A knowledge base article about Best Practices for Telecommuting Securely provided by the UC Berkeley IT Service Hub - Knowledge Portal
Please note: Personally-owned computers used by multiple people in the household are unlikely to meet the Campus Minimum Security for Networked Devices (MSSND) Standard. Risks to consider with home systems include:
Therefore, we highly recommend that remote workers use university-owned and managed equipment when working from home.
If you do not have a work computer and need to access highly sensitive (P4) data, please contact security@berkeley.edu.
Using a personally-owned device for university business puts both you and the campus at risk. If you do not have a work computer to use at home, you must follow the practices listed below.
Update everything on your devices, including operating systems, web browsers, and apps. Enable automatic updates on Microsoft Windows and macOS to ensure vulnerabilities are patched promptly.
Install anti-malware software and enable a firewall on your devices. Default firewall settings are usually acceptable for current Macs and PCs, but verify that they are turned on.
Do not use public Wi-Fi when logging into campus systems. Use the Campus Virtual Private Network (VPN) or your phone as a personal hotspot instead.
Note for VPN use: When accessing enterprise systems with moderate to high data classification (BFS, Blu, CalCentral, etc.), connect to the Full Tunnel. For general tasks like email or Zoom, use the Split Tunnel to reduce system load.
Sensitive or notice-triggering data must not be stored on portable devices unless absolutely necessary and strongly encrypted.
Approved backup locations vary by data classification. Certain data can be backed up using bConnected collaboration services. If using external drives, ensure they are encrypted and unplugged after the backup is complete.
Never leave your device unattended. Always lock your doors and never leave your device in a vehicle—not even in the trunk.
Lock up your laptop when you step away, even at home. Physical incidents can happen, and securing your equipment is a primary baseline defense.
Create strong passphrases (multiple words). Use a unique passphrase for every device. We recommend using a password manager to store these securely. UC Berkeley offers Free LastPass Premium to faculty, staff, and students.
Configure your desktop to automatically lock after 15 minutes of inactivity. Set your mobile phone to lock after no more than 15 minutes (shorter is better).
When using public phone charging stations, use a USB data blocker to prevent unauthorized data exchange and protect your device from malware.