ks6+Pf&Ô,YnRi$M^~HH  JoE-ǹy&qbw/o~?޼ C1A1uw 92b$C i456ǂ:'rjyO$JZ&aًKlnD#ƹvfvIو',v=%$TNcdgEV5iWtg\8&О1r@Җ y>e3F\  C#B(jW/#8yDG802ê[[fTF o^ӆ[XO0)D䔜J=%$+9õ@h;loj[{f:Z4*gN:®!$Cʴ>6RhM X_Oyާί9ϩ4wGD3щfљEԀTW)e4e\֠Ә}*ӓX[1%v"*DD7k.Ml MLKݷIrǮ,JpP^1bxmGˁF9%n{?Z?86;3zeS֪M<3jB Mp`L%dNw^3 ddZP^<%E`ָ N# Zf\gnM3[KJ_'Ut=QpF gh+cjT:s!7ԞԚUY u+>nU{Z `|`27 uqI"ru"Mqv=C9cX;hc-Pffq P]=8" YS\1*)k>՝_}0t$^YZ1lq#l07N"n5+a8i^& "hUM zVCA+>qOZx,VsW4E IFrD`,POSJ#Xz+6h4om̅Ři8 5(A`jh7?9hDzCCPVA81@Fqk$麮5Gff^t:^BЊº(ƃs^"X`37MZ 3<2!nc *6GLkW,sC{Y2`: R10S"ӸSmXm!u5u=7 1@1}RS :޺CL惇?܄U?hnŀ\`E,Vwǵ>h?>3º_]B|NWyiZsw@EUPQM~]8.\:K̍pXl` ~ 47,HJ- .qe3- #4[Is0FW9jY2#̺PlQG A0@;9l7 KBBN@n?+,56f?+"w^ټoPK$w!8CoL'1^f$оn67ءUasb !eܘ쥫3}sZn`ChЪ6:*YR)uߔy2:&f&9+*uJHjƓ}XNjL8_ȘRu@cޑ7/^*~q 8l,=*֞߻ß~"pw>(A?ݣaFLK*?Ow 1$mj $jl׏V~`"WqlUfa_y5O]κ.ƾqg1F3r{ iٞ0OaU fZOsKU٧ 5QK4cb ffTtirrk%6Lss}wߕ)vHlN1f3<6"bSyr͜p"e:MFLL3yC15Z9,vo[q)mԨS ,xd4YR,ݫmF>;S]&apV+2KHq&y6]y @eQ9J?:;b}3ĭY!g\OTeCO*%qA2d#dp 5w|˷ĞUbI(L]{.Rɏ7'G7O>׼FjSvON`R$H'/z[H9 ,oFcSc>f,ɬ{ah/rnh?n4O==l>i*=$c'rR~HաjU0 єz \ܩ &@@q!?O5/G3(\۝UiZ|Wm^ި5P[< +yc"=C'\:E.|`*Mz1´h&b ̛\ 01/16/07, One Step Ahead - Almanac, Vol. 53, No. 18
Print This Issue

One Step Ahead
January 16, 2007, Volume 53, No. 18

One Step Ahead

Another tip in a series provided by the Offices of Information Systems & Computing and Audit, Compliance & Privacy.

What Keeps You Up at Night?

If the answer is:  I have a lot of personal, sensitive data in a database or application and I’m not sure I’m protecting it appropriately, you are not alone, and unfortunately, your concerns may very well be valid! 

Many faculty and staff at Penn are now learning different ways of building databases and applications to run administrative and academic functions -- but many have not had the security training to minimize the risks of hackers accessing data, physical theft, web crawlers like Google picking up the data and making it publicly searchable, and other risks that are all too real in today’s world.

A new tool is now available to help you identify the top privacy and security risks, and more importantly, identify strategies that help to minimize those risks.  It is called the Security and Privacy Impact Assessment (SPIA) and was developed jointly by Information Systems and Computing and the Office of Audit, Compliance, and Privacy.  The process is described and the tool available by visiting www.upenn.edu/privacy and clicking on “Conduct Your Own Security and Privacy Impact Assessment.” We are all much better off finding security holes and plugging them through our own proactive activities rather than hearing about them from others once the damage has already been done.

If you have questions about the SPIA process or tool, please write to spia@pobox.upenn.edu.  An ounce of prevention . . . still makes sense.


For additional tips, see the One Step Ahead link on the Information Security website: www.upenn.edu/computing/security/.


Almanac - January 16, 2007, Volume 53, No. 18