IT is aware that myBanner is currently down. ITEC was
doing maintenance early this morning and ran into an issue on their
end. They are expecting service to be restored by 10 am.
Wednesday, July 18, 2018
Tuesday, July 3, 2018
Campus Security Campaign - July 2018
It is well publicized that today's attackers are ever vigilant in their attempts to uncover weak points in networks, computers, and mobile devices to establish a foothold and leverage vulnerabilities, thus resulting in the compromise of critical assets or personal information. Areas of concern that can lead to a breach include the lack of physical security controls available at remote locations, the use of unsecured networks, and the connection of infected devices to internal networks. The challenge is especially daunting when:
- Staff, faculty, and students are accustomed to using use free public Wi-Fi hot spots, and some will use them to access institutional e-mails and documents.
- Some campus employees will e-mail work documents to and from their personal account, despite numerous security problems this creates.
- Some campus employees will use free USB charging ports available at airports and other public places. These ports pose the risk of transferring viruses and malware to unsuspecting users.
Planning for Secure Remote Access
- Assume the worst will occur and plan accordingly. Laptops and other wireless devices are prone to loss or theft. External networks not controlled by an institution are especially susceptible to compromise and data interception. Finally, remote users' devices may eventually become infected with malware.
- Develop an appropriate remote access policy. It should define what's allowable in terms of remote access. Data sensitivity is another factor to be considered, as access to confidential or sensitive information should be restricted.
- Configure remote access servers to enforce policies. Consider the placement of remote access servers at the network perimeter, so it serves as a single point of entry to the network and enforces the security policy before any remote access traffic is permitted into internal networks.
- Ensure personal devices are secured against common threats. Remote devices should receive the same security applications, software, and devices as those found on campus. They should employ antivirus software and data loss protection capabilities, whenever possible.
- Employ strong user authentication. Many external security threats will be mitigated through the deployment of multifactor authentication.
- Create a remote access policy. Users should take every reasonable precaution to ensure their remote access connections are secured from interception, eavesdropping, or misuse. To facilitate this, anyone remotely accessing campus resources for business, maintenance, or upgrade actions should use a virtual private network (VPN) provided by the institution. Also remind staff and faculty not save or store sensitive or restricted institutional data on any remote host or external computing (access) device.
Additional Requirements for System Administrators and End Users
- Apply computer and mobile device security software, applications, and operating system patches and updates regularly.
- Install and use antivirus, antispyware, and VPN software on computers, laptops, and mobile devices, keeping software definitions up-to-date and running regular scans.
- Install and enable a hardware and/or software firewall.
- Configure devices so that authentication is required (e.g., password, passphrase, token, or biometric authentication), runs in "least privilege" mode (e.g., user instead of admin), and times out after a 15-minute period of inactivity.
- Activate and use a "lock" feature prior to leaving the computing device unattended.
- Set the security settings to the highest level on Internet browsers and adjust downward as necessary for Internet use.
- At no time should a campus employee provide usernames or passwords to anyone, not even family members.
Wednesday, June 27, 2018
Banner Problem Resolved 6/27/2018
Happy to let everyone know that Banner along with Argos is now up and running--
Please contact the help desk for any other questions or concerns.
962-9555 or email helpdesk@corning-cc.edu
ITEC has released a statement that their network
services have been restored. I have checked with a few people to test
access to Banner and it is working. Please report services that are not
working.
962-9555 or email helpdesk@corning-cc.edu
Problem with Banner 6/27/2018
IT is aware that Banner is currently down. ITEC was
doing maintenance early this morning and ran into a network issue on their
end. They are working with their support to get the problem fixed as soon
as possible.
Labels:
Banner Issue
Thursday, June 21, 2018
Spam Alert - 6/21/18
If you have received an email with the title "Account Notice" or from the sender IT SERVICES please delete the email or mark as SPAM. If you clicked on the link, please change your MyCCC password. If assistance with this is needed please contact the IT Helpdesk at 607-962-9555. As a reminder, IT will never ask for your username or password.

Thank you,
CCC IT
Friday, June 8, 2018
Campus Security Campaign - June 2018
Employing good physical security practices does not have to include hiring a detachment of the queen's guard for your campus (though this might be a nice attraction for prospective students!). Instead, just getting the word out to your community about the importance of a few basic physical security tips can substantially improve your institution's security risk profile. Below are some tips to share with your community:
- Prevent tailgating. In the physical security world, tailgating is when an unauthorized person follows someone into a restricted space. Be aware of anyone attempting to slip in behind you when entering an area with restricted access.
- Don't offer piggyback rides. Like tailgating, piggybacking refers to an unauthorized person attempting to gain access to a restricted area by using social engineering techniques to convince the person with access to let them in. Confront unfamiliar faces! If you're uncomfortable confronting them, contact campus safety.
- Put that shredder to work! Make sure to shred documents with any personal, medical, financial, or other sensitive data before throwing away. Organizing campus-wide or smaller-scale shred days can be a fun way to motivate your community to properly dispose of paper waste.
- Be smart about recycling or disposing of old computers and mobile devices. Make sure to properly destroy your computer's hard drive. Use the factory reset option on your mobile devices and erase or remove SIM and SD cards.
- Lock your devices. Protecting your mobile devices and computers with a strong password or PIN provides an additional layer of protection to your data in the event of theft. Set your devices to lock after a short period of inactivity; lock your computer whenever you walk away. If possible, take your mobile devices and/or laptop with you. Don't leave them unattended, even for a minute!
- Lock those doors and drawers. Stepping out of the room? Make sure you lock any drawers containing sensitive information and/or devices and lock the door behind you.
- Encrypt sensitive information. Add an additional layer of protection to your files by using the built-in encryption tools included on your computer's operating system (e.g., BitLocker or FileVault).
- Back up, back up, back up! Keeping only one copy of important files, especially on a location such as your computer's hard drive, is a disaster waiting to happen. Make sure your files will still be accessible in case they're stolen or lost by backing them up on a regular basis to multiple secure storage solutions.
- Don't leave sensitive data in plain sight. Keeping sensitive documents or removable storage media on your desk, passwords taped to your monitor, or other sensitive information in visible locations puts the data at risk to be stolen by those who would do you or your institution harm. Keep it securely locked in your drawer when not in use.
- Put the laptop in your trunk. Need to leave your laptop or other device in your car? Lock it in your trunk (before arriving at your destination). Don't invite criminals to break your car windows by leaving it on the seat.
- Install a remote location tracking app on your mobile device and laptop. If your smartphone, tablet, or laptop is lost or stolen, applications such as Find My iPhone/iPad/Mac or Find My Device (Android) can help you to locate your devices or remotely lock and wipe them.
Thursday, May 24, 2018
Campus Security Campaign - May 2018
Your passwords are the key to a host of information about you, and potentially those close to you. If someone can access your personal information, it can have serious long-term effects—and not just online! Follow these recommendations from the World Password Day website to protect your identity while making the Internet more secure for everyone:
- Use a passphrase instead of a password. Passphrases are usually 16 characters or more and include a combination of words or short sentence that is easy to remember (e.g., MaryHadALittleLamb!)
- Use a fingerprint or biometric requirement to sign in when available. This provides an extra layer of protection for devices and apps.
- Request single-use authentication codes that can be sent to your phone or delivered by an app.
- Take advantage of whatever multifactor authentication methods are available for your service. Learn more about adding MFA to any account.
- Use a password manager or password vault software to help keep track of all your passwords and avoid password reuse.
Subscribe to:
Posts (Atom)