Go Directly to Page Content
Go Directly to Site Search
Go Directly to Site Navigation
ITS Safe Computing

Information and Infrastructure Assurance Services

Attack Recognition and Mitigation

IIA offers network monitoring that can provide a department, unit, or research team with information about who is using the network, the applications being used, and when the network is used. This information is useful for detecting activity that indicates potential security and policy violations and for resolving these issues.

Educational Materials and Activities

IIA develops materials and activities to help educate the campus community on IT security topics. These materials include online how-to documentation for those who manage their own computer security and various events aimed at students, faculty and staff.

Incident Response

IIA has established an incident response team to provide the university with rapid identification, analysis, and response to an incident.

  • In MiWorkspace Units: Report IT security incidents to the ITS Service Center. The Service Center will involve IIA as appropriate.
  • In units not yet using MiWorkspace: Report all incidents to the unit security coordinator designated by your school, college, or department or to your IT department.

If the incident seems serious or urgent, you can also contact IIA directly by sending email to security@umich.edu. For more information, see Report an IT Incident.

Managed Security Services

IIA offers Managed Security Services to units needing assistance with performing information security coordination and administration activities. Through this program, one IIA Information Security Coordinator will work with the unit to provide consistent, reliable information security services, which are listed on Managed Security Services.

Michigan IT Security Services

These services, available to U-M departments, can be ordered through the Michigan IT website. Details about the services are also available there.

Network Intrusion Prevention System (IPS) - Planned for 2014-15

A network IPS will provide advanced threat detection and allow the university to extend protection to its wireless networks. For information about the status of this effort and more, see Network IPS Planned for 2014-15.

Risk Analysis

Each university unit must undergo regular risk analyses of all its sensitive and mission-critical computing environments according to a four-year cycle established by ITS. The responsibility for initiating these analyses has fallen to units in the past, but ITS has begun a transition to take this work on itself. ITS will assume this responsibility gradually, unit-by-unit, with the goal of assuming responsibility for initiating and conducting all unit risk assessments by 2015.

More information about this service is available on the Michigan IT Services Portal website as part of the IT Security Essential service. U-M's risk assessment methodology and tool, RECON, is adapted from security controls developed by the National Institute of Standards and Technology (NIST) (U.S. Department of Commerce).

User Advocate

The ITS User Advocate works with the University of Michigan community to ensure that U-M information technology policies and guidelines are followed, and to respond to computer abuse and misuse of U-M electronic resources.

The User Advocate enforces compliance through a variety of means, including temporary denial of service or filing a formal complaint about a student with the Office of Student Conflict Resolution (OSCR).

Specifically, the User Advocate

  • Receives and investigate reports of U-M technology and information policy violations as they pertain to U-M-provided resources
  • Coordinates problem-solving with other information technology service providers and campus units—including Student Life and the Department of Public Safety and Security (DPSS)
  • Provides IT policy interpretation and information to help students, faculty, and staff understand university and departmental policy, including the responsible use of shared resources
  • Engages in outreach activities, including general community education and awareness

Vulnerability Scanning

Vulnerability scanning is a process of remotely examining hosts on a network for known, detectable vulnerabilities. IIA offers a free monthly scanning service to units that would like regular scans of their networks without the cost of maintaining their own local scanning infrastructure. This service is an appropriate option for networks that are accessible from campus, or where the scanner can be allowed through a firewall.