Information Security Program Overview (SFA 06‑107)

Quick Overview
  • This is the starting point for SFA's information security program, established under SFA 06-107.
  • The program is organized into three kinds of documents: Policies (what SFA must achieve), Standards (the specific requirements), and Procedures (the step-by-step how-to).
  • It applies to everyone who uses SFA information resources: employees, students in a user role, vendors, contractors, and research partners.
  • It exists to protect the university's systems, data, and people, and to meet Texas Administrative Code 202 (TAC 202) and UT System UTS 165.
  • Use this page to understand how the pieces fit together and to jump to any policy or standard.

Stephen F. Austin State University protects its information, systems, and data through a single, coordinated information security program. This page is the front door to that program. It explains what SFA 06-107 is, who it applies to, and how its documents are organized, and it links to every policy and standard so you can find what you need. It is the successor to the former ITS Policy Handbook: the same protections, now organized into clear, separate documents.

i
How the pieces fit together
Policy = the goal (what SFA must achieve).   Standard = the requirement (the specific rules that meet the goal).   Procedure = the how-to (the exact steps a team follows). A policy sets the objective, its standards state the requirements, and procedures describe the day-to-day steps.

Who This Applies To

SFA 06-107 applies to all SFA employees, students acting in a user capacity, third-party service providers, research partners, contractors, and other authorized users of SFA information resources. It covers the university's information systems, assets, and data wherever they are located, except where a written contract or an approved exception provides otherwise.

How the Program Is Organized

Every document in the program shares the SFA 06-107 root and a consistent numbering scheme:

  • 06-107 is the information security program as a whole (this page).
  • 06-107.x is a Policy (for example, 06-107.1 Information Security Organization, Personnel & Privacy Policy).
  • 06-107.x.y is a Standard that supports the policy above it (for example, 06-107.1.1 Information Security Governance Standard).
  • Procedures will follow the same pattern beneath their standards as they are developed.

Document Library

The program currently has four policies and sixteen standards. Expand a policy area below to see the policy and the standards that carry it out.

Physical & Environmental  Policy 06-107.3 ⌄

Policy: SFA 06-107.3 Information Security Physical & Environmental Policy — protecting the facilities, equipment, and environmental controls behind the systems.

Supporting standard:

Third-Party & Vendor Risk Management  Policy 06-107.4 ⌄

Policy: SFA 06-107.4 Third-Party & Vendor Risk Management Policy — managing the security and privacy risks introduced by vendors and third-party services.

This policy is carried out through standards that live under Policy 06-107.1:

Procedures are being developed and will be published beneath their governing standards using the same 06-107 numbering. Until a procedure is issued, the relevant standard and any interim guidance apply.

Who Is Responsible

The program is led by the SFA Chief Information Security Officer (CISO), supported by the Office of Information Security, with privacy matters coordinated by the university's Privacy Officer(s). The President (Agency Head) approves the program and ensures resources and accountability, and every user carries defined security responsibilities. The complete set of roles is defined in the Information Security Governance Standard (06-107.1.1).

A note on names: At SFA, the senior information security role is the Chief Information Security Officer (CISO). There is no separate "Information Security Officer" position. The abbreviation ISO at SFA refers to the Office of Information Security (the office that supports the CISO), not to a person.

Compliance, Exceptions & Enforcement

Following SFA 06-107 and its standards is mandatory unless a written contract provides otherwise or a formal exception has been granted. Where a requirement genuinely cannot be met and there is no workable fix, an exception may be requested from the CISO, who weighs the risk and may approve compensating controls. Exceptions are not granted to the Acceptable Use Standard (06-107.1.6). Each policy and standard states its own compliance provisions in full.

!
Important
Violations of SFA 06-107 may lead to disciplinary action, up to and including involuntary separation from employment.

Definitions & References

Definitions: terms shown in italics throughout the policies and standards are defined in the SFA 06-107 Definitions.

Controls Crosswalk: the SFA 06-107 Controls Crosswalk maps each requirement to TAC 202, DIR, and NIST 800-53.

Aligned with: UT System UTS 165 · Texas Administrative Code, Chapter 202 · Texas Government Code, Chapter 2054 · DIR Security Controls Catalog · NIST 800-53 Rev. 5.1.1

Responsible office: Office of Information Security  ·  Contact: itsecurity@sfasu.edu, privacyofficer@utsystem.edu

Need Help?

Contact the IT Help Desk at (936) 468-4357 (HELP) or submit a ticket at help.sfasu.edu. For questions about the information security program, contact the Office of Information Security at itsecurity@sfasu.edu.