\n
Compliance and Security<\/h3>\n NIST 800-171 Standards. Reassessed our compliance with these standards over the summer, and we are over 92% fully implemented (note that 70% is considered aligned and is our minimum goal).<\/p>\n
Bitsight. Our Bitsight score has been fluctuating between 700 and 720, primarily due to security on certain academic servers. ITS has been working with the faculty involved to remediate. (Note that Bitsight scores range from 250 (lowest) to 900 (highest); at 720, our Bitsight score puts us in the 80th percentile within higher education.)<\/p>\n
We have been dealing with increased Phishing and Smishing activity over the last two weeks; the source has been compromised email accounts.<\/p>\n
Policies, Protocols and Procedures<\/h2>\nCompleted and ratified by appropriate body: Business Continuity Plan<\/h4>\n Business Impact Analysis<\/p>\n
Data Protection (Personally Identifiable Information) Plan of Actions and Milestones (POAM, NIST related)<\/p>\n
Final draft submitted for ratification:<\/h4>\n Acceptable Use for Information and Technological Resources Policy<\/p>\n
Cybersecurity Policy<\/p>\n
Cybersecurity Protocols & Compliance Manual<\/p>\n
Software, Hardware, and Supporting Devices Requests and Distribution Policy and<\/p>\n
Procedure<\/p>\n
In process, pre-final submission:<\/h4>\n IT Risk Assessment Plan, Policy, and Procedure<\/p>\n
System Security Plan<\/p>\n
Guidelines for Secure Handling and Disposal of Documents under BDM<\/p>\n
Website Policy (Note: we will have to deprecate support for \u201cPages\u201d in the very near future. We are working to identify a list of current users so that we can collaborate with them to help them move their content to Canvas or to WordPress websites.)<\/p>\n
Ongoing Projects:<\/h3>\n Endpoint Hardware Deployment (Updating and replacing computers throughout campus to get all machines onto the Windows 11 OS; we are 79.5% of way there as of 1:30pm on 9\/15\/2025. Support for Windows 10 ends on 10\/14\/2025. We\u2019ve gotten 1366 machines on to Windows 11; we have 352 to go before 10\/14.)<\/p>\n
Network Hardware Deployment \u2013 Research Network connected! ERP Modernization<\/p>\n
Experience (We are planning to launch this at the beginning of the spring semester in Jan conditional on working out several remaining bugs. Experience provides a new user interface for accessing Banner, and it also provides an application for Banner on mobile devices.)<\/p>\n
Banner Document Management (BDM) (We are in the process of implementing an electronic document storage system within Banner to reduce the need for hard copy storage.)<\/p>\n
DegreeWorks (We are in the process of implementing a new Degree Audit tool.)<\/p>\n
Power BI (We are in the process of developing methods for users to access data and use Power BI to produce tables, graphs, and reports to reduce the need to work through ITS for the development of Argos reports.)<\/p>\n
Faculty Load and Compensation (FLAC) (We are beginning the process of implementing this add-on application to Banner to assist with audit compliance.)<\/p>\n
Ethos User Provisioning (EUP) (We are beginning the process of implementing this within Banner as a method to improve identify verification and passwords management.)<\/p>\n
Other Items \u2013 Work to Begin this Fall:<\/h3>\nGoTo Phone System Replacement \u2013 Implementation begins Fall 2025<\/h4>\n Hard phones staying in place; we will just be using a different VOIP service provider as our contract with Cisco will end in February 2026. We will not be transitioning to soft phones in the near future.<\/p>\n
Webex Meetings will be deprecated in February 2026 when the Cisco contract ends.<\/p>\n
ITS provided a brief demonstration of the capabilities of MS Teams as Webex will no longer be available starting in February 2026.<\/p>\n
MS Teams and Google Meet, both already available, will both be supported alternatives.<\/p>\n
All meeting recordings from Webex that people want to save must be downloaded by 1\/31\/2026!<\/p>\n
ITS plans to make a broadcast announcement within the next couple of weeks about these changes. ITS will also provide instructions about how to download videos from Webex, and will work with IDC to provide training on MS Teams.<\/p>\n
FA offered to provide ITS with 15 minutes at its next meeting to discuss these changes.<\/p>\n
Entra ID Project \u2013 October 2025 to June 2026<\/h4>\n Complete overhaul of RCNJ Identity Access Management (IAM). Eliminates Red Hat LDAP, saving the College money.<\/p>\n
Creates a hybrid cloud\/on premises IAM system allowing cloud only authentication<\/p>\n
providing ongoing services if campus data centers are offline. Cuts in half the attack vectors on RCNJ systems.<\/p>\n
Uses Microsoft Authenticator, replacing DUO, for MFA, saving the College money.<\/p>\n
Streamlines new application setup and provides more versatility for future enterprise grade applications.<\/p>\n
MUCH better security tools than current environment.<\/p>\n
Cuts down on or eliminates outage times for all cloud applications. BYOD Campus<\/p>\n
BYOD Campus<\/h4>\n With rare exceptions, such as video rendering, the individual computers are relatively unimportant as technology moves to cloud computing. The computer is a ubiquitous portal.<\/p>\n
Most classroom PCs have been removed because they are severely underutilized. Also, even when a student logs into one and uses it, the classroom computer has no unique purpose.<\/p>\n
Providing software to students such as SPSS, EViews, and Stata for their installation allows the student far greater access to having it limited to their time in the classroom.<\/p>\n
Getting to the point where students all have the same minimum computer allows for greater equity to students (recommended specifications are published on the ITS website and updated annually; see https:\/\/www.ramapo.edu\/its\/student-laptop- recommendations\/).<\/p>\n
Challenge: What is the methodology to ensure all students have a minimum level laptop meeting specs during their College career?<\/p>\n
Some options:<\/p>\n
Provide a laptop with 4-year warranty through fees when students begin at<\/p>\n
Ramapo. This could be done with a one-time fee or leveled fees.<\/p>\n
Make laptops available for purchase through the bookstore via a process that would allow students to use Financial Aid funds.<\/p>\n
Simply state it as a requirement and allow students to bring their own.<\/p>\n
The first two options allow us to have the computers preconfigured with the software all students are entitled to such as MS Office, as well as what may be required such as Lockdown Browser. They would also allow standardization and more efficient help desk support. The first option would also mitigate the issue of affordability for financially challenged students.<\/p>\n
Implementation timeline:<\/p>\n
From a shared governance perspective, which entities from across campus should we seek input?<\/p>\n
Should we start with the incoming freshman and transfer students starting in the summer of 2026?<\/p>\n
<\/p>\n<\/div>\n
November 17, 2025<\/strong><\/h2>\nCall to Order<\/h3>\nCompliance and Security<\/h3>\n NIST 800-171 \u2013 Reassessed over the summer. Over 92% fully implemented. 70% is considered aligned and is our minimum goal.<\/p>\n
Working on supply chain and removable media risk identification to approach 100% Bitsight \u2013 Now at 770. \u00a0Higher than 95% of our peer group (North America, Higher Education) Foundation PCI \u2013 Compliant as of 9\/2025<\/p>\n
College PCI \u2013 Upcoming in 12\/2025<\/p>\n
Web Content Accessibility Guidelines 2.1 \u2013 4\/24\/2026 \u2013 participating in multidiscipline group to address compliance<\/p>\n
Policies, Protocols and Procedures\u00a0 Completed and ratified by appropriate body:<\/span><\/h4>\nBusiness Continuity Plan<\/p>\n
Business Impact Analysis<\/p>\n
Data Protection (Personally Identifiable Information) Plan of Actions and Milestones (POAM, NIST related)<\/p>\n
Cybersecurity Policy (new or changed status)<\/p>\n
Cybersecurity Protocols & Compliance Manual (new or changed status)<\/p>\n
Final draft reviewed by PRC and MET and out for Public Comment:<\/p>\n
Acceptable Use for Information and Technological Resources Policy (new or changed status)<\/p>\n
Software, Hardware, and Supporting Devices Requests and Distribution Policy and Procedure (new or changed status)<\/p>\n
Final draft submitted for ratification:<\/p>\n
Website Policy (new or changed status)<\/p>\n
Guidelines for Secure Handling and Disposal of Documents under BDM (new or changed status)<\/p>\n
In process, pre final submission:<\/p>\n
IT Risk Assessment Plan, Policy, and Procedure<\/p>\n
System Security Plan<\/p>\n
Email Issuance Policy (new or changed status)<\/p>\n
ITS Supply Chain Risk Management Policy<\/p>\n
Student Access Management Policy<\/p>\n
Identity Theft Protection (need input from Student\/Staff\/Management perspectives to proceed)<\/p>\n
Projects:<\/p>\n
Completed Projects (since last meeting):<\/h3>\n Endpoint Hardware Deployment \u2013 Complete<\/p>\n
DegreeWorks (new or changed status)<\/p>\n
Banner Document Management (BDM) (new or changed status)<\/p>\n
Network Hardware Deployment \u2013 Research Network connected!<\/p>\n
Ongoing Projects:<\/h3>\nERP Modernization<\/h4>\n Experience tentative go live 2\/2026<\/p>\n
Banner Self Service 8 (SS8) no longer supported after December, all remaining SS8 pages (Surveys, EPAF, Hold releases) moving to SS9 by then. DegreeWorks (some populations still use UAchieve until May)<\/p>\n
Data Visualization (via Power BI) Faculty Load and Compensation (FLAC) Ethos User Provisioning (EUP)<\/p>\n
Microsoft Teams<\/h4>\n GoTo Phone System Replacement \u2013 Fall 2025<\/p>\n
Webex Meetings will be deprecated Feb 2026<\/p>\n
MS Teams and Google Meet, both already available, will both be supported alternatives.<\/p>\n
All meeting recordings that people want to save \u00a0must be downloaded by 1\/31\/2026!<\/p>\n
Soft phones vs hard (traditional desk) phones<\/p>\n
Surveys going to Departmental leads to confirm locations and soft phone volunteers. Please fill out and return ASAP if received.<\/p>\n
Phone project currently on schedule<\/p>\n
Entra ID Project \u2013 Oct 2025 to June 2026<\/h4>\n Complete overhaul of RCNJ Identity Access Management (IAM) Eliminates Red Hat LDAP, saving the College money<\/p>\n
Creates a hybrid cloud\/on premises IAM system allowing cloud only authentication providing ongoing services if campus data centers are offline<\/p>\n
Cuts in half the attack vectors on RCNJ systems<\/p>\n
Uses Microsoft Authenticator, replacing DUO, for MFA, saving the College money<\/p>\n
Streamlines new application setup and provides more versatility for future enterprise grade applications.<\/p>\n
MUCH better security tools than current environment.<\/p>\n
Cuts down on or eliminates outage times for all cloud applications.<\/p>\n
Moving forward:<\/h3>\nBYOD Campus<\/h4>\n With rare exceptions, such as video rendering, the individual computers are relatively unimportant as technology moves to cloud computing. The computer is a ubiquitous portal.<\/p>\n
Most classroom PCs have been removed because they are severely underutilized.\u00a0 Also, even when a student logs into one and uses it, the classroom computer has no unique purpose.<\/p>\n
Providing software to students such as SPSS, EViews and Stata for their installation allows the student far greater access to having it limited to their time in the classroom.<\/p>\n
Getting to the point where students all have the same minimum computer (published on the ITS website and updated annually) allows for greater equity to students.<\/p>\n
Challenge: What is the methodology to ensure all students have a minimum level laptop meeting specs during their College career:<\/p>\n
Some options:<\/p>\n
Provide a laptop with a 4-year warranty through fees when students begin at<\/p>\n
Ramapo. This could be done with a one-time fee or leveled fees.<\/p>\n
Make laptops available for purchase through the bookstore that allow students to use Financial Aid funds.<\/p>\n
