Collaboration is essential to the university’s mission, and technology makes it easier for us to work together. But that convenience comes with an important responsibility: making sure the right people—and the right technology—have access to university information.
In other words, who has the keys to your digital work?
Protecting your accounts, devices, and other tools helps prevent university information from being accessed, copied, changed, or deleted without authorization. Equally important is managing who has access to information and what they are allowed to do with it.
Here are a few everyday habits that can make a difference:
- Use your own account to access documents, tools, and systems.
- Keep your password private.
- Never approve a Duo authentication request you didn’t initiate.
- Don’t share your account with someone who needs access. Instead, use approved sharing methods so they can sign in as themselves.
- Review access when people join a team, change roles, or leave the university. This includes student employees and temporary collaborators. Check account permissions, shared folders, and group memberships.
- Remove access that is no longer needed. Work with supervisors and IT to transfer file ownership so important work isn’t lost or interrupted.
Don’t forget about outside tools
Access isn’t limited to people. External companies, software, and connected applications also may have access to university systems or information. Before adopting a new tool or granting vendor access, contact your local IT team and the Information Security and Policy Office (ISPO). They can help determine what access is necessary and what university information it can reach.
Some access requires extra care
Certain university staff and applications need greater levels of access to do their jobs. Sometimes this is called privileged access.
This access may allow them to install software, change security settings, manage accounts, or erase devices. Because misuse or compromise of that access could affect an entire team or system, people should receive only the permissions necessary to complete assigned tasks. Employees who administer university systems should also use separate administrator accounts and service IDs and, where supported, require additional approval for actions that could have a significant impact.
Carefully managing access helps protect university information and the people who rely on our services.
When something doesn’t seem right
Report all IT security incidents—including possible account or system compromises, misuse, or unintended disclosure of information—to ISPO at it-security@uiowa.edu or 319-335-6332.
You don’t need to be certain there’s an issue before asking for help. Contact ISPO right away so the team can investigate and help limit potential harm.
Campus partners can also contact ISPO for guidance on securely meeting their business, teaching, research, and operational needs.