Information Security Physical & Environmental Policy (SFA 06-107.3)

Summary

Sets SFA's objectives for protecting the facilities, equipment, and environmental controls that support its information systems; carried out by the Physical and Environmental Security Standard (06-107.3.1).

Body

Quick Overview
  • This is one of the information security policies that make up SFA 06-107 and satisfy the state and UT System rules SFA must follow (TAC 202 and UTS 165).
  • It sets the university's high-level goals for keeping IT facilities physically secure and protected from environmental hazards, such as fire, flooding, power loss, and unauthorized entry.
  • It applies to everyone who uses SFA information resources, and especially to anyone who works inside SFA IT facilities, including employees, contractors, vendors, and visitors.
  • A policy says what we must achieve. The matching standard says how. This policy points to one supporting standard.
  • Following SFA 06-107 is mandatory. Not following it can lead to disciplinary action.

Stephen F. Austin State University depends on data centers, server rooms, wiring closets, and other IT facilities to keep its systems running. This policy establishes the university's expectations for keeping those facilities physically secure and protected from environmental threats. In plain terms, it is about who can walk into the rooms that hold SFA's critical technology, and about protecting the equipment inside from hazards like fire, water, extreme temperature, and power failure. It does not contain step-by-step technical instructions; those live in the supporting standard and its procedures. Think of this policy as the "why and what" that everything else builds on.

i
How the pieces fit together
Policy = the goal (what SFA must achieve).   Standard = the requirement (the specific rules that meet the goal).   Procedure = the how-to (the exact steps a team follows). This document is a policy, and it is put into practice by the SFA 06-107.3.1 Physical & Environmental Security Standard listed near the bottom of this article.

Who This Applies To

This policy applies to all users of SFA information resources, and its physical rules matter most to anyone who enters or works inside SFA IT facilities, including:

  • SFA employees (faculty and staff) and student workers
  • Contractors, vendors, and other third-party service providers
  • Research partners and other authorized users of SFA systems and data
  • Visitors and contingent (temporary) workers who enter or work inside SFA IT facilities

Wherever you see an italicized term in the full policy, its exact meaning is in the SFA 06-107 Definitions.

Who Is Responsible

The policy assigns specific duties to leaders at both the UT System and SFA levels. Most users won't hold these roles, but it helps to know who is accountable. Expand for a plain-language summary of the key roles.

Key roles & responsibilities ⌄
A note on names: At SFA, the senior information security role is the Chief Information Security Officer (CISO). There is no separate "Information Security Officer" position. The abbreviation ISO at SFA refers to the Office of Information Security (the office that supports the CISO), not to a person. This article uses CISO for the person and Office of Information Security for the office.

At SFA (Institution level)

  • Agency Head (President): Ensures SFA complies with 06-107, appoints the CISO, funds the security program, and ensures corrective action when rules are broken.
  • Chief Information Security Officer (CISO): Runs SFA's security program and has independent oversight of security across IT, including physical protections for IT facilities.
  • Information Resource Manager (IRM): Implements security controls across the university.
  • Privacy Officer (PO): Guides how the university safeguards records and personal information.
  • Research Security Officer (RSO): Runs the research security program.
  • Data Management Officer (DMO): Oversees how data is classified, managed, and protected.
  • Chief Business Officer (CBO): Ensures procurement includes security and privacy review of vendors.
  • Information Resource Owners & Custodians (IRO / IRC): Grant, control, and monitor access to systems, data, and facilities.
  • Information Security Administrator (ISA): Puts security policies, standards, and procedures into practice for assigned systems.
  • IT Lead of High Risk Assets: Ensures high-risk systems have adequate architecture, backup, recovery, and security and privacy controls.
  • All users: Must follow every 06-107 policy and standard when using SFA information resources.

At the UT System level

Systemwide leaders, including the Chancellor, UT System CISO, CIO, Chief Privacy Officer, Chief Risk Officer, Data Management Officer, and the Risk Management Executive Committee (RMEC), set direction, issue the policies and standards, and designate high-risk assets across all institutions.

