Policy 8 - Mobile Device Policy

1.0 Overview

Portable computing devices, including but not limited to smartphones, tablets, and laptop computers are becoming increasingly powerful and affordable. However, the portability offered by these devices increases the risk that information stored or transmitted on them will be exposed. 

Murray State University allows personal mobile computing devices to be used for business purposes as long as those devices adhere to the guidelines as stated below.

2.0 Purpose 

The purpose of the Murray State University Mobile Device Policy is to establish the rules for the use of mobile computing devices. These rules are necessary to preserve the integrity, availability and confidentiality of Murray State University information. Any questions or comments about this policy should be directed to Information Systems.

3.0 Scope

This policy applies to students, faculty, staff or individuals external to MSU who own or operate a mobile device that communicates with Murray State University’s equipment, networks or stores MSU data in any way.

4.0 Policy

Listed below are the minimum guidelines when using a mobile device. Users must also follow additional guidelines which are defined in the Mobile Device Standard.

  • Murray State University sensitive data should not be stored on portable computing devices. However, in the event that there is no alternative to local storage, all sensitive Murray State University data must be encrypted using approved encryption techniques and password protected.
  • Murray State University sensitive data must not be transmitted via wireless communication to or from a portable computing device unless approved wireless transmission protocols along with approved encryption techniques are utilized.
  • Computer systems not owned by Murray State University that require network connectivity must conform to Murray State University's information security policies and procedures.
  • All mobile computing devices must have approved virus and spyware detection/protection software along with personal firewall protection (where applicable).
  • When mobile devices that stored sensitive information are no longer in use or changing ownership, the sensitive data should be deleted. 
  • Any stored accounts, passwords, or cached credentials on mobile devices should be removed if no longer in use or before changing ownership. 
  • Upon separation from the University, it is an employee’s responsibility to remove all email and sensitive data from personal mobile devices.
  • Unattended portable computing devices must be physically secured.  

5.0 Enforcement 

Anyone found to have violated this policy may be subject to disciplinary action according to personnel policies and procedures. Students may be referred to Student Affairs for discipline. A violation of this policy by a temporary worker, contractor or vendor may result in action up to and including termination of their contract or assignment with Murray State University.

6.0 Definitions

Murray State University Network

Being connected to a Murray State University network includes the following:

  • If you have a network capable device (ex. laptop) plugged into a Murray State University owned building, then you are connected to the MSU LAN (local area network).
  • If you have a wireless capable device (ex. laptop, iPhone) and connect to one of the approved SSIDs, then you are connected to the MSU WLAN (wireless local area network).
  • If you connect from a computer through the Murray State University VPN (virtual private network) or approved remote access software, you are then connected to the MSU LAN (local area network).


Policy adopted:  02-25-2011
Revision adopted: 08-24-2026
Policy approval and adoption: Murray State University President's Office and Information Systems Security

Take the next step

© Murray State University Department of Web ManagementWe are Racers.