Third-Party Session Integrated Protocol Devices at UB Policy

Category: Information Technology

Responsible Office: Network and Communication Services

Responsible Executive: Vice President and Chief Information Officer (VPCIO)

Date Established: July 8, 2021

Date Last Revised: July 16, 2026

On this page:

Summary

The University at Buffalo Office of Information Technology (UBIT) integrates customer session integrated protocol (SIP) devices with the university's communications infrastructure, to provide enhanced capabilities and to allow for specialized and connected applications.

Policy Statement

The University at Buffalo, (UB, university) is committed to safeguarding university information systems and data by implementing appropriate security measures to prevent unauthorized access, use, disclosure, disruption, modification, or destruction of such systems and data. All university stakeholders including but not limited to UBIT, university clients, system integrators, contracted vendors, and technology support personnel share the responsibility for maintaining these protections.

Authorization and Approval

All third-party SIP devices must be reviewed and approved by Network and Communication Services (NCS) prior to integration with the university’s communications network. SIP devices not explicitly approved may be disconnected without notice to protect university assets.

Security Requirements

All SIP devices must support and enforce strong authentication mechanisms (e.g., unique credentials, secure password policies). SIP devices must support end-to-end encrypted traffic to protect communications from interception and tampering. Vendor supplied default passwords, and configurations must be changed prior to deployment. SIP devices must be regularly updated with the latest firmware and security patches. Unsupported or end-of-life SIP devices are prohibited from network connection and may be disconnected without notice to protect university assets. SIP devices must be configured to minimize exposure to unnecessary services and ports.

Network and Compatibility Standards

SIP devices must comply with UB’s network standards, as outlined in the UB Network Connection Policy. Only SIP devices compatible with UB’s core communications infrastructure is permitted for use on the UB network. SIP devices must not interfere with the operation of other networked systems or degrade network performance.

Operational Requirements

All SIP devices must be registered and inventoried with NCS, including SIP device type, location, responsible party, and support contacts. SIP device owners are responsible for ongoing maintenance, including timely application of updates and prompt response to identified vulnerabilities. All SIP devices must be tested for functionality and security prior to production use. Any SIP devices intended for critical functions (e.g., emergency communications) must have documented redundancy and failover plans.

Monitoring and Incident Response

SIP device activity is subject to monitoring by NCS for security and operational purposes. Any suspected or confirmed security incident involving an SIP device must be reported immediately to the Information Security Office. NCS reserves the right to disconnect without notice, any SIP device that poses a security or operational risk.

Summary of Costs

Communications cabling, wiring, data activation, or other services may be required and carry associated costs. Final estimates and actual costs may vary; UBIT’s Cost of Services page outlines the most current pricing.

As of December 2025, there is no cost to add SIP devices to communication systems. Customer costs will vary and are subject to change at any time in UBIT’s sole discretion.

Applicability

This policy applies to any individual involved in installing or using a non‑UBIT provided SIP device on the university’s communications network. All such parties must comply with this policy, related to university IT security standards, policies, procedures, and applicable laws and regulations.

Non-compliance may result in SIP device removal, loss of network access, or disciplinary action as permitted by law, rule, regulation, policy, procedure, or contract.

Definitions

Firmware: Embedded software that controls hardware functionality.

Session Initiation Protocol (SIP): a signaling protocol used for initiating, maintaining, and terminating communication sessions that include voice, video, and messaging applications. SIP is widely used in internet telephony, private internet protocol telephone systems, and mobile phone calling.

SIP Device: Any hardware or software endpoint that uses SIP for communication (e.g., VoIP phones, softphones).

Voice over Internet Protocol (VoIP): a technology that allows individuals to make voice calls using a broadband Internet connection instead of a regular (or analog) phone line.

Responsibilities

Requesting Customer:

  • Engage with UBIT and NCS before selecting or purchasing SIP devices to ensure compatibility and compliance with this policy.
  • Select a qualified systems integrator (if required) and plan for ongoing SIP device maintenance and support.
  • Ensure proposed SIP devices are suitable for the intended use case and meet university security and operational requirements.
  • Bear all costs related to procurement, installation, contracting, parts, and labor for any SIP devices.
  • Maintain awareness of SIP device requirements, product lifecycle, and end-of-life planning. Test SIP devices regularly and keep software and firmware up to date.
  • Act promptly if a security concern is identified and follow system administration best practices.
  • Subscribe to UBIT Alert Email Notifications to stay informed about maintenance windows and security issues.
  • Recognize that most third-party SIP devices are not suitable for life safety, business continuity, or mission-critical applications without additional safeguards.

Network and Communication Services (NCS) Responsibilities

  • Provide guidance to customers regarding SIP device selection, integration, and ongoing support.
  • Maintain and support the university’s communications infrastructure, including telephony and data networking.
  • Troubleshoot issues related to integrated SIP devices and provide support, as necessary.
  • Maintain service to customer SIP devices as long as feasible; reserving the right to deny or terminate integration if a SIP device is incompatible, malfunctions, or poses a security risk.
  • Notify customers of equipment lifecycle milestones, maintenance windows, security issues, and known problems.

System Integrator Responsibilities (when applicable)

  • Consult on, install, configure, and maintain SIP devices in accordance with university policies and industry best practices.
  • Provide necessary documentation for ongoing support and maintenance.
  • Coordinate with the requesting customer and NCS to ensure successful integration and support of SIP devices.

Shared Responsibilities

  • Work with the Information Security Office to address security issues and vulnerabilities, ensuring adherence to best practices and compliance requirements.
  • Follow established lifecycle management practices, including proper decommissioning of end-of-life SIP devices.
  • Use the UBIT Alert Email Notifications LISTSERV to share issues, questions, concerns, and notifications of maintenance or outages.
  • Participate in ongoing reviews and updates to ensure the policy and practices remain effective and current.

Contact Information

Office of the Vice President and Chief Information Officer
Phone: 716-645-7979
Email: vpcio@buffalo.edu

Network and Communications Systems
Phone: 716-645-3542
Email: ubithelp@buffalo.edu

Related Information

University Links