“…distributed leadership requires shared values and a sense of community.”
- UW Provost Phyllis Wise
Executive Summary
The state supported University of Washington (UW) is faced with a Herculean set of information age problems to ensure its reputation, which may be viewed as risk management issues, framed within its own mission of providing educational excellence for the state, the region, and the nation. As limited economic resources are used to protect and manage information, paying for information management and security reduces the amount of funds remaining to serve the University’s primary mission, ”the preservation, advancement, and dissemination of knowledge.” (Board of Regents, 1998)
The University’s senior management strategy is that a collaborative, institution-wide model (Strategic Risk Initiative Review Committee, 2006) built on best practices will work best within their framework while reducing costs. Using this method will protect its decentralized, collaborative and entrepreneurial culture, and its information technology, including Personally Identifiable Information, and education information assets, while conforming to state and federal regulations.
Upon the request of UW President Mark Emmert a study was conducted, and, after an in-depth analysis and public comment period (Strategic Risk Initiative Review Committee, 2006), they chose to hire one executive as a C-Level manager, their Chief of Information Security, Kirk Bailey. Although he has no staff, he has the ability to summarily shut down any system. His objective is to advise and inform the three campus and sixteen colleges, and their information manage teams to secure sensitive and other information, and provide a clear direction for information risk management based on his expert knowledge domain, including dynamic social networking (Interview with Kirk Bailey, 2007).
Background
Founded on November 4, 1861, the University of Washington is comprised of three campuses: Seattle, with sixteen schools and colleges ranging from first-year undergraduates through doctoral-level candidates; and the Bothell, and Tacoma campuses, with upper-division undergraduates and graduate students.
As a core value to serve its purpose “the University is committed to maintaining an environment for objectivity and imaginative inquiry and for the original scholarship and research that ensure the production of new knowledge in the free exchange of diverse facts, theories, and ideas.“ (Board of Regents, 1998) In effect this means allowing colleges and schools a great deal of self-governance within the University, because those organizations are the best at understanding what they do.
As a large educational, research, and medical facility the UW acquires, stores, disseminates, and uses vast amounts of data, through its libraries and collections, courses, faculty scholarship, and publications. It advances new knowledge through research, inquiry, and discussion; and disseminates it through classrooms, laboratory, scholarly exchanges, creative practice, international education, and public service. As such the University itself can be considered both a consumer of vast amounts of data, and a source of information.
Some of this information is directly related to individuals – this essentially private data is termed “Personally Identifiable” and has broad implications in its use in credit, grades, tracking and membership, medical, and as related to other types of sensitive research, such as intelligence. Personally Identifiable Information (Executive Officers of the University of Washington, 2001) is regulated by state and federal laws, such as the Health Insurance Portability and Accountability Act (HIPAA) catching up to the ramifications of easily collectable, storable, and frequently transferable information (PII). As a best practice there is also a wealth of compliance issues related to private data housed within a public institution. (Strategic Risk Initiative Review Committee, 2006)
References:
Title: UW Role and Mission Statement
Author: Board of Regents
Publication: http://www.washington.edu/home/mission.html
Date: February 1981; revised February 1998, modified: November 5, 1998
Title: Collaborative Enterprise Risk Management
Author: Strategic Risk Initiative Review Committee, V’Ella Warren, Vice President, Financial Management, David Hodge, Dean, College of Arts and Sciences, co-chairs
Publication: www.washington.edu/admin/finmgmt/erm/ermsummary021306b.pdf
Date: February 13, 2006
Title: Enterprise Risk Management, University of Washington
Author: Strategic Risk Initiative Review Committee, V’Ella Warren, Vice President, Financial Management, David Hodge, Dean, College of Arts and Sciences, co-chairs
Publication: http://www.washington.edu/faculty/facsen/sec_minutes/05-06/sec_021306.pdf.
Date: January 9, 2006
Title: Privacy Policy, University of Washington
Author: Executive Officers of the University of Washington; the President, the Executive Vice President, the Provost, and the University's Privacy Officer, Vice President for Computing and Communications
Publication: http://www.washington.edu/computing/rules/privacypolicy.html
Date: October 6, 2001
Title: Interview with Kirk Bailey
Location: University of Washington, Seattle
Date: February 22, 2007
Showing posts with label risk. Show all posts
Showing posts with label risk. Show all posts
Thursday, March 01, 2007
Thursday, February 15, 2007
You Can't Save the Stupid from Phishing attacks
Like many User Interface professionals I received the recent email notice from VeriSign about their new Secure Socket Layer Certificates which turn green when the site is secure - to make ecommerce and other information transfers through -
"Maximize customer confidence and sales with new VeriSign® EV SSL Certificates
In response to increasing consumer fear of online fraud, VeriSign has introduced *Extended Validation (EV) SSL Certificates*. The new certificates turn the browser address bar green, communicating to consumers that your site is secure."
Taking a quick look around Technorati I found this blog Cyber Top Cops Security http://cybertopcops.blogspot.com/2007/02/green-means-trust-but-does-it-mean.html

