Data security standards Overview

Overview

Data and information are important assets of the university and must be protected from loss of integrity, confidentiality, or availability in compliance with university policy and standards, Board of Regents policy, applicable contracts, and state and federal laws and regulations. These documents define the base requirements for processing, storing, or transmitting University Data as per APM 30.11.

The standards are published here: https://www.uidaho.edu/oit/standards/data-security
Additional policies regarding technology can be found in APM chapter 30.

For any questions regarding the standards please feel free to reach out to OIT Security.

How do I meet the standards?

For students
For faculty
For staff

FAQ

Do I need to meet the requirements of each document?
What if something is vague or undefined?
What do these document mean when they say 'systems'?
What do I do if I am working with regulated data or under a contract that has additional requirements that aren't met by these standards?
How do these standards differ from the APM?

Changes to standards

April 2024 Changes:

The new revision was to make minor adjustments that do not make any material changes to the standards.

September 2023 Changes:

The new revision is primarily built to document the existing practices already in place that map to the NIST SP 800-171 controls. As a result, the impact to production systems is minimal. Changes that may be required are mostly to align similar systems that are configured differently to be aligned together. There are a few changes that required some changes to systems within IT. The owners of those systems have already been contacted and standard alignment is already underway.

Other changes include:

  • Separating controls into domains
  • Defining scopes per domain
  • Additional definitions
  • References to source NIST SP 800-171

2017 Changes:

  • Creation of standards
100% helpful - 1 review
Print Article

Related Articles (2)

Storage locations approved by OIT for storage of university data, consistent with U of I policies and standards.
Tuesday January 28th is National Data Privacy Day. You can take control of your data. Data privacy is the right to control access to your digital life and information. To find out more about Data Privacy best practices click here.

Related Services / Offerings (1)

This service includes policy exceptions, reviews & auditing, consulting (including research cyber support), TLS certificates, policy feedback, and other security or policy support.

Attachments (0)

No attachments found.