SlideShare a Scribd company logo
Responsible disclosure in
Higher Education
Giles Howard
Surveying Higher Education for good responsible disclosure practice
» Public-facing policies indicating a commitment or understanding of cyber
issues and the risk that they represent
» Dedicated email addresses representing a route to report cyber issues
» A brief survey of acceptable use policies or disciplinary policies to indicate the
penalties for unauthorised access to systems
» Any whistleblowing policies that might extend to students or
cyber issues specifically
» Any mention of leveraging students as assets for ‘white-hat’ hacking or any
process by which systems may be tested involving students
A holistic, qualitative approach – we were looking around other
Higher Education providers for:
23/03/2016 Responsible disclosure in Higher Education
Additional work (undertaken simultaneously)
» Bug bounties
» Whitelists of systems that can be attacked
» Leaderboards
» Guarantee of safe disclosure if flaws are reported using a defined
procedure instead of being simply publically disclosed
» Assurances that flaws reported via the defined process will be afforded
high priority
» Test accounts for performing exploitation testing without damaging
own/other accounts
Surveying industrial practice in responsible disclosure:
23/03/2016 Responsible disclosure in Higher Education
Complications
» Professional services (student services, finance, HR, etc.) could not risk
interruptions to core business due to unregulated attempts to exploit their systems
» Concerns from multiple stakeholders as to which students/staff this was going to
apply to and in particular, how the students would be vetted
» Further concerns that this may need doing at a much higher level (i.e. an
institutional policy of responsible disclosure of a variety of situations, not purely
cyber security ones)
» Not all University systems are directly managed by the IT service – reporting
out to vendors and manufacturers might take substantial time before
fixes are available
Consulting with key stakeholders within our institution resulted
in the following issues being highlighted:
23/03/2016 Responsible disclosure in Higher Education
Primary outcomes
» Utilising either the student-run cyber security society or a self-selected population
of interested students to exploit systems with some further constraints
» Usage of ‘at-risk’ periods (as are used for schedule maintenance/system upgrades
at present) outside of core business hours which would allow the systems to be
tested with little-to-no risk to business processes
» Coordination with the Chief Information Officer and others to determine systems
which both had value in being tested as well as not representing a substantial risk
in letting students make attempts to exploit them
Initial groundwork for a localised responsible disclosure process:
23/03/2016 Responsible disclosure in Higher Education
Current work
» HEA-funded project led by Federica Paci (F.M.Paci@soton.ac.uk) at University of
Southampton under the title of “Enhancing campus cyber security through
constructivist student learning”
» Work is beginning on selecting systems for the first round of penetration testing by a
group of interested students
» There is no official policy on responsible disclosure (yet!) but multiple parties are
working together on this initial activity to hopefully iron out a more structured and
policy-backed process for doing this in future
23/03/2016 Responsible disclosure in Higher Education
23/03/2016 Responsible disclosure in Higher Education
Questions?
Thank you
23/03/2016 Responsible disclosure in Higher Education
Giles Howard
University of Southampton
giles.howard@soton.ac.uk

More Related Content

What's hot

Electronic Management of Assessment
Electronic Management of AssessmentElectronic Management of Assessment
Electronic Management of Assessment
Jisc
 
Implementing analytics part 2 - Moriamo Oduyemi
Implementing analytics part 2 - Moriamo OduyemiImplementing analytics part 2 - Moriamo Oduyemi
Implementing analytics part 2 - Moriamo Oduyemi
Jisc
 
Implementing analytics - Paul Bailey and Dr Nick Moore
Implementing analytics - Paul Bailey and Dr Nick MooreImplementing analytics - Paul Bailey and Dr Nick Moore
Implementing analytics - Paul Bailey and Dr Nick Moore
Jisc
 
Leveraging change through digital capability - Lawrie Phipps, Terri Smith and...
Leveraging change through digital capability - Lawrie Phipps, Terri Smith and...Leveraging change through digital capability - Lawrie Phipps, Terri Smith and...
Leveraging change through digital capability - Lawrie Phipps, Terri Smith and...
Jisc
 
Delivering online learning: are you ready?
Delivering online learning: are you ready?Delivering online learning: are you ready?
Delivering online learning: are you ready?
Jisc
 
Making a difference with technology enhanced learning - Esther Barrett, Andre...
Making a difference with technology enhanced learning - Esther Barrett, Andre...Making a difference with technology enhanced learning - Esther Barrett, Andre...
Making a difference with technology enhanced learning - Esther Barrett, Andre...
Jisc
 
Designing and developing great courses together - Jisc Digifest 2016
Designing and developing great courses together - Jisc Digifest 2016Designing and developing great courses together - Jisc Digifest 2016
Designing and developing great courses together - Jisc Digifest 2016
Jisc
 
Student digital experience tracker 2017: summary of key findings
Student digital experience tracker 2017: summary of key findingsStudent digital experience tracker 2017: summary of key findings
Student digital experience tracker 2017: summary of key findingsJisc
 
Digital Diagnostic: identifying staff digital capabilities at Staffordshire U...
Digital Diagnostic: identifying staff digital capabilities at Staffordshire U...Digital Diagnostic: identifying staff digital capabilities at Staffordshire U...
Digital Diagnostic: identifying staff digital capabilities at Staffordshire U...
Jisc
 
Keeping learners safe online presentation
Keeping learners safe online presentationKeeping learners safe online presentation
Keeping learners safe online presentation
Jisc
 
Facilitating your registration with the Office for Students using the Jisc st...
Facilitating your registration with the Office for Students using the Jisc st...Facilitating your registration with the Office for Students using the Jisc st...
Facilitating your registration with the Office for Students using the Jisc st...
Jisc
 
YSJ and Jisc: standing on the shoulders of giants - Phil Vincent
YSJ and Jisc: standing on the shoulders of giants - Phil VincentYSJ and Jisc: standing on the shoulders of giants - Phil Vincent
YSJ and Jisc: standing on the shoulders of giants - Phil Vincent
Jisc
 
Jisc toolkit: supporting the digital experience of new students
Jisc toolkit: supporting the digital experience of new studentsJisc toolkit: supporting the digital experience of new students
Jisc toolkit: supporting the digital experience of new students
Jisc
 
Making a difference with technology-enhanced learning - Esther Barrett, Debbi...
Making a difference with technology-enhanced learning - Esther Barrett, Debbi...Making a difference with technology-enhanced learning - Esther Barrett, Debbi...
Making a difference with technology-enhanced learning - Esther Barrett, Debbi...
Jisc
 
