---
language: "en"
---
# Computer Security Standard

## Purpose

This standard establishes minimum computer-security requirements based on security best practices and developed in response to UTS 165. Compliance is intended to create a safer computing environment and better protect University Information Resources. These requirements supplement all other UTRGV policies and applicable federal and state data-protection requirements.

## Scope

This standard applies to:

1. all computers owned, leased, or managed by UTRGV;

2. any physical or virtual computer connected to a UTRGV network by wired, wireless, or VPN connection; and

3. any computer that stores or accesses UTRGV confidential or sensitive data.

## Audience

Employees, students, consultants, vendors, contractors, and other people who operate a computer within the scope above.

## Authority

* UTS 165

* [UTRGV Acceptable Use Policy](../policies/acceptable-use-policy.md)

## Definitions

Click to expand...  
**Computer:** Includes physical and virtual computing devices such as desktops, workstations, servers, laptops, tablets, and smartphones.

**Personally Owned:** A computer not owned, leased, or managed by UTRGV.

**Portable Computer:** A portable, typically battery-powered computer such as a laptop, tablet, or smartphone.

**Software Firewall:** Software that limits network traffic to and from a computer according to a security policy.

**Computer Lab:** A group of computers located near one another and providing services to a UTRGV-defined group.

**Podium Computer:** A UTRGV computing device located in a room for presentations or lectures.

## Requirements

### 1. Requirements for All Computers

#### 1.1 Security Updates and Patches

Operating-system and application security updates and patches must be installed expediently.

#### 1.2 Unsupported Products

Operating systems and other products that no longer receive vendor security updates are not authorized.

#### 1.3 Malware Protection

Computers must run enabled malware protection, such as antivirus software, with current definitions.

#### 1.4 Malware and Copyright Compliance

Computers must be free of malware and must not use software in a manner that violates copyright law.

#### 1.5 Password Protection

Computers must be password protected. Default and generic usernames/passwords should be changed or disabled.

#### 1.6 Unattended Computers

Users must log out of or lock computers when they leave them unattended.

#### 1.7 Software Firewall

A software firewall is required.

#### 1.8 Full-Disk Encryption

Full-disk encryption is required.

#### 1.9 Computer Backups

Computer backups are the responsibility of the computer operator or primary user.

### 2. Additional Requirements for UTRGV-Owned, Leased, or Managed Computers

#### 2.1 Change Management

Configuration changes should follow applicable change-management procedures.

#### 2.2 Managed Software Firewall

Computers must run a software firewall that is enabled and managed by UTRGV Computer Support Staff.

#### 2.3 Approved Encryption and Password Protection

Computers must be encrypted and password protected using methods approved by the UTRGV Information Security Office.

#### 2.4 Unattended Computer Security

All computers must automatically lock and require a password after no more than **20 minutes** of inactivity. Unattended portable computers must also be physically secured.

#### 2.5 Hostnames

Computer hostnames must comply with the UTRGV Computer Naming Standard.

#### 2.6 Domain Membership

* Wherever possible, computers must be joined to the UTRGV domain unless the Information Security Office grants an exception.

* When a computer is joined to the UTRGV domain, local accounts must not exist.

* Only UTRGV-owned, leased, or managed computers may join the UTRGV domain.

#### 2.7 Administrative Privileges

* The built-in local administrator account must be disabled and renamed.

* On UTRGV domain-joined computers, LAPS must be used to manage enabled local administrator accounts and enforce password requirements and practices.

* Administrative logons should be limited to tasks that require elevated privileges and only for the necessary duration.

* Administrative privileges are limited to employees responsible for services such as system maintenance and user support.

* Local-administrator requests are granted through an approval process defined by the Information Security Office.

#### 2.8 Confidential Data Registration

Computers that store UTRGV confidential data must be registered with the Information Security Office.

### 3. Additional Requirements for Computers Storing or Accessing Confidential or Sensitive Data

These requirements apply to all computers, including personally owned computers, that store or access UTRGV confidential or sensitive data. The source directs readers to the UTRGV Data Classification Standard for classification guidance.

