Purpose
The purpose of this Policy is to establish Information Security standards for the situational awareness processes relevant to University Information Technology Resources.
Scope and Applicability
This Policy applies to all University Information Systems and Information Technology Resources. All Users are responsible for adhering to this Policy.
Policy Statement Information System Stewards or their designee must adhere to this Policy when managing University Information Technology Resources by monitoring threats that may impact University Information Systems and Information.
Information sharing forums and sources must be used to receive and respond to cyber threat intelligence and communicate to stakeholders.
Exceptions Exceptions to this policy should be submitted to Information Security for review and approval. If an exception is requested a compensating control or safeguard should be documented and approved.
Enforcement
Any Employee, Contractor, or third-party performing duties on behalf of the University with knowledge of an alleged violation of this Policy shall notify Information Security as soon as practicable.
Any Employee, Contractor, or other third-party performing duties on behalf of the University who violates this Policy may be denied access to Information Resources and may be subject to disciplinary action, up to and including termination of employment or contract or pursuit of legal action.
Standards Referenced
Most recent versions:
USM IT Security Standards
NIST SP 800-171 “Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations”