Tag Archives: Post for MiddNotes

@MiddInfoSec: Information Security’s ‘Security Scout of the Month’

To help raise awareness about community efforts to prevent significant security issues, Middlebury Information Security has launched a ‘Security Scout of the Month’ award.

This month Information Security would like to recognize Amy Dale who promptly and accurately responded to potential malware activity by unplugging her computer and reaching out to the Help Desk for immediate assistance.

When asked, Amy shared this advice about computer security, “My previous work experience, particularly at AOL, helped prepare me to be more alert and aware of scams. A previous manager always said, “when in doubt, leave it out.”  In other words, when you’re the least bit hesitant, then don’t open/click/download, etc. “

This astute awareness and keen insight is why Amy is this month’s ‘Security Scout of the Month’.

We are excited to celebrate the hard work and security conscious efforts of our community. Please watch for the next ‘Security Scout of the Month’ and help us recognize these efforts.

If you would like to recognize an individual for their information security contributions or would like to raise an information security concern, please contact infosec@middlebury.edu.

@MiddInfoSec: Stay Safe and Secure when Online

When you are reading e-mail or browsing online, be on the lookout for suspicious links and deceptive web pages, which are major sources of malware. Also be careful of downloadable files since they can introduce malware. And remember that additional browser plugins and unused applications require additional patching to remain secure. Here are some suggestions to make your day-to-day computing more productive, safe, and secure.

  • Keep your software up-to-date. Be sure to install antivirus updates and regularly check for and install updates for any applications or browser plugins you may run on your computer. (e.g., Adobe Flash and Java)
  • Be more secure! Don’t enter sensitive or personal information into a URL unless you have verified the address and you have ensured its security by checking that it includes HTTPS.
  • When in doubt, ignore. Don’t click on pop-up windows or extraneous ads. And, don’t click on links in emails or web sites until you have verified their destinations by hovering your mouse over the link.
  • Keep your private information safe. Use a strong, unique password or passphrase for each account, and avoid storing account information on a website. And consider using a digital password wallet such as 1Password or LastPass to secure your passwords.
  • Segregate your browsing activities. Consider using separate browsers for sensitive logins and general web browsing.
  • Use private networks for sensitive transactions. Avoid checking your bank account, making purchases, or logging in to other websites that include sensitive information when using public Wi-Fi.

Go stealth when browsing. Your browser can store quite a bit of information about your online activities, including cookies, cached pages, and history. To ensure the privacy of personal information online, limit access by going “incognito” and using the browser’s private mode.

Notes for Google Apps and OneDrive Project Presentation

  • Cloud Services: Google and Microsoft
    • Goal: provide better (cloud-based) services to the community
  • Infrastructure
    • Storage
      • Available from anywhere
      • Private, secure, encrypted
      • Scales to demand
    • Access to info
      • Collaboration and sharing
    • Familiar and consistent
  • Why are we doing this?
    • Better consume our resources
      • Home directories on middfiles are 25TB
      • Grows a half TB a month
    • Enhance service offerings
      • Available anywhere on most any device
      • Scalable and efficient use of eresources
      • Cost effective
      • Highly available
      • On demand automatic provisioning
  • What we can provide
    • Google apps for edu
      • No longer in beta!
      • Online collaboration
      • Drive
    • 365
      • Online collaboration suite – word, excel
      • Software distribution (local office install)
      • Onedrive
      • More nuanced levels of licensing and access – differences between MIIS and Midd College, working through those issues
    • Email in the cloud!
      • Fully hosted or hybrid model
  • Where we are now
    • Groundwork has been laid
    • All midd users automatically have GAfE account
      • Including access to apps, drive, and youtube
    • All midd users automatically have an O365 account
      • College students can install local copies of Office through O365
        • Only for residential students, MIIS students can access cloud-based Office suite
      • Everyone has accounts but they don’t have access yet
    • All active directory groups exist in both GAfE and O365
  • Still to come
    • A series of projects as opposed to one big unveiling
      • Documentation and education project
      • Microsoft’s online collaboration apps
      • OneDrive and GoogleDrive
      • Home use software distribution Faculty/Staff
      • Everyone currently has access to Google Apps (but most people don’t know)
      • Everyone does not currently have access to OneDrive – still to come
      • Cloud-based email still to come
  • Decisions that still need to be made
    • Which service do we recommend to people?
    • How do different groups collaborate effectively?
    • Do professors choose one or the other?
      • Will students need access to both?
    • Others?

