DEVICE SECURITY
Protect the devices you use for BU work and understand the security requirements for accessing, storing, and working with University information.
DEVICE BASICS
Start with the Essentials
Whether you’re using a computer, phone, or tablet, a few basic protections form the foundation of device security at BU.
Keep It Updated
Use a supported operating system and keep the operating system and applications current. Automatic updates should be enabled whenever possible.
Require Authentication
Protect access to your device with a strong password, PIN, passcode, or supported biometric authentication.
Use Endpoint Protection
Keep endpoint protection software installed and updated to help protect against viruses, spyware, and other malicious activity.
Protect Stored Data
Devices containing Sensitive Information must use encryption at rest, such as BitLocker on Windows, FileVault on Mac, or native encryption on supported mobile devices.
Using a BU-owned computer? Contact Questrom Tech before installing or changing endpoint protection software on a managed device. For a personally owned computer, BU provides CrowdStrike installation resources directly.
BU REQUIREMENTS
Minimum Security Checklist
BU’s Minimum Security Standards establish baseline protections for devices that access, store, or process University information. Use this checklist as a starting point.
Supported Operating System
Use an operating system that is still supported by its vendor and continues to receive security updates.
Automatic Updates
Configure the operating system and applications to install updates automatically. If your device isn’t centrally managed by IT, BU requires it to be configured to update within 2–3 days of a patch release.
Screen Lock
Configure your computer, phone, or tablet to lock automatically and require authentication after no more than 15 minutes of inactivity.
Endpoint Protection
BU uses CrowdStrike as its endpoint protection platform. CrowdStrike provides protection against malware, ransomware, zero-day exploits, and other threats and is available to BU faculty, staff, and students for both BU-owned and personally owned desktop and laptop computers.
Secure Storage
Information critical to University operations must also be stored in an approved enterprise location, such as OneDrive, rather than existing only on a laptop, desktop, or mobile device.
Encryption
Devices containing Sensitive Information must use encryption at rest. This requirement also applies to removable storage devices.
DEVICE OWNERSHIP
BU-Owned vs Personal Devices
The security requirements follow the University information you are working with, not simply who owns the computer.
BU-Managed Device
MANAGED BY BU OR YOUR IT GROUP
University-managed devices may have security settings, endpoint protection, asset-management tools, Active Directory, or device-management services configured centrally. Keep those protections enabled and contact your IT support group before changing managed security settings.
Personal Device
YOUR RESPONSIBILITY
If you choose to use a personally owned computer, phone, or tablet for University business, you are responsible for ensuring that it meets the applicable BU Minimum Security Standards.
Personal device doesn’t mean personal rules. The type and sensitivity of University information you’re accessing determines which protections are required.
UNIVERSITY DATA
Protect the Data, Not Just the Device
Security requirements depend partly on the information you’re working with. BU classifies University Data according to its sensitivity, and stronger protections apply to Confidential and Restricted Use information.
Store Files in the Right Place
Avoid keeping important University files only on your computer. Information that is critical to University operations should also exist in an approved BU storage location so it remains protected, recoverable, and available when needed.
Be Careful with Personal Cloud Services
Personal cloud-storage accounts are not automatically appropriate for University information. BU places additional restrictions on Confidential and Restricted Use data, and Restricted Use data may not be stored in personal cloud services.
Keep BU credentials separate from personal services. Do not use your BU Kerberos password as the password for a personal cloud-storage or other non-BU account.
REMOTE & MOBILE WORK
Working Away from Campus
The same security requirements apply when you’re working from home, traveling, or connecting from another location.
01
Use a Secure Connection
When accessing Confidential or Restricted Use information from off campus, make sure the connection is encrypted using HTTPS, the BU VPN, or another appropriate secure connection.
02
Use a Device You Trust
Don’t conduct BU business on a public kiosk, hotel computer, or other device whose security configuration you can’t verify.
03
Keep Control of Your Device
Keep laptops, phones, tablets, and removable storage physically secure when traveling or working in public spaces.
Using public Wi-Fi? BU’s security guidance recommends using the VPN when connecting through potentially insecure wireless networks.
