Skip to main content

Revised System Regulation 29.01.03

· One min read
Nick McLarty
Nick McLarty
Deputy Chief Information Security Officer

A revised System Regulation 29.01.03, Information Security, was released today. This revision:

  • adds or clarifies language to reflect the reorganization of the Security Operations Center (SOC) to Texas A&M University System Cybersecurity,
  • clarifies the purpose of the Texas A&M System Security Control Standards Catalog and eliminates duplicative or redundant reference to the Texas DIR Security Control Standards Catalog,
  • adds supporting language that references system requirements to Texas statute or administrative rule,
  • establishes a required frequency for performing risk assessments based on the impact of the system being assessed,
  • moves detailed guidance for data center consolidation to the A&M System Security Control Standards Catalog, and
  • eliminates guidance for member CIO approval of commodity IT services

The revised regulation is available at https://policies.tamus.edu/29-01-03.pdf.

Identity Proofing and Verification Security Control Standards

· One min read
Nick McLarty
Nick McLarty
Deputy Chief Information Security Officer

The comment period for new security control standards regarding Identity Proofing (IA-12(2)) and Identity Evidence Validation and Verification (IA-12(3)) has closed and the new standards have been published in the A&M System Security Control Standards Catalog.

Because this is a time-sensitive procedural implementation to address actively-exploited cyber risks, the implementation date is effective September 1.

When developing your member-level procedures to implement this control standard, please also take into consideration distributed systems with user accounts for which organizations other than IT may be responsible (this includes HR for TAMUS SSO accounts, Provost/Enrollment Management/Alumni Affairs for prospective students, alumni, etc.) and ensure those administrators are properly briefed on the control requirement.

Change to Incident Reporting Process

· One min read
Nick McLarty
Nick McLarty
Deputy Chief Information Security Officer

We have made slight modifications to the incident reporting process within the TAMUS ISAO Portal. Please see the updated instructions here: https://cyber.tamus.edu/policy/guidelines/incident-notification/submit-incident/

These changes simplify the steps necessary for members to submit incident reports, eliminates extraneous actions on the back-end for TAMUS Cyber, and allows for TAMUS Cyber to communicate back-and-forth with the reporting member directly within the TAMUS ISAO Portal.

Welcome

· One min read
Nick McLarty
Nick McLarty
Deputy Chief Information Security Officer

Welcome to the Cybersecurity blog!

We will post any updates, changes, answers to questions, etc. regarding the A&M System's cybersecurity policy program here.

Related posts include System Regulation 29.01.03 (and other regulations that may have security implications), the security control standards catalog, their supporting guidelines, as well as useful information regarding the implementation of the standards.

Stay tuned!