%7C637152245732306469&amp;sdata=pXwZd76Db8AG3xGcC47X5IBonbp%2BIdhd%2BoRRzCDCDUw%3D&amp;reserved=0=

**********
Replies to EDUCAUSE Community Group emails are sent to the entire community list. If you want to reply only to the 
person who sent the message, copy and paste their email address and forward the email reply. Additional participation 
and subscription information can be found at 
https://nam02.safelinks.protection.outlook.com/?url=https%3A%2F%2Furldefense.proofpoint.com%2Fv2%2Furl%3Fu%3Dhttps-3A__www.educause.edu_community%26d%3DDwIFaQ%26c%3DodzYs1kPF7h99M0Vn1uLzg%26r%3DjKMTIfZiBnBYrk_cRkqhrq0vZwXKksqj0lGxPgjosOo%26m%3DPCH4pSQdJHnemwXCid22jVtPnrEXBJK3q7fAp2ujQXk%26s%3DipDfAu95YytXt6pdbXXudY9CcmGpIRo-e8vMZATurtU%26e&amp;data=02%7C01%7Cwferland%40ccri.edu%7C7031cfce83124235a2b008d79e97786b%7Caf75351b37eb4405bf7a7327cec380a5%7C0%7C0%7C637152245732306469&amp;sdata=pXwZd76Db8AG3xGcC47X5IBonbp%2BIdhd%2BoRRzCDCDUw%3D&amp;reserved=0=

**********
Replies to EDUCAUSE Community Group emails are sent to the entire community list. If you want to reply only to the 
person who sent the message, copy and paste their email address and forward the email reply. Additional participation 
and subscription information can be found at 
https://nam02.safelinks.protection.outlook.com/?url=https%3A%2F%2Furldefense.proofpoint.com%2Fv2%2Furl%3Fu%3Dhttps-3A__www.educause.edu_community%26d%3DDwIFaQ%26c%3DodzYs1kPF7h99M0Vn1uLzg%26r%3DjKMTIfZiBnBYrk_cRkqhrq0vZwXKksqj0lGxPgjosOo%26m%3DPCH4pSQdJHnemwXCid22jVtPnrEXBJK3q7fAp2ujQXk%26s%3DipDfAu95YytXt6pdbXXudY9CcmGpIRo-e8vMZATurtU%26e&amp;data=02%7C01%7Cwferland%40ccri.edu%7C7031cfce83124235a2b008d79e97786b%7Caf75351b37eb4405bf7a7327cec380a5%7C0%7C0%7C637152245732306469&amp;sdata=pXwZd76Db8AG3xGcC47X5IBonbp%2BIdhd%2BoRRzCDCDUw%3D&amp;reserved=0=

------------------------------

Date:    Tue, 14 Jan 2020 08:15:05 -0800
From:    Francisco Chavez <fac3 () STMARYS-CA EDU>
Subject: Re: Ransomware Playbook

Paul,

It is available here.

https://nam02.safelinks.protection.outlook.com/?url=https%3A%2F%2Furldefense.proofpoint.com%2Fv2%2Furl%3Fu%3Dhttps-3A__library.educause.edu_resources_2019_10_national-2Dstudent-2Dclearinghouse-2Dplaybooks%26d%3DDwIFaQ%26c%3DodzYs1kPF7h99M0Vn1uLzg%26r%3DjKMTIfZiBnBYrk_cRkqhrq0vZwXKksqj0lGxPgjosOo%26m%3DPCH4pSQdJHnemwXCid22jVtPnrEXBJK3q7fAp2ujQXk%26s%3DeqI_Z2l1fOW2w2EIp5wHWcEClPv1e2GcoSoXfksZ7bs%26e&amp;data=02%7C01%7Cwferland%40ccri.edu%7C7031cfce83124235a2b008d79e97786b%7Caf75351b37eb4405bf7a7327cec380a5%7C0%7C0%7C637152245732316456&amp;sdata=3MLr9yxVt%2BzY7dQ2qm5MVSjouxsudfrizGcIInmni8s%3D&amp;reserved=0=
  
<https://nam02.safelinks.protection.outlook.com/?url=https%3A%2F%2Furldefense.proofpoint.com%2Fv2%2Furl%3Fu%3Dhttps-3A__library.educause.edu_resources_2019_10_national-2Dstudent-2Dclearinghouse-2Dplaybooks%26d%3DDwIFaQ%26c%3DodzYs1kPF7h99M0Vn1uLzg%26r%3DjKMTIfZiBnBYrk_cRkqhrq0vZwXKksqj0lGxPgjosOo%26m%3DPCH4pSQdJHnemwXCid22jVtPnrEXBJK3q7fAp2ujQXk%26s%3DeqI_Z2l1fOW2w2EIp5wHWcEClPv1e2GcoSoXfksZ7bs%26e&amp;data=02%7C01%7Cwferland%40ccri.edu%7C7031cfce83124235a2b008d79e97786b%7Caf75351b37eb4405bf7a7327cec380a5%7C0%7C0%7C637152245732316456&amp;sdata=3MLr9yxVt%2BzY7dQ2qm5MVSjouxsudfrizGcIInmni8s%3D&amp;reserved=0=



Regards,
Francisco Chavez






Manager - IT Security
fac3 () stmarys-ca edu <mailto:fac3 () stmarys-ca edu>
Office: (925) 631-8236




On Jan 14, 2020, at 8:00 AM, Paul Usama <paul.usama () SAIT CA> wrote:

Hi,

Am not sure if this is still shared, I am interested in the Ransomware Playbook.


<image002.jpg>
Paul Usama
Information Security Analyst
Information Technology Services

Southern Alberta Institute of Technology E.H. Crandell, G200
1301 – 16 Avenue NW, Calgary AB, T2M 0L4
(Cell) 403.836.3489 (Ph) 403.284.8328
Paul.Usama () sait ca <mailto:Paul.Usama () sait ca>







From: The EDUCAUSE Security Community Group Listserv
<SECURITY () LISTSERV EDUCAUSE EDU
<mailto:SECURITY () LISTSERV EDUCAUSE EDU>> On Behalf Of Jamie Schademan
Sent: Friday, October 4, 2019 11:08 AM
To: SECURITY () LISTSERV EDUCAUSE EDU
<mailto:SECURITY () LISTSERV EDUCAUSE EDU>
Subject: Re: [SECURITY] Ransomware Playbook

Me too please.
Jamie
CWU

Jamie Schademan, CISM
Chief Information Security Officer
CWU

From: The EDUCAUSE Security Community Group Listserv
<SECURITY () LISTSERV EDUCAUSE EDU
<mailto:SECURITY () LISTSERV EDUCAUSE EDU>> on behalf of Oberlin, Craig
<coberlin1 () CCCD EDU <mailto:coberlin1 () CCCD EDU>>
Sent: Friday, October 4, 2019 11:03:02 AM
To: SECURITY () LISTSERV EDUCAUSE EDU
<mailto:SECURITY () LISTSERV EDUCAUSE EDU>
<SECURITY () LISTSERV EDUCAUSE EDU
<mailto:SECURITY () LISTSERV EDUCAUSE EDU>>
Subject: Re: [SECURITY] Ransomware Playbook

Caution: This email originated from outside the university.
Do not click on links, open attachments, or reply unless you recognize the sender and know the content is safe. If 
you have questions about this email please forward it tocwuservicedesk () cwu edu <mailto:cwuservicedesk () cwu edu>.




John,
  My thanks and I would appreciate copies as well.

Craig


Craig Oberlin, CISSP
Sr. Director IT, Users Services & Chief Information Security Officer
Coast Community College District P 714.438.6808 coberlin1 () cccd edu
<mailto:coberlin1 () cccd edu> <image001.png>



From: The EDUCAUSE Security Community Group Listserv
[mailto:SECURITY () LISTSERV EDUCAUSE EDU
<mailto:SECURITY () LISTSERV EDUCAUSE EDU>] On Behalf Of Babak Oskouian
Sent: Friday, October 4, 2019 9:49 AM
To: SECURITY () LISTSERV EDUCAUSE EDU
<mailto:SECURITY () LISTSERV EDUCAUSE EDU>
Subject: Re: [SECURITY] Ransomware Playbook

Hi John,

It goes without saying that you and your team must have done a tremendous amount of work to put these playbooks 
together and it is very generous of you to be willing to share them with the community.

So, thank you very much indeed.

Babak

Babak Oskouian, Ph.D. | Director of Networking and Infrastructure
Mills College | 5000 MacArthur Blvd | Oakland, CA 94613-1301
Office: Stern Hall 007; Phone: 510-430-2224  <tel:510-430-2224>



On Fri, Oct 4, 2019 at 4:47 AM John Ramsey <jramsey () studentclearinghouse org <mailto:jramsey () 
studentclearinghouse org>> wrote:
Everybody,

The interest in playbooks, especially ransomware, is great to see (as playbooks are time consuming to create and 
there aren’t enough hours in the day as it is).  I’ve been through a few ransomware incidents, so the playbook is 
battle ready.  However, as some have pointed out, you’ll want to customize to your organization where applicable.  
When my team creates playbooks, our goal is to keep it simple and flexible and easy to follow (versus flipping back 
and forth as you might in a plan.)  The first page is almost always how to easily and quickly contain and then 
triage.  Once that is done, the rest is post event activities.  If you have any questions, please don’t hesitate to 
ask me.  Since the NSC is a third-party service provider for most of you, I’m happy to share what we’re doing in 
order to further gain your confidence in our processes to protect your data.  At the end of the day, we’re one team!

We also have other playbooks that I’m happy to share (maybe it makes sense for Educause or REN-ISAC or both to post 
what all of us are willing to share amongst ourselves.  Then we’ll have a pretty robust set to select from and modify 
as appropriate).  Here are some others that we have finalized:

Notifications and Escalations Playbook.  This walks through the first six hours of an incident in 30-minute 
increments indicating what each stakeholder is doing as well as what message gets communicated and to whom.
DDOS Playbook.  Being one of the top attacks in the Education
industry, this was one of the first ones we did.  Internet 2 was kind enough to provide some guidance on the playbook 
(which we incorporated.) Foreign Travel Playbook.  Actions we take when somebody travels overseas and has the 
requirement to take a company device.
Incident Handling Checklists/Chains of Custody forms.
Network Compromise Playbook.
Spoofed URL Playbook.

John

John Ramsey, Chief Information Security Officer, National Student
Clearinghouse
Certified:  CISSP, CISM, PMP, CSSLP, CRISC, CGEIT
2300 Dulles Station Blvd., Suite 220, Herndon, VA 20171
P: 703.742.4428  |   
https://nam02.safelinks.protection.outlook.com/?url=https%3A%2F%2Furldefense.proofpoint.com%2Fv2%2Furl%3Fu%3Dhttp-3A__www.studentclearinghouse.org%26d%3DDwIFaQ%26c%3DodzYs1kPF7h99M0Vn1uLzg%26r%3DjKMTIfZiBnBYrk_cRkqhrq0vZwXKksqj0lGxPgjosOo%26m%3DPCH4pSQdJHnemwXCid22jVtPnrEXBJK3q7fAp2ujQXk%26s%3DDYLwvVGFZ86lTat6NxteKGY0Nal1lJiGpnys2patNJA%26e&amp;data=02%7C01%7Cwferland%40ccri.edu%7C7031cfce83124235a2b008d79e97786b%7Caf75351b37eb4405bf7a7327cec380a5%7C0%7C0%7C637152245732316456&amp;sdata=3x4hWT88EM6fD6qTfEBwNYrMT6Z3EIOhkhXFYM8eZao%3D&amp;reserved=0=
  
<https://nam02.safelinks.protection.outlook.com/?url=https%3A%2F%2Furldefense.proofpoint.com%2Fv2%2Furl%3Fu%3Dhttp-3A__www.studentclearinghouse.org_%26d%3DDwMFaQ%26c%3DfH4LSaxSgjWoCqli9ejpOKSimqfdcqwvdi9ZfjV67eI%26r%3DL2JLRtXHlhmcrIANbzJ5bJIItX7BypJgN7IAY1kklS0%26m%3D0-1lrb9bNf5O_UNDlxFb2Xqz31Z6UafxAW4sVo70TsY%26s%3D6KKsFoIKTYgAD7pi6C5TjYlGRwjXxnpP9eNEoUg6tCk%26e&amp;data=02%7C01%7Cwferland%40ccri.edu%7C7031cfce83124235a2b008d79e97786b%7Caf75351b37eb4405bf7a7327cec380a5%7C0%7C0%7C637152245732316456&amp;sdata=t14XLBxb1b9bxibevV8CfQn%2FNsrjdKlp1yWS3%2BWeb68%3D&amp;reserved=0=>
Read the Clearinghouse Today Blog
<https://nam02.safelinks.protection.outlook.com/?url=https%3A%2F%2Furldefense.proofpoint.com%2Fv2%2Furl%3Fu%3Dhttps-3A__nscblog.org_%26d%3DD&amp;data=02%7C01%7Cwferland%40ccri.edu%7C7031cfce83124235a2b008d79e97786b%7Caf75351b37eb4405bf7a7327cec380a5%7C0%7C0%7C637152245732316456&amp;sdata=1IWTiZqmVAuQ0t27Fcp2yf4oHh7my4%2BwN6uVY0GJs8M%3D&amp;reserved=0
wMFaQ&c=fH4LSaxSgjWoCqli9ejpOKSimqfdcqwvdi9ZfjV67eI&r=L2JLRtXHlhmcrIAN
bzJ5bJIItX7BypJgN7IAY1kklS0&m=0-1lrb9bNf5O_UNDlxFb2Xqz31Z6UafxAW4sVo70
TsY&s=br2kQUxQhQEaZoZzMS3ZTNXObY1JGi_7GUtwR3uC7kg&e=>

