Information Security Tips

Protect your CSUN account, devices, personal information, and university data with practical cybersecurity guidance from CSUN Information Security.

Use these resources to recognize scams, secure your devices, protect sensitive information, and respond quickly when something goes wrong.

Quick links:

Start With These Security Basics

A few habits can prevent many common security problems:

  • Use a unique password for your CSUN account.
  • Use Duo Multi-Factor Authentication when prompted.
  • Never share your password or MFA verification code.
  • Pause before opening unexpected links, attachments, or QR codes.
  • Keep your operating system, browser, and software updated.
  • Install software only from trusted sources.
  • Store sensitive university information only in approved locations.
  • Lock your device when you step away.
  • Back up important information using approved services.
  • Report suspicious messages, compromised accounts, malware, or possible data exposure promptly.

Protect Your Account

Your CSUN password should be known only to you.

To protect your account:

  • use a password that is unique to your CSUN account;
  • never provide your password in response to an email, text message, phone call, or unexpected website;
  • verify that you are on a legitimate CSUN sign-in page before entering your credentials;
  • do not share your password with coworkers, friends, or family members; and
  • change your password immediately if you believe it has been exposed.

Unexpected Duo approval requests can be a sign that someone has obtained your password.

Review CSUN Password Security Guidance

Duo Multi-Factor Authentication adds another layer of protection to your CSUN account.

When using Duo:

  • approve only sign-in requests that you initiated;
  • never provide a Duo passcode to another person;
  • reject unexpected authentication requests; and
  • report repeated or suspicious Duo prompts.

If you receive an unexpected Duo request, do not approve it.

Learn About Duo Multi-Factor Authentication

Recognize Phishing and Scams

Phishing can arrive through email, text messages, QR codes, websites, or other communication channels.

Today's scams may look professional, use familiar names and university branding, and appear to come from faculty members, supervisors, Microsoft, financial institutions, or other trusted organizations.

Watch for messages that:

  • ask for your password or MFA code;
  • send you to an unexpected login page;
  • ask you to scan an unfamiliar QR code;
  • request money, cryptocurrency, or gift cards;
  • advertise suspicious jobs or internships;
  • impersonate a professor, supervisor, or university official;
  • contain unexpected attachments;
  • pressure you to act immediately; or
  • ask you to keep the request secret.

A professional appearance does not guarantee that a message is legitimate.

Protect Yourself from Phishing and Cyber Threats

Review Examples of Phishing Reported at CSUN

Before You Click

Ask yourself:

  1. Was I expecting this message?
  2. Does the actual sender address match the person or organization it claims to represent?
  3. Is the message asking for a password, MFA code, money, or sensitive information?
  4. Is there unusual urgency or pressure?
  5. Does the link or QR code lead where the message claims?
  6. Can I verify the request using another trusted method?

If something does not look right, stop and verify before taking action.

If You Receive a Suspicious Message

Stop. Verify. Report.

If you receive a suspicious message:

  1. Do not click suspicious links.
  2. Do not scan unexpected QR codes.
  3. Do not open unknown attachments.
  4. Do not approve unexpected Duo requests.
  5. Do not send passwords, MFA codes, money, gift-card codes, or sensitive information.
  6. Verify unusual requests through a separate trusted method.
  7. Report suspicious email to abuse@csun.edu.

When possible, send the suspicious email as an attachment so CSUN Information Security can review the original message and its technical information.

If you entered your CSUN password on a suspicious website or approved an unexpected Duo request, change your password immediately and report the incident.

Change Your CSUN Password

Protect Your Devices

Security updates correct vulnerabilities that attackers can use to compromise a device.

Protect your computer and mobile devices by:

  • enabling automatic updates when appropriate;
  • keeping your operating system supported and current;
  • updating browsers and applications;
  • removing software you no longer use; and
  • restarting devices when required to complete security updates.

CSUN may restrict devices running unsupported operating systems from accessing university networks.

Install software only from trusted sources.

Avoid disabling security software or changing security settings unless instructed by authorized CSUN support personnel.

When connecting remotely:

  • use trusted networks whenever possible;
  • avoid sensitive activity on unknown public Wi-Fi;
  • use the CSUN VPN when required;
  • lock your screen when you step away; and
  • do not leave devices unattended in public locations.

