Section: 530-6
Effective: 06/28/2024
Supersedes: 12/22/2020
Next Review Date: 06/28/2027
Issuance Date: 06/28/2024
Issuing Office:  Vice Chancellor – Operations Management and Capital Programs

Key Control and Electronic Access Policy

 

SCOPE

This policy applies to all personsat all UC San Diego locations.

POLICY SUMMARY

This policy governs the issuance and control of Building and Space Keys, Keycards, and/orCredentials at UC San Diegoto ensure the safety and security of the campus community.

DEFINITIONS

A.   Authorized Persons:Authorized personnel designated by Departments who are chargedwith the responsibility of maintaining Key Control. In the case of ElectronicAccess, Authorized Persons also include the Administrative Authority.

B.   Buildings: Any buildingowned or leasedby UC San Diego whetherpermanently affixed or mobile.

C.    Check Out: Temporary Key/Keycard issuance.

 

D.   Credentialing: Provisioning accessto the assigned department group and authorized areas by theDepartment Access Coordinator.

E.    Department: A UC San Diego department, program,organization, or group.

F.    DepartmentAccess Coordinator (DAC): The personneldesignated by a Vice Chancellor, Dean, Director, Department Head, or Building Manager to be responsible for authorizing, provisioning and maintaining access control transactions forthe department.

G.   Designated SecurityIntegrator: A recharge support service provided by FMor by a contracted professional group to help organizations combine all theirsecurity, access and utility systems into oneintelligently designed, reliable and interconnected security system.

H.   Electronic Access: A type of networked lock which is opened with a Key Fob, Keycard, Keypad, Smartphoneor Biometric credential.

 

I.      DivisionalControl Point (DCP): Authorized personnel designated by a Vice Chancellor,Dean, Director, Department Head, or Building Manager to be responsible fordesignating the Department Access Coordinator(s).

 

J.    ElectronicAccess Control Program Manager (EACP): An authorized Program Manager designated by OMCP who is charged withthe responsibility of maintaining the enterprise Electronic Access Controlsystem. This role is also responsible for ensuring the consistent applicationof access in new Capital Projects, renovations, alterations, coordination withFacilities Management and Department Access Coordinators.

K.   Enabled: The grantingof rights in a softwaresystem which allows a Key, Keycard, and/or Credential to open a lock.

 

L.    Keys: Tangible devicesused to open a PhysicalLock.

 

M.   KeyControl: Provision of Code, Keys and/or Credential to authorized personnelas appropriate, updating a log of the Code, Key and/orCredential holders, secure any unissuedCodes, Keys and/or Credentials provided to or by the Department, andupdating Electronic Access client software updated as needed.

N.   Keycard: A devicewhich, once enabled,can open an Electronic Access lock that secures a physical space.

O.   Managing: Lock maintenance and rekeying.

 

P.    Physical Lock: Mechanical devices used to secure a Space or Building. PhysicalLocks as described in thispolicy require the use of a Key to be opened. Combination, Padlock or self-administered locking devices are not included in this definition.

Q.   SecuritySite Assessment: Examines and analyzes the actual, perceivedor anticipated risks that may impact normal operations. During an assessment, aprofessional who has been trained specificallyto identify risksand provide recommendations based on industrybest-practices will review the physical location. Theassessment will:

a.    Determine existing securityconditions and protection needed for specificlocation

b.    Identify risks, security-related vulnerabilities and deficiencies

c.    Make recommendations for improvement

R.   Space: Enclosed portionsof Core Funded Buildings owned or leased by UC San Diego as well as outdoor areas which are enclosedby fences or walls. Examples of a Space include but are not limited to: anoffice, lab, or storage area.

S.     Vestibule:An interior area such asantechamber, hall, or lobby next to the external door of a building

POLICY STATEMENT

Facilities Management (FM) is responsible for Managing applicable Physical Locks and Electronic Access to Buildings and Spaces locatedon UC San Diegoproperty at designated entry doors on the perimeterof the facility with the exception of UC San DiegoHealth Systems and Housing Dining Hospitality. FM may set fees as appropriatefor this service. Electronic Access system repairs will be performed by FM oran approved vendor. The cost of repairs will be determined as follows:

1.    Electronic Access Control Hardware on ExteriorDoors leading into Common Areas - FM

2.    Electronic Access Control Hardware on Doorsleading into Department Spaces - Recharge

 

Both FM and UC San Diego Police Department (UCPD) areresponsible for specifying new Electronic Access whether in new construction or retrofit. All installations or changes to an Electronic Access system shallbe overseen by FM and UCPD, under an approved work order or building projectcontract.

