LETU Information Security Program Home Index (Controls, Safeguards and Compliance)
LETU Information Security Program & Compliance Reference
Security Awareness Program: Title IV Data
Data Classification Standard LETU Policy 6.2: Data Classification (Secure Document: available internally) Annual Risk Assessment (Secure Document: available internally)
NIST Framework for Improving Critical infrastructure CyberSecurity v1.1 (Secure Document: available internally)
Security Safeguards Program: Title IV Data
LETU Policy 6.12: Data Retention (Secure Document: available internally) Disposal of Disk, Tape and other Media Data Retention Procedures
Change Request Process (Secure document: available internally)
Orion Network Config Manager (Secure system: available internally)
LETU HECVAT and Cloud Vendor Guidelines (Required for approval of new Information Systems Vendors)
Acceptable Use for Technology Systems LETU Policy 6.1: Acceptable Use for Technology Systems (Secure Document: available internally)
Addtl Title IV / GLBA Safeguards References:
The Dear Colleague letter of July 29, 2015 (https://ifap.ed.gov/dpcletters/GEN1518.html and https://ifap.ed.gov/dpcletters/GEN1612.html) requires specific requirements of institutions handling Title IV data when signed up for SAIG (https://ifap.ed.gov/dpcletters/attachments/20152016SAIGFormWatermarked.pdf#page=31).
LETU InfoSec Compliance Reference: These requirements are outlined below and detailed in the LETU Information Security program & Compliance Reference.
Additional information from FSA: https://fsapartners.ed.gov/title-iv-program-eligibility/cybersecurity
Additional information from FTC RE: Safeguards: https://www.ftc.gov/legal-library/browse/rules/safeguards-rule
Additional information from FTC on Service provider Monitoring: Federal Register :: Standards for Safeguarding Customer Information (2021-Dec-09)
Additional information from EDUCAUSE:
Additional FSA Cybersecurity Compliance information is available at https://ifap.ed.gov/eannouncements/Cyber.html