Purpose

The purpose of this policy is to protect the College’s information resources from accidental or intentional unauthorized access, modification, or damage, while also preserving the open information-sharing requirements of its academic culture. It prescribes comprehensive security controls that include administrative, technical, and physical safeguards that are required by regulatory obligations, insurance requirements, or best practice.

Policy

Designated Qualified Individual1

The Information Security Officer is responsible for overseeing and implementing and enforcing the College’s information security program.

Assessment2

The information security program will be based on a risk assessment that identifies reasonably foreseeable internal and external risks to the confidentiality, integrity, and availability of institutional data and systems and assesses the adequacy of the security controls in place to safeguard these systems and data.

Risk assessments will be performed regularly to evaluate the sufficiency of elements of the information security program to meet the current and foreseeable threats to institutional data and systems.

Policies

The information security program will include policies appropriate to the size and complexity, the nature and scope of College activities, and the sensitivity of the data and systems in scope. These will include, at a minimum:

  • Data classification policy3 that Identify and manage the data, personnel, devices, systems, and facilities in accordance with their importance and risk
  • Secure coding practices4 for “in-house” development
  • Data and log retention policies5
  • Change management plan6
  • Oversight of service providers policy7
  • Incident response plan8

Security Controls9

The information security program10 will include platforms, processes, and procedures appropriate to the size and complexity, the nature and scope of College activities, and the sensitivity of the data and systems in scope. These elements will include, at a minimum:

  • Periodic review of both logical and physical access11
  • Protect by encryption all customer information both in transit and at rest12
  • Multi Factor authentication13
  • Secure disposal of customer information14
  • Monitoring and logging of the activity of authorized users and the detection of unauthorized access or use of customer information by such users15
  • Continuous monitoring and intrusion detection16
  • Penetration testing17
  • Vulnerability management18
  • Training19 to include end user cybersecurity training20, phishing simulation21, and training22 of information security personnel23

Periodic Re-evaluation and Adjustment24

The information security officer will re-assess and adapt the information security program based on the findings from testing, monitoring, and assessment activities, significant changes to the operations or business arrangements, security incidents, the threat environment, or any other circumstances might reasonably have a significant influence on the risk posture of College data or systems.

Reporting25

The information security officer will provide regular reports, either in person or in writing, to the audit committee of the board of trustees or equivalent governing body. These reports, which should occur at least annually, will encompass various aspects such as the overall status of the information security program, compliance with applicable regulations, and existing risks. The reports will also cover assessments, outcomes, and concerns pertaining to service providers, security incidents and responses, as well as recommendations for enhancing the information security program.

Revision History

Date of change: May 6, 2025
Responsible: J. Scannell and K. George
Summary of change: Minor formatting changes

Issuing Authority

CIO/CTO

References

Code of Federal Regulations, Title 16, Part 314, Standards for Safeguarding Customer Information
1Code of Federal Regulations, Title 16, Part 314, Standards for Safeguarding Customer Information, Section 4, Paragraph (a)
216 CFR 314.4(b)
316 CFR 314.4 (c) (2)
416 CFR 314.4 (c) (4)
516 CFR 314.4 (c) (6) (ii)
616 CFR 314.4 (c) (7)
716 CFR 314.4 (f)
816 CFR 314.4(h)
916 CFR 314.4 (c)
1016 CFR 314.3 (a)
1116 CFR 314.4 (c) (1)
1216 CFR 314.4 (c) (3)
1316 CFR 314.4 (c) (5)
1416 CFR 314.4 (c) (6) (i)
1516CFR 314.4 (c) (8)
1616 CFR 314.4 (d) (1)
1716 CFR 314.4 (d) (2) (i)
1816 CFR 314.4 (d) (2) (ii)
1916 CFR 314.4 (e)
2016 CFR 314.4 (e) (1)
2116 CFR 314.4 (e) (2)
2216 CFR 314.4 (e) (3)
2316 CFR 314.4 (e) (4)
2416 CFR 314-4 (g)
2516 CFR 314.4 (i)