Educause Security Discussion mailing list archives

Re: Secure file transfers


From: Ken Connelly <Ken.Connelly () UNI EDU>
Date: Mon, 7 May 2007 08:14:56 -0500

We don't even allow inbound, plain-text FTP to cross our border.
Outbound connections are allowed, but not inbound.  Also, within our
campus, plain-text FTP is only allowed within (and between) computer
room subnets for which we fully control the switches involved.

Plain-text FTP is *not* "secure enough" for any sensitive/protected data.

- ken

Theresa M Rowe wrote:
We have a big push for using outsourced ASP/data hosting services here.  We have a strong policy for contract review, 
including a security review.

We've been insisting on secure file transfer methods for data exchanges between the university and the vendor.  We've 
accepted VPN or SFTP as methods for data exchange, especially for those contracts where the data exchanges include confidential 
data (we have a state law in Michigan that protects certain data such as social security numbers and credit card numbers).  Data 
exposure (unauthorized access) of those data elements can result in a maximum $750,000 fine for the university.

We've been getting a push back from some vendors that "standard FTP" is secure enough.  We've been saying it isn't good 
enough.

I am checking in on best practice.  I'd appreciate your thoughts on this.

Thanks in advance -
Theresa
Theresa Rowe
Assistant Vice President
University Technology Services
www.oakland.edu/uts - the latest news from University Technology Services


--
- Ken
=================================================================
Ken Connelly             Associate Director, Security and Systems
ITS Network Services                  University of Northern Iowa
email: Ken.Connelly () uni edu   p: (319) 273-5850 f: (319) 273-7373

Current thread: