Information Security Docs
Breadcrumbs

Kiosk Security Standard

Purpose

This standard establishes minimum requirements for generally shared computing devices that need to be easily accessible to faculty, staff, students, and the public. The source states that the requirements reflect security best practices and were drafted in response to UTS 165. Compliance is intended to improve kiosk security and protect University Information Resources in addition to other UTRGV, federal, and state requirements.

Scope

This standard applies to computing devices owned, leased, or managed by UTRGV that are generally shared and easily accessible to faculty, staff, students, and the general public.

It does not apply to UTRGV-owned, leased, or managed computers governed by the regular Computer Security Standard.

Source Examples of Kiosk Use

The source provides these examples:

  • kiosk machines used by non-affiliated students;

  • sign-in stations for prospective or current employees;

  • iPads used by international current or prospective students to sign in at the International Admissions and Student Services Office; and

  • tablets used for sign-in at the UTRGV Student Food Pantry.

Audience

Employees, students, consultants, vendors, contractors, and affiliated or non-affiliated people who operate a computing device within this scope.

Authority

Definitions

Click to expand...

Computer: Includes physical or virtual computing devices such as desktops, workstations, servers, laptops, tablets, and smartphones.

Kiosk: An interactive computing device that is easily accessible.

Personally Owned: A computer not owned, leased, or managed by UTRGV.

Portable Computer: A portable, normally battery-powered computer, including laptops, tablets, and smartphones.

Software Firewall: Software that limits network traffic to and from a computer according to a security policy.

Requirements

1. Security Updates and Change Management

Operating-system and application security updates/patches should be installed expediently. Configuration changes should be performed consistently with applicable change-management procedures.

2. Hostnames

Kiosk hostnames must comply with the UTRGV Computer Naming Standard and include the asset property number at the end.

3. Domain Membership

  • Kiosk computers must be joined to the UTRGV Domain under the Kiosk Group OU.

  • Only UTRGV-owned, leased, or managed computers may join the UTRGV domain.

4. Administrative Privileges

  • The built-in local administrator account must be disabled and renamed.

  • UTRGV domain-joined kiosks must use LAPS to manage enabled local administrator accounts and enforce password policy/standards and good practice.

  • Administrative logons should be limited to tasks requiring elevated privileges and only for the necessary duration.

  • Administrative privileges are limited to employees responsible for administrative services such as maintenance and user support.

  • Local-administrator privileges are granted through an approval process defined by the Information Security Office.

5. Unsupported Products

Products, including operating systems, that no longer receive vendor security updates are not authorized.

  • Kiosk computers must use a software firewall that is enabled and managed by UTRGV Computer Support Staff.

  • Kiosks must have enabled malware protection, such as antivirus, with current definitions.

  • Kiosks must be free of malware and must not use software in a manner that infringes copyright law.

7. Physical Security

All kiosk computers must be physically secured.

8. Encryption and Password Protection

  • Kiosk computers must be encrypted and password protected using methods approved by the UTRGV Information Security Office.

  • Full-disk encryption is required.

  • Default and generic usernames and passwords should be changed or disabled.

9. Auto Logon

  • The computer must be configured for auto logon.

  • The auto-logon password should not be shared outside IT.

  • The source states that the UTRGV kiosk account SVR_KIOSK should be used for automatic login.

10. Screen Lockout

Screen lockout is not required for kiosk computers under this standard.

11. Return to Preconfigured State

  • The device/computer should be capable of returning to a preconfigured state.

  • The system must not permanently save user information after restart or user logout.

  • Kiosks should reset to a standard image after a reasonable period when not in use.

12. Backups

Computer backups are the responsibility of the computer operator or primary user.

13. Auditing Tools

Kiosk computers must have auditing tools that allow the Information Security Office to validate compliance with UTRGV, UT System, state, and federal policies and standards.

Roles and Responsibilities

Resource Owner

Ensures kiosks they own or operate meet this standard and should engage UTRGV Computer Support Staff for implementation guidance and compliance.

UTRGV Computer Support Staff

Ensure kiosk computers are configured to support the requirements in this standard.

Information Security Office

Defines and maintains this standard, including necessary configuration and security practices, to protect UTRGV Information Resources and support compliance with UT System, state, and federal requirements.

Exceptions and Non-Compliance

Administrator Access Exceptions

If a person with administrator access cannot meet a requirement for an applicable Information Resource they use or support, the Security Exception Process must be followed to address the associated risk.

Loss of Access

Machines classified by the Information Security Office as kiosks that do not comply may lose access to UTRGV resources.

Disciplinary Action

Non-compliance may result in supervisor notification and disciplinary action under applicable UTRGV rules and policies.

  • Acceptable Use Policy

  • Computer Security Standard

  • UTRGV Data Classification Standard (referenced by source; no page was exposed in reviewed Information Security navigation)

  • UTRGV Computer Naming Standard (referenced by source; no page was exposed in reviewed Information Security navigation)

  • UTRGV Security Exception Standard / Process (referenced by source; no page was exposed in reviewed Information Security navigation)

External References

Source references retained as published:

See the review report before updating the NIST or CIS version citations.

Revision History

Date

Revision

Initial migration to https://docs.utrgv.edu

Contact Information

Information Security Office
Email: is@utrgv.edu
Phone: 956-665-7823