Protect Information

Different kinds of information require different safeguards.

AreaGood Security PracticeResource
Sensitive FilesUse approved storage and access controlsInformation Protection
Confidential DataUse approved secure storageConfidential Box
Files and DevicesEncrypt protected information when requiredEncryption
Printed InformationRetrieve sensitive documents promptly and secure printersSecure Printing
Student RecordsFollow FERPA privacy requirementsFERPA Resources
Zoom MeetingsUse appropriate meeting access and participant controlsZoom Security
Mobile DevicesUse device locks, updates, and secure configurationMobile Device Security

Verified resource links:

Protect Against Malware and Ransomware

Malware is software designed to damage systems, steal information, or gain unauthorized access.

Ransomware is a form of malware that can encrypt files or prevent access to systems.

Reduce your risk by:

  • keeping software and operating systems updated;
  • avoiding unexpected links and attachments;
  • installing software only from trusted sources;
  • using approved security software;
  • maintaining approved backups of critical information; and
  • limiting unnecessary administrative privileges.

Review CSUN Ransomware Guidance

If you believe a device may be infected with ransomware or other serious malware:

  1. Stop working on the affected device.
  2. Disconnect it from wired and wireless networks when it is safe to do so.
  3. Do not attempt to pay a ransom.
  4. Do not delete evidence or perform extensive troubleshooting on your own.
  5. Contact CSUN Information Security or the IT Help Center.

Information Security: (818) 677-6100

Get IT Support

Protect Yourself When Traveling

Before traveling with electronic devices:

  • install current security updates;
  • remove information you do not need for the trip;
  • back up important information using an approved service;
  • verify that device encryption is enabled when required; and
  • make sure you know how to report a lost or stolen university device.

Take only the devices and information necessary for your trip.

When traveling:

  • keep devices under your control;
  • use trusted internet connections;
  • avoid charging devices through unknown USB ports;
  • be cautious when discussing or displaying confidential information in public;
  • use the CSUN VPN when required; and
  • lock your device whenever you are not actively using it.

Report a lost or stolen university device promptly.

Provide as much information as possible about:

  • the device;
  • where and when it was lost;
  • whether it contained university information; and
  • whether you believe anyone accessed the device.

Contact CSUN Information Security

Specialized Security Resources

Learn how to reduce the risk of identity theft and protect personal information.

Use this guidance when you believe personal information may have been exposed or misused.

Review university guidance regarding copyright compliance and the Digital Millennium Copyright Act.

View CSUN Information Security Resources

Administrative privileges allow users to make significant changes to computers and can increase the impact of malware or account compromise.

Use administrative privileges only when necessary and in accordance with CSUN requirements.

Information Security works with campus departments to identify and reduce technical and operational security risks.

Departments that need assistance evaluating vulnerabilities or security risks should contact Information Security.

Visit CSUN Information Security

Security awareness training helps CSUN community members recognize threats and understand their responsibilities for protecting university information.

Complete all assigned security and privacy training.

Visit CSUN Information Security

Security Checklist

Use these practices regularly:

  • Use a unique password for your CSUN account.
  • Use Duo Multi-Factor Authentication safely.
  • Never share passwords or MFA codes.
  • Verify unexpected requests before acting.
  • Keep operating systems and software updated.
  • Use trusted software and networks.
  • Protect confidential and sensitive information.
  • Secure your computer and mobile devices.
  • Back up important information using approved services.
  • Recognize phishing and other scams.
  • Report suspicious activity promptly.

Report a Security Concern

Information Security

Contact Information Security for:

  • phishing and suspicious messages;
  • compromised accounts;
  • malware or ransomware;
  • lost or stolen devices containing university information;
  • possible data exposure; or
  • other information-security concerns.

Phone: (818) 677-6100
Email: iso@csun.edu

Report suspicious email: abuse@csun.edu

Visit CSUN Information Security

IT Help Center

Contact the IT Help Center for assistance with:

  • passwords;
  • Duo;
  • account access;
  • software;
  • device troubleshooting; and
  • other technical issues.

Phone: (818) 677-1400

Get IT Help and Support

Related Resources