UTS 165 – General Security Standards

Table of Contents:


 

The UTS 165 General Security Standards are applicable to all University of Texas System Administration and University of Texas (UT) Institutional employees, users, third party service providers, research partners, and other authorized users of UT System information resources, information systems, assets, and data as contractually obligated and / or defined by UT System. All users who work within IT facilities at UT System, including authorized vendors, visitors, or contingent workers, must adhere to this Standard when utilizing UT System information resources unless otherwise contractually documented and agreed.

All Requirements contained in this Standard serve as the minimum-security baseline that must be implemented by UT Institutions. In addition, UT Institutions must also consider additional requirements above the baseline level that should be implemented based on the unique risks, capacity, or other regulatory requirements that warrant the adoption of a higher control set. 

UT Institutions should also take into consideration any additional policies, standards, procedures, guidelines, and / or handbooks that expand upon the requirements within this Standard and prescribe Institution-specific mechanisms for implementing and complying with these requirements. UT Institutions may develop more stringent requirements but must not develop any requirements that are below the minimum threshold of this Standard.

Refer to the UTS 165 Definitions for the italicized definitions of defined terms used in this Standard.


 

165.1.1 Information Security Governance Standard

Purpose

The Purpose of this Standard is to establish the requirements for Information Security Governance to support the University of Texas System Administration and UT Institutions in achieving its mission, objectives, and applicable external and internal compliance obligations. This Standard is supported by the UTS 165.1 Information Security Organization, Personnel, & Privacy Policy objectives which are located within the UTS 165 Policy Library.

Conformance

Conformance to this Standard is mandatory unless otherwise contractually documented between the UT Institution and relevant party, or an exception is agreed to as outlined below. All requirements in this Standard are effective as of the publication of the Standard and the required timing for conformance is immediate, unless otherwise indicated.

In limited circumstances where a requirement in this Standard cannot be met and there is no feasible remediation, refer to the UTS 165.1 Information Security Organization, Personnel, & Privacy Policy for guidance on exceptions.

Violations of UTS 165 may lead to disciplinary action, up to and including involuntary separation from employment.


Standard Requirements

Requirement Subsection 1: Information Security Program Strategy

Requirement 165.1.1.1.1:

Develop a comprehensive information security program strategy aligned with the UT Institution mission and regulatory requirements.

 

Requirement 165.1.1.1.2:

Maintain and continually improve the UT Institution information security program and framework.

 

Requirement 165.1.1.1.3:

Create a UT Institution Information Security Plan that documents the information security strategy and framework, outlining key elements of the program for recording and tracking purposes, and including key elements as required by the Texas Department of Information Resources (DIR).

 

Requirement 165.1.1.1.4:

Identify, align with, and keep current with the legal, statutory, regulatory, and contractual requirements relevant to the information security program by collaborating with departments relevant to the management of the various in-scope requirements.

 

Requirement 165.1.1.1.5:

Review and select all in-scope information security and privacy related controls as provided by UT System to develop a comprehensive, UT Institution-specific control set.

[Back to Table of Contents]


 

Requirement Subsection 2: Information Security Documentation

Requirement 165.1.1.2.1:

Develop, in collaboration with applicable cross-functional teams and Privacy Officers (PO), information security Policies, Standards, and Operating Procedures. Document all minimum required information security objectives, requirements, and processes that must be implemented by all UT Institutions and disseminate the requirements users.

 

Requirement 165.1.1.2.2:

Obtain, review, and approve of all information security documentation from necessary management users including the UT System Administration Chief Information Security Officer (CISO), Institutional Information Security Officers (ISO), and/or other Subject Matter Experts (SME), as applicable, at a minimum once every 36 calendar months or sooner as needed.

 

Requirement 165.1.1.2.3:

Modify or update information security documents on an as- needed, ongoing basis in the event of the following triggers:

  • Policy / control / risk changes,
  • Policy / Standard exception request,
  • Input from Subject Matter Experts (SME),
  • Multiple questions on interpretation,
  • Legislation changes,
  • Changes to NIST 800-53 or in-scope privacy frameworks and regulations, and
  • Changes to the organizational environment, technical environment, business circumstances, or legal conditions.

 

Requirement 165.1.1.2.4:

Implement and maintain a process for recording, assessing, approving, and tracking non-compliance situations with information security documentation, due to exceptions or any other reason, including assessing the risk of the non-compliance to determine how to address any gaps.

[Back to Table of Contents]


 

Requirement Subsection 3: Information Security & Privacy Roles

Requirement 165.1.1.3.1

Appoint a UT System Administration Chief Information Security Officer (CISO) and Institutional Information Security Officers (ISO) with the mission and resources to coordinate, develop, implement, and maintain the systemwide and Institution-specific information security programs.

[Back to Table of Contents]


 

Requirement Subsection 4: Information Security Program Capital Planning, Reporting, & Milestones

Requirement 165.1.1.4.1:

Include the resources needed to implement the information security and privacy programs in capital planning and investment requests and prepare documentation as needed for addressing information security and privacy programs in capital planning and investment requests in accordance with applicable laws, executive orders, directives, policies, regulations, and standards.

 

Requirement 165.1.1.4.2:

Implement a process to develop, maintain, document, and track plans of actions and milestones related to the information security program to measure and report the effectiveness of the program goals and mission in alignment with the defined strategy and framework.

 

Requirement 165.1.1.4.3:

Report to the Agency Head at least once every 12 calendar months on the adequacy and effectiveness of the information security program.

[Back to Table of Contents]


 

Requirement Subsection 5: Information Security System Inventory & Architecture

Requirement 165.1.1.5.1:

Develop, maintain, and update an inventory of information systems at least once every 24 calendar months.

 

Requirement 165.1.1.5.2:

Develop and maintain UT Institution-specific architectures with consideration for information security, privacy, and the resulting risk to UT Institution operations and assets, individuals, other organizations, and the Nation.

[Back to Table of Contents]


 

Requirement Subsection 6: Security & Privacy Groups & Associations, Reports, & Restrictions

Requirement 165.1.1.6.1:

Identify and document relevant special interest groups or other specialist security forums, including the UT Information Security annual conference, and their contact information that should be contacted in order to:

  • facilitate ongoing security and privacy education and training for organizational users,
  • maintain currency with recommended security and privacy practices, techniques, and technologies, and
  • share relevant in-scope security and privacy information.
     

Review the list of special interest groups and their contact information at least once every 12 calendar months to ensure their contact information is up to date and make any updates as needed to maintain adequate correspondence and information sharing.

Contact relevant special interest groups periodically, as determined and documented by the Institutions, to communicate, collaborate, and share relevant insights with one another.

 

Requirement 165.1.1.6.2:

Define and implement processes to collect UT Institution threat intelligence information from applicable sources. Processes must include how information is received and the frequency with which it is obtained and processed.

 

Requirement 165.1.1.6.3:

Collaborate with Privacy Officers (PO) to define, implement, and review UT Institution-specific procedures regarding the usage of Personally Identifiable Information (PII) at least once every 12 calendar months.

 

Requirement 165.1.1.6.4:

Collaborate with Privacy Officers (PO) to develop privacy reports at least once every 12 calendar months, or sooner as requested.

 

Requirement 165.1.1.6.5:

Collaborate with applicable information security and privacy teams as identified by the UT Institutions to determine, document, and allocate the resources required to protect the Institutions as part of the information security and privacy program.


[Back to Table of Contents]


 

165.1.2 Cybersecurity Risk Management Standard

Standard Requirements Subsection 1: Assessment & Continuous Monitoring Strategy

 

Requirement 165.1.2.1.1:

Develop and implement a UT Institution-specific process for the variety of assessments to be performed (e.g., risk assessments, maturity, and / or control compliance), including a continuous monitoring strategy and framework.

[Back to Table of Contents]


 

Standard Requirements Subsection 2: Control Compliance Assessments

Requirement 165.1.2.2.1:

Conduct control compliance assessments at least once every 12 calendar months or sooner as required by UT Institutions.

 

Requirement 165.1.2.2.2:

An assessment of UT Institution's information security program for compliance with Texas Administrative Code chapter 202 subchapter C (TAC202) must be reported by the Institutional

Information Security Officer (ISO) directly to the state Agency Head once every 12 calendar months.

 

Requirement 165.1.2.2.3:

Perform and submit an information security assessment of each UT Institution of higher education for compliance with the requirements of Texas Government Code §2054.515 and Texas Administrative Code chapter 202 subchapter C (TAC202) at least once every 24 calendar months.

 

Requirement 165.1.2.2.4:

Engage with individual(s) independent of the information security program and designated by the state Agency Head or their designated representative(s) to perform compliance reviews of the UT Institution’s information security program at least once every 24 calendar months using a risk-based approach.

[Back to Table of Contents]


 

Standard Requirements Subsection 3: Risk Assessments

Requirement 165.1.2.3.1:

Conduct risk assessments at least once every 12 calendar months or sooner as required by the UT Institutions that include the following:

  • identification of threats to and vulnerabilities in the system,
  • identification of supply chain risk,
  • determination of the likelihood and impact of harm from unauthorized access, use, disclosure, disruption, modification, or destruction of the system, the data it processes, stores, or transmits, and any related information, and
  • determination of the likelihood and impact of adverse effects on individuals arising from the processing of Personally Identifiable Information (PII).

Document risk assessment results in a risk assessment report and security and privacy plans. Risks and impacts must be ranked, at a minimum, as either "High," "Moderate," or "Low."

Approval of information security risk acceptance, transference, or mitigation decisions shall be the responsibility of the Institutional Information Security Officer (ISO) for all systems with an identified High residual risk.

Institutional Information Resource Owners (IRO) are responsible for defining, approving, and documenting acceptable risk levels and mitigation strategies for their systems and data when required by the Institutional Information Security Officer (ISO).

Note: This requirement and the performance of risk assessments can only be performed following establishment and implementation of an Institution-defined risk assessment process.

 

Requirement 165.1.2.3.2:

UT Institutions that view, store, process, or transmit electronic Protected Health Information (ePHI) must conduct an accurate and thorough assessment of the potential risks and vulnerabilities to the confidentiality, integrity, and availability of ePHI.

Institutions that provide financial products or services, such as loans, must conduct a risk assessment that includes categorization of identified security risks or threats, assessment of the confidentiality, integrity, and availability of information systems and customer data, including the adequacy of the existing controls in the context of the identified risks or threats, and how identified risks will be mitigated or accepted based on the risk assessment and how the information security program will address the risks.

