Purpose
These minimum requirements supplement the UTRGV Computer Security Standard, which the source states was developed in response to UTS 165. Compliance improves mobile-device security and helps protect UTRGV Information Resources. The requirements supplement other UTRGV policies and applicable federal and state data-protection requirements.
Scope
This standard applies to all personally owned mobile devices that access or store UTRGV data.
Audience
Employees, students, consultants, vendors, contractors, and other people who own or operate a mobile device that stores or accesses UTRGV data.
Authority
-
UTS 165
Definitions
Requirements
1. Mobile Devices Accessing UTRGV Information Resources
Any mobile device that accesses UTRGV Information Resources must be password protected in accordance with UTRGV requirements. Passwords must be changed whenever compromise is suspected.
2. Mobile Devices Accessing and Storing UTRGV Data
A mobile device that both accesses and stores UTRGV data, including UTRGV email, must meet all of the following requirements.
2.1 Vendor Support
The device must be fully supported by its vendor.
2.2 Unauthorized Modifications
Jailbroken, rooted, or similarly modified devices are not authorized.
2.3 Security Updates and Patches
Operating-system and application security updates/patches must be installed expediently.
2.4 Malware and Copyright Compliance
The device must be free of malware and must not use software in a way that violates copyright law.
2.5 Encryption
The device must be encrypted using a method approved by the Information Security Office.
2.6 Auto-Lock
The device must automatically lock and require a password after 5 minutes of inactivity.
2.7 Auditing Tool
The device must have an auditing tool that enables the Information Security Office to validate compliance with this standard.
2.8 Backups
Mobile-device backups must be password protected and encrypted using methods approved by the Information Security Office.
2.9 Confidential UTRGV Data Storage
Confidential UTRGV data created or stored on a mobile device should be transferred to UTRGV-owned or sanctioned storage as soon as feasible.
2.10 Lost or Stolen Devices
A lost or stolen mobile device must be reported immediately to the Information Security Office.
2.11 Legal and Records Requirements
Mobile devices are subject to public-information requests, subpoenas, court orders, litigation holds, discovery requests, and other requirements that apply to University Information Resources.
Roles and Responsibilities
End User
The end user ensures that a personally owned mobile device they own or operate meets this standard and should work with UTRGV Computer Support Staff for guidance and compliance.
UTRGV Computer Support Staff
Computer Support Staff ensure that mobile devices storing or accessing UTRGV data are configured to support the minimum requirements in this standard.
Information Security Office
The Information Security Office defines and maintains this standard at a level sufficient to specify necessary configurations and security practices, protect UTRGV Information Resources, and support compliance with UT System, state, and federal policies and standards.
Exceptions and Non-Compliance
A mobile device that does not meet these minimum requirements or that otherwise threatens UTRGV Information Resources may have access to UTRGV Information Resources revoked immediately and without notice.
Related UTRGV Documents
External References
Revision History
|
Date |
Revision |
|---|---|
|
Initial migration to https://docs.utrgv.edu |
Contact Information
Information Security Office
Email: is@utrgv.edu
Phone: 956-665-7823