Information Security Policy
The Goldey-Beacom College (GBC) Information Security Policy is designed to protect all information resources (as defined below) essential to performing the College business. These are College assets over which the College has both rights and obligations to provide reasonable physical, administrative, and technical safeguards that:
- ensure the security and confidentiality of this information,
- protect against threats to the security and/or integrity of such records
- protect against unauthorized access to or use of the data that could result in substantial harm or inconvenience to any constituent,
- ensure compliance with state and federal law and regulations regarding information security,
- ensure that the use of the College computing resources meets the highest ethical standards.
The Executive Vice President and the Dean of Information Technology are the designated GBC compliance officers for Goldey-Beacom College with regards to this policy.
A. Information Resources – Definition
For the purpose of this policy, information resources refers to:
- All Goldey-Beacom College owned computer hardware, software, communications equipment, networking equipment, networking and telecommunications protocols, associated storage, and peripherals.
- All computer hardware, software, communications equipment, networking equipment, associated storage and peripherals that are connected to any Goldey-Beacom College information resource.
- All computer hardware, software, communications equipment, networking equipment, associated storage and peripherals that store or transmit information that belongs to Goldey-Beacom College.
- All College-related data, information and intellectual property that may be transmitted over or stored on any Goldey-Beacom College information resource or a personally owned resource connected to the College network.
- All College-related data, information, intellectual property, and security and/or audit records stored, maintained, or transmitted by third-party services and vendors, who are authorized and approved by the College to store and manage this data.
- Any paper reports, microfilm, microfiche, books, films or any media containing information, data or intellectual property that is the property of Goldey-Beacom College.
B. Information Security - Definition
Information Security is the protection of information resources against unintended uses. This includes, but is not limited to, protection against:
- inappropriate release of data (advertently or inadvertently),
- access of the College’s data without the permission of Goldey-Beacom College,
- illegal or unethical use of Goldey-Beacom College’s data, computing or network resources,
- disruption of computing and network resources at Goldey-Beacom College or by resources of Goldey-Beacom College,
- violations of intellectual property rights of Goldey-Beacom College and members of the Goldey-Beacom community,
- violations of intellectual property rights by members of the Goldey-Beacom community,
- other activities that interfere with the education, research, or service mission of the College.
This policy applies to all Goldey-Beacom students, faculty and staff. This policy also applies to anyone who has access to, or uses any Goldey-Beacom College information resources. Contractors performing work for Goldey-Beacom College that involves any information resources must also meet the requirements of this policy.
This policy is meant to be consistent with all other College policies. In the event that state or federal law, regulation or local policy imposes more specific or more stringent requirements than are required by this policy, the law, regulation or policy shall take precedence.
College employees/contractors are granted access to those information resources required to carry out the responsibilities of their position. It is prohibited for any College employee/contractor to knowingly damage or misuse computing resources or data.
Access capabilities/restrictions apply to all information resources as defined above. Safeguards are taken to ensure the security of the resources and to maximize the integrity of the information.
Access privileges are determined based on the duties and responsibilities of each position. Users with access privileges are assigned an access username. Use of another person’s access username is prohibited.
Users are individuals who access and use College electronic information resources. Without exception, all members of the College community are "users" of Goldey-Beacom's information resources. Users must:
- become knowledgeable about relevant security requirements and guidelines,
- protect the information resources they have access to or control, such as access passwords, computers, and data,
- adhere to all College information security policies and procedures,
- use Goldey-Beacom information resources in an ethical manner consistent with the College’s mission.
The Dean of Information Technology, with the advice and consent of the Executive Vice President, shall publish and enforce guidelines for users relating to physical security, logical security, passwords, software and patches, data backup, viruses, remote access and other topics critical to the information security posture of Goldey-Beacom College.
F. Information Classification
Data and information that are owned by Goldey-Beacom College must be protected to ensure the rights of Goldey-Beacom College, its students, faculty and staff are safeguarded. These safeguards are required, in some cases, by law, in some cases by College policy, and in some cases by high ethical standards.
This Policy applies to all College information resources, including those used by the College under license or contract. "Information resources” include information in any form and recorded on any media, and all computer and communications equipment and software.
All information covered by this Policy is assigned one of three classifications depending on the level of security required. In decreasing order of sensitivity, these classifications are Confidential, Internal use only, and Unrestricted. Information that is either Confidential or Internal Use Only is also considered to be restricted.
This classification covers sensitive information about individuals, including information identified in the Staff Personnel Policy Manual and Faculty Policy and Resource Manual, and sensitive information about the College. Information receiving this classification requires a high level of protection against unauthorized disclosure, modification, destruction, and use. This information must not be downloaded, copied, or transmitted to any information resource which is not controlled/secured by the College. Specific categories of confidential information include information about:
- Current and former students whose education records are protected under the Family Educational Rights and Privacy Act (FERPA) of 1974, including student academic, disciplinary, and financial records; and prospective students, including information submitted by student applicants to the College.
- Current, former, and prospective students’ personal health information regulated by Health Insurance Portability and Accountability Act (HIPAA).
- Donors and potential donors.
- Current, former, and prospective employees, including employment, pay, benefits data, personal health information regulated by HIPAA, and other personnel information.
- Certain College business operations, finances, legal matters, or other operations of a particularly sensitive nature.
- Information security data, including but not limited to passwords, access codes, and encryption keys.
- Information about security-related incidents.
