4124 IT Security Procedure

Procedure

Policy Name: IT Security

Policy Number:  4124

Applicable Code/Law: 

1 Purpose

This procedure defines the steps required to implement and maintain compliance with the Information Technology (IT) Security Policy, ensuring the protection of Shoreline College owned or managed IT resources. Shoreline College will provide secure information technology resources consistent with its mission and goals in support of the college’s instructional and administrative activities.

2 Scope

This procedure applies to all employees, students, contractors, and third-party users who have access to Shoreline College 's IT systems, data, and networks.

3 Responsibilities

  • Technology Support Services (TSS): 
    • Develop and maintain appropriate and necessary policies and procedures to provide security & data privacy-related controls addressing statutory, regulatory and contractual obligations, as well as addressing potential threats to data and or assets.  
    • Maintain and monitor security controls and respond to security incidents. 
    • Conduct regular audits and vulnerability assessments. As needed, revise processes to address necessary changes and evolving conditions, and communicate the changes to key personnel.
    • Provide cybersecurity training and awareness programs. 
    • Employees & Students: 
      • Follow established and approved security policies and procedures. 
      • Report any security incidents or suspicious activities. 
      • Complete, as required, any assigned security training and awareness programs.  
    • Third Party Users: 
      • Comply with Shoreline College's security policies and procedures. 
      • Ensure their systems and practices meet Shoreline College's security standards 

