This Week’s Cybersecurity News, 07/15/2026

Share on

Good afternoon, all.

Today I am pleased to let you know that the latest UTIA Vulnerability Management Procedure is now available on the UTIA Policies, Standards, and Procedures site. I also want to remind those managing shared mailboxes about the need to keep these properly maintained.

Procedure Update

  • UTIA Vulnerability Management Procedure
    • Over the past couple of years, UT System has been making several changes to the UTSA IT Security Policies, as we are now using multiple frameworks for system policies, and campus/institute standards and procedures.
    • I am happy to say that UTIA IT0124P2 – Vulnerability Assessment Procedures has been replaced with IT7801P – UTIA Vulnerability Management Procedure.
    • This is the same general document as previous versions, but has a new name and number based on UTSA changes.
    • This updated procedure will not directly affect many users across UTIA, but I will say that it will definitely help by ensuring our data stored on servers will continue to be secure.
    • In the past I had used Qualys for our scanning tool, but in late 2025, we moved our servers to Tenable, which is what UTSA and UTK have been using.
    • These tools scan a little differently, so there is a slight difference in the number of vulnerability levels used.
    • However, I have maintained the timelines for remediation, which are stronger than the UTSA policy, and should make for an easy transition.
    • System owners and system administrators (i.e., those responsible for maintaining our servers) will be required to follow the appropriate timelines and remediation requirements.
    • Those responsible for maintaining UTIA servers are also required to let me know if any server is added or removed.
    • If you have any questions or concerns, please don’t hesitate to let me know.

Important Reminders

  • Maintaining Shared Mailboxes
    • When someone terminates, transfers, or retires from a position with UTIA, which includes UTCVM, they are listed on reports that I receive from DASH.
    • With these reports, I am able to see who I need to remove from the Institute’s Active Directory (AD) Groups.
    • Some AD groups are used for sending group emails (distribution groups).
    • Most importantly, AD groups are used for assigned rights and permissions to members of those groups, based on a need to know.
    • I remove those who no longer have a need to know so they don’t have access to things they shouldn’t until their NetIDs expire.
    • This brings me to another kind of object within AD, called shared mailboxes.
    • Shared mailboxes can allow members to read and send email to that group, but they are different than the distribution groups because they often provide a common calendar to be used by members of that group.
    • These shared mailboxes are assigned specific managers to maintain the members of these mailboxes.
    • Only those managing shared mailboxes can make changes, which means I cannot remove people from them when they leave.
    • Please help me keep your group’s emails and calendar secure by maintaining the group members.
    • Properly maintaining these shared mailboxes and calendars will allow only those with a need to know to read important emails and see group calendar information.
    • While we don’t want to think someone we know or worked with would do anything harmful or spiteful, it is always best to be cautious when someone leaves.

Thank you so much for everything you do every day to protect the Institute, its data, students, employees, clients, and yourself!

Sandy

Important Note: Thank you so much for sharing these e-newsletters with family, friends, clients, students, and anyone else who may benefit from the information. I would like to stress that you should keep your students in mind, as non-employee students will not get this information without someone sharing. If anyone has an email group for students who are not employees of your department, please let me know what that address is, and I can include it. I do this as a blind copy so student names and addresses will not show up!