SECURITY ALERT
Hackers are now routinely exploiting computer
server vulnerabilities. Many of these exploits are relatively harmless, like
those looking for space on servers to store and share movie files. Others are
quite harmful, such as the exploits for the purpose of identity theft.
Recently several computer systems at CU Boulder were attacked by computer
hackers. It is important for all computer system owners to demonstrate vigilance
in protecting systems and data.
As a server operator, you are responsible for its security. IT Services
recommends these best business practices to help you protect your data.
- Move your server behind the campus firewall. This is the most secure
environment that can be provided for servers. If at all possible, move any
server with student or patient information behind the firewall.
- Use the latest version of operating systems and applications feasible.
- Make sure your operating system and applications are up-to-date by patching
them as required.
- Install anti-virus software on your server and keep it up-to-date.
- Eliminate unnecessary services running on the server. For instance, if
your server doesn’t provide web services, the web server services should be
removed. Many services have known vulnerabilities, and if you aren’t using the
service, it is easy to forget about updating them.
- Identify a person who is responsible for managing the server and ensuring
that it is protected.
- Perform regular backups and store backup media off-site.
- Perform a regular risk analysis – know what applications on the server are
hosting sensitive information (e.g. protected health information (PHI), SSN,
credit card numbers, etc.), and who is using that information.
- Use proper disposal procedures.
If you have questions about how to achieve any of the above recommendations,
please contact the UCD Help Desk at 303-724-4357 (HSC) or 303-315-4357 (DDC).
Back
Updated 2005-08-15