{"id":671,"date":"2020-10-27T12:00:00","date_gmt":"2020-10-27T16:00:00","guid":{"rendered":"https:\/\/rossweb.bus.umich.edu\/ross-it\/technology\/university-information-security-requirements-systems-applications-and\/"},"modified":"2025-05-10T11:47:21","modified_gmt":"2025-05-10T15:47:21","slug":"university-information-security-requirements-systems-applications-and","status":"publish","type":"page","link":"https:\/\/rossweb-uat.bus.umich.edu\/ross-it\/university-information-security-requirements-systems-applications-and\/","title":{"rendered":"University Information Security Requirements for Systems, Applications, and Data (601.27)"},"content":{"rendered":"<p>U-M&#039;s&nbsp;<a href=\"http:\/\/spg.umich.edu\/policy\/601.27\">Information Security policy (SPG 601.27)<\/a>&nbsp;and the&nbsp;<a href=\"https:\/\/it.umich.edu\/information-technology-policies\/general-policies\/#standards\">U-M&nbsp;IT security standards<\/a>&nbsp;apply to all&nbsp;U-M&nbsp;units, faculty, staff, affiliates, and vendors&nbsp;with access to&nbsp;U-M&nbsp;institutional data. Federal or state regulations and contractual agreements may require additional actions that exceed those included in&nbsp;U-M&#039;s&nbsp;policies and standards.<\/p>\n<p>Requirements are organized by standard:<\/p>\n<ul>\n<li><a href=\"https:\/\/safecomputing.umich.edu\/information-security-requirements#DS22\">Access, Authentication, and Authorization Management<\/a><\/li>\n<li><a href=\"https:\/\/safecomputing.umich.edu\/information-security-requirements#DS16\">Awareness, Training, and Education<\/a><\/li>\n<li><a href=\"https:\/\/safecomputing.umich.edu\/information-security-requirements#DS12\">Disaster Recovery Planning and Data Backup for Information Systems and Services<\/a><\/li>\n<li><a href=\"https:\/\/safecomputing.umich.edu\/information-security-requirements#DS11\">Electronic Data Disposal and Media Sanitization<\/a><\/li>\n<li><a href=\"https:\/\/safecomputing.umich.edu\/information-security-requirements#DS15\">Encryption<\/a><\/li>\n<li><a href=\"https:\/\/safecomputing.umich.edu\/information-security-requirements#DS13\">Information Security Risk Management<\/a><\/li>\n<li><a href=\"https:\/\/safecomputing.umich.edu\/information-security-requirements#DS14\">Network Security<\/a><\/li>\n<li><a href=\"https:\/\/safecomputing.umich.edu\/information-security-requirements#DS17\">Physical Security<\/a><\/li>\n<li><a href=\"https:\/\/safecomputing.umich.edu\/information-security-requirements#DS18\">Secure Coding and Application Security<\/a><\/li>\n<li><a href=\"https:\/\/safecomputing.umich.edu\/information-security-requirements#DS19\">Security Log Collection, Analysis, and Retention<\/a><\/li>\n<li><a href=\"https:\/\/safecomputing.umich.edu\/information-security-requirements#DS-09\">Security of Enterprise Application Integration<\/a><\/li>\n<li><a href=\"https:\/\/safecomputing.umich.edu\/information-security-requirements#DS20\">Third Party Vendor Security and Compliance<\/a><\/li>\n<li><a href=\"https:\/\/safecomputing.umich.edu\/information-security-requirements#DS21\">Vulnerability Management<\/a><\/li>\n<\/ul>\n<p>Ross School of Business &ndash; 601.27 Alignment<\/p>\n<p>Below is the measure of Ross IT&rsquo;s work toward compliance with the 601.27 SPG.&nbsp;&nbsp;<\/p>\n<p>Each standard that is listed below has&nbsp;a series of security elements that need to be met to maintain and achieve compliance. The score for each standard represents the level of alignment and compliance for that standard.