Editorial: KU computer security adequate despite audit

In a recent follow-up report on a computer security audit released in 2005 by the Kansas Legislative Division of Post Audit, the University received negative marks after implementing only five of the 33 recommended policy changes.

At first glance, these numbers seem alarming, but ultimately they do not represent a significant threat to the University’s information system. The University is doing an adequate job with regard to computer security.

Bill Myers, director of assessment and outreach for information services, said the audit was focused solely on written policy regarding security measures, not on whether or not certain practices were being conducted.

“It was about having written policy,” Myers said. “It’s not a reflection whatsoever on the security measures that we’ve implemented with our whole IT structure.”

Myers said the University practiced many of the policies included in the audit but had not finalized them on paper.

This presents a problem, according to the audit report released in 2005.

The audit reads: “When computer security policies aren’t written, people tend to make up their own ways of doing things, or don’t do anything at all. It takes only one ‘hole’ in an organization’s computer security for its data to be compromised.”

In an article published in The Kansan on March 2, Rep. Virgil Peck (R-Tyro), chairman of the legislative post audit committee, said he was “disturbed” by the University’s lack of effort to correct the problems noted in the audit.

But Myers said the University’s inability to meet the requirements was mainly due to its large size and the lengthy process required for implementation. He said all 33 requirements should be in written policy by January 2010.

Myers said the University of Kansas, one of the three universities subject to the audit, had 11 policies in draft form in addition to the five already written into policy. In comparison, K-State has seven policies in draft form with seven finalized written policies.

The University hasn’t had a major computer-related information security breach in more than five years.

“There are 16 of the policy recommendations that we don’t have anything for in writing, and that’s the post legislative committee’s concern,” Myers said. “That says nothing about whether we’re practicing the kind of security those policies would relate to.”

Though written policy is an extremely important component to information systems security and should be completed as soon as possible, the University is taking appropriate and timely action.

 

Related articles

Response to computer security audit slow

The University has resolved few issues from the state’s 2005 audit.

/news/2009/mar/02/computers/

General address Bush, terrorism in speech

Gen. Richard B. Myers spoke about terrorism and his relationship with President ...

/news/2007/may/03/myers/

Student Senate creates new graduate position

Student Body President Michael Wade Smith hopes the move will improve relations ...

/news/2010/sep/22/senate-graduate/

University alerts network users to phishing

A fraudulent e-mail asked students and faculty to provide their usernames and ...

/news/2008/aug/22/Phishing/

Four more buildings go wireless on campus

Student Senate surveyed campus and students to decide the buildings to make ...

/news/2008/feb/04/wireless/

New password policy is in effect at ...

/news/2005/jul/22/Passwords/

Guest speaker discusses safety in Nigeria

Parts of Nigeria are perfectly safe to travel to, says Mukhtar Shehu ...

/news/2008/feb/19/guest_speaker/

Stouffer Apartments experience technical difficulties

Residents have been out of phone and internet service for three weeks.

/news/2008/apr/29/stouffer_apartments_experience_technical_difficult/

University anti-virus software plagues students

Residence hall students find that KU's required anti-virus program causes problems.

/news/2008/mar/06/sophos/

Students, faculty must change passwords for stronger ...

/news/2005/sep/13/password/

System seeks to include ‘A+’

The College of Liberal Arts and Sciences requests a change in its ...

/news/2007/oct/04/CLAS/

Changes to senate executive board may be ...

A student senator has asked for an injunction preventing Senate from drafting ...

/news/2010/nov/29/changes-senate-executive-board-may-be-delayed/

Gray-Little plans University initiative

Chancellor wants to improve school’s national academic rankings and retention rate.

/news/2009/nov/11/gray-little-plans-university-initiative/

KU Hospital switches to electronic records

The University of Kansas Hospital is in the second stage of a ...

/news/2008/nov/13/ku_hospital_switches_electronic_records/

Editorial: Student Senate makes progress but needs ...

United Students has made headway, but stalled proposals pose problems.

/news/2007/dec/03/editorial/

Senate rule accidentally omitted

The requirement for senators to submit event surveys for funding evaluation was ...

