The emergency card, which contains the key contact details of the people or departments to be notified in the event of an IT security incident, as well as recommended actions, can be found on the forms page: Link
SID – Information Security
One of the two main areas of focus for the Staff Unit for Information Security and Data Protection is - as the name suggests - information security. This involves ensuring the three objectives of confidentiality, availability and integrity in the processing, provision and administration of information.
Emergency Card For IT Security Incidents
Dos
Disconnect from the network (LAN, Wi-Fi, VPN)
Do not switch off IT systems
Notify the emergency contact
Document observations
Execute measures as instructed by IT
Things not to do
Responding to (financial) claims
Switch off IT systems (to preserve evidence)
Disseminating information to the outside world (Communication exclusively via the press office)
Policies and Guidelines on Information Security
The ‘Guidelines on Information Security at the University of Koblenz’, which were unanimously adopted by the senate, came into force upon their publication in the University Bulletin on 11 March 2024. In addition to these guidelines, the University Management will issue guidelines on information security covering specific subject areas.
The aim is, in particular, to ensure the security of work-related communication when using the university’s email system.
The aim is to ensure the secure operation and use of the university’s services and servers, and to minimise risks that may arise, for example, from data manipulation or unauthorised access.
The aim is to ensure a secure, reliable and efficient IT infrastructure.
The aim is to ensure that the cloud storage services used are handled securely, whilst at the same time enabling users to benefit from the advantages of cloud technology.
Useful information on information security
Information security refers to the development and implementation of comprehensive strategies aimed at establishing and maintaining protection for all of an institution’s information. The focus here is on the institution’s processes, systems, applications and premises. A key factor for the university in this regard is, amongst other things, the so-called ‘IT Basic Protection’, as defined by the BSI (see also: Link). Unlike data protection, this primarily concerns the institution itself, whereas data protection focuses on individuals’ data. However, the two issues are closely intertwined.
IT Grundschutz is a comprehensive set of standards, recommendations and guidance issued by the BSI (Federal Office for Information Security) to ensure information security in institutions and organisations, as set out in the IT Grundschutz Compendium (Link).
Malware comes in many forms and types. Three of the most relevant are what are known as viruses, Trojans and worms.
Viruses
The best-known type is probably the classic virus. Just as a biological virus infects human cells, this form of malware infects a system’s files and replicates itself whenever the relevant file is opened. Although the term is often used synonymously with ‘Trojan’, the classic virus requires another file that it has infected to act as a carrier, or must initially enter the system via an infected carrier file.
Trojan
Most people are also familiar with what is known as a Trojan. Just as the Trojan horse in Homer’s epic was used to open the gates of Troy unnoticed, the aim here is to cause damage to or infiltrate the system unnoticed in some way. Generally speaking, the system is tricked into believing that this is a normal programme. The malware only becomes noticeable – if at all – once the damage has already been done. Examples include:
- Compromising the system to prepare an attack using further malware
- Encryption of data for the purposes of blackmail
Worms
Worms are a term that is generally less well known. Amongst other things, they pose a threat to networks. Worms are a type of malware that spreads autonomously on a massive scale within networks, but also, for example, via USB, thereby paralysing connected devices or executing pre-programmed malicious code.
Malware can also operate in conjunction with other types of malware; for example, a Trojan may be used to download a virus, and vice versa.
Examples of the consequences of malware:
- Spying on users / data (including passwords, login details and personal data)
- Compromising the system to prepare an attack using further malware
- Encryption of data for the purposes of blackmail
- Gaining control of the system (gaining admin rights)
If you have reasonable grounds to suspect that malware is present on a university IT device, please take the following action immediately, following the Emergency card!
Links from the Centre for Information and Media Technologies (University of Koblenz):
What should I do if I am blackmailed via email?
Links from the BSI:
As well as the user’s general handling of hardware and software, the hardware level is likely to be the most fundamental starting point for any security strategy. Hardware should be replaced at regular intervals, particularly whilst it remains connected to the internet for productive purposes. The reason for this is security vulnerabilities, which inevitably come to light over time (e.g. Spectre and Meltdown). Whilst these vulnerabilities may be fixed in the software, this can sometimes – particularly in older systems – result in significant, long-term performance losses. Furthermore, it may also be the case that the vulnerabilities need to be addressed at the BIOS level (i.e. a BIOS update usually has to be initiated manually), which means that, as a rule, manufacturers no longer provide such BIOS updates for older hardware, leaving it vulnerable. If, on the other hand, such a security vulnerability can only be fixed at the hardware level (i.e. a new product with a new ‘design’ must be created), then it is quite obvious that all current and older hardware is outdated in terms of security and should be replaced as soon as possible.
Generally speaking, however, a degree of discretion is required here too, depending on the severity of the vulnerability and how up-to-date the hardware is. Replacing hardware that is only a few months old goes against a certain approach to sustainability – particularly in the case of a vulnerability that is extremely difficult to exploit. Conversely, in the case of a widely known and easily exploitable vulnerability, combined with an old device (e.g. >5 years), replacement is strongly recommended.
Generally speaking, the older a system is, the greater the likelihood that it contains known and widespread vulnerabilities. If a system is no longer covered by the manufacturer’s support period (BIOS updates, etc.), consideration should be given to replacing it.
After the BIOS/UEFI and the most basic firmware, the operating system (including Windows, macOS and Linux) is usually the lowest level of software. As with hardware, security flaws or vulnerabilities inevitably come to light over time. Operating system updates should therefore be installed promptly to keep the operating system secure and up to date.
Just as there is malware, there is also software designed to detect it specifically and neutralise it. This software, known as a virus scanner, is constantly evolving in a race against the development of malware. Hardly any other software is therefore more dependent on being kept up to date.
Virus scanners are often already included as built-in programmes in the operating system (e.g. Windows Defender in Windows). If the operating system does not include one, or if you do not wish to use it, you can also install a different virus scanner. These separately installed antivirus programmes are sometimes criticised because they interfere deeply with the system and exert a great deal of control over it, meaning that they may, under certain circumstances, impair the system’s functionality, in the event of poor programming, they may even damage the system itself, or – if there are vulnerabilities in the antivirus programme itself – they may exacerbate the effects of malware. However, such cases are considered rather unlikely with reputable providers.
Where an existing, built-in antivirus scanner is already in place, the installation of an additional one should be considered carefully, as this involves trusting yet another provider, as well as potentially introducing further people (programmers) as factors who may make – or have made – errors during operation (updates) and development of the antivirus programme. It is therefore advisable to weigh this up against the benefits one hopes to gain from it.
The provider generally plays a very significant role.
Not every piece of software labelled or described as a virus scanner is worthy of the name. Sometimes, it may even conceal malware! For this reason, you should only use virus scanners from reputable and well-known providers that have been tested by independent bodies. Further information on this is available from the BSI: Link.
As a general rule, it is strongly recommended that you have some form of antivirus programme on your system (from a trusted provider!) – whether it is the built-in antivirus programme or one that you have installed manually.
Software (in this context, specifically application software) must, just like the operating system, always be kept up to date to avoid providing a target for attacks. This ranges from simple office programmes, through browsers (Chrome, Firefox, Safari) and email clients, to software that interacts deeply with the system (e.g. virtualisation). Application software is handled differently by various operating systems. On Linux, for example, software is usually obtained from so-called package repositories and can then be updated all at once with just a few clicks. With Windows, on the other hand, users often have to check for updates themselves either within the programme itself or even check the manufacturer’s website manually on a regular basis for the latest versions.
It is important to note that application software must also be updated regularly. Depending on the system and software, it is possible that the user will have to carry out this process entirely on their own, without the system prompting them to do so!
Passwords are the key you use to log in to an account or user account. Together with a username, they form the login details. Clearly, this information is critical, as attackers can use it to infiltrate the entire system (your own computer, the institution’s or employer’s software and data, customer or user data…..) and even bring the entire system to a standstill. Even if you generally trust the person – once you pass on this information, you lose control over its potential disclosure to third parties at that very moment!
You should therefore never share your login details (usernames, passwords, etc.)!
A sufficiently secure password consists of:
- at least 12 characters/digits
- Both lower-case and upper-case letters
- at least one number
- at least one special character
Avoid combinations that are easy to guess or personal details (e.g. date of birth). Change any initial or default passwords as soon as possible!
As passwords can sometimes be cracked or stolen, it is helpful to introduce or use what is known as a second factor for authentication (2FA – or MFA, which stands for multi-factor authentication). This involves one-off codes generated by an app or device, which are always required in addition to the password when logging in. Further information on 2FA and MFA, and on their implementation at the University of Koblenz, can be found on the Centre for Information and Media Technologies website: Link.
