8.2 Information Security Program

8.2 Information Security Program

Policy Tracking

Date

Policy Tracking

Date

Approved

March 13, 2023

Revised

 

Reviewed

 Revision History

  1. Overview: The College operates and maintains an Information Security Program ("ISP") to ensure the confidentiality, integrity, and availability of college data, based on classification, and those related information systems and services that are necessary to the support of the mission of the college and the students while maintaining compliance with local, State, and federal standards, policies, and laws.  The College uses the Statewide Information Security Manual published by the North Carolina Department of Information Technology as the principal cybersecurity framework for a system-wide information security and risk management program.  The College's use shall be consistent with the provisions of the State Board Code.

  2. Cybersecurity Incidents: The College shall not submit payment or otherwise communicate with an entity that has engaged in a cybersecurity incident on an information technology system by encrypting data and then subsequently offering to decrypt that data in exchange for a ransom payment.  Consistent with State law, the College consults with the North Carolina Department of Information Technology regarding cybersecurity incidents.

 Change History
Version Date Comment
Current Version (v. 5) Oct 15, 2025 19:49 Jessica Harrell
v. 4 Sept 29, 2025 18:57 Jessica Harrell
v. 3 Mar 14, 2023 18:20 Jessica Harrell
v. 2 Feb 02, 2022 21:37 Amy Williford
v. 1 Oct 01, 2021 14:43 James Simmons

Blue Ridge Community College Policies and Procedures Manual