[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"doc-seo-430892-105":3,"detail-sidebar-cat-0-en-105":80,"doc-detail-430892-en":130},{"code":4,"msg":5,"data":6},0,"ok",{"site_id":7,"language":8,"slug":9,"title":10,"keywords":11,"description":12,"schema_data":13,"social_meta":73,"head_meta":75,"extra_data":77,"updated_unix":79},105,"en","xavier-university-information-security-policy-effective-2222018","XAVIER UNIVERSITY - Information Security Policy - Effective 2/22/2018","","Xavier University Information Security Policy defines an Information Security Risk Management Program to protect the confidentiality, integrity, and availability of university information assets. It establishes an approach for identifying security threats, assessing vulnerabilities and risks, and implementing appropriate controls to reduce compromise risk while supporting academic freedom. The program manages risks across financial, operational, reputational, and regulatory compliance dimensions through securing information systems, enabling informed user decisions, and aligning with related risk activities, including defined ownership, review cadence, and user scope.",{"@graph":14,"@context":72},[15,34,55],{"@type":16,"itemListElement":17},"BreadcrumbList",[18,23,27,31],{"item":19,"name":20,"@type":21,"position":22},"https://docshare.wps.com","Home","ListItem",1,{"item":24,"name":25,"@type":21,"position":26},"https://docshare.wps.com/document/","Document",2,{"item":28,"name":29,"@type":21,"position":30},"https://docshare.wps.com/document/research-report/","Research & Report",3,{"item":32,"name":10,"@type":21,"position":33},"https://docshare.wps.com/document/xavier-university-information-security-policy-effective-2222018/430892/",4,{"url":32,"name":10,"@type":35,"image":36,"author":41,"headline":10,"publisher":44,"fileFormat":47,"inLanguage":8,"description":12,"dateModified":48,"datePublished":49,"encodingFormat":47,"isAccessibleForFree":50,"interactionStatistic":51},"DigitalDocument",{"url":37,"@type":38,"width":39,"height":40},"https://docshare.wps.com/thumbnails/xavier-university-information-security-policy-effective-2222018/430892.png","ImageObject",300,407,{"name":42,"@type":43},"Kurz","Person",{"url":19,"name":45,"@type":46},"DocShare","Organization","application/pdf","2026-09-30","2026-09-29",true,{"@type":52,"interactionType":53,"userInteractionCount":26},"InteractionCounter",{"@type":54},"ViewAction",{"@type":56,"mainEntity":57},"FAQPage",[58,64,68],{"name":59,"@type":60,"acceptedAnswer":61},"What is the main purpose of Xavier University’s Information Security Risk Management Program?","Question",{"text":62,"@type":63},"To identify information security threats, assess vulnerabilities of Xavier systems, and define controls that reduce risk to data and systems in compliance with applicable laws and standards.","Answer",{"name":65,"@type":60,"acceptedAnswer":66},"Who owns, and how often is the policy reviewed?",{"text":67,"@type":63},"The Associate Provost and Chief Information Officer owns the policy, and it is reviewed annually for updates or when the Information Security Office determines significant change is required.",{"name":69,"@type":60,"acceptedAnswer":70},"What does the policy require Xavier to do regarding risk assessments?",{"text":71,"@type":63},"Perform risk assessments for proposed hardware and software acquisitions and for data transmissions, and conduct periodic risk assessments of installed applications and hardware configurations to maintain the lowest attainable exposure.","https://schema.org",{"og:url":32,"og:type":74,"og:title":10,"og:site_name":45,"og:description":12},"article",{"robots":76,"canonical":32},"index,follow",{"doc_id":78,"site_id":7},430892,1790766887,{"code":4,"msg":81,"data":82},"success",[83,87,91,95,100,105,110,114,119,122,126],{"id":22,"doc_module":4,"doc_module_name":25,"category_name":84,"show_sort_weight":85,"slug":86},"Story & Novel",90,"story-novel",{"id":26,"doc_module":4,"doc_module_name":25,"category_name":88,"show_sort_weight":89,"slug":90},"Literature",80,"literature",{"id":33,"doc_module":4,"doc_module_name":25,"category_name":92,"show_sort_weight":93,"slug":94},"Exam",70,"exam",{"id":96,"doc_module":4,"doc_module_name":25,"category_name":97,"show_sort_weight":98,"slug":99},5,"Comic",60,"comic",{"id":101,"doc_module":4,"doc_module_name":25,"category_name":102,"show_sort_weight":103,"slug":104},6,"Technology",50,"technology",{"id":106,"doc_module":4,"doc_module_name":25,"category_name":107,"show_sort_weight":108,"slug":109},7,"Healthcare",40,"healthcare",{"id":111,"doc_module":4,"doc_module_name":25,"category_name":29,"show_sort_weight":112,"slug":113},8,30,"research-report",{"id":115,"doc_module":4,"doc_module_name":25,"category_name":116,"show_sort_weight":117,"slug":118},9,"Religion & Spirituality",20,"religion-spirituality",{"id":117,"doc_module":4,"doc_module_name":25,"category_name":120,"show_sort_weight":117,"slug":121},"World Cup","world-cup",{"id":123,"doc_module":4,"doc_module_name":25,"category_name":124,"show_sort_weight":123,"slug":125},10,"Lifestyle","lifestyle",{"id":127,"doc_module":4,"doc_module_name":25,"category_name":128,"show_sort_weight":96,"slug":129},19,"General","general",{"code":4,"msg":81,"data":131},{"doc_id":78,"user_id":132,"nickname":42,"user_avatar":133,"doc_module":4,"category_id":111,"category_name":29,"doc_title":10,"doc_description":12,"doc_content":134,"file_id":135,"file_url":136,"file_type":137,"file_size":138,"view_count":26,"is_deleted":4,"is_public":22,"is_downloadable":22,"audit_status":22,"page_count":139,"language":140,"language_code":8,"site_id":7,"html_lang":8,"table_of_contents":141,"faqs":142,"seo_title":143,"seo_description":12,"update_tm":144,"read_time":145},2336478945635,"https://ap-avatar.wpscdn.com/davatar_6f874abed73319feea01a86fa6f0fab8","XAVIER UNIVERSITY  \nInformation Security Policy  \nEffective: 2/22/2018  \nLast Updated: 3/08/2018  \nLast Reviewed: 10/15/2021  \nResponsible University Office: Information Security Office  \nResponsible Executive: Associate Provost and Chief Information Officer  \nScope: This policy applies to all University owned information that is present on or transmitted through University owned systems and networks. University owned information assets can take the form of electronic and hard copy information.  \nA. REASON FOR POLICY  \nThis document defines the Information Security Risk Management Program (Risk Management Program) for Xavier University. Xavier University is committed to protecting the confidentiality, integrity and availability of information assets from all threats including unauthorized access, modification or damage while also providing for the open information sharing requirements of academic freedom. The purpose is to establish the University’s approach to information security risk management and define the appropriate controls that are required to prevent compromises to information assets. The purpose of this Risk Management Program is to describe the policy and practices that identify information security threats, assess the vulnerability of Xavier information systems to those threats, and reduce risk to Xavier data and systems in compliance with applicable laws and standards. The objective of Xavier’s Risk Management Program is to support Xavier’s mission while also mitigating financial, operational, reputational and regulatory compliance risk. This Risk Management Program shall enable Xavier to accomplish its mission(s) by:  \n1. Securing the Information Systems that create, maintain, process, or transmit Xavier data.  \n2. Enabling the appropriate Xavier personnel to make well-informed decisions regarding risk and risk management.  \n3. Collaborating with other Xavier risk management activities to ensure Xavier priorities are aligned.  \nOwnership, Review and approval  \nThe Associate Provost and Chief Information Officer owns this policy. The Information Security Policy is approved as defined by the Policy Development Process at Xavier University. It is reviewed on an annual basis for update or when significant change is required by the Information Security Office.  \nAudience  \nThe Terms apply to all individuals that have access to Xavier’s information resources, including but not limited to: all faculty, staff, students, alumni, retirees, temporary workers, library patrons, visitors, contractors and vendors using University information resources, whether on‐ or off‐site (hereafter collectively referred to as “Users”) .  \nB. POLICY  \nThe Xavier Information Security Office will perform risk assessments on all proposed hardware and software acquisitions, and data transmissions and periodic risk assessments of installed software applications and hardware configurations. This is to ensure that Xavier’s risk posture is maintained at the lowest exposure attainable.  \nC. DEFINITION  \nFor the purposes of this document, these words and phrases have the following meanings: Asset – Any Information System that is a part of Xavier’s business processes  \nInformation System – A workstation, server, or other information technology resource owned and/or managed by Xavier used for electronic storage, processing or transmitting of any data or information  \nIntellectual Property – Intellectual Property is any intangible asset that consists of human knowledge and ideas. Some examples are patents, copyrights, trademarks and software.  \nRisk – Risk is the likelihood of a threat agent taking advantage of a vulnerability and the corresponding business impact. Risk is usually calculated as either a quantitative or qualitative score, and can be represented in the following equation:  \nRisk = (Likelihood of Threat/Vulnerability Event Occurrence) X (Business Impact of Event  \nOccurring)  \n• Inherent Risk – Inherent Risk is defined as the likelihood ","cbCaiqHy9Us1N8YO","https://ap.wps.com/l/cbCaiqHy9Us1N8YO","pdf",281585,11,"English","# Reason for Policy\n## Ownership, Review and approval\n## Audience\n# Policy\n# Definition\n## Asset and Information System\n## Risk, Threat, User, Vulnerability\n# Procedures\n## Methodology\n## Phase 1 - Risk Analysis\n### Threat Assessment","[{\"question\":\"What is the main purpose of Xavier University’s Information Security Risk Management Program?\",\"answer\":\"To identify information security threats, assess vulnerabilities of Xavier systems, and define controls that reduce risk to data and systems in compliance with applicable laws and standards.\"},{\"question\":\"Who owns, and how often is the policy reviewed?\",\"answer\":\"The Associate Provost and Chief Information Officer owns the policy, and it is reviewed annually for updates or when the Information Security Office determines significant change is required.\"},{\"question\":\"What does the policy require Xavier to do regarding risk assessments?\",\"answer\":\"Perform risk assessments for proposed hardware and software acquisitions and for data transmissions, and conduct periodic risk assessments of installed applications and hardware configurations to maintain the lowest attainable exposure.\"}]","XAVIER UNIVERSITY - Information Security Policy - Effective 2/22/2018 | PDF",1790653955,28]