Information Systems Personnel Security
Blinn College Administrative Regulations Manual
Subject: Information Systems Personnel Security
Effective Date: March 1, 2020; amended September 19, 2023
Board Policy Reference: CS
Purpose
Develop policies and procedures for personnel security.
Process
Personnel Security Policy and Procedures (PS-01)
The College District:
- Develops, documents, and disseminates to information owners and custodians:
- A personnel security policy that addresses purpose, scope, roles, responsibilities, management commitment, coordination among organizational entities, and compliance; and
- Procedures to facilitate the implementation of the personnel security policy and associated personnel security controls; and
- Reviews and updates the current:
- Personnel security policy biennially; and
- Personnel security procedures annually.
Position Risk Designation (PS-02)
The College District:
- Assigns a risk designation to all organizational positions;
- Establishes screening criteria for individuals filling those positions; and
- Reviews and updates position risk designations annually.
Position Screening (PS-03)
The College District:
- Screens individuals prior to authorizing access to the information system; and
- Rescreens individuals according to Human Resources employment procedures.
- All authorized users (including, but not limited to, Blinn College District personnel, temporary employees, and employees of independent contractors) of the District’s information resources shall formally acknowledge that they will comply with the security policies and procedures of the District or they shall not be granted access to information resources. The method of acknowledgement is part of the required cyber security training which is conducted annually to maintain access to College District information resources.
Personnel Termination (PS-04)
The College District upon termination of individual employment:
- Disables information system access within 24 hours;
- Terminates/revokes any authenticators/credentials associated with the individual;
- Conducts exit interviews that include a discussion of topics determined by Human Resources procedures;
- Retrieves all security-related organizational information system-related property;
- Retains access to organizational information and information systems formerly controlled by terminated individual; and
- Notifies additional information owners within 48 hours.
Personnel Transfer (PS-05)
The College District:
- Reviews and confirms ongoing operational need for current logical and physical access authorizations to information systems/facilities when individuals are reassigned or transferred to other positions within the organization;
- Initiates standard account modification procedures within 48 hours;
- Modifies access authorization as needed to correspond with any changes in operational need due to reassignment or transfer; and
- Notifies additional information owners within 48 hours.
Access Agreements (PS-06)
The College District:
- Develops and documents access agreements for organizational information systems;
- Reviews and updates the access agreements annually; and
- Ensures that individuals requiring access to organizational information and information systems:
- Sign appropriate access agreements prior to being granted access; and
- Re-sign access agreements to maintain access to organizational information systems when access agreements have been updated or biennially.
Third Party Personnel Security (PS-07)
The College District:
- Establishes personnel security requirements including security roles and responsibilities for third-party providers;
- Requires third-party providers to comply with personnel security policies and procedures established by the organization;
- Documents personnel security requirements;
- Requires third-party providers to notify information owners of any personnel transfers or terminations of third-party personnel who possess organizational credentials and/or badges, or who have information system privileges within 72 hours; and
- Monitors provider compliance.
Personnel Sanctions (PS-08)
The College District:
- Employs a formal sanctions process for individuals failing to comply with established information security policies and procedures; and
- Notifies information system owners following Human Resources and Board Policy procedures.