Supporting staff to teach effectively online
Supporting staff to teach effectively onlineSupporting staff to teach effectively online
Supporting staff to teach effectively online
Jisc
 
Making a difference with technology-enhanced learning - Sarah Knight and Sara...
Making a difference with technology-enhanced learning - Sarah Knight and Sara...Making a difference with technology-enhanced learning - Sarah Knight and Sara...
Making a difference with technology-enhanced learning - Sarah Knight and Sara...
Jisc
 
Introducing professionalism as an assessed element of the nursing undergradua...
Introducing professionalism as an assessed element of the nursing undergradua...Introducing professionalism as an assessed element of the nursing undergradua...
Introducing professionalism as an assessed element of the nursing undergradua...
Jisc
 
The benefits and challenges of open access: lessons from practice - Helen Bla...
The benefits and challenges of open access: lessons from practice - Helen Bla...The benefits and challenges of open access: lessons from practice - Helen Bla...
The benefits and challenges of open access: lessons from practice - Helen Bla...
Jisc
 
Digital leadership
Digital leadershipDigital leadership
Digital leadership
Jisc
 
Student experience experts meeting
Student experience experts meetingStudent experience experts meeting
Student experience experts meeting
Jisc
 

What's hot (20)

Electronic Management of Assessment
Electronic Management of AssessmentElectronic Management of Assessment
Electronic Management of Assessment
 
Implementing analytics part 2 - Moriamo Oduyemi
Implementing analytics part 2 - Moriamo OduyemiImplementing analytics part 2 - Moriamo Oduyemi
Implementing analytics part 2 - Moriamo Oduyemi
 
Implementing analytics - Paul Bailey and Dr Nick Moore
Implementing analytics - Paul Bailey and Dr Nick MooreImplementing analytics - Paul Bailey and Dr Nick Moore
Implementing analytics - Paul Bailey and Dr Nick Moore
 
Leveraging change through digital capability - Lawrie Phipps, Terri Smith and...
Leveraging change through digital capability - Lawrie Phipps, Terri Smith and...Leveraging change through digital capability - Lawrie Phipps, Terri Smith and...
Leveraging change through digital capability - Lawrie Phipps, Terri Smith and...
 
Delivering online learning: are you ready?
Delivering online learning: are you ready?Delivering online learning: are you ready?
Delivering online learning: are you ready?
 
Making a difference with technology enhanced learning - Esther Barrett, Andre...
Making a difference with technology enhanced learning - Esther Barrett, Andre...Making a difference with technology enhanced learning - Esther Barrett, Andre...
Making a difference with technology enhanced learning - Esther Barrett, Andre...
 
Designing and developing great courses together - Jisc Digifest 2016
Designing and developing great courses together - Jisc Digifest 2016Designing and developing great courses together - Jisc Digifest 2016
Designing and developing great courses together - Jisc Digifest 2016
 
Student digital experience tracker 2017: summary of key findings
Student digital experience tracker 2017: summary of key findingsStudent digital experience tracker 2017: summary of key findings
Student digital experience tracker 2017: summary of key findings
 
Digital Diagnostic: identifying staff digital capabilities at Staffordshire U...
Digital Diagnostic: identifying staff digital capabilities at Staffordshire U...Digital Diagnostic: identifying staff digital capabilities at Staffordshire U...
Digital Diagnostic: identifying staff digital capabilities at Staffordshire U...
 
Keeping learners safe online presentation
Keeping learners safe online presentationKeeping learners safe online presentation
Keeping learners safe online presentation
 
Facilitating your registration with the Office for Students using the Jisc st...
Facilitating your registration with the Office for Students using the Jisc st...Facilitating your registration with the Office for Students using the Jisc st...
Facilitating your registration with the Office for Students using the Jisc st...
 
YSJ and Jisc: standing on the shoulders of giants - Phil Vincent
YSJ and Jisc: standing on the shoulders of giants - Phil VincentYSJ and Jisc: standing on the shoulders of giants - Phil Vincent
YSJ and Jisc: standing on the shoulders of giants - Phil Vincent
 
Jisc toolkit: supporting the digital experience of new students
Jisc toolkit: supporting the digital experience of new studentsJisc toolkit: supporting the digital experience of new students
Jisc toolkit: supporting the digital experience of new students
 
Making a difference with technology-enhanced learning - Esther Barrett, Debbi...
Making a difference with technology-enhanced learning - Esther Barrett, Debbi...Making a difference with technology-enhanced learning - Esther Barrett, Debbi...
Making a difference with technology-enhanced learning - Esther Barrett, Debbi...
 
Supporting staff to teach effectively online
Supporting staff to teach effectively onlineSupporting staff to teach effectively online
Supporting staff to teach effectively online
 
Making a difference with technology-enhanced learning - Sarah Knight and Sara...
Making a difference with technology-enhanced learning - Sarah Knight and Sara...Making a difference with technology-enhanced learning - Sarah Knight and Sara...
Making a difference with technology-enhanced learning - Sarah Knight and Sara...
 
Introducing professionalism as an assessed element of the nursing undergradua...
Introducing professionalism as an assessed element of the nursing undergradua...Introducing professionalism as an assessed element of the nursing undergradua...
Introducing professionalism as an assessed element of the nursing undergradua...
 
The benefits and challenges of open access: lessons from practice - Helen Bla...
The benefits and challenges of open access: lessons from practice - Helen Bla...The benefits and challenges of open access: lessons from practice - Helen Bla...
The benefits and challenges of open access: lessons from practice - Helen Bla...
 
