Minimum Standards

hand using a pencil noting on notepad

Why Minimum Standards Matter

Minimum Standards establish a common cyber security baseline for protecting University systems, services, and data. They translate responsibilities into required actions.

If you are a System or Service Custodian, use these standards to secure the systems or services you control, manage, or support and to meet the requirements of the University Information Security Policy.

If you are a Community Member, use these standards to secure your personal devices, accounts and passwords.

Steps to Follow

The University Minimum Standards identify the actions required to protect University data, systems, and services.

  1. Determine the applicable Risk Classification.
  2. Review the standards for your role.
  3. If you manage a system or service, review All Systems and Services and each technology tab that apply.

 

This is the place to add a blurb and a link to BUT WAIT THERE'S MORE!!! e.g. Privacy, regulatory, special cases, etc.

Community Member Minimum Standards

These standards apply to Community Members who use University data, systems, or other digital resources. For the full role description, review Community Member Responsibilities.

Accounts and Passwords

University accounts and authentication credentials used for University activities.

StandardApplies ToSteps to Follow
Passwordless authentication and MFA
University accounts
Use passwordless authentication or multi-factor authentication where available.
Strong, unique passwords
University accounts that require a password
Use a strong, unique password for each University account that requires one. Use HarvardKey or another Harvard-managed authentication service where available.
Credential protection
Named University accounts
Never share passwords, MFA codes, recovery codes, access tokens, or other credentials.
 
Unexpected authentication requests
Accounts using MFA
Deny and promptly report requests you did not initiate.
Account recovery
Accounts with recovery options
Keep approved recovery information current and protect recovery codes.
Suspected compromise
University accounts
Immediately change affected credentials and report the suspected compromise.

 

 

Implementation help: Review the Accounts, Passwords, and MFA Guide. HarvardKey required.

Personal Devices

Computers, laptops, tablets, and mobile devices purchased and maintained by a Community Member.

StandardApplies ToSteps to Follow
Network access
Personal devices connecting to Harvard networks
Use the appropriate Harvard network and register the device when required.
Updates
Personal devices used for University activities
Enable automatic operating system and application updates. Do not use devices that no longer receive security updates.
Device authentication
Personal devices used for University activities
Protect the device with a strong password, PIN, or biometric.
Screen lock
Personal devices used for University activities
Configure the device to lock automatically after 15 minutes or less of inactivity.
Encryption
Personal devices used for University activities
Enable full-device encryption..
Required protections
Personal devices used for University activities
Do not disable or bypass controls required by the University.
Level 4 and Level 5 Data
All personal devices
Do not store Level 4 or Level 5 University Data on a personal device. Use an approved University system.
Application Permissions
Personal devices used for University activities
Allow applications to access only the information and device features required for an approved use.
Disposal
Personal devices used for University activities
Remove University Data, accounts, applications, and stored credentials before sale, transfer, recycling, or disposal. Securely erase the device using an approved method.
University-Owned Devices
Devices purchased by the University
Remove University data, accounts, applications, and credentials before selling, transferring, recycling, or disposing of a personal device. Return University-owned devices to the responsible IT organization.

 

Implementation help: Review the Personal Device Security Guide and Secure Device and Media Disposal Guide. HarvardKey required.

University Data

University Data in electronic, printed, audio, visual, or other formats.

StandardApplies ToSteps to Follow
Minimum necessary
All University Data
Access, collect, use, and retain only the information necessary for an approved University purpose.
Approved systems
All University Data
Store and process University data only in systems and services approved for its Risk Classification.
Secure sharing
Levels 2–5
Share only with authorized people who need the information for a University purpose.
Public access
Levels 2–5
Do not make Confidential Information publicly accessible or use unrestricted sharing links.
Secure transmission
Levels 3–5
Use approved encrypted University systems to transmit or share information.
Removable media
University Data stored on removable media
Use removable media only when permitted and use approved encryption and access protection appropriate to the Risk Classification.
Printing and scanning
Levels 3–5
Use an approved printing or scanning service. Retrieve output promptly, verify scan destinations, remove originals, and report misdirected or exposed jobs.
Physical records
Printed or other physical records
Secure records when unattended and use locked storage where appropriate.
Retention and disposal
All University Data
Retain information only as long as required by the General Records Schedule, law, contract, research requirements, or business need.
Secure Disposal
All University Data
Follow the General Records Schedule and securely delete or destroy information when it is no longer required.

 

Implementation help: Review additional Data Handling Guidance.

Incident Reporting

Promptly report suspected or confirmed security and privacy incidents.

StandardApplies ToSteps to Follow
Report promptly
All incidents
Report suspected or confirmed security and privacy incidents immediately.
Examples
All incidents
Lost or stolen devices or records; phishing; unexpected MFA prompts; unauthorized access; accidental disclosure; malware; or unusual system behavior.
Preserve information
All incidents
Preserve relevant messages, logs, records, or device information and cooperate with response activities.

 

Implementation help: Review Incident Reporting or Phishing Reporting procedures.

System or Service Custodian Minimum Standards

Custodians must meet the Community Member Minimum Standards and the standards below. The Custodian remains accountable for ensuring the standards are met, including when implementation is performed by another Harvard team, vendor, or service provider. Review the System or Service Custodian Responsibilities page for additional details.

All Systems and Services

These standards apply to each University system or service managed by a Custodian.

Implementation help: Review the System or Service Custodian Implementation Guide. HarvardKey required.

Asset Types

In addition, these requirements apply to specific technology asset types.

Endpoints

Laptops, desktops, mobile devices, and other University managed endpoints.

StandardApplies whenSteps to Follow
Device management
All risk levels
Enroll supported devices in the approved management platform and enforce required configuration profiles.
Encryption
All risk levels
Enable full-device encryption. Level 4-5 endpoint storage is not authorized by this requirement; follow Data Handling and any separately approved environment requirements.
Firewall
All risk levels
Enable and manage the host firewall.
Secure destruction
All risk levels
Sanitize or destroy data and storage before reassignment, repurposing, return, or disposal.
Backup
Levels 3-5 or when continuity requires it
Back up required data and configurations consistent with documented continuity requirements.

 

Implementation help: Review the Devices section of the System or Service Custodian Guide. HarvardKey required.

Printers

Printing and scanning devices that process University Data. 

RequirementApplies ToSteps to Follow
Permissions
Managed printers and multi-function devices
Restrict administrative and network access and require authentication for protected printing and scanning.
Secure transmission and destinations
Protected print and scan workflows
Encrypt traffic. Restrict scanning to authenticated University mailboxes and approved secure storage. Block unauthenticated, external, and guest fallback destinations.
Stored jobs and scans
Devices that temporarily store jobs
Delete completed and held jobs within 2 hours. Delete failed, abandoned, or expired jobs immediately where possible and no later than 24 hours.
Secure release
Print jobs containing Confidential Information
Require release by an authorized user at the device or through another approved secure-release method.
Secure disposal
Devices containing internal storage
Sanitize or destroy internal storage before return, transfer, reuse, or disposal.
Unmanaged Printers
Any device not integrated with central identity and firmware management, or operating on a guest or unsegmented network
Configure to protect Confidential Information. No Level 4 printing.

 

Implementation help: Review the Configure and Manage Printers Guide. HarvardKey required.

Servers

Physical, virtual, on-premises, and cloud-hosted servers.

StandardApplies whenSteps to Follow
Encryption at rest
Servers at Levels 3-5
Encrypt University Data at rest.
Secure destruction
Servers, all risk levels
Sanitize or destroy storage before repurposing or decommissioning.
Backup
Servers at Levels 3-5 when continuity requires it
Back up required systems, configurations, and data.
Recovery validation
Servers at Levels 4-5
Periodically test recovery and confirm restoration within required timeframes.
Firewall
Servers, all risk levels
Implement and manage a host or network firewall.
Outbound traffic
Servers at Levels 4-5
Restrict outbound traffic to approved destinations and required services.
Private addressing
Servers at Levels 4-5
Use private IP addressing unless an approved design requires public exposure.
Physical access
Servers at Levels 3-5
Restrict physical access to server rooms, racks, consoles, and related infrastructure.
Separate log collection
Servers at Levels 3-5
Send relevant logs to a collection system separate from the source system.
Administrative sessions
SSH, RDP, console, and equivalent access
End inactive sessions after 15 minutes and require reauthentication after 8 hours maximum.

 

Implementation help: Review the Servers section of the System or Service Custodian Guide. HarvardKey required.

Applications

Custom applications, vendor applications requiring configuration, APIs, connectors, plugins, integrations, and research platforms.

StandardApplies whenSteps to Follow
Authentication and authorization
Non-public applications and APIs, all risk levels
Authenticate users or services and enforce server-side authorization for every protected function and resource.
Encryption at rest
Applications at Levels 3-5
Encrypt University Data at rest.
Input and output protection
Applications and APIs, all risk levels
Validate requests and input, protect output, and do not expose sensitive information in errors.
Web Application Firewall
Web applications at Levels 3-5, where available
Use a Web Application Firewall or approved equivalent protection.
Denial-of-service protection
Applications at Levels 4-5
Apply appropriate denial-of-service and abuse protections.
Separate log collection
Applications at Levels 3-5
Send relevant logs to a collection system separate from the source system.
API credentials
APIs using keys or tokens
Use scoped, expiring credentials and do not place secrets in source code, URLs, logs, or client-side applications.
API abuse protection
Externally accessible or high-volume APIs
Apply rate limiting, quotas, throttling, or an approved equivalent.
API lifecycle
Production APIs
Document ownership, consumers, versions, support dates, deprecation, and endpoint retirement.

