Educause Security Discussion mailing list archives

Re: Security Awareness Training for Managers of Decentralized IT Systems


From: "Sarazen, Daniel" <dsarazen () UMASSP EDU>
Date: Fri, 9 Jul 2010 16:48:29 -0400

It would have to be general. My audience would be from everywhere, in theory. Ideally they'd be enough time to answer 
specific questions.

From: The EDUCAUSE Security Constituent Group Listserv [mailto:SECURITY () LISTSERV EDUCAUSE EDU] On Behalf Of Ben Woelk
Sent: Friday, July 09, 2010 3:41 PM
To: SECURITY () LISTSERV EDUCAUSE EDU
Subject: Re: [SECURITY] Security Awareness Training for Managers of Decentralized IT Systems

Daniel,
Are you providing a general security awareness presentation or something specific to their departments?

Ben Woelk '07
Policy and Awareness Analyst
Information Security Office
Rochester Institute of Technology
Ross 10-A204
151 Lomb Memorial Drive
Rochester, New York 14623
585.475.4122
585.475.7920 fax
ben.woelk () rit edu<mailto:ben.woelk () rit edu>
http://security.rit.edu/dsd.html

Become a fan of RIT Information Security at http://rit.facebook.com/profile.php?id=6017464645

Follow us on Twitter: http://twitter.com/RIT_InfoSec

CONFIDENTIALITY NOTE:  The information transmitted, including attachments, is intended only for the person(s) or entity 
to which it is addressed and may contain confidential and/or privileged material.  Any review, retransmission, 
dissemination or other use of, or taking of any action in reliance upon this information by persons or entities other 
than the intended recipient is prohibited.  If you received this in error, please contact the sender and destroy any 
copies of this information.


From: The EDUCAUSE Security Constituent Group Listserv [mailto:SECURITY () LISTSERV EDUCAUSE EDU] On Behalf Of Sarazen, 
Daniel
Sent: Friday, July 09, 2010 3:16 PM
To: SECURITY () LISTSERV EDUCAUSE EDU
Subject: [SECURITY] Security Awareness Training for Managers of Decentralized IT Systems

Hi All,

We have a large population of decentralized departmental IT systems and typically these are under the direction of 
Business Management who have little to no IT background. I'm considering providing the management of decentralized IT 
systems within our system with an Information Security Awareness presentation and was wondering if anybody had prepared 
anything similar.

I tried something similar in the past, using ISO 27002 controls, but they just sent their IT Administrators and 
completely missed my point.

Thanks



[cid:image001.gif@01CB1F7D.CCD51200]

:: Daniel Sarazen, CISSP, CISA
:: Senior Information Technology Auditor
:: University Internal Audit
:: University of Massachusetts President's Office

:: 774-455-7558
:: 781-724-3377 Cell
:: 774-455-7550 Fax
:: Dsarazen () umassp edu<mailto:Dsarazen () umassp edu>

University of Massachusetts : 333 South St. : Suite 450 : Shrewsbury, MA 01545 : 
www.massachusetts.edu<http://www.massachusetts.edu/>




Current thread: