Scottish College Information Leads (SCIL) Minutes. Stirling Business Centre, Stirling

Similar documents
Higher Education Information Directors in Scotland (HEIDS) Draft Minutes

HE/FE Collaboration Catalyst / IS Shared Services

the steps that IS Services should take to ensure that this document is aligned with the SNH s KIMS and SNH s Change Requirement;

LEADERSHIP GROUP LG (2017) Paper October 2017 RESILIENCE BOARD

Next Generation Broadband South of Scotland and Highlands and Islands

ISSC is invited to consider the attached report and to support the proposal to change the priority order for the migration UEA web services.

Cyber Security Strategy

ENISA EU Threat Landscape

Incentives for IoT Security. White Paper. May Author: Dr. Cédric LEVY-BENCHETON, CEO

PREPARE FOR TAKE OFF. Accelerate your organisation s journey to the Cloud.

Brussels, 19 May 2011 COUNCIL THE EUROPEAN UNION 10299/11 TELECOM 71 DATAPROTECT 55 JAI 332 PROCIV 66. NOTE From : COREPER

IN THE FRAME. Computacenter Public Sector Frameworks FRAMEWORK

Cybersecurity-Related Information Sharing Guidelines Draft Document Request For Comment

NHS Scotland Cyber Attack: NSS Evidence to Scottish Parliament Health & Sport Committee (Jun 17)

DATA SHEET RSA NETWITNESS PLATFORM PROFESSIONAL SERVICES ACCELERATE TIME-TO-VALUE & MAXIMIZE ROI

Cyber Security School

Strategic and operational threat analysis at Europol's EC3

National Business Crime Partnership Association

ITU-ACMA Asia Pacific Regulators Roundtable July 2014

Mission: Continuity BUILDING RESILIENCE AGAINST UNPLANNED SERVICE INTERRUPTIONS

Introductory Speech to the Ramboll Event on the future of ENISA. Speech by ENISA s Executive Director, Prof. Dr. Udo Helmbrecht

Marine Institute Job Description

Meeting of the BBC Audit and Risk Committee SUMMARY MINUTES. Thursday 22 June, 2017 New Broadcasting House, London

Data Centers & Technology:

Building a Resilient Security Posture for Effective Breach Prevention

The Africa Utilities Telecom Council Johannesburg CC, South Africa 1 st December, 2015

SECURING THE UK S DIGITAL PROSPERITY. Enabling the joint delivery of the National Cyber Security Strategy's objectives

NIS Directive : Call for Proposals

Case Study: myaccount

NOT PROTECTIVELY MARKED

Gigabit West Sussex. Report to Cabinet. Executive Summary. Recommendations. Reasons for Recommendations. Background Papers

ICANN Identifier System SSR Update 1H 2015

Marine Institute Job Description

Bring Your Own Device (BYOD)

13967/16 MK/mj 1 DG D 2B

Strengthening the Cybersecurity of Federal Networks and Critical Infrastructure

The European Policy on Critical Information Infrastructure Protection (CIIP) Andrea SERVIDA European Commission DG INFSO.A3

Annual Report for the Utility Savings Initiative

Senior Manager Information Technology (India) Duration of job

Assessment of the progress made in the implementation of and follow-up to the outcomes of the World Summit on the Information Society

CYBER INCIDENT REPORTING GUIDANCE. Industry Reporting Arrangements for Incident Response

EOLP Portfolio. Version 1.0

Manchester Metropolitan University Information Security Strategy

Cloud solution consultant

6056/17 MK/ec 1 DG D 2B

Welcome to the NHSmail LA webinar

ESFRI Strategic Roadmap & RI Long-term sustainability an EC overview

Aneurin Bevan Health Board

Implementation Strategy for Cybersecurity Workshop ITU 2016

Case Study. Encode helps University of Aberdeen strengthen security and reduce false positives with advanced security intelligence platform

You can access the AIMS user guide in the Related Links section at the top right of the page.