 

Questions

  • Do we want to offer the same level of support for both or favor one?
    • One platform may be better for certain uses than the other
    • We like the idea of a default/one that is better supported
  • Any support requests re: Google to date?
    • A few calendar items, nothing major
    • Most people are using web interface
  • I’m a student with a google account that I use for school work – I graduate and move on. How do I transition my work to my private account?  (Bill)
    • No fee, but there will be some hoops/procedures to go through
  • I’m a student with a Microsoft account that I use for school work – I graduate and move on. How do I transition my work to my private account? (Bill)
    • Currently more complicated than Google
    • Everything that is cloud-delivered is free
  • Do we have an inventory of what’s been turned on by Google Admin? (Joe)
    • Yes, a list can be shared
    • When you’re logged in you can see a list of some applications, but not all of them
  • How does a faculty member associate Google resources with a course?
    • A Course Hub integration would be helpful here; it’s currently tough to find the right group in Google
      • Create the resource, connect with the correct student group
    • With OneDrive, groups can own files/documents – more ownership-based management than Google-drive
      • If group owns documentation, data management is simpler from an administrative perspective. Group membership should be able to shift seamlessly
      • This is a nuance we’ll have to figure out between Google and OneDrive
  • Monterey and Midd campuses have the exact same access to this functionality? (Bill)
    • Yes, only difference is residential component for the College (Office installs)
    • This is an example of “big M” Middlebury thinking
  • For a guest lecturer or auditor, they could be added to a Google folder not a group?
    • Another nuance that needs to be explored/determination needs to be made about what to recommend to faculty
  • In terms of announcements/messaging/role out, does Course Hub integration need to be in place first?
    • We need to have nuances largely figured out before we make an announcement
  • So what’s the rollout timeframe?
    • Timeline needs to include various project teams
    • Probably not reality to have ready for fall 2016 roll out
    • Do we need to roll both platforms out at the same time?
      • It would behoove us to roll out the recommended platform first
  • We need to give faculty clear instructions about procedure change, as they are not accustomed to provisioning folders themselves (Joe)
    • Now they will need a folder with the appropriate permissions
  • What’s the motivation for having both services?
    • We have to have some of each. Google is already pretty ubiquitous in usage across Middlebury. We have to roll out Microsoft because of software distribution. Or do we? We can control what Microsoft functionality is available to avoid too much overlap with Google.
    • Encryption/security implications – Microsoft is superior to Google in this respect
    • Google doesn’t work in China – Jeff Cason currently testing OneDrive in China
    • A potential differentiation could be
      • Academic – Google. Administrative – Microsoft.
        • In reality this won’t happen
  • While Microsoft is in beta, the move to single sign on for everyone seems like a big step (Bob)
    • MIIS users having to sign on with @middlebury.edu account
    • We want to promote access to Google Apps – it would be disappointing if we couldn’t make an official announcement to the MIIS campus this fall even if the Course Hub integration is not in place.
    • What happens when students graduate? Some of our students are only here for a year, some do Peace Corps during their degree – leave campus for 2 years and come back.
      • How do the nuances of those different user needs get managed? We need an exit strategy.
    • Exit strategy for individuals and Middlebury as a whole is important.
  • Where is this project in terms of the ACTT life cycle? (Bob)
    • Should OneDrive be rolled out the same way Google Apps was?
      • Resource constraints
  • Is there a downside to MIIS announcing Google Apps rollout to campus? (Bob)
    • When Microsoft is rolled out, there may be an inordinate number of help desk tickets from people who want to migrate content from Google to Microsoft
    • It depends on when OneDrive becomes available
      • Timelines are not currently known, several different project teams
  • 2,000 Google Apps accounts active before syncing took place
  • There was already a OneDrive instance at MIIS that was being used by 40 people – no administrator
  • There’s nothing stopping any Middlebury user from using Google Apps (they just don’t know about it)
    • We are currently not fully committing or walking away from either

ACTT In-progress Project Presentation for Canvas

The new ACT Team process includes in-progress project presentations. These presentations are meant to inform the community about how things are going, what has been done and what still needs to be done, what is going well and what are the challenges.

