POLICIES OF COLORADO STATE UNIVERSITY UNIVERSITY POLICY

Size: px
Start display at page:

Download "POLICIES OF COLORADO STATE UNIVERSITY UNIVERSITY POLICY"

Transcription

1 POLICIES OF COLORADO STATE UNIVERSITY UNIVERSITY POLICY Policy Title: Effective Date: Click here to enter text. Policy Owner: Vice President for Information Technology Policy ID # Category: 4. Information Technology Contact(s): Laura Jensen, Associate Provost for Planning and Effectiveness Bob Engmark, Director of Information Systems Table of Contents PURPOSE OF THIS POLICY... 2 APPLICATION OF THIS POLICY... 2 DEFINITIONS USED IN THIS POLICY... 2 POLICY PROVISIONS... 3 A. Data Classifications... 3 B. Data Governance Roles... 4 C. Administrative Data Governance and Architecture Committee... 6 APPENDIX A Governing Regulations... 8 APPENDIX B Sensitive Data User Agreement... 9

2 PURPOSE OF THIS POLICY Administrative data of all kinds are an institutional asset. The value of data as an institutional asset is increased through its widespread and appropriate use; its value is diminished through misuse, misinterpretation, or unnecessary restrictions to its access. Therefore, it is necessary to be explicit about data governance roles, data access and appropriate data use; all of which are under the purview of the Administrative Data Governance and Architecture Committee, hereinafter referred to as the Committee. The purpose of this Administrative Data Governance Policy is to formalize policies, procedures, and oversight for the Colorado State University (CSU) administrative data environment, balancing the issues of providing/accommodating access while ensuring that there are reasonable and prudent safeguards to protect and preserve the security, integrity and privacy of those data. Specifically, the policy sets forth 1) the definition of administrative data as distinct from other types of data at CSU, 2) the definition of Administrative Systems, i.e. IT systems containing administrative data, 3) the framework for classifying administrative data and administrative data users, 4) the responsibilities for managing different classifications of administrative data, and 5) the responsibilities for custodianship of university data by requiring Data Stewards to coordinate implementation of this policy for the Data Users under their purview. APPLICATION OF THIS POLICY The scope of this policy is institutional administrative data, as defined below. Hereinafter, Data or data is synonymous with Administrative Data. Data must be substantive, reliable, secure, timely, and well-defined in order to be relevant to the planning, managing, operating, documenting, staffing or auditing of one or more administrative functions of the University. This policy encompasses data regardless of whether created, validated, or accessed from oncampus or off-campus locations. This policy applies to all employees at Colorado State University and anyone involved in any way with CSU s Administrative Data. DEFINITIONS USED IN THIS POLICY Administrative Data Data pertaining to the administrative operations of the University, i.e. data contained within our selected administrative systems, including data extracted from those systems and made available elsewhere for access. Administrative Systems Those major information technology (IT) systems required for the effective and efficient operations of the University, including, but not limited to, the following Systems of Record (SORs): the Student Information System, the Human Resources System, the Kuali Financial System, the POLICIES OF COLORADO STATE UNIVERSITY page 2

3 Kuali Research System, the Facilities Management and Information System, the Operational Data Store (ODS), and other such systems as may emerge. Data Access Access to institutional data refers to the permission to view or query institutional data; permission does not necessarily imply delivery or support of specific methods or technologies of information access. The permission to access institutional data is granted to current employees and designated appointees for legitimate university business only. Learner Analytics Data Warehouse A system maintained by the Data Analytics Group in CSU Online to perform analyses and studies of learner and learning data in conjunction with the Center for Analytics for Learning and Teaching (C-ALT), The Institute for Learning and Teaching (TILT), and other units, both internal and external to CSU. Other Data Data contained in systems other than SORs, including data maintained for Institutional Research Planning and Effectiveness, learner and learning data maintained by and within Canvas and other systems, in-course data maintained in the Unizin Data Warehouse, scholarly communications consisting of publications and data associated therewith (particularly including research data), working data sets associated with academic courses and research projects, etc. Other data are not covered under this policy. Unizin Data Warehouse A system operated and maintained by Unizin for in-course and pre-course learner data. POLICY PROVISIONS A. Data Classifications Institutional data falls into three classifications. In the absence of being formally classified, institutional data should be treated as restricted, internal use only, by default. Classifications are intended to provide guidance to issues of access and distribution. All data will be classified. Inappropriate handling of data could result in criminal or civil penalties, identity theft, personal financial loss, invasion of privacy, and/or unauthorized access to information by an individual or many individuals (data breach). Public Public data are directory data, and data explicitly made available to the public, for example, data available on open, public web pages, or in other unrestricted publications and venues. Restricted Restricted data must be treated with propriety, and used only within the confines of the University, unless specific and appropriate approval is provided for sharing, generally from the Office of the General Counsel. Restricted data may be accessed by all eligible employees of the university needing such access in the conduct of university business. Employees accessing data must conform to the de minimis access principle, where they are personally responsible for accessing only the minimum amount of data required in the conduct of their business. Employees are also personally responsible for adhering to any and all pertinent university policies, including POLICIES OF COLORADO STATE UNIVERSITY page 3

4 the CSU IT Security Policy, the Acceptable Use Policy, etc. Any requests for restricted data from a member of the public should be referred to the appropriate data authority or the Office of the General Counsel. Private Private data are the most sensitive data at CSU, and as such are subject to the greatest protections. Because of legal, ethical, or other constraints, private data may not be accessed without specific authorization, and access may be granted only selectively with final approval from the appropriate Data Authority. Private data encompasses social security numbers, financial information including credit card information, driver s license information, legally protected personnel information, proprietary research information, third-party proprietary information, personal health information and any other information that through disclosure would adversely affect an individual or tarnish the reputation of the University. Private data may not be shared outside of the University without the express, prior approval of the Office of General Counsel. NOTE: Irrespective of classification under this policy, institutional administrative data may be subject to disclosure under the Colorado Open Records Act and/or subject to subpoena. Immediately contact the Office of General Counsel upon receipt of any such request. B. Data Governance Roles Principals involved in Data Governance exist in four categories, as defined below. Chief Data Administrator The Chief Data Administrator co-chairs the Data Governance Committee and has overall responsibility for the operational, procedural, and technological data environment. Unless otherwise appointed by the Provost, this person shall be the Director of Information Systems. The Chief Data Administrator shall be responsible for carrying out the policies, procedures and activities engendered by the Committee. It shall also be the responsibility of the Chief Data Administrator to oversee the appointment of Data Stewards in colleges and administrative units, and to distribute updates to documentation and guidelines as appropriate. Data Authority A Data Authority is ultimately responsible for data pertaining to the System of Record under their authority, and is normally at the level of Director or above. The Data Authority is responsible for classifying the data on the System of Record under their auspices into the Data Classifications set forth previously herein. Administrative Data security is managed, ultimately, through Information Systems. Examples of data authorities are: The Registrar Student Information System CSU Controller Kuali Finance System Associate Vice President for Research Kuali Research System Assistant Vice President for Human Resources and Equal Opportunity Human Resources System Assistant Vice President for Facilities FAMIS Vice President for University Development Advance system POLICIES OF COLORADO STATE UNIVERSITY page 4

