Page Content Main Links Utility Links Footer
You are here: Home > > Information Technology > Standards > Enhanced Security for Desktop/Notebooks
Enhanced Security Management for Desktop/Notebook Computers
Version: 1.1
Status: Approved
Effective Date: 07/01/08
Contact: Director, Technology Administration Services
PURPOSE
The VCCS provides shared information technology resources and services to faculty, students, staff, and college patrons for activities supporting the VCCS mission. The purpose of this standard is to ensure the IT resources used specifically in support of academic instruction and research systems follow the educational industry best practices for protecting endpoints.
SCOPE
The following standard describes some specific risks associated with the granting of administrative rights to a notebook or desktop computer. It further outlines the associated controls that must be in place no later than July 1, 2009 before granting administrative rights on an individual notebook or desktop computer. Computers used in the classrooms and student labs are exempted from this standard.
APPLICABILITY
This standard is applicable to the System Office and all colleges.
DEFINITION
Academic instruction and research systems, as noted in the SEC501-01 Security Standard, are defined as those systems used by institutions of higher education for the purpose of providing instruction to students and/or faculty for the purpose of conducting research. As such, these systems are exempt from the requirements of the Standard. For VCCS purposes, academic instruction and research systems include the desktop computers, notebook computers, computer labs, classrooms, and related infrastructure used by the college teaching faculty, teaching assistants, and instructional technologist providing direct instructional support to the students and faculty.
STANDARD
In accordance with the VCCS Information Security Standard, notebook and desktop computers used in support of academic instruction and research systems can be granted administrative rights, and support the use of non COV owned mobile devices. All authorized individuals granted administrative rights under this standard will be required to follow and adhere to all local college policies and procedures that maybe derived from this guidance. However, the following also applies:
Major Risks & Controls
Risks are associated with using computers to conduct the business activities; as such they can have intentional and unintentional consequences. If they are intentional then it is quite possible that the best controls may be defeated. However, risk assessment remains a critical activity in protecting Information Technology resources. Therefore the following are list of the risks normally associated with the use of desktop and notebook computers and the controls that are required by this standard:
Controlling access to local administrative rights is a portion of a layered security model or defense-in-depth strategy. Colleges and System Office should conduct an assessment for each application of this standard.
RELATED LINKS
Open the original version of this page.
Usablenet Assistive is a UsableNet product. Usablenet Assistive Main Page.