Successfully reported this slideshow.
We use your LinkedIn profile and activity data to personalize ads and to show you more relevant ads. You can change your ad preferences anytime.



Published on

  • Be the first to comment

  • Be the first to like this


  1. 1. Research Data Protection: An Overview of the VCUeRA System Jim Ward Director of Research Information Systems Office of Research
  2. 2. What Types of Data Protection? <ul><li>Physical Protection </li></ul><ul><ul><li>Physical access and environmental controls </li></ul></ul><ul><li>Network Protection </li></ul><ul><ul><li>Network attacks and threats </li></ul></ul><ul><li>Application Protection </li></ul><ul><ul><li>Authentication and Authorization </li></ul></ul><ul><li>Hardware Protection </li></ul><ul><ul><li>Hardware failures, backups and redundancy </li></ul></ul>
  3. 3. Current Configuration <ul><li>Office of Research currently manages eleven servers </li></ul><ul><ul><li>Windows 2003 Server </li></ul></ul><ul><li>The VCUeRA production system consists of four servers </li></ul><ul><ul><li>Two Web servers </li></ul></ul><ul><ul><ul><li>IIS (Internet Information Services) 6.0 </li></ul></ul></ul><ul><ul><li>Two Database servers </li></ul></ul><ul><ul><ul><li>SQL Server 2000 </li></ul></ul></ul><ul><ul><ul><li>Database size: 95GB (24 DVDs or 132 CDs) </li></ul></ul></ul>
  4. 4. Physical Security <ul><li>Located at University Computer Center </li></ul><ul><ul><li>Building and VCU Computer Center have 24 hour security and access </li></ul></ul><ul><li>Require passwords at system console </li></ul><ul><li>Renamed administrator’s account </li></ul><ul><li>Disable guest accounts </li></ul>
  5. 5. Physical Security Cont. <ul><li>Environmental Controls </li></ul><ul><ul><li>Dedicated air conditioning and noise containment </li></ul></ul><ul><li>Dedicated Power and UPS </li></ul><ul><ul><li>All servers have redundant power supplies </li></ul></ul><ul><ul><li>Servers should be on a dedicated circuit </li></ul></ul><ul><ul><ul><li>Multiple circuits are installed at Computer Center </li></ul></ul></ul><ul><ul><li>UPS (Uninterruptable Power Supply) </li></ul></ul><ul><ul><ul><li>Computer Center has a dedicate USP for entire center </li></ul></ul></ul>
  6. 6. Network Security <ul><li>VLAN (Virtual Local Area Network) </li></ul><ul><ul><li>Server VLAN </li></ul></ul><ul><ul><li>Desktop VLAN (SECNet) </li></ul></ul><ul><ul><li>Wireless VLAN </li></ul></ul><ul><ul><li>Residence Hall VLAN </li></ul></ul>VCU Network Server VLAN Desktop VLAN Residence Hall VLAN Wireless VLAN
  7. 7. Network Security Cont. <ul><li>Firewall – defines which ports the system is allowed to use </li></ul>Only allow Web access from anywhere Only allow web access from VCU address <ul><li>Web Servers </li></ul><ul><ul><li>Only allow access to http and https ports from anywhere </li></ul></ul><ul><li>Database Servers </li></ul><ul><ul><li>Only allow access to SQL port from web server </li></ul></ul><ul><li>Implemented using two firewalls </li></ul><ul><ul><li>Network based (controlled by VCU Network Services) </li></ul></ul><ul><ul><li>Server based (installed on server and controlled by OR IT staff) </li></ul></ul>
  8. 8. Application Security <ul><li>Secure HTTP (HTTPS) </li></ul><ul><ul><li>A secure method for viewing web pages </li></ul></ul><ul><ul><li>Same technology as used by banks and other online commercial retailers </li></ul></ul><ul><ul><li>At VCU, a certificate must be issued and installed on each server yearly </li></ul></ul><ul><ul><ul><li>A certificate is issued for </li></ul></ul></ul><ul><li>Application Authentication </li></ul><ul><ul><li>Process for determining user identity </li></ul></ul><ul><ul><li>VCUeRA uses VCU eID </li></ul></ul>
  9. 9. Application Security Cont. <ul><li>Application Authorization </li></ul><ul><ul><li>Process by which user is granted access to specific area of the application </li></ul></ul><ul><ul><li>VCUeRA uses application roles </li></ul></ul><ul><ul><ul><li>Access granted to a specific department or school requires department chair or school dean approval </li></ul></ul></ul><ul><ul><ul><li>Access to a entire module requires approval from the Vice President for Research </li></ul></ul></ul>
