Use and Security of University-Owned Computing Devices, Procedure on

Topic: Employees, Employment and Workplace
Approval Authority: President and Vice-Chancellor
Approval Date: June 2, 2026
Effective Date: June 2, 2026

1. Purpose

York University provides computing devices to support teaching, research, and administrative operations. In response to increasingly evolving cyber threats as well as regulatory, research and contractual obligations, the University must ensure that all University-owned computing devices meet baseline security requirements, as determined by the University or by regulatory requirements, and are managed consistently throughout their lifecycle.

This Procedure establishes the governance framework for the secure use, management, and protection of University-owned computing devices. It ensures compliance with university policies, privacy legislation, research security requirements, and sectoral best practices.

2. Scope and Application

This Procedure applies to all individuals who are assigned a University-owned computing device regardless of funding source, location, or user role (faculty, staff, researcher, administrator, or contractor). Devices personally owned by individuals are not covered by this Procedure, but their use for university business is governed by the Information Security Policy and related standards.

3. Definitions

Assigned User

Individual faculty, staff, researcher, administrator, or contractor who is assigned a university-owned computing device.

University-owned Computing Device

A computing device purchased, leased, or otherwise owned by York University for use by an Assigned User in teaching, research, or administrative activities.

Managed Device

A University owned computing device enrolled in a University-approved device management platform to receive security configurations, updates, and protections required to safeguard University data and systems.

Limited Managed Device
A managed device where the Assigned User retains local administrator privileges due to academic, research, or operational requirements.

Fully Managed Device

A managed device where the Assigned User does not have local administrator privileges. This model is typically used for administrative and high-risk environments.

Security Baseline Standard

The minimum configuration standards required to protect University systems and data, including encryption, malware protection, operating system patching, identity controls, and configuration monitoring.

4. Roles and Responsibilities

4.1 University Information Technology (UIT)

UIT is responsible for maintaining this Procedure and related standards. This includes:

  • Selecting and operating device management platforms. Defining and maintaining Security Baseline Standard Compliance.
  • Ensuring managed devices receive required configurations and updates. Maintaining central asset inventory system.
  • Supporting assigned users and providing secure lifecycle management.

4.2 Faculty IT Units

Faculty IT units are responsible for:

  • Supporting Assigned Users in their faculty in meeting University security requirements.
  • Implementing software and hardware standards in their areas, including specialized research needs.
  •  Coordinating, reviewing and approving exceptions to the Security Baseline Standard where unique academic or research requirements necessitate alternative approaches.

4.3 Assigned Users

Assigned Users are responsible for:

  • Using University-owned computing devices in accordance with this Procedure.
  • Maintaining physical security of University-owned computing devices.
  • Reporting incidents, loss, or suspected tampering promptly to UIT and in the case of theft, Community Safety.
  • Refraining from attempting to circumvent device management or security controls.

4.4 Academic and Administrative Leaders

Where relevant, leaders are responsible for:

  • Supporting compliance within their units.
  •  Approving specialized device requirements where necessitated by academic, research, or operational needs.

5. Procedures

5.1 Managed Device Enrolment

All University-owned computing devices must be enrolled in a University-approved device management platform appropriate to the device type and operating system. Devices must maintain compliance with the University’s Security Baseline standard.

5.2 Security Baseline Compliance

Managed devices will automatically receive updates, patches, and security configurations. Assigned users must not disable, remove, or circumvent security controls.

6. Principles

6.1 Security First

All University-owned computing devices must be configured, monitored, and maintained to safeguard the confidentiality, integrity, and availability of university data and systems.

6.2 Privacy and Academic Freedom

The University is committed to protecting the privacy of its faculty, staff, researchers, administrators, and contractors. Device management platforms do not provide IT with the ability to track or provide access to files, research materials, email, browsing history, or other personal content. Remote support may only occur with explicit Assigned User consent. Device management does not monitor Assigned User activity.

6.3 Consistency and Lifecycle Management

Devices must be procured, managed, supported, and disposed of following University standards to ensure security, reliability, and cost effectiveness.

6.4 Accountability

Roles and responsibilities for management of university-owned computing devices are shared among UIT, Faculty IT units and Assigned Users (being faculty, staff, researchers, administrators and contractors).

7. Use of University-owned Computing Devices

University-owned computing devices must be used primarily for university-related activities. Limited incidental personal use is permitted, provided it does not interfere with university operations, violate policy, or compromise security.

7.1 Use of Personal Computing Devices

Personal devices may not be used for high-risk or restricted University activities and may not be substituted for required University-owned devices in circumstances where compliance with the Security Baseline Standard is necessary.

7.2 Protection and Reporting

Assigned Users must take reasonable steps to prevent loss, theft, or unauthorized use of University-owned devices. Assigned Users must promptly report loss, theft, or suspected security incidents to UIT and in the case of theft, Community Safety.

7.3 Configuration Integrity

Any attempt by Assigned Users to circumvent security controls including unenrollment from management platforms, disabling protective tools, or altering security baseline compliance may result in restricted access to university resources until the device is restored to Security Baseline Standard compliance.

8. Compliance and Exceptions

8.1 Compliance Monitoring

UIT will use authorized management tools to identify University-owned computing devices that fall out of compliance with the Security Baseline Standard. UIT will make reasonable efforts to contact the Assigned User and restore compliance.

8.2 Non-Compliance

Where noncompliance is due to technical issues outside the Assigned User’s control, UIT will remediate the device and restore normal operation. Where noncompliance results from intentional circumvention of security controls or negligence, access to certain University IT services may be restricted until compliance is restored. Further action will be taken in accordance with applicable University policies and if applicable, collective agreement terms and conditions.

8.3 Exceptions

Exceptions may be granted only in limited circumstances where specific academic, research, or technical requirements cannot be met through standard device management. Exception requests must be submitted through the approved University process and require UIT and Faculty IT review and approval.

9. Device Disposal and Decommissioning

University-owned computing devices must be returned to UIT or Faculty IT units at the device’s end-of-life or when no longer required. Devices may not be independently disposed of by Assigned Users. UIT or Faculty IT units will securely dispose of University-owned computing devices following applicable University procedures.

Legislative History: Approved by the President June 2, 2026
Date of Next Review: May 2031
Related Policies, Procedures and Guidelines: This Procedure operates in accordance with the: