  {"id":697,"date":"2020-06-05T13:15:51","date_gmt":"2020-06-05T23:15:51","guid":{"rendered":"https:\/\/www.hawaii.edu\/testinfosec\/?page_id=697"},"modified":"2021-02-26T09:54:32","modified_gmt":"2021-02-26T19:54:32","slug":"infosecprogram","status":"publish","type":"page","link":"https:\/\/www.hawaii.edu\/infosec\/infosecprogram\/","title":{"rendered":"University of Hawai\u02bbi Information Security Program"},"content":{"rendered":"<p>The University of Hawai\u02bbi System encompasses 10 accredited campuses and additional education, training, and research centers on six islands throughout the State of Hawai\u02bbi. This highly decentralized and complex organization is dedicated to the highest standards of scholarship and service, which requires an open flow of information and communication.<\/p>\n<p>Unfortunately, over the last decade, the emergence of increasing abuse by criminals of personal information used by universities, such as social security numbers and credit card or other banking information, has challenged the decentralized culture of free flow of information. In today\u2019s world, access to personal information must be restricted to uses where it is necessary and close guarded wherever it is stored or used. Those individuals whose personal information has been entrusted to the University deserve no less.<\/p>\n<p>While information security has long been the responsibility of each campus, as of 2011 the University leadership has committed to establishing and resourcing a new system-wide information security program. This approach is more cost-effective and comprehensive than is possible by continuing the decentralized approach that has been in use.<\/p>\n<p>The University of Hawai\u02bbi Information Security Program is composed of the following strategic areas:<\/p>\n<ol>\n<li>Data Governance and Oversight<\/li>\n<li>Information Security Audits &amp; Risk Assessments<\/li>\n<li>Information Security Policies &amp; Procedures<\/li>\n<li>Identity Management &amp; Access Controls<\/li>\n<li>Information Security Training and Awareness<\/li>\n<\/ol>\n<h2>Information Security Governance Structure<\/h2>\n<p>Additionally, the University has established an Information Security Governance Structure. This leadership group is tasked with ensuring that all information security policies, procedures and other initiatives are implemented and maintained within their authorities. It is composed of senior campus administrators (appointed by their Chancellors) and IT Security Leads (technology support staff designated by their campus leadership or dean\/director). This leadership group meets each semester and once during summer. <\/p>\n<h2>Keeping Personally Identifiable Information Private @ UH<\/h2>\n<p>Protecting Personally Identifiable Information (PII) is everyone&#8217;s responsibility at the University of Hawai\u02bbi. Understanding what PII is and how to protect it is extremely important to ensuring that the data does not get into the wrong hands or inadvertently exposed. If you suspect that data has been exposed, or someone is inappropriately handling sensitive information, please report it at <a href=\"mailto:infosec@hawaii.edu\">infosec@hawaii.edu<\/a> (or see <a href=\"..\/notification\/\">Report Security Issues or Incidents<\/a>).<\/p>\n<p><\/p>\n<p><!--this h3 header --><\/p>\n<div id=\"accordion\">\n<div class=\"card\">\n<div class=\"card-header\" id=\"headingOne\">\n            <a href=\"#\" class=\"accordion-toggle\" role=\"button\" data-toggle=\"collapse\" data-target=\"#collapseOne\" style=\"color: #006BEF\">What is Personally Identifiable Information?<\/a>\n        <\/div>\n<div id=\"collapseOne\" class=\"collapse show\" aria-labelledby=\"headingOne\">\n<div class=\"card-body\">\n                Personally Identifiable Information (PII) is the type of information that needs to be protected because the inadvertent disclosure or inappropriate access requires a breach notification or is subject to financial fines. Information such as Social Security Numbers, Driver\u2019s License numbers or <span aria-label=\"Hawaii\">Âé¶¹´«Ã½<\/span> Identification Card numbers, Financial Account numbers, PCI-DSS information, and Health information, including anything covered by the Health Insurance Portability and Accountability Act (HIPAA) are categorized as \u201cRegulated\u201d by the University of <span aria-label=\"Hawaii\">Âé¶¹´«Ã½<\/span>.\n            <\/div>\n<\/p><\/div>\n<\/p><\/div>\n<div class=\"card\">\n<div class=\"card-header\" id=\"headingTwo\">\n            <a href=\"#\" class=\"accordion-toggle\" role=\"button\" data-toggle=\"collapse\" data-target=\"#collapseTwo\" style=\"color: #006BEF\">New University Data Governance and Data Classification Policies<\/a>\n        <\/div>\n<div id=\"collapseTwo\" class=\"collapse\" aria-labelledby=\"headingTwo\">\n<div class=\"card-body\">\n<p><a href=\"https:\/\/www.hawaii.edu\/policy\/ep2.215\/\">E2.215 Institutional Data Governance <i class=\"fa fa-external-link\" aria-hidden=\"true\"><\/i><\/a> \u2014 Established to provide principles governing the management and use of data and information at the University, including, but not limited to, the collection and creation, privacy and security, and integrity and quality of that data and information. <\/p>\n<p><a href=\"https:\/\/www.hawaii.edu\/policy\/ep2.214\/\">E2.214 Data Classification Categories <i class=\"fa fa-external-link\" aria-hidden=\"true\"><\/i><\/a> \u2014 Established to organize Âé¶¹´«Ã½Institutional Data into data classification categories based on the different levels of security risk and penalties that may result from the inadvertent exposure and inappropriate disclosure of those data. The categories are: Public, Restricted, Sensitive, and Regulated.<\/p>\n<\/p><\/div>\n<\/p><\/div>\n<\/p><\/div>\n<div class=\"card\">\n<div class=\"card-header\" id=\"headingThree\">\n            <a href=\"#\" class=\"accordion-toggle\" role=\"button\" data-toggle=\"collapse\" data-target=\"#collapseThree\" style=\"color: #006BEF\">Do you handle PII, &#8220;Âé¶¹´«Ã½Sensitive&#8221;, or &#8220;Âé¶¹´«Ã½Regulated&#8221; data?<\/a>\n        <\/div>\n<div id=\"collapseThree\" class=\"collapse\" aria-labelledby=\"headingThree\">\n<div class=\"card-body\">\n<p>If at any point you handle or view any sensitive data or regulated data, you must acknowledge the online General Confidentiality Notice, found at <a href=\"https:\/\/www.hawaii.edu\/its\/acer\/\">https:\/\/www.hawaii.edu\/its\/acer\/ <i class=\"fa fa-external-link\" aria-hidden=\"true\"><\/i><\/a>. The general confidentiality notice identifies the types of information that is considered sensitive and confidential (note that it is not exhaustive). The document also identifies the responsibilities of people who have access to sensitive information.<\/p>\n<p>You should also take the Information Security Awareness Training found in Laulima. This brief course goes over various topics, such as data breaches, securing information, and policy. A link to the Security Awareness Training could be found here: <a href=\"..\/training\/\">https:\/\/www.hawaii.edu\/infosec\/training\/<\/a>.<\/p>\n<\/p><\/div>\n<\/p><\/div>\n<\/p><\/div>\n<div class=\"card\">\n<div class=\"card-header\" id=\"headingFour\">\n            <a href=\"#\" class=\"accordion-toggle\" role=\"button\" data-toggle=\"collapse\" data-target=\"#collapseFour\" style=\"color: #006BEF\">Do you store &#8220;Âé¶¹´«Ã½Regulated&#8221; data electronically or in paper format?