4 Procedures

  1. Documentation
    Shoreline College will develop, maintain, and follow information security guidelines and procedures as appropriate to the college and consistent with the intent of information security standards and best practices in accordance with WaTech IT Security Program Policy. Applicable security guidelines and procedures will be reviewed annually as well as prior to and after any significant change to applications, processes, procedures, or infrastructure is proposed or implemented.
  2. Account Access Controls
    1. General Access: Technology Support Services (TSS) will use industry-recognized secure practices to enable the implementation of appropriate physical, administrative and technical controls are sufficient for implementing and managing a formal user access provisioning process to assign and/or revoke access rights for all user types to all systems by: 
      1. Provisioning account access (e.g., employees, students, contractors, business partners, service providers, and/or supplier relationships) to data and organizationally owned or managed (physical and virtual) applications, infrastructure systems, and network components is authorized by Shoreline management prior to access being granted;  
      2. Timely de-provisioning (revocation or modification) of account access to data and college owned or managed applications, infrastructure systems, and network components. Access revocation is implemented per established procedures and based on account change in status (e.g., termination of employment or other business relationship, job change, or transfer). 
      3. Authentication, Authorization, and Accounting (AAA) controls (e.g., strong/multifactor, expirable, non-shared authentication secrets) adhere to industry-accepted requirements; 
      4. Credential lifecycle management is accounted for from instantiation through revocation; and 
      5. Where technically feasible, secure identity trust verification is utilized through service-to-service application (e.g., APIs) and information processing interoperability (e.g., SSO and Federation).  
    2. Unique Accounts: Implement appropriate administrative and technical means to assign all users a unique identification (ID) before allowing them to access systems. 
    3. Change of Roles and Duties: Upon change or roles and duties, the account’s privileges and access controls are reviewed and updated to reflect the new role responsibilities. Appropriate actions will be taken to secure any privileged account access based on role responsibility change.  
    4. Termination of Access
      1. Employee: Upon termination of employment, the following actions will take place as soon as possible, but no longer than 24 hours: 
        1. The user’s privileges and access is revoked;
        2. The user’s password is changed or the account(s) disabled to preclude access; 
        3. All shared or privileged account passwords known by the user on all applicable systems are changed; 
        4. If necessary, incoming mail for the user is redirected as requested by the user’s supervisor and approved by the HR department; 
        5. If necessary, all files owned by the user are identified and ownership changed to the supervisor or a valid designee; and 
        6. All Shoreline property is collected, or accounted for. 
      2. Service Accounts: Service accounts are to be deactivated immediately upon the end of the contracted period as specified, or upon contract termination for any reason. Service accounts will be evaluated annually to verify ongoing usage. 
    5. Role Based Access: TSS utilizes Role Based Access Control (RBAC) to restrict access to sensitive data and to support separation of duties that are based on the least privileges necessary for the operability of system(s), application(s) and/or processes: 
      1. Ensure prior approval by authorized Shoreline personnel in management roles, who are knowledgeable about the position’s access requirements and responsibilities to ensure appropriate security controls are administered. 
    6. Password-Based Authentication: TSS implements password-based authentication requirements, in accordance with Shoreline policies and standards. 
      1. Password Length: 
        1. Minimum of twelve (12) characters 
      2. Password Reuse:  
        1. Users cannot reuse the same as any of the last twenty-four (24) passwords/passphrases used; 
      3. Password Life: 
        1. Maximum: At least once every one-hundred eighty (180) days; and 
        2. Minimum: one (1) day;  
      4. Password Complexity:  
        1. Passwords are not a derivative of the user ID. 
        2. Passwords have at least one (1) lower alpha, one (1) upper alpha, one (1) number and one (1) special character. 
      5. Prohibited password practices:  
        1. Do not use default vendor passwords; 
        2. Do not reveal a password over the phone to anyone for any reason; 
        3. Do not reveal a password in an e-mail message; 
        4. Do not reveal a password to a co-worker or supervisor; 
        5. Do not talk about a password in front of others; 
        6. Do not hint at the format of a password (e.g., "my family name"); 
        7. Do not reveal a password on questionnaires or security forms; 
        8. Do not share a password with family members; 
        9. Do not write passwords down and store them anywhere in the user’s office; and 
        10. Do not store passwords in a file on any information asset without encryption. 
      6. Compromise: 
        1. If an account or password is suspected to have been compromised, it should be reported to TSS immediately. All passwords, multifactor authentication methods or access tokens/keys are revoked and required to be changed immediately.  
    7. Account Management: TSS ensures proper identification and authentication management for all accounts used on college owned or managed systems by:  
      1. Proactively monitoring system accounts usage;  
      2. Disabling system accounts when:
        1. The accounts have expired; 
        2. The accounts are no longer associated with a user or individual;  
        3. The accounts violate organizational policy;  
        4. Significant risks have been discovered with an individual or individuals.  
      3. Identifying: 
        1. Authorized users;  
        2. Processes acting on behalf of authorized users; and 
        3. Devices (and other systems) authorized to connect to the system.  
      4. Limit system access to: 
        1. Authorized users;  
        2. Processes acting on behalf of authorized users; and 
        3. authorized devices (including other systems).  
      5. Controlling the addition, deletion and modification of user IDs, credentials and other identifier objects to ensure authorized use is maintained; 
      6. Verifying user identity before issuing initial passwords or performing password resets; 
      7. Setting passwords for first-time use and resets to a unique value for each user and change immediately after the first use; 
      8. Immediately revoking access for any terminated users; 
      9. Limiting repeated access attempts by locking out the user ID after not more than ten (10) attempts; 
      10. Automatically terminating access for temporary and emergency accounts after the accounts are no longer needed; 
      11. Minimizing the use of group, shared or generic accounts and passwords; 
      12. Disabling or removing default user IDs and accounts; 
      13. Forcing service providers with remote access to Shoreline’s systems (e.g., for support of sensitive systems or servers) to use a unique authentication credential (such as a password/phrase) for each customer; and 
      14. Uses industry-recognized secure practices to permit the use of shared / group accounts.  
    8. Directory Services: TSS enables the implementation of appropriate physical, administrative and technical mechanisms to configure automated mechanisms to: 
      1. Configure access for all accounts through a centralized point of authentication; 
      2. Automatically alert appropriate personnel for security-related changes in privileged account status; 
      3. Use the information system to monitor account usage; and 
      4. Report atypical system account usage. 
    9. Least Privilege: TSS implements the “principle of least privilege,” which states that only the minimum access necessary to perform an operation should be granted. 
      1. Grant access only for the minimum:  
        1. Levels of permissions necessary to perform the job function; and
        2. Time required.
    10. Review: Access controls are reviewed annually through the Account Verification process, when new systems are introduced, or when changes are made to an existing computing environment. Whenever the process is updated, changes and updates are to be communicated to key personnel. 
  3. Asset Management 
  • Asset Governance: TSS maintains current inventories of Shoreline’s technology assets that includes, but is not limited to: 
    • A list of all such devices and personnel with access; 
    • A method to accurately and readily determine owner, contact information, and purpose (e.g., labeling, coding, and/or inventorying of devices); and  
    • A list of company-approved products. 
  • Updates During Installations/Removals: TSS updates the system inventory after component installations, removals, and system updates. 
  • Component Duplication Avoidance: On at least an annual basis, TSS reviews in-scope assets and verifies that system components are not duplicated in other asset inventories. 
  • Approved Baseline Deviations: Any request for a deviation from Shoreline’s standardized baseline security configuration must be evaluated and approved by TSS. 
  • Asset Ownership Assignment: TSS ensures property accountability through:  
    • All persons entrusted with Shoreline College property are made responsible for its proper use, care, custody, safekeeping and disposition; 
    • Persons will not be assigned to a role(s) that will prevent them from exercising proper care and custody for the property for which they are responsible; 
    • When a person assumes responsibility for property that is remotely located, records must be maintained to show the persons charged with its care and safekeeping; 
    • Shoreline property will not be used for any private purpose except as authorized by TSS in alignment with any applicable local or state policy; 
    • No Shoreline property will be sold, given as a gift, loaned, exchanged or otherwise disposed of; and 
    • Property documents shall at a minimum identify the manufacturer’s make, model and serial number.  
  • Secure Disposal, Destruction, or Re-use of Equipment: TSS ensures the implementation of appropriate physical, administrative and technical mechanisms to securely dispose of, destroy or repurpose system components to prevent information being recovered from these components upon decommissioning. 
  • Return of Assets: TSS ensures the direct manager of a terminated user has an accurate inventory to account for all Shoreline-issued assets, prior to the individual’s departure.  
  • Review: Asset management processes are reviewed annually, when new systems are introduced, or when changes are made to an existing computing environment. Whenever the process is updated, changes and updates are to be communicated to key personnel.

