Quick Overview
- This is the starting point for SFA's information security program, established under SFA 06-107.
- The program is organized into three kinds of documents: Policies (what SFA must achieve), Standards (the specific requirements), and Procedures (the step-by-step how-to).
- It applies to everyone who uses SFA information resources: employees, students in a user role, vendors, contractors, and research partners.
- It exists to protect the university's systems, data, and people, and to meet Texas Administrative Code 202 (TAC 202) and UT System UTS 165.
- Use this page to understand how the pieces fit together and to jump to any policy or standard.
Stephen F. Austin State University protects its information, systems, and data through a single, coordinated
information security program. This page is the front door to that program. It explains what SFA 06-107 is,
who it applies to, and how its documents are organized, and it links to every policy and standard so you can find what you need.
It is the successor to the former ITS Policy Handbook: the same protections, now organized into clear, separate documents.
|
i
|
How the pieces fit together
Policy = the goal (what SFA must achieve).
Standard = the requirement (the specific rules that meet the goal).
Procedure = the how-to (the exact steps a team follows).
A policy sets the objective, its standards state the requirements, and procedures describe the day-to-day steps.
|
Who This Applies To
SFA 06-107 applies to all SFA employees, students acting in a user capacity, third-party service providers,
research partners, contractors, and other authorized users of SFA information resources. It covers the university's
information systems, assets, and data wherever they are located, except where a written contract or an approved exception
provides otherwise.
How the Program Is Organized
Every document in the program shares the SFA 06-107 root and a consistent numbering scheme:
- 06-107 is the information security program as a whole (this page).
- 06-107.x is a Policy (for example, 06-107.1 Information Security Organization, Personnel & Privacy Policy).
- 06-107.x.y is a Standard that supports the policy above it (for example, 06-107.1.1 Information Security Governance Standard).
- Procedures will follow the same pattern beneath their standards as they are developed.
Document Library
The program currently has four policies and sixteen standards. Expand a policy area below to see the
policy and the standards that carry it out.
Organization, Personnel & Privacy Policy 06-107.1
⌄
Technology Policy 06-107.2
⌄
Physical & Environmental Policy 06-107.3
⌄
Third-Party & Vendor Risk Management Policy 06-107.4
⌄
Procedures are being developed and will be published beneath their governing standards using the same 06-107 numbering. Until a procedure is issued, the relevant standard and any interim guidance apply.
Who Is Responsible
The program is led by the SFA Chief Information Security Officer (CISO), supported by the Office of
Information Security, with privacy matters coordinated by the university's Privacy Officer(s). The
President (Agency Head) approves the program and ensures resources and accountability, and every user carries defined security
responsibilities. The complete set of roles is defined in the
Information Security Governance Standard (06-107.1.1).
A note on names: At SFA, the senior information security role is the Chief Information Security Officer (CISO). There is no separate "Information Security Officer" position. The abbreviation ISO at SFA refers to the Office of Information Security (the office that supports the CISO), not to a person.
Compliance, Exceptions & Enforcement
Following SFA 06-107 and its standards is mandatory unless a written contract provides otherwise or a formal
exception has been granted. Where a requirement genuinely cannot be met and there is no workable fix, an exception may be
requested from the CISO, who weighs the risk and may approve compensating controls. Exceptions are not granted
to the Acceptable Use Standard (06-107.1.6). Each policy and standard states its own compliance provisions in full.
|
!
|
Important
Violations of SFA 06-107 may lead to disciplinary action, up to and including involuntary separation from employment.
|
Definitions & References
Definitions: terms shown in italics throughout the policies and standards are defined in the SFA 06-107 Definitions.
Controls Crosswalk: the SFA 06-107 Controls Crosswalk maps each requirement to TAC 202, DIR, and NIST 800-53.
Aligned with: UT System UTS 165 · Texas Administrative Code, Chapter 202 · Texas Government Code, Chapter 2054 · DIR Security Controls Catalog · NIST 800-53 Rev. 5.1.1
Responsible office: Office of Information Security ·
Contact: itsecurity@sfasu.edu, privacyofficer@utsystem.edu
Need Help?
Contact the IT Help Desk at
(936) 468-4357 (HELP) or submit a ticket at
help.sfasu.edu.
For questions about the information security program, contact the Office of Information Security at
itsecurity@sfasu.edu.