Vendor Access to Internal Systems
Scope
Vendors requiring access to the Loyola systems for configuration, maintenance, and emergency support must adhere to the restricted and monitored channels that ITS staff uses to access the environment. Additionally, the access should only be activated on an as-needed basis and disabled when not in use. This policy applies to Loyola University Chicago faculty, staff, students, contractors and vendors that connect to servers, applications or network devices that contain or transmit Loyola Protected Data, per the Data Classification Policy.
Purpose
Conduct vendor access to internal systems as listed in PCI requirement 8.1.5 to minimize potential exposure to the University resulting from unauthorized use of resources and to preserve and protect the confidentiality, integrity and availability of the University networks, systems and applications.
Policy
Segregation of Duties
Access to High Security Systems will only be provided to users based on business requirements, job function, responsibilities, or need-to-know. All additions, changes, and deletions to individual system access must be approved by the appropriate supervisor and the ISO, with a valid business justification. All servers, applications or network devices that contain, transmit or process Loyola Protected Data are considered “High Security Systems”.
User Account Access
User Access
All users of High Security Systems will abide by the following set of rules:
- Users with access to High Security Systems will utilize a separate unique account, different from their normal University account. This account will conform to the following standards:
- The password will conform, at a minimum, to the published ITS Password Standards.
- Inactive users will be disabled after 90 days of inactivity.
- Users will not login using generic, shared or service accounts.
RemoteApp Access
Users may only gain access to the RemoteApp environment if:
- Request is submitted by a user’s manager.
- Request is approved by the Director of Cash Management and/or E-Commerce Coordinator.
- User abides by the above user access guidelines.
- Users has completed annual PCI training through the Treasurer’s office.
Administrative Access
- Administrators will abide by the Privileged Access Policy.
- Access will be immediately revoked to all of a user’s access to High Security Systems when a change in employment status, job function, or responsibilities dictate the user no longer requires such access.
- All service accounts must be used by no more than one service, application, or system.
- Administrators must not extend a user group’s permissions in such a way that it provides inappropriate access to any user in that group.
- All servers, applications and network devices shall contain a login banner that displays the following content:
“This computer and network are provided for use by authorized members of the Loyola community. Use of this computer and network are subject to all applicable Loyola policies, including Information Technology Services policies, and any applicable Loyola Handbooks. Any use of this computer or network constitutes acknowledge meant that the user is subject to all applicable policies. Any other use is prohibited.
Users of any networked system, including this computer, should be aware that due to the nature of electronic communications, any information conveyed via a computer or a network may not be private. Sensitive communications should be encrypted or communicated via an alternative method.”
Remote Access
All users and administrators accessing High Security Systems must abide by the following rules:
- No modems or wireless access points are allowed on high security networks, or other unapproved remote access technology.
- All remote access must be authenticated and encrypted through the University’s Virtual Private Network (VPN).
- All remote access will be accomplished through the use of two factor authentication; a username/password combination, and a second method not based on user credentials, such as a certificate or token, provisioned to the user.
- Any third party, non-Loyola affiliate that requires remote access to High Security Systems for support, maintenance or administrative reasons must designate a person to be the Point of Contact (POC) for their organization. In the event the POC changes, the third party must designate a new POC.
- All third party access to High Security Systems must be approved by the Information Security Officer.
- Third parties may access only the systems that they support or maintain.
- All third party accounts on High Security Systems will be disabled and inactive unless needed for support or maintenance.
- The server System Administrator will be responsible for enabling/disabling accounts and monitoring vendor access to said systems.
- All third parties with access to any High Security Systems must adhere to all regulations and governance standards associated with that data (e.g. PCI security requirements for cardholder data, FERPA requirements for student records).
- Data must not be copied from high security systems to a user’s remote machine.
- Access must be requested using published procedures.
Physical Access
All ITS data centers will abide by the following physical security requirements:
- Video surveillance will be installed to monitor access into and out of ITS data centers.
