Responsible Executive: Executive Vice President for Business and Finance
Responsible Officer: Chief Information Officer
I. PURPOSE
- The purpose of this policy is to protect and ensure the integrity of the Motlow State Community College (Motlow State) network and institutional data on mobile devices, including personally owned devices and College-issued devices.
- This policy intends to prevent Motlow State-owned data from being deliberately or inadvertently stored insecurely on a mobile device or carried over an unsecure network where it can potentially be accessed by unauthorized parties. A breach of this type could result in loss of student or employee information, damage to critical applications, and/or damage to the institution’s public image. Therefore, all users employing a mobile device that connects to an unmanaged network outside of the College’s direct control to backup, store, and otherwise access Motlow State-owned data must adhere to Motlow State-defined processes for doing so.
II. Scope
- This policy applies to, but not limited to, the following classifications of devices
and accompanying media:
- Laptop/notebook/tablet computers
- Mobile/cellular phones/smartphones
- IoT/smart devices
- Media players
- Digital or video cameras
- Storage devices/media
- Peripheral devices connected to a mobile device
- Home or personal computers used to access institutional resources
- Any other device capable of storing Motlow State-owned data which can connect to a non-Motlow State network.
- The policy applies to any employee, student, or any other third-party at Motlow State who establishes a connection from a mobile device to any Motow State provided network, software, service, or data resource.
III. Definitions
- Mobile device: Any device that is both portable and capable of collecting, storing, transmitting or processing electronic data or images in an untethered manner utilizing wireless services such as cellular data or Wi-Fi.
- Mobile Device Management or MDM: An application designed to manage mobile devices, with capabilities including but not limited to patch management, asset tracking, and remote wiping.
- Mobile Application Management or MAM: Software designed to secure company data inside work applications such as email, Teams, and other approved business apps. MAM only applies to the work apps themselves, not your entire mobile device.
- Secure storage: Motlow State-owned Microsoft OneDrive, SharePoint, and internal network shares.
- Institutional data: Information that is defined via TBR Policy 1.08.04.00 - Personally Identifiable Information.
IV. Policy Introduction
B. Access to Motlow State resources is a privilege, not a right, and forms the basis of the trust Motlow State has built with its students, employees, and community. Consequently, employment at Motlow State does not guarantee the initial and ongoing ability to use mobile devices to gain access to institutional networks and information. The Information Technology (IT) department addresses a range of threats to – or related to the use of – institutional data, including but not limited to the following scenarios:
- Loss and/or theft of data, such as having a device stolen or misplaced.
- Copyright and licensing violations
- Spyware, viruses, ransomware, or other malware.
- Compliance and audit violations, such as FERPA, GLBA, HIPAA, or other governance.
C. It is the responsibility of the employee, student, or any other third-party at the Motlow State who uses a mobile device to access institutional resources to ensure that all security protocols normally used in the management of data on conventional storage infrastructure are also applied. This policy is in addition to TBR and Motlow State policies and does not supersede any existing policy in place. Motlow State reserves the right to refuse, by physical and non-physical means, the ability to connect mobile devices to institutional and institutional-connected systems. Motlow State will engage in appropriate access control actions if it has determined a mobile device is being used in a way that places the Motlow State’s resources at risk.
V. Disclaimers
D. Employees, students, and third parties who elect to utilize personally owned mobile devices making a connection to any Motlow State's resource accept the following risks, liabilities and disclaimers.
E. Employees and third parties shall not store college data on personal devices outside of IT approved applications and storage. IT reserves the right to restrict usage of college resources on personally owned devices.
F. At no time does Motlow State accept liability for the maintenance, backup or loss of data on a personally owned device. It is the responsibility of the equipment owner to backup all software, service and data to other appropriate backup storage systems.
