1 of 15

  • Adria Snead, CyberSecurity Research Analyst
  • Damon Armour, Director of Information Security Risk & Assurance

CYBERSECURITY LIAISON PROGRAM

2 of 15

Poll Question #1:�

  • How many of you were involved in the previous Security Liaison Program?

a.) Heard about it but wasn’t involved

b.) Was involved in the program

c.) That was before my time

3 of 15

Program Purpose

  • NC State, like many other institutions of higher education, is at risk from cyber threats to its digital assets and daily operations.
  • In an effort to strengthen our cybersecurity infrastructure against security challenges, NC State leadership has charged the Security and Compliance (S&C) unit, along with campus IT partners, to implement and manage a Cybersecurity Liaison Program.
  • The program will be a network of college and unit representatives who will collaborate with S&C to defend the university against cyber threats.

We want to stop brush fires before they become a wildfire.

4 of 15

Program Mission

  • To keep the university’s digital assets secure by continuously identifying and addressing weaknesses in its cyber defenses
  • To address security incidents and compliance requirements at the college, division or unit level in coordination with S&C

5 of 15

Program Goals

  • Raise cybersecurity awareness across the university
  • Enable better collaboration on cybersecurity
  • Establish bi-directional feedback on cybersecurity
  • Improve efficiencies in cybersecurity operations
  • Ensure that both business functional and technical aspects are accounted for early and continuously
  • Foster career growth in cybersecurity for liaison members

6 of 15

Tentative Roadmap

    • Socialize
    • Gather Feedback
    • Start small

Do Now

    • Design program
    • Create Communication
    • Kick-off program

Do Next

    • Create Certifications
    • Bring in Speakers
    • Expand program

Do Later

7 of 15

  • How can we move from feeling like a lone wolf to a pack determined to make sure everyone succeeds?

TECHNOLOGY ALONE IS NOT ENOUGH

8 of 15

Poll Question #2:�

  • How many of you would be interested�in being more knowledgeable about cybersecurity threats and how they could affect you professionally and personally?

a.) Would be interested

b.) Not interested

9 of 15

Poll Question #3:�

  • How many of you are the “go-to” IT/technical person for your family?

a.) That’s Me

b.) Not Me

10 of 15

Liaison Responsibility

  • Representatives may be appointed at the department level based on the size and scope of the division or college.
  • Each representative should have basic knowledge of the business processes or information technology systems within their college or unit.
  • Basic IT security knowledge is always a plus but is not required.
  • S&C will coordinate and provide ongoing training to help liaisons develop basic security knowledge, greatly strengthening the university’s ability to defend against increasing cyber threats.
  • Liaisons are expected to commit about three hours per month to this program.

11 of 15

Liaison Duties

  • Inform local unit/department on cybersecurity issues
  • Serve as ambassador for cybersecurity compliance, policies/standards and best practices
  • Report any suspected breach/exposure of sensitive data
  • Provide unit concerns on cybersecurity matters to S&C
  • Serve as point of contact for S&C identified incidents
  • Assist with IT Purchase Compliance process
  • Raise awareness of the university’s data management regulation and framework
  • Participate in security training, briefings and events

12 of 15

Success Story

  • DASA Technologies, a Division of Academic and Student Affairs, works with Deborah Booth (S&C) on IT Purchase Compliance process. Together, we review campus system applications for new purchases or annual license renewals. In this process, Deborah handles the security review of these applications. Working with Campus Health Services which consists of Health Services and Counseling, Housing and other critical applications sometimes these requests for purchase or renewal can be sudden and need to be expedited so that these departments can continue to function seamlessly.��In these cases, Deborah has shown great tenacity and gone above and beyond to see that these reviews are done correctly and in a timely fashion all while working with me, someone that is relatively new to this process, and the university to make sure that I have all that I need as well.��— from Tremone Gilchrist

13 of 15

  • How can we move from feeling like a lone wolf to a pack determined to make sure everyone succeeds?

CREATE THE CYBERSECURITY PACK

14 of 15

Poll Question #4:�

  • How should people join the program?

a.) By appointment

b.) Volunteer

15 of 15

  • A network of designated college and department/unit representatives who collaborate to defend the university from cyber threats

Q&A

CYBERSECURITY LIAISON PROGRAM