2021-03-01 CCR Check-in Meeting Agenda, Notes and Actions

People in attendance bolded

Former user (Deleted)

Corn, Michael (Deactivated)

Daniel Quach

Claire

Hersberger, Mark (Deactivated)

Phillip Lopo

James Dotson

Purpose

  • Check-in on CCR project deliverables


ITS-Pro codes:   CIC-285 - Getting issue details... STATUS (Mar)


Project related links:

Main site - https://assure.ucsd.edu

Kuali form - https://certify.assure.ucsd.edu (note that certificate issue needs to be fixed)

SharePoint Secure Portal - https://ucsdcloud.sharepoint.com/sites/cybercertification/

Project Collab site: https://ucsdcollab.atlassian.net/wiki/display/CCR/Cybersecurity+Certification+for+Research+%28CCR%29+Home

High Risk Labs list -

Early adopters list -

Support-related working document:  https://docs.google.com/document/d/1nX4SOUQL78T28xXgRo2br8yTbkvLeMo3uyxSF_ydQvg/edit?usp=sharing

Discussion items

TopicWhoComments/ Actions

Web site and SharePoint site updates

Mark and Sean

2/16 updates:

  • MC wants us to revisit FAQs:
    • How to handle students
    • Revise the privacy content
    • Claire's team review and provide feedback?
  • Suggest one more pass of site and then we communicate the s@#t out of it.
  • Former user (Deleted) to check on any lingering Health and SDSC content/updates to make sure we have all of them on the SharePoint site (A few install packages are missing).
  • Phillip Lopo to check on FireEye install package for OSX

3/1 updates:

Process and Kuali forms

Sean and Daniel

3/1 updates:

  • Nothing new
Early adopters and/or High Risk Lab submissionsSean et al

2/16 updates:

  • No new candidates as of today.
  • Next session is Monday (2/22).

3/1 updates:

  • Goal is to get High Risk Labs certified by summer
CommunicationsMark et al

Prior topics/updates:

2/16 updates:

  • Comms will be the focus as we move forward.
  • Podcast interviewing Mike and Claire?  Yes!
  • Need to create a micro-presentation that Mike, Claire, etc. could use to meet with various constituencies to educate them on it.

3/1 updates:

  • Mark sent draft Comms Plan - ready for review by Corn, Michael (Deactivated)
  • MC meeting with Vince
  • Letter for dept heads ready to go.
  • Certification letter ~90% done. Corn, Michael (Deactivated) to finish this up and send to Daniel.
  • Stephan's draft testimonial on its way. Corn, Michael (Deactivated) will send on to Mark when it comes in.
  • Idea = Create a focus group to look at site, form, process, etc. and give feedback to us?  Corn, Michael (Deactivated) to email one faculty committee, as well as recently compromised folks and see if we can scare up a focus group.
  • Corn, Michael (Deactivated) to draft initial communications to...
    • Dept heads/chairs
    • Heads of high risk lab depts
    • Cc' IT Directors on the above

HX/Qualys Alerting updates

Phillip

2/16 updates:

3/1 updates:

  • Nothing new

CCR Support Process updates

All

2/16 updates:

  • Claire brought up how her team can make sure questions/tickets are routed to the correct person(s). Is there a cheat sheet and/or one person that can help with this.  Phillip Lopo to request an email list group that includes a limited set of key OIA personnel (Phillip, Daniel and ), who can can help ensure Research Team's requests get routed to the correct person(s).

3/1 updates:

  • Claire is responsible for overall program
  • Daniel or Phillip (?) will responsible for OIA's day-to-day activities (i.e., OIA program manager) for this program (escalations, process break-downs, assignments of work, etc.). Daniel Quach to draft a list of what this program manager role will entail.

Other topics


Prior updates:

  • Parking Lot for now - Guidance with regard to mobile and/or personal devices use when accessing labs and such? Create and require signature of a principle of security (patch device, anti-virus, etc.) document or something of this sort?  A one-page guidance paper can probably eventually be drafted.

3/1 updates:

  • Nada