(1) This Policy outlines how IT Resources and user accounts are to be secured in accordance with the Cyber Security Policy. (2) This Policy applies to all staff employed by Macquarie University and its controlled entities and Affiliates who: (3) Macquarie University (the University) is committed to maintaining a secure technology environment and as such, has established requirements to secure the University’s IT Resources. Establishing these requirements aims to decrease the likelihood of negative consequences impacting the Confidentiality, Integrity and Availability of IT Resources. (4) User access provisioning, account management, and password allocation should only be performed by the Central IT team, in accordance with approved operational procedures. (5) Access to IT Resources should be controlled through a central identity management platform (e.g., Active Directory (AD) group membership). (6) Access to applications should be facilitated via Single-Sign-On (SSO), where possible. (7) User accounts must be configured with Multi Factor Authentication(MFA) and User accounts should be unique to an individual. (8) A user access provisioning process should be implemented to assign or revoke access to IT Resources. User access should be: (9) Systems under organisational control must enforce account lockout controls to mitigate brute-force and credential guessing attacks. Specific lockout parameters (including attempt threshold, lockout duration, and counter reset) are defined in the standards/baseline and approved by the cyber security function. (10) User access permissions should be reviewed for suitability by the Business Owner (or authorised delegate) or Cyber Security team, at the following cadences: (11) User access permissions should also be reviewed in response to one of the following: (12) Access management systems must be configured to ‘deny by default’ unless explicit access is granted. (13) Both privileged and unprivileged access to IT Resources should be automatically disabled after 90 days of inactivity. (14) Privileged Users should maintain a Standard User account for their day-to-day non-privileged work and use a specific Privileged User account for any tasks that require elevated privileges. (15) Elevated/higher privileges should not be granted to a Standard User account. (16) The owner of a user account will be held responsible for all actions undertaken by the account. (17) The use of shared user accounts must be documented and an owner must be assigned to each shared user account. (18) Where available, University approved password managers should be used. (19) IT Resources that manage/enforce passwords should be configured to enforce the following requirements: (20) Privileged account passwords must be randomly generated at build time and at any time the password is communicated. (21) Temporary passwords should adhere to the same requirements detailed in clause 19 and be set to expire after 24 hours. (22) Passwords must be changed in response to one of the following: (23) Password resets should be logged to provide an audit trail for any future investigation. (24) Passwords should be securely stored within a University approved password manager. (25) Password generated by applications/systems should be shared via a secure and approved distribution method. (26) Passwords must not be shared with another individual. (27) Scripts, code, or macros should not contain passwords. (28) Passwords used for encryption keys should comply with the same minimum requirements as required by the Privileged User Accounts. (29) Passwords used to decrypt keys should only be verbally shared with authorised users. (30) IT Resources should be documented within an asset register, inclusive of the following information: (31) IT Resources not approved by the University should not be connected to the University’s corporate network. (32) IT Resources should be onboarded, maintained and offboarded in accordance with a defined asset management process. (33) Networks should be segmented and network zones classified different from public. (34) Network zones should be protected from the internet and Third-Party environments by perimeter controls including but not limited to a firewall and Access Control Lists (ACLs). (35) IT Resources attached to the University’s network must have anti-malware software installed. The software must: (36) Malware-infected IT Resources must be removed from the network until it is verified as virus-free. (37) All encrypted artefacts must be scanned for malware after decryption and before execution. (38) All artefacts obtained or downloaded must be scanned for malware before executing. (39) Locally mounted disks should be scanned by anti-malware software on a weekly basis. (40) University information should be encrypted in-transit and at-rest, in accordance with the Australian Signal Directorate (ASD) Approved Cryptographic Algorithms. (41) Internet-facing website validation should adhere to the criteria below: (42) System-to-system interfaces should adhere to the criteria below: (43) Encryption keys must adhere to the criteria below: (44) University records must be retained in accordance with the Records and Information Management Policy. (45) Information that is not required to be retained for regulatory or University purposes on printed material or in a digital format should be securely destroyed so that the information is not able to be recovered by unauthorised parties. (46) Destruction of University records should be approved by authorised staff and documented. (47) Printed documents should be destroyed by using secure facilities provided by the University by: (48) Optical media and hard disks that contain University information should be securely deleted/wiped before being repurposed. (49) Optical media and hard disks should be physically destroyed before being disposed, by disintegration, incineration, pulverising, shredding, melting or through a AAA certified National Association for Information Destruction organisation, with a certificate of destruction. (50) Decommissioned, disposed and repurposed IT Resources must have: (51) Any exemption from this Policy must be sought from the Chief Information Security Officer (CISO). (52) Breaches of this Policy will be managed in accordance with the applicable provisions of the Staff Code of Conduct and other relevant policy instruments. (53) IT Resources must be built/configured in accordance with, but not limited to, the following requirements: (54) IT Resources that handle Highly Sensitive information (refer Information Classification and Handling Procedure) must be built/configured in accordance with, but not limited to, the following requirements: (55) Firewalls must be built/configured in accordance with, but not limited to, the following requirements: (56) Firewall rule changes must be reviewed and approved by the Cyber Security team to determine if they meet one or more of the following conditions: (57) Web application environments should adhere to the following requirements: (58) Access to specific IT Resources should adhere to the requirements outlined within the following table: (59) A message that discourages unauthorised access and notifies the user of activity monitoring should be displayed before a user attempts to logon to an IT Resource, as outlined in the table below: (60) Nil. (61) The following definitions apply for the purpose of this Policy:Computer and Network Security Policy
Section 1 - Purpose
Scope
Background
Section 2 - Policy
General Access Management
Account Management
Password Management
Requirement
Settings
Network Security
Malware
Encryption
IT Resource Decommissioning
Compliance and Exemptions
Section 3 - Procedures
Type
Requirements
Top of Page
IT Resource Type
Warning Message
Access to this system is restricted to authorised users only. Actions performed by users on this system are logged and monitored. Activities conducted on this system that contravene the University’s policies and procedures will be reported to the relevant authorities.
Section 4 - Guidelines
Section 5 - Definitions
Privileged User Account means an account with elevated permissions to manage and make system-wide changes (e.g., configure systems, install software, access sensitive data).
View Document
This is the current version of this document. To view historic versions, click the link in the document's navigation bar.
Minimum Password Length
Standard User accounts (8 characters); and
Privileged User accounts (16 characters).
Password Expiry
Standard and Privileged User accounts (1 year).
Password History
5 previous passwords.
Password Complexity
Passwords must contain:
at least one uppercase or lowercase character (e.g., A – Z or a – z);
at least once number/digit (e.g., 1 – 9); and
at least one special character (e.g., #, %, $).
Passwords must not contain:
Commonly used words or commonly used passphrases; and
Part of a users’ username, first name, or last name.
The asset register will be maintained by IT, with input from relevant business owners to ensure completeness and accuracy.
Database Access
non-production applications and databases must not contain production data;
the System Administrator (SA) account must only be used in the case of an emergency;
all direct access to databases must be conducted with the users unique ID;
applications that integrate with a database must be assigned a unique application account, used exclusively for the interactions with the database; and
applications that allow users to access data directly from a database must log the identity of the user within user activity logs for data create, read, update or delete activities.
Root Access
root Access accounts should only be used in the case of an emergency;
root Access account passwords should be stored in a secure digital format protected by strong encryption;
root Access accounts should only be accessible by the minimum number of support staff required; and
root Access account passwords should not be sent by email, instant message technology or over the phone.
Console Access
require re-authentication after 20 minutes of inactivity if facilitating access to Highly Sensitive information; and
not be directly accessible from the internet with a single factor of authentication.
System-to-System Access
not be used by individuals for day-to-day operations;
be either certificate based or consist of a password of at least 16 characters;
can be set to never expire; and
be protected by strong encryption or restrictive file system permissions when stored (only permit access to the required application accounts).
Remote Access
only be permitted via an approved Virtual Private Network (VPN) solution;
be protected by strong encryption; and
be removed immediately when no longer required.
Computers and Network Devices
Example: WARNING! This system belongs to Macquarie University. AUTHORISED ACCESS ONLY.
Application
This application is operated by Macquarie University. Access to this application is restricted to authorised users only. Actions performed by users within this application are logged and monitored. Misuse of this application and its facilities will be reported to the relevant authorities.