Simply state it as a requirement and allow students to bring their own.<\/p>\n
The first two options allow us to have the computers preconfigured with the software to which all students are entitled, such as MS Office, as well as what may be required, such as Lockdown Browser. They would also allow standardization and more efficient help desk support. The first option would also mitigate the issue of affordability for financially challenged students.<\/p>\n
ERP Strategy \u2013 3 years out from contract termination, need to determine approach for next steps.<\/h4>\n <\/p>\n
January 26, 2026<\/strong><\/h2>\n\n
Call to Order<\/h3>\nProjects:<\/h3>\nCompleted Projects (since last meeting):<\/h4>\n Endpoint Hardware Deployment \u2013 Complete<\/em><\/p>\nDegreeWorks<\/em><\/p>\nBanner Document Management (BDM)<\/em><\/p>\nNetwork Hardware Deployment \u2013 Research Network connected!<\/p>\n
Ongoing Projects:<\/h3>\nERP Modernization<\/h4>\n Experience go live 2\/2026<\/p>\n
DegreeWorks (some populations still use UAchieve until May)<\/p>\n
Data Visualization (via Power BI)<\/p>\n
Faculty Load and Compensation (FLAC)<\/p>\n
Ethos User Provisioning (EUP)<\/p>\n
Comprehensive Academic Plan Implementation<\/p>\n
Unimarket (supporting Finance Group)<\/h4>\nMicrosoft Teams<\/h4>\nNEOD Integration<\/h4>\nGoTo Phone System Replacement \u2013 Winter 2026<\/h4>\n Webex Meetings will be deprecated Feb 2026<\/p>\n
MS Teams and Google Meet, both already available, will both be supported alternatives.<\/p>\n
All meeting recordings that people want to save must be downloaded by January 31, 2026!!<\/strong><\/p>\nSoft phones vs hard (traditional desk) phones<\/p>\n
Surveys going to Departmental leads to confirm locations and soft phone volunteers. Please fill out and return ASAP if received.<\/p>\n
Phone project currently on schedule<\/p>\n
Entra ID Project \u2013 Oct 2025 to August 2026<\/h4>\n Complete overhaul of RCNJ Identity Access Management (IAM) Eliminates Red Hat LDAP, saving the College money<\/p>\n
Creates a hybrid cloud\/on premises IAM system allowing cloud only authentication providing ongoing services if campus data centers are offline<\/p>\n
Cuts in half the attack vectors on RCNJ systems<\/p>\n
Uses Microsoft Authenticator, replacing DUO, for MFA, saving the College money Streamlines new application setup and provides more versatility for future enterprise grade applications.<\/p>\n
MUCH better security tools than current environment.<\/p>\n
Cuts down on or eliminates outage times for all cloud applications.<\/p>\n
Moving forward:<\/h3>\nQualtrix Replacement<\/strong><\/h4>\nPrinting \/ Copier Contract (new community printer locations in ASB and\/or Gwing?) BYOD Campus<\/strong><\/h4>\nWith rare exceptions, such as video rendering, the individual computers are relatively unimportant as technology moves to cloud computing.\u00a0 The computer is a ubiquitous portal.<\/p>\n
Most classroom PCs have been removed because they are severely underutilized.\u00a0 Also, even when a student logs into one and uses it, the classroom computer has no unique purpose.<\/p>\n
Providing software to students such as SPSS, EViews and Stata for their installation allows the student far greater access to having it limited to their time in the classroom.<\/p>\n
Getting to the point where students all have the same minimum computer (published on the ITS website and updated annually) allows for greater equity to students. Challenge:\u00a0 What is the methodology to ensure all students have a minimum level laptop meeting specs during their College career:<\/p>\n
Some options:<\/p>\n
Provide a laptop with a 4-year warranty through fees when students begin at<\/p>\n
Ramapo.\u00a0 This could be done with a one-time fee or leveled fees.<\/p>\n
Make laptops available for purchase through the bookstore that allow students to use Financial Aid funds.<\/p>\n
