Securing and Protecting Citizens' Data

19
J. Rick Mihalevich Dean of Information Technology Linn State Technical College [email protected] 573.897.5129 June 18, 2009

description

Securing and Protecting Citizens' Data. J. Rick Mihalevich Dean of Information Technology Linn State Technical College [email protected] 573.897.5129 June 18, 2009. Securing and Protecting Citizen Data Goals. Provide awareness of the need - PowerPoint PPT Presentation

Transcript of Securing and Protecting Citizens' Data

Page 1: Securing and Protecting Citizens' Data

J. Rick MihalevichDean of Information Technology

Linn State Technical [email protected]

573.897.5129June 18, 2009

Page 2: Securing and Protecting Citizens' Data

Provide awareness of the need Provide awareness of the major laws that

impact public entities Provide information on best practices,

technology, and trends Provide resources for further information

Page 3: Securing and Protecting Citizens' Data

Open Accessible Transparent Accountable

Page 4: Securing and Protecting Citizens' Data

LSTC currently utilizes XXXXXX to provide data XXXXXX processes which impacts approximately XXXXXX blocked attacks daily.

XXXXXXX manages a XXXX XXXX router at the gateway

LSTC utilizes XXXXXX Firewall The DMZ is attached to a XXXXXXX appliance. All packets are inspected by XXXXXX and XXXX

security software is used to protect against XXXXXX attacks.

Page 5: Securing and Protecting Citizens' Data

2006 26.5 million veterans was compromised when a laptop was stolen

2007 Inspector General for Tax Administration found 490 laptops containing sensitive taxpayer data had been lost or stolen

2006 Employee information at the department of agriculture was compromised by unauthorized access

Examples of Compromised Data

Page 6: Securing and Protecting Citizens' Data

FERPA: Family educational rights and privacy act

HIPAA: Health insurance portability and accountability act

GLB: Gramm-Leach-Bliley Act The Privacy Act E-government Act FISMA: The Federal Information Security

Management act

Page 7: Securing and Protecting Citizens' Data

Conclusion #1: LSTC Infrastructure◦ Security by Obscurity

Conclusion #2: Examples of Compromised Data◦ Employees may pose the greatest risk

Conclusion #3: Public Laws◦ Balance between openness and security

Public Trust Restricting access, in the name of security is no vise

Page 8: Securing and Protecting Citizens' Data
Page 9: Securing and Protecting Citizens' Data

Pass Phrase Thumb drive encryption Encryption of laptops Virtual Private Networks (VPN’s) Touchpad security Effective patch management

Page 10: Securing and Protecting Citizens' Data

Security officer Security by Obscurity Not using SSN Training and awareness Change passwords frequently (Strong) Don’t click on e-mail links

Page 11: Securing and Protecting Citizens' Data
Page 12: Securing and Protecting Citizens' Data

www.cybersecurity.mo.gov www.msisac.org Department of Homeland Security National Governors Association Center for

Best Practices National Association of Chief Information

Officers Governmental Accountability Office

Page 13: Securing and Protecting Citizens' Data
Page 14: Securing and Protecting Citizens' Data
Page 15: Securing and Protecting Citizens' Data
Page 16: Securing and Protecting Citizens' Data
Page 17: Securing and Protecting Citizens' Data
Page 18: Securing and Protecting Citizens' Data

Principles of openness, accuracy, transparency and accountability

How would you like your personal information handled fairly and lawfully process it process it only for limited, specifically stated purposes use the information in a way that is adequate, relevant and

not excessive use the information accurately keep the information on file no longer than absolutely

necessary process the information in accordance with your legal rights keep the information secure never transfer the information outside

Page 19: Securing and Protecting Citizens' Data

ethnic background political opinions religious beliefs health sexual life criminal history