Contents
Overview
This article is the University of Washington's (UW's) only authoritative reference for technology security when you travel internationally for UW-related purposes. It replaces all previous international travel-related documents.
This article applies to all UW faculty, staff, students, and affiliates who travel outside the United States (US) while conducting UW business. This includes research, teaching, conferences, field work, and remote work abroad.
This article is for the following audiences:
- Faculty, staff, and students traveling internationally on UW-related business
- UW Global staff that advise travelers
- Department IT staff that prepare devices for international travelers
- Principal Investigators that manage grants that have international field components
- Human Resources and department administrators that approve international remote work
Country risk framework
Before any international travel, travelers, and their departments must determine the risk level of the destination country. UW uses the US Department of State Travel Advisory system as its primary risk classification framework. Always check the current advisories before every trip at Travel.State.Gov.
Travel advisory table
| Level |
Advisory |
UW requirement |
IT guidance tier |
| Level 1 |
Take typical precautions |
Register travel with UW Global Travel Health & Safety |
Standard - Follow all general guidance in this article |
| Level 2 |
Use increased caution |
Register travel; review country-specific advisories |
Standard and heightened vigilance; loaner device recommended |
| Level 3 |
Reconsider travel |
Unit head approval required; export controls review |
Elevated - Loaner device strongly recommended; Technology Control plan may be required |
| Level 4 |
Do not travel |
Prohibited for official UW activities; rare exceptions require Vice President-level approval |
Restricted - Contact Office of Export Controls before any device travel |
Countries that receive special technology guidance
Certain countries need supplemental technology security guidance beyond the standard tiers listed in the previous table. This might be due to:
- Unique legal environments
- VPN and encryption restrictions
- Documented state-level threat activity
- Office of Foreign Assets Control (OFAC) sanctions
For more information about these destinations, go to Device and data security while traveling.
IT requirements for remote work abroad
UW employees who perform UW work from a foreign country must adhere to UW’s Remote Work Abroad policy. Some requests require submitting a Remote Work Abroad Request to UW Global at least four weeks before your departure date. This requirement applies to any period of remote work abroad, not only extended stays. Do not make any arrangements to work abroad until your request is formally approved.
The following sections discuss IT-specific requirements and considerations. For full policy, eligibility, process, and approval conditions, go to the Remote Work Abroad Policy.
IT conditions for remote work abroad approvals
To approve a Remote Work Abroad Request, the following IT-specific conditions apply:
- You must use a UWIT-managed workstation or approved loaner device. You can only use a personal device if approved UW devices are not available, and only if they meet the UW minimum security standards.
- Make sure that there is enough physical and cybersecurity for any UW equipment and information, as outlined in Device and data security while traveling.
- We strongly recommend that you contact the Office of Export Controls to implement a Technology Control Plan (TCP) for work involving research data, sponsored projects, or regulated information.
- You must use the UWIT Husky OnNet VPN (F5 BIG-IP) when you access UW systems remotely, except in countries where local law restricts VPN use.
- Do not store UW data locally on personal or unapproved devices. Only access and store data through UW-managed services (like Microsoft 365 and OneDrive) when technically possible.
Before you travel
This section applies to all UW-related international travel. It’s organized by preparation area.
Prepare your device
When possible, use a UWIT-managed workstation laptop. These laptops are pre-configured with the most up-to-date Microsoft operating system (OS) patches, antivirus software, and Microsoft Intune so you can remotely erase your device. Before you travel:
- Contact your local IT office for a loaner device. We strongly recommend that you use a loaner device when you travel to Level 2, 3, and 4 countries.
- Turn on full-disk encryption. By default, full-disk encryption is turned on for UWIT-managed workstations.
- On mobile devices, turn on security or PIN codes for your device’s lock screen.
- Install end-to-end encrypted messaging applications that are legal to use in your destination country (for example, WhatsApp and Signal).
- Apply all outstanding OS and application updates.
- Install and configure the UWIT Husky OnNet VPN (F5 BIG-IP Edge Client). Note: Certain countries might restrict VPN use. For more information, go to Device and data security while traveling.
- Turn off biometric access (Face ID, fingerprint) on mobile devices. Instead, configure the device to require a PIN or password to help prevent unauthorized access.
- Turn off Wi-Fi, Bluetooth, and the option to join Wi-Fi connections automatically.
- Plan for limited or no access to blocked UW services when you’re in-country. Learn about approved alternatives.
- Configure eduroam access.
Prepare your data
Before you travel, do the following:
- Back up all data and store it in a secure, UW-managed cloud service like Microsoft 365 and OneDrive.
- Remove all Level 4 Special Handling Requirements from devices unless you need it for the trip.
- Scan your device for sensitive data. You can be surprised by the information that the Downloads and Documents folders store and your web browser’s locally saved passwords.
- Store only the minimum amount of data that you need while you’re in-country. Consider Virtual Desktop Infrastructure to keep data off the physical device while in-country.
- Do not store data locally on loaner devices; access it by using UW-managed cloud services.
- Review export control restrictions, especially encryption and border inspection laws. Some countries might inspect laptops and data when you enter. Contact the Office of Export Controls if your work involves sensitive, proprietary, or export-controlled research data.
- Review data protection laws and requirements. Many countries have specific data handling regulations and breach notification laws. If you have questions about in-country data compliance obligations, contact the UWIT Privacy Team.
Prepare your account and passwords
- Make sure that all passwords are strong, unique, and current. Use a UW-approved password manager.
- Do not save passwords in browsers on loaner devices.
- Set up bypass codes or offline multi-factor authentication methods before you leave. This helps you avoid relying on mobile roaming for authentication.
- Consider requesting a temporary UW NetID account from UWIT for high-risk destinations, to avoid using your primary UW credentials on unfamiliar networks.
Device and data security while traveling
The precautions listed in Before you travel help reduce risks before you leave the US. This section describes the security practices to use during travel and when you’re in-country.
Physical device security
- Always keep all devices on your person or in a secure location. Do not leave devices unattended. Do not rely on hotel room safes, they are not reliably secure and not considered adequate protection in high-risk destinations. Level 3 and 4 countries are examples high-risk destinations, as listed in the Country risk framework section.
- Do not check your devices in your luggage. Keep all electronic devices in your carry-on luggage.
- If a customs or border officer requests to inspect your device or confiscates your device, you might have to comply.
- Unlock the device yourself.
- Do not share your password.
- If you’re obligated to provide a password, change it immediately after the inspection.
- Note the date, time, location, and details of the inspection or confiscation.
- Immediately upon your return, report the incident to Information Security.
- Cover cameras and microphones during confidential meetings or calls.
- Be aware of your surroundings when you enter passwords or access sensitive information in public.
- Consider a privacy screen for laptops in public settings like airports, trains, and cafés.
Network and connection security
- Use a UW-approved VPN (UWIT Husky OnNet/F5 BIG-IP Edge) when possible. Note: Some countries restrict VPN use. For information about countries that have specific technology guidance, go to Countries that require special technology guidance.
- Turn off Wi-Fi and Bluetooth when you’re not actively using them.
- Do not connect to unknown or unsecured Wi-Fi networks. When you must use Wi-Fi, use networks that you can verify. For example, the hotel’s official network provided by the front desk personnel.
- Use eduroam for wireless service if it’s available. UW is a member and you can access secured wireless at participating international institutions.
- Do not use public charging stations or USB charging kiosks, which can be compromised. Only use your own charger and cable.
- Do not accept unexpected Bluetooth, Apple AirDrop, or other wireless connection requests.
- Only connect to cloud storage when it’s necessary for work purposes.
- Be aware of Bluetooth devices that try to connect to your devices without your knowledge.
- Be alert for suspicious activity on accounts and devices.
- If a pop-up window or dialog appears on your device in a foreign language, do not interact with it until after you verify its meaning with a trusted source.
- Report any suspected security incident, device loss, data breach, or unauthorized access of UW systems to UWIT Information Security within 24 hours.
- Do not use public Wi-Fi networks to access UW systems unless you connect through the UWIT-approved VPN.
Data and communications security
- You must comply with the data protection laws of your host country, including any local data breach notification obligations, and UW policy requirements.
- Use UW-managed, encrypted communications applications (like Microsoft Teams) for sensitive discussions. Avoid using personal or unknown third-party messaging applications for UW business.
- Be aware that certain countries monitor communications. Use discretion in all communications when you’re abroad.
- If you’re using a phone for translation purposes, always keep the device in your physical possession.
Countries that require special technology guidance
A country might require more technology precautions beyond the standard guidance in Sections 3–4.3, due to:
- Unique legal environments
- VPN and encryption restrictions
- Documented state-level threat activity
- OFAC sanctions
These precautions are examples. The list of countries that have special guidance changes as geopolitical conditions evolve. Always consult current State Department advisories and contact Information Security before you travel to a country that might have heightened technology risk. For current State Department Travel Advisories, go to Travel Advisories.
Common characteristics of countries that receive special guidance include:
- VPN and encryption restrictions. Standard VPN clients might not function. If you have an active VPN and you’re stopped by law enforcement, it can create more complications.
- Widespread blocking of commonly used UW services (like Google Workspace and social media platforms).
- Documented state-level cyber threat activity or electronic devices and communications surveillance.
- OFAC sanctions that restrict using US technology and services.
- Border inspection laws require that you decrypt device contents when you enter.
Incident response
Despite all precautions, security incidents can occur. Knowing what to do if an incident occurs is as important as prevention.
If your device is lost or stolen
- Contact Information Security immediately.
- If the device is a UWIT-managed workstation or loaner device, contact UWIT at 206-221-5000 to start a remote wipe.
- Contact the U.S. Embassy or Consulate in your destination country.
- File a local police report.
- Notify your departmental IT staff and supervisor.
- Change all passwords associated with accounts accessed on the device, from a separate, secure device.
Note: Do not reconnect the device to UW systems until after UWIT clears it.
If you suspect a cyber breach or if your device was compromised
- Immediately disconnect the device from all networks (Wi-Fi, Bluetooth, mobile).
- Do not turn off the device unless IT security staff instructs you to. Turning off the device can remove forensic evidence.
- Report the incident to Information Security immediately.
- Use a different, unaffected device to change all account passwords.
- Report your suspicions to any local stakeholders in your project or department.
Emergency contacts:
- Information Security: help@uw.edu
- UWIT Help Desk: help@uw.edu | 1-206-221-5000
- State Department Emergency (from US): 1-888-407-4747
- State Department Emergency (international): 1-202-501-4444
- UW 24/7 Global Emergency Line: 1-206-632-0153
Resources and contacts
After you return
- Do not connect loaner devices to UW systems or your personal network before you return them.
- Return the loaner device for reimaging.
- Change all passwords that you used when you were traveling.
- After you return from a Level 3 or 4 country, have UWIT or your department IT staff factory resent your UW-issued devices. Do this before you reconnect to UW systems, networks, or cloud services. Your devices must be reset unless the device has approved Endpoint Detection Response software (Falcon) installed.