{"id":11399,"date":"2018-12-14T07:48:16","date_gmt":"2018-12-14T12:48:16","guid":{"rendered":"https:\/\/michigan.it.umich.edu\/news\/?p=11399"},"modified":"2024-07-08T06:05:38","modified_gmt":"2024-07-08T10:05:38","slug":"it-security-and-privacy-keeping-you-and-the-u-safe","status":"publish","type":"post","link":"https:\/\/michigan.it.umich.edu\/news\/2018\/12\/14\/it-security-and-privacy-keeping-you-and-the-u-safe\/","title":{"rendered":"IT security and privacy: Keeping you and the U safe"},"content":{"rendered":"<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone wp-image-11403 size-large\" src=\"https:\/\/michigan.it.umich.edu\/news\/wp-content\/uploads\/2018\/12\/Screen-Shot-2018-12-13-at-9.42.59-AM-700x400.png\" alt=\"U-M protected by Duo\" width=\"665\" height=\"380\"><\/p>\n<p><span style=\"font-weight: 400;\">As the University of Michigan gets ready for winter break, remember that cyber attackers never take time off. The university takes measures to protect the institution\u2019s data and systems no matter the time of the year. While Information Assurance (IA) leads and coordinates these efforts, everyone in the U-M community has a shared responsibility to do their part. <\/span><\/p>\n<p><span style=\"font-weight: 400;\">The revised <\/span><a href=\"http:\/\/spg.umich.edu\/policy\/601.27\" target=\"_blank\" rel=\"noopener\"><span style=\"font-weight: 400;\">Information Security SPG 601.27<\/span><\/a><span style=\"font-weight: 400;\"> policy, the <\/span><a href=\"https:\/\/it.umich.edu\/information-technology-policies\/general-policies\/#standards\" target=\"_blank\" rel=\"noopener\"><span style=\"font-weight: 400;\">accompanying IT Security standards<\/span><\/a><span style=\"font-weight: 400;\">, and the <\/span><a href=\"https:\/\/www.safecomputing.umich.edu\/duo-two-factor-expansion-project\" target=\"_blank\" rel=\"noopener\"><span style=\"font-weight: 400;\">expansion of two-factor authentication<\/span><\/a><span style=\"font-weight: 400;\"> are recent examples of steps U-M has taken to appropriately secure the university while continuing to enable its teaching, research, clinical, and administrative missions. <\/span><\/p>\n<h1><b>Two-factor authentication: Where are we?<\/b><\/h1>\n<p><span style=\"font-weight: 400;\">Two-factor (Duo) for Weblogin will be required for all U-M faculty, staff, student employees, and sponsored affiliates across all campuses on Wednesday, January 23, 2019. It has been required in Michigan Medicine since October. Thus far, nearly 70,500 U-M employees already have turned on Duo for Weblogin. <\/span><\/p>\n<p><span style=\"font-weight: 400;\">Some of the steps taken to encourage individuals to turn on two-factor before the go-live date include: <\/span><\/p>\n<ul>\n<li style=\"font-weight: 400;\"><span style=\"font-weight: 400;\">Targeted emails, which are being sent regularly to those who have not enrolled in Duo, as well as those who have enrolled, but not turned on two-factor for Weblogin.<\/span><\/li>\n<li style=\"font-weight: 400;\"><span style=\"font-weight: 400;\">Expanded help documentation and videos for U-M community self-service. <\/span><\/li>\n<li style=\"font-weight: 400;\"><span style=\"font-weight: 400;\">The <\/span><a href=\"https:\/\/duo.it.umich.edu\"><span style=\"font-weight: 400;\">U-M Duo tool<\/span><\/a><span style=\"font-weight: 400;\">, which helps individuals determine whether they are using two-factor and, if not, assists them in turning it on. <\/span><\/li>\n<li style=\"font-weight: 400;\"><span style=\"font-weight: 400;\">The U-M Weblogin page, which currently includes a banner reminding people to turn on two-factor\u2014in January, employees who are not using Duo will encounter an interrupt screen encouraging them to turn it on. <\/span><\/li>\n<li style=\"font-weight: 400;\"><span style=\"font-weight: 400;\">The Duo dashboard, to be shared with deans, directors, and department heads and unit IT staff\u2014the dashboard will allow unit leaders to track how their unit is doing and to use the information as a means for encouraging participation.