Educause Security Discussion mailing list archives

Re: Blackboard and IE Patch


From: Keith Schoenefeld <schoenk () UTULSA EDU>
Date: Tue, 18 Apr 2006 14:06:02 -0500

At this point, we've decided to hold off on deploying the patch until the end of the semester (two weeks away) so we 
won't affect students' ability to finish projects and graduate.  After finals are over, we'll apply the patch and work 
to resolve any issues that result.

In the mean time we're following our normal practices of watching the IDS systems, watching flows, etc. to ensure (as 
best we can) that any compromised system is taken offline immediately.

-- KS

Quoting "Allen, Jon D." <Jon_Allen () BAYLOR EDU>:

I was just curious how other institutions that use Blackboard
are
handling the recommendation by Blackboard not to apply the
latest IE
patches.  Obviously with the package containing multiple
patches
including critical security fixes it poses quite the dilemma.
On the
one hand patching could case major issues with a key academic
system.
On the other hand not patching places systems at a risk of
compromise.
Any philosophies or thoughts?

Thanks,

Jon Allen
Information Security Officer
Baylor University


Current thread: