Purpose: Pittsburg State University (PSU) provides network infrastructure to support academic, administrative, research, and student activities. To ensure availability, integrity, and security of institutional systems and data, all devices, systems, and services connected to the PSU network must comply with this policy and applicable security standards.
This policy is aligned with modern security principles including least privilege, Zero Trust architecture, and continuous monitoring.
Applies to: Faculty, staff, students, official university affiliates, and any other individuals who use Pittsburg State University information technology resources.
Definitions:
- Device: Any endpoint or equipment capable of connecting to the PSU network, including but not limited to desktops, laptops, servers, mobile devices, IoT devices, and network infrastructure equipment.
- Service: Any application, system, or process that transmits, processes, or receives data over the network, including cloud-hosted services.
- PSU Network: All wired, wireless, and remote-access network connections operated or managed by PSU, including connections to external providers (e.g., KANREN, Internet, cloud services).
- ITS: Information Technology Services, responsible for network governance, security, and operations.
Statement:
Pittsburg State University (PSU) provides network infrastructure to support academic, administrative, research, and student activities. To ensure availability, integrity, and security of institutional systems and data, all devices, systems, and services connected to the PSU network must comply with this policy and applicable security standards.
This policy is aligned with modern security principles including least privilege, Zero Trust architecture, and continuous monitoring.
Policy:
A. Network Access and Device Authorization
1. Approval and Registration
All devices and services connecting to the PSU network must:
- Be approved and registered with ITS prior to connection.
- Meet minimum security baseline requirements (e.g., supported OS, patching, endpoint protection).
- Be assigned network identification through approved methods (e.g., DHCP, IPAM, NAC systems).
- Connection to the GusNet Guest does not require approval or registration but should meet other requirements.
2. Technical Standards
ITS is responsible for:
- Defining and enforcing network architecture, segmentation, and security controls.
- Managing network configuration services (e.g., DHCP, DNS, IP addressing).
- Establishing standards for:
- Wired and wireless connectivity
- Encryption protocols (e.g., WPA3, TLS)
- Authentication methods (e.g., MFA, 802.1X)
3. Access Control and Monitoring
- All network access is subject to authentication, authorization, and logging.
- PSU reserves the right to monitor, inspect, and analyze network traffic to ensure:
- Security
- Compliance
- Operational integrity
- Monitoring will be conducted in accordance with applicable laws and university policies.
4. Right to Restrict or Disconnect
ITS may limit, quarantine, or disconnect any device or service that:
- Presents a security risk (e.g., malware, vulnerability exploitation)
- Causes network disruption or degradation
- Violates university policy or legal requirements
B. Network Security Requirements
1. Prohibited Activities
Devices and services may not:
- Intercept, monitor, or capture network traffic without explicit authorization (e.g., approved security tools).
- Circumvent network security controls (e.g., firewalls, NAC, VPN requirements).
- Provide unauthorized network services (e.g., rogue DHCP, access points, VPNs, switches).
2. Endpoint Security
All devices must:
- Maintain current security updates and patches.
- Use approved endpoint protection solutions.
- Support centralized management or compliance verification, when applicable.
3. Wireless and Personal Devices (BYOD)
- Personal and unmanaged devices must connect through designated network segments (e.g., guest or BYOD networks).
- Access to sensitive institutional resources may require:
- Device compliance checks
- Multi-factor authentication
- Managed device enrollment or registration
4. Cloud and Remote Services
- All externally hosted services (SaaS, IaaS, PaaS) must be:
- Reviewed through the PSU IT procurement process (e.g., SOC2, HECVAT)
- Approved prior to transmitting or storing institutional data
- Remote access to PSU systems must use secure methods (e.g., VPN, Zero Trust access solutions).
C. Department-Managed Systems and Services
Departments operating their own systems must:
1. Responsibilities
- Designate a system owner/administrator (must be a PSU employee).
- Ensure systems meet security and compliance requirements (NIST CSF, FERPA, PCI DSS, etc., where applicable).
- Control authorized access to the server or system.
- Run supported operating systems.
- Utilize approved endpoint protection and EDR solutions (where applicable)
- Support compliance validation (e.g., MDM, posture checks).
- Maintain:
- Logging and monitoring
- A defined patch management schedule
- Awareness of and address known security vulnerabilities
2. ITS Coordination
- Work with ITS for:
- Network integration and segmentation
- Firewall and routing configuration
- Security review and approval
3. Administrative Access
- Provide ITS with appropriate administrative or audit-level access, as required for:
- Incident response
- Security validation
- Compliance review
4. Cost Responsibility
Departments may be responsible for additional infrastructure or security costs required to meet compliance standards.
D. Network Segmentation and Isolated Systems
1. Systems not connected to the PSU network (standalone or isolated networks):
- Are not supported by ITS unless formally approved.
- Must not be bridged or connected to the PSU network without prior authorization.
2. If an isolated network is later connected:
- All systems within that network become subject to this policy and must meet compliance requirements.
Consequences
Failure to comply with this policy may result in immediate disconnection from the network, suspension of network access privileges, and/or disciplinary action, up to and including termination in accordance with university policy and any applicable labor agreements.
Contact:
Angela Neria
153 Kelce Center
1701 South Broadway, Pittsburg, KS 66762
Phone: (620) 235-4600
e-mail: its@pittstate.edu
Website
Review cycle: Annually
Change history:
- Updated: 06-24-2026, Updated policy to to align with current security practices and compliance requirements