Administrative Policies
Information and Information Technology Policy for Security Breaches and Suspected Security BreachesPolicy Number: 4.2.6 Current Effective Date: 11/02/2010 Original Effective Date: 05/20/2008 Revision Dates: 08/06/2008, 11/02/2010 Revision Number: 2 Revision Summary: Responsible Official: Vice President Technology Solutions References: This policy applies to data in electronic form and not to hard copies of same. 4.2.6.1 DefinitionsSecurity Breach means when unencrypted confidential and restricted information of an individual is reasonably believed to have been acquired by an unauthorized person. Acquisition of Personal Information by a KCTCS employee or agent for bona fide KCTCS business purposes does not constitute a Security Breach, provided that the Personal Information is not used or subject to further unauthorized disclosure. Security Breach Coordinator, for purposes of this Policy, is the individual or functional position to whom suspected Security Breaches are reported and with overall responsibility for ensuring compliance with this Policy, by his/her respective KCTCS college or functional area. Suspected Security Breach means when a System containing Personal Information is, among other possibilities, lost or stolen, accessed in unauthorized fashion or infected by a virus or worm, but it is not yet known whether the Personal Information has been compromised to meet the level of a Security Breach. System, for purposes of this policy, is any computer or computing device, including, but not limited to, desktops, laptops, PDAs, removable media such as CDs, USB flashdrives or iPods used as storage devices. 4.2.6.2 Responsibilities and DutiesCollege Presidents and KCTCS Vice Presidents must designate a Security Breach Coordinator and ensure that that individual reads this Policy and understands his/her responsibilities thereof. Changes to a designated Security Breach Coordinator must be approved by the appropriate official and communicated to system-level Information Security Officer. Security Breach Coordinators are responsible for:
Other related duties and responsibilities may be assigned to a Security Breach Coordinator as deemed necessary. KCTCS Chief Information Officer is the designated KCTCS authority responsible for:
System-level Information Security Officer is responsible for:
4.2.6.3 Notification RequirementsIn the event of a Security Breach, KCTCS must provide notification of the breach to those individuals whose unencrypted confidential and restricted information Personal Information is reasonably believed to have been acquired by an unauthorized person. Notification must occur without unreasonable delay, except:
4.2.6.4 Security Breach Incident Response ProcessAny instance of a Suspected Security Breach must be reported immediately to the appropriate Security Breach Coordinator who will initiate the incident response process described below. Initial Reporting and AnalysisSecurity Breach Coordinator
KCTCS Chief Information OfficerAs appropriate, notifies the KCTCS President, KCTCS Chancellor, KCTCS Vice President primarily responsible for Institutional Advancement, KCTCS Legal Services. Notifies the System-level Information Security Officer. System-level Information Security OfficerIn conjunction with the Security Breach Coordinator:
KCTCS Chief Information OfficerBased on the recommendation from the System-level Information Security Officer, makes a final determination as to whether this is a Security Breach or not. Security Breach NotificationIf a Security Breach has occurred, the following steps should be taken: Security Breach CoordinatorIn conjunction with the System-level Information Security Officer, works with the KCTCS Chief Information Officer, KCTCS Vice President primarily responsible for Institutional Advancement, and KCTCS Legal Services to:
KCTCS Chief Information OfficerIn consultation with the KCTCS Chancellor, KCTCS Vice President primarily responsible for Institutional Advancement, KCTCS Legal Services, and the appropriate college official whose college or unit experienced the Security Breach, determines the most appropriate college official to sign the notification letter. Security Breach Coordinator
The KCTCS Chief Information Officer will notify the KCTCS President of the final disposition of the Security Breach incident, including a description of the incident, the response process, the notification process, and the actions taken to prevent further breaches of security.
|