Policies, Standards, and Procedures
- Access Control and Authorization Standard
- Account Identity and Authentication Management Standard
- Anti-Malware Standard
- Business Application Security Standard
- Business Continuity and Disaster Recovery
- Cloud Services, System Development, and Supply Chain Management Standard
- Configuration Management and Change Management Standard
- Data Protection and Classification Standard
- Data Retention Backup and Archive Standard
- E-mail Use and Security Standard
- Encryption Security Standard
- Endpoint Security Standard
- Information Security Incident Management and Breach Notification Standard
- Information Security Planning Standard
- Information Security Risk Assessment Standard
- Logging and Monitoring Standard
- Network Security Standard
- Personnel Security Standard
- Physical Security Standard
- Remote Access Standard
- Security Control Exception Standard
- Security Assessment and Authorization Standard
- Security Awareness and Training Standard
- Software Development Standard
- System Decommission and Data Destruction Standard
- System and Information Integrity Standard
- Vulnerability Management Standard
- Wireless and IoT Standard
- Access Control and Authorization Procedure
- Account Identity and Authentication Procedure
- Anti-Malware Procedure
- Business Application Security Procedure
- Business Continuity and Disaster Recovery Procedure
- Cloud Services, System Development, and Supply Chain Management Procedure
- Configuration Management and Change Management Procedure
- Control Exception Procedure
- Data Protection and Classification Procedure
- Data Retention, Backup, and Archive Procedure
- E-Mail Use and Security Procedure
- Encryption Security Procedure
- Endpoint Security Procedure
- Information Security Incident Management and Breach Notification Procedure
- Information Security Planning Procedure
- Information Security Risk Assessment Procedure
- Logging and Monitoring Procedure
- Network Security Procedure
- Personnel Security Procedure
- Physical Security Procedures
- Remote Access Procedure
- Security Assessment and Authorization Procedure
- Security Awareness and Training Procedure
- Software Development Procedure
- System and Information Integrity Procedure
- System Decommission and Data Destruction Procedure
- Vulnerability Management Procedure
- Wireless and IoT Security Procedure
WSU’s Information Security Program (ISP) is managed and operated by the university’s central Information Technology Services (ITS) department. Within ITS, the ISP has a broad role and responsibility with respect to information security and privacy across the institution. The mission of WSU’s ISP is to provide clear and flexible information security and privacy policies, standards, and procedures to mitigate risk and enable WSU to safely carry out its mission and accomplish its strategic goals.
The ISP exists to appropriately protect, maintain, and ensure legal, compliant, and appropriate use of the university’s information technology assets. Security and privacy policies work together to lay the foundation for the campus community to build and operate a high quality and trusted campus computing environment.
To complement the requirements outlined in WSU’s University Policies and Procedures Manual (UPPM), OISA created associated standards and provides guidance on operationalizing the policies through example procedures to ensure compliance with applicable policies, laws, and regulations.
All users and WSU departments are expected to help safeguard and secure WSU institutional information and information resources by adhering to these policies and standards where applicable, or to request an exception.
Please report suspected violations to abuse@wsu.edu.