INFORMATION SECURITY POLICY

 

INTRODUCTION

Storage of university data on computers and transfer across the network eases use and expands our functionality.  Commensurate with that expansion is the need for the appropriate security measures. Security is not distinct from the functionality.

 

The Information Security Policy (Policy) recognizes that not all communities within the University are the same and that data are used differently by various units within the University. The principles of academic freedom and free exchange of ideas apply to this policy, and this policy is not intended to limit or restrict those principles. These policies apply to all units within the University.

 

Each unit within the University should apply this policy to meet their information security needs. The Policy is written to incorporate current technological advances. The technology installed at some units may limit immediate compliance with the Policy. Instances of non-compliance must be reviewed and approved by the chief information officer or the equivalent officer(s).

 

Throughout the document the term must and should are used carefully. "Musts" are not negotiable; "shoulds" are goals for the university. The terms data and information are used interchangeably in the document.

 

The terms system and network administrator are used in this document. These terms are generic and pertain to any person who performs those duties, not just those with that title or primary job duty. Many students, faculty and staff member are the system administrators for their own machines.

 

PURPOSE OF THIS POLICY

By information security we mean protection of the University's data, applications, networks, and computer systems from unauthorized access, alteration, or destruction

 

The purpose of the information security policy is:

RESPONSIBILITY

The chair of the University Technology Management Team (UTMT) is responsible for implementing the policy. UTMT, chaired by the Vice President for Administration, is a coordinating group comprised of chief information officers from the three campuses, the university administration, and the hospital.

 

UTMT must see to it that:

Members of UTMT are each responsible for establishing procedures to implement these policies within their areas of responsibility, and for monitoring compliance.

 

GENERAL POLICY

Required Policies

Recommended Practices

DATA CLASSIFICATION POLICY

It is essential that all University data be protected. There are however gradations that require different levels of security. All data should be reviewed on a periodic basis and classified according to its use, sensitivity, and importance. We have specified three classes below:

 

High Risk: Information assets for which there are legal requirements for preventing disclosure or financial penalties for disclosure. Data covered by federal and state legislation, such as FERPA, HIPAA or the Data Protection Act, are in this class. Payroll, personnel, and financial information are also in this class because of privacy requirements.

 

This policy recognizes that other data may need to be treated as high risk because it would cause severe damage to the University if disclosed or modified. The data owner should make this determination. It is the data owner’s responsibility to implement the necessary security requirements.

 

Confidential: Data that would not expose the University to loss if disclosed, but that the data owner feels should be protected to prevent unauthorized disclosure. It is the data owner’s responsibility to implement the necessary security requirements.

 

Public: Information that may be freely disseminated

 

All information resources should be categorized and protected according to the requirements set for each classification. The data classification and its corresponding level of protection should be consistent when the data is replicated and as it flows through the University.

ACCESS CONTROL POLICY

VIRUS PREVENTION POLICY 

INTRUSION DETECTION POLICY

INTERNET SECURITY POLICY

SYSTEM SECURITY POLICY

ACCEPTABLE USE POLICY

Each Campus and UA must have a policy on appropriate and acceptable use that includes these requirements:

EXCEPTIONS

In certain cases, compliance with specific policy requirements may not be immediately possible.  Reasons include, but are not limited to, the following:

In such cases, units must develop a written explanation of the compliance issue and a plan for coming into compliance with the University's Information Security Policy in a reasonable amount of time. Explanations and plans must be submitted to the campus CIO or the equivalent officer(s).

 


June 14, 2004:  Approved by Senate of Urbana-Champaign Campus


Date Revised: July 22, 2004
Date Issued:  April 8, 2003
Issued by: Office of the Chief Information Officer
Approved by: Office of the Provost and Vice Chancellor for Academic Affairs
Use of University Premises, Facilities and Computing Infrastructure:  Section VIII/1.2