Information Security Plan
- Home
- Offices and Services
- Technology & Innovation
- IT Guidelines & Policies
- Information Security Plan
- AP Summer Institute
- Deliberative Citizenship Initiative
- Division of Student Life
- Institutional Biosafety Committee
- Jay Hurt Hub for Innovation and Entrepreneurship
- The College Crisis Initiative
- The Office of Equity Compliance
- Archives and Special Collections
- College Communications
- College Store
- Arts & Creative Engagement
- Academic Access & Disability Resources
- Academic Affairs
- Lula Bell's Resource Center
- Animal Care and Use
- Auxiliary Services
- Controller's Office
- Post and Print
- Carnegie Guest House
- Human Subjects IRB
- CatCard Services
- Matthews Center for Career Development
- Center for Teaching and Learning
- Chidsey Program for Leadership Development
- Civic Engagement
- College Relations
- Davidson Outdoors
- Dean Rusk International Studies Program
- Dining Services
- Center for Student Diversity and Inclusion
- Education Abroad
-
Environmental Health and Safety
- Fire & Life Safety
-
Occupational Safety
- Contractor Safety
- Confined Space Entry Program
- Electrical Safety
- Lockout Tagout Procedure
- Ladders and Scaffolding
- Personal Protective Equipment
- Respiratory Protection
- Hearing Conservation Program
- Hand and Power Tools
- Steam System Safety
- Welding, Cutting and Brazing
- Compressed Gas Cylinders
- Construction and Excavation
- Fork Lift Safety
- Motor Vehicle Safety
- Golf Cart Safety
- Biological, Chemical & Laboratory Safety
- Chemical Inventory
- Safety Data Sheets
- Training
- Environmental
- Indoor Air Quality
- Ergonomics
- Forms and Policies
- Incident Reporting
- EHS Committee
-
Office of Fellowships
- Appointments & Contact Information
-
Fellowship Opportunities
- Beinecke Scholarship
- Boren Fellowships
- Churchill Scholarship
- Critical Language Scholarship Program
- DAAD Rise Germany
- Fulbright U.S. Student Program
- Gaither Junior Fellows Program
- Gates Cambridge Scholarships
- Goldwater Scholarships
- Knight-Hennessy Scholars
- Luce Scholarships
- Marshall Scholarships
- McCall MacBain Scholarships
- National Science Foundation Graduate Fellowships
- NOAA Hollings Scholarship
- Paul & Daisy Soros Fellowships for New Americans
- Pickering Fellowship Program
- Rangel Fellowship Program
- Rhodes Scholarships
- Schwarzman Scholars
- Smith Scholarship
- Truman Scholarships
- Udall Scholarships
- UK Summer Institutes
- Watson Fellowship
- Fellowship Resources for Faculty & Staff
- Finance & Administration
-
Office of Sponsored Programs
- Research Compliance
- Proposal Development
-
Policies
- NSF and NIH Sexual Harassment Notification Policy
- NSF and NIH Breach of Personally Identifiable Information (PII) Policy
- Conflict of Interest
- NIH and NSF Public Access Policy
- Policy and Procedure for Responsible Conduct of Research
- Effort Reporting Policy
- Export Control Policy
- Ethical Conduct in Research and Scholarship
- Financial Conflict of Interest Policy
- Full Year Sabbatical Fringe Benefits
- Grants Record Management Policy
- Drug Free Workplace
- Intellectual Property Policy
- Indirect Cost
- Postdoctoral Positions Policy
- Determination of Allowable Costs Policy
- Summer Salary Distribution
-
Post Award Management
- Procurement Policy
- Suspension and Debarment Policy and Procedure
- Grant-Related Expenditure Approval and Monitoring Procedure
- Unallowable Cost Policy
- Cost Transfer Policy
- Sub-Recipient Monitoring Policy
- Award Cash Management Service Procedure
- Hiring New Personnel
- Rebudgeting and Program Revisions
- Reporting and Closeout
- Staff
- Guest Services
- Student Health and Well-Being
- Housing and Relocation
-
Human Resources
- Benefits
- Retirement
-
Employee Guide
- Americans with Disabilities (ADA)
- Leave Accruals
- Attendance
- Background Checking Policy
- Confidentiality of Information
- Conflict of Interest
- Consensual Relationships
- Copyrights
- Dependent Tuition Assistance Policy
- Disciplinary Action
- Dress Code
