Information Security Docs
Breadcrumbs

Multi-Factor Authentication Standard

Purpose

This standard establishes minimum multi-factor authentication requirements aligned with security best practices. The source states that it was developed in response to UTS 165 Section 4.7 to protect the confidentiality and integrity of UTRGV confidential data. The requirements add a layer of protection against unauthorized access and supplement other UTRGV policies and applicable federal/state data-protection requirements.

Scope

This standard applies to implementation of multi-factor authentication used to ensure only authorized users can access sensitive information by verifying identity through multiple forms of evidence.

Audience

All faculty, staff, student employees, retirees, former employees, contractors, and vendors who access, view, or edit confidential data or other critical University resources.

Authority

  • UTS 165

Definitions

Click to expand...

MFA / Multi-Factor Authentication: A security enhancement, sometimes called two-factor authentication or 2FA, that requires two pieces of evidence/credentials when a person logs in. Credential factors include:

  • something the user knows, such as a password or PIN;

  • something the user has, such as a smart card; and

  • something the user is, such as a fingerprint.

Remote Access: Access to University Information Resources that originates from a remote location.

Remote Location: A location outside the institution's physical UTRGV network boundary, while including University-leased/rented properties and locations within the University's compliance environment as specified by the source.

Requirements

MFA is required in the following cases:

  1. When an employee or another person providing University services - including a student employee, contractor, or volunteer - logs on to a University network using an enterprise remote-access gateway such as VPN, Terminal Server, Connect, Citrix, or a similar service.

  2. When a person remotely accesses an online function, such as a web page, to view or modify employee banking, tax, or financial information.

  3. When a server administrator or another person uses administrator credentials to access a server that contains, or can access, confidential University data.

  4. When a person described in item 1 remotely accesses a web-based University email interface or an application containing confidential University data as defined by the UTRGV Data Classification Standard.

Roles and Responsibilities

The source does not provide a separate roles section. People in scope are responsible for using MFA in the situations identified above. The Information Security Office receives exemption requests and enforces the standard through access-management and compliance processes.

Exceptions and Non-Compliance

Exemption requests must be submitted to the Information Security Office.

Non-compliance may result in revocation of system or network access, supervisor notification, and reporting to Internal Audit or Compliance. UTRGV employees must comply with institutional rules and regulations, applicable UT System rules and regulations, and applicable state law and regulation.

External References

Source references:

  • UT System UTS 165 Information Resources Use and Security Policy

  • UTS 165 Standard 4: Access Management

  • Center for Internet Security two-factor-authentication newsletter

  • NIST "Back to Basics: Multi-Factor Authentication (MFA)"

Current UT System policy page:

Revision History

Date

Revision

Initial migration to https://docs.utrgv.edu

Contact Information

Information Security Office
Email: is@utrgv.edu
Phone: 956-665-7823