<\/span><\/li>\n<li style=\"font-weight: 400;\"><span style=\"font-weight: 400;\">Prize drawing for those who turn on Duo before December 19, consisting of a chance to win an Apple Watch 4, iPad Mini 4, or Airpods. <\/span><\/li>\n<\/ul>\n<p><span style=\"font-weight: 400;\">IA highly recommends that U-M employees turn on two-factor for Weblogin sooner rather than later. This approach allows new users time to become familiar with the tool and its various options, such as the seven day \u201cRemember me\u201d function, availability of offline passcodes, and more. While the overwhelming majority of the university community prefers using the Duo Mobile app on their smartphone, <\/span><a href=\"https:\/\/documentation.its.umich.edu\/2fa\/options-two-factor-authentication\" target=\"_blank\" rel=\"noopener\"><span style=\"font-weight: 400;\">other options are available<\/span><\/a><span style=\"font-weight: 400;\"> to address individual circumstances and needs.<\/span><\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone wp-image-11402 size-large\" src=\"https:\/\/michigan.it.umich.edu\/news\/wp-content\/uploads\/2018\/12\/SPG-pyramid1-700x530.png\" alt=\"SPG 601.27; 13 Information Security Standards; Safe Computing Content and Minimum Security Requirements Checklist\" width=\"665\" height=\"504\"><\/p>\n<h1><b>Revised information security policy: What\u2019s coming?<\/b><\/h1>\n<p><span style=\"font-weight: 400;\">Back in August, U-M\u2019s Executive Officers approved a long-awaited revision to SPG 601.27, the university\u2019s IT Security policy. Since then, IA has been meeting with a variety of stakeholders, including unit IT staff, to provide support for their implementation planning well in advance of December 31, 2020, when full compliance with the policy and standards is expected. The goal is to provide IT staff with information, tools, and resources\u2014with an emphasis on the key message that IT security and compliance is a shared responsibility for all university community members.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">In addition to the SPG approval, 13 IT Security standards were approved. These standards provide specific direction on how to appropriately secure U-M systems and data. An IT Standards Advisory Group is being convened that will provide IA with feedback and support on how best to actualize the SPG and standards. Advisory group members will represent a cross section of the university community. &nbsp;<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Beginning in winter 2019 and continuing through the spring, IA will hold campuswide information sessions on each of the IT Security standards. The goal of these sessions will be to provide IT and interested business and administrative staff with an opportunity to expand their technical knowledge of each standard, ask questions of subject matter experts, and get a better understanding of the implementation process. Information session dates, times, and locations will be announced in the Michigan IT Newsletter and through communications to a variety of U-M IT communities and other stakeholders. <\/span><\/p>\n<p><span style=\"font-weight: 400;\">Detailed implementation guidance and documentation is available on the <\/span><a href=\"https:\/\/www.safecomputing.umich.edu\/protect-the-u\/protect-your-unit?nav\"><span style=\"font-weight: 400;\">Protect Your Unit\u2019s IT<\/span><\/a><span style=\"font-weight: 400;\"> webpage along with <\/span><a href=\"https:\/\/www.safecomputing.umich.edu\/information-security-requirements\"><span style=\"font-weight: 400;\">Minimum Information Security Requirements for Systems, Applications, and Data<\/span><\/a><span style=\"font-weight: 400;\">. These materials provide a baseline that applies to all U-M units, faculty, staff, affiliates, and vendors with access to institutional data, and are a useful backdrop for the coming information session discussions. <\/span><\/p>\n<p><span style=\"font-weight: 400;\">The latest updates and information about two-factor authentication, the revised SPG 601.27, and the accompanying IT standards can be found on the <\/span><a href=\"https:\/\/www.safecomputing.umich.edu\/\"><span style=\"font-weight: 400;\">Safe Computing<\/span><\/a><span style=\"font-weight: 400;\"> website.<\/span><\/p>\n","protected":false},"excerpt":{"rendered":"<p>As U-M gets ready for Winter Break, remember that cyber attackers never take time off. The university takes measures to protect the institution\u2019s data and systems no matter the time of the year.