{"id":1165,"date":"2026-08-04T12:52:29","date_gmt":"2026-08-04T17:52:29","guid":{"rendered":"https:\/\/it.rutgers.edu\/cybersecurity-compliance-program\/?page_id=1165"},"modified":"2026-08-04T13:39:14","modified_gmt":"2026-08-04T18:39:14","slug":"endpoint-security-standards-for-data-protection","status":"publish","type":"page","link":"https:\/\/it.rutgers.edu\/cybersecurity-compliance-program\/endpoint-security-standards-for-data-protection\/","title":{"rendered":"Endpoint security standards for data protection"},"content":{"rendered":"    <section class=\"cc--component-container cc--rich-text  rich-text\">\n\n<div class=\"c--component c--rich-text\">\n        <div class=\"inner-wrapper\">\n    \n    <div class=\"f--field f--rich-text \"><h2>Endpoint security standards for data protection<\/h2>\n<p>The purpose of the Rutgers Endpoint Security Standards is to provide the minimum information security standards necessary to comply with the <a href=\"https:\/\/policies.rutgers.edu\/B.aspx?BookId=12018&amp;PageId=459369\">Rutgers Information Classification Policy<\/a>. These standards are <strong>mandatory requirements<\/strong> and <strong>establish an effective baseline of appropriate system, administrative, and physical controls to apply to data and\/or the systems that process data based upon its classification<\/strong>.<\/p>\n<h4><strong>Scope<\/strong><\/h4>\n<p>This standard applies to all University data, including but not limited to: HIPAA\/PHI, student record data, personnel data, financial data (budget and payroll), student life data, departmental administrative data, police records and legal files, and all other data that pertains to, or supports the mission and\/or administration of the University or any of its functions.<\/p>\n<h4><strong>Classification levels<\/strong><\/h4>\n<p>The Information Classification Policy identifies four (4) categories of data: Critical, Restricted, Internal, and Public.\u00a0 For more information on these classification levels and the major responsibilities of the parties involved (i.e. Vice Presidents, Chancellors, Deans, Information Owners Data Custodians, Information Managers and Information Users) please\u00a0<a href=\"https:\/\/policies.rutgers.edu\/B.aspx?BookId=12018&amp;PageId=459369\"><strong>review the policy<\/strong><\/a>\u00a0(PDF).<\/p>\n<h4><strong>Standard<\/strong><\/h4>\n<p>The following security standards outline the minimum level of protection and controls that must be adhered to based on the information classification of the data.<\/p>\n<p>* <em>Endpoint Security Standards<\/em>, as it relates to the Palo Alto Perimeter Project, for the \u201cvpn-admin-internal\u201d zone.<\/p>\n<p><strong>Network<\/strong><\/p>\n<div id=\"footable_parent_1169\"\n         class=\" footable_parent ninja_table_wrapper loading_ninja_table wp_table_data_press_parent semantic_ui \">\n                <table data-ninja_table_instance=\"ninja_table_instance_0\" data-footable_id=\"1169\" data-filter-delay=\"1000\" aria-label=\"7-31-24 Network table (Risk Policy Compliance) - Sheet1.csv( Duplicate )\"            id=\"footable_1169\"\n           data-unique_identifier=\"ninja_table_unique_id_3110060212_1169\"\n           class=\" foo-table ninja_footable foo_table_1169 ninja_table_unique_id_3110060212_1169 ui table  nt_type_legacy_table selectable striped  footable-paging-right ninja_table_search_disabled ninja_table_pro\">\n                <colgroup>\n                            <col class=\"ninja_column_0 \">\n                            <col class=\"ninja_column_1 \">\n                            <col class=\"ninja_column_2 \">\n                            <col class=\"ninja_column_3 \">\n                            <col class=\"ninja_column_4 \">\n                    <\/colgroup>\n        <thead>\n<tr class=\"footable-header\">\n                                                                                        <th scope=\"col\"  class=\"ninja_column_0 ninja_clmn_nm_controlstandard \">Control Standard<\/th><th scope=\"col\"  class=\"ninja_column_1 ninja_clmn_nm_restricted \">Critical<\/th><th scope=\"col\"  class=\"ninja_column_2 ninja_clmn_nm_restricted1 \">Restricted<\/th><th scope=\"col\"  class=\"ninja_column_3 ninja_clmn_nm_internal \">*Internal<\/th><th scope=\"col\"  class=\"ninja_column_4 ninja_clmn_nm_public \">Public<\/th><\/tr>\n<\/thead>\n<tbody>\n\n        <tr data-row_id=\"4\" class=\"ninja_table_row_0 nt_row_id_4\">\n            <td>A network-based Firewall (or functional equivalent) shall be implemented that denies traffic from networks and hosts that are not secured at this level.<\/td><td>Required<\/td><td>Required<\/td><td>Recommended<\/td><td>Not Applicable<\/td>        <\/tr>\n            <tr data-row_id=\"5\" class=\"ninja_table_row_1 nt_row_id_5\">\n            <td>Network traffic shall be limited to only those services and ports considered essential for departmental business practices.<\/td><td>Required<\/td><td>Required<\/td><td>Recommended<\/td><td>Not Applicable<\/td>        <\/tr>\n            <tr data-row_id=\"6\" class=\"ninja_table_row_2 nt_row_id_6\">\n            <td>Networks and devices shall be scanned for vulnerabilities on a regular schedule. Those that contain Restricted data should be scanned more frequently. Vulnerabilities detected shall be remediated in a timely manner.<\/td><td>Required<\/td><td>Required<\/td><td>Recommended<\/td><td>Suggested<\/td>        <\/tr>\n            <tr data-row_id=\"7\" class=\"ninja_table_row_3 nt_row_id_7\">\n            <td>Security detection and prevention tools (Intrusion Prevention Systems) (IPS) and Endpoint Detection &#038; Response (EDR) shall be implemented.<\/td><td>Required<\/td><td>Required<\/td><td>Recommended<\/td><td>Suggested<\/td>        <\/tr>\n            <tr data-row_id=\"8\" class=\"ninja_table_row_4 nt_row_id_8\">\n            <td>Devices processing or storing data shall log all significant security event information. Logs should be reviewed on a daily basis (Monday-Friday) and retained according to its data classification and\/or regulatory mandates.<\/td><td>Required<\/td><td>Required<\/td><td>Recommended<\/td><td>Suggested<\/td>        <\/tr>\n    <\/tbody><!--ninja_tobody_rendering_done-->\n    <\/table>\n    \n    \n    \n<\/div>\n\n<p>&nbsp;<\/p>\n<p><strong>Servers<\/strong><\/p>\n<div id=\"footable_parent_1170\"\n         class=\" footable_parent ninja_table_wrapper loading_ninja_table wp_table_data_press_parent semantic_ui \">\n                <table data-ninja_table_instance=\"ninja_table_instance_1\" data-footable_id=\"1170\" data-filter-delay=\"1000\" aria-label=\"6-19-25 Servers table (Risk, Policy, Compliance) - Sheet1.csv( Duplicate )( Duplicate )\"            id=\"footable_1170\"\n           data-unique_identifier=\"ninja_table_unique_id_691222389_1170\"\n           class=\" foo-table ninja_footable foo_table_1170 ninja_table_unique_id_691222389_1170 ui table  nt_type_legacy_table selectable striped vertical_centered  footable-paging-right ninja_table_search_disabled ninja_table_pro\">\n                <colgroup>\n                            <col class=\"ninja_column_0 \">\n                            <col class=\"ninja_column_1 \">\n                            <col class=\"ninja_column_2 \">\n                            <col class=\"ninja_column_3 \">\n                            <col class=\"ninja_column_4 \">\n                    <\/colgroup>\n        <thead>\n<tr class=\"footable-header\">\n                                                                                        <th scope=\"col\"  class=\"ninja_column_0 ninja_clmn_nm_controlstandard \">Control Standard<\/th><th scope=\"col\"  class=\"ninja_column_1 ninja_clmn_nm_restricted \">Critical<\/th><th scope=\"col\"  class=\"ninja_column_2 ninja_clmn_nm_restricted1 \">Restricted<\/th><th scope=\"col\"  class=\"ninja_column_3 ninja_clmn_nm_internal \">Internal<\/th><th scope=\"col\"  class=\"ninja_column_4 ninja_clmn_nm_public \">Public<\/th><\/tr>\n<\/thead>\n<tbody>\n\n        <tr data-row_id=\"9\" class=\"ninja_table_row_0 nt_row_id_9\">\n            <td>Devices hosting Rutgers services, applications and restricted data (as defined by Policy 70.1.2) shall be housed in a physically secure location, accessible to only those with a business purpose.<\/td><td>Required<\/td><td>Required<\/td><td>Required<\/td><td>Recommended<\/td>        <\/tr>\n            <tr data-row_id=\"10\" class=\"ninja_table_row_1 nt_row_id_10\">\n            <td>Security updates and patches shall be applied as soon as practical, or automatically when possible.<\/td><td>Required<\/td><td>Required<\/td><td>Required<\/td><td>Recommended<\/td>        <\/tr>\n            <tr data-row_id=\"11\" class=\"ninja_table_row_2 nt_row_id_11\">\n            <td>Computer system support staff must monitor for announced vulnerabilities in their hardware and software.<\/td><td>Required<\/td><td>Required<\/td><td>Required<\/td><td>Recommended<\/td>        <\/tr>\n            <tr data-row_id=\"12\" class=\"ninja_table_row_3 nt_row_id_12\">\n            <td>Enable university-approved Endpoint Protection to guard against viruses, malware, and other cyber-threats.<\/td><td>Required<\/td><td>Required<\/td><td>Required<\/td><td>Recommended<\/td>        <\/tr>\n            <tr data-row_id=\"13\" class=\"ninja_table_row_4 nt_row_id_13\">\n            <td>Where available, a host-based firewall shall be implemented.<\/td><td>Required<\/td><td>Required<\/td><td>Recommended<\/td><td>Recommended<\/td>        <\/tr>\n            <tr data-row_id=\"14\" class=\"ninja_table_row_5 nt_row_id_14\">\n            <td>The principle of least privilege shall be applied when deploying services and applications.<\/td><td>Required<\/td><td>Required<\/td><td>Recommended<\/td><td>Recommended<\/td>        <\/tr>\n            <tr data-row_id=\"15\" class=\"ninja_table_row_6 nt_row_id_15\">\n            <td>Passwords shall be changed from the vendor defaults.  (Default credentials shall be prohibited)<\/td><td>Required<\/td><td>Required<\/td><td>Required<\/td><td>Recommended<\/td>        <\/tr>\n            <tr data-row_id=\"16\" class=\"ninja_table_row_7 nt_row_id_16\">\n            <td>Systems shall be configured to comply with industry standards. (e.g. Center for Internet Security (CIS) Workbench)<\/td><td>Required<\/td><td>Required<\/td><td>Recommended<\/td><td>Recommended<\/td>        <\/tr>\n            <tr data-row_id=\"17\" class=\"ninja_table_row_8 nt_row_id_17\">\n            <td>Individual access to data shall be limited to only those needing access for legitimate purposes.<\/td><td>Required<\/td><td>Required<\/td><td>Required<\/td><td>Not Applicable<\/td>        <\/tr>\n            <tr data-row_id=\"18\" class=\"ninja_table_row_9 nt_row_id_18\">\n            <td>The amount of restricted information collected and stored shall be the minimum amount required for the efficient and effective conduct of business functions.<\/td><td>Required<\/td><td>Required<\/td><td>Not Applicable<\/td><td>Not Applicable<\/td>        <\/tr>\n            <tr data-row_id=\"19\" class=\"ninja_table_row_10 nt_row_id_19\">\n            <td>Only secure (encrypted) transmission shall be allowed. In absence of mitigating controls (e.g. a physically secured area), encrypted storage of Restricted information is required.<\/td><td>Required<\/td><td>Required<\/td><td>Recommended<\/td><td>Not Applicable<\/td>        <\/tr>\n            <tr data-row_id=\"20\" class=\"ninja_table_row_11 nt_row_id_20\">\n            <td>Files shall be backed up and tested on a regular schedule and stored in a secured location both on and off-site (following the 3-2-1 backup strategy).<\/td><td>Required<\/td><td>Required<\/td><td>Recommended<\/td><td>Recommended<\/td>        <\/tr>\n            <tr data-row_id=\"21\" class=\"ninja_table_row_12 nt_row_id_21\">\n            <td>Hardware, Software and data shall be securely disposed of at the termination of business need in accordance with Rutgers records management policy, 30.4.5.<\/td><td>Required<\/td><td>Required<\/td><td>Recommended<\/td><td>Not Required<\/td>        <\/tr>\n    <\/tbody><!--ninja_tobody_rendering_done-->\n    <\/table>\n    \n    \n    \n<\/div>\n\n<p>&nbsp;<\/p>\n<p><strong>User Accounts\u00a0<\/strong><\/p>\n<div id=\"footable_parent_1171\"\n         class=\" footable_parent ninja_table_wrapper loading_ninja_table wp_table_data_press_parent semantic_ui \">\n                <table data-ninja_table_instance=\"ninja_table_instance_2\" data-footable_id=\"1171\" data-filter-delay=\"1000\" aria-label=\"7-31-24 User Accounts (Risk Policy Compliance) - Sheet1.csv( Duplicate )\"            id=\"footable_1171\"\n           data-unique_identifier=\"ninja_table_unique_id_2035099205_1171\"\n           class=\" foo-table ninja_footable foo_table_1171 ninja_table_unique_id_2035099205_1171 ui table  nt_type_legacy_table selectable striped vertical_centered  footable-paging-right ninja_table_search_disabled ninja_table_pro\">\n                <colgroup>\n                            <col class=\"ninja_column_0 \">\n                            <col class=\"ninja_column_1 \">\n                            <col class=\"ninja_column_2 \">\n                            <col class=\"ninja_column_3 \">\n                            <col class=\"ninja_column_4 \">\n                    <\/colgroup>\n        <thead>\n<tr class=\"footable-header\">\n                                                                                        <th scope=\"col\"  class=\"ninja_column_0 ninja_clmn_nm_controlstandard \">Control Standard<\/th><th scope=\"col\"  class=\"ninja_column_1 ninja_clmn_nm_restricted \">Critical<\/th><th scope=\"col\"  class=\"ninja_column_2 ninja_clmn_nm_restricted1 \">Restricted<\/th><th scope=\"col\"  class=\"ninja_column_3 ninja_clmn_nm_internal \">Internal<\/th><th scope=\"col\"  class=\"ninja_column_4 ninja_clmn_nm_public \">Public<\/th><\/tr>\n<\/thead>\n<tbody>\n\n        <tr data-row_id=\"22\" class=\"ninja_table_row_0 nt_row_id_22\">\n            <td>A process shall be established to create and assign, maintain, and verify a unique system identifier (e.g. NetID, UserID) for each user.<\/td><td>Required<\/td><td>Required<\/td><td>Recommended<\/td><td>Recommended<\/td>        <\/tr>\n            <tr data-row_id=\"23\" class=\"ninja_table_row_1 nt_row_id_23\">\n            <td>Authentication to a system identifier shall be controlled by a mechanism implemented based upon the sensitivity of the data.<\/td><td>Required<\/td><td>Required<\/td><td>Recommended<\/td><td>Recommended<\/td>        <\/tr>\n    <\/tbody><!--ninja_tobody_rendering_done-->\n    <\/table>\n    \n    \n    \n<\/div>\n\n<p>&nbsp;<\/p>\n<p><strong>Desktop<\/strong><\/p>\n<div id=\"footable_parent_1172\"\n         class=\" footable_parent ninja_table_wrapper loading_ninja_table wp_table_data_press_parent semantic_ui \">\n                <table data-ninja_table_instance=\"ninja_table_instance_3\" data-footable_id=\"1172\" data-filter-delay=\"1000\" aria-label=\"6-19-25 Desktop (Risk Policy Compliance) - Sheet1.csv( Duplicate )( Duplicate )\"            id=\"footable_1172\"\n           data-unique_identifier=\"ninja_table_unique_id_2589859867_1172\"\n           class=\" foo-table ninja_footable foo_table_1172 ninja_table_unique_id_2589859867_1172 ui table  nt_type_legacy_table selectable striped vertical_centered  footable-paging-right ninja_table_search_disabled ninja_table_pro\">\n                <colgroup>\n                            <col class=\"ninja_column_0 \">\n                            <col class=\"ninja_column_1 \">\n                            <col class=\"ninja_column_2 \">\n                            <col class=\"ninja_column_3 \">\n                            <col class=\"ninja_column_4 \">\n                    <\/colgroup>\n        <thead>\n<tr class=\"footable-header\">\n                                                                                        <th scope=\"col\"  class=\"ninja_column_0 ninja_clmn_nm_controlstandard \">Control Standard<\/th><th scope=\"col\"  class=\"ninja_column_1 ninja_clmn_nm_restricted \">Critical<\/th><th scope=\"col\"  class=\"ninja_column_2 ninja_clmn_nm_restricted1 \">Restricted<\/th><th scope=\"col\"  class=\"ninja_column_3 ninja_clmn_nm_internal \">Internal<\/th><th scope=\"col\"  class=\"ninja_column_4 ninja_clmn_nm_public \">Public<\/th><\/tr>\n<\/thead>\n<tbody>\n\n        <tr data-row_id=\"24\" class=\"ninja_table_row_0 nt_row_id_24\">\n            <td>Services and applications should be the minimum necessary to accomplish the required business functions.<\/td><td>Required<\/td><td>Required<\/td><td>Recommended<\/td><td>Recommended<\/td>        <\/tr>\n            <tr data-row_id=\"25\" class=\"ninja_table_row_1 nt_row_id_25\">\n            <td>Passwords shall be changed from the vendor defaults.<\/td><td>Required<\/td><td>Required<\/td><td>Required<\/td><td>Recommended<\/td>        <\/tr>\n            <tr data-row_id=\"26\" class=\"ninja_table_row_2 nt_row_id_26\">\n            <td>Systems shall be configured to a recognized standard. (e.g. Center for Internet Security (CIS) Workbench)  <\/td><td>Required<\/td><td>Required<\/td><td>Recommended<\/td><td>Recommended<\/td>        <\/tr>\n            <tr data-row_id=\"27\" class=\"ninja_table_row_3 nt_row_id_27\">\n            <td>Security updates and patches shall be applied as soon as practical, or automatically when possible.<\/td><td>Required<\/td><td>Required<\/td><td>Required<\/td><td>Recommended<\/td>        <\/tr>\n            <tr data-row_id=\"28\" class=\"ninja_table_row_4 nt_row_id_28\">\n            <td>Computer system support staff must monitor for announced vulnerabilities in their hardware and software.<\/td><td>Required<\/td><td>Required<\/td><td>Required<\/td><td>Recommended<\/td>        <\/tr>\n            <tr data-row_id=\"29\" class=\"ninja_table_row_5 nt_row_id_29\">\n            <td>Enable university-approved Endpoint Protection to guard against viruses, malware, and other cyber-threats.  <\/td><td>Required<\/td><td>Required<\/td><td>Required<\/td><td>Recommended<\/td>        <\/tr>\n            <tr data-row_id=\"30\" class=\"ninja_table_row_6 nt_row_id_30\">\n            <td>The amount of restricted information collected and stored shall be the minimum amount required for the efficient and effective conduct of business functions<\/td><td>Required<\/td><td>Required<\/td><td>Not Applicable<\/td><td>Not Applicable<\/td>        <\/tr>\n            <tr data-row_id=\"31\" class=\"ninja_table_row_7 nt_row_id_31\">\n            <td>Hardware, Software and data shall be securely disposed of at the termination of business need in accordance with Rutgers records management policy, 30.4.5.<\/td><td>Required<\/td><td>Required<\/td><td>Recommended<\/td><td>Not Required<\/td>        <\/tr>\n            <tr data-row_id=\"32\" class=\"ninja_table_row_8 nt_row_id_32\">\n            <td>Only secure (encrypted) transmission shall be allowed. In absence of mitigating controls (e.g. a physically secured area), encrypted storage of Restricted information is required.<\/td><td>Required<\/td><td>Required<\/td><td>Recommended<\/td><td>Not Applicable<\/td>        <\/tr>\n            <tr data-row_id=\"33\" class=\"ninja_table_row_9 nt_row_id_33\">\n            <td>Automatic screen lock must be enabled after 15 minutes of inactivity and set to require a password to unlock.<\/td><td>Required<\/td><td>Required<\/td><td>Required<\/td><td>Recommended<\/td>        <\/tr>\n    <\/tbody><!--ninja_tobody_rendering_done-->\n    <\/table>\n    \n    \n    \n<\/div>\n\n<p>&nbsp;<\/p>\n<p><strong>Portable devices (laptops, cell phones, tablets, etc.), removable media and non-Rutgers owned machines\/equipment<\/strong><\/p>\n<p><div id=\"footable_parent_1173\"\n         class=\" footable_parent ninja_table_wrapper loading_ninja_table wp_table_data_press_parent semantic_ui \">\n                <table data-ninja_table_instance=\"ninja_table_instance_4\" data-footable_id=\"1173\" data-filter-delay=\"1000\" aria-label=\"6-19-25 Portable Devices (Risk Policy Compliance) - Sheet1.csv( Duplicate )( Duplicate )\"            id=\"footable_1173\"\n           data-unique_identifier=\"ninja_table_unique_id_2278943946_1173\"\n           class=\" foo-table ninja_footable foo_table_1173 ninja_table_unique_id_2278943946_1173 ui table  ninja_search_right nt_type_legacy_table selectable striped vertical_centered  footable-paging-right ninja_table_search_disabled ninja_table_pro\">\n                <colgroup>\n                            <col class=\"ninja_column_0 \">\n                            <col class=\"ninja_column_1 \">\n                            <col class=\"ninja_column_2 \">\n                            <col class=\"ninja_column_3 \">\n                            <col class=\"ninja_column_4 \">\n                    <\/colgroup>\n        <thead>\n<tr class=\"footable-header\">\n                                                                                        <th scope=\"col\"  class=\"ninja_column_0 ninja_clmn_nm_controlstandard \">Control Standard<\/th><th scope=\"col\"  class=\"ninja_column_1 ninja_clmn_nm_restricted \">Critical<\/th><th scope=\"col\"  class=\"ninja_column_2 ninja_clmn_nm_restrictedcol \">Restricted<\/th><th scope=\"col\"  class=\"ninja_column_3 ninja_clmn_nm_internal \">Internal<\/th><th scope=\"col\"  class=\"ninja_column_4 ninja_clmn_nm_public \">Public<\/th><\/tr>\n<\/thead>\n<tbody>\n\n        <tr data-row_id=\"34\" class=\"ninja_table_row_0 nt_row_id_34\">\n            <td>Hardware, software and data must be securely disposed of at the termination of business need in accordance with Rutgers records management policy. Hardware not capable of being digitally wiped must be physically destroyed.<\/td><td>Required<\/td><td>Required<\/td><td>Recommended<\/td><td>Not Required<\/td>        <\/tr>\n            <tr data-row_id=\"35\" class=\"ninja_table_row_1 nt_row_id_35\">\n            <td>Devices used for Rutgers business should utilize secure storage (full disk\/device encryption) whenever possible. Encrypted storage of Restricted information is required. Exceptions to this standard must be vetted by the Risk Management team.<\/td><td>Required<\/td><td>Required<\/td><td>Recommended<\/td><td>Not Applicable<\/td>        <\/tr>\n            <tr data-row_id=\"36\" class=\"ninja_table_row_2 nt_row_id_36\">\n            <td>Automatic screen lock must be enabled after 15 minutes of inactivity and set to require a password to unlock.<\/td><td>Required<\/td><td>Required<\/td><td>Required<\/td><td>Recommended<\/td>        <\/tr>\n            <tr data-row_id=\"37\" class=\"ninja_table_row_3 nt_row_id_37\">\n            <td>Security standards for desktops are followed.<\/td><td>Required<\/td><td>Required<\/td><td>Required<\/td><td>Recommended<\/td>        <\/tr>\n            <tr data-row_id=\"38\" class=\"ninja_table_row_4 nt_row_id_38\">\n            <td>Devices used for Rutgers business should be remotely traceable, lockable and wipeable.<\/td><td>Required<\/td><td>Required<\/td><td>Recommended<\/td><td>Not Applicable<\/td>        <\/tr>\n            <tr data-row_id=\"39\" class=\"ninja_table_row_5 nt_row_id_39\">\n            <td>Devices used for Rutgers business should have a \u201cstrong password\u201d enabled and should lock (or wipe) after 10 failed attempts to login.<\/td><td>Required<\/td><td>Required<\/td><td>Recommended<\/td><td>Not Applicable<\/td>        <\/tr>\n            <tr data-row_id=\"40\" class=\"ninja_table_row_6 nt_row_id_40\">\n            <td>Use of personal devices (non-Rutgers-owned equipment -BYOD) for conducting Rutgers business.<\/td><td>Not permiteed<\/td><td>Not permitted<\/td><td>Allowed (*with prior authorization)<\/td><td>Allowed<\/td>        <\/tr>\n    <\/tbody><!--ninja_tobody_rendering_done-->\n    <\/table>\n    \n    \n    \n<\/div>\n<br \/>\n*Note: <em>BYOD (Bring Your Own Device) is generally permitted with prior review and authorization by the user\u2019s management and OIT leadership. While the use of personal devices for university business is generally authorized under specific conditions, there may be exceptions that require additional review and approval. These exceptions will be considered in collaboration with management, local IT, the Office of General Counsel (OGC), the University Ethics Committee (UEC), and other relevant stakeholder groups as applicable and commensurate with risk. The need for additional review is based on the type of data classification, which can be found in the <a href=\"https:\/\/policies.rutgers.edu\/B.aspx?BookId=12018&#038;PageId=459369&#038;Search=data%20classification\">Information Classification Policy<\/a>, the ability to enforce appropriate security controls on the device, and the susceptibility of the device to cyber threats.<\/em><\/p>\n<p><em><strong>Computing devices acquired through a grant or research contract authorized by the University, and\/or those that utilize the University&#8217;s computing infrastructure, are classified as university assets.<\/strong><\/em><\/p>\n<p><strong>Software Development<\/strong><\/p>\n<div id=\"footable_parent_1174\"\n         class=\" footable_parent ninja_table_wrapper loading_ninja_table wp_table_data_press_parent semantic_ui \">\n                <table data-ninja_table_instance=\"ninja_table_instance_5\" data-footable_id=\"1174\" data-filter-delay=\"1000\" aria-label=\"Software Development (Risk Policy Compliance) - Sheet1.csv\"            id=\"footable_1174\"\n           data-unique_identifier=\"ninja_table_unique_id_2148979509_1174\"\n           class=\" foo-table ninja_footable foo_table_1174 ninja_table_unique_id_2148979509_1174 ui table  nt_type_legacy_table selectable striped vertical_centered  footable-paging-right ninja_table_search_disabled ninja_table_pro\">\n                <colgroup>\n                            <col class=\"ninja_column_0 \">\n                            <col class=\"ninja_column_1 \">\n                            <col class=\"ninja_column_2 \">\n                            <col class=\"ninja_column_3 \">\n                            <col class=\"ninja_column_4 \">\n                    <\/colgroup>\n        <thead>\n<tr class=\"footable-header\">\n                                                                                        <th scope=\"col\"  class=\"ninja_column_0 ninja_clmn_nm_controlstandard \">Control Standard<\/th><th scope=\"col\"  class=\"ninja_column_1 ninja_clmn_nm_restricted \">Critical<\/th><th scope=\"col\"  class=\"ninja_column_2 ninja_clmn_nm_restricted1 \">Restricted<\/th><th scope=\"col\"  class=\"ninja_column_3 ninja_clmn_nm_internal \">Internal<\/th><th scope=\"col\"  class=\"ninja_column_4 ninja_clmn_nm_public \">Public<\/th><\/tr>\n<\/thead>\n<tbody>\n\n        <tr data-row_id=\"41\" class=\"ninja_table_row_0 nt_row_id_41\">\n            <td>Internally developed software shall be based on secure coding guidelines and reviewed regularly for common coding vulnerabilities.<\/td><td>Required<\/td><td>Required<\/td><td>Recommended<\/td><td>Recommended<\/td>        <\/tr>\n    <\/tbody><!--ninja_tobody_rendering_done-->\n    <\/table>\n    \n    \n    \n<\/div>\n\n<\/div><!-- f--field f--rich-text -->\n\n    <\/div>\n    <style>\n        .cc--rich-text .c--rich-text:has(.inner-wrapper) {\n            padding: 0 !important;\n        }\n\n        .cc--rich-text .c--rich-text .inner-wrapper {\n            padding-right: 8%;\n            padding-left: 8%;\n        }\n\n        @media screen and (min-width: 768px) {\n            .cc--rich-text .c--rich-text .inner-wrapper {\n                padding-right: 12%;\n                padding-left: 12%;\n            }\n        }\n\n        @media screen and (min-width: 1024px) {\n            .cc--rich-text .c--rich-text .inner-wrapper {\n                padding-right: 10%;\n                padding-left: 10%;\n            }\n        }\n    <\/style>\n<\/div><!-- c--component c--rich-text -->\n\n    <\/section><!-- cc--component-container cc--section -->\n","protected":false},"excerpt":{"rendered":"","protected":false},"author":992,"featured_media":0,"parent":0,"menu_order":0,"comment_status":"closed","ping_status":"closed","template":"","meta":{"_acf_changed":false,"footnotes":""},"page-category":[],"class_list":["post-1165","page","type-page","status-publish","hentry"],"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v28.0 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Endpoint security standards for data protection - Cybersecurity Compliance Program<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/it.rutgers.edu\/cybersecurity-compliance-program\/endpoint-security-standards-for-data-protection\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Endpoint security standards for data protection - Cybersecurity Compliance Program\" \/>\n<meta property=\"og:url\" content=\"https:\/\/it.rutgers.edu\/cybersecurity-compliance-program\/endpoint-security-standards-for-data-protection\/\" \/>\n<meta property=\"og:site_name\" content=\"Cybersecurity Compliance Program\" \/>\n<meta property=\"article:modified_time\" content=\"2026-08-04T18:39:14+00:00\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/it.rutgers.edu\\\/cybersecurity-compliance-program\\\/endpoint-security-standards-for-data-protection\\\/\",\"url\":\"https:\\\/\\\/it.rutgers.edu\\\/cybersecurity-compliance-program\\\/endpoint-security-standards-for-data-protection\\\/\",\"name\":\"Endpoint security standards for data protection - Cybersecurity Compliance Program\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/it.rutgers.edu\\\/cybersecurity-compliance-program\\\/#website\"},\"datePublished\":\"2026-08-04T17:52:29+00:00\",\"dateModified\":\"2026-08-04T18:39:14+00:00\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/it.rutgers.edu\\\/cybersecurity-compliance-program\\\/endpoint-security-standards-for-data-protection\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/it.rutgers.edu\\\/cybersecurity-compliance-program\\\/endpoint-security-standards-for-data-protection\\\/\"]}]},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/it.rutgers.edu\\\/cybersecurity-compliance-program\\\/endpoint-security-standards-for-data-protection\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"LinkedIn Learning\",\"item\":\"https:\\\/\\\/it.rutgers.edu\\\/cybersecurity-compliance-program\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Endpoint security standards for data protection\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/it.rutgers.edu\\\/cybersecurity-compliance-program\\\/#website\",\"url\":\"https:\\\/\\\/it.rutgers.edu\\\/cybersecurity-compliance-program\\\/\",\"name\":\"Cybersecurity Compliance Program\",\"description\":\"A Rutgers IT Service\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/it.rutgers.edu\\\/cybersecurity-compliance-program\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Endpoint security standards for data protection - Cybersecurity Compliance Program","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/it.rutgers.edu\/cybersecurity-compliance-program\/endpoint-security-standards-for-data-protection\/","og_locale":"en_US","og_type":"article","og_title":"Endpoint security standards for data protection - Cybersecurity Compliance Program","og_url":"https:\/\/it.rutgers.edu\/cybersecurity-compliance-program\/endpoint-security-standards-for-data-protection\/","og_site_name":"Cybersecurity Compliance Program","article_modified_time":"2026-08-04T18:39:14+00:00","twitter_card":"summary_large_image","schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"WebPage","@id":"https:\/\/it.rutgers.edu\/cybersecurity-compliance-program\/endpoint-security-standards-for-data-protection\/","url":"https:\/\/it.rutgers.edu\/cybersecurity-compliance-program\/endpoint-security-standards-for-data-protection\/","name":"Endpoint security standards for data protection - Cybersecurity Compliance Program","isPartOf":{"@id":"https:\/\/it.rutgers.edu\/cybersecurity-compliance-program\/#website"},"datePublished":"2026-08-04T17:52:29+00:00","dateModified":"2026-08-04T18:39:14+00:00","breadcrumb":{"@id":"https:\/\/it.rutgers.edu\/cybersecurity-compliance-program\/endpoint-security-standards-for-data-protection\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/it.rutgers.edu\/cybersecurity-compliance-program\/endpoint-security-standards-for-data-protection\/"]}]},{"@type":"BreadcrumbList","@id":"https:\/\/it.rutgers.edu\/cybersecurity-compliance-program\/endpoint-security-standards-for-data-protection\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"LinkedIn Learning","item":"https:\/\/it.rutgers.edu\/cybersecurity-compliance-program\/"},{"@type":"ListItem","position":2,"name":"Endpoint security standards for data protection"}]},{"@type":"WebSite","@id":"https:\/\/it.rutgers.edu\/cybersecurity-compliance-program\/#website","url":"https:\/\/it.rutgers.edu\/cybersecurity-compliance-program\/","name":"Cybersecurity Compliance Program","description":"A Rutgers IT Service","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/it.rutgers.edu\/cybersecurity-compliance-program\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"}]}},"_links":{"self":[{"href":"https:\/\/it.rutgers.edu\/cybersecurity-compliance-program\/wp-json\/wp\/v2\/pages\/1165","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/it.rutgers.edu\/cybersecurity-compliance-program\/wp-json\/wp\/v2\/pages"}],"about":[{"href":"https:\/\/it.rutgers.edu\/cybersecurity-compliance-program\/wp-json\/wp\/v2\/types\/page"}],"author":[{"embeddable":true,"href":"https:\/\/it.rutgers.edu\/cybersecurity-compliance-program\/wp-json\/wp\/v2\/users\/992"}],"replies":[{"embeddable":true,"href":"https:\/\/it.rutgers.edu\/cybersecurity-compliance-program\/wp-json\/wp\/v2\/comments?post=1165"}],"version-history":[{"count":5,"href":"https:\/\/it.rutgers.edu\/cybersecurity-compliance-program\/wp-json\/wp\/v2\/pages\/1165\/revisions"}],"predecessor-version":[{"id":1180,"href":"https:\/\/it.rutgers.edu\/cybersecurity-compliance-program\/wp-json\/wp\/v2\/pages\/1165\/revisions\/1180"}],"wp:attachment":[{"href":"https:\/\/it.rutgers.edu\/cybersecurity-compliance-program\/wp-json\/wp\/v2\/media?parent=1165"}],"wp:term":[{"taxonomy":"page-category","embeddable":true,"href":"https:\/\/it.rutgers.edu\/cybersecurity-compliance-program\/wp-json\/wp\/v2\/page-category?post=1165"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}