Thispolicygoverns theissuance andcontrol ofBuilding andSpace Keys,Keycards, and/orCredentialsat UC San Diegoto ensure the safety and security of the campus community.
DEFINITIONS
A.Authorized Persons:Authorizedpersonneldesignated byDepartments whoare chargedwith the responsibility of maintaining Key Control. In the case of ElectronicAccess, Authorized Persons also include the Administrative Authority.
B.Buildings:Any buildingownedor leasedbyUCSanDiego whetherpermanentlyaffixed or mobile.
F.DepartmentAccess Coordinator (DAC):Thepersonneldesignatedby aVice Chancellor,Dean,Director, DepartmentHead, or Building Manager to be responsible for authorizing, provisioning and maintaining access control transactions forthe department.
G.Designated SecurityIntegrator: A recharge support service provided by FMor by a contracted professional group to help organizations combine all theirsecurity, access and utility systems into oneintelligently designed, reliable and interconnected security system.
I.DivisionalControl Point (DCP): Authorized personnel designated by a Vice Chancellor,Dean, Director, Department Head, or Building Manager to be responsible fordesignating the Department Access Coordinator(s).
J.ElectronicAccess Control Program Manager (EACP): Anauthorized Program Manager designated by OMCP who is charged withthe responsibility of maintaining the enterprise Electronic Access Controlsystem. This role is also responsible for ensuring the consistent applicationof access in new Capital Projects, renovations, alterations, coordination withFacilities Management and Department Access Coordinators.
K.Enabled:The grantingofrights ina softwaresystemwhich allowsa Key,Keycard, and/or Credential to open a lock.
L.Keys:Tangible devicesusedto opena PhysicalLock.
M.KeyControl: Provision of Code, Keys and/or Credential to authorized personnelas appropriate,updating alog ofthe Code,Key and/orCredentialholders, secureany unissuedCodes, Keys and/or Credentials provided to or by the Department, andupdating Electronic Access client software updated as needed.
N.Keycard:A devicewhich,once enabled,canopen anElectronic Accesslock that secures a physical space.
O.Managing:Lock maintenanceandrekeying.
P.Physical Lock: Mechanicaldevicesused tosecure aSpace orBuilding. PhysicalLocksas described in thispolicy require the use of a Key to be opened. Combination, Padlock or self-administered locking devices are not included in this definition.
Q.SecuritySite Assessment: Examines and analyzes the actual, perceivedor anticipated risks that may impact normal operations. During an assessment, aprofessional who has been trained specificallytoidentify risksandprovide recommendationsbasedon industrybest-practiceswill review the physical location. Theassessment will:
R.Space:Enclosed portionsofCore FundedBuildings ownedor leasedby UCSan Diegoas well as outdoor areas which are enclosedby fences or walls. Examples of a Space include but are not limited to: anoffice, lab, or storage area.
S.Vestibule:An interior area such asantechamber, hall, or lobby next to the external door of a building
POLICYSTATEMENT
FacilitiesManagement (FM)is responsibleforManaging applicablePhysicalLocks andElectronic Access toBuildings and Spaces locatedonUC San Diegopropertyat designated entrydoors on theperimeterof the facility with the exception of UC San DiegoHealth Systems and Housing Dining Hospitality. FM may set fees as appropriatefor this service. Electronic Access system repairs will be performed by FM oran approved vendor. The cost of repairs will be determined as follows:
1.Electronic Access Control Hardware on ExteriorDoors leading into Common Areas - FM
2.Electronic Access Control Hardware on Doorsleading into Department Spaces - Recharge
Both FM and UC San Diego Police Department (UCPD) areresponsible for specifying new Electronic Accesswhetherin newconstruction orretrofit. Allinstallations orchanges toan ElectronicAccesssystem shallbe overseen by FM and UCPD, under an approved work order or building projectcontract.
Campus Cards office issues credentials (OneCard)and the Department Access Coordinator is responsible for provisioning access tospace.
Department and Program Authorized Persons shall distributeKeys, Keycards and/or Credentials to employees as appropriate and be theinitial point of contact should a lock out occur. If an Authorized Employee orDepartment cannot resolve the lock out, they may contact FM Customer Relationsfor assistance and they will provide a response as quickly as possible. FM mayset fees as appropriate for thisservice. Uponrequest theunlock servicerequestormust providephotographicidentification (campus identification credentialpreferred) to confirm occupancy of space. UCPD does not provide unlockingservices except in exigent circumstances or emergencies.
Reproductionof UCSan Diegokeys byanyone otherthan FMis prohibited.NoKeys orKeycards maybeissued or duplicated without the consent of FM. It is a misdemeanor crime to duplicate,cause to duplicate, possess or use any Key or Keycard to UC San Diego Buildingsor Spaces without proper authorization. Violators may be prosecuted inaccordance with California Penal Code, Section 469.
Electronic Access Control Program Manager (EACP) shallperiodically audit Departments to determine whether they are complying withthis policy. Annually, each Department shall conduct a self-audit by taking inventoryofall keys,keycards, and/orcredentialsand comparingthosefindings withtheir records. Any discrepancies shall bereviewed and corrected, as appropriate.
BuildingAccessStandard
1.Designatedentry doorswill belocked andunlocked electronically,accordingto apredeterminedschedule and will be accessible by card reader and/or CREDENTIAL entry afterhours and on weekends. In some cases, card reader and/or CREDENTIAL entry maybe required at all times for access to secure spaces, such as laboratories,storage locations, and other designated locations that require higher levels ofsecurity.
2.Interiordoors and/orsecuredvestibules willbe lockedandunlocked accordingtoaschedulebut may notbe equipped with card readers.
3.Egressonly doorswillremainsecuredatalltimes.These doorsmay alsobe equippedwitha door monitoringcontact, local sounder or piezo device that will alarm if propped or left open.
4.Perimeterdoors equippedwithaccess controldeviceswill beequipped withdoor statuscontacts and dog-down devices shall be removed.
5.After-hoursbuilding accessisgranted bypresenting validaccess key,keycard, and/orcredentialsto create an audit trail. Building entrance doors will be rekeyed off buildingmaster keys to reduce the liability of lost or stolen keys. Emergency overridekeys will be issued to building emergency responders only.
B.Key, Keycard, and/or Credential holders are responsiblefor proper care and storage that they have been issued. If a Key or Keycard islost or stolen, the Key/Keycard holder must report it promptly to their Department&sAuthorizedPerson. Failuretoreport alost orstolen Keyor Keycardmayresult in disciplinary action.
C.Departments shall establish, enforce, andmaintain proper Key and Access Control in their department orarea. Departmentsshalldesignate AuthorizedPersonsand providetheirnames toFM.Departments shall update these names with FM as appropriate.
a.A Keyor Keycardwillonly beissued whennecessary. Whenaccess canbe gainedby other means (e.g., leaving doorsunlocked, attended doors) a key will not be issued.
b.When aDepartmentreceives anallocation ofspace, departmentsshouldconsult FM regarding keying, or re-keying of theassigned space.
c.AKey or Lock Request SignatureAuthorization (including e-signature) form signed by the Department headmust be on file in the FM Customer Relations Office before any Keys or Keycardscan be issued or lock changes made. The Keyor Lock Request Signature Authorizationform isavailable fromFM CustomerRelationsand shouldbecompleted whenadepartmental or program representative is first designated or when there is achange in the Department head.
d.Any exceptiontothis policymustbeapprovedby theVice Chancellor-OperationsManagement and Capital Programs (VC-OMCP). The VC-OMCP can redelegate thisauthority.
2.Workwill onlybe initiatedafteracompletedservicerequest (SR)has beensent toFM, processed and a work order has beenissued.
3.The person designated to pick up Keys/Keycardsmust be an active UC San Diego employee listedontheservice request(SR),or anindividual listedontheKey orLock RequestSignature Authorization form on file with FM Customer Relations.
4.Keys willnot besent throughcampus mail.
B.Key, Keycard,and/orCredential CheckoutProcess
1.WhereKeys/Keycards areneeded fora temporaryperiodoftimebya UCSan DiegoDepartmentor an outside entity providing services to UC San Diego, Keys/Keycards may betemporarily Checked Out.
