(no title)
pletsch | 4 months ago
With that said, I find myself agreeing with the mandate, if you're using university resources, they have a responsibility to protect those resources and EDR is table stakes these days.. but they also need to be providing any devices required for the job, allowing BYOD for restricted data makes an already tough environment to secure harder than it needs to be.
jltsiren|4 months ago
It's pretty common, particularly among researchers who do not handle sensitive data, to have a burner laptop for accessing university resources and personal devices for the actual work. Many people also use personal email addresses for work. Work email rarely survives changes in employment, making it too short-lived for many purposes.
mindslight|4 months ago
asacrowflies|4 months ago
musicale|4 months ago
Moreover, universities should avoid the chilling effects of intrusive monitoring of faculty and student devices, as well as the potential legal liability.
A better solution is resource access revocation upon detection of bad behavior, with an administrative escalation path to manage false positives.