Policy Category | Policy Owner | Version Effective Date | Review Cycle | Last Reviewed | Policy Contact |
X. Information Governance, Security & Technology | SVP, General Counsel, Chief People Officer | October 1, 2025 | Every 3 years | October 1, 2025 | Information Governance |
Purpose
The purpose of this Policy is to establish the minimum requirements for the University's Security Awareness and Training Program. The Security Awareness and Training Program aims to strengthen the University's overall security posture through the education of basic cybersecurity best practices, informing and highlighting the responsibilities of Employees regarding their Information Security obligations, and raising awareness around University Information Security policies, procedures, and standards. As members of the 黑料社区 community, Employees have an obligation to demonstrate an understanding of security awareness as it applies to their unique role and responsibility as the best defense to ensure the protection of the University's information, data, and reputation.
Scope and Applicability
This Policy and its supporting standards and procedures apply to all Employees that use University Information Systems and Information Resources.
Definitions
Defined terms are capitalized throughout this Policy and can be found in the听Information Governance Glossary.
Exceptions
Exceptions to this Policy must be submitted to secops@umgc.edu for review and approval.