Information Security Policy

Summary

This policy defines the framework and authority for the University of North Carolina at Chapel Hill's Information Security Program. It establishes the institution's commitment to managing information security risk in a coordinated way across a distributed, risk-diverse environment.

Body

University Policy

Title

University of North Carolina at Chapel Hill Policy on Information Security

Introduction

Purpose

This policy defines the framework and authority for the University of North Carolina at Chapel Hill's ("University" or "UNC-Chapel Hill") Information Security Program. It establishes the institutional commitment to managing information security risk in a coordinated way across a distributed and risk-diverse environment. The policy authorizes the creation and enforcement of supporting policies, standards, and procedures necessary to protect University information and technology resources. The structure of those supporting documents is described in the Supporting Policy Documents section of this policy.

Scope

This policy applies to all members of the University community, including faculty, staff, students, affiliates, contractors, and third parties acting on behalf of the University. It applies to all University units. For other organizations closely connected with the University such as Affiliated Entities (AE), this policy applies only to those operations and resources that fall within the University's obligation to protect.

It governs all data, systems, services, networks, electronic devices, and credentials for which the University of North Carolina at Chapel Hill has a formal obligation to protect, regardless of ownership or location. These obligations may arise from:

  • Legal, regulatory, or contractual requirements;
  • Institutional commitments;
  • Reputational risk; and
  • The need to preserve the security, availability, and integrity of University infrastructure.

Examples include, but are not limited to:

  • University data stored in third-party IT services regardless of how the IT service is procured;
  • Personally owned devices connected to the University network;
  • Vendor-managed systems that process University-regulated data; and
  • Credentials that access University systems or services.

The scope of the security program is determined by whether the University has an obligation to protect the resource or information. The determination of protection obligation accounts for factors including regulatory requirements, contractual commitments, institutional risk, and potential reputational harm. How these factors are assessed and how protection levels are assigned is defined in the supporting policy documents.

Business continuity and disaster recovery are addressed through separate institutional functions and are not governed by this policy.

Policy

Policy Statement

UNC-Chapel Hill operates in a highly distributed environment. Schools, departments, and administrative units vary significantly in their technology use, mission requirements, and risk exposure. The University's Information Security Program is designed for this reality: it establishes common requirements and governance structures that apply institution-wide while accommodating the distributed nature of how technology is operated and controlled.

The University requires that information and technology resources for which it has an obligation to protect be managed in accordance with this policy and its supporting standards. Every member of the University community shares responsibility for the security of University information and systems within the scope of their role and access.

Authority and Program Oversight

This policy implements the University's obligations under UNC System Policy 1400.1, which requires each constituent institution to establish and maintain an information security program consistent with industry standards. The Chancellor has delegated authority to the University's Chief Information Security Officer (CISO) to issue and enforce information security policies, standards, and procedures on behalf of the University.

The program is responsible for:

  • Coordinating the institution's response to cyber risk;
  • Establishing and enforcing common security policies, standards, and controls;
  • Supporting regulatory compliance efforts;
  • Delivering an annual report on the security program to the Chancellor, Provost, and Board of Trustees; and
  • Representing the University's security posture to auditors, regulators, and other external parties as required.

The program aligns with the NIST Cybersecurity Framework and incorporates practices from other recognized professional standards as appropriate.

The annual report to the Board of Trustees will document:

  • The current security strategy and roadmap;
  • Execution status of the commitments made in the prior report;
  • Material changes in the threat landscape, technology environment, regulatory and compliance requirements, and institutional context that bear on security strategy; and
  • The security program's commitments for the coming reporting cycle.

Policy Authority and Review

All information security policies, standards, and procedures issued under the Information Security Program derive their authority from this policy. Supporting policies, standards, and procedures are issued by the CISO and are binding and enforceable under this Policy.

This policy and all supporting documents are subject to periodic review. The Information Security Program will reassess and update policies, standards, and procedures as the threat environment, regulatory landscape, and program priorities require, and no less than every three years.

Program Roles and Responsibilities

The following roles are foundational to the operation of the University's Information Security Program and are used throughout the University's information security policies and standards.

Chief Information Security Officer: Accountable for operating the Information Security Program for the University and reporting on its effectiveness and future direction to the Chancellor, Provost, and Board of Trustees.

