Skip to main content
University of California San Francisco Give to UCSF

UCSF IT Technology

  • About Us
    • About Us
    • Mission Areas
    • IT Strategy
    • IT Governance
    • IT Directory
    • Standards and Guidelines
  • Resources
    • Oracle Cloud
    • Services
    • System Status
    • Security Notices
    • Software
  • Initiatives
    • Initiatives
    • AI at UCSF
    • IT Operating Model (ITOM)
    • Digital Accessibility Compliance Project
    • Knowledge Management Project
    • Zoom Workspace
    • IAM Modernization Program
  • News & Events
    • News & Events
  • How-To Articles
  • Log In
Open Close Search
Open menu
Give to UCSF
  1. Home
  2. Standards & Guidelines
  3. UCSF 650-16 Addendum H — Staff VPN and Remote Access Standard

This content is viewable by Everyone

Standard

UCSF 650-16 Addendum H — Staff VPN and Remote Access Standard

Save

Log in via MyAccess to save.

  • Effective Date: August 18, 2026
  • Impacted Services VPN - Remote connection, Palo Alto GlobalProtect VPN

Purpose 

To establish and set the requirements for standard staff remote access to UCSF networks, systems, and applications using UCSF-approved VPN and related remote-access services.

Table of Contents

  • Overview and Scope
  • Definitions
  • Staff VPN and Remote Access Standards
  • Privacy
  • Incident reporting and response
  • Exceptions
  • Enforcement
  • Policy ownership and review

Overview and Scope 

This standard applies to all UCSF workforce members using remote-access methods to connect to UCSF networks, systems, applications, or data, including workforce members using non-UCSF devices for UCSF business. This standard applies to both routine staff access and administrative remote access performed by UCSF personnel. Third-party remote access remains governed by UCSF 650-16 Addendum G.

Definitions 

Use the UC Systemwide IT Policy Glossary for standard terms. For this addendum: 

  • Staff VPN means the UCSF enterprise VPN service approved by UCSF IT for workforce-member remote access. 
  • Managed Device means a UCSF-owned endpoint enrolled in UCSF-prescribed management and security tooling. 
  • Compliant Personal Device means a non-UCSF endpoint that meets applicable UCSF minimum-security requirements before it is used for UCSF business or VPN access. 
  • Restricted and Sensitive Information means institutional information classified as P4 or P3. 
  • Elevated Administrative Access means privileged remote access used to administer servers, network devices, applications, security tools, or data stores.

Staff VPN and Remote Access Standards

Approved remote-access methods 

Only UCSF-approved remote-access methods may be used to access UCSF internal resources from non-UCSF networks. Staff remote access that requires a UCSF network presence must use the UCSF enterprise VPN or another UCSF-approved remote-access service.

Authorized users 

Staff VPN access is limited to workforce members with a business need for remote access and an active UCSF identity. Access must be provisioned through UCSF identity and access-management processes and must be removed when no longer required.

Authentication 

All staff VPN access must use UCSF single sign-on and UCSF-approved multi-factor authentication. Password-only VPN access is prohibited. Administrative remote access must use MFA and, where applicable, separate elevated accounts.

Device trust requirement 

UCSF-owned devices are the default and preferred method for staff VPN access. Personal devices may be used only when they comply with applicable UCSF minimum-security requirements for systems used for UCSF business, including management, encryption, endpoint protection, and other controls prescribed by UCSF IT Security.

Minimum endpoint security controls 

Any device used for staff VPN access must meet minimum security standards as defined in UCSF Policy 650-16, Addendum B: 

  • must be inventoried or otherwise identifiable in UCSF enterprise management database (CMDB) 
  • install system management software Windows = BigFix; MAC = BigFix & JAMF
  • install current enterprise endpoint security (AV) or equivalent running current definitions
  • install current Endpoint Detection & Response (EDR) Agent,
  • install Network Access Control (NAC) client
  • install host-based firewall controls where supported
  • device encryption
  • maintain Operating System patching in a timely manner
  • comply with UCSF mobile-management requirements for mobile access.

The software required to meet UCSF IT Minimum Security Standards are available for download via UCSF IT Software Download Page 

Individuals that believe their devices are unable to meet UCSF IT Minimum Security Standards must request an exception and follow the instructions available at Instructions for Security Exception Request.

Split tunneling 

Split tunneling may be used only where approved by UCSF IT and only for use cases that do not involve Restricted or Sensitive Information, privileged administration, or access to internal management planes. Full-tunnel or equivalent protected routing is required when accessing P3/P4 data, performing administrative remote access, or using workflows designated by UCSF IT Security as higher risk.

Use of web-accessible services 

Where a UCSF application is Internet-accessible and protected through UCSF SSO and MFA, VPN should not be required solely by habit. Workforce members should use the lowest-risk UCSF-approved access path that satisfies the security and business requirement.

Restricted and Sensitive Information 

Restricted and Sensitive Information transmitted over non-UCSF networks must be encrypted. Workforce members must minimize local storage of P3/P4 data on remote endpoints and must use UCSF-approved collaboration, email, file-transfer, and application services when handling such information.

Acceptable use 

Staff VPN access may be used only for legitimate UCSF business. Users must not use VPN to circumvent UCSF security controls, enable unauthorized peer-to-peer access, expose remote desktop services directly to the Internet, or route non-UCSF administrative activity through UCSF VPN in a manner inconsistent with UCSF policy.

Administrative remote access 

Remote administration of UCSF systems must use separate privileged accounts where required, must not rely on shared administrative credentials, and must be limited to approved administrative pathways. Direct Internet exposure of administrative services is prohibited unless explicitly approved and protected by compensating controls meeting UCSF and UC requirements.

** UCSF prohibits use of insecure terminal protocols (i.e., Telnet) and requires that SSH/RDP is only used via UCSF-approved VPN.

Privacy 

VPN security monitoring must be limited to the least intrusive collection, access, review, and retention necessary to protect UCSF systems and data, comply with law and policy, and support investigations. Content inspection without consent must follow applicable UC policies and UCSF procedures.

Incident reporting and response 

Suspected compromise of a remote endpoint, VPN credentials, MFA method, or remote-access session must be reported immediately to the UCSF IT Service Desk and IT Security. UCSF may suspend or revoke remote access pending investigation and remediation.

Exceptions 

Any deviation from this standard requires a UCSF IT Security Exception Request approved through the UCSF exception process. Exception requests must identify the control gap, business justification, duration, compensating controls, data classification involved, and accountable approver.

Enforcement 

Devices, accounts, or services found to be non-compliant with this standard and without an approved exception may be denied or removed from VPN or other UCSF remote-access services. Repeated or serious violations may result in additional administrative action consistent with UCSF policy.

Policy ownership and review 

Owning teams: Identity and Access Management, Network Security Services, and IT Security. 

Review authority: UCSF Chief Information Security Officer. 

Review cycle: at least annually and more frequently as security, regulatory, or operational conditions require.

  • Owning Team: IT Security
Section Menu
VPN - Remote connection
  • When Should I Use VPN?
  • VPN Web Portal
  • Palo Alto GlobalProtect VPN
  • VPN FAQs
UCSF IT homepage
  • Status
  • Services
  • How To
  • News & Events
  • About
  • IT Directory
  • Standards & Guidelines
  • Get Help
  • Recognize IT Staff

Submit a Support Inquiry

For emergencies and high priority issues please call the IT Service Desk (415) 514-4100

  • Facebook
  • Twitter
  • YouTube
  • Instagram

© 2026 The Regents of the University of California

  • Accessibility
  • Privacy Policy
  • Terms of Use
  • A-Z Website List