Pages

Wednesday, October 21, 2009

21st Century Skills and Technology Education

Our lives in the 21st century are significantly influenced by technology, both current and that yet imagined. To properly prepare our students for their future, we need to teach 21st century skills. This means a seamless integration of technology across the spectrum of school activities by the students, staff, and community.

Monday, October 19, 2009

Feedburner Site Stats

I just checked my stats on Feedburner and learned that I’ve had 25 hits in the past 8 hours. The hits were from all around the world, some US, but many in Canada, France and Germany. I’ve also had 8 subscribers since I checked last night. I poked around a bit more and learned that the site stats feature is now available free, so I subscribed and hope to learn a bit more about my subscribers.

Friday, October 16, 2009

More on Website Security Plans

I recently read an article by Gary Kessler, professor at Champlain College. In his article on Securing your Website, Mr. Kessler recommends that we ask ourselves five questions:

  • “What are you trying to protect?
  • From whom are you protecting it?
  • What is the likelihood of an attack and what kind of attack is most likely?
  • What are the possible results of an attack or compromise?
  • How much protection can I afford?”

While some of the answers to these questions may seem obvious, it is essential and very useful to reflect on the issues and clarify the answers. The assessment process with provide an opportunity to review and analyze the current state of security, and identify the assets to be protected, which include hardware, software, data, documentation and people. Categorizing information and establishing a sensitivity scale will be helpful in this process. It is essential to reflect on threats and evaluate the exposure for assets and services. The formula

R (Risk) = A (Asset) *T (Threat) * V (vulnerability)

is helpful in assessing a site’s changing security risk. Even though there are risks for every server, there is no “package deal” for security. While there are recommendations for network and web server security, each organization has individual and specific needs. It is essential to asses these individual needs and develop a security plan in accordance.

The planning process is likely to take time and in the meantime it is crucial to develop an interim plan to protect a network and web server.

According to Microsoft’s Publication Security Guide for Small Business “A good plan today is better than a perfect plan tomorrow. Planning for security is a cyclical and repetitive process so it makes sense to execute a quick plan now and refine it later.” During this process it is important to remember that “the objective is not to eliminate all risks regardless of the cost, but to minimize the risk as much as possible. There are three main tradeoffs:

  • Factuality versus security needed
  • Ease of use versus security
  • Cost of security versus risk of loss” (Microsoft p.50, Creating a Security Plan).

During the planning stages it is likely for a team to collaborate and establish guidelines and recommendations, as well as document the process of planning. Many organizations use checklists, such as the Rutgers State University of New Jersey resource. This checklists provides a series of questions regarding many aspect of network and server security. Some of the most obvious questions may prove to be the most difficult, and possibly the easiest to overlook. The checklist approach may provide “baseline” security information, which would allow a security department to review this information and establish further recommendations to departments. Security questionnaires should include questions about hardware, software, network and environmental risks, as well as duties and responsibilities, users, and user security, physical security and network configuration security. Disaster planning and continuity, as well as backup and recovery, patching, software licensing, anti virus software, and network security should also be included. It is also crucial to include plans for disaster recovery and a plan for dealing with a security breach. One of the most important (and most frequently overlooked) aspects is ongoing user training and support.

Thursday, October 15, 2009

Security Plan

Establishing a security plan may seem easy and almost unnecessary, why not “lock down” a webserver, install a firewall and follow general advise that all servers should follow. While there are guidelines that should be followed for all servers, security is mesh of technology, people, processes and policies. A good security plan matches a company’s security policy and assures that there are no gaps in the process.

According to Microsoft’s Publication Security Guide for Small Business “ there are four steps to creating a good security plan: assess, plan, execute and monitor.”

Wednesday, September 30, 2009

Summer work and Conferences

Much of my work this summer revolved around planning for technology in our District. In June we submitted our technology plan, and had worked with teams of from other schools around Vermont as a group called VT LEAD IT (Vermont Leadership for Information Technology in Education )

In the summer the teams had the wonderful opportunity to spend several days at UVM to continue the work at a conference. Teams had time to work as teams, and also to learn from nationally recognized technology experts. Bernie Dodge, the “guru” of Webquests was the keynote speaker at an evening event. David Warlick, the founder of the Landmark Project shared many Web2.0 resources. One of my absolute favorite tools is the Citation Machine. Jim Moulton presentation on Project Based Learning rounded out the event.

Several members of our admin team also attended Alan November's Conference in Boston.