4 Network Security 

  • General Network Security: TSS ensures controls are sufficient for protecting communications and networks, including: 
    • Administrative controls that govern changes to the environment;
    • Technical controls that provide a defense-in-depth approach; and 
    • Service Level Agreements, whether these services are provided in-house or outsourced to trusted third-parties. 
  • Layered Defenses: TSS establishes and maintains physical, administrative, and technical controls to ensure cybersecurity tools and support components are isolated from other internal or external information systems using physically separate subnetworks. 
  • Boundary Protection: TSS uses external system connections through managed interfaces consisting of boundary protection devices arranged in accordance with industry best practices. 
  • Network Intrusion Detection & Prevention Systems: TSS enables the implementation of appropriate physical, administrative and technical mechanisms to employ Network Intrusion Detection Systems (NIDS) and/or Intrusion Prevention Systems (NIPS) to:  
    • Prevent intrusions into the network; 
    • Monitor all traffic at the perimeter of the network, as well as at critical points in the network;  
    • Alert personnel to suspected compromises within the network; and 
    • Keep all intrusion-detection and prevention engines, baselines and signatures up-to-date. 
  • Session integrity: TSS ensures integrity is maintained for session authenticity to specifically protect against:  
    • Man-In-The-Middle (MITM) attacks; 
    • Session hijacking; and 
    • The insertion of false information into sessions. 
  • Domain Name Service (DNS) Resolution: TSS implements Domain Name Service (DNS) services, in accordance with industry best practices and standards through: 
    • Using trusted sources for authoritative DNS queries to prevent DNS spoofing attacks for both IPv4 and IPv6 protocols: 
    • IPv4: The Verisign Public DNS IP addresses (IPv4) are as follows: 
      • 64.6.64.6; and 
      • 64.6.65.6  
    • IPV6: The Verisign DNS IPv6 addresses are as follows: 
      • 2620:74:1b::1:1; and 
      • 2620:74:1c::2:2  
    • Enabling DNS query logging to detect hostname lookup for known malicious Command & Control (C2) domains. 
  • Electronic Messaging: TSS establishes the usage restrictions and implementation guidance for the following communications technologies based on the potential to cause damage to systems, if used maliciously: 
    • Electronic Mail (email); 
    • Instant Messaging (IM); 
    • Short Message Service (SMS); 
    • Voice Over Internet Protocol (VOIP); 
    • Analog Lines (Plain Old Telephone Service (POTS); and 
    • Facsimile (Fax) Machines (analog & digital). 
  • Remote Access: Shoreline College defines authorized methods of remote access as:  
    • Authorized methods include:  
      • Virtual Private Network (VPN); 
      • Virtual Desktop Infrastructure (VDI); and 
      • Remote Monitoring and Management (RMM) tools; and 
    • Prohibited methods include, but are not limited to: 
      • Direct access (e.g., Remote Desktop Connection); 
    • TSS implements remote access, in accordance with Shoreline College’s policies and procedures, as follows: 
      • Document allowed methods of remote access to the system;
      • Establish usage restrictions and implementation guidance for each allowed remote access method;  
      • Monitor for unauthorized remote access to systems; 
      • Authorize remote access to systems prior to connection;  
      • Enforce requirements for remote connections to systems; 
      • Use cryptography to protect the confidentiality and integrity of remote access sessions; 
      • Automatically sign out remote access sessions after no more than twenty (20) minutes of inactivity; and 
      • Immediately deactivate vendor and business partner remote access when it is no longer needed. 
  • Wireless Networking: TSS configures wireless networks to: 
    • Authorize access prior to allowing connections; and 
    • Implement strong encryption for authentication and transmission, commensurate with the sensitivity of the data being transmitted.  
    • Establish usage restrictions and implementation guidance for wireless access. 
    • Monitor for unauthorized wireless access to the system. 
    • Enforce requirements for wireless connections to systems. 
  • DNS and Content Filtering: TSS enables the implementation of appropriate technical mechanisms to configure systems to route all HTTP (port 80) and HTTPS (port 443) traffic through designated DNS and/or content filtering technology.  
  • Network Maintenance: TSS utilizes regularly scheduled maintenance windows during off hours to install updates, patches, and reboot devices when necessary. This may cause intermitted downtime and will be communicated with the campus prior to taking place. Other necessary emergency maintenance activities may still be required. 
  • Review: Network security processes are reviewed annually, when new systems are introduced, or when changes are made to an existing computing environment. Whenever the process is updated, changes and updates are to be communicated to key personnel.   

5 Endpoint Security 

  •  General Security: TSS enables the implementation of appropriate physical, administrative and technical mechanisms to ensure controls are sufficient to protect End User Computing (EUC) assets against potential threats, based on current organizational risk and threat assessments. 
  • Endpoint Protection Measures: TSS implements the principle of “least functionality,” which is utilized where the minimum functionality is implemented on an asset through:  
    • Identifying and removing insecure services, protocols, and ports; 
    • Enabling only necessary and secure services, protocols, and daemons, as required for the function of the system; 
    • Implementing security features for any required services, protocols or daemons that are considered to be insecure (e.g., NetBIOS, Telnet, FTP, etc.); 
    • Verifying services, protocols, and ports are documented and properly implemented by examining firewall and router configuration settings; and 
    • Removing all unnecessary functionality, such as: 
      • Scripts; 
      • Drivers; 
      • Feature; 
      • Subsystems; 
      • File systems; and  
      • Unnecessary web servers. 
    • Configure antimalware and firewall software configurations to:
      • Not be alterable by standard users; and
      • Include “always on” protection. 
    • Use industry-recognized secure practices to ensure mechanisms protect sensitive information at rest and require a secondary authentication mechanism, not integrated into the operating system, in order to access the information by: 
      • Employing cryptographic mechanisms to prevent unauthorized disclosure and modification of information at rest unless otherwise protected by alternative physical measures.  
  • Prohibit Installation without Privileged Status: TSS restricts software installation permissions to authorized system administrators. 
  • Malicious Code Protection: TSS deploys Shoreline College-approved antimalware software on all systems capable of running antimalware software. For systems not capable of running supported antimalware software, justification for this system usage will be documented along with what compensating controls are in place to minimize the risk associated with the lack of antimalware software on that system.  
  • Automatic Signature Updates: TSS ensures antimalware mechanisms (e.g., antimalware software): 
    • Automatically update signature files to keep current the latest version from the antimalware vendor; and 
    • Actively run on systems the antimalware software is deployed to. 
  • Centralized Management: TSS implements appropriate technology for centrallymanaging host-based, malicious code protection mechanisms. 
  • Always On Protection: TSS deploys appropriate physical, administrative and technical configurations to ensure antimalware mechanisms: 
    • Actively run on systems (e.g., “always on protection) to perform real-time scans of files from external sources at endpoints or system entry and exit points as the files are downloaded, opened, or executed; and
    • Cannot be disabled or altered by users, unless specifically authorized by management on a case-by-case basis for a limited time period. 
  • Review: Endpoint security processes are reviewed annually, when new systems are introduced, or when changes are made to an existing computing environment. Whenever the process is updated, changes and updates are to be communicated to key personnel. 