5 It shall be the responsibility of the Data Authority to ensure that processes are in place to make certain that administrative data are accurate and that the appropriate data are collected to accommodate business purposes of the University, reporting requirements to governing bodies, and data sharing with the University community. The Data Authority will be supportive of and work collaboratively with the Department of Information Systems to ensure data security and protect student, faculty and staff, and administration confidentiality. Data Stewards Data Stewards are responsible for oversight of the Data Users under their authority, including understanding the individual s business needs for access to data, approving requests for access to data from potential Data Users, ensuring Data Users have the knowledge, expertise, and ability to access, manipulate and generate high-quality reports from institutional administrative data (including attending training as need to maintain a high level of skill and facility), informing Data Authorities when responsibilities or job duties have changed such that a Data User no longer needs or should have access to institutional administrative data, and verifying and keeping up to date the list of Data Users under their authority. The Data Steward shall attend required training appropriate to the Data Authority s area prior to being authorized to function as a Data Steward and participate in management of and coordination/communication with their Data Users. Data Users Data Users are CSU employees who have been given permission to access institutional administrative data by their Data Steward, as approved by the appropriate Data Authority(ies), and generally as implemented by the Department of Information Systems. Data Users must: Complete training on the appropriate definition, access, storage and use of data sets as well as centrally managed enterprise reporting tool(s). Access only the minimum amount of data required to perform their business functions. Access data only in their conduct of university business, and in ways consistent with furthering the university's mission of education, research, and public service. Preserve the confidentiality and privacy of individuals whose records they may access. Observe any ethical restrictions that apply to the data to which they have access. Abide by applicable laws, regulations, standards, and policies with respect to access, use, disclosure, retention, and/or disposal of information (see Appendices A & B). Data Users must not: Disclose data to others except as required by their job responsibilities and approved by their Data Steward. Use data for their own or others personal gain or profit. Access data to satisfy personal curiosity. Store data in any manner that violates existing university policies. POLICIES OF COLORADO STATE UNIVERSITY page 5

6 Training Data Stewards are responsible for ensuring Data Users attend training on the appropriate access and use of data generated or stored within their functional areas. No request for data access will be granted without the completion of appropriate training. Updates on data structures and definitions should be provided by Data Authorities to all approved Users as warranted. Noncompliance Sanctions Colorado State University will handle reports of misuse and abuse of information and information technology resources in accordance with existing policies and procedures issued by appropriate authorities. Abuse and misuse may result in disciplinary action, up to and including dismissal from the university, depending upon the severity of the misconduct. This may involve the offices of Human Resources, Provost and Executive Vice President, Vice President for Information Technology, Dean of Students, Office of General Counsel, and/or appropriate law enforcement agencies. Failure to comply with or report violations of this policy, all other related Colorado State University policies, and related state or federal laws may result in sanctions relating to the individual's use of information technology resources (such as suspension or termination of access, or removal of online material); the individual's studies within the university (such as student discipline in accordance with applicable university policy); civil or criminal liability; or any combination of these. C. Administrative Data Governance and Architecture Committee The Administrative Data Governance and Architecture Committee serves as the steering committee for institutional administrative data governance, and shall be a standing committee. The Executive Sponsor of the Committee is the Vice President for Information Technology ( VP for IT ). The VP for IT will receive quarterly updates on the Committee s work. Committee members shall be as follows: The Director of Information Systems, co-chair The Associate Provost for Planning and Effectiveness, co-chair The Registrar, or his/her designee The Director of Business and Financial Services, or his/her designee The Director of the Human Resources department, or his/her designee The Director of Budgets, or his/her designee The Director of IT for CSU Online, or his/her designee The Director of Student Financial Aid, or his/her designee Vice President for University Development, or his/her designee An additional member representing the Colleges, appointed by the director of the College IT Advisory Council (CITAC) An additional member representing a Vice Presidential unit, excluding the VP units already represented. POLICIES OF COLORADO STATE UNIVERSITY page 6

7 The Committee may call upon additional personnel for advice and counsel, as it deems advisable to meet its goals and objectives. Such additional participants shall be ex-officio, non-voting, and generally their service shall be temporary. Committee members have planning and policy-level responsibility and accountability for data within their functional area(s) and are expected to thoroughly understand data generated in their functional area. Meeting this expectation helps them anticipate how data from their area might be used strategically. The Committee shall be responsible for the efficient and effective operations of the administrative data environment, including oversight and management of this policy. The Committee is responsible for the operational, procedural, and cultural aspects associated with administrative data. The Committee is responsible for the operational, procedural, and cultural aspects associated with administrative data, including 1) maintenance and update of this policy, 2) approval of the administrative data architecture, data systems, and technologies used for data transfer, storage, aggregation, archival, and delivery, 3) maintenance of metadata for administrative data (e.g., data dictionaries and associated communications about administrative data), 4) efficient and effective delivery of data from Systems of Record, 5) procedures and requirements for efficient and effective access to administrative data, including requirements for training, 6) advice and input associated with Data User support, and 7) overall coordination and communications associated with the administrative data environment inclusive of change notifications relating to data and/or processes. Reporting The Committee shall deliver updates at least quarterly to the ITEC Advisory Council and provide an update as often as appropriate to the CAAG, at least once annually. After appropriate input, communications, and consultation, the Committee may devise proposals and budget requests for appropriate upgrades to the administrative data environment, in accordance with CSU annual planning and budgeting processes. POLICIES OF COLORADO STATE UNIVERSITY page 7

