Who this is for
This is the starting point for keeping your work at the SC Johnson College of Business secure — your Cornell account, your JCB computer, and the university data you handle. Use it to jump to the most common security tasks, to understand the rules you're expected to follow, and to know who to contact when something goes wrong.
If you're dealing with something urgent right now — a suspicious email, a lost laptop, or an account you think may be compromised — skip to Report a security problem at the bottom.
Common security tasks
The most frequent security how-tos at JCB:
Protect your account and devices
A few habits prevent the large majority of security problems:
- Use Two-Step Login (Duo) everywhere it's offered, and never approve a Duo prompt you didn't start — an unexpected prompt can mean someone has your password.
- Never share your NetID password, and don't reuse it on non-Cornell sites. No legitimate Cornell staff member will ever ask you for it.
- Keep confidential data on approved, encrypted storage. Cornell's Regulated Data Chart shows what counts as confidential and where it may be stored. See also Encrypt Your Computer and Data Hygiene Best Practices.
- Lock your screen when you step away, and don't leave laptops or phones unattended in public.
For the full checklist, see Protect Your Account and Your Data (Everyday Security Habits).
Know the rules: Cornell IT policies
Several university policies define your responsibilities when you use Cornell technology and data. You don't need to memorize them, but it's worth knowing what each one covers and where to find it. The first four matter most in day-to-day work.
The ones that matter most
- Policy 5.10 — Information Security: Cornell's master information-security policy. It sets the baseline requirements for securing university systems and data — the “why” behind encryption, Two-Step Login, and Certified Desktop. Start here if you read only one.
- Policy 4.12 — Data Stewardship and Custodianship: Explains that you are the custodian of Cornell data you work with, and that you must access and handle it only as your job requires. This is the rule that governs “can I look at / share this data?”
- Policy 5.1 — Responsible Use of IT Resources: The acceptable-use policy for Cornell computers, networks, and accounts — what responsible use looks like and what's prohibited.
- Policy 5.4.2 — Reporting Electronic Security Incidents: Requires prompt reporting of security incidents (like a phishing click or a lost device). This is the policy behind “report it right away” — see Report a security problem below.
Other IT policies worth knowing
For the complete set, see the university's Information Technologies policy library and Cornell's IT Security & Policy site.
Report a security problem
When in doubt, report — it's always better to raise a false alarm than to stay quiet:
Still stuck?
If you're not sure where something fits, start with JCB IT and we'll point you the right way. You can also browse Cornell's full security guidance at it.cornell.edu/security-and-policy.
Still need help? Contact the Cornell SC Johnson College of Business Helpdesk at itrequests@business.cornell.edu.
[edited via Jane by rtm25 on 2026-09-09 19:05 UTC]