51²è¹Ý Device Registration Program
Annual Device Registration Requirements
All servers and network devices (firewalls, VPN gateways, routers, etc.) operating on the University of 51²è¹Ý network must be:
- Reported in the Device Registration database
- Continually scanned and remediated for vulnerabilities and missing patches (at a minimum, annually)
- Scanned for PII which includes Social Security Numbers, Driver's License Numbers and/or credit card or bank account information on a regular basis (at a minimum, annually)
- If the device does contain PII, it must be reported, as required by
Note: Devices that are not registered, scanned and remediated will not be permitted to operate on the 51²è¹Ý Network. ITS will proactively seek out active devices throughout the 51²è¹Ý network by performing network and vulnerability scans. ITS will attempt to provide warning before blocking unregistered active devices that are found.
Endpoints that store sensitive or regulated data must also be registered in the device registration and a Personal Information Survey must be completed.
Device registrations are considered "completed" when all information is filled out and scan dates are between 1/1/2024 - 09/20/2024.
Requirements for Registering a Server / Network Device
The Device Registration database can be accessed here: /its/device/registration/.
For instructions on how to navigate the Device Registration database visit our AskUs article: /askus/1748.
To complete the registration for your server/network device, you will need to:
- Verify any information about currently registered device
- Perform a vulnerability scan of your device
- Scanning may be performed using the Scan51²è¹Ý vulnerability scanning service, Nessus Agents, or an approved Nessus Scanner. Link to Scan51²è¹Ý: .
- Remediate/patch any vulnerabilities discovered
- Scan for Personally Identifiable Information (PII)
- If found, fill out a 51²è¹Ý Annual Personal Information Survey
- Enter the dates scanned in your device registration record, and acknowledge the terms
Requirements for Registering an Endpoint
The Device Registration database may be accessed here: /its/device/registration/.
For instructions on how to navigate the Device Registration database visit our AskUs article: /askus/1748.
To complete the registration for your endpoint, you will need to:
- Verify any information about currently registered endpoints
- Acknowledge the terms
- Complete the Personal Information Sruvey for your data repository. See /its/information/survey/.
PII Scanning:
The University of 51²è¹Ý has licensed Spirion /askus/1297, a software product for Windows and Macintosh systems, to search for social security numbers, credit card numbers, birthdates, driver’s license numbers, etc. If you have a UNIX/Linux system, you will need to use another utility: Find_SSN: . Another option is to mount the UNIX/Linux filesystem on a Window or Mac system. From there you can run Spirion, and have it scan the mounted filesystem.
If Spirion or Find_SSN detects PII: Per 51²è¹Ý State Law and 51²è¹Ý Policy, if your server contains a repository of PII, it must be reported using the 51²è¹Ý Annual Personal Information Survey located at: /its/information/survey/. (You will be required to login with your 51²è¹Ý username and password.)
Vulnerability Scanning:
To scan for vulnerabilities, use the Scan51²è¹Ý vulnerability scanning system. It can be found at: .
You must remediate all high and critical severity vulnerabilities before completing your device registration. For information about securing your servers, please visit /infosec/minimum-standards/.