{"id":1169,"date":"2024-12-24T14:00:36","date_gmt":"2024-12-24T20:00:36","guid":{"rendered":"https:\/\/creativedisturbance.org\/?p=1169"},"modified":"2025-01-09T23:16:14","modified_gmt":"2025-01-10T05:16:14","slug":"artscilab-cyber-security-policy-overview-and-review","status":"publish","type":"post","link":"https:\/\/creativedisturbance.org\/index.php\/2024\/12\/24\/artscilab-cyber-security-policy-overview-and-review\/","title":{"rendered":"ArtSciLab Cyber Security Policy: Overview and Review"},"content":{"rendered":"\n<p><span style=\"font-weight: 100;\" class=\"editor-bridge-has-font-weight\"><span style=\"font-size: 20px;\" class=\"editor-bridge-has-font-size\"><strong>Author<\/strong>: <a href=\"http:\/\/creativedisturbance.org\/index.php\/collins-mwange\/\">Collins Mwange<\/a>, Dec 24, 2024<\/span><\/span><\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Audio Deep Dive<\/h3>\n\n\n\n<div style=\"height:10px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<iframe title=\"Embed Player\" style=\"border: medium;\" src=\"https:\/\/play.libsyn.com\/embed\/episode\/id\/34798380\/height\/192\/theme\/modern\/size\/large\/thumbnail\/yes\/custom-color\/414141\/time-start\/00:00:00\/playlist-height\/200\/direction\/backward\/download\/yes\/font-color\/FFFFFF\" height=\"192\" width=\"100%\" scrolling=\"no\" allowfullscreen=\"\" webkitallowfullscreen=\"true\" mozallowfullscreen=\"true\" oallowfullscreen=\"true\" msallowfullscreen=\"true\"><\/iframe>\n\n\n\n<div style=\"height:30px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<h3 class=\"wp-block-heading\">Policy Overview<\/h3>\n\n\n\n<p>ArtSciLab&#8217;s cybersecurity policy manual outlines procedures for protecting lab technology and information assets. It details classifications for information and computer systems, specifying access levels and user responsibilities. The policy addresses various security threats, including insider threats, hackers, and vulnerabilities. It establishes acceptable use guidelines, penalties for violations, and procedures for handling security incidents. The document emphasizes user accountability and proactive security measures to maintain the lab&#8217;s data integrity and system availability.<\/p>\n\n\n\n<div style=\"height:20px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<h3 class=\"wp-block-heading\">Policy Manual PDF<\/h3>\n\n\n\n<div style=\"height:10px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<div data-wp-interactive=\"core\/file\" class=\"wp-block-file\"><object data-wp-bind--hidden=\"!state.hasPdfPreview\" hidden class=\"wp-block-file__embed\" data=\"http:\/\/creativedisturbance.org\/wp-content\/uploads\/2024\/08\/ArtSciLab-Cyber-Policy-v1.0-Spring2025.pdf\" type=\"application\/pdf\" style=\"width:100%;height:500px\" aria-label=\"Embed of ArtSciLab-Cyber-Policy-v1.0-Spring2025.\"><\/object><a id=\"wp-block-file--media-b5abfcd3-a488-479d-8012-8f71d6813d05\" href=\"http:\/\/creativedisturbance.org\/wp-content\/uploads\/2024\/08\/ArtSciLab-Cyber-Policy-v1.0-Spring2025.pdf\">ArtSciLab-Cyber-Policy-v1.0-Spring2025<\/a><a href=\"http:\/\/creativedisturbance.org\/wp-content\/uploads\/2024\/08\/ArtSciLab-Cyber-Policy-v1.0-Spring2025.pdf\" class=\"wp-block-file__button wp-element-button\" download aria-describedby=\"wp-block-file--media-b5abfcd3-a488-479d-8012-8f71d6813d05\">Download<\/a><\/div>\n\n\n\n<div style=\"height:20px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<h3 class=\"wp-block-heading\">Policy Briefing<\/h3>\n\n\n\n<p><strong>Overview:<\/strong> This briefing doc summarizes the key themes and important facts outlined in the &#8220;ArtSciLab Cyber Security Policy&#8221; document, version Spring 2025.<\/p>\n\n\n\n<p><strong>Purpose:<\/strong> The policy aims to inform all lab users (faculty, staff, students, visiting researchers, etc.) about their responsibilities in protecting lab technology and information assets. It outlines acceptable use policies, internet access rules, and procedures for handling security incidents.<\/p>\n\n\n\n<p><strong>Key Themes<\/strong><\/p>\n\n\n\n<p>1. <strong>Asset Protection:<\/strong> The policy prioritizes the protection of lab assets, including:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Hardware: Computers, servers, printers, etc.