Note: This risk assessment activity may be covered / encompassed as part of broader Institution risk assessments and related activities.

 

Requirement 165.1.2.3.3:

Conduct a risk assessment prior to the acquisition or outsourcing of information services that processes, stores, or transmits Confidential or Controlled data and verify that the acquisition or outsourcing of dedicated information security services is approved by the appropriate Compliance and / or Privacy Officers (PO), Office of the General Counsel (OGC), and other UT Institution information security stakeholders as necessary.

UT Institutions contracting for cloud computing services that store, process, or transmit data of the Institution of higher education must:

  • confirm that vendors contracting with the Institution to provide cloud computing services for the Institution are certified through the Texas Risk and Authorization Management Program (TXRAMP), if applicable, prior to entering or renewing a cloud computing services contract on or after January 1, 2022; and
  • require a vendor contracting with the UT Institution to provide cloud computing services for the Institution that are subject to the state risk and authorization management program to maintain program compliance and certification throughout the term of the contract.

Risk assessments for systems, components, or services that contain published data may be conducted at the discretion of the Institutional ISO.

 

Requirement 165.1.2.3.4:

Develop a plan of action and milestones for UT Institutions to document the planned remediation actions to correct weaknesses or deficiencies noted during assessments and to reduce or eliminate known vulnerabilities in the information systems.

 

Requirement 165.1.2.3.5:

Work collaboratively with security, Information Technology (IT), and privacy teams to respond to findings from security and privacy related assessments, monitoring, and audits in accordance with UT Institution defined risk tolerance levels.

[Back to Table of Contents]


 

Standard Requirements Subsection 4: Vendor Risk Management

Requirement 165.1.2.4.1:

Collaborate with procurement and / or Privacy Officers (PO) to develop and implement standard vendor contract language regarding information security responsibilities and requirements, and data privacy matters, including the following at a minimum:

  • Roles and responsibilities of both parties regarding information security management, protection of UT Institution data, incident reporting and response,
  • Minimum security controls that must be in place,
  • Specific requirements for the secure handling, storage, return, deletion, or disposal of Institution data upon and after contract termination,
  • Processes to follow in the event of a security incident or data breach,
  • Compliance with relevant security standards, frameworks, and certifications,
  • Compliance with statutes pertaining to foreign-based vendors connected to critical infrastructure services, software, or components; and
  • Ability to audit / monitor vendor compliance with security controls and contractual requirements.

 

Requirement 165.1.2.4.2:

Develop a plan for managing vendor risks, weaknesses, or deficiencies associated with the research and development, design, manufacturing, acquisition, delivery, integration, operations and maintenance, and disposal of systems, system components or system services.

 

Requirement 165.1.2.4.3:

Monitor using a risk-based approach at least once every 12 calendar months vendor information security and privacy

controls in alignment with terms and conditions as established by the UT Institution to ensure compliance and adequate protections remain in place.

Address or mitigate any vendor issues or service, practice, or product changes identified as a result of monitoring in collaboration with Privacy Officers (PO) and other applicable teams.

[Back to Table of Contents]


 

165.1.3  Personnel & Third-Party Security Standard

Requirement Subsection 1: Vendor Job Responsibilities & Rules of Behavior

Requirement 165.1.3.1.1:

Evaluate, define, and implement terms and conditions for any trust relationships with vendors and other organizations owning, operating, and / or maintaining external information systems that are allowed to:

  • access UT Institution information systems from external information systems, and / or
  • process, store, or transmit UT Institution data.

Vendors and other organizations must maintain adequate information security and privacy controls to ensure the appropriate use and protection of UT Institution information resources and assets following the requirements provided in all Policy and Standard documents.

 

Requirement 165.1.3.1.2:

Define and document access agreements for UT Institution information systems and review and update the access agreements at least once every 12 calendar months.

Require that users needing access to UT Institution information systems sign appropriate access agreements prior to being granted access and re-sign access agreements to maintain access when access agreements have been updated or when changes to individual job responsibilities, access requirements, or information system status occur.

 

Requirement 165.1.3.1.3:

Define and document user security requirements and procedures specific to the UT Institution, including security roles and responsibilities for vendors, and ensure compliance with all defined requirements by UT Institution vendors and users.

At a minimum, include the following requirements in documented procedures for vendors:

- require vendors to notify the Institution as soon as possible of any user transfers or separations of vendors who possess UT Institution credentials and / or badges.

 

Requirement 165.1.3.1.4:

Define procedures and establish agreements with vendors involved in the supply chain for the critical system, system component, or system service for the notification of supply chain compromises.

[Back to Table of Contents]


 

Requirement Subsection 2: Job Responsibilities & Rules of Behavior

Requirement 165.1.3.2.1:

Collaborate with Privacy Officers (PO) to establish and provide to users the rules that describe their responsibilities and expected behavior for information system and data usage, security, and privacy per the defined UT Institution roles and responsibilities of their job.

 

Requirement 165.1.3.2.2:

Include in the rules of behavior the UT Institution-specific key components.

 

Requirement 165.1.3.2.3:

Collaborate with Human Resources (HR), Privacy Officers (PO), and other relevant departments to document all organizational positions related to information security and privacy.

[Back to Table of Contents]


 

Requirement Subsection 3: Personnel Screening

Requirement 165.1.3.3.1:

Collaborate with Human Resources and other relevant departments to perform background checks or other required screening as part of the employee hiring process prior to authorizing access to any UT Institution information systems or data before user start date.

 

Requirement 165.1.3.3.2:

Verify in collaboration with Human Resources and other relevant departments that, prior to start date, users accessing an information system that processes, stores, or transmits UT Institution data have obtained cleared and / or satisfactory screenings as required prior to granting the user information system or data access.

[Back to Table of Contents]


 

Requirement Subsection 4: Employee Transfer

Requirement 165.1.3.4.1:

Review and confirm ongoing operational need for current logical and physical access authorizations to information systems, assets, and IT facilities when users are reassigned or transferred to other positions within the UT System and modify access authorization as needed to correspond with any changes in operational need due to reassignment or transfer. Notify users as necessary to update them on changes.

[Back to Table of Contents]


 

Requirement Subsection 5: Offboarding Separated Individuals

Requirement 165.1.3.5.1:

Schedule and conduct exit interviews, surveys, or questionnaires with to-be-separated users, as determined by the Institution, the employee's access / position type, and in collaboration with Human Resources (HR) and other relevant departments, within 7 calendar days of their last day of employment.

 

Requirement 165.1.3.5.2:

Collaborate with Human Resources (HR) and other relevant departments to define separation actions that must be implemented as soon as possible in advance of user separation from the UT System.

 

Requirement 165.1.3.5.3:

Use automated mechanisms to notify and terminate user access in advance of and on the last day of user employment as technically feasible by the UT Institutions.

[Back to Table of Contents]


 

Requirement Subsection 6: Disciplinary Actions

Requirement 165.1.3.6.1:

Collaborate with Human Resources (HR) and other relevant departments to employ the HR defined disciplinary measures for UT Institution vendors and users failing to comply with established information security and privacy Policies and Standards (UTS 165).

Notify the user disciplined and the user’s manager or equivalent, as requested / in collaboration with HR, within one business day when a formal employee disciplinary process is initiated, identifying the user disciplined and the reason for the disciplinary action.

[Back to Table of Contents]


 

165.1.4  Awareness & Training Standard

 

Requirement Subsection 1: Literacy Training and Awareness

Requirement 165.1.4.1.1:

Provide security and privacy literacy training to UT System as part of initial onboarding training within 30 days of employment or engagement start date and at least once every 12 calendar months thereafter as prescribed by the Texas Department of Information Resources and Texas Government Code 2054.519.

 

Requirement 165.1.4.1.2:

Review and update security and privacy literacy training and awareness content at least once every 36 calendar months or sooner as required.

 

Requirement 165.1.4.1.3:

Create and administer security and privacy awareness activities to all UT System users at least once every 3 calendar months.

 

Requirement 165.1.4.1.4:

Include UT Institution defined key features in security and privacy training.

[Back to Table of Contents]


 

Requirement Subsection 2: Role-based Training

Requirement 165.1.4.2.1:

Create and administer role-based security training, leveraging a risk-based approach to identify roles that require a specific understanding of information security.

 

Requirement 165.1.4.2.2:

Include foundational privacy topics rooted in the Fair Information Practice Principles (FIPPs) and other privacy regulations, as part of annual required training for any individuals that handle confidential data, such as Protected Health Information (PHI).

[Back to Table of Contents]


 

Requirement Subsection 3: Training Records

Requirement 165.1.4.3.1:

Document and monitor information security and privacy training and awareness activities, including completion of security and privacy training and specific role-based security and privacy training, and retain individual training records in accordance with Institution-specific record retention requirements, but for no less than 24 calendar months.

Enforce compliance with required trainings within defined time periods using Institution-specific compliance enforcement techniques.

[Back to Table of Contents]


 

165.1.5  Information Data Protection & Privacy Standard

Standard Requirements Subsection 1: Data Flow Enforcement

Requirement 165.1.5.1.1:

Control the flow of data within UT Institution information systems and between interconnected systems using Institution- defined processes, addressing any data flow failures as necessary. The data flow control implemented must be commensurate with the classification of the data, whether it is confidential, controlled, or published data.

 

Requirement 165.1.5.1.2:

Perform reviews of data flow controls at least once every 12 calendar months to confirm the appropriate protections are in place to protect the flow of data within UT Institution information systems commensurate with the data classification.

 

Requirement 165.1.5.1.3:

Implement restrictions (e.g., filters) on data that is transferred between UT Institution information systems with different levels of security that is commensurate with the classification of the data being transferred.

 

Requirement 165.1.5.1.4:

Define and implement, in collaboration with the Data Management Officers (DMO) and Privacy Officers (PO), a UT Institution-specific process for the assignment of security and privacy attributes to data in storage, in process, and / or in transmission based on its classification. Processes must include identification, classification, tagging, and associated handling of the data.

 

Requirement 165.1.5.1.5:

Implement UT Institution-specific security controls or technical configurations to restrict the use of unapproved information systems or system components that process, store, or transmit UT Institution data.

[Back to Table of Contents]


 

Standard Requirements Subsection 2: Data Agreements, Notices, Publishing, & Consent 

Requirement 165.1.5.2.1:

Approve and manage the exchange of data between external information systems in collaboration with UT Institution Privacy Officers using appropriate agreements depending on the type of data or exchange.

Document, as part of each exchange agreement, the interface characteristics, security and privacy requirements, controls, and responsibilities for each information system, and the impact level of the data being communicated. Review and update the agreements at defined intervals as established by and in collaboration with UT Institution Privacy Officers (PO).

 

Requirement 165.1.5.2.2:

Designate individuals authorized to make data publicly accessible and provide training for the authorized individuals to ensure that published data does not contain confidential data.

Review the proposed content of data in collaboration with UT Institution Data Management Officers (DMO) prior to posting onto publicly accessible information systems to ensure that confidential and controlled data are not included. Review the content on the publicly accessible system at least once every 12 calendar months to confirm that only the appropriate, approved data is present.

 

Requirement 165.1.5.2.3:

Implement UT Institution-defined restrictions on data mining, excluding purchased data, in alignment with applicable privacy frameworks and internal requirements in collaboration with Privacy Officers (PO) and Data Management Officers (DMO), if necessary.

 

Requirement 165.1.5.2.4:

Obtain consent from all individuals for the processing of their confidential data or individual-identifying information prior to its collection and processing in accordance with relevant regulations.

 

Requirement 165.1.5.2.5:

Provide notice to individuals about the processing of their confidential data.

[Back to Table of Contents]


 

Standard Requirements Subsection 3: Handling of Confidential Data

Requirement 165.1.5.3.1:

Define and document rules for the handling and processing of confidential data by authorized UT Institution users, restricting or prohibiting the handling of confidential data by unauthorized users.

 

Requirement 165.1.5.3.2:

Implement and enforce minimum protections for UT Institution confidential data in alignment with in-scope privacy regulations and frameworks.

[Back to Table of Contents]


 

Standard Requirements Subsection 4: Transmission & Encryption Methods

Requirement 165.1.5.4.1:

Protect the processing of confidential data using encryption techniques and other protections or automated mechanisms as determined by the UT Institutions based on asset type, data type, and data sensitivity / classification. Encryption methods must be tailored to the specific use case, environment, and classification level of the data being protected.

At a minimum, confidential data must be encrypted when in transit to a vendor or other third party, including via email.

 

Requirement 165.1.5.4.2:

Exchange data over secure and approved connections when high levels of confidentiality or integrity are required. Protect the confidentiality and integrity of transmitted data by implementing technical security measures commensurate with the classification / sensitivity of the data being transmitted such as cryptographic mechanisms to prevent unauthorized disclosure.

 

Requirement 165.1.5.4.3:

Establish and manage cryptographic keys when cryptography is employed within the information system in accordance with UT Institution-defined management processes and protections.

 

Requirement 165.1.5.4.4:

Maintain the availability of data in the event of the loss of cryptographic keys by users using UT Institution-defined methods, such as backup processes or alternative encryption methods to prevent the loss of data availability.

 

Requirement 165.1.5.4.5:

Protect the confidentiality and integrity of data at rest across information systems using protections that are commensurate with the classification / sensitivity of the data as defined by the UT Institutions.

 

Requirement 165.1.5.4.6:

Limit the use of data used in artificial intelligence systems using protections that are commensurate with the classification / sensitivity of the data as defined by the UT Institutions.

Published data may be used freely in association with artificial intelligence systems. Controlled information must be limited to use in artificial intelligence systems where access is restricted to authorized personnel only. Confidential information must be limited to use in artificial intelligence systems with heightened security measures and documented approval from the Institutional Information Security Officer (ISO) or their designee.

[Back to Table of Contents]


 

Standard Requirements Subsection 5: Data Management & Retention

Requirement 165.1.5.5.1:

Collaborate with Data Management Officers (DMO), Record Management Officers (RMO), and other applicable departments to manage and retain UT Institution data within information systems in accordance with applicable laws, executive orders, directives, regulations, policies, standards, guidelines, and operational requirements.

 

Requirement 165.1.5.5.2:

Limit confidential data being processed in the information life cycle to only the elements of confidential data that are absolutely necessary as defined by UT Institutions.

 

Requirement 165.1.5.5.3:

Implement UT Institution-defined techniques to minimize the use of confidential data for research, testing, and training.

 

Requirement 165.1.5.5.4:

Define and implement a process in collaboration with Record Management Officers (RMO) and Data Management Officers (DMO) for the disposal, destruction, or erasure of data following retention periods as defined by the UT Institutions.

 

Requirement 165.1.5.5.5:

Correct or delete confidential data if applicable and after consultation with appropriate Privacy Officers (PO) or other appropriate departments upon request by individuals or their designated representatives. After approved correction or deletion has been performed, notify individuals of the update to their data.

 

Requirement 165.1.5.5.6:

Define and implement UT Institution-specific procedures for the appropriate protections and processes that must be in place as part of data collection and handling. At a minimum, the following must be performed in in collaboration with appropriate Privacy Officers (PO), Data Protection Officers (DPO), and other appropriate departments:

  • removal of certain elements of confidential data from datasets, and
  • evaluation that the de-identification of confidential data was successful and compliant.
     

Requirement 165.1.5.5.7:

Remove confidential data elements from a dataset in collaboration with Record Management Officers (RMO) and Data Management Officers (DMO) prior to its release if those elements in the dataset do not need to be part of the data release as technically feasible by the UT Institutions.

 

Requirement 165.1.5.5.8:

Remove, mask, encrypt, hash, or replace direct identifiers in a dataset as technically feasible by the UT Institutions.

 

Requirement 165.1.5.5.9:

Manipulate numerical data, contingency tables, and statistical findings so that no individual or organization is identifiable in the results of the analysis.
 

[Back to Table of Contents]


 

165.1.6  Acceptable Use Standard

Requirement Subsection 1: Mobile Device Management

Requirement 165.1.6.1.1:

Define and implement a mobile device management program for UT Institution provided mobile devices that store, process, or transmit UT Institution data. The program must establish usage restrictions, configuration / connection requirements, and implementation guidance and procedures.

 

Requirement 165.1.6.1.2:

Define and implement Bring Your Own Device (BYOD) security controls and parameters for personally owned devices that store, process, or transmit UT Institution data. These controls / parameters must be defined and documented at the Institution level.

The storage, processing, or transmission of Confidential or Controlled data is prohibited on non-institutionally managed or personally owned devices (BYOD) regardless of Institutional affiliation. Exceptions must be thoroughly documented and approved by both the Institutional Information Security Officer (ISO) and Executive Management (Dean or Vice President).

UT Institution data created or stored on a user’s personal computers, smart phones, or other devices, or in databases that are not part of UT Institution information resources, are subject to Public Information Requests, subpoenas, court orders, litigation holds, discovery requests and other requirements applicable to UT Institution information resources.

[Back to Table of Contents]


 

Requirement Subsection 2: User Endpoint Devices

Requirement 165.1.6.2.1:

Report lost or stolen UT Institution assets, including portable computing devices, electronic media, or any other device containing Institution data immediately to appropriate security users or group(s) as necessary, including but not limited to Compliance, and Privacy Officers (PO), and law enforcement.

Loss of a device determined to be unencrypted must be reported to UT System Administration within 7 calendar days (one week) of the onset or discovery of the incident.

 

Requirement 165.1.6.2.2:

Prohibit the use of any unapproved portable computing, transmitting or storage devices in IT facilities containing information systems processing, storing, or transmitting confidential data unless approved and documented by both the UT Institutional ISO and executive management.

If an unapproved portable computing device will be used in IT facilities containing confidential data in limited circumstances, implement the following protections, at a minimum:

  • connection of unapproved portable computing devices to classified systems is prohibited,
  • connection of unapproved portable computing devices to unclassified systems requires approval from necessary management users,
  • the use of internal or external modems or wireless interfaces within the unapproved portable computing device is prohibited, and
  • unapproved portable computing devices and the data stored on those devices are subject to random reviews and inspections.

 

Requirement 165.1.6.2.3:

Limit the use of portable and removable electronic media using a combination of technical safeguards as determined necessary by UT Institutions. At a minimum, electronic media devices must be:

  • protected from unauthorized access, and
  • physically secured when not in use or unattended.

 

Requirement 165.1.6.2.4:

Obtain documented approval from the Institutional Information Security Officer (ISO) or their designee for the storage of confidential data on portable or removable electronic media.

Personally procured or external portable and removable devices are prohibited from being used to store UT Institution confidential data without authorization and the appropriate encryption enabled as defined by the UT Institutions.

 

Requirement 165.1.6.2.5:

Invoke user screen locking mechanisms on UT Institution provided user devices, including electronic media and user portable computing devices, when left unattended both on UT Institutions premises and at external locations after a maximum of 15 minutes of inactivity.

 

Requirement 165.1.6.2.6:

Store electronic media, user portable computing devices, hardcopies of data, and removable electronic media in a secure manner if left unattended on UT Institution premises or at external locations in locked file cabinets, desks, safes, or other furniture when not being actively used to prevent unauthorized users from accessing or viewing the data.

 

Requirement 165.1.6.2.7:

Position display screens (e.g., personal device screens, projector screen-shares, etc.) when working in public locations so that UT Institution confidential or controlled data cannot be easily viewed by unauthorized persons, including data being displayed when in conference rooms or collaboration spaces.

Ensure any physical confidential or controlled data is erased / disposed of when no longer necessary (e.g., confidential data that is written on whiteboard in shared collaboration spaces is erased, paper where notes are recorded are shredded or disposed of accordingly, etc.).

[Back to Table of Contents]


 

Requirement Subsection 3: Management Information Security & Privacy Responsibilities

Requirement 165.1.6.3.1:

Include information security and privacy responsibilities in roles and responsibilities and performance objectives developed for users under management supervision. Communicate clear information security roles and responsibilities to these users.

 

Requirement 165.1.6.3.2:

Monitor completion of required information security and privacy training by users under management supervision and support users in ensuring information security training is completed on time.

 

Requirement 165.1.6.3.3:

Escalate any information security or privacy related issues identified within the work area or reported by users under management supervision per defined UT Institution processes.

[Back to Table of Contents]


 

Requirement Subsection 4: General Users Information Security & Privacy Responsibilities

Requirement 165.1.6.4.1:

Attest to the understanding of information security and privacy responsibilities applicable to user roles as a part of initial onboarding or transfer of position processes. Re-attest to the understanding of information security responsibilities at least once every 24 calendar months or sooner as required, in a method determined by UT Institutions, such as the Acceptable Use Policy (AUP), including but not limited to as a part of annual training or the password reset process.

 

Requirement 165.1.6.4.2:

Adhere to legal, statutory, regulatory, contractual, and privacy requirements as reflected in information security Policies, Standards and Procedures, and operationalized within UT Institutions.

 

Requirement 165.1.6.4.3:

Report any observed unusual or suspicious events to UT Institution-defined reporting channels immediately.

 

Requirement 165.1.6.4.4:

Use UT Institution information systems and assets for their intended business purpose to perform assigned job functions only, except in the case of incidental usage. Users are permitted to use Institution information systems and assets for incidental use within reason, with the exception of the following instances:

  • to conduct or promote user's outside employment, including self-employment,
  • to participate in political lobbying or campaigning, and
  • to view, access, store, or transmit sexually explicit materials.

Storage of any email messages, voice messages, files, or documents created as incidental use by a user must be nominal (less than 5% of a user's allocated mailbox space). Users must clearly convey that the contents of any email messages or social media posts that are the result of incidental use are not provided on behalf of the UT Institution and do not express the opinion or position of the UT Institution. Files not related to UT Institution business may not be stored on network file servers.

Any use of UT Institution information systems and assets that is illegal, violates Policies and Standard, or that could embarrass, offend, or harm the UT System or its employees, students, or affiliated users is prohibited. Additionally, the downloading and usage of prohibited software and hardware products on UT Institution information systems and assets per the DIR list of Prohibited Technologies or any other prohibited technologies as defined by the Institutions is strictly prohibited.

[Back to Table of Contents]


 

165.2.1  Access Management Standard

Purpose

The Purpose of this Standard is to establish the requirements for Access Management to support the University of Texas System (UTS) in achieving its mission, objectives, and applicable external and internal compliance obligations. This Standard is supported by the UTS 165.2 Information Security Technology Policy objectives which are located within the UTS 165 Policy Library.

 

Standard Requirements

Standard Requirements Subsection 1: Access Enforcement

Requirement 165.2.1.1.1:

Define and implement UT Institution-specific logical access controls for all applicable UT Institution information systems, system resources, networks, applications, and assets, including at a minimum:

  • discretionary access controls, and
  • role-based access controls.

 

Requirement 165.2.1.1.2:

Review access authorizations at least once every 12 calendar months or sooner using a UT Institution-defined risk-based approach and revoke or update access authorizations as necessary based on changes to access or business need.

 

Requirement 165.2.1.1.3:

Restrict access to data repositories containing confidential and controlled data to only those authorized to access the data and enforce additional access controls as determined necessary by the UT Institutions.
 

[Back to Table of Contents]


 

Standard Requirements Subsection 2: Account Management

Requirement 165.2.1.2.1:

Define and document UT Institution-specific processes and procedures for account management.

 

Requirement 165.2.1.2.2:

Disable user and service accounts immediately, as technically feasible, or within a UT Institution-defined time period.

 

Requirement 165.2.1.2.3:

Institutional Information Security Officers (ISO) and Information Resource Managers (IRM) must collaborate to define UT Institution-specific session lock requirements using a risk-based approach.

 

Requirement 165.2.1.2.4:

Define and implement a process for the administration, management, and maintenance of UT Institution privileged user and service accounts.

 

Requirement 165.2.1.2.5:

Define and implement UT Institution-specific requirements for the provisioning and creation of shared / group accounts.

 

Requirement 165.2.1.2.6:

Monitor the activity of system user accounts, service accounts, shared / group accounts, and privileged user accounts on a regular basis as determined by the UT Institutions to detect anomalous behavior, escalating or reporting observations of anomalous account activity to Institution-defined users as soon as possible.

[Back to Table of Contents]


 

Standard Requirements Subsection 3: Authenticator Management

Requirement 165.2.1.3.1:

Institutions must develop, document, and implement processes and procedures for managing information system authenticators including specific processes for mass resets of authenticator passwords when necessary.

 

Requirement 165.2.1.3.2:

Define and implement UT Institution-specific password management processes and procedures depending on account type and using a risk-based approach.

Institutional Information Security Officers (ISO) may implement stricter complexity requirements or additional methods of authentication, such as public key cryptography, based on risk.

Institutional ISO’s may provide exemptions for legacy systems that cannot meet the minimum password complexity requirements.

 

Requirement 165.2.1.3.3:

Limit feedback of authentication information during the authentication process to protect the information from possible exploitation or use by unauthorized individuals.

 

Requirement: 165:2.1.3.4:

Implement UT Institution-defined authentication requirements for accessing cryptographic modules that are commensurate with the sensitivity of the modules being accessed. Ensure only authorized roles or users can access cryptographic modules.

 

Requirement 165.2.1.3.5:

Document and maintain a list of all allowed UT Institution external authenticators.

[Back to Table of Contents]


 

Standard Requirements Subsection 4: Collaborative Devices & Device Lock

Requirement 165.2.1.4.1:

Prohibit remote activation of collaborative computing devices such as smart displays, interactive whiteboards, etc. by non-UT Institution users and provide indication of devices in use to users present at the device.

 

Requirement 165.2.1.4.2:

Implement device lock where session activity can be determined to prevent further access to the information system after a UT Institution-defined period of inactivity. Retain the device lock until the user re-authenticates into the device.

[Back to Table of Contents]


 

Standard Requirements Subsection 5: Segregation of Duties & Least Privilege

Requirement 165.2.1.5.1:

Define and implement segregation of duties to the maximum extent possible within UT Institution information systems and review these duties at least once every 12 calendar months.

 

Requirement 165.2.1.5.2:

Employ and maintain the principle of least privilege for all UT Institution accounts, allowing only authorized access for users that is necessary to accomplish assigned tasks.

 

Requirement 165.2.1.5.3:

Configure the information system to prevent the execution of privileged functions by non-privileged users or accounts.

[Back to Table of Contents]


 

Standard Requirements Subsection 6: Identification & Authentication

Requirement 165.2.1.6.1:

Define and implement a UT Institution-specific user identification schema to uniquely identify and authenticate all users across UT Institution assets and information systems, including unique employee ID numbers or other employee identifiers.

 

Requirement 165.2.1.6.2:

Implement multi-factor authentication so that one of the factors is provided by a device separate from the system gaining access, unless otherwise specified by the UT Institutions, and

the device is approved and is equipped with security measures that must provide a reliable and secure factor for authentication, as determined by the UT Institutions.

 

Requirement 165.2.1.6.3:

Implement multi-factor authentication for systems that store, process, or transmit confidential and controlled data

 

Requirement 165.2.1.6.4:

Identify information system users, processes acting on behalf of users, and devices and authenticate (or verify) the identities of users, processes, or devices, as a prerequisite to allowing access to information systems.
 

Requirement 165.2.1.6.5:

Manage information system identifiers using UT Institution- specific processes. Information system identifiers must be centrally managed where technically feasible within UT Institution directory systems

 

Requirement 165.2.1.6.6:

Define and document processes for the unique identification and authentication of non-UT Institution users (vendors) or processes acting on behalf of non-UT Institution users.

 

Requirement 165.2.1.6.7:

Define and enforce logical access controls to UT Institution information systems for remote access, including at a minimum: two-factor authentication, use of Virtual Private Network (VPN), encrypted connections, and other usage restrictions based on UT Institution defined requirements.

 

Requirement 165.2.1.6.8:

Define and implement scenarios when users must reauthenticate.

 

Requirement 165.2.1.6.9:

Define and enforce logical access controls to UT Institution information systems for wireless access. Vendor and visitor networks shall be configured in a way that logically isolates them from internal UT Institution networks.

[Back to Table of Contents]


 

Standard Requirements Subsection 7: System Use & Logon

Requirement 165.2.1.7.1:

Enforce a UT Institution-defined limit of consecutive invalid logon attempts by a user at the information system / application level within a UT Institution-defined time period. Once the maximum number of attempts has been reached within the defined time period, enforce automatic account locking mechanisms which require an account administrator or other user with appropriate authorizations to unlock the account.

 

Requirement: 165.2.1.7.2

Display a UT Institution-specific use notification message or banner to users within information systems prior to granting access, created and / or reviewed by the Institution’s Privacy Officer (PO), that provides the privacy and security notices consistent with applicable laws or directives.

Retain the notification message or banner on the screen until users acknowledge the usage conditions and take explicit actions to log on to or further access the system.

For publicly accessible systems, a system use notification message or banner must be presented to and acknowledged by users before system access is granted.

 

Requirement 165.2.1.7.3:

Determine and document any UT Institution-defined user actions that are authorized to be performed on the information system without identification or authentication.
 

[Back to Table of Contents]


 

165.2.2  Asset Management Standard

Requirement Subsection 1: Inventory & Maintenance of Assets

Requirement 165.2.2.1.1:

Document and maintain inventories of UT Institution-owned and leased assets that include the following key components, at a minimum:

  • is updated and accurate,
  • includes all assets within necessary information systems and IT facilities as determined by the UT Institutions, and
  • is at the level of granularity deemed necessary for tracking and reporting.
     

Requirement 165.2.2.1.2:

Review and update the UT Institution asset inventories at least once every 24 calendar months or sooner as required by the following:

  • as part of installations or asset commissioning,
  • following asset decommissioning or removal,
  • after information system updates / changes,
  • after asset owner changes, and
  • following other UT Institution-defined triggers.

 

Requirement 165.2.2.1.3:

Perform asset discovery on a regular basis using manual or automated processes as determined technically feasible by the UT Institutions.
 

Requirement 165.2.2.1.4:

Define and implement a UT Institution asset classification and rating scale using a risk-based approach that assesses assets based on their confidentiality, integrity, availability, regulatory, compliance, and other relevant requirements.

Determine asset classification and rating based on data classification, data attributes, and status.

[Back to Table of Contents]


 

Requirement Subsection 2: Asset Management & Protection

Requirement 165.2.2.2.1:

Identify, document, and implement protections as determined necessary by the UT Institution for assets (digital and non-digital media) based on their classification.

 

Requirement 165.2.2.2.2:

Restrict and log physical and logical access attempts for critical assets using manual or automated mechanisms as defined by the UT Institutions based on technical feasibility.

 

Requirement 165.2.2.2.3:

Protect and control assets during transport outside of UT Institution controlled areas and premises using defined controls.

