Network Security

The Network Security service provides security controls and technical assistance designed to protect University networks, systems, information, and network communications from unauthorized access and other cybersecurity threats. The service supports the implementation and management of network security controls, including firewall rules, network segmentation, access restrictions, and other safeguards used to control communication between University systems, networks, and external resources.

Network Security is a coordinated service involving Network/Infrastructure and Information Security, with each team retaining responsibility for its respective areas of expertise. Information Security manages security policy and controls associated with border firewall rules and security-driven network restrictions, while Network/Infrastructure manages the underlying network architecture, infrastructure, routing, switching, connectivity, and other network configurations. Network/Infrastructure implements or supports network changes as appropriate, and the teams coordinate when a request involves both network operations and information security requirements.

Service Offerings

  • Firewall and Network Segmentation - Provides review, implementation, modification, or removal of firewall rules, network segmentation, and related network security controls. Requests are evaluated based on business need, system purpose, required network communication, data sensitivity, security risk, and applicable University requirements. Network access will be limited to the systems, services, ports, protocols, and sources necessary to support the approved business purpose.
  • Network Access Assistance - Provides assistance when a device or system has been restricted, isolated, or blocked from University network resources because of a security concern or network security control. Information Security and Network/Infrastructure teams will review the reason for the restriction, identify any necessary remediation, and determine whether network access can be safely restored. Restoration of access may require remediation of vulnerabilities, malware, insecure configurations, or other identified security concerns before network restrictions are removed.

Network restrictions may also be implemented as part of Security Incident Response, Vulnerability Management, Cyber Threat Intelligence, or other security activities. Network Access Assistance provides the customer-facing path for resolving the resulting network access issue but does not guarantee that a security restriction will be removed.

Policies and Requirements

Network Security activities are performed in accordance with applicable University of Missouri System policies, standards, procedures, and security requirements. Network security controls are implemented based on the sensitivity of University information, the purpose and configuration of the affected systems, identified cybersecurity risks, and applicable University requirements.

Applicable policies and standards include:

  • Network Security Standard: Workstations & Mobile Devices - Establishes network and remote-access security requirements for workstations and mobile devices connected to University networks. The standard requires central IT departments to protect workstations through enterprise firewalls and appropriate intrusion prevention and detection capabilities and establishes requirements for secure remote and third-party access. https://www.umsystem.edu/policies/information-technology/information-security-policies/network-security-standard-workstations-mobile-devices
  • Systems & Applications - Establishes security requirements for systems and applications based on University data classification. Network requirements include use of enterprise firewall protection, default-deny firewall configurations that permit only necessary services, and additional network isolation and inbound-access restrictions for systems handling higher classifications of University information. https://www.umsystem.edu/policies/information-security-policies/systems-applications-data-classification
  • Network Device Hardening Standard - Establishes security requirements for the configuration and management of network infrastructure devices. Network Security activities involving supported network infrastructure will follow applicable hardening and configuration requirements established by this standard. https://www.umsystem.edu/policies/information-technology/information-security-policies/network-device-hardening-standard
  • Information Security Risk Management - Establishes the University's information security risk management program and processes for identifying, evaluating, treating, and accepting information security risk. Network security decisions may require risk evaluation when a requested configuration introduces additional exposure or cannot meet established security requirements. https://www.umsystem.edu/policies/information-technology/information-security-policies/information-security-risk-management
  • Encryption Standard - Establishes requirements for protecting University information through encryption, including requirements applicable to data transmitted across networks. Network designs and configurations involving sensitive University information must support applicable encryption and secure transmission requirements. https://www.umsystem.edu/policies/information-technology/information-security-policies/encryption-standard

Network Security may also apply other relevant UM System information security policies and standards based on the systems, data, or technology involved in a request.

Firewall and network segmentation requests will follow the principle of least privilege and minimum necessary network access. Requested connectivity should be limited to the systems, services, ports, protocols, sources, destinations, and duration necessary to support the authorized University purpose. Requests that create unnecessary exposure or conflict with established security requirements may require an alternative technical solution, additional safeguards, or an approved Security Exception Request.

Information Security may direct that network access be restricted or systems isolated when necessary to protect University resources, contain a suspected or confirmed security incident, address a significant vulnerability, or respond to identified malicious activity. Restrictions will remain in place until appropriate remediation has occurred and the identified risk has been reduced to an acceptable level.

Where a network security request requires specialized Infrastructure support, centralized UM System resources, additional security review, or an exception to established security requirements, the appropriate teams will coordinate to resolve the request.

The service provides a consistent, risk-based, and policy-aligned approach to protecting University network communications while enabling necessary and authorized access to University technology resources.