icon

University Systems and Networking

University Systems and Networking (USAN) oversees the University's Data Centers and Wired / Wireless Network. We support both the Metropolitan and Florham campuses, as well as our international campuses in Vancouver and Wroxton. USAN enables the access, flow and storage of information within the University while defending our network against all threats and maintaining the integrity of our data.

Support
background
Search Department Resources

Safeguard Rules Under The Gramm-Leach-Bliley Act

Resources for:
icon Close

Responsible Office: Data Security Incident Response Team (DSIRT)
Responsible Official: Chief Information Officer, Chief Information Security Officer
DSIRT Approval: Neal M. Sturm on behalf of DSIRT

Effective Date: 12/01/2022
Last Review Date: 11/22/2022
Last Revision Date: 11/22/2022


  1. Purpose: This Policy sets the standards for developing, implementing, and maintaining reasonable administrative, technical, and physical safeguards to protect the security, confidentiality, and integrity of information covered by applicable provisions of the Gramm-Leach-Bliley Act (“GLBA”) and associated regulations. In particular, this document describes various measures being taken by FDU to (i) ensure the security and confidentiality of covered information, (ii) protect against any anticipated threats or hazards to the security of these records, and (iii) protect against the unauthorized access or use of such records or information in ways that could result in substantial harm or inconvenience (collectively, the “Program”). The practices described in this Policy are in addition to any institutional policies and procedures that may be required pursuant to other federal and state laws and regulations, including, without limitation, the Family Educational Rights and Privacy Act (“FERPA”).
  1. Scope of Program: The Program applies to any record containing “nonpublic personal information” about a student or other individual who has a continuing relationship with the University, whether the record is in paper, electronic, or other form, and which is handled or maintained by or on behalf of the University (“covered information”).(1) This includes any information that a student or other individual provides to FDU in connection with financial aid and tuition/fee collection efforts.

(1) Nonpublic personal information means: (i) personally identifiable financial information; and (ii) any list, description, or other grouping of consumers (and publicly available information pertaining to them) that is derived using any personally identifiable financial information that is not publicly available. “Personally identifiable financial information” means any information that a consumer provides to FDU to obtain a financial product or service, any information about a consumer resulting from a transaction involving a financial product or service between FDU and that consumer, or information that FDU otherwise obtains about a consumer in connection with the provision of a financial product or service to that consumer. A “consumer” is an individual, including a student, who obtains or has obtained a financial product or service from FDU that is to be used primarily for personal, family, or household purposes, or that individual’s legal representative. Examples include information an individual provides to FDU on an application for financial aid, account balance information and payment history, the fact that a student has received financial aid from FDU, and any information that FDU collects through an internet “cookie” in connection with a financial product or service.

  1. Roles and Responsibilities: Compliance and cooperation with this Policy is the responsibility of every employee at all levels within FDU. FDU’s Vice President and Chief Information Officer (CIO), assisted by the Chief Information Security Officer (the “CISO”), has the overall responsibility for coordinating information security pursuant to this Policy. The CIO or CISO may designate other representatives of FDU to help oversee and coordinate particular elements of the Program. The team will work closely with other members of the Office of Information Resources and Technology (OIRT), the Data Security & Incident Response Team (“DSIRT”), the University Risk Manager, the Vice President for Human Resources, and the General Counsel, as well as relevant academic and administrative units throughout the University to implement the Program.
  1. Risk Assessment: The CIO and CISO will help the relevant offices of FDU to identify reasonably foreseeable internal and external risks to the security, confidentiality, and integrity of covered information that could result in the unauthorized disclosure, misuse, alteration, destruction, or other compromise of the information; and to assess the sufficiency of the safeguards in place to controls these risks. This effort will be embodied in a risk assessment document.

    The risk assessment is a written document that includes:

    (i) Criteria for the evaluation and categorization of identified security risks or threats that FDU faces;

    (ii) Criteria for the assessment of the confidentiality, integrity, and availability of FDU’s information systems and covered information, including the adequacy of the existing controls in the context of the identified risks or threats that FDU faces; and

    (iii) Requirements describing how identified risks will be mitigated or accepted based on the risk assessment and how the information security program will address the risks.
  1. Access Controls: The Program includes implementing and periodically reviewing access controls, including technical and, as appropriate, physical controls to:

    (i) Authenticate and permit access only to authorized users to protect against the unauthorized acquisition of covered information; and

    (ii) Limit authorized users’ access only to covered information that they need to perform their duties and functions, or, in the case of third parties, to access their own information.

The Program is designed to identify and help manage safeguards for the data, personnel, devices, systems, and facilities that enable FDU to achieve its mission – efforts are prioritized in accordance with our objectives and risk strategy.

FDU has adopted authentication and access controls as needed to implement the “principle of least privilege” around accessing covered data, meaning that no user should have access greater than is necessary for legitimate FDU purposes Data owners within each applicable University unit approve and periodically review access. This includes a periodic review by the Office of Enrollment Services of all users who have access to Enrollment Services security tracks in the Colleague System and a periodic review by other administrative departments that maintain students’ financial aid information regarding user access to the information.

These efforts also include employee training regarding these controls. The OIRT will coordinate with representatives in FDU’s Office of Finance, Office of Financial Aid, Enrollment Services and other offices to evaluate on a regular basis the effectiveness of the University’s training, procedures, and practices relating to access to and use of student records, including financial aid information as well as financial information. This evaluation will include assessing the effectiveness of the University’s current policies and procedures in this area. All employees are required to train in FDU’s Written Information Security Program (WISP) (training.fdu.edu), which program is incorporated by reference into this Policy.

