zotdefend
Differences
This shows you the differences between two versions of the page.
Both sides previous revisionPrevious revisionNext revision | Previous revision | ||
zotdefend [2025/05/19 19:57] – jnilsson | zotdefend [2025/06/30 13:06] (current) – [Method One (preferred): Book an appointment with SSCS] jnilsson | ||
---|---|---|---|
Line 1: | Line 1: | ||
====== ZotDefend security package information ====== | ====== ZotDefend security package information ====== | ||
- | {{:: | + | [[https:// |
- | Below you can find a brief summary of the information we currently have available about the ZotDefend program. | + | ===== What is ZotDefend? ===== |
+ | ZotDefend is OIT's branding for the programs and policies that are being enforced in response to the {{ :: | ||
- | ===== Book an appointment with SSCS to get ZotDefend | + | More information about ZotDefend, including what needs to be installed, can be found in the [[# |
- | Send us an email ([[sscs@uci.edu]]) | + | ===== Temporary Exemption ===== |
+ | If you need to quickly access a site that has been blocked, you can request | ||
- | {{:proptag.png?200|}} | + | * [[https://activate.uci.edu/ |
- | The appointment should take 15-30 minutes, during which we will install an application called BigFix. This will add the computer to our inventory | + | You may do this on personal devices |
- | ===== Two stages | + | ===== How to set up ZotDefend |
- | Only stage 1 is being implemented right now: | + | ==== Method One (preferred): Book an appointment with SSCS ==== |
- | ===== 1. Minimum Requirements for the UCOP Mandate ===== | + | Send us an email ([[sscs@uci.edu]]) to make an appointment to set up the ZotDefend requirements on your computer. This is only required on university-owned computers, not on tablets, phones, or personal devices. |
- | The [[https:// | + | === Property Tag === |
- | We will use an application called BigFix to install the following packages: | + | Please provide your computer' |
+ | |||
+ | {{: | ||
+ | |||
+ | === Appointment info === | ||
+ | |||
+ | The appointment should take 15-30 minutes, during which we will install | ||
+ | |||
+ | We will use BigFix to install the following packages: | ||
* [[https:// | * [[https:// | ||
* [[https:// | * [[https:// | ||
+ | * [[https:// | ||
- | ==== BigFix Installer | + | ==== Method Two: Install the ZotDefend components on your own ==== |
- | You can download the installer | + | === Instructions |
+ | If you use a Windows | ||
- | * For Mac: [[https:// | ||
* For Windows: [[https:// | * For Windows: [[https:// | ||
- | The BigFix installer is password protected. We will provide the password to open the .zip archives during our appointment with you. | + | The BigFix installer is **password protected**. We will provide the password to open the .zip after you have sent us the property tag for your computer. See the example image above for what a [[ # |
- | If you are installing this on your own, please email us ([[sscs@uci.edu]]) with the computer' | + | After BigFix is installed, we can use that to automate |
- | {{: | + | === Instructions for Mac computers === |
- | ===== 2. Enforcement of more strict security standards ===== | + | If you use a Mac computer, then we recommend scheduling an appointment with us by contacting us via email ([[sscs@uci.edu]]). You can install BigFix, but we have observed that BigFix will usually not install Trellix HX correctly. If the installation ends in a broken state, then we must manually uninstall and reinstall it. |
- | This will not be implemented right away, but in the future OIT is discussing requiring the following additional security policies: | + | If you want to install BigFix on your own, you can use this link: |
- | * the above minimum packages, plus | + | * For Mac: [[https:// |
- | * Duo Desktop | + | |
- | * Full Disk Encryption | + | |
- | * MS Defender | + | |
- | * Jamf/Intune device management enrollment | + | |
- | They would enforce this by blocking access | + | The BigFix installer is **password protected**. We will provide the password |
