Trusted CI
Trusted CI podcast
Trusted CI is the NSF Cybersecurity Center of Excellence. The mission of Trusted CI is to lead in the development of an NSF Cybersecurity Ecosystem with the workforce, knowledge, processes, and cyberinfrastructure that enables trustworthy science and NSF’s vision of a nation that is a global leader in research and innovation. More information can be found at trustedci.org.
Where to listen?
Podcasts in the app Replaio Radio Coming soonPodcasts are coming to the app soon. Install now and be the first to see a whole new take on podcasts
Episodes
August 2022: CIS Controls with Trusted CI 22.08.2022 57:55
The Trusted CI Information Security Office (ISO) team will be presenting a webinar on the CIS Controls. This will include background and information on the CIS controls, our recent experiences using the controls to assess Trusted CI’s own cybersecurity program and operations, and how that can be applied to your own project. Topics include: * Who Trusted CI is and why we have a cybersecurity progra...
June 2022: Ransomware: Threats & Mitigations with REN-ISAC 27.06.2022 53:15
The education industry has unceremoniously emerged as the second most common target for ransomware. It continues to evolve in how it is used as a fund-raiser for criminal organizations and how the technology works, to keep its victims guessing as to defense and eradication. Institutions face the difficult challenge of preserving academic freedom, easy access to information, and open collaboration...
Apr 2022: Updates from the Trusted CI Framework Cohort 25.04.2022 47:09
The Trusted CI Framework is a minimum standard for cybersecurity programs. In response to cybersecurity guidance focused narrowly on cybersecurity controls, the Trusted CI Framework provides a more holistic and mission-focused standard for managing cybersecurity. In order to encourage adoption of the Trusted CI Framework, we have created a program called the Framework Cohort, where representatives...
Feb 2022: The Results of the Trusted CI Annual Challenge on Software 28.02.2022 54:03
This webinar presents the results of Trusted CI's 2021 examination of the state of software assurance in scientific computing, and also gives an overview of the contents of its recently released Guide to Securing Scientific Software (GS3), aimed at helping developers of software used in scientific computing improve the security of that software. See our blog post announcing the report: https://blo...
Jan 2022: Populating the HECVAT as an Academic Research Provider - Representing Your Security Posture For Your Higher-Ed Information Security Partners 24.01.2022 47:26
At one time, higher-ed was the requestor of HECVAT's - now we are being called to populate them for our peers. The Higher Education Community Vendor Assessment Toolkit (HECVAT) has become the de facto standard for vendor risk and security assessment in higher education and the number of universities around the globe using the HECVAT in their assessment process is well into the hundreds. As researc...
Dec 2021: Lessons learned from a real-world ransomware attack on researchers at MSU 06.12.2021 46:37
Ransomware report: https://hdl.handle.net/2022/26638 Cybercriminals are increasingly targeting researchers (along with hospitals, cities, schools, and utilities) because ransomware allows them to target a broader set of victims. Ransomware monetizes the attack by encrypting data and holding it ransom until victims pay, meaning victims no longer need to hold data of direct financial value. The prol...
Oct 2021: The Trusted CI Framework; Overview and Recent Developments 25.10.2021 1:01:32
The Trusted CI Framework is a tool to help organizations establish and refine their cybersecurity programs. In response to an abundance of guidance focused narrowly on cybersecurity controls, Trusted CI set out to develop a new framework that would empower organizations to confront cybersecurity from a mission-oriented, programmatic, and full organizational lifecycle perspective. The Trusted CI Fr...
Sep 2021: Q-Factor: Real-time data transfer optimization 27.09.2021 1:02:44
Q-Factor is a framework to enable data transfer optimization based on real-time network state information provided by programmable data planes. Communication networks are critical components of today’s scientific workflows. Researchers leverage long-distance ultra-high-speed networks to transfer massive data sets from acquisition sites to processing sites and share measurements with scientists wor...
Aug 2021: NCSA Experience with SOC2 in the Research Computing Space 30.08.2021 49:33
As the demand for research computing dealing with sensitive data increases, institutions like the National Center for Supercomputing Applications work to build the infrastructure that can process and store these types of data. Along with the infrastructure can come a host of regulatory obligations including auditing and examination requirements. We will present NCSA’s recent SOC2 examination of it...
July 2021: A capability-based authorization infrastructure for distributed High Throughput Computing 26.07.2021 57:26
The OSG Consortium provides researchers with the ability to bring their distributed high throughput computing (dHTC) workloads to a pool of resources consisting of hardware across approximately 100 different sites. Using this “Open Science Pool” resource, projects can leverage the opportunistic access (nodes that would be otherwise idle at the site), dedicated hardware, or allocated time at large-...
June 2021: Investigating Secure Development In Practice: A Human-Centered Perspective 26.07.2021 1:04:43
Secure development is not just a technical problem: it’s a human and organizational problem as well. To understand the causes of insecurity, and find effective solutions, we must understand how and why security problems happen, and what barriers stand in the way of fixing them. How can we make it easier for developers to write secure code, even without special training? In this talk, I will report...
May 2021: Identifying Vulnerable GitHub Repositories in Scientific Cyberinfrastructure 25.05.2021 59:00
The scientific cyberinfrastructure community heavily relies on public internet-based systems (e.g., GitHub) to share resources and collaborate. GitHub is one of the most powerful and popular systems for open source collaboration that allows users to share and work on projects in a public space for accelerated development and deployment. Monitoring GitHub for exposed vulnerabilities can save financ...
