Published on Information Security at UVA (https://security.virginia.edu)

Home > About Us

University Information Security (InfoSec)

About

The University of Virginia Information Security office (InfoSec) supports the mission of the University by focusing on the continuous enhancement of information policies and security of UVA's diverse and decentralized computing environment.  InfoSec works in partnership with units and individuals across the University to formulate IT policies, standards, and procedures; assess security risks; establish strategic direction; provide security education and training; implement security safeguards; track security incidents; and oversee the annual risk assessment process to evaluate the effectiveness of IT security controls within the IT environments of all UVA departments. This department also provides information security consultation, guidance, and investigative support to the UVA community.

The UVA Information Security office reports to the Office of the Chief Information Officer (CIO) [1].

LEADERSHIP

Jason C. Belford, Chief Information Security Officer (CISO)
jcb3zr@virginia.edu [2]
(434) 924-4165

Michael Grinnell, Deputy Chief Information Security Officer (DCISO)
     Interim ISO, Security Engineering and Operations 
mg7aa@virginia.edu [3]
(434) 924-7748

Brian Davis, Information Security Officer – Governance, Risk and Compliance
bd2m@virginia.edu [4]
(434) 243-8707

Dale Dew, Director
dtd5x@virginia.edu [5]
(434) 924-7525

InfoSec Areas

Information Security Engineering [6]

The Information Security Engineering group designs and implements information security architecture to protect UVA's internal network and resources from unauthorized access. By utilizing the latest in Information Security technologies, participating in threat intelligence services, and maintaining connections with a variety of Higher Education Information Security organizations, the information security engineers stay abreast of trends in the cybersecurity threat landscape and mitigate these threats by implementing applicable solutions and tools in a proactive manner to maintain the security of UVA IT resources.

This group can be reached by sending an email to it-security@virginia.edu [7].

Information Security Operations [8]

The Information Security Operations group maintains the security of the UVA computing environment, focusing on data minimization, security incident response, and departmental security liaison activities.

Information Security Analysts monitor multiple threat intelligence sources, logs, and tools, responding to any incident identified. They also facilitate sensitive data scanning and remediation, web application vulnerability scanning and remediation, and security consultations.This group can be reached by sending an email to it-security@virginia.edu [7].

Information Technology Compliance [9]

The Information Technology Compliance team within InfoSec is responsible for coordinating efforts across the University to meet the existing requirements, regulations, and review standards to which UVA departments are accountable. As part of these activities, the IT Compliance team facilitates some risk review functions such as the ones described in the University Data Protection Standards 3.0 regarding the information security review requirement for the storage of University data in a cloud environment.

This team can be reached by sending an email to it-compliance@virginia.edu [10].

Information Technology Policy and Outreach [11]

The Information Technology Policy & Outreach team within InfoSec is responsible for developing and updating information technology policies, standards, and procedures to keep them current with changing information security landscape.  This team provides support to departments regarding UVA information technology resource policies [12].   In addition, it conducts information security education and outreach programs such as the required Information Security Awareness Training [13] and High Security Awareness Training [14] for HSVPN users [15].  It also conducts employee awareness training, speaker series [16], phishing [17] simulation exercises, and cybersecurity awareness [18].   Part of its outreach efforts includes the Information Security Liaison program, which serves as InfoSec's representatives to schools, departments, and units, providing information security analysis, implementation, reporting and communication activity in support of University-wide technical solutions.

This team can be reached by sending an email to infosec-training@virginia.edu [19].

Contacting University Information Security (InfoSec):

918 Emmet Street
P.O. Box 400898
Charlottesville, VA 22904
Email: UVA Information Security office [10]


Source URL:https://security.virginia.edu/about-university-information-security

Links
[1] https://cio.virginia.edu/organization [2] mailto:jcb3zr@virginia.edu [3] mailto:mg7aa@virginia.edu [4] mailto:bd2m@virginia.edu [5] mailto:dtd5x@virginia.edu [6] https://security.virginia.edu/information-security-engineering [7] mailto:it-security@virginia.edu?subject=%5BFrom%20Website%5D [8] https://security.virginia.edu/information-security-operations [9] https://security.virginia.edu/policy-team [10] mailto:it-policy@virginia.edu?subject=%5BFrom%20Website%5D [11] https://security.virginia.edu/education-outreach [12] https://security.virginia.edu/information-policy [13] https://in.virginia.edu/isat-training [14] https://in.virginia.edu/hsat-training [15] https://in.virginia.edu/hsvpn [16] https://security.virginia.edu/webinars [17] https://security.virginia.edu/what-is-phishing [18] https://security.virginia.edu/Cybersecurity-Awareness [19] mailto:infosec-training@virginia.edu?subject=%5BFrom%20Website%5D