Educause Security Discussion mailing list archives

JumpForward NCAA Compliance and Recruiting


From: Shawn Kohrman <skohrman () APU EDU>
Date: Mon, 25 Jun 2012 15:16:03 -0700

Hello,
We are moving forward with an implementation of JumpForward
http://www.jumpforward.com/ in collaboration with our Athletics department.
 During the course of training, we discovered that there was a
"username/password" report available to members of the admin role that
displayed user's full name, preferred email, username, and password for all
users in the system (for our organization).

We immediately notified JumpForward about this, and they have been
extremely willing to work with us to remove the report and address
underlying concerns about how the credential information was stored.
 During the course of the conversation, they indicated that the report
existed due to high demand from large universities.

They also indicated that we were one of the few universities they've worked
with where IT is working closely with Athletics on the implementation.

I'm curious how many of you are using JumpForward, and how you have dealt
with the "username/password" report.  Thanks!

Shawn
-----
Shawn A. Kohrman, Security Architect

Azusa Pacific University
Information & Media Technology
901 E. Alosta Ave., PO Box 7000
Azusa, CA 91702-7000

P:  626.815.2054 | F:  626.815.2061 | http://www.apu.edu/
-----

Current thread: