ZotDefend Project
Quicklink(s)
ZotDefend is an initiative by UC Irvine to enhance cybersecurity across campus by implementing new security standards, ensuring compliance through mandatory training, and deploying advanced security measures to comply with UCOP-mandated targets.
ZotDefend: Protecting UCI’s Digital World
As we become increasingly more collaborative online, protecting our shared electronic information is critical. Over the next year, UC Irvine will be working diligently to update, strengthen and elevate our security processes to achieve new security standards that all UC’s have committed to upholding.
We are branding this initiative, ZotDefend, as we roll out our plans to campus. Many of these improvements will be happening behind the scenes, but several, like Cybersecurity Awareness Training, will be the responsibility of our campus community as a whole, making it imperative that a strong awareness for the initiative is established.
What will change?
- Cybersecurity Awareness Training – Integrate with UCI Single Sign-On (web login) process to display warnings to users whose training is due in 14 days and restrict application access once the training becomes overdue.
- Incident Response Process – Timely escalation of incident response in alignment with UC standards.
- Ensure identification, tracking, and vulnerability management of all university computing devices.
- ZotDefend Security Package – All compatible university computing devices will be required to have the minimum security packages. Devices that do not meet this requirement will be restricted from certain UCI web applications and/or from parts of the UCI network.
- Email Duo Multi-factor Authentication – Disable UCI mail forwarders and provision UCI mailboxes for users without a UCI mailbox. Enforce DUO multifactor authentication for all university email accounts.
*For additional unit-level changes, please contact your local information security representative.
Estimated Enforcement Timeline
ZotDefend Target | Enforcement | Enforcement Date | Status |
---|---|---|---|
Ensure cyber security awareness training for 100 percent of location employees. | Warning of expiring and expired training after each SSO login. | October 8, 2024 | Complete |
Restricting access to SSO based applications until training is completed. | February 10, 2025 | Complete | |
Enable DUO multi-factor authentication (MFA) on 100 percent of campus and health email systems. | Disable self-service forwarding. | August 22, 2024 | Complete |
Provision OIT-Managed mailboxes for alumni and retirees who does not have OIT-Managed mailboxes. | September 2, 2024 | Complete | |
Self-register to DUO. | Available | Complete | |
Enforce DUO authentication to access email. | February 4, 2025 | Complete | |
Deploy ZotDefend Security Package on 100 percent of university owned assets. | Self-managed endpoints, contact the local IT department. | April 18, 2025 | |
Block non-compliant endpoints from some Wi-Fi and VPN network access. | May 19, 2025 | ||
Block non-compliant endpoints from some single sign-on application access. | May 19, 2025 |
*For additional unit-level changes, please contact your local information security representative.
Self-Enroll Security Package
Use the instructions below to use the ZotDefend Self-Enroll packages.
Project Status
- Percentage Complete 80%
Project Phase
Executing
Communities Affected
- UCI Campus
- College of Health Sciences
Start Date
July 2024
Projected Completion Date
May 28, 2025
Key Stakeholders
- Client: All Campus and Health Employees
- Sponsor: Kian Colestock
- Project Manager: Josh Drummond