Information Security
Information security is vital for securing data, maintaining guidelines, ensuring compliance, preventing cyber-attacks, and building trust. The IT security office is dedicated to protecting the college’s systems, data, and community. We work to ensure a safe digital environment for students, faculty, and staff while supporting teaching, learning and innovation.
Security Awareness
Cybercriminals often use fake emails, texts, phone calls or links to steal your information. They often pretend to be a legitimate organization, create a problem, apply pressure and ask for payment or personal info.
Think Before You Click
Cybercriminals often use fake emails, texts, phone calls, or links to steal your information. They often Pretend to be a legitimate organization, create a Problem, apply Pressure, and ask for Payment or personal info.
Watch for:
- Urgent or threatening messages
- Requests for passwords or MFA codes
- Unexpected attachments or links
- Messages that seem “too good to be true”
Never share your password or verification code with anyone.
The IT Department and Helpdesk will never ask you to share your password, multi-factor authentication (MFA) codes, or account information by email, text, or phone.
Protect Your Account
- Use strong, unique passwords
- Enable Multi-Factor Authentication (MFA)
- Do not reuse passwords across sites
- Lock your computer when unattended
Phishing Awareness
Phishing emails may look like they come from trusted sources such as
Microsoft or college departments.
Common examples:
- “Your account will be suspended”
- “You received a file”
- “Verify your account now”
Always verify the sender before clicking.
Report Suspicious Activity
If you receive a suspicious email or notice unusual activity:
- Do NOT click links or download attachments
- Report it immediately to the IT Helpdesk
- Use the “Report Phishing” button
NEVER disclose ANY personally identifying information via an unsolicited email, text, or phone. This includes:
- Account numbers or debit/credit card numbers
- Personal Identification Numbers (PIN) or passwords
- Social Security number
- Mother's maiden name
For More Information
Refer to the Federal Trade Commission (FTC) for more information. If you have any questions, contact the IT Help Desk at x4357.
Tax Scams and Malicious Activity
Every year, the bad guys take advantage of innocent taxpayers, like you, who are patiently waiting on their tax return. Last year, the IRS noticed a significant increase in phishing attempts to steal money or tax data, therefore you must be on high alert.
How it Happens: Tax Scams and Malicious Activity
The bad guys have several tax-related tricks up their sleeves when it comes to stealing your money and/or sensitive information. Here are a few examples of sophisticated tax scams that have been found in the wild:
- Scammers send emails posing as tax service companies by spoofing emails and using stolen logos. Once you respond to the email with personal data or tax information, they can pocket your hard-earned money.
- Like the scam above, the bad guys send look-alike emails containing hyperlinks that lead you to malicious websites or fake PDF attachments that download malware or viruses to your computer.
- Tax scams aren’t limited to emails! Be on the lookout for callers posing as IRS representatives claiming you owe money that must be paid immediately. The callers typically threaten arrests, deportation, or suspension of business or driver’s license.
Keep in mind, these are only a few examples, and these scam artists are constantly coming up with new ways to fool you.
How Do I Know it’s a Scam?
Always remember the following during tax season, and all year long:
- The IRS will always mail a bill before calling you about taxes owed.
- The IRS will never ask for credit or debit card numbers over the phone.
- The IRS will never immediately threaten to arrest you for not paying taxes owed.
- The IRS will always offer the opportunity to question or appeal the amount owed before demanding your payment.
- The IRS does not use emails or text messages to discuss personal tax matters, such as taxes owed or tax refunds.
Only share sensitive data over email when there is no other alternative, and you’re certain the recipient is valid.
A First-Class Ticket to Fraud
In this scam, you’ve booked travel plans on an upcoming flight when you receive a text message. It appears to be from the airline’s support team and contains some alarming news: your flight has been canceled. The text urges you to select a link or call a phone number immediately to rebook your flight. The message looks official and even includes your real flight number, which might make you panic and try to fix the problem right away.
