Responsible Office: Office of Cybersecurity
Last Review: 11/17/2020
Next Review: 11/17/2022
Contact: Chris Madeksho
Authentication mechanisms such as username and passwords combinations are the primary means of obtaining access to computer systems and data. It is essential that these authenticators be strongly constructed and used in a manner that prevents their compromise. They are designed to minimize the potential security exposure to UTHSC from damages which may result from unauthorized use of UTHSC resources. Multi-factor authentication is an additional protection to systems and applications.
This standard applies to members of the UTHSC Community who have been granted access to UTHSC IT Resources and/or represent UTHSC in any capacity.
Central Authentication Service (CAS): is a sign-on protocol that authenticates users to multiple systems using the same authenticators, i.e. NetID and password.
DUO: UTHSC’s multi-factor authentication application
Multi-factor authentication: a method of computer access control that requires the user to provide two or more verification factors to gain access to a UTHSC resource.
UTHSC Resource: Any data, device, or other component of the information environment that supports information-related activities. Assets generally include hardware (e.g. endpoint devices), software (e.g. critical applications and support systems), and information.
Office of Cybersecurity is responsible for setting basic security standards for the UTHSC Resource.
ITS Infrastructure team is responsible for the deployment of technical controls to establish authentication.
UTHSC Community is responsible for adhering to this standard and the security controls set forth in it to prevent unauthorized access using their authenticators or credentials.
- Access to all university data and systems not intended for unrestricted public access requires authentication.
- All users of networks, systems, or applications must be supplied with a unique authenticator, i.e. UTHSC NetID and a password, or other individually identifiable authentication method, to gain access to such systems to protect from unauthorized use.
- The individual registered as the owner of the authenticator accessing UTHSC data, information, and systems is responsible and liable for all processes initiated with that authenticator. Unacceptable use, whether intentional or unintentional, will result in immediate suspension of the access privileges.
- Authenticators must be constructed in compliance with the complexity standard for the employed authenticator, for example, passwords must comply with Practice-InfoSec-AC-002.02 Password Management and Complexity.
- Users are required to use multi-factor authentication (MFA) in accessing UTHSC systems and applications.
- Users will be required to enroll a device to serve as the second authentication method as part of MFA. This device may be a cell phone or DUO token.
- Information about UTHSC’s MFA solution, DUO, can be found on this webpage.
- No one may share or require another to share authenticators to individually assigned access to any systems or data while acting as a representative of UTHSC.
- Generic or group authenticators are not permitted except for business justified requested exemptions and exceptions, if sufficient other controls on access are in place.
- UTHSC applications and systems are designed to authenticate using Central Authentication Service (CAS) using UTHSC NetID and password along with DUO MFA.
- Applications and systems that do not have users authenticate using NetIDs must establish an alternative mean of authentication, using MGA if such authentication is supported.
- UTHSC systems must be designed and configured to protect authentication factors during storage and transmission utilizing the data ranking system designed in Standard-InfoSec-GP-002-Data & System Classification.
- Any, either known or suspected, compromise of an authenticator must be immediately reported to the access grantor and the authenticator changed.
- Suspected or known compromises should be reported to, and investigated by, the by Security Incident Response Team in accordance with Standard-InfoSec-IR-001-Secuity Incident Response.
- Exceptions to this Standard should be requested using the process outlined in Practice-InfoSec-GP-001.02 Security Exceptions and Exemptions to ITS Standards and Practices.
- Standard-InfoSec-AC-001-Access Controls
- Standard-InfoSec-GP-002-Data & System Classification
- Practice-InfoSec-AC-002.02 Password Management and Complexity
- Standard-InfoSec-IR-001-Security Incident Response
- Practice-InfoSec-GP-001.02 Security Exceptions and Exemptions to ITS Standards and Practices