Important Site Links


Information Trust Institute: University of Illinois at Urbana-Champaign

Short Course: Security Policies and Practices for the IT Professional

COURSE DESCRIPTION:

This course provides IT professionals with the background necessary to understand organizational security and privacy policies. The goal of the course is to educate employees about the nature and scope of organizational security policies, and acquaint them with security practices deployed to address concerns with respect to protecting their data and the assets of their organization. An employee with a better understanding of these issues is more likely to realize the importance of complying with an organization's security practices. The course will focus on acceptable use policies for organizational equipment, disclosure policies for sensitive information, encryption policies, anti-virus and email protection policies, auditing and email retention, DMZ security policies, web browsing, password protection, remote access, router, server and VPN policies, privacy concerns, intellectual property, legal issues, and ethics.

PREREQUISITE: Familiarity with computers and applications

HIGH-LEVEL COURSE OUTLINE AND TIMETABLE:

6 web or live sessions of 50 minutes including quizzes, discussions, and examples.

  1. Security Policies and Practices: Introduction
    1. Need for Organizational Security and Privacy Policies
    2. Organizational Assets
    3. Defining Acceptable Use, Liability
    4. Common Vulnerabilities, Threats, and Attacks
    5. Policy Compliance and Implementation
  2. Protecting Equipment
    1. Application Service Provider Policies and Standards
    2. DMZ Equipment Policy
    3. Physical Security
  3. Protecting Access to Information
    1. Password Protection
    2. Database Access Credentials
    3. Email Policy
    4. Extranet Policy, Remote Access
  4. Information Use Policies
    1. Server Security Policies
    2. Information Sensitivity, Encryption Use Policies
    3. Anti-Virus Protection
    4. Router Security Policies
    5. Audit Vulnerability and Scanning
    6. Email Retention
  5. Information Dissemination Policies
    1. VPN Security Policies
    2. Web Browsing Policies
    3. Wireless Security Policies
  6. Privacy, Legal Issues, Ethics
    1. Privacy Policies, Disclosure Agreements
    2. Intellectual Property
    3. Copyright Issues
    4. Ethics

Instructor Biography

Roy H. Campbell is Abbasi Professor in Computer Science in the Department of Computer Science at the University of Illinois. He is an IEEE Fellow, a member of the ACM, and a member of IFIP Working Group 10.3. He received his Honors B.S. Degree in Mathematics, with a Minor in Physics, from the University of Sussex in 1969 and his M.S. and Ph.D. Degrees in Computer Science from the University of Newcastle upon Tyne in 1972 and 1976, respectively. In 1976 he joined the faculty of the University of Illinois. He has supervised the completion of 31 Ph.D. dissertations and over 123 M.S. theses. He is the author of over 228 research papers on security, programming languages, software engineering, operating systems, distributed systems, and networking.  His past research accomplishments include path expressions, various deadline and error recovery mechanisms for asynchronous processes, the Choices object-oriented operating system, the VDP protocols for streaming audio and video used by Vosaic LLC, dynamic TAO, 2K (a distributed object operating system), UIUC Sesame (a Java implementation of Sesame security protocols), and the Seraphim active security policies.  His current research projects include the Gaia project on active spaces, authentication for mobile sensors, security interoperability, security policies, and active security in active networks. He is an active participant in the department's distance learning program.

Professor Campbell is director of the NSA-designated University of Illinois Center of Academic Excellence in Information Assurance Education.