Winner “2016 When Work Works” & “Excellence in Work-Life Balance”


**********
Replies to EDUCAUSE Community Group emails are sent to the entire
community list. If you want to reply only to the person who sent the
message, copy and paste their email address and forward the email
reply. Additional participation and subscription information can be
found at
https://nam02.safelinks.protection.outlook.com/?url=https%3A%2F%2Furldefense.proofpoint.com%2Fv2%2Furl%3Fu%3Dhttps-3A__www.educause.edu_&amp;data=02%7C01%7Cwferland%40ccri.edu%7C7031cfce83124235a2b008d79e97786b%7Caf75351b37eb4405bf7a7327cec380a5%7C0%7C1%7C637152245732326459&amp;sdata=NQCoqGYaq8GXKOkOvuSF4fwCXhmmfhUC%2Bf2SLmpFYVM%3D&amp;reserved=0
community&d=DwIFaQ&c=odzYs1kPF7h99M0Vn1uLzg&r=jKMTIfZiBnBYrk_cRkqhrq0v
ZwXKksqj0lGxPgjosOo&m=PCH4pSQdJHnemwXCid22jVtPnrEXBJK3q7fAp2ujQXk&s=ip
DfAu95YytXt6pdbXXudY9CcmGpIRo-e8vMZATurtU&e=
<https://nam02.safelinks.protection.outlook.com/?url=https%3A%2F%2Furldefense.proofpoint.com%2Fv2%2Furl%3Fu%3Dhttps-3A__www.educause.edu&amp;data=02%7C01%7Cwferland%40ccri.edu%7C7031cfce83124235a2b008d79e97786b%7Caf75351b37eb4405bf7a7327cec380a5%7C0%7C1%7C637152245732326459&amp;sdata=nvJABL2yL0xh5%2Fh9zHrex%2FBKHzkX3Ejmt3V2ablBTt4%3D&amp;reserved=0
_community&d=DwMFaQ&c=fH4LSaxSgjWoCqli9ejpOKSimqfdcqwvdi9ZfjV67eI&r=L2
JLRtXHlhmcrIANbzJ5bJIItX7BypJgN7IAY1kklS0&m=0-1lrb9bNf5O_UNDlxFb2Xqz31
Z6UafxAW4sVo70TsY&s=DhYpkgwVTyvpma9kqNW0oPJOoD9fGCjPJNYoFsmlsjU&e=>
----------------------------------------------------------------------
---------------
*** NOTICE *** This message was sent from an external sender and did
not originate from Coast Community College District. If you are unsure
of the authenticity of the sender, DO NOT click any links or download
any attachments. Instead, click on FORWARD and address to phishing
**********
Replies to EDUCAUSE Community Group emails are sent to the entire
community list. If you want to reply only to the person who sent the
message, copy and paste their email address and forward the email
reply. Additional participation and subscription information can be
found at
https://nam02.safelinks.protection.outlook.com/?url=https%3A%2F%2Furldefense.proofpoint.com%2Fv2%2Furl%3Fu%3Dhttps-3A__www.educause.edu_&amp;data=02%7C01%7Cwferland%40ccri.edu%7C7031cfce83124235a2b008d79e97786b%7Caf75351b37eb4405bf7a7327cec380a5%7C0%7C1%7C637152245732326459&amp;sdata=NQCoqGYaq8GXKOkOvuSF4fwCXhmmfhUC%2Bf2SLmpFYVM%3D&amp;reserved=0
community&d=DwIFaQ&c=odzYs1kPF7h99M0Vn1uLzg&r=jKMTIfZiBnBYrk_cRkqhrq0v
ZwXKksqj0lGxPgjosOo&m=PCH4pSQdJHnemwXCid22jVtPnrEXBJK3q7fAp2ujQXk&s=ip
DfAu95YytXt6pdbXXudY9CcmGpIRo-e8vMZATurtU&e=
<https://nam02.safelinks.protection.outlook.com/?url=https%3A%2F%2Furldefense.proofpoint.com%2Fv2%2Furl%3Fu%3Dhttps-3A__www.educause.edu&amp;data=02%7C01%7Cwferland%40ccri.edu%7C7031cfce83124235a2b008d79e97786b%7Caf75351b37eb4405bf7a7327cec380a5%7C0%7C1%7C637152245732326459&amp;sdata=nvJABL2yL0xh5%2Fh9zHrex%2FBKHzkX3Ejmt3V2ablBTt4%3D&amp;reserved=0
_community&d=DwIFaQ&c=odzYs1kPF7h99M0Vn1uLzg&r=jKMTIfZiBnBYrk_cRkqhrq0
vZwXKksqj0lGxPgjosOo&m=PCH4pSQdJHnemwXCid22jVtPnrEXBJK3q7fAp2ujQXk&s=i
pDfAu95YytXt6pdbXXudY9CcmGpIRo-e8vMZATurtU&e= >
**********
Replies to EDUCAUSE Community Group emails are sent to the entire
community list. If you want to reply only to the person who sent the
message, copy and paste their email address and forward the email
reply. Additional participation and subscription information can be
found at
https://nam02.safelinks.protection.outlook.com/?url=https%3A%2F%2Furldefense.proofpoint.com%2Fv2%2Furl%3Fu%3Dhttps-3A__www.educause.edu_&amp;data=02%7C01%7Cwferland%40ccri.edu%7C7031cfce83124235a2b008d79e97786b%7Caf75351b37eb4405bf7a7327cec380a5%7C0%7C1%7C637152245732326459&amp;sdata=NQCoqGYaq8GXKOkOvuSF4fwCXhmmfhUC%2Bf2SLmpFYVM%3D&amp;reserved=0
community&d=DwIFaQ&c=odzYs1kPF7h99M0Vn1uLzg&r=jKMTIfZiBnBYrk_cRkqhrq0v
ZwXKksqj0lGxPgjosOo&m=PCH4pSQdJHnemwXCid22jVtPnrEXBJK3q7fAp2ujQXk&s=ip
DfAu95YytXt6pdbXXudY9CcmGpIRo-e8vMZATurtU&e=
<https://nam02.safelinks.protection.outlook.com/?url=https%3A%2F%2Furldefense.proofpoint.com%2Fv2%2Furl%3Fu%3Dhttps-3A__www.educause.edu&amp;data=02%7C01%7Cwferland%40ccri.edu%7C7031cfce83124235a2b008d79e97786b%7Caf75351b37eb4405bf7a7327cec380a5%7C0%7C1%7C637152245732326459&amp;sdata=nvJABL2yL0xh5%2Fh9zHrex%2FBKHzkX3Ejmt3V2ablBTt4%3D&amp;reserved=0
_community&d=DwIFaQ&c=odzYs1kPF7h99M0Vn1uLzg&r=jKMTIfZiBnBYrk_cRkqhrq0
vZwXKksqj0lGxPgjosOo&m=PCH4pSQdJHnemwXCid22jVtPnrEXBJK3q7fAp2ujQXk&s=i
pDfAu95YytXt6pdbXXudY9CcmGpIRo-e8vMZATurtU&e= >
**********
Replies to EDUCAUSE Community Group emails are sent to the entire
community list. If you want to reply only to the person who sent the
message, copy and paste their email address and forward the email
reply. Additional participation and subscription information can be
found at
https://nam02.safelinks.protection.outlook.com/?url=https%3A%2F%2Furldefense.proofpoint.com%2Fv2%2Furl%3Fu%3Dhttps-3A__www.educause.edu_&amp;data=02%7C01%7Cwferland%40ccri.edu%7C7031cfce83124235a2b008d79e97786b%7Caf75351b37eb4405bf7a7327cec380a5%7C0%7C1%7C637152245732326459&amp;sdata=NQCoqGYaq8GXKOkOvuSF4fwCXhmmfhUC%2Bf2SLmpFYVM%3D&amp;reserved=0
community&d=DwIFaQ&c=odzYs1kPF7h99M0Vn1uLzg&r=jKMTIfZiBnBYrk_cRkqhrq0v
ZwXKksqj0lGxPgjosOo&m=PCH4pSQdJHnemwXCid22jVtPnrEXBJK3q7fAp2ujQXk&s=ip
DfAu95YytXt6pdbXXudY9CcmGpIRo-e8vMZATurtU&e=
<https://nam02.safelinks.protection.outlook.com/?url=https%3A%2F%2Furldefense.proofpoint.com%2Fv2%2Furl%3Fu%3Dhttps-3A__www.educause.edu&amp;data=02%7C01%7Cwferland%40ccri.edu%7C7031cfce83124235a2b008d79e97786b%7Caf75351b37eb4405bf7a7327cec380a5%7C0%7C1%7C637152245732326459&amp;sdata=nvJABL2yL0xh5%2Fh9zHrex%2FBKHzkX3Ejmt3V2ablBTt4%3D&amp;reserved=0
_community&d=DwIFaQ&c=odzYs1kPF7h99M0Vn1uLzg&r=jKMTIfZiBnBYrk_cRkqhrq0
vZwXKksqj0lGxPgjosOo&m=PCH4pSQdJHnemwXCid22jVtPnrEXBJK3q7fAp2ujQXk&s=i
pDfAu95YytXt6pdbXXudY9CcmGpIRo-e8vMZATurtU&e= >

**********
Replies to EDUCAUSE Community Group emails are sent to the entire community list. If you want to reply only to the 
person who sent the message, copy and paste their email address and forward the email reply. Additional participation 
and subscription information can be found at 
https://nam02.safelinks.protection.outlook.com/?url=https%3A%2F%2Furldefense.proofpoint.com%2Fv2%2Furl%3Fu%3Dhttps-3A__www.educause.edu_community%26d%3DDwIFaQ%26c%3DodzYs1kPF7h99M0Vn1uLzg%26r%3DjKMTIfZiBnBYrk_cRkqhrq0vZwXKksqj0lGxPgjosOo%26m%3DPCH4pSQdJHnemwXCid22jVtPnrEXBJK3q7fAp2ujQXk%26s%3DipDfAu95YytXt6pdbXXudY9CcmGpIRo-e8vMZATurtU%26e&amp;data=02%7C01%7Cwferland%40ccri.edu%7C7031cfce83124235a2b008d79e97786b%7Caf75351b37eb4405bf7a7327cec380a5%7C0%7C0%7C637152245732336447&amp;sdata=76yGCk%2FCNT5M%2FSgjuWo3IXYt2V%2FVghWFnkBhKJMffsc%3D&amp;reserved=0=

------------------------------

Date:    Tue, 14 Jan 2020 17:18:15 +0000
From:    John Ramsey <jramsey () STUDENTCLEARINGHOUSE ORG>
Subject: Re: Ransomware Playbook

I’m also working on getting clearance to share a few more.

