{"id":123403,"date":"2019-09-19T16:38:19","date_gmt":"2019-09-19T20:38:19","guid":{"rendered":"http:\/\/www.bu.edu\/tech\/?page_id=123403"},"modified":"2023-04-11T13:35:53","modified_gmt":"2023-04-11T17:35:53","slug":"ncsam-2018","status":"publish","type":"page","link":"https:\/\/www.bu.edu\/tech\/support\/information-security\/cam\/archives\/ncsam-2018\/","title":{"rendered":"NCSAM 2018"},"content":{"rendered":"<h2><span style=\"color: #0000ff;\">Information Security Awareness Month: October 2018<\/span><a href=\"\/tech\/files\/2017\/10\/ISAWday5.png\"aria-label=\"Web Accessibility Initiative\"><\/a><\/h2>\n<h2 aria-hidden=\"true\" style=\"text-align: center;\"><strong>Week 4: Securing Your Devices<\/strong><\/h2>\n<p><!-- This h2 is not included in the accessibility tree and therefore ignored by the rule --><br \/>\nIt is important these days to make sure that our devices are secure. Boston University has the<span>\u00a0<\/span><a href=\"http:\/\/www.bu.edu\/policies\/minimum-security-standards\/\">Minimum Security Standards<\/a><span>\u00a0<\/span>policy that defines the security requirements for devices that have University data on them. For personal devices that aren\u2019t used for University business, here are some tips to help protect them and your personal information.<\/p>\n<p><strong>Keep your computer and applications updated.<span>\u00a0<\/span><\/strong>Patches or updates help resolve security flaws that you might have on your system, protecting you from malicious attempts to compromise your system.\u00a0 Patches should be applied on a fairly regular basis at a time that\u2019s convenient for you.<\/p>\n<p><strong>Install antivirus software.<span>\u00a0<\/span><\/strong>You should install antivirus software on your personal devices.\u00a0 Antivirus isn\u2019t just for laptops!\u00a0 It should be installed on your desktop computers, tablets, and phones! Boston University provides McAfee for free<span>\u00a0<\/span><a href=\"https:\/\/www.bu.edu\/tech\/services\/cccs\/desktop\/software\/security\/macafee\/\">here<\/a>.<\/p>\n<p><strong>Enable Encryption on your device.<span>\u00a0<\/span><\/strong>Your devices should be encrypted using the built in encryption feature included in your phone or computer\u2019s operating system. For personal computers, On Mac there is<span>\u00a0<\/span><span><a href=\"https:\/\/support.apple.com\/en-us\/HT204837\" target=\"_blank\" rel=\"noopener noreferrer\">FileVault<i class=\"icon-external-link external\"><\/i><\/a><\/span><span>\u00a0<\/span>and Windows there is<span>\u00a0<\/span><span><a href=\"https:\/\/www.windowscentral.com\/how-use-bitlocker-encryption-windows-10\" target=\"_blank\" rel=\"noopener noreferrer\">Bitlocker<i class=\"icon-external-link external\"><\/i><\/a><\/span>.<\/p>\n<p><strong>Require a password when logging into your devices.<span>\u00a0<\/span><\/strong>It is always good to have a password required to login to your devices. If your device gets stolen and there isn\u2019t a login password, then the thief would have access to all of your data immediately.<\/p>\n<p><strong>Use a secure connection (often called a \u201cVPN\u201d) to connect to the network.<span>\u00a0<\/span><\/strong>Using a secure connection provides an encrypted tunnel for information to travel from your computer and throughout the internet. This is important when you are working remotely or using public WiFi hotspots where data can potentially be read by malicious individuals if it isn\u2019t encrypted.<\/p>\n<p><strong><div class=\"bu_collapsible_container \" aria-live=\"polite\" data-customize-animation=\"false\"><h3 class=\"bu_collapsible\" aria-expanded=\"false\"tabindex=\"0\" role=\"button\">Week 3: Know Your Data<\/h3><div class=\"bu_collapsible_section\" style=\"display: none;\"><\/strong><\/p>\n<p style=\"text-align: center;\"><img loading=\"lazy\" src=\"\/tech\/files\/2018\/10\/ISAMWeek3-636x429.jpg\" alt=\"\" width=\"636\" height=\"429\" class=\"alignnone size-medium wp-image-117134\" srcset=\"https:\/\/www.bu.edu\/tech\/files\/2018\/10\/ISAMWeek3-636x429.jpg 636w, https:\/\/www.bu.edu\/tech\/files\/2018\/10\/ISAMWeek3-768x517.jpg 768w, https:\/\/www.bu.edu\/tech\/files\/2018\/10\/ISAMWeek3.jpg 932w\" sizes=\"(max-width: 636px) 100vw, 636px\" \/><\/p>\n<p>At Boston University, our data can be classified into 4 groups:<\/p>\n<p><strong>Public Data: <\/strong>Data that is disclosed to anyone regardless of affiliation.