![]() |
Technology Standard
|
Contingency Planning and Business Recovery Program
IT Security Governance
Version: 1.0
Status: Approved 02/21/07
Contact: Director, Technology Services
PURPOSE
The effectiveness of an enterprise information security practices depends to a large degree on the way that security responsibilities are organized and assigned. The purpose of the IT Security Governance Standard is to identify all of the primary roles and associated responsibilities for creating and maintaining the VCCS Information Security Program.
SCOPE
The IT Security Governance Standard covers all VCCS and college business processes and the related Information Technology infrastructure.
APPLICABILITY
The IT Security Governance Standard is applicable to the System Office and all Colleges.
STANDARD
One of the key components in building a strong IT security organization is to clearly identify all the primary roles and responsibilities. To support the VCCS security infrastructure and the local college security infrastructure the following Governance Model and associated enterprise security organization is required:
College Information Security Officers (CISO) Group
The College Information Security Officers (CISO) Group addresses issues and matters specific to information security and their impact on telecommunications and computing areas as voice, data, and video; desktops and servers; and general computing applications and services.
The College Information Security Offices Group is specifically charged with the discussion, review, and planning of the VCCS Information Technology Security Program and all the related standards, guidelines, and procedures on which all colleges must base their local IT security programs. The Group shall facilitate an appropriate exchange of information among the Interest Groups, Workgroups, ad-hoc committees for the expressed purpose of building consensus on related issues. The CISO Group plays an advisory role to the Technology Council and the VCCS colleges. It shall be a focal point of discussion across the more limited boundaries of the various VCCS peer groups and workgroups to bring understanding of the interplay and impact of security on the various technologies, applications, and services deployed within VCCS. The CISO Group shall identify proposals, provide guidance to the peer groups, and provide advice and counsel to the Technology Council.
VCCS Information Technology Security Organization
The diagram below provides a functional representation of how the VCCS information security is organized to support the twenty-three colleges, System Office, and Enterprise applications, services, and supporting IT infrastructure. The colleges and System Offices are expected to maintain organization charts that identify the specific individual assignments and reporting relationships.
Roles and Responsibilities
College Presidents – Each College President is responsible for college’s IT systems and data. Their IT security responsibilities include:
- Requiring development and implementation of the College Contingency Planning and Business Recovery Program, and submitting the Annual Statement of Compliance to the System Office;
- Requiring that the planned IT security audits are conducted;
- Receiving reports of the results of IT security audits;
- Requiring development of Corrective Action Plans to address findings of IT security audits; and
- Reporting to the System Office all IT security audit findings and progress in implementing corrective actions in response to IT security audit findings.
VCCS Information Security Officer – The System Office ITS Office has been designated as the primary liaison for developing and managing the VCCS IT security program and the supporting shared security infrastructure. As such, this office will perform the following duties:
College Information Security Officer (ISO) - The ISO is responsible for the development and administration of the college Contingency Planning and Business Recovery Program as well as the college local IT security architecture. They are expected to perform the following duties:
System Administrators - The System Administrator is an analyst, engineer, or technician who implements, manages, and/or operates a system or systems. The System Administrator assists College and System Office management in the day-to-day administration of the IT systems, and implements security controls and other requirements of the local IT security program on IT systems for which the System Administrator have been assigned responsibility. Typically in the VCCS these are SIS Security Officers, LAN Administrators, Network Security Engineers, etc.
IT System Users - All users of COV IT systems including employees and contractors are responsible for the following:
System Owners - The System Owner is the manager responsible for operation and maintenance of an IT system. With respect to IT security, the System Owner’s responsibilities include the following:
Data Owners - The Data Owner is the manager responsible for the policy and practice decisions regarding data, and is responsible for the following:
Data Custodians - Data Custodians are
individuals or organizations in physical or logical possession of data for Data
Owners. Data Custodians are responsible for the following: