Educause Security Discussion mailing list archives
Re: [EXTERNAL] Re: [SECURITY] [EXT] Re: [SECURITY] student systems and NIST 800-171
From: "Jackson, Ms. D'Ann" <DJACKSON () TARLETON EDU>
Date: Mon, 8 Feb 2021 15:56:07 +0000
Please add me to the working group. D’Ann Jackson I.T. Policy Analyst Information Technology Services tarleton state university Box T-0220, Stephenville, TX 76402 o 254-968-9675 tarleton.edu<https://www.tarleton.edu/> Information Technology Services staff will never ask for your password in an email. Do not send your password to anyone or share confidential information in email. Confidentiality Notice: This electronic message, including any attachments, is for the sole use of the intended recipient(s) and may contain confidential and privileged information. Any unauthorized review, use, disclosure or distribution is prohibited. If you are not the intended recipient, please contact the sender by reply e-mail and destroy all copies of the original message. From: The EDUCAUSE Security Community Group Listserv <SECURITY () LISTSERV EDUCAUSE EDU> On Behalf Of Karen A Bell (kbell) Sent: Monday, February 8, 2021 9:43 AM To: SECURITY () LISTSERV EDUCAUSE EDU Subject: Re: [SECURITY] [EXTERNAL] Re: [SECURITY] [EXT] Re: [SECURITY] student systems and NIST 800-171 Please add me to the working group. Karen Bell Director | IT Security and Identity Management Information Technology The University of Memphis 152 Administration Building Memphis, TN 38152 901.678.4274 | kbell () memphis edu<mailto:kbell () memphis edu> ________________________________ From: The EDUCAUSE Security Community Group Listserv <SECURITY () LISTSERV EDUCAUSE EDU<mailto:SECURITY () LISTSERV EDUCAUSE EDU>> on behalf of Mavour, Monique A <mmavour () MOCS FLSOUTHERN EDU<mailto:mmavour () MOCS FLSOUTHERN EDU>> Sent: Monday, February 8, 2021 7:51 AM To: SECURITY () LISTSERV EDUCAUSE EDU<mailto:SECURITY () LISTSERV EDUCAUSE EDU> <SECURITY () LISTSERV EDUCAUSE EDU<mailto:SECURITY () LISTSERV EDUCAUSE EDU>> Subject: Re: [SECURITY] [EXTERNAL] Re: [SECURITY] [EXT] Re: [SECURITY] student systems and NIST 800-171 CAUTION: This email originated from outside of the organization. Do not click links or open attachments unless you recognize the sender and trust the content is safe. Hello All, I am interested in being added to the group as well Thank you, Monique Mavour IT Project Manager Florida Southern College On Feb 2, 2021, at 6:29 PM, Dan Wasson <dan () nmc edu<mailto:dan () nmc edu>> wrote: CAUTION: This email originated from outside your organization. Exercise caution when opening attachments or clicking links, especially from unknown senders. I would be interested in the working group. Dan Wasson Director Systems & LAN Management Northwestern Michigan College 231-995-1164 dwasson () nmc edu<mailto:dwasson () nmc edu> Don't be a scam victim - NMC and other reputable organizations will never use email to request that you reply with your password, social security number or confidential personal information. On Tue, Feb 2, 2021 at 5:45 PM Ricardo Fitipaldi <rfitipal () sdsu edu<mailto:rfitipal () sdsu edu>> wrote: Please include sdsu.edu<https://nam11.safelinks.protection.outlook.com/?url=https%3A%2F%2Fprotect-us.mimecast.com%2Fs%2F4bT2Czp5wPhryKQh4JLgR%3Fdomain%3Dlinkprotect.cudasvc.com&data=04%7C01%7Cdjackson%40TARLETON.EDU%7C53f60b57e7bb4033110208d8cc499c10%7C2c5ee638a96349c0ac26828dd9b78d5e%7C0%7C0%7C637483964879391674%7CUnknown%7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C3000&sdata=n2gwW03HWplNH2hnafkTMQfpYyCyfyl9QuSoksf0ftE%3D&reserved=0> in the