\u00a0 Examples &#8211; The published BU Directory, public websites<\/p>\n<p><strong>Internal Data: <\/strong>information that is potentially sensitive and is not intended to be shared with the public.\u00a0 Examples &#8211; procedural documentation, memos, meeting minutes<\/p>\n<p><strong>Confidential Data: <\/strong>Information that, if made available to unauthorized parties, may adversely affect individuals or the business of Boston University. This classification also includes data that the University is required to keep confidential, either by law (e.g., FERPA) or under a confidentiality agreement with a third party.\u00a0 Examples \u2013 FERPA data, BUID, salary information<\/p>\n<p><strong>Restricted Use Data: <\/strong>Any information that BU has a contractual, legal, or regulatory obligation to safeguard in the most stringent manner. Examples \u2013 Passwords, Social Security numbers, Driver\u2019s License numbers, Credit Card numbers, Financial Account Information, and HIPAA data<\/p>\n<p>Details on how protect our data are spelling out in our Data Protection Standards.<\/p>\n<ul>\n<li><span> <\/span>You can read more about data types and classification <a href=\"http:\/\/www.bu.edu\/policies\/information-security-home\/data-protection-standards\/data-classification-policy\/\">here<\/a><\/li>\n<li>Once you know how to classify your data, you can read our guidelines on how to properly secure your data <a href=\"http:\/\/www.bu.edu\/policies\/information-security-home\/data-protection-standards\/data-protection-requirements\/\">here<\/a><\/li>\n<\/ul>\n<p>&nbsp;<\/p>\n<p>You should think of your own personal data the same way.\u00a0 It is important to know what data should and should not be made public online.\u00a0 Always be mindful of what you consider your most sensitive data (social security number, banking info, passwords etc) and make sure you take extra precautions to secure this information.<\/p>\n<p>Information that is most critical to you (your own confidential and restricted use data) should never be shared online publicly. Always keep your passwords private, and treat answers to your security questions the same. Always consider the information you\u2019re sharing online, including family and other personal information, as it can potentially be accessed by anyone to try to gain unauthorized access to your accounts.<\/p>\n<p><strong><\/div>\n<\/div>\n<\/strong><\/p>\n<p><strong><div class=\"bu_collapsible_container \" aria-live=\"polite\" data-customize-animation=\"false\"><h3 class=\"bu_collapsible\" aria-expanded=\"false\"tabindex=\"0\" role=\"button\">Week 2: How to Avoid Being Phished<\/h3><div class=\"bu_collapsible_section\" style=\"display: none;\"><\/strong><\/p>\n<p>Good morning! Welcome to Week 2 of Information Security Awareness Month! Don&#8217;t miss the cybersecurity-related events on campus this week. In addition to hosting our\u00a0<a href=\"https:\/\/www.bu.edu\/tech\/2018\/09\/27\/bu-information-security-shredding-event-october-9-11-2018\/\">three shredding events<\/a>, the\u00a0<a href=\"https:\/\/www.bu.edu\/tech\/about\/fair\/\">IS&amp;T Tech Fair<\/a>, themed &#8220;Secure Your Digital Life&#8221;, takes place on Wednesday October 10th at the GSU.<\/p>\n<p>Our tip for the week is how to avoid being phished.<\/p>\n<p>A common tactic of cyber criminals is to send very legitimate looking emails that will request you to provide your personal information. These emails are &#8220;phishing&#8221; you to see if you will provide it. If you do reply to one of these messages and provide your password, you have given the sender access to sensitive information about yourself and enabled them to use your account for a variety of illicit purposes. Some phishing messages are very clever and even the sharpest eye may fall for one.\u00a0If you think you may have responded to a phishing message, or that your account has been compromised in any way, \u00a0the most important thing is to\u00a0<strong>immediately change your password<\/strong>\u00a0and contact the Incident Response Team at\u00a0<a href=\"mailto:irt@bu.edu\">irt@bu.edu<\/a>. They will help determine if your account has been used by someone else and follow-up with any appropriate actions as needed.<\/p>\n<p>For more detailed information on spoofed messages and phishing schemes, please see\u00a0<a href=\"https:\/\/www.bu.edu\/tech\/services\/comm\/email\/unwanted-email\/how-to-fight-phishing\/\">https:\/\/www.bu.edu\/tech\/services\/comm\/email\/unwanted-email\/how-to-fight-phishing\/<\/a><\/p>\n<p><strong><\/div>\n<\/div>\n<\/strong><\/p>\n<p><strong><div class=\"bu_collapsible_container \" aria-live=\"polite\" data-customize-animation=\"false\"><h3 class=\"bu_collapsible\" aria-expanded=\"false\"tabindex=\"0\" role=\"button\">Week 1: Welcome to Information Security Awareness Month!