Text Only Version

Minimum Security Standards Policy


UGA Minimum Security Standards for Networked Devices Policy

This policy establishes enforcement for the Minimum Security Standards, mentioned in our Acceptable Use Policy. Its main function is setting the scope and detailing responsibilities in enforcing the Minimum Security Standards. This page is simply a summary of this policy and wording should not be used in place of the official policy. For any clarification, please contact the EITS Help Desk.

Official Policy Text:

Click any statement to reveal the official text and commentary where available.
Expand All   View Printable Version

Scope

This policy applies to all devices connected to the UGA Network (wired or wireless). It also applies to any devices using the uga.edu domain to send or receive data.

Standards Summary

  1. Install all security patches for major programs.

  2. Have updated anti-virus software installed.

  3. Use host-based firewalls.

  4. Password authenticate resources, follow the password standard.

  5. Authentication must be done over encrypted channels, such as HTTPS, SFTP, SSH, and encrypted IMAP. Do not log in using unencrypted means.

  6. Do not allow unauthorized SMTP email relays.

  7. Do not establish unauthenticated proxy servers.

  8. Auto-lock workstations and servers after 20 minutes of inactivity.

  9. Disable all unnecessary services.

Network access or privileges may be revoked if these standards are not followed.