Information system personnel security

Purpose

The purpose of this policy is to implement appropriate safeguards to ensure data users granted access to university information systems have been properly vetted.

Policy

It is the policy of Lynn University to limit access to university information systems to authorized data users that are trustworthy and meet established security criteria and to ensure that such systems are protected during and after personnel actions such as terminations and transfers.

Definitions

Data managers - data managers are application module administrators or power users responsible for the daily operation and management of systems and processes that collect, manage and provide access to institutional data.

Data users - individuals, including, but not limited to, employees, temporary employees, faculty, students, alumni, trustees, campus visitors, contractors, vendors, consultants and their related personnel authorized by the university to access information systems that collect, process, maintain, use, share, disseminate or dispose of institutional data.

Executive data stewards - executive data stewards are defined as institutional officers (e.g., vice presidents, deans, etc.) who have authority over policies and procedures regarding business definitions of data and the access and usage of that data within their delegations of authority. Each executive data steward appoints data stewards and data managers for their subject area domains.

Information system(s) - a set of information resources organized expressly for the collection, processing, maintenance, use, sharing, dissemination, or disposition of information. The term system is used to represent any method that can process, store, or transmit institutional data.

Institutional data
- any information collected, manipulated, stored, reported, or presented in any format, on any medium, at any location by any unit, program or office of the university in support of Lynn University’s mission. There are three types of institutional data: high risk; medium risk; and low risk.

IT coordinators - IT coordinators are information technology staff responsible for the daily operation and management of systems, processes and applications that collect, manage, bridge and provide access to institutional data.

Procedures/Guidelines

To learn more about this policy or the supporting procedures, please contact  Information Technology.

Policy updated on: Jun. 1, 2021