UTS Standard: Network Security

Overview

The Network Security Standard establishes the minimum security requirements for protecting the confidentiality, integrity, and availability of the Oakland University (OU) Network. The standard ensures that network infrastructure is securely deployed, managed, and monitored; access to University resources is appropriately controlled; and operations comply with regulatory, contractual, and institutional information security requirements.

Scope

This standard applies to:

  • All network infrastructure components, including:
    • Firewalls
    • Routers
    • Switches
    • Wireless access points
    • Network appliances
    • Communication cabling
    • Telecommunications systems
    • Any network-connected device on the OU production Network
  • All network environments supporting:
    • Academic and research operations
    • Administrative and business functions
    • Teaching and learning environments

Lifestyle Networks (e.g., Residence Halls, campus residential dwellings) are considered partially in scope and governed by documented blanket deviations due to their unique operational requirements.

Standard

Secure management of the Oakland University Network requires centralized control of network infrastructure, regulated installation and configuration of components, appropriate monitoring, and enforcement of security controls.

All Network, communications, and telecommunications services and devices including cabling must be installed, configured, and maintained by University Technology Services (UTS).

Network Protection Requirements

The following must be installed, maintained, and managed exclusively by UTS:

  • Communications cabling (permanent and inter-room cabling used for voice, data, and communications)
  • Routers that segment or route traffic on the OU Network
  • Communications switches (e.g., Ethernet switches)
  • Wireless Access Points (WAPs) and wireless devices providing or bridging access to the University Network
  • Wireless equipment operating within or interfering with authorized OU spectrum
  • Telecommunications systems (e.g., IP/VoIP phones, hosted telephony services)
  • Cellular communication infrastructure (antennas, cabling, equipment)
  • Cable and satellite television infrastructure

Network Configuration Requirements

All network-connected devices must use UTS-provided:

  • DHCP for IP address configuration
  • DNS for name resolution

Lifestyle Network: Operates under a documented exception due to specialized requirements.

Departmental IT units, with UTS support, must implement required logging and monitoring in accordance with the IT Logging and Management Standard.

Network Security Controls

Network Segmentation

  • The OU Network must be segmented into appropriate security zones based on data classification, system criticality, and compliance obligations.
  • High-risk systems (e.g., PHI systems, PCI systems, research computing with CUI) must be isolated.
  • Internal segmentation must use ACLs, VLANs, or firewalls to restrict unnecessary lateral movement.

Access Controls

  • Network devices must enforce strong authentication and authorization controls.
  • Role-Based Access Control (RBAC) must be used for network administration.
  • Remote administrative access requires:
    • Authorization
    • Strong authentication
    • Multi-Factor Authentication (MFA)

Firewalls and Perimeter Security

  • Firewalls must enforce the principle of least privilege.
  • Default-deny policies must be applied to block unauthorized inbound and outbound traffic.
  • Firewall rules must be:
    • Regularly reviewed
    • Updated as systems and risks evolve
    • Monitored for compliance

Wireless Security

  • Secure wireless networks must use WPA2-Enterprise or a stronger encryption standard.
  • Separate SSIDs must be used for:
    • Institutional use (e.g., Eduroam)
    • Guest access
    • Lifestyle/residential networks
    • Research or specialized environments
  • Unauthorized wireless access points or ad hoc wireless networks are strictly prohibited.

Patch Management

  • All network devices must be patched in accordance with the UTS Patching Standard.
  • Automated patching tools should be used wherever technically feasible.
  • End-of-life (EOL) or unsupported network devices must:
    • Be replaced, or
    • Be isolated/segmented from production network environments

Lifestyle Network: Operates under a documented exception due to unique operational requirements.

Bandwidth Management

To ensure optimal network performance and availability, UTS may implement:

  • Bandwidth quotas
  • Traffic shaping
  • Congestion-control mechanisms

Enforcement and Compliance

  • The Information Security Office (ISO) reserves the right to audit, assess, and enforce security requirements on any OU Network-connected system.
  • Regular network security assessments, including vulnerability scans and configuration reviews, must be performed to identify and remediate risks.

Waivers and Exceptions

Compliance with this standard is mandatory.

If compliance is not feasible, a formal Security Exception Request must be submitted to the Information Security Office for review and potential approval.

<Link to Exception Process KB Article>

Roles and Responsibilities

Chief Information Officer

  • Approves changes to this standard.

Chief Information Security Officer

  • Administers, interprets, and enforces this standard.
  • Oversees network-related risk management and compliance efforts.

Network Infrastructure Team

  • Deploys, manages, and supports network hardware, software, configurations, and segmentation.
  • Implements and maintains network security controls.

Information Security Office

  • Conducts network audits, assessments, and compliance reviews.
  • Provides guidance on network security architecture and risk mitigation.
  • Coordinates incident response for network-related security events.

Definitions

Definitions of capitalized terms used in this standard are maintained in the UTS Standard: IT Terminology.

Related Documents, Forms, and Tools

Additional Support

  • OU Technology Center
  • 44 Oakland Center
  • Rochester, MI 48309-4479
  • Phone: (248) 370-4357
  • Email: support@oakland.edu
  • Office Hours: M-F 8:00am - 5:00pm

Last Modified: 8/26/2026
Authority: Approved by University Technology Services (UTS) Chief Information Officer
Category: Security Standards
Status: Approved