<?xml version="1.0" encoding="UTF-8" ?>
<rss version="2.0">
 <channel>
  <title>IT News</title>
  <link>http://www.it.utah.edu/leadership/news/index.html</link>
  <description>Information Technology news for the University of Utah community.</description>
  <lastBuildDate>Thu, 27 Mar 2008 15:49:58 GMT</lastBuildDate>
  <generator>ListGarden Program 1.3.1</generator>
  <docs>http://blogs.law.harvard.edu/tech/rss</docs>
  <item>
   <title>It’s Time to Update Your Qwest Dex White Pages Listings!</title>
   <link>http://www.it.utah.edu/leadership/news/news/mar2008.html#qwestdex</link>
   <description>Please submit your additions, corrections or deletions for the Qwest Dex 2008-2009 Salt Lake City White Pages. The deadline is April 25, 2008. Delivery will be in the fall of 2008. The University of Utah listings begin on page 213 in the business section of the 2007-2008 White Pages. &lt;br>&lt;br>The listings under the University of Utah heading are paid for by Office of Information Technology (OIT) (listings under the University Health Care heading on page 212 are paid for by Hospital Telecommunications). Other listings your department may have in the White Pages business section (i.e., University Health Care physicians’ listings) will be billed to your department. The charge is $3.00/month per listing line. All changes should be made online at &lt;a href="http://www.it.utah.edu/services/phones/qwestdex.html">www.it.utah.edu/services/phones/qwestdex.html&lt;/a>. If you have no changes, there is no need to submit the form.&lt;br>&lt;br>Departments with extension offices or locations outside of Salt Lake City may want to take the time to review their White Pages listings in other local directories. If you anticipate changes or additions to these directories, please call Robin or Allyson (phone numbers below) so we can provide Qwest with that information. The online form is not for any directory changes other than the Salt Lake City White Pages.&lt;br>&lt;br>The Dex Media representative will be contacting departments directly about your Yellow Pages listing(s). If you wish to advertise in the Yellow Pages, contact Beckie Penman at 284-5055 or send an email to &lt;b>beckie.penman@dexmedia.com&lt;/b>. Please note, if your department has a listing in the Qwest DEX Yellow Pages, you will be billed directly from Dex Media. Your department will make the payment directly to Dex Media, also.&lt;br>&lt;br>Please call Robin Horton in OIT at 585-7205 with any questions for listings under the University of Utah heading and related alphabetical White Pages listings. For listings under University Health Care, Moran Eye Center, UNI, University Health Care Community Clinics and physician and clinic alphabetical listings, please call Allyson Tanner in Hospital Telecommunications at 581-3879.</description>
   <pubDate>Thu, 31 Jan 2008 22:14:19 GMT</pubDate>
  </item>
  <item>
   <title>ACS Milestone: 10 Years Supporting ASUU Elections</title>
   <link>http://www.it.utah.edu/leadership/news/news/mar2008.html#asuu</link>
   <description>&lt;i>by Starlee Holman&lt;/i> &lt;br>&lt;br>For the past 10 years, Administrative Computing Services (ACS) has worked to make elections for new ASUU representatives smooth and successful events. By having all voting available online, it allows as many students as possible to get involved.&lt;br>&lt;br>It makes it “really easy to hurry and vote,” said David Martini, ASUU elections registrar.  Before ACS made voting available online in 1998, all ballots had to be cast in person. Polling stations were placed around campus where students could stop by and fill out a ballot after showing their student ID card. These processes required outside sources coming in and conducting the polls as well as counting ballots and announcing the winners.&lt;br>&lt;br>After making voting available online, ACS continued to improve the voting system. “What I really like is that ACS does test voting to make sure everything runs smooth,” said Martini.  During orientation, the students running for ASUU office are asked to participate in a test vote. Though ACS runs multiple tests on the program, the team likes to double check that all students will be able to cast their votes without any difficulties.&lt;br>&lt;br>“The test groups allow us to get a larger pool of different levels and types of students testing the voting system to make sure that it is working as it should each year,” said Jennifer Loudiana, ACS senior web coordinator.&lt;br>&lt;br>This test then goes on to make sure that all ballots are consistent. “We take the results of the test and then compare them to the statistics that the system keeps to make sure the tallies are correct.” said Loudiana. This test also checks to make sure that students are getting the correct ballots when they log in to vote.&lt;br>&lt;br>Voting was held March 12th and 13th through a link on CIS. More than 2,900 students participated. A re-vote for the College of Education took place March 25th and 26th. </description>
   <pubDate>Thu, 31 Jan 2008 22:17:42 GMT</pubDate>
  </item>
  <item>
   <title>To patch or not to patch?	</title>
   <link>http://www.it.utah.edu/leadership/news/news/mar2008.html#iso</link>
   <description>&lt;strong&gt;Note&lt;/strong&gt;: The following is part of  a regular series on security  from the Information Security Operations office. &lt;/br&gt;
&lt;p&gt;That is the question.  The majority of software vendors  published a monthly patch schedule where they
release updates to their software.  These releases are often publicized in advance so that system administrators and users can decide which patches they need to apply and be prepared for them.  Once you have the list of patches, how do you decide which ones you need?&lt;/p&gt;
&lt;p&gt;&lt;b&gt;Patches fall into 4 categories:&lt;/b&gt;
&lt;ul&gt;
&lt;table border=1&gt;
  &lt;tr&gt;
    &lt;th&gt;&lt;b&gt;Patch Type&lt;/b&gt;&lt;/th&gt;
    &lt;th&gt;&lt;b&gt;Description&lt;/b&gt;&lt;/th&gt;
    &lt;th&gt;&lt;b&gt;Action&lt;/b&gt;&lt;/th&gt;
  &lt;/tr&gt;
  &lt;tr&gt;
    &lt;td align=right valign=top&gt;
      &lt;div align=&quot;center&quot;&gt;&lt;b&gt;Critical&lt;/b&gt;        &lt;/div&gt;&lt;/td&gt;
    &lt;td align=left&gt;
      A &lt;b&gt;Critical&lt;/b&gt; patch is a security-oriented patch rated &lt;b&gt;Critical&lt;/b&gt; by the vendor of the software  (Microsoft, Adobe, Oracle, etc.).