- Access to ITS data centers will be accomplished the use of electronic badge systems.
- Only the Director of Facilities, ITS Infrastructure Services Director, and Service Operations and Data Center Manager will have physical key access.
- Physical access to ITS data centers is limited to ITS personnel, designated approved Loyola employees or contractors whose job function or responsibilities require such physical access.
- These individuals will be classified appropriately in the ITS Roles and Responsibilities Matrix.
- Loyola badges will be prominently displayed.
- Visitors accessing ITS data centers will be accompanied by authorized ITS personnel, and all access will be logged via the ITS Data Center Visitor Access Log.
- This log will be stored at each ITS Data Center.
- Each visitor, and accompanying authorized ITS personnel, must sign in and out of the data center.
- The log will be kept for at least a period of three months.
- Modification, additions or deletions of physical access to ITS data centers will be accomplished by utilizing the ITS High Security Authorization Form. Physical access requires the approval of the ITS Infrastructure Services Director.
The Information Security Team and the ITS Infrastructure Services Director will audit physical access to ITS data centers on an annual basis.
Policy adherence:
Failure to follow this policy can result in disciplinary action as provided in the Employee Staff Handbook, Student Worker Employment Guide, and Faculty Handbook. Disciplinary action for not following this policy may include termination, as provided in the applicable handbook or employment guide.
Questions about this policy:
If you have questions about this policy, please contact the Information Security team at datasecurity@luc.edu.
History:
- November 6, 2013: Initial Policy
- June 17, 2015: Annual review for PCI Compliance
- June 17, 2015: Version 1.1, Minor editing and reordering for readability
- June 22, 2016: Updated “Citrix” to “RemoteApp”, Annual review for PCI Compliance
- June 23, 2017: Annual review for PCI Compliance
- Sep 7, 2018: Annual review for PCI Compliance
- July 12, 2019: Annual review for PCI Compliance
- August 1, 2020: Annual review for PCI Compliance
Scope
Vendors requiring access to the Loyola systems for configuration, maintenance, and emergency support must adhere to the restricted and monitored channels that ITS staff uses to access the environment. Additionally, the access should only be activated on an as-needed basis and disabled when not in use. This policy applies to Loyola University Chicago faculty, staff, students, contractors and vendors that connect to servers, applications or network devices that contain or transmit Loyola Protected Data, per the Data Classification Policy.
Purpose
Conduct vendor access to internal systems as listed in PCI requirement 8.1.5 to minimize potential exposure to the University resulting from unauthorized use of resources and to preserve and protect the confidentiality, integrity and availability of the University networks, systems and applications.
Policy
Segregation of Duties
Access to High Security Systems will only be provided to users based on business requirements, job function, responsibilities, or need-to-know. All additions, changes, and deletions to individual system access must be approved by the appropriate supervisor and the ISO, with a valid business justification. All servers, applications or network devices that contain, transmit or process Loyola Protected Data are considered “High Security Systems”.
User Account Access
User Access
All users of High Security Systems will abide by the following set of rules:
- Users with access to High Security Systems will utilize a separate unique account, different from their normal University account. This account will conform to the following standards:
- The password will conform, at a minimum, to the published ITS Password Standards.
- Inactive users will be disabled after 90 days of inactivity.
- Users will not login using generic, shared or service accounts.
RemoteApp Access
Users may only gain access to the RemoteApp environment if:
- Request is submitted by a user’s manager.
- Request is approved by the Director of Cash Management and/or E-Commerce Coordinator.
- User abides by the above user access guidelines.
- Users has completed annual PCI training through the Treasurer’s office.
Administrative Access
- Administrators will abide by the Privileged Access Policy.
- Access will be immediately revoked to all of a user’s access to High Security Systems when a change in employment status, job function, or responsibilities dictate the user no longer requires such access.
- All service accounts must be used by no more than one service, application, or system.
