PROTECTING PENN · 2019-12-12 · stakeholders across campus participated in a multi-year project...

4
PENN’S TRUSTED IT PARTNER Information Systems & Computing INFORMATION SECURITY PROTECTING PENN

Transcript of PROTECTING PENN · 2019-12-12 · stakeholders across campus participated in a multi-year project...

Page 1: PROTECTING PENN · 2019-12-12 · stakeholders across campus participated in a multi-year project to enhance information security at Penn, resulting in 18 new initiatives. Largely

PENN’S TRUSTED IT PARTNER

Information Systems& Computing

I N F O R M A T I O N S E C U R I T Y

PROTECTING PENN

Page 2: PROTECTING PENN · 2019-12-12 · stakeholders across campus participated in a multi-year project to enhance information security at Penn, resulting in 18 new initiatives. Largely

ISC’s Office of Information Security partners with Schools and Centers to implement tools and programs that protect Penn’s digital assets.

Institutional Risk ManagementCyberattacks continue to increase in number and sophistication. For this reason, information security was

recently selected by Penn’s Institutional Risk Management Committee as a critical area of focus. More than 140

stakeholders across campus participated in a multi-year project to enhance information security at Penn, resulting

in 18 new initiatives. Largely completed in 2017, that work is significantly improving Penn’s ability to identify and

protect against attacks, and to more rapidly detect, respond to, and recover from computer compromises.

Centers of ExcellenceSchools and Centers play a critical role in implementing information security at Penn. A new program, PennSec, has

been established to help manage information security consistently and comprehensively across campus. PennSec

provides a common framework and vocabulary, yet is designed to be flexible so Schools and Centers

can deliver security controls in a way that best suits their local needs.

C O M P L I M E N T A R Y I N F O R M A T I O N S E C U R I T Y S E R V I C E S A T Y O U R F I N G E R T I P S

Contact Information Security at [email protected] or (215) 898-2172 for help enrolling.

LastPass password manager

Antivirus software

Security logging

SafeDNS to block malicious URLs

Security consultations

In-person and online training

Two-step verification

Vulnerability scanning

Page 3: PROTECTING PENN · 2019-12-12 · stakeholders across campus participated in a multi-year project to enhance information security at Penn, resulting in 18 new initiatives. Largely

INFORMATION SECURITY

PROTECT

RESPOND

IDENTIFY

DETECTRECOVER

1

2

3

4

5

PROGRAMS & TOOLSDisaster

Recovery & Mission Continuity

ISC HireIT & Client Care

Incident Response Team

Information Security [email protected] or (215) 898-2172

Security & Privacy Impact Assessment (SPIA)

Critical Components

Governance & Policy

Threat Monitoring

University Firewall

Two-Step Verification

Training & Awareness

Intrusion Detection System

Security Logging Service

Vulnerability Scanning & Penetration Testing

LEARN MORE

www.isc.upenn.edu/security

Page 4: PROTECTING PENN · 2019-12-12 · stakeholders across campus participated in a multi-year project to enhance information security at Penn, resulting in 18 new initiatives. Largely

Daily PennKey Authentications

3MILL ION

Processed Automatically

OF INCIDENTS

75%

BY THE NUMBERSI N F O R M A T I O N S E C U R I T Y

A V E R A G E

MILL ION11

CRITICAL SYSTEMS Scanned For Vulnerabilities

1.2K

Monthly Events Monitored By Logging Service

6 BILLIONMalicious Website Visits Prevented

20KMONTHLY

EVERY DAY

LEARN MORE ABOUT OUR SECURITY SERVICES www.isc.upenn.edu/security

BLOCKED BY University Firewall

Monthly Attacks