Role: System Administrator

  • Secure deletion

    by

    Securely delete information when it is no longer required by means that make it impossible to reconstruct the records.

  • Copiers & shared devices

    by

    Remove information on copiers, fax machines, or other shared devices promptly.

  • Mailing physical media

    by

    Use appropriately secure means when transferring physical media containing information. Track transfers to confirm that they reached the intended recipient.

  • Limit physical access

    by

    Limit physical access to organizational systems, equipment, and the respective operating environments to authorized individuals.

  • Incident Reporting

    by

    Promptly report actual or suspected compromise, including loss, theft, improper use, modification of, or access to information to security@mit.edu.

  • Self Assessment

    by

    Review your systems and procedures regularly to ensure the tasks for this risk level are applied.

  • Security by design

    by

    If you are developing (or contracting a vendor to develop) applications processing this level of information, include security as a design requirement.

  • Code review

    by

    If you are developing (or contracting a vendor to develop) applications processing this level of information, review code and correct flaws prior to deployment.

  • Annual Review

    by

    Contact security@mit.edu for an annual review to verify that all security tasks are working properly.

  • Payment processing

    by

    If you are accepting credit card payments, you may need to complete additional tasks. Please contact infoprotect@mit.edu