John Ramsey, Chief Information Security Officer, National Student Clearinghouse
Certified:  CISSP, CISM, PMP, CSSLP, CRISC, CGEIT
2300 Dulles Station Blvd., Suite 220, Herndon, VA 20171
P: 703.742.4428  |   
https://nam02.safelinks.protection.outlook.com/?url=https%3A%2F%2Furldefense.proofpoint.com%2Fv2%2Furl%3Fu%3Dhttp-3A__www.studentclearinghouse.org%26d%3DDwIFaQ%26c%3DodzYs1kPF7h99M0Vn1uLzg%26r%3DjKMTIfZiBnBYrk_cRkqhrq0vZwXKksqj0lGxPgjosOo%26m%3DPCH4pSQdJHnemwXCid22jVtPnrEXBJK3q7fAp2ujQXk%26s%3DDYLwvVGFZ86lTat6NxteKGY0Nal1lJiGpnys2patNJA%26e&amp;data=02%7C01%7Cwferland%40ccri.edu%7C7031cfce83124235a2b008d79e97786b%7Caf75351b37eb4405bf7a7327cec380a5%7C0%7C0%7C637152245732336447&amp;sdata=x8XR0uoLDUG%2FivWlwHDbx%2FDXvJ63x%2BW7eS2oWBKFD%2BY%3D&amp;reserved=0=
 
<https://nam02.safelinks.protection.outlook.com/?url=https%3A%2F%2Furldefense.proofpoint.com%2Fv2%2Furl%3Fu%3Dhttps-3A__nam01.safelinks.protection.outlook.com_-3Furl-3Dhttp-253A-252F-252Fwww.studentclearinghouse.org-252F-26data-3D02-257C01-257Cjramsey-2540studentclearinghouse.org-257Cb9a990ac212442f4966708d7307ccb81-257C8cc02fea054043a688b6069d3eac0119-257C0-257C1-257C637031184868460784-26sdata-3Drnlj9A1ay7hmHTLXDAE0sESGGvBVWkPDO3NekqwvRIM-253D-26reserved-3D0%26d%3DDwIFaQ%26c%3DodzYs1kPF7h99M0Vn1uLzg%26r%3DjKMTIfZiBnBYrk_cRkqhrq0vZwXKksqj0lGxPgjosOo%26m%3DPCH4pSQdJHnemwXCid22jVtPnrEXBJK3q7fAp2ujQXk%26s%3DisxmLtWHwPT0BWzVHGGwHyGPHa8rYjnKJp0m2m-ArcQ%26e&amp;data=02%7C01%7Cwferland%40ccri.edu%7C7031cfce83124235a2b008d79e97786b%7Caf75351b37eb4405bf7a7327cec380a5%7C0%7C0%7C637152245732336447&amp;sdata=SZ4s92fkaRk8ma9ayQpLU6uLdGWO73NSoaWWR2QnZ70%3D&amp;reserved=0=

Read the Clearinghouse Today 
Blog<https://nam02.safelinks.protection.outlook.com/?url=https%3A%2F%2Furldefense.proofpoint.com%2Fv2%2Furl%3Fu%3Dhttps-3A__nam01.safelinks.protection.outlook.com_-3Furl-3Dhttps-253A-252F-252Fnscblog.org-252F-26data-3D02-257C01-257Cjramsey-2540studentclearinghouse.org-257Cb9a990ac212442f4966708d7307ccb81-257C8cc02fea054043a688b6069d3eac0119-257C0-257C1-257C637031184868460784-26sdata-3D-252BIijkuOIRKNNuBeLyoZeeSAuxkRsldvCfMOFWXWf7wQ-253D-26reserved-3D0%26d%3DDwIFaQ%26c%3DodzYs1kPF7h99M0Vn1uLzg%26r%3DjKMTIfZiBnBYrk_cRkqhrq0vZwXKksqj0lGxPgjosOo%26m%3DPCH4pSQdJHnemwXCid22jVtPnrEXBJK3q7fAp2ujQXk%26s%3DCMq-EIOtSC1ux1H4UmdrlvwTUa7W5JdqF0EgRnromG0%26e&amp;data=02%7C01%7Cwferland%40ccri.edu%7C7031cfce83124235a2b008d79e97786b%7Caf75351b37eb4405bf7a7327cec380a5%7C0%7C0%7C637152245732336447&amp;sdata=v3mjdPoswqmIKxb3wLQIcXeBWEa3nOnsgDIRVZLqqSQ%3D&amp;reserved=0=


Winner “2016 When Work Works” & “Excellence in Work-Life Balance”

From: The EDUCAUSE Security Community Group Listserv <SECURITY () LISTSERV EDUCAUSE EDU> On Behalf Of Francisco Chavez
Sent: Tuesday, January 14, 2020 11:15 AM
To: SECURITY () LISTSERV EDUCAUSE EDU
Subject: Re: [SECURITY] Ransomware Playbook

Paul,

It is available here.

https://nam02.safelinks.protection.outlook.com/?url=https%3A%2F%2Furldefense.proofpoint.com%2Fv2%2Furl%3Fu%3Dhttps-3A__library.educause.edu_resources_2019_10_national-2Dstudent-2Dclearinghouse-2Dplaybooks%26d%3DDwIFaQ%26c%3DodzYs1kPF7h99M0Vn1uLzg%26r%3DjKMTIfZiBnBYrk_cRkqhrq0vZwXKksqj0lGxPgjosOo%26m%3DPCH4pSQdJHnemwXCid22jVtPnrEXBJK3q7fAp2ujQXk%26s%3DeqI_Z2l1fOW2w2EIp5wHWcEClPv1e2GcoSoXfksZ7bs%26e&amp;data=02%7C01%7Cwferland%40ccri.edu%7C7031cfce83124235a2b008d79e97786b%7Caf75351b37eb4405bf7a7327cec380a5%7C0%7C0%7C637152245732346440&amp;sdata=D6CeiCLNx7VV8jEjb1yEGKamLmCh68x60sJQWGpm%2BRQ%3D&amp;reserved=0=


Regards,
Francisco Chavez



[cid:image001.jpg@01D5CAD4.B18F1740]


Manager - IT Security
fac3 () stmarys-ca edu<mailto:fac3 () stmarys-ca edu>
Office: (925) 631-8236




On Jan 14, 2020, at 8:00 AM, Paul Usama <paul.usama () SAIT CA<mailto:paul.usama () SAIT CA>> wrote:

Hi,

Am not sure if this is still shared, I am interested in the Ransomware Playbook.


<image002.jpg>
Paul Usama
Information Security Analyst
Information Technology Services

Southern Alberta Institute of Technology E.H. Crandell, G200
1301 – 16 Avenue NW, Calgary AB, T2M 0L4
(Cell) 403.836.3489 (Ph) 403.284.8328
Paul.Usama () sait ca<mailto:Paul.Usama () sait ca>







From: The EDUCAUSE Security Community Group Listserv <SECURITY () LISTSERV EDUCAUSE EDU<mailto:SECURITY () LISTSERV 
EDUCAUSE EDU>> On Behalf Of Jamie Schademan
Sent: Friday, October 4, 2019 11:08 AM
To: SECURITY () LISTSERV EDUCAUSE EDU<mailto:SECURITY () LISTSERV EDUCAUSE EDU>
Subject: Re: [SECURITY] Ransomware Playbook

Me too please.
Jamie
CWU

Jamie Schademan, CISM
Chief Information Security Officer
CWU

________________________________
From: The EDUCAUSE Security Community Group Listserv <SECURITY () LISTSERV EDUCAUSE EDU<mailto:SECURITY () LISTSERV 
EDUCAUSE EDU>> on behalf of Oberlin, Craig <coberlin1 () CCCD EDU<mailto:coberlin1 () CCCD EDU>>
Sent: Friday, October 4, 2019 11:03:02 AM
To: SECURITY () LISTSERV EDUCAUSE EDU<mailto:SECURITY () LISTSERV EDUCAUSE EDU> <SECURITY () LISTSERV EDUCAUSE 
EDU<mailto:SECURITY () LISTSERV EDUCAUSE EDU>>
Subject: Re: [SECURITY] Ransomware Playbook

Caution: This email originated from outside the university.
Do not click on links, open attachments, or reply unless you recognize the sender and know the content is safe. If you 
have questions about this email please forward it tocwuservicedesk () cwu edu<mailto:cwuservicedesk () cwu edu>.




John,
  My thanks and I would appreciate copies as well.

Craig


Craig Oberlin, CISSP
Sr. Director IT, Users Services & Chief Information Security Officer Coast Community College District P 714.438.6808 
coberlin1 () cccd edu<mailto:coberlin1 () cccd edu>
<image001.png>



From: The EDUCAUSE Security Community Group Listserv [mailto:SECURITY () LISTSERV EDUCAUSE EDU] On Behalf Of Babak 
Oskouian
Sent: Friday, October 4, 2019 9:49 AM
To: SECURITY () LISTSERV EDUCAUSE EDU<mailto:SECURITY () LISTSERV EDUCAUSE EDU>
Subject: Re: [SECURITY] Ransomware Playbook

Hi John,

It goes without saying that you and your team must have done a tremendous amount of work to put these playbooks 
together and it is very generous of you to be willing to share them with the community.

So, thank you very much indeed.

Babak

Babak Oskouian, Ph.D. | Director of Networking and Infrastructure Mills College | 5000 MacArthur Blvd | Oakland, CA 
94613-1301
Office: Stern Hall 007; Phone: 510-430-2224 <tel:510-430-2224>



On Fri, Oct 4, 2019 at 4:47 AM John Ramsey <jramsey () studentclearinghouse org<mailto:jramsey () studentclearinghouse 
org>> wrote:
Everybody,

The interest in playbooks, especially ransomware, is great to see (as playbooks are time consuming to create and there 
aren’t enough hours in the day as it is).  I’ve been through a few ransomware incidents, so the playbook is battle 
ready.  However, as some have pointed out, you’ll want to customize to your organization where applicable.  When my 
team creates playbooks, our goal is to keep it simple and flexible and easy to follow (versus flipping back and forth 
as you might in a plan.)  The first page is almost always how to easily and quickly contain and then triage.  Once that 
is done, the rest is post event activities.  If you have any questions, please don’t hesitate to ask me.  Since the NSC 
is a third-party service provider for most of you, I’m happy to share what we’re doing in order to further gain your 
confidence in our processes to protect your data.  At the end of the day, we’re one team!

We also have other playbooks that I’m happy to share (maybe it makes sense for Educause or REN-ISAC or both to post 
what all of us are willing to share amongst ourselves.  Then we’ll have a pretty robust set to select from and modify 
as appropriate).  Here are some others that we have finalized:


  1.  Notifications and Escalations Playbook.  This walks through the first six hours of an incident in 30-minute 
increments indicating what each stakeholder is doing as well as what message gets communicated and to whom.
  2.  DDOS Playbook.  Being one of the top attacks in the Education industry, this was one of the first ones we did.  
Internet 2 was kind enough to provide some guidance on the playbook (which we incorporated.)
  3.  Foreign Travel Playbook.  Actions we take when somebody travels overseas and has the requirement to take a 
company device.
  4.  Incident Handling Checklists/Chains of Custody forms.
  5.  Network Compromise Playbook.
  6.  Spoofed URL Playbook.

John

John Ramsey, Chief Information Security Officer, National Student Clearinghouse
Certified:  CISSP, CISM, PMP, CSSLP, CRISC, CGEIT
2300 Dulles Station Blvd., Suite 220, Herndon, VA 20171
P: 703.742.4428  |   
https://nam02.safelinks.protection.outlook.com/?url=https%3A%2F%2Furldefense.proofpoint.com%2Fv2%2Furl%3Fu%3Dhttp-3A__www.studentclearinghouse.org%26d%3DDwIFaQ%26c%3DodzYs1kPF7h99M0Vn1uLzg%26r%3DjKMTIfZiBnBYrk_cRkqhrq0vZwXKksqj0lGxPgjosOo%26m%3DPCH4pSQdJHnemwXCid22jVtPnrEXBJK3q7fAp2ujQXk%26s%3DDYLwvVGFZ86lTat6NxteKGY0Nal1lJiGpnys2patNJA%26e&amp;data=02%7C01%7Cwferland%40ccri.edu%7C7031cfce83124235a2b008d79e97786b%7Caf75351b37eb4405bf7a7327cec380a5%7C0%7C0%7C637152245732346440&amp;sdata=slEX9uEzv9fTlYMlVi0gcwoNXJreg2KPO7E06wV0LnQ%3D&amp;reserved=0=
 
<https://nam02.safelinks.protection.outlook.com/?url=https%3A%2F%2Furldefense.proofpoint.com%2Fv2%2Furl%3Fu%3Dhttp-3A__www.studentclearinghouse.org_%26d%3DDwMFaQ%26c%3DfH4LSaxSgjWoCqli9ejpOKSimqfdcqwvdi9ZfjV67eI%26r%3DL2JLRtXHlhmcrIANbzJ5bJIItX7BypJgN7IAY1kklS0%26m%3D0-1lrb9bNf5O_UNDlxFb2Xqz31Z6UafxAW4sVo70TsY%26s%3D6KKsFoIKTYgAD7pi6C5TjYlGRwjXxnpP9eNEoUg6tCk%26e&amp;data=02%7C01%7Cwferland%40ccri.edu%7C7031cfce83124235a2b008d79e97786b%7Caf75351b37eb4405bf7a7327cec380a5%7C0%7C0%7C637152245732346440&amp;sdata=XEjYTvlGiKe39USjxRkD90sAtD466Ll5QW4Awfig%2Fdw%3D&amp;reserved=0=>
Read the Clearinghouse Today 
Blog<https://nam02.safelinks.protection.outlook.com/?url=https%3A%2F%2Furldefense.proofpoint.com%2Fv2%2Furl%3Fu%3Dhttps-3A__nscblog.org_%26d%3DDwMFaQ%26c%3DfH4LSaxSgjWoCqli9ejpOKSimqfdcqwvdi9ZfjV67eI%26r%3DL2JLRtXHlhmcrIANbzJ5bJIItX7BypJgN7IAY1kklS0%26m%3D0-1lrb9bNf5O_UNDlxFb2Xqz31Z6UafxAW4sVo70TsY%26s%3Dbr2kQUxQhQEaZoZzMS3ZTNXObY1JGi_7GUtwR3uC7kg%26e&amp;data=02%7C01%7Cwferland%40ccri.edu%7C7031cfce83124235a2b008d79e97786b%7Caf75351b37eb4405bf7a7327cec380a5%7C0%7C0%7C637152245732346440&amp;sdata=7fPoB%2FSXGOR0iI8H3PUuUpzW2KNoOehs%2F4urijLI7AA%3D&amp;reserved=0=>

Winner “2016 When Work Works” & “Excellence in Work-Life Balance”

