View this email in a browser

UTA Information Security Office

 

 

February 16, 2023

Dear UTA Students, Faculty, and Staff,

UTA has been taking steps to follow Gov. Greg Abbott’s Dec. 7 directive to state agencies to ban the video-sharing application TikTok from all university-owned and state-issued devices and networks due to potential international government surveillance risks. To comply, the University has been restricting access to the app on UTA-owned computing devices and UTA wired and wireless networks.

Last week, the governor’s office issued a statewide model security plan that provided guidance on managing personal devices used to conduct state business and expanded the list of prohibited technologies. All state agencies, including The University of Texas at Arlington, were directed to develop their own prohibited technologies security policy and submit it to the state. UTA’s new standard, which took effect Feb. 15, 2023, can be found in the Handbook of Operating Procedures Information Security and Acceptable Use Policy.

As University leadership continues to evaluate the best ways to substantially comply with the model security plan, we want to be transparent about the plan’s impact on the UTA community. Here’s what you need to know.

How does the new policy affect me?

The model security plan provides guidance on University-owned devices; personal devices belonging to faculty, staff, and students; and locations where sensitive information could be accessed.

  • Excluding specific approved exceptions, the use or download of these listed applications or technologies is prohibited on all University-owned devices, including cellphones, tablets, desktop and laptop computers, and other internet-capable devices.
  • Employees and contractors may not install or operate prohibited applications or technologies on any personal device that is also used to conduct University business, in accordance with UTA’s Acceptable Use Policy. University business includes accessing any University-owned data, applications, email accounts, nonpublic-facing communications, state email, VoIP, SMS, video conferencing, CAPPS, Texas.gov, and any other state databases or applications. For example, if you check your UTA employee email account on a personal device, you cannot download prohibited technologies to that device.
  • Unauthorized devices such as personal cellphones, tablets, or laptops may not enter sensitive locations, which includes any electronic meeting labeled as a sensitive location. A sensitive location is any location, physical or digital, that is used to discuss confidential or controlled information, as defined by the Information Security Office’s Data Classification Standard.

What are the prohibited technologies?

The up-to-date list of prohibited technologies is published at https://dir.texas.gov/information-security/prohibited-technologies.

As of Jan. 23, 2023, prohibited software, applications, and developers include:

  • TikTok
  • Kaspersky
  • ByteDance Ltd.
  • Tencent Holdings Ltd.
  • Alipay
  • CamScanner
  • QQ Wallet
  • SHAREit
  • VMate
  • WeChat
  • WeChat Pay
  • WPS Office
  • Any subsidiary or affiliate of an entity listed above

 Prohibited hardware, equipment, and manufacturers include:

  • Huawei Technologies Company
  • ZTE Corporation
  • Hangzhou Hikvision Digital Technology Company
  • Dahua Technology Company
  • SZ DJI Technology Company
  • Hytera Communications Corporation
  • Any subsidiary or affiliate of an entity listed above

Why is UTA doing this?

The University is taking these important steps to help address vulnerabilities presented by the use of TikTok and other technologies on personal and state-issued devices. These measures help protect both information contained in the University’s network and our critical infrastructure from potential international government surveillance risks.

What if I need to use a prohibited technology for research, course instruction, or class work?

The governor’s directive allows for exceptions to the policy to be directed by the agency head. Exceptions to the policy may be considered when the use of prohibited technologies is required for a specific business need. The University has requested exceptions for teaching and research, which are still pending with the University of Texas System.

We are appreciative of the UTA community’s understanding and flexibility as we work through these changes. For questions regarding the University’s new standard on prohibited technologies, please contact the Information Security Office at security@uta.edu.

Sincerely,

Cheryl Nifong
Chief Information Security Officer

Deepika Chalemela
Chief Information Officer

-

 

 

Information Security Office

The University of Texas at Arlington

Box 19800 • Arlington, TX 76019

security@uta.edu

Phone: 817-272-5487 • Fax: 817-272-2612