Purpose
This standard establishes minimum security requirements for computers connected to the non-managed Research Network. It is intended to protect University Information Resources from unauthorized access, data breaches, and other security threats by aligning the environment with security best practices, UTS 165, and other applicable requirements.
The requirements are mandatory and supplement other UTRGV policies and federal/state regulation. Where this standard conflicts with another compliance requirement, the source directs use of the most stringent requirement to maximize protection of University data.
Scope
This standard:
-
applies to every device connected to the Non-Managed Research Network, whether or not UTRGV owns, leases, or manages the device;
-
applies to all people who use, manage, or support those devices, including faculty, employees, students, consultants, vendors, and contractors;
-
requires every in-scope device to meet the minimum controls, with the Information Security Office authorized to restrict or deny network access for non-compliance;
-
is intended for non-operational systems used for academic or research purposes; and
-
applies only to wired systems and does not cover wirelessly connected systems.
Audience
Employees, faculty, students, consultants, vendors, contractors, and other people who operate a computer within the scope above.
Authority
-
UTS 165
Definitions
Requirements
1. System Requirements for All UTRGV and Non-UTRGV Devices
1.1 Host Naming Standard
All computers must use the following hostname convention.
First three characters:
-
RDW- Research Desktop Windows -
RLW- Research Laptop Windows -
RDM- Research Desktop Mac -
RLM- Research Laptop Mac -
RDL- Research Desktop Linux -
RLL- Research Laptop Linux
Next five characters: UTRGV Tag Number, used as the device's unique identifier.
Additional characters: At the System Owner's discretion.
Source example: RDW12345 for a Windows research desktop whose UTRGV tag is 12345.
1.2 Operating System and Application Updates
-
Computers must have current operating-system and application security updates/patches. Updates should be applied within one month of release to reduce vulnerability exposure.
-
Unsupported/end-of-life operating systems and software that no longer receive vendor security fixes are strictly prohibited.
1.3 Malware Protection
Approved antivirus or anti-malware software must be installed and actively running. Malware definitions and protection engines must remain current through automatic or scheduled updates.
1.4 Software Firewall
A software firewall must be enabled to monitor/control network traffic and add protection from unauthorized network access.
1.5 Required Security Agents
-
EDR: An approved Endpoint Detection and Response solution must be installed and enabled.
-
Network Vulnerability Agent: A vulnerability-scanning agent must be installed for continuous assessment/reporting.
-
NAC Agent: A network-access-control agent must be installed to identify, assess, and report system health.
1.6 Password Protection
-
Computers must require strong, complex passwords for user authentication.
-
Passwords must comply with University password standards and be changed regularly as specified by the source.
1.7 Logging
-
Default logging must be enabled for all applications.
-
At minimum, operating-system security activity and authentication logs must be retained and protected from unauthorized modification or deletion.
1.8 Administrative Privileges
-
A separate administrator-level account must be created for elevated access.
-
The built-in local administrator account must be disabled and renamed.
-
Separate non-administrative accounts must be used for ordinary user activity.
-
Administrative privileges should be used only for work requiring elevated access and only for the necessary duration.
1.9 Physical Security
Devices must be physically secured at all times, preferably in locked rooms or cabinets. Where possible, cable locks or similar mechanisms should be used to reduce theft or unauthorized access.
1.10 Endpoint Registration
All devices must be registered with IT, including IP address, MAC address, and physical location, so devices can be identified and governed by network-access controls.
1.11 Backup and Recovery
-
Backups are the responsibility of the device operator or primary user.
-
A documented backup standard must be developed, implemented, and followed to support recovery after loss or failure.
1.12 Disk Encryption
Disk encryption must be enabled on computers that store or access confidential or sensitive University data. Encryption keys must be securely managed and access must be limited to authorized personnel.
1.13 Network Segmentation
-
Devices storing or accessing sensitive data must be placed on a segregated VLAN with internet access limited to essential ports; the source specifies ports 80 and 443.
-
Wireless connectivity must be disabled.
2. Access Requirements for All Computers
2.1 Application Access Management
-
Application access must be administratively supported by the designated user or owner.
-
Maintain a documented list of everyone with access to each application.
-
Log account provisioning and de-provisioning, including dates and responsible personnel.
-
Perform quarterly access audits to verify appropriate access and remove unnecessary accounts.
-
Keep access-audit records for at least three years, or for the life of the grant/project if that period is longer.
2.2 Remote Access
-
Remote computer access must use the UTRGV VPN with MFA enabled.
-
Access by external vendors or collaborators must be initiated by a local administrator or authorized user and documented.
2.3 Access Review and Monitoring
-
Regularly review access logs and authentication records for unauthorized or suspicious activity.
-
Implement automated alerts for failed logins or unusual access patterns.
2.4 Compliance
-
Access controls must comply with University policy, applicable federal/state regulation, and grant requirements.
-
Unauthorized access or access-control failures must be reported to the Information Security Office immediately.
3. Storage Requirements for Confidential or Sensitive Data
These requirements apply to computers that store or access UTRGV confidential or sensitive data; the source directs readers to the UTRGV Data Classification Standard.
3.1 Data Classification
-
Stored data must be classified according to the UTRGV Data Classification Standard.
-
Safeguards must correspond to the data's classification level.
3.2 Retention and Disposal
-
Data retention must follow University policy, grant requirements, and applicable regulation.
-
When data is no longer required, approved secure-disposal methods must be used, including approved data wiping or physical destruction where appropriate.
3.3 Access Controls
-
Stored-data access must be limited to authorized personnel.
-
Records of data access and modification should be maintained where feasible.
3.4 Documentation
Maintain documentation of backup procedures, encryption methods, and access controls for audit/compliance purposes.
4. Networking Requirements for Computers Storing or Accessing Confidential or Sensitive Data
4.1 Network Segmentation
-
Devices that store or access confidential/sensitive UTRGV data must reside on a segregated VLAN within the Research Network.
-
The VLAN must restrict internet access to essential ports; the source again gives ports 80 and 443 as examples.
-
The VLAN must prevent default internal connectivity to the UTRGV operational network.
4.2 Wireless Connectivity
Wireless access is not authorized and must be disabled on all devices.
4.3 Device Registration
Every Research Network device must be registered with IT with its IP address, MAC address, physical location, asset owner, and technical contact. Registration supports device identification and NAC enforcement.
4.4 Network Access Control
-
The NAC agent is required for posture assessment and compliance verification.
-
Only authorized and compliant devices may connect to the Research Network.
4.5 Inventory Management
All network-connected equipment must be registered in inventory with at least:
-
make and model number;
-
asset owner;
-
asset-owner email;
-
technical contact; and
-
physical location.
Roles and Responsibilities
Staff and Faculty
-
Ensure computers they own or operate comply with this standard.
-
Complete required security-awareness training, including password creation, information classification, and privileged-user responsibilities.
-
Work with UTRGV IT Computer Support Staff for guidance, configuration, and ongoing compliance.
-
Promptly report security incidents, vulnerabilities, or non-compliance to the Information Security Office.
UTRGV IT Computer Support Staff
-
Assist with configuration, maintenance, and support so systems meet this standard.
-
Provide technical assistance and guidance to faculty, staff, and other users.
-
Perform periodic audits/reviews and address compliance gaps.
-
Assist with device registration, network segmentation, and security-control implementation.
For general technical issues, hardware support, or account assistance, the source lists:
-
Edinburg: Computer Center Lobby, 956-665-2020
-
Brownsville: Main Building 1.212A, 956-882-2020
-
Online support: UTRGV IT Support
For specialized research technology, data-management, or specialized software needs, the source lists the Office of Faculty and Research Support (OFRS):
-
Phone: 956-665-3417
-
Location: EECTR 2.602, Edinburg
Information Security Office
-
Define, maintain, and update the standard in alignment with UT System, state, and federal policy.
-
Monitor compliance, investigate violations, and manage the Security Exception Process.
-
Provide Research Network security oversight, risk management, and incident response.
-
Communicate relevant policy, standard, and procedure changes to stakeholders.
Vendor Support Staff
-
Ensure vendor-managed devices meet applicable requirements.
-
Work with UTRGV IT Computer Support Staff to maintain compliance and address technical issues.
-
Provide documentation and justification when an exception is necessary.
-
Cooperate with audits and requests for information or remediation.
All Users, Including Students, Consultants, Contractors, and External Collaborators
-
Follow the security requirements while using, managing, or supporting Research Network devices.
-
Protect confidential and sensitive data under University policy and standards.
-
Report suspected security incidents, unauthorized access, or policy violations to the Information Security Office or IT support staff.
Exceptions and Non-Compliance
Immediate Remediation
Computers that do not comply, lack required security software, or otherwise threaten UTRGV Information Resources may be disconnected from any UTRGV network immediately and without notice.
Exception Process
-
If an applicable requirement cannot be met, the Security Exception Process must be followed.
-
An exception request must document and justify the specific unmet requirement, the reason for non-compliance, and proposed risk-mitigation measures.
-
All exceptions require Information Security Office review and approval; submission does not guarantee approval.
Reporting and Notification
-
Non-compliance may be reported to supervisors, department heads, or project managers.
-
Suspected security incidents, unauthorized access, or policy violations must be reported promptly to the Information Security Office or IT support staff.
Disciplinary Action
Non-compliance may result in disciplinary or administrative action under applicable UTRGV rules and policies, including loss of network privileges.
Continuous Review
The Information Security Office will monitor compliance, investigate violations, and manage exceptions. Periodic audits will verify adherence and identify gaps.
Related UTRGV Documents
-
UTRGV Data Classification Standard
-
UTRGV Computer Naming Standard
-
UTRGV Security Exception Standard / Process
External References
Source references retained as published:
-
NIST SP 800-53 Revision 4
-
Center for Internet Security Critical Security Controls Version 6
See the review report before changing framework versions.
Revision History
|
Date |
Revision |
|---|---|
|
Initial migration to https://docs.utrgv.edu |
Contact Information
Information Security Office
Email: is@utrgv.edu
Phone: 956-665-7823