/news/2010/aug/31/student-senate-corrects-mistake/

Senate considers fee increases

The fees have not been implemented yet.

/news/2008/mar/27/senatenotebook/

Studio completes trailhead project

Student-constructed structure complements overlook deck northeast of Lawrence.

/news/2009/apr/28/trailhead_project/

Student Senate notebook: Funds may be used ...

Student organizations with selective membership may qualify for free advertising in the ...

/news/2008/feb/08/senate_notebook/

Task force to work with administration on ...

The Student Rights’ Committee formed finalized a task force to investigate the ...

/news/2007/oct/25/Sued/

Senate coalitions face off on technology platform

KUnited and RenewKU state their position and promises for improving technology aspects ...

/news/2011/apr/11/senate-coalitions-face-technology-platform/

State bill proposes right to carry concealed ...

The bill would require the University to either allow guns inside or ...

/news/2012/jan/29/state-bill-proposes-right-carry-concealed-weapons-/

Student Senate drafts bill to reconstruct its ...

Court of Appeals allows bill to pass, but Rules and Regulations are ...

/news/2010/nov/30/student-senate-drafts-bill-reconstruct-its-executi/

Departments implement revised privacy policy

After incident last September, University has adopted new rules to protect personal ...

/news/2008/aug/27/shredders/

Coalitions offer their platforms to campus

ConnectKU, Students of Liberty, and United Students hope to appeal to students ...

/news/2008/apr/01/coalitions_offer_their_platforms_campus/

Editorial: Credit-hour requirement should be lowered

Proposal before Board of Regents would lower needed hours to graduate.

/news/2010/oct/11/editorial-credit-hour-requirement-should-be-lowere/

Students respond to concealed weapons bill

The bill would allow people with concealed carry licenses to bring weapons ...

/news/2010/mar/30/concealed-weapons-bill-causes-stir/

Student Senate passes alcohol resolution

Survey says students rely on University services, know little about community resources.

/news/2009/dec/03/student-senate-alcohol-resolution/

A sobering conversation

University struggles to address the complexities of alcohol policy in the wake ...

/news/2009/apr/30/sobering_conversation/

New grading policy implemented in CLAS

Professors can choose to use the new system, which makes a C- ...

/news/2008/aug/27/grades/

Looking at both sides of the scalp

The Athletics Department has begun to take legal action against ticket scalpers ...

/news/2008/jan/24/scalping/

Amendment to expand University jurisdiction to off-campus ...

The amendment would allow the University to discipline students for off-campus issues.

/news/2012/feb/26/amendment-expand-university-jurisdiction-campus-fa/

Student Senate examines students' online rights and ...

Student senators are addressing concerns over whether social media profiles could pose ...

/news/2011/nov/10/student-senate-examines-students-online-rights-and/

Student Senate works issues for this semester, ...

Many issues are works in progress right now for the Senate

/news/2007/dec/05/student_senate_works_issues_semester_next/

Editorial: Bill reducing legacy tuition deserves students’ ...

Legislation would encourage more out-of-state students to attend the University.

/news/2009/mar/03/editorial_bill/

Professors censured for plagiarism

On Oct. 4, the University cited two professors for academic misconduct.

/news/2011/oct/11/professors-censured-plagiarism/

University e-mail accounts attacked by fake KU ...

The IT Security Office is formulating how to stop the scam e-mails, ...

/news/2008/jun/07/credit/

Cosby: Proceed with caution in concealed carry ...

Students should voice concerns with concealed carry bill to lawmakers, not just ...

/news/2010/apr/08/cosby-proceed/

Editorial: Conceal and carry bill dangerous, unwanted

A dangerous bill allowing concealed weapons to be carried on campuses in ...

/news/2010/mar/30/conceal-and-carry-bill-dangerous-unwanted/

ResNet moves to Burge Union

Over winter break, Resnet moved their location from McCollum Hall to the ...

/news/2008/feb/06/resnet_moves_burge_union/

Comments

Use the comment form below to begin a discussion about this content.

Sign in to comment