However, the text wasn’t sent by the airline, but by cybercriminals who are hoping to scare you into acting without thinking. If you select the link or call the number provided in the text, you won't be connected to the airline's customer service team. Instead, you will be connected to a scammer who will pretend to work for the airline. They will ask you for your financial information so they can “rebook” your flight. But if you give them your credit card number or personal details, they’ll steal your money and your identity!
Tips to Avoid Falling Victim
- Always verify flight changes through official sources. If you receive a text about cancellation, go to the airline’s official app or website to check your flight’s status.
- Never trust a link or phone number in an unexpected text message. If you need to contact an airline, call the customer service number in your booking confirmation email or on their official website.
Scammers use phrases like "act now" or "call immediately" to prompt you into making a rushed decision. Always stop and verify the information before you act.
This Free Gift Has a High Cost
In this scam, you get an email that looks like it’s from a trusted brand, such as Costco or AAA. The email promises a free gift if you fill out a short survey and pay a small shipping fee so that the gift can be delivered to you. The email may create a sense of urgency by claiming that only a few free gifts are left. All you have to do is click a link in the email, which takes you to a website with the survey.
However, the website and survey are fake, and the gift doesn’t exist. The small shipping fee is actually a trick to steal your financial information. If you enter your credit card details on the website, you’ll give your payment information directly to scammers. Then, they can use your card for more expensive purchases or sell your data to other cybercriminals. Even worse, they can use the personal information you entered to steal your identity!
Tips to Avoid Falling Victim
- Legitimate organizations would not ask for your credit card details to cover shipping for a completely free promotional item.
- Instead of clicking links in an email, go directly to the organization’s official website to check if the offer is real. Think before you click!
Be skeptical of any offer that seems too good to be true, even if it appears to come from a brand you know and trust.
A Fine Way to Get Scammed
In this scam, you receive a text message that appears to be from the Department of Motor Vehicles (DMV). The text states that you must pay a traffic fine by a certain date. If you don’t pay on time, your vehicle registration will be suspended, and you’ll lose your driving privileges. Some versions of the message even state that you’ll go to jail or your credit score will be affected if you don't pay.
The text message contains a link and instructs you to click it so that you can pay the fee. However, these messages aren’t sent by the DMV. They’re actually phishing texts (smishing) sent by cybercriminals. There was never an actual traffic fine or penalty. If you click the link in the text message and make a payment, your money will go directly into the cybercriminals’ pockets!
Follow these tips to avoid falling victim to a smishing scam:
- Be cautious if you receive text messages claiming you must pay a fine immediately. Scammers often create a sense of urgency to trick you into acting impulsively.
- The DMV wouldn’t ask you for personal information or money through a text message. If you have questions about paying a fine, contact your local DMV through its official website or phone number.
- This scam targets users in the United States. However, cybercriminals can use these same tactics to try and trick users anywhere in the world. Always stop and think before you click!
Deepfake, Deep Trouble
In this week’s scam, cybercriminals are using artificial intelligence (AI) to try to trick you into clicking malicious links. You receive a text message or voice call from someone claiming to be a senior United States government official. They will try to establish a friendly relationship with you by sounding genuine, making the official seem trustworthy.
But these messages are fake and were actually created by AI. No matter the message you receive, the “official” will eventually ask you to use a different messaging app to continue the conversation. They will then send you a link that will supposedly take you to the new app. However, the link is actually malicious. If you click it, cybercriminals will be able to access your data and personal information!
Tips to Avoid Falling Victim
- Be suspicious when strangers try to become friends quickly through texts or calls. Scammers will often try to become friendly with you so that you will be more likely to fall for their tricks.
- Never click on links sent to you by an unknown person. These links could install malware, steal your data, or take you to fake websites designed to capture your personal information.
This scam is based in the United States but be careful about messages from anyone claiming to be a government official, even if they act friendly. Scammers could use similar tactics anywhere in the world to try to steal your data!
Recommendations for Safeguarding Data
- Maintain physical security by locking rooms and/or file cabinets where protected data and information is stored. Ensuring windows are locked and using safes when practicable for especially sensitive protected data and information.
- Maintaining adequate key control and limiting access to sensitive areas to those individuals with a “need to know” in order to perform their job.
