In Depth
Crash Course: Information Security at Universities
How do universities cope each fall when students stream back to campus with infected, unpatched PCs? CISOs say it's (almost) all about the education.
By Tracy Mayor
"From the standpoint of the students in the dorms, we're like an ISP, and you wouldn't want your ISP telling you what applications to run," says Christopher Cramer, information technology security officer at Duke University.
Many colleges and universities rely on a two-pronged approach that security officers say delivers surprisingly good results: First, an aggressive education campaign encourages voluntary compliance with stated computing policies
The 5,500 or so residential students at Duke who enjoy 100-megabit connections to their dorm rooms have access to a wide range of security tools and technologies
On the network, Duke runs an antivirus checker on the e-mail system and occasionally uses access-control lists on the routers to lock problem ports at the border. When students return in the fall, they're automatically directed to a private address space on the network where their machines are scanned for operating system vulnerabilities. Last year, students were given information at that point on how to patch their operating systems. For 2004, Cramer has beefed that up to a requirement: Students won't be allowed onto the university network
To skeptical corporate CISOs accustomed to a higher degree of control, Cramer says the system works just fine. "When Blaster hit, when Slammer hit, Duke survived better than many other corporations I'd heard of. The mixed environment (Macs, Microsoft, Linux, Unix), the collaborative environment, the education all work together to make this a valid approach. If it didn't work, we wouldn't do it."
This "scan and block" policy is common in the college world says John Pescatore, who, as a vice president and research fellow at Gartner, has a roster of clients in academia. "They stop short of saying what you should have on your computer, but they're not stopping short of saying what can run on their networks," Pescatore emphasizes. Universities are some of the biggest buyers of intrusion detection and prevention software, he notes; in the past few years, higher education has jumped up dramatically in its purchase of firewalls
$firstKeyword
Security Directions: A Virtual Conference
Available On Demand Sept. 30 - Dec. 30
Join us for a virtual event with candid, expert information on top security challenges and issues - all from the comfort of your desktop.
Protecting PII: How to Work with IT to Manage Risk
Understand the critical nature of the test data privacy problem and get tips on how to work with IT to implement a test data privacy program.



