Information Security

Policy number: 8.2

Policy section: Information Technology

Revised Date: August 19, 2026


1.  Definitions

Definitions of capitalized terms are set forth in Appendix A.

2.  Policy Statement

It is the policy of the University to manage and protect the confidentiality, integrity, and availability of University Data and information systems, including Personally Identifiable Information, relating to students, employees and other members of the University community, in a manner consistent with federal, state, and applicable international privacy laws. The University will implement safeguards to protect the confidentiality, integrity, and availability of information in a manner that supports its academic mission and institutional reputation. Personally Identifiable Information is protected by federal laws including but not limited to the Gramm-Leach-Bliley Act (“GLBA”) for the safeguarding of non-public information, the Family Educational Rights and Privacy Act (“FERPA”) for the protection of information contained in student records, and, to the extent applicable, the Health Insurance Portability and Accountability Act (“HIPAA”) for the management of protected health information.

The Information Security Program is designed to:

  1. to assist University employees in the identification of reasonably foreseeable internal risks to the security of Personally Identifiable Information and University Data, the assessment of the potential damage of those risks and the evaluation of the sufficiency of existing procedures, business practices, and other safeguards;
  2. to create procedures, business practices, or safeguards to minimize those risks; and
  3. to monitor and improve of the effectiveness of those procedures, business practices and safeguards.

This policy provides a minimum-security standard for University Data and does not restrict creation and enforcement of more restrictive policies for individual University administrative or academic units, provided that such additional policies conform to this policy.

3.  Purpose

The purpose of this policy is to promote effective administrative, technical, and physical safeguards for the protection of University Data, including Personally Identifiable Information, maintained by the University on the University’s Resources. University Resources are valuable institutional assets and must be managed appropriately to ensure their confidentiality, integrity, and availability in support of the University’s lawful educational, research, service and administrative activities.  The safeguards described in this policy are intended to support the University’s academic and research mission while appropriately managing institutional risk and protecting the University’s reputation. The University manages information security risk through ongoing assessment, mitigation, and governance activities designed to support the confidentiality, integrity, and availability of University Data and information systems.

4.  Applicability

This policy applies to all active members of the University community, including faculty, staff, students, vendors, contractors, and affiliates, and to authorized visitors, guests, and others who are granted access to University Data, information systems, or University Resources, including access to the University network.

5.  General

  1. All Users are responsible for protecting University Data and University Resources in accordance with this policy. At a minimum, each User must comply with the following requirements:
  2. All University-owned laptop computers must be encrypted;
  3. All University-owned computers must be configured according to OIT minimum security standards, including antivirus, password-enabled screen savers, and inventory. This security lockout feature must automatically initiate after the computer remains idle from user interaction after a predefined time period.
  4. Users must immediately report to the OIT Help Desk at help@smu.edu:
    1. stolen laptop computers and other security breaches;
    2. suspected unauthorized access to Resources or other suspected security breaches; or
    3. disclosure or suspected disclosure of Personally Identifiable Information.
  5. Users must comply with all requirements of OIT’s Information Security Incident Response Procedures, available https://www.smu.edu/oit/infosec/it-procedures. Because specific processes have been established to address security breaches, any suspected security breach should be reported immediately to the IT Help Desk, help@smu.edu.
  6. It is University policy to regulate and manage the selection, distribution, use, modification and testing of computer access authentication solutions such as biometrics and/or smart cards. Effective password management is a critical element in assuring the overall security of the University’s information systems and protection of its information assets. Unauthorized use of a computer password is a violation of University policy and may lead to disciplinary action.
  7. OIT shall establish minimum baseline standards for passwords on all multi-user systems for which it has responsibility. These standards shall include minimum length, characteristics, and expiration cycles for all Resources. OIT’s responsibility for monitoring the overall security of the University’s information technology environment includes testing the strength of passwords on all multi-user systems. The computer access authentication solution standards established by OIT are available to campus users as part of the Procedures for Using Information Technology Resources at SMU on the University web site (http://www.smu.edu/OIT/Infosec/Password).
  8. Access to University Data and information systems, including privileged or administrative access, must be granted based on documented business need and the principle of least privilege. Administrative access should be time-bound and elevated only as needed through approved mechanisms (e.g., the University’s “Make Me Admin” tool). Standing administrative privileges are not permitted.
  9. In addition to complying with the requirements of this policy, Users are directed to University Policies 8.1, Acceptable Use, 4.4, Collection of Funds, 8.3 Mobile Equipment and Mobile Services, and 8.6, Institutional Data Governance for additional requirements.

6.  Responsibilities

  1. OIT is responsible for establishing and maintaining appropriate information security safeguards for University Data and information systems. As part of the University’s Information Security Program, establishes baseline requirements for access to University Resources and University Data. OIT may employ monitoring and assessment activities to ensure that University Data and Resources are protected.
  2. Faculty and staff members are required to complete annual information security training, as applicable, to support the protection of University Data and University Resources. Training is incorporated into all full time staff and faculty new orientation requirements and must be completed within 6 months of hire and annually thereafter.
  3. Users and managers of University administrative or academic units are responsible for the security of Resources, and University Data stored within their individual domains. Each User and each manager of a University administrative or academic unit is responsible for determining whether particular University Data must be maintained in confidence and, with the assistance of OIT, for implementing and enforcing appropriate safeguards consistent with this policy
  4. Users must abide by all applicable University guidelines, policies and procedures by complying with all applicable federal and state laws and regulations.
  5. System Administrators are also responsible for promptly identifying and reporting suspected abuse or security incidents to OIT, especially any damage to or problems with files or systems. Electronic logs of all security problems and related matters must be maintained by each System Administrator.
  6. Users must cooperate with System Administrators and OIT in the investigation of suspected security incidents or misuse of University Resources.
  7. The Chief Information Security Officer (“CISO”), or a person designated by the Chief Information Officer (“CIO”), will establish and chair an Information Security Advisory Council that includes representation from Academic Affairs, the University Internal Auditor, Campus Services, Development and External Affairs, Student Affairs, and other divisions of the University. The ISAC shall meet regularly to review and recommend policy changes, additions or requests for exceptions. Each member of the Council will serve as a liaison to that member’s administrative or academic units and other units as assigned by the CISO for communication and training related to the Information Security Program.
  8. The CISO, or a person designated by the CIO, is the primary contact for the interpretation, enforcement and monitoring of this policy and the resolution of issues, including resolving conflicts between security policies and procedures of University administrative or academic units and this policy. The CISO is responsible for the administration of the University’s Information Security Program. The CISO is responsible for overseeing information security risk management activities. In the event of a conflict between this policy and any security policies or procedures of a University administrative or academic unit, this policy controls. Legal questions must be referred to the Office of Legal Affairs.
  9. Access to University Data and information systems, including privileged, administrative, or system-level access, must be granted based on documented business need and the principle of least privilege. Privileged access is restricted to authorized personnel, must be elevated only as necessary through approved mechanisms unless formally exempted, and is subject to monitoring and periodic review to ensure compliance with this policy. Failure to comply with this policy may result in corrective action consistent with University policy and applicable law. Additional sanctions are set forth in Paragraph 20 of University Policy 8.1, Acceptable Use. In situations involving an imminent threat to University Resources, the CISO is authorized to take reasonable actions necessary to protect University Data and information systems, consistent with University procedures. When possible, the CISO will follow the incident handling procedures to mitigate the threat. In an urgent situation requiring immediate action and leaving no time for collaboration, the CISO is authorized to disconnect any affected device or system from the network to protect University Data and Resources. University Resources are subject to vulnerability assessment and safeguard verification by the CISO.

7.  Protection of University Data

The University is committed to protecting the confidentiality, integrity, and availability of University Data. University Data must be protected from unauthorized access, disclosure, alteration, or destruction, regardless of format, location, or the device or system used to access or store the data.

  1. University Data may not be disclosed, transmitted, stored, or processed using systems, services, or technologies that have not been authorized in accordance with University policy. Third parties and external service providers that access, store, or process University Data must comply with applicable University information security requirements.
  2. Users will protect and safeguard against unlawful disclosure or unlawful use of any Personally Identifiable Information collected or maintained by the University in the regular course of business in accordance with University policies and applicable information security standards and procedures.
  3. Each University administrative or academic unit that collects or processes data will determine which Users may have access rights to Personally Identifiable Information. Personally Identifiable Information will be stored in the minimum number of places possible to protect the Personally Identifiable Information, while continuing to conduct University business effectively and efficiently. Access to Resources and any other records or files containing Personally Identifiable Information is restricted to those who need such information to perform their job duties.
  4. Users must comply with the following requirements:
    1. Personally Identifiable Information may only be released in accordance with University Policies, applicable standards and procedures,, and policies and procedures of University administrative or academic units;
    2. Any member of the campus community who is contacted by individuals who identify themselves as law enforcement officers or otherwise request information for law enforcement purposes must direct the requestor to the University Police Department. See University Policy 1.9, Service of Subpoenas and Agency Requests, for Information.
  5. Personally Identifiable Information will be treated as follows:
    1. Personally Identifiable Information may be stored only on University-owned or University-approved Resources.
    2. University-owned Resources or approved third-party services that store Personally Identifiable Information must be protected in accordance with University information security requirements.
  6. All Resources authorized to store or process Personally Identifiable Information must be protected in accordance with University information security requirements. In addition to the requirements relating to computing Resources, paper records or files containing Personally Identifiable Information will be kept in secured locations on the University premises. Storage of paper records containing Personally Identifiable Information outside of University premises requires appropriate University approval.]

Each University administrative or academic unit responsible for Personally Identifiable Information will arrange for the destruction of records or files containing Personally Identifiable Information that are not to be retained, by shredding, erasing, or otherwise modifying the Personally Identifiable Information to make the information unreadable or undecipherable through any means. Destruction must be performed in accordance with SMU Policy 1.25, Records Retention Policy, and applicable information security requirements.

8. Research

It is the University’s policy that all individuals involved in research at the University, including faculty, staff, and students, conduct their research-related activities and transactions in accordance with applicable research-sponsor requirements, federal and state laws and regulations, and University policies and procedures. Research data that incorporates restricted, sensitive, or regulated data, including proprietary University information, trade secrets, controlled unclassified information, or export-controlled information, must have adequate security protections in place. It is the responsibility of the Principal Investigator to properly identify the classification of research data in their custody, and to coordinate with the CISO and OIT in coordination with the Office of Research to ensure appropriate protections are in place. It is the responsibility of the Principal Investigator to immediately report any suspected or confirmed disclosure or exposure of Personally Identifiable Information or other restricted or regulated research data in the custody of the Principal Investigator to the CISO.

9. European Union (EU) Residents

The University acknowledges the rights given to European Union (EU) residents under the General Data Protection Regulation (GDPR) over how their personal data is collected, processed, and transferred. The GDPR grants EU residents the right to:

  1. Be informed about the collection and use of personal data;
  2. Access personal information collected by the University;
  3. Correct any inaccurate or incomplete personal data processed by the University;
  4. Erasure of information when it is no longer necessary for the University to retain it;
  5. Data portability;
  6. Withdraw previously given consent to process personal data;
  7. Restrict or object to processing of personal information; and
  8. Object to automated decision-making and profiling where applicable.

Please click here for the University’s GDPR privacy notice.

10. Questions

The CISO or designee shall be responsible for interpretation of this policy, resolution of problems and conflicts with departmental policies, and review of special situations. The CISO may grant documented, time-bound exceptions to this policy and associated standards following formal review, business justification, and risk evaluation. Acceptance of information security risk associated with an approved exception must be documented. Exceptions that result in material institutional risk may require written acknowledgment and approval by the appropriate Vice President or higher-level University leadership. Compliance with this policy may be monitored through security assessments, audits, or technical controls implemented to protect University Data and information systems.

Appendix A: Definitions

“Breach” means an unauthorized access to, unauthorized use of, or disclosure of unencrypted data or encrypted data along with the key used to decrypt the encrypted data that is capable of compromising the security, confidentiality, or integrity of University Data, including Personally Identifiable Information. A good faith but unauthorized acquisition of Personally Identifiable Information for lawful purposes is not considered a breach unless the information is used in an unauthorized manner or is subject to further unauthorized disclosure.

“CIO” means the Chief Information Officer of the University.

“Information Security Program” consists of the information security governance, policies, standards, procedures, and activities designed to protect University Data and University Resources

“ISAC” means the Information Security Advisory Council established by this policy.

“CISO” means the Chief Information Security Officer of the University.

“Mobile Equipment” means cellular telephones, smart phones, data cards, hotspot devices, tablets, accessories and other telecommunications equipment requiring access to a telecommunications service provider network.

“OIT” means the Office of Information Technology of the University.

“Paper Records” means physical documents created or maintained by the University which contain Personally Identifiable Information.

“Personally Identifiable Information” means information that alone or in conjunction with other information identifies an individual, including:

  1. Standalone Information - information that alone identifies an individual, including:
    1. social security number;
    2. driver’s license number or government-issued identification number; or
    3. any information described under “Combined Information” that alone identifies a person or permits access to the University’s or an individual's financial account.
  2. Combined Information - an individual's first name or first initial and last name, or other unique identifier, in combination with any one or more of the following items, if the name and the items are not encrypted (or, if encrypted, are accompanied by the key used to decrypt the encrypted information):
    1. unique biometric data, including the individual's fingerprint, voice print, and retina or iris image;
    2. personal medical information;
    3. mother’s maiden name;
    4. date of birth;
    5. financial information pertaining to an individual; or
    6. credit or debit card number (including a University-issued procurement card number), unique electronic identification number, address, routing code or financial institution account number, in combination with any required security code, access code, or password that would permit access to the University’s or an individual's financial account.
  3. Sensitive Personal Information that identifies an individual and relates to:
    1. the physical or mental health or condition of the individual;
    2. the provision of health care to the individual; or
    3. payment for the provision of health care to the individual.

Personally Identifiable Information does not include directory information described in Policy 1.10 (Privacy of Education Records (FERPA)) (applying that definition to University trustees, officers, employees, students, alumni, applicants, volunteers, donors, guests, customers and contractors engaged in University sponsored activities) or publicly available information that is lawfully made available to the public from the federal government or a state or local government.

"Principal Investigator/Project Director” means the individual solely responsible for technical conduct of a Sponsored Project, technical contact with the Sponsor, expenditure of Sponsored Project Funding, and fulfillment of technical performance and reporting obligations under an Award. "Principal Investigator” (PI) includes an individual designated in an Award as "Project Director" (PD), when performing the functions of a Principal Investigator, or other individuals performing the functions of a Principal Investigator. For the period of the Award, the Principal Investigator/Project Director must be a full-time employee (staff, tenured or, tenure track faculty, Research Professor, Research Associate Professor, Research Assistant Professor, or, if approved by the Provost or his or her designee, a non-tenure track, non-tenure eligible faculty member) appointed pursuant to University Policy 2.3, Faculty Ranks, Academic Titles, and Voting Rights.

“Research Data”: Information collected, created, received, maintained, or used in the conduct of research or other scholarly activities. Research Data incorporates restricted, sensitive, or regulated information—including proprietary University information, trade secrets, Controlled Unclassified Information (CUI), or export-controlled information.

“Responsible Official” with respect to this policy is the CIO.

“Server” is any computer which shares applications, peripherals, file storage and other Resources, with client computers on a network.

“System Abuse” means the proscribed activities described in Policy 8.1 (Acceptable Use) and any other activities deemed abusive by the CIO.

“System Administrator” means an employee of the University who has been delegated responsibility for the operation, maintenance and administration of a Server or other Resource. University Data refers to critical data necessary to the University’s operation and other information created by or for the University, or by or for University trustees, officers, employees, students, alumni, applicants, volunteers, donors, guests, customers or contractors engaged in University-sponsored activities.

“University Resources” means the University’s computing, communications, and other information technology systems and includes all hardware, software (including data and documentation), local area networks, internet systems, and applications and data stored on such information technology systems and any other electronic device or service that can store, transmit, or receive information. Resources include, but are not limited to, Servers, computers, personal computers, workstations, laptops, mainframes, minicomputers, Mobile Equipment, land line telephones, wireless devices, media.


Revised: August 19, 2026

Adopted: February 25, 2002

The official University Policy Manual is housed in the Office of the University Secretary. The University Secretary is responsible for maintaining new and updated policies and for maintaining this website. Should the official University Policy Manual conflict with any internal policies, procedures, departmental administrative rules, or guidelines, that may be contained in manuals provided by schools, departments, or divisions within the University, the official University Policy Manual controls.