Skip to main content

CA-2 Security Assessments

Description

A review of the university's information security program for compliance with Texas Administrative Code 202 standards will be performed at least biennially, based on business risk management decisions, by individual(s) independent of the information security program and designated by the university President or his or her designee.

Applicability

  • This Control applies to the university Chief Information Security Officer (CISO) who has the authority to administer the information security functions for the entire institution and is responsible for assessing and reporting to the President the status and effectiveness of security controls under Texas Administrative Code (TAC) §202.76(c). This Control is distinct from the unit security risk assessments described in RA-3 Risk Assessment.

Implementation

  • 1The Chief Information Security Officer shall develop a security assessment plan that describes the scope of the assessment including:

    • 1.1university security controls under assessment;
    • 1.2assessment procedures to be used to determine security control effectiveness; and
    • 1.3assessment environment, assessment team, and assessment roles and responsibilities.
  • 2The security assessment will:

    • 2.1review the university security controls and the environment of operation to determine the extent to which the controls are implemented correctly, operate as intended, and produce the desired outcome with respect to meeting the university’s security requirements;
    • 2.2be performed by individual(s) independent of the Office of the Chief Information Security Officer; and
    • 2.3be performed at least biennially.
  • 3The results of the security assessment shall be reported to the President or designated representative.