The University of Tennessee System Office · Courses
IT
37 courses with the subject IT, each shown exactly as we captured it from the college's catalog, with every element we hold. Where the wording looks broken, that is our reading of the catalog, not the college's text.
IT 0001General Statement on Information Technology Policy
This policy establishes the University’s general cybersecurity framework, roles and responsibilities for university constituents as they relate to information technology policies and procedures, the University’s rights, and definitions for terms used throughout System-wide information technology policies.
This policy provides guidance and structure for the University to establish a risk-based Information Technology Security Program Strategy for the University.
This policy provides guidance and structure for the University to properly categorize the University’s Data to ensure that the appropriate controls are in place to provide the most effective protections.
The University of Tennessee (UT) strives to deploy information, materials, and technology that have been designed, developed, or procured to be accessible to individuals with disabilities, including those who use assistive technologies.
IT 0014Information Technology Security Awareness Training Management
This policy provides guidance and structure to the University to establish an information technology security awareness program strategy that enhances the ability to recognize threats and react accordingly.
IT 0017Information Technology Incident Response Management
This policy provides guidance and structure for the University to develop and maintain a thorough written incident response plan that includes a written process for Users to report incidents and guidance for security issues that cross multiple campus and institute boundaries.
This policy provides guidance and structure for the University to create and maintain sound processes for procuring, identifying, tracking, maintaining, and disposing of all University Information Technology Assets.
IT 0110Acceptable Use of Information Technology Resources
This policy governs the use of the university’s information technology resources in an atmosphere that encourages free exchange of ideas and an unwavering commitment to academic freedom.
This policy provides policies for information, and information system categorization, and establishes Federal Information Processing Standard 199 (FIPS 199) as the University of Tennessee’s Information Categorization model. This policy provides the definitions for creation and maintenance of a secure systems infrastructure, including both wired and wireless technologies.
IT 0123Security Awareness, Training, and Education
This document establishes policy for maintaining the security skills of the organizational users, IT personnel, and security staff. Family Educational Rights and Privacy Act (FERPA) The Family Educational Rights and Privacy Act (FERPA) (20 U.S.C. § 1232g; 34 CFR Part 99) is a Federal law that protects the privacy of student education records. The law applies to all schools that receive funds under an applicable program of the U.S. Department of Education. Health Insurance Portability and Accountability Act (HIPPA) The Administrative Simplification provisions of the Health Insurance Portability and Accountability Act of 1996 (HIPAA, Title II) required the Department of Health and Human Services (HHS) to establish national standards for electronic health care transactions and national identifiers for prov Gramm-Leach Bliley Act (GLB Act) The Financial Modernization Act of 1999, also known as the “Gramm-Leach-Bliley Act” or GLB Act, includes provisions to protect consumers’ personal financial information held by financial institutions. There are three principal parts to the privacy requirements: the Financial Privacy Rule, Safe IT00004-K Information Security Version: 1 // Effective: 06/14/2018
To establish a Physical and Environmental Protection Policy for implementing best practices with regard to the protection of facilities where information systems reside.
IT 0134M-E - System and Communication Protection Program Exceptions
Full Guidance Document > New Policy and Policy Revision Flowchart This flowchart is intended to help individuals understand the how to initiate and/or revise University policy. Full Guidance Document >
IT 0311Information Technology Data Access, Management, and Recovery
This policy provides guidance and structure for the University to complete sound Data inventory, categorization, protection, handling, and disposal practices, including backup and recovery of University Data, as well as business continuity guidance.
IT 0506Information Technology Account and Credential Management
This policy provides guidance and structure for the University to establish User Account lifecycle management and inventory processes of University accounts used for access to University Information Technology Resources. This will include guidelines for credential creation and issuance, account and credential usage, modifying access, and account termi
NIST SP 800-53 Revision 5.1, Recommended Security Controls for Information Systems and Organizations Definitions: Account Management: The identification of authorized users of the information system and the specification of access privileges. Active Directory ( AD) : The Windows OS directory service that facilitates working with interconnected, complex, and different network resources in a unified manner. Authenticator: The means used to confirm the identity of a user, process, or device (e.g., user password or token). Forest: The topmost logical container in an AD configuration that contains domains, users, computers, and group policies; the security and administrative boundary for objects and entities. Identifier: Unique data used to represent a person’s identity and associated attributes.
IT 1318Information Technology Network Monitoring and Defense and Penetration Testing
This policy provides guidance and structure for the University to establish appropriate control mechanisms for securing the University Information Technology Networks and to create a Penetration Testing process.
IT 1516Information Technology Service Provider Management and Application Software Security Management
This policy provides guidance and structure for the University to establish an IT Service Provider program that manages inventory, classifies each IT Service Provider, ensures that IT Service Provider contracts include security requirements, and securely decommissions IT Service Providers. This policy also provides guidance and structure for Universit
IT 4912Information Technology Secure Configuration Management
This policy provides guidance and structure for the University to establish configuration guidelines for University Assets, as well as cloud platforms deployed for University use.
IT 7810Information Technology Vulnerability Management, Audit Log Management, and Malware Defense Policy
This policy provides guidance and structure for the University to establish sound processes for performing Vulnerability Management, for performing threat and vulnerability monitoring, for creation and maintenance of audit logs, and for installation of anti-malware software on all University Assets.