**********
Replies to EDUCAUSE Community Group emails are sent to the entire community list. If you want to reply only to the 
person who sent the message, copy and paste their email address and forward the email reply. Additional participation 
and subscription information can be found at 
https://nam02.safelinks.protection.outlook.com/?url=https%3A%2F%2Furldefense.proofpoint.com%2Fv2%2Furl%3Fu%3Dhttps-3A__www.educause.edu_community%26d%3DDwIFaQ%26c%3DodzYs1kPF7h99M0Vn1uLzg%26r%3DjKMTIfZiBnBYrk_cRkqhrq0vZwXKksqj0lGxPgjosOo%26m%3DPCH4pSQdJHnemwXCid22jVtPnrEXBJK3q7fAp2ujQXk%26s%3DipDfAu95YytXt6pdbXXudY9CcmGpIRo-e8vMZATurtU%26e&amp;data=02%7C01%7Cwferland%40ccri.edu%7C7031cfce83124235a2b008d79e97786b%7Caf75351b37eb4405bf7a7327cec380a5%7C0%7C0%7C637152245732356439&amp;sdata=%2FfIlXY6RpVEXfec4jZe6rbIq1sar1k0Ev%2FUJh3PGkPo%3D&amp;reserved=0=
 
<https://nam02.safelinks.protection.outlook.com/?url=https%3A%2F%2Furldefense.proofpoint.com%2Fv2%2Furl%3Fu%3Dhttps-3A__www.educause.edu_community%26d%3DDwMFaQ%26c%3DfH4LSaxSgjWoCqli9ejpOKSimqfdcqwvdi9ZfjV67eI%26r%3DL2JLRtXHlhmcrIANbzJ5bJIItX7BypJgN7IAY1kklS0%26m%3D0-1lrb9bNf5O_UNDlxFb2Xqz31Z6UafxAW4sVo70TsY%26s%3DDhYpkgwVTyvpma9kqNW0oPJOoD9fGCjPJNYoFsmlsjU%26e&amp;data=02%7C01%7Cwferland%40ccri.edu%7C7031cfce83124235a2b008d79e97786b%7Caf75351b37eb4405bf7a7327cec380a5%7C0%7C0%7C637152245732356439&amp;sdata=KVcXDSdRx7pyr16UDEjBMnu%2BG7XArCQckH4MAICrmUY%3D&amp;reserved=0=>
-------------------------------------------------------------------------------------
*** NOTICE *** This message was sent from an external sender and did not originate from Coast Community College 
District. If you are unsure of the authenticity of the sender, DO NOT click any links or download any attachments. 
Instead, click on FORWARD and address to phishing
**********
Replies to EDUCAUSE Community Group emails are sent to the entire community list. If you want to reply only to the 
person who sent the message, copy and paste their email address and forward the email reply. Additional participation 
and subscription information can be found at 
https://nam02.safelinks.protection.outlook.com/?url=https%3A%2F%2Furldefense.proofpoint.com%2Fv2%2Furl%3Fu%3Dhttps-3A__www.educause.edu_community%26d%3DDwIFaQ%26c%3DodzYs1kPF7h99M0Vn1uLzg%26r%3DjKMTIfZiBnBYrk_cRkqhrq0vZwXKksqj0lGxPgjosOo%26m%3DPCH4pSQdJHnemwXCid22jVtPnrEXBJK3q7fAp2ujQXk%26s%3DipDfAu95YytXt6pdbXXudY9CcmGpIRo-e8vMZATurtU%26e&amp;data=02%7C01%7Cwferland%40ccri.edu%7C7031cfce83124235a2b008d79e97786b%7Caf75351b37eb4405bf7a7327cec380a5%7C0%7C0%7C637152245732356439&amp;sdata=%2FfIlXY6RpVEXfec4jZe6rbIq1sar1k0Ev%2FUJh3PGkPo%3D&amp;reserved=0=
**********
Replies to EDUCAUSE Community Group emails are sent to the entire community list. If you want to reply only to the 
person who sent the message, copy and paste their email address and forward the email reply. Additional participation 
and subscription information can be found at 
https://nam02.safelinks.protection.outlook.com/?url=https%3A%2F%2Furldefense.proofpoint.com%2Fv2%2Furl%3Fu%3Dhttps-3A__www.educause.edu_community%26d%3DDwIFaQ%26c%3DodzYs1kPF7h99M0Vn1uLzg%26r%3DjKMTIfZiBnBYrk_cRkqhrq0vZwXKksqj0lGxPgjosOo%26m%3DPCH4pSQdJHnemwXCid22jVtPnrEXBJK3q7fAp2ujQXk%26s%3DipDfAu95YytXt6pdbXXudY9CcmGpIRo-e8vMZATurtU%26e&amp;data=02%7C01%7Cwferland%40ccri.edu%7C7031cfce83124235a2b008d79e97786b%7Caf75351b37eb4405bf7a7327cec380a5%7C0%7C0%7C637152245732356439&amp;sdata=%2FfIlXY6RpVEXfec4jZe6rbIq1sar1k0Ev%2FUJh3PGkPo%3D&amp;reserved=0=
**********
Replies to EDUCAUSE Community Group emails are sent to the entire community list. If you want to reply only to the 
person who sent the message, copy and paste their email address and forward the email reply. Additional participation 
and subscription information can be found at 
https://nam02.safelinks.protection.outlook.com/?url=https%3A%2F%2Furldefense.proofpoint.com%2Fv2%2Furl%3Fu%3Dhttps-3A__www.educause.edu_community%26d%3DDwIFaQ%26c%3DodzYs1kPF7h99M0Vn1uLzg%26r%3DjKMTIfZiBnBYrk_cRkqhrq0vZwXKksqj0lGxPgjosOo%26m%3DPCH4pSQdJHnemwXCid22jVtPnrEXBJK3q7fAp2ujQXk%26s%3DipDfAu95YytXt6pdbXXudY9CcmGpIRo-e8vMZATurtU%26e&amp;data=02%7C01%7Cwferland%40ccri.edu%7C7031cfce83124235a2b008d79e97786b%7Caf75351b37eb4405bf7a7327cec380a5%7C0%7C0%7C637152245732356439&amp;sdata=%2FfIlXY6RpVEXfec4jZe6rbIq1sar1k0Ev%2FUJh3PGkPo%3D&amp;reserved=0=


**********
Replies to EDUCAUSE Community Group emails are sent to the entire community list. If you want to reply only to the 
person who sent the message, copy and paste their email address and forward the email reply. Additional participation 
and subscription information can be found at 
https://nam02.safelinks.protection.outlook.com/?url=https%3A%2F%2Furldefense.proofpoint.com%2Fv2%2Furl%3Fu%3Dhttps-3A__www.educause.edu_community%26d%3DDwIFaQ%26c%3DodzYs1kPF7h99M0Vn1uLzg%26r%3DjKMTIfZiBnBYrk_cRkqhrq0vZwXKksqj0lGxPgjosOo%26m%3DPCH4pSQdJHnemwXCid22jVtPnrEXBJK3q7fAp2ujQXk%26s%3DipDfAu95YytXt6pdbXXudY9CcmGpIRo-e8vMZATurtU%26e&amp;data=02%7C01%7Cwferland%40ccri.edu%7C7031cfce83124235a2b008d79e97786b%7Caf75351b37eb4405bf7a7327cec380a5%7C0%7C0%7C637152245732366430&amp;sdata=e3wOc0nANaI%2FcTFjcV0KRGnPiInE1%2Fa3UTOu1LvItWA%3D&amp;reserved=0=

**********
Replies to EDUCAUSE Community Group emails are sent to the entire community list. If you want to reply only to the 
person who sent the message, copy and paste their email address and forward the email reply. Additional participation 
and subscription information can be found at 
https://nam02.safelinks.protection.outlook.com/?url=https%3A%2F%2Furldefense.proofpoint.com%2Fv2%2Furl%3Fu%3Dhttps-3A__www.educause.edu_commun%26d%3DDwIFaQ%26c%3DodzYs1kPF7h99M0Vn1uLzg%26r%3DjKMTIfZiBnBYrk_cRkqhrq0vZwXKksqj0lGxPgjosOo%26m%3DPCH4pSQdJHnemwXCid22jVtPnrEXBJK3q7fAp2ujQXk%26s%3DYRUZrE3p-yQqIe_4C1f2UCdi4PJjHfYt60g5qaqrqBw%26e&amp;data=02%7C01%7Cwferland%40ccri.edu%7C7031cfce83124235a2b008d79e97786b%7Caf75351b37eb4405bf7a7327cec380a5%7C0%7C0%7C637152245732366430&amp;sdata=DZt2XWvu2gEJXBs4meguJZniR32q%2F8Ff9qAyXz345Gw%3D&amp;reserved=0=

------------------------------

Date:    Tue, 14 Jan 2020 17:23:52 +0000
From:    Paul Usama <paul.usama () SAIT CA>
Subject: Re: Ransomware Playbook

Thanks

From: The EDUCAUSE Security Community Group Listserv <SECURITY () LISTSERV EDUCAUSE EDU> On Behalf Of Francisco Chavez
Sent: Tuesday, January 14, 2020 9:15 AM
To: SECURITY () LISTSERV EDUCAUSE EDU
Subject: Re: [SECURITY] Ransomware Playbook

Paul,

It is available here.

https://nam02.safelinks.protection.outlook.com/?url=https%3A%2F%2Furldefense.proofpoint.com%2Fv2%2Furl%3Fu%3Dhttps-3A__library.educause.edu_resources_2019_10_national-2Dstudent-2Dclearinghouse-2Dplaybooks%26d%3DDwIFaQ%26c%3DodzYs1kPF7h99M0Vn1uLzg%26r%3DjKMTIfZiBnBYrk_cRkqhrq0vZwXKksqj0lGxPgjosOo%26m%3DPCH4pSQdJHnemwXCid22jVtPnrEXBJK3q7fAp2ujQXk%26s%3DeqI_Z2l1fOW2w2EIp5wHWcEClPv1e2GcoSoXfksZ7bs%26e&amp;data=02%7C01%7Cwferland%40ccri.edu%7C7031cfce83124235a2b008d79e97786b%7Caf75351b37eb4405bf7a7327cec380a5%7C0%7C0%7C637152245732366430&amp;sdata=3Tg0E0D63OLqNLc8GroYH%2FSxlC%2FF56Str9n%2BFRmTyvI%3D&amp;reserved=0=


Regards,
Francisco Chavez



[cid:image001.jpg@01D5CAC4.B737B5E0]


Manager - IT Security
fac3 () stmarys-ca edu<mailto:fac3 () stmarys-ca edu>
Office: (925) 631-8236




On Jan 14, 2020, at 8:00 AM, Paul Usama <paul.usama () SAIT CA<mailto:paul.usama () SAIT CA>> wrote:

Hi,

Am not sure if this is still shared, I am interested in the Ransomware Playbook.


<image002.jpg>
Paul Usama
Information Security Analyst
Information Technology Services

Southern Alberta Institute of Technology E.H. Crandell, G200
1301 – 16 Avenue NW, Calgary AB, T2M 0L4
(Cell) 403.836.3489 (Ph) 403.284.8328
Paul.Usama () sait ca<mailto:Paul.Usama () sait ca>







From: The EDUCAUSE Security Community Group Listserv <SECURITY () LISTSERV EDUCAUSE EDU<mailto:SECURITY () LISTSERV 
EDUCAUSE EDU>> On Behalf Of Jamie Schademan
Sent: Friday, October 4, 2019 11:08 AM
To: SECURITY () LISTSERV EDUCAUSE EDU<mailto:SECURITY () LISTSERV EDUCAUSE EDU>
Subject: Re: [SECURITY] Ransomware Playbook

Me too please.
Jamie
CWU

Jamie Schademan, CISM
Chief Information Security Officer
CWU

________________________________
From: The EDUCAUSE Security Community Group Listserv <SECURITY () LISTSERV EDUCAUSE EDU<mailto:SECURITY () LISTSERV 
EDUCAUSE EDU>> on behalf of Oberlin, Craig <coberlin1 () CCCD EDU<mailto:coberlin1 () CCCD EDU>>
Sent: Friday, October 4, 2019 11:03:02 AM
To: SECURITY () LISTSERV EDUCAUSE EDU<mailto:SECURITY () LISTSERV EDUCAUSE EDU> <SECURITY () LISTSERV EDUCAUSE 
EDU<mailto:SECURITY () LISTSERV EDUCAUSE EDU>>
Subject: Re: [SECURITY] Ransomware Playbook

Caution: This email originated from outside the university.
Do not click on links, open attachments, or reply unless you recognize the sender and know the content is safe. If you 
have questions about this email please forward it tocwuservicedesk () cwu edu<mailto:cwuservicedesk () cwu edu>.




John,
  My thanks and I would appreciate copies as well.