<\/p>\n","protected":false},"author":15,"featured_media":11403,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_uag_custom_page_level_css":"","_umich_oidc_access":"","_monsterinsights_skip_tracking":false,"_monsterinsights_sitenote_active":false,"_monsterinsights_sitenote_note":"","_monsterinsights_sitenote_category":0,"_ef_editorial_meta_date_first-draft-date":"","_ef_editorial_meta_paragraph_assignment":"","_ef_editorial_meta_checkbox_needs-photo":"1","_ef_editorial_meta_number_word-count":"","footnotes":""},"categories":[27],"tags":[78,63,23,572,77],"class_list":["post-11399","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-safe-computing","tag-duo","tag-policy","tag-security","tag-spg","tag-two-factor"],"uagb_featured_image_src":{"full":["https:\/\/michigan.it.umich.edu\/news\/wp-content\/uploads\/2018\/12\/Screen-Shot-2018-12-13-at-9.42.59-AM-e1544729491814.png",600,343,false],"thumbnail":["https:\/\/michigan.it.umich.edu\/news\/wp-content\/uploads\/2018\/12\/Screen-Shot-2018-12-13-at-9.42.59-AM-200x114.png",200,114,true],"medium":["https:\/\/michigan.it.umich.edu\/news\/wp-content\/uploads\/2018\/12\/Screen-Shot-2018-12-13-at-9.42.59-AM-300x171.png",300,171,true],"medium_large":["https:\/\/michigan.it.umich.edu\/news\/wp-content\/uploads\/2018\/12\/Screen-Shot-2018-12-13-at-9.42.59-AM-768x439.png",665,380,true],"large":["https:\/\/michigan.it.umich.edu\/news\/wp-content\/uploads\/2018\/12\/Screen-Shot-2018-12-13-at-9.42.59-AM-700x400.png",600,343,true],"1536x1536":["https:\/\/michigan.it.umich.edu\/news\/wp-content\/uploads\/2018\/12\/Screen-Shot-2018-12-13-at-9.42.59-AM-e1544729491814.png",600,343,false],"2048x2048":["https:\/\/michigan.it.umich.edu\/news\/wp-content\/uploads\/2018\/12\/Screen-Shot-2018-12-13-at-9.42.59-AM-e1544729491814.png",600,343,false],"excerpt-thumbnail":["https:\/\/michigan.it.umich.edu\/news\/wp-content\/uploads\/2018\/12\/Screen-Shot-2018-12-13-at-9.42.59-AM-200x140.png",200,140,true],"themonic-thumbnail":["https:\/\/michigan.it.umich.edu\/news\/wp-content\/uploads\/2018\/12\/Screen-Shot-2018-12-13-at-9.42.59-AM-60x42.png",60,42,true],"ioslider-thumbnail":["https:\/\/michigan.it.umich.edu\/news\/wp-content\/uploads\/2018\/12\/Screen-Shot-2018-12-13-at-9.42.59-AM-658x300.png",658,300,true],"post-thumbnail":["https:\/\/michigan.it.umich.edu\/news\/wp-content\/uploads\/2018\/12\/Screen-Shot-2018-12-13-at-9.42.59-AM-665x380.png",665,380,true],"400x250-crop":["https:\/\/michigan.it.umich.edu\/news\/wp-content\/uploads\/2018\/12\/Screen-Shot-2018-12-13-at-9.42.59-AM-e1544729491814.png",400,229,false]},"uagb_author_info":{"display_name":"Dana Fair, ITS Marketing &amp; Communications","author_link":"https:\/\/michigan.it.umich.edu\/news\/author\/danafair\/"},"uagb_comment_info":0,"uagb_excerpt":"As U-M gets ready for Winter Break, remember that cyber attackers never take time off. The university takes measures to protect the institution\u2019s data and systems no matter the time of the year.","_links":{"self":[{"href":"https:\/\/michigan.it.umich.edu\/news\/wp-json\/wp\/v2\/posts\/11399","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/michigan.it.umich.edu\/news\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/michigan.it.umich.edu\/news\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/michigan.it.umich.edu\/news\/wp-json\/wp\/v2\/users\/15"}],"replies":[{"embeddable":true,"href":"https:\/\/michigan.it.umich.edu\/news\/wp-json\/wp\/v2\/comments?post=11399"}],"version-history":[{"count":7,"href":"https:\/\/michigan.it.umich.edu\/news\/wp-json\/wp\/v2\/posts\/11399\/revisions"}],"predecessor-version":[{"id":11598,"href":"https:\/\/michigan.it.umich.edu\/news\/wp-json\/wp\/v2\/posts\/11399\/revisions\/11598"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/michigan.it.umich.edu\/news\/wp-json\/wp\/v2\/media\/11403"}],"wp:attachment":[{"href":"https:\/\/michigan.it.umich.edu\/news\/wp-json\/wp\/v2\/media?parent=11399"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/michigan.it.umich.edu\/news\/wp-json\/wp\/v2\/categories?post=11399"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/michigan.it.umich.edu\/news\/wp-json\/wp\/v2\/tags?post=11399"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}