Educause Security Discussion mailing list archives
Re: Equipment Loan Policy
From: Stacy Lee <sbl () STANFORD EDU>
Date: Thu, 16 Jul 2020 15:39:20 +0000
James, Stanford University IT has a couple resources online on this. https://uit.stanford.edu/guide/telecommuting https://uit.stanford.edu/guide/telecommuting/equipment If you have a endpoint management agent that can track hardware you could inventory equipment and changes if you wanted to get that down to that level of detail and monitoring. Enforcing verifiable disk encryption would help protect in the event of physical loss of equipment. That might contain PII. https://uit.stanford.edu/service/encryption/wholedisk Tools such as an EDR, NGAV, password managers, enforcing regular patching, pop up blockers, email protections (Url defense, attachment scanning, imposter protections), logging to a siem, are some way to help protect the users from phishing and online compromises while giving your team ways investigate incidents. Thanks, Stacy Lee ISO Security Operations Stanford University Thanks, Stacy Lee ISO | Security Operations ________________________________ From: The EDUCAUSE Security Community Group Listserv <SECURITY () LISTSERV EDUCAUSE EDU> on behalf of Pardonek, Jim <jpardonek () LUC EDU> Sent: Thursday, July 16, 2020 7:22:26 AM To: SECURITY () LISTSERV EDUCAUSE EDU <SECURITY () LISTSERV EDUCAUSE EDU> Subject: [SECURITY] Equipment Loan Policy Good Morning, Apologize for the cross posting. With the growing push to mostly online classes here at Loyola Chicago, we have had several discussions regarding faculty and staff taking equipment home. We are concerned about Computer equipment and have said “No” to many requests to take these from offices over the last few months. It is a general thought that many faculty do not have adequate computing power at home to teach online. While they pushed through this in the fall out of necessity, for many it was in no way at the level/quality needed. Given this, I think that ‘loans’ will last as long as faculty are teaching online. One option would be to have departments “own” some of the decision of who needs equipment, and the cost (maybes split it?) so that they have some teeth in the game of how many laptops are requested. Another option is that each department has an allocation of # laptops for every # of faculty. They could then determine the greatest need. For example: “Psychology, you get 2 laptops. Let us know who gets these.” We have elements of an existing process in ITS to leverage and we’d like ensure that individuals are not removing CPUs, desktops, etc. from offices – this increases our risk and ability to protect PII and Loyola confidential information along with losing track of assets. We are looking for feedback on what other EDU’s have for policy on taking equipment home, equipment loan, how tracking is done, penalties for not returning equipment and any other thoughts. Thanks! Jim James Pardonek, MS, CISSP, CEH, GSNA Associate Director Chief Information Security Officer Loyola University Chicago 1032 W. Sheridan Road | Chicago, IL 60660 •: (773) 508-6086 Loyola University Chicago will never ask you for your username or password. For the latest information security news at Loyola, please follow us online, Twitter: @LUCUISO Facebook: https://www.facebook.com/lucuiso/<https://urldefense.com/v3/__https://www.facebook.com/lucuiso/__;!!POPwgc47LqelFC4T6Q!cHNFYW5o0vwqt7DmrajAtGM8EdJNSYEy04uqorXsmhWegRkHbmSgIvLOCC3bL4kaQ5y5Wg$> Our Blog http://blogs.luc.edu/uiso/ ********** Replies to EDUCAUSE Community Group emails are sent to the entire community list. If you want to reply only to the person who sent the message, copy and paste their email address and forward the email reply. Additional participation and subscription information can be found at https://www.educause.edu/community<https://urldefense.com/v3/__https://www.educause.edu/community__;!!POPwgc47LqelFC4T6Q!cHNFYW5o0vwqt7DmrajAtGM8EdJNSYEy04uqorXsmhWegRkHbmSgIvLOCC3bL4mj2KIcFA$> ********** Replies to EDUCAUSE Community Group emails are sent to the entire community list. If you want to reply only to the person who sent the message, copy and paste their email address and forward the email reply. Additional participation and subscription information can be found at https://www.educause.edu/community
Current thread:
- Equipment Loan Policy Pardonek, Jim (Jul 16)
- Re: Equipment Loan Policy Andrews, Loretta (Jul 16)
- Re: Equipment Loan Policy Stacy Lee (Jul 16)