Training, Governance & Vendor Controls
All ÎÞÂë×¨Çø employees complete annual data security and privacy training, delivered through the Vector Solutions LMS. New employees complete training within 90 days of hire; all employees renew annually. The training requirement was established by presidential directive in 2015 and covers student data confidentiality, credential security, and appropriate data handling. Duo MFA is required to access the training system itself.
ÎÞÂë×¨Çø's Institutional Data Governance Policy (Policy 8.6) establishes a formal Data Governance Committee and assigns Data Stewards for every institutional data domain. The publicly accessible Data Stewards registry contains 147 entries; student data stewardship is assigned to the University Registrar.
All third-party vendors that host or access University data are assessed by the Chief Security Officer and must meet ÎÞÂë×¨Çø information security requirements. Contracts include required information security provisions per Policy 8.1, Section 14. Student records may not be stored on non-University-owned resources without CIO approval.