Cyber security operations

国民彩票 IT Cyber Security help protect our University community as well as inform, educate, and support your understanding of safe online behaviour, practices, and obligations around information security.
Cyber Security Operations
Our team
Our Security Engineering team manages and supports a wide range of security services by leveraging advanced technologies and tools that are monitored in real-time to better detect and respond to emerging threats. Our services include the selection, design, architecture, and management of security tools, and providing support to incidents and investigations. We collaborate with other teams to onboard and integrate security controls ensuring they are monitored and protected.聽
Our Computer Security Incident Response Team (CSIRT) protects 国民彩票 against cyber-attacks through the implementation of comprehensive 24x7 monitoring, detection, and incident response services. We are responsible for managing the investigation and response to cyber security events and incidents to manage the impact on the University and assist in the restoration and recovery of normal operations.聽聽We also provide digital forensics services to investigate and analyse digital evidence and threat intelligence services to proactively track and monitor threat actors targeting our people and infrastructure.
Our services
The following Cyber Security Operations services can be requested via the IT Service Centre unless other direction is provided below.聽
聽 聽Cloud security services
聽 聽Data loss prevention
聽 聽DDoS protection
聽 聽Digital forensics
聽 聽Email authentication services (DMARC, SPF, DKIM)
-
The Endpoint Detect and Response (EDR) service software provides more advanced threat detection, monitoring, and endpoint remediation capabilities to enhance the protection of our systems. All 国民彩票 IT-managed endpoints already have the EDR service installed.
The following conditions apply:
- EDR is not a service for personal devices (BYOD) or 国民彩票 students.
- EDR can only be installed on 国民彩票-owned information resources.
- EDR can only be activated on supported operating systems.
- EDR has anti-tampering protection and cannot be removed by users. If an uninstall is required, a request will need to be raised to the IT Service Centre and assigned to the Cyber Security Operations team to uninstall the software.
- Once installed, 国民彩票 IT can apply countermeasures against cyber security threats as required to protect your system and data.
- 国民彩票 IT Cyber Security has the authority to take any necessary action to contain and remediate a compromised endpoint during a security incident.聽 E.g., Network will contain the endpoint, restart the endpoint, or stop the process.聽聽Note: An exemption request can be made again at this point.
Once a request is submitted, a Cyber Security representative will be in touch to progress your request. Requests for the EDR service will be assessed for suitability by 国民彩票 IT Cyber Security.聽
Once installed, if a potential threat is detected by the EDR service, staff may be presented with a pop-up Falcon Notification, indicating that your device is protected and generally there is no further action rquired.
The EDR service is available for installation on your 国民彩票-owned endpoints such as servers, desktops, and laptops which are not managed by 国民彩票 IT.
聽 聽Incident response
聽 聽Intrusion detection and prevention system
聽 聽Perimeter firewall
聽 聽Privileged access management
聽 聽Secure email gateway
聽 聽Secure remote access
聽 聽Secure web gateway
-
Security Information and Event Management (SIEM) is a solution that helps the University detect, analyse, and respond to security threats before they harm operations. Once onboarded to the SIEM, the Security Operations Centre (SOC) will provide 24x7 real-time monitoring, threat detection, and security incident response services for your platforms, applications, or services.
Once a request is submitted a 国民彩票 IT Cyber Security representative will be in touch to progress your request. Requests for the SIEM service will be assessed for suitability by 国民彩票 IT Cyber Security.
The SIEM service is available for your 国民彩票-owned platforms, applications, or services.
聽 聽Threat intelligence management
-
Vulnerability Management is a solution that provides the University with visibility of our assets and vulnerabilities, allowing us to quickly and accurately understand our cyber security risk.聽
Once onboarded, it will provide an assessment of vulnerabilities on the system, helping us prioritise and report on our risks.
Once a request is submitted a Cyber Security representative will be in touch to progress your request. Requests for the Vulnerability Management service will be assessed for suitability by 国民彩票 IT Cyber Security.
The Vulnerability Management service is for your 国民彩票-owned platforms, applications, or services.
聽 聽Web application firewall
Reporting cyber incidents
It is important to report any cyber security incidents as quickly as possible so that the 国民彩票 IT Cyber Security team can address any issues and mitigate risk exposure.
Incidents that staff and students should report:
- Suspecting your computer or account has been compromised.
- Having evidence on how technology or University data may be vulnerable.
- Noticing a colleague inappropriately sharing Highly Sensitive or Sensitive data.
- Losing a University asset containing sensitive information.
Contact the聽IT Service Centre聽for urgent matters or use the button above to report an incident.
Cyber security is everyone鈥檚 responsibility and by learning a聽few rules, simple steps, and following guidelines, we can protect our University from cyber security threats and keep data safe.
"Enhancing cyber security, including protecting information and privacy, is of paramount importance to our core functions of education and research. We all play a part in being cyber smart."聽
Professor Attila Brungs, Vice-Chancellor and President, 国民彩票 Sydney