Engaging Executives and Boards in Cybersecurity Session 303, Feb 20, 2017 Sanjeev Sah, CISO, Texas Children s Hospital Jimmy Joseph, Senior Manager,

Scottish Wide Area Network (SWAN) update & Partnership Connectivity

Defensible and Beyond

JUSTICE SUB-COMMITTEE ON POLICING AGENDA. 2nd Meeting, 2014 (Session 4) Thursday 20 February 2014

Protecting information across government

Securing Europe's Information Society

acknowledged by the United Nations University

UNCLASSIFIED. National and Cyber Security Branch. Presentation for Gridseccon. Quebec City, October 18-21

Distribution Long Term Development Statement

INVITATION TO TENDER. Website Specification for Herefordshire & Worcestershire Chamber of Commerce. Date: 18/07/2017 Version 1.0

Council, 8 February 2017 Information Technology Report Executive summary and recommendations

Update on the Government of Canada s Information Technology Transformation Plan

Independent Advocacy and the Adult Support & Protection (Scotland) Act A survey of independent advocacy organisations

Securing Digital Transformation

Risk Mitigation Strategies 2017 Tier 1 Risk Profile Interim Report UNCW Institutional Risk Management

Security and resilience in Information Society: the European approach

Minutes of the Annual General Meeting Held at Canterbury Christ Church University 6 th September

CYBER RESILIENCE & INCIDENT RESPONSE

Birmingham Community Healthcare NHS Foundation Trust. 2017/17 Data Security and Protection Requirements March 2018

UNB S CYBERSECURITY PROGRAM

The Tagging Tangle: Creating a librarian s guide to tagging. Gillian Hanlon, Information Officer Scottish Library & Information Council

EISAS Enhanced Roadmap 2012

Your Journey to a Modern Desktop and Beyond

Network Essentials for Superintendents

NHS Fife. 2015/16 Audit Computer Service Review Follow Up

The UK s National Cyber Security Strategy

IT Services. We re the IT in OrganIsaTion.

08 November Jisc s global reach. Dr Esther Wilkinson, Head of international Dr Baoyu Wang, International services manager

PULLING OUR SOCS UP VODAFONE GROUP AT RSAC Emma Smith. Andy Talbot. Group Technology Security Director Vodafone Group Plc

Cyber Partnership Blueprint: An Outline

Andrew Durant/Ellen Sullivan

NOT PROTECTIVELY MARKED. Public SPA Board Meeting Date 15 December 2016 Assembly Room, Tulliallan, Alloa

The role of municipal government in preventing crime and building community safety

The University of Queensland

NOT PROTECTIVELY MARKED

McClelland Report. John McClelland CBE, June 2011

EU policy on Network and Information Security & Critical Information Infrastructures Protection

Preparing your C-Suite for a Cyber Crisis

PONEMON INSTITUTE RESEARCH REPORT 2018 STUDY ON GLOBAL MEGATRENDS IN CYBERSECURITY

Jisc update. Paul Feldman CEO Jisc REPO Fringe 2/8/ /08/2016 REPO Fringe 1

WA Govt Changing Cyber Security Landscape

MEETING: RSSB Board Meeting DATE: 03 November 2016 SUBJECT: Rail Industry Cyber Security Strategy SPONSOR: Mark Phillips AUTHOR: Tom Lee

GREEN DEFENCE FRAMEWORK

Valérie Andrianavaly European Commission DG INFSO-A3

Cyber Security in Europe

N4 Design Options. Andy McAnaney DHID VDNS (Voice and Data Networks Services) Team

The European Platform in Network and Information Security (NIS) Fabio Martinelli

TX CIO Leadership Journey Texas CIOs Bowden Hight Texas Health and Human Services Commission Tim Jennings Texas Department of Transportation Mark

ETSI Workshop ICT Energy Efficiency and Environmental Sustainability Latest projects and upcoming developments. Chiara Venturini Director, GeSI

Transcription:

Scottish College Information Leads (SCIL) Minutes Thursday 22 nd of September 2016 Stirling Business Centre, Stirling (Approved 8 th Feb 2017) Present: Terry Trundley Edinburgh College TT Fraser Wight Borders College FW Kris Getchell Dundee and Angus College KG Chris Sumner South Lanarkshire College CS Scott Renton Glasgow Clyde College SR Tom MacMaster Fife College TMacM Jason Miles-Campbell Jisc JMC Andy Laszlo Glasgow Kelvin College AL Owen Freel Mike Burns Scott Mathew Michael McLaughlin Paul Smith Kenji Lamb Eric Dunbar UCSS- Note-taker University of the Highlands and Islands North East College Scotland APUC North East College Scotland Colleges Development Scotland Dumfries and Galloway College OF MB SM MMcL PS KL ED Apologies David Black Angus Warren John Maher David Beards West College Scotland APUC/UCSS University of the Highlands and Islands Scottish Funding Council (Introductory comment- This meeting was chaired by Terry Trundley of Edinburgh College. Future meetings will be chaired alternately by David Black of West College Scotland and Terry.) 1. Welcome and Apologies Terry Trundley (TT) welcomed the group to Q3 2016 SCIL Meeting.