  1. Monitoring Unauthorized Users and Use: FDU has implemented policies, procedures, and controls designed to monitor and log the activity of authorized users and detect unauthorized access or use of, tampering with, covered information. Various specific measures are identified in Appendix 1.

    These measures will include assessing the University’s current policies and procedures relating to FDU’s Acceptable Use Policy for Computer Usage, Confidentiality Agreement and Security Policy, FDU Procedure on Handling Data on Separating Employees, Password Policy, Policy for Acceptable Use of Email, Software Compliance & Distribution Policy, and Written Information Security Program. The CISO will also coordinate with the CIO and the OIRT to assess procedures for monitoring potential information security threats associated with software systems and for updating such systems by, among other things, implementing patches or other software fixes designed to deal with known security flaws.
  1. Monitoring the Effectiveness of Safeguards: FDU periodically conducts penetration tests and vulnerability assessments on its network and key information systems. These measures are designed to test and monitor the effectiveness of the safeguards’ key controls, systems, and procedures, including those to detect actual and attempted attacks on, or intrusions into, FDU’s information systems.

    For those systems where continuous monitoring (or other methods to detect, on an ongoing basis, changes in information systems that may create vulnerabilities), is not practical, FDU will conduct:

    (i) Annual penetration testing on FDU’s information systems identified by OIRT based on relevant identified risks under the risk assessment; and

    (ii) Vulnerability assessments of FDU’s information systems, including systemic scans or reviews of information systems designed to identify publicly known security vulnerabilities in FDU’s information systems based on the risk assessment, at least every six months; and whenever there are material changes to FDU’s operations or business arrangements; and whenever there are circumstances that OIRT knows (or has reason to know) may have a material impact on FDU’s information security program.
  1. Detecting, Preventing and Responding to Attacks: The OIRT and University Risk Manager will on a regular basis evaluate procedures for and methods of detecting, preventing, and responding to attacks or other system failures and existing network access and security policies and procedures, as well as procedures for coordinating responses to network attacks and developing incident response teams and policies. The FDU Data Security Incident & Response Team implements all aspects of, oversees other Departments’ adherence to, and documents all incident response activities. Upon determination by the CISO and General Counsel that a Security Incident triggers breach notification laws, the University will report the breach to relevant federal or state regulatory authorities by their designated methods; and, where applicable, the U.S. Department of Education, including details about date of breach (suspected or known); impact of breach (e.g. number of records); method of breach (e.g. hack, accidental disclosure); information security program point of contact – email and phone details; remediation status (e.g. complete, in process); and next steps (as needed).

    These measures will be documented in a comprehensive incident response plan that addresses:

    (i) The goals of the incident response plan;

    (ii) The internal processes for responding to a security event;

    (iii) The definition of clear roles, responsibilities, and levels of decision-making authority;

    (iv) External and internal communications and information sharing;

    (v) Identification of requirements for the remediation of any identified weaknesses in information systems and associated controls;

    (vi) Documentation and reporting regarding security events and related incident response activities; and

    (vii) The evaluation and revision as necessary of the incident response plan following a security event.
  1. Overseeing In-House Developed Applications and External Service Providers: The OIRT leadership working in collaboration with the CISO will help ensure that software applications and solutions developed in-house by FDU, including modifications to third-party programs, meet the safeguard standards of this Policy. The CIO, CISO and other appropriate OIRT leaders will also coordinate with FDU’s contract review teams to raise awareness of, and to institute methods for, selecting and retaining only those service providers that can maintain appropriate safeguards for nonpublic financial information of students and other third parties to which they will have access. In addition, the CIO and CISO will work with the General Counsel and the University Risk Manager to develop and incorporate standard, contractual protections applicable to third-party service providers, which will require the providers to implement and maintain appropriate safeguards.

    Utilizing a variety of automated risk assessment tools such as Bitsight, OIRT periodically assesses FDU’s service providers on the risk they present and the continued adequacy of their safeguards.
  1. Encryption: FDU adopts methods to protect by encryption covered information held or transmitted by the University by encrypting both in transit over external networks and at rest. To the extent that encryption of covered information, either in transit over external networks or at rest, is infeasible, FDU secures the covered information using effective alternative compensating controls reviewed and approved by the CISO.
  1. Multifactor authentication: FDU has implemented multi-factor authentication for any individual accessing the University’s information systems, except where the CISO has approved in writing the use of reasonably equivalent or more secure access controls.

    Multi-factor authentication is defined as authentication through verification of at least two of the following types of authentication factors:

    (1) Knowledge factors, such as a password;

    (2) Possession factors, such as a token; or

    (3) Inherence factors, such as biometric characteristics.
  1. Data Retention and Disposal Controls: FDU has in place procedures for the secure disposal of covered information in any format, consistent with the University’s operations and other legitimate business purposes, except where required to be retained by law or regulation, or where targeted disposal is not reasonably feasible due to the manner in which the information is maintained. Where information is not needed to be retained, the University will take reasonable measures to include processes for disposal of covered information no later than two years after the last date the information is used for legitimate University purposes. The Program includes periodic review of our data retention policy to minimize the unnecessary retention of data.
  1. Adjustments to Program: Risk assessment activities will be periodically performed to reexamine the reasonably foreseeable internal and external risks to the security, confidentiality, and integrity of covered information that could result in the unauthorized disclosure, misuse, alteration, destruction, or other compromise of such information, and to reassess the sufficiency of any safeguards in place to control these risks. The CISO is responsible for evaluating and recommending adjustments to the program based on the undertaken risk identification and assessment activities, as well as any material changes to FDU’s operations or other circumstances that may have a material impact on the Program.
  1. Reports to the Board: The Vice President of OIRT will submit written reports to the Board of Trustees at least once each calendar year. The report will include the following information:

    (1) The overall status of the Program and FDU’s compliance with the safeguard requirements under the GLBA;

    (2) Material matters related to the Program, addressing issues such as risk assessment, risk management and control decisions, service provider arrangements, results of testing, security events or violations and management’s responses thereto, and recommendations for changes in the information security program.