Digital leadership
Digital leadershipDigital leadership
Digital leadership
 
Student experience experts meeting
Student experience experts meetingStudent experience experts meeting
Student experience experts meeting
 

Viewers also liked

IPv4 address planning - Networkshop44
IPv4 address planning - Networkshop44IPv4 address planning - Networkshop44
IPv4 address planning - Networkshop44
Jisc
 
Ipv6 deployment at the university of reading - Networkshop44
Ipv6 deployment at the university of reading - Networkshop44Ipv6 deployment at the university of reading - Networkshop44
Ipv6 deployment at the university of reading - Networkshop44
Jisc
 
SafeShare - Networkshop44
SafeShare - Networkshop44SafeShare - Networkshop44
SafeShare - Networkshop44
Jisc
 
Network engineering surgery - Networkshop44
Network engineering surgery - Networkshop44Network engineering surgery - Networkshop44
Network engineering surgery - Networkshop44
Jisc
 
Find out about Jisc - Networkshop44 2016
Find out about Jisc - Networkshop44 2016Find out about Jisc - Networkshop44 2016
Find out about Jisc - Networkshop44 2016
Jisc
 
Ipv6 deployment at the university of warwick - networkshop44
Ipv6 deployment at the university of warwick - networkshop44Ipv6 deployment at the university of warwick - networkshop44
Ipv6 deployment at the university of warwick - networkshop44
Jisc
 
Development of Jisc security programme - Networkshop44
Development of Jisc security programme - Networkshop44Development of Jisc security programme - Networkshop44
Development of Jisc security programme - Networkshop44
Jisc
 
IPv6 experience from a large enterprise - Networkshop44
IPv6 experience from a large enterprise - Networkshop44IPv6 experience from a large enterprise - Networkshop44
IPv6 experience from a large enterprise - Networkshop44
Jisc
 
Trust and identity services and architecture - Networkshop44
Trust and identity services and architecture  - Networkshop44Trust and identity services and architecture  - Networkshop44
Trust and identity services and architecture - Networkshop44
Jisc
 
IPv6 at Mythic Beasts - Networkshop44
IPv6 at Mythic Beasts - Networkshop44IPv6 at Mythic Beasts - Networkshop44
IPv6 at Mythic Beasts - Networkshop44
Jisc
 
The simplification of the campus network Juniper - Networkshop44
The simplification of the campus network Juniper - Networkshop44The simplification of the campus network Juniper - Networkshop44
The simplification of the campus network Juniper - Networkshop44
Jisc
 
Telephony developments at pirbright - Networkshop44
Telephony developments at pirbright - Networkshop44Telephony developments at pirbright - Networkshop44
Telephony developments at pirbright - Networkshop44
Jisc
 
Data networking at UCL - Networkshop44
Data networking at UCL - Networkshop44Data networking at UCL - Networkshop44
Data networking at UCL - Networkshop44
Jisc
 
Session initiation protocol (sip) the force awakens in the Janet network comm...
Session initiation protocol (sip) the force awakens in the Janet network comm...Session initiation protocol (sip) the force awakens in the Janet network comm...
Session initiation protocol (sip) the force awakens in the Janet network comm...
Jisc
 
Handling vulnerability reports - Networkshop44
Handling vulnerability reports - Networkshop44Handling vulnerability reports - Networkshop44
Handling vulnerability reports - Networkshop44
Jisc
 
Data centre networking at the University of Bristol - Networkshop44
Data centre networking at the University of Bristol  - Networkshop44Data centre networking at the University of Bristol  - Networkshop44
Data centre networking at the University of Bristol - Networkshop44
Jisc
 
IPv6 deployment status - Networkshop44
IPv6 deployment status - Networkshop44IPv6 deployment status - Networkshop44
IPv6 deployment status - Networkshop44
Jisc
 
Vscene - Networkshop44
Vscene - Networkshop44Vscene - Networkshop44
Vscene - Networkshop44
Jisc
 
Data centre networking at London School of Economics and Political Science - ...
Data centre networking at London School of Economics and Political Science - ...Data centre networking at London School of Economics and Political Science - ...
Data centre networking at London School of Economics and Political Science - ...
Jisc
 
Software defined networking - huawei - Networkshop44
Software defined networking -  huawei - Networkshop44Software defined networking -  huawei - Networkshop44
Software defined networking - huawei - Networkshop44
Jisc
 

Viewers also liked (20)

IPv4 address planning - Networkshop44
IPv4 address planning - Networkshop44IPv4 address planning - Networkshop44
IPv4 address planning - Networkshop44
 
Ipv6 deployment at the university of reading - Networkshop44
Ipv6 deployment at the university of reading - Networkshop44Ipv6 deployment at the university of reading - Networkshop44
Ipv6 deployment at the university of reading - Networkshop44
 
SafeShare - Networkshop44
SafeShare - Networkshop44SafeShare - Networkshop44
SafeShare - Networkshop44
 
Network engineering surgery - Networkshop44
Network engineering surgery - Networkshop44Network engineering surgery - Networkshop44
Network engineering surgery - Networkshop44
 
Find out about Jisc - Networkshop44 2016
Find out about Jisc - Networkshop44 2016Find out about Jisc - Networkshop44 2016
Find out about Jisc - Networkshop44 2016
 
Ipv6 deployment at the university of warwick - networkshop44
Ipv6 deployment at the university of warwick - networkshop44Ipv6 deployment at the university of warwick - networkshop44
Ipv6 deployment at the university of warwick - networkshop44
 
Development of Jisc security programme - Networkshop44
Development of Jisc security programme - Networkshop44Development of Jisc security programme - Networkshop44
Development of Jisc security programme - Networkshop44
 
IPv6 experience from a large enterprise - Networkshop44
IPv6 experience from a large enterprise - Networkshop44IPv6 experience from a large enterprise - Networkshop44
IPv6 experience from a large enterprise - Networkshop44
 
Trust and identity services and architecture - Networkshop44
Trust and identity services and architecture  - Networkshop44Trust and identity services and architecture  - Networkshop44
Trust and identity services and architecture - Networkshop44
 
IPv6 at Mythic Beasts - Networkshop44
IPv6 at Mythic Beasts - Networkshop44IPv6 at Mythic Beasts - Networkshop44
IPv6 at Mythic Beasts - Networkshop44
 
The simplification of the campus network Juniper - Networkshop44
The simplification of the campus network Juniper - Networkshop44The simplification of the campus network Juniper - Networkshop44
The simplification of the campus network Juniper - Networkshop44
 
Telephony developments at pirbright - Networkshop44
Telephony developments at pirbright - Networkshop44Telephony developments at pirbright - Networkshop44
Telephony developments at pirbright - Networkshop44
 
Data networking at UCL - Networkshop44
Data networking at UCL - Networkshop44Data networking at UCL - Networkshop44
Data networking at UCL - Networkshop44
 
Session initiation protocol (sip) the force awakens in the Janet network comm...
Session initiation protocol (sip) the force awakens in the Janet network comm...Session initiation protocol (sip) the force awakens in the Janet network comm...
Session initiation protocol (sip) the force awakens in the Janet network comm...
 
