Table of Contents
UVA CS Policy: Endpoint Device Security
Purpose
Describes the requirements and process for endpoint devices within the CS department.
Scope
This policy applies to Faculty, Staff, and Graduate student end user devices such as laptops, desktops, and workstations.
Any endpoint that the department has purchased or reimbursed is covered under this policy.
Not included are CS Linux research servers that are stored in the Rice Hall data center 003, or end user server rooms 374 or 574 as these are managed by another tool such as Ansible. While servers must still be managed, onboarded by CS IT, and adhere to secuity policies, this policy covers specifically end user devices.
Personal Endpoints
In the event that a personal device is used, this can be onboarded and inventoried by CS IT systems staff. In most cases, this may require a wipe/reload of the operating system.
Personal devices for work and research are not supported within the department.
Requirements
For any endpoint device that is under this policy, it must be managed by CS IT, which requires installing security and remote management software.
In instances when research or work conflicts arise from the security and management software, an exception request may be pursued by CS IT on your behalf. This requires specifying justification, and CS IT must still maintain an inventory of the endpoints.
Note, reimbursements cannot be granted until a device has been onboarded by CS IT.
Process - New Equipment
Before equipment is purchased, it may have to be reviewed and approved by CS IT.
When equipment is purchased, it is onboarded by CS IT systems staff before being deployed. This is to ensure the device is enrolled into our inventories regardless if an exception is pursued.
Process - Existing Equipment
The CS IT systems staff are responsible for managing all endpoints covered by this policy, onboarding endpoints, or must pursue exception requests on a per-device basis.
If you have devices that have not been onboarded, or need to pursue an exception request, please complete the following steps
- Complete this Equipment Form to specify your endpoint device information
- Start a ticket with the helpdesk including the completed form
- Email: cshelpdesk@virginia.edu
- Subject: Device Security Onboarding Request for: Your Name
- Be sure to include the completed form in your request
Process - Offboarding Equipment
At the end of your time at the university, for any personal equipment that was onboarded, CS IT must offboard the equipment, removing software and updating inventories.
- Complete this Equipment Form to specify your endpoint device information
- Start a ticket with the helpdesk including the completed form
- Email: cshelpdesk@virginia.edu
- Subject: Device Security Offboarding Request for: Your Name
- Be sure to include the completed form in your request