{"id":356,"date":"2024-07-22T16:02:23","date_gmt":"2024-07-22T16:02:23","guid":{"rendered":"https:\/\/www.mtsu.edu\/policies\/?page_id=356"},"modified":"2026-08-05T14:29:42","modified_gmt":"2026-08-05T14:29:42","slug":"p920","status":"publish","type":"page","link":"https:\/\/www.mtsu.edu\/policies\/p920\/","title":{"rendered":"920 \u00a0Information Security"},"content":{"rendered":"\n
Approved by President<\/strong> I. Purpose<\/strong><\/p>\n\n\n\n This policy ensures the confidentiality, integrity, availability, and regulatory compliance of 糖心Vlog官方\u2019s (糖心Vlog官方 or University) information assets. This policy pertains to all University information assets, whether the assets are individually or departmentally controlled; enterprise managed; stand-alone; and\/or stored via electronic, paper, or other media. The policy reflects 糖心Vlog官方\u2019s commitment to stewardship of sensitive personal information and critical business information, in acknowledgement of the many threats to information security and the importance of protecting the privacy of University constituents, safeguarding vital business information, and fulfilling legal obligations. It is 糖心Vlog官方\u2019s intent to protect the personal information of its students, staff, faculty, alumni, and other individuals associated with the University from unauthorized access or disclosure and possible misuse or abuse.<\/p>\n\n\n\n This policy establishes awareness and provides guidance on the proper handling of personally identifiable information (PII) including individual social security numbers (SSN) maintained by or on behalf of 糖心Vlog官方. 糖心Vlog官方 has implemented this policy to reduce the risk of exposure when PII is used as a primary identifier at the University and in other valid business applications and to ensure that all PII is handled consistently throughout the University. Personally identifiable information may not be captured, retained, communicated, transmitted, displayed, or printed, in whole or in part, except where required by law, and\/or in accordance with the standards outlined in this policy. For example, because 糖心Vlog官方 is a public institution, some PII may be subject to disclosure pursuant to the Tennessee Public Records Act, T.C.A. \u00a7 10-7-101 et seq. In addition, the University may disclose information to third parties, when such disclosure is required or permitted by law.<\/p>\n\n\n\n The information assets of the University, including the network, hardware, software, facilities, infrastructure, hard-copy documents and any other such assets must be available to support the teaching, learning, research, and administrative roles for which they are created. The University strives to employ appropriate physical and technical safeguards without creating unjustified obstacles to the conduct of the business and research of the University and the provision of services to its many constituencies in compliance with applicable state and federal laws. As a result, the University requires all employees to complete Information Security training annually to educate University employees on the safeguards and procedures available to protect the University\u2019s information assets.<\/p>\n\n\n\n This policy serves as a companion to Policy 910 Information Technology Resources<\/a>.<\/p>\n\n\n\n II. Policy Development and Maintenance<\/strong><\/p>\n\n\n\n This policy was drafted by the Information Security Task Force, and shall be reviewed by the Chief Information Security Officer (CISO) at least every three (3) years. Revisions shall be forwarded to the Vice President for Information Technology and CIO for further review.<\/p>\n\n\n\n III. Scope<\/strong><\/p>\n\n\n\n 糖心Vlog官方 maintains records to carry out its educational mission. Federal and state laws and regulations govern access to these records. This policy and related procedures are established to ensure compliance with these laws and regulations and to protect the integrity of University records and the privacy of individuals. This policy applies to all University students, faculty, staff, affiliates, third-party support contractors, and all others granted access to 糖心Vlog官方 information assets. The policy applies to the use of PII including SSN whether that information is maintained, used, or displayed, wholly or in part, and in any data format, including, but not limited to, oral or written words, screen display, electronic transmission (especially email), stored media, printed material, facsimile, or other medium as determined.<\/p>\n\n\n\n IV. Definitions<\/strong><\/p>\n\n\n\n V. Standards<\/strong><\/p>\n\n\n\n VI.<\/strong> Procedure<\/strong><\/p>\n\n\n\n Individual business units are responsible for the development, documentation, and implementation of applicable procedures to effectuate this policy. The departmental chair\/director or designee is responsible for informing new departmental personnel regarding the 糖心Vlog官方 Information Security policy. Procedures are subject to review by ITD Information Security Services.<\/p>\n\n\n\n VII. Incident Reporting and Response<\/strong><\/p>\n\n\n\n Any member of the University who has knowledge of any evidence of PII being compromised or who detects any suspicious activity that could potentially expose, corrupt, or destroy PII must report such information to the departmental chair\/director or designee. They will, in turn, report the information to his\/her supervisor, ITD Information Security Services, University Counsel, and the appropriate Vice President.<\/p>\n\n\n\n VIII. Non-Compliance<\/strong><\/p>\n\n\n\n Violation of this policy may result in one or more actions, including, but not limited to:<\/p>\n\n\n\n IX. Approved Uses of SSN<\/strong><\/p>\n\n\n\n University offices may not collect SSNs for purposes other than those noted in Section V. Standards.<\/p>\n\n\n\n The primary uses and reasons for the continued capture, storage, retention, and processing of SSN data are identified and documented in the\u00a0Approved Uses of SSNs and Other Personally Identifiable Information<\/a>\u00a0form. Typically, processes that access historical SSN data, or require or permit continued use of SSN data, are described here. Additional processes may be added by contacting ITD Information Security Services.<\/p>\n\n\n\n Forms: <\/p>\n\n\n\n Checklist for Usage of PII<\/a><\/p>\n\n\n\n
Effective Date: June 5, 2017
Responsible Division: Information Technology
Responsible Office: Information Technology
Responsible Officer: <\/strong>Vice President for Information Technology<\/strong><\/p>\n\n\n\n\n
\n
\n
\n