Handling vulnerability reports - Networkshop44
Handling vulnerability reports - Networkshop44Handling vulnerability reports - Networkshop44
Handling vulnerability reports - Networkshop44
 
Data centre networking at the University of Bristol - Networkshop44
Data centre networking at the University of Bristol  - Networkshop44Data centre networking at the University of Bristol  - Networkshop44
Data centre networking at the University of Bristol - Networkshop44
 
IPv6 deployment status - Networkshop44
IPv6 deployment status - Networkshop44IPv6 deployment status - Networkshop44
IPv6 deployment status - Networkshop44
 
Vscene - Networkshop44
Vscene - Networkshop44Vscene - Networkshop44
Vscene - Networkshop44
 
Data centre networking at London School of Economics and Political Science - ...
Data centre networking at London School of Economics and Political Science - ...Data centre networking at London School of Economics and Political Science - ...
Data centre networking at London School of Economics and Political Science - ...
 
Software defined networking - huawei - Networkshop44
Software defined networking -  huawei - Networkshop44Software defined networking -  huawei - Networkshop44
Software defined networking - huawei - Networkshop44
 

Similar to Finding vulnerabilities - networkshop44

Jisc's FE and skills strategic priorities and opportunities to get involved
Jisc's FE and skills strategic priorities and opportunities to get involvedJisc's FE and skills strategic priorities and opportunities to get involved
Jisc's FE and skills strategic priorities and opportunities to get involved
Jisc
 
Right Here; Right Now: Providing the Information your Students Need and your...
Right Here; Right Now: Providing the Information your Students Need and your...Right Here; Right Now: Providing the Information your Students Need and your...
Right Here; Right Now: Providing the Information your Students Need and your...
Marieke Guy
 
Avoiding Invasive Surveillance, Ensuring Trust: ENSURING TRUST UNED’S AvEx
Avoiding Invasive Surveillance, Ensuring Trust: ENSURING TRUST UNED’S AvExAvoiding Invasive Surveillance, Ensuring Trust: ENSURING TRUST UNED’S AvEx
Avoiding Invasive Surveillance, Ensuring Trust: ENSURING TRUST UNED’S AvEx
EADTU
 
PreventionMitigation_Philadelphia_Breakout.ppt
PreventionMitigation_Philadelphia_Breakout.pptPreventionMitigation_Philadelphia_Breakout.ppt
PreventionMitigation_Philadelphia_Breakout.ppt
JessaEraldinOrigines
 
introduction of data structure and design and analysis of algorithm
introduction of data structure and design and analysis of algorithmintroduction of data structure and design and analysis of algorithm
introduction of data structure and design and analysis of algorithm
YerosanTafesse
 
introduction of data structure and design and analysis of algorithm
introduction of data structure and design and analysis of algorithmintroduction of data structure and design and analysis of algorithm
introduction of data structure and design and analysis of algorithm
YerosanTafesse
 
Slides - Leveraging institutional open practices to promote access- AVU Confe...
Slides - Leveraging institutional open practices to promote access- AVU Confe...Slides - Leveraging institutional open practices to promote access- AVU Confe...
Slides - Leveraging institutional open practices to promote access- AVU Confe...
Kathleen Ludewig Omollo
 
Access denied? Managing access to the Web within the NHS in England: technolo...
Access denied? Managing access to the Web within the NHS in England: technolo...Access denied? Managing access to the Web within the NHS in England: technolo...
Access denied? Managing access to the Web within the NHS in England: technolo...
Catherine Ebenezer
 
METRAC's Campus Safety Audit Process
METRAC's Campus Safety Audit ProcessMETRAC's Campus Safety Audit Process
METRAC's Campus Safety Audit Process
METRAC
 
Are you really ready to roll out learning analytics across your entire instit...
Are you really ready to roll out learning analytics across your entire instit...Are you really ready to roll out learning analytics across your entire instit...
Are you really ready to roll out learning analytics across your entire instit...
Jisc
 
What data from 3 million learners can tell us about effective course design
What data from 3 million learners can tell us about effective course designWhat data from 3 million learners can tell us about effective course design
What data from 3 million learners can tell us about effective course design
John Whitmer, Ed.D.
 
Kuali - Building a Community (KDUK14)
Kuali - Building a Community (KDUK14)Kuali - Building a Community (KDUK14)
Kuali - Building a Community (KDUK14)
Martin Hamilton
 
Information security at University of East London: the benefits (and pitfalls...
Information security at University of East London: the benefits (and pitfalls...Information security at University of East London: the benefits (and pitfalls...
Information security at University of East London: the benefits (and pitfalls...
Jisc
 
Blue Futuristic Illustrative Artificial Intelligence Project Presentation.pdf
Blue Futuristic Illustrative Artificial Intelligence Project Presentation.pdfBlue Futuristic Illustrative Artificial Intelligence Project Presentation.pdf
Blue Futuristic Illustrative Artificial Intelligence Project Presentation.pdf
erickamangaring25
 
OLI Findings and Innovations Panel
OLI Findings and Innovations PanelOLI Findings and Innovations Panel
OLI Findings and Innovations PanelBill Jerome
 
Privacy & Ethical Impact Assessment Workshop_RAMSES Project
Privacy & Ethical Impact Assessment Workshop_RAMSES ProjectPrivacy & Ethical Impact Assessment Workshop_RAMSES Project
Privacy & Ethical Impact Assessment Workshop_RAMSES Project
Trilateral Research
 
A Review On Recommender Systems For University Admissions
A Review On Recommender Systems For University AdmissionsA Review On Recommender Systems For University Admissions
A Review On Recommender Systems For University Admissions
Becky Gilbert
 
Ivins, "E-Learning Systems and Content"
Ivins, "E-Learning Systems and Content"Ivins, "E-Learning Systems and Content"
Ivins, "E-Learning Systems and Content"
National Information Standards Organization (NISO)
 
Rcademy pitch 2012
Rcademy pitch 2012Rcademy pitch 2012
Rcademy pitch 2012
Jonathan Cornelissen
 

Similar to Finding vulnerabilities - networkshop44 (20)

Jisc's FE and skills strategic priorities and opportunities to get involved
Jisc's FE and skills strategic priorities and opportunities to get involvedJisc's FE and skills strategic priorities and opportunities to get involved
Jisc's FE and skills strategic priorities and opportunities to get involved
 
Right Here; Right Now: Providing the Information your Students Need and your...
Right Here; Right Now: Providing the Information your Students Need and your...Right Here; Right Now: Providing the Information your Students Need and your...
Right Here; Right Now: Providing the Information your Students Need and your...
 
Avoiding Invasive Surveillance, Ensuring Trust: ENSURING TRUST UNED’S AvEx
Avoiding Invasive Surveillance, Ensuring Trust: ENSURING TRUST UNED’S AvExAvoiding Invasive Surveillance, Ensuring Trust: ENSURING TRUST UNED’S AvEx
Avoiding Invasive Surveillance, Ensuring Trust: ENSURING TRUST UNED’S AvEx
 
PreventionMitigation_Philadelphia_Breakout.ppt
PreventionMitigation_Philadelphia_Breakout.pptPreventionMitigation_Philadelphia_Breakout.ppt
PreventionMitigation_Philadelphia_Breakout.ppt
 
Digital Proctor Whitepaper #1
Digital Proctor Whitepaper #1Digital Proctor Whitepaper #1
Digital Proctor Whitepaper #1
 
introduction of data structure and design and analysis of algorithm
introduction of data structure and design and analysis of algorithmintroduction of data structure and design and analysis of algorithm
introduction of data structure and design and analysis of algorithm
 
introduction of data structure and design and analysis of algorithm
introduction of data structure and design and analysis of algorithmintroduction of data structure and design and analysis of algorithm
introduction of data structure and design and analysis of algorithm
 
Slides - Leveraging institutional open practices to promote access- AVU Confe...
Slides - Leveraging institutional open practices to promote access- AVU Confe...Slides - Leveraging institutional open practices to promote access- AVU Confe...
Slides - Leveraging institutional open practices to promote access- AVU Confe...
 
Access denied? Managing access to the Web within the NHS in England: technolo...
Access denied? Managing access to the Web within the NHS in England: technolo...Access denied? Managing access to the Web within the NHS in England: technolo...
Access denied? Managing access to the Web within the NHS in England: technolo...
 
METRAC's Campus Safety Audit Process
METRAC's Campus Safety Audit ProcessMETRAC's Campus Safety Audit Process
METRAC's Campus Safety Audit Process
 
Are you really ready to roll out learning analytics across your entire instit...
Are you really ready to roll out learning analytics across your entire instit...Are you really ready to roll out learning analytics across your entire instit...
Are you really ready to roll out learning analytics across your entire instit...
 
What data from 3 million learners can tell us about effective course design
What data from 3 million learners can tell us about effective course designWhat data from 3 million learners can tell us about effective course design
What data from 3 million learners can tell us about effective course design
 
Kuali - Building a Community (KDUK14)
Kuali - Building a Community (KDUK14)Kuali - Building a Community (KDUK14)
Kuali - Building a Community (KDUK14)
 
Information security at University of East London: the benefits (and pitfalls...
Information security at University of East London: the benefits (and pitfalls...Information security at University of East London: the benefits (and pitfalls...
Information security at University of East London: the benefits (and pitfalls...
 
Blue Futuristic Illustrative Artificial Intelligence Project Presentation.pdf
Blue Futuristic Illustrative Artificial Intelligence Project Presentation.pdfBlue Futuristic Illustrative Artificial Intelligence Project Presentation.pdf
Blue Futuristic Illustrative Artificial Intelligence Project Presentation.pdf
 
OLI Findings and Innovations Panel
OLI Findings and Innovations PanelOLI Findings and Innovations Panel
OLI Findings and Innovations Panel
 
Privacy & Ethical Impact Assessment Workshop_RAMSES Project
Privacy & Ethical Impact Assessment Workshop_RAMSES ProjectPrivacy & Ethical Impact Assessment Workshop_RAMSES Project
Privacy & Ethical Impact Assessment Workshop_RAMSES Project
 
A Review On Recommender Systems For University Admissions
A Review On Recommender Systems For University AdmissionsA Review On Recommender Systems For University Admissions
A Review On Recommender Systems For University Admissions
 
Ivins, "E-Learning Systems and Content"
Ivins, "E-Learning Systems and Content"Ivins, "E-Learning Systems and Content"
Ivins, "E-Learning Systems and Content"
 
Rcademy pitch 2012
Rcademy pitch 2012Rcademy pitch 2012
Rcademy pitch 2012
 

More from Jisc

Adobe Express Engagement Webinar (Delegate).pptx
Adobe Express Engagement Webinar (Delegate).pptxAdobe Express Engagement Webinar (Delegate).pptx
Adobe Express Engagement Webinar (Delegate).pptx
Jisc
 
How libraries can support authors with open access requirements for UKRI fund...
How libraries can support authors with open access requirements for UKRI fund...How libraries can support authors with open access requirements for UKRI fund...
How libraries can support authors with open access requirements for UKRI fund...
Jisc
 
Supporting (UKRI) OA monographs at Salford.pptx
Supporting (UKRI) OA monographs at Salford.pptxSupporting (UKRI) OA monographs at Salford.pptx
Supporting (UKRI) OA monographs at Salford.pptx
Jisc
 
The approach at University of Liverpool.pptx
The approach at University of Liverpool.pptxThe approach at University of Liverpool.pptx
The approach at University of Liverpool.pptx
Jisc
 
Jisc's value to HE: the University of Sheffield
Jisc's value to HE: the University of SheffieldJisc's value to HE: the University of Sheffield
Jisc's value to HE: the University of Sheffield
Jisc
 
Towards a code of practice for AI in AT.pptx
Towards a code of practice for AI in AT.pptxTowards a code of practice for AI in AT.pptx
Towards a code of practice for AI in AT.pptx
Jisc
 
Jamworks pilot and AI at Jisc (20/03/2024)
Jamworks pilot and AI at Jisc (20/03/2024)Jamworks pilot and AI at Jisc (20/03/2024)
Jamworks pilot and AI at Jisc (20/03/2024)
Jisc
 
Wellbeing inclusion and digital dystopias.pptx
Wellbeing inclusion and digital dystopias.pptxWellbeing inclusion and digital dystopias.pptx
Wellbeing inclusion and digital dystopias.pptx
Jisc
 
Accessible Digital Futures project (20/03/2024)
Accessible Digital Futures project (20/03/2024)Accessible Digital Futures project (20/03/2024)
Accessible Digital Futures project (20/03/2024)
Jisc
 