In this meeting we will talk about Canvas.

These are open meetings, please feel free to share the invitation with anyone you feel is interested in the topics discussed.

 

Middlebury will Adopt Canvas

In January, 2016, the ACTT (formerly CTT) submitted a recommendation for Middlebury to adopt Canvas. We have received budget approval, and will begin the work of moving Middlebury into the Canvas service.

Thank you to all of the faculty and students that participated in the pilot. Your participation and feedback (Midd and MIIS) helped to make a strong recommendation. And thank you to Joe Antonioli, Bob Cole, Bill Koulopoulos, Stacy Reardon, Shel Sax and Heather Stafford for supporting these classes during the pilot.

Also, thank you to all of the schools that provided us with insight and the benefit of their experience with Canvas. We learned a lot from you.

There is a lot of work still to be done to move Canvas from pilot to enterprise, but we do hope that you take a moment to celebrate this milestone and the collective effort to get to this point.

ACTT In-Progress Project Presentation for GoogleApps for Edu and OneDrive

[This meeting was rescheduled from May 17th to May 31st.]

Tuesday, May 31st from 3-4pm
LIB 105A or Polycom 712833

The new ACT Team process includes in-progress project presentations. These presentations are meant to inform the community about how things are going, what has been done and what still needs to be done, what is going well and what are the challenges.

Agenda

In this meeting we will look at the GoogleApps for Edu and OneDrive projects.

In-progress project presentations are open meetings, anyone may attend. Please feel free to share the invitation with anyone you feel is interested in the topics discussed.

@MiddInfoSec: Preventing Device Theft

With an increasing amount of storage space and institutional connectivity on personal devices, the value and mobility of smartphones, tablets, and laptops make them appealing and easy targets. These simple tips will help you protect against and prepare for the potential loss or theft of a laptop or mobile device.

    • Don’t leave your device alone, even for a minute. If you’re not using it, lock your device in a cabinet or drawer, use a security cable, or take it with you. Middlebury has seen laptops stolen in the College library and from individual’s cars. Don’t assume your devices are safe because you feel at home with your surroundings.
    • Report any lost or stolen device promptly. Both institutional and personal devices may contain Middlebury data. Even if you only lose a personal device, work with the College’s Information Security workgroup to ensure that institutional or sensitive data is accounted for. Information Security may also be able to help you recover the device. If a device is lost or stolen contact the helpdesk at x2200 immediately.
    • Do not store extremely sensitive or internal data. Never store protected or sensitive data on your laptop. Refer to the Data Classification policy for clear definitions of data types. (http://go.middlebury.edu/dcp)
    • Keep your master and working copy of all data on network storage. Keeping your master and working copies of all of your data on Middlebury Google Drive or other secure network file storage such as Middfiles. This ensures that your data is protected and backed-up if your laptop is stolen or lost. Photos, papers, research, and other files are irreplaceable, and losing them may be worse than losing your device.
    • Record the serial number. Keep the serial number and asset tag of your device and store it in a safe place. This information can be useful for verifying your device if it’s found. This is especially important when you travel. Airport and police agencies may ask for this information when reporting lost or stolen devices.
    • Enable device tracking and wiping services. Use tracking and recovery software included with most devices (e.g., the “Find iDevice” feature in iOS) Some software includes remote-wipe capabilities. This feature allows you to log on to an online account and delete all of the information on your laptop. Mobile resources can be found here:
    • Apple iCloud: http://www.icloud.com
    • Microsoft Account: http://account.Microsoft.com/devices
    • Android Device Manager: https://support.google.com/accounts/topic/6160499?hl=e