Information Security for Faculty and Staff

Protect your CSUN account, devices, and university information by following these recommended security practices and using CSUN-supported security services.

Use this page to:

  • protect your CSUN account;
  • securely store and share university information;
  • recognize phishing, ransomware, and other cyber threats;
  • access required security and FERPA training; and
  • report a suspected security incident.

Links:

Start With These Security Practices

Faculty and staff can reduce many common security risks by following a few basic practices:

  • Use Duo Multi-Factor Authentication when prompted.
  • Never share your CSUN password or MFA verification code.
  • Verify unexpected requests before clicking links, scanning QR codes, opening attachments, or sending information.
  • Store confidential university information only in approved locations.
  • Keep university and personal devices updated.
  • Use secure connections when accessing protected CSUN resources.
  • Complete assigned security and privacy training.
  • Report suspected phishing, account compromise, malware, or data exposure promptly.

If you believe your CSUN account or device has been compromised, change your password when appropriate and contact Information Security or the IT Help Center.

Protect Your Account

Duo Multi-Factor Authentication adds a second verification step when you sign in to protected CSUN services.

MFA helps protect your account even if someone obtains your password.

When using Duo:

  • approve only sign-in requests you initiated;
  • never provide an MFA verification code to another person;
  • reject unexpected Duo requests; and
  • report repeated or suspicious authentication requests.

Learn about Duo Multi-Factor Authentication at CSUN

CSUN will not ask you to provide your password by email.

To protect your account:

  • use a unique password for your CSUN account;
  • do not share passwords with coworkers, supervisors, family members, or friends;
  • do not enter your password after following an unexpected email, text-message, or QR-code link;
  • verify the website before entering your CSUN credentials; and
  • change your password promptly if you believe it has been exposed.

If an unexpected message asks for your password, MFA code, money, gift cards, or other sensitive information, verify the request using a separate trusted method.

Protect University Data

Use the appropriate CSUN service and security practice based on the type of information you are handling.

AreaRecommended PracticeResource
Confidential Level 1 DataStore approved confidential data in Confidential BoxConfidential Box
File and Device ProtectionUse appropriate encryption for protected informationEncryption
Student RecordsFollow FERPA privacy requirementsFERPA Training
Remote AccessUse the CSUN VPN when required for protected university resourcesVPN
Zoom MeetingsApply appropriate meeting security controlsZoom Security
DevicesKeep systems updated and protect against malware and ransomwareMalware and Ransomware

Links for the Resource column:

Storing Confidential Information

Confidential Box is CSUN's secure solution for storing approved Confidential Level 1 data.

Do not store unencrypted confidential information in a regular myCSUNbox account.

Confidential Box includes additional security controls, including Duo Multi-Factor Authentication. Access is limited to users who have been approved to handle confidential data.

When accessing Confidential Box off campus, a CSUN VPN connection may also be required.

Learn about Confidential Box at CSUN

Encryption protects information by making it unreadable without the appropriate key or credentials.

Encryption may be appropriate for:

  • computers and storage devices;
  • protected files;
  • confidential information sent electronically; and
  • removable storage when its use is authorized.

Use CSUN-approved encryption methods appropriate for the type of information you are handling.

Review CSUN Encryption Guidance

Protect Student Information

Faculty and staff who access student education records are responsible for protecting those records in accordance with FERPA and university requirements.

Student information that may require protection includes:

  • grades and GPA information;
  • test scores;
  • advising records;
  • student identification information;
  • educational records; and
  • other information connected to a student's academic record.

Do not make student records available to people who do not have an appropriate educational need to access them.

Complete assigned FERPA and information-security training and follow university procedures when handling student information.

Access CSUN Security and FERPA Training

Review CSUN Privacy Rights of Students in Education Records

Recognize and Respond to Cyber Threats

Phishing messages may arrive through email, text messages, QR codes, or other communication channels.

Modern phishing messages may look professional and can imitate CSUN, Microsoft, supervisors, faculty members, banks, or other trusted organizations.

Be cautious when a message:

  • asks for your password or MFA code;
  • asks you to send money or purchase gift cards;
  • directs you to an unexpected login page;
  • contains an unexpected attachment or QR code;
  • creates unusual urgency;
  • asks you to keep the request secret; or
  • comes from an address that does not match the claimed sender.

Before responding, verify unusual requests using another trusted method.

Review CSUN Phishing and Cyber Threat Guidance

If you receive a suspicious message:

  1. Do not click suspicious links.
  2. Do not scan unexpected QR codes.
  3. Do not open unknown attachments.
  4. Do not approve unexpected MFA requests.
  5. Do not send money, gift-card codes, passwords, or other sensitive information.
  6. Verify the request through a trusted source.
  7. Report suspicious email to abuse@csun.edu.

When possible, send the suspicious email as an attachment so Information Security can review the original message and its technical information.

If you entered your CSUN password on a suspicious website or approved an unexpected MFA request, change your password immediately and report the incident.

Ransomware is malicious software that can lock a device or encrypt files and demand payment for access.

Reduce your risk by:

  • keeping operating systems and software updated;
  • avoiding unexpected links and attachments;
  • installing software only from trusted sources;
  • maintaining approved backups of critical information;
  • limiting unnecessary administrative privileges; and
  • reporting suspicious activity promptly.

If you suspect ransomware or another serious malware infection on a device, disconnect the affected device from the network when it is safe to do so and contact Information Security.

Review CSUN Ransomware Guidance

Secure Remote Work and Access

Some CSUN systems and resources require the university VPN when accessed remotely.

Use the VPN when required by the service you are accessing or when instructed by Information Technology.

Avoid conducting sensitive university business over unknown or untrusted public Wi-Fi networks.

When working remotely:

  • use trusted networks whenever possible;
  • protect your screen from unauthorized viewing;
  • lock your computer when stepping away; and
  • store university information only in approved systems.

Zoom meetings involving confidential or sensitive university information should use appropriate security controls.

Depending on the meeting, controls may include:

  • authentication;
  • waiting rooms;
  • meeting passcodes;
  • restricted screen sharing;
  • participant management; and
  • controlled recording access.

Review CSUN Zoom Security Practices

Required Security and Privacy Training

Faculty, staff, and student employees are required to complete assigned Information Security Awareness training in accordance with CSU and CSUN requirements.

Training frequency may vary based on job responsibilities and access to confidential information.

Employees with privileged access or access to confidential data may be assigned more frequent or specialized training.

FERPA and student-record privacy content is also included in applicable university training.

Access CSUN Security and FERPA Training Information

Security Alerts and Updates

Information Security publishes guidance about security threats, vulnerabilities, phishing campaigns, and other issues that may affect the CSUN community.

Review current alerts when you receive a campus security notification or want information about an emerging threat.

Visit CSUN Information Security

Faculty and Staff Security Checklist

Use these practices as part of your regular work:

  • Use Duo Multi-Factor Authentication when prompted.
  • Never share your CSUN password or MFA code.
  • Verify unexpected requests before responding.
  • Store confidential data only in approved systems.
  • Protect student education records.
  • Keep your devices and software updated.
  • Use encryption when required.
  • Use the CSUN VPN when required for remote access.
  • Secure Zoom meetings that involve protected information.
  • Complete assigned security and privacy training.
  • Report phishing, malware, suspected account compromise, and possible data exposure promptly.

Report a Security Concern

IT Help Center

Contact the IT Help Center for assistance with passwords, Duo, VPN, account access, software, and other technical issues.

Phone: (818) 677-1400

Submit an IT Support Request

Information Security

Contact Information Security for suspected security incidents, phishing, account compromise, malware, data exposure, or questions about information-security requirements.

Phone: (818) 677-6100
Email: iso@csun.edu

Visit CSUN Information Security

Related Resources