<\/a>\n        <\/div>\n<div id=\"collapseFour\" class=\"collapse\" aria-labelledby=\"headingFour\">\n<div class=\"card-body\">\n<p>According to <span aria-label=\"Hawaii\">Âé¶¹´«Ã½<\/span> Revised Statutes (HRS) 487N-7, any personal information system (regardless if it is paper-based or electronic) needs to be reported. For the University of <span aria-label=\"Hawaii\">Âé¶¹´«Ã½<\/span>, this information needs to be reported in the <a href=\"https:\/\/www.hawaii.edu\/its\/information\/survey\/\">Personal Information Survey site <i class=\"fa fa-external-link\" aria-hidden=\"true\"><\/i><\/a>. This information survey MUST be reviewed and updated yearly.<\/p>\n<\/p><\/div>\n<\/p><\/div>\n<\/p><\/div>\n<div class=\"card\">\n<div class=\"card-header\" id=\"headingFive\">\n            <a href=\"#\" class=\"accordion-toggle\" role=\"button\" data-toggle=\"collapse\" data-target=\"#collapseFive\" style=\"color: #006BEF\">Are you responsible for a server running on the Âé¶¹´«Ã½Network?<\/a>\n        <\/div>\n<div id=\"collapseFive\" class=\"collapse\" aria-labelledby=\"headingFive\">\n<div class=\"card-body\">\n<p>If you are hosting a server on the University of <span aria-label=\"Hawaii\">Âé¶¹´«Ã½<\/span> network (regardless if it is behind a firewall) MUST be registered on the <a href=\"https:\/\/www.hawaii.edu\/its\/server\/registration\/\">Server Registration site <i class=\"fa fa-external-link\" aria-hidden=\"true\"><\/i><\/a>. In addition to registering your server, it must be scanned for vulnerabilities and sensitive information yearly. More information on this requirement can be found here: <a href=\"https:\/\/hawaii.edu\/askus\/1312\">https:\/\/hawaii.edu\/askus\/1312 <i class=\"fa fa-external-link\" aria-hidden=\"true\"><\/i><\/a>. <\/p>\n<\/p><\/div>\n<\/p><\/div>\n<\/p><\/div>\n<div class=\"card\">\n<div class=\"card-header\" id=\"headingSix\">\n            <a href=\"#\" class=\"accordion-toggle\" role=\"button\" data-toggle=\"collapse\" data-target=\"#collapseSix\" style=\"color: #006BEF\">Information Security is ALL OUR Responsibility<\/a>\n        <\/div>\n<div id=\"collapseSix\" class=\"collapse\" aria-labelledby=\"headingSix\">\n<div class=\"card-body\">\n<p>Everyone is responsible for the privacy of sensitive information. This task should not be left for one person to accomplish. It requires everyone&#8217;s comprehension and participation to be effective. Everyone should know and understand the procedures of securing data at the University of <span aria-label=\"Hawaii\">Âé¶¹´«Ã½<\/span>.<\/p>\n<\/p><\/div>\n<\/p><\/div>\n<\/p><\/div>\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>The University of Hawai\u02bbi System encompasses 10 accredited campuses and additional education, training, and research centers on six islands throughout the State of Hawai\u02bbi. This highly decentralized and complex organization is dedicated to the highest standards of scholarship and service, &hellip; <\/p>\n","protected":false},"author":86,"featured_media":0,"parent":0,"menu_order":0,"comment_status":"closed","ping_status":"closed","template":"page-onecolumn.php","meta":{"footnotes":""},"class_list":["post-697","page","type-page","status-publish","hentry"],"_links":{"self":[{"href":"https:\/\/www.hawaii.edu\/infosec\/wp-json\/wp\/v2\/pages\/697","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.hawaii.edu\/infosec\/wp-json\/wp\/v2\/pages"}],"about":[{"href":"https:\/\/www.hawaii.edu\/infosec\/wp-json\/wp\/v2\/types\/page"}],"author":[{"embeddable":true,"href":"https:\/\/www.hawaii.edu\/infosec\/wp-json\/wp\/v2\/users\/86"}],"replies":[{"embeddable":true,"href":"https:\/\/www.hawaii.edu\/infosec\/wp-json\/wp\/v2\/comments?post=697"}],"version-history":[{"count":19,"href":"https:\/\/www.hawaii.edu\/infosec\/wp-json\/wp\/v2\/pages\/697\/revisions"}],"predecessor-version":[{"id":1347,"href":"https:\/\/www.hawaii.edu\/infosec\/wp-json\/wp\/v2\/pages\/697\/revisions\/1347"}],"wp:attachment":[{"href":"https:\/\/www.hawaii.edu\/infosec\/wp-json\/wp\/v2\/media?parent=697"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}