Information Security Team
Information Security Policies and Standards site. Click the "Standards History" on left menu to view current Information Security Policies and Standards.
Wendy Wilde, CISSP, CISM, MSIT, | Information Security Officer & GLBA Program Officer
757-594-0704 | wendy.wilde@cnu.edu
Karl Anderson, CISSP, MSIT, | Information Security Analyst
757-594-0708 | karl.anderson@cnu.edu
2024 Security Awareness Training Due December 31. 2024:
Christopher Newport Information Security Policies and Standards
GROUP | TYPE | NAME | RESPONSIBLE | LAST UPDATE/REVIEW |
VITA | POLICY | VITA SEC-530 Information Security Standard | VITA | September 2023 |
VITA | POLICY | VITA SEC-520 Risk Management Standard | VITA | December 2021 |
VITA | POLICY | VITA SEC-527 Security Awareness Training Standard | VITA | December 2022 |
ACCOUNT MANAGEMENT | STANDARD | Account Management Standard | INFORMATION SECURITY | June 2024 |
ACCOUNT MANAGEMENT | STANDARD | University Password Standard | INFORMATION SECURITY | June 2024 |
ACCOUNT MANAGEMENT | GUIDELINE | Local Administrative Privileges | INFORMATION SECURITY | June 2024 |
ACCOUNT MANAGEMENT | PROCEDURE | Account Management | INFORMATION SECURITY | June 2024 |
ACCOUNT MANAGEMENT | PROCEDURE | VPN Account Management | INFORMATION SECURITY | June 2024 |
ACCOUNT MANAGEMENT | PROCEDURE | Firewall Account Management | INFRASTRUCTURE | June 2024 |
ACCOUNT MANAGEMENT | PROCEDURE | Banner Account Management | SYSTEMS & DATABASE OPERATIONS | June 2023 |
DATA GOVERNANCE | STANDARD | Data Access Standard | INFORMATION SECURITY | June 2024 |
DATA GOVERNANCE | STANDARD | Data Classification Standard | INFORMATION SECURITY | June 2024 |
DATA GOVERNANCE | STANDARD | Data Protection Standard | INFORMATION SECURITY | June 2024 |
DISASTER RECOVERY | STANDARD | ITS Disaster Recovery Plan (DRP) | ITS LEADERSHIP | June 2024 |
DISASTER RECOVERY | PROCEDURE | Banner Disaster Recovery | SYSTEMS & DATABASE OPERATIONS | June 2024 |
ENTERPRISE SERVICES | STANDARD | Software Development Standard & Roadmap | ENTERPRISE SERVICES | January 2023 |
GLBA | STANDARD | GLBA Information Security Program | INFORMATION SECURITY | June 2024 |
INCIDENT RESPONSE | STANDARD | Security Incident Response Plan | ITS LEADERSHIP | June 2024 |
INCIDENT RESPONSE | PROCEDURE | Security Incident Response Plan Guidelines & Procedures | ITS LEADERSHIP | June 2024 |
NETWORK | STANDARD | Network Firewall Standard | INFRASTRUCTURE | June 2024 |
NETWORK | STANDARD | Remote Access & VPN Standard | INFRASTRUCTURE | June 2024 |
POLICIES | POLICY | 6010 Acceptable Use of Computing Resources | ITS LEADERSHIP | July 2024 |
POLICIES | POLICY | 6015 Unified Data Policy | ITS LEADERSHIP | July 2024 |
POLICIES | POLICY | 6035 Information Technology Change Management | ITS LEADERSHIP | July 2024 |
POLICIES | POLICY | 6040 Remote Access & Virtual Private Network Policy | ITS LEADERSHIP | July 2024 |
POLICIES | POLICY | 6045 Information Security Policy | ITS LEADERSHIP | July 2024 |
RISK MANAGEMENT | STANDARD | Risk Assessment Standard | INFORMATION SECURITY | June 2024 |
RISK MANAGEMENT | STANDARD | Third Party Vendor Risk Management Standard | INFORMATION SECURITY | June 2024 |
RISK MANAGEMENT | STANDARD | Business Continuity Plan (BCP) | INFORMATION SECURITY | DRAFT |
RISK MANAGEMENT | PROCEDURE | Risk Assessment Guidelines & Procedures | INFORMATION SECURITY | June 2024 |
RISK MANAGEMENT | POLICY | Third Party Vendor Risk Mangement Procedures | INFORMATION SECURITY | June 2024 |
SYSTEMS & DESKTOP | STANDARD | Systems Monitoring & Logging Standard | INFORMATION SECURITY | June 2024 |
SYSTEMS & DESKTOP | STANDARD | Systems & Software Patching Standard | INFORMATION SECURITY | June 2024 |
SYSTEMS & DESKTOP | STANDARD | Vulnerability Assessment & Management Standard | INFORMATION SECURITY | June 2024 |
SYSTEMS & DESKTOP | STANDARD | Encryption Standard | INFORMATION SECURITY | June 2024 |
SYSTEMS & DESKTOP | GUIDELINE | ITS Systems & Application Hardening Guidelines | SYSTEMS & DATABASE OPERATIONS | March 2020 |
SYSTEMS & DESKTOP | PROCEDURE | ITS System Logging Procedures | SYSTEMS & DATABASE OPERATIONS | February 2023 |
TRAINING | STANDARD | Security Awareness Training Standard | INFORMATION SECURITY | June 2024 |
TRAINING | STANDARD | Role Based Security Training Standard | INFORMATION SECURITY | June 2024 |