University Standard
Title
University of North Carolina at Chapel Hill Standard on Information Security Defined Terms
Introduction
Purpose
The University of North Carolina at Chapel Hill ("UNC-Chapel Hill" or "University") Information Security Office (ISO) sets policy that defines the University's Information Security Program (Program). The Program and its processes require action by specific groups and individuals, and some requirements apply to every person at the University. The policies that create the Program are intended to be clear and consistent. To promote consistency, this Standard sets out certain key defined terms that support understanding of all Program policies and are to be used as defined in all Program activities.
Scope
The defined terms in this Standard apply to all University Information Security policy documents that reference it.
Use of the terms in the context of Program activities is required of all individuals, groups, roles, and University units.
Standard
The defined terms below are defined for the purposes of the Information Security Program and apply to each policy document that references this Standard in its "Definitions" section. Definitions in this Standard do not supersede any terms defined directly in any policy document.
Exceptions
This Standard is informational for all other University Information Security and Information Technology policies where the given term is not defined in that document.
Definitions
- Accountable Person: Dean, Vice Chancellor, or other senior University leader who bears institutional accountability for cybersecurity outcomes within their unit under the Coordination of Security program. Deans and Vice Chancellors are Accountable Persons by virtue of their role. The CISO may identify additional University leaders as Accountable Persons where necessary to ensure complete coverage of the University and its Affiliated Entities. Accountable Persons are responsible for designating Delegated Security Authorities, allocating resources sufficient to meet program requirements, and formally affirming their security accountability through the annual Key Controls Attestation. Together, the set of Accountable Persons spans the full institutional authority structure with no gaps.
- Associated Entity (AE): A type of Closely Affiliated Entity, an Associated Entity is a foundation, association, corporation, limited liability company, partnership, or other nonprofit entity formally recognized and approved in writing pursuant to the University of North Carolina System Regulation on Required Elements of University-Associated Entity Relationship (G.S. 116-30.20 and related policies). The regulation requires each Associated Entity to maintain a written agreement with the University obligating the Associated Entity to comply with applicable University and UNC System policies and regulations, including the University's Information Security policies and related standards, unless specific exceptions are expressly stated in the agreement or written exceptions are provided as allowed under a specific policy or standard.
- Authentication Modernization Initiative (AMI): An initiative to rebuild the University's digital identity and credentialing. Based on identified outcomes, the program establishes, clarifies, or modifies University policy, business processes, and technical systems to deliver sustainable governance and operational practices for digital credentials.
- Baseline Protection Level: The protection tier — Low, Moderate, or High — assigned to a University system or service as part of the Security Rating. The Baseline Protection Level determines which set of security controls under the Information Security Controls Standard applies to the system, and governs the level of DSA and ISO involvement required for Security Planning Assessments and exception handling under the Coordination of Security program.
- Chief Information Security Officer (CISO): Senior University leader responsible for the Information Security Program. Designated by the Chancellor under University of North Carolina System Regulation 1400.1 to create, operate, and report on a cybersecurity program for the University.
- Closely Affiliated Entity: An organization that is closely connected with the University but is not itself a University unit — such as a foundation, institute, or other entity with a formal relationship to UNC-Chapel Hill. Affiliated Entities are subject to the University's Information Security Program only to the extent that their operations or resources fall within the University's obligation to protect. When an Affiliated Entity connects to University networks, uses University systems or credentials, or handles data for which the University has an obligation to protect, it is required to comply with applicable University information security policies and standards. Affiliated Entities confirm this obligation through a written agreement with the University.
- Common Control: A security control that is implemented once and inherited by one or more University systems or services. Common controls reduce the security burden on individual Responsible Persons by providing baseline protections at the university, unit, or platform level. Examples include single sign-on for authentication requirements, network firewalls for intrusion detection and boundary defense, or endpoint detection and response software for host-based monitoring and incident response.
- Coordination of Security (CoS): The University's operating model for cybersecurity governance in a distributed environment. CoS establishes how security accountability is assigned across University units, how required security processes are implemented, and how units and the institutional security program coordinate to manage risk effectively. It is the mechanism through which the University's Information Security Program operates at institutional scale. The requirements of the CoS program are defined in the Coordination of Security Standard.
- Critical IT Infrastructure: Anything that serves as a "common control" (A security control that is inherited by one or more organizational information systems) such as a Single Sign-On portal. Largely or massively shared Infrastructure shared between multiple high-protection-obligation systems (such as a central virtualized system environment.) Technology may be designated as "Critical IT Infrastructure" if a security compromise of the technology also compromises multiple, unrelated IT systems with a high protection obligation.