Simply state it as a requirement and allow students to bring their own. The first two options allow us to have the computers preconfigured with the software to which all students are entitled, such as MS Office, as well as what may be required, such as Lockdown Browser.\u00a0 They would also allow standardization and more efficient help desk support.\u00a0 The first option would also mitigate the issue of affordability for financially challenged students.<\/p>\n
ERP Strategy <\/strong>\u2013<\/h4>\n3 years out from contract termination, need to determine approach for next steps.\u00a0 To that end, inviting Workday clients (Stevens, WPU, MSU) to campus for<\/p>\n
fact finding, ERP transition experience and networking on 2\/12. With Ellucian purchasing Anthology, the number of software manufacturers serving a school our size has decreased. Possible migration to O365 \/ Outlook<\/strong> \u2013 At least 18 months out, if ever. Migrating campus, or at least staff, to Exchange would allow RCNJ to leverage many of the efficiencies built into the existing Teams environment.<\/p>\nCompliance and Security<\/h3>\n NIST 800-171<\/p>\n
Reassessed over the summer.\u00a0 Over 92% fully implemented.\u00a0 70% is considered aligned and is our minimum goal.<\/p>\n
Working on supply chain and removable media risk identification to approach 100%<\/strong><\/p>\nBitsight<\/h4>\n Now at 760 for College, 720 for Dorms + College.\u00a0 Higher than 89% of our peer group (North America, Higher Education).\u00a0 Down from high of 770 due to updated standards.\u00a0 Items have been remediated but it takes time to completely fall off the report. Foundation PCI \u2013 Compliant as of 9\/2025<\/p>\n
College PCI \u2013 Pending<\/h4>\nWeb Content Accessibility Guidelines 2.1 \u2013 4\/24\/2026<\/h4>\n participating in multidiscipline group to address compliance<\/p>\n
College is procuring AudioEye for assessment and enumeration of items to remediate on public sites.<\/p>\n
Policies, Protocols and Procedures (Italics Indicates new or changed status)<\/h3>\nCompleted and ratified by appropriate body:<\/h4>\nBusiness Continuity Plan<\/h5>\nBusiness Impact Analysis<\/h5>\nData Protection (Personally Identifiable Information) Plan of Actions and Milestones (POAM, NIST related)<\/h5>\nCybersecurity Policy<\/h5>\nCybersecurity Protocols & Compliance Manual<\/h5>\nIncident Response Plan<\/em><\/h5>\nITS Change Management Protocol<\/em><\/h5>\nFinal draft reviewed by PRC and MET and out for Public Comment: Acceptable Use for Information and Technological Resources Policy<\/p>\n<\/div>\n
Software, Hardware, and Supporting Devices Requests and Distribution Policy and Procedure<\/div>\n
\n
U<\/em>se of AI in the Workplace<\/em>Email Issuance Policy<\/em><\/p>\nFinal draft submitted for ratification:<\/h4>\nWebsite Policy<\/h5>\nGuidelines for Secure Handling and Disposal of Documents under BDM In process, pre final submission:<\/h5>\nIT Risk Assessment Plan, Policy, and Procedure<\/h5>\nSystem Security Plan<\/h5>\nITS Supply Chain Risk Management Policy<\/em><\/h5>\nStudent Access Management Policy<\/em><\/h5>\nIdentity Theft Protection <\/em><\/h5>\nOther New Business from group<\/h3>\nAdjournment<\/h3>\n<\/div>\n March 30, 2026<\/strong><\/p>\n <\/p>\n<\/div><\/div>\n","protected":false},"excerpt":{"rendered":"
Strategic Technology Advisory Board (STAB) Charter Date Endorsed by MET: 3\/13\/2024 The purpose of the STAB is to provide advice on the development and advancement of academic and administrative computing resources. The STAB serves as the advisory board for the ongoing systematic development and advancement of computing resources in the context of the overall institutional […]<\/p>\n","protected":false},"author":335,"featured_media":0,"parent":0,"menu_order":0,"comment_status":"closed","ping_status":"closed","template":"","meta":{"footnotes":""},"class_list":["post-1032","page","type-page","status-publish","hentry"],"yoast_head":"\n
Strategic Technology Advisory Board (STAB) - Information Technology Services (ITS) || 秘密研究所 of New Jersey<\/title>\n \n \n \n \n \n \n \n \n \n \n \n \n \n\t \n