Network & Web Application Security Tools

Service Initiation

Network security –CISO Office

Send email to security@columbia.edu

Joel Rosenblatt (joel@columbia.edu) 212-854-3033

Martin Wren (wren@columbia.edu) 212-854-9826

Spencer Malmad (sm3281@columbia.edu) 212-854-2911 

 

Support

Service Support Contact: 

CUIT HelpDesk

Service Targets: 

 

Priority

Response Time

1

4 hours

2

3 business days

3

5 business days

Service Description

The CISO (Columbia University Information Security Office) Security group uses various tools for network security, web application security, and risk mitigation.
Status: 
Active

Details

The CISO (Columbia University Information Security Office) Security group uses various tools for

  • network security, log consolidation and monitoring
  • web application security; tools for
    • port scanning,
    • dynamic application review
    • static code review
  • mitigating risk associated with loss of sensitive information (SSN, and other PII); tools
    •  SSN discovery and remediation
    • full disk encryption
    • encrypting email attachments
    • application white-listing

The CISO Security group also offers consulting, investigative and security advisory services.

  • Security consulting - CISO Security group contributes to projects by participating at critical points in the project implementation life-cycle (SDLC). It also documents Standard operating environment guidelines for applications, databases and Operating Systems.
  • Investigative services - CISO Security group assists various groups, like CU Department of Public Safety, across campus in their investigations.

Advisory services - CISO Security group also provides security-related advisory services to various groups across campus by conducting trainings, etc. 

Standard Service Features

Consulting, investigative and security advisory services. 

Standard Costs: 

Consulting, investigative and security advisory services are available for free.

There may be costs involved with tools used for network, web application and data security; depending on the contracts with the vendor of a specific tool. 

Prerequisites

None