Information Security Program Definitions (SFA 06-107)

Summary

Definitions of the key terms used throughout the SFA 06-107 information security program; any term shown in italics in a policy or standard is defined here.

Body

Quick Overview
  • Definitions of the key terms used across the SFA 06-107 information security policies and standards.
  • Any term shown in italics in a policy or standard is defined here.
  • These are the official definitions from Appendix A of SFA 06-107.
  • Use the A–Z links below, or your browser's Find (Ctrl+F / Cmd+F), to jump to a term.

The SFA 06-107 policies and standards use a number of defined terms with specific meanings. This glossary collects those definitions in one place so you can look up a term without hunting through the individual documents. The definitions are reproduced from the official SFA 06-107 Definitions; if you need the authoritative source, it is attached to this article as a PDF.

i
Where you'll see these terms
Throughout the SFA 06-107 policies and standards, defined terms appear in italics. When you come across one and want its exact meaning, this glossary is where to look.
Jump to:  A  |  B  |  C  |  D  |  E  |  F  |  H  |  I  |  M  |  N  |  P  |  R  |  S  |  T  |  U  |  V

A

Artificial intelligence systems means systems capable of: (A) perceiving an environment through data acquisition and processing and interpreting the derived information to take an action or actions to imitate intelligent behavior given a specific goal; and (B) learning and adapting behavior by analyzing how the environment is affected by prior actions.

Asset(s): all the hardware, software, data, and network resources that the University owns and uses to conduct business operations or research. Examples include but are not limited to computers, servers, laptops, mobile devices, printers, storage devices, routers, switches, firewalls, software licenses, databases, digital medical devices, and other digital information resources.

Audit record(s): electronic or paper records that provide documented details of activities performed within an information system, network, or application. Audit records provide a detailed account of all system and user activities, including authentication, authorization, access to sensitive data, configuration changes, software installations, network connections, and other events that could impact system or data security or privacy. Audit records typically contain information such as user ID, date and time of the event, IP address, system location and any related data or actions.

Authenticator(s): a mechanism used to confirm the identity of a user, device, or entity before granting access to sensitive data or information resources. It is typically a password, passphrase, persona identification number (PIN), token, or biometric identifier that is used to authenticate the user's identity. External authenticators are often used in situations where there is a high risk of password compromise or where advanced authentication beyond a user ID and password may be necessary. External authenticators can include smart cards, Universal Serial Bus (USB) keys, one-time passwords, and more, which are used in combination with a password or PIN to authenticate the user's identity.

B

Backup(s): copy of files or applications created to avoid loss of data and facilitate recovery in the event of an information system failure or other data loss event.

Biannual: a cadence of twice within 12 calendar months.

Biennial: a cadence of once every 2 calendar years.

Bring Your Own Device (BYOD): the practice of allowing users (employees, visitors, students, etc.) to use their personal mobile devices such as smartphones, tablets, and laptops within the University IT facilities. With BYOD, users may use their own devices to access company or school information systems, collaborate with colleagues or classmates, and complete work-related tasks via the company network if there are no dedicated guest or student networks available.

C

Change management: process of controlling the communication, approval, implementation, and documentation of changes to information systems, hardware, software, and procedures to ensure that information resources are protected against improper modification before, during, and after system implementation.

Change(s): any addition, modification, update, or removal / disposal of an information resource.

Classification / classify: the process of categorizing data and assets based on their level of sensitivity, confidentiality, availability, regulatory provisions, or value and potential risk if disclosed inappropriately. Classification helps organizations to identify their most valuable or critical assets and data, apply appropriate security measures to protect them and allocate resources more efficiently, reducing the risk of unauthorized disclosure, data breaches, and other security incidents and risks. See the and the SFA 06-107 definitions for confidential data, controlled data, and published data for more information.

Cloud computing / cloud services / cloud: has the same meaning as "advanced Internet-based computing service" as defined in Texas Government Code 2157.007(a): “a service that provides network access to a shared pool of configurable computing resources on demand, including networks, servers, storage, applications, or related technology services, that may be rapidly provisioned and released by the service provider with minimal effort and interaction. The term does not include telecommunications service, or the act of hosting computing resources dedicated to a single purchaser.”

Confidential data: the confidential classification applies to data that is exempt from disclosure under applicable state law, including the Texas Public Information Act, and federal laws. Data or information meeting these criteria are designated with the classification of “confidential” within the SFA 06-107.1.6 Information Data Protection & Privacy Standard. Examples include: patient billing Information and Protected Health Information subject to the Health Insurance Portability and Accountability Act (HIPAA) or applicable state law, student education records subject to the Family Educational Rights and Privacy Act (FERPA), a social security number, medical research data that contains protected health information, certain student loan information subject to the Gramm Leach Bliley Act (GLBA), certain personal information associated with individuals from the European Union subject to the General Data Protection Regulation (GDPR), or cardholder data subject to the Payment Card Industry Data Security Standard (PCI DSS).

Controlled data: the controlled classification applies to information / data that is not generally created for or made available for public consumption but may be subject to release to the public through the Texas Public Information Act or similar state or federal law. Examples include: operational records, operational statistics, employee salaries, budgets, expenditures, and certain internal communications.

Critical / criticality / mission critical information resources: information resources defined by the University or state agency to be essential to the University’s ability to meet its instructional, research, patient care, or public service missions. The loss of these resources or inability to restore them in a timely fashion would result in the failure of the University’s operations, inability to comply with regulations or legal obligations, negative legal or financial impact, or endanger the health and safety of faculty, students, staff, and patients. Mission critical information resources include but are not limited to: Information systems managing confidential data, common use infrastructures, Institutional network and data center infrastructure, identity and access management systems (such as single-sign-on or other applications required to enable access to other critical systems), administrative systems (e.g., Human Resources (HR), Finance, Payroll, student / patient enrollment and billing, etc.), student information systems, patient care and life-support systems, etc.

Cryptographic module: a set of hardware, software, and / or firmware that implements approved security functions and is contained within a cryptographic boundary, including cryptographic algorithms (mathematical functions that perform encryption, decryption, hashing, and digital signatures), keys (used to encrypt and decrypt data and to digitally sign messages), and other secrets (such as passwords, application programming interface (API) keys, and certificates).

D

Data: elemental units, regardless of form or media, that are combined to create information used to support research, teaching, patient care, and other University business processes. Data may include but is not limited to: written, electronic video, and audio records, photographs, negatives, etc.

Data breach: the acquisition, access, use, or disclosure of protected health information (PHI) in a manner not permitted under subpart E of the Health Insurance Portability and Accountability Act (HIPAA) which compromises the security or privacy of the protected health information.

Data minimization: the Fair Information Practice of only collecting personally identifiable information (PII) that is directly relevant and necessary to accomplish the specified purpose(s), and only retaining PII for as long as is necessary to fulfill the specified purpose(s). It also extends to only allowing access to specific PII elements to only those individuals who have a legitimate need to view and utilize those elements.

Data mining: the process of extracting and discovering useful information and patterns from large datasets. Data mining involves using statistical and machine learning techniques to identify trends, correlations, and relationships within the data that might not be immediately apparent. The goal of data mining is to uncover insights that can be used to make more informed business decisions or gain a better understanding of a particular phenomenon.

Decentralized IT: information technology service and support organizations reporting to the heads of business units, departments, or programs, including researchers that manage or support their own information systems.

Device(s) / computing device(s): any physical tool or piece of equipment capable of sending, receiving, or storing digital data. Devices include but are not limited to: computer servers, workstations, desktop computers, laptop computers, tablet computers, cellular / smart phones, personal digital assistants, Universal Serial Bus (USB) drives, embedded devices, smart watches and other wearable electronic devices, etc.

Digital media / digital data: electronic content / data that is transmitted or stored digitally, and can be displayed, accessed, and distributed through electronic devices such as computers, smartphones, and tablets. Digital media encompasses any form of electronic media that can be recorded, edited, transmitted, and stored using digital technology. Examples of digital media include online videos, photos, music files, eBooks, websites, and social media platforms.

Disposal / dispose: the process of securely and permanently removing data from the University information system or storage medium in a way that does not allow for its recovery or reconstruction. The disposal method used depends on the type and criticality / sensitivity of the data, the medium on which it is stored, and regulatory or legal requirements. Disposal of physical assets typically involves evaluating the asset's value, determining if it can be sold or recycled, and following established procedures for removing it from the University's inventory and transferring it to its new owner or ending its use. Disposal of assets must be executed by the appropriate University-defined users and must not be executed by individual users.

E

Electronic media: electronic storage media including storage devices in computers (hard drives, memory) and any removable / transportable digital storage medium, such as magnetic tape or disk, optical disk, or digital memory card; or transmission media used to exchange data already in electronic storage media. Transmission media includes, for example, the internet (wide-open), extranet (using internet technology to link a business with data accessible only to collaborating parties), leased lines, dial-up lines, private networks, intranet, and the physical movement of removable / transportable electronic storage media.

F

Fair Information Practice Principles (FIPPS): collection of widely accepted principles that the University use when evaluating information systems, processes, programs, and activities that affect individual privacy. The FIPPs serve as the foundation for privacy laws and policies and include but are not limited to: transparency, security, purpose specification and use limitation, individual participation, quality and integrity, minimization, and authority.

H

High impact / high impact information resource(s) / high impact asset(s): information resources whose loss of confidentiality, integrity, or availability could be expected to have a severe or catastrophic adverse effect on organizational operations, organizational assets, or individuals. Such an event could: cause a severe degradation in or loss of mission capability to an extent and duration that the organization is not able to perform one or more of its primary functions, result in major damage to organizational assets, result in major financial loss, or result in severe or catastrophic harm to individuals involving loss of life or serious life threatening injuries.

High Risk Asset(s): assets which store, process, or transmit highly sensitive or confidential data that include data from Institutions or organizations other than the sponsoring Institution that are designated by the SFA Administration Risk Management Executive Committee (RMEC) to be “high risk”.

I

Identifier: a piece of information used to uniquely identify a individual / user, system, or entity within a particular University information system / environment. These identifiers are used in authentication and authorization processes to ensure only authorized access to the system is granted. Identifiers include but are not limited to: usernames, employee IDs, IP addresses, machine names, biometric data, or any other unique piece of information that can be used to associate a user with a specific device or account.

Incidental use: infrequent use of the University provided technology resources in short intervals of time and unrelated to the University work or business and which does not cause additional expense or burden to the University.

Information resource(s): any and all computer printouts, online display devices, mass storage media, and all computer-related activities involving any device capable of receiving email, browsing the Internet, or otherwise capable of receiving, storing, managing, or transmitting data. Additionally, information resources are the procedures, equipment, facilities, software, and data that are designed, built, operated, and maintained to create, collect, record, process, store, retrieve, display, and transmit data. Information resources include but are not limited to: mainframes, servers, network infrastructure, personal computers, notebook computers, hand-held computers, pagers, distributed processing systems, network attached, and computer controlled medical and laboratory equipment (i.e. embedded technology), telecommunication resources, network environments, telephones, fax machines, printers and service bureaus.

Information security program / program: the Policies, Standards, Procedures, Guidelines, processes, elements, structure, strategies, objectives, plans, metrics, reports, resources, and services adopted for the purpose of securing SFA information resources.

Information system(s) / system(s): an interconnected set of information resources under the same direct management control that shares common functionality. An information system typically includes hardware, software, network infrastructure, information, data, applications, communications, and users.

Insider threat: a risk caused by an individual or user within the University who has access to sensitive data, information, or information systems and intentionally or unintentionally causes harm to the University, its assets, or its users. Insider threats can be caused by various factors, such as a user’s motivation to harm the University, carelessness, errors, or lack of knowledge. Insider threat may include any activity that poses a threat to the University, such as stealing and unauthorized disclosure of confidential data or intellectual property, sabotaging information systems, unauthorized access, or financial fraud.

Intra-system connections: enable devices to interact with each other for transmission, processing, and storage of data.

IT Lead of High Risk Asset(s): the individual responsible for overseeing or directing the architecture and development and designated to be “high risk” by the SFA Administration Risk Management Executive Committee (RMEC).

M

Maintenance: the process of keeping hardware, software, other components of an information system, asset, or IT facility in good working condition to ensure that information systems, assets, and IT facilities operate efficiently, effectively, and securely over their entire life cycle.

Monitor(ing): the process of observing and tracking the activities and events taking place within an IT environment in order to detect and prevent security incidents before they can cause substantial damage, such as data breaches, unauthorized disclosures, information system disruption, or compliance violations. Monitoring activities can include but are not limited to: Intrusion Detection and Prevention Systems (IDPS), Security Information and Event Management (SIEM) tools, File Integrity Monitoring (FIM), vulnerability scanning, penetration testing, and continuous compliance monitoring.

N

Network infrastructure: the distributed hardware and software (i.e., cabling, routers, switches, wireless access points, access methods, and protocols), information, and integrating components that allow institutional network hosts to communicate with one another and enable the administrative, learning, research, and health care missions of the University.

Non-digital media: any type of content / data that is not created, stored, or transmitted in electronic form. These forms of media rely on physical objects and require manual manipulation and distribution. Non-digital media includes but is not limited to: printed materials such as books, newspapers, and magazines, as well as analog recordings such as vinyl records, cassette tapes, and VHS tapes. Other examples of non-digital media include: paintings, sculptures, and traditional forms of communication such as face-to-face conversations and snail mail.

P

Portable computing device(s): any easily movable device capable of viewing, receiving, transmitting, and / or storing data. Portable computing devices include, but are not limited to: notebook computers, handheld computers, tablets (e.g., iPads, etc.), PDAs (personal digital assistants), pagers, smartphones (e.g., iPhones, etc.), Universal Serial Bus (USB) drives, memory cards, external hard drives, data disks, CDs, DVDs, and similar storage devices.

Privileged user account(s) / privileged / privileged user(s) / privilege account(s) / privileged access: accounts / users with administrative privileges or elevated permissions within the University information system or network, which enable the users to access and perform tasks that are otherwise not provisioned for standard user accounts, such as configuring settings, installing software, and administering the network.

Published data: the published classification is the lowest risk and includes data / information made available to the public through posting to public websites or distribution through email, social media, print publications, or other media. Published data includes but is not limited to: statistical reports, Fast Facts, Published Research, unrestricted directory information, or educational content available to the public at no cost.

R

Recovery Point Objective(s) (RPO(s)): the maximum amount of data loss that the University can tolerate following a disruption. Recovery Point Objectives specify the specific point in time to which data must be recovered after a failure or disaster in order for the business to be able to resume operations.

Recovery Time Objective(s) (RTO(s)): the maximum amount of time that the University can afford to be without its information systems, applications, and data following a disruption. Recovery Time Objectives represent the amount of time that the University is willing to tolerate before resuming normal business operations.

S

Security incident(s) / incident (s): an event that indicates potential / suspected unauthorized access, loss, unauthorized disclosure, data breach, modification, disruption, or destruction of data or information resources whether accidental or deliberate, or evidence of intrusion.

Shared / group account(s): user accounts that are accessed and used by multiple individuals, usually created for a specific purpose, such as accessing a shared information resource or for a team project. Instead of having individual accounts for each user, a shared / group account allows multiple people to use a single account.

Significant attack(s): a security incident that is a major threat to the confidentiality, integrity, or availability of the University information recourses / data / assets or causes a substantial material loss or disruption of institutional activities. A significant attack could be a deliberate attempt to compromise or exploit a vulnerability in the University's information systems, or an unintentional event that results in a significant impact to the University's information security posture.

Social engineering: the use of psychological manipulation or deception to influence individuals / users to disclose sensitive or confidential data, perform certain actions, or compromise information systems. The goal of social engineering is to exploit human weaknesses and trust in order to gain access to data or information systems that would otherwise be difficult to obtain. Social engineers may use a variety of techniques such as posing as a legitimate authority figure, creating a sense of urgency or fear, or building a rapport with the target in order to build trust and gain access to sensitive data or information systems.

Social mining: refers to the process of extracting insights or data from social media platforms, online forums, and other publicly available information resources. This can include data on user behavior, preferences, opinions, and sentiment, as well as potential indicators of cyber-attacks or vulnerabilities. Social mining is often used by marketers, researchers, and law enforcement agencies to gain insights into consumer behavior, public opinion, and potential security threats, among other things.

Stephen F. Austin State University (SFA) / SFA: Stephen F. Austin State University, a member institution of the University of Texas (UT) System. Within these documents, SFA, the University, and the Institution refer to Stephen F. Austin State University.

System / systemwide: the University of Texas (UT) System considered as a whole, including UT System Administration and all UT System member institutions. Used to describe requirements or functions that apply across the entire UT System rather than to SFA alone.

T

Tactics, techniques, and procedures (TTPs): hash values, IP addresses, malware types and / or signatures / domains, or other methods used by threat actors to achieve specific objectives during a cyber-attack. Tactics refer to the overall goals or objectives of an attack, such as gaining access to a network or stealing sensitive data. Techniques refer to the specific methods or tools used to carry out an attack, such as malware, phishing, or social engineering. Procedures refer to the step-by-step actions that threat actors take to execute an attack, such as reconnaissance, initial exploitation, command and control, and exfiltration.

U

Unauthorized disclosure: a security incident in which confidential, sensitive, or private data is unintentionally, accidentally, or purposefully released to an uncontrolled environment outside of the University or is accessed by an unauthorized individual without proper permission. It can occur due to various reasons, such as human error, system errors, lack of appropriate security measures, or through malicious attacks.

University of Texas (UT) Institution(s) / Institution(s) / institutional: Stephen F. Austin State University (SFA). SFA is a member institution of the University of Texas (UT) System; within these documents, references to the Institution or the University mean SFA.

University of Texas (UT) System Administration / System Administration: the central administrative offices of the University of Texas (UT) System that provide oversight and coordination across UT System institutions, including SFA. Includes the UT System Administration Chief Information Security Officer (CISO) and the UT System Administration Chief Information Officer (CIO).

