1. Purpose
These guidelines establish the minimum security standards for UC-owned devices. These measures ensure compliance with UC’s IS-3 policy, UCOP Drake Mandate and protect Institutional Information and IT Resources.
2. Scope
Applies to all UC-owned servers, workstations, laptops, and mobile devices used by faculty, staff, researchers, and students.
3. Minimum Security Requirements
-
Operating System & Software:
- Devices must run a supported and regularly updated operating system.
- Security patches and updates ust be applied within 30 days of release.
-
Authentication & Access Control:
- Least Privilege Access (LPA): Administrative accounts must be used only for privileged tasks.
- Strong Password Enforcement: Use strong passwords which aligns with modern NIST guidance (passphrases, MFA, special character + complexity).
-
Automatic Screen Lock: Enforced after 15 minutes of inactivity.
-
Data Protection & Encryption:
-
Full-disk encryption (FDE) required for all laptops and mobile devices.
-
Full-disk encryption (FDE) required for all laptops and mobile devices.
-
Network & Endpoint Security:
- Firewalls must be enabled and configured to block unauthorized access.
- Devices must use UC-approved antivirus and endpoint protection software (EDR).
- Windows PC - Trellix
- MacOS - Trellix
- Mobile - Exempt
- Tablet - Exempt
-
Device Management:
- Lost or stolen devices must be reported to IT within 24 hours.
- All devices must be enrolled in UCSB’s mobile device management (MDM) or endpoint security solution, if available.
- Windows PC - MaaS360 + TRMM
- MacOS - JAMF + TRMM
- Mobile - MaaS360
- Tablet - MaaS360
4. Exception Process
- Exceptions to MDM or EDR enrollment may be considered and require approval of Bren School Dean, IT Director, and UCSB CISO.
- If you wish to pursue an exemption please contact request@bren.ucsb.edu
- Until an exemption is granted, UC-owned devices default to being in-scope.
5. Compliance & Review
- These guidelines will be reviewed annually and updated as necessary to align with IS-3 and other UC security policies. The more detailed and up to date official UC policy can be found here and here.
- Non-compliant devices may be restricted from network access until they meet security standards.
For questions, contact the Unit Information Security Lead (UISL) at itcontact@bren.ucsb.edu