Information Security Docs
Breadcrumbs

Data Protection Standard for Personally Owned Mobile Devices

Purpose

These minimum requirements supplement the UTRGV Computer Security Standard, which the source states was developed in response to UTS 165. Compliance improves mobile-device security and helps protect UTRGV Information Resources. The requirements supplement other UTRGV policies and applicable federal and state data-protection requirements.

Scope

This standard applies to all personally owned mobile devices that access or store UTRGV data.

Audience

Employees, students, consultants, vendors, contractors, and other people who own or operate a mobile device that stores or accesses UTRGV data.

Authority

Definitions

Click to expand...

Mobile Device: Includes tablets, mobile phones, and similar devices.

Personally Owned: A mobile device not owned, leased, or managed by UTRGV.

Requirements

1. Mobile Devices Accessing UTRGV Information Resources

Any mobile device that accesses UTRGV Information Resources must be password protected in accordance with UTRGV requirements. Passwords must be changed whenever compromise is suspected.

2. Mobile Devices Accessing and Storing UTRGV Data

A mobile device that both accesses and stores UTRGV data, including UTRGV email, must meet all of the following requirements.

2.1 Vendor Support

The device must be fully supported by its vendor.

2.2 Unauthorized Modifications

Jailbroken, rooted, or similarly modified devices are not authorized.

2.3 Security Updates and Patches

Operating-system and application security updates/patches must be installed expediently.

The device must be free of malware and must not use software in a way that violates copyright law.

2.5 Encryption

The device must be encrypted using a method approved by the Information Security Office.

2.6 Auto-Lock

The device must automatically lock and require a password after 5 minutes of inactivity.

2.7 Auditing Tool

The device must have an auditing tool that enables the Information Security Office to validate compliance with this standard.

2.8 Backups

Mobile-device backups must be password protected and encrypted using methods approved by the Information Security Office.

2.9 Confidential UTRGV Data Storage

Confidential UTRGV data created or stored on a mobile device should be transferred to UTRGV-owned or sanctioned storage as soon as feasible.

2.10 Lost or Stolen Devices

A lost or stolen mobile device must be reported immediately to the Information Security Office.

Mobile devices are subject to public-information requests, subpoenas, court orders, litigation holds, discovery requests, and other requirements that apply to University Information Resources.

Roles and Responsibilities

End User

The end user ensures that a personally owned mobile device they own or operate meets this standard and should work with UTRGV Computer Support Staff for guidance and compliance.

UTRGV Computer Support Staff

Computer Support Staff ensure that mobile devices storing or accessing UTRGV data are configured to support the minimum requirements in this standard.

Information Security Office

The Information Security Office defines and maintains this standard at a level sufficient to specify necessary configurations and security practices, protect UTRGV Information Resources, and support compliance with UT System, state, and federal policies and standards.

Exceptions and Non-Compliance

A mobile device that does not meet these minimum requirements or that otherwise threatens UTRGV Information Resources may have access to UTRGV Information Resources revoked immediately and without notice.

External References

Revision History

Date

Revision

Initial migration to https://docs.utrgv.edu

Contact Information

Information Security Office
Email: is@utrgv.edu
Phone: 956-665-7823