Procuring digital preservation CAN be quick and painless with our new dynamic...
Procuring digital preservation CAN be quick and painless with our new dynamic...Procuring digital preservation CAN be quick and painless with our new dynamic...
Procuring digital preservation CAN be quick and painless with our new dynamic...
Jisc
 
International students’ digital experience: understanding and mitigating the ...
International students’ digital experience: understanding and mitigating the ...International students’ digital experience: understanding and mitigating the ...
International students’ digital experience: understanding and mitigating the ...
Jisc
 
Digital Storytelling Community Launch!.pptx
Digital Storytelling Community Launch!.pptxDigital Storytelling Community Launch!.pptx
Digital Storytelling Community Launch!.pptx
Jisc
 
Open Access book publishing understanding your options (1).pptx
Open Access book publishing understanding your options (1).pptxOpen Access book publishing understanding your options (1).pptx
Open Access book publishing understanding your options (1).pptx
Jisc
 
Scottish Universities Press supporting authors with requirements for open acc...
Scottish Universities Press supporting authors with requirements for open acc...Scottish Universities Press supporting authors with requirements for open acc...
Scottish Universities Press supporting authors with requirements for open acc...
Jisc
 
How Bloomsbury is supporting authors with UKRI long-form open access requirem...
How Bloomsbury is supporting authors with UKRI long-form open access requirem...How Bloomsbury is supporting authors with UKRI long-form open access requirem...
How Bloomsbury is supporting authors with UKRI long-form open access requirem...
Jisc
 
Jisc Northern Ireland Strategy Forum 2023
Jisc Northern Ireland Strategy Forum 2023Jisc Northern Ireland Strategy Forum 2023
Jisc Northern Ireland Strategy Forum 2023
Jisc
 
Jisc Scotland Strategy Forum 2023
Jisc Scotland Strategy Forum 2023Jisc Scotland Strategy Forum 2023
Jisc Scotland Strategy Forum 2023
Jisc
 
Jisc stakeholder strategic update 2023
Jisc stakeholder strategic update 2023Jisc stakeholder strategic update 2023
Jisc stakeholder strategic update 2023
Jisc
 
JISC Presentation.pptx
JISC Presentation.pptxJISC Presentation.pptx
JISC Presentation.pptx
Jisc
 
Community-led Open Access Publishing webinar.pptx
Community-led Open Access Publishing webinar.pptxCommunity-led Open Access Publishing webinar.pptx
Community-led Open Access Publishing webinar.pptx
Jisc
 

More from Jisc (20)

Adobe Express Engagement Webinar (Delegate).pptx
Adobe Express Engagement Webinar (Delegate).pptxAdobe Express Engagement Webinar (Delegate).pptx
Adobe Express Engagement Webinar (Delegate).pptx
 
How libraries can support authors with open access requirements for UKRI fund...
How libraries can support authors with open access requirements for UKRI fund...How libraries can support authors with open access requirements for UKRI fund...
How libraries can support authors with open access requirements for UKRI fund...
 
Supporting (UKRI) OA monographs at Salford.pptx
Supporting (UKRI) OA monographs at Salford.pptxSupporting (UKRI) OA monographs at Salford.pptx
Supporting (UKRI) OA monographs at Salford.pptx
 
The approach at University of Liverpool.pptx
The approach at University of Liverpool.pptxThe approach at University of Liverpool.pptx
The approach at University of Liverpool.pptx
 
Jisc's value to HE: the University of Sheffield
Jisc's value to HE: the University of SheffieldJisc's value to HE: the University of Sheffield
Jisc's value to HE: the University of Sheffield
 
Towards a code of practice for AI in AT.pptx
Towards a code of practice for AI in AT.pptxTowards a code of practice for AI in AT.pptx
Towards a code of practice for AI in AT.pptx
 
Jamworks pilot and AI at Jisc (20/03/2024)
Jamworks pilot and AI at Jisc (20/03/2024)Jamworks pilot and AI at Jisc (20/03/2024)
Jamworks pilot and AI at Jisc (20/03/2024)
 
Wellbeing inclusion and digital dystopias.pptx
Wellbeing inclusion and digital dystopias.pptxWellbeing inclusion and digital dystopias.pptx
Wellbeing inclusion and digital dystopias.pptx
 
Accessible Digital Futures project (20/03/2024)
Accessible Digital Futures project (20/03/2024)Accessible Digital Futures project (20/03/2024)
Accessible Digital Futures project (20/03/2024)
 
Procuring digital preservation CAN be quick and painless with our new dynamic...
Procuring digital preservation CAN be quick and painless with our new dynamic...Procuring digital preservation CAN be quick and painless with our new dynamic...
Procuring digital preservation CAN be quick and painless with our new dynamic...
 
International students’ digital experience: understanding and mitigating the ...
International students’ digital experience: understanding and mitigating the ...International students’ digital experience: understanding and mitigating the ...
International students’ digital experience: understanding and mitigating the ...
 
Digital Storytelling Community Launch!.pptx
Digital Storytelling Community Launch!.pptxDigital Storytelling Community Launch!.pptx
Digital Storytelling Community Launch!.pptx
 
Open Access book publishing understanding your options (1).pptx
Open Access book publishing understanding your options (1).pptxOpen Access book publishing understanding your options (1).pptx
Open Access book publishing understanding your options (1).pptx
 
Scottish Universities Press supporting authors with requirements for open acc...
Scottish Universities Press supporting authors with requirements for open acc...Scottish Universities Press supporting authors with requirements for open acc...
Scottish Universities Press supporting authors with requirements for open acc...
 
How Bloomsbury is supporting authors with UKRI long-form open access requirem...
How Bloomsbury is supporting authors with UKRI long-form open access requirem...How Bloomsbury is supporting authors with UKRI long-form open access requirem...
How Bloomsbury is supporting authors with UKRI long-form open access requirem...
 
