Information Security Program (Policy IT-9)

Policy: 

Clarkson College has adopted the following Information Security Policy ("policy") as a measure to protect the confidentiality, integrity, and availability of institutional data as well as any information systems that store, process, or transmit institutional data. Clarkson College has a critical duty to comply with information security laws, regulations, and requirements to protect the data of its constituents. 

Procedure: 

Scope 

This policy applies to all faculty, staff, and third-party Agents of Clarkson College and any other Clarkson College affiliate, including student workers authorized to access or manage institutional data. 

Maintenance: 

Clarkson College's Information Security Team will review this policy annually or as appropriate based on changes in technology or regulatory requirements. 

Enforcement: 

Violations of this policy may result in suspension or loss of the violator's use privileges concerning institutional data and Clarkson College-owned information systems. Additional administrative sanctions may apply up to and including termination of employment or contractor status with Clarkson College. Civil, criminal, and equitable remedies may apply. 

Exceptions: 

Exceptions to this policy must be approved by the Information Security Team and formally documented. Policy exceptions will be reviewed periodically for appropriateness. 

Definitions 

Agent: for the purpose of this policy, an agent is defined as any third party that has been contracted by Clarkson College to provide a set of services and who stores, processes, or transmits institutional data as part of those services. 

Information System: is defined as any electronic system that stores, processes, or transmits information. 

Institutional Data: is defined as any data owned or licensed by Clarkson College. 

Policies 

01 

Throughout its lifecycle, all institutional data shall be protected in a manner that is considered reasonable and appropriate, as defined in documentation approved and maintained by the Information Security Team, given the level of sensitivity, value, and criticality that the institutional data has to Clarkson College. 

02 

Any information system that stores, processes, or transmits institutional data shall be secured in a manner that is considered reasonable and appropriate, as defined in documentation approved and maintained by the Information Security Team, given the level of sensitivity, value, and criticality that the institutional data has to Clarkson College.  

03 

Individuals who are authorized to access institutional data shall adhere to the appropriate roles and responsibilities, as defined in the documentation and approved and maintained by the Information Security Team.