6 Cloud Security 

  • Cloud Services: TSS maintains a comprehensive list of those service providers, including all applicable Service Level Agreements (SLAs). 
    • Require that providers of external systems comply with Shoreline cybersecurity requirements and employ appropriate security controls in accordance with local, state and Federal laws, as well as all applicable regulatory and contractual requirements (e.g., PCI DSS). 
    • Define oversight responsibilities regarding external system services. 
    • Perform a review of the service provided for acceptable service levels. 
    • Conduct a risk assessment outsourcing of services. 
    • Monitor security control compliance by those external service providers. 
  • Cloud Security Architecture: TSS designs, configures and implements cloud-based applications, infrastructure and system-to-system interfaces (e.g., APIs) in accordance with mutually agreed-upon service, security and capacity-level expectations from both enterprise technology and security architects. 
  • Review: Cloud security processes are reviewed annually, when new systems are introduced, or when changes are made to an existing computing environment. Whenever the process is updated, changes and updates are to be communicated to key personnel.   

7 Data Classification and Handling 

  • Data Classification Levels: Data is classified in 4 categories: Category 1 – Public information; Category 2 – Sensitive information; Category 3 – Confidential information; Category 4 – Confidential information requiring special handling 
  • Data Handling Requirements: All data will be handled appropriately according to the WaTech Data Classification Standards 
  • Review: Data Classification processes are reviewed annually, when new systems are introduced, or when changes are made to an existing computing environment. Whenever the process is updated, changes and updates are to be communicated to key personnel.   

8 Incident Response 

  •  Incident Reporting: All actual or suspected cybersecurity incidents are to be reported by: 
    • Requiring users to report system weaknesses, deficiencies, and/or vulnerabilities through appropriate management channels to the TSS department without delay; and 
    • Involving management and the TSS department in suspected cybersecurity events as quickly as possible.  
  • Incident Handling: TSS will leverage available Shoreline College systems and services to: 
    • Log, investigate, and escalate incidents accordingly per severity and classification of incidents as determined by the Executive Director of Technology Support Service or designated TSS Systems Administrator; 
    • Respond with appropriate remediation actions to minimize impact and ensure the continuation of business functions; and 
    • Ensure sufficient and timely communication to appropriate stakeholders including administrators and users of affected systems, managers of affected users, and where appropriate E-Team members, and the College President.  
  • Root Cause Analysis & Lessons Learned: TSS will implement appropriate administrative means to ensure every incident concludes by: 
    • Performing a Root Cause Analysis following events classifying as a cybersecurity incident;  
    • Incorporating lessons learned to update current processes and practices; and 
    • Documenting the event with a TSS Incident Report in the support system.  
  • Review: Incident Response processes are reviewed annually, when new systems are introduced, or when changes are made to an existing computing environment. Whenever the process is updated, changes and updates are to be communicated to key personnel.  

9 Training and Awareness 

  • Cybersecurity & Data Privacy-Minded Workforce: The College will document the knowledge, skills, and abilities required for personnel performing work affecting Cybersecurity and ensure that personnel assigned IT Security responsibilities are competent to perform the required tasks.  
  • Cybersecurity & Data Privacy Awareness Employee Training: New employees will receive training within the first 30 days of employment on security awareness that identifies the risks of data compromise, their role in prevention, and how to respond in the event of an incident as relevant to the individual’s job function. Thereafter, all employees will receive security awareness training on an annual basis. 
  • Cybersecurity & Data Privacy Awareness Student Training: Students will receive security awareness training during orientation. 
  • Review: Training and Awareness processes are reviewed annually, when new systems are introduced, or when changes are made to an existing computing environment. Whenever the process is updated, changes and updates are to be communicated to key personnel. 

10 Compliance 

  • Internal Compliance Audits: Regular audits are conducted by TSS to ensure adherence to state and federal regulations. 
  • Compliance Scope: Shoreline College will require that contractors comply with Office of the Chief Information Officer (OCIO) and College IT security standards relative to the services provided. 
  • Independent Compliance Audits: An independent audit will be performed every three years to assess compliance with OCIO IT security standards. The College will ensure the audit is performed by qualified parties independent of Shoreline College and submit the results of the audit to the state Chief Information Security Officer. 

Approvals 

Reviewed and Approved by Executive Team: 07/21/2026