{"id":159161,"date":"2025-08-13T09:54:11","date_gmt":"2025-08-13T13:54:11","guid":{"rendered":"https:\/\/www.bu.edu\/tech\/?page_id=159161"},"modified":"2025-08-13T16:18:38","modified_gmt":"2025-08-13T20:18:38","slug":"2025-2","status":"publish","type":"page","link":"https:\/\/www.bu.edu\/tech\/services\/security\/education\/camp\/archives\/2025-2\/","title":{"rendered":"2025"},"content":{"rendered":"<h1 aria-hidden=\"true\"><strong><span>Privileged Access Management (PAM): moving from Project to Program<\/span><\/strong><\/h1>\n<p><strong><span data-ogsc=\"black\">Jon Rice, Ian Altgilbers, Petar Ivanov, Galen Lipin, Tufts University<\/span><\/strong><\/p>\n<p><strong><div class=\"bu_collapsible_container \" aria-live=\"polite\" data-customize-animation=\"false\"><h3 class=\"bu_collapsible\" aria-expanded=\"false\"tabindex=\"0\" role=\"button\">Slide Deck<\/h3><div class=\"bu_collapsible_section\" style=\"display: none;\"><\/strong><\/p>\n<p><a href=\"\/tech\/files\/2025\/08\/Jon-Rice_PAM_Program_BU_Final.pptx\">Privileged Access Management (PAM): moving from Project to Program<\/a><\/p>\n<p><strong><\/div>\n<\/div>\n<\/strong><\/p>\n<p><strong><div class=\"bu_collapsible_container \" aria-live=\"polite\" data-customize-animation=\"false\"><h3 class=\"bu_collapsible\" aria-expanded=\"false\"tabindex=\"0\" role=\"button\"><em>About the talk<\/em><\/h3><div class=\"bu_collapsible_section\" style=\"display: none;\"><\/strong><\/p>\n<p><span>This group presentation will provide an overview of ongoing efforts to integrate PAM principles, practices, and technologies at Tufts. We will review key milestones, current initiatives, and upcoming steps in the transition from a project-based approach to a broader, programmatic strategy. Along the way, we will highlight the challenges encountered and lessons learned.<\/span><\/p>\n<p><strong><\/div>\n<\/div>\n<\/strong><\/p>\n<h1 aria-hidden=\"true\"><strong><span>Harvard\u2019s approach to risk based vulnerability management<\/span><\/strong><\/h1>\n<p><strong><span data-ogsc=\"black\">Todd Connetta &amp; John Sorel, Harvard University<\/span><\/strong><\/p>\n<p><strong><div class=\"bu_collapsible_container \" aria-live=\"polite\" data-customize-animation=\"false\"><h3 class=\"bu_collapsible\" aria-expanded=\"false\"tabindex=\"0\" role=\"button\"><em>Slide Deck and musical track<\/em><\/h3><div class=\"bu_collapsible_section\" style=\"display: none;\"><\/strong><\/p>\n<p><a href=\"\/tech\/files\/2025\/08\/John-Sorel-and-Todd-Connetta_v2-Transforming-Vulnerability-Management-BU-Security-Camp-6-Aug.pdf\">Harvard\u2019s approach to risk based vulnerability management<\/a><\/p>\n<!--[if lt IE 9]><script>document.createElement('audio');<\/script><![endif]-->\n<audio class=\"wp-audio-shortcode\" id=\"audio-159161-1\" preload=\"none\" style=\"width: 100%;\" controls=\"controls\"><source type=\"audio\/mpeg\" src=\"\/tech\/files\/2025\/08\/RBVM-Rap.mp3?_=1\" \/><a href=\"\/tech\/files\/2025\/08\/RBVM-Rap.mp3\">\/tech\/files\/2025\/08\/RBVM-Rap.mp3<\/a><\/audio>\n<p><strong><\/div>\n<\/div>\n<\/strong><\/p>\n<p><strong><div class=\"bu_collapsible_container \" aria-live=\"polite\" data-customize-animation=\"false\"><h3 class=\"bu_collapsible\" aria-expanded=\"false\"tabindex=\"0\" role=\"button\"><em>About the talk<\/em><\/h3><div class=\"bu_collapsible_section\" style=\"display: none;\"><\/strong><\/p>\n<p><span>In 2023,\u00a0<\/span><span data-markjs=\"true\" class=\"outlook-search-highlight\">Harvard<\/span><span>\u00a0embarked on a three-year initiative\u00a0<\/span><span data-markjs=\"true\" class=\"outlook-search-highlight\">to<\/span><span>\u00a0modernize its\u00a0<\/span><span data-markjs=\"true\" class=\"outlook-search-highlight\">vulnerability<\/span><span>\u00a0<\/span><span data-markjs=\"true\" class=\"outlook-search-highlight\">management<\/span><span>\u00a0<\/span><span data-markjs=\"true\" class=\"outlook-search-highlight\">approach<\/span><span>. The