Security Tips & Best Practices

Keeping your system and data secure by following good security practices can help others in the University community benefit from decreased risk. The following security best practices have been sorted based on your needs.

How To Be Secure

Secure Your Office

  • When leaving, lock the door and keep unauthorized users away from systems.
  • Keep all media containing confidential information in a secure place.
  • Keep any paper records containing level 1 data in a locked location.
  • Keep your desk clean of any level 1 data.

Secure Your Computer

  • Enable password-protect or biometric authentication on your devices.
  • When changing your password, make sure you change it everywhere you may have your credentials stored.
  • Close applications and log out when you're away from your computer for any length of time.
  • Install the UHS required endpoint protection software and scan all removable media for malware before plugging them into your devices.
  • Turn on automatic updates to apply operating system security updates and application updates. When using images to support multiple systems, be sure the image is updated regularly with all applicable patches and malware protection. Check regularly for updates to third party applications such as Adobe Acrobat, Google Chrome, etc., or consider using an automated patching solution. Automatic updates offered by Windows and Macs do not always patch these applications.

Secure Your Data

  • Backup systems thoroughly and often, and store your backups in a separate secure location. When dealing with mission critical data, considering following the rule of 3-2-1. There should be 3 copies of data, on 2 different media, with 1 copy being off-site. 
  • Do not save sensitive information to portable drives. Be sure to encrypt sensitive data wherever it is stored.

Secure Your Email

  • Verify the contents of any email attachment before opening and never open attachments from unknown persons.
  • Do not respond to any email requesting confidential information (username, password, social security number, etc.). Legitimate businesses will never ask for this information via email.
  • Delete messages that you no longer need - some common practices include emptying your trash and outgoing mail folders.
  • Delete spam, or suspect messages or use Outlook to report the message.
  • To protect university email accounts against spamming, each university has limits on sending out mass email communications from personal email accounts.  If you need to communicate with all of your students, consider using the communication tools built into Canvas, distribution lists, or contact your IT contact/UHS Information Security and work with us to ensure your communication gets delivered.

Tips for IT Administrators

  • Limit the use of administrator privileges. Restricting adminstrative rights will help prevent the potential installation of malware and other unwanted software by unsuspecting users.
  • Keep systems updated with all of the current security patches. Enroll your devices in the UHS Information Security approved management systems, and opt into the automatic patching configurations.
  • Apply the required information security baseline to all your UHS owned devices.
  • Delete all data from computers before they are sent to property management.
  • Enable computer firewalls. Macos and Windows computers come with built-in firewalls.
  • Ensure that all users complete Security Awareness Training.
  • Enforce policies to prevent the installation of unlicensed/unapproved software.