Craig


Craig Oberlin, CISSP
Sr. Director IT, Users Services & Chief Information Security Officer Coast Community College District P 714.438.6808 
coberlin1 () cccd edu<mailto:coberlin1 () cccd edu>
<image001.png>



From: The EDUCAUSE Security Community Group Listserv [mailto:SECURITY () LISTSERV EDUCAUSE EDU] On Behalf Of Babak 
Oskouian
Sent: Friday, October 4, 2019 9:49 AM
To: SECURITY () LISTSERV EDUCAUSE EDU<mailto:SECURITY () LISTSERV EDUCAUSE EDU>
Subject: Re: [SECURITY] Ransomware Playbook

Hi John,

It goes without saying that you and your team must have done a tremendous amount of work to put these playbooks 
together and it is very generous of you to be willing to share them with the community.

So, thank you very much indeed.

Babak

Babak Oskouian, Ph.D. | Director of Networking and Infrastructure Mills College | 5000 MacArthur Blvd | Oakland, CA 
94613-1301
Office: Stern Hall 007; Phone: 510-430-2224 <tel:510-430-2224>



On Fri, Oct 4, 2019 at 4:47 AM John Ramsey <jramsey () studentclearinghouse org<mailto:jramsey () studentclearinghouse 
org>> wrote:
Everybody,

The interest in playbooks, especially ransomware, is great to see (as playbooks are time consuming to create and there 
aren’t enough hours in the day as it is).  I’ve been through a few ransomware incidents, so the playbook is battle 
ready.  However, as some have pointed out, you’ll want to customize to your organization where applicable.  When my 
team creates playbooks, our goal is to keep it simple and flexible and easy to follow (versus flipping back and forth 
as you might in a plan.)  The first page is almost always how to easily and quickly contain and then triage.  Once that 
is done, the rest is post event activities.  If you have any questions, please don’t hesitate to ask me.  Since the NSC 
is a third-party service provider for most of you, I’m happy to share what we’re doing in order to further gain your 
confidence in our processes to protect your data.  At the end of the day, we’re one team!

We also have other playbooks that I’m happy to share (maybe it makes sense for Educause or REN-ISAC or both to post 
what all of us are willing to share amongst ourselves.  Then we’ll have a pretty robust set to select from and modify 
as appropriate).  Here are some others that we have finalized:


  1.  Notifications and Escalations Playbook.  This walks through the first six hours of an incident in 30-minute 
increments indicating what each stakeholder is doing as well as what message gets communicated and to whom.
  2.  DDOS Playbook.  Being one of the top attacks in the Education industry, this was one of the first ones we did.  
Internet 2 was kind enough to provide some guidance on the playbook (which we incorporated.)
  3.  Foreign Travel Playbook.  Actions we take when somebody travels overseas and has the requirement to take a 
company device.
  4.  Incident Handling Checklists/Chains of Custody forms.
  5.  Network Compromise Playbook.
  6.  Spoofed URL Playbook.

John

John Ramsey, Chief Information Security Officer, National Student Clearinghouse
Certified:  CISSP, CISM, PMP, CSSLP, CRISC, CGEIT
2300 Dulles Station Blvd., Suite 220, Herndon, VA 20171
P: 703.742.4428  |   
https://nam02.safelinks.protection.outlook.com/?url=https%3A%2F%2Furldefense.proofpoint.com%2Fv2%2Furl%3Fu%3Dhttp-3A__www.studentclearinghouse.org%26d%3DDwIFaQ%26c%3DodzYs1kPF7h99M0Vn1uLzg%26r%3DjKMTIfZiBnBYrk_cRkqhrq0vZwXKksqj0lGxPgjosOo%26m%3DPCH4pSQdJHnemwXCid22jVtPnrEXBJK3q7fAp2ujQXk%26s%3DDYLwvVGFZ86lTat6NxteKGY0Nal1lJiGpnys2patNJA%26e&amp;data=02%7C01%7Cwferland%40ccri.edu%7C7031cfce83124235a2b008d79e97786b%7Caf75351b37eb4405bf7a7327cec380a5%7C0%7C0%7C637152245732366430&amp;sdata=BOHSzlfSyYuEp1uPiiXam3ubPAObiss%2BiXxewMxgGgk%3D&amp;reserved=0=
 
<https://nam02.safelinks.protection.outlook.com/?url=https%3A%2F%2Furldefense.proofpoint.com%2Fv2%2Furl%3Fu%3Dhttp-3A__www.studentclearinghouse.org_%26d%3DDwMFaQ%26c%3DfH4LSaxSgjWoCqli9ejpOKSimqfdcqwvdi9ZfjV67eI%26r%3DL2JLRtXHlhmcrIANbzJ5bJIItX7BypJgN7IAY1kklS0%26m%3D0-1lrb9bNf5O_UNDlxFb2Xqz31Z6UafxAW4sVo70TsY%26s%3D6KKsFoIKTYgAD7pi6C5TjYlGRwjXxnpP9eNEoUg6tCk%26e&amp;data=02%7C01%7Cwferland%40ccri.edu%7C7031cfce83124235a2b008d79e97786b%7Caf75351b37eb4405bf7a7327cec380a5%7C0%7C0%7C637152245732366430&amp;sdata=pG%2Bj83Dlts5FJ%2BsHIU8sRnMiHrRp1xa8HJk0oGeh9Eo%3D&amp;reserved=0=>
Read the Clearinghouse Today 
Blog<https://nam02.safelinks.protection.outlook.com/?url=https%3A%2F%2Furldefense.proofpoint.com%2Fv2%2Furl%3Fu%3Dhttps-3A__nscblog.org_%26d%3DDwMFaQ%26c%3DfH4LSaxSgjWoCqli9ejpOKSimqfdcqwvdi9ZfjV67eI%26r%3DL2JLRtXHlhmcrIANbzJ5bJIItX7BypJgN7IAY1kklS0%26m%3D0-1lrb9bNf5O_UNDlxFb2Xqz31Z6UafxAW4sVo70TsY%26s%3Dbr2kQUxQhQEaZoZzMS3ZTNXObY1JGi_7GUtwR3uC7kg%26e&amp;data=02%7C01%7Cwferland%40ccri.edu%7C7031cfce83124235a2b008d79e97786b%7Caf75351b37eb4405bf7a7327cec380a5%7C0%7C0%7C637152245732376417&amp;sdata=9d3EkzcUBdkvU3BC9ncLxQvhsY1XxYIw8f%2B5cYgr8A4%3D&amp;reserved=0=>

Winner “2016 When Work Works” & “Excellence in Work-Life Balance”

**********
Replies to EDUCAUSE Community Group emails are sent to the entire community list. If you want to reply only to the 
person who sent the message, copy and paste their email address and forward the email reply. Additional participation 
and subscription information can be found at 
https://nam02.safelinks.protection.outlook.com/?url=https%3A%2F%2Furldefense.proofpoint.com%2Fv2%2Furl%3Fu%3Dhttps-3A__www.educause.edu_community%26d%3DDwIFaQ%26c%3DodzYs1kPF7h99M0Vn1uLzg%26r%3DjKMTIfZiBnBYrk_cRkqhrq0vZwXKksqj0lGxPgjosOo%26m%3DPCH4pSQdJHnemwXCid22jVtPnrEXBJK3q7fAp2ujQXk%26s%3DipDfAu95YytXt6pdbXXudY9CcmGpIRo-e8vMZATurtU%26e&amp;data=02%7C01%7Cwferland%40ccri.edu%7C7031cfce83124235a2b008d79e97786b%7Caf75351b37eb4405bf7a7327cec380a5%7C0%7C0%7C637152245732376417&amp;sdata=jHavnz26ZfoNKOlnh%2BVlycB%2FmI%2FtscKHboL2aw1H4cw%3D&amp;reserved=0=
 
<https://nam02.safelinks.protection.outlook.com/?url=https%3A%2F%2Furldefense.proofpoint.com%2Fv2%2Furl%3Fu%3Dhttps-3A__www.educause.edu_community%26d%3DDwMFaQ%26c%3DfH4LSaxSgjWoCqli9ejpOKSimqfdcqwvdi9ZfjV67eI%26r%3DL2JLRtXHlhmcrIANbzJ5bJIItX7BypJgN7IAY1kklS0%26m%3D0-1lrb9bNf5O_UNDlxFb2Xqz31Z6UafxAW4sVo70TsY%26s%3DDhYpkgwVTyvpma9kqNW0oPJOoD9fGCjPJNYoFsmlsjU%26e&amp;data=02%7C01%7Cwferland%40ccri.edu%7C7031cfce83124235a2b008d79e97786b%7Caf75351b37eb4405bf7a7327cec380a5%7C0%7C0%7C637152245732376417&amp;sdata=MoI4udOgtp5I3ajbzr35B5Pt3rR5vpcqFHsscHArY58%3D&amp;reserved=0=>
-------------------------------------------------------------------------------------
*** NOTICE *** This message was sent from an external sender and did not originate from Coast Community College 
District. If you are unsure of the authenticity of the sender, DO NOT click any links or download any attachments. 
Instead, click on FORWARD and address to phishing
**********
Replies to EDUCAUSE Community Group emails are sent to the entire community list. If you want to reply only to the 
person who sent the message, copy and paste their email address and forward the email reply. Additional participation 
and subscription information can be found at 
https://nam02.safelinks.protection.outlook.com/?url=https%3A%2F%2Furldefense.proofpoint.com%2Fv2%2Furl%3Fu%3Dhttps-3A__www.educause.edu_community%26d%3DDwIFaQ%26c%3DodzYs1kPF7h99M0Vn1uLzg%26r%3DjKMTIfZiBnBYrk_cRkqhrq0vZwXKksqj0lGxPgjosOo%26m%3DPCH4pSQdJHnemwXCid22jVtPnrEXBJK3q7fAp2ujQXk%26s%3DipDfAu95YytXt6pdbXXudY9CcmGpIRo-e8vMZATurtU%26e&amp;data=02%7C01%7Cwferland%40ccri.edu%7C7031cfce83124235a2b008d79e97786b%7Caf75351b37eb4405bf7a7327cec380a5%7C0%7C0%7C637152245732376417&amp;sdata=jHavnz26ZfoNKOlnh%2BVlycB%2FmI%2FtscKHboL2aw1H4cw%3D&amp;reserved=0=
**********
Replies to EDUCAUSE Community Group emails are sent to the entire community list. If you want to reply only to the 
person who sent the message, copy and paste their email address and forward the email reply. Additional participation 
and subscription information can be found at 
https://nam02.safelinks.protection.outlook.com/?url=https%3A%2F%2Furldefense.proofpoint.com%2Fv2%2Furl%3Fu%3Dhttps-3A__www.educause.edu_community%26d%3DDwIFaQ%26c%3DodzYs1kPF7h99M0Vn1uLzg%26r%3DjKMTIfZiBnBYrk_cRkqhrq0vZwXKksqj0lGxPgjosOo%26m%3DPCH4pSQdJHnemwXCid22jVtPnrEXBJK3q7fAp2ujQXk%26s%3DipDfAu95YytXt6pdbXXudY9CcmGpIRo-e8vMZATurtU%26e&amp;data=02%7C01%7Cwferland%40ccri.edu%7C7031cfce83124235a2b008d79e97786b%7Caf75351b37eb4405bf7a7327cec380a5%7C0%7C0%7C637152245732376417&amp;sdata=jHavnz26ZfoNKOlnh%2BVlycB%2FmI%2FtscKHboL2aw1H4cw%3D&amp;reserved=0=
**********
Replies to EDUCAUSE Community Group emails are sent to the entire community list. If you want to reply only to the 
person who sent the message, copy and paste their email address and forward the email reply. Additional participation 
and subscription information can be found at 
https://nam02.safelinks.protection.outlook.com/?url=https%3A%2F%2Furldefense.proofpoint.com%2Fv2%2Furl%3Fu%3Dhttps-3A__www.educause.edu_community%26d%3DDwIFaQ%26c%3DodzYs1kPF7h99M0Vn1uLzg%26r%3DjKMTIfZiBnBYrk_cRkqhrq0vZwXKksqj0lGxPgjosOo%26m%3DPCH4pSQdJHnemwXCid22jVtPnrEXBJK3q7fAp2ujQXk%26s%3DipDfAu95YytXt6pdbXXudY9CcmGpIRo-e8vMZATurtU%26e&amp;data=02%7C01%7Cwferland%40ccri.edu%7C7031cfce83124235a2b008d79e97786b%7Caf75351b37eb4405bf7a7327cec380a5%7C0%7C0%7C637152245732386415&amp;sdata=OMuexxgW%2BM648Y6Ajmw9KE75iV%2F24EEhaBLq4p4c298%3D&amp;reserved=0=


**********
Replies to EDUCAUSE Community Group emails are sent to the entire community list. If you want to reply only to the 
person who sent the message, copy and paste their email address and forward the email reply. Additional participation 
and subscription information can be found at 
https://nam02.safelinks.protection.outlook.com/?url=https%3A%2F%2Furldefense.proofpoint.com%2Fv2%2Furl%3Fu%3Dhttps-3A__www.educause.edu_community%26d%3DDwIFaQ%26c%3DodzYs1kPF7h99M0Vn1uLzg%26r%3DjKMTIfZiBnBYrk_cRkqhrq0vZwXKksqj0lGxPgjosOo%26m%3DPCH4pSQdJHnemwXCid22jVtPnrEXBJK3q7fAp2ujQXk%26s%3DipDfAu95YytXt6pdbXXudY9CcmGpIRo-e8vMZATurtU%26e&amp;data=02%7C01%7Cwferland%40ccri.edu%7C7031cfce83124235a2b008d79e97786b%7Caf75351b37eb4405bf7a7327cec380a5%7C0%7C0%7C637152245732386415&amp;sdata=OMuexxgW%2BM648Y6Ajmw9KE75iV%2F24EEhaBLq4p4c298%3D&amp;reserved=0=

