skip to main contentskip to footer

Quick links

  • Athletics
  • Make a gift
  • Newsroom
  • Job openings
  • Employee directory
  • Apply
  • Costs
  • Explore
Explore U of I
  • Visit and virtual tour
  • Student life
  • Find your degree
  • Get around campus
  • Meet Moscow
  • Join our email list
  • Events
  • Join ZeeMee
  • Athletics
Academics
  • Academic calendar
  • Find a major
  • Student support resources
  • Undergrad research opportunities
  • Meet the colleges
  • Online learning
  • Explore in-demand careers
Admissions
  • Meet your counselor
  • Deadlines
  • First-year students
  • Graduate students
  • Law students
  • Online students
  • Transfer students
  • International students
  • Admitted students
Financial aid
  • Cost of attendance
  • Steps for financial aid
  • FAFSA information
  • Financial aid FAQs
  • In-state scholarships
  • Out-of-state and international scholarships
  • Connect with financial aid
More
  • Student life
  • Research
  • Recreational offerings
  • Student resources
  • Alumni
  • Parents
  • Newsroom
  • Events
  • Sustainability initiatives
Find your passion - Explore majors Become a Vandal - Start an application
  • U of I news
  • Make a gift
  • Athletics
  • Directory
Events
Residence Hall Move-in
Welcome home! Move into your residence hall and start settling in for the 2025–26 academic year.
New Student Orientation
Orientation helps you navigate campus life, connect with your peers and prepare for your first semester at U of I.
Week of Welcome
Aug. 19-24, 2025 | Celebrate the start of a new academic year with a full week of fun, informative and community-building events for all Vandals.
Events
News
Student Dan Lauritzen working in the drone lab with Jason Karl for the College of Natural Resources
Drone lab supports aerial-based research
University of Idaho Fall 2023 Start up events.
Five reasons to join a U of I club or organization
News
Support a Vandal - Make a gift
  • Apply
  • Costs
  • Explore
  • Explore
  • Academics
  • Admissions
  • Financial Aid
  • Student life
  • Research
  • Recreational offerings
  • Student resources
  • Alumni
  • Parents
  • Newsroom
  • Events
  • Sustainability initiatives

Maintenance

  • leadership
  • President's Office
  • Provost's Office
  • Finance and Administration
  • General Counsel
  • Information technology
  • leadership
  • President's Office
  • Provost's Office
  • Finance and Administration
  • General Counsel
  • Information technology
leadership
  • President's Office
  • Provost's Office
  • Finance and Administration
  • General Counsel
  • Information technology
  1. Home/
  2. leadership/
  3. Information technology/
  4. IT standards/
  5. Maintenance

Overview

This updated standard is to help align existing practices within Office of Information Technology (OIT) around maintenance controls to the requirements in NIST 800-171 (MA | 3.7.x) as well as industry best practices. This document does not give full coverage of 3.7.x controls within 171 due to existing limitations and other requirements that are specific to CUI.

What is in this document:

  • Patching requirements
  • Access control tie-in for remote maintenance
  • Security requirements for third party repairs

What is NOT in this document:

  • Patching procedures or methods
  • Remote maintenance procedures or methods
  • Approved third party repair providers  
     

Policy reference

  • APM 30.11 University Data Classification and Standards
  • APM 30.12 Acceptable Use of Technology Resources
  • APM 30.14 Cyber Incident Reporting and Response
  • APM 30.15 Technology Hardware Lifecycle Management

Purpose
This Access Control standard supports APM 30.11 University Data Classification and Standards and other relevant university policies.

Scope
These standards are the minimum baseline for all managed and unmanaged systems that access, store or process University of Idaho data (see APM 30.14 C-6) or using University of Idaho technology resources (see APM 30.12 C-1) at the Low, Moderate- or High risk levels (see APM 30.11) not otherwise covered by an approved systems security plan.

Standards

U of I Office of Information Technology (OIT) is responsible for the content and management of these standards.

To request an exception to this standard contact: oit-security@uidaho.edu 

1. Patch management

Only run operating systems which are currently supported and patched. Apply security patches to address flaws in systems and applications automatically, or within 10 days.

  1. Patches may be applied in a timeframe approved through a risk-based vulnerability assessment process approved by the OIT Security Office and all affected data and system owners.
    Applies to: Low / Moderate / High
2. Remote maintenance

Authentication for remote maintenance must go through authenticated channels compliant with Access Control and Identification and Authentication standards.

Applies to: Low / Moderate / High

3. Third-party repairs
  1. Prior to sending equipment back to vendors or third parties for repairs that are unable to be done in-house, systems must be sanitized using the standards described in Media Protection
    Applies to: High
  2. Prior to sending equipment back to vendors or third parties for repairs that are unable to be done in-house, systems must be either encrypted using OIT-Managed encryption or sanitized using the standards described in Media Protection.
    Applies to: Moderate
  3. Keys, passwords or other authentication secrets for accessing university technology resources must not be shared with third parties, as required by APM 30.15.
    Applies to: Low / Moderate / High
    1. Temporary credentials assigned only to vendor must be used if access is required to perform or validate repairs.
  4. Any maintenance on site by third parties must be supervised unless operating under an approved contract.
    Applies to: Moderate / High

Other references

  1. NIST SP800-171r2 (February 2020)
  2. NIST SP800-53r5 (September 2020)
  3. Media Protection standard

Definitions

  1. Security patches

    Updates or fixes released by vendors to resolve a security vulnerability.

  2. Remote maintenance

    Accessing a system via a network connection for the purpose of working on the system itself.

  3. Third party

    Any entity that is not an owner, user or otherwise authorized individual within a system. This may include university affiliates that are not authorized for a specific system.

Revision history

3/1/2024 — Minor updates

  • Minor formatting/wording/reference changes.

6/23/2023 — Original standard

  • Full re-write to align with NIST 800-171r2

Footer

Ready to apply?

Start your application
Joe Vandal head illustration

Footer Navigation

Resources

  • Policies
  • Privacy statement
  • Web accessibility
  • Title IX

Campus

  • Directory
  • Map
  • Safety
  • Events

Information For

  • Prospective students
  • Current students
  • Parents
  • Employees
Logo

University of Idaho

875 Perimeter Drive, Moscow, ID 83844

208-885-6111

info@uidaho.edu

Engage with U of I on Facebook. Get the latest U of I updates on X. Catch up with U of I on Instagram. Grow your professional network by connecting with U of I on LinkedIn. Interact with University of Idaho's video content on YouTube. Join the University of Idaho ZeeMee conversation.
Support a Vandal - Make a gift
  • Athletics
  • Jobs
  • News

© 2025 University of Idaho