User Tools

Site Tools


policies:security:access

Differences

This shows you the differences between two versions of the page.

Link to this comparison view

Both sides previous revisionPrevious revision
Next revision
Previous revision
policies:security:access [2018/01/05 13:32] – [25. Secure login] deulpolicies:security:access [2018/01/12 10:42] (current) – [26. User security policy] deul
Line 4: Line 4:
 New users are either students or institute members. Their enrolment in the courses or their appointment as member of the institute is regulated elsewhere. Once this has taken place, personal information of these persons are entered into the Person database by the institute secretariat. Once this is done system management can use a WEB forms system to generate an account. New users are either students or institute members. Their enrolment in the courses or their appointment as member of the institute is regulated elsewhere. Once this has taken place, personal information of these persons are entered into the Person database by the institute secretariat. Once this is done system management can use a WEB forms system to generate an account.
  
-Detail of [[:new|starting]] and [[:depart|ending]] the membership at the institute can be found here.+Detail of [[:strw:new|starting]] and [[:strw:depart|ending]] the membership at the institute can be found here.
 ====21. External user access computerroom==== ====21. External user access computerroom====
 No one is allowed to access the computer server room without a IT Department person accompanying.  No one is allowed to access the computer server room without a IT Department person accompanying. 
Line 15: Line 15:
  
 ====24. Password requirements==== ====24. Password requirements====
-Passwords are not freely formatted, there are [[:observatory_account_policy|restrictions in place]].+Passwords are not freely formatted, there are [[:strw:observatory_account_policy|restrictions in place]].
  
 ====25. Secure login==== ====25. Secure login====
Line 21: Line 21:
  
 ====26. User security policy==== ====26. User security policy====
 +Users have been [[:strw:observatory_account_policy|instructed]] to handle password information with care.
 +
 +All Linux and Windows systems have an automatic 'screen lock' enabled initiated after a period of in-activity.
  
 ====27. Network usage policy==== ====27. Network usage policy====
 +Wired network access is granted on the basis of membership of an associated institute as described in the account policy. Once connected to the wired network, access to system assets is controlled by user authorization and authentication. Authorization is governed by the status of the membership. Students and postdocs have supervisors granting the access restrictions. Postdoc usually acquire their on devices, while staff member are granted general access.
 ====28. BYOD==== ====28. BYOD====
 +External machines, not acquired through university funding or not maintained by system admin, can only obtain access to the wireless network to which [[:generic:wireless|general restrictions]] are applied.
 ====29. Remote access critical applications==== ====29. Remote access critical applications====
 +Only system managers require remote access to critical applications. Critical applications are not accessible from selected devices inside the IT Department infrastructure. System managers both need to authenticate  to these devices and to the critical application for being granted access.
  
 ====30. Mobile equipment and concern data==== ====30. Mobile equipment and concern data====
 +There are no mobile devices storing concern information.
policies/security/access.1515159179.txt.gz · Last modified: 2018/01/05 13:32 by deul