G. Motlow State shall not be liable for the loss, theft or damage of any personally owned devices.
VI. Security and Protection Methods
H. All users of mobile devices utilizingMotlow State resources must employ reasonable physical security measures. Users are expected to secure all such devices used for this activity. Suggested methods of security and protection are:
-
- Encrypt or password protect all data owned by the Motlow State
- Use network shared drives, which are secured and only allow authenticated user access
- Use virtual private networks (VPN), which provide secure and encrypted connections to the college’s network and data
- Use tracking and recovery software to enable the identification and retrieval of the device in the event of theft or loss
- Use device security locks, which may include password, pin or biometric security
- Use anti-virus and anti-malware protection
- Disable unused services, such as wireless, infrared or Bluetooth when not in use
- Avoid unencrypted storage of usernames and passwords
- Avoid usage of location-based services and mobile check-in services, which leverage device GPS capabilities to share real-time user location with external parties
I. Any non-Motlow State computers used to synchronize with these devices will also conform to the methods of security and protection listed above
VII. Access and Storage of Sensitive Motlow College Information
All mobile devices used to access or store sensitive college information must meet the following requirements:
J. Unencrypted sensitive information must not be permanently stored on an unsecured mobile device. Information may be temporarily accessed, stored, and utilized for business purposes but should be removed from the unsecured mobile device and stored via a secure storage method within a reasonable timeframe.
K. Mobile devices used to temporarily access or store sensitive Motlow College information must not be left unattended and should be physically secured.
L. Mobile devices used to temporarily store sensitive Motlow College information should never be shared with any unauthorized user.
M. The owner of any mobile device used to temporarily store sensitive Motow College information should always take reasonable care when using the device in public places or other unprotected areas to avoid unauthorized access or disclosure of information stored on the device.
VIII. Separation of College Relationship
- All employees and third parties, upon termination or separation from Motlow College, must remove all Motlow College-related data from all personally owned mobile devices. In addition, any software applications purchased by Motlow College and installed on a personal mobile device must be removed. IT reserves the right to wipe college owned data from institutional applications.
IX. Loss, Theft, or Misuse
-
- In the event of any suspected unauthorized data access, data loss, and/or disclosure of institutional data, or in the event of a lost or stolen mobile device, it is imperative for the employee to report this to IT immediately. On Motlow College-owned mobile devices, IT will attempt to lock the device and/or forcefully wipe all data from the device to prevent potential unauthorized access.
X. Privacy and Security
All College-owned mobile devices will be managed by IT using an MDM platform.
N. IT will maintain administrative control of these devices with capabilities including but not limited to the following:
-
- Remote locking and wiping in the event of loss or theft.
- Encryption of internal storage.
- Security scans.
- Enforced password protection.
O. IT reserves the right to, without notice, prevent or ban any individual from using Motlow College-owned devices if there is reason to believe there is a threat to Motlow College resources.
P. All Motlow College-owned software applications and services can be managed using technology such as Mobile Application Management (MAM). Certain applications can also be blocked from devices not owned by the college completely due to the sensitive nature of the data contained within them.
Q. MAM policies within applications helps protect college data by:
-
- Ensuring company data stays within approved work applications
- Preventing accidental sharing of work data into personal apps
- Encrypting company data inside work apps
- Allowing college data to be removed from work apps if needed (for example, if a device is lost or an employee leaves)
- These policies will not allow IT to see any personal information on a person’s mobile device including but not limited to location, personal apps, and personal files. Only company data inside approved work apps can be protected and managed on devices not owned by the college.
XI. Help and Support
R. IT will not provide support for hardware and software issues on personally owned devices.
S. All employees and third parties will make no modifications of any kind to Motlow College-owned devices without the express approval of IT.
T. It is expected that mobile devices are on the latest security and operating system patches.
U. Motlow College reserves the right to limit and/or terminate the individual’s ability to access and/or transfer institutional data utilizing Motlow College resources.
XII. Violation of Policy
All violations of this policy shall be reported to the CIO or designee.
A. Disciplinary Procedures
Allegations of violation of this policy shall be referred by the CIO or designee to the appropriate person(s) for employee disciplinary action.
V. Sanctions
-
- Persons violating this policy are subject to revocation or suspension of access privileges to Motlow College for institutional resources.
- Sanctions for violation of this policy by employees may result in disciplinary action up to and including termination of employment. Violations of law will be referred to appropriate authorities.
- Other sanctions may be appealed under established Institution procedures.
Sources
CORRESPONDING POLICIES
TBR Policy 1.08.03.00 Access Control
HISTORY
New Policy: Mobile Device Management (MDM) Policy
Replace Existing Policy 1:08:00:05 – Bring Your Own Device (BYOD)
IOC Approved Revisions: June 24, 2026
President’s Cabinet: July 14, 2026
Effective date: July 14, 2026