The CIO may approve deviations to the processes set forth in this Policy to meet changing conditions at the University, so long as such deviations are designed to achieve the safeguard goals set forth in this Policy and do not violate the GLBA and other applicable laws.

Appendix 1
Certain Additional Specific Safeguards

Periodically (generally at least once each year), leaders from applicable University departments and units are surveyed regarding their processes for safeguarding covered information, using a standard template. Results are compiled and conveyed to the CIO for review and follow-up, including adopting and incorporating results in the University-wide Risk Assessment.

The CIO will determine which departments and units should receive the assessment survey, based on their handling of covered information. Currently, the units are: OIRT, Office of Enrollment Services, Credits and Collections, Admissions, International Admissions, Financial Aid, Veteran Services, Accounts Payable, Management Information Systems, Conference & Summer Programs, School of Pharmacy, and the Controller’s Office.

The standard assessment template is as follows.

  1. Designate an employee or employees to coordinate the unit’s information security program.
  2. Identify reasonably foreseeable internal and external risks to the security, confidentiality, and integrity of customer information that could result in the unauthorized disclosure, misuse, alteration, destruction or other compromise of such information, and assess the sufficiency of any safeguards in place to control these risks. At a minimum, such a risk assessment should include consideration of risks in each relevant area of your operations, including:
  • Unauthorized disclosure of sensitive information by employees through intentional or unintentional methods.
  • Unauthorized access, disclosure, misuse, alteration or destruction of information on hosts.
  • Detection and prevention of attacks on the systems.
  • Unsecured transmission of data.
  • Physical security of computer systems, network equipment, backups and paper materials.
  • Managing data integrity and system failures.
  1. Design and implement information safeguards to control the risks you identify through risk assessment, and regularly test or otherwise monitor the effectiveness of the safeguards’ key controls, systems, and procedures.
  1. Unauthorized disclosure of sensitive information by employees through intentional or unintentional methods:
  2. Unauthorized access, disclosure, misuse, alteration or destruction of information on hosts:
  3. Detection and prevention of attacks on the systems:
  4. Unsecured transmission of data:
  5. Physical security of computer systems, network equipment, backups and paper materials:
  6. Managing data integrity and system failures:
  1. Oversee service providers, by: (1) Taking reasonable steps to select and retain service providers that are capable of maintaining appropriate safeguards for the customer information at issue; and (2) Requiring FDU’s service providers by contract to implement and maintain such safeguards.
  1. Evaluate and adjust FDU’s information security program in light of the results of the testing and monitoring required by this Policy; any material changes to FDU’s operations or business arrangements; or any other circumstances that are known or have reason to be known as having a material impact on FDU’s information security program.

The following is an example of a completed assessment survey, from OIRT:

Gramm Leach Bliley Security Program
Office of Information Resources Technology
Standards for Safeguarding Customer Information

(a) Designate an employee or employees to assist the CIO in the coordination of the Program.

In addition to the CISO, the Director of Systems and the Director of Networking are the designated employees for the Office of Information Resources Technology

(b) Identify reasonably foreseeable internal and external risks to the security, confidentiality, and integrity of customer information that could result in the unauthorized disclosure, misuse, alteration, destruction or other compromise of such information, and assess the sufficiency of any safeguards in place to control these risks. At a minimum, such a risk assessment should include consideration of risks in each relevant area of your operations, including:

  • Unauthorized disclosure of sensitive information by employees through intentional or unintentional methods.
  • Unauthorized access, disclosure, misuse, alteration or destruction of information on hosts.
  • Detection and prevention of attacks on the systems.
  • Unsecured transmission of data.
  • Physical security of computer systems, network equipment, backups and paper materials.
  • Managing data integrity and system failures.

(c) Design and implement information safeguards to control the risks you identify through risk assessment, and regularly test or otherwise monitor the effectiveness of the safeguards’ key controls, systems, and procedures.

  1. Unauthorized disclosure of sensitive information by employees through intentional or unintentional methods:
  • Employees go through mandatory Written Information Security Program (WISP) Training
  • Prior to any IT requests, User Information Is checked against WISP to ensure they are current with training
  • Employees are provided training and are closely observed by managers before being given access to sensitive information. Training includes password policy and management, physical security of cabinets, storage, and equipment rooms, and recognizing fraudulent attempts to obtain sensitive information.
    • Policy, social engineering, keystrokes loggers, etc.
  • All employees must sign and accept the University’s “Acceptable Use Policy” and the “Confidentiality Agreement” if applicable.
  • Requests for sensitive information are directed to individuals with proper training and authority to review the request.
  • Potential employees are subjected to a background check before being hired by the University.
  • Updated IT Informational website that includes documentation of all policies and procedures specific to securing data.
  • Use of Data Loss Prevention tool to proactively monitor and correct non-compliance issues
  • Access to information is granted only to the extent required for the employee to perform their job functions.

