Educause Security Discussion mailing list archives

Re: Policy Enforcement


From: John Ladwig <John.Ladwig () CSU MNSCU EDU>
Date: Fri, 26 Mar 2010 15:57:48 -0500

That must have been a ways back.  In 1998 or 1999 I was impounding a hard drive from an academic lab for more or less 
the same thing, and the faculty member in question observed that a hard drive or three over the course of the year was 
money way ahead of paying an actual sysadmin or doing any security on the server in question.  He did make sure that 
regular backups got made, as part of his incident response.

Kind of unsatisfying, from the security-guy perspective.

   -jml

Valdis Kletnieks <Valdis.Kletnieks () VT EDU> 2010-03-26 13:24 >>>
On Fri, 26 Mar 2010 13:34:17 EDT, Scott Sweren said:
- How did you get the authority to impose the sanctions?

Sometimes, the best sanctions are the ones somebody else imposes.

A number of years ago, we had a high-profile incident on campus, where
an ISP's DNS server got hacked and a website redirected to a hacked machine
on campus.  Of course, this meant that within 3 or 4 hours, the hard drive
of the on-campus machine ended up in an evidence bag. The machine had gotten
hacked because a professor had specifically told the grad student admin'ing
the machine not to waste time patching, and the box of course got pwned by
a hack that had a patch available.

So the professor goes to the department chair to get $$ to replace the
hard drive (which at that time was still a pretty sizable chunk of change).
The department chair told the professor "No, this was your screw-up, it's
coming out of your budget".

Randy's office was *swamped* with requests for awareness training for the
next few months.  Nobody else wanted to have that talk with their department
chair. :)
 

Current thread: