MSSND: How to Secure Personally-Managed Devices

A knowledge base article about MSSND: How to Secure Personally-Managed Devices provided by the UC Berkeley IT Service Hub - Knowledge Portal

Table of Contents

Overview

If you have a personally-managed Windows, Mac, iOS, or Android device that needs to comply with the Minimum Security Standards for Networked Devices (MSSND), follow the instructions below to configure your device to meet campus policy. Find additional details and instructions on our website.


MSSND #1: Patching and Updates

Upgrade your operating system and applications to the latest versions to take advantage of built-in security features.

Operating System Updates

Mobile Device Updates

Supported Software

Ensure applications like Microsoft Office, Google Chrome, Firefox, and Zoom are kept up to date by following update prompts immediately.


MSSND #2: Anti-malware Software

Enable built-in anti-malware features to detect and block malicious software.


MSSND #3: Host-based Firewall Software

Turn on the built-in host-based firewall to block unauthorized network traffic.

Enable Firewalls

Firewall Logging


MSSND #4: Use of Authentication

There are no actions needed for this requirement beyond maintaining your standard secure login.


MSSND #5: Passphrase Requirements


MSSND #6: Device Lock-out

Configure your devices to automatically lock the screen after 15 minutes of inactivity.


MSSND #7: Unnecessary Services

No actions needed for this requirement.


MSSND #8: Remote Access Services

If you need remote access from off-campus, use an Approved Campus Remote Access Service. All remote access must comply with the MSSND #8 Guidelines.


MSSND #9: Privileged Accounts

Do not use an Administrator account for daily activity. Create a separate, "Standard" user account for routine work.