effort centered on shifting from a high-volume, resource-intensive model\u00a0<\/span><span data-markjs=\"true\" class=\"outlook-search-highlight\">to<\/span><span>\u00a0a\u00a0<\/span><span data-markjs=\"true\" class=\"outlook-search-highlight\">risk<\/span><span>&#8211;<\/span><span data-markjs=\"true\" class=\"outlook-search-highlight\">based<\/span><span>\u00a0strategy. The program positions the university\u00a0<\/span><span data-markjs=\"true\" class=\"outlook-search-highlight\">to<\/span><span>\u00a0prioritize vulnerabilities\u00a0<\/span><span data-markjs=\"true\" class=\"outlook-search-highlight\">based<\/span><span>\u00a0on standard\u00a0<\/span><span data-markjs=\"true\" class=\"outlook-search-highlight\">risk<\/span><span>\u00a0fac<\/span><span data-markjs=\"true\" class=\"outlook-search-highlight\">to<\/span><span>rs, ensuring more efficient resource allocation. The transformation represented a cultural change as much as it did a technology challenge. A dedicated, university-wide program team has carefully aligned key stakeholders and leadership behind new\u00a0<\/span><span data-markjs=\"true\" class=\"outlook-search-highlight\">approach<\/span><span>\u00a0and now midway through the program\u2019s implementation, the first set of schools and units are adopting this new way of life. The team will first present our problem, balancing increasing demands of\u00a0<\/span><span data-markjs=\"true\" class=\"outlook-search-highlight\">vulnerability<\/span><span>\u00a0and exposure\u00a0<\/span><span data-markjs=\"true\" class=\"outlook-search-highlight\">management<\/span><span>\u00a0amid a constantly evolving threat landscape with the pressures of\u00a0<\/span><span data-markjs=\"true\" class=\"outlook-search-highlight\">to<\/span><span>day\u2019s funding environment and the scarcity of resources. Next, the team will present a brief his<\/span><span data-markjs=\"true\" class=\"outlook-search-highlight\">to<\/span><span>ry of the solution\u2019s design, build, and implementation before opening a demonstration of the technology. The demonstration will simultaneously communicate how the solution works and the solution\u2019s scaled impact across the university. This portion of the presentation will underscore the importance of managing\u00a0<\/span><span data-markjs=\"true\" class=\"outlook-search-highlight\">risk<\/span><span>s over lists and clearly communicate a path\u00a0<\/span><span data-markjs=\"true\" class=\"outlook-search-highlight\">to<\/span><span>\u00a0building that capability. Finally, we will conclude the session with a focus on lessons learned and a summary of key organizational change\u00a0<\/span><span data-markjs=\"true\" class=\"outlook-search-highlight\">management<span>\u00a0<\/span><\/span><span>activities.<\/span><\/p>\n<p><strong><\/div>\n<\/div>\n<\/strong><\/p>\n<h1 aria-hidden=\"true\"><strong><span>Outsmarting Our Future Selves: Boston College Information Technology Services and the Journey to an Enterprise Password Manager<\/span><\/strong><\/h1>\n<p><strong><span data-ogsc=\"black\">Tiffany Bradford, Boston College<\/span><\/strong><\/p>\n<p><strong><div class=\"bu_collapsible_container \" aria-live=\"polite\" data-customize-animation=\"false\"><h3 class=\"bu_collapsible\" aria-expanded=\"false\"tabindex=\"0\" role=\"button\"><em>Slide Deck<\/em><\/h3><div class=\"bu_collapsible_section\" style=\"display: none;\"><\/strong><\/p>\n<p><a href=\"\/tech\/files\/2025\/08\/Tiffany-Bradford_2025-BU-Security-Camp-1Password.pptx\">Outsmarting Our Future Selves: Boston College Information Technology Services and the Journey to an Enterprise Password Manager<\/a><\/p>\n<p><strong><\/div>\n<\/div>\n<\/strong><\/p>\n<p><strong><div class=\"bu_collapsible_container \" aria-live=\"polite\" data-customize-animation=\"false\"><h3 class=\"bu_collapsible\" aria-expanded=\"false\"tabindex=\"0\" role=\"button\"><em>About the talk<\/em><\/h3><div