Information Security for Faculty and Staff
Protect your CSUN account, devices, and university information by following these recommended security practices and using CSUN-supported security services.
Use this page to:
- protect your CSUN account;
- securely store and share university information;
- recognize phishing, ransomware, and other cyber threats;
- access required security and FERPA training; and
- report a suspected security incident.
Links:
Start With These Security Practices
Faculty and staff can reduce many common security risks by following a few basic practices:
- Use Duo Multi-Factor Authentication when prompted.
- Never share your CSUN password or MFA verification code.
- Verify unexpected requests before clicking links, scanning QR codes, opening attachments, or sending information.
- Store confidential university information only in approved locations.
- Keep university and personal devices updated.
- Use secure connections when accessing protected CSUN resources.
- Complete assigned security and privacy training.
- Report suspected phishing, account compromise, malware, or data exposure promptly.
If you believe your CSUN account or device has been compromised, change your password when appropriate and contact Information Security or the IT Help Center.
Protect Your Account
Duo Multi-Factor Authentication adds a second verification step when you sign in to protected CSUN services.
MFA helps protect your account even if someone obtains your password.
When using Duo:
- approve only sign-in requests you initiated;
- never provide an MFA verification code to another person;
- reject unexpected Duo requests; and
- report repeated or suspicious authentication requests.
CSUN will not ask you to provide your password by email.
To protect your account:
- use a unique password for your CSUN account;
- do not share passwords with coworkers, supervisors, family members, or friends;
- do not enter your password after following an unexpected email, text-message, or QR-code link;
- verify the website before entering your CSUN credentials; and
- change your password promptly if you believe it has been exposed.
If an unexpected message asks for your password, MFA code, money, gift cards, or other sensitive information, verify the request using a separate trusted method.
Protect University Data
Use the appropriate CSUN service and security practice based on the type of information you are handling.
| Area | Recommended Practice | Resource |
|---|---|---|
| Confidential Level 1 Data | Store approved confidential data in Confidential Box | Confidential Box |
| File and Device Protection | Use appropriate encryption for protected information | Encryption |
| Student Records | Follow FERPA privacy requirements | FERPA Training |
| Remote Access | Use the CSUN VPN when required for protected university resources | VPN |
| Zoom Meetings | Apply appropriate meeting security controls | Zoom Security |
| Devices | Keep systems updated and protect against malware and ransomware | Malware and Ransomware |
Links for the Resource column:
- Confidential Box at CSUN
- CSUN Encryption Guidance
- CSUN Security and FERPA Training
- How to Keep Your Zoom Meetings Secure
- Protect Against Ransomware
Storing Confidential Information
Confidential Box is CSUN's secure solution for storing approved Confidential Level 1 data.
Do not store unencrypted confidential information in a regular myCSUNbox account.
Confidential Box includes additional security controls, including Duo Multi-Factor Authentication. Access is limited to users who have been approved to handle confidential data.
When accessing Confidential Box off campus, a CSUN VPN connection may also be required.
Encryption protects information by making it unreadable without the appropriate key or credentials.
Encryption may be appropriate for:
- computers and storage devices;
- protected files;
- confidential information sent electronically; and
- removable storage when its use is authorized.
Use CSUN-approved encryption methods appropriate for the type of information you are handling.
Protect Student Information
Faculty and staff who access student education records are responsible for protecting those records in accordance with FERPA and university requirements.
Student information that may require protection includes:
- grades and GPA information;
- test scores;
- advising records;
- student identification information;
- educational records; and
- other information connected to a student's academic record.
Do not make student records available to people who do not have an appropriate educational need to access them.
Complete assigned FERPA and information-security training and follow university procedures when handling student information.
Access CSUN Security and FERPA Training
Review CSUN Privacy Rights of Students in Education Records
Recognize and Respond to Cyber Threats
Phishing messages may arrive through email, text messages, QR codes, or other communication channels.
Modern phishing messages may look professional and can imitate CSUN, Microsoft, supervisors, faculty members, banks, or other trusted organizations.
Be cautious when a message:
- asks for your password or MFA code;
- asks you to send money or purchase gift cards;
- directs you to an unexpected login page;
- contains an unexpected attachment or QR code;
- creates unusual urgency;
- asks you to keep the request secret; or
- comes from an address that does not match the claimed sender.
Before responding, verify unusual requests using another trusted method.
If you receive a suspicious message:
- Do not click suspicious links.
- Do not scan unexpected QR codes.
- Do not open unknown attachments.
- Do not approve unexpected MFA requests.
- Do not send money, gift-card codes, passwords, or other sensitive information.
- Verify the request through a trusted source.
- Report suspicious email to abuse@csun.edu.
When possible, send the suspicious email as an attachment so Information Security can review the original message and its technical information.
If you entered your CSUN password on a suspicious website or approved an unexpected MFA request, change your password immediately and report the incident.
Ransomware is malicious software that can lock a device or encrypt files and demand payment for access.
Reduce your risk by:
- keeping operating systems and software updated;
- avoiding unexpected links and attachments;
- installing software only from trusted sources;
- maintaining approved backups of critical information;
- limiting unnecessary administrative privileges; and
- reporting suspicious activity promptly.
If you suspect ransomware or another serious malware infection on a device, disconnect the affected device from the network when it is safe to do so and contact Information Security.
Secure Remote Work and Access
Some CSUN systems and resources require the university VPN when accessed remotely.
Use the VPN when required by the service you are accessing or when instructed by Information Technology.
Avoid conducting sensitive university business over unknown or untrusted public Wi-Fi networks.
When working remotely:
- use trusted networks whenever possible;
- protect your screen from unauthorized viewing;
- lock your computer when stepping away; and
- store university information only in approved systems.
Zoom meetings involving confidential or sensitive university information should use appropriate security controls.
Depending on the meeting, controls may include:
- authentication;
- waiting rooms;
- meeting passcodes;
- restricted screen sharing;
- participant management; and
- controlled recording access.
Required Security and Privacy Training
Faculty, staff, and student employees are required to complete assigned Information Security Awareness training in accordance with CSU and CSUN requirements.
Training frequency may vary based on job responsibilities and access to confidential information.
Employees with privileged access or access to confidential data may be assigned more frequent or specialized training.
FERPA and student-record privacy content is also included in applicable university training.
Access CSUN Security and FERPA Training Information
Security Alerts and Updates
Information Security publishes guidance about security threats, vulnerabilities, phishing campaigns, and other issues that may affect the CSUN community.
Review current alerts when you receive a campus security notification or want information about an emerging threat.
Visit CSUN Information Security
Faculty and Staff Security Checklist
Use these practices as part of your regular work:
- Use Duo Multi-Factor Authentication when prompted.
- Never share your CSUN password or MFA code.
- Verify unexpected requests before responding.
- Store confidential data only in approved systems.
- Protect student education records.
- Keep your devices and software updated.
- Use encryption when required.
- Use the CSUN VPN when required for remote access.
- Secure Zoom meetings that involve protected information.
- Complete assigned security and privacy training.
- Report phishing, malware, suspected account compromise, and possible data exposure promptly.
Report a Security Concern
IT Help Center
Contact the IT Help Center for assistance with passwords, Duo, VPN, account access, software, and other technical issues.
Phone: (818) 677-1400
Information Security
Contact Information Security for suspected security incidents, phishing, account compromise, malware, data exposure, or questions about information-security requirements.
Phone: (818) 677-6100
Email: iso@csun.edu