<\/li>\n\n\n\n<li>Software: Operating systems, applications, databases, etc.<\/li>\n\n\n\n<li>Information: Classified as confidential or non-confidential.<\/li>\n<\/ul>\n\n\n\n<div style=\"height:8px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<p>2. <strong>Threat Identification:<\/strong> The policy acknowledges various threats:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Internal<strong>:<\/strong> Lab members potentially cause damage through negligence or malicious intent.<\/li>\n\n\n\n<li><em>&#8220;One of the biggest security threats is system users. They may damage lab systems either through incompetence or on purpose.&#8221;<\/em><\/li>\n\n\n\n<li>External<strong>:<\/strong> Amateur hackers, criminal hackers, and nation-state actors exploiting vulnerabilities.<\/li>\n<\/ul>\n\n\n\n<div style=\"height:8px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<p>3. <strong>Layered Security Approach:<\/strong> The policy advocates a multi-layered security strategy:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Access Control: Unique user IDs and passwords, 2FA, special access accounts with limited privileges, and physical access control through key cards.<\/li>\n\n\n\n<li>Network Security: Firewalls, intrusion detection systems, secure remote access via VPN.<\/li>\n\n\n\n<li>Vulnerability Management: Regular patching of devices and software, penetration testing, and vulnerability scanning.<\/li>\n\n\n\n<li>User Training<strong>:<\/strong> Mandatory cybersecurity awareness training for all lab users, including visiting researchers.<\/li>\n<\/ul>\n\n\n\n<div style=\"height:8px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<p>4. <strong>Acceptable Use:<\/strong> The policy clearly defines acceptable use of lab resources:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Business Use Only<strong>:<\/strong> Personal use of lab computer systems is prohibited.<\/li>\n\n\n\n<li><em>&#8220;User accounts on lab computer systems are to be used only for business in the lab and not to be used for personal activities.&#8221;<\/em><\/li>\n\n\n\n<li>Internet Usage<strong>:<\/strong> Permitted for research purposes only, with restrictions on inappropriate content.<\/li>\n\n\n\n<li>TikTok Ban<strong>:<\/strong> According to Texas state government orders, TikTok is prohibited on all lab devices and devices connected to the UTD network.<\/li>\n<\/ul>\n\n\n\n<div style=\"height:8px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<p>5. <strong>Incident Handling:<\/strong> Clear procedures are outlined for reporting and handling security incidents:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Immediate Reporting: Lab members must immediately report suspected incidents to the security administrator.<\/li>\n\n\n\n<li>Preservation of Evidence: Affected computers must be left untouched to assist with investigations.<\/li>\n<\/ul>\n\n\n\n<div style=\"height:10px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<p><strong>Important Facts<\/strong><\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Information classification is based on confidentiality levels (Red, Green, White, Black) and determines access privileges.<\/li>\n\n\n\n<li>Passwords must adhere to complexity requirements and be changed every 365 days.<\/li>\n\n\n\n<li>User activity, including internet usage and email communication, can and may be monitored by the lab.<\/li>\n\n\n\n<li>Violation of the security policy can lead to disciplinary actions, including dismissal.<\/li>\n<\/ul>\n\n\n\n<div style=\"height:10px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<p><strong>Quotes<\/strong><\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><em>&#8220;The lab has the right and capability to monitor electronic information created and\/or communicated by persons using lab computer systems and networks, including e-mail messages and usage of the Internet.&#8221;<\/em><\/li>\n\n\n\n<li><em>&#8220;Lab members, who believe their terminal or computer systems have been subjected to a security incident, or have otherwise been improperly accessed or used, should report the situation to the lab\u2019s security administrator immediately.