Â̾ÞÈËÊÓƵ Cybersecurity Policies
A.ÌýCybersecurity Policy (effective October 19, 2023)
B.ÌýAcceptable Use PolicyÌýÌý(effective July 1, 2022)
C.ÌýInformation Classification Policy (effective July 1, 2022)
D.ÌýPassword PolicyÌý(effective October 4, 2022)
E.ÌýPrivacy PolicyÌý(effective August 1, 2022)
Â̾ÞÈËÊÓƵ Cybersecurity Standards
- Artificial Intelligence Standard (effective 30 May 2024)
- Email Security Standard (effective 30 May 2024)
- Digital Millennium Copyright Act RequirementsÌý(DMCA)Ìý (effective 30 May 2024)
- Training & Awareness Standard (effective 30 May 2024)
- Security Categorization StandardÌý (effective 17 SEPT 2024)
- Shared File Management Standard (effective 30 May 2024)
- Â̾ÞÈËÊÓƵ Data Security Addendum (effective 30 May 2024)
- System Security Plan TemplateÌý (effective 30 May 2024)
- Endpoint Management Standard (effective 17 DecemberÌý2024)
- Internet of Things Usage Standard (effective 30 May 2024)
- Mobile Device Security StandardÌý(effective 30 May 2024)
- Vulnerability and Patch Management Standard (effective 30 May 2024)
- IT Inventory Standard (effective 17 DecemberÌý2024)
- Access Management Standard (effective 30 May 2024)
- Account Management Standard (effective 30 May 2024)
- Access to Password Protected Information StandardÌý (effective 30 May 2024)
- Privileged Access Management StandardÌý (effective 30 May 2024)
- Remote Access Security Standard (effective 30 May 2024)
- Sponsored Accounts Standard (effective 30 May 2024)
- Network Security and Management Standard (effective 30 May 2024)
- Privately Managed Network Standard (effective 30 May 2024)
- Physical and Camera Security StandardÌý (effective 30 May 2024)
- Lab Security Standard (effective 17 DecemberÌý2024)
- Exception Standard (effective 30 May 2024)
- Incident Response StandardÌý (effective 30 May 2024)
- Risk Acceptance StandardÌý (effective 30 May 2024)
- Risk Management StandardÌý (effective 30 May 2024)
- Configuration Management StandardÌý (effective 30 May 2024)
- Security Monitoring and Log Management Standard (effective 30 May 2024)
- Third-Party Information Security Standard (effective 30 May 2024)
- Â̾ÞÈËÊÓƵ Written Information Security ProgramÌý(effective 10 September 2024)
Standards
In Force:
- Cybersecurity Exception Standard (effective 15ÌýFEB 2021)
- Cybersecurity Risk Management StandardÌý(effective 15ÌýFEB 2021)
- Cybersecurity Risk Acceptance StandardÌý(effective 15ÌýFEB 2021)
- Security Categorization StandardÌý(effective 15ÌýFEB 2021)
- Endpoint Management Standard (effective 10ÌýAUG 2021)
- Access Management Standard (effectiveÌý19 AUG 2021)
- Cybersecurity Awareness & Training Standard (effectiveÌý19 AUG 2021)
- Privately Managed Network Standard (effectiveÌý19 AUG 2021)
- Vendor Cloud Service Security Standard (effectiveÌý19 AUG 2021)
- Access to Password Protected Information Standard (effectiveÌý6 JAN 2022)
- Digital Millennium Copyright Act StandardÌý(DMCA) (effective 29 JAN 2022)
- Network Security and Management Standard (effectiveÌý29 JAN 2022)
- Sponsored Accounts Standard (effective 10 FEB 2022)
- Ìý
Ìý
ET&S PolicyÌý& StandardÌýInitiative
Technology/Cybersecurity Policies & Standards
ProvideÌýFeedback on Proposed Policies
Sign-up to Receive Policy & Standard Initiative Updates via Email
- Endpoint Management Standard (effective 6 AUG 2021)
- Cybersecurity Awareness and Training (effectiveÌý6 AUG 2021)
- Vendor Cloud Service Security (effectiveÌý6 AUG 2021)
- Privately Managed Network (effectiveÌý6 AUG 2021)
- Access Management (effectiveÌý6 AUG 2021)
Policies
In Force:
- Â̾ÞÈËÊÓƵ Use of Technological Resources PolicyÌý
- Â̾ÞÈËÊÓƵ Password PolicyÌý(effective 20 JAN 2020)
- Â̾ÞÈËÊÓƵ Privacy PolicyÌý(effective AUG 2018)
Proposed
Targeted effective date 01 MAY 2021
- Â̾ÞÈËÊÓƵ Acceptable Use Policy
- Â̾ÞÈËÊÓƵ Cybersecurity Policy
- Â̾ÞÈËÊÓƵ Information Classification Policy
Feedback on or questions about these Proposed Policies can be submitted .
