Information Technology Strategic Planning
All Projects
Proposed
- Network Intrusion Detection and Prevention System - The current network environment lacks tools and processes to efficiently and continuously monitor, detect and react to intrusive and/or disruptive network traffic.
To address the above issues, the following system is proposed which will provide us with tools to accurately, efficiently monitor, detect and react to intrusive and/or disruptive network traffic.
The requirements for this system are:
• monitor edge and internal network traffic
• detect traffic patterns based on known signatures and notify appropriate staff and/or systems
• capability to make dynamic or manual changes to modify (stop or limit) unwanted traffic for a variable length of time
• capability of real-time change notifications
• capability of keeping history of traffic patterns and changes which could be easily used for further analysis, troubleshooting and forensics
The following will meet all of the requirements listed above:
• implementation of Snort open-source IDPS
• integration of Extreme Networks’ existing Sentriant devices to
o capture traffic
o feed raw details to other IDS Decision Support Systems (DSS)
o make dynamic network traffic rules on Extreme hardware
• implementation of Oracle RDBMS to store traffic data and history of dynamic and/or manual changes by IDS’s DSS (Sentriant and/or customized application)
Current
- Active Directory Expansion - Create a framework for departments and schools to join workstations to the UCMerced Active Directory domain to leverage existing investment in the system.
- Banner Faculty and Advisor Self Service Phase I -
Install and implement SunGard’s Banner Faculty and Advisor Self Service module.
The implementation of this project will provide an integrated solution for faculty and advisors in accessing up-to-date and accurate academic information. Delivered functionality includes:
· Information about faculty schedule
· Class rosters by term (historical)
· Grade rosters by term (enter as well as view historical)
· View list of advisees
· View advisee test scores
· View student academic transcripts
· View student information, including addresses, phone number, and e-mail
· View student’s schedule
· Other….Additional functionality will be evaluated for release as part of the project design and configuration sessions. - Business Intelligence Platform - Select, procure, and deploy a business intelligence software (query, analysis, dashboards, etc.), including pilot reports and functionality.
- Campus Event Calendar - Implement events calendar developed by UC Berkeley in portal.
- COEUS - Support the deployment of Kuali COEUS (KC) for grant management. COEUS originated at MIT, and has undergone several platform upgrades. The KC version is being developed and released in phases. The Sponsored Projects Office has chosen to to install the KC version and wait for some of the functionality to become available, rather than implement the older version and be faced with a migration.
An initial launch will provide proposal package development; support for grants.gov will follow, and then IRB, awards management, and conflict of interest.
- Emergency Notification - Support the diverse set of functional goals coordinated by the Emergency Notification Work Group providing different abilities to communicate with the UC Merced community, the public, emergency responders, etc.
- fsaATLAS - Implementation of the SungardHE fsaATLAS system for managing information related to our international student and scholar population, and supporting the business function of the campus International Student and Scholar office (ISSO). fsaATLAS enables automated SEVIS reporting (Student and Exchange Visitor Information System), and integrates with the Banner Student Information System. The fsaATLAS software is built using .NET/MS SQL Server, and is to be hosted on Windows servers administered by Information Technology.
- IT Services Menu - The project is intended to discuss and share information related to IT services for new and existing employees. This concept is supported under the User empowerment initiative. With a new IT awareness, employees will be able to access resources through a consistent channel-set of information sharing. Information regarding the various services, products, and systems available from the Information Technology department would be readily accessible from multiple sources, including "advertising".
- Merced Academic Resource System (MARS) - Develop and support datamart to enable reporting and analysis in the areas of faculty workload, instructional space utilization, and TIE course categorization.
- NetLogin Solution - The purpose of this project is to identify an implementable standards-based solution that will provide a means to track and identify users and machines utilizing UCM network resources. This will allow us to locate and potentially take action towards computers and their owners that are involved in security incidents or when illegal activities are reported to us. A subsequent project will address the actual deployment of the solution.
