Limit Network and Restricted Data Access on Personal Machines
The University of North Carolina at Greensboro
Policy Reference: Acceptable Use of Computing and Electronic Resources
Approved: November 30, 2006
Document Maintainer: Associate Vice Chancellor ITS - Compliance and Business Continuity
Purpose
This procedure addresses the following section of the related policy:
Section III.A
"Students and employees using personal machines may be subject to restricted network access and may only be permitted access to data that is classified as public under the Data Classification Policy. Students and employees may not access restricted data on personal machines except for purposes and practices authorized by the appropriate Data Trustee or Data Steward under the Data Classification Policy."
Risks mitigated through the application of this procedure include reducing loss, mishandling and protection of sensitive data.
Scope
This procedure covers all network and data access using personal machines. All faculty, staff, and vendors are implicitly covered. Students will not have access to sensitive data. Students who are granted access to sensitive data in the course of employment or academic internship are considered staff for the purpose of this procedure.
Responsible Parties
- Faculty and Staff
- ITS Employees
- Remote or Onsite Vendor support
Procedure
Personal machines are only permitted to connect to UNCG's physical network in dorms and designated public network access areas.
Public network areas
These areas are logically or physically separated from the campus and include wireless connections, as well as designated wall ports such as classrooms and the public ports in the Elliot University Center. These locations will be treated as insecure, and access to campus resources from personal machines will be the same as if the computer was a node on the Internet. Users are required to authenticate to a centralized database prior to any network activity.
Public data use
Personal machines will only have access to any UNCG publicly available Web resources (authenticated and non-authenticated) as well as Internet Web resources.
Restricted data use
Personal machines used for University business that require accessing restricted data must adhere to the Remote Access Procedure. Remote access of a system will avoid violation of UNCG software licensing agreements and caching of sensitive data on personal machines.
Telecommuting Policy
Use of personal machines for UNCG business (both on and off campus) under the University's Teleworking Program Policy must adhere to this procedure.
