Skip Links

Network World

  • Social Web 
  • Email 
  • Close

IT departments must cope with Patriot Act, university CIO says

By John Cox , NetworkWorld.com , 08/03/2004
  • Share/Email
  • Comment
  • Print

Nearly three years after its enactment, the USA Patriot Act remains not just a political but also a technological issue on many college campuses.

Unprepared or ill-prepared schools can find themselves facing network problems, service disruptions, and in the worse case FBI agents driving onto the campus with subpoenas to haul off PCs, servers, and computer log data.

IT groups can minimize the potential disruptions of Patriot Act investigations by taking the lead on campus to pull together legal counsel, administration, and faculty to craft a clear process for handling investigations that will become more common, says Peter Siegel, CIO at University of Illinois at Urbana Champaign.

Siegel spoke this week at the annual conference of the Association for Communications Technology Professionals in Higher Education (ACUTA) meeting in Chicago.

"The status of dealing with the Patriot Act in higher education is very mixed," Siegel said. "Some people say, ‘What does this have to do with IT?’ Others say, ‘We have [network] security professionals who work closely with law enforcement agencies.’ There's not much in between, where you find people just ramping up [to deal with the Act]. For one thing, it's very hard to get people to share information about this."

Siegel pointed out to his audience that while the Patriot Act is new, it doesn't actually introduce new legal instruments or actions.

"Every component of the Patriot Act was present in previous law," he said. "But just not often used. Now, it's more likely that a Patriot Act incident will start or end or, especially, go through your campus."

Siegel said the act does, however, lower the bar on judicial oversight on searches and seizures. But oversight is still required: seizing records or doing electronic surveillance requires a subpoena issued by a judge.

"It allows [electronic] searches without requiring the person [under investigation] being notified, for an undefined 'reasonable time,'" he said.

Schools may find themselves drawn into a Patriot Act investigation even if those being investigated are not actually students or employees of the school. The school's network and computers may be hijacked by someone halfway around the world to attack a third location. "You need a solid policy," Siegel told his audience. "If it's 2 a.m. and your network is being used to attack another university or a private company, who gets called?"

  • Share/Email
  • Comment
  • Print
Partner Content

Brilliantly simple security and control solutions for email, web and endpoint

www.sophos.com

Stopping data leakage

Learn how to exploit your current security investment to control the information that flows into, through and out of your network.

Download the white paper.

Why detection rates aren't enough

Evaluating endpoint security products is a time-consuming and daunting task. Learn the six critical questions you need to ask prospective vendors to get the right endpoint solution.

Download the white paper.

Applications: taking back control

Employees installing unauthorized applications is a growing threat to business security and productivity. Cost-effectively reduce this threat by integrating control into your malware protection.

Learn more today.

Comment
Login
Forgot your account info?
Add comment
Anonymous comments subject to approval. Register here for member benefits.
Have a NetworkWorld account? Log in here. Register now for a free account.

Videos

rssRss Feed
Get instant email notification when white papers, webcasts, executive guides are added to our library. Stay informed and up-to-date with the latest on IT Technologies with Network World's Resource Alerts.
Network World,to go. Wherever you are. Breaking news delivered to your mobile device. Select the hottest topics in networking and start receiving Network World on your mobile device today.