The University of Arizona

Policy and Guidance

The Information Security Office (InfoSec) is responsible for coordinating the development and dissemination of information security policies, standards, procedures and guidelines for the University. InfoSec is also responsible for coordinating various regulatory compliance efforts. 


Policies:  High level statements, equivalent to organizational law, that drive decision making within the University. University policies are subject to a rigorous review process.

Standards:  Minimum requirements designed to address certain risks and specific requirements that ensure compliance with a policy or standard. These provide a basis for verifying compliance through audits and assessments. All units must meet the standards supporting the Information Security Policy and are encouraged to adopt local standards that exceed the minimum requirements.

Procedures:  Step-by-step instructions for accomplishing a task. Procedures published by Info Sec are designed to reinforce University policies. Procedures may also play an important role in maintaining compliance with regulations.

Guidelines:  General recommendations or instructions that provide a framework for achieving compliance with policies. They are more technical in nature than policies and standards and are updated on a more frequent basis to account for changes in technology and/or University practices.


Policy Framework
Legal Resources

Policy Framework

Number

Previous Number (if applicable)

Title

Type

   
 
IS-100
 
Policy
IS-P100
 
Procedure
IS-G100
 
Guideline
IS-S101
 
Standard
IS-G101
 
Guideline
 
 
 
 
 
IS-G200
 
Guideline
IS-G201
 
Guideline
 
 
 
 
Asset Management  
IS-S301
 
Standard
IS-S302
 
Standard
IS-S303
IS-G301
Encryption
(note: this is still a guideline, and only in draft form)
Standard
 
 
 
 
Human Resource Security  
IS-S400
 
Standard
 
 
 
 
Physical and Environmental Security  
IS-S501
 
Standard
IS-P501 (UITS)
 
Procedure
 
 
 
 
Communications and Operations Management  
IS-S600
 
IS-S602
(NOTE:  The University Network Operational Security Standard will be replaced by the Network Security Standard as soon as the new standard is finalized)
Standard
Standard
IS-S601
 
Standard
IS-S602
IS-S701
Standard
IS-G602A
IS-G706
Guideline
IS-G602B
IS-G704
Guideline
IS-G602C
IS-G702
Guideline
IS-G602D
IS-G705
Guideline
IS-G602E
IS-G703
Guideline
IS-S603
IS-S702
Standard
IS-P603
IS-P601
Procedure
IS-G603   Information System Activity Review Guideline
IS-G604
IS-G601
Guideline
       
Access Control  
IS-700
 IS-701
Policy
IS-701
 IS-702
Policy
IS-S702
 IS-S500/700
Standard
IS-P702
 IS-P701
Procedure
IS-P702M
 IS-P701M
Procedure
IS-S703U
 
Standard
IS-G703
 IS-G701
Guideline
 
 
 
 
Information Systems Acquisition, Development, and Maintenance  
IS-S801
 
Standard
IS-P801
 
Procedure
IS-P802
 
Procedure
 
 
 
 
Business Continuity Management  
IS-S900
 
Standard
IS-G901
 
Guideline
IS-G902
 
Guideline
IS-G903
 
Guideline
 
 
 
 
Compliance  
IS-1000
 
Policy
IS-G1001
 
Guideline
 
 
 
 
Information Security Incident Management  
IS-S1100
 
Standard
IS-P1100
 
Procedure
IS-G1100
 
Guideline
 
 
 
 
Risk Assessment  
IS-S1200
 
Standard
IS-P1200
 
Procedure
IS-G1200   Unit Asset Identification and Workbook Guideline
 

Legal Sources

Federal Policy
Health Insurance Portability and Accountability Act 45 CFR Parts 160,162, and 164 (HIPAA)
Family Educational Rights and Privacy Act 34 CFR Part 99 (FERPA)
Computer Fraud and Abuse Act of 1986
USA PATRIOT Act of 2001
Computer Security Act of 1987
Homeland Security Act
The Children's Internet Protection Act of 2000
The No Electronic Theft (NET) Act of 1997
 
State & Local Policy
Arizona Revised Statutes Section 15-1823 (Identification numbers; social security numbers)
Arizona Revised Statutes 44-1373 (Restricted use of personal identifying information; civil penalty)
Arizona Revised Statutes Section 44-7501 (Notification of breach of security system)
Arizona Board of Regents Policy 6-912 (Access to or Disclosure of Personnel Records or Information)
Arizona Board of Regents Policy 9-201 (General Policy)
Arizona Board of Regents Policy 9-202 (University Responsibilities)
Payment Card Industry Data Security Standard (PCI DSS)