Further information on passwords at the University of Koblenz:
Links from the BSI:
The Internet is a network comprising many millions of computers that communicate with one another and exchange data via this network. The network comprises not only traditional end devices (PCs, laptops, smartphones, etc.) but also servers, switching centres and much more. A connection between two computers (e.g. required to send an email) or from a computer to a server (e.g. when accessing a website or using the cloud) does not usually take place directly, but via several intermediate stations. The transmission of information is not necessarily encrypted, meaning that important information may be read or intercepted by third parties whilst passing through these intermediate stations!
When a website is accessed, data is exchanged (e.g. the website’s content is sent to the user, or the user’s password is sent to the website) via the HTTP or HTTPS protocols. In the case of HTTP, the data exchanged is unencrypted – with HTTPS, it is encrypted.
The connection to the internet is generally established in two ways: via cable (DSL ‘copper’ / FTTH ‘fibre optic’ / HFC ‘cable’) or via LTE/5G (mobile networks).
LAN (wired) and Wi-Fi (wireless) generally first establish connections to a local network (i.e. a separate network cell that presents itself to the outside world – the internet – as a single unit). From this local network, requests and responses from the internet are then forwarded to or administered by the individual devices.
A local network can be set up in many different ways by any user with the appropriate hardware (router, smartphone (hotspot) and much more). There are also use cases where an internet connection on the device responsible for network administration is not even necessary – if this local network serves solely to exchange data between devices within it. If, on the other hand – which is likely to be the classic use case – you wish to connect to the internet using the devices on the local network, this connection (device responsible for network administration <-> internet) is, of course, absolutely essential.
It should generally be borne in mind that the operator/creator of a local network can, in principle, view the data traffic (provided it is unencrypted) and – depending on the connection and firewall settings (more on this in section 4.2) – may also, in some cases, cause damage to the device.
As a general rule: only connect to local networks whose operators or creators you know and trust!
Whilst, in the case of a LAN cable, it is typically quite easy to identify the operator or set-up provider of the local network, or to draw conclusions about them, this is somewhat more difficult in the case of Wi-Fi. Even if a Wi-Fi network is called, for example, ‘Deutsche Bahn Hotspot’, this does not necessarily mean that it actually belongs to that company – the name of a Wi-Fi network can be chosen at will!
As the person setting up a local network, it is, however, more difficult in the case of a Wi-Fi network to control who connects to the network. It is therefore important always to secure a local network you have set up yourself (e.g. a hotspot) with a password!
Public Wi-Fi networks are particularly important in this context. These are generally provided by large organisations or companies to offer customers access to the internet (e.g. railway stations, airports, hotels, cafés, etc.). Even if the provider is generally trustworthy, it is best to avoid these public Wi-Fi networks (where possible), as other users or devices on the same local network may, under certain circumstances, cause damage to your device (e.g. if devices are already infected with malware) and it is possible that the creator or operator has configured the Wi-Fi network inadequately (e.g. outdated or missing encryption, etc.). If you do need to connect to a Wi-Fi network that is available to the general public, we recommend using a VPN (you can find out more about VPNs on the BSI website: Link). Generally speaking, from a safety perspective, a wired connection is always preferable to a wireless connection.
The role of a firewall is to control data traffic with other devices. This control usually operates at various levels. At the local network level (e.g. a router), the focus is on protection against attacks from the internet (as well as detecting and containing infections where a device within the local network has already been compromised). To this end, the firewall checks, for example, the authorisation and routing of data packets, as well as connections to and from specific device addresses.
At the computer level (personal firewall), the focus is again on protection against attacks via the network connection – also by monitoring and controlling the flow of data.
Generally speaking, stricter settings are always more advisable from a security perspective, but may also impose restrictions in very specific use cases. If you do not have the knowledge to know exactly what these use cases might be, you will not be affected by any restrictions and should always use the stricter firewall settings.
If in doubt, you should always use the stricter setting for the firewall (e.g. in Windows: ‘public network’).
Broadly speaking, browsers are applications that enable the clear display of website content (Note: modern browsers offer a wide range of additional features and options that go beyond their core functionality). There are essentially three different types in use today: Chromium (Chrome, Microsoft Edge, Vivaldi, Brave...), Gecko (Firefox, Tor, Librewolf...) and WebKit (Safari), developed by Google, Mozilla and Apple respectively. For many people, the browser – alongside their email programme – is, in a sense, the ‘gateway to the internet’. This makes it all the more important to have the browser configured correctly, as regardless of type or developer, most modern browsers offer a wide range of settings that are well worth taking a closer look at. For instance, the default settings usually allow user statistics to be sent to the developer, or for all website data and browsing history to be stored locally (history). The settings typically allow you to simply disable the former and configure the latter in great detail. In addition, you can also specify how cookies, fingerprinting and similar technologies are handled, as well as how the browser behaves with websites that do not support the HTTPS protocol (i.e. HTTP only). You can also change your choice of search engines or your preferred default search engine here, and specify how login details (usernames and passwords) are handled.
