Skip Navigation
University of Maryland Global Campus University of Maryland Global Campus
  • Locations
    • U.S. Locations
    • UMGC Asia
    • UMGC Europe
    • Learn Online
  • Get Help
    • Find Answers
    • Chat Now
    • Email Us
  • 855-655-8682
  • Current Students
Login
Request Info
Apply Now
  • Leadership & Governance
    Leadership & Governance
    • Office of the President
    • Strategic Plan
    • Boards and Committees
    • Executive Committee
    • Maryland Cybersecurity Council
    • Shared Governance
    • Academic Advisory Board
    • Adjunct Faculty Association
    • Student Advisory Council
    Related Links
    • Awards and Recognition
    • Mission and History
    • Regional Accreditation
    • University System of Maryland Membership
  • Arts
    Arts
    • Arts Program
    • Art Exhibitions
    • Art Collections
    • Art Talks
    • Art Galleries and Hours
    • UMGC TV
  • Policies & Reporting
    Policies & Reporting
    • Institutional Data
    • Facts at a Glance
    • Fact Book and Fact Sheet Archive
    • Policies
    • Academic Affairs Policies
    • Administration Policies
    • External Relations Policies
    • Faculty Policies
    • Fiscal and Business Affairs Policies
    • General Policies
    • Human Resources Policies
    • Info Governance, Security & Technology Policies
    • Research Policies
    • Student Affairs Policies
    • Fair Practices
    • Sexual Misconduct (Title IX)
    • Suspected Child Abuse and Neglect
  • Jobs At UMGC
    Jobs At UMGC
    • Apply for a Job
    • Who We Are
    • Culture
    • Faculty Careers
    • Professional Careers
    • Benefits
    • Careers FAQs
    • Community Engagement
    • New Hire Orientation
    • New Hire Onboarding
    • Benefits Enrollment Information
    • Retirement Enrollment Information
  • UMGC Blog
  • UMGC Podcast
    • U.S. Locations
    • UMGC Asia
    • UMGC Europe
    • Learn Online
    • Find Answers
    • Chat Now
    • Email Us
  • 855-655-8682
  • Current Students
Request Info
Apply Now
Skip to Menu Toggle Button

UMGC Policy X-1.10 UMGC Policy on Identity and Access Management

  1. University of Maryland Global Campus
  2. Administration
  3. Policies & Reporting
  4. Policies
  5. Info Governance, Security, & Technology Policies
  6. UMGC Policy on Identity and Access Management

EXPLORE MORE OF UMGC

  • Administration
    • Policies & Reporting
      • Policies
        • Info Governance, Security, & Technology Policies
Policy CategoryPolicy OwnerVersion Effective DateReview CycleLast ReviewedPolicy Contact
X. Info. Governance, Security & TechnologySVP, General Counsel, and Chief People OfficerNovember 26, 2024Every 2 yearsNovember 26, 2024Information Governance
  1. Purpose

    This Policy establishes information security standards for the identity and access management processes relevant to University Information Technology Resources.

  2. Scope and Applicability

    This Policy applies to all University Information Systems and Information Technology Resources. All Users are responsible for adhering to this Policy.

  3. Definitions

    Defined terms are capitalized throughout this Policy and can be found in the Information Governance Glossary.

  4. Account Management
    1. Information System Stewards must adhere to the University's Account Management Policies, UMGC Policy X-1.19A Account Management (UMGC Learner Community) and UMGC Policy X-1.19B Account Management (UMGC Workforce), when creating, administering, and disabling University Accounts.
    2. Users must take security awareness training within 90 days of their hire date as required by UMGC Policy X-1.05 Information Security Awareness and Training Policy.
  5. Authentication
    1. University Information Resources that provide authentication services shall uniquely identify (e.g., username) Users prior to allowing access to the said systems.
    2. Whenever possible and reasonable, any application or Information System, whether on premise or in the cloud, should use Single Sign-on authentication.
    3. Unique identifiers shall not be reused once assigned to a User.
    4. Multi-Factor Authentication (MFA) should be used to protect Critical Information Systems (CIS) whenever possible and reasonable to do so.
    5. Passwords must be constructed in accordance with the minimum requirements of the most recent University System of Maryland IT Security Standards and where technically feasible, should further meet the following requirements:
      1. Authorized User Account passwords must meet a minimum length of 12 characters.
      2. Administrative and Privileged Account passwords must meet a minimum length of 12 characters.
      3. Passwords must contain a mix of alphanumeric characters. Passwords must not consist of all digits, all special characters, or all alphabetic characters.
      4. Automated controls must ensure that passwords are changed at least annually for general Users, and at 90-day intervals for administrative- level accounts.
      5. User IDs associated with a password must be disabled for a period of time after not more than 6 consecutive failed login attempts. A minimum of 10 minutes is required for the reset period.
      6. Password must not be the same as the User ID.
      7. Store and transmit only encrypted representation of passwords.
      8. Passwords must not be displayed on screens.
      9. Users must not share passwords except with other approved Users of an Account that has been documented as a Functional ID. Functional ID passwords must be changed upon termination or transfer of an Employee or Contractor with whom the Account password(s) have been shared.
      10. Initial passwords and password resets must be issued pre-expired forcing the User to change the password upon first use.
      11. Password reuse must be limited by not allowing the last 10 passwords to be reused. In addition, password age must be at least 2 days before it can be reset.
      12. When a User password is reset or redistributed, the validation of the User identity must be at least as strong as when originally established.
      13. Expired passwords must be changed before any other system activity is allowed.
  6. Auditing
    1. Information System Stewards are responsible for ensuring that audit trails are maintained to record appropriate events and actions occurring in the Information System.
    2. Audit procedures are to be defined to periodically review the audit records of Information Systems for unusual or suspicious activities or suspected violations.
  7. Exceptions

    Exceptions to this Policy should be submitted to Information Security for review and approval. If an exception is requested, a compensating control or safeguard should be documented and approved.

  8. Enforcement
    1. Any Employee, Contractor, or third-party performing duties on behalf of the University with knowledge of an alleged violation of this Policy shall notify Information Security as soon as practicable.
    2. Any Employee, Contractor, or other third-party performing duties on behalf of the University who violates this Policy may be denied access to Information Resources and may be subject to disciplinary action, up to and including termination of employment or contract or pursuit of legal action.
  9. Standards Referenced
    1. USM IT Security Standards, v.5, dated July 2022
    2. NIST SP 800-171r3 “Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations”, dated May 2024
    3. Cybersecurity Maturity Model Certification (CMMC), v.2.0, dated December 2021
  10. Related Policies
    1. UMGC Policy X-1.02 Data Classification 
    2. UMGC Policy X-1.04 Information Security 
    3. UMGC Policy X-1.05 Information Security Awareness and Training Policy
    4. UMGC Policy X-1.06 Information Security Incident Response 
    5. UMGC Policy X-1.12 Acceptable Use 
    6. UMGC Policy X-1.19A Account Management (UMGC Learner Community) 
    7. UMGC Policy X-1.19B Account Management (UMGC Workforce)
Request Info
Apply Now
Quick Links
  • Academic Calendar
  • Schedule of Classes
  • Submit Transcripts
  • Request Transcripts
  • Library
  • Events
  • News
  • Administration
  • University Store
  • FERPA
UMGC For
  • Prospective Students
  • Military & Veterans
  • Current Students
  • Partners
  • Alumni
  • Donors
  • Media
  • Job Seekers
Contact Us

855-655-8682
Help Center
More Contact Options
Social Links

Mailing Address
No classes or services at this location
3501 University Blvd. East,
Adelphi, MD 20783

  • Academic Calendar
  • Schedule of Classes
  • Submit Transcripts
  • Request Transcripts
  • Library
  • Events
  • News
  • Administration
  • University Store
  • FERPA
  • Prospective Students
  • Military & Veterans
  • Current Students
  • Partners
  • Alumni
  • Donors
  • Media
  • Job Seekers

855-655-8682
Help Center
More Contact Options
Social Links

Mailing Address
No classes or services at this location
3501 University Blvd. East,
Adelphi, MD 20783

University of Maryland Global Campus
UMGC is a proud member of the University System of Maryland.

Accessibility Terms & Conditions Consumer Disclosures & Policies Privacy Policy Social Media Guidelines Media Protection Title IX/Sexual Misconduct Report Fraud, Waste & Abuse Sitemap
The appearance of U.S. Department of Defense visual information does not imply or constitute DOD endorsement.
Copyright © 2025 University of Maryland Global Campus. All Rights Reserved.

By using our website you agree to our use of cookies. Learn more about how we use cookies by reading our Privacy Policy.

|