MUSC Enterprise Wireless Network Policy
View/print the pdf copy.Purpose and Scope
This policy applies to all use of 2400-2483.5MHz (2.4GHz) and 5725-5850MHz (5.7GHz) bands) wireless devices. This policy includes both network and non-networked devices. MUSC reserves the use of these frequencies for the MUSC owned and operated 802.11 wireless network. All other policies covering the use of University computing services by authorized users (e.g. the MUSC Computer Use Policy) are still in effect when resources are accessed from wireless devices, as are all regulations (e.g. HIPAA and FERPA) which protect the confidentiality and integrity of information entrusted to the University's stewardship.
802.11 wireless networking technologies allow MUSC staff and guests to access networked information from any mobile device, without the restrictions on location imposed by wired connections. Wireless mobility can support diverse applications, ranging from more efficient bedside patient care, to new forms of teaching and learning in the classroom. At the same time, the broadcast nature of wireless (radio) communications raises security concerns, and carries the potential for interference between neighboring devices, if wireless devices are inappropriately installed or used naively.
For these reasons, any wireless Access Point (AP), Repeater or Bridge, which is connected to the MUSC campus network, will be treated as an extension of the campus network.Policy
No device using 2400-2483.5MHz (2.4GHz) and 5725-5850MHz (5.7GHz) frequency bands may be installed on the MUSC campus except as authorized by the OCIO-IS Network Systems Team (NST). This includes both network and non-networked wireless devices. MUSC owns and operates the airspace used by these frequencies and restricts the use of these frequencies on its main campus and at its remote sites. MUSC reserves these frequencies for the sole use of the MUSC wireless network. All wireless access points, bridges or repeaters will be centrally managed by the NST like other parts of MUSC's network infrastructure. No access point, repeater or bridge implementing 802.11 or any other wireless networking standard may be connected to the MUSC network except as authorized by the OCIO-IS Network Systems Team. The nature of a wireless network is to share bandwidth amongst mobile users on any given access point. This limits the amount of bandwidth available. The MUSC wireless network is designed to provide connectivity and bandwidth to mobile users and no stationary device should be configured to use the MUSC wireless network except as authorized by the OCIO-IS Network Systems Team (NST).
Procedures:
Network Topology
MUSC operates a controller based centrally managed and monitored wireless network. NST will configure every connected AP with specific SSIDs (wireless networks) that allow for authentication and secure communications to production networks for staff and enterprise devices. Unsecure unauthenticated access to the MUSC guest network is provided for all others.
User AuthenticationUsers connecting to the muscsecure network must be authenticated. MUSC production networks utilize WPA2 enterprise security with authentication required. The MUSC guest network does not require authentication but does requires the acceptance of a network use policy.
Data EncryptionAll sensitive information traversing wireless links connected to the MUSC network must be protected using an approved encryption method. Information and guidelines on currently approved encryption methods is available from NST.
AuditsOCIO-IS will maintain access logs for all wireless APs connected to the MUSC network. OCIO-IS will also conduct periodic audits throughout MUSC's airspace to ensure that APs have not been attached to MUSC's network without authorization. Any unauthorized APs will be removed, and the person(s) responsible for them will be subject to sanctions as outlined in the MUSC Computer Use Policy.
Procurement and InstallationPersons planning to enable wireless access to the MUSC network must contact OCIO-IS's Network Systems Team prior to purchasing or installing any equipment. NST's engineers will facilitate the procurement of APs and other equipment from an approved equipment list, and will install, configure and manage all APs in accordance with applicable networking and security policies and standards. NST's engineers will also help ensure that APs are placed to maximize coverage and minimize interference, and will facilitate the sharing of APs between neighboring departments and programs where feasible.
Contacting NSTInformation Services
Attn: Michael Haschker, Team Leader – MUSC Network Systems Team Lead
E-Mail: haschker@musc.edu
Additional information can be found at http://nstwiki.musc.edu/index.php/Main_Page