working ground. Sincerely, Ricardo Fitipaldi IT Security Office | Interim Information Security Officer San Diego State University | sdsu.edu<https://nam11.safelinks.protection.outlook.com/?url=https%3A%2F%2Fprotect-us.mimecast.com%2Fs%2FCnjiCADoYquRPjLI8HCnm%3Fdomain%3Dlinkprotect.cudasvc.com&data=04%7C01%7Cdjackson%40TARLETON.EDU%7C53f60b57e7bb4033110208d8cc499c10%7C2c5ee638a96349c0ac26828dd9b78d5e%7C0%7C0%7C637483964879401668%7CUnknown%7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C3000&sdata=zZksVzVrzM%2B%2B9jEpVkFsUiWRILRGxUbvIKTgr0RfovQ%3D&reserved=0> (619)-594-0099 [https://docs.google.com/uc?export=download&id=1W9Aoru8ls-WFwlVb-gThaCnomKy9dpkJ&revid=0B8viOvS3VVasWXBudHNjdHdLcmU5ZkdOc24zYlFHdHdzdWZZPQ] Get Duo, Stay Protected. Learn More at the IT Security Duo MFA<https://nam11.safelinks.protection.outlook.com/?url=https%3A%2F%2Fprotect-us.mimecast.com%2Fs%2FwnczCBBpYohnkvpcN1gEA%3Fdomain%3Dlinkprotect.cudasvc.com&data=04%7C01%7Cdjackson%40TARLETON.EDU%7C53f60b57e7bb4033110208d8cc499c10%7C2c5ee638a96349c0ac26828dd9b78d5e%7C0%7C0%7C637483964879401668%7CUnknown%7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C3000&sdata=j4Nmn4yURc%2BqECl7URnO92ogefZ4Op%2BkyB0uzT6jd6Q%3D&reserved=0> page | @SDSUITSO<https://nam11.safelinks.protection.outlook.com/?url=https%3A%2F%2Fprotect-us.mimecast.com%2Fs%2FQeYCCDkrVNfxWXNhZGCCd%3Fdomain%3Dtwitter.com&data=04%7C01%7Cdjackson%40TARLETON.EDU%7C53f60b57e7bb4033110208d8cc499c10%7C2c5ee638a96349c0ac26828dd9b78d5e%7C0%7C0%7C637483964879411659%7CUnknown%7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C3000&sdata=41WE7zrv%2F7QxmK059HcH3vB81GvcFZ%2BrcnhA3QmSI5s%3D&reserved=0> On Fri, Jan 29, 2021 at 5:43 AM Harry Hoffman <hhoffman () ip-solutions net<mailto:hhoffman () ip-solutions net>> wrote: We're just starting to look into this among a broader effort around compliance. I'd be interested in what other are doing or forming an interest/working group if there's enough folks keen to do so. Cheers, Harry On Thu, Jan 28, 2021 at 11:35 AM Fugett, Julie C <jcf () ku edu<mailto:jcf () ku edu>> wrote: Is anyone aware of templates, checklists, or other guidance around performing this self-assessment? I just watched Mia Jordan’s talk from the 2020 Virtual FSA training conference and while the talk was informative, she didn’t provide any resources or a timeline for the self-assessment process. I’m reaching out to the contact email in the slides, but I’m wondering if I’ve missed something somewhere along the way. ______________________________________ Julie C. Fugett, CISSP Chief Information Security Officer KU Information Technology The University of Kansas Email jcf () ku edu<mailto:jcf () ku edu> Mobile +1 785 691 9023 Office +1 785 864 0490 She/Her/Hers From: The EDUCAUSE Security Community Group Listserv <SECURITY () LISTSERV EDUCAUSE EDU<mailto:SECURITY () LISTSERV EDUCAUSE EDU>> On Behalf Of Ross Mukai Sent: Wednesday, January 27, 2021 6:10 PM To: SECURITY () LISTSERV EDUCAUSE EDU<mailto:SECURITY () LISTSERV EDUCAUSE EDU> Subject: Re: [SECURITY] student systems and NIST 800-171 Some slides from the 2020 student aid conference describing a compliance framework for glba + CUI The bullet points on the near-term plan on pg 18 include the 12/18/20 letter and self-assessments https://fsaconferences.ed.gov/conferences/library/2020/2020FSAConfSessionBO15.pdf<https://nam11.safelinks.protection.outlook.com/?url=https%3A%2F%2Fprotect-us.mimecast.com%2Fs%2FRfpqCERvVOcqzBVsZEnGv%3Fdomain%3Dnam10.safelinks.protection.outlook.com&data=04%7C01%7Cdjackson%40TARLETON.EDU%7C53f60b57e7bb4033110208d8cc499c10%7C2c5ee638a96349c0ac26828dd9b78d5e%7C0%7C0%7C637483964879411659%7CUnknown%7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C3000&sdata=oKqqINR27kiBkSBWyCwfRDAlaFY7K%2BPEHKrWXwxgWTM%3D&reserved=0> On