Standards
In Force
- Cybersecurity Exception Standard (effective 15ÌýFEB 2021)
- Cybersecurity Risk Management StandardÌý(effective 15ÌýFEB 2021)
- Cybersecurity Risk Acceptance StandardÌý(effective 15ÌýFEB 2021)
- Security Categorization StandardÌý(effective 15ÌýFEB 2021)
Proposed
TargetedÌýeffective date 01 MAY 2021
- Access Management Standard
- Cybersecurity Awareness & Training Standard
- Identity Management Standard
- Privately Managed Network Standard
- Privileged Access Management Standard
- Vendor Cloud Service Security Standard
Feedback on or questions about these Proposed Standards can be submitted .
Planned
Phase 1 Remaining Standards, targeted to become effective 01 May 2021, will be available for review byÌýearly March 2021
- Access to Password Protected Information Standard
- Public and Sensitive Information Handling StandardÌý
- Protected Information Handling StandardÌý
- Restricted Information Handling StandardÌý
- Confidential Information Handling StandardÌý
- Endpoint Management StandardÌý
Phase 2 Standards, targeted to become effective late summer/early fall 2021
- Account Management Standard
- Institutional Email Security and Use Standard
- Network Security and Management Standard
- Server Security and Management Standard
- Sponsored/Guest Access Management Standard
Phase 3+ Standards, planned for late 2021 and 2022
- Application Administration Standard
- Contingency Planning Standard
- Cybersecurity Roles and Responsibilities Standard
- Data Breach Notification Standard
- Data Center Facility Security, Access, and Use Standard
- Data Administration and Management Standard
- Information Technology Resource Secure Disposal Standard
- Information Technology Inventory Management Standard
- Non-Primary Identity Management Standard
- Password Management Standard
- Personnel Security Standard
- Physical Information Technology Asset Access and Management Standard
- Remote Access and VPN Standard
- Security Assessment and Testing Standard
- Security Configuration Management Standard
- Security Logging and Monitoring Standard
- Shared File Storage Standard
- System Acquisition, Development, and Maintenance Lifecycle Standard
- Vulnerability and Patch Management Standard
- Wireless Network Security and Management Standard
Ìý
Ìý
Ìý
Ìý
Contact Information
The Ìýform can be used to ask questionsÌýor raise concerns about any of the published Standards.Ìý
You can also contact the Cybersecurity GRC team atÌýCybersecurity.GRC@usnh.edu. However, unless specifically noted as being open for Public Comment, Standards published to this site are final, approved versions provided to allow administrative, academic, and business units an opportunity to review prior to their effective date and, if needed, request exceptions.
All other requests can be submitted here:Ìý
Failure to comply with the Â̾ÞÈËÊÓƵ Cybersecurity Standards puts the University System, its component institutions, and its information and information technology resources at risk and may result in disciplinary action. Disciplinary procedures will be proportionally appropriate for the individual responsible for noncompliance (e.g., students, faculty, staff, vendors) as outlined in the relevant institutional regulations for that individual (e.g., student conduct and/or applicable personnel policies). Non-compliant technology and/or activities may be mitigated as deemed necessary by the CISO and/or CIO. Employees who are members of institutionally recognized bargaining units are covered by the disciplinary provisions set forth in the agreement for their bargaining units.
Requests for exceptions to any of the Â̾ÞÈËÊÓƵ Cybersecurity Standards may be submitted and approved according to the requirements provided in the Cybersecurity Exception Standard.
Glossary
For terms and definitions, please refer to the