信息技术

资讯保安政策

资讯保安政策

执行概要  

An information security program (ISP) is designed to protect information resources from a wide range of threats, ensure business continuity, and minimize business risk to Lindenwood University and members of the Lindenwood community. 信息资源安全是 achieved by implementing applicable policies, processes, procedures, controls, standards, guidelines, organizational structures, and supporting technology. The information security program (ISP) governs the confidentiality, integrity, and availability of 澳门威尼斯人平台官网 data, especially highly sensitive or critical data, and defines the responsibilities of departments and individuals for such data. 

范围

This information security program applies to any person granted access to Lindenwood University information resources, including but not limited to students, faculty, staff, alumni, temporary employees, contractors, volunteers, friends of 澳门威尼斯人平台官网, and guests who have access to 澳门威尼斯人平台官网 information resources. 这些技术资源包括 但不局限于数据, 图片, 文本, 录音, and software which are stored on hardware or other digital storage media both on-campus and at outsourced locations. 

政策及程序

The following foundational elements are designed to create a framework for the information security program (ISP), help 澳门威尼斯人平台官网 adopt a control catalog, and comply with 资讯保安的最佳实务. 

  • Inventory and Accountability of Information Assets: 澳门威尼斯人平台官网 collects, 商店, and uses various data as part of normal operations.  This information is stored in various systems that are inventoried and managed by the Lindenwood IT Enterprise team. 
  • Sensitive Data Classification: Data classification is required to determine the relative sensitivity of information resources, which is the basis for protection and access control.  
  • Data Risk Management:  澳门威尼斯人平台官网's risk management cycle includes assessment, 审查, 缓解, and reporting based upon the university’s risk tolerance. 
  • Identity and Access Management:   Ensures accurate identification of authorized users and provides access controls to the use of information resources. 
  • Control Activity: Defined controls provide a system of checks and balances intended to identify irregularities, 防止滥用的发生, and assist in resolving discrepancies that are introduced into the operation of the business. 
  • IT Security Awareness: The goal of the information security awareness program is to strengthen the information security culture of 澳门威尼斯人平台官网 through education, 主动学习, 沟通, 和协作. 
  • Physical Security: Physical security controls and secure areas are used to minimize unauthorized access, 损害, and interference to information resources. This includes providing environmental safeguards and controlling physical access to equipment and 澳门威尼斯人平台官网 data. 
  • IT Contingency Planning: The Lindenwood IT contingency Plan is designed to minimize the impact of a disaster or disruptive incident on an organization's IT systems and operations, and to ensure that mission-critical functions can be quickly restored in the event of an outage or other disruption. 
  • Security Incident Response: Effectively and efficiently handle and manage any security incidents that may occur within 澳门威尼斯人平台官网’s IT infrastructure. 

责任及执行

Vice President/Chief Information Officer (CIO): 澳门威尼斯人平台官网’s Chief 信息安全 Officer is responsible for overseeing the organization’s technology infrastructure and ensuring that it aligns with the business goals and objectives.  The CIO will periodically present an update on the status of the ISP to the executive officers and the Board of Trustees.  

Assistant Vice President for 信息技术 (AVPIT): The AVPIT of 澳门威尼斯人平台官网 is responsible for managing the day-to-day operations of the university’s IT systems.  This includes ensuring that the ISP is properly implemented and maintained. 

IT Governance Committee: Works in conjunction with the CIO and AVPIT to 审查 and recommend university policies regarding information security. 

定义

Access Controls: The process of controlling access to systems, networks and information based on business and security requirements of the user’s role within 澳门威尼斯人平台官网.  

Risk Tolerance: 澳门威尼斯人平台官网’s willingness to accept risk by either accepting, 转移, 或者降低风险暴露.  

信息安全 Incident: An event that impacts or has the potential to impact the confidentiality, availability, or integrity of 澳门威尼斯人平台官网's information resources.  

其他文件及政策


最后修订日期:2023年5月