Page tree

Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.

...

The Information Security Office (ISO) will monitor and report on the status of University-wide business continuity management activities, plans, protocols and testing to each Dean and the Executive for each business unit on a periodic basis. Additionally, the ISO will provide regular reporting to the Board Risk Committee regarding the state of the University's Business Continuity Management Program and preparedness.

 

VI. ATTACHMENTS

A. Attachment 1, Roles and Responsibilities

B. Attachment 2, Non-Compliance and Sanctions

...


Image Added By Direction of the CIO:

_________________________________
Mira Lalovic-Hand,
VP and Chief Information Officer

ATTACHMENT 1

ROLES and RESPONSIBILITIES

A. Board of Directors

 The Board Risk Committee will: 

  • Annually review and approve this any substantial changes to this policy.
  • Maintain a general understanding of the scope of the policy and make inquiries of a responsible senior officer with respect to this policy.
  • Review reports, as and when presented to the Board Risk Committee by executive management of the University, with respect to the outcome of significant business continuity events and the resulting action plans for mitigating recurrence.

B. Deans and Business Units

 All areas are to ensure that faculty, staff, and management are familiar with incident protocols for emergencies and business disruptions. Deans and Executive management is to ensure compliance to this Business Continuity Management Policy and its supporting standards and guidelines.

...

...

C. Information Resources and Technology (IRT)

IRT is responsible for supporting the information systems and technology requirements of business management's Business Continuity Management activities. This includes supporting the development and implementation of appropriate strategies to recover infrastructure platforms and restore critical applications consistent with business management's continuity and recovery objectives. 

IRT is also responsible for overseeing the creation, execution, and testing of a formal Disaster Recovery (DR) Plan and activities related to the systems and infrastructure it supports on behalf of the businesses.  

D. Information Security Office (ISO)

The ISO is responsible for the oversight of university-wide Business Continuity Management and for making appropriate recommendations to the Board Risk Committee regarding BCP and DR strategies and activities. 

E. Legal

Upon engagement by the sponsoring business, legal supports the risk management objectives of this policy by providing advice and support with contracts impacted by this policy 

 VII.

ATTACHMENT 2

NON-COMPLIANCE AND SANCTIONS

Violations of this policy may subject the violator to disciplinary actions, up to or including termination of employment or dismissal from a school, and may subject the violator to penalties stipulated in applicable state and federal statutes. Sanctions shall be applied consistently to all violators regardless of job titles or level in the organization.

...