Full role definitions The complete list of responsibilities for every role is in the attached policy PDF (Sec. 3, Authority).

What This Policy Covers

The policy sets one group of goal areas for physical and environmental security. Expand the section below to see what it covers in plain language and which standard puts it into practice.

4.1  Physical & Environmental Security Objectives  Securing IT facilities & equipment ⌄

SFA must control who can physically reach its IT facilities and equipment, watch those facilities for unauthorized entry, and protect them from hazards like fire, flooding, and power loss.

  • Security perimeters & protections: Define and put in place secure boundaries and controls around IT facilities that hold equipment, data, wiring, and supporting power and cooling systems, so no one can enter, damage, or interfere with them without authorization.
  • Access provisioning, review & removal: Have a clear process to approve and grant physical access, issue badges or keys, review who still needs access, and take access away when it is no longer needed.
  • Physical security monitoring: Continuously watch IT facilities and their entry points, inside and out, to detect and respond to unauthorized physical access.
  • Visitor control: Set requirements and procedures for visitors entering IT facilities so their access is controlled and monitored.
  • Protecting against physical & environmental threats: Design and maintain IT facilities to guard against threats such as natural disasters, theft, intrusion, and accidents that could affect the confidentiality, integrity, or availability of critical systems.
  • Supporting utilities: Protect facilities and equipment from disruptions to supporting utilities (for example power, cooling, and telecommunications) to prevent loss, damage, or interruption of critical operations.
Put into practice by SFA 06-107.3.1 Physical & Environmental Security Standard

Compliance, Exceptions & Enforcement

Compliance with SFA 06-107 is mandatory unless a written contract says otherwise or a formal exception has been granted. If a requirement genuinely can't be met and there's no workable fix, a user may request an exception through the SFA Chief Information Security Officer (CISO), who weighs the business need against the risk and may approve it with compensating protections. All approved exceptions are documented in an exception log at the institution level.

!
Important
Violations of SFA 06-107 may lead to disciplinary action, up to and including involuntary separation from employment. Exceptions are never granted to the Acceptable Use Standard (06-107.1.6).

Compliance Mapping (Reference)

This section is for auditors, security staff, and anyone who needs the underlying control references. Everyday users can skip it.

Frameworks & control references ⌄

SFA 06-107.3 was written to align with the following authoritative sources:

  • Texas Administrative Code (TAC) 202, Subchapter C: the state rule for information security at Texas institutions of higher education.
  • Texas DIR Security Controls Catalog: the state's baseline control set (for example, the physical protection controls PE-2, PE-3, PE-6, PE-8, PE-12 through PE-17).
  • NIST 800-53 Revision 5.1.1: the federal security and privacy control catalog (this policy's objectives map to the Physical and Environmental Protection family, PE-02 through PE-20).

Each objective in the policy lists the specific control numbers it maps to (for example, NIST PE-02, PE-03, and DIR PE-2, PE-3). The complete objective-by-objective mapping is in the attached policy PDF and in the SFA 06-107 Controls Crosswalk.

Related Policies & Standards

This policy is carried out by the following standard:

Related standards:

Responsible office: Office of Information Security  ·  Contact: itsecurity@sfasu.edu

📎
Official document
The complete, official policy is attached to this article as a PDF, including its full objectives, role definitions, and control mappings. This article summarizes that policy in plain language. If anything in this article conflicts with the attached PDF, the PDF is the official version and takes precedence.

Need Help?

Contact the IT Help Desk at (936) 468-4357 (HELP) or submit a ticket at help.sfasu.edu. For questions about this policy, contact the Office of Information Security at itsecurity@sfasu.edu.

Details

Details

Article ID: 173920
Created
Thu 7/16/26 2:14 PM
Modified
Thu 7/16/26 5:53 PM

Related Articles

Related Articles (2)

Definitions of the key terms used throughout the SFA 06-107 information security program; any term shown in italics in a policy or standard is defined here.
Requirements for physically protecting SFA's facilities and equipment, including physical access controls, visitor controls, environmental protections, and data-center facility requirements; supports Policy 06-107.3.