2. Review Previous Minutes and Actions The previous minutes of SCIL was accepted with no challenges. The Terms of Reference draft produced for the SCIL Group was accepted unchallenged. 3. Round table inputs from each IS Lead Each College s lead representative briefed the group on latest challenges/successes and areas of work upcoming. There was a degree of commonality to the updates (with each institution recently welcoming new students). This round the table provoked some interesting discussions around common issues. Areas covered included- network resilience, information security, telephony (including IT telephony), virtualisation, on-line enrolment, o365, business intelligence, BYOD, SWAN, Service Desk, Wi-Fi, timetabling. 4. Police Scotland, Cyber Crime Presentation and Discussion Eamonn Keane (EK) of Police Scotland presented on the subject of Cyber Crime from a Scottish perspective. This was an informative and engaging presentation with some key points emphasised below. Cyber Crime is evolving in types of threats and volume. EK stressed the importance of reporting instances of Cyber Crime detected at our institutions- only if reported can resources be allocated appropriately to deal with. EK stressed that if reporting a cyber-crime then the police will work with you to ensure that business can continue while investigations take place- no desire to get in the way of core business. EK stated that in cases such as ransomware that paying ransom merely funds future attacks. EK asked institutions to consider if they have an overarching Cyber Security strategy. EK stated education and awareness of one s board is crucial to ensuring a proper security posture. Evolutions such as the growth of hacking groups, growth of cyber-terrorism highlighted. ACTION: OF to find out how training material used disseminated in InfoSec Service. ACTION: EK to share slide sets and contact details with group. EK raised fact that EU direction next year will be to mandate the reporting of Information Security incidents. EK stressed need to collaborate and share to overcome Cyber Crime, and asked for criticisms and feedback on presentation and approach, via e-mail. Incidents can be reported via calling 101, but EK acknowledged that for complex attacks the skills may not be available on the front desk to assess and act upon all areas of Cyber Crime- BUT only by reporting can the gap be identified and a case for more training/resources made in this area.

5. Microsoft, Roadmap & Structure - Presentation Andy Nagle and Mark McManus presented on behalf of Microsoft. ACTION OF to share AN s contact details with the SCIL croup. AN explained the MS strategy (Cloud first and Mobile first) and the support available to Colleges in Scotland. AN stated that happy to be invited for workshops at individual colleges, or crossinstitutional events such as SCIL as desired. AN encouraged the group to outline their use of MS products within their institutions. MS Office, Azure, Yammer and OneDrive all brought up. Some institutional contacts voiced their frustration that functionality changes/additions and deletions take place without the College administrators being alerted, and therefore unable to set expectation or training for wider user base. General feeling that there is a high pace of change. MS stated that update information for administrators should be improved so that one knows which day changes will take place. MMcM offered webinar on (for example) Yammer to address management segregation of staff and students where desired. ACTION: OF to put on agenda of next SCIL what webinars would be of use to the group. MS mentioned that they were looking to institute monthly Webinars for Education in the UK. AN stated that o365 now being seen as a Teaching and Learning tool by many- MS Classrooms offering coming out soon- a full collaborative program. MMcM presented for Microsoft on Cloud Strategy- vision is to provide full power to administrators but to reduce complexity. MMcM stated that complexity/barriers can lead to user dissatisfaction and the growth of shadow OT. MMcM stresses Microsoft s move to be more open- work with Red Hat, open source and ios offered as examples of this. UK data centres have recently been opened by Microsoft due to rise in demand of cloud computing (azure). Peer connection with JANET now upgraded. One attraction of cloud characterised as ability to commission a minimum spec and to burst when/if demand rises (as opposed to previous model where one would often over commission to guard against possible subsequent high demand. Test and Dev environments can also be commissioned and decommissioned as required. Data Analytics and Internet of Things both drivers of Cloud. AN stated that all FE institutions now Managed Accounts- which opens up offerings that AN can make. AN stated he can be contacted by FE contacts at any time and he will direct the query to relevant experts within Microsoft. Proof of concept projects can be considered- please contact Andy to begin discussions to see if this approach will work. ACTION: OF to cascade Andy Nagle s details to SCIL.