2) Unauthorized access, disclosure, misuse, alteration or destruction of information on hosts:

  • Passwords are required for access to any system with sensitive information.
  • Strong password policies are in place where possible.
  • Multi-factor authentication to access sensitive systems for all faculty, adjuncts, staff and students.
  • Multi-factor authentication for all admin accounts.
  • Auditing systems (e.g. Change Management Process, Netwrix, Microsoft ATP) are used to track and report on changes to critical files.
  • Notifications of employee terminations are received prior to or on date of termination. Immediate notification is received when circumstances warrant instant suspension of access to systems.

3) Detection and prevention of attacks on the systems:

  • Auditing systems (e.g., Netwrix) are used to detect attempts to breach systems or alter system configurations.
  • System logs are reviewed daily for evidence of attacks.
  • Policies are in place to regularly apply patches to systems.
  • A firewall is in place for perimeter protection.
  • Obsolete systems are being replaced by newer systems that are better supported by hardware and software vendors. Most systems include host-based firewalls.
  • The wired portion of the university network is entirely switched to minimize the possibility of packet sniffing and other similar attacks.
  • WPA2 Enterprise is deployed and available for wireless accessible locations.
  • Endpoint protection software is in place, which automatically updates servers & clients.

4) Unsecured transmission of data:

  • Connections to all systems are using modern cryptographic techniques.
  • University standard practice is to use HTTPS for web services; all publicly accessible web traffic is proxied through load balancers.
  • SFTP is used to transmit data to various vendors securely.
  • EFax services deployed, ensuring fax transmission are encrypted both in transit and at rest.
  • Virtru software for encrypted email communication of sensitive and Personally Identifiable Information
  • 7-Zip is used to encrypt files being sent to and from vendors.

5) Physical security of computer systems, network equipment, backups and paper materials:

  • All computer systems and core network equipment are physically secured in locked rooms or cabinets.
  • Essential services are monitored for availability and alerts are sent when a system or service becomes unavailable.
  • Printed material with personal information is shredded when no longer needed.
  • The main datacenters and several ancillary MDF’s have heat and humidity detection systems as well as a fire suppression system.
  • Alarms with motion detectors are in place in all data centers. The university department of Public Safety monitors the alarms.
  • Security cameras are set and on 24 hour recording on both main data centers
  • A card access system controls access to the data centers and IT administrative offices.

6) Managing data integrity and system failures:

  • Daily backups of host systems are performed.
  • Network hardware configurations are backed up weekly.
  • Out of band capabilities exist to support network management and large-scale outages.
  • Continual off-site backup of all FDU owned workstations.
  • Mirroring of networked file services across campuses is occurring.
  • UPS systems provide backup power to central data centers.
  • Extending backup capabilities to include off-site backup of all University systems
  • A backup generator is in place for the main data centers.
  • A disaster recovery plan has been developed.

(d) Oversee service providers, by: (1) Taking reasonable steps to select and retain service providers that are capable of maintaining appropriate safeguards for the customer information at issue; and (2) Requiring FDU’s service providers by contract to implement and maintain such safeguards.

Contracts require appropriate safeguarding measures be taken by the vendor. Third Party Assessment evaluation using Industry best practice tools prior to executing contracts.

(e) Evaluate and adjust FDU’s information security program in light of the results of the testing and monitoring required by this Policy; any material changes to FDU’s operations or business arrangements; or any other circumstances that are known or have reason to be known as having a material impact on FDU’s information security program.

OIRT continually performs extensive reviews of applicable written policies and has a continuous program in place to review applicable policies and procedures.

OIRT periodically (generally annually) performs an eMail Phishing test to all full-time faculty and staff. FDU uses a third party as the tool for performing the test. Individuals who fail the Phishing test are required to complete remedial training with a passing score. Supervisors are made aware of those who fail the test and are encouraged to speak with their employees.

OIRT conducts comprehensive vulnerability assessments aligned to the NIST Risk Management Framework (RMF) that included external vulnerability scanning, penetration testing, netflow analysis of our IP ranges, review of IT and cybersecurity-specific and FDU-wide documentation, and dark web footprinting.

OIRT takes action to increase the cadence of monitoring and reacting to server, desktop and mobile device alerts, ensure compliance of website configurations and deploy security measures to ensure security of email system and reduce spoofing of emails.


Last Modified:

SAMI Shorts

Resources for:
icon Close

SAMI Shorts are brief informational videos that provide key insights on a variety of IT-related topics. Most videos run 45–90 seconds, include closed captioning, and are also available in text format. As new SAMI Shorts are released, we will periodically share them with the community via email. You may also receive a related SAMI Short as part of a response to a SAMI Support ticket.

View our entire catalog of SAMI Shorts:

SAMI Shorts Catalog

Last Modified:

SAMI Support Public Request Form

Resources for:
icon Close

The SAMI Support portal requires a valid NetID and password, along with DUO multi-factor authentication, for access. Upon entry, users can create new tickets, review open or closed requests, and explore the IT Knowledgebase for solutions to common issues. Access the support portal using the button below:

SAMI Support Portal

If you need to open a request and cannot access SAMI Support for any of the reasons below, please complete this request form to contact the Fairleigh Dickinson University Technical Assistance Center (UTAC). A member of the IT support team will assist you via phone call or email.

  • I do not have a valid University issued NetID
  • I am not able to authenticate through DUO
  • I have not set up my DUO account
  • I am a vendor without a University issued NetID
  • I am an admitted student
  • I am a newly hired employee or adjunct
  • My FDU account is locked
  • I need my Net ID password reset and have already attempted to do that through identity.fdu.edu

Tip

The form below is not compatible with Dark Mode. For an optimal experience, disable Dark Mode either in your device’s system settings or directly from the FDU IT website menu bar.