 

Implementation help: Review the Applications section of the System or Service Custodian Guide. HarvardKey required.

SaaS

Software-as-a-Service and other provider-hosted applications.

StandardApplies whenSteps to Follow
Administrative controls
All SaaS
Use named administrators, Harvard-managed authentication where supported, MFA, and least privilege.
External sharing
SaaS that supports sharing
Disable anonymous access and unrestricted public links unless specifically required and approved.
Audit logging
SaaS where logs are available
Enable authentication, administrative, sharing, security, and configuration logs.
Procurement and contract terms
All SaaS acquisitions or renewals
Consult the appropriate University procurement team and include required security, privacy, data-use, incident-notification, return, and destruction terms.
Risk assessment
SaaS at Levels 3-5 or otherwise enhanced risk
Complete the required assessment before contract execution or service use.
Data destruction
All SaaS at contract or service end
Confirm return or secure destruction of University Data and retain evidence when required.
Denial-of-service protection
SaaS at Levels 4-5
Confirm the provider supplies appropriate denial-of-service protection.

Implementation help: Review the SaaS and Cloud sections of the Custodian Implementation Guide. HarvardKey required.

IaaS

AWS, Azure, Google Cloud, and other infrastructure or platform services.

StandardApplies ToSteps to Follow
Administrative controls
All IaaS/PaaS
Use named administrators, MFA, least privilege, roles or managed identities, and approved secrets management where required.
Cloud audit logging
All IaaS/PaaS
Enable provider audit and administrative logging across all accounts, subscriptions, projects, or equivalent environments.
Public administrative access
All IaaS/PaaS
Do not expose SSH, RDP, management consoles, or equivalent administrative services directly to the Internet unless specifically approved.
Private addressing
IaaS/PaaS at Levels 4-5
Use private IP addressing for applicable resources unless an approved design requires public exposure.
Procurement and contract terms
All contracted IaaS/PaaS
Consult the appropriate University procurement team and include required terms.
Risk assessment
IaaS/PaaS at Levels 3-5 or otherwise enhanced risk
Complete the required assessment before contract execution or service use.
Data destruction
All contracted IaaS/PaaS at service end
Confirm return or secure destruction of University Data and retain evidence when required.

Implementation help: Review the SaaS and Cloud sections of the Custodian Implementation Guide. HarvardKey required.

Networks

Switches, routers, firewalls, wireless access points, VPN gateways, network-management systems, and related infrastructure.

StandardApplies ToSteps to Follow
Administrative Access
All network infrastructure
Restrict management interfaces to authorized administrators and approved management networks.
Firewall Rules
Firewalls and network controls
Allow only traffic required for an approved purpose; use least-access or default-deny principles where appropriate.
Segmentation
Sensitive or specialized environments
Separate user, server, administrative, IoT, research, and other environments according to risk.
Public Administrative Access
All network infrastructure
Do not expose management interfaces directly to the Internet unless specifically approved.
Wireless Security
University wireless infrastructure
Use approved enterprise wireless-security protocols.
Rogue Device Detection
Environments where required
Detect and respond to unauthorized network devices and wireless access points.
Configuration Logging
All network infrastructure
Log administrative access and configuration changes.
Remote Administration
All network infrastructure
Use approved encrypted protocols, MFA, and secure access paths.
Session Limits
VPN and network administration
End after 15 minutes of inactivity and require reauthentication after 8 hours maximum.
Configuration Backup
Network infrastructure
Securely back up critical configurations and test restoration.

Implementation help: Review the Networks section of the Custodian Implementation Guide. HarvardKey required.


THE CONTENT BELOW IS IN PROCESS OF BEING REWORKED.

Why Privacy Matters in Applying Standards

At Harvard, we are dedicated to safeguarding personal data. Securing technology assets is an important step but not all that is required. Certain information, including health and financial data, may require additional steps to comply with a law and/or regulation.

For additional guidance and training, visit the Privacy Principles page.

Sometimes contracts, laws, university rules, or system limits mean we have to use extra or different protections than our usual standards. View examples and guidance to help you recognize and handle these situations correctly.

This section to be removed.

Researchers should also review OVPR Research Data Management guidance. Contractual, legal, institutional, or system requirements may require additional or different safeguards.

Related Resources

Use these resources to take the next step, find University guidance, or explore trusted external references.