Official university social media accounts represent Villanova’s institutional brand and are often targeted by cyber criminals seeking to spread misinformation, conduct scams, or cause the University reputational harm. This article provides information security best practices for any employee or student worker involved in managing University-affiliated social media accounts.
If you have any questions about how to implement these best practices, please submit a Security Consult Request.
Best Practices
Account Set-up and Credentials
- Set account recovery email addresses to shared (Type 2) Villanova email accounts rather than individual Villanova Accounts to ensure social handles remain accessible during staffing transitions.
- Create unique, 15+ character passwords for each individual social media account. Do not reuse passwords from other work-related or personal accounts.
- Enable multi-factor authentication (MFA) on all social media accounts whenever supported.
- Securely store and, when needed, share account credentials in Villanova’s enterprise password manager. Never keep passwords in spreadsheets, word documents, email, or on a post-it note.
Administrative Access
- Grant administrative access only to people with a legitimate business need.
- Use individual administrator accounts whenever supported by the platform instead of sharing credentials. Assign roles and limit access to what is needed to complete job tasks (e.g., Admin, Editor, Contributor, Analyst)
- Consider leveraging an approved social media management platform when individual administrator accounts are not available.
- Review account administrators at least once per semester and remove former employees, student workers, contractors, or vendors who no longer require access.
- Immediately remove access when an administrator changes roles or leaves the University.
Data Protection
- Do not post information classified as Private or Restricted Data on social media.
- Verify that photos, videos, and screenshots do not inadvertently expose personally identifiable information (PII), student records, financial information, or sensitive internal systems.
- Never allow API access and add plugins to official social media accounts without prior review and approval from Information Security.
- Access official accounts only from University-managed devices whenever possible. Personally-owned devices must meet minimum security requirements before accessing these accounts. Avoid logins on public computers or untrusted Wi-Fi networks.
- Remove or disable unused social media accounts to avoid unknown data breaches or unauthorized account takeovers.
Social Engineering Awareness
- Be cautious of direct messages, emails, or posts requesting passwords, security codes, or urgent account action. Do not click on links or open attachments from unknown sources.
- Validate requests for account access or content changes through trusted communication channels, not information provided in suspicious messages.
- Report suspected phishing attempts or account compromises immediately through the platform and to Information Security via the Report a Security Concern form.
By following these practices, you ensure Villanova's official social media accounts remain trusted, accessible, and protected.