Site Tools


cs_policy_device_security

UVA CS Policy: Endpoint Device Security

Purpose

Describes the requirements and process for endpoint devices within the CS department.


Scope

This policy applies to Faculty, Staff, and Graduate student end user devices such as laptops, desktops, and workstations.

Any endpoint that the department has purchased or reimbursed is covered under this policy.

Not included are CS Linux research servers that are stored in the Rice Hall data center 003, or end user server rooms 374 or 574 as these are managed by another tool such as Ansible. While servers must still be managed, onboarded by CS IT, and adhere to secuity policies, this policy covers specifically end user devices.


Personal Endpoints

In the event that a personal device is used, this can be onboarded and inventoried by CS IT systems staff. In most cases, this may require a wipe/reload of the operating system.

Personal devices for work and research are not supported within the department.


Requirements

For any endpoint device that is under this policy, it must be managed by CS IT, which requires installing security and remote management software.

In instances when research or work conflicts arise from the security and management software, an exception request may be pursued by CS IT on your behalf. This requires specifying justification, and CS IT must still maintain an inventory of the endpoints.

Note, reimbursements cannot be granted until a device has been onboarded by CS IT.


Process - New Equipment

Before equipment is purchased, it may have to be reviewed and approved by CS IT.

When equipment is purchased, it is onboarded by CS IT systems staff before being deployed. This is to ensure the device is enrolled into our inventories regardless if an exception is pursued.


Process - Existing Equipment

The CS IT systems staff are responsible for managing all endpoints covered by this policy, onboarding endpoints, or must pursue exception requests on a per-device basis.

If you have devices that have not been onboarded, or need to pursue an exception request, please complete the following steps

  1. Complete this Equipment Form to specify your endpoint device information
  2. Start a ticket with the helpdesk including the completed form
    1. Email: cshelpdesk@virginia.edu
    2. Subject: Device Security Onboarding Request for: Your Name
    3. Be sure to include the completed form in your request

Process - Offboarding Equipment

At the end of your time at the university, for any personal equipment that was onboarded, CS IT must offboard the equipment, removing software and updating inventories.

  1. Complete this Equipment Form to specify your endpoint device information
  2. Start a ticket with the helpdesk including the completed form
    1. Email: cshelpdesk@virginia.edu
    2. Subject: Device Security Offboarding Request for: Your Name
    3. Be sure to include the completed form in your request

cs_policy_device_security.txt · Last modified: 2026/08/10 18:13 by 127.0.0.1