Search26 Results

The University has obligations to ensure integrity and accessibility of records, and security of sensitive University information that may be sent or received via email. This policy advises individuals of their obligations to use only their University email account and not personal email accounts for University business and to manage the records resulting from that use in accordance with applicable policy, standards, and procedures.
Some University business units operate their own email systems. Email accounts used to conduct the business of the University require that appropriate security, backup, and records-retention measures be in place. Departments may host or contract for separate email systems using either unc.edu sub-domains (such as "physics.unc.edu") or entirely separate domains (such as "unclatindepartment.org"). This Policy addresses requirements for these units.
To guide University Constituents in preserving the integrity, confidentiality, and availability of University information and information systems. Access controls are intended to minimize inappropriate exposure of University information by limiting system access to authorized individuals.
The University of North Carolina at Chapel Hill (“University”) has a strong interest in the integrity, confidentiality, and availability of University information and systems. Access controls protect University information by only allowing authorized people to access systems. Following this policy minimizes risk to the University resulting from unauthorized use of resources. Access control at the University happens through procedures and standards that follow this policy.
The Onyen ("Only Name You'll Ever Need") is a unique identifier given to everyone affiliated with the University. The Onyen gives each person secure access to electronic resources and proves their identity if they follow this policy.
The University's Information Security Office is working to make the Information Security Program more consistent and clear. This Standard provides definitions that will apply to all Information Security Policies, Standards, and Procedures as they are updated to refer to it.
This policy defines the framework and authority for the University of North Carolina at Chapel Hill's Information Security Program. It establishes the institution's commitment to managing information security risk in a coordinated way across a distributed, risk-diverse environment.
The University is committed to establishing a welcoming and equitable digital experience. This policy provides direction on creating an accessible experience that enhances usability for everyone. Implementing this policy will ensure that all individuals have access to Digital Content, Resources, and Technology (“Digital Material”) provided by or on behalf of the University.
This Standard provides requirements for the procurement of accessible Digital Content, Resources, and Technology (“Digital Material”). Implementing this standard will ensure that all individuals have access to Digital Material purchased by or on behalf of the University in compliance with the Policy on Digital Accessibility and with governing law.
This Standard sets out the minimum requirements for creating accessible Digital Content, Resources, and Technology (“Digital Material”) to advance the University’s commitment to providing equitable access in compliance with the University Policy on Digital Accessibility. Accessibility is a shared responsibility among those who maintain University Digital Material.
This policy defines a listserv, explains that the School of Government manages listservs to help local government officials share information with peers and faculty, and provides technical resources.
This Standard defines the minimum security standards “MSS” for Information Technology systems in use at UNC-Chapel Hill including personal and University-owned devices and third-party systems. Units within the University may apply stricter controls to protect information and technology in their areas of responsibility. The standard applies to each person in the University community and their devices. Please see the “Exceptions” section for phased implementation options through 2027.
To describe minimum requirements for members of the University of North Carolina at Chapel Hill ("University" or "UNC-Chapel Hill") experiencing a concern that might indicate a Possible Information Security Incident. To specify Information Security Incident authority and role requirements for Information Security Incident Handlers and Information Security Liaisons.
This policy sets up a framework for protecting University data. This framework: gives responsibilities to the stewards, managers, and custodians of University data; empowers the Enterprise Data Coordinating Committee (EDCC) to give advice about the best way to manage and protect enterprise data that still meets the University’s needs; and charges the EDCC with recommending standards and procedures for governing enterprise data.
This policy describes the terms required for use of ConnectCarolina, InfoPorte, associated reporting tools, and other University business applications (“Administrative Systems”).