Wed, Jan 27, 2021 at 2:01 PM Sam Horowitz <samh () ucsb edu<mailto:samh () ucsb edu>> wrote: https://ifap.ed.gov/electronic-announcements/121820CybersecurityProtectStudentInfoComplianceCUInGLBA<https://nam11.safelinks.protection.outlook.com/?url=https%3A%2F%2Fprotect-us.mimecast.com%2Fs%2FhCM7CG6xVnu8PwKi0GhaN%3Fdomain%3Dnam10.safelinks.protection.outlook.com&data=04%7C01%7Cdjackson%40TARLETON.EDU%7C53f60b57e7bb4033110208d8cc499c10%7C2c5ee638a96349c0ac26828dd9b78d5e%7C0%7C0%7C637483964879421654%7CUnknown%7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C3000&sdata=ppL1vM5Mea6eRu85wLZ2bnMwCQFvqxPqNfkAT33aXtk%3D&reserved=0> ------------------------------------------- Sam Horowitz, CISSP, CISM Chief Information Security Officer he/him/his Office: (805) 893-5005 Email: samh () ucsb edu<mailto:samh () ucsb edu> On Wed, Jan 27, 2021 at 3:38 PM Alex Jalso <ACJalso () mail wvu edu<mailto:ACJalso () mail wvu edu>> wrote: Hello Everyone, In a meeting with peer institutions it was said that at the Federal level there’s been discussions that university student information systems must treat resident data as CUI and have their systems be compliant with NIST 800-171 or risk losing financial aid. Has anyone heard something similar to this or received communications about it? Alex Alex Jalso, PMP, CISM, CDPSE Chief Information Security Officer Information Technology Services West Virginia University p: 304-293-4457 Defend your data. ITS will NEVER ask you for your WVU Login credentials, Social Security number or credit card information via email. NEVER click on suspicious email links or attachments, even those that appear to be from a legitimate source. Hover over links to see where they really lead before clicking on them. When in doubt, contact DefendYourData () mail wvu edu<mailto:DefendYourData () mail wvu edu>. ********** Replies to EDUCAUSE Community Group emails are sent to the entire community list. If you want to reply only to the person who sent the message, copy and paste their email address and forward the email reply. Additional participation and subscription information can be found at https://www.educause.edu/community<https://nam11.safelinks.protection.outlook.com/?url=https%3A%2F%2Fprotect-us.mimecast.com%2Fs%2FeNZTCJ6A9Dun2x3cp2TKv%3Fdomain%3Dnam10.safelinks.protection.outlook.com&data=04%7C01%7Cdjackson%40TARLETON.EDU%7C53f60b57e7bb4033110208d8cc499c10%7C2c5ee638a96349c0ac26828dd9b78d5e%7C0%7C0%7C637483964879421654%7CUnknown%7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C3000&sdata=vMlgRJMZltlxTYo3aSojdJB0j1uCoO%2BbvX7ifeeCwYg%3D&reserved=0> ********** Replies to EDUCAUSE Community Group emails are sent to the entire community list. If you want to reply only to the person who sent the message, copy and paste their email address and forward the email reply. Additional participation and subscription information can be found at https://www.educause.edu/community<https://nam11.safelinks.protection.outlook.com/?url=https%3A%2F%2Fprotect-us.mimecast.com%2Fs%2F9TpXCKrBVXu1YLzTnnN3L%3Fdomain%3Dnam10.safelinks.protection.outlook.com&data=04%7C01%7Cdjackson%40TARLETON.EDU%7C53f60b57e7bb4033110208d8cc499c10%7C2c5ee638a96349c0ac26828dd9b78d5e%7C0%7C0%7C637483964879431649%7CUnknown%7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C3000&sdata=YpbWIei%2F9sjj27cNUHwb4Yh82%2BtRyGCTIaiaqTjV%2Fik%3D&reserved=0> ********** Replies