UW-Madison - IT - Cybersecurity Risk Management Policy
Applies to all information systems of any kind that store or process data used to accomplish University research, teaching and learning, or administration.
The Policy requires application of the currently approved Implementation Plan to all covered systems.
Cybersecurity risk will be managed to ensure that the likelihood and impact of threats and vulnerabilities are minimized to the extent practical. Guided by the Principles below, the focus of this policy is the protection of University data and the associated information systems.
The process described in the Implementation Plan of this policy, is the mandatory process for managing the cybersecurity risk associated with all information systems of any kind that store or process data used to accomplish University research, teaching and learning, or administration. Data not owned by the University may fall within the scope of this policy if the data is stored or processed using University assets.
The initial process and any future revisions of the process will be reviewed and approved by IT Governance(1). Any IT governance group or the Office of Cybersecurity may initiate a revision by contacting the Policy Analysis Team who will engage IT Governance.
The process will be phased in. Restricted Data systems will be first, with Sensitive and Internal then Public systems to follow. The activity level to secure a system will be proportional to the data driven categorization of the information system and intended level of risk with the system in operation.
- Rates for assessing risk or providing a central hosting service which meets many of the risk management requirements will be developed by the service provider, vetted within IT governance, with final determination by senior campus leadership.
- Determining funding for risk management activity and compliance matters is the responsibility of each school, college, or division through use of approved sources.
Research, teaching and learning, or administrative systems that have a short life span (less than one year) and present a low risk, or that temporarily present a moderate risk, may be granted a temporary exception by registering and describing the system through the Risk Management Framework package intake process, or its successor or designee. Each system will be evaluated on a case-by-case basis to determine the system risk category, the estimated duration of the risk, and if granted, the duration of the exception.
The Office of Cybersecurity will provide mandatory cybersecurity training for leaders, managers, system developers and users. Training will be appropriate to the audience, and will be phased in over time.
The University of Wisconsin-Madison is a leading public institution of learning and higher education. As such, our mission is to create and disseminate knowledge and to learn the truth wherever it may be found. Fundamental to this mission is the academic freedom, the “fearless sifting and winnowing” process emblazoned at the entrance to Bascom Hall by the class of 1910.
Recognizing that monitoring and analysis employed for network defense against cybersecurity threats can have a significant chilling effect on learning and academic freedom, the Office of Cybersecurity will operate under the following principles:
We respect academic freedom and personal privacy as we help protect the integrity and reputation of the University, and provide a secure and safe computing environment for teaching, research, and outreach.
We understand the value of University information as a product of research, teaching, and learning, including the personal data of our faculty, staff, and students.
We are committed to ensuring the appropriate security of all data, specifically ensuring that faculty, staff, and student data is not placed at undue risk of exposure.
We are accountable to the University community for our deployment and use of network analysis and monitoring tools. Our activity preserves and strengthens the privacy and academic freedom of faculty, staff, students, and other members of our community.
We ensure that risk analysis tools and active filtering methods are used only for the detection of malicious activity, and are not used for examining any other content in the data stream.
We evaluate the content of system and network traffic only to the extent necessary to detect known security threats or emerging indications of compromised systems. Specifically:
Our tools and techniques are not used to monitor individual activity. Data generated or collected that may identify individual behavior will be retained no longer than is necessary to identify and evaluate malicious traffic.
Data generated is used only to detect threats, vulnerabilities, and compromises. Any personal or private content captured during the testing and detection process is ignored, and is either not recorded at all, or is eliminated immediately in cases where temporary recording is technologically necessary.
Data collected is accessible only by staff responsible for maintaining the security of computing systems, and only for the purpose of diagnosing and remediating security incidents. This data will not be released for any other purpose, except to comply with legal requests.
We make decisions on network and cybersecurity defensive measures through a defined and shared process that implements the principles above. We will ensure that our process allows for temporary situations where immediate defensive action is needed, and reviews those temporary measures to determine if they should become ongoing.
We implement prevailing cybersecurity practices that reduce or eliminate the potential for impacting Availability, Integrity or Confidentiality of data and information systems.
The procedures that implement the Risk Management Framework are developed with collaboration in mind and will be revised collaboratively as conditions warrant.
Cybersecurity is a collective responsibility which requires policy that applies to all components of the University of Wisconsin-Madison. Threat, vulnerability and likelihood of exploitation are complex and unique to specific business processes and technologies. Cybersecurity risk is measurable depending on quantified or classified aspects of the data; characteristics of the information system; the definitions and characteristics of internal or external threat, system or environmental vulnerabilities; and the likelihood that the event or situation may manifest itself within a given application, information system or architecture. External threats evolve rapidly and are persistent based on the criminal intent or the resources of the attacker, whether they are criminal or nation state backed. Internal threats can be accidental or intentional.
The impact of using diverse but competing approaches in implementing security controls applied to information systems tends to elevate overall cybersecurity risk.(2) The management of cybersecurity risk will use a detailed Risk Management Framework to balance among academic / business needs, the potential impact of adverse events, and the cost to reduce the likelihood and severity of those events.
The risk management process is established in policy so that the University community can share a common understanding that:
The University is determined to manage cybersecurity risk effectively. Not doing so is likely to have unacceptable consequences to individuals and increase cost to the institution.
This is the University’s mandatory and universally applicable process for managing cybersecurity risk. The process can be tailored to specific technologies, processes, or services.
The process must include policy and procedural controls to ensure that privacy and academic freedom are respected.
AuthorityThis policy was approved by the Information Technology Committee and issued by the CIO on March 16, 2018.
Failure to build and maintain information systems that adhere to the policy and principles or which significantly deviate from the Implementation Plan will likely increase risk to University data and information systems. Significant architecture, development or operating and process deviations which result is elevated risk or which impact compliance may result in the following:
Computing services or devices may be denied access to University information resources.
University employees may be subject to disciplinary action up to and including termination of employment.
Contractors or associates may be subject to penalty under the governing agreement. Compliance may be a consideration affecting new or renewed agreements.
Please address questions or comments to the Office of Cybersecurity at email@example.com.
- Cybersecurity Risk Management Implementation Plan - https://kb.wisc.edu/itpolicy/it-cybersecurity-risk-management-plan.
- Cybersecurity Risk Management Memorandum - https://kb.wisc.edu/itpolicy/it-cybersecurity-risk-management-memorandum.
- IT Policy Glossary – https://kb.wisc.edu/itpolicy/glossary.
- IT Governance is defined at https://it.wisc.edu/it-community/governance/.
- From Framework for Improving Critical Infrastructure Cybersecurity, National Institute for Standards and Technology, February 2014.