Wednesday, October 21, 2009
21st Century Skills and Technology Education
Monday, October 19, 2009
Feedburner Site Stats
Friday, October 16, 2009
More on Website Security Plans
I recently read an article by Gary Kessler, professor at Champlain College. In his article on Securing your Website, Mr. Kessler recommends that we ask ourselves five questions:
- “What are you trying to protect?
- From whom are you protecting it?
- What is the likelihood of an attack and what kind of attack is most likely?
- What are the possible results of an attack or compromise?
- How much protection can I afford?”
R (Risk) = A (Asset) *T (Threat) * V (vulnerability)
is helpful in assessing a site’s changing security risk. Even though there are risks for every server, there is no “package deal” for security. While there are recommendations for network and web server security, each organization has individual and specific needs. It is essential to asses these individual needs and develop a security plan in accordance.
The planning process is likely to take time and in the meantime it is crucial to develop an interim plan to protect a network and web server.
According to Microsoft’s Publication Security Guide for Small Business “A good plan today is better than a perfect plan tomorrow. Planning for security is a cyclical and repetitive process so it makes sense to execute a quick plan now and refine it later.” During this process it is important to remember that “the objective is not to eliminate all risks regardless of the cost, but to minimize the risk as much as possible. There are three main tradeoffs:
- Factuality versus security needed
- Ease of use versus security
- Cost of security versus risk of loss” (Microsoft p.50, Creating a Security Plan).
During the planning stages it is likely for a team to collaborate and establish guidelines and recommendations, as well as document the process of planning. Many organizations use checklists, such as the Rutgers State University of New Jersey resource. This checklists provides a series of questions regarding many aspect of network and server security. Some of the most obvious questions may prove to be the most difficult, and possibly the easiest to overlook. The checklist approach may provide “baseline” security information, which would allow a security department to review this information and establish further recommendations to departments. Security questionnaires should include questions about hardware, software, network and environmental risks, as well as duties and responsibilities, users, and user security, physical security and network configuration security. Disaster planning and continuity, as well as backup and recovery, patching, software licensing, anti virus software, and network security should also be included. It is also crucial to include plans for disaster recovery and a plan for dealing with a security breach. One of the most important (and most frequently overlooked) aspects is ongoing user training and support.
Thursday, October 15, 2009
Security Plan
Establishing a security plan may seem easy and almost unnecessary, why not “lock down” a webserver, install a firewall and follow general advise that all servers should follow. While there are guidelines that should be followed for all servers, security is mesh of technology, people, processes and policies. A good security plan matches a company’s security policy and assures that there are no gaps in the process.
According to Microsoft’s Publication Security Guide for Small Business “ there are four steps to creating a good security plan: assess, plan, execute and monitor.”
Wednesday, September 30, 2009
Summer work and Conferences
In the summer the teams had the wonderful opportunity to spend several days at UVM to continue the work at a conference. Teams had time to work as teams, and also to learn from nationally recognized technology experts. Bernie Dodge, the “guru” of Webquests was the keynote speaker at an evening event. David Warlick, the founder of the Landmark Project shared many Web2.0 resources. One of my absolute favorite tools is the Citation Machine. Jim Moulton presentation on Project Based Learning rounded out the event.
Several members of our admin team also attended Alan November's Conference in Boston.
