Information Security Organization, Personnel & Privacy Policy (SFA 06-107.1)

Quick Overview
  • This is one of four information security policies that together make up SFA 06-107 and satisfy the state and UT System rules SFA must follow (TAC 202 and UTS 165).
  • It sets the university's high-level goals for how we organize security, manage our people and vendors, protect privacy, and govern new areas like AI and research security.
  • It applies to everyone who uses SFA computers, systems, or data, including employees, students, contractors, vendors, and research partners.
  • A policy says what we must achieve. The matching standards say how. This policy points to six supporting standards.
  • Following SFA 06-107 is mandatory. Not following it can lead to disciplinary action.

Stephen F. Austin State University protects the information, systems, and data the university depends on to do its work. This policy establishes the university's expectations for how information security is organized and governed, how the people and vendors who handle SFA data are managed, and how privacy is protected. It does not contain step-by-step technical instructions; those live in the supporting standards and procedures. Think of this policy as the "why and what" that everything else builds on.

i
How the pieces fit together
Policy = the goal (what SFA must achieve).   Standard = the requirement (the specific rules that meet the goal).   Procedure = the how-to (the exact steps a team follows). This document is a policy, and it is supported by six standards listed near the bottom of this article.

Who This Applies To

This policy applies to all users of SFA information resources, including:

  • SFA employees (faculty and staff) and student workers
  • Contractors, vendors, and other third-party service providers
  • Research partners and other authorized users of SFA systems and data
  • Visitors and temporary workers who use SFA technology or work inside IT facilities

Wherever you see an italicized term in the full policy, its exact meaning is in the SFA 06-107 Definitions (Appendix A).

What This Policy Covers

The policy is organized into eight goal areas. Each area sets objectives that are carried out through a supporting standard. Expand any section below to see what it covers in plain language and which standard puts it into practice.

4.1  Information Security Governance  Leadership, strategy & documentation ⌄

SFA must run its security program in an organized, documented, and leadership-backed way, and keep it current with the laws and contracts that apply to the university.

  • Build and maintain a written information security strategy and program that uses a risk-based approach.
  • Put a governance structure in place, with senior leaders accountable for security.
  • Write down, approve, and maintain security policies, standards, and procedures, and have users acknowledge them.
  • Track the legal, regulatory, and contractual rules SFA must meet, and keep security aligned with them.
Put into practice by SFA 06-107.1.1 Information Security Governance Standard
4.2  Cybersecurity Risk Management  Finding & managing risk ⌄

SFA must have a consistent way to identify security risks, decide what to do about them, and check that controls are working, including risks that come from vendors.

  • Use a defined framework to assess, prioritize, and remediate (or formally accept) risks.
  • Regularly assess whether security controls meet state, regulatory, and contract requirements.
  • Evaluate vendors before use and re-check their security over time.
  • Have the UT System Risk Management Executive Committee periodically review "high risk" assets.
Put into practice by SFA 06-107.1.2 Cybersecurity Risk Management Standard
4.3  Personnel & Third-Party Security  People & vendors ⌄

Security depends on people. This area sets expectations for staff and vendors from hiring through separation.

  • Put security and privacy responsibilities into vendor contracts.
  • Screen candidates (for example, background checks) appropriate to the role and data involved.
  • Include security and privacy duties in job descriptions and terms of employment.
  • Follow a defined process when someone leaves or changes roles, so access is removed.
  • Apply a clear disciplinary process for security and privacy violations.
Put into practice by SFA 06-107.1.3 Personnel & Third-Party Security Standard
4.4  Awareness & Training  Knowing your part ⌄

Everyone needs the right level of security and privacy training for their job.

  • Provide security and privacy awareness training to all users.
  • Provide role-based training for people with special security or privacy duties.
  • Cover SFA's security policies and standards as part of that training.
Put into practice by SFA 06-107.1.4 Awareness & Training Standard
4.5  Information Data Protection & Privacy  Protecting data & personal information ⌄

SFA must protect data throughout its life and respect the privacy rights of individuals.

  • Set rules for using, handling, keeping, and disposing of data based on how sensitive it is.
  • Honor individuals' privacy rights (such as access to and correction of their personal information).
  • Inventory and label important data so it gets the right protection.
  • Detect and prevent data from leaking out of SFA systems.
  • Use approved encryption and data-masking to protect sensitive data.
Put into practice by SFA 06-107.1.5 Information Data Protection & Privacy Standard
4.6  Acceptable Use  Using SFA technology responsibly ⌄

This area covers the everyday rules for using SFA technology, including devices you carry.

  • Maintain an Acceptable Use Policy that users acknowledge annually.
  • Follow clear-desk and clear-screen practices so sensitive information isn't left exposed.
  • Define security responsibilities for both managers and general users.
  • Secure university-owned devices and follow mobile-device rules, including approved Bring Your Own Device (BYOD) use.
!
Important
Exceptions are not granted to Acceptable Use requirements. These rules apply to everyone, without exception.
Put into practice by SFA 06-107.1.6 Acceptable Use Standard
4.7  Artificial Intelligence Governance  UTS 165  Using AI safely ⌄

Any AI system SFA buys, builds, or uses must be assessed for risk and used responsibly.

