| Developing an enterprise information security policy |
| Full text |
Pdf
(635 KB)
|
| Source
|
User Services Conference
archive
Proceedings of the 30th annual ACM SIGUCCS conference on User services
table of contents
Providence, Rhode Island, USA
Pages: 153 - 156
Year of Publication: 2002
ISBN:1-58113-564-5
|
|
Author
|
|
| Sponsors |
|
| Publisher |
|
| Bibliometrics |
Downloads (6 Weeks): 39, Downloads (12 Months): 388, Citation Count: 5
|
|
|
ABSTRACT
The University of Pittsburgh is at the midpoint of a three-year strategic plan focused on information technology. Our strategic direction is based on a tiered model consisting of these layers: network infrastructure, middleware, Web infrastructure, and the set of applications and services that can be provided to our user community. As applications and services become increasingly more complex, there is a greater potential for security breaches that must be adequately addressed.The ability for students and faculty to share data and collaborate on projects is of utmost importance to any higher education institution. A large, multidisciplinary institution such as the University of Pittsburgh must be able to find an effective balance between the need to provide people in the local, national, and international communities with access to information and the need to protect sensitive information from unauthorized access and misuse.The subject of information security has received a great deal of attention within academia before and after the events of September 11, 2001. Federal regulations such as the HIPAA legislation protecting patient data, the USA PATRIOT Act, and the Digital Millennium Copyright Act all have significant impact. The complexities involved in developing adequate security plans have resulted in the development of the ISO 17799 standard, used widely in security plan development.A University-wide security plan is under development that, when completed, will address security at all levels. This comprehensive security plan will cover policies, business practice changes, and user awareness concerns. This presentation focuses on the process that is underway to identify security issues and to design and implement a comprehensive security plan that maintains an open academic environment and fully addresses relevant legislation and best practice models.
CITED BY 5
|
|
Ernesto Damiani , S. De Capitani Vimercati , Sushil Jajodia , Stefano Paraboschi , Pierangela Samarati, Balancing confidentiality and efficiency in untrusted relational DBMSs, Proceedings of the 10th ACM conference on Computer and communications security, October 27-30, 2003, Washington D.C., USA
|
|
|
Alberto Ceselli , Ernesto Damiani , Sabrina De Capitani Di Vimercati , Sushil Jajodia , Stefano Paraboschi , Pierangela Samarati, Modeling and assessing inference exposure in encrypted databases, ACM Transactions on Information and System Security (TISSEC), v.8 n.1, p.119-152, February 2005
|
|
|
Jorge Alberto Ruiz-Vanoye , Ocotlan Díaz-Parra , Ismael Rafael Ponce-Medellín , Alejandro Fuentes-Penna , Juan Carlos Olivares-Rojas, Strategic planning for the computer science security of banking organizations, companies and government, Proceedings of the 2nd WSEAS International Conference on Computer Engineering and Applications, p.60-64, January 25-27, 2008, Acapulco, Mexico
|
|
|
Masato Masuya , Takash Yamanoue , Shinichiro Kubota, An experience of monitoring university network security using a commercial service and DIY monitoring, Proceedings of the 34th annual ACM SIGUCCS conference on User services, p.225-230, November 05-08, 2006, Edmonton, Alberta, Canada
|
|
|
|
INDEX TERMS
Primary Classification:
K.
Computing Milieux
K.6
MANAGEMENT OF COMPUTING AND INFORMATION SYSTEMS
K.6.5
Security and Protection (D.4.6, K.4.2)
Subjects:
Unauthorized access (e.g., hacking, phreaking)
General Terms:
Legal Aspects,
Management,
Security
Keywords:
compliance,
data security,
network management,
network security,
policies,
regulation,
security,
unauthorized access
|