Deans and Vice-Chancellors: Accountable for security outcomes within their unit, including ensuring their unit operates in compliance with the requirements of the University's Information Security Program.

Delegated Security Authority (DSA): Appointed by a Dean or Vice-Chancellor to implement the Key Controls within the unit on their behalf, as defined in the Coordination of Security Standard.

Responsible Person or Party: Every IT device, application, system, service, data set, business process making use of University IT, and third-party agreement for University IT systems or services must have at least one Responsible Person (RP). The RP is a person in a University relationship, not a third-party entity. The RP may rely on IT teams or vendors to perform technical work, but oversight obligations remain with the RP throughout the lifecycle. The division of RP responsibility must be documented. The RP is not required to be a technical administrator. For personal devices used for business purposes or containing University Information, the Responsible Person is the University-associated owner or main user of the device. The RP must ensure that required security controls are implemented as defined in the Information Security Controls Standard (MSS).

A Primary Responsible Person may delegate a portion of their responsibilities to another individual, who then assumes Responsible Person obligations for that scope. Delegation does not relieve the delegating Responsible Person of obligation to ensure the overall security of the system or service. Each Responsible Person must carry out obligations assigned to them under this Policy unless responsibility has been expressly allocated or shared with another Responsible Person.

A "primary" Responsible Person for any University IT that has a Moderate or High obligation rating must be a permanent University employee or employee of an Affiliated Entity (Employee). That person must be able to ensure the work of any non-University employee Responsible Persons meets requirements.

IT Service Provider: A permanent University Employee who is the primary Responsible Person for a discrete IT service provided to people beyond an individual University workgroup. Service Providers have extra obligations reflected in the Information Security Controls Standard (MSS). For large and complex services, multiple Responsible Persons may collaborate to identify areas of responsibility, but a single point of contact for any discrete functional "IT Service" must be identified. While others may be operational points of contact, the Service Provider is in the escalation for cybersecurity issues with the service.

Information Security Office (ISO) Staff: Act under the CISO's authority to conduct investigations, advise units, assess compliance, review exceptions, and support implementation across the institution.

University Community Member: Any individual who operates on University network infrastructure, holds or uses a University-issued credential, or accesses data that the University has provided or to which the University has granted access where that data carries an obligation to protect -- regardless of employment status, organizational affiliation, or device ownership. This includes but is not limited to students, faculty, staff, contractors, vendors, guests, and individuals affiliated with associated or connected entities. All University Community Members must comply with applicable University information security policies, standards, acceptable use requirements, and completion of assigned training when working within this scope. Individuals who connect personally owned devices to University network infrastructure or use them to access University systems or data are responsible for the security of those devices following applicable standards.

Supporting Policy Documents

This policy is supported by a structured family of documents organized into three categories:

Control Objectives: Centered on the Information Security Controls Standard, which defines the required security safeguards for systems, services, and data the University is obligated to protect.

Governance Processes: Centered on the Coordination of Security Standard, which defines the governance structures, roles, and operational requirements necessary to implement the Information Security Program across the University's distributed environment.

Identity and Access: Will define the University's models for managing the identity of people with relationships to the University and governing their access to University systems and data. These standards are under development as part of the Authentication Modernization Initiative.

Enforcement and Oversight

Violations of this policy will result in a response fitting the role, circumstances, and severity of the incident. Responses may include revocation of access, corrective action, or disciplinary measures up to and including termination of employment or termination of a business relationship with the University.

The CISO may:

  • Investigate suspected violations and security incidents;
  • Access system logs and related data, consistent with applicable law and University policy;
  • Take immediate protective action -- including isolation of systems or revocation of access -- when necessary to contain an active security incident, without prior approval; and
  • Coordinate with law enforcement and regulatory bodies as necessary.

Exceptions

All exceptions, deviations, and risk acceptance for those deviations from this Policy, or those policies, procedures, and standards established under this Policy are subject to the authority of the University's Chief Information Security Officer. Written exception and deviation processes for routine exceptions are established by the Information Security Office. Urgent exceptions or those not in scope of any defined exception process may be made in writing by the Chief Information Security Officer.

University information security policies and standards establish default requirements. Units may request exceptions to these requirements, propose alternative implementations that deviate from the default while still meeting the underlying control objective, or formally accept residual risk where a requirement cannot be met. All such requests are subject to defined exception and deviation processes to ensure appropriate institutional oversight.