<\/p>\n<table border=\"1\" cellpadding=\"1\" cellspacing=\"1\" style=\"width:100%\">\n<thead>\n<tr>\n<th class=\"rteleft\" scope=\"col\">Information Security Requirements for Systems, Applications, and Data<\/th>\n<th scope=\"col\">Current<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td>Access, Authentication, and Authorization Management<\/td>\n<td class=\"rtecenter\">5<\/td>\n<\/tr>\n<tr>\n<td>Awareness, Training, and Education<\/td>\n<td class=\"rtecenter\">5<\/td>\n<\/tr>\n<tr>\n<td>Disaster Recovery Planning and Data Backup for Information Systems and Services<\/td>\n<td class=\"rtecenter\">5<\/td>\n<\/tr>\n<tr>\n<td>Electronic Data Disposal and Media Sanitization<\/td>\n<td class=\"rtecenter\">5<\/td>\n<\/tr>\n<tr>\n<td>Encryption<\/td>\n<td class=\"rtecenter\">5<\/td>\n<\/tr>\n<tr>\n<td>Information Security Risk Management<\/td>\n<td class=\"rtecenter\">5<\/td>\n<\/tr>\n<tr>\n<td>Network Security<\/td>\n<td class=\"rtecenter\">5<\/td>\n<\/tr>\n<tr>\n<td>Physical Security<\/td>\n<td class=\"rtecenter\">5<\/td>\n<\/tr>\n<tr>\n<td>Secure Coding and Application Security<\/td>\n<td class=\"rtecenter\">5<\/td>\n<\/tr>\n<tr>\n<td>Security Log Collection, Analysis, and Retention<\/td>\n<td class=\"rtecenter\">5<\/td>\n<\/tr>\n<tr>\n<td>Security of enterprise Application Integration<\/td>\n<td class=\"rtecenter\">5<\/td>\n<\/tr>\n<tr>\n<td>Third Party Vendor Security and Compliance<\/td>\n<td class=\"rtecenter\">5<\/td>\n<\/tr>\n<tr>\n<td>Vulnerability Management<\/td>\n<td class=\"rtecenter\">5<\/td>\n<\/tr>\n<tr>\n<td>&nbsp;<\/td>\n<td>&nbsp;<\/td>\n<\/tr>\n<tr>\n<td class=\"rteright\"><strong>Current Total<\/strong><\/td>\n<td class=\"rtecenter\"><strong>65<\/strong><\/td>\n<\/tr>\n<tr>\n<td class=\"rteright\"><strong>Goal Total<\/strong><\/td>\n<td class=\"rtecenter\"><strong>65<\/strong><\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<table align=\"right\" border=\"1\" cellpadding=\"1\" cellspacing=\"1\">\n<tbody>\n<tr>\n<td class=\"rtecenter\" style=\"width: 40px\"><strong>5<\/strong><\/td>\n<td><strong>Met Goal<\/strong><\/td>\n<\/tr>\n<tr>\n<td class=\"rtecenter\"><strong>4<\/strong><\/td>\n<td><strong>75% or more of goal reached<\/strong><\/td>\n<\/tr>\n<tr>\n<td class=\"rtecenter\"><strong>3<\/strong><\/td>\n<td><strong>At least 50% of goal reached<\/strong><\/td>\n<\/tr>\n<tr>\n<td class=\"rtecenter\"><strong>2<\/strong><\/td>\n<td><strong>Less then 50%<\/strong><\/td>\n<\/tr>\n<tr>\n<td class=\"rtecenter\"><strong>1<\/strong><\/td>\n<td><strong>In progress<\/strong><\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<h2>&nbsp;<\/h2>\n","protected":false},"excerpt":{"rendered":"<p>U-M&#039;s&nbsp;Information Security policy (SPG 601.27)&nbsp;and the&nbsp;U-M&nbsp;IT security standards&nbsp;apply to all&nbsp;U-M&nbsp;units, faculty, staff, affiliates, and vendors&nbsp;with access to&nbsp;U-M&nbsp;institutional data. Federal or state regulations and contractual agreements may require additional actions that exceed those included in&nbsp;U-M&#039;s&nbsp;policies and standards. Requirements are organized by standard: Access, Authentication, and Authorization Management Awareness, Training, and Education Disaster Recovery Planning and Data&#8230;<\/p>\n","protected":false},"author":4819,"featured_media":0,"parent":0,"menu_order":104,"comment_status":"closed","ping_status":"closed","template":"","meta":{"_acf_changed":false,"_seopress_titles_title":"","_seopress_titles_desc":"","_seopress_robots_index":"","_seopress_robots_follow":"","_seopress_robots_imageindex":"","_seopress_robots_snippet":"","_seopress_robots_primary_cat":"","_seopress_robots_breadcrumbs":"","_seopress_robots_freeze_modified_date":"","_seopress_robots_custom_modified_date":"","_seopress_robots_canonical":"","_seopress_social_fb_title":"","_seopress_social_fb_desc":"","_seopress_social_fb_img":"","_seopress_social_fb_img_attachment_id":0,"_seopress