to EDUCAUSE Community Group emails are sent to the entire community list. If you want to reply only to the person who sent the message, copy and paste their email address and forward the email reply. Additional participation and subscription information can be found at https://www.educause.edu/community<https://nam11.safelinks.protection.outlook.com/?url=https%3A%2F%2Fprotect-us.mimecast.com%2Fs%2F9TpXCKrBVXu1YLzTnnN3L%3Fdomain%3Dnam10.safelinks.protection.outlook.com&data=04%7C01%7Cdjackson%40TARLETON.EDU%7C53f60b57e7bb4033110208d8cc499c10%7C2c5ee638a96349c0ac26828dd9b78d5e%7C0%7C0%7C637483964879431649%7CUnknown%7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C3000&sdata=YpbWIei%2F9sjj27cNUHwb4Yh82%2BtRyGCTIaiaqTjV%2Fik%3D&reserved=0> ********** Replies to EDUCAUSE Community Group emails are sent to the entire community list. If you want to reply only to the person who sent the message, copy and paste their email address and forward the email reply. Additional participation and subscription information can be found at https://www.educause.edu/community<https://nam11.safelinks.protection.outlook.com/?url=https%3A%2F%2Fprotect-us.mimecast.com%2Fs%2Facb4CL9DV6u3gLys1O-wB%3Fdomain%3Dlinkprotect.cudasvc.com&data=04%7C01%7Cdjackson%40TARLETON.EDU%7C53f60b57e7bb4033110208d8cc499c10%7C2c5ee638a96349c0ac26828dd9b78d5e%7C0%7C0%7C637483964879441641%7CUnknown%7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C3000&sdata=MXCZiwWGGp%2FG1VV891AoAIBiZRJtRJobi9dn3UrS%2Bbw%3D&reserved=0> ********** Replies to EDUCAUSE Community Group emails are sent to the entire community list. If you want to reply only to the person who sent the message, copy and paste their email address and forward the email reply. Additional participation and subscription information can be found at https://www.educause.edu/community<https://nam11.safelinks.protection.outlook.com/?url=https%3A%2F%2Fprotect-us.mimecast.com%2Fs%2FATE3CM8gVDhJLjMTRLGmx%3Fdomain%3Dlinkprotect.cudasvc.com&data=04%7C01%7Cdjackson%40TARLETON.EDU%7C53f60b57e7bb4033110208d8cc499c10%7C2c5ee638a96349c0ac26828dd9b78d5e%7C0%7C0%7C637483964879441641%7CUnknown%7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C3000&sdata=wtXHOy%2B6b7nLVnY3LMbZj2dDVY%2BicMXtvXZHQ%2B4lpdo%3D&reserved=0> ********** Replies to EDUCAUSE Community Group emails are sent to the entire community list. If you want to reply only to the person who sent the message, copy and paste their email address and forward the email reply. Additional participation and subscription information can be found at https://www.educause.edu/community<https://nam11.safelinks.protection.outlook.com/?url=https%3A%2F%2Fprotect-us.mimecast.com%2Fs%2FgS3gCNkj6Df6QoDi9vuP9%3Fdomain%3Dlinkprotect.cudasvc.com&data=04%7C01%7Cdjackson%40TARLETON.EDU%7C53f60b57e7bb4033110208d8cc499c10%7C2c5ee638a96349c0ac26828dd9b78d5e%7C0%7C0%7C637483964879451640%7CUnknown%7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C3000&sdata=QyvWslSAFmHyVwo4J6g1Dth13MBlmKtQJzNSlo3qy%2BY%3D&reserved=0> ********** Replies to EDUCAUSE Community Group emails are sent to the entire community list. If you want to reply only to the person who sent the message, copy and paste their email address and forward the email reply. Additional participation and subscription information can be found at https://www.educause.edu/community<https://nam11.safelinks.protection.outlook.com/?url=https%3A%2F%2Fprotect-us.mimecast.com%2Fs%2FqOORCOYk0luOg3zTJ1s-i%3Fdomain%3Dlinkprotect.cudasvc.com&data=04%7C01%7Cdjackson%40TARLETON.EDU%7C53f60b57e7bb4033110208d8cc499c10%7C2c5ee638a96349c0ac26828dd9b78d5e%7C0%7C0%7C637483964879451640%7CUnknown%7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C3000&sdata=g3casqxLnrxvcBfY6IoJ4qwIWFF1eXu3YJ9tv4idH7w%3D&reserved=0> ********** Replies