IT-5 Security of Information Technology Resources Standard


Table of contents

The IT-1 Standard for IT Security Roles and Responsibilities states that the security of IT resources is a shared responsibility between the campus units operating these resources, the technical staff supporting these resources, and the user community using and potentially storing these resources. The Standard below sets forth requirements for how IT resources are to be securely managed.

Definitions

For the purpose of this document, sensitive data is information categorized as High (Level 3) by the IT-2 UMD Data Classification Standard.

Top

Implementation

It is possible to implement compensating controls for standard items that achieve the same results. Compensating controls should be reviewed in advance with the Division of IT (DIT) Security Office to ensure suitability.

Top

Standards

For a computer system to be managed securely, unit management must:

For a computer system to be managed securely, unit technical staff must abide by the following standards.
 
Top

Data protection

Top

System security

Top

Access control

Top

Accountability

If you need any assistance or guidance, contact us at it-compliance@umd.edu.

Top