- Drug-free Workplace
- Employee Designations
- Employee Files
- Employee Honor Code
- Employment and Recruitment
- Employment of Minors
- Employment of Relatives
- Family Medical Leave Act
- Firearms and Dangerous Weapons
- Funeral and Bereavement Leave
- Grievance Procedure
- Identification Cards/CatCards
- Immigration Sponsorship for College Employees
- Inclement Weather
- Jury Duty
- Long Term Disability
- Military Leave
- Non-Discrimination Policies
- Occupational Health and Safety
- Other Employment
- Overtime
- Parental Leave
- Pay During Special Circumstances
- Pet Policy
- Political Activity
- Reduced Hours and Voluntary Time Off
- References for Former Employees
- Relocation and Moving Expense Policy
- Resignation
- Retirement Health Insurance
- Short Term Disability
- Sick Leave
- Smoking Policy
- Sports Betting Policy
- Staff Tuition Policy
- Support for Lactation Policy
- Remote Work Policy
- Transfer, Promotion and Classification
- Use of College-owned Equipment and Work Areas
- Vacation
- Vehicles/Parking
- Volunteer Policy
- Voting
- Work Schedules
- Workers Compensation
- Employee Resources
- Manager Resources
- Work at Davidson
- Student Employment
- HR Staff
- Institutional Effectiveness
- International Student Engagement
- Investment Office
- July Experience
- Laundry Self-Service Facilities
- Motor Pool Services
- Physical Plant
- Public Safety
-
Registrar
- Academic Calendars
- Course Offerings
- Course Registration and WebTree Overview
- Holistic Advising
- Student Schedules, Grades, Add/Drop
- Transcripts
- Record Requests & Forms
- Graduation Requirements
- Transfer Credit
- New Student Resources
- Faculty Resources
- College Catalog
- Academic Regulations
- FERPA
- Graduating Class Profiles
- Staff
- Religious and Spiritual Life
- Residence Life
- Staff Council
-
Student Activities
-
Student Organizations
- Academic Clubs and Societies
- Affinity & Identity Organizations
- Civic Engagement Council
- Fraternity & Sorority Life (Patterson Court Council)
- Health & Wellness Organizations
- Media Organizations
- Performance Groups
- Political Organizations
- Pre-Professional Organizations
- Religious Organizations
- Special Interest and Recreational Organizations
- Programs
- Student Activities Staff
-
Student Organizations
- Sustainability Office
-
Technology & Innovation
- Getting Started
- Services
-
IT Guidelines & Policies
- Emeriti Technology Policy
- 国产福利精品推荐 Technology Terms of Service
- Account Management
- College Access to Electronic Communications Policy
- Computer Workstation Purchasing
- Copyright Compliance with Laws and Acts
- Data Privacy Statement
- Data Security Policy
- Desktop Computer Support
- Guidelines for Mass Email Communications
- Information Security Plan
- Information Systems Security Policy
- Log Retention Guidelines
- Moodle Usage Tracking
- Purchasing Technology
- About
- Staff
- The Farm at Davidson
- Wildcat Wellness
Information Security Plan
Overview
This Information Security Plan describes the safeguards implemented by 国产福利精品推荐 to protect confidential data. The goal of the program is to ensure the security of these assets in an effort to support the academic mission and culture of 国产福利精品推荐. These safeguards are provided to:
- ensure the security and confidentiality of all information assets including confidential and nonpublic data,
- protect against any anticipated threats or hazards to the security of such assets, and
- protect against unauthorized access or use of such assets in ways that could result in substantial harm or inconvenience to customers.
Confidential Data
Within 国产福利精品推荐鈥檚 Data Security Policy, 鈥渃onfidential data鈥 is defined as data protected by federal and state regulations and are intended for use only by individuals who require that information in the course of performing their college functions. For these purposes, confidential data refers to, but is not limited to, financial information, academic and employment information, and other private paper and electronic records.