8 APPENDIX A Governing Regulations There are many regulations governing data. These regulations cover topics such as access, security, privacy, theft, and rights. At the University, the final authority is the General Counsel. Responsibility for and access to correspondence and documents created or received by University personnel are governed by the following overarching policies and legal statutes: Colorado Open Records Act (CORA) Health Insurance Portability and Accountability Act (HIPAA) Colorado State Records Retention Schedule Americans with Disabilities Act (ADA) The Electronic Communications Privacy Act of 1986 (ECPA) Federal Trade Commission (FTC) Red Flags Rule Gramm Leach Bliley Act (GLBA) Colorado State University Research Data Policy Colorado State University Information Collection and Personal Records Privacy Policy Colorado State University Information Technology Security Policy Colorado State University Accessibility of Electronic Information and Technologies Policy Colorado State University Red Flags Policy Colorado State University Information Technology Governance Charter (ITEC) POLICIES OF COLORADO STATE UNIVERSITY page 8

9 APPENDIX B Sensitive Data User Agreement This form is intended for those who, by virtue of their position and function, have elevated or privileged access to sensitive and/or personal information. This Agreement is part of the continuing effort to maintain a high degree of awareness and accountability regarding such access, and to ensure consistency with respect to the handling of this information. The CSU IT Security Policy defines sensitive data to include " social security numbers, personally identifiable health information, personally identifiable financial information, personnel employment and student performance information, proprietary research and academic information, and any other information that through disclosure would adversely affect an individual or besmirch the reputation of the University." This includes information stored on electronic media as well as hardcopy (printed material). As one who has such access, I agree to the following practices and guidelines: Hardcopy containing sensitive data should be protected from open view, stored behind locked doors and/or cabinets, and shredded for disposal. Access to desktops, particularly when logged into with privileged accounts, must be protected when unattended during work hours and at night. This protection can be in the form of software screen locking or logging out of the system. Portable devices, e.g. laptops, tablets, smart phones, storage devices associated with such systems, e.g. memory sticks, etc. containing sensitive data must have sensitive data encrypted with strong encryption. Removable media containing sensitive information, e.g. CDs, DVDs, memory sticks, tapes, and removable hard drives, etc. must be physically secured (key access) and accessible only to those requiring access necessary to perform their job duties. Disks containing sensitive information in obsolete systems bound for Surplus must be sanitized in a timely fashion using DiskWipe or another product meeting or exceeding the latest NIST standards for data disposal. Surplus Property will perform this function for a modest fee. I agree to raise awareness of these requirements with others to whom I grant access to such information. I agree to de minimis access, that is, to access only the minimum amount of information necessary to perform my job duties. I am responsible for reading, understanding, and complying with the CSU IT Security Policy. I am responsible for reading and understanding the CSU Acceptable Use Policy for Computing and Networking Resources. I must exercise similar safeguards with my home computer whenever handling the University's sensitive data. I agree not to share my password or my access to sensitive information or systems containing sensitive information with others. POLICIES OF COLORADO STATE UNIVERSITY page 9

10 In the case that sensitive data has been compromised, it is my responsibility to immediately notify my supervisor, and the Vice President for Information Technology. Use storage in the cloud for sensitive data strictly in accordance with the CSU IT Security Policy. POLICIES OF COLORADO STATE UNIVERSITY page 10

INFORMATION TECHNOLOGY DATA MANAGEMENT PROCEDURES AND GOVERNANCE STRUCTURE BALL STATE UNIVERSITY OFFICE OF INFORMATION SECURITY SERVICES

INFORMATION TECHNOLOGY DATA MANAGEMENT PROCEDURES AND GOVERNANCE STRUCTURE BALL STATE UNIVERSITY OFFICE OF INFORMATION SECURITY SERVICES INFORMATION TECHNOLOGY DATA MANAGEMENT PROCEDURES AND GOVERNANCE STRUCTURE BALL STATE UNIVERSITY OFFICE OF INFORMATION SECURITY SERVICES 1. INTRODUCTION If you are responsible for maintaining or using

More information

UTAH VALLEY UNIVERSITY Policies and Procedures

UTAH VALLEY UNIVERSITY Policies and Procedures Page 1 of 5 POLICY TITLE Section Subsection Responsible Office Private Sensitive Information Facilities, Operations, and Information Technology Information Technology Office of the Vice President of Information

More information

Subject: University Information Technology Resource Security Policy: OUTDATED

Subject: University Information Technology Resource Security Policy: OUTDATED Policy 1-18 Rev. 2 Date: September 7, 2006 Back to Index Subject: University Information Technology Resource Security Policy: I. PURPOSE II. University Information Technology Resources are at risk from

More information

Southern Adventist University Information Security Policy. Version 1 Revised Apr

Southern Adventist University Information Security Policy. Version 1 Revised Apr Southern Adventist University Information Security Policy Version 1 Revised Apr 27 2015 Summary The purpose of this policy statement is to establish the requirements necessary to prevent or minimize accidental

More information

B. To ensure compliance with federal and state laws, rules, and regulations, including, but not limited to:

B. To ensure compliance with federal and state laws, rules, and regulations, including, but not limited to: Executive Policy, EP 2.215 Institutional Data Governance Page 1 of 14 Executive Policy Chapter 2, Administration Executive Policy EP 2.215, Institutional Data Governance Effective Date: xxxx 2017 Prior

More information

Gramm Leach Bliley Act 15 U.S.C GLBA/HIPAA Information Security Program Committee GLBA, Safeguards Rule Training, Rev.

Gramm Leach Bliley Act 15 U.S.C GLBA/HIPAA Information Security Program Committee GLBA, Safeguards Rule Training, Rev. Gramm Leach Bliley Act 15 U.S.C. 6801-6809 GLBA/HIPAA Information Security Program Committee GLBA, Safeguards Rule Training, Rev. 11/30/2016 1 Objectives for GLBA Training GLBA Overview Safeguards Rule

More information

MANUAL OF UNIVERSITY POLICIES PROCEDURES AND GUIDELINES. Applies to: faculty staff students student employees visitors contractors

MANUAL OF UNIVERSITY POLICIES PROCEDURES AND GUIDELINES. Applies to: faculty staff students student employees visitors contractors Page 1 of 6 Applies to: faculty staff students student employees visitors contractors Effective Date of This Revision: June 1, 2018 Contact for More Information: HIPAA Privacy Officer Board Policy Administrative

More information

Document Title: Electronic Data Protection and Encryption Policy. Revision Date Authors Description of Changes

Document Title: Electronic Data Protection and Encryption Policy. Revision Date Authors Description of Changes Effective Date: 01/01/2014 Page 1 of 7 REVISION HISTORY Revision No. Revision Date Authors Description of Changes 1.0 11/04/2013 CISO Populate Into Standard Template APPROVED BY This Policy is established

More information

Cloud Computing Standard 1.1 INTRODUCTION 2.1 PURPOSE. Effective Date: July 28, 2015

Cloud Computing Standard 1.1 INTRODUCTION 2.1 PURPOSE. Effective Date: July 28, 2015 Cloud Computing Standard Effective Date: July 28, 2015 1.1 INTRODUCTION Cloud computing services are application and infrastructure resources that users access via the Internet. These services, contractually

More information

UNIVERSITY OF MASSACHUSETTS AMHERST INFORMATION SECURITY POLICY October 25, 2017

UNIVERSITY OF MASSACHUSETTS AMHERST INFORMATION SECURITY POLICY October 25, 2017 UNIVERSITY OF MASSACHUSETTS AMHERST INFORMATION SECURITY POLICY October 25, 2017 I. Introduction Institutional information, research data, and information technology (IT) resources are critical assets

More information

Virginia Commonwealth University School of Medicine Information Security Standard

Virginia Commonwealth University School of Medicine Information Security Standard Virginia Commonwealth University School of Medicine Information Security Standard Title: Scope: Personnel Security Standard This standard is applicable to all VCU School of Medicine personnel. Approval

More information

Employee Security Awareness Training Program

Employee Security Awareness Training Program Employee Security Awareness Training Program Date: September 15, 2015 Version: 2015 1. Scope This Employee Security Awareness Training Program is designed to educate any InComm employee, independent contractor,

More information

UNIVERSITY OF MASSACHUSETTS AMHERST INFORMATION SECURITY POLICY September 20, 2017

UNIVERSITY OF MASSACHUSETTS AMHERST INFORMATION SECURITY POLICY September 20, 2017 UNIVERSITY OF MASSACHUSETTS AMHERST INFORMATION SECURITY POLICY September 20, 2017 I. Introduction Institutional information, research data, and information technology (IT) resources are critical assets

More information

DATA STEWARDSHIP STANDARDS

DATA STEWARDSHIP STANDARDS DATA STEWARDSHIP STANDARDS Policy: Enterprise Data Stewardship Policy Document: Data Stewardship Standards Campus: MSU-Billings (MSUB) Revision: 01-08-18 Contact: Michael Barber, Chief Information Officer

More information

Policies & Regulations

Policies & Regulations Policies & Regulations Email Policy Number Effective Revised Review Responsible Division/Department: Administration and Finance / Office of the CIO/ Information Technology Services (ITS) New Policy Major

More information

Access to University Data Policy

Access to University Data Policy UNIVERSITY OF OKLAHOMA Health Sciences Center Information Technology Security Policy Access to University Data Policy 1. Purpose This policy defines roles and responsibilities for protecting OUHSC s non-public

More information

RMU-IT-SEC-01 Acceptable Use Policy

RMU-IT-SEC-01 Acceptable Use Policy 1.0 Purpose 2.0 Scope 2.1 Your Rights and Responsibilities 3.0 Policy 3.1 Acceptable Use 3.2 Fair Share of Resources 3.3 Adherence with Federal, State, and Local Laws 3.4 Other Inappropriate Activities

More information

Policies and Procedures Date: February 28, 2012

Policies and Procedures Date: February 28, 2012 No. 5200 Rev.: 1 Policies and Procedures Date: February 28, 2012 Subject: Information Technology Security Program 1. Purpose... 1 2. Policy... 1 2.1. Program Elements... 1 2.2. Applicability and Scope...

More information

Acceptable Use Policy

Acceptable Use Policy Acceptable Use Policy POLICY 07.01.01 Effective Date: 01/01/2015 The following are responsible for the accuracy of the information contained in this document Responsible Policy Administrator Information

More information

PROCEDURE POLICY DEFINITIONS AD DATA GOVERNANCE PROCEDURE. Administration (AD) APPROVED: President and CEO

PROCEDURE POLICY DEFINITIONS AD DATA GOVERNANCE PROCEDURE. Administration (AD) APPROVED: President and CEO Section: Subject: Administration (AD) Data Governance AD.3.3.1 DATA GOVERNANCE PROCEDURE Legislation: Alberta Evidence Act (RSA 2000 ca-18); Copyright Act, R.S.C., 1985, c.c-42; Electronic Transactions

More information

Definitions Application is a computer software program run on a computer for the purpose of providing a business/academic function.

Definitions Application is a computer software program run on a computer for the purpose of providing a business/academic function. Colorado State University Information Technology (IT) Security Policy Introduction Colorado State University collects information of a sensitive nature to facilitate and enable its business/academic functions.

