UMCERT
ALL members of the University community MUST regularly referred to the ICT Guideline website:UM ICT-POLICY, RULES & GUIDELINES for any updates
UMCERT is UM’ Computer Emergency Response Team. Officially established in July 2011.UMCERT is responsible for activities related to awareness, prevention and handling of on campus ICT Security incidents.
Background ::
Given that cyber attacks have the potential to have security implications for ICT assets and delivery systems at the University of Malaya, the effort to overcome them should be wisely implemented to ensure that the ICT system can operate smoothly and without interruption. The establishment of the UMCERT team is proposed as a step towards streamlining the management of ICT security incident management at the University of Malaya and complying with the government's recommendations in line with the General Circular Letter No. 4 Year 2006: Public Sector Information and Communication Technology Incident Management Handling Management (ICT) (Surat Pekeliling Am Bil. 4 Tahun 2006: Pengurusan Pengendalian Insiden Keselamatan Teknologi Maklumat dan Komunikasi (ICT) Sektor Awam.). This team will act as the first level support for handling ICT security incidents, monitoring and advising on ICT security.
Vision ::
- To reduce the possibility of a successful attack & minimize the risk of damage from an attack.
Mission ::
- To overcome the problem of ICT users of campus network security.
Objective ::
- Enhanced PTM's responsibility for ICT security incidents at University of Malaya.
- Developing expertise and human capital in handling ICT security incidents.
- Strengthen the management of ICT security incidents through the establishment of UMCERT as First Level Support.
- More trained and experienced ICT personnel in the management of ICT security incident handling at the University of Malaya.
- ICT security incidents are effectively managed and systematized with UMCERT as the first level support.
- Efforts to overcome ICT security incidents at the University of Malaya are enhanced and streamlined.
The roles and responsibilities of this team.
- Receives and tracks ICT security complaints and assessing the incidence and the type of incident;
- Records and conducts an initial investigation of the reported incident;
- Take an action on the reported ICT security incidents;
- Addresses the ICT security incident response and taking action;
- Advises PTj to take remedial action and consolidation if incidents involve ICT assets that are under the responsibility of PTj;
- Contacts and reports the incident to GCERT MAMPU;
- Prepares an ICT security incident report to the ICT Security Committee;
- Provides advisory services to users in tracking, identifying and addressing ICT security incidents;
- Disseminates information to assist the enhancement of ICT security at UM from time to time;
- Conducts assessments to ensure the level of ICT security and takes corrective action or consolidation to improve the security of ICT infrastructure so that new incidents can be avoided;
- Enhances ICT awareness and awareness through ICT security awareness programs. Each user should be given ICT awareness and training programs in carrying out their duties and responsibilities.
UMCERT's membership is as follows:
- CERT Director : Madam Asiah Abu Samah (Chief Technology Officer)
- CERT Manager : Madam Nor Azliza Abd Wahab (ICT Security Officer)
Members ::
- Information Technology Officer at ICT Security and Research Computing Division.
- Assistant Information Technology Officer at ICT Security and Research Computing Division.
- Data Center Management Representative.
- Network Division Representative.
- Administrative Application Division Representative.
- Collaborative and Communication Application Representative Division.
- Customer Service Division Representative.
Field of Work ::
- Director of CERT
- Enhances the responsibilities of all PTj Heads on the ICT security incident at UM;
- Improves compliance with the requirements of ICT security, deeds, rules and procedures; and
- Develops expertise and human capital in the handling of ICT security incidents.
- Manager of CERT
- Determines the stage and type of incident;
- Provides a complete report of the incident;
- Informing detected incidents of internal monitoring and external sources;
- Provides incident information to GCERT MAMPU.
- Receives GCERT MAMPU assistance, if necessary.
- Conducts an assessment of ICT security level and taking action on recovery; and
- Manages the overall UM ICT security program.
- Members of CERT
- Receives and track incidents through internal monitoring and external sources;
- Conduct investigations / investigations on incidents;
- Take appropriate remedial action and prevention measures; and
- Report incidents to ICTSO / CIO.
The establishment of this team is expected to further strengthen the process of handling ICT security incidents to ensure that recovery and prevention measures are implemented as soon as possible to minimize the impact of the incident. More importantly, the number of ICT security incidents is expected to be mitigated with greater collaboration between all divisions.
All members, staff, students and visitors using the University's ICT facilities including the connection of any device to a departmental or college network connected to the University backbone network,must follow these regulations.The use of ICT facilities and the UM network is regulated by rules of use and behaviour based on the principle that the ICT facilities are used in a professional and responsible, lawful, ethical, reasonable and careful way.