Skip to main content
BYU Logo_Blue.svg

WORKSTATION - OIT EMPLOYEES ADDENDUM

Type: Standard
Last Updated: December 27, 2023
Sponsor: Scott Hunt, Assistant Vice President, OIT
Owner: Ryan Amy, Computer Support Portfolio Director
Custodian: Mary Stevens, IT Governance, OIT
Version: 1.0

PURPOSE

This addendum adds to the IT Standards for Workstations. Its purpose is to ensure university-owned workstations deployed to Office of Information Technology (OIT) employees use actively patched and supported operating systems and software, are patched monthly, and run required endpoint protection software.

SCOPE

These standards apply to all OIT users of university workstations, including laptops. They extend to all university departments, employees, students, partners, consultants, and vendors utilizing university workstations.

POLICY BASIS

These standards support the Appropriate Use of Information Technology Resources Policy and the Data Use, Privacy, and Security Policy.

REQUIREMENTS

End-of-Life Operating Systems: Only install and use actively patched and supported vendor operating systems. Any operating system identified as End-of-Life must be upgraded. Major vendor operating systems include Microsoft Windows, Apple macOS, and Linux (Red Hat, Ubuntu) with the latest distribution or distribution marked Long-Term Support (LTS).

Operating System Patches: Patch vendor-supported operating systems monthly through the built-in, automatic update functionality of the operating system. If a university-approved endpoint management platform is being used, such as Microsoft Endpoint Manager (MEM), use it to patch monthly.

Workstation Software: All installed software must be patched monthly. If the software can no longer be patched or is End-of-Life, it must be removed or uninstalled. Configure updates to run automatically, if available.

Endpoint Protection Software: CrowdStrike Falcon is the required endpoint protection platform for BYU and CES. It protects and alerts on potential malicious computer activity within the organization. Falcon must be installed and running on all university-owned workstations. Do not disable or uninstall Falcon unless specifically directed by the CES Security Operations Center. If Falcon conflicts with other anti-virus software, remove the other anti-virus products. The Falcon client does not need to be installed on tablets and mobile devices.

Managed System Images: CSRs build images for OIT use cases. Laptops and desktops are built from those images so devices start on Day 1 with pre-deployed protections and controls.

Local Virtualization: Any operating system installs on university workstations should be built from a managed system image, including anything running as a virtual machine on the device.

Local Admin and Use of Software Center/Jamf: Local admin rights are a significant risk when an attacker gains access to a system. More work-related software should be in Software Center and local admin use should be eliminated or reduced for workstations wherever possible.

VDI (Citrix) as an Option: Not all use cases will be covered by the imaging effort. Workstation virtual machines hosted through a university provided solution such as Citrix may be used for those cases.

Linux: Endpoint management for Linux is not mature at Brigham Young University. Use of Linux for workstations needs a written justification describing the use case and pre-approval from line management. Linux endpoint management systems are being explored and should be in place for OIT by the end of 2027.

Harvesting Old Equipment: Sometimes employees keep devices just in case, often powered off in a desk or closet. Please do not increase risk by retaining these items. Surplus these items.

Remote Access to Devices: Remote access to devices should be done on a very limited basis, with one method for doing so.

Use of Personal Devices: Connecting to web-enabled services such as email and Box is OK. Logging into BYU servers by VPN or other means, or pulling code, containers, or similar work down to a personal device, is not OK.

COMPLIANCE & ENFORCEMENT

Operating systems that are no longer supported or are reaching End-of-Life must be removed or upgraded to a supported version. Software that can no longer be patched or is End-of-Life must be removed or uninstalled. Falcon must not be disabled or uninstalled unless specifically directed by the CES Security Operations Center.

The Appropriate Use of Information Technology Resources Policy states:
The university reserves the right, in its sole discretion and for any reason or no reason, to immediately revoke authorization to access or use any or all IT Resources.

STANDARDS OWNERSHIP & REVIEW

This standard is reviewed every year, or sooner if there is a major change in policy, regulations, or systems.

RELATED RESOURCES

IT Standards are developed by subject matter experts and approved by the Information Technology Committee, which consists of the CIO, the CISO, University Vice Presidents and other senior leaders.