All new systemrequests will requirea formal, on-site,and documented SecuritySite Assessment.

Campus Cards office issues credentials (OneCard)and the Department Access Coordinator is responsible for provisioning access tospace.

Department and Program Authorized Persons shall distributeKeys, Keycards and/or Credentials to employees as appropriate and be theinitial point of contact should a lock out occur. If an Authorized Employee orDepartment cannot resolve the lock out, they may contact FM Customer Relationsfor assistance and they will provide a response as quickly as possible. FM mayset fees as appropriate for this service. Upon request the unlock servicerequestor must providephotographic identification (campus identification credentialpreferred) to confirm occupancy of space. UCPD does not provide unlockingservices except in exigent circumstances or emergencies.

Reproduction of UC San Diego keys by anyone other than FM is prohibited. No Keys or Keycards may beissued or duplicated without the consent of FM. It is a misdemeanor crime to duplicate,cause to duplicate, possess or use any Key or Keycard to UC San Diego Buildingsor Spaces without proper authorization. Violators may be prosecuted inaccordance with California Penal Code, Section 469.

Electronic Access Control Program Manager (EACP) shallperiodically audit Departments to determine whether they are complying withthis policy. Annually, each Department shall conduct a self-audit by taking inventory of all keys, keycards, and/orcredentials and comparing those findings with their records. Any discrepancies shall bereviewed and corrected, as appropriate.

 

Building Access Standard

 

1.    Designated entry doors will be locked and unlocked electronically, according to a predeterminedschedule and will be accessible by card reader and/or CREDENTIAL entry afterhours and on weekends. In some cases, card reader and/or CREDENTIAL entry maybe required at all times for access to secure spaces, such as laboratories,storage locations, and other designated locations that require higher levels ofsecurity.

2.    Interior doors and/orsecured vestibules will be lockedand unlocked accordingto a schedule but may notbe equipped with card readers.

 

3.    Egress only doors will remain securedat all times. These doors may also be equippedwith a door monitoringcontact, local sounder or piezo device that will alarm if propped or left open.

4.    Perimeter doors equippedwith access controldevices will be equipped with door statuscontacts and dog-down devices shall be removed.

5.    After-hours building accessis granted by presenting valid access key, keycard, and/or credentialsto create an audit trail. Building entrance doors will be rekeyed off buildingmaster keys to reduce the liability of lost or stolen keys. Emergency overridekeys will be issued to building emergency responders only.

 

RESPONSIBILITIES

 

A.   FM will createand publish appropriate guidelines for Key, Keycard, and/orCredential issuance, lock maintenance, and rekeying pursuant tothis policy.

B.   Key, Keycard, and/or Credential holders are responsiblefor proper care and storage that they have been issued. If a Key or Keycard islost or stolen, the Key/Keycard holder must report it promptly to their Department&s Authorized Person. Failureto report a lost or stolen Key or Keycardmay result in disciplinary action.

 

C.   Departments shall establish, enforce, andmaintain proper Key and Access Control in their department or area. Departments shall designate Authorized Persons and providetheir names to FM.Departments shall update these names with FM as appropriate.

D.   Both FM and UCPD are responsible for reviewing all requests for new systemsand modifications to existing electronic security systems.

E.     EACP is responsible for auditing department and program Key Control compliance.

 

PROCEDURES

Please see Appendices and https://police.ucsd.edu/about/security/electronic-access.html

 

FORMS

None

 

RELATED INFORMATION

None

 

FREQUENTLY ASKED QUESTIONS (FAQ&S)

None

 

REVISION HISTORY

2020-12-22       The policywas reviewed as part of the 3 year policy review cycle.Edits were made toweblinks and formatting. Policy reissued.

2024-06-28       Policyrevised and reissued.


APPENDIX A - Key, Keycard, and/orCredential Processes

 

A.    RequestingKeys (Initial Issuance)

Only those service requestssubmitted via the FM CustomerPortal by Authorized Personnel will beaccepted.

1.     Requirements for ordering keyingservices

a.     A Key or Keycardwill only be issued when necessary. When access can be gained by other means (e.g., leaving doorsunlocked, attended doors) a key will not be issued.

b.     When a Department receives an allocation of space, departments should consult FM regarding keying, or re-keying of theassigned space.

c.     AKey or Lock Request SignatureAuthorization (including e-signature) form signed by the Department headmust be on file in the FM Customer Relations Office before any Keys or Keycardscan be issued or lock changes made. The Keyor Lock Request Signature Authorization form is available from FM CustomerRelations and shouldbe completed when adepartmental or program representative is first designated or when there is achange in the Department head.

d.     Any exceptionto this policymust be approved by the Vice Chancellor - OperationsManagement and Capital Programs (VC-OMCP). The VC-OMCP can redelegate thisauthority.

2.    Work will only be initiatedafter a completed service request (SR) has been sent to FM, processed and a work order has beenissued.

3.    The person designated to pick up Keys/Keycardsmust be an active UC San Diego employee listedon the service request(SR), or an individual listedon the Key or Lock RequestSignature Authorization form on file with FM Customer Relations.

4.     Keys will not be sent throughcampus mail.

B.    Key, Keycard,and/or Credential CheckoutProcess

1.    Where Keys/Keycards are needed for a temporaryperiod of time by a UC San Diego Departmentor an outside entity providing services to UC San Diego, Keys/Keycards may betemporarily Checked Out.

2.    All Checkout requestsmust be made at least72 hours prior to issuance.All requests must besubmitted to FM&s Customer Relations Department using the FM CustomerPortal.

3.    All Checkout requestsrequire a UC San Diego Department sponsor,Department IFIS index number, work order number, jobnumber and project name.

4.    Prior to makinga Checkout request,every effort must be made to obtaina Key/Keycard from thesponsoring Department&s Authorized Persons. If a Key/Keycard is not available,a Checkout request may be initiated.

5.    Every Key/Keycard CheckedOut will be at the lowest levelof a keying system possibleto achieve the purpose for which the Key/Keycard is being issued.

6.    Only the individual designated in the Checkout requestcan pick up the Key/Keycard(s). Valid picture ID is required when picking up Checked OutKey/Keycard(s).

7.    The loaning or transferring of a Checked Out Key/Keycard is strictlyprohibited. If a Key/Keycardis loaned or transferred to someone other than the person to whom it is issued,the Key/Keycard will beconfiscated, and disciplinary action may be initiated.

8.    All keys/keycards shallbe returned on or beforethe date specifiedon the checkout request form. Ifa project exceedsthe return date, the sponsoring department must requestan extension seven (7) days prior to the expiration date. This extension will be processed electronically using a digitalor hand-signed version of the original form, with a new return date specified.

9.     Key/Keycards will not be held over from one project to another (thereare no exceptions).

C.    Keying Services

1.    The FM Lock Shop will perform the work anddeliver completed Key/Keycard to FM Customer Relations. FM Customer Relations will notify customers that the Key/Keycard(s) are available for pick up.

2.    Key/Keycards must be picked up at the CampusServices Complex inside Building C&s north entrance weekdays between 9:00 a.m.and 12:00 p.m. Only the person listed on the service request (SR) form is authorized to pick up keys. Any person pickingup Key/Keycard(s) from FMCustomer Relations must provide current campus identification and sign areceipt before Key/Keycard(s) will be released. Receipt signature must matchthat on file with FM Customer Relations.

3.    In instances where work is required to becompleted onsite, FM Lock Shop employees will perform the work and leave the necessary Key/Keycard(s) with the Authorized Person. TheAuthorized Person will provide current campus identification and sign a receiptbefore Key/Keycard(s) will be released by the FM Lock Shop employee.

D.    Departmental Key Issue andControl

1.     Every UC San Diego Department that issues campus Key/Keycard(s) will designate a(n) Authorized Person(s) who will be responsible for Key Controlfor that Department&s assigned Spaces and/or Building(s).

2.    All Authorized Persons shall keep a writtenrecord of their Departmental Key/Keycard assignments and require a receipt signaturefrom the individual assigned the Key/Keycard. The Authorized Person will maintain documentation showingappropriate Key Control, as detailed above, to be made available for internalaudit.

3.    All Key/Keycards shall remain in the solepossession of the employee to whom the Key/Keycard(s) are assigned. Loaning,borrowing, or sharing Key/Keycards is strictly prohibited. If an employee loans or shares an assignedKey/Keycard with anyone who is not authorized, the Key/Keycard will be confiscated. Key/Keycards no longerneeded by the assigned employeeshall be returned to the Department&s Authorized Person forre-assignment or returned to FM Customer Relations.

4.    Employees are required to return Key/Keycards tothe Department Authorized Person upon termination of their employment with the University. Possessing or usingany Key/Keycard without proper authorization is amisdemeanor crime under California PenalCode, Section 469.

5.    Department Heads are, by default, AdministrativeAuthorities; they determine who the Department Access Coordinator will be - inmost instances, it will be the current Department Key Manager.

E.     Lost, Stolen,or Unreturned Keys

1.    Lost or stolenKey/Keycards should be immediately reportedto the Key/Keycard holder&ssupervisor.

2.      Once they receive a report of a lost or stolenKey/Keycard, supervisors must immediately notify their Departmental AuthorizedPerson.

3.    Upon receiving a report of a lost or stolen Key/Keycard, an Authorized Person must immediately notify FM Customer Relationsat (858) 534-2930.

4.    If a Department is unable to return assignedKey/Keycards as required, the Department may beheld fiscally responsible for rekeying costs.

F.     Billing

Keyor lock work requests will be billed on a recharge basis to the departmentrequesting the work based on the information providedon the service request (SR) submitted via the FM CustomerPortal.

For additional procedural information go to Blink:How to Request Key or LockChanges.


 

APPENDIX B - Electronic AccessProcesses

 

A.    Electronic AccessControl Systems (EACS)Requests

1.    Departments are responsible for all costs related to interior door access component installation, repair, and replacement in those areas includingbut not limited to:

a.     Keyless accessthat has been specified by Department stakeholders during the Capital Planning stage and installed aspart of new construction projects.

b.     Keyless accessthat has been installed after the originalbuilding construction.

c.     Replacing standalone keyless entry systemsthat are not already integrated or capable of integrating with the existingenterprise-wide access control system

d.     State, federal,or university policiesand/or regulations requirekeyless or enhancedaccess control to a building or area

B.    Technology Standard

1.    All Electronic Accesssystems must meet the campusstandard as specified within the current design guidelines andspecifications, unless exempted in writing by the VC-OMCP or their designee.All Electronic Access installations for interior doors that are initiated afterthe implementation of this policy shall also meet this campus standard.

2.    All Electronic Access hardware that does not interface with or meet the campusstandard shall be identified and a feasibility study conducted to evaluate the efficacy of changing the system to onethat meets the campus standard. All costs associated with the feasibility study and for any required conversion will be at the expense of the Department.

3.    Building additions or modifications that include Electronic Access Control System (EACS) shall becommunicated promptly to the Electronic Access Control Program (EACP) Manager.The Manager shall update the Department Access Coordinators (DAC) impacted andupdate the EACS as necessary. DACs shall notify personnel impacted by anyadditions or modifications to their areas. Any system updates required toprovision access to the new or modified areas shall be completed by the DACs.

C.    Electronic AccessResponsibilities

1.     Administrative Authority(AA) Responsibilities

a.     In conjunction with the facilitysupervisors, are responsible to designate two individuals within a facility or department area toact as primary and secondary Department Access Coordinators (DAC). Departmentsmay assign additional DACs, depending on their specific requirements.

b.     The Administrative Authority may serve as the primary DAC, or delegateother individuals in thebuilding to serve as primaryor secondary DACs. The DAC will work with the DesignatedSecurity Integrator in maintaining the department&s access control and physicalsecurity systems program. Failure to designate a back-up DAC could delayprocessing of access transactions when the primary DAC is unavailable.

c.     The name and contactinformation of the assigned Administrative Authority and theirbackup and any changes in this capacity must be sent to FM and EACPManager.

d.     Departmentsare responsible for controlling and scheduling electronic card reader and/orCREDENTIAL access to building entry and perimeter doors and to all areas assigned to, orunder, the department&s control and responsibility.

e.     The department authorizing access for an individual is responsible for removing, returning, or revoking the access as required. This includes any metal keysor electronic access devices issued to allow access to department-controlledareas.

2.     Department AccessCoordinator (DAC) Responsibilities

a.     Obtain authorization from their Divisional Control Point (DCP)or Director to requisition new EACS or initiate modification ofexisting EACS. All installations and modifications shall comply with university policyand standards and be conducted by or under the oversight of Planning,Capital Program Management or FM.

b.     Implement department access control procedures.

c.     Managing electronic card reader and/orcredential access to building entry and perimeter doors and other card accessareas under the department&s control

d.     Grantingor removing card reader authorization for user access to building entrances andother areas under the department&s control, including grantingand removing accessfor new employees, departmentallysponsored visitors, retiring employees, terminated employees, and rotatingstudent access as required.

e.     Provisioning door schedules for the facilityor area under their control.

f.       Routinely contacting the Designated SecurityIntegrator to re-authorize individual card-readeraccess users, based on the level of access and security required (The DAC shouldauthorize the minimal level of access required for an individual toperform their assigned duties or responsibilities).

g.     Terminating any means of electronic accessto building perimeters or other university areas under their control when the user or employee leaves thedepartment or university.

h.     Maintaining accuraterecords for individuals who have been granted electronic access to buildingperimeter doors and all other areas under the department&s control.

i.       Routinely evaluateaccess control systemsand requested modifications for functionality and effectiveness.

j.       WhenEACS or access permissions to buildings or rooms change (departmental spacechanges, doors are added, rekeyed,or reprogrammed), the DAC shall notify FM and UCPD so that affected users (ITS, CampusFire Marshal etc.) are notified appropriately.

3.     Divisional ControlPoint (DCP) responsibilities:

a.     Document DACs, telephone number,email, department name and buildinglocation; and shall send the information to therelevant DCP for compiling into a master list of DACs for the relevant division.

b.     Each DCP shall send their divisional master list of DACs to the EACP designees in FM and UCPD.

c.     Departments are responsible for notifying DCPs of all changes to their department delegations.

d.     Create and maintain theirdivisional master lists of DACs up to date and for promptlysending updated lists to the EACS designees in FM and UCPD.

e.     Only DACs on the master list are authorized to request EACSactions.

4.     Facilities Management (FM) responsibilities:

a.     Performing or managing all lock work,EACS readers and door hardwarerepair for campus managed facilities.

b.     Review and fulfill Work Order requestsfor EACS issuesand recovering costs as applicable.

c.     Assisting in the on-boarding of new EACS systems and devices duringthe commissioning of a Capital Project or Renovation at arecharge.

d.     Assisting in the trainingof new DACs to includeone-on-one, group, and facilitycommissioning of Capital Projects or Renovations at a recharge.

e.     Ensuring scheduled closures such as holidays are, by default,programmed to automatically secure facilities.

5.     EACP Managerresponsibilities:

a.     Ensure that the electronic access control systemserver is onlineand functioning.

b.     Validate the redundant, failoversystem server is functioning and tested quarterly.

c.     Request and ensure proper backup and system firewalltemplates are appliedand maintained.

d.     Maintain systemrecords, including purgingtransactions every 12 months to maintain system performance.

e.     Coordinate system-related activities between the Integrator, ITS, and DACs as appropriate to ensure successful device installation.

f.       Troubleshoot and resolve system-related problems.

g.     Actively auditsystem account management.

h.     Document and submit changemanagement requests for proper approvalas required for anychange that may affect system-wide end users and departments.

i.       Schedule and perform system-level housekeeping and audit activities to ensure optimal system operation.

j.       Coordinate formaltraining programs and documentation to on-board new DACs and FMpersonnel.