- Delegated Security Authority (DSA): The DSA is the person or people formally designated by the unit head (Dean or Vice Chancellor) who implements the Key Controls within the unit. The DSA acts on behalf of the Accountable Person in all matters relating to the Coordination of Security program. The DSA is accountable for ensuring Key Control obligations are met within their span of authority, though the work may be performed by others. What may not be delegated is the DSA's accountability for ensuring the work is done, that it meets program requirements, and that results are reported accurately.
- Documented: In writing, stored along with comparable documentation in a way that is accessible to the people who need it and available in case of staff turnover.
- Encryption: The process of transforming information using an algorithm to make it unreadable to anyone except those having special knowledge; often referred to as a key or password.
- Encryption or "cryptographic" key: A mathematic variable required to encrypt and to decrypt encoded data. Examples: keys for full-disc encryption, keys for Web site certificate keys, keys for encryption of backups.
- Endpoint: The device, like a laptop or mobile phone, used by a single person at a time to access other systems. Endpoints are typically used for web browsing and email.
- External Obligation: A specific regulatory, legal, or contractual requirement that applies to a University system or service in addition to its Baseline Protection Level. External Obligations are identified as part of the Security Rating process and recorded as tags alongside the Baseline Protection Level. Each External Obligation triggers a defined set of additional security controls under the Information Security Controls Standard beyond those required by the Baseline Protection Level alone. This structure simplifies the understanding of complex security requirements by separating universal baseline controls from obligation-specific controls, making clear exactly what applies to any given system. External Obligations may also affect the Security Planning Assessment and exception handling processes, and may require additional contract terms with vendors or third parties. Examples include HIPAA, PCI-DSS, and CMMC.
- Incident Handler: An individual authorized by the Chief Information Security Officer (CISO) or acting under the direction of the University Information Security Office (ISO) to perform information security incident response on behalf of UNC-Chapel Hill. Incident Handlers are responsible for managing potential and confirmed Information Security Incidents in accordance with University standards and procedures.
- Individual Account: An arrangement by which a person is given personalized access to University IT. Examples include email, file storage, cloud, phone voicemail, and similar accounts assigned to a single individual person.
- Information Security Incident: A Suspected Information Security Incident that has been confirmed through investigation by the University Information Security Office, involving unauthorized access to or disruption of the availability, confidentiality, or integrity of University data, systems, networks, services, or credentials. An Information Security Incident may trigger internal response processes and reporting obligations under applicable laws, contracts, regulations, or University policies.
- Information Security Office (ISO): Office of the University that operates the Information Security Program under the direction of the Chief Information Security Officer. ISO staff act under the CISO's authority to develop and maintain security policies, standards, and methodologies; conduct investigations; advise units; assess compliance; review and approve Security Planning Assessments and exceptions for High protection level systems; and support implementation of the Information Security Program across the institution. ISO also operates certain Common Controls on behalf of the University, providing shared security capabilities that University systems and services may inherit.
- Information Security Program: The University's institutional program for managing information security risk, established under the authority of the University's Information Security Policy and operated by the Chief Information Security Officer. The program is responsible for coordinating the institution's response to cyber risk; establishing and enforcing security policies, standards, and controls; supporting regulatory compliance; and delivering an annual report on program effectiveness and direction to the Chancellor, Provost, and Board of Trustees. The program operates through a structured family of policies, standards, and procedures that together govern security control objectives, governance processes, and identity and access management across the University. The program aligns with the NIST Cybersecurity Framework and remains responsive to evolving industry standards and professional practices as the threat and regulatory landscape changes.
- Information Sharing Agreement: In the context of Coordination of Security (CoS), a written agreement governing access to and use of information shared within the Coordination of Security program's collaboration space. The agreement is established and maintained by the CISO and is binding on all ISO staff and Delegated Security Authorities with access to the space. It uses the Traffic Light Protocol (TLP) to specify permitted sharing levels for information in the space, ensuring that sensitive security information is shared appropriately across the institution while mitigating the risk of unauthorized disclosure. All participants are required to abide by the agreement as a condition of access.
- Internet Accessible: Systems not protected by border firewalls, Intrusion Protection and Intrusion Detection Systems that are configured in a way that will prevent exploitation of a specific vulnerability, are generally considered "Internet Accessible." If an uncredentialed person can reach the service in a way that they could exploit a Vulnerability from non-University address space, it is "Internet Accessible."
- Intrusion Detection System (IDS): A security service that monitors and analyzes network or system events for the purpose of finding, and providing real-time or near real-time warning of, tries to access system resources in an unauthorized manner.
