Coordination of Information Security Standard

Summary

This Standard describes the way that the Information Security Program is distributed and coordinated between the central Information Security Office and campus units. The Standard sets out roles and responsibilities, basic process requirements, and authorities granted to people acting within the Program

Body

University Standard

Title

University of North Carolina at Chapel Hill Standard on Coordination of Information Security

Introduction

Purpose

This Standard defines the Coordination of Security (CoS) program -- the University's operating model for cybersecurity governance in a distributed environment. CoS establishes how security accountability is assigned, how required security processes are implemented across University units, and how the institutional security program and individual units coordinate to manage risk effectively. It is the mechanism through which the University's Information Security Program operates at an institutional scale.

Scope

This Standard applies to all University units and their leadership, and to all individuals with assigned roles under the Coordination of Security program, including Accountable Persons, Delegated Security Authorities, Responsible Persons, and IT Service Providers. It applies to the coordination of information security governance across all University operations and Affiliated Entities.

Standard

Roles

Chief Information Security Officer

Under the Coordination of Security program, the CISO is responsible for:

  • Administering the annual Key Controls Attestation;
  • Meeting with each DSA at least annually to review unit security performance data and risk concerns, and to communicate institutional security program direction and its implications for the unit;
  • Training DSAs on required CoS processes and providing documentation necessary to carry them out;
  • Producing and reporting unit-level Key Control performance data and CoS program metrics that inform the CISO's annual report to the Chancellor, Provost, and Board of Trustees.

Accountable Persons

An Accountable Person (AP) is a Dean or Vice Chancellor, or any other University leader identified by the CISO as necessary to ensure complete coverage of the University and its Affiliated Entities. Together, the set of Accountable Persons spans the full institutional authority structure with minimum overlap. The set of Accountable Persons is confirmed annually by the CISO as part of the Key Controls Attestation.

Under the Coordination of Security program, each Accountable Person is responsible for:

  • Designating one or more Delegated Security Authorities to implement the Key Controls within their unit and to serve as the coordination point between the unit and ISO. The DSAs designated by an AP must together cover the AP's entire span of authority with no gaps;
  • Setting information security priorities and allocating resources sufficient for their unit to meet program requirements;
  • Meeting directly with their DSA at least annually to review unit security performance, risks, and resource needs. This meeting may not be delegated by either the DSA or the Accountable Person;
  • Participating in the annual Key Controls Attestation at the joint cabinet level, formally affirming their security accountability and the designation of their DSA.

Delegated Security Authorities

The Delegated Security Authority (DSA) is a University employee appointed by an Accountable Person to implement the Key Controls within the unit and to serve as the primary coordination point between the unit and the Information Security Office. The DSA acts on behalf of the Accountable Person in all matters relating to the CoS program.

If more than one DSA is appointed for a unit, their areas of responsibility must be clearly defined, non-overlapping, and together cover the AP's entire span of authority.

The DSA has a coordination and accountability role. The DSA is responsible for ensuring that the Key Controls are implemented and operational within their unit. This does not require the DSA to personally execute all work associated with the Key Controls -- that work may be delegated to others within the unit or performed with ISO support. The DSA may identify and nominate other University employees to assist with the implementation of the Key Controls. What may not be delegated is the DSA's accountability for ensuring the work is done, that it meets program requirements, and that results are reported accurately.

Under the Coordination of Security program, each DSA is responsible for:

  • Implementing the Four Key Controls within their span of authority, or ensuring they are implemented by others;
  • Reporting Key Control performance data to their Accountable Person and to the CISO;
  • Meeting directly with their Accountable Person at least annually to report on unit security status, risks, and resource needs;
  • Meeting with the CISO at least annually as required under Key Control One;
  • Serving as the primary two-way coordination point between their unit and ISO;
  • Documenting Key Control implementation within their span of authority and filing all required documentation in the shared CoS resource space maintained by ISO. Documentation that is not properly filed is not considered complete.

Responsible Persons and IT Service Providers

Responsible Persons and IT Service Providers operate within the CoS framework as defined in the Information Security Policy. Within their unit, they are required to comply with the CoS implementation procedures established by their DSA, including participation in security planning assessments and exception processes as required under Key Control Two.

Key Controls

The work of the Coordination of Security program is defined through four required institutional processes known as the Four Key Controls. Together, these controls represent the minimum set of actions necessary to manage cybersecurity risk consistently and at scale across the University's distributed environment. Each Key Control establishes specific obligations for the roles defined in this Standard. The Four Key Controls are: Security Risk Management, Security Process, Security Analysis, and Security Communications.

Key Control One: Security Risk Management

Key Control One establishes the governance cadence through which cybersecurity accountability is reinforced at every level of the institution. It ensures that security risk information reaches the appropriate decision-makers, that resource and prioritization decisions are made at the right level of authority, and that the institutional security program and individual units remain aligned.

Key Control One requires three recurring governance mechanisms:

Annual Key Controls Attestation: The Chancellor convenes an annual review of CoS obligations at the joint cabinet level. At this meeting, Accountable Persons formally affirm their security accountability and confirm the designation of their Delegated Security Authorities. The CISO administers this process.

Annual DSA and Accountable Person Meeting: Each DSA meets directly with their Accountable Person at least once annually. The purpose of this meeting is to review unit security performance, material risks, and any decisions requiring the accountable person's authority including risk acceptance, resource allocation, and prioritization. This meeting may not be delegated by the accountable person or the DSA.

Annual DSA and CISO Meeting: Each DSA meets with the CISO at least once annually. The purpose of this meeting is for the CISO to share institutional security program direction and its implications for the unit, and for the DSA to present unit risk concerns and security performance data. This data informs the CISO's reporting to the Chancellor, Provost, and Board of Trustees.

Key Control Two: Security Process

Key Control Two governs how University systems are assessed for security risk and how exceptions to security requirements are handled. It establishes consistent, institution-wide processes for both functions while distributing approval authority to the DSA level for most cases. This distribution is how CoS scales security governance across the University without creating a bottleneck through a single central team.

Security Planning Assessment (SPA)

The CISO defines and maintains the Security Planning Assessment (SPA) methodology and makes it available to DSAs. DSAs are required to complete ISO training on the SPA methodology before conducting or approving assessments.

The DSA is responsible for ensuring that SPAs are completed for all systems within their span of authority in accordance with the methodology. The DSA is not required to personally conduct every SPA -- that work may be performed by Responsible Persons or others within the unit. The DSA is responsible for the quality and accuracy of all SPAs completed within their span of authority.

The CISO defines and maintains the Security Rating methodology for University technology as part of the SPA. This methodology establishes a baseline protection level -- Low, Moderate, or High -- for each system, along with a list of identified External Obligations which apply. Together, the baseline protection level and external obligations ("Security Rating") fully determine all institutionally-required security controls for the system. In addition, the baseline protection level assigned to a system determines the approval authority for SPAs and exceptions under this Standard.

Low protection level systems follow the SPA methodology as guidance to the Responsible Person. DSA involvement is not required unless the unit determines otherwise.

For Moderate protection level systems, the DSA reviews, adjusts as needed, and provides final approval of the SPA. The DSA has full approval authority for Moderate systems. Approved SPAs must be filed in the shared CoS resource space. A SPA that is not filed is not considered complete.

For High protection level systems, the DSA reviews and adjusts the SPA as needed, then submits it to ISO for secondary review and final approval. The DSA may not provide final approval for High protection level systems. ISO will complete its secondary review and provide written sign-off or a documented reason for rejection to the DSA within two business days of submission. ISO approval is required before the SPA is considered complete.

Security Exception Handling

The CISO defines and maintains the Security Exception Handling (SEH) methodology. The DSA must adopt the SEH methodology within their span of authority.

When a required security control cannot be implemented as specified, or when a unit proposes an alternative implementation, an exception must be documented and reviewed. When a control cannot be met and no alternative exists, the unit may formally accept the residual risk through the same process.

For Moderate protection level systems with no additional obligations, the DSA reviews exception requests and has final approval authority. Approved exceptions must be filed in the shared CoS resource space. An exception that is not filed is not considered approved.

For High protection level systems or those with additional external obligations, the DSA reviews the exception request and submits it to ISO for secondary review and final approval. The DSA may not provide final approval for High protection level systems. ISO will complete its secondary review and provide written sign-off or a documented reason for rejection to the DSA within two business days of submission. The DSA may implement interim measures while ISO review is pending.

In all cases, exceptions must document compensating controls where available and specify whether the exception is temporary or permanent. All approved exceptions are subject to periodic review and do not constitute permanent relief from the underlying requirement.

Key Control Three: Security Analysis

Key Control Three establishes DSAs as the formal voice of their unit in the evolution of the institutional security program. It creates a disciplined mechanism for the CISO to gather unit-level information and for units to influence program direction. The absence of this control would leave the security program without a reliable feedback loop and units without a formal channel to shape requirements that affect them.

ISO will use periodic requests — including structured questionnaires and other methods — to gather information on specific security topics, assess the feasibility and impact of proposed program changes, and evaluate whether systemic risks warrant new or improved common controls. When ISO identifies a stakeholder group of DSAs from which a complete response is needed, members of that group must respond. ISO is responsible for ensuring requests are clearly scoped, providing sufficient context for DSAs to respond accurately, and allowing a reasonable response window. Incomplete responses limit the CISO's ability to make informed program decisions and to advocate effectively for resources and common controls that reduce unit burden.

DSAs are responsible for proactively raising unit-specific risk concerns and operational constraints to the CISO, particularly where those concerns may have implications beyond their unit. The annual DSA and CISO meeting required under Key Control One serves as a standing opportunity for DSAs to raise such concerns, and DSAs should not wait for that meeting when a concern is time-sensitive.

The CISO is responsible for documenting how unit feedback has been considered when making material changes to program requirements. This does not require the CISO to act on every concern raised but does require that unit input is demonstrably part of the decision process.

Key Control Four: Information Security Communication

Key Control Four governs how cybersecurity information flows between ISO and University units and establishes the collaboration infrastructure through which ISO and DSAs work together. It has two components.

Structured Security Communications

The CISO defines and maintains a set of standard security communication types. Each type specifies its purpose, intended audience, urgency level, and any restrictions on sharing. This list is published and made available to all DSAs.

For each communication type requiring DSA involvement, the DSA and ISO will agree in advance on how that communication will be delivered and acted upon within the unit. This agreement must be established during DSA onboarding and reviewed at least every two years, or within six months of a new DSA being appointed.

The DSA is responsible for maintaining an operational playbook within their unit for each communication type. The playbook ensures that when a communication is received, the unit can act on it promptly and consistently without requiring ad hoc coordination.

ISO is responsible for ensuring that all structured security communications are succinct, necessary, and actionable. The goal is to make clear and comprehensive security communication routine and operationally straightforward for units.

CoS Collaboration Space

ISO will maintain a shared collaboration space for ISO and DSAs. This space serves as the common repository for program documentation, communication templates, training materials, and filed security artifacts required by this Standard.

Access to the collaboration space is governed by an information sharing agreement established and maintained by the CISO. The agreement uses the Traffic Light Protocol (TLP) to specify permitted sharing levels for information in the space. The agreement is binding on all participants and is designed to facilitate the appropriate sharing of sensitive security information across the institution while mitigating the risk of inappropriate disclosure. All DSAs and ISO staff with access to the space are required to abide by the information sharing agreement.

Timeline

The Coordination of Security program was introduced in the January 2025 Annual Information Security Update to the Board of Trustees and has been under active implementation since that time.

As of January 1, 2026, all provisions of this Standard are in effect with the following exceptions:

  • Key Control One -- the governance cadence requirements are established, and the first full annual execution cycle will be completed in 2026.
  • Key Control Two -- the Security Planning Assessment and Exception Management processes are in a phased rollout. Implementation plans are in place, and execution is underway.

Key Controls Three and Four are fully operational as of the effective date of this Standard.

By January 1, 2027:

  • Key Control One will be fully executed and part of the operational cadence of the program.
  • Key Control Two will have completed the following: the SPA and SEH methodology documentation; planning changes to impacted organizational processes including data governance and procurement; DSA training on both methodologies; and initial implementation scope planning with each DSA. Beginning in 2027, ISO will work with each DSA annually to expand KC2 implementation scope within their unit until full unit coverage is achieved.

Exceptions

Every University unit must have a Delegated Security Authority designated by its Dean or Vice Chancellor and is required to implement the Four Key Controls. Exceptions to this requirement are not expected. Where exceptional circumstances exist, the CISO may grant a documented exception. Any such exception must be filed in the CoS collaboration space, granted for a defined period, and reviewed periodically. An exception that is not documented and filed is not considered granted.

Definitions

Please see the Information Security Defined Terms Standard.

Related Requirements

External Regulations

Compliance

Failure to comply with this policy may put University information assets at risk and may have disciplinary consequences for employees, up to and including termination of employment. Students who fail to adhere to this policy may be referred to the UNC-Chapel Hill Office of Student Conduct. Contractors, vendors, and others who fail to adhere to this policy may face termination of their business relationships with UNC-Chapel Hill.

Violation of this policy may also carry the risk of civil or criminal penalties.

University Policies, Standards, and Procedures

Contact Information

Primary Contact

Name: ITS Policy Office

Email: its_policy@unc.edu

Other Contacts

Subject: Security activity under this Standard

Name: Information Security Office

Online: help.unc.edu

Email: security@unc.edu

Details

Details

Article ID: 163637
Created
Mon 7/20/26 4:42 PM
Modified
Fri 8/21/26 12:08 PM
Responsible Unit
School, Department, or other organizational unit issuing this document.
Information Technology Services - Information Security Office
Issuing Officer
Name of the document Issuing Officer. This is the individual whose organizational authority covers the policy scope and who is primarily responsible for the policy.
Issuing Officer Title
Title of the person who is primarily responsible for issuing this policy.
Chief Information Security Officer
Policy Contact
Person who handles document management. Best person to contact for information about this policy. In many cases this is not the Issuing Officer. It may be the Policy Liaison, or another staff member.
Next Review
Date on which the next document review is due.
08/21/2029 12:00 AM
Effective Date
If the date on which this document became/becomes enforceable differs from the Origination or Last Revision, this attribute reflects the date on which it is/was enforcable.
08/21/2026 12:00 AM
Origination
Date on which the original version of this document was first made official.
08/21/2026 12:00 AM
Flesch-Kincaid Reading Level
14.6