Inside Southside / Security / Information Security

Information Security

[ Information Security | Identifty Theft Prevention| Security Awareness and Training | Acceptable Use Policy ]
[ Security Policies | Disaster Recovery Plan | BIA and RA information ]

 

 

Southside Virginia Community College (SVCC) Information Technology Security Plan will comply with COV policies, standards, and guidelines for managing information technology resources in the Commonwealth. The College’s plan will establish, implement, and maintain an information technology security program appropriate to its information technology environment and consistent with State laws, regulations, policies, procedures, and standards. The College exercises the latitude to use risk-based decision-making processes to determine the appropriate level of protection and product types to be used for obtaining compliance to COV security policies.  SVCC's Information Technology Security Plan provides a framework to enable secure communications and the appropriate protection of information resources for the College by including adequate and appropriate levels of protection for all sensitive information technology resources within the organization, including hardware, software, physical, and environmental facilities that support information technology systems, telecommunications, administrative, personnel, and data. 

The Virginia Community College System (VCCS) created technology models and guidelines to aid community colleges to better facilitate the primary components of Business Analysis and Risk Assessment, and Security Awareness.  The VCCS models and guidelines provide procedures to identify critical business processes, resources or assets; identify and evaluate potential security threats to these resources; assess how we can limit vulnerabilities to these resources; determine safeguards for these processes and resources based on defined risks; and cumulate in providing procedures for sustaining essential business operations while recovering from a significant disruption.

The SVCC Security Plan is is a dynamic document which must be updated annually.

Please review the IT Security Annual Events Checklist to identify  specific employee responsibilities.