it briefing thursday, march 20, 2008

34
IT Briefing Thursday, March 20, 2008 University Technology Services

Upload: caine

Post on 18-Jan-2016

39 views

Category:

Documents


0 download

DESCRIPTION

University Technology Services. IT Briefing Thursday, March 20, 2008. IT briefing. AGENDA FOR february 2008. Updates & Announcements Oxford Website Server Virtualization CISO Introduction. Karen Jenkins Seth Tepfer & Mahbuba Ferdousi Steve Siegelman Brett Coryell Brad Sanford. - PowerPoint PPT Presentation

TRANSCRIPT

Page 1: IT Briefing Thursday, March 20, 2008

IT Briefing

Thursday, March 20, 2008

UniversityTechnologyServices

Page 2: IT Briefing Thursday, March 20, 2008

IT briefingUPDATES &

ANNOUNCEMENTS

OXFORD WEBSITE

SERVER VIRTUALIZATION

CISO INTRODUCTION

KAREN JENKINS

SETH TEPFER & MAHBUBA FERDOUSI

STEVE SIEGELMAN

BRETT CORYELL

BRAD SANFORD

AGENDA FOR FEBRUARY 2008

2

Page 3: IT Briefing Thursday, March 20, 2008

WEB HOSTING MIGRATION• All testing of currently migrated sites must be complete NLT 3/26!!

ENTERPRISE CONTENT MANAGEMENT• Selected Cascade Server from Hannon Hill!• Huge higher ed presence (over 50 universities including Duke, Clemson, Cornell,

Carnegie Mellon)

• Great reference checks with CMU, Texas A&M Health Sciences Center, and the Medical College of Georgia – outstanding support and responsiveness!

• Healthcare presence as well (although not as large a vertical – about a dozen)

• Easy to use interface

• Standards based XML templates

SERVICE MANAGEMENT TEAM (REMEDY & LANDESK)• Very limited resources over the next few weeks!

generalUPDATES & ANNOUNCEMENTS

3

Page 4: IT Briefing Thursday, March 20, 2008

OXFORD WEBSITE REDESIGN

Mahbuba FerdousiSeth Tepfer

Page 5: IT Briefing Thursday, March 20, 2008

• SEND RFP

• VENDOR SELECTION COMMITTEE

• INVITE 3 VENDORS

• UNANIMOUSLY CHOSE DOT MARKETING

• SOLD THE CMS

• UNIVERSITY DID NOT HAVE PLANS FOR CMS

• TALKED WITH JOHN MILLS AND ITPC

oxford website redesignAPPROACH

Page 6: IT Briefing Thursday, March 20, 2008

• EDUCATION CUSTOMER BASE

• SURVEYS OF HIGH SCHOOL STUDENTS

• VISUAL APPEAL OF DESIGNS IN PORTFOLIO

• METHODOLOGIES WELL THOUGHT OUT

• THEIR CMS

oxford website redesignWHY DOTMARKETING

Page 7: IT Briefing Thursday, March 20, 2008

THEIR CMS • Written in Java

• Db independent (Oracle, MySQL, SQLServer, etc)

• Runs on Linux and Windows

• LDAP Authentication

• R25 interface experience

• Open Source Product

oxford website redesignWHY DOTMARKETING (CONT)

Page 8: IT Briefing Thursday, March 20, 2008

• EASE OF END-USER DEVELOPMENT

• BUILT IN GROUPS/ROLES BASED PERMISSIONS

• DYNAMIC DATA

• DESIGN CONTROL

• WORKFLOW PROCESS

• ABILITY TO ROLL-BACK TO PREVIOUS VERSIONS

oxford website redesignCMS ADVANTAGES

Page 9: IT Briefing Thursday, March 20, 2008

• EDIT/PREVIEW/LIVE MODES

• LEFT MENU NAVIGATION AND BREADCRUMBS

• PHOTO/VIDEO GALLERY

• STREAMING .MP3 PLAYER

• FORM HANDLING

• WEBDAV

oxford website redesignCMS ADVANTAGES (CONT)

