Quick Overview
- This standard sets the specific requirements for how SFA identifies, assesses, and manages cybersecurity risk, both its own risks and the risks that come from vendors and other third parties.
- It carries out the goals in the SFA 06-107.1 Information Security Organization, Personnel & Privacy Policy.
- Most requirements are carried out by security leadership and technical teams (the CISO, Privacy Officers, IT, and risk managers), not by general users.
- It covers four areas: an assessment and monitoring strategy, control compliance assessments, risk assessments, and vendor risk management.
- These requirements are the minimum baseline SFA must meet; the university may choose to do more.
- Meeting this standard is mandatory unless a formal exception is granted.
"Risk management" is how SFA figures out what could go wrong with its information systems and data, how likely and how serious each problem
would be, and what to do about it. This standard spells out what the university must do to build that process: create a repeatable way to
assess and monitor risk, check that required security controls are actually working, run regular risk assessments, and keep a close eye on the
vendors and cloud services that handle SFA data. The goal is to catch problems early and fix them before they turn into incidents.
|
i
|
Policy vs. Standard
The matching policy (06-107.1) says what SFA wants to achieve. This standard says how, the concrete requirements. Day-to-day steps live in procedures.
|
Who This Applies To
This standard applies to all SFA employees, users, third-party service providers, research partners, and other authorized users
of SFA information resources. In practice, the requirements below are carried out mostly by the people who identify, assess, and manage
risk: the CISO, the Office of Information Security, Privacy Officers, IT management and risk managers, business continuity teams, and
external assessors.
|
i
|
Baseline, not a ceiling
Everything here is the minimum SFA must do. Departments may add stricter requirements, but never anything weaker. See the SFA 06-107 Controls Crosswalk for higher control tiers.
|
Who Is Responsible
Key roles & responsibilities
⌄
A note on names: At SFA, the senior information security role is the Chief Information Security Officer (CISO). There is no separate "Information Security Officer" position. The abbreviation ISO at SFA refers to the Office of Information Security (the office that supports the CISO), not to a person.
- Chief Information Security Officer (CISO): Establishes and oversees the risk management process, sets the risk appetite and tolerance levels, allocates resources, and keeps oversight of risk management practices and outcomes.
- Privacy Officers (PO): Work with the CISO and IT to build standard third-party contract language on security and privacy, oversee vendor risk assessments, and keep risk requirements in step with current laws and regulations. (A Privacy Officer may also serve in a legal or compliance capacity.)
- IT Management, Teams & Risk Managers: Conduct risk, control-compliance, and maturity assessments, review the results, and take the needed reporting or mitigating actions.
- Business Continuity Management & Teams: Work with IT to carry out response and mitigation actions after a risk assessment, tied to business continuity and disaster recovery plans.
- External Assessment Teams: Independent parties who perform required or requested risk, control-compliance, and maturity assessments at the direction of the CISO and IT teams.
Full role definitions
Complete responsibilities for each role are in the attached standard PDF.
What This Standard Requires
The requirements are grouped into four areas. Expand any area for a plain-language summary of what it requires.
The official requirement numbers (like 06-107.1.2.1.1) are shown so you can match them to the attached PDF.
1 Assessment & Continuous Monitoring Strategy
The plan for how we check
⌄
SFA must build a documented, repeatable process for the assessments it will run and for monitoring risk over time. At a minimum, that process must:
- Define the types of assessments to be performed (risk, compliance, and controls assessments) in line with TAC 202, the DIR Security Controls Catalog, and other in-scope privacy and security rules (06-107.1.2.1.1).
- Set a schedule for when those assessments happen (06-107.1.2.1.1).
- Set criteria for evaluating and categorizing the security risks and threats that turn up (06-107.1.2.1.1).
- Set criteria for judging the confidentiality, integrity, and availability of systems and data, and whether existing controls are strong enough for the risks found (06-107.1.2.1.1).
- Define metrics that measure how well controls and risk mitigation are working (06-107.1.2.1.1).
- Decide how often monitoring happens, including when to use independent assessors (06-107.1.2.1.1).
- Continuously monitor those defined metrics (06-107.1.2.1.1).
- Correlate and analyze the information that control assessments and monitoring produce (06-107.1.2.1.1).
- Define response actions for what the assessments and monitoring find (06-107.1.2.1.1).
- Report the security and privacy status of systems to the right regulators and stakeholders (06-107.1.2.1.1).
2 Control Compliance Assessments
Checking that controls actually work
⌄
SFA must regularly confirm that its required security controls are in place and effective, and report the results to the right people.
- Run control compliance assessments at least once every 12 months, using independent assessors, trend analysis, and reviews of log reviews, vulnerability assessments, penetration tests, and IT audits; these must cover FERPA, GDPR, HIPAA, GLBA, the DIR Security Controls Catalog, and TAC 202 where they apply (06-107.1.2.2.1).
- Have the CISO report the TAC 202 assessment of the security program directly to the state Agency Head once every 12 months, including program effectiveness, residual risks, and institutional needs (06-107.1.2.2.2).
