Purpose
This standard establishes minimum computer-security requirements based on security best practices and developed in response to UTS 165. Compliance is intended to create a safer computing environment and better protect University Information Resources. These requirements supplement all other UTRGV policies and applicable federal and state data-protection requirements.
Scope
This standard applies to:
-
all computers owned, leased, or managed by UTRGV;
-
any physical or virtual computer connected to a UTRGV network by wired, wireless, or VPN connection; and
-
any computer that stores or accesses UTRGV confidential or sensitive data.
Audience
Employees, students, consultants, vendors, contractors, and other people who operate a computer within the scope above.
Authority
-
UTS 165
Definitions
Requirements
1. Requirements for All Computers
1.1 Security Updates and Patches
Operating-system and application security updates and patches must be installed expediently.
1.2 Unsupported Products
Operating systems and other products that no longer receive vendor security updates are not authorized.
1.3 Malware Protection
Computers must run enabled malware protection, such as antivirus software, with current definitions.
1.4 Malware and Copyright Compliance
Computers must be free of malware and must not use software in a manner that violates copyright law.
1.5 Password Protection
Computers must be password protected. Default and generic usernames/passwords should be changed or disabled.
1.6 Unattended Computers
Users must log out of or lock computers when they leave them unattended.
1.7 Software Firewall
A software firewall is required.
1.8 Full-Disk Encryption
Full-disk encryption is required.
1.9 Computer Backups
Computer backups are the responsibility of the computer operator or primary user.
2. Additional Requirements for UTRGV-Owned, Leased, or Managed Computers
2.1 Change Management
Configuration changes should follow applicable change-management procedures.
2.2 Managed Software Firewall
Computers must run a software firewall that is enabled and managed by UTRGV Computer Support Staff.
2.3 Approved Encryption and Password Protection
Computers must be encrypted and password protected using methods approved by the UTRGV Information Security Office.
2.4 Unattended Computer Security
All computers must automatically lock and require a password after no more than 20 minutes of inactivity. Unattended portable computers must also be physically secured.
2.5 Hostnames
Computer hostnames must comply with the UTRGV Computer Naming Standard.
2.6 Domain Membership
-
Wherever possible, computers must be joined to the UTRGV domain unless the Information Security Office grants an exception.
-
When a computer is joined to the UTRGV domain, local accounts must not exist.
-
Only UTRGV-owned, leased, or managed computers may join the UTRGV domain.
2.7 Administrative Privileges
-
The built-in local administrator account must be disabled and renamed.
-
On UTRGV domain-joined computers, LAPS must be used to manage enabled local administrator accounts and enforce password requirements and practices.
-
Administrative logons should be limited to tasks that require elevated privileges and only for the necessary duration.
-
Administrative privileges are limited to employees responsible for services such as system maintenance and user support.
-
Local-administrator requests are granted through an approval process defined by the Information Security Office.
2.8 Confidential Data Registration
Computers that store UTRGV confidential data must be registered with the Information Security Office.
3. Additional Requirements for Computers Storing or Accessing Confidential or Sensitive Data
These requirements apply to all computers, including personally owned computers, that store or access UTRGV confidential or sensitive data. The source directs readers to the UTRGV Data Classification Standard for classification guidance.
3.1 Password Protection
Computers must be password protected using standards approved by the Information Security Office.
3.2 Encryption
Any computer on which Confidential University Data is stored or created must use encryption approved by the Information Security Office.
3.3 Backups
Backups should be stored only on UTRGV-owned or sanctioned storage and must be encrypted and password protected.
3.4 Auditing Tools
Computers must have auditing tools that enable the Information Security Office to validate compliance with UTRGV, UT System, state, and federal policies and standards.
4. Additional Requirements for UTRGV-Owned, Leased, or Managed Lab and Podium Computers
4.1 Domain Membership
Lab and Podium computers must join the UTRGV Domain under the Lab and Podium Group OU.
4.2 Hostnames
Lab and Podium hostnames must comply with the UTRGV Computer Naming Standard.
4.3 Physical Security
All Lab and Podium computers must be physically secured.
4.4 Screen Lockout
-
Lab computers must automatically lock after no more than 30 minutes of inactivity.
-
Podium computers must automatically lock and require a password after no more than 60 minutes of inactivity.
4.5 Automatic Restart
Lab and Podium computers must automatically restart after no more than 180 minutes of inactivity.
4.6 Return to Preconfigured State
The device/computer should be capable of returning to a preconfigured state. Lab and Podium computers must reset to a standard image after a reasonable period of non-use. Systems must not permanently retain user information after restart, logout, system failure, power loss, or similar incidents.
4.7 Lab/Podium Software Exceptions
If specific software requirements prevent a Lab or Podium computer from meeting a requirement, the source requires the Service Request Process to be followed to address the associated risk.
Roles and Responsibilities
End User
Ensures any computer they own or operate meets this standard and should work with UTRGV Computer Support Staff for guidance and compliance.
UTRGV Computer Support Staff
Ensure computers are configured to support the requirements in this standard.
Information Security Office
Defines and maintains the standard, including necessary configurations and security practices, to protect UTRGV Information Resources and support compliance with UT System, state, and federal policy and standards.
Exceptions and Non-Compliance
Administrator Access Exceptions
If an individual with administrator access cannot meet a requirement on an applicable Information Resource they use or support, the Security Exception Process must be followed to address the associated risk.
Network Disconnection
A computer that does not meet this standard, lacks required security software, or otherwise threatens UTRGV Information Resources may be disconnected from a UTRGV network immediately and without notice.
Disciplinary Action
Non-compliance may result in supervisor notification and disciplinary action under applicable UTRGV rules and policies.
Related UTRGV Documents
-
Data Protection Standard for Personally Owned Mobile Devices
-
Minimum Security Requirements for Non-Managed Research Network Devices
-
UTRGV Data Classification Standard (referenced by source; no page was exposed in reviewed Information Security navigation)
-
UTRGV Computer Naming Standard (referenced by source; no page was exposed in reviewed Information Security navigation)
-
UTRGV Security Exception Standard / Process (referenced by source; no page was exposed in reviewed Information Security navigation)
External References
Source references retained as published:
-
NIST SP 800-53 Revision 4
-
Center for Internet Security Critical Security Controls Version 6
See the review report before updating the NIST or CIS version citations; version changes should be accompanied by a control-impact review.
Revision History
|
Date |
Revision |
|---|---|
|
Initial publication |
Contact Information
Information Security Office
Email: is@utrgv.edu
Phone: 956-665-7823