POLICY:
All desktop computers shall be configured to have a password-enabled screen saver. This security-lockout feature shall automatically initiate after the desktop computer remains idle from user interaction after a predefined time period. The user must then reenter their password to gain access to the computer. This time period shall be published as part of the Campus's IT standards.
PURPOSE:
Desktop computers are the entry point into the Campus's Enterprise systems. The Enterprise systems provide the individual with access to both private and confidential information in addition to the data located on the computer's hard drive. A password-enabled screen saver helps to protect the information displayed on your screen, stored on your computer's hard drive, and the information that is accessible from your computer when you walk away from the desktop computer.
PROCEDURES:
- 1. Users are encouraged to explicitly lock their desktop computer prior to leaving the computer unattended.
- 2. The time period in which the security lockout feature is initiated shall be posted on the Technology Support Advisory Group (TSAG) website (http://www.csun.edu/tsag/standards).
- 3. The Chief Information Officer (or designee) may grant a larger time period in which that security lockout feature is initiated when sufficient security safeguards exist to protect the information accessible from the computer. Such safeguards include (but are not limited to):
- a. The computer is located within a secure environment
- b. The computer is used exclusively by a single user
- Requests for a larger time period shall be submitted via the University Helpdesk (helpdesk@csun.edu).
- 4. Local IT units may select an appropriate password-protected screen saver based upon local needs. E.g., a screen-saver with auto-logout capabilities can be configured for open laboratories.
RESPONSIBILITIES:
Users are responsible for taking steps to protect the information that is viewable on their computer screen, that is located on the computer's hard drive, and that is accessible from the computer. Users are also responsible to maintain and update their passwords on a regular basis to preserve the integrity of both confidentiality and personal data.
The Chief Information Officer (CIO) is responsible for ensuring that the time periods for the security lockout
feature are sufficient to meet prevailing standards for data integrity and for ensuring that these standards meet the needs
of the Campus.
When an exception is granted, IT/Middleware is responsible for making appropriate changes to the Enterprise Identity Management
system to enable desktop-level screen-saver controls. The local IT staff is responsible for updating the security protocols
on the desktop computer to match the approved time periods.
REFERENCES:
University Policy for Use of Computing Resources
Desktop Standards Policy
Campus Password Policy
FURTHER INFORMATION:
Chief Information Officer (hilary.baker@csun.edu)
Approved by the President
California State University, Northridge at 18111 Nordhoff Street, Northridge, CA 91330 / Phone: 818-677-1200 / © 2006 CSU Northridge
Last Updated: 4/19/2007