SAMI Support Public Request

Last Modified:

Secure Deletion Steps for Personal Information

Resources for:
icon Close

Introduction

This document outlines the university approved process for securely deleting Personal Information (PI) and Protected Health Information (PHI) after the PI or PHI has been encrypted.

Prerequisite

Eraser Portable® Secure Data Remove software needs to be installed on your computer. Please contact the Fairleigh Dickinson University Technical Assistance Center (UTAC) to request the installation of this software. A member of USAN will assist with the installation and setup of the software.

Document Deletion Process

To securely delete an unencrypted version of a document that contain PI and/or PHI that has been encrypted, complete the following steps:

  1. Find the “Secure Deletion” shortcut folder on your computer desktop screen
  2. Cut and paste the unencrypted version of the file to be deleted into this folder
  3. Find the “Eraser Portable” shortcut folder on your computer desktop screen and click to open the folder
  4. Double Click on “EraserPortable.exe“. The screen below will appear
  5. Click on the Green Run arrow to erase the file securely
secure 1
  1. A dialogue box will appear
  1. Click “Yes
  2. When the deletion process completes, you will see a report appear
  1. You may check your “Secure Deletion” folder to see if all documents have been erased

Outlook E-mail Deletion Process

To securely remove emails which contain PI and PHI from your Outlook client, complete the following steps:

  1. Delete the email from your Inbox and/or Sent items folder
  2. Delete the email from your Deleted Items
  3. Go to “Recover Deleted Items
  4. Highlight Deleted Items Folder
  1. Then go to Folder > Recover Deleted Items
  1. Highlight email which requires permanent deleting and select “Purge Selected Items” and then click “OK“. Now message is permanently out of your email system
  1. Finally, click “OK” on the following screen
secure8
Last Modified:

Secure Encryption Steps for Personal Information

Resources for:
icon Close

This document outlines the University approved process for securely encrypting Personally Identifiable Information (PII).

Prerequisite

7Zip software needs to be installed on the end user’s computer. Please contact the Fairleigh Dickinson University Technical Assistance Center (UTAC) to request the installation of this software. If justification is needed, notify UTAC that 7Zip is needed to encrypt documents containing PII.

Process

Encrypting Files and Folders

To encrypt a single file, find the file in your directory (or where you have it saved).

  1. Right click on the document (do not open the document)
  2. On the drop down menu, Find 7zip
  3. Click “Add to archive…
  4. When 7zip opens, there are three (3) settings which need to be changed:
    • Archive Format = Select zip from drop down
    • Encryption Method = select AES-256 from drop down
    • Check “show password” and type in a password that the user creates
    • Click “OK
    • A 7Zip Archive with the encrypted document will now appear in your directory

NOTE: Do not utilize any password that you use to access internal systems. The password cannot be recovered if forgotten.

Editing Encrypted Files and Folders

When editing an encrypted file or folder, you must make sure that you leave the 7zip archive open. If you close the archive, you will be able to work on the document, but it will not save.

Opening an Encrypted File or Folder

To open an encrypted file or folder:

  1. Right click on the 7Zip archive
  2. On the drop down menu, find 7Zip
  3. Click on the first “Open archive”
  4. Click to open your document

Saving an Encrypted File or Folder

To save an encrypted file or folder:

  1. Save the document as normal
  2. Upon closing document, the 7Zip archive will prompt the user to save the changes
Last Modified:

Setting up a Security Key for Duo Authentication

Resources for:
icon Close

Setting up a security key for Duo authentication ensures a higher level of protection for your online accounts. This guide walks you through the process step by step, helping you seamlessly integrate this secure method into your two-factor authentication system.

Compatibility Notice

To ensure compatibility, please use the current version of Google Chrome, Firefox, Safari, or Microsoft Edge. Legacy devices that are incapable of receiving browser updates will be unable to authenticate via security key. To ensure that you can still authenticate to these legacy devices and to other potentially incompatible applications, we ask that you keep Duo Push active as a secondary authentication method.

Setting up a Security Key for DUO Authentication

  1. Visit 2fa.fdu.edu and log in using your NetID username and password

DUO Management Portal

  1. When prompted by Duo authentication, select “Send Me a Push” or select your preferred authentication method and authenticate
  1. Plug your security key into an available USB port on your computer

Tip

All FDU-issued laptops are equipped with USB-C connections. If your device does not have a USB-C port, you can use a USB-C to USB-A adapter to connect the security key.

  1. Once the security key is connected, select “Add Another Device”
  1. Select “Security Key” and click “Continue”
  1. Click “OK” on the security key setup screen
  1. Click “OK” on the Continue Setup screen
  1. Press the button on your security key when prompted
  1. To set the security key as your default device:
    • Select “Security Key” from the Default Device dropdown menu
    • Click “Save”

Recommended Security Keys

For enhanced security and seamless integration with Duo authentication, we recommend purchasing Yubico NFC security keys. Yubico offers both USB-C and USB-A versions to suit your device’s port compatibility.

Last Modified:

Spot a Phishing Scam

Resources for:
icon Close

What is a phishing scam?

Phishing refers to the act of using a fraudulent identity and scenario to extract personal information or something else of value. Although phishing scams can occur over various mediums including text messages, phone calls, and social media, they are most frequently carried out via email.

Scammers have many means of acquiring bulk email addresses. Receiving a phishing attempt does not mean that your account has been singled out or has been compromised in any way.

Fairleigh Dickinson University’s email accounts employ Microsoft’s Advanced Threat Protection (ATP) which, in addition to traditional spam filtering, removes malware infected attachments and utilizes Safelinks to scan messages for malicious links. Additionally, we have appended the subject line of messages coming from outside of the FDU domain with the “[External]” tag. Although phishing can occasionally come from inside of our domain, messages with the external tag demand extra scrutiny.

Despite all of these efforts, keeping up with the latest scams is always a cat and mouse game. It is best practice to have a solid foundational knowledge of how these scams work.

Detecting a Phishing Scam

Although each phishing scam is unique, there are certain common traits which can serve as red flags. The most common “tell” is a sense of urgency. Generally, phishers would like for you to act promptly and without careful consideration. As a result, they will pepper their email with phrases such as “immediate action required” and “to avoid the immediate suspension of your account”.

Although an urgent tone is likely to be your first clue, there are plenty of other red flags that you will begin to notice over time. Many phishing attempts are poorly constructed emails. Incorrect spelling and grammatical errors are common. The message could contain a blank subject line and the sender’s signature may only list their title instead of their name. Be wary of messages in which the quality of writing does not meet your expectations for the purported institution.

The goal of many scams is to make a request for your personal information. This can take the form of bluntly asking for your social security number. However, it may also take a subtler approach. Many phishing attempts will create a mock version of a University, banking institution, or commerce website and ask you to log in. Once you enter your account information, the scammers have acquired your password.

Although most phishing scams cast a wide net, some recent attacks have specifically targeted individual members of the University. If someone is claiming to be your colleague or supervisor, check to confirm that the message is coming from their FDU account. Do not trust messages claiming to be from FDU employees which originate from external accounts such as Gmail and Yahoo.

Many of these personalized scams also have a very specific common thread. After a bit of conversation, the scammer will request that you purchase gift cards for common services such as iTunes, Google Play, or Amazon. No, your boss does not urgently require you to purchase gift cards out of pocket.

Also, beware of solicitations coming to your FDU email address from businesses offering deals or asking you to click on a banner to receive a promotion. Make sure that the email is coming from the domain of the company offering the sale or promotion.

What does a phishing scam look like?

Now that you know what to look for, let’s look at a sample phishing attempt:

Reporting a Phishing Scam

You can use your newfound expertise to assist the FDU community. When you see a message that you believe to be a phishing scam, please report it to us. Via Outlook this can be accomplished via our reporting tool. Please see Reporting Phishing or Junk Emails for more information. If you are using an alternative mail client such as Apple Mail, you can forward the suspected scam to phishing@fdu.edu.

How should I proceed if I have already replied to a Phishing Scam?

Please change any passwords that you have provided to the scammer. Once this is completed, please contact the Fairleigh Dickinson University Technical Assistance Center (UTAC) for further instructions.

Last Modified:

Student Technology Resources

Resources for:
icon Close

Fairleigh Dickinson University provides an extensive array of technological resources and services tailored for our students. This guide is designed to assist students in navigating and utilizing these tools effectively, ensuring they can easily set up, access, and manage their accounts, while also offering comprehensive information on each service.

ID and Email

FDU NetID

Your FDU NetID verifies who you are and ensures the privacy of your personal information. Your FDU NetID and your NetID password will provide access to a variety of IT resources including your Self-Service, WebCampus, Office365, and Email.

To obtain your NetID, follow the guide below:

close
Changing your FDU NetID Password

To protect the University and our Students from cyber attacks and other malicious activity, we require that everyone in our community to periodically change their password.

To change your password, follow the guide below:

close
DUO Multi-factor Authentication

To successfully use your NetID to access your accounts, you will need Two-Factor Authentication with Cisco DUO MFA.

Two-factor authentication adds a second layer of security to your FDU NetID. It requires two factors to verify identity. These factors include something you know – your FDU NetID and password, and something you have – a phone or passcode, to authenticate and gain access to your account on FDU services. Passwords alone no longer provide adequate protection against cyber hacking. DUO is required for all current FDU students.

To set up your mobile device with DUO MFA, follow the guide below:

Additionally, refer to our FAQ for commonly asked questions about DUO:

close
Email and Office 365

Students can access their emails through any Web browser using their NetID and password to log in. To access our email, visit the Office 365 Portal:

Office 365 Portal

Students can also access their FDU Email accounts on their mobile devices by installing the Outlook app. For instructions to setting up your FDU Email account in the Outlook app, follow the guide below:

Current students who are registered for classes for the current term, or a future term have access to Microsoft Office 365 Suite applications. For more information, visit the links below:

close

Academic Systems

Webcampus

Webcampus is a course content management system. FDU’s Webcampus is also known as the Blackboard System. On-line courses are taught through this system which also allows for interaction between the student and faculty member as well as on-line class discussions.

To learn more about how to access Webcampus, review the guide below:

close
Self-Service

Self-Service is an interactive web application that enables students to view their individual information contained in FDU’s Student Information System. Students can use Self-Service to do things like view their financial aid, pay their bills, and register for classes.

Review the Tutorial below to learn how to use Self Service:

close

Connectivity

Connecting to the FDU Wireless Network

Using your FDU NETID, you can connect to the FDU Wireless Network. For instructions view the links below:

close

Security

Security Resources

Understanding and implementing cybersecurity measures is crucial for protecting your personal and institutional information. This section provides essential resources to help you navigate the landscape of cyber threats.

Stay safe online by reviewing the articles below:

close

Software

Available Software for FDU Students

Fairleigh Dickinson University has both licensed and open-source software, that is offered for academic and/or personal use for students. The links below point out to commonly used software, both licensed and open source, that are offered for academic and/or personal use to all Fairleigh Dickinson University faculty, staff and students.