[Back to Table of Contents]


 

Requirement Subsection 3: Acceptable Use of Assets

Requirement 165.2.2.3.1:

Prohibit the misuse of UT Institution assets in accordance with contract agreements, copyrights laws, and other business requirements by performing the following activities, at a minimum:

  • enforce the use of assets for only their intended business purpose,
  • track the use of assets by users to ensure compliance and appropriate use,
  • maintain the correct number of assets such as software licenses to ensure only the number of assets needed to support business requirements and responsibilities are maintained,
  • implement regular asset maintenance activities such as software updates, physical repairs, etc., and
  • collaborate with UT Institution Privacy Officers (PO) to establish requirements for the correct usage or distribution of applicable assets within user and vendor contracts and agreements to maintain compliance with applicable copyright laws or vendor restrictions.
     

Requirement 165.2.2.3.2:

Define and implement UT Institution-specific processes and procedures that govern the correct rules and usage of software.

 

Requirement 165.2.2.3.3:

Define and document a list or process of restricted or prohibited assets that should not be used within certain UT Institution IT facilities, broader UT Institution premises, or on UT Institution internal networks

Restrict the use of UT Institution-owned and operated assets and user personal devices as technically feasible and determined by the UT Institutions.

[Back to Table of Contents]


 

Requirement Subsection 4: Return, Disposal, & Reuse of Assets

Requirement 165.2.2.4.1:

Document processes to collect UT Institution-owned assets from users as part of the Human Resources (HR) user separation and offboarding process.

Decommission and physically remove assets from IT facilities and networks at the end of their lifecycle or when no longer required or supported in accordance with applicable contracts or grants within a UT Institution-defined time period for on-prem assets, and as soon as possible following collection / receival of user assets.

 

Requirement 165.2.2.4.2:

Delete (sanitize) UT Institution-owned data contained on UT Institution assets as necessary and in accordance with applicable contracts and grants, prior to asset disposal, release out of UT Institution control (transfer), or reuse. Deletion must be performed using approved UT Institution-defined methods.

Data deletion must be completed with strength and integrity commensurate with the asset's classification level and in accordance with applicable record retention requirements.

 

Requirement 165.2.2.4.3:

Return decommissioned or removed UT Institution assets to the asset provider or dispose of the assets appropriately following UT Institution-specific asset disposal processes and in accordance with applicable contracts or grants. Disposal of assets must be executed by the appropriate Information Security or Information Technology (IT) users / management and must not be executed by individual users.

 

Requirement 165.2.2.4.4:

Define and implement restrictions and processes for the internal reuse and external release of UT Institution assets.

 

Requirement 165.2.2.4.5:

Review, approve, track, verify and update in UT Institution asset inventories changes to asset status following sanitization, return, removal, or reuse.

Maintain a record documenting the removal and completion of sanitization of media that stored confidential and controlled information in accordance with UT Institutional records retention requirements.

[Back to Table of Contents]


 

165.2.3  System Development & Maintenance Standard

Requirements Subsection 1: System Operational Documentation

Requirement 165.2.3.1.1:

Develop, document, review and update at least once every 12 calendar months UT-Institution specific information system security plans, in collaboration with the developers of the information system.

Update plans following annual reviews or as part of ongoing review and maintenance activities to address changes to the information system and environment of operation or problems identified during plan implementation or control assessments.

 

Requirement 165.2.3.1.2:

Approve, document, and control the use of production data in non-production environments for UT Institution information systems, system components, or system services.

Protect preproduction environments with protections, as determined by the Institution, commensurate with the data classification level of any live data in the preproduction environments.

 

Requirement 165.2.3.1.3:

Develop and maintain UT Institution-specific administrator operational documentation for necessary information systems, system components, or system services.

Distribute operational documentation to necessary users as determined by the UT Institutions.

[Back to Table of Contents]


 

Requirements Subsection 2: System Development

Requirement 165.2.3.2.1:

Employ the principle of least functionality as part of system development by configuring UT Institution information systems to provide only essential capabilities.

Define and implement specific system hardening requirements that must be implemented to support information system configurations.

 

Requirement 165.2.3.2.2:

Review UT Institution information systems at least once every 3 calendar months to identify unnecessary or nonsecure functions, ports, protocols, software, and / or services and disable or remove them as determined necessary by the Institutions.

 

Requirement 165.2.3.2.3:

Develop and / or obtain software internally by UT Institutions or from legitimate and reliable third parties (e.g., validated and procured through Institution vendor management and third- party contracts or processes).

Prohibit the use of unapproved Free and Open-Source Software (FOSS) unless use of such software on Institution information systems is reviewed and approved by the Institutional Information Security Officer (ISO) using appropriate change management processes.
 

Requirement 165.2.3.2.4:

Develop and document a UT Institution configuration management plan for necessary information systems.

[Back to Table of Contents]


 

Requirements Subsection 3: Secure System Protections

Requirement 165.2.3.3.1:

Maintain the following by UT Institution developers of information systems, system components, and system services to perform the key development activities of their role:

  • appropriate access authorizations as determined by the Institution, and
  • meets required additional user screening criteria depending on the sensitivity of their development role as determined by the Institution in collaboration with respective Human Resources (HR) user / departments.
     

Requirement 165.2.3.3.2:

Replace system components when support for the components is no longer available from the UT Institution developer, vendor, or manufacturer within Institution-defined time periods as technically feasible.

System components that are unable to be replaced after End of Life may be used without replacement only if approval of the Institutional Information Security Officer (ISO) and a risk mitigation/reduction processes is implemented.

 

Requirement 165.2.3.3.3:

Define and implement protections that must be implemented throughout the System Development Life Cycle.

 

Requirement 165.2.3.3.4:

Define and implement UT Institution secure design principles, including secure coding, that ensure each executive system process operates in its own separate executive domain throughout the System Development Life Cycle.

 

Requirement 165.2.3.3.5:

Identify, report, and correct UT Institution information system flaws in a timely manner, as soon as technically feasible.

Test software and firmware updates related to flaw remediation for effectiveness and potential side effects before installation.

Install security-relevant software and firmware updates within an Institution-defined time period of the release of the updates. Incorporate flaw remediation into the organizational configuration management process.

 

Requirement 165.2.3.3.6:

Develop, document, and implement processes for patch management to facilitate flaw remediation to UT Institution- defined information system components.

 

Requirement 165.2.3.3.7:

Define and implement effective UT Institution malicious code protection mechanisms at information system ingress / egress points and on endpoints to enable the detection and prevention of malicious code. Update malicious code protection mechanisms whenever new releases are available in accordance with applicable configuration management requirements.

Enable anti-malware software or other approved endpoint protection software (i.e., real-time scanning) on all UT Institution owned servers, workstations, laptops, and computers

[Back to Table of Contents]


 

Requirements Subsection 4: Secure System Engineering

Requirement 165.2.3.4.1:

Define and document a common set of UT Institution information systems security and privacy engineering principles that must be considered and incorporated in the specification, design, development, implementation, and modification of new and existing information systems and system components.

 

Requirement 165.2.3.4.2:

Require UT Institution developer(s) of information systems, system components, or system services to perform key development change management activities.

 

Requirement 165.2.3.4.3:

Require the UT Institution developer of information systems, system components, or system services, at all post-design stages of the System Development Life Cycle, to define, document, and implement integrated test plans, practices, and procedures commensurate with the Institution environment and strategic technology plans.

[Back to Table of Contents]


 

Requirements Subsection 5: System Connections

Requirement 165.2.3.5.1:

Define and implement a process to authorize internal system connections between UT Institution information systems and system components.

[Back to Table of Contents]


 

Requirements Subsection 6: Configuration Baselines

Requirement 165.2.3.6.1:

Document and maintain inventories of UT Institution baseline configurations for critical or high impact information systems throughout the respective System Development Life Cycle as determined by the Institutions.

 

Requirement 165.2.3.6.2:

Review and update the UT Institution baseline configuration inventories at least once every 12 calendar months or sooner as required in the following circumstances to maintain baseline configuration currency, completeness, accuracy, and availability.

 

Requirement 165.2.3.6.3:

Retain previous versions of baseline configurations for a UT Institution-defined time period to support rollback and data restoration activities where necessary.
 

Requirement 165.2.3.6.4:

Track, review, approve or disapprove, log, and implement configuration changes to UT Institution information systems as required.

Retain configuration change logs for an Institution-defined time period or as required by applicable contractual or regulatory requirements.

 

Requirement 165.2.3.6.5:

Define and implement a process to test, validate, and document changes to the information system before implementing any changes, and review changes after implementation to confirm success and accuracy.

System configurations must be reviewed regularly, as defined by the UT Institutions, to determine if unauthorized changes have occurred within the information systems or to system components.

 

Requirement 165.2.3.6.6:

Define and implement UT Institution-specific automated processes as technically feasible to identify, respond to, and mitigate any configuration changes that are implemented without proper authorization.

[Back to Table of Contents]


 

Requirements Subsection 7: Deviations from Baselines

Requirement 165.2.3.7.1:

Establish and implement security configuration settings for UT Institution information technology products employed in information systems.

Monitor and control changes to the configuration settings in accordance with Institution-defined maintenance parameters.

 

Requirement 165.2.3.7.2:

Identify, document, and approve any deviations from established configuration settings by authorized UT Institution users. If unapproved deviations in configuration settings are observed within information systems as part of regular monitoring, implement Institution-defined processes to report and remediate the deviation as soon as technically feasible.

[Back to Table of Contents]


Requirements Subsection 8: System Maintenance

Requirement 165.2.3.8.1:

Define and implement UT Institution-specific processes and procedures for the performance of regular maintenance activities on information systems.

 

Requirement 165.2.3.8.2:

Perform the following for all UT Institution information system maintenance tools:

  • obtain review and approval by necessary users on all tools before use to confirm no malicious code is present (at a minimum),
  • control and monitor the use of maintenance tools using Institution-defined processes, and
  • review approved maintenance tools at least once every 12 calendar months.
     

Requirement 165.2.3.8.3:

Prevent the removal of maintenance equipment containing UT Institution data.

 

Requirement 165.2.3.8.4:

Approve and monitor non-local maintenance and diagnostic activities on UT Institution information systems and maintain records of such activities.

Require a process to appropriately authorize all external / vendor maintenance users before granting them access to Institution information systems, networks, or IT facilities.

[Back to Table of Contents]


 

Requirements Subsection 9: Change Management

Requirement 165.2.3.9.1:

Define and implement a UT Institution-specific information system change management processes and procedures.

 

Requirement 165.2.3.9.2:

Review implemented UT Institution information system changes within an identified, technically feasible timeframe after implementation to ensure that changes are implemented correctly, operating as intended, and producing the desired outcome of the change.