- Intrusion Prevention System (IPS): Software that has all the capabilities of an intrusion detection system and can also try to stop possible incidents. Systems that watch network or computer activities to spot malicious activity. An IPS will log information, try to stop the activity, and report what it has found. The University implements various IPSs, including web application firewalls. Please contact your local IT admin or ISL if you have questions.
- Key Controls: The four required institutional processes through which the Coordination of Security program is implemented across the University. The Key Controls define the minimum set of actions necessary to manage cybersecurity risk consistently and at scale in a distributed environment. Each Key Control establishes specific obligations for Accountable Persons, Delegated Security Authorities, and the Information Security Office. The Four Key Controls are: Security Risk Management, Security Process, Security Analysis, and Security Communications.
- Least Functionality: Set up systems to only do things they need to do. Preventing the use of unnecessary or insecure functions, ports, protocols, and services. For example, turning off Trivial File Transfer Protocol (TFTP) or peer-to-peer file sharing protocols are examples of least functionality.
- Mission Critical: A system so critical to the mission of the UNC-Chapel Hill business unit that any incident requires immediate response. If a system is considered Mission Critical by the department (which makes that decision), then they will have supplied contact and escalation information in advance of any incident or outage. Heightened information security requirements apply to a mission critical system. The goal is to keep the resource available for use. If a unit does not choose a resource as mission critical, that resource falls to a lower priority to bring services back if there is an incident or outage.
- Obligation to Protect: The University has an obligation to implement reasonable and appropriate administrative, technical, and physical safeguards to protect University networks and systems under its operational control, digital credentials issued by the University, and electronic data within its custody or control. Where third parties receive University data or operate IT systems on the University's behalf, the University must ensure, through contracts or other legally enforceable mechanisms, that such third parties maintain safeguards consistent with applicable law, regulation, and University policy, and provide timely notification of any security incident involving University Data. The Information Security Program's scope is determined by this Obligation to Protect.
- Overlays: See the Minimum Security Standard "Overlays" section.
- Privileged Account: System or Application Administrator accounts. If account privileges allow: changes to security configuration of the system or application; change to authentication or authorization methods used by the system or application; or access to "bulk" Tier 2 or 3 data. The account is "privileged."
- Primary Responsible Person (PRP): The University employee (SHRA or EHRA Permanent) individual who ensures that a device, system, application, service, business process, or third‑party IT agreement (University IT) is properly governed and meets required security controls throughout its lifecycle. The PRP is typically the person who sponsors or has the business need for the system. The PRP need not be an IT professional, they may rely on IT staff, vendors, or others (Responsible Parties, RP's) to perform technical tasks, but remains ultimately responsible for oversight and coordination of security obligations. The person in this role exercises this responsibility by confirming all required security control objectives for the University IT System are assigned to the groups or vendors who will implement these controls, and that no required security control objectives are unassigned. The PRP is responsible for initiating the SPA for a new system or for a system whose security rating has changed. If the IT service supports people outside a single workgroup, the Primary RP also serves as the IT Service Provider. For a personal device containing University Information, the PRP is the University‑affiliated owner or primary user.
- Responsible Party or Person: A Responsible Party or Person is an individual, a University group, or a third party with all or a defined subset of security control objectives for a University IT System. When the University IT System requires Moderate Protection Level or above, third party RPs require binding contract terms governing their security obligations. To complete a SPA, an RP must represent the security for those portions of a University IT System for which they are responsible.
- Secret: A cryptographic key that is used with a (symmetric) cryptographic algorithm that is uniquely associated with one or more entities and is not made public. The use of the term "secret" in this context does not imply a classification level, but rather implies the need to protect the key from disclosure. A password is an example of a secret.
- Security Exception Handling (SEH): The formal process under the Coordination of Security program by which a unit documents and seeks approval for a deviation from a required security control, proposes an alternative implementation that meets the underlying control objective, or formally accepts residual risk where a control cannot be met and no alternative exists. The SEH methodology is defined and maintained by the CISO and made available to DSAs. Approval authority for exceptions is determined by the Baseline Protection Level of the affected system and whether External Obligations apply, with High protection level systems and those with External Obligations requiring ISO review and approval. SEH also processes exceptions to other Information Security Policies and Standards.
- Security Planning Assessment (SPA): The formal process under the Coordination of Security program by which a University unit evaluates a system or service, determines its Security Rating, and confirms the controls required to operate it in compliance with the Information Security Controls Standard. The SPA methodology is defined and maintained by the CISO and made available to DSAs. Completion of a SPA is required for all University systems and services. Approval authority for SPAs is determined by the Baseline Protection Level of the system, with High protection level systems requiring ISO review and final approval. A SPA that is not filed in the CoS collaboration space is not considered complete.