class=\"bu_collapsible_section\" style=\"display: none;\"><\/strong><\/p>\n<p><span>Passwords, passkeys, API credentials, and SSH keys are more than just tech buzzwords \u2013 they&#8217;re daily realities. Join us as we discuss the journey of Boston College\u00a0<\/span><span>Information Technology Services<\/span><span>\u00a0(ITS) fr<\/span><span>om merely the idea of an enterprise password manager to the rollout of a full fledged solution for the department. We will begin with why we chose to procure this type of tool, what should be considered when choosing a vendor for your\u00a0own environment, then move to a lessons learned section, and finish with next steps for our use of the product. We hope this talk provides listeners with a\u00a0forum for those who struggle with credential management but don&#8217;t yet have a clear business case for an enterprise password manager, and a place for those who are using an enterprise password manager to think about what&#8217;s next for their own tool.<\/span><\/p>\n<p><strong><\/div>\n<\/div>\n<\/strong><\/p>\n<p><strong><div class=\"bu_collapsible_container \" aria-live=\"polite\" data-customize-animation=\"false\"><h3 class=\"bu_collapsible\" aria-expanded=\"false\"tabindex=\"0\" role=\"button\"><em>About the speaker<\/em><\/h3><div class=\"bu_collapsible_section\" style=\"display: none;\"><\/strong><\/p>\n<div class=\"gmail_default\"><span>Tiffany Bradford has been working at Boston College for 8 years and has been using a password manager for 6 of those years. She loves collaborating with others and working through difficult problems. When not at work, she and her better half Jordan can be found spending time with their &#8220;Cybersecurity Dog&#8221;, Kodi, and watching trash TV.\u00a0<\/span><\/div>\n<p><strong><\/div>\n<\/div>\n<\/strong><\/p>\n<blockquote><\/blockquote>\n<h1 aria-hidden=\"true\"><strong><span>Incident Response Tabletop Exercises: They&#8217;re not just a game<\/span><\/strong><\/h1>\n<p><strong><span data-ogsc=\"black\">Shane Albright, REN-ISAC<\/span><\/strong><\/p>\n<p><span><strong><div class=\"bu_collapsible_container \" aria-live=\"polite\" data-customize-animation=\"false\"><h3 class=\"bu_collapsible\" aria-expanded=\"false\"tabindex=\"0\" role=\"button\"><em>Slide Deck<\/em><\/h3><div class=\"bu_collapsible_section\" style=\"display: none;\"><\/strong><\/span><\/p>\n<p><a href=\"\/tech\/files\/2025\/08\/Shane-Albright_Incident-Response-Tabletop-Exercises.pdf\">Incident Response Tabletop Exercises: They&#8217;re not just a game.<\/a><\/p>\n<p><strong><\/div>\n<\/div>\n<\/strong><\/p>\n<p><span><strong><div class=\"bu_collapsible_container \" aria-live=\"polite\" data-customize-animation=\"false\"><h3 class=\"bu_collapsible\" aria-expanded=\"false\"tabindex=\"0\" role=\"button\"><em>About the talk<\/em><\/h3><div class=\"bu_collapsible_section\" style=\"display: none;\"><\/strong><\/span><\/p>\n<p>Incident response tabletop exercises are an efficient and effective way to test your organization&#8217;s incident response plan. They provide a low-stakes opportunity for your staff to learn to respond to incidents in your environment and identify areas of improvement in your incident response process. Tabletop exercises also help highlight the need for collaboration among various roles and teams during an incident. Attendees will learn the fundamentals of planning and facilitating an incident response tabletop exercise with the goal of increasing their organization&#8217;s resilience to information security risk. A small portion of this session (&lt;5 minutes) will be dedicated to discussing the value of REN-ISAC&#8217;s Information Security Assessment and Advisory Services&#8217; tabletop exercise offerings.