Jisc Northern Ireland Strategy Forum 2023
Jisc Northern Ireland Strategy Forum 2023Jisc Northern Ireland Strategy Forum 2023
Jisc Northern Ireland Strategy Forum 2023
 
Jisc Scotland Strategy Forum 2023
Jisc Scotland Strategy Forum 2023Jisc Scotland Strategy Forum 2023
Jisc Scotland Strategy Forum 2023
 
Jisc stakeholder strategic update 2023
Jisc stakeholder strategic update 2023Jisc stakeholder strategic update 2023
Jisc stakeholder strategic update 2023
 
JISC Presentation.pptx
JISC Presentation.pptxJISC Presentation.pptx
JISC Presentation.pptx
 
Community-led Open Access Publishing webinar.pptx
Community-led Open Access Publishing webinar.pptxCommunity-led Open Access Publishing webinar.pptx
Community-led Open Access Publishing webinar.pptx
 

Recently uploaded

Unit 8 - Information and Communication Technology (Paper I).pdf
Unit 8 - Information and Communication Technology (Paper I).pdfUnit 8 - Information and Communication Technology (Paper I).pdf
Unit 8 - Information and Communication Technology (Paper I).pdf
Thiyagu K
 
Francesca Gottschalk - How can education support child empowerment.pptx
Francesca Gottschalk - How can education support child empowerment.pptxFrancesca Gottschalk - How can education support child empowerment.pptx
Francesca Gottschalk - How can education support child empowerment.pptx
EduSkills OECD
 
Thesis Statement for students diagnonsed withADHD.ppt
Thesis Statement for students diagnonsed withADHD.pptThesis Statement for students diagnonsed withADHD.ppt
Thesis Statement for students diagnonsed withADHD.ppt
EverAndrsGuerraGuerr
 
The basics of sentences session 5pptx.pptx
The basics of sentences session 5pptx.pptxThe basics of sentences session 5pptx.pptx
The basics of sentences session 5pptx.pptx
heathfieldcps1
 
Guidance_and_Counselling.pdf B.Ed. 4th Semester
Guidance_and_Counselling.pdf B.Ed. 4th SemesterGuidance_and_Counselling.pdf B.Ed. 4th Semester
Guidance_and_Counselling.pdf B.Ed. 4th Semester
Atul Kumar Singh
 
The Roman Empire A Historical Colossus.pdf
The Roman Empire A Historical Colossus.pdfThe Roman Empire A Historical Colossus.pdf
The Roman Empire A Historical Colossus.pdf
kaushalkr1407
 
Lapbook sobre os Regimes Totalitários.pdf
Lapbook sobre os Regimes Totalitários.pdfLapbook sobre os Regimes Totalitários.pdf
Lapbook sobre os Regimes Totalitários.pdf
Jean Carlos Nunes Paixão
 
CACJapan - GROUP Presentation 1- Wk 4.pdf
CACJapan - GROUP Presentation 1- Wk 4.pdfCACJapan - GROUP Presentation 1- Wk 4.pdf
CACJapan - GROUP Presentation 1- Wk 4.pdf
camakaiclarkmusic
 
Honest Reviews of Tim Han LMA Course Program.pptx
Honest Reviews of Tim Han LMA Course Program.pptxHonest Reviews of Tim Han LMA Course Program.pptx
Honest Reviews of Tim Han LMA Course Program.pptx
timhan337
 
Introduction to AI for Nonprofits with Tapp Network
Introduction to AI for Nonprofits with Tapp NetworkIntroduction to AI for Nonprofits with Tapp Network
Introduction to AI for Nonprofits with Tapp Network
TechSoup
 
Overview on Edible Vaccine: Pros & Cons with Mechanism
Overview on Edible Vaccine: Pros & Cons with MechanismOverview on Edible Vaccine: Pros & Cons with Mechanism
Overview on Edible Vaccine: Pros & Cons with Mechanism
DeeptiGupta154
 
The French Revolution Class 9 Study Material pdf free download
The French Revolution Class 9 Study Material pdf free downloadThe French Revolution Class 9 Study Material pdf free download
The French Revolution Class 9 Study Material pdf free download
Vivekanand Anglo Vedic Academy
 
The Challenger.pdf DNHS Official Publication
The Challenger.pdf DNHS Official PublicationThe Challenger.pdf DNHS Official Publication
The Challenger.pdf DNHS Official Publication
Delapenabediema
 
The geography of Taylor Swift - some ideas
The geography of Taylor Swift - some ideasThe geography of Taylor Swift - some ideas
The geography of Taylor Swift - some ideas
GeoBlogs
 
Polish students' mobility in the Czech Republic
Polish students' mobility in the Czech RepublicPolish students' mobility in the Czech Republic
Polish students' mobility in the Czech Republic
Anna Sz.
 
Operation Blue Star - Saka Neela Tara
Operation Blue Star   -  Saka Neela TaraOperation Blue Star   -  Saka Neela Tara
Operation Blue Star - Saka Neela Tara
Balvir Singh
 
aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa
aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa
aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa
siemaillard
 
June 3, 2024 Anti-Semitism Letter Sent to MIT President Kornbluth and MIT Cor...
June 3, 2024 Anti-Semitism Letter Sent to MIT President Kornbluth and MIT Cor...June 3, 2024 Anti-Semitism Letter Sent to MIT President Kornbluth and MIT Cor...
June 3, 2024 Anti-Semitism Letter Sent to MIT President Kornbluth and MIT Cor...
Levi Shapiro
 
Synthetic Fiber Construction in lab .pptx
Synthetic Fiber Construction in lab .pptxSynthetic Fiber Construction in lab .pptx
Synthetic Fiber Construction in lab .pptx
Pavel ( NSTU)
 
The Accursed House by Émile Gaboriau.pptx
The Accursed House by Émile Gaboriau.pptxThe Accursed House by Émile Gaboriau.pptx
The Accursed House by Émile Gaboriau.pptx
DhatriParmar
 

Recently uploaded (20)

Unit 8 - Information and Communication Technology (Paper I).pdf
Unit 8 - Information and Communication Technology (Paper I).pdfUnit 8 - Information and Communication Technology (Paper I).pdf
Unit 8 - Information and Communication Technology (Paper I).pdf
 
Francesca Gottschalk - How can education support child empowerment.pptx
Francesca Gottschalk - How can education support child empowerment.pptxFrancesca Gottschalk - How can education support child empowerment.pptx
Francesca Gottschalk - How can education support child empowerment.pptx
 
Thesis Statement for students diagnonsed withADHD.ppt
Thesis Statement for students diagnonsed withADHD.pptThesis Statement for students diagnonsed withADHD.ppt
Thesis Statement for students diagnonsed withADHD.ppt
 
The basics of sentences session 5pptx.pptx
The basics of sentences session 5pptx.pptxThe basics of sentences session 5pptx.pptx
The basics of sentences session 5pptx.pptx
 
Guidance_and_Counselling.pdf B.Ed. 4th Semester
Guidance_and_Counselling.pdf B.Ed. 4th SemesterGuidance_and_Counselling.pdf B.Ed. 4th Semester
Guidance_and_Counselling.pdf B.Ed. 4th Semester
 