- Perform and submit a security assessment of each institution for compliance with Texas Government Code 2054.515 and TAC 202 at least once every 24 months (06-107.1.2.2.3).
- Engage someone independent of the security program, designated by the state Agency Head, to perform risk-based compliance reviews at least once every 24 months (06-107.1.2.2.4).
3 Risk Assessments
Finding & ranking what could go wrong
⌄
SFA must run regular risk assessments, document and rank the results, and act on them.
- Conduct risk assessments at least once every 12 months that identify threats and vulnerabilities, judge how likely and how damaging harm would be, and weigh the privacy impact of processing Personally Identifiable Information (PII); document the results, rank risks as High, Moderate, or Low, and route acceptance, transfer, or mitigation decisions for High residual risks to the CISO (06-107.1.2.3.1).
- If SFA handles electronic Protected Health Information (ePHI), assess the risks to its confidentiality, integrity, and availability; if SFA offers financial products or services, run a risk assessment that categorizes risks, weighs control adequacy, and documents how risks will be mitigated or accepted (06-107.1.2.3.2).
- Conduct a risk assessment before buying or outsourcing security services, with approval from Privacy Officers, the Office of the General Counsel, and other stakeholders; for cloud services, confirm the vendor is TX-RAMP certified before signing or renewing and require them to stay certified for the life of the contract (06-107.1.2.3.3).
- Develop and maintain a plan of action and milestones to correct weaknesses and reduce known vulnerabilities, and update it at least once every 12 months based on assessments, audits, and monitoring (06-107.1.2.3.4).
- Work with security, IT, and privacy teams to respond to findings from assessments, monitoring, and audits within the institution's defined risk tolerance (06-107.1.2.3.5).
4 Vendor Risk Management
Managing risk from third parties
⌄
SFA must manage the security and privacy risks that come from vendors, cloud providers, and the wider supply chain.
- Work with procurement and Privacy Officers to build standard vendor contract language covering security roles and responsibilities, minimum controls, secure handling and disposal of SFA data, breach response, compliance with security standards, foreign-vendor statutes, and audit rights; for cloud vendors, also address data sovereignty, exit rights, and TX-RAMP certification (06-107.1.2.4.1).
- Develop a plan for managing vendor risks across the full supply chain lifecycle (design, manufacturing, acquisition, delivery, operations, and disposal), review and update it at least once every 12 months, and protect it from unauthorized disclosure or change (06-107.1.2.4.2).
- Monitor vendor security and privacy controls using a risk-based approach at least once every 12 months, and address or mitigate any issues with Privacy Officers and other teams (06-107.1.2.4.3).
- Develop and implement anti-counterfeit procedures to detect and prevent counterfeit system components from entering SFA systems, and scan for them at a defined frequency
UTS 165
(06-107.1.2.4.4).
Conformance & Exceptions
Meeting this standard is mandatory and effective as of the standard's publication, unless a written contract says otherwise
or a formal exception has been granted. If a requirement genuinely can't be met and there's no feasible fix, follow the exception process in
the SFA 06-107.1 policy; requests go to the SFA Chief Information Security Officer (CISO).
|
!
|
Important
Violations of SFA 06-107 may lead to disciplinary action, up to and including involuntary separation from employment.
|
Compliance Mapping (Reference)
For auditors and security staff. Everyday users can skip this section unless you need control references.
Frameworks & control references
⌄
Each requirement in this standard maps to one or more of these authoritative sources:
- NIST 800-53 Rev 5.1.1, for example the CA (Assessment & Authorization), RA (Risk Assessment), PM (Program Management), SA (System & Services Acquisition), and SR (Supply Chain Risk Management) control families.
- TAC 202, Subchapter C, for example 202.7, 202.73, 202.74, 202.75, 202.76, 202.77.
- Texas DIR Security Controls Catalog, for example CA-2, CA-7, PM-9, PM-10, RA-7, SA-9, and the SR controls.
- NIST CSF and NIST 800-171 for risk, monitoring, and supply-chain outcomes.
- Privacy and regulatory frameworks: FERPA, GDPR, HIPAA, and GLBA where they apply.
- UTS 165 for supply-chain and anti-counterfeit requirements.
The full requirement-by-requirement control mapping is in the attached standard PDF and the SFA 06-107 Controls Crosswalk.
Related Policies & Standards
Supporting policy: SFA 06-107.1 Information Security Organization, Personnel & Privacy Policy
Related standards:
Other references:
- Texas Risk and Authorization Management Program (TX-RAMP)
- SFA 06-107 Controls Crosswalk Reference
Responsible office: Office of Information Security ·
Contact: itsecurity@sfasu.edu
|
📎
|
Official document
The complete, official standard is attached to this article as a PDF, including its full requirement text, role definitions, and control mappings. This article summarizes that standard in plain language. If anything in this article conflicts with the attached PDF, the PDF is the official version and takes precedence.
|
Need Help?
Contact the IT Help Desk at
(936) 468-4357 (HELP) or submit a ticket at
help.sfasu.edu.
For questions about this standard, contact the Office of Information Security at
itsecurity@sfasu.edu.