<\/p>\n<p><strong><\/div>\n<\/div>\n<\/strong><\/p>\n<p><span><strong><div class=\"bu_collapsible_container \" aria-live=\"polite\" data-customize-animation=\"false\"><h3 class=\"bu_collapsible\" aria-expanded=\"false\"tabindex=\"0\" role=\"button\"><em>About the speaker<\/em><\/h3><div class=\"bu_collapsible_section\" style=\"display: none;\"><\/strong><\/span><\/p>\n<p style=\"font-weight: 400;\"><span data-markjs=\"true\" class=\"outlook-search-highlight\">Shane<\/span><span>\u00a0<\/span><span data-markjs=\"true\" class=\"outlook-search-highlight\">Albright<\/span><span>\u00a0began his career as an IT Support Center computer consultant at Indiana University twenty years ago. After a few years working as an infrastructure specialist in enterprise IT for a software company, he returned to IU as a senior system administrator at the Student Health Center where, for over a decade, he was a leader in the management and security of IT infrastructure and services and the protection of electronic protected health information (ePHI).\u00a0<\/span><span data-markjs=\"true\" class=\"outlook-search-highlight\">Shane<\/span><span>joined the\u00a0<\/span><span data-markjs=\"true\" class=\"outlook-search-highlight\">REN-ISAC<\/span><span>\u00a0in 2021 as a principal security engineer. For the last year and a half, he\u2019s facilitated\u00a0<\/span><span data-markjs=\"true\" class=\"outlook-search-highlight\">REN-ISAC<\/span><span>&#8216;s Information Security Assessment and Advisory Services&#8217; tabletop exercises.<\/span><\/p>\n<p><strong><\/div>\n<\/div>\n<\/strong><\/p>\n<h1 aria-hidden=\"true\"><strong><b>Tool Time<\/b><\/strong><\/h1>\n<p><strong><span data-ogsc=\"black\">Alexan Mardigian, Brian Gerdon, Mallory Ren, Boston University\u00a0<\/span><\/strong><\/p>\n<p><span><strong><div class=\"bu_collapsible_container \" aria-live=\"polite\" data-customize-animation=\"false\"><h3 class=\"bu_collapsible\" aria-expanded=\"false\"tabindex=\"0\" role=\"button\"><em>Slide Decks<\/em><\/h3><div class=\"bu_collapsible_section\" style=\"display: none;\"><\/strong><\/span><\/p>\n<p><a href=\"\/tech\/files\/2025\/08\/Alexan-M-BU-Security-Camp-GitLeaks.pptx\">GitLeaks<\/a><\/p>\n<p><a href=\"\/tech\/files\/2025\/08\/Brian-Gerdon-Security-Camp-2025-Tool-Talk-DuoHunter.pdf\">Duo Hunter<\/a><\/p>\n<p><a href=\"\/tech\/files\/2025\/08\/renm-bu-security-camp-2025.pdf\">Linux Server Secrets Management with Systemd, Python, and Hashicorp Vault<\/a><\/p>\n<p><strong><\/div>\n<\/div>\n<\/strong><\/p>\n<p><span><strong><div class=\"bu_collapsible_container \" aria-live=\"polite\" data-customize-animation=\"false\"><h3 class=\"bu_collapsible\" aria-expanded=\"false\"tabindex=\"0\" role=\"button\"><em>About the talks<\/em><\/h3><div class=\"bu_collapsible_section\" style=\"display: none;\"><\/strong><\/span><\/p>\n<div class=\"elementToProof\" data-ogsc=\"rgb(0, 0, 0)\">\n<p>Boston University&#8217;s Information Security team has successfully implemented<span>\u00a0<\/span><strong>GitLeak<\/strong>s as a pre-commit hook to prevent credential exposure across their codebase.This presentation will demonstrate practical deployment strategies, share lessons learned from implementation, and provide actionable insights for integrating<span>\u00a0<\/span><strong>GitLeaks<\/strong><span>\u00a0<\/span>into development workflows.<\/p>\n<p><strong>Duo Hunter<\/strong><span>\u00a0<\/span>is a custom tool built to help the BU SOC identify compromised accounts and pivot for additional hunting.<\/p>\n<p><span>BU Infrastructure is in early deployment of\u00a0<strong>Linux Server Secrets Management with Systemd, Python, and Hashicorp Vault<\/strong>\u00a0to address a core modernization need. This presentation will summarize the implementation, illustrating the importance of agreeing to well-defined interfaces and the necessity of starting from daily user experience to gain adoption.