**********
Replies to EDUCAUSE Community Group emails are sent to the entire community list. If you want to reply only to the 
person who sent the message, copy and paste their email address and forward the email reply. Additional participation 
and subscription information can be found at 
https://nam02.safelinks.protection.outlook.com/?url=https%3A%2F%2Furldefense.proofpoint.com%2Fv2%2Furl%3Fu%3Dhttps-3A__www.educause.edu_comm%26d%3DDwIFaQ%26c%3DodzYs1kPF7h99M0Vn1uLzg%26r%3DjKMTIfZiBnBYrk_cRkqhrq0vZwXKksqj0lGxPgjosOo%26m%3DPCH4pSQdJHnemwXCid22jVtPnrEXBJK3q7fAp2ujQXk%26s%3DICJfiJqqh5bP6RqS29xcePtEv4_-1I67OLM8w1eeiA0%26e&amp;data=02%7C01%7Cwferland%40ccri.edu%7C7031cfce83124235a2b008d79e97786b%7Caf75351b37eb4405bf7a7327cec380a5%7C0%7C0%7C637152245732386415&amp;sdata=jfkHcauw%2B6l4SReus8TI0F6P%2BswWFxW3YYqlMlBkWhs%3D&amp;reserved=0=

------------------------------

End of SECURITY Digest - 13 Jan 2020 to 14 Jan 2020 (#2020-10)
**************************************************************

**********
Replies to EDUCAUSE Community Group emails are sent to the entire community list. If you want to reply only to the 
person who sent the message, copy and paste their email address and forward the email reply. Additional participation 
and subscription information can be found at 
https://nam02.safelinks.protection.outlook.com/?url=https%3A%2F%2Fwww.educause.edu%2Fcommunity&amp;data=02%7C01%7Cwferland%40ccri.edu%7C7031cfce83124235a2b008d79e97786b%7Caf75351b37eb4405bf7a7327cec380a5%7C0%7C1%7C637152245732386415&amp;sdata=R9NXxG03xi8ZJBcvn0c54D1B102iNymKrzoDd%2FyD138%3D&amp;reserved=0

**********
Replies to EDUCAUSE Community Group emails are sent to the entire community list. If you want to reply only to the 
person who sent the message, copy and paste their email address and forward the email reply. Additional participation 
and subscription information can be found at 
https://nam02.safelinks.protection.outlook.com/?url=https%3A%2F%2Fwww.educause.edu%2Fcommunity&amp;data=02%7C01%7Cwferland%40ccri.edu%7C7031cfce83124235a2b008d79e97786b%7Caf75351b37eb4405bf7a7327cec380a5%7C0%7C1%7C637152245732386415&amp;sdata=R9NXxG03xi8ZJBcvn0c54D1B102iNymKrzoDd%2FyD138%3D&amp;reserved=0

------------------------------

Date:    Wed, 15 Jan 2020 15:15:54 +0000
From:    Bryce Cunningham <bcunningham () COLLEGES-FENWAY ORG>
Subject: SOP for Releasing Private Data Generated by Deceased Student?

At the institutions I serve, we’ve had a few tragic cases of deceased students where the parents or other family 
requested access to the deceased’s emails, laptop contents, or both. If your institution has a request form or policy 
for this situation I’d appreciate you sharing it since I’ve been asked if we can establish a procedure that handles 
such requests in order to reduce our response time and improve consistency.  My question is only about policy and SOP, 
*not* the legal question of whether or not the data should be released (that is determined by whether the deceased has 
a Will covering their digital legacy).

Bryce Cunningham, MS, CISM, CISSP
Information Security Officer
Colleges of the Fenway:
Mass College of Art and Design &
Wentworth Institute of Technology
C: 617-396-7052




**********
Replies to EDUCAUSE Community Group emails are sent to the entire community list. If you want to reply only to the 
person who sent the message, copy and paste their email address and forward the email reply. Additional participation 
and subscription information can be found at 
https://nam02.safelinks.protection.outlook.com/?url=https%3A%2F%2Fwww.educause.edu%2Fcommun&amp;data=02%7C01%7Cwferland%40ccri.edu%7C7031cfce83124235a2b008d79e97786b%7Caf75351b37eb4405bf7a7327cec380a5%7C0%7C1%7C637152245732386415&amp;sdata=TzNP6Cxj%2BLYv0WkPL61I8go6m6%2FvOFDWcW6lOFDNMhs%3D&amp;reserved=0

------------------------------

Date:    Wed, 15 Jan 2020 10:55:26 -0500
From:    Eva Lorenz <vapensiere () GMAIL COM>
Subject: Re: SOP for Releasing Private Data Generated by Deceased Student?

Please contact me offline and I can share the handful of cases I was
involved in and how they were handled

Eva

On Wed, Jan 15, 2020 at 10:16 AM Bryce Cunningham <
bcunningham () colleges-fenway org> wrote:

At the institutions I serve, we’ve had a few tragic cases of deceased
students where the parents or other family requested access to the
deceased’s emails, laptop contents, or both. If your institution has a
request form or policy for this situation I’d appreciate you sharing it
since I’ve been asked if we can establish a procedure that handles such
requests in order to reduce our response time and improve consistency.  My
question is only about policy and SOP, **not** the legal question of
whether or not the data should be released (that is determined by whether
the deceased has a Will covering their digital legacy).



Bryce Cunningham, MS, CISM, CISSP

Information Security Officer

Colleges of the Fenway:

Mass College of Art and Design &

Wentworth Institute of Technology

*C: *617-396-7052







**********
Replies to EDUCAUSE Community Group emails are sent to the entire
community list. If you want to reply only to the person who sent the
message, copy and paste their email address and forward the email reply.
Additional participation and subscription information can be found at
https://nam02.safelinks.protection.outlook.com/?url=https%3A%2F%2Fwww.educause.edu%2Fcommunity&amp;data=02%7C01%7Cwferland%40ccri.edu%7C7031cfce83124235a2b008d79e97786b%7Caf75351b37eb4405bf7a7327cec380a5%7C0%7C1%7C637152245732396404&amp;sdata=hL0zqO99VLweqB9nvZLBT0O7QvOK1kSI4CB%2BfSBKYAc%3D&amp;reserved=0


**********
Replies to EDUCAUSE Community Group emails are sent to the entire community list. If you want to reply only to the 
person who sent the message, copy and paste their email address and forward the email reply. Additional participation 
and subscription information can be found at 
https://nam02.safelinks.protection.outlook.com/?url=https%3A%2F%2Fwww.educause.edu%2Fcommunity&amp;data=02%7C01%7Cwferland%40ccri.edu%7C7031cfce83124235a2b008d79e97786b%7Caf75351b37eb4405bf7a7327cec380a5%7C0%7C1%7C637152245732396404&amp;sdata=hL0zqO99VLweqB9nvZLBT0O7QvOK1kSI4CB%2BfSBKYAc%3D&amp;reserved=0

------------------------------

Date:    Wed, 15 Jan 2020 11:12:59 -0500
From:    randy <marchany () VT EDU>
Subject: VA Tech SANS Onsite Class 3/9-14/2020 Simulcast Update

Just wanted to let everyone know that the simulcast registration link for
the SANS SEC 530 class hosted at VA Tech on 3/9-14/2020 is active. Onsite
and simulcast registration info is at
https://nam02.safelinks.protection.outlook.com/?url=http%3A%2F%2Fwww.cpe.vt.edu%2Fisect%2Fregistration.html&amp;data=02%7C01%7Cwferland%40ccri.edu%7C7031cfce83124235a2b008d79e97786b%7Caf75351b37eb4405bf7a7327cec380a5%7C0%7C0%7C637152245732396404&amp;sdata=hJjuU107zAjN7ObyA%2FBTwv3oBZX3JNsT48j8QGV13QY%3D&amp;reserved=0.

If you have any questions, please let me know. Thanks.

-Randy Marchany
VA Tech IT Security Office and Lab

**********
Replies to EDUCAUSE Community Group emails are sent to the entire community list. If you want to reply only to the 
person who sent the message, copy and paste their email address and forward the email reply. Additional participation 
and subscription information can be found at 
https://nam02.safelinks.protection.outlook.com/?url=https%3A%2F%2Fwww.educause.edu%2Fcommunity&amp;data=02%7C01%7Cwferland%40ccri.edu%7C7031cfce83124235a2b008d79e97786b%7Caf75351b37eb4405bf7a7327cec380a5%7C0%7C1%7C637152245732396404&amp;sdata=hL0zqO99VLweqB9nvZLBT0O7QvOK1kSI4CB%2BfSBKYAc%3D&amp;reserved=0

------------------------------

Date:    Wed, 15 Jan 2020 16:13:35 +0000
From:    "Ullman, Catherine" <cende () BUFFALO EDU>
Subject: Re: SOP for Releasing Private Data Generated by Deceased Student?

Hi Bryce,



We typically defer to the Office of General Counsel and require the requestor to provide proof of authorization such as 
documentation that they’re executor of the will.  Here is our official policy:



 
<https://nam02.safelinks.protection.outlook.com/?url=http%3A%2F%2Fwww.buffalo.edu%2Fubit%2Fpolicies%2Fguidance-documents%2Faccessing-accounts-deceased-incapacitated.html&amp;data=02%7C01%7Cwferland%40ccri.edu%7C7031cfce83124235a2b008d79e97786b%7Caf75351b37eb4405bf7a7327cec380a5%7C0%7C0%7C637152245732396404&amp;sdata=MaHG5LsZT3u9JWZCStJrrhvwTaI5rltrjFvykZ2vvvk%3D&amp;reserved=0>
 
https://nam02.safelinks.protection.outlook.com/?url=http%3A%2F%2Fwww.buffalo.edu%2Fubit%2Fpolicies%2Fguidance-documents%2Faccessing-accounts-deceased-incapacitated.html&amp;data=02%7C01%7Cwferland%40ccri.edu%7C7031cfce83124235a2b008d79e97786b%7Caf75351b37eb4405bf7a7327cec380a5%7C0%7C0%7C637152245732396404&amp;sdata=MaHG5LsZT3u9JWZCStJrrhvwTaI5rltrjFvykZ2vvvk%3D&amp;reserved=0



Hope that helps.



Best,

Cathy





Dr. Catherine J Ullman

Senior Information Security Analyst

Information Security Office

University at Buffalo

 <mailto:cende () buffalo edu> cende () buffalo edu







From: The EDUCAUSE Security Community Group Listserv <SECURITY () LISTSERV EDUCAUSE EDU> On Behalf Of Bryce Cunningham
Sent: Wednesday, January 15, 2020 10:16 AM
To: SECURITY () LISTSERV EDUCAUSE EDU
Subject: [SECURITY] SOP for Releasing Private Data Generated by Deceased Student?



At the institutions I serve, we’ve had a few tragic cases of deceased students where the parents or other family 
requested access to the deceased’s emails, laptop contents, or both. If your institution has a request form or policy 
for this situation I’d appreciate you sharing it since I’ve been asked if we can establish a procedure that handles 
such requests in order to reduce our response time and improve consistency.  My question is only about policy and SOP, 
*not* the legal question of whether or not the data should be released (that is determined by whether the deceased has 
a Will covering their digital legacy).



Bryce Cunningham, MS, CISM, CISSP

Information Security Officer

Colleges of the Fenway:

Mass College of Art and Design &

Wentworth Institute of Technology

C: 617-396-7052









**********
Replies to EDUCAUSE Community Group emails are sent to the entire community list. If you want to reply only to the 
person who sent the message, copy and paste their email address and forward the email reply. Additional participation 
and subscription information can be found at  
<https://nam02.safelinks.protection.outlook.com/?url=https%3A%2F%2Fwww.educause.edu%2Fcommunity&amp;data=02%7C01%7Cwferland%40ccri.edu%7C7031cfce83124235a2b008d79e97786b%7Caf75351b37eb4405bf7a7327cec380a5%7C0%7C1%7C637152245732396404&amp;sdata=hL0zqO99VLweqB9nvZLBT0O7QvOK1kSI4CB%2BfSBKYAc%3D&amp;reserved=0>
 
https://nam02.safelinks.protection.outlook.com/?url=https%3A%2F%2Fwww.educause.edu%2Fcommunity&amp;data=02%7C01%7Cwferland%40ccri.edu%7C7031cfce83124235a2b008d79e97786b%7Caf75351b37eb4405bf7a7327cec380a5%7C0%7C1%7C637152245732406402&amp;sdata=L3ssKxapONp6t7s9wWjtAet1%2BY1sCoASywXGLancSZg%3D&amp;reserved=0


**********
Replies to EDUCAUSE Community Group emails are sent to the entire community list. If you want to reply only to the 
person who sent the message, copy and paste their email address and forward the email reply. Additional participation 
and subscription information can be found at 
https://nam02.safelinks.protection.outlook.com/?url=https%3A%2F%2Fwww.educause.edu%2Fcommunity&amp;data=02%7C01%7Cwferland%40ccri.edu%7C7031cfce83124235a2b008d79e97786b%7Caf75351b37eb4405bf7a7327cec380a5%7C0%7C1%7C637152245732406402&amp;sdata=L3ssKxapONp6t7s9wWjtAet1%2BY1sCoASywXGLancSZg%3D&amp;reserved=0

------------------------------

Date:    Wed, 15 Jan 2020 16:30:31 +0000
From:    "Madl, Michael" <michael.madl () INDWES EDU>
Subject: Re: HECVAT Tool with Current Vendors

Hi Ron,

I have been utilizing the HECVAT for 18 months now for new vendors.  I do plan on doing the same and think it is a good 
idea.  Depending on the results of each assessment it could determine your renewal decision for a specific vendor 
especially if they are lacking based on the results.