User(s): an individual, automated application, or process that is authorized by the owner to access the information resource, in accordance with federal and state law, the University policy, and the owner's procedures and rules. Has the responsibility to use the information resource only for the purpose specified by the owner, comply with controls established by the owner, and prevent the unauthorized disclosure of confidential data. The user is any person who has been authorized by the owner of the information resource to read, enter, or update that data / information and can include students and volunteers. The user is the single most effective control for providing adequate security.

V

Vendor(s) / third party(ies) / third party service provider(s): any third-party user or entity that contracts with the University to provide goods and / or services to the Institutions.

Visitor(s): an individual who enters the University physical space or virtual environment that belongs to an organization, but who is not an authorized user of the University. A visitor may be a vendor or other third-party service provider, patient, consultant, auditor, customer, prospective student and guests, or any other person who has a legitimate reason to be present, but who does not have the same level of access or permissions as an employee or authorized user. Individuals with permanent physical access authorization credentials are not considered visitors.

Related Policies & Standards

These definitions apply across the entire SFA 06-107 family. Browse the documents that use them:

📎
Official document
The complete, official SFA 06-107 Definitions are attached to this article as a PDF. This glossary reproduces those definitions; if anything here ever conflicts with the attached PDF, the PDF is the official version and takes precedence.

Need Help?

Contact the IT Help Desk at (936) 468-4357 (HELP) or submit a ticket at help.sfasu.edu. For questions about these definitions, contact the Office of Information Security at itsecurity@sfasu.edu.

Details

Details

Article ID: 173941
Created
Thu 7/16/26 4:39 PM
Modified
Fri 7/17/26 3:20 PM

Related Articles

Related Articles (17)

Requirements for the responsible use of SFA technology, including mobile and endpoint devices and the security duties of managers and general users; applies to everyone with no exceptions and supports Policy 06-107.1.
Requirements for controlling who can access SFA systems and data, including account and authenticator (password) management, least privilege, and identity and login controls; supports Policy 06-107.2.
Requirements for tracking and protecting SFA's technology assets across their life, from inventory and acceptable use through secure return, disposal, and reuse; supports Policy 06-107.2.
Requirements for SFA's security and privacy training, including general awareness training, role-based training for specialized duties, and training records; supports Policy 06-107.1.
Requirements for keeping SFA services running and recoverable during a disruption, including continuity and disaster-recovery planning, impact analysis, alternate capacity, and backups; supports Policy 06-107.2.
Requirements for identifying, assessing, and managing cybersecurity risk at SFA, including risk assessments, continuous monitoring, control assessments, and vendor risk management; supports Policy 06-107.1.
Requirements for preparing for and responding to security incidents at SFA, including incident planning, response, communication, and reporting; supports Policy 06-107.2.
Requirements for protecting SFA data and personal information throughout its life, including data handling and classification, encryption and transmission, consent and notices, and retention; supports Policy 06-107.1.
Requirements for governing SFA's security program, including the security strategy, documentation, leadership roles, planning and reporting, system inventory, and the insider-threat and research-security programs; supports Policy 06-107.1.
Sets SFA's objectives for governing the security program and protecting its people, vendors, data, and privacy, including awareness and training, acceptable use, AI governance, and research security; carried out by Standards 06-107.1.1 through 06-107.1.6.
Sets SFA's objectives for protecting the facilities, equipment, and environmental controls that support its information systems; carried out by the Physical and Environmental Security Standard (06-107.3.1).
Sets SFA's objectives for the technical safeguards that protect its systems, devices, and data, covering access, asset management, system development, continuity and disaster recovery, security monitoring, and incident response; carried out by Standards 06-107.2.1 through 06-107.2.6.
Requirements for managing the security responsibilities of staff and vendors across the employment lifecycle, from screening and rules of behavior through transfers, offboarding, and discipline; supports Policy 06-107.1.
Requirements for physically protecting SFA's facilities and equipment, including physical access controls, visitor controls, environmental protections, and data-center facility requirements; supports Policy 06-107.3.
Requirements for watching for and responding to security threats, including event logging, network security, malware protection, penetration testing, threat intelligence, and vulnerability remediation; supports Policy 06-107.2.
Requirements for building, configuring, and maintaining SFA systems securely, including secure development, configuration baselines, system maintenance, and change management; supports Policy 06-107.2.
Sets SFA's objectives for identifying and managing the security and privacy risks introduced by vendors and third-party services, from pre-purchase review through ongoing oversight; carried out through the Cybersecurity Risk Management (06-107.1.2) and Personnel & Third-Party Security (06-107.1.3) Standards.