WiscVPN GlobalProtect Host Information Profile (HIP) - Compliance Levels
When you use the GlobalProtect client to connect to WiscVPN, GlobalProtect gathers and logs information about your device into what is known as a Host Information Profile (HIP) Report. This document provides details about the compliance levels as determined by HIP in alignment with UW–Madison security policies and standards (e.g., UW-526 and the Endpoint Management and Security Policy Standards).
Devices connecting to WiscVPN are checked against UW-Madison's Endpoint Management and Security Policy Standards as a baseline. The Low Compliance security level is used as a baseline for device compliance notifications as outlined in WiscVPN GlobalProtect Host Information Profile (HIP) Compliance.
Two additional levels are identified by the device compliance checks in HIP. The changes for those levels are defined below.
Medium Compliance
To meet medium device compliance, in addition to the Low requirements, the following additional requirements must be met:
- Encryption must be enabled on the device storage
- Security updates applied within 45 days
-
- Note: Critical patches may be required in less than 45 days based on the Vulnerability Management section of the Endpoint Management and Security Policy Standards and anticipated threat to the university.
High Compliance
To meet high device compliance, in addition to the Low requirements, the following additional requirements must be met:
- Encryption must be enabled on the device storage
- Security updates applied within 15 days
-
- Note: Critical patches may be required in less than 15 days based on the Vulnerability Management section of the Endpoint Management and Security Policy Standards and anticipated threat to the university.