MICHAEL MADL
INFORMATION SECURITY OFFICER
UNIVERSITY INFORMATION TECHNOLOGY

INDIANA WESLEYAN UNIVERSITY
4201 SOUTH WASHINGTON STREET
MARION, IN 46953

  [signature_744753374] 
<https://nam02.safelinks.protection.outlook.com/?url=https%3A%2F%2Ftwitter.com%2FInfosecurityIwu&amp;data=02%7C01%7Cwferland%40ccri.edu%7C7031cfce83124235a2b008d79e97786b%7Caf75351b37eb4405bf7a7327cec380a5%7C0%7C0%7C637152245732406402&amp;sdata=Vnqqa6HWQxRqGJ9cafPM6cJhrL5WEltJCOF1kGXSPsE%3D&amp;reserved=0>
  [signature_1345253181] 
<https://nam02.safelinks.protection.outlook.com/?url=https%3A%2F%2Fwww.linkedin.com%2Fin%2Fmichaelmadl%2F&amp;data=02%7C01%7Cwferland%40ccri.edu%7C7031cfce83124235a2b008d79e97786b%7Caf75351b37eb4405bf7a7327cec380a5%7C0%7C0%7C637152245732406402&amp;sdata=SI8jISM8%2FIJqTfXRlgRnhFRjg0gqGoLOGDHRcU5W1jY%3D&amp;reserved=0>
  [signature_464874313] <mailto:michael.madl () indwes edu>
     765.677.2688

[cidimage004.jpg@01D51231.B0363E20]

DO NOT provide your username, password, or any personal information requested by any email.
IWU WILL NEVER ask you for your username or password via email.
DO NOT CLICK links or attachments unless you are positive the content is safe.

CONFIDENTIALITY NOTICE: This email, including applicable attachments, may include legally protected information.  If 
you are not the intended recipient of this message, you may not disclose, print, copy, save, or disseminate this 
information. If you have received this email in error, please notify the sender by replying to this message and 
immediately delete this message.




From: The EDUCAUSE Security Community Group Listserv <SECURITY () LISTSERV EDUCAUSE EDU> on behalf of Ronald Loneker 
<rloneker () CSE EDU>
Reply-To: The EDUCAUSE Security Community Group Listserv <SECURITY () LISTSERV EDUCAUSE EDU>
Date: Monday, January 13, 2020 at 11:40 AM
To: "SECURITY () LISTSERV EDUCAUSE EDU" <SECURITY () LISTSERV EDUCAUSE EDU>
Subject: [SECURITY] HECVAT Tool with Current Vendors

** This message originated from outside the Indiana Wesleyan University email system **
________________________________
Good Morning -

We recently were made aware of, and decided to start using, the HECVAT tool with new vendors we use for future projects.

I'm wondering whether we should go back to our current vendors offering cloud applications and have them complete the 
tool even though we're existing customers.

Just asking for thoughts and whether anyone has done this before and gotten a lot of pushback from existing vendors.

I think our IT auditors would be pleased if we have this information centralized.

Ron Loneker, Jr.
Director, IT Special Projects
College of Saint Elizabeth
Mahoney Library
2 Convent Road
Morristown, NJ  07960

Phone:  973-290-4229<tel:973-290-4229>

e-mail:  rloneker () cse edu<mailto:rloneker () cse edu>


CSE's IT department will never ask for your password, social security number or other personal information in an e-mail 
message.

Please do not share any information with others!






**********
Replies to EDUCAUSE Community Group emails are sent to the entire community list. If you want to reply only to the 
person who sent the message, copy and paste their email address and forward the email reply. Additional participation 
and subscription information can be found at 
https://nam02.safelinks.protection.outlook.com/?url=https%3A%2F%2Fwww.educause.edu%2Fcommunity&amp;data=02%7C01%7Cwferland%40ccri.edu%7C7031cfce83124235a2b008d79e97786b%7Caf75351b37eb4405bf7a7327cec380a5%7C0%7C1%7C637152245732406402&amp;sdata=L3ssKxapONp6t7s9wWjtAet1%2BY1sCoASywXGLancSZg%3D&amp;reserved=0

**********
Replies to EDUCAUSE Community Group emails are sent to the entire community list. If you want to reply only to the 
person who sent the message, copy and paste their email address and forward the email reply. Additional participation 
and subscription information can be found at https://www.

------------------------------

Date:    Wed, 15 Jan 2020 16:47:50 +0000
From:    "Stone, Todd A" <toddston () IU EDU>
Subject: ResearchSOC Cybersecurity Webinars

These webinars may be of interest.

How to use security exercises to mature an information security program -- a ResearchSOC Webinar

ResearchSOC, the National Science Foundation’s collaborative security response operations center, announces its 
inaugural 2020 technical training webinar "How to use security exercises to mature an information security program"

 DATE: January 30th, 2020, TIME: 3:00 PM EST
Learn to use a regular program of security exercises to probe your infrastructure, program, and incident response for 
weaknesses and opportunities, then use your home-court advantage to constantly, incrementally improve security posture 
rather than waiting for disaster to strike.  Participants will learn key elements in writing a table-top security 
exercise that can test their incident response plans with their home organization. There is no charge for this webinar.

Register here 
<https://nam02.safelinks.protection.outlook.com/?url=https%3A%2F%2Fiu.zoom.us%2Fwebinar%2Fregister%2FWN_W8boEDR0ST-VVNeks_A8ug&amp;data=02%7C01%7Cwferland%40ccri.edu%7C7031cfce83124235a2b008d79e97786b%7Caf75351b37eb4405bf7a7327cec380a5%7C0%7C0%7C637152245732406402&amp;sdata=e35ZfbsMGlfyzLrvZmhTBik975S7q5wMOWkcNclQVfo%3D&amp;reserved=0>
Who should attend:
IT and security personnel supporting open science and research projects, especially those who may be involved in 
cybersecurity incident response, program design and measurement, security exercises, or other security operations.

Learn more about this and other ResearchSOC webinars at researchsoc.iu.edu/webinars

Todd A. Stone M.A., MAJ USAR (Ret.).
Manager, Cybersecurity Communications
Information Technology Communications Office
Office of the Vice President for Information Technology
Indiana University
toddston () iu edu
https://nam02.safelinks.protection.outlook.com/?url=https%3A%2F%2Fresearchsoc.iu.edu%2F&amp;data=02%7C01%7Cwferland%40ccri.edu%7C7031cfce83124235a2b008d79e97786b%7Caf75351b37eb4405bf7a7327cec380a5%7C0%7C0%7C637152245732406402&amp;sdata=%2BQ3tJoy2QhDgCQ2jKn7v%2F3BEnjkZbNdU5QSlRPoI3Mk%3D&amp;reserved=0

**********
Replies to EDUCAUSE Community Group emails are sent to the entire community list. If you want to reply only to the 
person who sent the message, copy and paste their email address and forward the email reply. Additional participation 
and subscription information can be found at 
https://nam02.safelinks.protection.outlook.com/?url=https%3A%2F%2Fwww.educause.edu%2Fcommunity&amp;data=02%7C01%7Cwferland%40ccri.edu%7C7031cfce83124235a2b008d79e97786b%7Caf75351b37eb4405bf7a7327cec380a5%7C0%7C1%7C637152245732406402&amp;sdata=L3ssKxapONp6t7s9wWjtAet1%2BY1sCoASywXGLancSZg%3D&amp;reserved=0

------------------------------

Date:    Wed, 15 Jan 2020 17:23:59 +0000
From:    Bob Wilson <bob.wilson () USM EDU>
Subject: Re: SOP for Releasing Private Data Generated by Deceased Student?

So, at USM we’ve only addressed it for the students, and actually rolled that into one of our policies.



3.9.         Email data of deceased or incapacitated students may be provided to an authorized individual.

3.9.1.     Authorized individuals include an executor or a person who holds power of attorney for the student.

3.9.2.     The authorized individual must provide a legal document demonstrating authorization.

3.9.3.     The request must be submitted in writing to the Office of the General Counsel.



Thanks

Bob



Remember that iTech will never ask for your password.

**********************************

Bob Wilson, CISSP

Technology Security Officer

University of Southern Mississippi

email :  <mailto:bob.wilson () usm edu> bob.wilson () usm edu

**********************************

:(){ :|:& };:



From: The EDUCAUSE Security Community Group Listserv <SECURITY () LISTSERV EDUCAUSE EDU> On Behalf Of Eva Lorenz
Sent: Wednesday, January 15, 2020 9:55 AM
To: SECURITY () LISTSERV EDUCAUSE EDU
Subject: Re: [SECURITY] SOP for Releasing Private Data Generated by Deceased Student?



Please contact me offline and I can share the handful of cases I was involved in and how they were handled



Eva



On Wed, Jan 15, 2020 at 10:16 AM Bryce Cunningham <bcunningham () colleges-fenway org <mailto:bcunningham () 
colleges-fenway org> > wrote:

At the institutions I serve, we’ve had a few tragic cases of deceased students where the parents or other family 
requested access to the deceased’s emails, laptop contents, or both. If your institution has a request form or policy 
for this situation I’d appreciate you sharing it since I’ve been asked if we can establish a procedure that handles 
such requests in order to reduce our response time and improve consistency.  My question is only about policy and SOP, 
*not* the legal question of whether or not the data should be released (that is determined by whether the deceased has 
a Will covering their digital legacy).



Bryce Cunningham, MS, CISM, CISSP

Information Security Officer

Colleges of the Fenway:

Mass College of Art and Design &

Wentworth Institute of Technology

C: 617-396-7052







**********
Replies to EDUCAUSE Community Group emails are sent to the entire community list. If you want to reply only to the 
person who sent the message, copy and paste their email address and forward the email reply. Additional participation 
and subscription information can be found at 
https://nam02.safelinks.protection.outlook.com/?url=https%3A%2F%2Fwww.educause.edu%2Fcommunity&amp;data=02%7C01%7Cwferland%40ccri.edu%7C7031cfce83124235a2b008d79e97786b%7Caf75351b37eb4405bf7a7327cec380a5%7C0%7C1%7C637152245732416390&amp;sdata=6azfUNF4Y1E4IWkTri%2BRNSrNyqftUE5ubCw3R6OxX%2BQ%3D&amp;reserved=0
 
<https://nam02.safelinks.protection.outlook.com/?url=https%3A%2F%2Fwww.educause.edu%2Fcommunity&amp;data=02%7C01%7Cwferland%40ccri.edu%7C7031cfce83124235a2b008d79e97786b%7Caf75351b37eb4405bf7a7327cec380a5%7C0%7C1%7C637152245732416390&amp;sdata=6azfUNF4Y1E4IWkTri%2BRNSrNyqftUE5ubCw3R6OxX%2BQ%3D&amp;reserved=0>

**********
Replies to EDUCAUSE Community Group emails are sent to the entire community list. If you want to reply only to the 
person who sent the message, copy and paste their email address and forward the email reply. Additional participation 
and subscription information can be found at 
https://nam02.safelinks.protection.outlook.com/?url=https%3A%2F%2Fwww.educause.edu%2Fcommunity&amp;data=02%7C01%7Cwferland%40ccri.edu%7C7031cfce83124235a2b008d79e97786b%7Caf75351b37eb4405bf7a7327cec380a5%7C0%7C1%7C637152245732416390&amp;sdata=6azfUNF4Y1E4IWkTri%2BRNSrNyqftUE5ubCw3R6OxX%2BQ%3D&amp;reserved=0
 
<https://nam02.safelinks.protection.outlook.com/?url=https%3A%2F%2Fwww.educause.edu%2Fcommunity&amp;data=02%7C01%7Cwferland%40ccri.edu%7C7031cfce83124235a2b008d79e97786b%7Caf75351b37eb4405bf7a7327cec380a5%7C0%7C1%7C637152245732416390&amp;sdata=6azfUNF4Y1E4IWkTri%2BRNSrNyqftUE5ubCw3R6OxX%2BQ%3D&amp;reserved=0>


**********
Replies to EDUCAUSE Community Group emails are sent to the entire community list. If you want to reply only to the 
person who sent the message, copy and paste their email address and forward the email reply. Additional participation 
and subscription information can be found at 
https://nam02.safelinks.protection.outlook.com/?url=https%3A%2F%2Fwww.educause.edu%2Fcommunity&amp;data=02%7C01%7Cwferland%40ccri.edu%7C7031cfce83124235a2b008d79e97786b%7Caf75351b37eb4405bf7a7327cec380a5%7C0%7C1%7C637152245732416390&amp;sdata=6azfUNF4Y1E4IWkTri%2BRNSrNyqftUE5ubCw3R6OxX%2BQ%3D&amp;reserved=0

------------------------------

Date:    Wed, 15 Jan 2020 17:24:08 +0000
From:    Dean Woodbeck <woodbeck () INTERNET2 EDU>
Subject: Re: Reminder: IAM Online Wednesday: Passwordless Authentication with Shibboleth and WebAuthn

What Valerie said ☺

I post the slides and a link to the video also at incommon.org/iamonline. Those are typically ready about an hour after 
the webinar ends.