&#8221;<\/em><\/li>\n<\/ul>\n\n\n\n<div style=\"height:10px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<p><strong>Conclusion:<\/strong> The ArtSciLab Cyber Security Policy provides a comprehensive framework for protecting lab assets and mitigating cybersecurity threats. Its emphasis on user education, access control, and incident response procedures highlights a proactive approach to ensuring a secure research environment.<\/p>\n\n\n\n<div style=\"height:10px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<h3 class=\"wp-block-heading\">FAQs<\/h3>\n\n\n\n<p><strong>1. What information is considered confidential in ArtSciLab?<\/strong><\/p>\n\n\n\n<p>Confidential information in ArtSciLab is any data that cannot be disclosed to individuals outside the lab. This includes information stored on computer systems, databases, and other digital platforms. Access to confidential information within the lab is granted on a need-to-know basis, as determined by the lab director. Examples of confidential data include research data, personal information of lab members, and sensitive project details.<\/p>\n\n\n\n<p><strong>2. What are the different classifications of computer systems in ArtSciLab, and what do they signify?<\/strong><\/p>\n\n\n\n<p>ArtSciLab uses a color-coded system to classify its computer systems based on the level of security required:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>RED<strong>:<\/strong> Systems containing confidential information and providing mission-critical services vital to lab operations. Access is strictly controlled, and failure of these systems could have severe consequences. Example: Server containing research data and financial information.<\/li>\n\n\n\n<li>GREEN<strong>:<\/strong> Systems that do not contain confidential information but can be used to access RED systems. These systems require a moderate level of security. Example: Staff workstations used to access research databases.<\/li>\n\n\n\n<li>WHITE<strong>:<\/strong> Isolated systems that are not externally accessible and do not contain sensitive information. These systems are used for specific purposes like software testing. Example: A standalone system for developing new software applications.<\/li>\n\n\n\n<li>BLACK<strong>:<\/strong> Externally accessible systems that are isolated from RED and GREEN systems by a firewall. These systems do not contain confidential information but may provide important services. Example: A public web server hosting non-sensitive lab information.<\/li>\n<\/ul>\n\n\n\n<div style=\"height:10px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<p><strong>3. What are the responsibilities of ArtSciLab users regarding the use of lab computers and the internet?<\/strong><\/p>\n\n\n\n<p>ArtSciLab users must adhere to the Acceptable Use Policy, which outlines responsible use of lab resources. Key responsibilities include:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Using lab computers and the internet for business purposes only, avoiding personal activities.<\/li>\n\n\n\n<li>Protecting confidential information accessed or stored on their accounts, including passwords.<\/li>\n\n\n\n<li>Refraining from activities that could harm the system or other users, such as harassment or unauthorized access attempts.<\/li>\n\n\n\n<li>Reporting any security weaknesses or policy violations to their supervisor or the security administrator.<\/li>\n\n\n\n<li>Using the internet for research-related purposes only, avoiding inappropriate or illegal content.<\/li>\n\n\n\n<li>Adhering to the ban on TikTok usage on all lab devices and networks, as per the Texas Governor&#8217;s order.<\/li>\n<\/ul>\n\n\n\n<div style=\"height:10px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<p><strong>4. What are the password requirements for ArtSciLab user accounts?<\/strong><\/p>\n\n\n\n<p>To maintain security, users must follow these password guidelines:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Passwords should not be dictionary words or common phrases.<\/li>\n\n\n\n<li>Passwords must not be written down or stored insecurely.<\/li>\n\n\n\n<li>Passwords must be changed every 365 days (1 year).<\/li>\n\n\n\n<li>Two-factor authentication (2FA), such as the Duo Authentication app, must be used in conjunction with passwords.<\/li>\n<\/ul>\n\n\n\n<div style=\"height:10px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<p><strong>5. What is the procedure for reporting security incidents in ArtSciLab?