to EDUCAUSE Community Group emails are sent to the entire community list. If you want to reply only to the person who sent the message, copy and paste their email address and forward the email reply. Additional participation and subscription information can be found at https://www.educause.edu/community<https://nam11.safelinks.protection.outlook.com/?url=https%3A%2F%2Fprotect-us.mimecast.com%2Fs%2Fq_tDCPNlVms62Q8iVmyor%3Fdomain%3Deducause.edu&data=04%7C01%7Cdjackson%40TARLETON.EDU%7C53f60b57e7bb4033110208d8cc499c10%7C2c5ee638a96349c0ac26828dd9b78d5e%7C0%7C0%7C637483964879461633%7CUnknown%7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C3000&sdata=JfPsWUyl0UME1k4azN%2F7oVxKySuySSiMNxiMh7yLg74%3D&reserved=0> ********** Replies to EDUCAUSE Community Group emails are sent to the entire community list. If you want to reply only to the person who sent the message, copy and paste their email address and forward the email reply. Additional participation and subscription information can be found at https://www.educause.edu/community<https://nam11.safelinks.protection.outlook.com/?url=https%3A%2F%2Fwww.educause.edu%2Fcommunity&data=04%7C01%7Cdjackson%40TARLETON.EDU%7C53f60b57e7bb4033110208d8cc499c10%7C2c5ee638a96349c0ac26828dd9b78d5e%7C0%7C0%7C637483964879461633%7CUnknown%7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C3000&sdata=l%2B00excWeBlZTVkz2Rq57SdL7RrGpH%2BS1%2FuXsuYl%2F%2FE%3D&reserved=0> ********** Replies to EDUCAUSE Community Group emails are sent to the entire community list. If you want to reply only to the person who sent the message, copy and paste their email address and forward the email reply. Additional participation and subscription information can be found at https://www.educause.edu/community
Current thread:
- Re: student systems and NIST 800-171, (continued)
- Re: student systems and NIST 800-171 Elizabeth Shannon (Feb 02)
- Re: student systems and NIST 800-171 Paco Rosas-Moreno (Feb 02)
- Re: student systems and NIST 800-171 Hintz, Debra A (Jan 29)
- Re: student systems and NIST 800-171 Mark Dieterich (Jan 29)
- Re: student systems and NIST 800-171 Vince Bonura (Jan 30)
- Re: student systems and NIST 800-171 Ronald Loneker (Feb 01)
- Re: [EXT] Re: [SECURITY] student systems and NIST 800-171 Ricardo Fitipaldi (Feb 02)
- Re: [EXTERNAL] Re: [SECURITY] [EXT] Re: [SECURITY] student systems and NIST 800-171 Dan Wasson (Feb 02)
- Re: [EXTERNAL] Re: [SECURITY] [EXT] Re: [SECURITY] student systems and NIST 800-171 Mavour, Monique A (Feb 08)
- Re: [EXTERNAL] Re: [SECURITY] [EXT] Re: [SECURITY] student systems and NIST 800-171 Karen A Bell (kbell) (Feb 08)
- Re: [EXTERNAL] Re: [SECURITY] [EXT] Re: [SECURITY] student systems and NIST 800-171 Jackson, Ms. D'Ann (Feb 08)
- Re: [EXTERNAL] Re: [SECURITY] [EXT] Re: [SECURITY] student systems and NIST 800-171 Steven Saine (Feb 08)
- Re: [EXTERNAL] Re: [SECURITY] [EXT] Re: [SECURITY] student systems and NIST 800-171 Nadim El-Khoury (Feb 08)
- Re: [EXTERNAL] Re: [SECURITY] [EXT] Re: [SECURITY] student systems and NIST 800-171 Brian Amstutz (Feb 08)
- Re: [EXTERNAL] Re: [SECURITY] [EXT] Re: [SECURITY] student systems and NIST 800-171 Ben Marsden (Feb 08)
- Re: [External] Re: [SECURITY] student systems and NIST 800-171 Coleman, Susan Elizabeth (Jan 28)
- Re: [External] Re: [SECURITY] student systems and NIST 800-171 Ross Mukai (Jan 28)
- Re: student systems and NIST 800-171 Welch, Von (Jan 29)