skip to main contentskip to footer

Quick links

  • Athletics
  • Make a gift
  • Newsroom
  • Job openings
  • Employee directory
  • Apply
  • Costs
  • Explore
Explore U of I
  • Visit and virtual tour
  • Student life
  • Find your degree
  • Get around campus
  • Meet Moscow
  • Join our email list
  • Events
  • Join ZeeMee
  • Athletics
Academics
  • Academic calendar
  • Find a major
  • Student support resources
  • Undergrad research opportunities
  • Meet the colleges
  • Online learning
  • Explore in-demand careers
Admissions
  • Meet your counselor
  • Deadlines
  • First-year students
  • Graduate students
  • Law students
  • Online students
  • Transfer students
  • International students
  • Admitted students
Financial aid
  • Cost of attendance
  • Steps for financial aid
  • FAFSA information
  • Financial aid FAQs
  • In-state scholarships
  • Out-of-state and international scholarships
  • Connect with financial aid
More
  • Student life
  • Research
  • Recreational offerings
  • Student resources
  • Alumni
  • Parents
  • Newsroom
  • Events
  • Sustainability initiatives
Find your passion - Explore majors Become a Vandal - Start an application
  • U of I news
  • Make a gift
  • Athletics
  • Directory
Events
Residence Hall Move-in
Welcome home! Move into your residence hall and start settling in for the 2025–26 academic year.
New Student Orientation
Orientation helps you navigate campus life, connect with your peers and prepare for your first semester at U of I.
Week of Welcome
Aug. 19-24, 2025 | Celebrate the start of a new academic year with a full week of fun, informative and community-building events for all Vandals.
Events
News
Student Dan Lauritzen working in the drone lab with Jason Karl for the College of Natural Resources
Drone lab supports aerial-based research
University of Idaho Fall 2023 Start up events.
Five reasons to join a U of I club or organization
News
Support a Vandal - Make a gift
  • Apply
  • Costs
  • Explore
  • Explore
  • Academics
  • Admissions
  • Financial Aid
  • Student life
  • Research
  • Recreational offerings
  • Student resources
  • Alumni
  • Parents
  • Newsroom
  • Events
  • Sustainability initiatives

System and communications protection

  • leadership
  • President's Office
  • Provost's Office
  • Finance and Administration
  • General Counsel
  • Information technology
  • leadership
  • President's Office
  • Provost's Office
  • Finance and Administration
  • General Counsel
  • Information technology
leadership
  • President's Office
  • Provost's Office
  • Finance and Administration
  • General Counsel
  • Information technology
  1. Home/
  2. leadership/
  3. Information technology/
  4. IT standards/
  5. System and communications protection

Overview

This updated standard is to help align existing IT practices around System and Communications Protection to the requirements in NIST 800-171 (SC | 3.13.x) as well as industry best practices. This document does not give full coverage of 3.13.x controls within 171 due to existing limitations and other requirements that are specific to CUI.

What is in this document:

  • System firewall requirement
  • Some firewall configuration requirements
  • Requirement for public systems to separate networks from non-public systems

What is NOT in this document:

  • Network logging requirements (AU standard)
  • Complete firewall configuration requirements 

Policy Reference

  • APM 30.11 University Data Classification and Standards
  • APM 30.12 Acceptable Use of Technology Resources
  • APM 30.14 Cyber Incident Reporting and Response

Purpose
This Access Control standard supports APM 30.11 University Data Classification and Standards and other relevant university policies.

Scope
These standards are the minimum baseline for all managed and unmanaged systems that access, store or process University of Idaho data (see APM 30.14 C-6) or using University of Idaho technology resources (see APM 30.12 C-1) at the Low, Moderate- or High risk levels (see APM 30.11) not otherwise covered by an approved systems security plan.

Standards

U of I Office of Information Technology (OIT) is responsible for the content and management of these standards.

To request an exception to this standard contact: oit-security@uidaho.edu 

1. Network boundary requirements

To ensure network connectivity is monitored, controlled and protected to adequate levels:

  1. All systems capable of running a host-based firewall, must have it turned on and configured consistent with the principles of least privilege.
  2. Both the external (north-south) and internal (east-west) edges of U of I Internal Networks must be monitored as per the Audit and Accountability standard.
  3. Both the external (north-south) and internal (east-west) edges of U of I managed networks must have a default block rule.

    1. Exceptions to the default block action must go through change management approval.
       

    Both the external (north-south) and internal (east-west) edges of U of I Internal Networks must be scanned using inline protection tools such as IPS.

    1. Instances that cannot use inline protections such as the Science DMZ must use out-of-path protections as approved by OIT Security.
2. Public systems

Implement subnetworks for publicly accessible system components that are physically or logically separated from internal networks.

  1. Public Systems must be registered with OIT Security as per Access Control standard.
    1. OIT Security May scan public U of I IP space to review what is and is not a public system and may respond to those accordingly.
  2. Non-public university-managed technology resources must be on separate VLANs from Public Systems.
    Applies to: Moderate and High
3. Split tunneling

Split tunneling must not be implemented unless specifically approved by OIT Security.

Other references

  1. NIST SP800-171r2 (February 2020)
  2. NIST SP800-53r5 (September 2020)
  3. NIST SP 800-94 (February 2007)
  4. NIST SP 800-113 (July 2008)
  5. CMMC glossary
  6. Audit and Accountability standard
  7. Access Control standard
  8. What are Azure AD "Named Locations"?

Definitions

  1. Firewall

    “A device or program that controls the flow of network traffic between networks or hosts that employ differing security postures.” (CMMC Glossary)

  2. U OF I internal networks

    Networks controlled by University of Idaho excluding networks for student or public systems such as AirVandalHome or AirVandalGuest as defined by ‘What are Azure AD "Named Locations"?’ (3.13.1[a-b])

  3. Public system

    A system that can be accessed in any form from the general public or internet.

  4. Intrusion Prevention System (IPS)

    “Software that has all the capabilities of an intrusion detection system and can also attempt to stop possible incidents. Also called an intrusion detection and prevention system.” (NIST SP800-94)

  5. Virtual Private Network (VPN)

    “A virtual network built on top of existing networks that can provide a secure communications mechanism for data and IP information transmitted between networks.” (NIST SP800-113)

  6. Internal network edge

    The boundary between two internal networks. Also referred to as east-west traffic.

  7. External network edge

    The boundary between an internal network and external network. Also referred to as north-south traffic.

  8. Split tunneling

    “The process of allowing a remote user or device to establish a non-remote connection with a system and simultaneously communicate via some other connection to a resource in an external network. This method of network access enables a user to access remote devices (e.g., a networked printer) at the same time as accessing uncontrolled networks.” (NIST SP800-171)Revision History

3/1/2024 — Minor updates

  • Minor formatting/wording/reference changes.

6/23/2023 — Original standard

  • Full re-write to align with NIST 800-171r2

Footer

Ready to apply?

Start your application
Joe Vandal head illustration

Footer Navigation

Resources

  • Policies
  • Privacy statement
  • Web accessibility
  • Title IX

Campus

  • Directory
  • Map
  • Safety
  • Events

Information For

  • Prospective students
  • Current students
  • Parents
  • Employees
Logo

University of Idaho

875 Perimeter Drive, Moscow, ID 83844

208-885-6111

info@uidaho.edu

Engage with U of I on Facebook. Get the latest U of I updates on X. Catch up with U of I on Instagram. Grow your professional network by connecting with U of I on LinkedIn. Interact with University of Idaho's video content on YouTube. Join the University of Idaho ZeeMee conversation.
Support a Vandal - Make a gift
  • Athletics
  • Jobs
  • News

© 2025 University of Idaho