Page 10: IT Briefing Thursday, March 20, 2008

• PROSPECT-ORIENTED PHILOSOPHY

• MULTIPLE NAVIGATION METHODS

• NEWS

• EVENTS/CALENDAR

• CMS

oxford website redesignOUR WEBSITE

Page 11: IT Briefing Thursday, March 20, 2008

• WE HAVE A LOT OF CONTENT

• NEED MORE ROBUST SEARCH THAN BUILT-IN

• EARLY ADOPTER OF LOAD BALANCER FOR THIS VENDOR

• VENDOR HAS BEEN RESPONSIVE AND STAYED WITH US

oxford website redesignWHAT WE LEARNED

Page 12: IT Briefing Thursday, March 20, 2008

MAHBUBA FERDOUSI• 770-784-4570

[email protected]

SETH TEPFER• 770-784-8487

[email protected]

oxford website redesignQUESTIONS

Page 13: IT Briefing Thursday, March 20, 2008

SERVER VIRTUALIZATION

Steve Siegelman

13

Page 14: IT Briefing Thursday, March 20, 2008

• SERVER CONSOLIDATION

• COST REDUCTION ON PHYSICAL INFRASTRUCTURE

• HARDWARE BUDGET CUTS

• PROVIDE FAILOVER AND HIGH AVAILABILITY

• PROVIDES MORE OPPORTUNITY FOR SERVER MAINTENANCE DURING NORMAL WORKING HOURS.

• PROVEN, MATURE TECHNOLOGY

server virtualizationWHY VIRTUALIZE

14

Page 15: IT Briefing Thursday, March 20, 2008

server virtualizationTO VM –OR– NOT TO VM

15

“For any new initiative, it is the direction of UTS to Virtualize first before deploying physical hardware.”

• VM Candidates:• Occasionally used development servers• Underutilized servers• Servers that have seasonal use• Application software that the vendor will support running in a VM

• Not VM Candidates:• IO intensive applications such as Oracle or SQL Server databases• Application software that is unsupported by the vendor in a VM infrastructure

Page 16: IT Briefing Thursday, March 20, 2008

server virtualizationVMWARE VI3

16

• VMWARE VI3 – SUITE OF PRODUCTS

• VMWARE ESX SERVER

• VMWARE VMFS

• VMWARE HIGH AVAILABILITY (HA)

• VMWARE DRS

• VMWARE VMOTION

Page 17: IT Briefing Thursday, March 20, 2008

server virtualizationVMWARE ESX SERVER

17

* Source – VWware Website

Page 18: IT Briefing Thursday, March 20, 2008

server virtualizationVMWARE VMFS

18

* Source – VWware Website

Page 19: IT Briefing Thursday, March 20, 2008

server virtualizationVMWARE HIGH AVAILABILITY (HA)

19

* Source – VWware Website

Page 20: IT Briefing Thursday, March 20, 2008

server virtualizationVMWARE VMOTION

20

* Source – VWware Website

Page 21: IT Briefing Thursday, March 20, 2008

server virtualizationVMWARE DRS

21

* Source – VWware Website

Page 22: IT Briefing Thursday, March 20, 2008

server virtualizationHARDWARE PLATFORM

22

HP c-Class Blades

Page 23: IT Briefing Thursday, March 20, 2008

server virtualizationPHASE ONE

23

• TWO VMWARE CLUSTERS

• 3 NODE CLUSTER – DMZ

• 3 NODE CLUSTER – ADMIN CORE

•TARGETED VMS

• 39 VMS – DMZ

• 23 VMS – ADMIN CORE

• OSS: WINDOWS 2003, REDHAT LINUX, SOLARIS 10 X86, SLES LINUX

Page 24: IT Briefing Thursday, March 20, 2008

server virtualizationPHASE TWO – FALL ‘08

24

• ACADEMIC CORE CLUSTER BUILD OUT

• 3 NODE CLUSTER – ACADEMIC CORE

• GROW OUT DMZ & ADMIN CORE CLUSTERS AS NEEDED

• CAMPUS WIDE HOSTING OFFERING

Page 25: IT Briefing Thursday, March 20, 2008

?Questions

25

Page 26: IT Briefing Thursday, March 20, 2008

BRAD SANFORDCHIEF INFORMATION SECURITY OFFICER

Brett Coryell

Page 27: IT Briefing Thursday, March 20, 2008

Brad Sanford, CISSP, GSEC, GCIHChief Information Security Officer (CISO), Emory

[email protected]

