TCR-IT-001: IT Policy Overview
Summary
Section titled “Summary”TCR is committed to a secure, efficient, and regulatory-compliant operational environment. This page is a centralized summary of the policies that support that commitment, so students, faculty, and staff have a single place to find the standard expected of them and a link to the full policy.
Policies
Section titled “Policies”- Password Creation & Management — how passwords are created, rotated, and protected across TCR systems.
- Device (EOL) Policy — securely decommissioning and disposing of devices at end of life.
- Acceptable Use Policy (AUP) — acceptable/unacceptable use of TCR’s IT resources, with signable summaries for staff and iPad users.
- Device Acceptable Use Policy — care, security, and return requirements specific to TCR-issued devices.
- Data Privacy and Protection — principles and rights around personal data, in line with FERPA, COPPA, PPRA, and HIPAA.
- BYOD Policy — rules for connecting personal devices to TCR’s network.
- Data Governance & Information Security — how TCR’s data assets and information systems are secured, including backup infrastructure.
- Security Awareness & Training — mandatory cybersecurity training for staff.
- Vendor & Contract Management — vendor selection, contract negotiation, and renewal tracking.
- Incident Response Plan — detection, containment, recovery, and post-incident review for cybersecurity incidents.
- Onboarding Process — IT steps for bringing a new employee’s accounts and equipment online.
- Offboarding Process — IT steps for revoking access and retrieving equipment when someone leaves.
- Surveillance System Policy — responsible use, access, and retention rules for on-campus security cameras.
- AI Usage Policy — guidelines for staff use of AI tools, with a focus on FERPA compliance.
- PCI DSS Policy — how TCR meets PCI DSS requirements by keeping cardholder data with third-party processors.
Why it exists
Section titled “Why it exists”New policies tend to pile up faster than anyone can track individually. This overview exists so no one has to already know which numbered policy covers a given topic before they can find it.
Compliance
Section titled “Compliance”Adherence to these policies is mandatory for all TCR community members. Non-compliance may result in disciplinary action and could negatively impact TCR’s operational effectiveness and security posture.
Accessing policies
Section titled “Accessing policies”All policies are accessible on this site. Printed copies are available on request from the Office of Information Technology.
- All employees: understand the basic elements of and support this program.
- IT Systems Coordinator: owner of this policy set, responsible for reviewing/updating at least once per year, including identifying, managing, executing, and deploying revisions.
- Leadership Team: final approval on the program and all of its elements.
Digitized from TCR-IT-001 - OiT Policy Overview [Rev 1.0].docx; the original is kept under source/policies/ in this repo.