This content is viewable by Everyone
Standard
UCSF 650-16 Addendum H — Staff VPN and Remote Access Standard
- Effective Date:
-
Impacted Services VPN - Remote connection, Palo Alto GlobalProtect VPN
Purpose
To establish and set the requirements for standard staff remote access to UCSF networks, systems, and applications using UCSF-approved VPN and related remote-access services.
Table of Contents
- Overview and Scope
- Definitions
- Staff VPN and Remote Access Standards
- Privacy
- Incident reporting and response
- Exceptions
- Enforcement
- Policy ownership and review
Overview and Scope
This standard applies to all UCSF workforce members using remote-access methods to connect to UCSF networks, systems, applications, or data, including workforce members using non-UCSF devices for UCSF business. This standard applies to both routine staff access and administrative remote access performed by UCSF personnel. Third-party remote access remains governed by UCSF 650-16 Addendum G.
Definitions
Use the UC Systemwide IT Policy Glossary for standard terms. For this addendum:
- Staff VPN means the UCSF enterprise VPN service approved by UCSF IT for workforce-member remote access.
- Managed Device means a UCSF-owned endpoint enrolled in UCSF-prescribed management and security tooling.
- Compliant Personal Device means a non-UCSF endpoint that meets applicable UCSF minimum-security requirements before it is used for UCSF business or VPN access.
- Restricted and Sensitive Information means institutional information classified as P4 or P3.
- Elevated Administrative Access means privileged remote access used to administer servers, network devices, applications, security tools, or data stores.
Staff VPN and Remote Access Standards
Approved remote-access methods
Only UCSF-approved remote-access methods may be used to access UCSF internal resources from non-UCSF networks. Staff remote access that requires a UCSF network presence must use the UCSF enterprise VPN or another UCSF-approved remote-access service.
Authorized users
Staff VPN access is limited to workforce members with a business need for remote access and an active UCSF identity. Access must be provisioned through UCSF identity and access-management processes and must be removed when no longer required.
Authentication
All staff VPN access must use UCSF single sign-on and UCSF-approved multi-factor authentication. Password-only VPN access is prohibited. Administrative remote access must use MFA and, where applicable, separate elevated accounts.
Device trust requirement
UCSF-owned devices are the default and preferred method for staff VPN access. Personal devices may be used only when they comply with applicable UCSF minimum-security requirements for systems used for UCSF business, including management, encryption, endpoint protection, and other controls prescribed by UCSF IT Security.
Minimum endpoint security controls
Any device used for staff VPN access must meet minimum security standards as defined in UCSF Policy 650-16, Addendum B:
- must be inventoried or otherwise identifiable in UCSF enterprise management database (CMDB)
- install system management software Windows = BigFix; MAC = BigFix & JAMF
- install current enterprise endpoint security (AV) or equivalent running current definitions
- install current Endpoint Detection & Response (EDR) Agent,
- install Network Access Control (NAC) client
- install host-based firewall controls where supported
- device encryption
- maintain Operating System patching in a timely manner
- comply with UCSF mobile-management requirements for mobile access.
The software required to meet UCSF IT Minimum Security Standards are available for download via UCSF IT Software Download Page
Individuals that believe their devices are unable to meet UCSF IT Minimum Security Standards must request an exception and follow the instructions available at Instructions for Security Exception Request.
Split tunneling
Split tunneling may be used only where approved by UCSF IT and only for use cases that do not involve Restricted or Sensitive Information, privileged administration, or access to internal management planes. Full-tunnel or equivalent protected routing is required when accessing P3/P4 data, performing administrative remote access, or using workflows designated by UCSF IT Security as higher risk.
Use of web-accessible services
Where a UCSF application is Internet-accessible and protected through UCSF SSO and MFA, VPN should not be required solely by habit. Workforce members should use the lowest-risk UCSF-approved access path that satisfies the security and business requirement.
Restricted and Sensitive Information
Restricted and Sensitive Information transmitted over non-UCSF networks must be encrypted. Workforce members must minimize local storage of P3/P4 data on remote endpoints and must use UCSF-approved collaboration, email, file-transfer, and application services when handling such information.
Acceptable use
Staff VPN access may be used only for legitimate UCSF business. Users must not use VPN to circumvent UCSF security controls, enable unauthorized peer-to-peer access, expose remote desktop services directly to the Internet, or route non-UCSF administrative activity through UCSF VPN in a manner inconsistent with UCSF policy.
Administrative remote access
Remote administration of UCSF systems must use separate privileged accounts where required, must not rely on shared administrative credentials, and must be limited to approved administrative pathways. Direct Internet exposure of administrative services is prohibited unless explicitly approved and protected by compensating controls meeting UCSF and UC requirements.
** UCSF prohibits use of insecure terminal protocols (i.e., Telnet) and requires that SSH/RDP is only used via UCSF-approved VPN.
Privacy
VPN security monitoring must be limited to the least intrusive collection, access, review, and retention necessary to protect UCSF systems and data, comply with law and policy, and support investigations. Content inspection without consent must follow applicable UC policies and UCSF procedures.
Incident reporting and response
Suspected compromise of a remote endpoint, VPN credentials, MFA method, or remote-access session must be reported immediately to the UCSF IT Service Desk and IT Security. UCSF may suspend or revoke remote access pending investigation and remediation.
Exceptions
Any deviation from this standard requires a UCSF IT Security Exception Request approved through the UCSF exception process. Exception requests must identify the control gap, business justification, duration, compensating controls, data classification involved, and accountable approver.
Enforcement
Devices, accounts, or services found to be non-compliant with this standard and without an approved exception may be denied or removed from VPN or other UCSF remote-access services. Repeated or serious violations may result in additional administrative action consistent with UCSF policy.
Policy ownership and review
Owning teams: Identity and Access Management, Network Security Services, and IT Security.
Review authority: UCSF Chief Information Security Officer.
Review cycle: at least annually and more frequently as security, regulatory, or operational conditions require.
- Owning Team: IT Security