DEVICE INCIDENTS
Lost, Stolen, or Compromised Device?
Act quickly if a device used for BU work is missing, stolen, or may have been compromised. The right response depends on whether you are dealing with theft, possible exposure of University information, or a cybersecurity incident.
Device Lost or Stolen
Report the Loss or Theft. If a device has been stolen or the loss involves a crime, report it promptly to the Boston University Police Department. For an emergency or situation requiring immediate police response, call BUPD.
BUPD: 617-353-2121
Report Possible Data Exposure
If the device contains or provides access to University information and you are concerned that data may have been exposed, report the incident to BU Information Security so the situation can be assessed.
Preserve the Device
If you suspect an active compromise, avoid making unnecessary changes to the computer before reporting it. BU advises preserving compromised systems for investigation and specifically warns against rebooting, shutting down, installing software, changing configurations, or deleting files unless instructed by the Incident Response Team.
What Should I Do Right Now?
Device is missing
Try to locate it and report the loss or theft as appropriate.
Credentials may be exposed
Secure your BU account and review the Duo devices registered to it.
University data may be exposed
Report the incident to BU Information Security promptly.
Device appears compromised
Preserve the device and follow BU Incident Response instructions before making changes.
CENTRAL BU RESOURCES
Explore BU Information Security
Questrom Tech provides practical guidance for the devices you use day to day. For authoritative security policies, detailed cybersecurity guidance, and University-wide security services, use BU Information Security resources.
Secure Your Devices
Practical guidance for securing computers, phones, tablets, and other devices, including passwords, updates, endpoint protection, VPN use, backups, and lost-device protection.
Minimum Security Standards
Review the University’s baseline security requirements for devices and services used to access, store, or process University information.
BU Information Security
Explore University-wide security services, cybersecurity operations, incident response, identity and access management, policy, risk, and security education. BU’s Information Security organization includes a Security Operations Center responsible for detecting and responding to cyber incidents.
SECURITY RESOURCES
Go Beyond the Basics
BU provides tools and resources to help you check your account security, recognize current phishing attempts, and build stronger everyday security habits.
01
Terrier Cybersecurity Checkup
Run a personalized security check on your BU account. Review your registered Duo devices, check the age of your BU password, and see whether your BU email address has appeared in known data breaches.
02
BU Phish Bowl
See actual phishing messages reported by the BU community. The Phish Bowl is updated with recent scams so you can compare a suspicious message with threats currently circulating at BU.
03
Security for Everyone
Browse practical BU guidance for protecting your accounts, devices, and information, including passwords, phishing, software updates, secure computing, identity theft, cloud storage, and other everyday security topics.
Last content review: August 24, 2026
COMMON QUESTIONS
Quick Answers
Can I use a personal computer for BU work?
BU’s security standards account for personally owned devices used for University business. If you choose to use one, you are responsible for ensuring that the device meets the applicable security requirements.
How quickly should I install updates?
Devices should be configured to install updates automatically. Unless updates are managed by an IT support group, BU’s current standard says devices should be configured to update within 2–3 days of a patch being released.
Does my computer need antivirus or endpoint protection?
BU requires endpoint protection software to be installed and updated on secure endpoint devices. BU provides CrowdStrike endpoint protection for Mac and Windows computers.
Do I need encryption?
Devices containing Sensitive Information must encrypt data at rest. BU specifically identifies technologies such as BitLocker for Windows and FileVault for Mac.
Can I store BU files in my personal Dropbox, Google Drive, or another cloud service?
Not automatically. BU prohibits Restricted Use data in personal cloud services, and Confidential data should not be stored there unless the service has appropriate BU approval.
Can I use a hotel or public computer for BU work?
No, not when you cannot configure or verify the security of the device. BU’s Minimum Security Standards specifically say such devices should not be used to conduct BU business.
Not Sure Your Device Meets BU Requirements?
If you're unsure whether a device is appropriately secured for the University information you're working with, contact Questrom ITS or BU Information Security before storing or accessing sensitive data.
Get IT Support
questromhelp@bu.edu
Visit The Helpdesk
617-353-9858
Mon – Thurs: 8am – 6pm
Friday: 8am – 5pm
