International Travel S&T IT Security Information
While traveling internationally, S&T IT Security would like to provide you with information to protect your data and computer while you are away from campus.
Protecting Your Data
Protecting your data (e.g., research, intellectual property (IP), university data) while traveling is the most important preparation you can do. Your data is too important to have it compromised. You have worked hard to produce sensitive data that is important to the university and to achieve your goals. A compromise can impact future research opportunities for you and the University.
The need for the cybersecurity process for international travel is to:
- Protect university data and research during travel.
- Protect Intellectual Property (IP), proposals, instructor materials, etc.
- Protect the campus community network and computers upon a traveler's return to campus.
Please review the UM System Information Security Travel Standard, found at https://www.umsystem.edu/ums/is/infosec/standards-travel.
Note: The IT Desktop Support will contact you approximately two weeks before your trip to discuss your computer and data needs for your upcoming international trip.
Cybersecurity Categorizations
The following three cybersecurity categories (A, B, C and D) for your trip are used to make computer and data preparations before you depart.
Category A: Traveler is on an export controlled or Controlled Unclassified Information project with a Technology Control Plan (TCP) and going to any country.
Category B: Traveler is going to a country on one of the following US Government lists.
- OFAC* Comprehensively Sanctioned or Embargoed Countries:
Iran, Cuba, North Korea, Russian-occupied regions of Ukraine (Crimea, Donetsk, Luhansk, Kherson, and Zaporizhzhia).
- OFAC* Targeted Sanctioned Countries:
Russia, Belarus, Burma (Myanmar), Syria, and Venezuela.
- Foreign Countries of Concern:
China (including Hong Kong and Macau), Iran, North Korea, Russia.
* Office of Foreign Assets Control (OFAC)
Category C: Traveler is not on an export controlled or Controlled Unclassified Information (CUI) project with a TCP, is not going to a country on one of above US Government lists and is doing University Business.
Category D: Traveler is going on a personal trip, is not taking any S&T managed devices and is not doing University business during the trip. If the traveler is doing University business during the trip, then use Category A, B, or C.
IT Cybersecurity Preparation: Categories A and B (High Risk)
It is required to temporarily exchange your S&T managed computer for a loaner laptop provided by S&T IT that does not contain sensitive information for your use during the trip. If you do not need to take an S&T computer or equipment with you, then you do not need to get a loaner laptop. This process does not apply to personal laptops with personal data. However, you are required to not store campus data on personal devices beyond data stored in communication tools, (https://www.umsystem.edu/ums/is/infosec/sections-mobile).A good data security practice is to have the traveler, and their department review the laptop contents to make sure there is no sensitive data on the laptop to be taken on the travel. Do not store any sensitive data on the laptop or other devices you take with you.
Use OpenVPN, IT Security International Travel Categories Presentation.pptx to connect to the campus network any time you are working on the laptop until you return to campus.
IT Desktop Support will do the following required items on the loaner laptop to be ready for travel:
- Configure Microsoft BitLocker on the loaner laptop.
- Onboard your loaner laptop into our Windows Defender security protection and monitoring system.
- Update software to be brought to the most recent patch levels to mitigate possible vulnerabilities.
- Assist with transferring only data needed for the trip. Do not put any sensitive data on the laptop.
Upon return to campus:
- The traveler is required to take the loaner laptop to the IT Service Desk to properly sanitize the laptop before connecting the loaner laptop to the campus network.
- The IT Service Desk will run the virus checker and Windows Defender on the loaner laptop.
- After the IT Service Desk confirms that the laptop is not infected with viruses, malware, or other security vulnerabilities, you may then request the IT Help Desk to transfer any data that you want to keep from a loaner laptop to your S&T managed laptop.
IT Cybersecurity Preparation: C (Medium Risk)
If you have a need to take an S&T managed computer on your trip, you have the option to take a loaner laptop provided by S&T IT instead of taking your S&T managed computer on your trip. If you do not need to take an S&T computer or equipment with you, then you do not need to get a loaner laptop. This process does not apply to personal laptops with personal data. However, you are required to not store campus data on personal devices beyond data stored in communication tools (https://www.umsystem.edu/ums/is/infosec/sections-mobile).
A good data security practice is to have the traveler, and their department review the laptop contents to make sure there is no sensitive data on the laptop to be taken on the travel. Do not store any sensitive data on the laptop or other devices you take with you.
Use OpenVPN, IT Security International Travel Categories Presentation.pptx to connect to the campus network any time you are working on the laptop until you return to campus.
IT Desktop Support will do the following required items on the loaner laptop to be ready for travel:
- Configure Microsoft BitLocker on the loaner laptop.
- Onboard your loaner laptop into our Windows Defender security protection and monitoring system.
- Update software to be brought to the most recent patch levels to mitigate possible vulnerabilities.
- Assist with transferring only data needed for the trip. Do not put any sensitive data on the laptop.
Upon return to campus:
- The traveler is required to take the loaner laptop or take your S&T managed laptop to the IT Service Desk to properly sanitize the laptop before connecting the loaner laptop to the campus network.
- The IT Service Desk will run the virus checker and Windows Defender on the laptop.
- After the IT Service Desk confirms that the loaner laptop is not infected with viruses, malware, or other security vulnerabilities, you may then request the IT Service Desk to transfer any data that you want to keep from a loaner laptop to your S&T managed laptop.
IT Cybersecurity Preparation: D (Low Risk)
If the traveler is only taking personal devices and not doing University business on the trip, then no S&T updates, S&T managed laptops, or loaner laptops are needed.
- S&T IT recommends that the traveler’s personal devices are up to date with current security patches and applications.
- Personal cell phones can use office.com to connect to Outlook
- S&T IT recommends the traveler removes the Outlook app from their personal phone before travel.
- If the traveler plans to do University business while on personal travel, then the trip is classified as a Category A, B, or C trip.
Note: The IT Desktop Support will contact you approximately two weeks before your trip to discuss your computer and data needs for your upcoming international trip.
IT Security Staff