  • Assess AI systems for risk when purchasing and while in use.
  • Keep an inventory of AI systems and set acceptable-use boundaries.
  • Control what data can go into and come out of AI tools based on its sensitivity.
  • Stay accountable for decisions or outputs produced by AI.
Supporting resources SFA 06-107.1.5 Information Data Protection & Privacy Standard · SFA AI Use Guidelines (TeamDynamix)
4.8  Research Security  UTS 165  Protecting research ⌄

SFA must run a research security program that addresses the risk areas identified by federal and state governments.

  • Protect research data, systems, and intellectual property.
  • Address foreign-collaboration and insider-threat risks in the research environment.
  • Coordinate research security with the CISO and Privacy Officers.
Put into practice by SFA 06-107.1.1 Information Security Governance Standard · SFA 06-107.1.2 Cybersecurity Risk Management Standard

Who Is Responsible

The policy assigns specific duties to leaders at both the UT System and SFA levels. Most users won't hold these roles, but it helps to know who is accountable. Expand for a plain-language summary of the key roles.

Key roles & responsibilities ⌄
A note on names: At SFA, the senior information security role is the Chief Information Security Officer (CISO). There is no separate "Information Security Officer" position. The abbreviation ISO at SFA refers to the Office of Information Security (the office that supports the CISO), not to a person. This article uses CISO for the person and Office of Information Security for the office.

At SFA (Institution level)

  • Agency Head (President): Ensures SFA complies with 06-107, appoints the CISO, and funds the security program.
  • Chief Information Security Officer (CISO): Runs SFA's security program and has independent oversight of security across IT.
  • Information Resource Manager (IRM): Implements security controls across the university.
  • Privacy Officer (PO): Guides how the university safeguards records and personal information.
  • Research Security Officer (RSO): Runs the research security program.
  • Data Management Officer (DMO): Oversees how data is classified, managed, and protected.
  • Chief Business Officer (CBO): Ensures procurement includes security and privacy review of vendors.
  • Data / resource owners & custodians: Grant, control, and monitor access to systems and data.
  • All users: Must follow every 06-107 policy and standard when using SFA information resources.

At the UT System level

Systemwide leaders, including the UT System CISO, CIO, Chief Privacy Officer, Chief Risk Officer, and the Risk Management Executive Committee (RMEC), set direction, issue the policies and standards, and review high-risk assets across all institutions.

Full role definitions The complete list of responsibilities for every role is in the attached policy PDF (Sec. 3, Authority).

Compliance, Exceptions & Enforcement

Compliance with SFA 06-107 is mandatory unless a written contract says otherwise or a formal exception has been granted. If a requirement genuinely can't be met and there's no workable fix, a user may request an exception through the SFA Chief Information Security Officer (CISO), who weighs the risk and may approve it with compensating protections. All approved exceptions are logged.

!
Important
Violations of SFA 06-107 may lead to disciplinary action, up to and including involuntary separation from employment. Exceptions are never granted to the Acceptable Use Standard (06-107.1.6).

Compliance Mapping (Reference)

This section is for auditors, security staff, and anyone who needs the underlying control references. Everyday users can skip it.

Frameworks & control references ⌄

SFA 06-107 was written to align with the following authoritative sources:

  • Texas Administrative Code (TAC) 202, Subchapter C: the state rule for information security at Texas institutions of higher education.
  • UT System UTS 165: the UT System information security policy.
  • Texas DIR Security Controls Catalog: the state's baseline control set.
  • NIST 800-53 Revision 5.1.1: the federal security and privacy control catalog.
  • Additional privacy frameworks referenced where relevant (e.g., HIPAA, GLBA, GDPR).

Each objective in the policy lists the specific control numbers it maps to (for example, NIST AC-01, TAC 202 202.74, DIR AC-1). The complete objective-by-objective mapping is in the attached policy PDF and in the SFA 06-107 Controls Crosswalk.

Related Policies & Standards

This policy is carried out by the following standards:

Responsible office: Office of Information Security, Privacy Officer  ·  Contact: itsecurity@sfasu.edu, privacyofficer@utsystem.edu

📎
Official document
The complete, official policy is attached to this article as a PDF, including its full objectives, role definitions, and control mappings. This article summarizes that policy in plain language. If anything in this article conflicts with the attached PDF, the PDF is the official version and takes precedence.

Need Help?

Contact the IT Help Desk at (936) 468-4357 (HELP) or submit a ticket at help.sfasu.edu. For questions about this policy, contact the Office of Information Security at itsecurity@sfasu.edu.
Print Article

Related Articles (7)

Requirements for the responsible use of SFA technology, including mobile and endpoint devices and the security duties of managers and general users; applies to everyone with no exceptions and supports Policy 06-107.1.
Requirements for SFA's security and privacy training, including general awareness training, role-based training for specialized duties, and training records; supports Policy 06-107.1.
Requirements for identifying, assessing, and managing cybersecurity risk at SFA, including risk assessments, continuous monitoring, control assessments, and vendor risk management; supports Policy 06-107.1.
Requirements for protecting SFA data and personal information throughout its life, including data handling and classification, encryption and transmission, consent and notices, and retention; supports Policy 06-107.1.
Requirements for governing SFA's security program, including the security strategy, documentation, leadership roles, planning and reporting, system inventory, and the insider-threat and research-security programs; supports Policy 06-107.1.
Definitions of the key terms used throughout the SFA 06-107 information security program; any term shown in italics in a policy or standard is defined here.
Requirements for managing the security responsibilities of staff and vendors across the employment lifecycle, from screening and rules of behavior through transfers, offboarding, and discipline; supports Policy 06-107.1.