Carnegie Mellon University Website Home Page
 

Documentation

Below you will find an index of all Policies, Standards, Procedures and Guidelines published by the Information Security Office.

Policies

Name  Version
Published
Updated
Data and Computer Security Policy 1.1
05/01/1990
04/01/2001
Gramm-Leach-Bliley Act Information Security Program Policy 1.0
05/16/2003  N/A
HIPAA Information Security Policy 1.0
02/15/2008 N/A
University Computing Policy 1.0
05/16/2003 N/A
Horizontal Rule

Standards

Name  Version
Published
Updated
Site to Site VPN Standards (Coming Soon)
1.0
TBD
N/A
Horizontal Rule

Procedures 

Name  Version
Published
Updated
Procedure for Employee Separation (Coming Soon)
1.0
TBD
N/A
Procedure for Requesting Access to Network Data for Research 1.1
07/06/2006
09/04/2007
Procedure for Responding to a Compromised Computer 1.2
05/11/2006 09/04/2007
Horizontal Rule

Guidelines

Name  Version
Published
Last Updated
Guidelines for Appropriate Use of Administrator Access 1.0
12/01/2007
N/A
Guidelines for Bulk Email Distribution
1.0
10/01/2007
N/A
Guidelines for Copyright Violations
1.1
07/11/2003
10/17/2005 
Guidelines for Data Sanitization and Disposal
1.0
10/01/2007
N/A
Guidelines for Instant Messaging Security and Usage
1.0
07/21/2006
07/21/2006 
Guidelines for Mobile Device Security and Usage
1.1
03/01/2005
10/18/2005
Guidelines for Open Mail Relay Security
1.1
06/08/2004
11/03/2005
Guidelines for Password Management 1.0
12/01/2007
N/A
Guidelines for Proxy Server Security
1.1
06/20/2004
11/03/2005
Guidelines for Recursive DNS Server Operations 1.1  02/27/2003
10/17/2005
Guidelines for Web Server Security
1.0 10/28/2005 N/A
Guidelines for Windows Administrator Accounts
1.0
04/11/2006
N/A
Horizontal Rule

Regulatory Compliance

Name  Version
Published
Updated
HIPAA Security Frequently Asked Questions
1.0
02/15/2008
N/A
HIPAA Security Rule Policy Map 1.0
02/15/2008
N/A