| Topic: | Employees, Employment and Workplace |
|---|---|
| Approval Authority: | President and Vice-Chancellor |
| Approval Date: | June 2, 2026 |
| Effective Date: | June 2, 2026 |
1. Purpose
York University provides computing devices to support teaching, research, and administrative operations. In response to increasingly evolving cyber threats as well as regulatory, research and contractual obligations, the University must ensure that all University-owned computing devices meet baseline security requirements, as determined by the University or by regulatory requirements, and are managed consistently throughout their lifecycle.
This Procedure establishes the governance framework for the secure use, management, and protection of University-owned computing devices. It ensures compliance with university policies, privacy legislation, research security requirements, and sectoral best practices.
2. Scope and Application
This Procedure applies to all individuals who are assigned a University-owned computing device regardless of funding source, location, or user role (faculty, staff, researcher, administrator, or contractor). Devices personally owned by individuals are not covered by this Procedure, but their use for university business is governed by the Information Security Policy and related standards.
3. Definitions
Assigned User
Individual faculty, staff, researcher, administrator, or contractor who is assigned a university-owned computing device.
University-owned Computing Device
A computing device purchased, leased, or otherwise owned by York University for use by an Assigned User in teaching, research, or administrative activities.
Managed Device
A University owned computing device enrolled in a University-approved device management platform to receive security configurations, updates, and protections required to safeguard University data and systems.
Limited Managed Device
A managed device where the Assigned User retains local administrator privileges due to academic, research, or operational requirements.
Fully Managed Device
A managed device where the Assigned User does not have local administrator privileges. This model is typically used for administrative and high-risk environments.
Security Baseline Standard
The minimum configuration standards required to protect University systems and data, including encryption, malware protection, operating system patching, identity controls, and configuration monitoring.
4. Roles and Responsibilities
4.1 University Information Technology (UIT)
UIT is responsible for maintaining this Procedure and related standards. This includes:
- Selecting and operating device management platforms. Defining and maintaining Security Baseline Standard Compliance.
- Ensuring managed devices receive required configurations and updates. Maintaining central asset inventory system.
- Supporting assigned users and providing secure lifecycle management.
4.2 Faculty IT Units
Faculty IT units are responsible for:
- Supporting Assigned Users in their faculty in meeting University security requirements.
- Implementing software and hardware standards in their areas, including specialized research needs.
- Coordinating, reviewing and approving exceptions to the Security Baseline Standard where unique academic or research requirements necessitate alternative approaches.
4.3 Assigned Users
Assigned Users are responsible for:
- Using University-owned computing devices in accordance with this Procedure.
- Maintaining physical security of University-owned computing devices.
- Reporting incidents, loss, or suspected tampering promptly to UIT and in the case of theft, Community Safety.
- Refraining from attempting to circumvent device management or security controls.
4.4 Academic and Administrative Leaders
Where relevant, leaders are responsible for:
- Supporting compliance within their units.
- Approving specialized device requirements where necessitated by academic, research, or operational needs.
5. Procedures
5.1 Managed Device Enrolment
All University-owned computing devices must be enrolled in a University-approved device management platform appropriate to the device type and operating system. Devices must maintain compliance with the University’s Security Baseline standard.
5.2 Security Baseline Compliance
Managed devices will automatically receive updates, patches, and security configurations. Assigned users must not disable, remove, or circumvent security controls.
6. Principles
6.1 Security First
All University-owned computing devices must be configured, monitored, and maintained to safeguard the confidentiality, integrity, and availability of university data and systems.
6.2 Privacy and Academic Freedom
The University is committed to protecting the privacy of its faculty, staff, researchers, administrators, and contractors. Device management platforms do not provide IT with the ability to track or provide access to files, research materials, email, browsing history, or other personal content. Remote support may only occur with explicit Assigned User consent. Device management does not monitor Assigned User activity.
6.3 Consistency and Lifecycle Management
Devices must be procured, managed, supported, and disposed of following University standards to ensure security, reliability, and cost effectiveness.
6.4 Accountability
Roles and responsibilities for management of university-owned computing devices are shared among UIT, Faculty IT units and Assigned Users (being faculty, staff, researchers, administrators and contractors).
7. Use of University-owned Computing Devices
University-owned computing devices must be used primarily for university-related activities. Limited incidental personal use is permitted, provided it does not interfere with university operations, violate policy, or compromise security.
7.1 Use of Personal Computing Devices
Personal devices may not be used for high-risk or restricted University activities and may not be substituted for required University-owned devices in circumstances where compliance with the Security Baseline Standard is necessary.
7.2 Protection and Reporting
Assigned Users must take reasonable steps to prevent loss, theft, or unauthorized use of University-owned devices. Assigned Users must promptly report loss, theft, or suspected security incidents to UIT and in the case of theft, Community Safety.
7.3 Configuration Integrity
Any attempt by Assigned Users to circumvent security controls including unenrollment from management platforms, disabling protective tools, or altering security baseline compliance may result in restricted access to university resources until the device is restored to Security Baseline Standard compliance.
8. Compliance and Exceptions
8.1 Compliance Monitoring
UIT will use authorized management tools to identify University-owned computing devices that fall out of compliance with the Security Baseline Standard. UIT will make reasonable efforts to contact the Assigned User and restore compliance.
8.2 Non-Compliance
Where noncompliance is due to technical issues outside the Assigned User’s control, UIT will remediate the device and restore normal operation. Where noncompliance results from intentional circumvention of security controls or negligence, access to certain University IT services may be restricted until compliance is restored. Further action will be taken in accordance with applicable University policies and if applicable, collective agreement terms and conditions.
8.3 Exceptions
Exceptions may be granted only in limited circumstances where specific academic, research, or technical requirements cannot be met through standard device management. Exception requests must be submitted through the approved University process and require UIT and Faculty IT review and approval.
9. Device Disposal and Decommissioning
University-owned computing devices must be returned to UIT or Faculty IT units at the device’s end-of-life or when no longer required. Devices may not be independently disposed of by Assigned Users. UIT or Faculty IT units will securely dispose of University-owned computing devices following applicable University procedures.
| Legislative History: | Approved by the President June 2, 2026 |
|---|---|
| Date of Next Review: | May 2031 |
| Related Policies, Procedures and Guidelines: | This Procedure operates in accordance with the: |
