Endpoint Protection and Device Security Regulation

Updated: August 24, 2026
Policy:
REG08.05.01
Title:
Endpoint Protection and Device Security Regulation
Category:
Information Technology
Sub-category:
Security and Compliance
Authority:
Chancellor
Contact:

Mark Webster, Chief Information Security Officer: (252) 328-9225

History:

ITCS Policy # 7.302 Supersedes Policy Dated: October 3, 2001 Review Date: November 9, 2011 Placed in University Policy Manual after EXPEDITED REVIEW, transitioned without substantive change from prior version, March 25, 2013. Updated from RUL to REG and approved by Chancellor's EC August 24, 2026.

Previous Versions:

All versions are available as PDF downloads

1. Introduction

1.1 Purpose of Policy:
This regulation establishes the hardware and software security requirements for access to any University Information and Technology Resource. This regulation applies to all university-managed and personally owned Computing Devices.

2. Scope

2.1 All Computing Devices – including desktops, laptops, mobile devices, and servers – connecting to any University Information Technology Resource, regardless of whether such Computing Device is owned by the University.

3. Definitions

3.1 Computing Device: Desktops, laptops, mobile devices, and servers which are capable of accessing, interacting with, or natively running University Information Technology Resources. Computing devices include but are not limited to: laptops, smartphones, and desktop computers.
3.2 Jailbroken: typically referring to iOS devices, where a device is modified through software or hardware to enable the installation of software from unapproved sources, a custom OS, custom firmware, or other modifications that affect the device’s default security posture.
3.3 Rooted: typically referring to Android devices, where a device is modified through software or hardware to enable the installation of software from unapproved sources, a custom OS, custom firmware, or other modifications that affect the device’s default security posture.
3.4 University Information Technology Resource: Any and all networks, servers, cloud-based storage or computing platforms, virtual private networks, or enterprise software (e.g. Microsoft Outlook) which has been procured by the University to conduct or transact University business or further the University’s scholarly and teaching mission.

4. Regulation

All Computing Devices connecting to or utilizing University Information Technology Resources, regardless of whether such Computing Devices are owned by University, are required, as part of the terms of use for connecting to or utilizing such University Information Technology Resources, to adhere to this Regulation as follows:

  • 4.1 Baseline Security Requirements
    • 4.1.1 All Computing Devices used to access University Information Technology Resources must meet the baseline level of security which includes: (1) enabling device encryption to the extent such encryption is available, (2) using screen locks/passcodes/biometrics, (3) keeping the Computing Device’s operating system and applications up to date, and (4) utilizing ITCS-approved and supported endpoint protection software that is correctly installed and kept up to date.
    • 4.1.2 Access to or use of University Information Technology Resources must be done in accordance with REG08.10.05 “Acceptable Use of IT Resources | University Policy Manual | ECU” and REG08.05.12 “Mobile Computing Regulation”.
    • 4.1.3 The use of endpoint protection software which has been, or which is provided by a company which has been, banned, disbarred, disqualified, or sanctioned by the United States Government or the State of North Carolina is prohibited.
    • 4.1.4 Computing Devices which contain endpoint protection software as identified in Section 4.1.3 above, or other software which as been, or which is provided by a company which has been, banned, disbarred, disqualified, or sanctioned by the United States Government or the State of North Carolina is ineligible for use with any University Information Technology Resource.
    • 4.1.5 University-owned phones and tablets must be enrolled in Microsoft Intune (or other ITCS-approved mobile device management (MDM) solution) and have endpoint protection enabled where technically feasible.
    • 4.1.6 Personally owned Computing Devices which are mobile devices (phones and tablets using a mobile operating system) are advised to have endpoint protection software as a condition of accessing University Information Technology Resources when feasible.
    • 4.1.7 Personally owned Computing Devices which are mobile devices used to access University Information Technology Resources must not be jailbroken, rooted, or otherwise have their base operating system compromised.
    • 4.1.8 Computing Devices may be required to comply with additional hardware, software, and usage requirements in order to comply with other University regulations and policies pertaining to data governance, including but not limited to REG01.15.06 or ECU’s Sensitive Data Storage and Transmission guidance, or else be ineligible for use in accessing certain University Information Technology Resources. Access to University Information Technology Resources or University Data may require approval from a Covered Person’s (as that term is defined in REG01.15.06) supervisor or the relevant data steward before access to a particular Computing Device may be granted.
    • 4.1.9 Before a Covered Person may use a personal Computing Device to access any University Information Technology Resource which provides access to level 3 or 4 data such Covered Person will need written permission from their direct supervisor and unit head. A Covered Person accessing University data on a personal device must adhere to the “Mobile Device Computing Regulation” as well as the “Sensitive Data Storage and Transmission” published guidance.
    • 4.1.10 To the extent a Covered Person utilizes their personal Computing Device not owned by the University for access to University Information Technology Systems, any and all records, data, and information generated with the use of the personal Computing Device shall and do remain University property. The Covered Person shall not and does not have any ownership interest in such records, data, or information except to the extent that may be granted under POL10.40.01 or REG10.40.02.
  • 4.2 Student Computers
    • 4.2.1 Notwithstanding other sections within this Regulation to the contrary, Computing Devices owned by students enrolled at the University which are being used solely in the course of a student’s academic coursework shall only be required to meet the hardware and software requirements set forth in guidance the University issues on student Computing Devices including “Article – FAQ – Student Computers”, as well as the “Student Computer Requirements and Recommendations.” Such guidelines may be amended or replaced from time to time at the discretion of the University. Notwithstanding the foregoing provisions of this Section 4.2.1, student Computing Devices shall always be required to have the appropriate antivirus protection installed at all times, including at minimum for Windows devices Windows Security or its official successor software, and for MacOS devices XProtect or its official successor software.
    • 4.2.2 Section 4.2.1 shall be inapplicable where a student is using their personal Computing Device in order to transact University business.
  • 4.3 Operating System and Software Updates
    • 4.3.1 Devices must be running an actively supported operating system with the latest security patches applied, except where such Computing Devices are University owned and part of legacy systems utilized for transacting mission critical University business or research. Such legacy systems which are unable to be kept up-to-date must have appropriate compensating controls where possible.
    • 4.3.2 Updates and patches should be applied to software as they become available.
    • 4.3.3 Automatic updates should be enabled whenever possible.

5. Violations

  • 5.1 Failure to comply with this Regulation may result in restricted or revoked access to University Information Technology Resources for noncompliant Computing Devices. Failure to comply with this Regulation may also result in sanctions, disciplinary action, or an internal or State run audit or investigation against the owner or operator of the noncompliant Computing Device.
  • 5.2 Please reach out to Pirate Techs with any questions or concerns, or visit your nearest campus Pirate Techs location.