- Security Rating (System Security Rating): A structured classification assigned to a University system or service that fully determines all institutionally-required security controls applicable to that system. The Security Rating is a two-part designation: a Baseline Protection Level (Low, Moderate, or High) and a list of zero or more External Obligations that apply. The Baseline Protection Level determines the set of baseline controls required under the Information Security Controls Standard. Each External Obligation adds a defined set of controls beyond the baseline. The Security Rating is determined as part of the Security Planning Assessment process using a methodology defined and maintained by the CISO. NOTE: Contextualize as "System Security Rating" or otherwise clarify when used anywhere the context might be ambiguous with other types of security.
- Security-relevant patches: Patches addressing identified security vulnerabilities (rather than functional issues).
- Self-service: Some systems with moderate or high protection obligations have roles in which people can access only their own information (like ConnectCarolina "Self-Service.") Some controls do not apply in the same way to people/devices/connections that are limited to self-service access only.
- Sensitive Information: Information classified as Tier 2 or Tier 3 in the UNC-Chapel Hill Information Classification Standard.
- Service Account: (also known as System or Device accounts) are often used by a group of administrators, rather than one person. These accounts are used to run IT services for applications (like Web services, database services, an application account created to run a specific application) or as built-in accounts in an operating system or application (like "root" or "system" or "admin")
- Service Provider: The University employee who is the Primary Responsible Person for an overall IT service throughout its lifecycle. The Service Provider is responsible for the service at the University regardless of where the technology components or professional resources exist. Service providers ensure that their application/system/service is available for use meeting documented service levels (service level agreements or SLAs). IT Service Providers are accountable to the University and to the people using the service.
- Span of Authority (DSA Span of Authority): The scope of a Delegated Security Authority's assigned responsibilities within the Coordination of Security program. A DSA's span of authority defines the University units, systems, services, and personnel for which they are accountable under the Key Controls. Where multiple DSAs are appointed within a single unit, their spans of authority must be clearly defined, non-overlapping, and together cover the Accountable Person's entire organizational scope with no gaps.
- Suspected Information Security Incident: The belief that unauthorized access may have occurred or may be imminent, or that an unauthorized attempt has been made to disrupt the availability of University data, systems, networks, services, or credentials. Only a University Information Security Office authorized Incident Handler may determine that an event is a Suspected Information Security Incident for purposes of this Standard and for the purposes of meeting all external contractual, legal, regulatory, or other compliance obligations. No internal classification or process will delay compliance with legally mandated breach notification requirements.
- Traffic Light Protocol (TLP): A standardized information sharing framework used by the Information Security Office to specify the permitted audience and distribution limits for sensitive security information shared within the Coordination of Security program. TLP designations are assigned to information in the CoS collaboration space to indicate how that information may be used and with whom it may be shared. The protocol uses four color-coded designations — TLP:RED, TLP:AMBER, TLP:GREEN, and TLP:CLEAR — each representing a progressively wider permitted sharing audience. TLP is maintained by the Forum of Incident Response and Security Teams (FIRST) and is widely adopted across the information security community. NOTE: Contextualize with "Information Security Traffic Light Protocol (TLP)" when used in a way that might be ambiguous with the Emergency Management TLP or other TLP.
- University Community Member: Anyone with a University relationship (students, employees, "affiliates," and others. Also, anyone using University information and information technology.
- University Data: any data the University has responsibility to protect. Any data or records created or received in the performance or transaction of University business, except where excluded under the Policy or Standard on University Data Governance. University Data includes, but is not limited to, machine-readable data, data in electronic communication systems, data in print, and backup and archived data on all media.
- University IT: Any device, application, or system that:
- Connects to a University network, or
- Is hosted on an Internet domain registered on behalf of the University, or
- Is used for University purposes, or that
- Stores, processes, or transmits data for which the University is responsible ("University Data")
- University Network: Any wired or wireless network provided by or contracted for the University.
- University Unit: Sometimes called a "Major Operating Unit" this Standard refers to a division or school headed by a Vice Chancellor, Vice Provost, or Dean who reports directly to the Provost or Chancellor. (Every part of the University is part of a "University Unit" as defined here.
- Web Application Firewall (WAF): an application firewall for HTTP applications. A WAF applies a set of rules to an HTTP conversation. Generally, these rules cover common attacks such as Cross-site Scripting (XSS) and SQL Injection. A WAF, to be effective, must be customized to protect its specific application.
Related Requirements
University Policies, Standards, and Procedures
Contact Information
Primary Contacts
ITS Policy Office
Email: its_policy@unc.edu
University Information Security Office
Phone: 919-962-HELP
Web: help.unc.edu