Standards & Guidelines
45 Results
Guideline
Access with Consent
The UC Electronic Communications Policy, Section IV, Privacy and Confidentiality, governs access to electronic communications records. In most circumstances, it is better to obtain the consent from the record holder before accessing records. However, consent is not required in every circumstance (See UCSF Implementation of the ECP - Access without Consent).
Impacted Services: IT Security Outreach and Training
Guideline
IT Enterprise Service Level Agreement (SLA)
This Service Level Agreement (hereafter referred to as "SLA") applies to all services provided by Enterprise IT ("Central IT") except where specific exceptions are noted or superseded by service-specific SLAs. For APeX, client connectivity and infrastructure support are covered by this agreement as well as first-level support provided by the Service Desk.
Standard
UCSF 650-16 Addendum B - UCSF Minimum Security Standards for Electronic Information Resources
Effective Date: December 2007, Updated February 2025
Impacted Services: IT Security Outreach and Training
Guideline
UCSF Incident Investigation Procedures
Effective Date: October 1, 2006This document provides an overview of computer incident response and investigations procedures at the University of California, San Francisco (UCSF), as mandated in UCSF Policy 650-16 Addendum C: Incident Investigation.
Impacted Services: Security Incident Response & Investigation
Standard
Exemption from IT Field Services
BackgroundExempt positionsTraineesVolunteersEmployees of affiliated organizationsExempt title codesGeographic service areaBasic science research exemptionResponsibilities of exempt users
Impacted Services: IT Desktop Field Services (IT-DFS) Support
Guideline
Criteria for Basic Support
Basic Desktop Support is available for computers and devices that meet the following criteria:
Impacted Services: IT Desktop Field Services (IT-DFS) Support
Standard
IT Field Services - Operating System Requirements
Impacted Services: IT Desktop Field Services (IT-DFS) Support , ITFS Supported Macs
Standard
UCSF 650-16 Addendum D - Wireless Networks
The use of wireless networking provides a more versatile way to access the Internet, broadening the scope of mobile computing. With the added benefits of a wireless network, there comes additional responsibility and additional risk. Authorized Users must be aware of the inherent security issues that exist in a wireless environment. Caution must be exercised to ensure a safe, secure, and reliable computing environment and reduce the risk of a security incident.
Impacted Services: IT Security Outreach and Training
Standard
The 18 Protected Health Information Identifiers
The 18 Protected Health Information (PHI) Identifiers include:
Impacted Services: IT Security Outreach and Training
Standard
UCSF 650-16 Addendum A - UCSF Roles and Responsibilities for Securing Institutional Information and IT Resources
RoleResponsibilitiesNotesCyber-risk Responsible Executive (CRE)
Impacted Services: IT Security Outreach and Training
Standard
Digital Millennium Copyright Act (DMCA)
UCSF complies with the provisions of the Digital Millennium Copyright Act (DMCA). If you have a concern regarding the use of copyrighted material on any site on the UCSF network, please contact the agent designated to respond to reports alleging copyright infringement.The current designated agent for the UCSF campus to receive notification of claimed infringement under Title II of the DMCA is on file with the U.S. Copyright Office.
Impacted Services: IT Security Outreach and Training
Standard
UCSF 650-16 Addendum C - UCSF Incident Investigation
This document outlines the requirements for information security incident investigations at the University of California, San Francisco (UCSF). Effective incident response is essential in mitigating damage and loss due to an information security incident. Proper handling minimizes the disruption to workflow and ensures compliance to federal, state, and University laws, rules, regulations, and policies. This document satisfies the requirement in BFB IS-3 Information Security for Incident Response Procedures.
Impacted Services: Security Incident Response & Investigation
Guideline
Field Services Customer Responsibilities
Customers must:
Impacted Services: IT Desktop Field Services (IT-DFS) Support
Standard
UCSF Plan for Combating Unauthorized Distribution of Copyrighted Materials
Compliance with the peer-to-peer (P2P) provisions of the Higher Education Opportunity Act (HEOA) A. Traffic monitoring B. DMCA notice response
Impacted Services: IT Security Outreach and Training
Guideline
Best Practices for Application and Website Security
By following application and website security best practices, application owners can take proactive steps to eliminate or significantly reduce vulnerabilities in software before deployment. These vulnerabilities potentially provide attackers with the ability to take control of a server or computer, which can result in the compromise of UCSF data and personal data, denial of service, loss of service or damage to a system used by thousands of users.
Impacted Services: IT Security Outreach and Training
Guideline
Physical Security Guidelines
Many information security breaches do not occur through the Internet but because the device containing information is misplaced, lost or stolen.
Standard
Unified UCSF Enterprise Password Standard
Standard has been moved to the UCSF IT Security Intranet Site.
Impacted Services: IT Security Outreach and Training
Guideline
IT Field Services - Service Level Agreement
Impacted Services: IT Desktop Field Services (IT-DFS) Support
Guideline
Recommendations for Securing Mobile Devices
The following recommendations apply to all mobile devices, including both personally and UCSF-owned mobile devices, used for UCSF business.Mobile devices include, but are not limited to:
Impacted Services: IT Security Outreach and Training
Guideline
Use of Third-party Email Systems at UCSF
Use of any 3rd-party email service by UCSF faculty, staff and learners is not approved by UCSF. This is due to:
Impacted Services: Email