Information Security Docs
Breadcrumbs

Prohibited Technologies Policy

Purpose

The policy implements Texas and UT System restrictions on prohibited technologies. The source traces the policy to Governor Greg Abbott's December 7, 2022 directive banning TikTok on state-owned/state-issued devices and networks, subsequent Texas Department of Public Safety (DPS) and Texas Department of Information Resources (DIR) guidance, the UT System Prohibited Technologies Security Policy issued February 14, 2023, and Senate Bill 1893 enacted by the 88th Texas Legislature.

Scope and Applicability

This policy follows UT System requirements and applies to UTRGV and to Prohibited Technologies identified through:

  • the Governor's December 7, 2022 directive or later Governor directives;

  • Texas Government Code Chapter 620, including covered applications defined there, or later Texas law/regulation; and

  • additional technologies designated by UT System or UTRGV as described below.

The policy replaces earlier UTRGV prohibited-technology policies adopted under the December 7, 2022 directive.

It applies to all full- and part-time UTRGV employees, contractors, paid or unpaid interns, apprentices, and other users of government-owned or leased devices or government networks (collectively, UTRGV Personnel).

Authority and Governing Requirements

  • Texas Government Code Chapter 620

  • Governor directives concerning covered applications and prohibited technologies

  • UT System policy, including UTS 165 and UTS 200

  • DPS and DIR prohibited-technology determinations

Definitions

Click to expand...

Prohibited Technologies: Technologies identified under applicable Governor directives, Texas Government Code Chapter 620 or subsequent law/regulation, and technologies identified by UT System or UTRGV under this policy. The source includes, but does not limit the term to:

  1. TikTok and successor applications/services developed or provided by ByteDance Limited or an entity owned by ByteDance Limited.

  2. Social-media applications/services specified by the Governor under Texas Government Code Section 620.005 or by DIR/DPS under Section 620.006.

  3. Prohibited Technologies made available through application stores for mobile, desktop, or other internet-capable devices.

Sensitive Location: A physical or logical location, while it is used to display or discuss confidential or sensitive information, including IT configurations, criminal-justice information, financial data, personally identifiable information, sensitive personal information, or data protected by federal/state law. The source gives a SCIF as an example and includes logical settings such as video conferences and electronic meeting rooms.

Policy Requirements

1. Government-Owned or Leased Devices

Except for approved exceptions, UTRGV prohibits purchase, use, and installation of Prohibited Technologies on government-owned or leased devices, including phones, tablets, desktops, laptops, and other internet-capable devices.

UTRGV must identify, track, and manage government-owned or leased devices to:

  1. prevent installation of Prohibited Technologies;

  2. prevent their use;

  3. stop use of Prohibited Technologies acquired before the effective date of the Governor's directive or Texas Government Code Chapter 620;

  4. remove Prohibited Technologies installed or used before those requirements took effect; and

  5. stop use and remove technologies after they are newly designated as prohibited.

UTRGV Information Technology and Information Security must, to the extent possible and practical with available or future technology:

  • document, maintain, and implement procedures restricting access to app stores, websites, and unauthorized software repositories to prevent prohibited installation/use;

  • use both procedural controls, such as acceptable-use terms, and technical controls that prevent access, download, installation, or execution;

  • maintain the capability to remotely wipe Prohibited Technologies from non-compliant or compromised devices, networks, and computer systems;

  • maintain the capability to remotely uninstall and disable Prohibited Technologies;

  • deploy secure baseline configurations for mobile devices as determined by UTRGV; and

  • audit government-owned or leased devices, networks, and computer systems for compliance.

2. Personal Devices Used for State Business

UTRGV Personnel may not install or operate Prohibited Technologies on personal devices used to conduct state business. State business includes using the device to access state-owned data, applications, email accounts, non-public communications, state email, VoIP, SMS, video conferencing, CAPPS, http://Texas.gov , or other state databases/applications.

The source cites UTS 200 and states that, where UTRGV operates a BYOD program, its BYOD policy must require enrollment of personal devices before continued governmental-business use and must prohibit Prohibited Technologies on those devices.

The source also states that UTRGV is instituting a BYOD and Mobile Device Management Program aligned with this policy, UTS 165, UTS 200, and the intent of the GLBA and HIPAA Safeguard Rules, and says: "Effective the Summer of 2026 UTRGV will institute a new and improved BYOD policy for the institution." This time-bound source statement is retained for owner review because this normalized package was prepared after Summer 2026.

