Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.

...

Security Control

High

Moderate

Low

Authentication is required to access systems

(tick)

(tick)

(tick)

Enterprise Directory Services (SSO) is required for authentication

(tick)

(tick)

Two-Factor authentication (2FA) is required for users to access systems

Note

Use of campus VPN can be leveraged to ensure 2FA.

(tick)

(tick)

Two-Factor authentication (2FA) is required for privileged access to systems

Note

Use of campus VPN can be leveraged to ensure 2FA.

(tick)

(tick)

(tick)

Two-Factor authentication (2FA) is required for all remote access solutions

Note

Use of campus VPN can be leveraged to ensure 2FA.

(tick)

(tick)

(tick)

All passwords must meet Password Standard

(tick)

(tick)

(tick)

Manage passwords for privileged Service Accounts in password vault

(tick)

(tick)

(tick)

Manage passwords for privileged Shared Application Accounts in privileged access management tool

(tick)

(tick)

(tick)

Manage passwords for Shared Application Accounts with non-privileged access in password vault

(tick)

(tick)

(tick)

Use of restrictive VPN that requires use of a University Devices to conduct privileged access

(tick)

(tick)

(tick)

Two-Factor authentication (2FA) required for non-local maintenance solutions. Individuals must actively accept remote sessions.

(tick)

(tick)

(tick)

Access granted on principle of Least Privilege

(tick)

(tick)

(tick)

Review accounts annually and remove individuals who no longer require access

(tick)

(tick)

Implement host-based firewalls to block all inbound traffic not required for use of computer and/or server

(tick)

(tick)

(tick)

Computer must use session lock after 15 min of inactivity

(tick)

(tick)

Physically secure servers within a University Data Center

(tick)

☑️

☑️

Physically secure servers within Secure Server Room

Note

High-security systems Server storing Sensitive Data MUST be stored in a University Data Center, not Secure Server Room.

(error)

(tick)

(tick)

Backup media must be secured from unauthorized physical access

(tick)

(tick)

(tick)

Printer securely configured in a restricted-access location with authorized person available to receive printout immediately, or printer is password-protected

(tick)

...

Security Control

High

Moderate

Low

Server housed in University Data Center whole-disk encrypted

Server housed in server rooms whole-disk encrypted

Note

High-security systems Servers storing Sensitive Data must be housed within a University Data Center.

(error)

(tick)

Server not in server room/device whole-disk encrypted

Note

Servers storing Sensitive Data must be in housed with a secured server roomUniversity Data Center.

(error)

(tick)

(tick)

Development and testing environments of systems storing data are separate from production environment

(tick)

...