Users of the wired network would have to authenticate, most likely using 802.1x protocols and their UCMNetIDs in a manner similar to wireless network usage. Their computers’ MAC addresses would be registered in a central data base or other repository. Special procedures may be required for systems not supporting 802.1x and in the Library.
The following platforms should be supported natively:
o Windows XP
o Windows 2003
o Windows Vista
o MAC
o Linux
o Solaris - Network Edge Re-Architecture - Re-architect the implementation of the campus network “edges”, leveraging the expanded capacity and functionality of new switches to provide better availability, security, and performance. Hardware, configuration changes, and the enablement of new functionality will be performed in a phased approach over a period of several months. No changes will be tangible on the user level; IP addressing and other functionality will be transparent across the upgrades.
- New Webmail Client - Replace both current webmail clients (the one in the portal and the legacy one) with a new client with expanded features, especially the ability to render HTML messages properly, and ongoing support from the community so that the application is updated as usage evolves in HTML and email functionality in general use.
- Operational Data Store (ODS) 8 - This project is prerequisite for the upgrade to Banner 8 which is planned for July 2009, as the current version of ODS will not function with Banner 8. The project will upgrade ODS (currently at version 3.1.0) to ODS 8.0. The reason for such a dramatic shift in version number is due to the fact that Sungard never released version 4 through 7 (Sungard only wished to line up all version numbers of their core products so that “Banner 8” would be in line with “ODS 8”).
- PDA Calendar Synchronization - Provide a software application allowing PDA calendar applications to directly access the campus calendar server, avoiding the need to synchronize via a notebook or office computer.
- Storage Strategy - Develop a strategy for the deployment and ongoing acquisition of central disk storage. The strategy should encompass a multi-tier “menu” for the ongoing acquisition of storage at different price/performance points suitable for different needs, as well as the disposition of existing storage.
- UC Trust Enablement - The project goal is to revamp the process relating to the issuance of UCMNetID and password (user credentials) so our users meet the basic level of identity assurance required by UC Trust policy. This will be done by Dec. 12, 2008.
Completed
- Web Content Management System (DRUPAL) - Deploy open-source web content management system to support primary and subsidiary web sites. Support advanced capabilities and electronic accessibility.
- Email Improvements - This project encompasses several improvements to email services which are planned to be implemented essentially concurrently, although they may be separated out should deployment challenges dictate that course of action. The project will reduce the risk of outages of the email service, and provide expanded capacity and a change in the way that SPAM is handled.
The email server and existing email will be migrated from the current server at Castle onto a new server at Telecom that will use the Storage Area Network (SAN) as the email store. The new email store will allow us to increase the quotas for all users to 1 GB. Most of this aspect of the project will have little impact on day-to-day use of email, other than potential access issues during the migration itself, and the appearance of more space of user email.
Changes in SPAM handling will, however, significantly change the user experience, and will require user education and actions. Currently as email arrives at UC Merced, it gets examined and tagged with a header before being delivered to a user’s Inbox on the mail server. The header categorizes the email as either vanilla, SPAM or bulk (bulk emails are usually unsolicited advertisements from legitimate vendors, as opposed to SPAM which is typically objectionable and/or fraudulent). It is left to user to configure their client email applications (such as Outlook, Thunderbird, Macintosh Mail, etc.) with a filtering rule if they want undesired email to be automatically moved out of the Inbox. Current user documentation explains how to set up filters for email tagged as SPAM.
With the new model, a new SPAM folder will be set up on the mail server for each user, and email tagged as SPAM will be automatically moved into it without any set-up or actions on the part of the user. Users will need to periodically inspect the SPAM folder for potentially incorrectly tagged email, and purge the unwanted messages. Beyond the changes on the email server side, users will have the potential to continue to perform further filtering on the client side to redirect BULK email.
- ID Management Release 7 - Upgrade IDM to support COEUS, alumni systems, and other functionality.
- Network Re-Architecture - Re-architect main campus network to move routing functions out of the buildings and into the core switches.
