GETTING STARTED

DEVICE SECURITY

Protect the devices you use for BU work and understand the security requirements for accessing, storing, and working with University information.

DEVICE BASICS

Start with the Essentials

Whether you’re using a computer, phone, or tablet, a few basic protections form the foundation of device security at BU.

Keep It Updated

Use a supported operating system and keep the operating system and applications current. Automatic updates should be enabled whenever possible.

Require Authentication

Protect access to your device with a strong password, PIN, passcode, or supported biometric authentication.

Use Endpoint Protection

Keep endpoint protection software installed and updated to help protect against viruses, spyware, and other malicious activity.

Protect Stored Data

Devices containing Sensitive Information must use encryption at rest, such as BitLocker on Windows, FileVault on Mac, or native encryption on supported mobile devices.

Using a BU-owned computer? Contact Questrom Tech before installing or changing endpoint protection software on a managed device. For a personally owned computer, BU provides CrowdStrike installation resources directly.

BU REQUIREMENTS

Minimum Security Checklist

BU’s Minimum Security Standards establish baseline protections for devices that access, store, or process University information. Use this checklist as a starting point.

Supported Operating System

Use an operating system that is still supported by its vendor and continues to receive security updates.

Automatic Updates

Configure the operating system and applications to install updates automatically. If your device isn’t centrally managed by IT, BU requires it to be configured to update within 2–3 days of a patch release.

Screen Lock

Configure your computer, phone, or tablet to lock automatically and require authentication after no more than 15 minutes of inactivity.

Endpoint Protection

BU uses CrowdStrike as its endpoint protection platform. CrowdStrike provides protection against malware, ransomware, zero-day exploits, and other threats and is available to BU faculty, staff, and students for both BU-owned and personally owned desktop and laptop computers.

Secure Storage

Information critical to University operations must also be stored in an approved enterprise location, such as OneDrive, rather than existing only on a laptop, desktop, or mobile device.

Encryption

Devices containing Sensitive Information must use encryption at rest. This requirement also applies to removable storage devices.

DEVICE OWNERSHIP

BU-Owned vs Personal Devices

The security requirements follow the University information you are working with, not simply who owns the computer.

BU-Managed Device

MANAGED BY BU OR YOUR IT GROUP

University-managed devices may have security settings, endpoint protection, asset-management tools, Active Directory, or device-management services configured centrally. Keep those protections enabled and contact your IT support group before changing managed security settings.

Personal Device

YOUR RESPONSIBILITY

If you choose to use a personally owned computer, phone, or tablet for University business, you are responsible for ensuring that it meets the applicable BU Minimum Security Standards.

Personal device doesn’t mean personal rules. The type and sensitivity of University information you’re accessing determines which protections are required.

UNIVERSITY DATA

Protect the Data, Not Just the Device

Security requirements depend partly on the information you’re working with. BU classifies University Data according to its sensitivity, and stronger protections apply to Confidential and Restricted Use information.

Store Files in the Right Place

Avoid keeping important University files only on your computer. Information that is critical to University operations should also exist in an approved BU storage location so it remains protected, recoverable, and available when needed.

Be Careful with Personal Cloud Services

Personal cloud-storage accounts are not automatically appropriate for University information. BU places additional restrictions on Confidential and Restricted Use data, and Restricted Use data may not be stored in personal cloud services.

Keep BU credentials separate from personal services. Do not use your BU Kerberos password as the password for a personal cloud-storage or other non-BU account.

REMOTE & MOBILE WORK

Working Away from Campus

The same security requirements apply when you’re working from home, traveling, or connecting from another location.

01

Use a Secure Connection

When accessing Confidential or Restricted Use information from off campus, make sure the connection is encrypted using HTTPS, the BU VPN, or another appropriate secure connection.

02

Use a Device You Trust

Don’t conduct BU business on a public kiosk, hotel computer, or other device whose security configuration you can’t verify.

03

Keep Control of Your Device

Keep laptops, phones, tablets, and removable storage physically secure when traveling or working in public spaces.

Using public Wi-Fi? BU’s security guidance recommends using the VPN when connecting through potentially insecure wireless networks.

DEVICE INCIDENTS

Lost, Stolen, or Compromised Device?

