Information Security Docs
Breadcrumbs

Minimum Security Requirements for Non-Managed Research Network Devices

Purpose

This standard establishes minimum security requirements for computers connected to the non-managed Research Network. It is intended to protect University Information Resources from unauthorized access, data breaches, and other security threats by aligning the environment with security best practices, UTS 165, and other applicable requirements.

The requirements are mandatory and supplement other UTRGV policies and federal/state regulation. Where this standard conflicts with another compliance requirement, the source directs use of the most stringent requirement to maximize protection of University data.

Scope

This standard:

  • applies to every device connected to the Non-Managed Research Network, whether or not UTRGV owns, leases, or manages the device;

  • applies to all people who use, manage, or support those devices, including faculty, employees, students, consultants, vendors, and contractors;

  • requires every in-scope device to meet the minimum controls, with the Information Security Office authorized to restrict or deny network access for non-compliance;

  • is intended for non-operational systems used for academic or research purposes; and

  • applies only to wired systems and does not cover wirelessly connected systems.

Audience

Employees, faculty, students, consultants, vendors, contractors, and other people who operate a computer within the scope above.

Authority

Definitions

Click to expand...

Non-Managed Research Network: A segmented research-network environment that permits devices not managed by UTRGV central IT to connect for internet access or specialized research functions. Unlike the managed network, devices are not domain-bound or centrally administered by central IT; users are responsible for local management and security compliance; and the environment is intended to support research flexibility, particularly specialized faculty/student computing needs.

Computer: Any electronic device capable of processing, storing, or transmitting data, including physical or virtual desktops, workstations, servers, laptops, tablets, and smartphones.

Medical Device Computer: A computer or computing device physically connected to a medical device solely to control, monitor, or manage that medical device.

Portable Computer: A mobile, battery-powered computer such as a laptop, tablet, or smartphone.

Software Firewall: A software application that monitors and controls inbound/outbound network traffic according to security rules.

Endpoint Detection and Response (EDR): A security solution that continuously monitors endpoints to detect, investigate, and respond to threats or suspicious activity.

Network Vulnerability Agent: Endpoint software that scans for and reports vulnerabilities so known weaknesses can be identified and addressed.

Disk Encryption: Technology that transforms data stored on disk so it cannot be read without authorized decryption credentials.

Authentication Logs: Records of authentication events such as successful logins, logouts, and failed access attempts.

Segregated VLAN: A virtual LAN isolated from other networks to restrict access and increase security for Research Network devices.

MAC Address: A unique identifier assigned to a network interface for data-link-layer communications.

IP Address: A numerical identifier assigned to a device on an Internet Protocol network.

Network Access Control (NAC): A security capability that enforces network-access policy and limits connectivity to authorized and compliant devices.

Local Administrator Account: A privileged local account with broad system-setting/configuration access, generally used for maintenance and support.

Backup: A separately stored copy of data used to restore information after loss or failure.

Vendor-Managed Device: A device maintained, configured, or supported by an external vendor rather than UTRGV IT staff.

Confidential or Sensitive Data: UTRGV information that requires protection because of legal, regulatory, or institutional requirements. The source directs readers to the UTRGV Data Classification Standard for classification guidance.

Requirements

1. System Requirements for All UTRGV and Non-UTRGV Devices

1.1 Host Naming Standard

All computers must use the following hostname convention.

First three characters:

  • RDW - Research Desktop Windows

  • RLW - Research Laptop Windows

  • RDM - Research Desktop Mac

  • RLM - Research Laptop Mac

  • RDL - Research Desktop Linux

  • RLL - Research Laptop Linux

Next five characters: UTRGV Tag Number, used as the device's unique identifier.

Additional characters: At the System Owner's discretion.

Source example: RDW12345 for a Windows research desktop whose UTRGV tag is 12345.

1.2 Operating System and Application Updates

  1. Computers must have current operating-system and application security updates/patches. Updates should be applied within one month of release to reduce vulnerability exposure.

  2. Unsupported/end-of-life operating systems and software that no longer receive vendor security fixes are strictly prohibited.

