Educause Security Discussion mailing list archives
Re: Risks of File Transfer on a Fully Switched Network
From: Gary Dobbins <dobbins () ND EDU>
Date: Wed, 30 Nov 2005 10:45:15 -0500
For all the reasons the other respondents have pointed out, you may want to choose to simply expect the campus net is just as potentially hostile as any cyber cafe, harden the endpoint machines, and use only encrypted transmission for sensitive data as a matter of policy. Then, permit variance from that default policy only by deliberate choice, and in the presence of sufficient local compensatory controls, such as within a managed datacenter. Sadler, Connie wrote:
I am being told that the risk of transferring sensitive files over our InTRAnet is so low that we should not require encryption for these internal file transfers. Transferring over the Internet in the clear is clearly a problem, but are others willing to share your position on the transmission of sensitive data in the clear internally (assuming a fully switched network)?? Thanks... Connie J. Sadler, CM, CISSP, CISM, GIAC GSLC Director, IT Security, Brown University Box 1885, Providence, RI 02912 Connie_Sadler () Brown edu Office: 401-863-7266 PGP Key: _http://pgp.mit.edu:11371/pks/lookup?op=get&search=0x91E38EFB_ <http://pgp.mit.edu:11371/pks/lookup?op=get&search=0x91E38EFB> _http://pgp.mit.edu:11371/pks/lookup?op=get&search=0x91E38EFB_ <http://pgp.mit.edu:11371/pks/lookup?op=get&search=0x91E38EFB> PGP Fingerprint: DA5F ED84 06D7 1635 4BC7 560D 9A07 80BA 91E3 8EFB
-- ------------------------------------------------------------ Gary Dobbins, CISSP -- Director, Information Security University of Notre Dame, Office of Information Technologies
Current thread:
- Re: Risks of File Transfer on a Fully Switched Network, (continued)
- Re: Risks of File Transfer on a Fully Switched Network Ken Layng (Nov 29)
- Re: Risks of File Transfer on a Fully Switched Network Ken Connelly (Nov 29)
- Re: Risks of File Transfer on a Fully Switched Network Russell Fulton (Nov 29)
- Re: Risks of File Transfer on a Fully Switched Network Richard Gadsden (Nov 29)
- Re: Risks of File Transfer on a Fully Switched Network David Gillett (Nov 29)
- Re: Risks of File Transfer on a Fully Switched Network Chad McDonald (Nov 30)
- Re: Risks of File Transfer on a Fully Switched Network wcon (Nov 30)
- Re: Risks of File Transfer on a Fully Switched Network jack suess (Nov 30)
- Re: Risks of File Transfer on a Fully Switched Network Dunker, Mary (Nov 30)
- Re: Risks of File Transfer on a Fully Switched Network Gary Flynn (Nov 30)
- Re: Risks of File Transfer on a Fully Switched Network Gary Dobbins (Nov 30)
- Re: Risks of File Transfer on a Fully Switched Network Huba Leidenfrost (Nov 30)
- Re: Risks of File Transfer on a Fully Switched Network Russell Fulton (Nov 30)
- Re: Risks of File Transfer on a Fully Switched Network Bradley Ellis (Nov 30)
- Re: Risks of File Transfer on a Fully Switched Network Cal Frye (Dec 01)
- Re: Risks of File Transfer on a Fully Switched Network Scholz, Greg (Dec 01)
- Re: Risks of File Transfer on a Fully Switched Network Gary Dobbins (Dec 01)
- Re: Risks of File Transfer on a Fully Switched Network Robert Kerr (Dec 02)
- Re: Risks of File Transfer on a Fully Switched Network Alan Amesbury (Dec 06)