#### 3.1 Password Protection

Computers must be password protected using standards approved by the Information Security Office.

#### 3.2 Encryption

Any computer on which Confidential University Data is stored or created must use encryption approved by the Information Security Office.

#### 3.3 Backups

Backups should be stored only on UTRGV-owned or sanctioned storage and must be encrypted and password protected.

#### 3.4 Auditing Tools

Computers must have auditing tools that enable the Information Security Office to validate compliance with UTRGV, UT System, state, and federal policies and standards.

### 4. Additional Requirements for UTRGV-Owned, Leased, or Managed Lab and Podium Computers

#### 4.1 Domain Membership

Lab and Podium computers must join the UTRGV Domain under the Lab and Podium Group OU.

#### 4.2 Hostnames

Lab and Podium hostnames must comply with the UTRGV Computer Naming Standard.

#### 4.3 Physical Security

All Lab and Podium computers must be physically secured.

#### 4.4 Screen Lockout

* Lab computers must automatically lock after no more than **30 minutes** of inactivity.

* Podium computers must automatically lock and require a password after no more than **60 minutes** of inactivity.

#### 4.5 Automatic Restart

Lab and Podium computers must automatically restart after no more than **180 minutes** of inactivity.

#### 4.6 Return to Preconfigured State

The device/computer should be capable of returning to a preconfigured state. Lab and Podium computers must reset to a standard image after a reasonable period of non-use. Systems must not permanently retain user information after restart, logout, system failure, power loss, or similar incidents.

#### 4.7 Lab/Podium Software Exceptions

If specific software requirements prevent a Lab or Podium computer from meeting a requirement, the source requires the **Service Request Process** to be followed to address the associated risk.

## Roles and Responsibilities

### End User

Ensures any computer they own or operate meets this standard and should work with UTRGV Computer Support Staff for guidance and compliance.

### UTRGV Computer Support Staff

Ensure computers are configured to support the requirements in this standard.

### Information Security Office

Defines and maintains the standard, including necessary configurations and security practices, to protect UTRGV Information Resources and support compliance with UT System, state, and federal policy and standards.

## Exceptions and Non-Compliance

### Administrator Access Exceptions

If an individual with administrator access cannot meet a requirement on an applicable Information Resource they use or support, the Security Exception Process must be followed to address the associated risk.

### Network Disconnection

A computer that does not meet this standard, lacks required security software, or otherwise threatens UTRGV Information Resources may be disconnected from a UTRGV network immediately and without notice.

### Disciplinary Action

Non-compliance may result in supervisor notification and disciplinary action under applicable UTRGV rules and policies.

## Related UTRGV Documents

* [Acceptable Use Policy](../policies/acceptable-use-policy.md)

* [Kiosk Security Standard](kiosk-security-standard.md)

* [Data Protection Standard for Personally Owned Mobile Devices](data-protection-standard-for-personally-owned-mobile-devices.md)

* [Multi-Factor Authentication Standard](multi-factor-authentication-standard.md)

* [Minimum Security Requirements for Non-Managed Research Network Devices](minimum-security-requirements-for-non-managed-research-network-devices.md)

* UTRGV Data Classification Standard (referenced by source; no page was exposed in reviewed Information Security navigation)

* UTRGV Computer Naming Standard (referenced by source; no page was exposed in reviewed Information Security navigation)

* UTRGV Security Exception Standard / Process (referenced by source; no page was exposed in reviewed Information Security navigation)

## External References

Source references retained as published:

* [UTS 165 Information Resources Use and Security Policy](https://www.utsystem.edu/sites/policy-library/policies/uts-165-information-resources-use-and-security-policy)

* NIST SP 800-53 Revision 4

* Center for Internet Security Critical Security Controls Version 6

See the review report before updating the NIST or CIS version citations; version changes should be accompanied by a control-impact review.

## Revision History

|  **Date**  |    **Revision**     |
|------------|---------------------|
| 2026-08-11 | Initial publication |

## Contact Information

Information Security Office

Email: [++is@utrgv.edu++](mailto:is@utrgv.edu)

Phone: 956-665-7823