Policies & Standards
CSUN's information security policies and standards establish requirements for protecting university information, technology, and systems.
Use the resources below to find the security requirements and guidance that apply to your work.
Understanding the Requirements
- Policies — Establish university requirements and responsibilities.
- Standards — Define required security controls and practices.
- Procedures — Provide instructions for meeting requirements.
- Guidelines — Provide recommended security practices.
Information Security Policies & Standards
Accordion: Information Security & Governance
Requirements for CSUN's Information Security Program, responsibilities, policy management, and compliance.
Requirements for managing access to university accounts, systems, and information.
Topics include:
- Identity and access management
- Account access
- Passwords and authentication
- Administrative privileges
- Employee access changes and separations
Requirements for classifying, accessing, storing, sharing, and protecting university information.
Requirements for assessing cybersecurity risks involving university projects, applications, vendors, cloud services, and sensitive information.
Planning a new technology purchase or service? Contact Information Security early when it will access, store, process, or transmit sensitive university information.
Requirements for protecting university computers, applications, networks, and other technology.
Topics include:
- Configuration and change management
- Vulnerability management
- System and application security
- Malware protection
- Network security
- Logging and monitoring
- Physical security
- Business continuity and disaster recovery
Requirements for cybersecurity awareness, training, reporting, and responding to security incidents.
Report suspected cybersecurity incidents as soon as possible.
University information and technology may also be subject to legal, regulatory, contractual, CSU, and CSUN requirements, including:
- FERPA — Student education records
- HIPAA — Certain protected health information
- PCI DSS — Payment card information
- GLBA — Certain financial information
- Records Retention — University records and information
- Accessibility — Accessible information and technology
- Copyright & DMCA — Copyrighted digital content
Access Requests & Exceptions
Need additional access or an exception to a security requirement?
- Administrative Rights to Computers — Review requirements and request administrative access to a university computer.
- USB Storage Device Exception — Review USB storage requirements and request an exception when needed.
- Confidentiality Statements — Complete the appropriate confidentiality agreement when access to protected university information requires one.
- SOLAR Security Access — Request appropriate access to authorized university administrative systems.
Resources
- CSUN University Policies & Procedures — Official repository for university policies, including the Information Security policy series.
- Information Security Plan — CSUN's approach to protecting university information and technology.
- Risk Management — Security assessments for projects, applications, vendors, and services.
- Security Checklist for Hosted IT Services — Security requirements for hosted, cloud, and third-party services.
- Digital Millennium Copyright Act (DMCA) — Copyright and digital infringement guidance.
- Information Security — Security guidance, services, training, and assistance.
Need Help?
Not sure which policy, standard, or security requirement applies?
Contact CSUN Information Security for assistance, particularly when planning technology that will handle sensitive university information.
Phone: (818) 677-6100
Email: iso@csun.edu