Security Responsibilities for Distributed IT

Guidance on IT security responsibilities for IT professionals outside of the IT Division
Anyone running information systems or services at NDSU is expected to do the following:
  1. Maintain working knowledge of contemporary security practices.
  2. Maintain working knowledge of relevant policy and law.
  3. Implement all basic requirements found in NIST 800-171 Rev. 3.
  4. Design systems and services based on zero trust security model.
  5. Comply with applicable state and federal laws.
  6. Comply with North Dakota University System policy.
  7. Comply with NDSU policy.
  8. Actively participate in relevant professional groups on campus, especially IT Technical Professionals and the Cybersecurity Group.
  9. Report any security incidents to NDSU IT security and work with IT Division staff on remediation.
  10. Provide IT with contact information for after hour, weekend, and holiday emergency coordination.
  11. Promptly remediate any identified vulnerabilities.
  12. Assess all derived requirements in NIST 800-171 Rev. 3 and implement those that are appropriate to the services you are running.
The responsibilities above are ongoing activities. Designs, processes, and compliance must be continually reassessed and adjusted to address new and evolving threats.


Keywords:
security, guide, policies 
Doc ID:
118216
Owned by:
Marc W. in NDSU IT Knowledge Base
Created:
2022-04-27
Updated:
2024-09-24
Sites:
NDSU IT Knowledge Base