3341-6-64 Information Security
| Applicability | All University units |
| Responsible Office | Vice President for Finance and Administration |
| Responsible Administrator | Chief Information Officer |
Policy Statement and Purpose
This policy serves as a measure to protect the confidentiality, integrity, and availability of Institutional Data as well as any Information Systems that store, process, or transmit Institutional Data. This policy establishes a framework to safeguard the university’s electronic information resources and computing and networking infrastructure from threats and to ensure compliance with applicable laws and regulations.
Policy Scope
This policy applies to all faculty, staff, students, third-party agents, contractors, and any other university affiliates authorized to access Institutional Data or use university-owned Information Systems. It encompasses all data and systems owned, managed, or used by the university, regardless of where they are stored or accessed.
Policy Definitions
Institutional Data
Data that are created, collected, stored, or managed by the university in the course of its academic, research, or administrative operations, including but not limited to student records, financial data, employee information, and research data.
Information Systems
Any hardware, software, networks, or services used to store, process, or transmit Institutional Data, including university-owned devices, cloud services, and personal devices used for university business.
Principle of Least Privilege
The Principle of Least Privilege is a foundational aspect of information security. It states that people should only have access to the minimum amount of data and systems that they require to perform the specific, intended functions of their jobs.
University Affiliate
Any individual or entity authorized to access Institutional Data or Information Systems, including faculty, staff, students, contractors, vendors, and third-party agents.
Policy
BGSU is committed to protecting the confidentiality, integrity, and availability of its Institutional Data and Information Systems. The university adopts the following principles to achieve this objective:
Data Protection
All Institutional Data must be protected in accordance with its classification, as defined by the university’s Data Use and Protection Policy.
System Security
Information Systems must be configured, maintained, and operated in a manner that minimizes risks to their security and ensures their availability for authorized use, as defined in the documentation and procedures approved by the Information Security Office, given the level of classification, value and criticality that the system and its data have to the University.
User Responsibility
All University Affiliates are responsible for safeguarding Institutional Data and Information Systems they access or use, adhering to university policies, procedures, and guidelines as defined by the Information Security Office.
Risk Management
The university will implement risk-based security measures (applying the Principle of Least Privilege) to identify, assess, and mitigate threats to Institutional Data and Information Systems.
Legal and Contractual Compliance Required
All activities involving Institutional Data and Information Systems must comply with federal, state, and local laws, as well as university policies and contractual obligations.
Roles and Responsibilities
Information Security Office (ISO)
The BGSU Information Security Office, under the direction of the Director of Information Security, is responsible for:
- Developing, maintaining, and enforcing this policy and related guidelines.
- Conducting risk assessments and security audits.
- Providing training and awareness programs for University Affiliates.
- Responding to security incidents and coordinating remediation efforts.
- Reviewing this policy annually, and more frequently if necessary, due to changes in technology, regulatory requirements, or university operations.
University Affiliates
University Affiliates must:
- Comply with this policy and related security guidelines, including the ITS Security Standards.
Report suspected security incidents to the ISO immediately. To report a security incident, contact:
Email: infosec@bgsu.edu
BGSU Information Security Office
Office of Information Technology Services
419-372-0999- Complete mandatory security awareness training as required.
University Administration – All Divisions
University administrators must ensure that their units comply with this policy and allocate resources to support security measures. In addition to being key stakeholders, university administrators are responsible for understanding the security risks that are associated with the decisions being made in their areas regarding Institutional Data and Information Systems. This responsibility includes collaborating with the ISO to ensure they are aware of these risks.
Vendors and Contractors
Vendors and contractors must adhere to this policy and any additional security requirements specified in their contracts with the university.
Compliance and Enforcement
The ISO will investigate reported violations and recommend appropriate sanctions to the relevant university decisional authority (e.g., Office of Human Resources, Office of the Provost, or Office of the Dean of Students).
Violations of this policy may result in disciplinary action, including but not limited to:
- Suspension or loss of access privileges to Institutional Data or Information Systems.
- Sanctions for employees, up to and including termination of employment.
- Sanctions for students in accordance with the Student Code of Conduct.
- Sanctions for vendors and contractors, up to and including termination for default and loss of status as an active supplier.
- Legal action, where violations involve criminal activity.
Exceptions
Any requests for exceptions to this policy must follow the formal exception procedure as defined by the BGSU IT Security Standards Exception Procedure.
Related Policies
3341-6-7 Acceptable Uses of BGSU Information Technology
3341-6-18 Data Use and Protection
3341-6-62 Password Standards
Registered Date: July 16 2026
Updated: 07/21/2026 05:33PM