In our digital learning environment, mastering online tools is essential for academic success. These resources are designed to guide you through the process of engaging in classes virtually via Zoom and accessing your files on OneDrive.

close

Printing and Labs

Computer Labs and Printing

Computing Services has multiple computer labs available on both New Jersey Campuses for classroom instruction and student use.

close
Virtual Labs

FDU also provides remote access to many of the software applications typically found in university computer labs through our platform FDU Anywhere. You can access it using your FDU NetID credentials using the link below:

FDU Anywhere

Review the FDU Anywhere Tutorial below to learn how to use our virtual labs:

close

For any IT related questions and support, contact our Fairleigh Dickinson University Technical Assistance Center (UTAC):

SAMI Support

Last Modified:

Use SFTP or SCP to Upload Files to a FDU Linux Server

Resources for:
icon Close

What’s SFTP and SCP?

Secure File Transfer Protocol (SFTP) is a file protocol for transferring large files over the web. It builds on the File Transfer Protocol (FTP) and includes Secure Shell (SSH) security components. This term is also known as Secure Shell (SSH) File Transfer Protocol. Secure copy protocol (SCP) is another method to securely transfer files between a your local PC and a remote host or between two remote hosts. It is also based on the Secure Shell (SSH) protocol.

Linux / Mac

If you are running a Linux or Mac computer, SFTP and SCP clients are already installed, so you don’t need to download anything using those OS. You can open up a terminal window and run the either command like below to connect to a remote Linux server.

sftp username@opus.fdu.edu

or

scp filename username@132.238.2.116:

Windows

Option 1: Use WinSCP (Recommended)

You will need to download and install WinSCP:

Download WinSCP

  1. Launch the WinSCP program
  2. In the login window, click “New Site
  1. Fill out the information as follows:
    • Host name: Enter opus.fdu.edu
    • User name: (username on FDU Linux servers will be the part of your FDU NetID to the left of the @ sign)
  2. Click “Advanced…
    • Select “Environment > SFTP” and enable “Allow SCP fallback
  1. Click “OK
  2. Click “Save“, enter a name for the connection, and click “OK
  3. In the WinSCP login window, select the connection name and click “Login

Option 2:

Install Putty, which also includes PSCP (SCP for Windows) and SFTP (SFTP for Windows):

Download Putty

Please select the latest version of MSI (‘Windows Installer’) for your computer (32-bit or 64-bit)

Optionally you may choose to download only pscp.exe(SCP for Windows) or “psftp.exe” (SFTP for Windows) and copy into the folder where you need to use it.

Once you have installed your program of choice, you’ll be able to launch each command from the Command Line of Windows.

pscp -P 22 filename username@opus.fdu.edu:
psftp username@opus.fdu.edu

Note

You may need to accept the server’s host key the first time you connect the Linux server.

Last Modified:

Use SSH to Log into Opus Linux Server

Resources for:
icon Close

Accessing the Opus server

The Opus server can be access using secure transport protocols such as SSH and SFTP. Access is only allowed from campus networks. All off campus users will need to access Opus using FDU’s Virtual Private Network (VPN) to use the Opus server

What’s SSH?

SSH stands for Secure Shell, which was invented in 1995 to replace the insecure Telnet (Telecommunication Network). It’s now the primary way for system administrators to securely log into remote Linux servers over the public Internet. Although it looks and acts the same as Telnet, all communications over the SSH protocol are encrypted to prevent packet sniffing.

Linux / Mac

If you are running a Linux or Mac computer, SSH client is installed by default. You can open up a terminal window and run the ssh command like below to connect to a remote Linux server.

ssh username@opus.fdu.edu

or

ssh username@132.238.2.116

Now let’s discuss how to use SSH on Windows.

Windows

Method 1: Windows 10’s Built-in SSH Client

The Microsoft PowerShell team decided to port OpenSSH (both the client and the server) to Windows in 2015. It finally arrived in Windows 10’s Fall Creator Update in 2017 and is enabled by default in the April 2018 Update.

To use the OpenSSH client on Windows 10, simply open a PowerShell window or a command prompt window and run the ssh command. For example, if I want to connect to the Opus Linux server on the FDU network, I would run

ssh username@opus.fdu.edu

username on FDU Linux servers will be the part of your FDU NetID to the left of the @ sign (username@fdu.edu becomes just username) and opus.fdu.edu is name the Linux server you want to access (The IP address of the Linux server can also be used). The first time you connect to a Linux computer, you will be prompted to accept the host key. Then enter your password to login. After login, you can run Linux commands to do tasks.

Note

If you want to paste a password into the PowerShell window, you need to right-click the mouse and press Enter.

To log out from the Linux box, run the “exit” command or press “Ctrl+D“.

The default font size in PowerShell Window is very small. To change it, right-click the titlebar and select properties, then you can change the font size, and the background color.

Method 2: Use SSH in Windows Subsystem for Linux

Windows Subsystem for Linux (WSL) enables you to run native Linux command-line tools directly on Windows 10. If you are a system administrator, WSL is probably an overkill for just using SSH because it would install and run a Linux distro (without graphical user interface) on your Windows 10 desktop. WSL is created for web developers or those who need to work on open-source projects. You can use not only SSH but also other Linux command line tools (Bash, sed, awk, etc).

Open the Microsoft Store and enter “WSL” in the search box. Select Run Linux on Windows and install a Linux distro of your choice.

For example, I choose “Ubuntu” and click the “Get” button to install it.

Once your Linux distro is installed, open the Control Panel and select Programs => Turn Windows features on or off. Tick on the checkbox of Windows Subsystem for Linux to enable this feature. (You may need to reboot your Windows PC for this change to take effect.)

