Security Awareness Policy
REVIEW
SCOPE
This policy outlines how information security awareness materials will be provided to the Loyola community.
PURPOSE
To ensure that all members of the Loyola community are exposed to information security awareness materials, and that they have some level of understanding of those materials.
POLICY
Methods of Delivery Information security awareness may be delivered through multiple methods. These methods include, but are not limited to:
- Information security website
- Information security blog
- Information provided via Inside Loyola Weekly
- Information provided via mass email to the Loyola community
- Information security awareness sessions
- Information provided via Loyola 101 sessions
- Information provided via new faculty orientation
- Information provided via Discover Loyola
Information Security Website - The Information Security Team will maintain a website at itsecurity.luc.edu providing information about information security concepts and best practices. This website will also house the information security blog. The website will be updated monthly at a minimum.
Information Security Blog - The Information Security Team will maintain a blog providing information about current issues and threats relating to information security. This blog will be housed on the information security website. The blog will be updated every 14 days at a minimum.
Information Provided via Inside Loyola Weekly - The information security team will work with University Marketing and Communications to send out low priority messages via Inside Loyola Weekly.
Information Provided via Mass Email to the Loyola Community - The information security team will work with University Marketing and Communications to send out high priority messages to the Loyola community via mass email distribution.
Information Security Awareness Sessions - The information security team will provide information security awareness sessions as requested by departments.
Information Provided via Loyola 101 Sessions - The information security team will meet with Human Resources on a yearly basis to ensure that information security materials included in the Loyola 101 information sessions are current and appropriate. The information security team will be available to assist in providing this information as required.
Information Provided via New Faculty Orientation - The information security team will work with Faculty Administration on a yearly basis to ensure that information security materials included in the New Faculty Orientation information sessions are current and appropriate. The information security team will be available to assist in providing this information as required.
Information Provided via Discover Loyola - The information security team will work with Residence Life on a yearly basis to ensure that information security materials included in Discover Loyola information sessions are current and appropriate. The information security team will be available to assist in providing this information as required.
EXCEPTIONS
Exceptions to this policy will be handled in accordance with the ITS Security Policy.
REVIEW
This policy will be maintained in accordance with the ITS Security Policy.
APPENDIX
Documents Referenced
ITS Security Policy
HISTORYJuly 30, 2008: Initial Policy
October 29, 2012: Annual Review for PCI Compliance
Author: UISO
Version: 1.1