Dean

From: The EDUCAUSE Security Community Group Listserv <SECURITY () LISTSERV EDUCAUSE EDU> on behalf of Dewight Fredrick 
Kramer <dfkramer () UCDAVIS EDU>
Reply-To: The EDUCAUSE Security Community Group Listserv <SECURITY () LISTSERV EDUCAUSE EDU>
Date: Tuesday, January 14, 2020 at 6:29 PM
To: "SECURITY () LISTSERV EDUCAUSE EDU" <SECURITY () LISTSERV EDUCAUSE EDU>
Subject: Re: [SECURITY] Reminder: IAM Online Wednesday: Passwordless Authentication with Shibboleth and WebAuthn

Second this inquiry!

Thank you,

Dewight F. Kramer
Assistant CISO
University of California, Davis
One Shields Avenue
Davis, CA 95616
(530)752-1700
dfkramer () ucdavis edu<mailto:dfkramer () ucdavis edu>
https://nam02.safelinks.protection.outlook.com/?url=http%3A%2F%2Fsecurity.ucdavis.edu&amp;data=02%7C01%7Cwferland%40ccri.edu%7C7031cfce83124235a2b008d79e97786b%7Caf75351b37eb4405bf7a7327cec380a5%7C0%7C1%7C637152245732416390&amp;sdata=K7ICRDRwu9FL%2ByqdvHS3B%2BN91LzuSu8jQ%2B0Rpcrw4CI%3D&amp;reserved=0<https://nam02.safelinks.protection.outlook.com/?url=http%3A%2F%2Fsecurity.ucdavis.edu%2F&amp;data=02%7C01%7Cwferland%40ccri.edu%7C7031cfce83124235a2b008d79e97786b%7Caf75351b37eb4405bf7a7327cec380a5%7C0%7C1%7C637152245732416390&amp;sdata=zB4MKEfQaYPpL3S4fPKtf6sCzS%2BUm3WHQf1TJIc80pk%3D&amp;reserved=0>


From: The EDUCAUSE Security Community Group Listserv <SECURITY () LISTSERV EDUCAUSE EDU> on behalf of "Jim A. Bole" 
<jbole () STEVENSON EDU>
Reply-To: The EDUCAUSE Security Community Group Listserv <SECURITY () LISTSERV EDUCAUSE EDU>
Date: Monday, January 13, 2020 at 8:44 AM
To: "SECURITY () LISTSERV EDUCAUSE EDU" <SECURITY () LISTSERV EDUCAUSE EDU>
Subject: Re: [SECURITY] Reminder: IAM Online Wednesday: Passwordless Authentication with Shibboleth and WebAuthn

Dean,

This looks interesting, but I may have conflict. Will a recording be available afterward?

Jim Bole
Director of Information Security
Stevenson University
1525 Greenspring Valley Road
Stevenson, MD, 21153-0641
jbole () stevenson edu | O: 443-334-2696



From: The EDUCAUSE Security Community Group Listserv <SECURITY () LISTSERV EDUCAUSE EDU> On Behalf Of Dean Woodbeck
Sent: Thursday, January 9, 2020 9:25 AM
To: SECURITY () LISTSERV EDUCAUSE EDU
Subject: Reminder: IAM Online Wednesday: Passwordless Authentication with Shibboleth and WebAuthn

This email originated from outside of Stevenson University. Use caution with links or attachments unless you know the 
content is safe.
A reminder of the IAM Online this Wednesday, January 15, at 2 pm ET.

From: Dean Woodbeck <woodbeck () internet2 edu<mailto:woodbeck () internet2 edu>>
Date: Wednesday, December 18, 2019 at 3:20 PM
Subject: January IAM Online: Passwordless Authentication with Shibboleth and WebAuthn

January IAM Online: Passwordless Authentication with Shibboleth and WebAuthn
Wednesday, January 15, 2020
2 pm ET | 1 pm CT | Noon MT | 11 am PT | 10 am AKT

Our first IAM Online of 2020 will provide another method of passwordless authentication; this one developed by Duke 
University.

Duke has integrated its Shibboleth Identity Provider with WebAuthn to allow one-step, passwordless multi-factor 
authentication. In this session we’ll discuss the evolution of this pilot, including:
    * Initial drivers
    * Proof of concept
    * Early release
    * Iterations, the feedback they generated, and resulting changes

For each of these phases, we’ll discuss challenges, lessons learned, and policy decisions that helped us move forward. 
We’ll wrap up with recommendations about how to make passwordless authentication a reality at your institution, 
including some thoughts about technical and political challenges and strategies for moving through those issues.

-----
Presenters

Mary McKee, Duke University
Shilen Patel, Duke University

-----
Connecting
Side sharing and audio via Zoom: 
https://nam02.safelinks.protection.outlook.com/?url=https%3A%2F%2Finternet2.zoom.us%2Fj%2F886598327&amp;data=02%7C01%7Cwferland%40ccri.edu%7C7031cfce83124235a2b008d79e97786b%7Caf75351b37eb4405bf7a7327cec380a5%7C0%7C1%7C637152245732416390&amp;sdata=qvFdJCtfIEt6nF%2F8aln8TbiK4x3jWJlqwgNoTHC%2BCdY%3D&amp;reserved=0<https://nam02.safelinks.protection.outlook.com/?url=https%3A%2F%2Finternet2.zoom.us%2Fj%2F886598327&amp;data=02%7C01%7Cwferland%40ccri.edu%7C7031cfce83124235a2b008d79e97786b%7Caf75351b37eb4405bf7a7327cec380a5%7C0%7C1%7C637152245732426384&amp;sdata=k%2B1%2B3U0htqAjoW%2BeW9hvtrGr1puWprx2QMXJABSzmuM%3D&amp;reserved=0>

Or join by phone:
Dial (US): (669) 900-6833 or (646) 558-8656
Webinar ID: 886 598 327

International numbers available: 
https://nam02.safelinks.protection.outlook.com/?url=https%3A%2F%2Fzoom.us%2Fu%2FbKX4teTZh&amp;data=02%7C01%7Cwferland%40ccri.edu%7C7031cfce83124235a2b008d79e97786b%7Caf75351b37eb4405bf7a7327cec380a5%7C0%7C0%7C637152245732426384&amp;sdata=XzWyV2KktQLWJtIbnxVJ6pzCC2mm%2BP%2B2LZJC2IlCgW0%3D&amp;reserved=0<https://nam02.safelinks.protection.outlook.com/?url=https%3A%2F%2Fzoom.us%2Fu%2FbKX4teTZh&amp;data=02%7C01%7Cwferland%40ccri.edu%7C7031cfce83124235a2b008d79e97786b%7Caf75351b37eb4405bf7a7327cec380a5%7C0%7C0%7C637152245732426384&amp;sdata=XzWyV2KktQLWJtIbnxVJ6pzCC2mm%2BP%2B2LZJC2IlCgW0%3D&amp;reserved=0>

-----
About IAM Online
IAM Online 
(https://nam02.safelinks.protection.outlook.com/?url=https%3A%2F%2Fwww2.internet2.edu%2Fl%2F66332%2F2019-09-20%2Fbwbqvx&amp;data=02%7C01%7Cwferland%40ccri.edu%7C7031cfce83124235a2b008d79e97786b%7Caf75351b37eb4405bf7a7327cec380a5%7C0%7C0%7C637152245732426384&amp;sdata=0XuspShe4FyWQhLeqBJ6HocjOdSoynpRaDT49s3mG3M%3D&amp;reserved=0<https://nam02.safelinks.protection.outlook.com/?url=https%3A%2F%2Fwww2.internet2.edu%2Fl%2F66332%2F2019-09-20%2Fbwbqvx&amp;data=02%7C01%7Cwferland%40ccri.edu%7C7031cfce83124235a2b008d79e97786b%7Caf75351b37eb4405bf7a7327cec380a5%7C0%7C0%7C637152245732426384&amp;sdata=0XuspShe4FyWQhLeqBJ6HocjOdSoynpRaDT49s3mG3M%3D&amp;reserved=0>)
 is a monthly online education series brought to you by Internet2’s InCommon community and the EDUCAUSE Higher 
Education Information Security Council (HEISC).


----
Dean Woodbeck
Director of Community Awareness
Internet2 Trust and Identity


**********
Replies to EDUCAUSE Community Group emails are sent to the entire community list. If you want to reply only to the 
person who sent the message, copy and paste their email address and forward the email reply. Additional participation 
and subscription information can be found at 
https://nam02.safelinks.protection.outlook.com/?url=https%3A%2F%2Fwww.educause.edu%2Fcommunity&amp;data=02%7C01%7Cwferland%40ccri.edu%7C7031cfce83124235a2b008d79e97786b%7Caf75351b37eb4405bf7a7327cec380a5%7C0%7C1%7C637152245732426384&amp;sdata=rDqF45sxn%2BFpAlJ%2B5tSOOnSgCv6WfcytzXNpk1k7W3s%3D&amp;reserved=0<https://nam02.safelinks.protection.outlook.com/?url=https%3A%2F%2Fwww.educause.edu%2Fcommunity&amp;data=02%7C01%7Cwferland%40ccri.edu%7C7031cfce83124235a2b008d79e97786b%7Caf75351b37eb4405bf7a7327cec380a5%7C0%7C1%7C637152245732436380&amp;sdata=Fh1fnGLHxud8U7H7drJxmsaS8GmlNQ095YXw2%2F9cZ7o%3D&amp;reserved=0>

**********
Replies to EDUCAUSE Community Group emails are sent to the entire community list. If you want to reply only to the 
person who sent the message, copy and paste their email address and forward the email reply. Additional participation 
and subscription information can be found at 
https://nam02.safelinks.protection.outlook.com/?url=https%3A%2F%2Fwww.educause.edu%2Fcommunity&amp;data=02%7C01%7Cwferland%40ccri.edu%7C7031cfce83124235a2b008d79e97786b%7Caf75351b37eb4405bf7a7327cec380a5%7C0%7C1%7C637152245732436380&amp;sdata=Fh1fnGLHxud8U7H7drJxmsaS8GmlNQ095YXw2%2F9cZ7o%3D&amp;reserved=0

**********
Replies to EDUCAUSE Community Group emails are sent to the entire community list. If you want to reply only to the 
person who sent the message, copy and paste their email address and forward the email reply. Additional participation 
and subscription information can be found at 
https://nam02.safelinks.protection.outlook.com/?url=https%3A%2F%2Fwww.educause.edu%2Fcommunity&amp;data=02%7C01%7Cwferland%40ccri.edu%7C7031cfce83124235a2b008d79e97786b%7Caf75351b37eb4405bf7a7327cec380a5%7C0%7C1%7C637152245732436380&amp;sdata=Fh1fnGLHxud8U7H7drJxmsaS8GmlNQ095YXw2%2F9cZ7o%3D&amp;reserved=0

**********
Replies to EDUCAUSE Community Group emails are sent to the entire community list. If you want to reply only to the 
person who sent the message, copy and paste their email address and forward the email reply. Additional participation 
and subscription information can be found

------------------------------

End of SECURITY Digest - 14 Jan 2020 to 15 Jan 2020 (#2020-11)
**************************************************************

**********
Replies to EDUCAUSE Community Group emails are sent to the entire community list. If you want to reply only to the 
person who sent the message, copy and paste their email address and forward the email reply. Additional participation 
and subscription information can be found at 
https://nam02.safelinks.protection.outlook.com/?url=https%3A%2F%2Fwww.educause.edu%2Fcommunity&amp;data=02%7C01%7Cwferland%40ccri.edu%7C7031cfce83124235a2b008d79e97786b%7Caf75351b37eb4405bf7a7327cec380a5%7C0%7C1%7C637152245732436380&amp;sdata=Fh1fnGLHxud8U7H7drJxmsaS8GmlNQ095YXw2%2F9cZ7o%3D&amp;reserved=0

**********
Replies to EDUCAUSE Community Group emails are sent to the entire community list. If you want to reply only to the 
person who sent the message, copy and paste their email address and forward the email reply. Additional participation 
and subscription information can be found at https://www.educause.edu/community

Current thread: