Purpose
This standard establishes minimum multi-factor authentication requirements aligned with security best practices. The source states that it was developed in response to UTS 165 Section 4.7 to protect the confidentiality and integrity of UTRGV confidential data. The requirements add a layer of protection against unauthorized access and supplement other UTRGV policies and applicable federal/state data-protection requirements.
Scope
This standard applies to implementation of multi-factor authentication used to ensure only authorized users can access sensitive information by verifying identity through multiple forms of evidence.
Audience
All faculty, staff, student employees, retirees, former employees, contractors, and vendors who access, view, or edit confidential data or other critical University resources.
Authority
-
UTS 165
Definitions
Requirements
MFA is required in the following cases:
-
When an employee or another person providing University services - including a student employee, contractor, or volunteer - logs on to a University network using an enterprise remote-access gateway such as VPN, Terminal Server, Connect, Citrix, or a similar service.
-
When a person remotely accesses an online function, such as a web page, to view or modify employee banking, tax, or financial information.
-
When a server administrator or another person uses administrator credentials to access a server that contains, or can access, confidential University data.
-
When a person described in item 1 remotely accesses a web-based University email interface or an application containing confidential University data as defined by the UTRGV Data Classification Standard.
Roles and Responsibilities
The source does not provide a separate roles section. People in scope are responsible for using MFA in the situations identified above. The Information Security Office receives exemption requests and enforces the standard through access-management and compliance processes.
Exceptions and Non-Compliance
Exemption requests must be submitted to the Information Security Office.
Non-compliance may result in revocation of system or network access, supervisor notification, and reporting to Internal Audit or Compliance. UTRGV employees must comply with institutional rules and regulations, applicable UT System rules and regulations, and applicable state law and regulation.
Related UTRGV Documents
-
Data Protection Standard for Personally Owned Mobile Devices
-
Minimum Security Requirements for Non-Managed Research Network Devices
-
UTRGV Data Classification Standard
External References
Source references:
-
UT System UTS 165 Information Resources Use and Security Policy
-
UTS 165 Standard 4: Access Management
-
Center for Internet Security two-factor-authentication newsletter
-
NIST "Back to Basics: Multi-Factor Authentication (MFA)"
Current UT System policy page:
Revision History
|
Date |
Revision |
|---|---|
|
Initial migration to https://docs.utrgv.edu |
Contact Information
Information Security Office
Email: is@utrgv.edu
Phone: 956-665-7823