Data Security Policy

Purpose

To provide ƽÌØÎå²»ÖÐ College with guidance in developing and implementing the appropriate protective safeguards to ensure the confidentiality, integrity, and availability of ƽÌØÎå²»ÖÐ College assets and information.

Policy

ƽÌØÎå²»ÖÐ College’s information, data, and records are managed in a manner consistent with ƽÌØÎå²»ÖÐ College’s risk strategy to protect the confidentiality, integrity, and availability of the assets. Data security controls are submitted to ƽÌØÎå²»ÖÐ College senior leadership for review and approval, and include a cost-benefit analysis to inform the executive staff in their risk strategy decisions.

Summary

  • Data security controls are submitted to ƽÌØÎå²»ÖÐ College senior leadership for review and approval
  • Data security controls will include a cost-benefit analysis to inform the executive staff in their risk strategy decisions
  • ƽÌØÎå²»ÖÐ College employs cryptographic controls in accordance with applicable Federal and State laws, regulations and standards
  • ƽÌØÎå²»ÖÐ College system that requires protection includes but is not limited to configuration settings, intrusion detection and prevention, various logs and password databases
  • ƽÌØÎå²»ÖÐ College protects the confidentiality and integrity of sensitive data by using cryptographic mechanisms
  • ƽÌØÎå²»ÖÐ College applies full disk encryption to all ƽÌØÎå²»ÖÐ College-owned laptops, mobile devices and desktop workstations
  • Backups are encrypted (at rest)
  • ƽÌØÎå²»ÖÐ College recommends that students enable full disk encryption on their personal devices
  • All transportable media is also encrypted
  • Papers containing confidential information must not be left out in public view and must be properly destroyed when no longer needed
  • ƽÌØÎå²»ÖÐ College hardware and software assets are documented, tracked, and managed through inventory management
  • Faculty and staff status is tracked and managed by Human Resources and the Dean of the College
  • Student documentation is managed by Admissions, Registrar’s Office, the Dean of Students and the Advancement Office depending upon student status
  • Prior to disposal, sanitization techniques are applied to media
  • ƽÌØÎå²»ÖÐ College ensures that there is adequate capacity to provide availability of its systems
  • ƽÌØÎå²»ÖÐ College employs reasonable and appropriate methods for data loss prevention

Data Security Policy Details [pdf]