Apr 2021: Trusted CI webinar: Arizona State's Science DMZ 26.04.2021 56:11
Drawing upon its mission to enable access to discovery and scholarship, Arizona State University is deploying an advanced research network employing the Science DMZ architecture. While advancing knowledge of managing 21st-century cyberinfrastructure in a large public research university, this project also advances how network cyberinfrastructure supports research and education in science, engineer...
Bonus episode: Operationalizing the Framework: Getting management to understand cybersecurity Video 16.04.2021 53:49
We have a bonus podcast episode, it is brought to us by our partners at the ReserachSOC. In March of this year, Trusted CI published its Framework Implementation Guide for Research Cyberinfrastructure Operators. In this podcast episode, Craig Jackson, architect of the Trusted CI Framework and Susan Sons, Deputy Director of Research SOC, discuss how to use the Framework to enhance relationships wit...
May 2016: Webinar Series Kick-off 16.04.2021 44:02
In January 2016 we announced that CTSC was named NSF's Cybersecurity of Excellence. Its role is to provide readily available cybersecurity services tailored to the NSF science community. With this in mind, we are announcing the CCoE Webinar Series. The kickoff presentation will be presented by members of the CTSC Leadership Team and focuses on who we are, our activities, projects, and areas we can...
Jun 2016: Risk Self-Evaluation 16.04.2021 30:17
This talk will present a self-evaluation spreadsheet which can be used by projects to make an initial assessment of their cybersecurity readiness. The spreadsheet is based on the “Securing Commodity IT in Scientific CI Projects” document available as part of CTSC’s Guide to Developing Cybersecurity Programs for NSF Science and Engineering Projects. More information can be found at: http://trustedc...
Jul 2016: XSEDE Information Sharing 16.04.2021 42:11
The Extreme Science and Engineering Discovery Environment (XSEDE) is the most advanced, powerful, and robust collection of integrated advanced digital resources and services in the world. It is a single virtual system that scientists can use to interactively share computing resources, data, and expertise. This session will provide an overview of the XSEDE information security program used to prote...
Aug 2016: The Science DMZ as a Security Architecture 16.04.2021 1:07:39
The Science DMZ architecture proposes a novel method of design for network segments optimized for large scale data transfer (LSDT) functionality. LSDT has special requirements, both in the security and functional arenas. Attempts to incorporate LSDT functionality into a more traditional perimeter security model can cause problems both with LSDT functionality, as well as weaken overall campus secu...
Sep 2016: The Risk of the Commons 16.04.2021 1:02:33
Open Source, as a development methodology has revolutionized how we innovate, how we develop, and how we consume software. Now, any cutting edge technology software is presumed to be open source. So what does software methodology have to learn from 19th century economics of farming? Unfortunately quite a lot. While the open source methodology allows tremendous speed in the rate of innovation; but...
Oct 2016: Science or Security? 16.04.2021 59:23
In my long career in science-related IT, I've seen security go from a non-issue to a big issue. I'll first relate a few security anecdotes from that career, including founding this series of summits. Then I'll describe some conclusions I've come to about this pesky subject. Finally, I'll outline the security research strategic plan created by the interagency NITRD program's senior steering group f...
Dec 2016: CICI Regional Cybersecurity Collaboration projects 16.04.2021 1:00:08
Our last webinar episode of the first season is a group presentation on the CICI Regional Cybersecurity Collaboration projects. The presenters and project names are: * Xinwen Fu, New England Cybersecurity Operation and Research Center (CORE) * James Joshi & Brian Stengel, SAC-PA: Towards Security Assured Cyberinfrastructure in Pennsylvania * Jaroslav Flidr, Substrate for Cybersecurity Education; a...
Jan 2017: Open Science Cyber Risk Profile 16.04.2021 1:04:42
The Open Science Cyber Risk Profile (OSCRP) is a joint project of the Center for Trustworthy Scientific Cyberinfrastructure, the NSF Cybersecurity Center of Excellence, and the Department of Energy’s Energy Sciences Network (ESnet). Over the course of 2016, the CTSC and ESnet organized a working group of research and education community leaders to develop a risk profile for open science. The risk...
Feb 2017: Practical Cybersecurity Program for (Smaller) Science Programs 16.04.2021 59:27
Based on CTSC’s cybersecurity program development guide (see trustedci.org/guide), this webinar addresses practical information security tasks for small and medium science projects. The NSF CCoE’s work spans the full range of NSF-funded projects and facilities, and cybersecurity is certainly *not* a one-size-fits-all endeavor. Some of the topics covered include: Cybersecurity’s relevance to scienc...
Mar 2017: SDN and IAM Integration at Duke 16.04.2021 58:54
Over the past 4 years, Duke has established SDN bypass networks, an SDN mediated Science DMZ, and other services that rely on identity data about the users and the equipment at Duke. One such service is the Protected Research and Data Network (PRDN), which makes use of our Identity Management (IDM) services both for Duke researchers and their collaborators at other institutions. In this presentati...
Apr 2017: HIPAA and FISMA: Computing with Regulated Data 16.04.2021 1:07:59
Please register here. Be sure to check spam/junk folder for registration confirmation with attached calendar file. With cyberattacks and breaches rising exponentially, there is increasing pressure on federally funded scientific and academic institutions to protect regulated data, including identifiable patient data protected by the Health Insurance Portability and Accountability Act (HIPAA), and d...
Similar podcasts
Replaio is not a podcast publisher; show names, artwork and audio belong to their authors and are distributed through public RSS feeds.