Technology Standard

 


IT Systems Security - IT Systems Interoperability

 

Version: 1.0
Status: Approved: 02/21/07
Contact: Director, Technology Services

 


PURPOSE

To provide guidelines necessary to implement Systems Office and College It Systems Interoperability Security standards and procedures.


SCOPE

In accordance with the COV ITRM 501-01, IT systems interoperability security requirements identify the steps necessary for protecting data shared with external IT systems.


APPLICABILITY

The IT Systems Interoperability Standard is applicable to the System Office and all Colleges.


STANDARD

A system interconnection may be defined as the direct connection of IT systems for the purpose of sharing data. This does not include instances where data is shared via tape or file exchanges. Interconnecting IT systems can have security consequences and may expose the VCCS to potential risks. The following recommendations are provided as minimum guidelines. Colleges are encouraged to apply additional safeguards that commensurate with the risks identified for the applicable IT system and associated data.

Requirement:

The System Owner and Data Owner must document the following information for interconnected systems:

It is critical that the System Office and Colleges document as much information as possible about the interconnection.

Requirement:

The System Office and Colleges must develop a written agreement that includes the following requirements:

Each System Owners must approve and enforce the written agreement.


Return to Information Security Program