Defines mandatory requirements that solutions must meet to align with architecture controls and approved architecture decisions.
Defines the requirements for authorization, access governance, privileged access, access reviews, role management, and access lifecycle management for University-managed technology solutions. The standard establishes requirements that ensure access to systems, services, applications, infrastructure, and data is granted, reviewed, modified, and removed according to approved business need, least privilege, and applicable governance requirements.
Defines the University’s data classification model and the minimum handling, protection, access, retention, and governance requirements applicable to each data classification. The standard establishes consistent requirements for managing Public, Sensitive/Internal, Highly Sensitive, and Restricted data throughout its lifecycle.
Defines the requirements for protecting University data throughout its lifecycle, including classification, access protection, encryption, monitoring, retention, recovery, disposal, and governance.
Defines the governance requirements used to ensure consistent, accountable, supportable, secure, and compliant technology decisions across University-managed technology environments. The standard establishes requirements for ownership, accountability, architecture review, standards compliance, exception management, shared service governance, lifecycle management, and ongoing governance oversight.
Defines the requirements for monitoring, logging, auditability, operational visibility, alerting, and investigation support for University-managed technology solutions. The standard establishes the controls necessary to support operations, governance, security investigations, compliance activities, architecture oversight, and accountability across Innovation, Enterprise, and Regulated workloads.
Defines the requirements for protecting the confidentiality, integrity, availability, and accountability of University-managed network communications and connectivity. The standard establishes requirements for network segmentation, approved connectivity, ingress and egress controls, security boundaries, private connectivity, operational visibility, and support for identity, monitoring, governance, and data protection capabilities across University-managed technology environments.
Defines the requirements for resilience, recoverability, operational continuity, backup, restoration, and recovery for University-managed technology solutions. The standard establishes requirements for recovery objectives, resilient architecture, operational ownership, recovery validation, monitoring, shared recovery services, governance, and alignment with workload and data classifications.
Defines the requirements for the governance, approval, operation, consumption, and lifecycle management of enterprise shared services. The standard establishes how shared services may be provided and consumed across Innovation, Enterprise, and Regulated workloads while maintaining appropriate governance, security, operational accountability, workload boundaries, and compliance requirements.
Defines the University’s workload classification model for applying governance, security, operational, and compliance requirements. Workloads are classified as Innovation, Enterprise, or Regulated based on applicable data classifications, obligations, risks, and required control baselines.