      The vulnerability the patch addresses can be exploited remotely, meaning over the network or Internet.  Exploits for
      the vulnerability have been  actively used, and there is a real danger of compromise.  Failure to apply a patch like this
      can result in a hacked system, and loss of data or personal information is possible.    &lt;/td&gt;
    &lt;td&gt;
      &lt;b&gt;You should apply the patch immediately.&lt;/b&gt;    &lt;/td&gt;
   &lt;/tr&gt;
  &lt;tr&gt;
    &lt;td align=right valign=top&gt;
      &lt;div align=&quot;center&quot;&gt;&lt;b&gt;High&lt;/b&gt;        &lt;/div&gt;&lt;/td&gt;
    &lt;td align=left&gt;
      A &lt;b&gt;High&lt;/b&gt; patch is also a security-oriented patch.  All the conditions that make a patch &lt;b&gt;Critical&lt;/b&gt; also make it &lt;b&gt;High&lt;/b&gt;,
      except there is no evidence of an exploit for this particuclar vulnerability.  Failure to apply a patch titled &lt;b&gt;High&lt;/b&gt; can result in a hacked
      system and a loss of data or personal information is possible if an exploit is released.    &lt;/td&gt;
    &lt;td&gt;
      You should &lt;strong&gt;apply the patch as soon as possible. &lt;/strong&gt;&lt;/td&gt;
  &lt;/tr&gt;
  &lt;tr&gt;
    &lt;td align=right valign=top&gt;
      &lt;div align=&quot;center&quot;&gt;&lt;b&gt;Medium&lt;/b&gt;&lt;/div&gt;&lt;/td&gt;
    &lt;td align=left&gt;
      A &lt;b&gt;Medium&lt;/b&gt; patch is also a security-oriented patch, however these types of patches only address vulnerabilities that can
      be exploited locally, meaning, an attacker needs to have local access to the machine.  In other words, they need to be
      sitting in front of it.  While vulnerabilities like this are important in an open environment such as the University, they are not as dangerous as having millions of people on the Internet having access to a flaw in your system.  Failure to patch a vulnerability of this type could result in a compromised system and a loss of information, however the chances are much lower than those of a &lt;b&gt;High&lt;/b&gt; or &lt;b&gt;Critical&lt;/b&gt; vulnerability.    &lt;/td&gt;
    &lt;td&gt;
      You should &lt;strong&gt;apply the patch when convenient.
      &lt;/strong&gt;&lt;/td&gt;
  &lt;/tr&gt;
  &lt;tr&gt;
    &lt;td align=right valign=top&gt;
      &lt;div align=&quot;center&quot;&gt;&lt;b&gt;Low&lt;/b&gt;&lt;/div&gt;&lt;/td&gt;
    &lt;td align=left&gt;
      A &lt;b&gt;Low&lt;/b&gt; patch includes all other types of patches.  The software vendor has stated that the patch is not a security oriented patch (it might add new functions to a program, for example), it is not addressing any kind of
vulnerability, and does not have any severity rating.  Failure to apply &lt;b&gt;Low&lt;/b&gt; priority patches can result in not being able to use new program features.    &lt;/td&gt;
    &lt;td&gt;
      You can choose whether or not to apply the patch depending on your need for the new features.    &lt;/td&gt;
  &lt;/tr&gt;
&lt;/table&gt;
&lt;/ul&gt;
&lt;b&gt;Virus Updates&lt;/b&gt;
&lt;p&gt;These, too, are considered a &lt;b&gt;patch&lt;/b&gt;, and you should always keep your anti-virus software updated. The Software Licensing office has low-cost or free anti-virus software available to department IT administrators for  machines they maintain and individual campus users for their home machines. See &lt;a href=&quot;http://www.software.utah.edu&quot;&gt;www.software.utah.edu&lt;/a&gt;.&lt;/p&gt;
&lt;b&gt;To patch or not to patch?&lt;/b&gt;
  &lt;ul&gt;
    &lt;dt&gt;Should no longer be a question.  It is now the &lt;b&gt;answer&lt;/b&gt;.&lt;/dt&gt;
  &lt;/ul&gt;</description>
   <pubDate>Thu, 31 Jan 2008 22:21:12 GMT</pubDate>
  </item>
 </channel>
</rss>
