University Policy
Title
University of North Carolina at Chapel Hill Policy on Information Security
Introduction
Purpose
This policy defines the framework and authority for the University of North Carolina at Chapel Hill's ("University" or "UNC-Chapel Hill") Information Security Program. It establishes the institutional commitment to managing information security risk in a coordinated way across a distributed and risk-diverse environment. The policy authorizes the creation and enforcement of supporting policies, standards, and procedures necessary to protect University information and technology resources. The structure of those supporting documents is described in the Supporting Policy Documents section of this policy.
Scope
This policy applies to all members of the University community, including faculty, staff, students, affiliates, contractors, and third parties acting on behalf of the University. It applies to all University units. For other organizations closely connected with the University such as Affiliated Entities (AE), this policy applies only to those operations and resources that fall within the University's obligation to protect.
It governs all data, systems, services, networks, electronic devices, and credentials for which the University of North Carolina at Chapel Hill has a formal obligation to protect, regardless of ownership or location. These obligations may arise from:
- Legal, regulatory, or contractual requirements;
- Institutional commitments;
- Reputational risk; and
- The need to preserve the security, availability, and integrity of University infrastructure.
Examples include, but are not limited to:
- University data stored in third-party IT services regardless of how the IT service is procured;
- Personally owned devices connected to the University network;
- Vendor-managed systems that process University-regulated data; and
- Credentials that access University systems or services.
The scope of the security program is determined by whether the University has an obligation to protect the resource or information. The determination of protection obligation accounts for factors including regulatory requirements, contractual commitments, institutional risk, and potential reputational harm. How these factors are assessed and how protection levels are assigned is defined in the supporting policy documents.
Business continuity and disaster recovery are addressed through separate institutional functions and are not governed by this policy.
Policy
Policy Statement
UNC-Chapel Hill operates in a highly distributed environment. Schools, departments, and administrative units vary significantly in their technology use, mission requirements, and risk exposure. The University's Information Security Program is designed for this reality: it establishes common requirements and governance structures that apply institution-wide while accommodating the distributed nature of how technology is operated and controlled.
The University requires that information and technology resources for which it has an obligation to protect be managed in accordance with this policy and its supporting standards. Every member of the University community shares responsibility for the security of University information and systems within the scope of their role and access.
Authority and Program Oversight
This policy implements the University's obligations under UNC System Policy 1400.1, which requires each constituent institution to establish and maintain an information security program consistent with industry standards. The Chancellor has delegated authority to the University's Chief Information Security Officer (CISO) to issue and enforce information security policies, standards, and procedures on behalf of the University.
The program is responsible for:
- Coordinating the institution's response to cyber risk;
- Establishing and enforcing common security policies, standards, and controls;
- Supporting regulatory compliance efforts;
- Delivering an annual report on the security program to the Chancellor, Provost, and Board of Trustees; and
- Representing the University's security posture to auditors, regulators, and other external parties as required.
The program aligns with the NIST Cybersecurity Framework and incorporates practices from other recognized professional standards as appropriate.
The annual report to the Board of Trustees will document:
- The current security strategy and roadmap;
- Execution status of the commitments made in the prior report;
- Material changes in the threat landscape, technology environment, regulatory and compliance requirements, and institutional context that bear on security strategy; and
- The security program's commitments for the coming reporting cycle.
Policy Authority and Review
All information security policies, standards, and procedures issued under the Information Security Program derive their authority from this policy. Supporting policies, standards, and procedures are issued by the CISO and are binding and enforceable under this Policy.
This policy and all supporting documents are subject to periodic review. The Information Security Program will reassess and update policies, standards, and procedures as the threat environment, regulatory landscape, and program priorities require, and no less than every three years.
Program Roles and Responsibilities
The following roles are foundational to the operation of the University's Information Security Program and are used throughout the University's information security policies and standards.
Chief Information Security Officer: Accountable for operating the Information Security Program for the University and reporting on its effectiveness and future direction to the Chancellor, Provost, and Board of Trustees.
Deans and Vice-Chancellors: Accountable for security outcomes within their unit, including ensuring their unit operates in compliance with the requirements of the University's Information Security Program.
Delegated Security Authority (DSA): Appointed by a Dean or Vice-Chancellor to implement the Key Controls within the unit on their behalf, as defined in the Coordination of Security Standard.
Responsible Person or Party: Every IT device, application, system, service, data set, business process making use of University IT, and third-party agreement for University IT systems or services must have at least one Responsible Person (RP). The RP is a person in a University relationship, not a third-party entity. The RP may rely on IT teams or vendors to perform technical work, but oversight obligations remain with the RP throughout the lifecycle. The division of RP responsibility must be documented. The RP is not required to be a technical administrator. For personal devices used for business purposes or containing University Information, the Responsible Person is the University-associated owner or main user of the device. The RP must ensure that required security controls are implemented as defined in the Information Security Controls Standard (MSS).
A Primary Responsible Person may delegate a portion of their responsibilities to another individual, who then assumes Responsible Person obligations for that scope. Delegation does not relieve the delegating Responsible Person of obligation to ensure the overall security of the system or service. Each Responsible Person must carry out obligations assigned to them under this Policy unless responsibility has been expressly allocated or shared with another Responsible Person.
A "primary" Responsible Person for any University IT that has a Moderate or High obligation rating must be a permanent University employee or employee of an Affiliated Entity (Employee). That person must be able to ensure the work of any non-University employee Responsible Persons meets requirements.
IT Service Provider: A permanent University Employee who is the primary Responsible Person for a discrete IT service provided to people beyond an individual University workgroup. Service Providers have extra obligations reflected in the Information Security Controls Standard (MSS). For large and complex services, multiple Responsible Persons may collaborate to identify areas of responsibility, but a single point of contact for any discrete functional "IT Service" must be identified. While others may be operational points of contact, the Service Provider is in the escalation for cybersecurity issues with the service.
Information Security Office (ISO) Staff: Act under the CISO's authority to conduct investigations, advise units, assess compliance, review exceptions, and support implementation across the institution.
University Community Member: Any individual who operates on University network infrastructure, holds or uses a University-issued credential, or accesses data that the University has provided or to which the University has granted access where that data carries an obligation to protect -- regardless of employment status, organizational affiliation, or device ownership. This includes but is not limited to students, faculty, staff, contractors, vendors, guests, and individuals affiliated with associated or connected entities. All University Community Members must comply with applicable University information security policies, standards, acceptable use requirements, and completion of assigned training when working within this scope. Individuals who connect personally owned devices to University network infrastructure or use them to access University systems or data are responsible for the security of those devices following applicable standards.
Supporting Policy Documents
This policy is supported by a structured family of documents organized into three categories:
Control Objectives: Centered on the Information Security Controls Standard, which defines the required security safeguards for systems, services, and data the University is obligated to protect.
Governance Processes: Centered on the Coordination of Security Standard, which defines the governance structures, roles, and operational requirements necessary to implement the Information Security Program across the University's distributed environment.
Identity and Access: Will define the University's models for managing the identity of people with relationships to the University and governing their access to University systems and data. These standards are under development as part of the Authentication Modernization Initiative.
Enforcement and Oversight
Violations of this policy will result in a response fitting the role, circumstances, and severity of the incident. Responses may include revocation of access, corrective action, or disciplinary measures up to and including termination of employment or termination of a business relationship with the University.
The CISO may:
- Investigate suspected violations and security incidents;
- Access system logs and related data, consistent with applicable law and University policy;
- Take immediate protective action -- including isolation of systems or revocation of access -- when necessary to contain an active security incident, without prior approval; and
- Coordinate with law enforcement and regulatory bodies as necessary.
Exceptions
All exceptions, deviations, and risk acceptance for those deviations from this Policy, or those policies, procedures, and standards established under this Policy are subject to the authority of the University's Chief Information Security Officer. Written exception and deviation processes for routine exceptions are established by the Information Security Office. Urgent exceptions or those not in scope of any defined exception process may be made in writing by the Chief Information Security Officer.
University information security policies and standards establish default requirements. Units may request exceptions to these requirements, propose alternative implementations that deviate from the default while still meeting the underlying control objective, or formally accept residual risk where a requirement cannot be met. All such requests are subject to defined exception and deviation processes to ensure appropriate institutional oversight.
All exceptions and deviations must be reviewed by the unit's Delegated Security Authority and filed with the Information Security Office. The CISO determines, based on the nature and risk of the request, whether additional review by ISO or approval by the relevant Dean or Vice-Chancellor is required. The process for submitting and evaluating exceptions and deviations is maintained by the ISO.
All approved exceptions and deviations must be documented in writing, granted for a defined period, and reviewed periodically. They do not constitute permanent relief from the underlying requirement.
Definitions
Please see the University's Information Security Defined Terms Standard.
Related Requirements
External Regulations and Consequences
Compliance
Failure to comply with this policy may put University information assets at risk and may have disciplinary consequences for employees, up to and including termination of employment. Students who fail to adhere to this policy may be referred to the UNC-Chapel Hill Office of Student Conduct. Contractors, vendors, and others who fail to adhere to this policy may face termination of their business relationships with UNC-Chapel Hill.
Violation of this policy may also carry the risk of civil or criminal penalties.
University Policies, Standards, and Procedures
Contact Information
Policy Contact
Unit: ITS Policy Office
Phone: 919-962-HELP
Email: its_policy@unc.edu
Other Contacts
Guidance on Specific Requests
Reach out to the ITS Policy Office (919-962-HELP or its_policy@unc.edu), or check out the resources on help.unc.edu.
Important Dates
- Effective Date and title of Approver:
- Effective Date: 6/30/2010
- Approver: Chief Information Officer
- Revision and Review Dates, Change notes, title of Reviewer or Approver:
- Last Revised Date: 10/24/2017
- Revised by: Chief Information Officer
- Substantive Revisions:
- Complete revision
- Dates after this point are maintained in the University policy repository.