I've Made Up My Mind, Don't Bother Me With the Facts
The report, Educational Security Incidents (ESI) Year in Review, spotlights institutions worldwide, and Penn State was included in the report with one data breach last year.
…
“My goal with ESI is to, hopefully, increase awareness within higher education that not only is information security a concern, but that the threats to college and university information is not as simple as network and/or computer attacks,” Adam Dodge, ESI creator, wrote in an e-mail.…
The report also shows the majority of information breaches at colleges came from unintentional leaks, rather than hackers. But Penn State Information Technology Vice Provost Kevin Morooney said he isn’t sure how deeply anyone should read into the report.“I’m ignoring the report,” he said. “Hackers are a constant and daily threat at the university, and we have many things put in place to mitigate the risk.” (Emphasis added.)
“Security of data analyzed in study,” The Daily Collegian at Penn State.
Adam Dodge runs the “Educational Security Incidents” blog, and his “Year In Review” is worth a look.
I hope that Vice Provost Morooney had other things to say about a comprehensive approach to security. Because otherwise, he’s made up his mind, and don’t wanna be bothered with no facts. A sad position for anyone at a University to take.
FINAL REPORT OF THE
COMPUTER INCIDENT FACTOR ANALYSIS
AND CATEGORIZATION (CIFAC) PROJECT,
VOLUME I: COLLEGE AND UNIVERSITY SAMPLE
“Are you the cause or the cure?” – UCLA BruinTech
I’m hoping Morooney was quoted out of context or something, because people doing dumb stuff are a huge piece of the puzzle when it comes to .edu breaches, and it isn’t a secret.
It’s not like those Penn alumni can get a new alma mater. They can, however, get a new provost.
Evidence? I don’t need no stinking evidence! As Pokey says:
Hmmm… Html for style only. No images. Whoops:
http://www.yellow5.com/pokey/archive/pokey484_4.gif
anyone on this blog who is a Penn State alum ought to be letting fellow alums know what the “thinking” is at the highest levels of their alma mater. Scary.
The problem is not ignoring evidence but being drowned in a sea of evidence. Morooney is right to be skeptical, he probably has at easy reach 20 other reports, all as superficial.
Indeed, we only have to skip a few posts back to discover that awareness training is good for sexual harrassment and deforestation, but does nothing for security. Any report that attributes 40% of the problem to carelessness is simply shifting the burden to somewhere else and should be treated skeptically.