Act quickly if a device used for BU work is missing, stolen, or may have been compromised. The right response depends on whether you are dealing with theft, possible exposure of University information, or a cybersecurity incident.

Device Lost or Stolen

Report the Loss or Theft. If a device has been stolen or the loss involves a crime, report it promptly to the Boston University Police Department. For an emergency or situation requiring immediate police response, call BUPD.

BUPD: 617-353-2121

Report Possible Data Exposure

If the device contains or provides access to University information and you are concerned that data may have been exposed, report the incident to BU Information Security so the situation can be assessed.

Preserve the Device

If you suspect an active compromise, avoid making unnecessary changes to the computer before reporting it. BU advises preserving compromised systems for investigation and specifically warns against rebooting, shutting down, installing software, changing configurations, or deleting files unless instructed by the Incident Response Team.

What Should I Do Right Now?

Device is missing

Try to locate it and report the loss or theft as appropriate.

Credentials may be exposed

Secure your BU account and review the Duo devices registered to it.

University data may be exposed

Report the incident to BU Information Security promptly.

Device appears compromised

Preserve the device and follow BU Incident Response instructions before making changes.

CENTRAL BU RESOURCES

Explore BU Information Security

Questrom Tech provides practical guidance for the devices you use day to day. For authoritative security policies, detailed cybersecurity guidance, and University-wide security services, use BU Information Security resources.

Secure Your Devices

Practical guidance for securing computers, phones, tablets, and other devices, including passwords, updates, endpoint protection, VPN use, backups, and lost-device protection.

Minimum Security Standards

Review the University’s baseline security requirements for devices and services used to access, store, or process University information.

BU Information Security

Explore University-wide security services, cybersecurity operations, incident response, identity and access management, policy, risk, and security education. BU’s Information Security organization includes a Security Operations Center responsible for detecting and responding to cyber incidents.

SECURITY RESOURCES

Go Beyond the Basics

BU provides tools and resources to help you check your account security, recognize current phishing attempts, and build stronger everyday security habits.

01

Terrier Cybersecurity Checkup

Run a personalized security check on your BU account. Review your registered Duo devices, check the age of your BU password, and see whether your BU email address has appeared in known data breaches.

02

BU Phish Bowl

See actual phishing messages reported by the BU community. The Phish Bowl is updated with recent scams so you can compare a suspicious message with threats currently circulating at BU.

03

Security for Everyone

Browse practical BU guidance for protecting your accounts, devices, and information, including passwords, phishing, software updates, secure computing, identity theft, cloud storage, and other everyday security topics.

Last content review: August 24, 2026

COMMON QUESTIONS

Quick Answers

Can I use a personal computer for BU work?

BU’s security standards account for personally owned devices used for University business. If you choose to use one, you are responsible for ensuring that the device meets the applicable security requirements.

How quickly should I install updates?

Devices should be configured to install updates automatically. Unless updates are managed by an IT support group, BU’s current standard says devices should be configured to update within 2–3 days of a patch being released.

Does my computer need antivirus or endpoint protection?

BU requires endpoint protection software to be installed and updated on secure endpoint devices. BU provides CrowdStrike endpoint protection for Mac and Windows computers.

Do I need encryption?

Devices containing Sensitive Information must encrypt data at rest. BU specifically identifies technologies such as BitLocker for Windows and FileVault for Mac.

Can I store BU files in my personal Dropbox, Google Drive, or another cloud service?

Not automatically. BU prohibits Restricted Use data in personal cloud services, and Confidential data should not be stored there unless the service has appropriate BU approval.

Can I use a hotel or public computer for BU work?

No, not when you cannot configure or verify the security of the device. BU’s Minimum Security Standards specifically say such devices should not be used to conduct BU business.

Not Sure Your Device Meets BU Requirements?

If you're unsure whether a device is appropriately secured for the University information you're working with, contact Questrom ITS or BU Information Security before storing or accessing sensitive data.

Get IT Support
Submit a support request
questromhelp@bu.edu
Visit The Helpdesk
Hariri, Room 342
617-353-9858
Mon – Thurs: 8am – 6pm
Friday: 8am – 5pm
Scroll to Top