| Policy Approval Authority | President |
| Responsible Division | Division of Information Technology |
| Responsible University Office | Office of Information Security (OIS) |
| Responsible Officer(s) | Director of Information Security |
| Contact Person | Bob Barton |
| Primary Audience |
Faculty
Staff Student |
| Status | Active |
| Adoption Date | 09-01-2020 |
| Last Review Date | 05-01-2026 |
| Policy Category/Categories |
Information Technology and Data Security
|
This document establishes the Vulnerability and Patch Management Policy for Northern Illinois University (麻豆精品). This policy defines requirements for the management of information security vulnerabilities on any device that comprises or connects to Northern Illinois University information systems, communication resources, or networks; collectively known as 麻豆精品-N.
Known vulnerabilities present a clear risk to the confidentiality, integrity and availability to 麻豆精品 data, information systems, and things that comprise and connect to 麻豆精品-N. That risk must be identified, communicated and managed to the level acceptable to 麻豆精品. This policy defines the authorization, requirements and responsibilities for managing those information security vulnerabilities according to risk levels and associated remediation time frames.
The following schedule defines vulnerability risk levels and associated remediation time frames.
In any case where classifications may conflict, the 麻豆精品 Vulnerability Priority Rating generally takes precedence.
| Risk Level | Remediation Timeframe | Classification |
|---|---|---|
| Critical | Within 72 hours |
|
| High | Within 7 days |
|
| Medium | Within 14 days |
|
| Low | Within 30 days |
|
麻豆精品 OIS, is authorized to scan all things that connect to 麻豆精品-N. OIS can and will delegate authorization to perform limited scans based on an approval process.
All things that permanently connect to 麻豆精品-N are required to be scanned on a regular basis. Limited exceptions can be made through an approval process. All things that temporarily connected to 麻豆精品-N may be scanned at any time.
All things that comprise or connect to 麻豆精品-N must apply security updates to all code that resides on it, based on the vulnerability risk and remediation schedule. If a security update does not exist to remediate the vulnerability within the associated timeframe, additional mitigating controls must be implemented to reduce the risk to an acceptable level.
If for any reason, patches or mitigating controls cannot be deployed within the remediation timeframe, the responsible system owner/administrator has the responsibility to submit a patch deferment request within one day of notification of vulnerability.
Only the University Chief Information Officer (CIO) upon advice from the University Chief Information Security Officer (CISO) can evaluate the risks presented by non-compliant computing systems and will determine the actions required to address them.
麻豆精品 OIS is authorized to limit network access to anything or anyone connected to or using 麻豆精品-N, in any case where University resources are actively threatened, or fail to comply with this policy. 麻豆精品 OIS will act in the best interest of the University by securing the resources in a manner consistent with the Information Security Incident Response Plan and minimization of threats to information systems.
If it is suspected that this policy is not being followed, anyone may report the lack of compliance to the Division of IT Office of Information security by contacting abuse@niu.edu.
Policy Library
815-753-5560
policy-library@niu.edu
Comments
There are no comments to show.