ITS Security Policy 001 - Governing Standards, Policies, and Guidelines

Summary

This security policy outlines the key regulatory and compliance standards governing data protection, privacy, and cybersecurity. It provides references to federal, state, and industry regulations to ensure institutional compliance and safeguard sensitive information.

Body

Status: Final Draft
Last Revision Date: March 6, 2025

Regulatory and Compliance References

To ensure compliance with federal, state, and industry security standards, the following regulations and guidelines serve as foundational references:

  1. U.S. Department of Education: Guidance Letter – Protecting Student Information
    Student Privacy

  2. U.S. Department of Education: Family Educational Rights and Privacy Act (FERPA)
    FERPA Policy

  3. U.S. Department of Homeland Security: Federal Information Security Management Act (FISMA)
    FISMA Overview

  4. Gramm-Leach-Bliley Act (GLBA)
    GLBA Compliance

  5. Federal Trade Commission (FTC) Red Flags Rule
    FTC Red Flags Guide

  6. Health Insurance Portability and Accountability Act (HIPAA)
    HIPAA Privacy Laws

  7. International Organization for Standardization (ISO) Standards
    ISO Standards

  8. National Institute of Standards and Technology (NIST) Cybersecurity Framework
    NIST Cybersecurity Framework

  9. Payment Card Industry Data Security Standard (PCI DSS)
    PCI Compliance

  10. Sarbanes-Oxley Act (SOX) for Colleges and Universities
    SOX Overview

  11. Oregon Identity Theft Protection Act, ORS 646A.600-628
    Oregon DOJ Data Breaches

This policy provides guidance for maintaining compliance with the aforementioned regulations to ensure the security and integrity of institutional data and sensitive information.

Details

Details

Article ID: 144969
Created
Wed 7/13/22 4:00 PM
Modified
Thu 3/6/25 7:24 PM