Download PDF
Effective Date: July 1, 2013 Revised: May 1, 2026
Standards

Cybersecurity Training, Compliance, and Remediation Standards


Purpose

Information Security has a critical role in ensuring the university community has a practical understanding of cybersecurity risks. As required by the Information Security Policy, Information Security promulgates the BU Data Protection Standards to provide guidance and direction for safeguarding data in today’s complex environment. To be effective, Information Security must communicate and provide training on cyber risks and the Standards, monitor for compliance, and remediate issues.

Scope

The Data Protection Standards apply to all University Data, both physical and electronic, throughout Boston University. This standard defines the responsibilities of Information Security to train, monitor, and remediate cybersecurity issues across the university.

 

Roles and Responsibilities

BU Information Security

To promote cybersecurity awareness and ensure policy compliance, Information Security will:

  • Supplement policies by providing guidance to the university community on cybersecurity topics, including meeting the Standards’ requirements.
  • Provide training and consulting on cybersecurity and the Standards to the University community.
  • Conduct cybersecurity policy and standard compliance reviews.
  • Alert individuals and organizations that are not complying with the Standards and provide additional training and consulting services to remediate issues.

 

Standards

 

Training Program

BU Information Security will organize training programs to support the University’s efforts in protecting Sensitive Information. These programs will raise awareness of information security issues and ensure the community understands the requirements of the Data Protection Standards.

This training is general in nature, providing an overview of information security and the legal and regulatory context in which we operate. It is not intended to replace regulation-specific training that may be required of people conducting specific duties and needing specific information about those duties. For example, FERPA training is and remains the responsibility of the Registrar’s Office.

Compliance Monitoring

BU Information Security and IS&T will employ technologies and processes to monitor our cybersecurity risks. These technologies monitor activities at a broad level and do not target specific individuals, though specific individuals may be identified as non-compliant as a result. Further investigation targeted at specific individuals will adhere to the Access to Electronic Information Policy, but discovered non-compliance may addressed directly.

Relationship to Internal Audit

The activities covered in this standard do not replace or affect the scope of other University audit requirements and do not affect Internal Audit’s authority to conduct any audit or to take or recommend any action relating to information security as the result of an audit. The Information Security and Internal Audit functions at Boston University should work together and exchange information to support their respective functions.

Remediation Processes

When an issue with compliance with the Data Protection Standards is identified, Information Security will:

  • Document the non-compliance.
  • Alert the individual owner or system administrator to what was found
  • Provide appropriate information regarding complying with the Data Protection Standards. Training will be offered where appropriate or desired.
  • Offer consulting to help prevent future violations
  • Work with the individual or representative of the organization to establish a timeline for the remediation based upon the severity of the risk, the business needs of the client, availability of appropriate technology and other appropriate considerations.

Escalation Process

Information Security may escalate issues through layers of management based on the severity of the non-compliance or the number of times non-compliance has been detected.  If appropriate, access by the offending account overall or to a system or specific data may be suspended until a remediation plan is agreed to and enacted.

Legal Obligations

If IS&T learns of a data breach, the University will notify state or federal authorities or individuals affected by the data breach and take any other action that, in the University’s judgment, is necessary to comply with its obligations.

 

Exceptions

Information Security is authorized to grant exceptions to the requirements set forth in this document. Any exception granted may require the implementation of appropriate compensating controls.

In addition, Information Security may publish directives aimed at clarifying the intent of a standard to aid in the interpretation of this standard.

Important

Failure to comply with the Data Protection Standards may result in harm to individuals, organizations, or Boston University. The unauthorized or unacceptable use of University Data, including the failure to comply with these standards, constitutes a violation of University policy and may subject the User to revocation of the privilege to use University Data or Information Technology or disciplinary action, up to and including termination of employment.

Version History

 

Notes Approver Date
Initial Publication of Education, Compliance, and Remediation Information Security and Business Continuity Governance Committee July 2013
Reviewed, No Changes Information Security and Business Continuity Governance Committee April 2018
Reviewed, No Changes Common Services and Information Security Governance Committee April 2019
Reviewed, No Changes Common Services and Information Security Governance Committee April 2020
Revised Standards and renamed Cybersecurity Training, Compliance, and Remediation Common Services and Information Security Governance Committee April 2021
Reviewed, No Changes Common Services and Information Security Governance Committee April 2022
Reviewed, No Changes Common Services and Information Security Governance Committee April 2023
Reviewed, No Changes Common Services and Information Security Governance Committee April 2024
Revised Standards and renamed Cybersecurity Training, Compliance, and Remediation Standards IS&T Policy and Standards Review Committee May 2026