 

Requirement 165.2.3.9.3:

Define, document, approve, and enforce physical and logical access restrictions associated with changes to UT Institution information systems adhering to the principle of least privilege.

[Back to Table of Contents]


 

165.2.4  Business Continuity & Disaster Recovery Standard

Requirement Subsection 1: Business Continuity & Disaster Recovery Planning

Requirement 165.2.4.1.1:

Develop and document business continuity and disaster recovery plans as determined necessary by UT Institutions. Allocate access to disaster recovery and business continuity plans after initial creation and following updates to existing plans to users with a need-to-know as determined by the Institutions.

Review and update business continuity and disaster recovery plans at least once every 12 calendar months or sooner as required by the Institution.

 

Requirement 165.2.4.1.2:

Identify, document, and coordinate with UT Institution-specific users and related groups that must be involved in the business continuity and disaster recovery planning, implementation, and testing process.

 

Requirement 165.2.4.1.3:

Perform tests of business continuity and disaster recovery plans using a risk-based approach at least once every 12 calendar months or sooner as determined by the UT Institutions. Review plans following testing activities and initiate any corrective actions as necessary, incorporating any lessons learned into the plans. At a minimum, tests must be performed for all critical mission and business functions.

 

Requirement 165.2.4.1.4:

Provide business continuity and disaster recovery training to necessary UT Institution users as determined by their assigned roles and responsibilities.

[Back to Table of Contents]


 

Requirement Subsection 2: Capacity Management / Alternate Sites

Requirement 165.2.4.2.1:

Establish and implement alternate storage sites and capabilities to support business continuity and recovery in alignment with capacity needs defined in UT Institution business continuity and disaster recovery plans.

All controls including access authorizations at the alternate storage site must be equivalent to that of the primary site.

 

Requirement 165.2.4.2.2:

Develop and implement a strategy for maintaining UT Institution alternate information processing sites, storage sites, and telecommunications capabilities that are designed to support defined business continuity and recovery requirements.

 

Requirement 165.2.4.2.3:

Develop and implement a strategy for testing UT Institution alternate information processing sites, storage sites, and telecommunications capabilities to support defined business continuity and recovery requirements at an Institution-defined frequency.

 

Requirement 165.2.4.2.4:

Develop and implement a strategy for maintaining alternate communication protocols during a disruption, failure, or other emergency in the event that normal communication channels are impacted.

[Back to Table of Contents]


 

Requirement Subsection 3: Impact Analysis

Requirement 165.2.4.3.1:

Identify and document in asset inventories the necessary business continuity objectives of UT Institution information systems mission and business functions leveraging a risk-based approach.

[Back to Table of Contents]


 

Requirement Subsection 4: Backup Methods

Requirement 165.2.4.4.1:

Collaborate with Asset and Application Owners to define and implement UT Institution processes and procedures to conduct backups of critical information resources, assets, and other data as necessary.

 

Requirement 165.2.4.4.2:

Recover or restore all critical UT Institution information systems to their previous (known) state in the event of security incident, disruption, compromise, or failure, using the defined business continuity and disaster recovery processes.

 

Requirement 165.2.4.4.3:

Define and implement protections for all critical UT Institution system components used for recovery and reconstitution.
 [Back to Table of Contents]


165.2.5  Security Monitoring & Vulnerability Scanning Standard

Standard Requirement Subsection 1: Event Logging

Requirement 165.2.5.1.1:

Create and retain UT Institution information system audit records and logs to the extent needed to enable the monitoring, analysis, investigation, and reporting of any activity or event.

 

Requirement 165.2.5.1.2:

Ensure UT Institution audit records contain information that establishes evidence requirements.

 

Requirement 165.2.5.1.3:

Define UT Institution asset and application log storage methods and capacity to meet log retention and protection requirements, ensuring storage is sufficient to meet log storage needs and is in accordance with Institution record retention requirements.

 

Requirement 165.2.5.1.4:

Define and implement processes to alert responsible or necessary UT Institution users immediately or automatically, as technically feasible, of logging failures or issues. Vendors or third-party service providers must also alert the appropriate Institution users of logging failures or issues within software or solutions owned and managed by the vendor or third-party service provider.

Take the appropriate remediation actions as soon as possible to address logging failures or other issues.

 

Requirement 165.2.5.1.5:

Define the event types that must be reviewed and analyzed when discovered in audit records. Review and analyze UT Institution information system audit records for critical systems and as determined based on risk by UT Institutions for all other systems to identify indicators of unusual or suspicious activity related to pre-defined event types.

Retain audit records in accordance with Institution data retention requirements.

 

Requirement 165.2.5.1.6:

Provide a system capability that compares and synchronizes internal UT Institution system clocks with an ISO approved authoritative source to generate time stamps for audit records.

 

Requirement 165.2.5.1.7:

Define and implement processes to protect UT Institution audit records and audit logging tools from unauthorized access, modification, and deletion.

 

Requirement 165.2.5.1.8:

Retain audit records for a UT Institution defined time period in alignment with established data retention requirements to provide support for after-the-fact investigations of incidents and to meet applicable regulatory requirements.

 

Requirement 165.2.5.1.9:

Configure UT Institution information systems as needed to perform event logging

[Back to Table of Contents]


 

Standard Requirement Subsection 2: Network Security

Requirement 165.2.5.2.1:

Deploy safeguards on UT Institution information systems to limit the effects of both external and internal denial-of-service events.

 

Requirement 165.2.5.2.2:

Monitor, control, and protect communications at the external boundaries and key internal boundaries of information systems.

Implement subnetworks for publicly accessible system components that are physically or logically separated from internal UT Institution networks.

 

Requirement 165.2.5.2.3:

Define and implement processes to manage UT Institution external communication services.

 

Requirement 165.2.5.2.4:

Deny network communications traffic by default and allow network communications traffic by exception where technically feasible on UT Institution networks.
 

Requirement 165.2.5.2.5:

Employ boundary protections to control the flow of data within UT Institution information systems and between interconnected systems based on attributes and classification of the data transferred.

 

Requirement 165.2.5.2.6:

Terminate network connections associated with communications sessions at the end of the sessions or after a defined period of inactivity as determined necessary and technically feasible by the UT Institutions.

 

Requirement 165.2.5.2.7:

Define and implement processes to manage UT Institution Address Name Resolution network services.

[Back to Table of Contents]


 

Standard Requirement Subsection 3: Penetration Testing

Requirement 165.2.5.3.1:

Define and implement UT Institution processes for performance of penetration testing at an Institution-defined cadence to evaluate information systems, system components, or system services to identify potential vulnerabilities or weaknesses that must be addressed when technically feasible.

[Back to Table of Contents]


 

Standard Requirement Subsection 4: Protection Against Malware

Requirement 165.2.5.4.1:

Employ effective spam and phishing protection mechanisms at UT Institution information system entry and exit points to detect and act on unsolicited messages as technically feasible.

 

Requirement 165.2.5.4.2:

Perform data validation and integrity checks on defined data inputs using automated software tools, for confidential data where technically feasible by the UT Institution.

[Back to Table of Contents]


 

Standard Requirement Subsection 5: Threat Intelligence and Management Function

Requirement 165.2.5.5.1:

Share with necessary management users and UT Institution stakeholders the indicators of compromise (IOCs) identified from security incidents so that lessons learned can be documented and employed to prevent similar situations from occurring in the future.

 

Requirement 165.2.5.5.2:

Obtain information system security alerts, advisories, and directives. Implement security directives in accordance with UT Institution-defined time frames.

[Back to Table of Contents]


 

Standard Requirement Subsection 6: Vulnerability Identification & Remediation

Requirement 165.2.5.6.1:

Monitor and scan UT Institution information systems for vulnerabilities at an Institution-defined time period that is commensurate with the risk or criticality of the systems being scanned.

 

Requirement 165.2.5.6.2:

Establish a secure reporting channel for the public to report the identification of any vulnerabilities in UT Institution information systems and system components.

 

Requirement 165.2.5.6.3:

Monitor UT Institution information systems, including inbound and outbound communications traffic.

Alert necessary incident response users immediately upon detected event discovery and following applicable incident response processes.

 

Requirement 165.2.5.6.4:

Employ a wireless intrusion detection system to identify rogue wireless devices and to detect attack attempts and potential compromises or breaches to UT Institution information systems.

 

Requirement 165.2.5.6.5:

Correlate event or suspicious activity information from monitoring activities.

 

Requirement 165.2.5.6.6:

Collaborate with Privacy Officers (PO), Human Resources (HR), and other applicable departments to implement user monitoring based on risk.

 

Requirement 165.2.5.6.7:

Define and implement UT Institution-defined processes for the acquisition, management, and exit from cloud computing (cloud services) to ensure appropriate protections are in place to prevent security incidents. Cloud protections must be commensurate with the classification / sensitivity level of the data transmitted in the cloud.

[Back to Table of Contents]


 

165.2.6  Incident Management Standard

Standard Requirements Subsection 1: Security Incident Planning

Requirement 165.2.6.1.1:

Provide incident response training to UT Institution users that have incident response roles or responsibilities.

Review and update incident response training at least once every 12 calendar months in alignment with the defined awareness and training requirements.

 

Requirement 165.2.6.1.2:

Incident response training must include the following key components, at a minimum:

  • how to respond to a data breach,
  • how to report incidents and who must report them to UT Institution management, Information Security Officers (ISO), and the UT System Administration Chief Information Security Officer (CISO),
  • how to report incidents and who must report them to state residents, law enforcement, and other state and federal entities as required,
  • how to collaborate with outside resources under contract to help with incident response and relevant insurance coverage, and
  • post incident response processes and containment training must include key components.

 

Requirement 165.2.6.1.3:

Test the effectiveness of the incident response capability for the necessary critical UT Institution information systems.

 

Requirement 165.2.6.1.4:

Identify, document, and coordinate with UT Institution-specific users and groups that must be involved in the incident response and testing process in alignment with the defined risk management requirements.

 

Requirement 165.2.6.1.5:

Implement a UT Institution-specific incident handling capability based on risks and in alignment with the risk management framework for security incidents.

 

Requirement 165.2.6.1.6:

Implement automated incident identification, response, tracking, and reporting capabilities where technically feasible based on UT Institution requirements.

 

Requirement 165.2.6.1.7:

Track and document all UT Institution security incidents using defined processes.

 

Requirement 165.2.6.1.8:

Collaborate with risk management, business continuity, and disaster recovery teams to develop UT Institution-specific incident response plans.

