1st question is: Do you think universities should have the same stringent information security controls that corporations do? Why or why not?
Yes the universities should have the same stringent information security controls that corporations have. Its because there are different transactions in any organization, institution, business, etc. Universities deal with mainly the following three transactions. They are:
- Financial Transactions: They are similar to transactions in any other financial institutions.
- Privacy Transactions: contain personal data that need to be logically and physically secured in order to ensure data protection.
- Information Transactions: They are primarily requests for information , such as curriculum, subject description etc.
The first two transactions are similar to the ones in different corporations. For the proper and secure execution of these transactions there should be information security controls in universities also.
2nd question is: Should universities segregate student networks?
The answer is again yes. The information in academic networks is sensitive. It should be kept secured and out of the reach of every other system or individual. The idea of segregation in the case study given is an excellent idea as I believe where the student residential networks are able to connect to the academic server but the connection can be quickly terminated by them.
I would like to add one more point in this regard that any network that is not under direct control of IT department should be treated as untrusted. Students networks should be firewalled. They can be then given a level of trust.
3rd question is: What security measures does your university require?
Our university, VTU is one of the biggest Technological Universities in India, having 144 colleges affiliated to it. The intake at UG level is about 45000 students and at the PG level it is about 7500 students. So naturally out of so many students there are many “Budding Hackers” which do activities that violate.
The security measures that should be taken are:
- Proper firewall for a secured network such as cyberoam used in our college
- Most of the students using the network “Eat up” the bandwidth as they keep their downloading of content involving images, sound and videos. So a check should be maintained on particular system of student who downloads large content.
- Students those who want to use extra bandwidth must be charged additional to the tuition fees.
- use of peer to peer(p2p) softwares must be banned and a check can be kept.
- A check on accessing inappropriate content must be done inside the network.
Uttamani Hitesh
1MS07IS110

Comments (0)
Post a Comment