<\/span><\/p>\n<\/div>\n<p><strong><\/div>\n<\/div>\n<\/strong><\/p>\n<p><span data-markjs=\"true\" class=\"outlook-search-highlight\"><span><strong><div class=\"bu_collapsible_container \" aria-live=\"polite\" data-customize-animation=\"false\"><h3 class=\"bu_collapsible\" aria-expanded=\"false\"tabindex=\"0\" role=\"button\">About the speakers<\/h3><div class=\"bu_collapsible_section\" style=\"display: none;\"><\/strong><\/span><\/span><\/p>\n<p><strong><span data-markjs=\"true\" class=\"outlook-search-highlight\">Alexan Mardigian<\/span><\/strong><span>\u00a0is a CISSP-certified Information Security Engineer at Boston University, where he has served since March 2020 developing and maintaining custom security tools. \u00a0His experience spans developing hardware emulators for the U.S. Air Force, building secure web solutions for diverse clients, security architecture, and creating AI-powered security tools.\u00a0 He is also dedicated to making cybersecurity accessible and understandable, bridging the gap between technical expertise and clear communication.\u00a0 He is currently pursuing his masters degree in computer science, with a focus in cyber security.\u00a0 Outside of his duties at Boston University, he is an avid DJ of electronic music and scuba diver.<\/span><\/p>\n<p><strong>Brian Gerdon<\/strong><span>\u00a0<\/span>is a Security Analyst in the SOC at Boston University. Over the past 20 years, Brian has held a variety of roles at BU, including Desktop Support, Network Engineering and Operations, and now Information Security. His primary focus areas are Digital Forensics, Incident Response, and managing the university\u2019s Firewall Services.<\/p>\n<p><span><strong>Mallory Ren<\/strong>\u00a0is a Linux Systems Administrator at Boston University. She has been working with Linux, configuration management, and infrastructure for the last ten years and is interested in solving for quality and scale at organizations both big and small.<\/span><\/p>\n<p><strong><\/div>\n<\/div>\n<\/strong><\/p>\n<h1 aria-hidden=\"true\"><strong><b>Additional camp links: <\/b><\/strong><\/h1>\n<p style=\"font-weight: 400;\"><a href=\"https:\/\/www.youtube.com\/embed\/Cb8b1RMX6XY\">Warriors of the Net Trailer<\/a><\/p>\n<p style=\"font-weight: 400;\"><a href=\"http:\/\/web.archive.org\/web\/20110610202255\/http:\/\/ftp.sunet.se\/pub\/tv%2Bmovies\/warriors\/warriors-700-VBR.mpg\">Warriors of the Net Movie<\/a><\/p>\n<p style=\"font-weight: 400;\"><a href=\"https:\/\/www.amazon.com\/My-First-Cyber-Toolbox-Friendly\/dp\/B0FDY792V8\">My First Cyber Toolbox: A Fun and Friendly Guide to Internet Safety for Kids<\/a> (link to order)<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Privileged Access Management (PAM): moving from Project to Program Jon Rice, Ian Altgilbers, Petar Ivanov, Galen Lipin, Tufts University Harvard\u2019s approach to risk based vulnerability management Todd Connetta &amp; John Sorel, Harvard University Outsmarting Our Future Selves: Boston College Information Technology Services and the Journey to an Enterprise Password Manager Tiffany Bradford, Boston College Incident&#8230;<\/p>\n","protected":false},"author":4352,"featured_media":0,"parent":18974,"menu_order":1,"comment_status":"closed","ping_status":"closed","template":"","meta":[],"_links":{"self":[{"href":"https:\/\/www.bu.edu\/tech\/wp-json\/wp\/v2\/pages\/159161"}],"collection":[{"href":"https:\/\/www.bu.edu\/tech\/wp-json\/wp\/v2\/pages"}],"about":[{"href":"https:\/\/www.bu.edu\/tech\/wp-json\/wp\/v2\/types\/page"}],"author":[{"embeddable":true,"href":"https:\/\/www.bu.edu\/tech\/wp-json\/wp\/v2\/users\/4352"}],"replies":[{"embeddable":true,"href":"https:\/\/www.bu.edu\/tech\/wp-json\/wp\/v2\/comments?post=159161"}],"version-history":[{"count":11,"href":"https:\/\/www.bu.edu\/tech\/wp-json\/wp\/v2\/pages\/159161\/revisions"}],"predecessor-version":[{"id":159190,"href":"https:\/\/www.bu.edu\/tech\/wp-json\/wp\/v2\/pages\/159161\/revisions\/159190"}],"up":[{"embeddable":true,"href":"https:\/\/www.bu.edu\/tech\/wp-json\/wp\/v2\/pages\/18974"}],"wp:attachment":[{"href":"https:\/\/www.bu.edu\/tech\/wp-json\/wp\/v2\/media?parent=159161"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}