_social_fb_img_width":0,"_seopress_social_fb_img_height":0,"_seopress_social_twitter_title":"","_seopress_social_twitter_desc":"","_seopress_social_twitter_img":"","_seopress_social_twitter_img_attachment_id":0,"_seopress_social_twitter_img_width":0,"_seopress_social_twitter_img_height":0,"_seopress_redirections_value":"","_seopress_redirections_enabled":"","_seopress_redirections_enabled_regex":"","_seopress_redirections_logged_status":"","_seopress_redirections_param":"","_seopress_redirections_type":0,"_seopress_analysis_target_kw":"","_seopress_news_disabled":"","_seopress_video_disabled":"","_seopress_video":[],"_seopress_pro_schemas_manual":[],"_seopress_pro_rich_snippets_disable_all":"","_seopress_pro_rich_snippets_disable":[],"_seopress_pro_schemas":[],"_lmt_disableupdate":"","_lmt_disable":"","advgb_blocks_editor_width":"","advgb_blocks_columns_visual_guide":"","_kad_blocks_custom_css":"","_kad_blocks_head_custom_js":"","_kad_blocks_body_custom_js":"","_kad_blocks_footer_custom_js":"","_kadence_starter_templates_imported_post":false,"_kad_post_transparent":"","_kad_post_title":"","_kad_post_layout":"","_kad_post_sidebar_id":"","_kad_post_content_style":"","_kad_post_vertical_padding":"","_kad_post_feature":"","_kad_post_feature_position":"","_kad_post_header":false,"_kad_post_footer":false,"_kad_post_classname":"","ep_exclude_from_search":false,"footnotes":"","advanced-sidebar-menu\/link-title":"","advanced-sidebar-menu\/exclude-page":false},"categories":[],"tags":[],"ep_post_type":[45],"class_list":["post-671","page","type-page","status-publish","hentry","ep_post_type-page"],"acf":[],"taxonomy_info":[],"featured_image_src_large":false,"author_info":{"display_name":"Don DuChateau II","author_link":"https:\/\/rossweb-uat.bus.umich.edu\/ross-it\/announcements\/author\/duck\/"},"comment_info":"","coauthors":[],"author_meta":{"author_link":"https:\/\/rossweb-uat.bus.umich.edu\/ross-it\/announcements\/author\/duck\/","display_name":"Don DuChateau II"},"relative_dates":{"created":"Posted 6 years ago","modified":"Updated 1 year ago"},"absolute_dates":{"created":"Posted on October 27, 2020","modified":"Updated on May 10, 2025"},"absolute_dates_time":{"created":"Posted on October 27, 2020 12:00 pm","modified":"Updated on May 10, 2025 11:47 am"},"featured_img_caption":"","featured_img":false,"series_order":"","_links":{"self":[{"href":"https:\/\/rossweb-uat.bus.umich.edu\/ross-it\/wp-json\/wp\/v2\/pages\/671","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/rossweb-uat.bus.umich.edu\/ross-it\/wp-json\/wp\/v2\/pages"}],"about":[{"href":"https:\/\/rossweb-uat.bus.umich.edu\/ross-it\/wp-json\/wp\/v2\/types\/page"}],"author":[{"embeddable":true,"href":"https:\/\/rossweb-uat.bus.umich.edu\/ross-it\/wp-json\/wp\/v2\/users\/4819"}],"replies":[{"embeddable":true,"href":"https:\/\/rossweb-uat.bus.umich.edu\/ross-it\/wp-json\/wp\/v2\/comments?post=671"}],"version-history":[{"count":1,"href":"https:\/\/rossweb-uat.bus.umich.edu\/ross-it\/wp-json\/wp\/v2\/pages\/671\/revisions"}],"predecessor-version":[{"id":2405,"href":"https:\/\/rossweb-uat.bus.umich.edu\/ross-it\/wp-json\/wp\/v2\/pages\/671\/revisions\/2405"}],"wp:attachment":[{"href":"https:\/\/rossweb-uat.bus.umich.edu\/ross-it\/wp-json\/wp\/v2\/media?parent=671"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/rossweb-uat.bus.umich.edu\/ross-it\/wp-json\/wp\/v2\/categories?post=671"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/rossweb-uat.bus.umich.edu\/ross-it\/wp-json\/wp\/v2\/tags?post=671"},{"taxonomy":"ep_post_type","embeddable":true,"href":"https:\/\/rossweb-uat.bus.umich.edu\/ross-it\/wp-json\/wp\/v2\/ep_post_type?post=671"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}