Skip Navigation
University of Maryland Global Campus University of Maryland Global Campus
  • Locations
    • U.S. Locations
    • UMGC Asia
    • UMGC Europe
    • Learn Online
  • Get Help
    • Find Answers
    • Chat Now
    • Email Us
  • 855-655-8682
  • Current Students
Login
Request Info
Apply Now
  • Leadership & Governance
    Leadership & Governance
    • Office of the President
    • Strategic Plan
    • Boards and Committees
    • Executive Committee
    • Maryland Cybersecurity Council
    • Shared Governance
    • Academic Advisory Board
    • Adjunct Faculty Association
    • Student Advisory Council
    Related Links
    • Awards and Recognition
    • Mission and History
    • Regional Accreditation
    • University System of Maryland Membership
  • Arts
    Arts
    • Arts Program
    • Art Exhibitions
    • Art Collections
    • Art Talks
    • Art Galleries and Hours
    • UMGC TV
  • Policies & Reporting
    Policies & Reporting
    • Institutional Data
    • Facts at a Glance
    • Fact Book and Fact Sheet Archive
    • Policies
    • Academic Affairs Policies
    • Administration Policies
    • External Relations Policies
    • Faculty Policies
    • Fiscal and Business Affairs Policies
    • General Policies
    • Human Resources Policies
    • Info Governance, Security & Technology Policies
    • Research Policies
    • Student Affairs Policies
    • Fair Practices
    • Sexual Misconduct (Title IX)
    • Suspected Child Abuse and Neglect
  • Jobs At UMGC
    Jobs At UMGC
    • Apply for a Job
    • Who We Are
    • Culture
    • Faculty Careers
    • Professional Careers
    • Benefits
    • Careers FAQs
    • Community Engagement
    • New Hire Orientation
    • New Hire Onboarding
    • Benefits Enrollment Information
    • Retirement Enrollment Information
  • UMGC Blog
  • UMGC Podcast
    • U.S. Locations
    • UMGC Asia
    • UMGC Europe
    • Learn Online
    • Find Answers
    • Chat Now
    • Email Us
  • 855-655-8682
  • Current Students
Request Info
Apply Now
Skip to Menu Toggle Button

UMGC Policy X-1.08 UMGC Policy on IT Resources Configuration Management

  1. University of Maryland Global Campus
  2. Administration
  3. Policies & Reporting
  4. Policies
  5. Info Governance, Security, & Technology Policies
  6. UMGC Policy on IT Resources Configuration Management Policy

EXPLORE MORE OF UMGC

  • Administration
    • Policies & Reporting
      • Policies
        • Info Governance, Security, & Technology Policies
Policy CategoryPolicy OwnerVersion Effective DateReview CycleLast ReviewedPolicy Contact
X. Information Governance, Security & TechnologySVP, General Counsel, and Chief People OfficerOctober 31, 2023Every 2 yearsJanuary 28, 2025Information Governance
  1. Purpose

    The purpose of this Policy is to establish Information Security standards for the configuration management processes relevant to University of Maryland Global Campus ("UMGC" or "University") Information Technology Resources.

  2. Scope and Applicability

    This Policy applies to all University Information Systems and Information Technology Resources. Information System Stewards and Technical System Leads are responsible for adhering to this Policy.

  3. Definitions

    Defined terms are capitalized throughout this Policy and can be found in the Information Governance Glossary.

  4. Configuration Management

    Information System Stewards or Technical System Leads should adhere to this Policy when configuring and managing University Information Technology Resources to prevent unauthorized changes from being made.

    1. Baseline Configurations and inventories of University Information Systems throughout the respective system development life cycles should be established, documented, and maintained.
    2. Information System Stewards must employ the principle of Least Functionality by configuring University Information Systems to provide only essential capabilities.
    3. User-Installed software must be controlled and monitored. The Information System Steward must ensure that all software end user licensing agreements (EULA) are reviewed and approved by the UMGC Procurement team prior to deployment on a University device.
    4. Security Configuration Settings for Information Technology Resources employed in University Information Systems must be established and enforced. Information System Stewards should document the Security-related configuration settings and apply them to all systems once tested and approved.
    5. Changes to University Information Systems must be tracked, reviewed, approved or disapproved, and logged. Configuration change control for Information Systems should involve the systematic proposal, justification, implementation, testing, review, and disposition of changes to the systems, including system upgrades and modifications.
    6. The security impact of changes should be analyzed prior to implementation and a plan established to ensure the ability to reverse a deployment or implementation.
    7. Physical and logical access restrictions associated with changes to University Information Systems should be defined, documented, approved, and enforced. Control of configuration management activities may involve:
      1. Logical access control which prevents unauthorized Users from logging onto an Information System to make configuration changes (e.g., requiring specific credentials for modifying configuration settings, patching software, or updating software libraries),
      2. Workflow automation in which configuration management workflow rules define human tasks and data or files are routed between people authorized to do configuration management based on pre-defined business rules (e.g., passing an electronic form to a manager requesting approval of configuration change made by an authorized Employee),
      3. An abstraction layer for configuration management that requires changes be made from an external system through constrained interface (e.g., software updates can only be made from a patch management system with a specific IP address), and/or
      4. Utilization of a configuration management change window.
    8. Nonessential programs, functions, ports, protocols, and services should be restricted, disabled, or prevented.
      1. All unnecessary programs and accounts are removed from all endpoints and servers.
      2. The University should apply deny-by-exception (Blacklisting) or permit-by-exception (Whitelisting) technical control policies on all Information Systems.  
      3. The University restricts the use of all unnecessary ports, protocols, and system services in order to limit entry points that attackers can use.
  5. Exceptions

    Exceptions to this Policy should be submitted to Information Security for review and approval. If an exception is requested a compensating control or safeguard should be documented and approved

  6. Enforcement
    1. Any Employee, Contractor, or third-party performing duties on behalf of the University with knowledge of an alleged violation of this Policy shall notify Information Security as soon as practicable.
    2. Any Employee, Contractor, or other third-party performing duties on behalf of the University who violates this Policy may be denied access to Information Resources and may be subject to disciplinary action, up to and including termination of employment or contract or pursuit of legal action.
  7. Standards Referenced
    1. Most recent versions:
      1. USM IT Security Standards
      2. NIST SP 800-171 “Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations”
      3. Cybersecurity Maturity Model Certification (CMMC)
  8. Related Policies
    1. UMGC Information Governance, Security, and Technology Policies
Request Info
Apply Now
Quick Links
  • Academic Calendar
  • Schedule of Classes
  • Submit Transcripts
  • Request Transcripts
  • Library
  • Events
  • News
  • Administration
  • University Store
  • FERPA
UMGC For
  • Prospective Students
  • Military & Veterans
  • Current Students
  • Partners
  • Alumni
  • Donors
  • Media
  • Job Seekers
Contact Us
  • 855-655-8682
  • Help Center
  • More Contact Options
  • Social Links

Mailing Address
No classes or services at this location
3501 University Blvd. East,
Adelphi, MD 20783

  • Academic Calendar
  • Schedule of Classes
  • Submit Transcripts
  • Request Transcripts
  • Library
  • Events
  • News
  • Administration
  • University Store
  • FERPA
  • Prospective Students
  • Military & Veterans
  • Current Students
  • Partners
  • Alumni
  • Donors
  • Media
  • Job Seekers
  • 855-655-8682
  • Help Center
  • More Contact Options
  • Social Links

Mailing Address
No classes or services at this location
3501 University Blvd. East,
Adelphi, MD 20783

University of Maryland Global Campus
UMGC is a proud member of the University System of Maryland.

Accessibility Terms & Conditions Consumer Disclosures & Policies Privacy Policy Social Media Guidelines Media Protection Title IX/Sexual Misconduct Report Fraud, Waste & Abuse Sitemap
The appearance of U.S. Department of Defense visual information does not imply or constitute DOD endorsement.
Copyright © 2026 University of Maryland Global Campus. All Rights Reserved.

By using our website you agree to our use of cookies. Learn more about how we use cookies by reading our Privacy Policy.

|