The Roman Empire A Historical Colossus.pdf
The Roman Empire A Historical Colossus.pdfThe Roman Empire A Historical Colossus.pdf
The Roman Empire A Historical Colossus.pdf
 
Lapbook sobre os Regimes Totalitários.pdf
Lapbook sobre os Regimes Totalitários.pdfLapbook sobre os Regimes Totalitários.pdf
Lapbook sobre os Regimes Totalitários.pdf
 
CACJapan - GROUP Presentation 1- Wk 4.pdf
CACJapan - GROUP Presentation 1- Wk 4.pdfCACJapan - GROUP Presentation 1- Wk 4.pdf
CACJapan - GROUP Presentation 1- Wk 4.pdf
 
Honest Reviews of Tim Han LMA Course Program.pptx
Honest Reviews of Tim Han LMA Course Program.pptxHonest Reviews of Tim Han LMA Course Program.pptx
Honest Reviews of Tim Han LMA Course Program.pptx
 
Introduction to AI for Nonprofits with Tapp Network
Introduction to AI for Nonprofits with Tapp NetworkIntroduction to AI for Nonprofits with Tapp Network
Introduction to AI for Nonprofits with Tapp Network
 
Overview on Edible Vaccine: Pros & Cons with Mechanism
Overview on Edible Vaccine: Pros & Cons with MechanismOverview on Edible Vaccine: Pros & Cons with Mechanism
Overview on Edible Vaccine: Pros & Cons with Mechanism
 
The French Revolution Class 9 Study Material pdf free download
The French Revolution Class 9 Study Material pdf free downloadThe French Revolution Class 9 Study Material pdf free download
The French Revolution Class 9 Study Material pdf free download
 
The Challenger.pdf DNHS Official Publication
The Challenger.pdf DNHS Official PublicationThe Challenger.pdf DNHS Official Publication
The Challenger.pdf DNHS Official Publication
 
The geography of Taylor Swift - some ideas
The geography of Taylor Swift - some ideasThe geography of Taylor Swift - some ideas
The geography of Taylor Swift - some ideas
 
Polish students' mobility in the Czech Republic
Polish students' mobility in the Czech RepublicPolish students' mobility in the Czech Republic
Polish students' mobility in the Czech Republic
 
Operation Blue Star - Saka Neela Tara
Operation Blue Star   -  Saka Neela TaraOperation Blue Star   -  Saka Neela Tara
Operation Blue Star - Saka Neela Tara
 
aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa
aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa
aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa
 
June 3, 2024 Anti-Semitism Letter Sent to MIT President Kornbluth and MIT Cor...
June 3, 2024 Anti-Semitism Letter Sent to MIT President Kornbluth and MIT Cor...June 3, 2024 Anti-Semitism Letter Sent to MIT President Kornbluth and MIT Cor...
June 3, 2024 Anti-Semitism Letter Sent to MIT President Kornbluth and MIT Cor...
 
Synthetic Fiber Construction in lab .pptx
Synthetic Fiber Construction in lab .pptxSynthetic Fiber Construction in lab .pptx
Synthetic Fiber Construction in lab .pptx
 
The Accursed House by Émile Gaboriau.pptx
The Accursed House by Émile Gaboriau.pptxThe Accursed House by Émile Gaboriau.pptx
The Accursed House by Émile Gaboriau.pptx
 

Finding vulnerabilities - networkshop44

  • 1. Responsible disclosure in Higher Education Giles Howard
  • 2. Surveying Higher Education for good responsible disclosure practice » Public-facing policies indicating a commitment or understanding of cyber issues and the risk that they represent » Dedicated email addresses representing a route to report cyber issues » A brief survey of acceptable use policies or disciplinary policies to indicate the penalties for unauthorised access to systems » Any whistleblowing policies that might extend to students or cyber issues specifically » Any mention of leveraging students as assets for ‘white-hat’ hacking or any process by which systems may be tested involving students A holistic, qualitative approach – we were looking around other Higher Education providers for: 23/03/2016 Responsible disclosure in Higher Education
  • 3. Additional work (undertaken simultaneously) » Bug bounties » Whitelists of systems that can be attacked » Leaderboards » Guarantee of safe disclosure if flaws are reported using a defined procedure instead of being simply publically disclosed » Assurances that flaws reported via the defined process will be afforded high priority » Test accounts for performing exploitation testing without damaging own/other accounts Surveying industrial practice in responsible disclosure: 23/03/2016 Responsible disclosure in Higher Education
  • 4. Complications » Professional services (student services, finance, HR, etc.) could not risk interruptions to core business due to unregulated attempts to exploit their systems » Concerns from multiple stakeholders as to which students/staff this was going to apply to and in particular, how the students would be vetted » Further concerns that this may need doing at a much higher level (i.e. an institutional policy of responsible disclosure of a variety of situations, not purely cyber security ones) » Not all University systems are directly managed by the IT service – reporting out to vendors and manufacturers might take substantial time before fixes are available Consulting with key stakeholders within our institution resulted in the following issues being highlighted: 23/03/2016 Responsible disclosure in Higher Education
  • 5. Primary outcomes » Utilising either the student-run cyber security society or a self-selected population of interested students to exploit systems with some further constraints » Usage of ‘at-risk’ periods (as are used for schedule maintenance/system upgrades at present) outside of core business hours which would allow the systems to be tested with little-to-no risk to business processes » Coordination with the Chief Information Officer and others to determine systems which both had value in being tested as well as not representing a substantial risk in letting students make attempts to exploit them Initial groundwork for a localised responsible disclosure process: 23/03/2016 Responsible disclosure in Higher Education
  • 6. Current work » HEA-funded project led by Federica Paci (F.M.Paci@soton.ac.uk) at University of Southampton under the title of “Enhancing campus cyber security through constructivist student learning” » Work is beginning on selecting systems for the first round of penetration testing by a group of interested students » There is no official policy on responsible disclosure (yet!) but multiple parties are working together on this initial activity to hopefully iron out a more structured and policy-backed process for doing this in future 23/03/2016 Responsible disclosure in Higher Education
  • 7. 23/03/2016 Responsible disclosure in Higher Education Questions?
  • 8. Thank you 23/03/2016 Responsible disclosure in Higher Education Giles Howard University of Southampton giles.howard@soton.ac.uk