. .

Recent News

The Compensating Controls & Exceptions Form is up

Here are the Compensating Controls & Exception process submision forms for the UCSS.


Security Boot Camp outline up for comment

The CIO Security Group is developing an "Information Security Boot Camp" program that will be taught later this year. Comment on the proposed outline is encouraged during development. Check out the basic outline here


Check the Blackhole List

To see the current Blackhole listing click here


Report an Incident

To report a security breach or other security incident send an email to Security@osu.edu

Security Boot Camp:

Format: formal classes, two ˝ day sessions

Session 1: Introduction to Information Security

Audience: Technical staff
Skill/Knowledge level: Introductory to Intermediate level technical skills

Topics:

Basic Security Concepts – definitions, threats, C.I.A.
Law & policy: State & Federal, UCSS
Security Services at OSU
Resources for DNA’s

Session 2: Security in Practice

Audience: Technical Staff
Skill/Knowledge: Intermediate technical skills

Topics:

Incident Response Basics - basic forensics, logging and procedure
Host Hardening Basics – covers overview/best practices for all platforms
Net Hardening Basics - Firewall/IDS/IPS and network scanning basics.

Follow on Sessions:

Format: 2 hour elective classes with focus on specific topics in security
Audience: Technical staff
Skill/Knowledge levels: Intermediate to Advanced technical skills

Topics (each represents one 2-hour session):

Understanding Networks
Telecommunications
Firewalls
Vulnerability scanning and Penetration testing
Intrusion Detection/Prevention
Logging and monitoring
Secure services configuration
Encryption
Security Training and Awareness – developing an internal plan

Comments or suggestions on this outline can be directed to security@osu.edu