- Administrators must not extend a user group’s permissions in such a way that it provides inappropriate access to any user in that group.
- All servers, applications and network devices shall contain a login banner that displays the following content:
“This computer and network are provided for use by authorized members of the Loyola community. Use of this computer and network are subject to all applicable Loyola policies, including Information Technology Services policies, and any applicable Loyola Handbooks. Any use of this computer or network constitutes acknowledge meant that the user is subject to all applicable policies. Any other use is prohibited.
Users of any networked system, including this computer, should be aware that due to the nature of electronic communications, any information conveyed via a computer or a network may not be private. Sensitive communications should be encrypted or communicated via an alternative method.”
Remote Access
All users and administrators accessing High Security Systems must abide by the following rules:
- No modems or wireless access points are allowed on high security networks, or other unapproved remote access technology.
- All remote access must be authenticated and encrypted through the University’s Virtual Private Network (VPN).
- All remote access will be accomplished through the use of two factor authentication; a username/password combination, and a second method not based on user credentials, such as a certificate or token, provisioned to the user.
- Any third party, non-Loyola affiliate that requires remote access to High Security Systems for support, maintenance or administrative reasons must designate a person to be the Point of Contact (POC) for their organization. In the event the POC changes, the third party must designate a new POC.
- All third party access to High Security Systems must be approved by the Information Security Officer.
- Third parties may access only the systems that they support or maintain.
- All third party accounts on High Security Systems will be disabled and inactive unless needed for support or maintenance.
- The server System Administrator will be responsible for enabling/disabling accounts and monitoring vendor access to said systems.
- All third parties with access to any High Security Systems must adhere to all regulations and governance standards associated with that data (e.g. PCI security requirements for cardholder data, FERPA requirements for student records).
- Data must not be copied from high security systems to a user’s remote machine.
- Access must be requested using published procedures.
Physical Access
All ITS data centers will abide by the following physical security requirements:
- Video surveillance will be installed to monitor access into and out of ITS data centers.
- Access to ITS data centers will be accomplished the use of electronic badge systems.
- Only the Director of Facilities, ITS Infrastructure Services Director, and Service Operations and Data Center Manager will have physical key access.
- Physical access to ITS data centers is limited to ITS personnel, designated approved Loyola employees or contractors whose job function or responsibilities require such physical access.
- These individuals will be classified appropriately in the ITS Roles and Responsibilities Matrix.
- Loyola badges will be prominently displayed.
- Visitors accessing ITS data centers will be accompanied by authorized ITS personnel, and all access will be logged via the ITS Data Center Visitor Access Log.
- This log will be stored at each ITS Data Center.
- Each visitor, and accompanying authorized ITS personnel, must sign in and out of the data center.
- The log will be kept for at least a period of three months.
- Modification, additions or deletions of physical access to ITS data centers will be accomplished by utilizing the ITS High Security Authorization Form. Physical access requires the approval of the ITS Infrastructure Services Director.
The Information Security Team and the ITS Infrastructure Services Director will audit physical access to ITS data centers on an annual basis.
Policy adherence:
Failure to follow this policy can result in disciplinary action as provided in the Employee Staff Handbook, Student Worker Employment Guide, and Faculty Handbook. Disciplinary action for not following this policy may include termination, as provided in the applicable handbook or employment guide.
Questions about this policy:
If you have questions about this policy, please contact the Information Security team at datasecurity@luc.edu.
History:
- November 6, 2013: Initial Policy
- June 17, 2015: Annual review for PCI Compliance
- June 17, 2015: Version 1.1, Minor editing and reordering for readability
- June 22, 2016: Updated “Citrix” to “RemoteApp”, Annual review for PCI Compliance
- June 23, 2017: Annual review for PCI Compliance
- Sep 7, 2018: Annual review for PCI Compliance
- July 12, 2019: Annual review for PCI Compliance
- August 1, 2020: Annual review for PCI Compliance