  10. 10. Hardware Failures <ul><li>Disk Failures </li></ul><ul><ul><li>RAID </li></ul></ul><ul><ul><li>Web servers use RAID 1 </li></ul></ul><ul><ul><li>Database servers use RAID 5 with hot spare </li></ul></ul><ul><li>Sever Log Monitoring </li></ul><ul><ul><li>Software installed to monitor servers log (application, security, system log) </li></ul></ul><ul><ul><li>Sends e-mail notification when an error or warning is written to any server log </li></ul></ul><ul><li>DELL Open Manage </li></ul><ul><ul><li>Monitors server for dell specific hardware issues and writes error to server logs when error occurs </li></ul></ul>
  11. 11. Backups <ul><li>Backups of Servers </li></ul><ul><ul><li>VCU has a dedicated VLAN for backups and requires using a second dedicated network card </li></ul></ul><ul><ul><li>Perform nightly incremental backups using Computer Center’s Tivoli Storage Management </li></ul></ul><ul><li>Additional Database Backups </li></ul><ul><ul><li>A full copy of the database is created each night on the server (takes about 15 minutes) </li></ul></ul><ul><ul><li>Every 20 minutes a copy of any database changes are copied to disk </li></ul></ul><ul><ul><li>These are backed up using Tivoli </li></ul></ul>
  12. 12. Redundancy <ul><li>Website </li></ul><ul><ul><li>Two servers acting as one </li></ul></ul><ul><ul><li>If one fails, we can continue to function on other </li></ul></ul><ul><li>Database </li></ul><ul><ul><li>The files created from the changes backup are also copied to the second database server. </li></ul></ul><ul><ul><li>If a manual restore of the production database was required, it would take 8-10 hours. </li></ul></ul><ul><ul><ul><li>4-5 hours to restore the backup file from tape, plus </li></ul></ul></ul><ul><ul><ul><li>4-5 hours to restore the database </li></ul></ul></ul><ul><ul><li>Can restore in a little as 20 minutes </li></ul></ul>
  13. 13. Additional Protections <ul><li>Security Patches </li></ul><ul><ul><li>Security patches are manually installed within 1 week of release from Microsoft </li></ul></ul><ul><ul><li>Usually installed after hours </li></ul></ul><ul><li>Remote Access </li></ul><ul><ul><li>On campus, use Remote Desktop for remote administration of servers </li></ul></ul><ul><ul><li>Off campus, a VPN (Virtual Private Network) session is required for all administrative functions </li></ul></ul>
  14. 14. VCUeRA Configuration DB1 DB2 Web1 Web2 HTTP and HTTPS requests to Web1 and Web2 VPN Server Remote administration of servers Tivoli Backup Management Data Copy Firewall
  15. 15. Future Plans <ul><li>Perform yearly vulnerability scans by Technology Services </li></ul><ul><li>System Logs sent to Technology Services MARS system (Technology Services’ Monitoring, Analysis and Response System) </li></ul><ul><li>Move two servers to Computer Center’s hot site </li></ul><ul><ul><li>Second web server </li></ul></ul><ul><ul><li>Backup database server </li></ul></ul>
  16. 16. What does this mean for me? <ul><li>Data needs to be protected with numerous layers of security </li></ul><ul><li>Make backups of your data and secure them </li></ul><ul><li>If you require a server or storage space, you should contact Technology Services at </li></ul><ul><ul><li>Provide storage space </li></ul></ul><ul><ul><li>Provide server support, maintenance, and security for dedicated servers at a cost of $100 per server per month </li></ul></ul><ul><ul><li>DO NOT install a server in your office </li></ul></ul>
  17. 17. Inquisite <ul><li>Accounts are distributed to departments </li></ul><ul><li>Annual fee of $800 per year per account </li></ul><ul><li>Department assigns an account administrator </li></ul><ul><ul><li>Manage all surveys for account </li></ul></ul><ul><ul><li>Serve as primary contact for department regarding Inquisite </li></ul></ul><ul><li>Investigators can request an account separate </li></ul><ul><ul><li>Still need to designate an account administrator </li></ul></ul><ul><ul><li>Still required to pay $800 per year per account </li></ul></ul><ul><ul><li>More information can be found at </li></ul></ul>
  18. 18. QUESTIONS?