The Bren School Compute Team uses device-management and support tools to maintain the security, reliability, and operation of Bren computing resources. These tools may provide technical capabilities such as hardware and software inventory, security and compliance checks, software installation, remote troubleshooting, command-line administration, and remote desktop support.
Having the technical capability to access a system does not, by itself, authorize a Compute Team member to use that capability for any purpose. Administrative access must be used only as necessary for legitimate University IT support, administration, security, and operational responsibilities.
Expectations for Compute Team Staff
When using privileged or remote-management tools, Compute Team members must:
- Have an authorized business purpose. Access systems only as necessary to perform assigned IT responsibilities or respond to an authorized support, administrative, or security need.
- Obtain permission for interactive remote support. When remotely viewing or controlling a faculty or staff member's active desktop for routine support, inform the user and obtain their permission before connecting whenever reasonably possible.
- Use least perusal. View or access only the information reasonably necessary to complete the task. The ability to browse files, run commands, or view a desktop does not authorize examination of unrelated files, communications, or activity.
- Respect the scope of consent. Permission to troubleshoot a particular problem does not constitute permission to examine unrelated information.
- Use unattended access appropriately. Some IT functions, including inventory, compliance checks, patching, security monitoring, software deployment, server administration, and other background management activities, may occur without an interactive user approval prompt when authorized as part of normal IT operations.
- Escalate when necessary. If a task would require examining electronic communications or other information beyond what is reasonably necessary for routine support or administration, stop and seek appropriate guidance or authorization. Nonconsensual access must follow applicable UCSB and UC procedures.
These expectations apply regardless of whether a management tool technically permits access without user interaction.
What Faculty and Staff Should Know
The presence of management or remote-support software on a UCSB computer does not give IT staff unrestricted authority to examine the contents of that computer.
Management tools are used for legitimate functions such as maintaining an inventory of University equipment and software, applying security requirements, identifying vulnerabilities, deploying updates, troubleshooting problems, and providing remote support.
For routine interactive remote-support sessions, the Compute Team's practice is to obtain the user's permission before viewing or controlling their desktop whenever reasonably possible. Administrative and automated activities that do not involve an interactive support session may occur in the background as part of normal system management.
Compute Team members are expected to limit access to what is necessary for the task and not examine unrelated files, communications, or other information.
UC and UCSB Policy Basis
These practices are based on University requirements including:
- UC BFB-IS-3, Electronic Information Security, §9.2.3 – Management of Privileged Access Rights: privileged access is assigned based on job functions and must include clear instructions for appropriate use.
- UC Electronic Communications Policy (ECP): establishes privacy protections and requirements governing access to electronic communications.
- UCSB Notice of Routine Monitoring Practices under the UC ECP: requires access to be limited to authorized personnel with a need for the information, applies the principle of least perusal, and prohibits seeking electronic communications or other content that is not germane to the authorized purpose.
- UCSB Access With and Without Consent procedures: provides formal procedures for consensual and, when justified and appropriately authorized, nonconsensual access to electronic communications records.
Questions about these practices or the use of Bren IT management tools may be directed to the Bren School Compute Team.