<\/h3><div class=\"bu_collapsible_section\" style=\"display: none;\"><\/strong><\/p>\n<p><img loading=\"lazy\" src=\"\/tech\/files\/2017\/10\/ISAWday1-636x422.jpg\" alt=\"ISAW1\" width=\"636\" height=\"422\" class=\"alignnone size-medium wp-image-110393 aligncenter\" srcset=\"https:\/\/www.bu.edu\/tech\/files\/2017\/10\/ISAWday1-636x422.jpg 636w, https:\/\/www.bu.edu\/tech\/files\/2017\/10\/ISAWday1-768x510.jpg 768w, https:\/\/www.bu.edu\/tech\/files\/2017\/10\/ISAWday1-1024x680.jpg 1024w, https:\/\/www.bu.edu\/tech\/files\/2017\/10\/ISAWday1.jpg 1701w\" sizes=\"(max-width: 636px) 100vw, 636px\" \/><\/p>\n<h2 style=\"text-align: center;\"><strong>Welcome to Information Security Awareness Month!<\/strong><\/h2>\n<p>Every year Information Services &amp; Technology dedicates time to focus on Information Security in alignment with<span>\u00a0<\/span><span><a href=\"https:\/\/www.dhs.gov\/national-cyber-security-awareness-month\">National Cyber Security Awareness Month<\/a><\/span>.\u00a0We would like to take this opportunity to remind you of some basic computer security good habits to practice, including keeping your devices secure.<\/p>\n<p>If you\u2019ve listened to the news recently you may have heard of the <span><a href=\"https:\/\/www.nytimes.com\/2018\/09\/28\/technology\/facebook-hack-data-breach.html\">breach<\/a><\/span> of over 50 million accounts at Facebook. Similar breaches have occurred over the past several years at Equifax, LinkedIn, Yahoo and more. If you\u2019re using the same password for Facebook as your other online accounts (including your BU Login), it might be time to change them as a precaution! If you use the same password on multiple sites the risk is even higher!<\/p>\n<p>Would you like to know if your username was included in one of the reported breaches? There are websites available to help you determine if your account was included in any known breaches, such as:<span>\u00a0<\/span><span><a href=\"https:\/\/haveibeenpwned.com\/\">https:\/\/haveibeenpwned.com\/<\/a><\/span><u><br \/>\n<\/u>(<em>note \u2013 the Facebook breach is very recent.\u00a0 Affected accounts from that specific breach may not yet be available<\/em>)<\/p>\n<p>If you find that your BU account has been compromised, we recommend you<span>\u00a0<\/span><span><a href=\"https:\/\/www.bu.edu\/tech\/contact\/\">report it<\/a><\/span><span>\u00a0<\/span>to the Incident Response Team and<span>\u00a0<\/span><span><a href=\"https:\/\/www.bu.edu\/tech\/services\/support\/iam\/authentication\/kerberos\/kerberos\/reset\/\">change your BU account password<\/a><\/span><span>\u00a0<\/span>immediately.<\/p>\n<p><strong><\/div>\n<\/div>\n<\/strong><\/p>\n<p>&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Information Security Awareness Month: October 2018 Week 4: Securing Your Devices It is important these days to make sure that our devices are secure. Boston University has the\u00a0Minimum Security Standards\u00a0policy that defines the security requirements for devices that have University data on them. For personal devices that aren\u2019t used for University business, here are some&#8230;<\/p>\n","protected":false},"author":4352,"featured_media":0,"parent":110387,"menu_order":6,"comment_status":"closed","ping_status":"closed","template":"","meta":[],"_links":{"self":[{"href":"https:\/\/www.bu.edu\/tech\/wp-json\/wp\/v2\/pages\/123403"}],"collection":[{"href":"https:\/\/www.bu.edu\/tech\/wp-json\/wp\/v2\/pages"}],"about":[{"href":"https:\/\/www.bu.edu\/tech\/wp-json\/wp\/v2\/types\/page"}],"author":[{"embeddable":true,"href":"https:\/\/www.bu.edu\/tech\/wp-json\/wp\/v2\/users\/4352"}],"replies":[{"embeddable":true,"href":"https:\/\/www.bu.edu\/tech\/wp-json\/wp\/v2\/comments?post=123403"}],"version-history":[{"count":6,"href":"https:\/\/www.bu.edu\/tech\/wp-json\/wp\/v2\/pages\/123403\/revisions"}],"predecessor-version":[{"id":144986,"href":"https:\/\/www.bu.edu\/tech\/wp-json\/wp\/v2\/pages\/123403\/revisions\/144986"}],"up":[{"embeddable":true,"href":"https:\/\/www.bu.edu\/tech\/wp-json\/wp\/v2\/pages\/110387"}],"wp:attachment":[{"href":"https:\/\/www.bu.edu\/tech\/wp-json\/wp\/v2\/media?parent=123403"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}