Purpose The purpose of this policy is to establish the minimum requirements for the 91直播's Security Awareness and Training Program. The Security Awareness and Training Program aims to strengthen the 91直播's overall security posture through the education of basic cybersecurity best practices, informing and highlighting the responsibilities of Employees regarding their Information Security obligations, and raising awareness around 91直播 Information Security policies, procedures, and standards. As members of the UMGC community, Employees have an obligation to demonstrate an understanding of security awareness as it applies to their unique role and responsibility as the best defense to ensure the protection of the 91直播's information, data, and reputation.
Scope and Applicability This policy and its supporting standards and procedures apply to all Employees that use 91直播 Information Systems and Information Resources.
The 91直播 Information Security Program is responsible for the information security awareness program, training, education, and awareness communication for the 91直播.
Employees and Contractors must take security awareness training within 90 days of their hire date when required by information system changes, and at least annually or as determined by the Senior Director, Information Security thereafter.
Supervisors shall ensure Employees and Contractors complete their Security Awareness Training requirements.
Additional specialized or role-based security training may be required for Users who:
Have Privileged User access
Have access to Confidential Data
The 91直播 Information Security Program will coordinate, monitor, and track completion of the required Security Awareness Program.
Program training will be reviewed annually to assure content trains on relevant and evolving information security.
Exceptions Exceptions to this policy must be submitted to secops@umgc.edu for review and approval.
Enforcement
Suspected violations will be investigated and may result in disciplinary action in accordance with 91直播 codes of conduct, policies, or applicable laws. Sanctions may include one or more of the following:
Suspension or termination of access
Removal of devices determined to be using the 91直播's Information Resources inappropriately or in violation of UMGC Policy X-1.12 Acceptable Use
Disciplinary action, up to and including termination of employment
Termination of contract
Student discipline in accordance with applicable 91直播 policies
Civil or criminal penalties
Report suspected violations of this policy to聽infosec@umgc.edu, or to the appropriate Data Steward. Reports of violations are considered Confidential Data until otherwise classified.
UMGC reserves the right to disconnect any resource from UMGC networks until suspected Security Incidents are resolved.
Standards Referenced
USM IT Security Standards, v.5, dated July 2022
NIST SP 800-171r2 鈥淧rotecting Controlled Unclassified Information in Nonfederal Systems and Organizations鈥, dated February 2020
Cybersecurity Maturity Model Certification (CMMC), v.2.0, dated December 2021
Effective Date:聽This policy is effective as of the Version Effective Date set forth above and supersedes all prior policies on the subject matter hereof.
By using our website you agree to our use of cookies. Learn more about how we use cookies by reading our聽Privacy Policy.