Educause Security Discussion mailing list archives

Re: Personal VPN Policy Accessing University Applications


From: Curt Kappenman <ckappenman () ANDERSONUNIVERSITY EDU>
Date: Tue, 6 Oct 2020 14:26:06 +0000

I have been dealing with this same issue for a while now.  My problem has been coming up with a policy that doesn’t 
almost immediately start having exceptions.  I look forward to hearing what others have been able to come up with.

Curt Kappenman
Security Compliance Officer / Systems Technician
316 Boulevard, Anderson, SC 29621
Phone: (864) 231-2850
Help Desk: (864) 231-2457
ckappenman () andersonuniversity edu<mailto:ckappenman () andersonuniversity edu>
www.andersonuniversity.edu<http://www.andersonuniversity.edu/>

From: The EDUCAUSE Security Community Group Listserv <SECURITY () LISTSERV EDUCAUSE EDU> On Behalf Of Theodore J. August
Sent: Tuesday, October 6, 2020 10:23 AM
To: SECURITY () LISTSERV EDUCAUSE EDU
Subject: [SECURITY] Personal VPN Policy Accessing University Applications

Hello all,

I was just wondering how other higher-ed institutions handle users who access applications using personal VPN services 
such as Express VPN, Cyberghost, etc?  We’re seeing an overall increase in the use of these services, especially on 
mobile devices, from students.  While we appreciate the heightened awareness of privacy and security that members of 
our community are displaying by using these services, it’s also causing lots of false positives for intrusions in a 
number of our detection systems, for obvious reasons.  Right now we handle these on a case-by-case basis, but that’s 
starting to become overwhelming, and we would love to come up with a blanket policy we can socialize to our end-users. 
I’m hesitant to ban them outright, but the anonymous nature of these services makes it extremely hard to filter out 
legitimate use from malicious use.

Thanks in advance for your feedback, and thank you to everyone who participates in this list – it’s enlightening and 
educational to read all the posts whenever I have the time to check-in and catch up!

Sincerely,

--
Ted August
Assistant Director of Cybersecurity and Compliance
Office of Information Technology
Salve Regina University


**********
Replies to EDUCAUSE Community Group emails are sent to the entire community list. If you want to reply only to the 
person who sent the message, copy and paste their email address and forward the email reply. Additional participation 
and subscription information can be found at https://www.educause.edu/community

**********
Replies to EDUCAUSE Community Group emails are sent to the entire community list. If you want to reply only to the 
person who sent the message, copy and paste their email address and forward the email reply. Additional participation 
and subscription information can be found at https://www.educause.edu/community

Current thread: