Application Server Administration Procedure
The University of North Carolina at Greensboro
Policy Reference: Security of Networks and Networked Data
Approved: November 30, 2006
Document Maintainer: Information Technology Manager, ITS - Data and Voice Operations
Purpose
This procedure addresses the following sections of the related policy:
Section III A.v
"Application server administrators are expected to adhere to the following:
- Ensure that operating system and application software is kept up to date with manufacturer patches.
- Take all necessary precautions to avoid server compromise. Employees and respective departments are responsible for making use of the recommended security software from the ITS division as set forth in the Standards for Computer and Related Technology (supported products list) and for configuring the software according to ITS standards.
- Physically secure the server.
- Endure that data is backed up and retained according to the Computer Systems Backup Policy.
- Maintain system activity logs for auditing purposes.
- Equipment disposal practices must follow ITS protocols to ensure protection of data and licensed software.
- Adhere to the Enterprise Systems Policy"
Risks mitigated through the application of this procedure include potentially damaging network traffic; poor network device performance; and reducing loss, mishandling, and compromise of sensitive data.
Scope
This procedure covers all network servers on the campus. All faculty, staff, and students are also implicitly covered.
Responsible Parties
- Faculty and Staff
- Students
- ITS Employees
- ITS Approved Representative
Procedure
New Networked Server Requests
Requests for connecting a new server to the UNCG network must be submitted to the Technology Service Center.
Network Server Configuration Compliance
Servers connected to the campus network are subject to the following rules and regulations:
- Networked servers must comply with the Enterprise Systems Policy.
- Administrators must take all necessary precautions to avoid server compromise by making use of the recommended security software from the ITS Division set forth in the Standards for Computer Related Technology (supported products list).
- Administrators must physically secure the server.
- Data on networked servers must be backed up and retained according to the Computer Systems Backup Policy.
- An ITS Server Profile must be completed for each server to be placed behind an ITS managed firewall.
- Servers are subject to the UNCG ITS ASP Standards.
Network scans are performed at regular intervals to verify that networked server operating systems and applications are kept up to date with manufacturer patches and no security compromises are detected. ITS reserves the right to remove access for devices that are deemed a security threat to the network environment.