2.AllCheckout requestsmustbemadeat least72hours priorto issuance.Allrequests mustbesubmitted to FM&s Customer Relations Department using the FM CustomerPortal.
3.AllCheckout requestsrequirea UCSan DiegoDepartment sponsor,DepartmentIFIS index number, work order number, jobnumber and project name.
4.Priorto makingaCheckout request,everyeffort mustbe madeto obtainaKey/Keycard fromthesponsoring Department&s Authorized Persons. If a Key/Keycard is not available,a Checkout request may be initiated.
5.EveryKey/Keycard CheckedOutwill beat thelowest levelofakeyingsystem possibleto achieve the purpose for which the Key/Keycard is being issued.
6.Onlythe individualdesignatedin theCheckout requestcanpick upthe Key/Keycard(s).Valid picture ID is required when picking up Checked OutKey/Keycard(s).
7.Theloaning ortransferring ofaCheckedOutKey/Keycardis strictlyprohibited.If aKey/Keycardisloanedortransferred tosomeone otherthan theperson towhom itis issued,theKey/Keycard will beconfiscated, and disciplinary action may be initiated.
8.Allkeys/keycards shallbereturned onor beforethedate specifiedonthecheckoutrequest form. Ifaproject exceedsthereturn date,the sponsoringdepartmentmust requestanextension seven (7)daysprior tothe expirationdate.This extensionwillbe processedelectronicallyusing adigitalor hand-signed version of the original form, with a new return date specified.
1.The FM Lock Shop will perform the work anddeliver completed Key/Keycard to FM Customer Relations.FMCustomer Relationswillnotify customersthatthe Key/Keycard(s)areavailable for pick up.
2.Key/Keycards must be picked up at the CampusServices Complex inside Building C&s north entrance weekdays between 9:00 a.m.and 12:00 p.m. Only the person listed on the service request (SR)form isauthorized topick upkeys. Anyperson pickingupKey/Keycard(s) fromFMCustomer Relations must provide current campus identification and sign areceipt before Key/Keycard(s) will be released. Receipt signature must matchthat on file with FM Customer Relations.
3.In instances where work is required to becompleted onsite, FM Lock Shop employees will performthework andleave thenecessary Key/Keycard(s)withthe AuthorizedPerson.TheAuthorized Person will provide current campus identification and sign a receiptbefore Key/Keycard(s) will be released by the FM Lock Shop employee.
2.All Authorized Persons shall keep a writtenrecord of their Departmental Key/Keycard assignmentsandrequire areceipt signaturefromthe individualassignedthe Key/Keycard.The Authorized Person will maintain documentation showingappropriate Key Control, as detailed above, to be made available for internalaudit.
3.All Key/Keycards shall remain in the solepossession of the employee to whom the Key/Keycard(s) are assigned. Loaning,borrowing, or sharing Key/Keycards is strictly prohibited. If an employee loans or shares an assignedKey/Keycard with anyone who is not authorized, the Key/Keycard willbe confiscated.Key/Keycardsno longerneededby theassigned employeeshall be returned to the Department&s Authorized Person forre-assignment or returned to FM Customer Relations.
4.Employees are required to return Key/Keycards tothe Department Authorized Person upon terminationoftheir employmentwiththe University.Possessingor usinganyKey/Keycard without proper authorization is amisdemeanor crime under California PenalCode, Section 469.
5.Department Heads are, by default, AdministrativeAuthorities; they determine who the Department Access Coordinator will be - inmost instances, it will be the current Department Key Manager.
Keyor lock work requests will be billed on a recharge basis to the departmentrequesting the work basedontheinformation providedontheservicerequest (SR)submitted viatheFMCustomerPortal.
1.Departmentsare responsibleforall costsrelated tointerior dooraccess componentinstallation, repair, and replacement in those areas includingbut not limited to:
a.Keyless accessthathas beenspecified byDepartment stakeholdersduringthe Capital Planning stage and installed aspart of new construction projects.
c.Replacing standalonekeylessentry systemsthatare notalready integratedorcapable of integrating with the existingenterprise-wide access control system
d.State, federal,oruniversity policiesand/orregulations requirekeylessor enhancedaccess control to a building or area
B.TechnologyStandard
1.AllElectronic Accesssystemsmust meetthe campusstandardas specifiedwithinthe current design guidelines andspecifications, unless exempted in writing by the VC-OMCP or their designee.All Electronic Access installations for interior doors that are initiated afterthe implementation of this policy shall also meet this campus standard.
3.Buildingadditions ormodifications thatinclude ElectronicAccessControl System(EACS) shallbecommunicated promptly to the Electronic Access Control Program (EACP) Manager.The Manager shall update the Department Access Coordinators (DAC) impacted andupdate the EACS as necessary. DACs shall notify personnel impacted by anyadditions or modifications to their areas. Any system updates required toprovision access to the new or modified areas shall be completed by the DACs.
C.Electronic AccessResponsibilities
1.Administrative Authority(AA)Responsibilities
a.In conjunctionwiththe facilitysupervisors,are responsibletodesignate twoindividuals within a facility or department area toact as primary and secondary Department Access Coordinators (DAC). Departmentsmay assign additional DACs, depending on their specific requirements.
b.The AdministrativeAuthoritymay serveas theprimary DAC,or delegateotherindividuals in thebuildingto serveas primaryorsecondary DACs.The DACwill workwith theDesignatedSecurity Integrator in maintaining the department&s access control and physicalsecurity systems program. Failure to designate a back-up DAC could delayprocessing of access transactions when the primary DAC is unavailable.
c.The nameand contactinformationof theassigned AdministrativeAuthorityand theirbackup and any changes in this capacity must be sent to FM and EACPManager.
d.Departmentsare responsible for controlling and scheduling electronic card reader and/orCREDENTIALaccess tobuilding entryand perimeterdoorsand toall areasassigned to,orunder, the department&s control and responsibility.
e.The departmentauthorizingaccess foran individualisresponsible forremoving, returning,or revoking the access as required. This includes any metal keysor electronic access devices issued to allow access to department-controlledareas.
a.Obtain authorizationfromtheir DivisionalControlPoint (DCP)orDirector torequisition new EACS or initiate modification ofexisting EACS. All installations and modifications shall comply with university policyand standards and be conducted by or under the oversight of Planning,Capital Program Management or FM.
b.Implement departmentaccesscontrolprocedures.
c.Managing electroniccardreader and/orcredentialaccess tobuilding entryand perimeter doors and other card accessareas under the department&s control
d.Grantingor removing card reader authorization for user access to building entrances andotherareasunderthe department&scontrol,including grantingandremoving accessfornew employees, departmentallysponsored visitors, retiring employees, terminated employees, and rotatingstudent access as required.
f.Routinely contactingtheDesignated SecurityIntegratorto re-authorizeindividualcard-readeraccess users,based onthe levelof access andsecurityrequired (TheDAC shouldauthorize the minimal level of access required for an individual toperform their assigned duties or responsibilities).
g.Terminating anymeans ofelectronic accesstobuilding perimetersorother universityareas under their control when the user or employee leaves thedepartment or university.
h.Maintaining accuraterecordsfor individualswhohave beengranted electronicaccessto buildingperimeter doors and all other areas under the department&s control.
i.Routinely evaluateaccesscontrol systemsandrequested modificationsforfunctionality and effectiveness.
j.WhenEACS or access permissions to buildings or rooms change (departmental spacechanges,doors areadded, rekeyed,orreprogrammed), theDAC shallnotify FMand UCPD so that affected users (ITS, CampusFire Marshal etc.) are notified appropriately.
3.Divisional ControlPoint(DCP)responsibilities:
a.Document DACs,telephone number,email,department nameand buildinglocation;and shall send the information to therelevant DCP for compiling into a master list of DACs for the relevant division.
b.Each DCPshall sendtheir divisionalmasterlist ofDACs tothe EACPdesignees inFM and UCPD.
c.Departments areresponsible fornotifying DCPsof allchanges totheir department delegations.
d.Create andmaintain theirdivisionalmaster listsof DACsup todate andfor promptlysending updated lists to the EACS designees in FM and UCPD.