WPI Network Security Policy

Preface

Today, the university is highly dependent upon networking and computing technologies. Our infrastructure must continue to be protected in order to ensure continuity of services for our core functions-research, education, and business processes required to run the university. It is crucial that we state and enforce a clear network security policy to protect our students, faculty, and staff from internal and external threats inherent in network usage. This document states the policy we currently practice which successfully protects our network, information resources, and users. We accomplish this by looking for anomalies in network use patterns and looking for security vulnerabilities on the devices connected to our network.

A prior version of this policy was reviewed and approved by the president, the president's cabinet, and the Trustee Technology Committee in May 2004. This policy was endorsed by the Faculty on January 20, 2005 and approved by the Board of Trustees in February 2005.

Scope

This policy statement covers all systems and devices of any kind that connect to the WPI network regardless of device ownership. The WPI network is defined to be any WPI network infrastructure (e.g. wired, wireless, residential, fraternity/sorority, etc.) on which systems can connect to each other or to the Internet.

Policy Goals

The goals of this network security policy are:

Policy Statement

This policy establishes measures to prevent or minimize the number of security incidents experienced by the WPI campus network and associated off-campus networks without impacting the university mission or the integrity of the university computing environment and user communities.

Roles & Responsibilities

In support of the WPI mission, the WPI Information Technology Division (IT) will be the sole provider of network resources for the entire WPI community. Special academic networks, not connected to the WPI network, may be designed and constructed by faculty members in pursuit of their educational or research mission. Before a network connection is made, the faculty must involve the WPI Network Operations group (NetOps) in the design to be sure that the WPI network is not adversely affected by such networks. Third party network providers may, from time-to-time, be engaged to support special circumstances; all such third-party relationships must be approved and managed by the IT Division.

The responsibility for the security of university computing resources rests with the individual system administrators who manage these resources. NetOps will support and advise system administrators who carry out these responsibilities in accordance with this policy.

The Vice President for Information Technology / Chief Information Officer leads the development of the network policy. The president, provost, the Vice President for Student Affairs, and other divisional vice presidents agree to support this policy and be responsible for holding their respective constituent groups (their staffs, the students, and the faculty) accountable for behavior that is consistent with this policy.

The Director of Network Operations and Security is in charge of enforcement of the policy. The director will review and respond to all formal complaints resulting from the implementation and enforcement of this policy. Violations will be resolved as stated in the Acceptable Use Policy and Campus Code of Conduct. If necessary, complaints may be escalated to the Campus Hearing Board, appropriate vice presidents, or the president.

All network users shall abide by this policy and the WPI Acceptable Use Policy or risk loss of network privileges and referral to the proper campus authorities for further action

Operational Functions

1. Network Operations (NetOps)

To accomplish the goals of this policy, the WPI NetOps group will perform the following functions.

2. Academic and Administrative Departments

In support of this policy all academic and administrative department heads will provide the Information Technology Division (IT) with the following information and keep it up to date:

If no contact person exists, or is provided to IT, NetOps will assume responsibility for system security.

3. System Administrators

System Administrators will perform the functions listed below:

4. Network Users

All network users will abide by this policy and the WPI Acceptable Use Policy.

Further Information

For more information or clarification of any of the provisions of this policy, please contact the Director of Network Operations and Security at soconnor@wpi.edu or 508-831-5115.

This policy will be reviewed by the IT Division on a yearly basis and updated as needed. When changes are required, IT will consult with faculty governance, department heads, and vice presidents.