Security Policy

Policy Information

  • Policy Name: IT Security Policy

  • Owner: Chief Campus Information Security Officer

  • Effective Date:

  • Applicable Laws, Regulations, and Standards:

    • Gramm-Leach-Bliley Act (GLBA)

    • HIPAA

    • FERPA

    • NIST Cybersecurity Framework

    • Applicable contractual and College requirements

 

I. Purpose

The purpose of this Information Technology Security Policy is to establish overarching requirements for protecting the confidentiality, integrity, and availability of The College of St. Scholastica’s information, systems, and technology resources. This policy defines the College’s core information technology security principles and responsibilities and supports the College’s broader information security program and related governance requirements.

II. Scope

This policy applies to College-owned or managed information, systems, applications, networks, devices, services, and other technology resources, regardless of where they are hosted or maintained. It also applies to all students, employees, contractors, affiliates, vendors, and other authorized users who access or support College information or technology resources.

III. Policy

  1. Governance and Risk Management:

    • Information technology security decisions must be based on identified risks, legal and regulatory obligations, contractual requirements, operational needs, and the sensitivity and criticality of the information and systems involved.

    • Security risks must be identified, assessed, treated, monitored, and reported in accordance with the College’s established information security governance and risk management requirements.

    • Security requirements should be proportionate to risk and appropriate to the size, scope, complexity, and resources of the College.

  2. Identity and Access Management:

    • Access to College information and systems must be limited to authorized users based on business need, role, and the principle of least privilege.

    • Account provisioning, authentication, privileged access, access reviews, and account deprovisioning must be managed in accordance with applicable College identity and access management requirements.

  3. Data Protection:

    • Institutional information must be classified, inventoried, stored, accessed, transmitted, retained, and disposed of in accordance with applicable College data protection policies.

    • Sensitive or regulated information must be protected using appropriate administrative, technical, and physical safeguards, including encryption where required.

  4. Secure Configuration, Maintenance, and Change:

    • College systems and technology resources must be securely configured, maintained, and supported throughout their lifecycle.

    • Patches, vulnerabilities, system changes, and unsupported technologies must be managed in accordance with applicable patch management, vulnerability management, change management, and risk management requirements.

  5. Monitoring and Incident Response:

    • Security-relevant activity must be monitored and logged as appropriate to support the detection, investigation, and response to unauthorized or suspicious activity.

    • Suspected or confirmed information security incidents must be reported promptly and handled in accordance with applicable College incident response requirements, plans, and procedures.

  6. Backup, Recovery, and Resilience:

    • Appropriate backup, recovery, disaster recovery, and business continuity capabilities must be maintained based on system criticality and business requirements.

    • Recovery capabilities must be documented, protected, and tested in accordance with applicable College backup, recovery, business continuity, and disaster recovery requirements and plans.

  7. Third-Party Services:

    • Technology vendors and other third parties that access College information or systems, provide critical technology services, or present material security risk must be evaluated and managed in accordance with applicable College third-party risk management and contracting requirements.

    • Vendor access and security obligations must be appropriate to the nature and level of risk presented by the relationship.

  8. Security Awareness and Acceptable Use:

    • Users must complete applicable information security education and awareness activities and comply with College acceptable use and other applicable technology requirements.

    • Users are responsible for protecting College information and technology resources and promptly reporting suspected security incidents, policy violations, or other security concerns.

  9. Exceptions:

    • Exceptions to this policy or related information security requirements must be documented, evaluated for risk, approved through the College’s established exception process, and reviewed as appropriate.

    • Compensating controls or other risk treatment measures may be required when an exception is approved.

IV. Responsibilities

  • Chief Campus Information Security Officer: Owns and oversees this policy, coordinates the College’s information security program, establishes security expectations, and ensures alignment with applicable governance, risk, legal, regulatory, contractual, and institutional requirements.

  • Chief Information Officer (CIO): Supports institutional technology governance, operational priorities, and the resources necessary to implement and maintain appropriate security controls.

  • Information Technologies: Implements, operates, monitors, and maintains information technology security controls and processes within its areas of responsibility.

  • Department Heads, Data Owners, and System Owners: Identify business and security requirements, support risk management activities, and ensure information and systems within their areas are managed in accordance with applicable College policies.

  • Users: Comply with College information technology and information security requirements, protect assigned accounts and devices, and promptly report suspected incidents or security concerns.

  • Vendors and Third Parties: Comply with applicable contractual, legal, regulatory, and College security requirements when accessing or supporting College information or technology resources.

V. Compliance and Review

  • This policy will be reviewed at least annually to ensure it remains effective and aligned with changes in technology, risk, operations, and applicable requirements.

  • Periodic reviews, assessments, or audits may be conducted to evaluate compliance with this policy and the effectiveness of related security controls.

  • Failure to comply with this policy may result in corrective or disciplinary action consistent with applicable College policies and contractual requirements.

VI. Individuals and Entities Affected by This Policy

This policy applies to:

  • All students, employees, contractors, affiliates, vendors, and other authorized users of College information or technology resources.

  • All academic and administrative departments that own, manage, use, or support College information, systems, applications, services, or technology resources.

VII. Related Documents, Forms, and Procedures

  • Written Information Security Program (WISP)

  • Applicable College information technology and information security policies, standards, procedures, and plans

  • Applicable College governance, risk management, business continuity, records management, and contractual requirements

Print Article

Related Services / Offerings (1)

View information about the College's multi-factor authentication tool.