
OIT Policies & Procedures
Policies
There are several different types of IT security documents governing and guiding how we secure our information across all of CU. IT security documents can be:
- System-level policies or CU Administrative Policy Statements (APS)
- Campus-wide policies (APS)
- IT Department guidelines, plans or procedures (sometimes loosely referred to as “IT policies”)
- Organizational unit (department, office, program, etc.) operating procedures and standards (also sometimes referred to as “departmental policies”)
UCCS IT Security Policies
UCCS has several campus-wide IT security policies. These have gone through the formal UCCS approval process, are designated with a specific policy number (700 series), and apply across the whole Colorado Springs campus. These policies can be found under the Information Technology heading (700 series)at the Office of the Vice Chancellor for Administration and Finance website.
They are:
- 700-001 E-Mail as Official Means of Communication
- 700-002 Responsible Computing
- 700-003 Information Technology
- 700-004 Wireless Network
- 700-005 Information Security Incident Response (Revised May 2024)
- 700-006 Computer and Electronics Disposal
- 700-008 Digital Accessibility
UCCS IT Department Security Documents
IT Department “policies” are not formally approved APS’s, but are IT’s rules for IT resource usage. These are statements about the way IT operates its labs, controls access to IT resources and what activities are and are not allowed on UCCS IT resources. Many of these “policies” are helpdesk help sheets.
Some important IT department security documents are:
- Using VPN – Securely connecting to the campus network from off-campus.
- Email Security and Virus Information – Tips on staying safe when using email.
- Electronic Mail Usage – Requirements on how and how not to use UCCS email.
- Library Computer User Policy – Responsibilities and expectations while using Kraemer Family Library computers.
- UCCS Copyright Infringement Statement and CU Boulder Illegal File Sharing Information site – Warnings against and consequences for illegal downloading and/or sharing of copyrighted material.
- UCCS IT Minimum Security Standard - Guidelines and standards for implementing technology
Organizational Unit Security Documents
Some UCCS organizational units are required by the Payment Card Industry (PCI) to have some written procedure or statement about the rules and decisions that govern how they secure their information, such as the Bursar’s office and the Campus Store. Even if not required, it is a good idea for organizational units to have these types of documents. Although in some places they may be referred to as internal “policies,” they are not official policies and thus should be called by a different name. Operating procedures, guidelines, measures, standards – these are all appropriate names. A good example of an organizational unit’s internal security document can be found at: COB Data Security Measures.htm