 

Requirement 165.2.6.1.9:

Include the following in the incident response plan for data breaches / unauthorized disclosures involving confidential data in collaboration with Data Protection Officers (DPO) and Privacy Officers (PO):

  • a process to determine if notice to individuals or other organizations, including oversight organizations, is needed,
  • an assessment process to determine the extent of the harm, embarrassment, inconvenience, or unfairness to affected individuals and any mechanisms to mitigate such harms, and
  • identification of applicable privacy requirements.
     

[Back to Table of Contents]


 

Standard Requirements Subsection 2: Response to Security Incidents

Requirement 165.2.6.2.1:

Respond to data breaches / unauthorized disclosures by assigning responsibilities for identifying, alerting, isolating, and eradicating contamination from UT Institutional information systems.

[Back to Table of Contents]


 

Standard Requirements Subsection 3: Security Incident Communication

Requirement 165.2.6.3.1:

Coordinate and share with internal and external organizations incident response details to correlate key incident information to achieve cross-organization and organization-wide perspectives on incident awareness and more effective incident responses.

[Back to Table of Contents]


 

Standard Requirements Subsection 4: Security Incident Reporting

Requirement 165.2.6.4.1:

Define and implement a process for UT Institution users to internally report suspected and confirmed privacy and security incidents to Institutional Information Security Officers (ISO), the UT System Administration Chief Information Security Officer (CISO), Privacy Officers (PO), and other necessary users with a role in incident response as identified by the Institutions.

Collaborate with the Office of General Counsel (OGC), Privacy Officers (PO), and External Communications Officers to define and implement processes for Institution users to report suspected and confirmed security incidents to external parties and regulatory agencies within defined time periods as required by security and privacy regulations.

 

Requirement 165.2.6.4.2:

Provide an incident response support resource, integral to the organizational incident response capability, that offers advice and assistance to users of UT Institution information systems for the handling and reporting of security incidents.

[Back to Table of Contents]


 

165.3.1 Physical and Environmental Security Standard

Purpose

The Purpose of this Standard is to establish the requirements for Physical and Environmental Security to support the University of Texas System (UTS) in achieving its mission, objectives, and applicable external and internal compliance obligations. This Standard is supported by the UTS 165.3 Information Security Physical & Environmental Policy objectives which are located within the UTS 165 Policy Library.

 

Standard Requirements

Requirement Subsection 1: Physical Security Protections

Requirement 165.3.1.1.1:

Define and implement procedures detailing the appropriate physical protections that must be implemented within UT Institution IT facilities to maintain physical safety and security by protecting against physical intrusion, theft, fire, flood, and other hazards.

[Back to Table of Contents]


 

Requirement Subsection 2: Physical Access Control

Requirement 165.3.1.2.1:

Restrict physical access to IT facilities to only authorized users based on UT Institution credentials.

 

Requirement 165.3.1.2.2:

Log all physical entries into IT facilities, including failed entry attempts, in local logs following applicable physical protection procedures.

 

Requirement 165.3.1.2.3:

Review or inspect physical entry logs for IT facilities using manual or automated processes at least once per calendar month to confirm appropriate access is maintained or to identify improper access, remediating any deficiencies or identified security incidents as necessary.

 

Requirement 165.3.1.2.4:

Review or inspect physical access protections, such as access cards, keys, facility locks, or other systems used to restrict access to IT facilities at least once every 12 calendar months to confirm access controls are functioning as intended and IT facilities are secured.

[Back to Table of Contents]


 

Requirement Subsection 3: Physical Security Incidents & Visitor Controls

Requirement 165.3.1.3.1:

Monitor, identify, and respond to any security incidents or environmental events at IT facilities according to UT Institution- specific incident management procedures and processes.

 

Requirement 165.3.1.3.2:

Obtain and document the signature of all visitors who enter IT facilities in logs (physical or electronic) prior to granting visitor access to the IT facility.

Retain visitor logs in accordance with the UT System retention requirements and based on risk.

 

Requirement 165.3.1.3.3:

Document and retain only the minimum visitor personal information required as determined by the UT Institution to log and track visitor access to limit the handling of Personally Identifiable Information (PII).

[Back to Table of Contents]


 

Requirement Subsection 4: Environmental Controls

Requirement 165.3.1.4.1:

Implement and maintain physical protections or backups at IT facilities in the event of emergencies such as power failure or fire.

 

Requirement 165.3.1.4.2:

Protect assets where the power source is unstable or static electricity excessive.

 

Requirement 165.3.1.4.3:

Define and implement emergency physical operating procedures that must be followed in the event of emergency situations impacting IT facilities.

 

Requirement 165.3.1.4.4:

Establish and maintain appropriate environmental protection within IT facilities as technically or physically feasible.

Monitor the environment regularly and review and / or update these protections at least once every 12 calendar months to maintain a stable IT facility environment.

[Back to Table of Contents]


 

Requirement Subsection 5: Facilities Requirements

Requirement 165.3.1.5.1:

Define and implement a process to authorize, control, and maintain records of critical assets and system components, as identified and defined by the UT Institutions, entering and exiting IT facilities at designated entry and exit points.

 

Requirement 165.3.1.5.2:

Identify and document alternate physical work sites allowed for use by employees and employ appropriate security controls equal to those at the source work site. Assess the effectiveness of controls at alternate work sites.

 

Requirement 165.3.1.5.3:

Implement asset tracking / location technologies to monitor and track the movement of critical system assets between IT facilities using technically feasible methods as determined by the UT Institutions.

 

Requirement 165.3.1.5.4:

Secure assets within controlled environments in IT facilities using protections commensurate with the value of the assets.

[Back to Table of Contents]


 

Appendix A

 

Definitions

Artificial intelligence systems means systems capable of: (A) perceiving an environment through data acquisition and processing and interpreting the derived information to take an action or actions to imitate intelligent behavior given a specific goal; and (B) learning and adapting behavior by analyzing how the environment is affected by prior actions.

Asset(s) - all the hardware, software, data, and network resources that a UT Institution owns and uses to conduct business operations or research. Examples include but are not limited to computers, servers, laptops, mobile devices, printers, storage devices, routers, switches, firewalls, software licenses, databases, digital medical devices, and other digital information resources.

Audit record(s) - electronic or paper records that provide documented details of activities performed within an information system, network, or application. Audit records provide a detailed account of all system and user activities, including authentication, authorization, access to sensitive data, configuration changes, software installations, network connections, and other events that could impact system or data security or privacy. Audit records typically contain information such as user ID, date and time of the event, IP address, system location and any related data or actions.

Authenticator(s) - a mechanism used to confirm the identity of a user, device, or entity before granting access to sensitive data or information resources. It is typically a password, passphrase, persona identification number (PIN), token, or biometric identifier that is used to authenticate the user's identity. External authenticators are often used in situations where there is a high risk of password compromise or where advanced authentication beyond a user ID and password may be necessary. External authenticators can include smart cards, Universal Serial Bus (USB) keys, one-time passwords, and more, which are used in combination with a password or PIN to authenticate the user's identity.

Backup(s) - copy of files or applications created to avoid loss of data and facilitate recovery in the event of an information system failure or other data loss event.

Bring Your Own Device (BYOD) - the practice of allowing users (employees, visitors, students, etc.) to use their personal mobile devices such as smartphones, tablets, and laptops within UT Institution IT facilities. With BYOD, users may use their own devices to access company or school information systems, collaborate with colleagues or classmates, and complete work- related tasks via the company network if there are no dedicated guest or student networks available.

Change(s) - any addition, modification, update, or removal / disposal of an information resource.

Change management - process of controlling the communication, approval, implementation, and documentation of changes to information systems, hardware, software, and procedures to ensure that information resources are protected against improper modification before, during, and after system implementation.

Classification / classify - the process of categorizing data and assets based on their level of sensitivity, confidentiality, availability, regulatory provisions, or value and potential risk if disclosed inappropriately. Classification helps organizations to identify their most valuable or critical assets and data, apply appropriate security measures to protect them and allocate resources more efficiently, reducing the risk of unauthorized disclosure, data breaches, and other security incidents and risks. See the Texas Department of Information Resources (DIR) Data Classification Guide and the UTS 165 definitions for confidential data, controlled data, and published data for more information.

Cloud computing / cloud services / cloud - has the same meaning as "advanced Internet-based computing service" as defined in Texas Government Code 2157.007(a): “a service that provides network access to a shared pool of configurable computing resources on demand, including networks, servers, storage, applications, or related technology services, that may be rapidly provisioned and released by the service provider with minimal effort and interaction. The term does not include telecommunications service, or the act of hosting computing resources dedicated to a single purchaser.”

Confidential data - the confidential classification applies to data that is exempt from disclosure under applicable state law, including the Texas Public Information Act, and federal laws. Data or information meeting these criteria are designated with the classification of “confidential”  within the UTS 165.1.6 Information Data Protection & Privacy Standard. Examples include: patient billing Information and Protected Health Information subject to the Health Insurance Portability and Accountability Act (HIPAA) or applicable state law, student education records subject to the Family Educational Rights and Privacy Act (FERPA), a social security number, medical research data that contains protected health information, certain student loan information subject to the Gramm Leach Bliley Act (GLBA), certain personal information associated with individuals from the European Union subject to the General Data Protection Regulation (GDPR), or cardholder data subject to the Payment Card Industry Data Security Standard (PCI DSS).

Controlled data - the controlled classification applies to information / data that is not generally created for or made available for public consumption but may be subject to release to the public through the Texas Public Information Act or similar state or federal law. Examples include: operational records, operational statistics, employee salaries, budgets, expenditures, and certain internal communications.

Cryptographic module - a set of hardware, software, and / or firmware that implements approved security functions and is contained within a cryptographic boundary, including cryptographic algorithms (mathematical functions that perform encryption, decryption, hashing, and digital signatures), keys (used to encrypt and decrypt data and to digitally sign messages), and other secrets (such as passwords, application programming interface (API) keys, and certificates).

Critical / criticality / mission critical information resources- -information resources defined by a UT Institution or state agency to be essential to the Institution’s ability to meet its instructional, research, patient care, or public service missions. The loss of these resources or inability to restore them in a timely fashion would result in the failure of the Institution’s operations, inability to comply with regulations or legal obligations, negative legal or financial impact, or endanger the health and safety of faculty, students, staff, and patients. Mission critical information resources include but are not limited to: Information systems managing confidential data, common use infrastructures, Institutional network and data center infrastructure, identity and access management systems (such as single-sign-on or other applications required to enable access to other critical systems), administrative systems (e.g., Human Resources (HR), Finance, Payroll, student / patient enrollment and billing, etc.), student information systems, patient care and life-support systems, etc.

