Quick Overview
- This standard sets the specific requirements for how SFA governs its information security program: the leadership, planning, and documentation behind everything else.
- It carries out the goals in the SFA 06-107.1 Information Security Organization, Personnel & Privacy Policy.
- Most requirements are carried out by security leadership (the CISO and Privacy Officers), not by general users.
- These requirements are the minimum baseline SFA must meet; the university may choose to do more.
- Meeting this standard is mandatory unless a formal exception is granted.
"Governance" is the structure that keeps SFA's security program organized, funded, documented, and accountable to leadership.
This standard spells out what the university must do to build and maintain that structure: create a written security strategy,
keep security documentation current, assign the right roles, plan and report on the program, track its systems, and run
insider-threat and research-security programs. It is the "backbone" standard that the other standards depend on.
|
i
|
Policy vs. Standard
The matching policy (06-107.1) says what SFA wants to achieve. This standard says how, the concrete requirements. Day-to-day steps will live in procedures.
|
Who This Applies To
This standard applies to all SFA employees, users, third-party service providers, research partners, and other authorized users
of SFA information resources. In practice, the requirements below are carried out mostly by the people who build and run the security
program: the CISO, the Office of Information Security, Privacy Officers, and their teams.
|
i
|
Baseline, not a ceiling
Everything here is the minimum SFA must do. Departments may add stricter requirements, but never anything weaker. See the SFA 06-107 Controls Crosswalk for higher control tiers.
|
Who Is Responsible
Key roles & responsibilities
⌄
A note on names: At SFA, the senior information security role is the Chief Information Security Officer (CISO). There is no separate "Information Security Officer" position. The abbreviation ISO at SFA refers to the Office of Information Security (the office that supports the CISO), not to a person.
- UT System CISO: Directs the creation and upkeep of SFA 06-107 in partnership with the institutions.
- SFA Chief Information Security Officer (CISO): Implements information security governance at SFA and reports to the UT System CISO.
- Privacy Officers (PO): Make sure privacy and regulatory obligations are built into governance and documentation.
Full role definitions
Complete responsibilities for each role are in the attached standard PDF.
What This Standard Requires
The requirements are grouped into eight areas. Expand any area for a plain-language summary of what it requires.
The official requirement numbers (like 06-107.1.1.1.1) are shown so you can match them to the attached PDF.
1 Information Security Program Strategy
The written game plan
⌄
SFA must have a documented security strategy and keep it up to date.
- Develop a comprehensive security program strategy aligned with SFA's mission and legal requirements (06-107.1.1.1.1).
- Review and improve the strategy at least once every 12 months (06-107.1.1.1.2).
- Create a written Information Security Plan that documents the strategy (06-107.1.1.1.3).
- Keep track of the laws, regulations, and contracts SFA must comply with (06-107.1.1.1.4).
- Select the specific controls SFA will implement, building an institution-specific control set (06-107.1.1.1.5).
2 Information Security Documentation
Writing it down & keeping it current
⌄
Security policies, standards, and procedures must be written, approved, shared, and maintained.
- Develop and distribute security policies, standards, and operating procedures (06-107.1.1.2.1).
- Get management approval for all security documentation (06-107.1.1.2.2).
- Update documents whenever there are policy, control, risk, or exception changes (06-107.1.1.2.3).
- Keep a process to record, assess, approve, and track cases of non-compliance and exceptions (06-107.1.1.2.4).
3 Information Security & Privacy Roles
Naming who's in charge
⌄
SFA must formally appoint the leaders who run the security program.
- Appoint a Chief Information Security Officer (CISO) with the mission and resources to coordinate, develop, and maintain the security program (06-107.1.1.3.1).
4 Capital Planning, Reporting & Milestones
Budgeting & measuring progress
⌄
The program must be funded, tracked, and reported to leadership.
- Include security program resources in capital planning and budget requests (06-107.1.1.4.1).