1.3 Malware Protection

Approved antivirus or anti-malware software must be installed and actively running. Malware definitions and protection engines must remain current through automatic or scheduled updates.

1.4 Software Firewall

A software firewall must be enabled to monitor/control network traffic and add protection from unauthorized network access.

1.5 Required Security Agents

  • EDR: An approved Endpoint Detection and Response solution must be installed and enabled.

  • Network Vulnerability Agent: A vulnerability-scanning agent must be installed for continuous assessment/reporting.

  • NAC Agent: A network-access-control agent must be installed to identify, assess, and report system health.

1.6 Password Protection

  1. Computers must require strong, complex passwords for user authentication.

  2. Passwords must comply with University password standards and be changed regularly as specified by the source.

1.7 Logging

  1. Default logging must be enabled for all applications.

  2. At minimum, operating-system security activity and authentication logs must be retained and protected from unauthorized modification or deletion.

1.8 Administrative Privileges

  1. A separate administrator-level account must be created for elevated access.

  2. The built-in local administrator account must be disabled and renamed.

  3. Separate non-administrative accounts must be used for ordinary user activity.

  4. Administrative privileges should be used only for work requiring elevated access and only for the necessary duration.

1.9 Physical Security

Devices must be physically secured at all times, preferably in locked rooms or cabinets. Where possible, cable locks or similar mechanisms should be used to reduce theft or unauthorized access.

1.10 Endpoint Registration

All devices must be registered with IT, including IP address, MAC address, and physical location, so devices can be identified and governed by network-access controls.

1.11 Backup and Recovery

  1. Backups are the responsibility of the device operator or primary user.

  2. A documented backup standard must be developed, implemented, and followed to support recovery after loss or failure.

1.12 Disk Encryption

Disk encryption must be enabled on computers that store or access confidential or sensitive University data. Encryption keys must be securely managed and access must be limited to authorized personnel.

1.13 Network Segmentation

  1. Devices storing or accessing sensitive data must be placed on a segregated VLAN with internet access limited to essential ports; the source specifies ports 80 and 443.

  2. Wireless connectivity must be disabled.

2. Access Requirements for All Computers

2.1 Application Access Management

  1. Application access must be administratively supported by the designated user or owner.

  2. Maintain a documented list of everyone with access to each application.

  3. Log account provisioning and de-provisioning, including dates and responsible personnel.

  4. Perform quarterly access audits to verify appropriate access and remove unnecessary accounts.

  5. Keep access-audit records for at least three years, or for the life of the grant/project if that period is longer.

2.2 Remote Access

  1. Remote computer access must use the UTRGV VPN with MFA enabled.

  2. Access by external vendors or collaborators must be initiated by a local administrator or authorized user and documented.

2.3 Access Review and Monitoring

  1. Regularly review access logs and authentication records for unauthorized or suspicious activity.

  2. Implement automated alerts for failed logins or unusual access patterns.

2.4 Compliance

  1. Access controls must comply with University policy, applicable federal/state regulation, and grant requirements.

  2. Unauthorized access or access-control failures must be reported to the Information Security Office immediately.

3. Storage Requirements for Confidential or Sensitive Data

These requirements apply to computers that store or access UTRGV confidential or sensitive data; the source directs readers to the UTRGV Data Classification Standard.

3.1 Data Classification

  1. Stored data must be classified according to the UTRGV Data Classification Standard.

  2. Safeguards must correspond to the data's classification level.

3.2 Retention and Disposal

  1. Data retention must follow University policy, grant requirements, and applicable regulation.

  2. When data is no longer required, approved secure-disposal methods must be used, including approved data wiping or physical destruction where appropriate.

3.3 Access Controls

  1. Stored-data access must be limited to authorized personnel.

  2. Records of data access and modification should be maintained where feasible.

3.4 Documentation

Maintain documentation of backup procedures, encryption methods, and access controls for audit/compliance purposes.

4. Networking Requirements for Computers Storing or Accessing Confidential or Sensitive Data

4.1 Network Segmentation

  1. Devices that store or access confidential/sensitive UTRGV data must reside on a segregated VLAN within the Research Network.

  2. The VLAN must restrict internet access to essential ports; the source again gives ports 80 and 443 as examples.

  3. The VLAN must prevent default internal connectivity to the UTRGV operational network.

4.2 Wireless Connectivity

Wireless access is not authorized and must be disabled on all devices.

4.3 Device Registration

Every Research Network device must be registered with IT with its IP address, MAC address, physical location, asset owner, and technical contact. Registration supports device identification and NAC enforcement.

4.4 Network Access Control

  1. The NAC agent is required for posture assessment and compliance verification.

  2. Only authorized and compliant devices may connect to the Research Network.

4.5 Inventory Management

All network-connected equipment must be registered in inventory with at least:

  • make and model number;

  • asset owner;

  • asset-owner email;

  • technical contact; and

  • physical location.

Roles and Responsibilities

Staff and Faculty

  1. Ensure computers they own or operate comply with this standard.

  2. Complete required security-awareness training, including password creation, information classification, and privileged-user responsibilities.

  3. Work with UTRGV IT Computer Support Staff for guidance, configuration, and ongoing compliance.

  4. Promptly report security incidents, vulnerabilities, or non-compliance to the Information Security Office.

UTRGV IT Computer Support Staff

  1. Assist with configuration, maintenance, and support so systems meet this standard.

  2. Provide technical assistance and guidance to faculty, staff, and other users.

  3. Perform periodic audits/reviews and address compliance gaps.

  4. Assist with device registration, network segmentation, and security-control implementation.

For general technical issues, hardware support, or account assistance, the source lists:

  • Edinburg: Computer Center Lobby, 956-665-2020

  • Brownsville: Main Building 1.212A, 956-882-2020

  • Online support: UTRGV IT Support

For specialized research technology, data-management, or specialized software needs, the source lists the Office of Faculty and Research Support (OFRS):

Information Security Office

  1. Define, maintain, and update the standard in alignment with UT System, state, and federal policy.

  2. Monitor compliance, investigate violations, and manage the Security Exception Process.

  3. Provide Research Network security oversight, risk management, and incident response.

  4. Communicate relevant policy, standard, and procedure changes to stakeholders.

Vendor Support Staff

  1. Ensure vendor-managed devices meet applicable requirements.

  2. Work with UTRGV IT Computer Support Staff to maintain compliance and address technical issues.

  3. Provide documentation and justification when an exception is necessary.

  4. Cooperate with audits and requests for information or remediation.

All Users, Including Students, Consultants, Contractors, and External Collaborators

  1. Follow the security requirements while using, managing, or supporting Research Network devices.

  2. Protect confidential and sensitive data under University policy and standards.

  3. Report suspected security incidents, unauthorized access, or policy violations to the Information Security Office or IT support staff.

Exceptions and Non-Compliance

Immediate Remediation

Computers that do not comply, lack required security software, or otherwise threaten UTRGV Information Resources may be disconnected from any UTRGV network immediately and without notice.

Exception Process

  1. If an applicable requirement cannot be met, the Security Exception Process must be followed.

  2. An exception request must document and justify the specific unmet requirement, the reason for non-compliance, and proposed risk-mitigation measures.

  3. All exceptions require Information Security Office review and approval; submission does not guarantee approval.

Reporting and Notification

  • Non-compliance may be reported to supervisors, department heads, or project managers.

  • Suspected security incidents, unauthorized access, or policy violations must be reported promptly to the Information Security Office or IT support staff.

Disciplinary Action

Non-compliance may result in disciplinary or administrative action under applicable UTRGV rules and policies, including loss of network privileges.

Continuous Review

The Information Security Office will monitor compliance, investigate violations, and manage exceptions. Periodic audits will verify adherence and identify gaps.

External References

Source references retained as published:

See the review report before changing framework versions.

Revision History

Date

Revision

Initial migration to https://docs.utrgv.edu

Contact Information

Information Security Office
Email: is@utrgv.edu
Phone: 956-665-7823