Personal Endpoint Protection Guidelines
Version 2.0
For Students, Faculty, Staff, Guests, Alumni
|
Sponsor |
Office of Information Technology |
|---|---|
| Audience | Faculty, students, administrative officials, staff, alumni, authorized guests, delegates, and independent contractors. |
| Effective Date | 02/11/2011 |
| Review Date | 08/21/2026 |
| Implementation History |
Review Frequency: Triennial
Responsible Person: Senior Director of IT Security and Assurance
Approved By: CISO
|
| Background Information | The purpose of this guideline is to provide practical guidance for using personal or host-based firewalls and related endpoint protections to help protect IT Resources from malicious and unauthorized activity. |
Definitions
Firewalls are used to prevent unauthorized access to IT Resources.
IT Resources include computing, networking, communications, applications, and telecommunications systems, infrastructure, hardware, software, data, databases, personnel, procedures, physical facilities, cloud-based vendors, Software as a Service (SaaS) vendors, and related materials and services.
Guidelines Statement
- Devices used to access the University’s IT Resources should have an active firewall or University-supported equivalent endpoint protection.
- Users should not disable or modify firewall, anti-malware, or endpoint-protection settings unless advised by the Office of Information Technology.
- Operating systems, firewall software, antivirus software, and other endpoint-security software should be maintained with current vendor-supported security updates.
- Only network services, applications, and firewall exceptions needed for legitimate use should be enabled; unnecessary ports and services should remain disabled.
- Endpoint security software should be allowed to perform real-time scanning, integrity checks, and monitoring when those features are available.
- If a device is suspected of malware infection, compromise, or unauthorized changes, users should contact the IT Service Desk for assistance.
- Users should follow Office of Information Technology security alerts and advisories that require action to protect their devices.
- If applicable, enable your operating system’s (e.g., Windows®1, Mac OS®2, *NIX) built-in firewall.
- For assistance with firewall or endpoint-protection software, contact the IT Service Desk at 718-817-3999 or [email protected].
Related Policies, Procedures, and Forms
- Configuration Management Policy
- Endpoint Protection Policy
- Firewall/Access Control List Policy
- Information Security Incident Response Policy
- Patch Management Policy
Revision History
| Version | Date | Description |
|---|---|---|
| 1.1 | 02/01/2011 | Initial document |
| 1.1.2 | 11/13/2019 | Update to links |
| 1.1.3 | 01/16/2020 | Updated statement |
| 1.2 | 05/23/2025 | Updated statement |
| 2.0 | 08/21/2026 | Added NIST.SP 800-53 r5 controls: SI-2, SI-3, SI-4, SI-5, SI-7, SI-12 |