3341-6-64 Information Security

ApplicabilityAll University units
Responsible OfficeVice President for Finance and Administration
Responsible AdministratorChief Information Officer
  1. Policy Statement and Purpose

    This policy serves as a measure to protect the confidentiality, integrity, and availability of Institutional Data as well as any Information Systems that store, process, or transmit Institutional Data. This policy establishes a framework to safeguard the university’s electronic information resources and computing and networking infrastructure from threats and to ensure compliance with applicable laws and regulations.

  2. Policy Scope

    This policy applies to all faculty, staff, students, third-party agents, contractors, and any other university affiliates authorized to access Institutional Data or use university-owned Information Systems. It encompasses all data and systems owned, managed, or used by the university, regardless of where they are stored or accessed.

  3. Policy Definitions

    1. Institutional Data

      Data that are created, collected, stored, or managed by the university in the course of its academic, research, or administrative operations, including but not limited to student records, financial data, employee information, and research data.

    2. Information Systems

      Any hardware, software, networks, or services used to store, process, or transmit Institutional Data, including university-owned devices, cloud services, and personal devices used for university business.

    3. Principle of Least Privilege

      The Principle of Least Privilege is a foundational aspect of information security. It states that people should only have access to the minimum amount of data and systems that they require to perform the specific, intended functions of their jobs.

    4. University Affiliate

      Any individual or entity authorized to access Institutional Data or Information Systems, including faculty, staff, students, contractors, vendors, and third-party agents.

  4. Policy

    BGSU is committed to protecting the confidentiality, integrity, and availability of its Institutional Data and Information Systems. The university adopts the following principles to achieve this objective:

    1. Data Protection

      All Institutional Data must be protected in accordance with its classification, as defined by the university’s Data Use and Protection Policy.

    2. System Security

      Information Systems must be configured, maintained, and operated in a manner that minimizes risks to their security and ensures their availability for authorized use, as defined in the documentation and procedures approved by the Information Security Office, given the level of classification, value and criticality that the system and its data have to the University.

    3. User Responsibility

      All University Affiliates are responsible for safeguarding Institutional Data and Information Systems they access or use, adhering to university policies, procedures, and guidelines as defined by the Information Security Office.

    4. Risk Management

      The university will implement risk-based security measures (applying the Principle of Least Privilege) to identify, assess, and mitigate threats to Institutional Data and Information Systems.

    5. Legal and Contractual Compliance Required

      All activities involving Institutional Data and Information Systems must comply with federal, state, and local laws, as well as university policies and contractual obligations.

  5. Roles and Responsibilities

    1. Information Security Office (ISO)

      The BGSU Information Security Office, under the direction of the Director of Information Security, is responsible for:

      1. Developing, maintaining, and enforcing this policy and related guidelines.
      2. Conducting risk assessments and security audits.
      3. Providing training and awareness programs for University Affiliates.
      4. Responding to security incidents and coordinating remediation efforts.
      5. Reviewing this policy annually, and more frequently if necessary, due to changes in technology, regulatory requirements, or university operations.
    2. University Affiliates

      University Affiliates must:

      1. Comply with this policy and related security guidelines, including the ITS Security Standards.
      2. Report suspected security incidents to the ISO immediately. To report a security incident, contact:

        Email: infosec@bgsu.edu
        BGSU Information Security Office
        Office of Information Technology Services
        419-372-0999

      3. Complete mandatory security awareness training as required.
    3. University Administration – All Divisions

      University administrators must ensure that their units comply with this policy and allocate resources to support security measures. In addition to being key stakeholders, university administrators are responsible for understanding the security risks that are associated with the decisions being made in their areas regarding Institutional Data and Information Systems. This responsibility includes collaborating with the ISO to ensure they are aware of these risks.

    4. Vendors and Contractors

      Vendors and contractors must adhere to this policy and any additional security requirements specified in their contracts with the university.

  6. Compliance and Enforcement

    The ISO will investigate reported violations and recommend appropriate sanctions to the relevant university decisional authority (e.g., Office of Human Resources, Office of the Provost, or Office of the Dean of Students).

    Violations of this policy may result in disciplinary action, including but not limited to:

    1. Suspension or loss of access privileges to Institutional Data or Information Systems.
    2. Sanctions for employees, up to and including termination of employment.
    3. Sanctions for students in accordance with the Student Code of Conduct.
    4. Sanctions for vendors and contractors, up to and including termination for default and loss of status as an active supplier.
    5. Legal action, where violations involve criminal activity.
  7. Exceptions

    Any requests for exceptions to this policy must follow the formal exception procedure as defined by the BGSU IT Security Standards Exception Procedure.

  8. Related Policies

    3341-6-7 Acceptable Uses of BGSU Information Technology
    3341-6-18 Data Use and Protection
    3341-6-62 Password Standards

Registered Date: July 16 2026

Updated: 07/21/2026 05:33PM