- Using and frequently changing passwords to access automated systems that process protected data and information. Also encouraging the use of “strong” passwords . Also encouraging the safeguarding of passwords (e.g. do not leave passwords written down in easy view of others in the vicinity of an employees work area).
- Using firewalls and encrypting protected data and information when appropriate and feasible. The Information Technology Services department provides for this on behalf of all college employees.
- Referring calls and mail requesting protected data and information to those individuals who have been trained in safeguarding protected data and information for these types of requests.
- Shredding and erasing customer information when no longer needed in accordance with Department policy.
- Taking reasonable efforts to limit the view of computer screens and other mediums (e.g. paper) displaying protected data and information to only those employees who have a “need to know” in order to perform their job.
- Erasing protected data and information from computer screens when it is no longer in use. And never leave your desk area with protected data and information still displayed on a computer screen or on some other medium (e.g. paper) on the desk in clear site of a casual passerby.
- Encouraging employees to report suspicious activity to supervisors and/or the COD Public Safety Police department, as appropriate.
- Encouraging password-activated screen savers and using them when an employee is away from his/her desk.
- Taking reasonable steps to ensure that all future contracts are with service providers that are capable of maintaining appropriate safeguards for the protected data and information at issue.
Please Note: The college may take disciplinary measures (including job termination) against any employee who intentionally, or through gross negligence, violates any of the above guidelines.
For more information refer to the College of DuPage Information Technology Services “Information Security Plan."
Best Practices for Safe Computing
- Software Updates: Keep operating systems, browsers, and applications updated automatically to patch security vulnerabilities. Lapses in updates allow for a larger surface area to attack. Some updates, Windows for example, may require a reboot to finalize the installation – reboot as soon as possible to avoid gaps in vulnerabilities
- Secure Network Usage: Avoid public Wi-Fi for sensitive tasks whenever possible. Many public Wi-Fi networks are not secured, and data sent over these unsecured networks is not encrypted. Public Wi-Fi is also notorious for man-in-the-middle (MITM) attacks, leaving data vulnerable to interception.
- QR Codes Safety: Before scanning a QR code, ensure it is from a trusted source. If the QR code is public facing of uncertain origin, it is untrusted. Attackers can create their own QR code that coincides with a malicious campaign designed to extract information or present malicious content.
All employees are required to complete cybersecurity awareness training.
Topics include:
- Phishing prevention
- Password security
- Safe browsing
- Data protection
Data Protection
All protected data and information is to be used only by authorized personnel necessary for the execution of their jobs. All protected data and information is protected by federal and state privacy laws and industry privacy standards. Unauthorized disclosure is prohibited by law. The college may take disciplinary measures, including job termination, against any employee who intentionally or through negligence violates these laws or policies.
Many College employees use portable media (ex. laptops/PCs, smartphones, USB sticks, etc.), to store protected data and information. All College staff using portable media (which includes laptops) to store College protected data and information must take the additional step to protect the data by encrypting it.
Compliance with these guidelines is also required for the College to comply with Federal and State regulations, and industry standards that mandate protection of data and information that could be used for identity theft.
COD employees are allowed to store protected data and information on portable media if they comply with the following requirements:
- Must only be done for business reasons.
- Storage of the data on the portable media must be password encrypted.
Transmission of protected data and information is only allowed if:
- Transmission is required for business purposes.
- It is password encrypted during transmission. It must never be sent through unencrypted email (e.g., in plain text).
Secure file transfer protocols use industry accepted encryption formats for sending files securely. Data backup is established to ensure the effective and secure backup of critical organizational data, minimizing the risk of data loss, and facilitating prompt recovery in the event of a system failure, data corruption, or other unforeseen circumstances.
This includes, but is not limited to, servers, email, databases, and workstations. Backup data will be stored in a secure, off-site location to mitigate risks associated with on-site disasters. The off-site storage facility will comply with relevant security standards. All backup data will be encrypted using industry-standard encryption algorithms. Encryption keys will be securely stored and managed to ensure data integrity.
