Unit Policy
Title
Information Technology Services Unit: Policy on Policies
(Formerly ITS Unit: Standard on Policies, Standards, and Procedures)
Introduction
Purpose
The purpose of this Policy is to establish a consistent framework for developing, reviewing, approving, publishing, and retiring policies under the authority of the Vice Chancellor for Information Technology and Chief Information Officer. This Policy ensures clarity, accuracy, and alignment with University policies, procedures, and standards (“policy documents”), while supporting transparency and accountability in all policy documents issued by the unit.
Scope
This Policy applies to Information Technology Services (ITS), and also applies to other units under the Vice Chancellor for IT and CIO, including the Information Security Office and Institutional Privacy Office which are independently responsible for their policy portfolios. For convenience, this policy refers to all covered areas as “ITS.”
All Unit employees who participate in drafting, reviewing, approving, or implementing Unit policy documents must comply with this Policy.
Policy
Policy Development
This Policy applies to all policy documents (University and Unit policies, standards, and procedures) created and maintained by ITS. ITS policy documents must be issued by the CIO, someone to whom they have delegated authority in writing in a notification to the University Policy Office or someone with independent policy authority.
When ITS creates new policy documents, they will be clear, consistent, and align with existing University policy documents. ITS must receive review of proposed policy documents from the Office of University Counsel to ensure that the language is legally sound. The Institutional Privacy Office will manage all legal review for policy documents issued from that office. All other legal review will be coordinated through the ITS policy office.
For University policy documents, ITS will ensure that representatives of stakeholder groups are included in drafting policies to provide input prior to review by the Policy Review Committee. The University community will also be provided with the opportunity to provide input on draft policy documents (through publication on the ITS policy page or similar, and notification to identified stakeholder groups.) Abbreviated reviews may be necessary in unusual circumstances, and may be authorized by the CIO in writing. ITS will consider the needed breadth of stakeholder groups and their duration of review based on expected impact and good change management practice. ITS may not communicate with every affected stakeholder, but will make efforts to connect policy decisions with expected impact in ways that do not take our customers and colleagues by surprise.
Policy Review
All policies must be reviewed at least once every three (3) years, and may be reviewed more frequently at the Unit’s discretion. The review process should be a substantive content review to confirm accuracy, relevance, and compliance with University requirements, and should also ensure hyperlinks and contact information remain correct. The ITS policy office will coordinate these reviews if requested to do so by the Issuing Officer.
"Quick fix" items identified by the review (or at other times) may be addressed by the ITS Policy Liaison in coordination with the University Policy Office. (e.g. broken links, organizational name changes, grammar issues, and similar.)
Major items requiring revision identified in the review will be handled through the Policy Development process. ITS will defer to the University Policy Office to determine whether a change is a quick fix or a revision. Decisions about when and whether to revise a policy will be made by the Issuing Officer.
Policy Retirement
Policies that are outdated or no longer necessary must be formally retired. ITS will submit a completed Request to Retire a University Policy Document (or other form or process as directed by the University Policy Office) to retire a policy document. This form must document the reason for retirement and communicate changes to affected stakeholders.
Policy Approval and Publication
The Vice Chancellor for Information Technology, or others with delegated authority (currently the VC for IT and Chief Information Security Officer and Chief Privacy Officer) must approve all new or updated University policy documents before publication under their authority as Issuing Officer. Policies must be published in the University’s central repository to ensure accessibility. Only documents stored in the University policy repository are official ITS policy documents. Once the Issuing Officer has approved the new or updated policy, the ITS policy Liaison will coordinate with the University Policy Office to publish the document. The UPO maintains records of approvals, reviews, and revisions over the life of the policy. The ITS Policy Office will maintain point-in-time reference copies and history of documents for convenience, and audit support purposes.
Policy Review Committee Participation
ITS will designate at least one member of the Unit to serve as a Policy Liaison on the University’s Policy Review Committee (PRC). The Liaison will communicate updates between the Unit and the PRC. This includes notifying unit stakeholders of policies under review by the PRC, and participating in the policy process to bring ITS policies to the PRC.
For any University Policies ITS is responsible for on behalf of the University, the Liaison is responsible for coordinating with the University Policy Office to ensure timely submission of policies to the PRC for review after all required prior ITS processes, including approval to send to the PRC from the Issuing Officer are complete.
Note: The Institutional Privacy Office and Information Security Office may opt to engage directly with the University Policy Office rather than through an ITS Policy Liaison.
Related Requirements
Policies, Standards, and Procedures
Contact Information
Primary Contact
Office: ITS Policy Office
Telephone: 919-962-HELP
Email: its_policy@unc.edu
Document History
- Effective Date and title of Approver:
- Origination/Effective Date: May 12, 2015
- Approver: Vice Chancellor for Information Technology and Chief Information Officer
- Revision and Review Dates, Change notes, title of Reviewer or Approver:
- Previous Revised Date: November 28, 2017
- Revised by: Chief Information Officer
- Substantive Revisions:
- Clarified processes for review, revision, and ministerial/administrative changes.
- Brought document into current template format.
- Altered requirements for record copy storage to remove requirement for paper documents. Change also anticipates shift from unit storage to OEEPM storage of official documents.
- Clarifications
- Previous Revised Date: March 14, 2017
- Revised by: Vice Chancellor for Information Technology and Chief Information Officer
- Substantive Revisions:
- Altered to comply with revised University Policy on Policy Development, Approval, and Publication;
- Renamed from "ITS Governance Document Standard;"
- Clarifications
- See University Policy Repository for additional document history.