- Track plans of action and milestones to measure the program's effectiveness (06-107.1.1.4.2).
- Report to the Agency Head at least once every 12 months on how well the program is working (06-107.1.1.4.3).
5 System Inventory & Architecture
Knowing what we have
⌄
SFA must keep an inventory of its systems and design them with security in mind.
- Maintain and update an inventory of in-scope information systems at least every 24 months (06-107.1.1.5.1).
- Develop and maintain security-aware system architectures (06-107.1.1.5.2).
- Have the Risk Management Executive Committee review high-risk assets at least every 24 months (06-107.1.1.5.3).
6 Groups, Reports & Privacy Restrictions
Staying informed & reporting
⌄
SFA must stay connected to the broader security community and handle privacy reporting properly.
- Identify relevant security groups and forums to stay current on threats (06-107.1.1.6.1).
- Collect and act on threat intelligence from trusted sources (06-107.1.1.6.2).
- Review procedures for handling Personally Identifiable Information (PII) at least every 12 months (06-107.1.1.6.3).
- Produce privacy reports at least every 12 months for the right stakeholders (06-107.1.1.6.4).
- Determine and allocate the resources needed to protect the institution (06-107.1.1.6.5).
7 Insider Threat Program
UTS 165
Risks from within
⌄
SFA must run a program to detect and respond to threats that come from people inside the organization.
- Establish an insider-threat program with procedures for reporting suspected activity to the CISO and appropriate offices (06-107.1.1.7.1).
8 Research Security Program
UTS 165
Protecting research
⌄
The Research Security Officer must run a program covering the key research risk areas identified by federal and state governments.
- Establish and maintain a research security program addressing intellectual property, research/proprietary data security, foreign collaboration, insider threats, and other key risks (06-107.1.1.8.1).
Conformance & Exceptions
Meeting this standard is mandatory and effective as of the standard's publication, unless a written contract says otherwise
or a formal exception has been granted. If a requirement genuinely can't be met and there's no workable fix, follow the exception process in
the SFA 06-107.1 policy; requests go to the SFA Chief Information Security Officer (CISO).
|
!
|
Important
Violations of SFA 06-107 may lead to disciplinary action, up to and including involuntary separation from employment.
|
Compliance Mapping (Reference)
For auditors and security staff. Everyday users can skip this section.
Frameworks & control references
⌄
Each requirement in this standard maps to one or more of these authoritative sources:
- NIST 800-53 Rev 5.1.1, for example the PM (Program Management), AC, AT, and PL control families.
- TAC 202, Subchapter C, for example 202.7, 202.71, 202.73, 202.74, 202.76.
- Texas DIR Security Controls Catalog, for example PM-2, PM-3, PM-4, PM-15.
- NIST CSF, NIST 800-171, and privacy frameworks (GDPR, HIPAA, GLBA) where relevant.
The full requirement-by-requirement control mapping is in the attached standard PDF and the SFA 06-107 Controls Crosswalk.
Related Policies & Standards
Supporting policy: SFA 06-107.1 Information Security Organization, Personnel & Privacy Policy
Definitions: SFA 06-107 Definitions
Related standards:
Other references:
- SFA 06-107 Controls Crosswalk Reference
- Texas DIR Information Security Plan Overview · Texas Government Code Title 10, Subtitle B, Chapter 2054
Responsible office: Office of Information Security; Systemwide Chief Privacy Officer ·
Contact: itsecurity@sfasu.edu, privacyofficer@utsystem.edu
|
📎
|
Official document
The complete, official standard is attached to this article as a PDF, including its full requirement text, role definitions, and control mappings. This article summarizes that standard in plain language. If anything in this article conflicts with the attached PDF, the PDF is the official version and takes precedence.
|
Need Help?
Contact the IT Help Desk at
(936) 468-4357 (HELP) or submit a ticket at
help.sfasu.edu.
For questions about this standard, contact the Office of Information Security at
itsecurity@sfasu.edu.