Identity and Access
Identity and access management services help protect College of DuPage systems, data and user accounts by ensuring secure access to technology resources. Through tools such as multi-factor authentication (MFA), password security practices and account protection measures, Information Technology works to reduce cybersecurity threats and safeguard sensitive information for students, faculty and staff.
The College has seen a significant increase in cyber-attacks. Many of these attacks are utilizing compromised student accounts to send “phishing” emails to other students. To combat this threat, the College has implemented Multifactor Authentication (MFA)
- Faculty and Staff: Authenticate using Duo Security.
- Students: Authenticate using Microsoft Authenticator with number matching.
Report Security Incidents
Report all security incidents immediately to our Help Desk.
Our dedicated support team is available to assist you during regular hours. Reach out to us for help with any of your technology needs.
- Phone: (630) 942-4357
- Email: helpdesk@cod.edu
- Phone: (630) 942-2999
- Email: studenthelp@dupage.edu
College-Wide Sensitive Data Incident Response Plan
The purpose of the College-Wide Sensitive Data Incident Response Plan (“The Plan”) is to provide a well-defined, organized approach for handling any potential unauthorized access/breach of sensitive data at College of DuPage.
The Plan identifies and describes the roles and responsibilities of the Incident Response Team. The Plan also contains instruction on how the team is to prepare and how The Plan is to be maintained. Also included in The Plan is the contact information for every team member and other important personnel at the College.
The College-Wide Sensitive Data Incident Response Team, under the coordination of the Chief Security Officer, IT, is responsible for putting the plan into action. Copies of the College-Wide Sensitive Data Incident Response Plan are confidential. Copies can be obtained by college staff, with the need to know, by contacting Ira Rezania at rezaniae@cod.edu or (630) 942-3055.
Frequently Asked Questions
The following frequently asked questions provide guidance on the COD's data protection standards, privacy responsibilities, and information security practices.
The College has chosen to define protected data and information to include student personal and financial information required to be protected under The Standards and the Family Educational Rights and Privacy Act (FERPA).
In addition to educational records and student personal and financial information, the College has chosen to also include the personal and financial information of faculty members, staff members, alumni, and other donors in the definition of protected data and information.
When in doubt as to whether a piece of data or information is to be protected, COD employees/contractors will err on the side that it is protected data and information.
Protected data and information includes both paper and electronic records. Examples of protected personal and financial information include addresses, phone numbers, bank and credit card account numbers, income and credit histories and social security numbers.
College employees and contractors who have a “need to know” in order to perform their jobs to further the mission of the college are allowed to view protected data and information. These college employees and contractors are said to have a “legitimate institutional interest” for viewing protected data and information.
Security Resources
For more information about College Guidelines, Federal Regulations and Industry Standards that the College and College staff must conform to, refer to the following references. The College must comply with these guidelines, regulations, and standards, or face liabilities including but not limited to fines, and lost service capability. The IT Security Management function is responsible for making sure compliance is met which includes technical compliance, and staff training, awareness and compliance demonstration.
FERPA (Family Educational Rights and Protection Act)
Requires protection of education records.
PCI DSS (Payment Card Industry Data Security Standard)
Requires the protection for all credit card information and transactions.
GLBA (Gramm-Leach-Bliley Act)
Requires protection of financial information
FTC - Summary and Act
HIPAA (Health Insurance Portability and Accountability Act)
Requires the protection of individually identifiable health information.
CALEA (Communications Assistance for Law Enforcement Act)
Requires electronic communication providers to provide easy access for law enforcement agencies to electronic communications for the purpose of electronic surveillance.
HEOA (Higher Education Opportunity Act)
Among other things outside IT requires the monitoring and stopping of illegal P2P file sharing.
- The Higher Education Opportunity Act (HEOA) Compliance Plan for Combating Unauthorized
Distribution of Copyrighted Materials
The Higher Education Opportunity Act (HEOA) was signed into law on Aug. 14, 2008. Final regulations were issued on Oct. 29, 2009. Enforcement of the HEOA provisions began July 1, 2010, and all colleges and universities are required to make a good-faith effort at compliance.
Take the Next Step
Whether you’re exploring, applying or planning your path, COD makes it easy to get started.
© College of DuPage