DRAFT: Data Protection Standard

Purpose

This standard establishes the requirements for authorization, access governance, role management, privileged access, and access lifecycle management for University-managed technology solutions.

The standard ensures access to systems, services, applications, infrastructure, and data is granted, reviewed, modified, and removed according to approved business need, least privilege, and applicable governance requirements.

Scope

This standard applies to:

  • Applications
  • Cloud services
  • Infrastructure platforms
  • Databases
  • Software-as-a-Service solutions
  • Data platforms
  • Integration services
  • Workforce identities
  • Privileged identities
  • Application identities
  • Automation identities

Authorization Principles

Business Need

Access must be granted only in support of approved University academic, research, operational, or administrative functions.

Least Privilege

Identities shall receive only the permissions required to perform approved business functions.

Separation of Duties

Access models should separate responsibilities where appropriate to reduce operational and security risk.

Role-Based Access Control

Access should be assigned through approved roles, groups, and access models rather than direct assignment to individual identities whenever practical.

Access Management Requirements

Role-Based Access

Systems should implement role-based access control where supported and practical.

Role definitions shall be maintained and aligned to business responsibilities.

Group-Based Assignment

Group-based assignment should be used whenever practical to improve consistency, auditability, and lifecycle management.

Direct Assignment Controls

Direct assignment of permissions to individual identities should be minimized and supported by documented justification when required.

Privileged Access

Privileged access shall be governed through approved administrative access management processes.

Administrative access shall be separated from standard user access whenever practical.

  • Administrative roles shall be identifiable.
  • Privileged access shall be auditable.
  • Privileged access shall be periodically reviewed.

Access Lifecycle Management

Provisioning

Access shall be provisioned through approved onboarding and access management processes.

Modification

Access changes shall align with approved governance and change processes.

Removal

Access shall be removed when business need no longer exists.

Access Reviews

Access reviews shall be performed periodically based on workload classification, data classification, business requirements, and applicable obligations.

Access reviews should evaluate:

  • Appropriateness of access
  • Role assignments
  • Privileged access assignments
  • Inactive access
  • Orphaned accounts

Auditability

Authorization decisions, role assignments, privileged access activities, and access changes shall be auditable through approved monitoring and logging capabilities.

Workload Classification Alignment

Innovation Workloads

Access controls shall support the approved innovation workload control baseline.

Enterprise Workloads

Access controls shall support the enterprise workload control baseline and applicable data protection requirements.

Regulated Workloads

Access controls shall support enhanced authorization, governance, review, monitoring, auditability, and compliance requirements.

Architecture Review

Authorization models that significantly deviate from approved standards, access governance approaches, or architecture patterns require architecture review before implementation.

Exceptions

Exceptions to this standard require documented approval through the approved architecture exception process.