an article which quickly pointed out that the average user could care less what color his/her browser turns for all they know it's just supposed to do that.
These Cyber Cops pointed the caring reader to Rachna Dhamija, a Postdoctoral Fellow at the Center for Research on Computation and Society at Harvard University; who besides an enviable career, including electronic commerce privacy and security at CyberCash, has done some interesting studies on scams and why they work on the Internet.
Replacing Rachna Dhamija's educated language with the vernacular, "you can't save the stupid people, because it doesn't really matter who you are, everyone is at risk."
Here's what Dr. Dhamija said -
"We discovered that existing security cues are ineffective, for three reasons:
1. The indicators are ignored (23% of participants in our study did not look at the address bar, status bar, or any SSL indicators).
2. The indicators are misunderstood. For example, one regular Firefox user told me that he thought the yellow background in the address bar was an aesthetic design choice of the website designer (he didn't realize that it was a security signal presented by the browser). Other users thought the SSL lock icon indicated whether a website could set cookies.
3. The security indicators are trivial to spoof. Many users can't distinguish between an actual SSL indicator in the browser frame and a spoofed image of that indicator that appears in the content of a webpage. For example, if you display a popup window with no address bar, and then add an image of an address bar at the top with the correct URL and SSL indicators and an image of the status bar at the bottom with all the right indicators, most users will think it is legitimate. This attack fooled more than 80% of participants.
We also found that popup warnings are ineffective. When presented with a browser warning of a self-signed certificate, 15 out of 22 participants proceeded to click OK (to accept the certificate) without reading the warning. Finally, participants were vulnerable across the board -- in our study, neither education, age, sex, previous experience, nor hours of computer use showed a statistically significant correlation with vulnerability to phishing."
See Fishing with Rachna
sounds friendly enough, na?

So, I believe, and catch me if I am wrong, that unless the Internet security industry comes up with better methods to prevent users from giving away their economic lives by mistake, eventually micro-public-Internets will spring up promising to provide enhanced security just like gated communities.
I know it's scary kids, but it is actually possible that AOL has a future in fear and security, if they can guarantee online safety for their stakeholder customers. It is possible that being an AOL member will mean you are richer and have more at stake than others, and we will have to forgive W because "The Internets" aren't so stupid after all.
"Maximize customer confidence and sales with new VeriSign® EV SSL Certificates
In response to increasing consumer fear of online fraud, VeriSign has introduced *Extended Validation (EV) SSL Certificates*. The new certificates turn the browser address bar green, communicating to consumers that your site is secure."
Taking a quick look around Technorati I found this blog Cyber Top Cops Security http://cybertopcops.blogspot.com/2007/02/green-means-trust-but-does-it-mean.html

an article which quickly pointed out that the average user could care less what color his/her browser turns for all they know it's just supposed to do that.
These Cyber Cops pointed the caring reader to Rachna Dhamija, a Postdoctoral Fellow at the Center for Research on Computation and Society at Harvard University; who besides an enviable career, including electronic commerce privacy and security at CyberCash, has done some interesting studies on scams and why they work on the Internet.
Replacing Rachna Dhamija's educated language with the vernacular, "you can't save the stupid people, because it doesn't really matter who you are, everyone is at risk."
Here's what Dr. Dhamija said -
"We discovered that existing security cues are ineffective, for three reasons:
1. The indicators are ignored (23% of participants in our study did not look at the address bar, status bar, or any SSL indicators).
2. The indicators are misunderstood. For example, one regular Firefox user told me that he thought the yellow background in the address bar was an aesthetic design choice of the website designer (he didn't realize that it was a security signal presented by the browser). Other users thought the SSL lock icon indicated whether a website could set cookies.
3. The security indicators are trivial to spoof. Many users can't distinguish between an actual SSL indicator in the browser frame and a spoofed image of that indicator that appears in the content of a webpage. For example, if you display a popup window with no address bar, and then add an image of an address bar at the top with the correct URL and SSL indicators and an image of the status bar at the bottom with all the right indicators, most users will think it is legitimate. This attack fooled more than 80% of participants.
We also found that popup warnings are ineffective. When presented with a browser warning of a self-signed certificate, 15 out of 22 participants proceeded to click OK (to accept the certificate) without reading the warning. Finally, participants were vulnerable across the board -- in our study, neither education, age, sex, previous experience, nor hours of computer use showed a statistically significant correlation with vulnerability to phishing."
See Fishing with Rachna
sounds friendly enough, na?

So, I believe, and catch me if I am wrong, that unless the Internet security industry comes up with better methods to prevent users from giving away their economic lives by mistake, eventually micro-public-Internets will spring up promising to provide enhanced security just like gated communities.
I know it's scary kids, but it is actually possible that AOL has a future in fear and security, if they can guarantee online safety for their stakeholder customers. It is possible that being an AOL member will mean you are richer and have more at stake than others, and we will have to forgive W because "The Internets" aren't so stupid after all.
Subscribe to:
Posts (Atom)