Skip to content

TCR-IT-007: Data Governance & Information Security Policy

TCR’s Data Privacy and Security Plan, describing the measures in place to protect institutional network data. Evaluated annually via staff/student feedback and made publicly available on TCR’s website.

Beyond the general commitment to data protection, TCR needs a concrete, technical account of how data is actually secured, stored, and backed up, so the institution can demonstrate compliance (Title 17 U.S. Code, Title IV Higher Education Opportunity Act) and so staff understand the real infrastructure behind the policy, not just the principle.

TCR adheres to Title 17 of the U.S. Code and Title IV of the Higher Education Opportunity Act. A partnership with the Delta County School District and Elevate Internet provides a secure network connection.

  • Online applications are configured to prevent local storage of sensitive personal information.
  • Email protection is provided through Google for Enterprise Pro.
  • Physical server security is maintained in a locked room within the Delta County School District Office of Information Technology, supplemented by an external alarm system.
  • Secured data storage uses RAID 5 protection with multiple backup systems, including shadow copy and stand-alone RAID.
  • Data is redundantly backed up at both TCR and North Fork High School, protecting against site-specific disasters.
  • Cloud-based services (SIS, LMS, word processing, and others) are maintained by their respective vendors, with additional snapshot capabilities for rapid data retrieval.
  • Password protection is layered, requiring annual updates to 9-character passwords.
  • Access to servers and sensitive information is role-specific, with MFA for high-risk services.
  • Student accounts are deactivated annually; departing employee access is deactivated immediately.
  • A secure, reliable system for distance education protects student records and ensures student verification.
  • Systems that compartmentalize student information are kept separate from each other.
  • The student information system stores sensitive information such as financial and personal data.
  • Students are provided a cloud-based email account isolated from other student software services.
  • Enrollment in online courses is managed through the Admissions Office, with unique IDs for LMS access.
  • Instructors use anti-cheating measures for online assessments (randomized questions, proctoring protocols).

Essential hard-copy records are stored in a fire-proof vault with restricted access.

TCR enforces this plan and takes appropriate action for violations. Regular audits and reviews ensure continuous compliance and improvement.

Report concerns or violations to help@tcr.edu / (970) 874-7671. By engaging with TCR’s IT resources and services, users acknowledge and consent to this plan.

  • 20 U.S.C. 6751 et seq. (Enhancing Education Through Technology Act of 2001)
  • 47 U.S.C. 254(h) (Children’s Internet Protection Act of 2000)
  • C.R.S. 22-87-101 et seq. (Children’s Internet Protection Act)
  • C.R.S. 24-72-204.5 (monitoring electronic communications)

This policy contains real infrastructure details (network partnership, backup architecture, physical server location) that are also good candidates for their own Systems & Infrastructure pages once written up in more depth.

Digitized from TCR-IT-007 - Data Governance & Information Security Policy [Rev 1.0].docx; the original is kept under source/policies/ in this repo.

Owner: IT Systems Coordinator · Revision 1 · Last reviewed Aug 18, 2026 · Next review due Aug 18, 2027