Content (959)
Web browsers are often used for day-to-day work and study. As web browsers have grown increasingly complex, featureful, and essential to many tasks, they have become one of the most common avenues for bad actors to compromise your security.Follow these guidelines to enhance your web browser…
For information on how to teach remotely, visit the Center for Teaching Innovation's Introduction to Online Teaching Tools.
See what tools can help you work remotely.
The Cornell IT Security Office (ITSO) recommends the following baseline precautions while traveling internationally. In the event your devices are lost, stolen, or altered while traveling, adhering to these precautions will reduce the risk to you and the University.
For questions about any of the…
Keeping Your Devices SafeNever leave anything unattended in a public area, in a shared living space, or visible for potential intruders. Use physical locking devices or take them with you.Use an inconspicuous protective bag or case to carry your laptop and other devices.
Getting ready to update your password?
Best practices for everyone (students, faculty, and staff): Although these are requirements for employees handling sensitive information, it is also good practice to configure all devices in this way for extra protection against loss or theft.Definition of mobile handheld devices:…
If your NetID password is stolen and your NetID is used to send email spam, there can be a number of warning signs:
Cornell is phasing out the use of security questions in favor of setting a recovery email address to reset forgotten or lost Cornell NetID passwords. Please visit Set a NetID Recovery Email for more details.If you:
1. Report the incident to the IT Security Office.
Don’t hesitate. Any possible or confirmed theft of a NetID password needs to be reported immediately to the IT Security Office via security-services@cornell.edu. You should also notify your department’s technical support staff.
Keeping your personal information, Cornell sign-in credentials, and important data safe means protecting your passwords. Anyone with active online accounts encounters dozens of passwords used to access Cornell resources, personal online banking, e-commerce sites, and other websites. Below you will…
You are tricked into giving away your NetID passwordThese days we are overwhelmed by fraudulent email messages and websites that try to steal personal information. These are often referred to as “phishes.” A common trick is to suggest that one of your accounts will be shut down unless you reply…
Getting ready to update your password? Review the Best Practices for a Successful Password Update.
Whenever possible, we recommend not storing confidential data on your computer. If you have a need to store confidential information on your computer temporarily, consult with your technical support team. You must:
Not sure what high-risk data is? See Data types (High Risk, Moderate Risk, Low Risk).
Report incidents immediately.Send an email to itsecurity@cornell.edu.If you require urgent assistance, please contact the IT Service Desk.
If you haven't already reported the incident, do so now. Work with technical support to contain the system (as outlined below) while you gather and provide incident details to the IT Security Office.
Do not
Scan the system with antivi
When you work with printed material containing high-risk data, handle it responsibly:
Cornell policy requires your department to escrow passwords (securely store a copy) for all encrypted data.Why password escrow is necessary:If you encrypt university data, you should not be the only person who knows the password needed to unlock it.If something should happen to you, or if you lose…
All devices holding confidential data (computers, smart phones, thumb drives, tablets, etc.) must be kept secure.You must ENCRYPT if:
Data DisposalOld information is risky information! Watch out for and regularly dispose of unneeded information:Social Security numbers used as general identifiers (this was often the case in the past)Data you think you've disposed of, lurking in backupsFiles from previous users on shared computers…