Particular attention should be paid here to the use of add-ons. Add-ons generally serve to extend or modify the browser’s functions and behaviour. This ranges from superficial customisations (e.g. tab administration) to the addition of entirely new functional areas that alter usage behaviour (calendars, price trackers, SEO tools, and much more). The problem, however, is that almost all add-ons require a wide range of permissions (access to/analysis of data traffic, storage on the device, contacts and much more). As add-ons in particular are made available in large numbers on the respective add-on platforms, it is all the more important – particularly in view of the permissions usually required – to take a closer look at the developers. After all, it is not uncommon for an extension that appears useful on the surface to actually conceal malware.
Only install add-ons from official platforms! Even if you find an add-on on an official platform, that is no guarantee that you can trust the developer.
So the rule is: the fewer add-ons you add to a browser, the better!
And: always take a close look at the developer of an add-on. Only install it if you can trust the developer!
Unfortunately, the prevalence of adverts has also increased over time. This is problematic in that adverts can often be associated with malware.
It is therefore also highly recommended that you install an ad-blocker add-on. You should, however, continue to exercise caution regarding the developer.
Generally speaking, it is a good idea to stick to websites you are familiar with when browsing. Unfamiliar addresses and unusual domain extensions (e.g. .to, .su, etc.) or spelling errors (e.g. payyyyypal.de) are signs of websites with malicious intent.
Important: Even website names that sound plausible can conceal a malicious website. You should therefore always check that the address of the website you wish to visit is correct!
The reason for this is that a company often reserves only a few variations of its actual address. The smaller the company, the fewer such variations there usually are. Unfortunately, the rest of the possible variations are often reserved by attackers who use them to target unsuspecting users (phishing, installation of malware, etc.)
You should therefore always take particular care when entering your login details. Make sure you use an encrypted connection (HTTPS instead of HTTP; see section 4.1) and check that the address is correct!
Note: Most browsers display the address of a link when you hover over it with the cursor (i.e. without clicking). The address is then shown, for example, in the bottom left-hand corner.
Links from the BSI:
E-mails (electronic mail) are electronic messages sent via the Internet. The messages are sent between two (or more) accounts, which in turn must be set up on a server (in simple terms: (virtual) hardware units with the relevant software that are accessible via the internet). The email servers are set up and administered by various providers. Users who wish to send emails generally need an account with one of these email providers or on their server. (Note: Users are, of course, free to set up and run their own email server, although this involves a fair amount of effort and expense). If a user wishes to send an email or retrieve emails received in their account, they must log in to their account on the email provider’s server. Access to this is generally possible from any internet-enabled device. Generally speaking, however, a screen and peripherals (mouse/keyboard) prove helpful, meaning that the most common devices can be narrowed down to laptops, PCs and smartphones.
Important: Emails are generally not encrypted – without any manual intervention!
Confidential data should therefore not be sent via Emails can be dispatched!
Further information on this and on the principles of encrypted emails can be found on the BSI’s website: Link.
Under Phishing This refers to password theft carried out via emails that bear a striking resemblance to legitimate ones. The perpetrators send the victim emails specifically designed to mimic standard correspondence from, for example, a bank, an insurance company or an employer, and these typically contain requests for login details. These requests are usually phrased in a subtle manner and often involve external platforms. Common (simplified) Examples are:
- "Click on this link to update your bank details ..."
- "Please call this telephone number if you do not agree with the following debit..."
- "Your account has been deactivated. To reactivate it, please send us your current username and password ..."
Unfortunately, such messages are often successful, particularly because they feature genuine or very similar logos and, in some cases, sender addresses that appear legitimate in the preview.
The immediate or indirect disclosure of login details is not always the main issue here. Often, it is simply a matter of Interaction to trick the victim into reloading or executing further malware!
Particularly in this context, Appendices and images, as well as formatting, are crucial points to have a closer look at!
- Appendices to begin with, simply contain files attached to the text message. Opening attachments automatically results in them being saved on the device. This also means that an attachment could be any kind of malware or could contain malware within the file itself (see the entry ‘Viruses’). As it is usually difficult to tell exactly what an attachment contains without opening it, the following rule applies: you should only open or save an attachment if the sender is known and absolutely trustworthy (in this case, check the actual email sender address, not just the displayed name or preview)!
- Formatting (i.e. the type and appearance of the message text beyond the basic options, e.g. emojis, special paragraph formats, line breaks and much more) usually consists of what is known as HTML code. However, this code may also conceal all manner of other commands, which can thus make the system more vulnerable to malicious code, execute malicious code directly, or even constitute malicious code in their own right. Email clients such as Thunderbird offer the Option Display Email as plain text and thus prevent HTML code from being executed when the message is displayed.
- External elements and images: Pictures may appear as an attachment (in which case, as explained above, they should be treated in the same way as any other attachment, as images can also contain viruses) or they may appear within the email itself. They may either form a direct part of the message or be included simply as a link. In the former case, it is also helpful to use the "Display Email as plain text" in the email programme, as this prevents any malicious code hidden within the image’s file structure from being executed.
In the latter case (an image as a link within the text), this corresponds to what is known as the external elements. These refer to any type of content that is downloaded from an external server when an email is opened. Here, too, any kind of malware can be downloaded! To address this, the most common email clients also offer an Option to block this external content across the board, i.e. they are not loaded.
Many antivirus programmes are capable of automatically scanning emails for malware. If you are unsure whether your antivirus programme supports this feature or whether it is enabled, please check its settings.
However, if you are experiencing problems sending or receiving emails, it may also be that the feature has not been implemented correctly or is incompatible with the email software and provider you are using. In that case, we recommend changing your antivirus programme or even switching to different email software and/or a different provider.
Phishing emails, just like spam emails, are sent out en masse or automatically; however, in the case of phishing, their content and appearance are tailored to everyday situations (banks, insurance companies, etc.). As a result, the perpetrators always manage to target a certain number of victims simply by virtue of the sheer volume of emails sent. Spear Phishing refers to a highly targeted approach, tailored to a specifically chosen victim. Spam or junk on the other hand, refers to the widespread, mass sending of emails that have hardly been customised and which generally contain advertising (often dubious and/or malicious). However, spam is also often used to test the legitimacy or validity of email addresses (belonging to the victims). You should therefore never reply to spam emails!
- Never blindly trust the content of emails, links, sender addresses or file attachments. If in doubt, do not open or click on them, as this alone can cause damage.
- In the event of a suspected or actual IT security incident, in accordance with the Emergency card proceed.
- In the event of misdirected messages, delete the message in question.
- If you have sent a message or confidential information to the wrong person, inform your line manager and ask the recipient of the misdirected message to delete it.
- Furthermore, if personal data is sent to the wrong recipient, the Data Protection Officer be consulted to assess the situation
- Only send confidential data over the internet in encrypted form.
Further information on emails at the University of Koblenz:
Phishing Early Warning System from the University of Koblenz
The correct use of attachments in bulk emails
Problems with the Outlook spam filter
Links from the BSI:
Password theft through phishing
How can I spot phishing emails?
Information security is not limited solely to the purely digital aspects of (working) life, but also extends to the analogue environment, particularly taking the human factor into account. In this regard, the following points should be borne in mind:
- When leaving your workstation:
- Lock PC/laptop screen
- Close the window to the workspace
- Lock the entrance/door to the workroom
- Prevent sensitive documents from being visible (e.g. folders or documents left out in the open)
- No access (physical or digital) for unknown staff members
- Do not connect any unknown devices (USB sticks, etc.)
It is important to bear in mind that the analogue sharing of information should follow similar security principles to those applied to digital communication. For example, a conversation with colleagues in the corridor involving sensitive information is equivalent to sending information openly and unencrypted via insecure servers in the digital realm and should therefore always be avoided!
When on business travel, the same rules regarding information security must generally be observed as at the permanent workplace (see Chapter 6.1: Security in the Workplace). In addition, there are the specific circumstances associated with mobile working. Therefore, in addition to the points set out in Chapter 6.1, the following rules must also be followed:
- Avoid using networks intended for the general public (e.g. Wi-Fi at airports, railway stations, etc.) wherever possible
- Using a VPN to access the employer’s network (i.e. the university)
- Use a privacy screen protector (plastic sheet) on the screens of mobile devices (smartphones, laptops, etc.)
- Do not leave mobile devices unattended (not even for brief trips to the toilet or similar)
Links from the University of Koblenz:
Access to e-resources from home
Links from the BSI:
BSI IT Security in the Workplace
‘Cloud’ is the term used to describe the concept of storage accessible via the internet on a server belonging to the relevant provider. However, whilst this can be summarised so simply in a single sentence, there are a number of points to bear in mind when using it:
- External provider v employer/organisation: Many employers/organisations operate their own cloud infrastructure or have contracts with companies that provide this infrastructure. If you need the cloud to carry out your work, use the infrastructure provided by your employer or institution.
- Trust in the provider: In principle, the provider can view the data you store on its server. You should therefore only upload data that could be even remotely important or sensitive – if at all – in encrypted form. Please read the provider’s terms and conditions and privacy policy carefully.
- Access permissions: Most providers offer you a number of options for controlling who has access (to upload, download or delete) to which of your data and folders in the cloud. Please take great care to ensure that access to the files is granted only where necessary.
- Be careful with your login details: Never share your cloud storage login details! Anyone in possession of this data can tamper with the files in your cloud storage as they see fit (e.g. delete files, inject malware into existing files, and much more).
- As a general rule: Only use the cloud if you are absolutely certain that there are no better alternatives, or that the additional effort involved would be unreasonable.
Cloud computing at the University of Koblenz:
Guideline on Cloud Storage Services
General information about the cloud
Links from the BSI:
The term “backup” refers to one (or more) copy(ies) of data, created as a safeguard against data loss. Data loss can result from physical damage to data storage media (aging, external factors such as excessive temperature, humidity, etc.) as well as indirectly, e.g., through encryption by an attacker using a Trojan or similar malware (as a result, the user can no longer access their own data, which is allegedly decrypted only upon payment of a “ransom”).
To protect against such situations, you should therefore create copies of your data that can then be used or restored instead (in the case of a Trojan, you must, of course, completely reset the device beforehand—that is, ensure absolutely that the malware has been completely removed first).
This data backup can be performed either on other external storage media or using the university's cloud instance.
Here, too, there are a few points to keep in mind:
- Backups must be created and updated regularly.
- External storage devices are connected to devices (PCs, laptops, etc.) solely for the purpose of updating them—that is, they are never left connected permanently.
- External storage devices are stored securely.
- Sensitive data is encrypted! (This applies to both external storage devices and cloud backups.)
- The points listed in Chapter 7 Cloud also apply to the use of the cloud for backup purposes.
Links from the ZIMT (University of Koblenz):
Links from Wikipedia:
Links from the BSI:
AI (artificial intelligence) describes the emulation of human intelligence using electronic systems (to the extent permitted by technological and conceptual capabilities). The following explanations are intended merely to provide a rough guide.
Particularly widespread are LLMs (Large Language Models – i.e. with a language orientation), as well as image generators and interpreters. What they have in common is the fundamental process of training a corresponding base model (neural network) with data. The model/network determines HOW it is trained and applied, whilst the data determines WHAT is learnt. This results in the finished AI model, with which a user can interact.
A distinction is made between local AI and cloud-based/online AI.
With local AI, the model runs locally on the user’s device, meaning all data is processed locally. With online AI, the AI model runs on the provider’s server, and the user sends queries to this AI model via the internet and receives the answers or results in the same way. Data processing takes place on the provider’s server.
Whilst the use of local AI systems tends to cause few problems for reasons of security and data protection (apart from general provisions on data processing, e.g. relating to third parties, etc.), particular caution is required when using cloud-based or online AI. The vast majority of the better-known AI models (e.g. ChatGPT, Copilot, Gemini...) are cloud-based. What already applied when using the cloud to store files applies here all the more. As AI systems in particular are heavily influenced and improved by data sets, both during development and ongoing operation, providers have an intrinsic interest in utilising user data (interaction with the AI, data/phrases entered, user profile creation and processing, etc.). If in doubt, be sure to read through the providers’ terms and conditions and privacy policies. As a general rule, when using cloud-based or online AI systems, you must assume that anything you share with the AI in any form (chat history, uploaded documents, etc.) will also be stored and used by the provider.
You should therefore never disclose confidential information to a cloud-based or online AI!
Links from the BSI:
For general enquiries about AI at the University of Koblenz, please also contact the Artificial Intelligence authorised representative.
UNIVERSITY OF KOBLENZ
Universitätsstraße 1
56070 Koblenz



