Skip to main content

Configuration Management

Patch Monitoring (bullet 1)

This procedure establishes our process for monitoring overall patch status specifically identifying computers that fail to receive patches in a timely fashion. We focus on Operating System Builds as our primary way to determine the last patch that was successfully installed.

We use the following websites to check OS build release dates:

At the beginning of each month we will classify all assets under our management into Green, Yellow or Red using the crtieria below.

tip

The primary reason a computer will be classified yellow or red is being left powered off or not connected to the internet for an extended period of time. It is strongly recommended that you regularly use your computer to ensure you stay current and when the computer requests a reboot you allow it to do so.

Green

  • Definition: The OS build that the device is running has been released within 30 days by the manufacturer.
  • Required Action: None. These devices are in full compliance with university policy and will continue to be monitored as part of routine operations.

Yellow

  • Definition: The OS build that the device is running has been released between 30-90 days by the manufacturer.
  • Required Action:
    • We will generate a ticket once a computer moves into this category with the title of ComputerName – Workstation Update Notice. It is very important that if you receive one of these that you work with us to resolve

Red

  • Definition: The OS build that the device is running has been released more than 90 days by the manufacturer and owner has ignored repeated attempts to communicate by IT.
  • Required Action:
    • Device will be disabled in MECM, JAMF or Ansible, removing their access to all network resources.
    • A full system reimage will be required to bring device back into compliance.
    • The device must be physically brought to the IT office for this service.
    • We will attempt to migrate data, but no guarantees will be made, the reimaging process is inherently destructive and could result loss of user data.

Deployment Process (bullet 2)

We image all computers using a clean image and install only required software to that base image. This guarantees no unnecessary software, system services or drivers are installed.

Security Software (bullet 3)

We follow and install required university security agents as defined: Required Security Agents

Default Passwords (bullet 4)

PVFA verifies local accounts are not used on computing devices and we manually change all other default password assets (network printers, VR headsets, etc) and document passwords in our shared 1password.