{"id":104,"date":"2021-09-07T12:39:15","date_gmt":"2021-09-07T16:39:15","guid":{"rendered":"https:\/\/www.bu.edu\/techplan\/?page_id=104"},"modified":"2024-05-29T16:37:01","modified_gmt":"2024-05-29T20:37:01","slug":"cybersecurity","status":"publish","type":"page","link":"https:\/\/www.bu.edu\/techplan\/priorities\/cybersecurity\/","title":{"rendered":"Maintain Cybersecurity Vigilance"},"content":{"rendered":"<p>&nbsp;<\/p>\n<p><a href=\"\/techplan\/files\/2021\/05\/cybersecurity.png\"><img loading=\"lazy\" src=\"\/techplan\/files\/2021\/05\/cybersecurity-150x150.png\" alt=\"\" width=\"150\" height=\"150\" class=\"alignleft wp-image-84 size-thumbnail\" srcset=\"https:\/\/www.bu.edu\/techplan\/files\/2021\/05\/cybersecurity-150x150.png 150w, https:\/\/www.bu.edu\/techplan\/files\/2021\/05\/cybersecurity-100x100.png 100w\" sizes=\"(max-width: 150px) 100vw, 150px\" \/><\/a>We will continue to enhance our cybersecurity processes and technologies, in line with best practices and the evolving threat landscape, to protect the confidentiality, availability and integrity of university digital services and information.<\/p>\n<h2><br style=\"clear: both;\" \/>Scope<\/h2>\n<hr style=\"height: 10px; border-width: 0; color: #11d76b; background-color: #11d76b;\" \/>\n<p>We will focus on two areas: Adopting tooling and awareness to address perennial issues like phishing and emerging threats like extortion via ransomware; and Improving the Identity and Access Management experience through adoption of new technologies to ease identity administration and support individual control over identity attributes.<\/p>\n<h2>Major Projects<\/h2>\n<hr style=\"height: 10px; border-width: 0; color: #11d76b; background-color: #11d76b;\" \/>\n<h3>Tooling and Awareness<\/h3>\n<ul>\n<li><b>Data Center Firewalls, Phase 1 &#8211; <\/b><span id=\"active\">Active<\/span><br \/>\nInstall Palo Alto Networks Firewalls in front of our IS&amp;T data centers.<\/li>\n<li><b>Data Center Firewalls, Phase 2 &#8211; <\/b><span id=\"identified\">Identified<\/span><br \/>\nInstall Palo Alto Networks Firewalls in front of BUMC data centers and administrative systems at MGHPCC.<\/li>\n<li><b>Domain Name Service (DNS) Security &#8211; <\/b><span id=\"complete\">Complete<\/span><br \/>\nProvide security controls at a low level of the network that can effectively thwart malware including ransomware with minimal impact on normal usage.<\/li>\n<li><b>Email Security Improvements &#8211; <\/b><span id=\"active\">Active<\/span><br \/>\nDeploy additional industry-standard security controls (DKIM\/DMARC) in the BU email environment that reduce the risk of receiving or being the source of phishing attacks and other fraudulent email on the internet and decrease the number of legitimate outgoing emails that are discarded as spam by remote mail systems.<\/li>\n<li><b>Entity Analytics &#8211; <\/b><span id=\"complete\">Complete<\/span><br \/>\nProvide analytical toolkit for our Security Event and Incident Management tool to detect new and anomalous behavior of devices on our network to enable better detection of compromised devices, especially \u201cInternet of Things\u201d devices.<\/li>\n<li><b>Expand Multifactor Authentication &#8211; <\/b><span id=\"complete\">Complete<\/span><br \/>\nContinuing from FY21, this effort will increase the number of places that multifactor authentication will be required including Office365, VPN services, and additional web applications.<\/li>\n<li><b>Integrate Vulnerability Management into <\/b><b>ServiceNow<\/b><b> &#8211; <\/b><span id=\"complete\">Complete<\/span><br \/>\nIntegrate the results of our vulnerability scanner directly into our IT service management system to enable enhanced reporting and better risk assessment.<\/li>\n<li><b>Third Party Risk Management Tooling &#8211; <\/b><span id=\"complete\">Complete<\/span><br \/>\nEvaluate tools and services to measure, track, and manage the risk of vendors with access to our sensitive data.<\/li>\n<\/ul>\n<h3>Improving the Identity and Access Management experience<\/h3>\n<ul>\n<li><b>Authorization Management &#8211; <\/b><span id=\"active\">Active<\/span><br \/>\nProvide enhanced group management capabilities, potentially including self-service, to enable efficient use of centrally-stored attributes to define access control for applications.<\/li>\n<li><b>Identity and Directory Modernization &#8211; <\/b><span id=\"complete\">Complete<\/span><br \/>\nReplaces our legacy, homegrown, mainframe-based identity system with vended, cloud-based identity solution<\/li>\n<li><b>Identity Governance and Administration &#8211; <\/b><span id=\"identified\">Identified<\/span><br \/>\nProvides an enhanced toolset for leaders, managers, data trustees, auditors, and individuals to review, request, authorize, and revoke privileges for individuals.<\/li>\n<li><b>Student Lifecycle Provisioning and Deprovisioning &#8211; <\/b><span id=\"complete\">Complete<\/span><br \/>\nStandardizes the processes by which student accounts are created and given access rights and manages how those rights evolve based on student status. This also includes a self-service portal to enable password reset and update of gender identity, pronouns, and preferred name.<\/li>\n<li><b>Campus Solutions Integration &#8211; <\/b><span id=\"complete\">Complete<\/span><br \/>\nIntegrates our IAM solution with the new Student Information System and addresses authorization of individuals within Campus Solutions for role-based and ad-hoc needs.<\/li>\n<\/ul>\n<h2>Stakeholders<\/h2>\n<hr style=\"height: 10px; border-width: 0; color: #11d76b; background-color: #11d76b;\" \/>\n<ul><\/ul>\n<ul><\/ul>\n<ul>\n<li>Strong cybersecurity practices will require everyone\u2019s participation and will benefit everyone as our data will be better protected. The Common Services and Information Security Governance Committee helps to govern the information security program and becomes the voice for everyone in the program, providing input on priorities, organizational change management, and communication efforts.<\/li>\n<li>The IAM program will bring particular benefits to non-binary individuals through support for gender fluidity, personal pronouns, and preferred name. The IAM Steering Committee will help guide the introduction of these and other features and includes representation from key identity providers: Enrollment Services, Human Resources, and Alumni Relations.<\/li>\n<li>The mission to secure the university\u2019s data both provides input to and takes guidance from IS&amp;T\u2019s Data Governance program on data management policy, roles and responsibilities, and needed controls. Increasingly this work will need to align with the University Privacy Coordinating Committee, particularly as legal regulations on data privacy grow.<\/li>\n<\/ul>\n","protected":false},"excerpt":{"rendered":"<p>&nbsp; We will continue to enhance our cybersecurity processes and technologies, in line with best practices and the evolving threat landscape, to protect the confidentiality, availability and integrity of university digital services and information. Scope We will focus on two areas: Adopting tooling and awareness to address perennial issues like phishing and emerging threats like [&hellip;]<\/p>\n","protected":false},"author":1301,"featured_media":0,"parent":23,"menu_order":6,"comment_status":"closed","ping_status":"closed","template":"","meta":[],"_links":{"self":[{"href":"https:\/\/www.bu.edu\/techplan\/wp-json\/wp\/v2\/pages\/104"}],"collection":[{"href":"https:\/\/www.bu.edu\/techplan\/wp-json\/wp\/v2\/pages"}],"about":[{"href":"https:\/\/www.bu.edu\/techplan\/wp-json\/wp\/v2\/types\/page"}],"author":[{"embeddable":true,"href":"https:\/\/www.bu.edu\/techplan\/wp-json\/wp\/v2\/users\/1301"}],"replies":[{"embeddable":true,"href":"https:\/\/www.bu.edu\/techplan\/wp-json\/wp\/v2\/comments?post=104"}],"version-history":[{"count":51,"href":"https:\/\/www.bu.edu\/techplan\/wp-json\/wp\/v2\/pages\/104\/revisions"}],"predecessor-version":[{"id":435,"href":"https:\/\/www.bu.edu\/techplan\/wp-json\/wp\/v2\/pages\/104\/revisions\/435"}],"up":[{"embeddable":true,"href":"https:\/\/www.bu.edu\/techplan\/wp-json\/wp\/v2\/pages\/23"}],"wp:attachment":[{"href":"https:\/\/www.bu.edu\/techplan\/wp-json\/wp\/v2\/media?parent=104"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}