- Operational Data Store (ODS) Implementation - The SungardHE Operational Data Store is a dedicated operational reporting environment that enables self service operational reporting of Banner/SIS and other data by business users with limited technical knowledge. The implementation of the ODS at UC Merced will eliminate the risk to our Banner/SIS production environment of degraded performance or system outages caused by operational reporting. It will also provide a secure mechanism for making key university data available to a broader set of constituents than is possible in our current reporting environment.
The implementation project will involve establishing ODS test and production environments, including Extract/Transform/Load (ETL) software processes that move the data from its source in the Banner/SIS transactional system to the ODS. The project also includes training of technical staff in the operation and development of the ODS environment, and training of business users in the end user reporting environment.
Over time, additional data sources beyond core Banner/SIS data (such as undergraduate admissions data via CASA XML files) can be incorporated into the ODS, increasing its overall value. But incorporating these data sources is outside the scope of the initial ODS Implementation project. - PAWS Phase III -
Modify PAWS to allow hiring managers to disposition candidates. Track the relevant data to be able to create the year end AA/EOP report, to produce the interview data form and to produce the academic affirmative action report.
- Remove 60 Day Email Limit - Remove the feature of the central email system that deletes email over 60 days old, and update documentation, facilities, and recommendations for users to manage their email by 1/14/2007.
- Shibboleth and UC Trust - The goals of this project are to:
• Create a Federated Identity Management solution using Shibboleth allowing UC Merced users to authenticate to applications which support UCTRUST or InCommon using their UCMNetIDs. Federated authentication means that users may access services external to our campus, and users external to our campus may access our services.
• Develop an attribute release policies:
o A general policy for all federated applications.
o A policy for specific applications if the application requires additional attributes.
• Participate in federated authentication for At Your Service Online (AYSO) and create an AYSO channel in the UC Merced portal for faculty/staff.
• Participate in federated authentication for UCLA Effort Reporting, removing the need for faculty to create accounts within the UCLA mainframe. Create an Effort Reporting link in the UC Merced portal for faculty.
• Evaluate the possibility of offering federated access to new or existing UC Merced applications and how these applications would have to be modified to become “Shibbolized.” In the future, we may decide to Shibbolize some local applications even if federated authentication isn’t enabled for them because this removes the need for the application to communicate with LDAP and it also allows fine-grained attribute release policies that can be configured on a per-user basis. - Track-It 7.0 Implementation - Upgrade our Track-It 6.5 software to Track-It 7.0. The upgrade and utilization of Track-It 7.0 will occur in separate phases, allowing the use of Track-It without any interruption to our current practices. To begin, all of the data in Track-It 6.5 will be migrated to our new Track-It 7.0 server. Once completed, this will change the way work orders are categorized, created and reported; Also, Track-It 7.0 contains a mail monitor system that will allow users to email separate departments (ITOC, IDM, HELPDESK, SOFTWARE) and have work orders automatically generated, cutting down the time it takes to open a work order. With Track-It 7.0, new modules/upgrades are introduced and will be tested and if possible, utilized. Some of the new features are Purchasing, Software and Inventory modules that work together to keep all of our IT inventory in one location. Other valuable modules include a Knowledge base and Self-Service tool that will provide users with around the clock service.
- WEBISOAE – Web Initial Sign On Application Enablement - To enable Confluence, Jira, Banner Self Service, and Statement of Legal Residence to support our central authentication service (CAS). CASifying applications will facilitate integrating them into the portal and UCMCROPS. It will eliminate the need for clients to login twice. We will tackle the applications that we have within the Banner and Web team first then look at which other applications to CASify.
- What's Happening Channel - Develop a channel for the portal that will allow for creating, editing, deleting, posting and emailing of RSS information to our campus portal.
Looking for help?
We offer a number of tutorials and FAQs available in the Guides & FAQs section.
If you have any questions, problems, or comments, please contact the IT Help Desk via email at helpdesk@ucmerced.edu, via phone at 209.228.HELP (4357), or visit them in the Classroom and Office Building room 132A.