AN stated that Customer Emersion Experience offered annually and would like to extend invite to SCIL meeting. A question arose over whether Azure would take over from System Centre and Configuration Manager? MMcM stated that this is customer s choice which to use. MMcM stated that MS Classroom will have connections between Moodle and Canvas. 6. Procurement Update from APUC MMcL updated on procurement milestones and important updates for the group. VLE Platform framework being worked through- expect multi-supplier framework in October. Finance and HR Payroll agreement update given. (This will not include ERP_ Scottish Procurement Digital Conferencing single supplier agreement available for Colleges to use. MMcL asked that if any institution would like to be involved in shaping the Office Equipment and MFD procurement exercise to please contact him. SUPC framework for storage now available (includes HPC). Apple framework- only 3 rd party supplier bid and therefore only 3 rd party suppliers on framework. Contract Management meeting has taken place with resellers and APUC- looking to reduce time to deliver. MMcL informed that there are 2 open days upcoming for HP Event ACTION: MMcL to send on invites 7. Update from ISSC OF updated on ISSC activity. OF related that Pauline Robertson has moved roles into the InfoSec Shared Service, and as such OF is Acting Head of Information Services Catalyst. Candidate Shared Services are being assessed and OF looking to meet each head of ICT at the Colleges to assess which areas are of the strongest interest. OF updated on InfoSec Shared Service in Chris Sutherland s absence. 11 Institutions now members and initial work with members taking place InfoSec Shared Service has been partnering with Scottish Government, who have received the InfoSec Shared Service model positively. Benchmarking exercises have been well received by institutions. Looking to identify gaps. Looking to see how we tackle common problems (within sector, and public sector as a whole. CS looking to initiate Breach Response workshop- looking at both business and technologyorganisational response key.

Tactical Working groups looking to be formed- idea is to bring in experts on specific area; Phishing, Ransomware etc. Positive response to idea for shared CERT team- many benefits including expanded resources when needed, exchange of knowledge, building teams across institutions, experience. Scottish government have asked InfoSec Shared Service to take leadership of a couple of Scottish Government initiatives. Scot Gov Operation Centre has been proposed, seems like a good idea- will be looked at in more detail in October. OF stated he will suggest that Chris be offered a slot at the next SCIL meeting 8. Update from Jisc JMC updated on migration of EastMan and ClydeNet almost complete. JMC observed that Scottish FE bandwidth grew 250% in one year. Jisc working within funding decreases. Looking to stay 18 months ahead of bandwidth demand. Resilience and response a key issue at present- appreciates that cost for some institutions with multiple campuses can be challenging. JMC offered for Jisc to host meetings around particular areas of interest at Lumen House, or to bring relevant Jisc experts to SCIL. Regarding common frustrations with installation/upgrades of internet connectivity felt by many colleges- Jisc has some power due to volume they have with 3 rd party suppliers. JMC stated that work to improve Service Desk is taking place within Jisc. Looking to form Scottish JANET Users group, as similar grouping in North East England has been beneficial. JMC updated on DDoS attacks in September 2015 and actions taken since then to mitigate future attacks- a full update will be made to stakeholders, probably face to face. Jisc Security Conference will be taking place on the 1 st and 2 nd of November. Networkshop will be taking place 11-13 th of April 2017- invites have already been sent for this. Future projects mentioned- Data Landscape Scotland and Common Apps/ Digital Resources- Jorum users group being deprecated, to be replaced by Content Store= quality controlled and consolidated/ Ser4vice Catalogue is being rationalised (organised into clusters) to ease navigation. JMC highlighted existent of Jisc Self-service dashboard- Account Manager for institution can talk through, help delegate access beyond strategic contact. This dashboard shows what you are eligible for, what you are signed up for, and what you actually use. 9. Update from CDN KM updated on CDN activity.

SharePoint User Group being set up. KM asked for input if other User Groups would be of value? Utility of a VLE User Group floated by the group. 10. Update from SFC In DB s absence OF passed on the following updates- Cyber-security: SFC is funding a new post to work with the university research community on cyber security, to help inform the Scottish Government s cyber strategy and next steps. Sector Oversight Board meeting on 28 October: will discuss future Jisc funding, UCSS-ISSC, Jisc work on College MIS. Of asked if there were any areas that DB could speak to at the next meeting- nothing immediately mentioned, OF offered to collate any mails around this subject. 11. AOB Need for SharePoint expertise for specific project raised. ACTION: OF to create Doodle poll for Q1 2017 Meetings TT stated he would look to encourage/shape working groups and webinars around specific areas that may be of value to the group.