Policy Category | Policy No. & Title | Policy Owner | Effective Date | Revision Number | Revision Eff. Date | Review Cycle |
X Information Governance, Security & Technology | X-1.22 System and Information Integrity | VP of Information Security | August 1, 2021 | N/A | N/A | Annually |
Purpose
The purpose of this policy is to establish information security standards for the System and Information Integrity processes relevant to University of Maryland Global Campus ("UMGC" or "University") Information Technology Resources.
Scope and Applicability
This policy applies to all University Information Systems and Information Technology Resources. All Information System Stewards and their designees are responsible for adhering to this policy.
Definitions
Capitalized terms shall have the meaning ascribed to them herein and shall have the same meaning when used in the singular or plural form or any appropriate tense.
Authorized User: A User who has been granted authorization to access electronic Information Resources and is current in their privileges.
Contractor: A person or a company that undertakes a contract to provide materials or labor to perform a service.
Data: Element(s) of Information in the form of facts, such as numbers, words, names, or descriptions of things from which "understandable information" can be derived.
Employee: University staff and faculty, including nonexempt, exempt, and overseas staff and collegiate faculty.
Information System: Inter-related components of Information Technology Resources working together for the collection, processing, maintenance, use, sharing, dissemination, or disposition of information.
Information System Steward: A UMGC staff member or other individual providing services to the University who is responsible for the development, procurement, compliance, and/or final disposition of an Information System.
Information Technology Resource: Any equipment or interconnected system or subsystem of equipment that is used in the automatic acquisition, storage, manipulation, management, movement, control, display, switching, interchange, transmission, or reception of data or information by UMGC directly or by a third party under a contract with UMGC which requires the use of such equipment. The term includes computers, mobile devices, software, firmware, services (including support services), and UMGC's network via a physical or wireless connection, regardless of the ownership of the Information Technology Resource connected to the network.
Integrity: Ensuring records and the Information contained therein are accurate and Authentic by guarding against improper modification or destruction.
User: A University community member, including but not limited to, staff, faculty, students, alumni, and individuals working on behalf of the University, including third party vendors, Contractors, consultants, volunteers, and other individuals who may have a need to access, use or control University Data.
System and Information Integrity
Information System Stewards or their designee must adhere to the University's System and Information Integrity Policy to ensure that University Information Systems are updated with security patches to prevent malware infections, to ensure that anti-malware software is deployed, and that e-mail systems are monitored and protected to detect malicious activity.
Information System flaws must be identified, reported, and corrected in a timely manner. The University must have a process to review relevant vendor announcements regarding weaknesses, vulnerabilities, and/or flaws. After reviewing the information, the Information System Stewards must execute a process called patch management that allows for systems to be updated without adversely affecting the organization.
Protection from malicious code (e.g. malware) must be provided at appropriate locations within University Information Systems. Malicious code is program code that purposefully creates an unauthorized function or process that will have a negative impact on the confidentiality, integrity, or availability of an information system. Malicious code may include viruses, spyware, and trojan horses.
Malicious code protection mechanisms must be updated when new releases are available.
Periodic scans of the Information System and real-time scans of files from external sources as files are downloaded, opened, or executed must be performed.
Information System security alerts and advisories must be monitored and where necessary acted upon.
University Information Systems, including inbound and outbound communications traffic, must be monitored to detect attacks and indicators of potential attacks.
Unauthorized use of University Information Systems must be identified. Information System Stewards can monitor systems by observing audit activities such as intrusion detection systems, intrusion prevention systems, and malicious code protection software.
Spam protection mechanisms must be employed at Information System access entry and exit points.
Email forgery protections must be implemented to prevent compromised accounts through attacks such as phishing and spam.
Sandboxing must be utilized to detect or block potentially malicious email.
Exceptions
Exceptions to this policy should be submitted to the VP of Information Security for review and approval. If an exception is requested a compensating control or safeguard should be documented and approved.
Enforcement
Any Employee, Contractor, or third-party performing duties on behalf of the University with knowledge of an alleged violation of this Policy shall notify the VP of Information Security as soon as practicable.
Any Employee, Contractor, or other third-party performing duties on behalf of the University who violates this Policy may be denied access to Information Resources and may be subject to disciplinary action, up to and including termination of employment or contract or pursuit of legal action.
Related Policies
Audit and Accountability Policy
Configuration Management Policy
Identity and Access Management Policy
Information Security Awareness and Training Policy
Information Security Incident Management Policy
Information Security Policy
Maintenance Policy
Media Protection Policy
System and Communication Protection Policy
Effective Date
This policy is effective as of the date set forth above.