Cybersecurity Training, Compliance, and Remediation Standards
Purpose
Information Security has a critical role in ensuring the university community has a practical understanding of cybersecurity risks. As required by the Information Security Policy, Information Security promulgates the BU Data Protection Standards to provide guidance and direction for safeguarding data in today’s complex environment. To be effective, Information Security must communicate and provide training on cyber risks and the Standards, monitor for compliance, and remediate issues.
Scope
The Data Protection Standards apply to all University Data, both physical and electronic, throughout Boston University. This standard defines the responsibilities of Information Security to train, monitor, and remediate cybersecurity issues across the university.
Roles and Responsibilities
BU Information Security
To promote cybersecurity awareness and ensure policy compliance, Information Security will:
- Supplement policies by providing guidance to the university community on cybersecurity topics, including meeting the Standards’ requirements.
- Provide training and consulting on cybersecurity and the Standards to the University community.
- Conduct cybersecurity policy and standard compliance reviews.
- Alert individuals and organizations that are not complying with the Standards and provide additional training and consulting services to remediate issues.
Standards
Training Program
BU Information Security will organize training programs to support the University’s efforts in protecting Sensitive Information. These programs will raise awareness of information security issues and ensure the community understands the requirements of the Data Protection Standards.
This training is general in nature, providing an overview of information security and the legal and regulatory context in which we operate. It is not intended to replace regulation-specific training that may be required of people conducting specific duties and needing specific information about those duties. For example, FERPA training is and remains the responsibility of the Registrar’s Office.
Compliance Monitoring
BU Information Security and IS&T will employ technologies and processes to monitor our cybersecurity risks. These technologies monitor activities at a broad level and do not target specific individuals, though specific individuals may be identified as non-compliant as a result. Further investigation targeted at specific individuals will adhere to the Access to Electronic Information Policy, but discovered non-compliance may addressed directly.
Relationship to Internal Audit
The activities covered in this standard do not replace or affect the scope of other University audit requirements and do not affect Internal Audit’s authority to conduct any audit or to take or recommend any action relating to information security as the result of an audit. The Information Security and Internal Audit functions at Boston University should work together and exchange information to support their respective functions.
Remediation Processes
When an issue with compliance with the Data Protection Standards is identified, Information Security will:
- Document the non-compliance.
- Alert the individual owner or system administrator to what was found
- Provide appropriate information regarding complying with the Data Protection Standards. Training will be offered where appropriate or desired.
- Offer consulting to help prevent future violations
- Work with the individual or representative of the organization to establish a timeline for the remediation based upon the severity of the risk, the business needs of the client, availability of appropriate technology and other appropriate considerations.
Escalation Process
Information Security may escalate issues through layers of management based on the severity of the non-compliance or the number of times non-compliance has been detected. If appropriate, access by the offending account overall or to a system or specific data may be suspended until a remediation plan is agreed to and enacted.
Legal Obligations
If IS&T learns of a data breach, the University will notify state or federal authorities or individuals affected by the data breach and take any other action that, in the University’s judgment, is necessary to comply with its obligations.
Exceptions
Information Security is authorized to grant exceptions to the requirements set forth in this document. Any exception granted may require the implementation of appropriate compensating controls.
In addition, Information Security may publish directives aimed at clarifying the intent of a standard to aid in the interpretation of this standard.
Important
Failure to comply with the Data Protection Standards may result in harm to individuals, organizations, or Boston University. The unauthorized or unacceptable use of University Data, including the failure to comply with these standards, constitutes a violation of University policy and may subject the User to revocation of the privilege to use University Data or Information Technology or disciplinary action, up to and including termination of employment.
Version History
| Notes | Approver | Date |
| Initial Publication of Education, Compliance, and Remediation | Information Security and Business Continuity Governance Committee | July 2013 |
| Reviewed, No Changes | Information Security and Business Continuity Governance Committee | April 2018 |
| Reviewed, No Changes | Common Services and Information Security Governance Committee | April 2019 |
| Reviewed, No Changes | Common Services and Information Security Governance Committee | April 2020 |
| Revised Standards and renamed Cybersecurity Training, Compliance, and Remediation | Common Services and Information Security Governance Committee | April 2021 |
| Reviewed, No Changes | Common Services and Information Security Governance Committee | April 2022 |
| Reviewed, No Changes | Common Services and Information Security Governance Committee | April 2023 |
| Reviewed, No Changes | Common Services and Information Security Governance Committee | April 2024 |
| Revised Standards and renamed Cybersecurity Training, Compliance, and Remediation Standards | IS&T Policy and Standards Review Committee | May 2026 |
Additional Resources Regarding This Policy
Related BU Policies, Procedures, and Standards
- Data Protection Standards Overview
- Data Classification Standard
- Data Access Management Standard
- Identity and Access Management Standards [this webpage]
- Data Lifecycle Management Standard
- Minimum Security Standards
- Cybersecurity Training, Compliance, and Remediation Standards
- Cyber Risk Assessment Standard
- Cyber Risk Management Standard
- Data Center Security Standards
- Vulnerability Management Standard
- Log Collection, Analysis, and Retention Standard
BU Websites
BU Resources
- Additional Guidance on Data Protection Standards
- 1.2.D.1 – Destruction of Paper Records and Non-Erasable Media -CD-ROMs, DVDs (Data Protection Standards Guidance)
- 1.2.D.2 – Destruction of Individual Files on Reusable Media (Data Protection Standards Guidance)
- 1.2.D.3 – Securely Erasing Entire Reusable Storage Devices (Data Protection Standards Guidance)
- 1.2.D.4 – Physically Destroying Reusable Storage Devices (Data Protection Standards Guidance)
History
This Cybersecurity Training, Compliance, and Remediation became the Cybersecurity Training, Compliance, and Remediation Standards - May 2026.