Data - elemental units, regardless of form or media, that are combined to create information used to support research, teaching, patient care, and other UT Institution business processes. Data may include but is not limited to: written, electronic video, and audio records, photographs, negatives, etc.

Data breach - the acquisition, access, use, or disclosure of protected health information (PHI) in a manner not permitted under subpart E of the Health Insurance Portability and Accountability Act (HIPAA) which compromises the security or privacy of the protected health information.

Data minimization - the Fair Information Practice of only collecting personally identifiable information (PII) that is directly relevant and necessary to accomplish the specified purpose(s), and only retaining PII for as long as is necessary to fulfill the specified purpose(s). It also extends to only allowing access to specific PII elements to only those individuals who have a legitimate need to view and utilize those elements.

Data mining - the process of extracting and discovering useful information and patterns from large datasets. Data mining involves using statistical and machine learning techniques to identify trends, correlations, and relationships within the data that might not be immediately apparent. The goal of data mining is to uncover insights that can be used to make more informed business decisions or gain a better understanding of a particular phenomenon.

Decentralized IT - information technology service and support organizations reporting to the heads of business units, departments, or programs, including researchers that manage or support their own information systems.

Device(s) / computing device(s) - any physical tool or piece of equipment capable of sending, receiving, or storing digital data. Devices include but are not limited to: computer servers, workstations, desktop computers, laptop computers, tablet computers, cellular / smart phones, personal digital assistants, Universal Serial Bus (USB) drives, embedded devices, smart watches and other wearable electronic devices, etc.

Digital media / digital data - electronic content / data that is transmitted or stored digitally, and can be displayed, accessed, and distributed through electronic devices such as computers, smartphones, and tablets. Digital media encompasses any form of electronic media that can be recorded, edited, transmitted, and stored using digital technology. Examples of digital media include online videos, photos, music files, eBooks, websites, and social media platforms.

Disposal / dispose - the process of securely and permanently removing data from a UT Institution information system or storage medium in a way that does not allow for its recovery or reconstruction. The disposal method used depends on the type and criticality / sensitivity of the data, the medium on which it is stored, and regulatory or legal requirements. Disposal of physical assets typically involves evaluating the asset's value, determining if it can be sold or recycled, and following established procedures for removing it from the Institution's inventory and transferring it to its new owner or ending its use. Disposal of assets must be executed by the appropriate Institution-defined users and must not be executed by individual users.

Electronic media - electronic storage media including storage devices in computers (hard drives, memory) and any removable / transportable digital storage medium, such as magnetic tape or disk, optical disk, or digital memory card; or transmission media used to exchange data already in electronic storage media. Transmission media includes, for example, the internet (wide- open), extranet (using internet technology to link a business with data accessible only to collaborating parties), leased lines, dial-up lines, private networks, intranet, and the physical movement of removable / transportable electronic storage media.

Fair Information Practice Principles (FIPPS) collection of widely accepted principles that UT Institutions use when evaluating information systems, processes, programs, and activities that affect individual privacy. The FIPPs serve as the foundation for privacy laws and policies and include but are not limited to: transparency, security, purpose specification and use limitation, individual participation, quality and integrity, minimization, and authority.

High impact / high impact information resource(s) / high impact asset(s) - information resources whose loss of confidentiality, integrity, or availability could be expected to have a severe or catastrophic adverse effect on organizational operations, organizational assets, or individuals. Such an event could: cause a severe degradation in or loss of mission capability to an extent and duration that the organization is not able to perform one or more of its primary functions, result in major damage to organizational assets, result in major financial loss, or result in severe or catastrophic harm to individuals involving loss of life or serious life threatening injuries.

Identifier - a piece of information used to uniquely identify a individual / user, system, or entity within a particular UT Institution information system / environment. These identifiers are used in authentication and authorization processes to ensure only authorized access to the system is granted. Identifiers include but are not limited to: usernames, employee IDs, IP addresses, machine names, biometric data, or any other unique piece of information that can be used to associate a user with a specific device or account.

Incidental use - infrequent use of UT Institution provided technology resources in short intervals of time and unrelated to UT Institution work or business and which does not cause additional expense or burden to UT Institutions.

Information resource(s) - any and all computer printouts, online display devices, mass storage media, and all computer-related activities involving any device capable of receiving email, browsing the Internet, or otherwise capable of receiving, storing, managing, or transmitting data. Additionally, information resources are the procedures, equipment, facilities, software, and data that are designed, built, operated, and maintained to create, collect, record, process, store, retrieve, display, and transmit data. Information resources include but are not limited to: mainframes, servers, network infrastructure, personal computers, notebook computers, hand- held computers, pagers, distributed processing systems, network attached, and computer controlled medical and laboratory equipment (i.e. embedded technology), telecommunication resources, network environments, telephones, fax machines, printers and service bureaus.

Information security program / program - the Policies, Standards, Procedures, Guidelines, processes, elements, structure, strategies, objectives, plans, metrics, reports, resources, and services adopted for the purpose of securing UT System and UT Institution information resources.

Information system(s) / system(s) - an interconnected set of information resources under the same direct management control that shares common functionality. An information system typically includes hardware, software, network infrastructure, information, data, applications, communications, and users.

Monitor(ing) - the process of observing and tracking the activities and events taking place within an IT environment in order to detect and prevent security incidents before they can cause substantial damage, such as data breaches, unauthorized disclosures, information system disruption, or compliance violations. Monitoring activities can include but are not limited to: Intrusion Detection and Prevention Systems (IDPS), Security Information and Event Management (SIEM) tools, File Integrity Monitoring (FIM), vulnerability scanning, penetration testing, and continuous compliance monitoring.

Network infrastructure - the distributed hardware and software (i.e., cabling, routers, switches, wireless access points, access methods, and protocols), information, and integrating components that allow institutional network hosts to communicate with one another and enable the administrative, learning, research, and health care missions of the UT Institution.

Non-digital media - any type of content / data that is not created, stored, or transmitted in electronic form. These forms of media rely on physical objects and require manual manipulation and distribution. Non-digital media includes but is not limited to: printed materials such as books, newspapers, and magazines, as well as analog recordings such as vinyl records, cassette tapes, and VHS tapes. Other examples of non-digital media include: paintings, sculptures, and traditional forms of communication such as face-to-face conversations and snail mail.

Portable computing device(s) - any easily movable device capable of viewing, receiving, transmitting, and / or storing data. Portable computing devices include, but are not limited to: notebook computers, handheld computers, tablets (e.g., iPads, etc.), PDAs (personal digital assistants), pagers, smartphones (e.g., iPhones, etc.), Universal Serial Bus (USB) drives, memory cards, external hard drives, data disks, CDs, DVDs, and similar storage devices.

Privileged user account(s) / privileged / privileged user(s) / privilege account(s) / privileged access - accounts / users with administrative privileges or elevated permissions within a UT Institution information system or network, which enable the users to access and perform tasks that are otherwise not provisioned for standard user accounts, such as configuring settings, installing software, and administering the network. 

Published data - the published classification is the lowest risk and includes data / information made available to the public through posting to public websites or distribution through email, social media, print publications, or other media. Published data includes but is not limited to: statistical reports, Fast Facts, Published Research, unrestricted directory information, or educational content available to the public at no cost.

Security incident(s) / incident (s) - an event that indicates potential / suspected unauthorized access, loss, unauthorized disclosure, data breach, modification, disruption, or destruction of data or information resources whether accidental or deliberate, or evidence of intrusion.

Shared / group account(s) - user accounts that are accessed and used by multiple individuals, usually created for a specific purpose, such as accessing a shared information resource or for a team project. Instead of having individual accounts for each user, a shared / group account allows multiple people to use a single account.

University of Texas (UT) Institution(s) / Institution(s) / institutional - University of Texas (UT) System Administration departments, the University of Texas / Texas A&M Investment Management Company (UTIMCO), or any of the academic Institutions, or health science centers that comprise the University of Texas System, or other entities that from time to time may be assigned by specific legislative act to the governance, control, jurisdiction, or management of the University of Texas System. Includes University of Texas at Arlington, University of Texas at Austin, University of Texas at Dallas, University of Texas at El Paso, University of Texas Permian Basin, University of Texas Rio Grande Valley, University of Texas at San Antonio, Stephen F. Austin State University, University of Texas at Tyler, University of Texas Southwestern Medical Center, University of Texas Medical Branch at Galveston, University of Texas Health Science Center at Houston, University of Texas Health Science Center at San Antonio, University of Texas MD Anderson Cancer Center, University of Texas System Administration departments, and University of Texas / Texas A&M Investment Management Company.

University of Texas (UT) System Administration / System Administration - the central administrative offices that provide oversight and coordination of the activities of the University of Texas System (UTS) and its Institutions. Includes the University of Texas System Administration Chief Information Security Officer (CISO), University of Texas System

Administration CISO’s office (Helen’s office), University of Texas System Administration Chief Information Officer (CIO), University of Texas System Administration Chief Privacy Officer (CPO). University of Texas System (UTS) / UT System / System / systemwide - (used to refer in the collective sense to) the academic University of Texas Institutions and health science centers plus the University of Texas System Administration, the University of Texas System Administration departments, and the University of Texas / Texas A&M Investment Management Company (UTIMCO), or other entities that from time to time may be assigned by specific legislative act to the governance, control, jurisdiction, or management of the University of Texas System.

User(s) - an individual, automated application, or process that is authorized by the owner to access the information resource, in accordance with federal and state law, UT Institution policy, and the owner's procedures and rules. Has the responsibility to use the information resource only for the purpose specified by the owner, comply with controls established by the owner, and prevent the unauthorized disclosure of confidential data. The user is any person who has been authorized by the owner of the information resource to read, enter, or update that data / information and can include students and volunteers. The user is the single most effective control for providing adequate security.

Vendor(s) / third party(ies) / third party service provider(s) - any third-party user or entity that contracts with UT Institutions to provide goods and / or services to the Institutions.

Visitor(s) - an individual who enters a UT Institution physical space or virtual environment that belongs to an organization, but who is not an authorized user of a UT Institution. A visitor may be a vendor or other third-party service provider, patient, consultant, auditor, customer, prospective student and guests, or any other person who has a legitimate reason to be present, but who does not have the same level of access or permissions as an employee or authorized user. Individuals with permanent physical access authorization credentials are not considered visitors.