.
About the Office of Information Security
Role, Function and Responsibilities
The Office of Information Security (OIS) is charged with the
development and enforcement of policies, procedures and practices,
maintains an up-to-date information security program and monitors
the effectiveness of defined security controls. The OIS will also
ensure that the confidentiality and integrity of all information
resources (IR) and submits status reports, at least annually to the
IRM as to the effectiveness of the overall information resources
security program.
Workload and Staffing
Information Resource Security policy and program development
1 Information Security Officer
- program management
-
security oversight
-
policy development,
-
enforcement and investigatory requirements
Information Security Analysis
2 Information Security Analysts
- eDiscovery, open records, compliance
related tasks, investigations
-
standards development augmentation
-
business Continuity Planning / Disaster Recover support for campus
-
security log/alert monitoring and reporting
FY08 Major Accomplishments and Challenges
Accomplishments
Developed, documented and published a comprehensive information
security program which has been reviewed and approved the president
of UTMB
Challenges
Increased legislative, audit and compliance requirements
Communication of new statutory requirements to end-users
--------------------------------------------------------------------------------------------------------------------------
Information Security Staff
Robert
Shaffer "Bob" joined UTMB in 2001 and is the Information Security
Officer (Interim) for UTMB. Bob is also the coordinator for UTMB's
Computer Incident Response Team and is responsible for the technical and
administrative oversight
of the UTMB Security program. Bob entered the I. S. Security field in 1999
and has over 10 years of I. T. Related experience. Some of his I. T.
Certifications include, Certified Information Systems Security
Professional (CISSP), Certified in Homeland Security Level III (CHS-III), INFOSEC Assessment Methodology (IAM)
and Microsoft Certified Systems Engineer (MCSE).
--------------------------------------------------------------------------------------------------------------------------
Louis
Perrin joined the Information Services Security Administration team in
March, 2005 with 22 years of I.T. experience (16 yrs. with NASA contractors, and
6 in private sector enterprises). Louis’
first I.S Security project with UTMB was the consolidation of five required
security related online training courses into a single “Information
Protection” course. Louis’ I.T.
certifications include CompTIA A+, Network+ and Security+, as well as Novell’s
Certified Netware Engineer (CNE).