Next, you can launch the Linux distro from the start menu by search the distro’s name. The first time you launch it, you need to create a user and set a password.

After that, you can use the ssh command like below to connect to a Linux server or PC that runs a SSH server.

ssh username@opus.fdu.edu

Method 3: Use Putty

Putty is a well-known and the most popular SSH client on Windows before the arrival of Windows OpenSSH client and Windows Subsystem for Linux. To use SSH with Putty, you need to download the Putty program from the official website and install it.

Launch Putty from the Start menu. Then enter the IP address or hostname of the Linux box and click the Open button to connect to it.

Accept the host key and you will be prompted to enter the username and password.

Tip

When you type in your password, the cursor doesn’t move, but it’s actually accepting your password. To paste text into Putty, first press Ctrl+C to copy the text, then go to Putty window and press the right-button of your mouse.

Last Modified:
FAQ
  • An alias is an additional email address that will direct mail to your FDU email account. Creating an alias for your account can be a useful strategy. For instance, if you are spearheading a project, it may be easier to solicit replies to an address that contains the name of the project than it would be to garner responses to your existing email address. If this solution interests you, please fill out the Email Alias form.

  • Due to the cavernous email storage offered on the Office365 platform, there has been little to no demand for FDU staff and faculty members to request an increased mail quota. Office365 email provides enough capacity for even our most prolific users. However, if special circumstances make you the exception to this rule, you can request a quota increase by completing the Quota request form.

  • FDU’s Acceptable Use Policy prohibits running software that accepts incoming connections from other computers. Programs such as BitTorrent or other P2P file sharing hosting program all contain server components that allow others to connect to your computer and retrieve files from your system. In addition to the legal implications of sharing copyrighted materials, file sharing software creates a security concern. Improper use of these programs could result in the compromise of your private files and may leave your system open to attacks from other computers.

  • Phishing involves the use of e-mail messages that appear to come from your bank or another trusted business in an attempt to scam the user into surrendering private information that will be used for identity theft. The phishing e-mail typically ask you to click a link to visit a Web site, where they are asked to update personal information, such as passwords and credit card, social security, and bank account numbers

    Scammers have become increasingly sophisticated in creating fraudulent emails and Web sites that look authentic. These emails and Web sites often appear to be from legitimate companies and include images and logos of these organizations.

  • The Network ID (NetID) is a Windows Active Directory account uniquely assigned to each student, faculty & staff. It serves as your login to many computing and networking services including FDU Email.

  • FDU’s Opus is a Red Hat Linux based server. Opus provides an environment for FDU students, staff, and faculty to practice using software such as:

    • Expect
    • Gcc
    • Gzip
    • Aspell (Ispell replacement)
    • Java (Now 1.8.0_181)
    • Make
    • Ncurses
    • Tcl
    • Tcsh
    • Tcl/Tk
    • Strace (Trace)
    • Emacs
    • Bison
    • Nano (Formerly Pico)
    • Perl
    • LaTeX
    • A2ps
    • Links (Lynx Alternative)

    If you require access to Opus, please fill out the form.

  • In order to provide a safe and stable computing environment, the FDU-Wireless and FDU-Secure wireless networks require NetID authentication. However, in certain instances our students, staff and faculty members will need to work on campus with people from outside of our community. This can include vendors, contractors, visiting scholars, or even a visiting family member or friend. In these instances, the FDU community member can sponsor a guest for temporary wireless access.  The sponsor of a guest account will be responsible for the actions of his or her guest. Please ensure that your guest(s) follow FDU’s Acceptable Use Policy for Computer Usage

  • In order to provide a safe and secure network environment, FDU IT requires devices to authenticate to the FDU network before connecting. This works well for computing devices such as desktop computers, laptop computers, and mobile devices such as tablets and phones. Most other electronics, including gaming consoles and streaming video boxes, cannot properly authenticate to the network. In these instances, we ask you to register the device using the online form below. Please note that each user on our network is entitled to register up to 5 devices.

Christopher Robley University Systems and Networking Director of Systems
Michael Reekie University Systems and Networking Director
Stuart Alper University Systems and Networking Associate Vice President
Anthony Licandro University Systems and Networking Manager
Atif Warriach University Systems and Networking Systems Administrator (Linux)
Basil Licop University Systems and Networking Office 365 Systems Administrator
Charles Ciccotto University Systems and Networking Operations Manager
Christopher Bland University Systems and Networking Systems Manager Lead
Cory Palacios Merino University Systems and Networking IT Assistant – Vancouver
Danovan Golding University Systems and Networking Senior System Technology Manager
Djeams Muse University Systems and Networking Network Analyst
Estref Resuli University Systems and Networking Technician Operations – Vancouver
Joshua Chan University Systems and Networking Systems Analyst
Juan Estrella University Systems and Networking Network Analyst
Juan Montufar University Systems and Networking Network Analyst
Karl Henry University Systems and Networking Senior Desktop Engineer
Kevin Atkinson University Systems and Networking Systems & Network Infrastructure Manager – Vancouver
Leslie McRae University Systems and Networking Operations Systems Analyst
Matt Gugel University Systems and Networking Senior Desktop Engineer
Rafael Alix University Systems and Networking Network Analyst
Shashi Patel University Systems and Networking Network Analyst
Thomas Grassi University Systems and Networking Junior Systems Administrator
Torence Bobbitt University Systems and Networking User Support Helpdesk Technician
Vishal Gandhi University Systems and Networking Systems Analyst / Application Developer / Email Specialist