Purpose
This standard establishes minimum requirements for generally shared computing devices that need to be easily accessible to faculty, staff, students, and the public. The source states that the requirements reflect security best practices and were drafted in response to UTS 165. Compliance is intended to improve kiosk security and protect University Information Resources in addition to other UTRGV, federal, and state requirements.
Scope
This standard applies to computing devices owned, leased, or managed by UTRGV that are generally shared and easily accessible to faculty, staff, students, and the general public.
It does not apply to UTRGV-owned, leased, or managed computers governed by the regular Computer Security Standard.
Source Examples of Kiosk Use
The source provides these examples:
-
kiosk machines used by non-affiliated students;
-
sign-in stations for prospective or current employees;
-
iPads used by international current or prospective students to sign in at the International Admissions and Student Services Office; and
-
tablets used for sign-in at the UTRGV Student Food Pantry.
Audience
Employees, students, consultants, vendors, contractors, and affiliated or non-affiliated people who operate a computing device within this scope.
Authority
-
UTS 165
Definitions
Requirements
1. Security Updates and Change Management
Operating-system and application security updates/patches should be installed expediently. Configuration changes should be performed consistently with applicable change-management procedures.
2. Hostnames
Kiosk hostnames must comply with the UTRGV Computer Naming Standard and include the asset property number at the end.
3. Domain Membership
-
Kiosk computers must be joined to the UTRGV Domain under the Kiosk Group OU.
-
Only UTRGV-owned, leased, or managed computers may join the UTRGV domain.
4. Administrative Privileges
-
The built-in local administrator account must be disabled and renamed.
-
UTRGV domain-joined kiosks must use LAPS to manage enabled local administrator accounts and enforce password policy/standards and good practice.
-
Administrative logons should be limited to tasks requiring elevated privileges and only for the necessary duration.
-
Administrative privileges are limited to employees responsible for administrative services such as maintenance and user support.
-
Local-administrator privileges are granted through an approval process defined by the Information Security Office.
5. Unsupported Products
Products, including operating systems, that no longer receive vendor security updates are not authorized.
6. Firewall, Malware Protection, and Copyright Compliance
-
Kiosk computers must use a software firewall that is enabled and managed by UTRGV Computer Support Staff.
-
Kiosks must have enabled malware protection, such as antivirus, with current definitions.
-
Kiosks must be free of malware and must not use software in a manner that infringes copyright law.
7. Physical Security
All kiosk computers must be physically secured.
8. Encryption and Password Protection
-
Kiosk computers must be encrypted and password protected using methods approved by the UTRGV Information Security Office.
-
Full-disk encryption is required.
-
Default and generic usernames and passwords should be changed or disabled.
9. Auto Logon
-
The computer must be configured for auto logon.
-
The auto-logon password should not be shared outside IT.
-
The source states that the UTRGV kiosk account SVR_KIOSK should be used for automatic login.
10. Screen Lockout
Screen lockout is not required for kiosk computers under this standard.
11. Return to Preconfigured State
-
The device/computer should be capable of returning to a preconfigured state.
-
The system must not permanently save user information after restart or user logout.
-
Kiosks should reset to a standard image after a reasonable period when not in use.
12. Backups
Computer backups are the responsibility of the computer operator or primary user.
13. Auditing Tools
Kiosk computers must have auditing tools that allow the Information Security Office to validate compliance with UTRGV, UT System, state, and federal policies and standards.
Roles and Responsibilities
Resource Owner
Ensures kiosks they own or operate meet this standard and should engage UTRGV Computer Support Staff for implementation guidance and compliance.
UTRGV Computer Support Staff
Ensure kiosk computers are configured to support the requirements in this standard.
Information Security Office
Defines and maintains this standard, including necessary configuration and security practices, to protect UTRGV Information Resources and support compliance with UT System, state, and federal requirements.
Exceptions and Non-Compliance
Administrator Access Exceptions
If a person with administrator access cannot meet a requirement for an applicable Information Resource they use or support, the Security Exception Process must be followed to address the associated risk.
Loss of Access
Machines classified by the Information Security Office as kiosks that do not comply may lose access to UTRGV resources.
Disciplinary Action
Non-compliance may result in supervisor notification and disciplinary action under applicable UTRGV rules and policies.
Related UTRGV Documents
-
UTRGV Data Classification Standard (referenced by source; no page was exposed in reviewed Information Security navigation)
-
UTRGV Computer Naming Standard (referenced by source; no page was exposed in reviewed Information Security navigation)
-
UTRGV Security Exception Standard / Process (referenced by source; no page was exposed in reviewed Information Security navigation)
External References
Source references retained as published:
-
NIST SP 800-53 Revision 4
-
Center for Internet Security Critical Security Controls Version 6
See the review report before updating the NIST or CIS version citations.
Revision History
|
Date |
Revision |
|---|---|
|
Initial migration to https://docs.utrgv.edu |
Contact Information
Information Security Office
Email: is@utrgv.edu
Phone: 956-665-7823