Internal Use Only
This classification covers information that requires protection against unauthorized disclosure, modification, destruction, and use, but the sensitivity of the information is less than that for confidential information. Examples of Internal Use Only information are internal memos, correspondence, and other documents whose access/distribution is limited as intended by the employee’s position.
This classification covers information that can be disclosed to any person inside or outside the College. Although security mechanisms are not needed to control disclosure and dissemination, they are still required to protect against unauthorized modification and destruction of information.
Information that is not classified explicitly is classified by default as follows: Information falling into one of the Confidentiality categories listed above is treated as Confidential. Other information is treated as Internal Use Only unless it is published (publicly displayed in any medium), in which case it is classified as Unrestricted.
G. Policy Violations
It is a violation of this policy to:
- Interfere with the normal operation of any Goldey-Beacom College information resource.
- Use Goldey-Beacom College information resources to interfere with the normal operation of information resources outside of Goldey-Beacom College.
- Use Goldey-Beacom College information resources to:
- Violate local, state, federal or international law.
- Cause, encourage or facilitate others in violating local, state, federal or international law.
- Access or cause another to access any information resource without permission of the Dean of Information Technology. The Dean will maintain a consistent, documented process for granting access to information resources. Permission is given generally to access publicly accessible webpages.
- Access or cause another to access intellectual property, copyright protected property or other legally protected property without permission from the property’s owner.
- Release information resources without the approval of the appropriate office of Goldey-Beacom College.
- Use any information resource to violate any policy of Goldey-Beacom College.
- Use any information resource to violate the security policy, acceptable use policy or other operational policies of organizations or institutions outside of Goldey-Beacom College.
- To promulgate software, data files or other materials that can be reasonably considered as viruses, Trojans or other “malware.”
- To use information resources to take part in, encourage or foster the development, exploitation or use of software, data files or other materials that can be reasonably considered viruses, Trojans or other ”malware.”
- Scan any information resource of Goldey-Beacom College without written approval of the Dean of Information Technology.
- Capture or monitor network transmissions, telecommunications transmissions, or any information resources without written approval of the Dean of Information Technology or, in the case of data, written permission of the appropriate College office.
- Share usernames, passwords, encryption keys, identity cards or other means of access to information resources. Exceptions to this may be requested of the Dean of Information Technology but will not generally be granted unless significant resource or operational inefficiency would occur by not granting an exception.
- Connect or disconnect any device to an information resource without written permission of the Dean of Information Technology. General exceptions are given to Information Technology staff who, as part of their normally assigned duties, continually connect and disconnect equipment from information resources. In addition, a general exception is given to connect storage devices to Goldey-Beacom College information resources if:
- The person connecting the device is authorized to use the information resource they are connecting to,
- The device does not interfere with the normal operation of information resource,
- Connecting this device does not otherwise violate this policy.
- Install or connect to any Goldey-Beacom College information resource any telecommunications equipment or networking equipment without the written permission of the Dean of Information Technology. General exceptions are given to Information Technology staff who, as part of their normally assigned duties, install or connect telecommunications and networking equipment.
H. Rights Reserved to Goldey-Beacom College
Goldey-Beacom College reserves the rights to:
- Examine or monitor any information resource including, but not limited to, equipment,
software, computer files, information and data. It is not the policy of the College
to routinely examine or monitor these resources. However, the College may choose to
do so at any time. The following is a list of situations where the College may invoke
this right. This is not intended as an exhaustive list.
- It is required by legal authority.
- The information resource in question may be in violation of this or other policies of the College.
- The Dean of Information Technology with the coordination, advice and consent of the Executive Vice President deems it necessary for the efficient and effective operation of the College’s information resources.
- The Dean of Information Technology is directed to do so by the College President.
- It is required for Information Technology staff to perform repair or normal operation and maintenance activity.
- Reasons determined by a member of the Executive Council of the College.
- Remove or block access to any information resource at any time on Goldey-Beacom College or elsewhere should the resource:
- Be in violation of this or any other policies of the College.
- Interfere with the operation of information resources at Goldey-Beacom College or elsewhere.
- Be in violation of state or federal law or regulation.
- For other reasons as determined and approved by Executive Vice President or President.
- Prohibit or inhibit any information resource that the Dean of Information Technology with the advice of Executive Vice President determines is:
- In violation of this or any policy of the College.
- Interfering with the operation of information resources at Goldey-Beacom College or elsewhere.
- In violation of state or federal law.
- Not in keeping with the high ethical standards of Goldey-Beacom College.
- Report to local, state or federal authorities’ information resource related activities that appear to violate the law or regulation.
I. Reporting ViolationsAll members of the Goldey-Beacom College community will report violations or suspected violations of this policy to the Dean of Information Technology at the following e-mail address: email@example.com. Alternatively, violations or suspected violations may be reported to the Executive Vice President. Information Technology staff, who become aware of a potential or suspected violation of this policy through the normal course of their work, are required to inform the Dean of Information Technology of the event. The Dean of Information Technology with the advice and consent of the Executive Vice President may, if appropriate, report violations of this policy to law enforcement.
J. Policy Sanctions
Anyone found to have violated this policy will be sanctioned using the processes found in existing Goldey-Beacom College policy and employment contracts where applicable.
K. Review Cycle
This policy will be reviewed and updated as needed, at least annually, based on the recommendations of the Office of Information Technology and the Executive Vice President.