Select Page

Project Planning Team

Executive Sponsor: Anne Milkovich, CIO

Project Sponsor: Anne Milkovich, CIO

Project Managers: Victor Alatorre, Mark Clements, Laura Knaapen

Technical Team Members: Dan Petersen, Christian Beck, Eamon Bauman, Michael Brunn, Michelle Loker, Ricky Johnson, Michelle Loker

 Contact IT

  Phone: (920) 424-3020
  Email: helpdesk@uwosh.edu

Status: 9/12/19

  • We will be extending all information security compliance procedures to the access campuses.
  • Duo, multi-factor authentication rollout is being planned for October 2019 for PeopleSoft and Image Now.
  • Wired network connection of personally-owned devices is no longer permitted. Wireless connection of these devices is still available.

Information Security Compliance

UW System has provided all UW campuses with five Administrative Policies and three Procedures on Information Security. These policies and procedures are mandatory for all UW campuses. The five policies and three procedures are listed on the IT Policies web page.

During the Spring semester IT completed the Authentication procedures regarding password requirements for the university NetID account. As part of the Legislative Bureau audit, several small projects were identified for IT to work on. The projects are listed below in priority order. Additional projects may be required based on the new UW System two-year Info Security plan.

Project/PolicySemester to Start WorkStatusRecentNext
Auditing desktop computers for high risk data.Fall 2018In ProgressTechnical requirements have been metCommunicate rollout of service to campus
Move all high risk data to encrypted storage.Fall 2018In ProgressO365 is the current recommendation for storing high risk data that must be shared.Migrating all UWO accounts to O365.
Require multi-factor authentication to access high risk data.Spring 2019In ProgressTesting product and processes on IT staff.Prepare documentation, training, and campus communication.
Review all enterprise applications to document security and dependenciesSpring 2019In ProgressReview is complete.Operationalizing review of new apps. Assigning and training data stewards.
Increase offering of security awareness education.Summer 2019In ProgressSecurity is included in employee orientations.Move from Lawroom to Canvas
Bring Gmail into compliance for password policiesSummer 2019PlanningMigrating from Google to O365Move Google login to shibboleth
Auditing employee data access through formal approval and renewal procedures.Fall 2019Not StartedWaiting on UW System recommendation of tool to use for this
Desupporting local hard drive storage.Fall 2019Not Started
Shift all full-time employees who maintained their student account to the employee account scheme.Fall 2019Not Started
Provide student accounts to employees taking classesFall 2019Not Started
No longer allow physical, wired attachment of non-university devices.Summer 2019OperationalAll known personally-owned devices have been removed from DHCPCommunicate that this is policy.
Enforce mandatory security training.Spring 2018OperationalEmployees out of compliance will have their accounts lockedImprove system automation by connecting to Canvas
Student employees cannot use generic, shared accounts.Summer 2018OperationalAccount creation semi-automated.
Immediate access removal upon employee separation from university or role.Summer 2018OperationalProcess maps are set.Verify process is working appropriately.
Remove administrative rights from desktop computers.Fall 2018OperationalAdmin rights are no longer the default.Outline new request and annual renewal processes.
Teach use of account delegation so email passwords are no longer being sharedSpring 2019OperationalAll accounts were informed of need use delegation and not share passwords.Reminder will be sent to all remaining accounts.
Communicate with past emeriti to verify relationship with campus and need for accountsSpring 2019OperationalAll retirees with accounts are notified of the change in practice regarding retaining accounts.Non-emeritus accounts will be deactivated June 3, 2019.

Recent:

  • Wired network connection of personally-owned devices is no longer available. Wireless connection is still available.
  • Multi-factor authentication technology is being tested and documented for release in October 2019.

Next:

  • Extend information security policies to the Fond du Lac and Fox Cities campuses.
  • Renewal of information security training at all three campuses.