Home > Security in 2007: No Surprises Here (Well Maybe a Few)

Opinion

Security in 2007: No Surprises Here (Well Maybe a Few)

11/9/2007

Each year O'Keeffe and Company conducts an online and in person IT Security survey of IT directors and managers for CDW-G. This year there were 151 respondents from a variety of higher education settings. The results are an important barometer of the state of IT Security in higher education. The full report is available here. If you haven't downloaded it already, you should do so now: It's important.

Things That Jump Out
As I read the report a couple of things stood out. First, high profile IT security incidents continue to plague higher education. For the second year in a row 58 percent of the respondents reported an IT security incident. And again, sensitive data residing on unprotected or vulnerable computers is ranked as the top security risk. (See my July 13 Campus Security Newsletter column "Who Knows What Evil Lurks in the Cyber Heart?" for comments on this problem.)

The second thing that jumped out at me was that things don't seem to be getting any better, although the good news is that they don't seem to be getting any worse. For the last three years the number of respondents reporting that they feel very safe from malicious attack has hovered around 8 percent, while the number that felt safe has stayed around 37 percent. There were no consistent trends of feeling more or less safe over that period.

Why Aren't Things Getting Better?
When asked what were the barriers to improving IT security, the responses were: too few staff resources, lack of funding, higher education culture, and lack of defined security policy. No surprise here. What I did find a little surprising was the apparent emphasis on technology to overcome these barriers. This may be an artifact of the way question was poised to the respondents. "Which of the following security devices are utilized on your campus?" The choices included such things as network authentication software, card access systems, and IP cameras. The problem is that acquiring these devices, while important, doesn't address resource, cultural, or policy barriers. How are institutions approaching the underlying problems?

To pursue this I had a long conversation with Louisiana State Universities CIO Brian Voss and their Chief Information Security & Policy Officer Brian Nichols. In the wake of Hurricane Katrina, LSU has been in the vanguard of improving IT security and implementing disaster recovery and business continuity strategies. Staff dedicated to IT security, disaster recovery, and business continuity have increased from zero to nine FTE.



Recommended Reading
  • RIAA Outsources Fingering of Students Who Share Music Illegally

    The RIAA is outsourcing the hunt for music thieves. Its largest target currently is those who operate from within colleges and universities, a move that has piqued the attention of Educause.

  • Microsoft Expands Education Footprint in Asia Pacific Region

    Microsoft Chairman Bill Gates announced new partnerships to extend accessibility and computer literacy in the Asia Pacific region during a speech in Jakarta at a government leader gathering earlier this week.

  • IT Struggling Over Security, Compliance

    IT pros are having a hard time balancing security, software patch management and IT auditing with a host of other duties, according to a survey released Monday by Shavlik Technologies.

  • Toronto College Upgrades Network with Gigabit Ethernet Wireless Links

    Toronto-based George Brown College has gone public about its deployment of six BridgeWave GE60 wireless links to upgrade its campus-wide network.

  • Gates Highlights R&D at CES08, Unveils Microsoft Touch Wall

    Microsoft's Chairman Bill Gates spent a lot of time Wednesday talking about "empowering the workers" at the Microsoft's 12th annual CEO Summit 2008 in Redmond, WA, where he gave a keynote speech. However, Gates wasn't talking about political revolutions or even pay raises for office workers before the CEO crowd. Instead, he was referring to new software technologies that can better enable collaboration, social networking and decision-making on the job.

  • Vista Vulnerability Study Puts Microsoft on Defensive

    Microsoft and some independent security researchers had the blogosphere buzzing Wednesday over a series of denunciations after one company claimed that the Vista operating system was more vulnerable to malware and other exploits than previous operating systems.