Educause Security Discussion mailing list archives

Re: Centralized security administration


From: Tom Davis <tdavis () IU EDU>
Date: Fri, 18 Aug 2006 09:32:46 -0400

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

Hunt,Keith A said the following on 8/17/06 11:19 AM:

Have you been able to establish effective policies and procedures that
provide for central IT personnel to oversee the security aspects of
non-IT devices (especially servers and network equipment)?  Have you
developed some other approach that works better? How do you reconcile
the need for decentralized systems/network admin functions with the need
for an enterprise approach to security?

Hi Keith,

We, like other universities, have IT departments throughout the schools
and departments here at Indiana University.  Although I wouldn't say
that our Security and Policy Office "oversees" the security efforts of
these IT departments, the policies and procedures published[1] by our
office are university-wide in scope and thus impact how those units
manage those systems.

With that said, we do have the backing of a Trustees resolution[2] in
the event that we need to take a more active role in the security of
these departmental systems.

[1] http://itpo.iu.edu/
[2] http://itpo.iu.edu/resolution.html

Hope this helps,

- --
Tom Davis, Chief IT Security Officer, CISSP, CISM, GCIA
Office of the VP for Information Technology, Indiana University
PGP key or S/MIME certificate: https://itso.iu.edu/Tom_Davis

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.5 (Darwin)
Comment: Using GnuPG with Mozilla - http://enigmail.mozdev.org

iD8DBQFE5cF+cxDtdAa0EQ0RAs1pAKDW0FZeYj8xNszTkLrKL+1gSsLNGQCgqVMY
W00c2GmTX5z84z1CMtYQSvs=
=jcrL
-----END PGP SIGNATURE-----

Current thread: