Information Security Office
The Office of Information Technology Information Security Office leads a robust cybersecurity program to support the university mission of research, teaching and outreach, and securely enable faculty, student and administrative needs. This includes support for university IT compliance efforts across regulatory and contractual agreements including GLBA, HIPAA, FERPA, PCI, NIST 800-171, CMMC, NSPM-33 and others.
Key elements of the cybersecurity program include:
- Annual security awareness training and monthly phish training for all employees, and supplemental cybersecurity training for select groups.
- Annual Risk Assessment and testing processes to identify and prioritize remediation for reasonably foreseeable internal and external risks to the security, confidentiality and integrity of university data.
- Data Classification program, per APM 30.11 to track and apply appropriate controls based on data classification and risk.
- Initial and periodic assessment of service providers through .
- Implementing the incident response plan including tools, services and timely response and recovery from any material security events, as authorized by APM 30.14, Cyber Incident Response and Reporting.
- Implement policies, stand