国产福利精品推荐 works to maintain a secure environment by using technical and administrative controls to protect data while stored, in use, and in transit. Data that is considered confidential per the Data Security Policy that is stored in T&I managed systems of record or confidential data file shares will be managed per the Confidential Data Retention Guidelines to support Davidson鈥檚 Information Security Plan and comply with applicable laws or regulations. Email infosec@davidson.edu for more information.
Change Management
Change management typically requires documentation, peer review and approval and/or approval by T&I leadership. Normal and Emergency changes that have an impact on service require completion of change approval through this documented change process. Standing changes and most operational work do not require approval and are considered pre-approved. Items may be approved as standing changes after completing an initial change management process for that specific work type. Work approved as standing changes and operational work use an abbreviated change process to communicate and document the change. Consult T&I's (Davidson login required) for more information.
Designation of Representatives
The Institution鈥檚 Information Security Analyst is designated as the Program Coordinator who shall be responsible for coordinating and overseeing the program. The Program Coordinator may designate other representatives of the Institution to oversee and coordinate particular elements of the program. (For instance, the Director of Public Safety/Chief of Police has been designated as the coordinator for all paper records and physical security.) Any questions regarding the implementation of the program or the interpretation of this document should be directed to the Program Coordinator or his or her designees.
Executive Report
The Information Security Program Manager will provide an annual written report to the CIO, Director of Finance & Administration and the Board of Trustees. At a minimum the report will include:
- Appropriate metrics to illustrate the state of the security profile
- Major Security Incidents overview and remediation
- Program Initiative Status
- Recommended & Planned Initiatives
Risk Identification and Assessment
国产福利精品推荐 identifies and assesses external and internal risks to the security and confidentiality of confidential data that could result in the unauthorized disclosure, misuse, alteration, destruction or other compromise of such information and assess the sufficiency of the safeguards in place to control these risks by:
- performing a risk assessment annually that rotates from an external vendor performed risk assessment to an internal assessment,
- performing annual penetration testing that rotates from an external vendor performed test to an internally performed test,
- performing monthly vulnerability assessments and as deemed necessary due to material changes to operations or business arrangements or other circumstances with a material impact to the information security program.
- monitoring of safeguards put in place to detect and identify potential threats, and
- monitoring advisory groups such as SANS, REN-ISAC, EDUCAUSE, and others to keep up to date on any new threats that may develop.
国产福利精品推荐 identifies and assesses risk in relevant areas, including:
- employee training and management,
- information systems, including network and software design, as well as information processing, storage, transmission and disposal; and
- detecting, preventing and responding to attacks, intrusions, or other systems failures.
Safeguards
The designated Program Coordinator will regularly monitor administrative, technical, and physical safeguards to control the risks identified through such assessments described above and to regularly test or otherwise monitor the effectiveness of such safeguards. The Technology & Innovation (T&I) division of the College designs and implements safeguards in areas highlighted by the aforementioned assessments. An internal T&I document outlines 国产福利精品推荐鈥檚 procedure for implementing and assessing these safeguards.
Service Providers
国产福利精品推荐 will, upon hiring or contracting third party service providers, ensure that they take similar steps to protect confidential data as outlined above. T&I has an internal document that states the security requirements current or potential providers must adhere to in order to protect Davidson鈥檚 confidential data. Additionally, 国产福利精品推荐 has a documented process for evaluating IT service providers including firms that host Davidson data or provide software as a service (SaaS) or similar solutions.
Training Program
The awareness and training program will occur on a regular basis and will be reviewed annually and updated as needed to address new technologies, threats, standards, and Davidson requirements. Where applicable, role-based training will be implemented to target specific vulnerabilities within the execution of a respective role.
Cybersecurity awareness training is required for all employees with Davidson credentials. Content and frequency will meet or exceed regulatory requirements. PCI training requirements are driven by roles within the College. View T&I's (Davidson login required) for more information.
Adjustments to Program
The designated Program Coordinator is responsible for adjusting and reevaluating the plan as regular risk assessment occurs or as major changes occur that may significantly impact Davidson鈥檚 operations. The designated Program Coordinator will revisit this plan at least annually to ensure it is reflective of Davidson鈥檚 practices and adherence to regulatory requirements.