<\/strong><\/p>\n\n\n\n<p>If a lab member suspects a security incident, such as unauthorized access or system compromise, they should immediately report it to the lab&#8217;s security administrator. It&#8217;s important NOT to turn off the computer or delete suspicious files, as this could hinder the investigation. Leaving the system in its current state helps identify the source of the problem and implement appropriate remediation measures.<\/p>\n\n\n\n<div style=\"height:10px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<p><strong>6. How does ArtSciLab handle security violations?<\/strong><\/p>\n\n\n\n<p>ArtSciLab takes security violations seriously. Depending on the nature and severity of the violation, disciplinary actions can range from mandatory cybersecurity training to termination. The lab director may also refer the incident to law enforcement agencies for potential criminal charges.<\/p>\n\n\n\n<div style=\"height:10px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<p><strong>7. What are the restrictions on connecting devices to the ArtSciLab network?<\/strong><\/p>\n\n\n\n<p>Only authorized devices, such as lab-owned computers and approved network infrastructure devices, are allowed to connect to the network. Users are prohibited from connecting personal computers, unauthorized storage devices (e.g., flash drives), or any devices that could compromise network security.<\/p>\n\n\n\n<div style=\"height:10px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<p><strong>8. What are the guidelines for remote access to the ArtSciLab network?<\/strong><\/p>\n\n\n\n<p>Remote access to the lab network is permitted only for authorized individuals with a legitimate need. Acceptable methods for remote connection include secure VPN or SSH. Users are prohibited from installing personal remote control software, as this bypasses the lab&#8217;s secure access methods and poses a significant security risk.<\/p>\n\n\n\n<p><span style=\"font-size: 13px;\" class=\"editor-bridge-has-font-size\"><em><strong>A<\/strong><\/em><\/span><em><span style=\"font-size: 13px;\" class=\"editor-bridge-has-font-size\"><strong>I Use Policy: GenAI was used to generate this blog article (audio + text).<\/strong><\/span><\/em><\/p>\n\n\n\n<p><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Author: Collins Mwange, Dec 24, 2024 Audio Deep Dive Policy Overview ArtSciLab&#8217;s cybersecurity policy manual outlines procedures for protecting lab technology and information assets. It details classifications for information and computer systems, specifying access levels and user responsibilities. The policy addresses various security threats, including&#8230;<\/p>\n","protected":false},"author":1,"featured_media":1549,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"content-type":"","_monsterinsights_skip_tracking":false,"footnotes":""},"categories":[8],"tags":[],"class_list":["post-1169","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-blog"],"_links":{"self":[{"href":"https:\/\/creativedisturbance.org\/index.php\/wp-json\/wp\/v2\/posts\/1169","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/creativedisturbance.org\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/creativedisturbance.org\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/creativedisturbance.org\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/creativedisturbance.org\/index.php\/wp-json\/wp\/v2\/comments?post=1169"}],"version-history":[{"count":13,"href":"https:\/\/creativedisturbance.org\/index.php\/wp-json\/wp\/v2\/posts\/1169\/revisions"}],"predecessor-version":[{"id":1630,"href":"https:\/\/creativedisturbance.org\/index.php\/wp-json\/wp\/v2\/posts\/1169\/revisions\/1630"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/creativedisturbance.org\/index.php\/wp-json\/wp\/v2\/media\/1549"}],"wp:attachment":[{"href":"https:\/\/creativedisturbance.org\/index.php\/wp-json\/wp\/v2\/media?parent=1169"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/creativedisturbance.org\/index.php\/wp-json\/wp\/v2\/categories?post=1169"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/creativedisturbance.org\/index.php\/wp-json\/wp\/v2\/tags?post=1169"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}