Information Security Governance Standard (SFA 06-107.1.1)

Quick Overview
  • This standard sets the specific requirements for how SFA governs its information security program: the leadership, planning, and documentation behind everything else.
  • It carries out the goals in the SFA 06-107.1 Information Security Organization, Personnel & Privacy Policy.
  • Most requirements are carried out by security leadership (the CISO and Privacy Officers), not by general users.
  • These requirements are the minimum baseline SFA must meet; the university may choose to do more.
  • Meeting this standard is mandatory unless a formal exception is granted.

"Governance" is the structure that keeps SFA's security program organized, funded, documented, and accountable to leadership. This standard spells out what the university must do to build and maintain that structure: create a written security strategy, keep security documentation current, assign the right roles, plan and report on the program, track its systems, and run insider-threat and research-security programs. It is the "backbone" standard that the other standards depend on.

i
Policy vs. Standard
The matching policy (06-107.1) says what SFA wants to achieve. This standard says how, the concrete requirements. Day-to-day steps will live in procedures.

Who This Applies To

This standard applies to all SFA employees, users, third-party service providers, research partners, and other authorized users of SFA information resources. In practice, the requirements below are carried out mostly by the people who build and run the security program: the CISO, the Office of Information Security, Privacy Officers, and their teams.

i
Baseline, not a ceiling
Everything here is the minimum SFA must do. Departments may add stricter requirements, but never anything weaker. See the SFA 06-107 Controls Crosswalk for higher control tiers.

Who Is Responsible

Key roles & responsibilities ⌄
A note on names: At SFA, the senior information security role is the Chief Information Security Officer (CISO). There is no separate "Information Security Officer" position. The abbreviation ISO at SFA refers to the Office of Information Security (the office that supports the CISO), not to a person.
  • UT System CISO: Directs the creation and upkeep of SFA 06-107 in partnership with the institutions.
  • SFA Chief Information Security Officer (CISO): Implements information security governance at SFA and reports to the UT System CISO.
  • Privacy Officers (PO): Make sure privacy and regulatory obligations are built into governance and documentation.
Full role definitions Complete responsibilities for each role are in the attached standard PDF.

What This Standard Requires

The requirements are grouped into eight areas. Expand any area for a plain-language summary of what it requires. The official requirement numbers (like 06-107.1.1.1.1) are shown so you can match them to the attached PDF.

1  Information Security Program Strategy  The written game plan ⌄

SFA must have a documented security strategy and keep it up to date.

  • Develop a comprehensive security program strategy aligned with SFA's mission and legal requirements (06-107.1.1.1.1).
  • Review and improve the strategy at least once every 12 months (06-107.1.1.1.2).
  • Create a written Information Security Plan that documents the strategy (06-107.1.1.1.3).
  • Keep track of the laws, regulations, and contracts SFA must comply with (06-107.1.1.1.4).
  • Select the specific controls SFA will implement, building an institution-specific control set (06-107.1.1.1.5).
2  Information Security Documentation  Writing it down & keeping it current ⌄

Security policies, standards, and procedures must be written, approved, shared, and maintained.

  • Develop and distribute security policies, standards, and operating procedures (06-107.1.1.2.1).
  • Get management approval for all security documentation (06-107.1.1.2.2).
  • Update documents whenever there are policy, control, risk, or exception changes (06-107.1.1.2.3).
  • Keep a process to record, assess, approve, and track cases of non-compliance and exceptions (06-107.1.1.2.4).
3  Information Security & Privacy Roles  Naming who's in charge ⌄

SFA must formally appoint the leaders who run the security program.

  • Appoint a Chief Information Security Officer (CISO) with the mission and resources to coordinate, develop, and maintain the security program (06-107.1.1.3.1).
4  Capital Planning, Reporting & Milestones  Budgeting & measuring progress ⌄

The program must be funded, tracked, and reported to leadership.

  • Include security program resources in capital planning and budget requests (06-107.1.1.4.1).
  • Track plans of action and milestones to measure the program's effectiveness (06-107.1.1.4.2).
  • Report to the Agency Head at least once every 12 months on how well the program is working (06-107.1.1.4.3).
5  System Inventory & Architecture  Knowing what we have ⌄

SFA must keep an inventory of its systems and design them with security in mind.

  • Maintain and update an inventory of in-scope information systems at least every 24 months (06-107.1.1.5.1).
  • Develop and maintain security-aware system architectures (06-107.1.1.5.2).
  • Have the Risk Management Executive Committee review high-risk assets at least every 24 months (06-107.1.1.5.3).
6  Groups, Reports & Privacy Restrictions  Staying informed & reporting ⌄

SFA must stay connected to the broader security community and handle privacy reporting properly.

  • Identify relevant security groups and forums to stay current on threats (06-107.1.1.6.1).
  • Collect and act on threat intelligence from trusted sources (06-107.1.1.6.2).
  • Review procedures for handling Personally Identifiable Information (PII) at least every 12 months (06-107.1.1.6.3).
  • Produce privacy reports at least every 12 months for the right stakeholders (06-107.1.1.6.4).
  • Determine and allocate the resources needed to protect the institution (06-107.1.1.6.5).
7  Insider Threat Program  UTS 165  Risks from within ⌄

SFA must run a program to detect and respond to threats that come from people inside the organization.

  • Establish an insider-threat program with procedures for reporting suspected activity to the CISO and appropriate offices (06-107.1.1.7.1).
8  Research Security Program  UTS 165  Protecting research ⌄

The Research Security Officer must run a program covering the key research risk areas identified by federal and state governments.

  • Establish and maintain a research security program addressing intellectual property, research/proprietary data security, foreign collaboration, insider threats, and other key risks (06-107.1.1.8.1).

Conformance & Exceptions

Meeting this standard is mandatory and effective as of the standard's publication, unless a written contract says otherwise or a formal exception has been granted. If a requirement genuinely can't be met and there's no workable fix, follow the exception process in the SFA 06-107.1 policy; requests go to the SFA Chief Information Security Officer (CISO).

!
Important
Violations of SFA 06-107 may lead to disciplinary action, up to and including involuntary separation from employment.

Compliance Mapping (Reference)

For auditors and security staff. Everyday users can skip this section.

Frameworks & control references ⌄

Each requirement in this standard maps to one or more of these authoritative sources:

  • NIST 800-53 Rev 5.1.1, for example the PM (Program Management), AC, AT, and PL control families.
  • TAC 202, Subchapter C, for example 202.7, 202.71, 202.73, 202.74, 202.76.
  • Texas DIR Security Controls Catalog, for example PM-2, PM-3, PM-4, PM-15.
  • NIST CSF, NIST 800-171, and privacy frameworks (GDPR, HIPAA, GLBA) where relevant.

The full requirement-by-requirement control mapping is in the attached standard PDF and the SFA 06-107 Controls Crosswalk.

Related Policies & Standards

Supporting policy: SFA 06-107.1 Information Security Organization, Personnel & Privacy Policy

Definitions: SFA 06-107 Definitions

Related standards:

Other references:

  • SFA 06-107 Controls Crosswalk Reference
  • Texas DIR Information Security Plan Overview · Texas Government Code Title 10, Subtitle B, Chapter 2054

Responsible office: Office of Information Security; Systemwide Chief Privacy Officer  ·  Contact: itsecurity@sfasu.edu, privacyofficer@utsystem.edu

📎
Official document
The complete, official standard is attached to this article as a PDF, including its full requirement text, role definitions, and control mappings. This article summarizes that standard in plain language. If anything in this article conflicts with the attached PDF, the PDF is the official version and takes precedence.

Need Help?

Contact the IT Help Desk at (936) 468-4357 (HELP) or submit a ticket at help.sfasu.edu. For questions about this standard, contact the Office of Information Security at itsecurity@sfasu.edu.
Print Article

Related Articles (6)

Requirements for the responsible procurement, deployment, and use of artificial intelligence at SFA, including AI governance, inventory and risk classification, data-input controls, prohibited uses, human oversight of consequential decisions, and testing and monitoring; supports Policy 06-107.1.
Requirements for protecting Criminal Justice Information (CJI) in line with the FBI CJIS Security Policy, including access control, multi-factor authentication, personnel background screening, media protection, physical security, and audits; applies primarily to the University Police Department and supports Policy 06-107.2.
Requirements for protecting Protected Health Information (PHI) at SFA's Academic Clinics designated as HIPAA Healthcare Components, covering administrative, physical, and technical safeguards, business associate agreements, privacy, and breach notification; supports Policy 06-107.1. Student Health and Counseling records are FERPA-governed and out of scope.
Sets SFA's objectives for governing the security program and protecting its people, vendors, data, and privacy, including awareness and training, acceptable use, AI governance, and research security; carried out by Standards 06-107.1.1 through 06-107.1.6.
Definitions of the key terms used throughout the SFA 06-107 information security program; any term shown in italics in a policy or standard is defined here.
Sets SFA's objectives for identifying and managing the security and privacy risks introduced by vendors and third-party services, from pre-purchase review through ongoing oversight; carried out through the Cybersecurity Risk Management (06-107.1.2) and Personnel & Third-Party Security (06-107.1.3) Standards.