Shared Systems Security Policies & Practices

Note: The policies detailed in this document were developed as result of the CUWL Data Privacy & Retention Task Force report. The recommendations in that report, including those below on best practices to protect sensitive data, were adopted by CUWL in April 2025. This document acknowledges that local campus security practices around systems and staff training exist, and may supersede the proposed and existing policies noted below.

Policies

General

  • Shared Systems used by staff such as Alma and ILLiad as well as Shared Systems tools such as Redmine, should only be accessed by devices configured securely to protect the privacy, security, confidentiality, integrity, and availability according to local campus IT and security policies.
  • All non-student library staff should be required to complete local campus IT security training at regular intervals according to local campus practice. If student staff are not required to complete the same training, they should be strongly encouraged to complete the same training.
  • Discovery-Fulfillment will take additional steps to ensure walk-in patron records are purged at the same time campuses are purging regular patron records.

Alma Staff Role Policies

Alma Analytics Access

Alma Analytics provides access to very sensitive data such as personally identifiable information (PII), which is subject to data governance restrictions. Alma Analytics has no granular data access restrictions. Alma Analytics is an expert's tool that will require a time commitment from staff to understand its user interface, data model and the Alma-to-Analytics data ingestion process (i.e., it is easy to get some numbers out of Analytics, but that does not guarantee they are the right numbers for your inquiry).

  • Alma roles with access to Alma analytics should be granted only after additional training is provided to staff that will:
    • Educate staff on what patron data is available within Analytics.
    • Include notes about how and where to save your work in Alma Analytics
    • Include an overview of basic functionality of the system, and, importantly, how to ensure that shared reports within Analytics are not modified in ways that break campus wide reporting.

Alma NZ Access

  • Access must be approved by Shared Systems Manager, the Shared Content Expertise Group, or the Discovery-Fulfillment Expertise Group.
  • Staff with NZ access are documented in [Link for document 115351 is unavailable at this time], which includes who requested access and who approved it and the date access was granted.

Practices



Keywords:
Shared Systems Security Policies & Practices Best Practices To Protect Patron Data Privacy
Doc ID:
150747
Owned by:
Curran R. in UWLSS
Created:
2025-05-13
Updated:
2025-12-18
Sites:
UW Libraries Shared Systems, UW-Madison Libraries