3. Sensitive Locations

  1. UTRGV Information Security and police departments must identify, catalog, label, and develop procedures for sensitive locations at UTRGV campuses and buildings.

  2. UTRGV Personnel whose personal device does not comply with this policy may not bring that device into a sensitive location or use it to access a sensitive location, including remotely participating in an electronic meeting or discussion taking place in such a location.

  3. Visitors are subject to the same limitations. If a visitor is admitted to a sensitive location and has Prohibited Technology on a personal device, the visitor must leave that device at a non-sensitive location approved by the Information Security Office or police department responsible for the secured location.

4. Network Restrictions

In addition to DIR blocking on the state network, UTRGV must provide defense in depth by:

  1. configuring firewalls to block Prohibited Technologies across UTRGV technology infrastructure, including local networks, WAN, and VPN connections;

  2. prohibiting personal devices containing Prohibited Technologies from connecting to UTRGV, UT System, or state technology infrastructure or state data; and

  3. with Presidential approval, providing a separate network that allows access to Prohibited Technologies only to the extent needed for an approved exception under this policy.

5. Ongoing and Emerging Technology Threats

  1. DPS and DIR will monitor and evaluate additional social-media applications/services that pose risk to Texas sensitive information or critical infrastructure.

  2. The source states that DIR will annually submit a list of risky social-media applications/services to the Governor and that the Governor may designate listed or otherwise identified technologies as prohibited.

  3. When the Governor designates a technology as prohibited, UTRGV must address it under this policy, including removal and prohibition where required.

  4. UTRGV and UT System may designate additional social-media applications, services, software, hardware, or other technologies as prohibited beyond Governor/DPS/DIR designations.

6. Prohibited Technology Exceptions

UT System and UTRGV authorize exceptions, consistent with Texas Government Code Chapter 620, only to the extent needed for:

  1. law enforcement, including land-management security and safety;

  2. public-safety investigations or other investigations/adjudications required by law, regulation, or policy;

  3. development or implementation of information-security measures;

  4. enforcement of UTRGV-owned intellectual-property rights; or

  5. research, including agricultural research, when covered technology is critical to the project and an approved technology control plan protects campus research security, data, and networks.

An implemented exception must be documented in writing, including risk-mitigation measures. Exception documentation must:

  • identify the UTRGV Personnel or students allowed to install/use the Prohibited Technology;

  • be approved by the applicable UTRGV police office/department for law-enforcement uses, by the CISO for information-security uses, by the Chief Research Officer for qualifying research, or by the Chief Legal Officer for intellectual-property enforcement and qualifying public-safety/investigation/adjudication uses;

  • also receive CISO approval for all exemption requests, with the source requiring the referenced category of request to be countersigned by the Chief Legal Officer;

  • permit emergency/exigent investigations or security countermeasures to be approved directly by either the CISO or Chief of Police, followed by review and approval from the applicable approver;

  • last no longer than one year; renewals require reevaluation, updated control plans, and approval under this policy;

  • be maintained by the Information Security Office and reviewed annually in a report to the UTRGV President; and

  • be reported to the UTRGV President, DIR, the System Vice Chancellor, and General Counsel once authorized and as required.

Roles and Responsibilities

  • UTRGV Personnel: comply with device, network, sensitive-location, and training requirements.

  • Information Technology and Information Security: implement device-management, blocking, remote-removal, baselines, audits, and other technical safeguards.

  • Information Security Office and police departments: identify and manage sensitive-location procedures.

  • CISO, Chief of Police, Chief Research Officer, Chief Legal Officer, and President: perform exception and network approvals as assigned above.

Compliance and Enforcement

  1. UTRGV Personnel shall complete annual information-security training confirming understanding of the Prohibited Technology and Covered Applications policy.

  2. The Information Security Office will verify compliance through methods that can include IT/security-system reports and feedback to leadership.

  3. Violations may result in disciplinary action, including termination of employment.

Exceptions

The exception process in Section 6 is the controlling process for installation/use of Prohibited Technologies when one of the enumerated purposes applies. No exception can exceed one year without reevaluation and reapproval.

External References

Review and Revision History

Date

Revision

Initial migration to https://docs.utrgv.edu

Contact Information

Information Security Office
Email: is@utrgv.edu
Phone: 956-665-7823