![]() |
Technology Standard
|
IT Systems Security - IT Systems Interoperability
Version: 1.0
Status: Approved: 02/21/07
Contact: Director, Technology Services
PURPOSE
To provide guidelines necessary to implement Systems Office and College It Systems Interoperability Security standards and procedures.
SCOPE
In accordance with the COV ITRM 501-01, IT systems interoperability security requirements identify the steps necessary for protecting data shared with external IT systems.
APPLICABILITY
The IT Systems Interoperability Standard is applicable to the System Office and all Colleges.
STANDARD
A system interconnection may be defined as the direct connection of IT
systems for the purpose of sharing data. This does not include instances
where data is shared via tape or file exchanges. Interconnecting IT systems
can have security consequences and may expose the VCCS to potential risks. The
following recommendations are provided as minimum guidelines. Colleges are
encouraged to apply additional safeguards that commensurate with the risks
identified for the applicable IT system and associated data.
Requirement:
The System Owner and Data Owner must document the following information for interconnected systems:
It is critical that the System Office and Colleges document as much information as possible about the interconnection.
Requirement:
The System Office and Colleges must develop a written agreement that includes the following requirements:
Each System Owners must approve and enforce the written agreement.