Introduction and Observations from My First 50 Days

Page 28: IT Briefing Thursday, March 20, 2008

PERSONAL BIO• Kentucky• Interest in Computers and Security• Education

WORK BIO• Humana through HCA• Vanderbilt• HCA (Security Assurance & Architecture)

brad sanfordINTRODUCTION

Page 29: IT Briefing Thursday, March 20, 2008

brad sanfordCISO ROLE AT EMORY

Richard Mendola

Vice President for Information

Technology & CIO

Linda Erhard

IT Governance

Marc Overcash

Deputy CIO,

Research and Health

Sciences IT

Brett Coryell

Deputy CIO,

University

Technology Services

Brad Sanford

Chief Information

Security Officer,

Emory University and

Healthcare

Dee Cantrell

CIO Emory

Healthcare

Information Services

John Connerat

IT Finance and

Administration

Earl Lewis

Provost and Executive Vice President for

Academic Affairs

Fred Sanfilippo

Executive Vice President for Health

Affairs and CEO, Woodruff Health

Sciences Center

Mike Mandl

Executive Vice President for

Finance and Administration

Page 30: IT Briefing Thursday, March 20, 2008

THE CHIEF INFORMATION SECURITY OFFICER IS RESPONSIBLE FOR COORDINATING AND LEADING INFORMATION SECURITY ACTIVITIES ACROSS EMORY UNIVERSITY AND EMORY HEALTHCARE

PRIMARY AREAS OF ACCOUNTABILITY

• Security Policy and Strategy

• Security Awareness

• Security Architecture

• IT Risk Management

• Security Incident Response

• Vulnerability Management

brad sanfordCISO ROLE AT EMORY

Page 31: IT Briefing Thursday, March 20, 2008

WILLINGNESS TO “DO THE RIGHT THING” IS HIGH

• Awareness is low• Expectations are unclear

OUR KNOWLEDGE IS LIMITED

• Where does sensitive data resides and how is it protected• But we do know we have a data protection problem

• What vulnerabilities are putting us at risk and how do we address them• Who is responsible• How should we respond to security incidents

DUPLICATION OF EFFORTS ACROSS SCHOOLS AND DEPARTMENTS IS HIGH

• Active Directory• Virtualization• Many Others

MANY SECURITY CONTROLS AND OPERATIONAL PROCESSES ARE IMMATURE

• Ad-Hoc• Limited in Scope / Coverage• Limited Effectiveness

brad sanfordINITIAL OBSERVATIONS

Page 32: IT Briefing Thursday, March 20, 2008

ONGOING• Information Gathering• Security Gap Analysis• Security Policy Review• Full Disk and Removable Media Encryption• Trusted Zone• Trusted Storage• Security Strategy

brad sanfordSECURITY RELATED INITIATIVES

Page 33: IT Briefing Thursday, March 20, 2008

FUTURE• Security Policy Overhaul

• Data focused

• Security Awareness Program

• Mobile Device Protection (PDAs, Smartphones, etc.)

• IT Risk Management Program

• Vulnerability management

• Expanded HIPAA Risk Assessment

• PCI Data Security Standard Compliance

• Evolution of Operational Security Capabilities

• Integrate Security Controls into Existing Processes

• Contracts

• New-Hire Process

• IRB

brad sanfordSECURITY RELATED INITIATIVES

Page 34: IT Briefing Thursday, March 20, 2008

?Questions

34