- | ===== OIT information about ZotDefend ===== | + | === Instructions for Linux computers |
- | Here are the OIT published pages about the ZotDefend project: | + | Please reach out to us via email ([[sscs@uci.edu]]) to let us know which computer(s) you are setting this up on and we can send you an installation script. When you reach out to us, please provide |
- | * [[https:// | + | ===== Frequently Asked Questions about ZotDefend |
- | * [[https:// | + | |
- | * [[https:// | + | |
- | * [[https:// | + | |
- | ===== FAQs about ZotDefend ===== | + | ==== How do I request an exemption? ==== |
- | + | ||
- | ==== How do I request an exception? ==== | + | |
If you need to log in to a site that is blocked because you do not yet have the ZotDefend security packages installed, you can use the link below to request a 24-hour exemption: | If you need to log in to a site that is blocked because you do not yet have the ZotDefend security packages installed, you can use the link below to request a 24-hour exemption: | ||
- | * [[http:// | + | * [[https:// |
+ | You may do this on personal devices and as often as needed. | ||
==== What are the software components being installed? ==== | ==== What are the software components being installed? ==== | ||
- | For now, these three components are being installed on Windows and Mac computers: | + | |
- | | + | |
* [[https:// | * [[https:// | ||
* [[https:// | * [[https:// | ||
+ | * [[https:// | ||
- | Linux computers only need the Trellix HX and Tenable Nessus | + | |
+ | ==== Which websites require Duo Desktop, in addition to Trellix HX and Tenable Nessus? ==== | ||
+ | |||
+ | Duo Desktop is required in order to verify your device' | ||
+ | * KFS | ||
+ | * Docusign | ||
+ | * Atlassian | ||
+ | * OneTrust | ||
+ | * [[https:// | ||
+ | |||
+ | Please be aware that OIT might change the security requirements and/or the list of sites and services that require enforcement. We will update this page as more information becomes available. | ||
==== What is the UC Cybersecurity Mandate? ==== | ==== What is the UC Cybersecurity Mandate? ==== | ||
- | OIT has a detailed overview page at the following link that provides a good overview | + | OIT has a detailed overview page at the following link that reviews each component |
* [[https:// | * [[https:// | ||
Line 99: | Line 112: | ||
- deploy, enable, and configure multi-factor authentication (MFA) on email systems | - deploy, enable, and configure multi-factor authentication (MFA) on email systems | ||
* this is done by requiring DUO when logging in to gmail and outlook email systems | * this is done by requiring DUO when logging in to gmail and outlook email systems | ||
+ | |||
+ | ==== Is ZotDefend required on personal computers too? ==== | ||
+ | |||
+ | No, it is neither required nor recommended to install or configure any of this on computers/ | ||
+ | |||
+ | Keep in mind that tablets, phones, and similar devices are also exempt from the ZotDefend project. | ||
+ | |||
+ | ==== But I use a personal computer for work... ==== | ||
+ | |||
+ | If you do not have a university-owned computer (purchased either with school funds or grant funding), reach out to us at [[sscs@uci.edu]] and we can help you determine what to do. | ||
+ | |||
+ | ==== What has OIT published about ZotDefend? ==== | ||
+ | |||
+ | Here are the OIT published pages about the ZotDefend project: | ||
+ | |||
+ | * [[https:// | ||
+ | * [[https:// | ||
+ | * [[https:// | ||
+ | * [[https:// | ||
+ | |||
+ | ==== What do I do if I installed ZotDefend following OIT's self-enrollment instructions? | ||
+ | |||
+ | Please reach out to us ([[sscs@uci.edu]]) and let us know the [[ # | ||
+ | |||
+ | ==== What is UCOP's response to my concerns about Trellix? ==== | ||
+ | |||
+ | UCOP has released the following statement regarding concerns about the EDR software, Trellix HX: | ||
+ | |||
+ | * [[https:// | ||
+ | |||
+ | There is also an FAQ which covers questions about compatible devices, privacy/ | ||
+ | |||
+ | * [[https:// | ||
[[https:// | [[https:// |
zotdefend.1747684649.txt.gz · Last modified: 2025/05/19 19:57 by jnilsson