Network Security

What Is It? 

The Network Security service provides security controls and technical assistance designed to protect University networks, systems, information, and network communications from unauthorized access and other cybersecurity threats. The service supports security-related network access controls, including border firewall rules, network access restrictions, network segmentation requirements, and other safeguards used to control communication between University resources and external networks.

Network Security is a coordinated service involving Network/Infrastructure and Information Security, with each team retaining responsibility for its respective areas of expertise. Information Security manages security policy and controls associated with border firewall rules and security-driven network restrictions, while Network/Infrastructure manages the underlying network architecture, infrastructure, routing, switching, connectivity, and other network configurations. The teams coordinate when a request involves both network operations and information security requirements.

Service Offerings

  • Firewall and Network Segmentation – Provides review and management of security-related firewall access and network segmentation requirements. Information Security manages border firewall rules and associated security requirements, while Network/Infrastructure retains responsibility for network architecture and implementation within its operational scope. Requests are evaluated based on business need, required network communication, data sensitivity, security risk, and applicable University requirements. Access should be limited to the systems, services, ports, protocols, sources, and destinations necessary to support the approved University purpose.
  • Network Access Assistance – Provides assistance when a device or system has been restricted, isolated, or blocked from University network resources because of a security concern or network security control. Information Security and Network/Infrastructure will coordinate as necessary to identify the reason for the restriction, determine required remediation, and restore access when appropriate security requirements have been satisfied.

Firewall and Network Segmentation

Firewall and network segmentation controls are used to reduce unnecessary network exposure and limit communication to that required for an authorized University purpose. Requests for new or modified access will be evaluated based on the systems involved, required communications, data sensitivity, security risk, and applicable University security requirements.

Firewall access should follow the principles of least privilege and minimum necessary network access. Requested connectivity should be limited to the systems, services, ports, protocols, sources, destinations, and duration necessary to support the approved purpose.

A request for network connectivity does not automatically result in approval of the requested firewall configuration. When a proposed configuration would introduce unnecessary exposure or conflict with established security requirements, Information Security and Network/Infrastructure may recommend an alternative technical approach, additional safeguards, or other appropriate controls. Requests that cannot meet applicable security requirements may require an approved Security Exception Request.

Information Security's responsibility for border firewall security controls does not replace Network/Infrastructure's responsibility for the design, operation, availability, and management of University network infrastructure.

Network Restrictions and Restoration of Access

Information Security may direct or coordinate restriction of network access when necessary to protect University resources, contain a suspected or confirmed security incident, address a significant vulnerability, or respond to identified malicious or inappropriate activity.

Network restrictions may include blocking external or internal communications, isolating a device or system, restricting particular services or protocols, or implementing other temporary controls appropriate to the identified risk.

A network restriction may originate from Security Incident Response, Vulnerability Management, Cyber Threat Intelligence, automated security tools or detections, Information Security staff, the UM System Security Operations Center (SOC), or other authorized security processes.

When a device or system has been restricted, Network Access Assistance provides the customer-facing path for understanding the reason for the restriction and completing any required remediation. Restoration of access may require remediation of malware, vulnerabilities, insecure configurations, unauthorized software, compromised credentials, or other identified security concerns.

Network restrictions will be reviewed as remediation progresses. Access may be restored when the identified security concern has been appropriately addressed and the affected resource can safely reconnect or resume the required network communication.

Coordination with Other Security and IT Services

Network Security works closely with other Information Security and IT services when network controls are required as part of a broader technology or security process.

  • Security Incident Response may require immediate network isolation, blocking, or other containment measures during investigation and response.
  • Cyber Threat Intelligence may identify malicious IP addresses, domains, or other indicators that should be monitored or blocked using available security controls.
  • Vulnerability Management may identify systems whose network exposure should be reduced until a significant vulnerability is remediated.
  • Security Risk Assessment may identify network segmentation or access-control requirements for new hardware, software, services, or third parties.
  • Security Compliance may establish required safeguards or manage approved exceptions when a requested network configuration cannot meet an established security requirement.
  • Network/Infrastructure provides and manages the underlying network architecture, infrastructure, routing, switching, connectivity, and other network services necessary to implement supported network configurations.

Customers are not expected to determine which technical team must implement each component of a network security request. Information Security and Network/Infrastructure will coordinate as necessary when fulfillment crosses organizational or technical responsibilities.

Policies and Requirements

Network Security activities are performed in accordance with applicable University of Missouri System policies, standards, procedures, and security requirements. Network security controls are implemented based on the purpose of the affected systems, sensitivity of University information, identified cybersecurity risks, and applicable University requirements.

Key policies and standards include:

  • Network Security Standard: Workstations & Mobile Devices – Establishes network and remote-access security requirements for workstations and mobile devices connected to University networks, including requirements for enterprise firewall protection, intrusion prevention and detection capabilities, and secure remote and third-party access.
  • Systems & Applications – Establishes security requirements for systems and applications based on University Data Classification Level (DCL), including firewall protection, network access restrictions, and additional isolation requirements for systems handling higher classifications of University information.
  • Network Device Hardening Standard – Establishes security requirements for the configuration and management of University network infrastructure devices.
  • Information Security Risk Management – Establishes the University's information security risk-management processes for identifying, evaluating, treating, and accepting information security risk. Network security requests may require risk evaluation when a requested configuration introduces additional exposure or cannot meet established security requirements.

Additional policies and standards may apply depending on the systems, technology, network access, or classification of University information involved. The complete collection is available in the UM System Information Security Policies Library.

Network Security will follow applicable University requirements when evaluating, implementing, restricting, or restoring network access. When a request cannot meet established security requirements, Information Security will work with the requester and Network/Infrastructure to identify an appropriate alternative, additional safeguards, or an approved security exception when applicable.

The Network Security service provides a consistent, risk-based, and policy-aligned approach to protecting University network communications while enabling necessary and authorized access to University technology resources.

Who Is Eligible To Use It? 

Eligibility for specific network security changes depends on the requester's responsibility for the affected system, network resource, application, or University business process and the authorization required for the requested change.

Firewall and network segmentation requests may require approval or technical information from system owners, application owners, departmental IT personnel, Network/Infrastructure, Information Security, or other responsible University personnel before implementation.

Network security activities may also be initiated without a customer-submitted request by Information Security staff, Network/Infrastructure staff, other IT staff, automated security tools and detections, or the UM System Security Operations Center (SOC) when a security concern requires network restriction, isolation, monitoring, or another protective action.

Network security actions may also result from information received from vendors, partner organizations, government agencies, law enforcement, or other trusted sources when potential malicious activity or risk involving University resources is identified.

How Much Does It Cost? 

Costs may be incurred when a request requires specialized equipment, additional network infrastructure, licensing, third-party services, dedicated connectivity, or other resources not normally provided as part of the standard service. Such costs may be the responsibility of the requesting or affected department, research lab, or unit, as applicable.