All exceptions and deviations must be reviewed by the unit's Delegated Security Authority and filed with the Information Security Office. The CISO determines, based on the nature and risk of the request, whether additional review by ISO or approval by the relevant Dean or Vice-Chancellor is required. The process for submitting and evaluating exceptions and deviations is maintained by the ISO.

All approved exceptions and deviations must be documented in writing, granted for a defined period, and reviewed periodically. They do not constitute permanent relief from the underlying requirement.

Definitions

Please see the University's Information Security Defined Terms Standard.

Related Requirements

External Regulations and Consequences

Compliance

Failure to comply with this policy may put University information assets at risk and may have disciplinary consequences for employees, up to and including termination of employment. Students who fail to adhere to this policy may be referred to the UNC-Chapel Hill Office of Student Conduct. Contractors, vendors, and others who fail to adhere to this policy may face termination of their business relationships with UNC-Chapel Hill.

Violation of this policy may also carry the risk of civil or criminal penalties.

University Policies, Standards, and Procedures

Contact Information

Policy Contact

Unit: ITS Policy Office

Phone: 919-962-HELP

Email: its_policy@unc.edu

Other Contacts

Guidance on Specific Requests

Reach out to the ITS Policy Office (919-962-HELP or its_policy@unc.edu), or check out the resources on help.unc.edu.

Important Dates

  • Effective Date and title of Approver:
    1. Effective Date: 6/30/2010
    2. Approver: Chief Information Officer
  • Revision and Review Dates, Change notes, title of Reviewer or Approver:
    1. Last Revised Date: 10/24/2017
    2. Revised by: Chief Information Officer
    3. Substantive Revisions:
      1. Complete revision
  • Dates after this point are maintained in the University policy repository.

Details

Details

Article ID: 131258
Created
Thu 4/8/21 9:04 PM
Modified
Fri 8/21/26 1:16 PM
Responsible Unit
School, Department, or other organizational unit issuing this document.
Information Technology Services
Issuing Officer
Name of the document Issuing Officer. This is the individual whose organizational authority covers the policy scope and who is primarily responsible for the policy.
Issuing Officer Title
Title of the person who is primarily responsible for issuing this policy.
Vice Chancellor for Information Technology and Chief Information Officer
Next Review
Date on which the next document review is due.
08/21/2029 12:00 AM
Last Review
Date on which the most recent document review was completed.
08/21/2026 12:00 AM
Last Revised
Date on which the most recent changes to this document were approved.
08/21/2026 12:00 AM
Effective Date
If the date on which this document became/becomes enforceable differs from the Origination or Last Revision, this attribute reflects the date on which it is/was enforcable.
08/21/2026 12:00 AM
Origination
Date on which the original version of this document was first made official.
06/30/2010 12:00 AM
Flesch-Kincaid Reading Level
18.3

Related Articles

Related Articles (5)

The UNC-Chapel Hill Adams School of Dentistry has a legal and ethical responsibility to safeguard patient information. This responsibility includes ensuring that devices storing Protected Health Information ("PHI") or other Sensitive Information are properly encrypted and are serviced by an appropriate vendor. The purpose of this Policy is to ensure that all Computing Devices used by students will meet institutional security requirements.
Some University business units operate their own email systems. Email accounts used to conduct the business of the University require that appropriate security, backup, and records-retention measures be in place. Departments may host or contract for separate email systems using either unc.edu sub-domains (such as "physics.unc.edu") or entirely separate domains (such as "unclatindepartment.org"). This Policy addresses requirements for these units.
All members of the University community who engage with any University information technology (including wireless or other networks) must adhere to this Acceptable Use Policy.
Failure to protect information through the use of strong passwords/pass-phrases and additional authentication methods may result in incidents that expose sensitive information and/or impact mission-critical UNC-Chapel Hill services. This Standard outlines minimum requirements for authentication mechanisms for information systems under the University's control and password strength and other requirements for accounts on University systems and accounts that use University data.
This standard sets a minimum baseline for managing vulnerabilities on any UNC-Chapel Hill system required by the UNC-Chapel Hill Information Security Controls Standard to be scanned for vulnerabilities. Please see the “Exceptions” section for phased implementation through 2026.