Policy and Guidance
The Information Security Office (InfoSec) is responsible for coordinating the development and dissemination of information security policies, standards, procedures and guidelines for the University. InfoSec is also responsible for coordinating various regulatory compliance efforts.

Policies: High level statements, equivalent to organizational law, that drive decision making within the University. University policies are subject to a rigorous review process.
Standards: Minimum requirements designed to address certain risks and specific requirements that ensure compliance with a policy or standard. These provide a basis for verifying compliance through audits and assessments. All units must meet the standards supporting the Information Security Policy and are encouraged to adopt local standards that exceed the minimum requirements.
Procedures: Step-by-step instructions for accomplishing a task. Procedures published by Info Sec are designed to reinforce University policies. Procedures may also play an important role in maintaining compliance with regulations.
Guidelines: General recommendations or instructions that provide a framework for achieving compliance with policies. They are more technical in nature than policies and standards and are updated on a more frequent basis to account for changes in technology and/or University practices.
- Information Security Policy
- Organization of Information Security
- Asset Management
- Human Resource Security
- Physical and Environmental Security
- Communications and Operations Management
- Access Control
- Information Systems Acquisition, Development and Maintenance
- Business Continuity Management
- Compliance
- Information Security Incident Management
- Risk Assessment
Policy Framework
|
Number |
Previous Number (if applicable) |
Title |
Type |
||||
|---|---|---|---|---|---|---|---|
|
IS-100
|
Policy
|
||||||
|
IS-P100
|
Procedure
|
||||||
|
IS-G100
|
Guideline
|
||||||
|
IS-S101
|
Standard
|
||||||
|
IS-G101
|
Guideline
|
||||||
|
|
|
|
|||||
|
IS-G200
|
Guideline
|
||||||
|
IS-G201
|
Guideline
|
||||||
|
|
|
|
|||||
| Asset Management | |||||||
|
IS-S301
|
Standard
|
||||||
|
IS-S302
|
Standard
|
||||||
|
IS-S303
|
IS-G301 |
Encryption
(note: this is still a guideline, and only in draft form) |
Standard
|
||||
|
|
|
|
|||||
| Human Resource Security | |||||||
|
IS-S400
|
Standard
|
||||||
|
|
|
|
|||||
| Physical and Environmental Security | |||||||
|
IS-S501
|
Standard
|
||||||
|
IS-P501 (UITS)
|
Procedure
|
||||||
|
|
|
|
|||||
| Communications and Operations Management | |||||||
|
IS-S600
|
IS-S602 |
(NOTE: The University Network Operational Security Standard will be replaced by the Network Security Standard as soon as the new standard is finalized)
|
Standard
Standard
|
||||
|
IS-S601
|
Standard
|
||||||
|
IS-S602
|
IS-S701 |
Standard
|
|||||
|
IS-G602A
|
IS-G706 |
Guideline
|
|||||
|
IS-G602B
|
IS-G704 |
Guideline
|
|||||
|
IS-G602C
|
IS-G702 |
Guideline
|
|||||
|
IS-G602D
|
IS-G705 |
Guideline
|
|||||
|
IS-G602E
|
IS-G703 |
Guideline
|
|||||
|
IS-S603
|
IS-S702 |
Standard
|
|||||
|
IS-P603
|
IS-P601 |
Procedure
|
|||||
| IS-G603 | Information System Activity Review | Guideline | |||||
|
IS-G604
|
IS-G601 |
Guideline
|
|||||
| Access Control | |||||||
|
IS-700
|
IS-701 |
Policy
|
|||||
|
IS-701
|
IS-702 |
Policy
|
|||||
|
IS-S702
|
IS-S500/700 |
Standard
|
|||||
|
IS-P702
|
IS-P701 |
Enterprise Applications Account Access (Legacy Systems)
|
Procedure
|
||||
|
IS-P702M
|
IS-P701M |
Enterprise Applications Account Access (UAccess)
|
Procedure
|
||||
|
IS-S703U
|
Standard
|
||||||
|
IS-G703
|
IS-G701 |
Guideline
|
|||||
|
|
|
|
|||||
| Information Systems Acquisition, Development, and Maintenance | |||||||
|
IS-S801
|
Standard
|
||||||
|
IS-P801
|
Procedure
|
||||||
|
IS-P802
|
Procedure
|
||||||
|
|
|
|
|||||
| Business Continuity Management | |||||||
|
IS-S900
|
Standard
|
||||||
|
IS-G901
|
Guideline
|
||||||
|
IS-G902
|
Guideline
|
||||||
|
IS-G903
|
Guideline
|
||||||
|
|
|
|
|||||
| Compliance | |||||||
|
IS-1000
|
Policy
|
||||||
|
IS-G1001
|
Guideline
|
||||||
|
|
|
|
|||||
| Information Security Incident Management | |||||||
|
IS-S1100
|
Standard
|
||||||
|
IS-P1100
|
Procedure
|
||||||
|
IS-G1100
|
Guideline
|
||||||
|
|
|
|
|||||
| Risk Assessment | |||||||
|
IS-S1200
|
Standard
|
||||||
|
IS-P1200
|
Procedure
|
||||||
| IS-G1200 | Unit Asset Identification and Workbook | Guideline | |||||
Legal Sources
| Federal Policy | |||
| Health Insurance Portability and Accountability Act 45 CFR Parts 160,162, and 164 (HIPAA) | |||
| Family Educational Rights and Privacy Act 34 CFR Part 99 (FERPA) | |||
| Computer Fraud and Abuse Act of 1986 | |||
| USA PATRIOT Act of 2001 | |||
| Computer Security Act of 1987 | |||
| Homeland Security Act | |||
| The Children's Internet Protection Act of 2000 | |||
| The No Electronic Theft (NET) Act of 1997 | |||
| State & Local Policy | |||
| Arizona Revised Statutes Section 15-1823 (Identification numbers; social security numbers) | |||
| Arizona Revised Statutes 44-1373 (Restricted use of personal identifying information; civil penalty) | |||
| Arizona Revised Statutes Section 44-7501 (Notification of breach of security system) | |||
| Arizona Board of Regents Policy 6-912 (Access to or Disclosure of Personnel Records or Information) | |||
| Arizona Board of Regents Policy 9-201 (General Policy) | |||
| Arizona Board of Regents Policy 9-202 (University Responsibilities) | |||
| Payment Card Industry Data Security Standard (PCI DSS) | |||

