Stimulating Discussions in a Beautiful Setting
Education has special needs for information security. Tom Candon and Adam Goldsmith have both deeply involved in organizing one of my favorite conferences, Securing the eCampus. I recently interviewed Tom and Adam for Network World.
Education has special needs for information security. Tom Candon and Adam Goldstein have both deeply involved in organizing one of my favorite conferences, Securing the eCampus. I recently interviewed Tom and Adam for Network World.
* * *
This is the fifth annual eCampus conference; tell our readers a bit about the history of the event. What prompted you to start the series?
We have been very fortunate here to have a great relationship between the computing services department and the researchers that are working on computer security issues, many through the Institute for Security, Technology, and Society (ISTS). In 2007, we had some funding to run a workshop on information security. We brainstormed a topic focus and, after some thought, looked around and realized there are plenty of security issues in academe that need to be considered in many, many contexts. Five years later, there is still much to discuss.
What are the special or particular requirements of universities that make security in universities a special issue?
There are so many policies with which a university must be concerned. From FERPA, to PCI, to HIPAA, to research data, and on and on, the university has numerous policy related responsibilities not to mention other IT related concerns like cyber bullying, RIAA notices, etc. Because of the changing policy issues alone, we make a point of inviting a speaker every year just to discuss changes to national policy that have an effect on how the institution needs to operate.
How has security for university and college systems changed in the last few years?
Many of the general trends in information technology have had an impact at higher education institutions. The efficiency and flexibility afforded by mobile computing has been beneficial but also raises risk due to the broader distribution of institutional data. Cloud computing can have attractive pricing and allow some institutions to better focus on their core missions. However, shifting services to the cloud raises questions regarding security, data ownership, and regulatory obligations. On a more technical level, the shift from standalone and client/server applications to web-based services has caused an increase in external attacks against web servers and heightened the need to implement secure web applications.
In my experience, there are conflicts between the academic culture of openness and free inquiry and the assumptions behind access controls and restrictions on transferring content (e.g., student records). Have you personally experienced some of these conflicts? How do you cope with these culture clashes?
Many institutions are attempting to address this issue by taking a layered approach to their security programs. By adopting security architectures, technical controls, and business processes that adequately protect administrative systems while not restricting scholarly pursuits, many schools are trying to meet their obligations to protect the institution while allowing for academic freedom. This, however, is challenging because many systems are used for both academic and administrative functions, data is often intermingled, and a sizeable portion of research and other educational activity also require security controls.
* * *
The program overview and detailed agenda list some exciting lectures and speakers. Topics on July 19 includeShari Lawrence Pfleeger)Charles Pfleeger)Larry Conrad)Alex Hutton)Larry Clinton)Adam Goldstein and the Cyber Security Initiative Team at Dartmouth)Jennifer Frank)
• Keeping the Human in the Loop (
• Dumb Ideas in Computer Security (
• Out of the Frying Pan and into the Fire: Protecting the Security of Research Data (
• Verizon Data Breach Investigations Report (
• The Evolution of Cyber Threats and Government Policy (
• Anatomy of an Attack (
• Social Media Security and Privacy (
Breakout sessions on July 20 will include discussions on
• Understanding Global Internet Events
• The OWASP Top Ten
• Building Security In Maturity Model (BSIMM)
• Cyber Insurance
One of the reasons I enjoy the Securing the eCampus conferences is that the Hanover, N.H., area is gorgeous in the summer – and visiting my alma mater (PhD 1976) is always fun. I hope to meet readers of this column who are interested in campus security issues at this excellent event.
* * *
Adam Goldstein is the IT security engineer with Peter Kiewit Computing Services at Dartmouth College, where he is the technical lead for information security operations and serves as the security adviser on numerous IT projects and working groups. With over 10 years’ experience in information security at institutions of higher education and a background in systems and network engineering, he has a thorough understanding of the unique security challenges in academia. Adam received his B.A. from Rutgers University and his Master of Science in Information Assurance from Norwich University. He is a GIAC Certified Forensic Analyst (GCFA), a Certified Computer Examiner (CCE), and also holds the CISSP certification.
Tom Candon has been the associate director of ISTS at Dartmouth College since June 2007. Prior to joining ISTS, Tom worked for 10 years with SAIC in the Washington, D.C. area. While with SAIC, he worked on government projects that focused on information operations policy, the revolution in military affairs, organizational adaptation, and technology assessments.