More information

Regulation P & GLBA Training

Regulation P & GLBA Training Regulation P & GLBA Training Overview Regulation P governs the treatment of nonpublic personal information about consumers by the financial institution. (Gramm-Leach-Bliley Act of 1999) The GLBA is composed

More information

Information Security Policy

Information Security Policy April 2016 Table of Contents PURPOSE AND SCOPE 5 I. CONFIDENTIAL INFORMATION 5 II. SCOPE 6 ORGANIZATION OF INFORMATION SECURITY 6 I. RESPONSIBILITY FOR INFORMATION SECURITY 6 II. COMMUNICATIONS REGARDING

More information

The University of British Columbia Board of Governors

The University of British Columbia Board of Governors The University of British Columbia Board of Governors Policy No.: 118 Approval Date: February 15, 2016 Responsible Executive: University Counsel Title: Safety and Security Cameras Background and Purposes:

More information

Virginia State University Policies Manual. Title: Information Security Program Policy: 6110

Virginia State University Policies Manual. Title: Information Security Program Policy: 6110 Purpose Virginia State University (VSU) uses information to perform the business services and functions necessary to fulfill its mission. VSU information is contained in many different mediums including

More information

RUTGERS POLICY. Section Title: Legacy UMDNJ policies associated with Information Technology

RUTGERS POLICY. Section Title: Legacy UMDNJ policies associated with Information Technology RUTGERS POLICY Section: 70.2.8 Section Title: Legacy UMDNJ policies associated with Information Technology Policy Name: Information Security: Acceptable Use Formerly Book: 95-01-09-05:00 Approval Authority:

More information

Mobile Device policy Frequently Asked Questions April 2016

Mobile Device policy Frequently Asked Questions April 2016 Mobile Device policy Frequently Asked Questions April 2016 In an attempt to help the St. Lawrence University community understand this policy, the following FAQ document was developed by IT in collaboration

More information

Seven Requirements for Successfully Implementing Information Security Policies and Standards

Seven Requirements for Successfully Implementing Information Security Policies and Standards Seven Requirements for Successfully Implementing and Standards A guide for executives Stan Stahl, Ph.D., President, Citadel Information Group Kimberly A. Pease, CISSP, Vice President, Citadel Information

More information

UT HEALTH SAN ANTONIO HANDBOOK OF OPERATING PROCEDURES

UT HEALTH SAN ANTONIO HANDBOOK OF OPERATING PROCEDURES ACCESS MANAGEMENT Policy UT Health San Antonio shall adopt access management processes to ensure that access to Information Resources is restricted to authorized users with minimal access rights necessary

More information

Institute of Technology, Sligo. Information Security Policy. Version 0.2

Institute of Technology, Sligo. Information Security Policy. Version 0.2 Institute of Technology, Sligo Information Security Policy Version 0.2 1 Document Location The document is held on the Institute s Staff Portal here. Revision History Date of this revision: 28.03.16 Date

More information

Cyber Security Program

Cyber Security Program Cyber Security Program Cyber Security Program Goals and Objectives Goals Provide comprehensive Security Education and Awareness to the University community Build trust with the University community by

More information

Red Flags/Identity Theft Prevention Policy: Purpose

Red Flags/Identity Theft Prevention Policy: Purpose Red Flags/Identity Theft Prevention Policy: 200.3 Purpose Employees and students depend on Morehouse College ( Morehouse ) to properly protect their personal non-public information, which is gathered and

More information

FLORIDA S PREHOSPITAL EMERGENCY MEDICAL SERVICES TRACKING & REPORTING SYSTEM

FLORIDA S PREHOSPITAL EMERGENCY MEDICAL SERVICES TRACKING & REPORTING SYSTEM FLORIDA S PREHOSPITAL EMERGENCY MEDICAL SERVICES TRACKING & REPORTING SYSTEM END USER SECURITY POLICY MANUAL 1 INTRODUCTION... 3 2 INFORMATION USAGE AND PROTECTION... 3 2.2 PROTECTED HEALTH INFORMATION...

More information

SPRING-FORD AREA SCHOOL DISTRICT

SPRING-FORD AREA SCHOOL DISTRICT No. 801.1 SPRING-FORD AREA SCHOOL DISTRICT SECTION: TITLE: OPERATIONS ELECTRONIC RECORDS RETENTION ADOPTED: January 25, 2010 REVISED: October 24, 2011 801.1. ELECTRONIC RECORDS RETENTION 1. Purpose In

More information

Data Compromise Notice Procedure Summary and Guide

Data Compromise Notice Procedure Summary and Guide Data Compromise Notice Procedure Summary and Guide Various federal and state laws require notification of the breach of security or compromise of personally identifiable data. No single federal law or

More information

Privacy Policy on the Responsibilities of Third Party Service Providers

Privacy Policy on the Responsibilities of Third Party Service Providers Privacy Policy on the Responsibilities of Third Party Service Providers Privacy Office Document ID: 2489 Version: 3.2 Owner: Chief Privacy Officer Sensitivity Level: Low Copyright Notice Copyright 2016,

More information

Data Governance Framework

Data Governance Framework Data Governance Framework Purpose This document describes the data governance framework for University of Saskatchewan (U of S) institutional data. It identifies designated roles within the university

More information

IAM Security & Privacy Policies Scott Bradner

IAM Security & Privacy Policies Scott Bradner IAM Security & Privacy Policies Scott Bradner November 24, 2015 December 2, 2015 Tuesday Wednesday 9:30-10:30 a.m. 10:00-11:00 a.m. 6 Story St. CR Today s Agenda How IAM Security and Privacy Policies Complement

More information

OUTDATED. Policy and Procedures 1-12 : University Institutional Data Management Policy

OUTDATED. Policy and Procedures 1-12 : University Institutional Data Management Policy Policy 1-16 Rev. Date: May 14, 2001 Back to Index Subject: WORLD WIDE WEB RESOURCES POLICY PURPOSE To outline the University's policy for students, faculty and staff concerning the use of the University's

More information

Table of Contents. PCI Information Security Policy

Table of Contents. PCI Information Security Policy PCI Information Security Policy Policy Number: ECOMM-P-002 Effective Date: December, 14, 2016 Version Number: 1.0 Date Last Reviewed: December, 14, 2016 Classification: Business, Finance, and Technology

More information

University Policies and Procedures ELECTRONIC MAIL POLICY

University Policies and Procedures ELECTRONIC MAIL POLICY University Policies and Procedures 10-03.00 ELECTRONIC MAIL POLICY I. Policy Statement: All students, faculty and staff members are issued a Towson University (the University ) e-mail address and must

More information

2016 SC REGIONAL HOUSING AUTHORITY NO. 3 S EIV SECURITY POLICY

2016 SC REGIONAL HOUSING AUTHORITY NO. 3 S EIV SECURITY POLICY 2016 SC REGIONAL HOUSING AUTHORITY NO. 3 S EIV SECURITY POLICY Purpose: The purpose of this policy is to provide instruction and information to staff, auditors, consultants, contractors and tenants on

More information

Records Management and Retention

Records Management and Retention Records Management and Retention Category: Governance Number: Audience: University employees and Board members Last Revised: January 29, 2017 Owner: Secretary to the Board Approved by: Board of Governors

More information

Data protection policy

Data protection policy Data protection policy Context and overview Introduction The ASHA Centre needs to gather and use certain information about individuals. These can include customers, suppliers, business contacts, employees

More information

Enviro Technology Services Ltd Data Protection Policy

Enviro Technology Services Ltd Data Protection Policy Enviro Technology Services Ltd Data Protection Policy 1. CONTEXT AND OVERVIEW 1.1 Key details Rev 1.0 Policy prepared by: Duncan Mounsor. Approved by board on: 23/03/2016 Policy became operational on:

More information

Standard for Security of Information Technology Resources

Standard for Security of Information Technology Resources MARSHALL UNIVERSITY INFORMATION TECHNOLOGY COUNCIL Standard ITP-44 Standard for Security of Information Technology Resources 1 General Information: Marshall University expects all individuals using information

More information

Definitions Application is a computer software program run on a computer for the purpose of providing a business/academic/social function.

Definitions Application is a computer software program run on a computer for the purpose of providing a business/academic/social function. Colorado State University Information Technology (IT) Security Policy Introduction Colorado State University collects information of a sensitive nature to facilitate and enable its business/academic functions.

More information

Constitution Towson University Sport Clubs Organization Campus Recreation Services. Article I Name. Article II Membership

Constitution Towson University Sport Clubs Organization Campus Recreation Services. Article I Name. Article II Membership Constitution Towson University Sport Clubs Organization Campus Recreation Services The organization shall be classified as the Sport Clubs Organization and shall be open to men and women alike. The organization

More information

Wireless Communication Device Policy Policy No September 2, Standard. Practice

Wireless Communication Device Policy Policy No September 2, Standard. Practice Standard This establishes the business need and use of cellular phones (hereinafter referred to as wireless communication devices ) as an effective means of conducting City of Richland business, and to

More information

Putting It All Together:

Putting It All Together: Putting It All Together: The Interplay of Privacy & Security Regina Verde, MS, MBA, CHC Chief Corporate Compliance & Privacy Officer University of Virginia Health System 2017 ISPRO Conference October 24,

More information

Red Flags Program. Purpose

Red Flags Program. Purpose Red Flags Program Purpose The purpose of this Red Flags Rules Program is to document the protocol adopted by the University of Memphis in compliance with the Red Flags Rules. Many offices at the University

More information

Data Protection Policy

Data Protection Policy Data Protection Policy Status: Released Page 2 of 7 Introduction Our Data Protection policy indicates that we are dedicated to and responsible of processing the information of our employees, customers,

More information

Data Inventory and Classification, Physical Devices and Systems ID.AM-1, Software Platforms and Applications ID.AM-2 Inventory

Data Inventory and Classification, Physical Devices and Systems ID.AM-1, Software Platforms and Applications ID.AM-2 Inventory Audience: NDCBF IT Security Team Last Reviewed/Updated: March 2018 Contact: Henry Draughon hdraughon@processdeliveysystems.com Overview... 2 Sensitive Data Inventory and Classification... 3 Applicable

More information

Information Technology Standards

Information Technology Standards Information Technology Standards IT Standard Issued: 9/16/2009 Supersedes: New Standard Mobile Device Security Responsible Executive: HSC CIO Responsible Office: HSC IT Contact: For questions about this

More information

Policy. Sensitive Information. Credit Card, Social Security, Employee, and Customer Data Version 3.4

Policy. Sensitive Information. Credit Card, Social Security, Employee, and Customer Data Version 3.4 Policy Sensitive Information Version 3.4 Table of Contents Sensitive Information Policy -... 2 Overview... 2 Policy... 2 PCI... 3 HIPAA... 3 Gramm-Leach-Bliley (Financial Services Modernization Act of

More information

POLICIES OF COLORADO STATE UNIVERSITY UNIVERSITY POLICY

POLICIES OF COLORADO STATE UNIVERSITY UNIVERSITY POLICY POLICIES OF COLORADO STATE UNIVERSITY UNIVERSITY POLICY Policy Title: INFORMATION TECHNOLOGY SECURITY Policy ID # 4-1018-009 Category: IV. INFORMATION TECHNOLOGY Version: 1.14 Policy Owner: Vice President

More information

Springfield, Illinois Police Department

Springfield, Illinois Police Department Directive Number: ADM-46 01-084 Issue Date: 05/28/01 Distribution: C,E* Revision Dates: 06/01/01 Effective Date: 06/01/01 Related CALEA Standards: 82.1.7 References: CALEA Standards Manual Rescinds: ADM-46/01-015

More information

Policy. London School of Economics & Political Science. Remote Access Policy. IT Services. Jethro Perkins. Information Security Manager.

Policy. London School of Economics & Political Science. Remote Access Policy. IT Services. Jethro Perkins. Information Security Manager. London School of Economics & Political Science IT Services Policy Remote Access Policy Jethro Perkins Information Security Manager Summary This document outlines the controls from ISO27002 that relate

More information

Data protection. 3 April 2018

Data protection. 3 April 2018 Data protection 3 April 2018 Policy prepared by: Ltd Approved by the Directors on: 3rd April 2018 Next review date: 31st March 2019 Data Protection Registration Number (ico.): Z2184271 Introduction Ltd

More information

Policy. Policy Information. Purpose. Scope. Background

Policy. Policy Information. Purpose. Scope. Background Background Congress enacted HIPAA Privacy & Security Compliance Policy Policy Information Policy Owner: (TBD Possibly HIPAA Privacy and Security Official or Executive Director of University Ethics and

More information

STOCKTON UNIVERSITY PROCEDURE DEFINITIONS

STOCKTON UNIVERSITY PROCEDURE DEFINITIONS STOCKTON UNIVERSITY PROCEDURE Identity Theft Prevention Program Procedure Administrator: Director of Risk Management and Environmental/Health/Safety Authority: Fair and Accurate Credit Transactions Act

More information

An Overview of the Gramm-Leach-Bliley (GLB) Act and the Safeguards Rule

An Overview of the Gramm-Leach-Bliley (GLB) Act and the Safeguards Rule An Overview of the Gramm-Leach-Bliley (GLB) Act and the Safeguards Rule Legal Disclaimer: This overview is not intended as legal advice and should not be taken as such. We recommend that you consult legal

More information

Computer Security Incident Response Plan. Date of Approval: 23-FEB-2014

Computer Security Incident Response Plan. Date of Approval: 23-FEB-2014 Computer Security Incident Response Plan Name of Approver: Mary Ann Blair Date of Approval: 23-FEB-2014 Date of Review: 31-MAY-2016 Effective Date: 23-FEB-2014 Name of Reviewer: John Lerchey Table of Contents

More information

Effective security is a team effort involving the participation and support of everyone who handles Company information and information systems.

Effective security is a team effort involving the participation and support of everyone who handles Company information and information systems. BACKED BY REFERENCE GUIDE Acceptable Use Policy GENERAL GUIDANCE NOTE: This sample policy is not legal advice or a substitute for consultation with qualified legal counsel. Laws vary from country to country.

More information

Identity Theft Prevention Policy

Identity Theft Prevention Policy Identity Theft Prevention Policy Purpose of the Policy To establish an Identity Theft Prevention Program (Program) designed to detect, prevent and mitigate identity theft in connection with the opening

More information

Responsible Officer Approved by

Responsible Officer Approved by Responsible Officer Approved by Chief Information Officer Council Approved and commenced August, 2014 Review by August, 2017 Relevant Legislation, Ordinance, Rule and/or Governance Level Principle ICT

More information

CSU IT Security Policy Version Approved by ITEC (date), Colorado State University Information Technology (IT) Security Policy

CSU IT Security Policy Version Approved by ITEC (date), Colorado State University Information Technology (IT) Security Policy Colorado State University Information Technology (IT) Security Policy Introduction Colorado State University collects information of a sensitive nature to facilitate and enable its business/academic functions.

More information

Element Finance Solutions Ltd Data Protection Policy

Element Finance Solutions Ltd Data Protection Policy Element Finance Solutions Ltd Data Protection Policy CONTENTS Section Title 1 Introduction 2 Why this Policy Exists 3 Data Protection Law 4 Responsibilities 5 6 7 8 9 10 Data Protection Impact Assessments

More information

MNsure Privacy Program Strategic Plan FY

MNsure Privacy Program Strategic Plan FY MNsure Privacy Program Strategic Plan FY 2018-2019 July 2018 Table of Contents Introduction... 3 Privacy Program Mission... 4 Strategic Goals of the Privacy Office... 4 Short-Term Goals... 4 Long-Term

More information

University of Pittsburgh Security Assessment Questionnaire (v1.7)

University of Pittsburgh Security Assessment Questionnaire (v1.7) Technology Help Desk 412 624-HELP [4357] technology.pitt.edu University of Pittsburgh Security Assessment Questionnaire (v1.7) Directions and Instructions for completing this assessment The answers provided

More information

Internet, , Social Networking, Mobile Device, and Electronic Communication Policy

Internet,  , Social Networking, Mobile Device, and Electronic Communication Policy TABLE OF CONTENTS Internet, Email, Social Networking, Mobile Device, and... 2 Risks and Costs Associated with Email, Social Networking, Electronic Communication, and Mobile Devices... 2 Appropriate use

More information

SAVANNAH LAKES VILLAGE PROPERTY OWNERS ASSOCIATION, INC. JOB DESCRIPTION

SAVANNAH LAKES VILLAGE PROPERTY OWNERS ASSOCIATION, INC. JOB DESCRIPTION SAVANNAH LAKES VILLAGE PROPERTY OWNERS ASSOCIATION, INC. JOB DESCRIPTION POSITION: CHIEF OPERATING OFFICER FUNCTION: Responsible for all aspects of the SLV POA day-to-day operations. In this capacity,

More information

Information Classification & Protection Policy

Information Classification & Protection Policy University of Scranton Information Technology Policy Information Classification & Protection Policy Executive Sponsor: AVP Information Resources Responsible Office: Information Security Originally Issued:

More information

01.0 Policy Responsibilities and Oversight

01.0 Policy Responsibilities and Oversight Number 1.0 Policy Owner Information Security and Technology Policy Policy Responsibility & Oversight Effective 01/01/2014 Last Revision 12/30/2013 Department of Innovation and Technology 1. Policy Responsibilities

More information

Bring Your Own Device Policy

Bring Your Own Device Policy Title: Status: Effective : Last Revised: Policy Point of Contact: Synopsis: Bring Your Own Device Policy Final 2017-Jan-01 2016-Nov-16 Chief Information Officer, Information and Instructional Technology

More information

Security and Privacy Breach Notification

Security and Privacy Breach Notification Security and Privacy Breach Notification Version Approval Date Owner 1.1 May 17, 2017 Privacy Officer 1. Purpose To ensure that the HealthShare Exchange of Southeastern Pennsylvania, Inc. (HSX) maintains

More information

ANNUAL SECURITY AWARENESS TRAINING 2012

ANNUAL SECURITY AWARENESS TRAINING 2012 UMW Information Technology Security Program Annual Security Awareness Training for UMW Faculty and Staff ANNUAL SECURITY AWARENESS TRAINING 2012 NETWORK AND COMPUTER USE POLICY Users of information technology

More information

13. Acceptable Use Policy

13. Acceptable Use Policy 13. Acceptable Use Policy Purpose Indian River State College s intention for publishing an Acceptable Use Policy is to outline the acceptable use of computer equipment and services at Indian River State

More information

XAVIER UNIVERSITY Building Access Control Policy

XAVIER UNIVERSITY Building Access Control Policy Effective: March 25, 2019 Last Updated: March 20, 2019 XAVIER UNIVERSITY Building Access Control Policy Responsible University Office: Auxiliary Services, Physical Plant Responsible Executive: Vice President,

More information

Guest Network Account Request Form

Guest Network Account Request Form Guest Network Account Request Form Applicant Information Name: Telephone Number: E-mail Address: Company Information Company Name: Address: State: Telephone Number: City: Zip: DURATION OF VISIT - Please

More information

Open Data Policy City of Irving

Open Data Policy City of Irving Open Data Policy City of Irving 1. PURPOSE: The City of Irving is committed to fostering open, transparent, and accessible city government, and recognizes that by sharing data freely, the city will generate

More information

HIPAA Privacy & Security Training. HIPAA The Health Insurance Portability and Accountability Act of 1996

HIPAA Privacy & Security Training. HIPAA The Health Insurance Portability and Accountability Act of 1996 HIPAA Privacy & Security Training HIPAA The Health Insurance Portability and Accountability Act of 1996 AMTA confidentiality requirements AMTA Professional Competencies 20. Documentation 20.7 Demonstrate

More information

Computer Use and File Sharing Policy

Computer Use and File Sharing Policy Computer Use and File Sharing Policy Williamson College recognizes the value of computer and other electronic resources to improve student learning and enhance the administration and operation of its school.

More information

Cybersecurity in Higher Ed

Cybersecurity in Higher Ed Cybersecurity in Higher Ed 1 Overview Universities are a treasure trove of information. With cyber threats constantly changing, there is a need to be vigilant in protecting information related to students,

More information

Security Awareness Compliance Requirements. Updated: 11 October, 2017

Security Awareness Compliance Requirements. Updated: 11 October, 2017 Security Awareness Compliance Requirements Updated: 11 October, 2017 Executive Summary The purpose of this document is to identify different standards and regulations that require security awareness programs.

More information

Department of Public Health O F S A N F R A N C I S C O

Department of Public Health O F S A N F R A N C I S C O PAGE 1 of 7 Category: Information Technology Security and HIPAA DPH Unit of Origin: Department of Public Health Policy Owner: Phillip McDown, CISSP Phone: 255-3577 CISSPCISSP/C Distribution: DPH-wide Other:

More information

IIT Cognos Portal Librarian Guide

IIT Cognos Portal Librarian Guide IIT Cognos Portal Librarian Guide 1.0 About the Cognos Portal The IIT Cognos Portal allows users to access reports and perform analysis based on data stored in the SunGard Banner Operation Data Store (ODS)

More information

University of Alabama at Birmingham MINIMUM SECURITY FOR COMPUTING DEVICES RULE July 2017

University of Alabama at Birmingham MINIMUM SECURITY FOR COMPUTING DEVICES RULE July 2017 University of Alabama at Birmingham MINIMUM SECURITY FOR COMPUTING DEVICES RULE July 2017 Related Policies, Procedures, and Resources UAB Acceptable Use Policy, UAB Protection and Security Policy, UAB

More information

University of Liverpool

University of Liverpool University of Liverpool Information Security Policy Reference Number Title CSD-003 Information Security Policy Version Number 3.0 Document Status Document Classification Active Open Effective Date 01 October

More information

SECURITY & PRIVACY DOCUMENTATION

SECURITY & PRIVACY DOCUMENTATION Okta s Commitment to Security & Privacy SECURITY & PRIVACY DOCUMENTATION (last updated September 15, 2017) Okta is committed to achieving and preserving the trust of our customers, by providing a comprehensive

More information

Date Approved: Board of Directors on 7 July 2016

Date Approved: Board of Directors on 7 July 2016 Policy: Bring Your Own Device Person(s) responsible for updating the policy: Chief Executive Officer Date Approved: Board of Directors on 7 July 2016 Date of Review: Status: Every 3 years Non statutory

More information

BFB-IS-3: Electronic Information Security

BFB-IS-3: Electronic Information Security Responsible Officer: Responsible Office: Chief Information Officer & VP - Information Technology Services IT - Information Technology Services Issuance Date: TBD, 2017 Effective Date: TBD, 2017 Last Review

More information

Information Security Strategy

Information Security Strategy Security Strategy Document Owner : Chief Officer Version : 1.1 Date : May 2011 We will on request produce this Strategy, or particular parts of it, in other languages and formats, in order that everyone

More information

Protecting Personally Identifiable Information (PII) Privacy Act Training for Housing Counselors

Protecting Personally Identifiable Information (PII) Privacy Act Training for Housing Counselors Protecting Personally Identifiable Information (PII) Privacy Act Training for Housing Counselors Presented by the Office of Housing Counseling and The Office of the Chief Information Officer Privacy Program

More information

Cleveland State University General Policy for University Information and Technology Resources

Cleveland State University General Policy for University Information and Technology Resources Cleveland State University General Policy for University Information and Technology Resources 08/13/2007 1 Introduction As an institution of higher learning, Cleveland State University both uses information

More information

Checklist: Credit Union Information Security and Privacy Policies

Checklist: Credit Union Information Security and Privacy Policies Checklist: Credit Union Information Security and Privacy Policies Acceptable Use Access Control and Password Management Background Check Backup and Recovery Bank Secrecy Act/Anti-Money Laundering/OFAC

More information

Secure Messaging Mobile App Privacy Policy. Privacy Policy Highlights

Secure Messaging Mobile App Privacy Policy. Privacy Policy Highlights Secure Messaging Mobile App Privacy Policy Privacy Policy Highlights For ease of review, Everbridge provides these Privacy Policy highlights, which cover certain aspects of our Privacy Policy. Please review

More information

GM Information Security Controls

GM Information Security Controls : Table of Contents 2... 2-1 2.1 Responsibility to Maintain... 2-2 2.2 GM s Right to Monitor... 2-2 2.3 Personal Privacy... 2-3 2.4 Comply with Applicable Laws and Site Specific Restrictions... 2-3 2.5

More information

Mitigation Framework Leadership Group (MitFLG) Charter DRAFT

Mitigation Framework Leadership Group (MitFLG) Charter DRAFT Mitigation Framework Leadership Group (MitFLG) Charter DRAFT October 28, 2013 1.0 Authorities and Oversight The Mitigation Framework Leadership Group (MitFLG) is hereby established in support of and consistent

More information

INCOMMON FEDERATION: PARTICIPANT OPERATIONAL PRACTICES

INCOMMON FEDERATION: PARTICIPANT OPERATIONAL PRACTICES INCOMMON FEDERATION: PARTICIPANT OPERATIONAL PRACTICES Participation in the InCommon Federation ( Federation ) enables a federation participating organization ("Participant") to use Shibboleth identity

More information