USNH Cybersecurity Policies
A. Cybersecurity Policy (effective October 19, 2023)
B. Acceptable Use Policy (effective July 1, 2022)
C. Information Classification Policy (effective July 1, 2022)
D. Password Policy (effective October 4, 2022)
E. Privacy Policy (effective August 1, 2022)
USNH Cybersecurity Standards
- Artificial Intelligence Standard (effective 30 May 2024)
- Email Security Standard (effective 30 May 2024)
- Digital Millennium Copyright Act Requirements (DMCA) (effective 30 May 2024)
- Training & Awareness Standard (effective 30 May 2024)
- Security Categorization Standard (effective 17 SEPT 2024)
- Shared File Management Standard (effective 30 May 2024)
- USNH Data Security Addendum (effective 30 May 2024)
- System Security Plan Template (effective 30 May 2024)
- Endpoint Management Standard (effective 17 December 2024)
- Internet of Things Usage Standard (effective 30 May 2024)
- Mobile Device Security Standard (effective 30 May 2024)
- Vulnerability and Patch Management Standard (effective 30 May 2024)
- IT Inventory Standard (effective 17 December 2024)
- Access Management Standard (effective 30 May 2024)
- Account Management Standard (effective 30 May 2024)
- Access to Password Protected Information Standard (effective 30 May 2024)
- Privileged Access Management Standard (effective 30 May 2024)
- Remote Access Security Standard (effective 30 May 2024)
- Sponsored Accounts Standard (effective 30 May 2024)
- Network Security and Management Standard (effective 30 May 2024)
- Privately Managed Network Standard (effective 30 May 2024)
- Physical and Camera Security Standard (effective 30 May 2024)
- Lab Security Standard (effective 17 December 2024)
- Exception Standard (effective 30 May 2024)
- Incident Response Standard (effective 30 May 2024)
- Risk Acceptance Standard (effective 30 May 2024)
- Risk Management Standard (effective 30 May 2024)
- Configuration Management Standard (effective 30 May 2024)
- Security Monitoring and Log Management Standard (effective 30 May 2024)
- Third-Party Information Security Standard (effective 30 May 2024)
- USNH Written Information Security Program (effective 10 September 2024)
Standards
In Force:
- Cybersecurity Exception Standard (effective 15 FEB 2021)
- Cybersecurity Risk Management Standard (effective 15 FEB 2021)
- Cybersecurity Risk Acceptance Standard (effective 15 FEB 2021)
- Security Categorization Standard (effective 15 FEB 2021)
- Endpoint Management Standard (effective 10 AUG 2021)
- Access Management Standard (effective 19 AUG 2021)
- Cybersecurity Awareness & Training Standard (effective 19 AUG 2021)
- Privately Managed Network Standard (effective 19 AUG 2021)
- Vendor Cloud Service Security Standard (effective 19 AUG 2021)
- Access to Password Protected Information Standard (effective 6 JAN 2022)
- Digital Millennium Copyright Act Standard (DMCA) (effective 29 JAN 2022)
- Network Security and Management Standard (effective 29 JAN 2022)
- Sponsored Accounts Standard (effective 10 FEB 2022)
ET&S Policy & Standard Initiative
Technology/Cybersecurity Policies & Standards
Provide Feedback on Proposed Policies
Sign-up to Receive Policy & Standard Initiative Updates via Email
- Endpoint Management Standard (effective 6 AUG 2021)
- Cybersecurity Awareness and Training (effective 6 AUG 2021)
- Vendor Cloud Service Security (effective 6 AUG 2021)
- Privately Managed Network (effective 6 AUG 2021)
- Access Management (effective 6 AUG 2021)
Policies
In Force:
- USNH Use of Technological Resources Policy
- USNH Password Policy (effective 20 JAN 2020)
- USNH Privacy Policy (effective AUG 2018)
Proposed
Targeted effective date 01 MAY 2021
Feedback on or questions about these Proposed Policies can be submitted here.
Standards
In Force
- Cybersecurity Exception Standard (effective 15 FEB 2021)
- Cybersecurity Risk Management Standard (effective 15 FEB 2021)
- Cybersecurity Risk Acceptance Standard (effective 15 FEB 2021)
- Security Categorization Standard (effective 15 FEB 2021)
Proposed
Targeted effective date 01 MAY 2021
- Access Management Standard
- Cybersecurity Awareness & Training Standard
- Identity Management Standard
- Privately Managed Network Standard
- Privileged Access Management Standard
- Vendor Cloud Service Security Standard
Feedback on or questions about these Proposed Standards can be submitted here.
Planned
Phase 1 Remaining Standards, targeted to become effective 01 May 2021, will be available for review by early March 2021
- Access to Password Protected Information Standard
- Public and Sensitive Information Handling Standard
- Protected Information Handling Standard
- Restricted Information Handling Standard
- Confidential Information Handling Standard
- Endpoint Management Standard
Phase 2 Standards, targeted to become effective late summer/early fall 2021
- Account Management Standard
- Institutional Email Security and Use Standard
- Network Security and Management Standard
- Server Security and Management Standard
- Sponsored/Guest Access Management Standard
Phase 3+ Standards, planned for late 2021 and 2022
- Application Administration Standard
- Contingency Planning Standard
- Cybersecurity Roles and Responsibilities Standard
- Data Breach Notification Standard
- Data Center Facility Security, Access, and Use Standard
- Data Administration and Management Standard
- Information Technology Resource Secure Disposal Standard
- Information Technology Inventory Management Standard
- Non-Primary Identity Management Standard
- Password Management Standard
- Personnel Security Standard
- Physical Information Technology Asset Access and Management Standard
- Remote Access and VPN Standard
- Security Assessment and Testing Standard
- Security Configuration Management Standard
- Security Logging and Monitoring Standard
- Shared File Storage Standard
- System Acquisition, Development, and Maintenance Lifecycle Standard
- Vulnerability and Patch Management Standard
- Wireless Network Security and Management Standard
Contact Information
The General Cybersecurity Services Request form can be used to ask questions or raise concerns about any of the published Standards.
You can also contact the Cybersecurity GRC team at Cybersecurity.GRC@usnh.edu. However, unless specifically noted as being open for Public Comment, Standards published to this site are final, approved versions provided to allow administrative, academic, and business units an opportunity to review prior to their effective date and, if needed, request exceptions.
All other requests can be submitted here: Submit an IT Question
Failure to comply with the USNH Cybersecurity Standards puts the University System, its component institutions, and its information and information technology resources at risk and may result in disciplinary action. Disciplinary procedures will be proportionally appropriate for the individual responsible for noncompliance (e.g., students, faculty, staff, vendors) as outlined in the relevant institutional regulations for that individual (e.g., student conduct and/or applicable personnel policies). Non-compliant technology and/or activities may be mitigated as deemed necessary by the CISO and/or CIO. Employees who are members of institutionally recognized bargaining units are covered by the disciplinary provisions set forth in the agreement for their bargaining units.
Requests for exceptions to any of the USNH Cybersecurity Standards may be submitted and approved according to the requirements provided in the Cybersecurity Exception Standard.
Glossary
For terms and definitions, please refer to the National Institute of Standards and Technology Glossary.