1.07.2009

Formal Review of New CSU Information Security Policy


In a CSU system-wide effort to enhance information security, a new set of CSU policies are in the final phases of review and deployment by all campuses. For San Francisco State University, the formal review of the CSU System-wide Information Security Policies will begin on approximately January 7th and end on February 15, 2009.

Below is a link for you to review this draft policy and provide comments. For quality control in the submittal of comments you will be required to authenticate using your

  • SF State Id#
  • SF State password

to read and post comments on the draft. Here is the link for the hosted policy:

http://www.sfsu.edu/~secure/policy review

Your comments will be captured, reviewed and aggregated into a campus-wide set of comments and proposed edits back to the Chancellor’s Office. Perhaps more importantly, as a result of this macro policy change, San Francisco State University plans to supplement and re-organize over the coming year its existing campus IT security policies:

• Confidential Information Security Plan (CISP),
• Secure Computing Webpage & Policy
• Acceptable Use Policy

to be consistent with the guidance stated in this CSU policy and, in some cases, will implement new policies and a proposed IT governance structure that currently do not yet exist.

The policies and standards provide direction to campuses and CSU staff in their efforts to protect CSU information assets and insure privacy protection to individuals in accordance with applicable laws and regulations and university requirements. The CSU System wide Information Security Policies have future implications for the management and control of IT assets and I therefore invite you to comment on the draft before it becomes final.